134. TrueSightKiller: Another Tool to Kill Your EDR
Hello everyone!
I know you enjoy AV\EDR killers, so I decided to share information on another one with you! For example, this tool was used by Earth Ammit. I'm talking about TrueSightKiller.
Just like many other EDR killers, this one creates typical artifacts we can use for detection. For example, it loads truesight.sys driver. We can use it to build our query:
event_type: "driverloadwin"
AND
file_name: "truesight.sys"
Another typical artifact - creating a new service:
event_type: "serviceinstallwin"
AND
service_name: "TrueSight"
And finally, executables' metadata, for example:
event_type: "processcreatewin"
AND
proc_file_productname: "Truesight"
See you tomorrow!
Comments
Post a Comment