LoFP LoFP / administrative scripts that use the same keywords.

Techniques

Sample rules

WMImplant Hack Tool

Description

Detects parameters used by WMImplant

Detection logic

condition: selection
selection:
  ScriptBlockText|contains:
  - WMImplant
  - ' change_user '
  - ' gen_cli '
  - ' command_exec '
  - ' disable_wdigest '
  - ' disable_winrm '
  - ' enable_wdigest '
  - ' enable_winrm '
  - ' registry_mod '
  - ' remote_posh '
  - ' sched_job '
  - ' service_mod '
  - ' process_kill '
  - ' active_users '
  - ' basic_info '
  - ' power_off '
  - ' vacant_system '
  - ' logon_events '