LoFP LoFP / legitimate audio capture by legitimate user.

Techniques

Sample rules

Audio Capture via PowerShell

Description

Detects audio capture via PowerShell Cmdlet.

Detection logic

condition: selection
selection:
  CommandLine|contains:
  - WindowsAudioDevice-Powershell-Cmdlet
  - Toggle-AudioDevice
  - 'Get-AudioDevice '
  - 'Set-AudioDevice '
  - 'Write-AudioDevice '

Audio Capture via SoundRecorder

Description

Detect attacker collecting audio via SoundRecorder application.

Detection logic

condition: selection
selection:
  CommandLine|contains: /FILE
  Image|endswith: \SoundRecorder.exe