Skip to content

Conversation

Aegrah
Copy link
Contributor

@Aegrah Aegrah commented Apr 29, 2025

Summary

This rule detects when a process executes a command line containing hexadecimal characters. Malware authors may use hexadecimal encoding to obfuscate their payload and evade detection.

Conversion

This is a rule converted from Endpoint to SIEM.

@tradebot-elastic
Copy link

tradebot-elastic commented Apr 29, 2025

⛔️ Test failed

Results
  • ❌ Potential Hex Payload Execution via Common Utility (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Potential Hex Payload Execution via Command-Line (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
@tradebot-elastic
Copy link

tradebot-elastic commented Apr 29, 2025

⛔️ Test failed

Results
  • ❌ Potential Hex Payload Execution via Common Utility (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Potential Hex Payload Execution via Command-Line (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
@tradebot-elastic
Copy link

tradebot-elastic commented Apr 30, 2025

⛔️ Test failed

Results
  • ❌ Potential Hex Payload Execution via Common Utility (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Potential Hex Payload Execution via Command-Line (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
@tradebot-elastic
Copy link

tradebot-elastic commented May 6, 2025

⛔️ Test failed

Results
  • ❌ Potential Hex Payload Execution via Common Utility (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
  • ❌ Potential Hex Payload Execution via Command-Line (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
@shashank-elastic shashank-elastic merged commit 4030de9 into main May 6, 2025
11 checks passed
@shashank-elastic shashank-elastic deleted the new-rule-hex-payload-execution branch May 6, 2025 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment