Skip to content

Conversation

@dan21san
Copy link
Contributor

@dan21san dan21san commented Aug 30, 2024

Summary of the Pull Request

Add a new detection rule about detection of incoming connections via the remote connection tool AnyDesk. This could be a sign of persistence and C2 activities.

This PR is related to the closed one #4897 . Now I fixed the detection.

Changelog

new: Remote Access Tool - AnyDesk Incoming Connection

Example Log Event

N/A

Fixed Issues

N/A

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules labels Aug 30, 2024
@nasbench nasbench merged commit bd284a9 into SigmaHQ:master Sep 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants