Antivirus - Hacktool Signature
Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Sigma rule (View on GitHub)
1title: Antivirus - Hacktool Signature
2id: fa0c05b6-8ad3-468d-8231-c1cbccb64fba
3status: stable
4description: |
5 Detects a highly relevant Antivirus alert that reports a hack tool or other attack tool.
6 This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
7references:
8 - https://www.nextron-systems.com/2021/08/16/antivirus-event-analysis-cheat-sheet-v1-8-2/
9 - https://www.nextron-systems.com/?s=antivirus
10author: Florian Roth (Nextron Systems), Arnim Rupp
11date: 2021-08-16
12modified: 2026-06-15
13tags:
14 - attack.execution
15 - attack.t1204
16logsource:
17 category: antivirus
18detection:
19 selection:
20 - Signature|startswith:
21 - 'ATK/' # Sophos
22 - 'Exploit.Script.CVE'
23 - 'HKTL'
24 - 'HTOOL'
25 - 'PWS.'
26 - 'PWSX'
27 - 'SecurityTool'
28 # - 'FRP.'
29 - Signature|contains:
30 - 'Adfind'
31 - 'BloodH'
32 - 'BloodyAD'
33 - 'Brutel'
34 - 'BruteR'
35 - 'Cobalt'
36 - 'COBEACON'
37 - 'Cometer'
38 - 'DumpCreds'
39 - 'EDRfreeze'
40 - 'FastReverseProxy'
41 - 'Hacktool'
42 - 'Havoc'
43 - 'Impacket'
44 - 'Keylogger'
45 - 'Koadic'
46 - 'Mimikatz'
47 - 'Nighthawk'
48 - 'PentestPowerShell'
49 - 'Potato'
50 - 'PowerSploit'
51 - 'PowerSSH'
52 - 'PshlSpy'
53 - 'PSWTool'
54 - 'PWCrack'
55 - 'PWDump'
56 - 'Responder'
57 - 'Rozena'
58 - 'Rusthound'
59 - 'Sbelt'
60 - 'Seatbelt'
61 - 'SecurityTool'
62 - 'SharpDump'
63 - 'SharpHound'
64 - 'Shellcode'
65 - 'Sliver'
66 - 'Snaffler'
67 - 'SOAPHound'
68 - 'Splinter'
69 - 'Stowaway'
70 - 'Swrort'
71 - 'Trojan.Hound'
72 - 'TurtleLoader'
73 - 'Undefend'
74 - 'Undfnd'
75 condition: selection
76falsepositives:
77 - Unlikely
78level: high
References
Related rules
- Payload Decoded and Decrypted via Built-in Utilities
- Suspicious Execution via macOS Script Editor
- Suspicious Binaries and Scripts in Public Folder
- Arbitrary Shell Command Execution Via Settingcontent-Ms
- PrinterNightmare Mimikatz Driver Name