(YARA) YARA_DebuggerCheck_GlobalFlags

Created the . Updated 1 year, 10 months ago.

            rule DebuggerCheck__GlobalFlags  {
    meta:
	description = "Rule to detect NtGlobalFlags debugger check"
        author = "Thibault Seret"
        date = "2020-09-26"
    strings:
        $s1 = "NtGlobalFlags"
    condition:
        any of them
}
        

Associated Techniques

Technique Name Technique ID's Has Snippet(s)
NtGlobalFlag U0111 B0001.036