Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Network connection from Microsoft Dialer #4834

Merged
merged 3 commits into from
Apr 29, 2024
Merged

Conversation

CertainlyP
Copy link
Contributor

@CertainlyP CertainlyP commented Apr 24, 2024

Summary of the Pull Request

Microsoft Windows Phone Dialer is a built-in utility application included in various versions of the Microsoft Windows operating system. Its primary function is to provide users with a graphical interface for managing phone calls via a modem or a phone line connected to the computer.
With the coming of teams/skype, this command has lost its purpose and is a common target of info stealers to inject into. the purpose of this detection is to look for network connections from this process.

Changelog

new: Outbound Network Connection Initiated By Microsoft Dialer

Example Log Event

N/A

Fixed Issues

N/A

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules labels Apr 24, 2024
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Welcome @CertainlyP 👋

It looks like this is your first pull request on the Sigma rules repository!

Please make sure to read the SigmaHQ conventions document to make sure your contribution is adhering to best practices and has all the necessary elements in place for a successful approval.

Thanks again, and welcome to the Sigma community! 😃

@nasbench nasbench self-assigned this Apr 24, 2024
@nasbench nasbench self-requested a review April 24, 2024 12:23
@nasbench nasbench added the Work In Progress Some changes are needed label Apr 24, 2024
@nasbench nasbench removed the Work In Progress Some changes are needed label Apr 26, 2024
@nasbench nasbench requested a review from phantinuss April 26, 2024 11:49
@nasbench nasbench added the 2nd Review Needed PR need a second approval label Apr 26, 2024
@nasbench nasbench merged commit 39db804 into SigmaHQ:master Apr 29, 2024
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants