11[metadata ]
22creation_date = " 2023/05/05"
3- integration = [" endpoint" ]
3+ integration = [" endpoint" , " sentinel_one_cloud_funnel " ]
44maturity = " production"
5- updated_date = " 2025/05/05 "
5+ updated_date = " 2025/08/26 "
66
77[rule ]
88author = [" Elastic" ]
@@ -11,7 +11,7 @@ Identifies suspicious instances of communications apps, both unsigned and rename
1111conceal malicious activity, bypass security features such as allowlists, or trick users into executing malware.
1212"""
1313from = " now-9m"
14- index = [" logs-endpoint.events.process-*" ]
14+ index = [" logs-endpoint.events.process-*" , " logs-sentinel_one_cloud_funnel.* " , " endgame-* " ]
1515language = " eql"
1616license = " Elastic License v2"
1717name = " Potential Masquerading as Communication Apps"
@@ -25,6 +25,8 @@ tags = [
2525 " Tactic: Defense Evasion" ,
2626 " Data Source: Elastic Defend" ,
2727 " Resources: Investigation Guide" ,
28+ " Data Source: SentinelOne" ,
29+ " Data Source: Elastic Endgame" ,
2830]
2931timestamp_override = " event.ingested"
3032type = " eql"
@@ -35,40 +37,40 @@ process where host.os.type == "windows" and
3537 (
3638 /* Slack */
3739 (process.name : "slack.exe" and not
38- (process.code_signature.subject_name in (
40+ (process.code_signature.subject_name : (
3941 "Slack Technologies, Inc.",
4042 "Slack Technologies, LLC"
4143 ) and process.code_signature.trusted == true)
4244 ) or
4345
4446 /* WebEx */
4547 (process.name : "WebexHost.exe" and not
46- (process.code_signature.subject_name in ("Cisco WebEx LLC", "Cisco Systems, Inc.") and process.code_signature.trusted == true)
48+ (process.code_signature.subject_name : ("Cisco WebEx LLC", "Cisco Systems, Inc.") and process.code_signature.trusted == true)
4749 ) or
4850
4951 /* Teams */
5052 (process.name : "Teams.exe" and not
51- (process.code_signature.subject_name == "Microsoft Corporation" and process.code_signature.trusted == true)
53+ (process.code_signature.subject_name : "Microsoft Corporation" and process.code_signature.trusted == true)
5254 ) or
5355
5456 /* Discord */
5557 (process.name : "Discord.exe" and not
56- (process.code_signature.subject_name == "Discord Inc." and process.code_signature.trusted == true)
58+ (process.code_signature.subject_name : "Discord Inc." and process.code_signature.trusted == true)
5759 ) or
5860
5961 /* RocketChat */
6062 (process.name : "Rocket.Chat.exe" and not
61- (process.code_signature.subject_name == "Rocket.Chat Technologies Corp." and process.code_signature.trusted == true)
63+ (process.code_signature.subject_name : "Rocket.Chat Technologies Corp." and process.code_signature.trusted == true)
6264 ) or
6365
6466 /* Mattermost */
6567 (process.name : "Mattermost.exe" and not
66- (process.code_signature.subject_name == "Mattermost, Inc." and process.code_signature.trusted == true)
68+ (process.code_signature.subject_name : "Mattermost, Inc." and process.code_signature.trusted == true)
6769 ) or
6870
6971 /* WhatsApp */
7072 (process.name : "WhatsApp.exe" and not
71- (process.code_signature.subject_name in (
73+ (process.code_signature.subject_name : (
7274 "WhatsApp LLC",
7375 "WhatsApp, Inc",
7476 "24803D75-212C-471A-BC57-9EF86AB91435"
@@ -77,17 +79,17 @@ process where host.os.type == "windows" and
7779
7880 /* Zoom */
7981 (process.name : "Zoom.exe" and not
80- (process.code_signature.subject_name == "Zoom Video Communications, Inc." and process.code_signature.trusted == true)
82+ (process.code_signature.subject_name : "Zoom Video Communications, Inc." and process.code_signature.trusted == true)
8183 ) or
8284
8385 /* Outlook */
8486 (process.name : "outlook.exe" and not
85- (process.code_signature.subject_name == "Microsoft Corporation" and process.code_signature.trusted == true)
87+ (process.code_signature.subject_name : "Microsoft Corporation" and process.code_signature.trusted == true)
8688 ) or
8789
8890 /* Thunderbird */
8991 (process.name : "thunderbird.exe" and not
90- (process.code_signature.subject_name == "Mozilla Corporation" and process.code_signature.trusted == true)
92+ (process.code_signature.subject_name : "Mozilla Corporation" and process.code_signature.trusted == true)
9193 )
9294 )
9395'''
0 commit comments