PUA - Mouse Lock Execution
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "Process started" AND PRODUCT_NAME contains "Mouse Lock" OR COMPANY_NAME contains "Misc314" OR COMMANDLINE contains "Mouse Lock_" select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Cian Heasley


