PUA - Mouse Lock Execution

Last updated on:

About the rule

Rule Type

Standard

Rule Description

In Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Process started" AND PRODUCT_NAME contains "Mouse Lock" OR COMPANY_NAME contains "Misc314" OR COMMANDLINE contains "Mouse Lock_" select Action1.HOSTNAME,Action1.MESSAGE,Action1.COMMANDLINE,Action1.FILE_NAME,Action1.PROCESSNAME,Action1.USERNAME,Action1.PARENTPROCESSNAME

Detection

Execution Mode

realtime

Log Sources

Windows

Author

Cian Heasley