Uncommon File Creation By Mysql Daemon Process
Last updated on:
In this page
About the rule
Rule Type
Standard
Rule Description
Detects the creation of files with scripting or executable extensions by Mysql daemon. Which could be an indicator of "User Defined Functions" abuse to download malware.
Severity
Trouble
Rule Requirement
Criteria
Action1: actionname = "File Created or Modified" AND PROCESSNAME endswith "\mysqld.exe,\mysqld-nt.exe" AND (FILENAME endswith ".bat,.dat,.dll,.exe,.ps1,.psm1,.vbe,.vbs" OR OBJECTNAME endswith ".bat,.dat,.dll,.exe,.ps1,.psm1,.vbe,.vbs") select Action1.HOSTNAME,Action1.MESSAGE,Action1.USERNAME,Action1.DOMAIN,Action1.OBJECTNAME,Action1.FILENAME,Action1.PROCESSNAME
Detection
Execution Mode
realtime
Log Sources
Windows
Author
Joseph Kamau


