Secuity Monitoring Forwarded Events: PowerSploit FindAV Signature Tool is in Use

Security.Monitoring.ForwardedEvents.FindAVSignature (Rule)

Find-AVSignature is used to split a file into smaller chunks to detect which piece is being identified by AV. That part can be redesigned to avoid detection.

Element properties:

Alert GenerateTrue
Alert SeverityError
Alert PriorityNormal
Alert Message
Secuity Monitoring Forwarded Events: PowerSploit FindAV Signature Tool is in Use

Find-AVSignature is used to split a file into smaller chunks to detect which piece is being identified by AV. That part can be redesigned to avoid detection. See for links to the tools and additional details.

Logging Computer: {0}

User Name: {1}

Event Description: {2}
Event LogForwardedEvents

Member Modules:

ID Module Type TypeId RunAs 
DS DataSource Microsoft.Windows.EventProvider Default
Alert WriteAction System.Health.GenerateAlert Default

Source Code:

<Rule ID="Security.Monitoring.ForwardedEvents.FindAVSignature" Target="WindowsEventCollectorDiscovery!WindowsEventCollectorDiscovery.EventLogCollectorServer" Enabled="true" ConfirmDelivery="false" Remotable="true" Priority="Normal" DiscardLevel="100">
<DataSource ID="DS" TypeID="Windows!Microsoft.Windows.EventProvider">
<XPathQuery Type="UnsignedInteger">EventDisplayNumber</XPathQuery>
<Value Type="UnsignedInteger">800</Value>
<XPathQuery Type="String">EventDescription</XPathQuery>
<WriteAction ID="Alert" TypeID="Health!System.Health.GenerateAlert">
<Custom10>Security Monitoring Forwarded Events</Custom10>