Skip to main content

SIEM rule to detect encryption

  • October 27, 2023
  • 2 replies
  • 5 views

Forum|alt.badge.img+2

anyone here tried creating a rule that was able to capture encryption in a host,

I would like to get some ideas on how you do it,

2 replies

Forum|alt.badge.img+4
  • Staff
  • November 14, 2023

I think some more information is needed before a suggestion can be made. What log types are being sent from the host ? And what in those logs can help determine if encryption is present ? If we can answer this, a suitable rule can be created. 

Hope this helps


AymanC
Forum|alt.badge.img+13
  • Bronze 5
  • November 14, 2023

As mentioned above, more information is needed. But at face value, if you know the encryption algorithm you can regex match an event for it.