Home
Blog
Playbooks, YARA rules, IoCs… Everything you need to know

Playbooks, YARA rules, IoCs… Everything you need to know

Learn about new and existing features that have seen improvements on our XDR platform. You will find playbooks and new detection rules there.
Beams of pink light overlapping against a darker pink background.

Key takeaways

August 2021 Sekoia update: playbook templates, 10 new rules, 25 YARA rules, and 94 new APT31 IoCs following ANSSI publication.

  • Four ready-to-use playbook templates were released in August 2021, enabling SOC teams to automate incident response processes through visual no-code block programming.
  • Ten new detection rules were added covering PrintNightmare exploitation, ransomware TTPs (service stopping, Windows Defender disabling via PowerShell), and the Lazarus APT group.
  • Twenty-five new YARA rules were deployed to track ransomware families (Avaddon, Avoslocker, Cuba, Hades, REvil, Thanos) and APTs (APT31, Lazarus, Thallium, Turla); new C2 trackers cover StrongPity and open-source offensive tools including BruteRatel, Caldera, and GoBot2.
  • Following ANSSI's July 21 publication on APT31 attacks targeting France, Sekoia mapped the campaign and added 94 additional malicious domains and IPs attributed with high confidence to APT31 infrastructure.
  • About ten existing detection rules were improved in the same cycle, reflecting Sekoia's continuous rule refinement alongside new threat coverage.

Sekoia Defend and Sekoia Intelligence are constantly evolving to meet the needs of our users, while taking into account their approach and user experience. Each month, we review and explain the new features to explain the new features and improvements of the existing.

Ready-to-use playbooks

Easily automate time-consuming activities with pre-designed, ready-to-use playbook templates. A playbook is a list of steps (blocks) and actions required to successfully respond to an incident or a threat. It provides a step-by-step approach to orchestration, helping security teams establish standardized incident response processes. Discover our 4 playbooks available now on Sekoia and stay tuned for the upcoming ones.

10 new detection rules in the catalog

Our analysts added 10 new detection rules to the rules catalog in July to detect, among others:

  • Exploiting the PrintNightmare vulnerability.
  • Several TTPs used by Ransomware groups as stop services, disabling Windows Defender in PowerShell, etc.
  • The North Korean APT group Lazarus.

About ten existing rules have also been improved.

25 new YARA rules and C2 Tracker

These trackers and rules have been integrated to continue tracking the latest cyber threats!

  • In July, 25 new YARA rules were implemented by our Sekoia CTI teams to track and collect IOCs mainly to detect ransomware (Avaddon, Avoslocker, Cuba, Hades, REvil and Thanos) as well as APTs such as APT31, Lazarus, Thallium or Turla.
  • New Sekoia C2 Tracker have also been added to allow our analysts to better detect APTs such as StrongPity or commercial or open source offensive tools such as TrevorC2, BruteRatel, Caldera, GoBot2, NorthStar, PowerHub or Satellite.

New IOCs for the Chinese APT group APT31

  • Following ANSSI’s publication on July 21, 2021 regarding a series of APT31 attacks targeting France, the campaign in point was mapped in the Sekoia CTI database and new IOCs were integrated in addition to those already known by Sekoia.
  • 94 new malicious domains and IPs attributed with high confidence to the APT31 infrastructure were found through the investigations of Sekoia analysts.

We hope you enjoy these new features and will be able to manage your cybersecurity even more efficiently.

Cyber Threat Intelligence

Actionable cyber threat intelligence for security teams that need to understand threats faster, focus on what matters, and operationalize intelligence across hunting, detection, and investigation.

Abstract circular icon with a central human figure surrounded by six connecting nodes.