Tag: CrowdStrike EQL

AI-Powered IOC Parsing for WRECKSTEEL Detection in CrowdStrike
AI-Powered IOC Parsing for WRECKSTEEL Detection in CrowdStrike

How It Works Uncoder AI automates the decomposition of complex IOC-driven detection logic authored in CrowdStrike Endpoint Query Language (EQL). This example centers around the CERT-UA#14283 report, targeting WRECKSTEEL — a PowerShell-based infostealer. The AI engine interprets an extensive detection rule designed to match various execution chains linked to WRECKSTEEL, enabling analysts to quickly understand […]

Read More