Tag: XQL detection

Full Detection Logic for LITERNAMAGER in Cortex XSIAM via Uncoder AI
Full Detection Logic for LITERNAMAGER in Cortex XSIAM via Uncoder AI

How It Works This Uncoder AI feature analyzes a complex CERT-UA#1170 threat report describing the LITERNAMAGER malware family and generates a Cortex XSIAM-compatible XQL rule. The AI extracts structured indicators and behaviors, then maps them to different Cortex datasets: 1. Process & Command Line Activity The rule detects suspicious command-line execution of: YOURClient.exe YOURServer.exe including […]

Read More