This detection identifies potential malware or suspicious artifacts matching the NeoLitev200 signature within the Azure Sentinel environment by leveraging YARA scanning capabilities. Proactive hunting for this indicator is essential to uncover early-stage threats that may evade standard heuristic controls, allowing the SOC team to investigate and contain low-severity anomalies before they escalate into broader incidents.
rule NeoLitev200
{
meta:
author="malware-lu"
strings:
$a0 = { 8B 44 24 04 23 05 [4] 50 E8 [4] 83 C4 04 FE 05 [4] 0B C0 74 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the NeoLitev200 detection rule, including suggested filters and exclusions tailored for a legitimate enterprise environment:
Scenario: Automated Endpoint Protection Scans
C:\Program Files\CrowdStrike\fs_qr.exe or C:\Windows\System32\mpcmdRun.exe) and exclude file paths under standard backup directories like D:\BackupLogs\*.Scenario: Scheduled PowerShell Maintenance Scripts
powershell.exe (or pwsh.exe) AND the command line contains specific keywords such as -ExecutionPolicy Bypass, or restrict detection to exclude runs occurring between 02:00 and 04:00 local time on weekdays.Scenario: Software Deployment via SCCM/Intune
C:\Windows\CCMCache or `C:\ProgramData\Microsoft