This detection identifies the presence of Obsidium software components within the environment to establish a baseline for legitimate application behavior and potential supply chain risks. Proactively hunting for these signatures in Azure Sentinel allows the SOC team to distinguish between expected software usage and anomalous deployments that could indicate unauthorized tooling or early-stage adversary activity.
rule Obsidium1311ObsidiumSoftware
{
meta:
author="malware-lu"
strings:
$a0 = { EB 02 [2] E8 27 00 00 00 EB 02 [2] EB 03 [3] 8B 54 24 0C EB 01 ?? 83 82 B8 00 00 00 22 EB 04 [4] 33 C0 EB 01 ?? C3 EB 02 [2] EB 02 [2] 64 67 FF 36 00 00 EB 04 [4] 64 67 89 26 00 00 EB 01 ?? EB 03 [3] 50 EB 03 [3] 33 C0 EB 01 ?? 8B 00 EB 03 [3] C3 EB 01 ?? E9 FA 00 00 00 EB 03 [3] E8 D5 FF FF FF EB 01 ?? EB 03 [3] 58 EB 03 [3] EB 01 ?? 64 67 8F 06 00 00 EB 01 ?? 83 C4 04 EB 03 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Obsidium1311ObsidiumSoftware detection rule, along with targeted filters and exclusions:
Scenario: Scheduled Antivirus Engine Updates
ObsidiumEngine.exe) spawns child processes that match the YARA signature, triggering alerts even though no malicious behavior is occurring.C:\Program Files\Obsidium\bin\ObsidiumEngine.exe and its immediate children when running under the system account (NT AUTHORITY\SYSTEM) during defined maintenance windows (e.g., 01:00–04:00 local time).Scenario: Enterprise Endpoint Management Deployment
ObsidiumSetup.exe), which generates file system artifacts and registry keys that mimic the rule’s detection logic.ccmexec.exe for SCCM or IntuneManagementExtension.exe) and the user context is an administrative account (e.g., DOMAIN\IT-Admins).Scenario: Automated Patch Management Scripts
ObsidiumCLI.exe) to query license status or generate compliance reports, causing the YARA rule to trigger on the CLI’s execution and output generation.