← Back to SOC feed Coverage →

PLINK8619841985

yara LOW Yara-Rules
community
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at Yara-Rules →
Retrieved: 2026-09-14T11:00:00Z · Confidence: medium

Hunt Hypothesis

This rule detects the presence of PLINK, a command-line tool frequently used by adversaries to establish remote connections or transfer files, often as part of lateral movement or initial access activities. Proactively hunting for this indicator in Azure Sentinel allows the SOC team to identify potential unauthorized remote access or data exfiltration attempts before they escalate into a full compromise.

YARA Rule

rule PLINK8619841985
{
      meta:
		author="malware-lu"
strings:
		$a0 = { FA 8C C7 8C D6 8B CC BA [2] 8E C2 26 }

condition:
		$a0 at pe.entry_point
}

Deployment Notes

This YARA rule can be deployed in the following contexts:

This rule contains 1 string patterns in its detection logic.

False Positive Guidance

Original source: https://github.com/Yara-Rules/rules/blob/main/packers/packer.yar