UNC4841 - SSL Certificate Exfiltration Via Openssl — Detection Rule

Detects the execution of "openssl" to connect to an IP address. This techniques was used by UNC4841 to exfiltrate SSL certificates and as a C2 channel with named pipes. Investigate commands executed in the temporal vicinity of this command.

Read the full analysis on IntelFusions