Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

Rubeus

Ransomware Needs review 20 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog because it self-identifies as ransomware-type malware, but no one has curated a full summary or double-checked its reference links. Treat the details below as a starting point, not a verified profile.

Also known as: Rubeus

Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S1071) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
elastic Kirbi File Creation production 2026-09-18
splunk Rubeus Kerberos Ticket Exports Through Winlogon Access production 2026-09-08
splunk PetitPotam Suspicious Kerberos TGT Request production 2026-07-04
splunk Rubeus Command Line Parameters production 2026-05-13
sigma HackTool - Rubeus Execution - ScriptBlock test 2023-04-27
sigma HackTool - Rubeus Execution stable 2023-04-20
sigma User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess' test 2022-12-25
sigma Register new Logon Process by Rubeus test 2022-10-09
sigma PetitPotam Suspicious Kerberos TGT Request test 2022-10-05
suricata ET CURRENT_EVENTS [Fireeye] HackTool.UDP.Rubeus.[nonce] rev 2 2020-12-08
suricata ET CURRENT_EVENTS [Fireeye] POSSIBLE HackTool.TCP.Rubeus.[User32LogonProcesss] rev 1 2020-12-08
suricata ET CURRENT_EVENTS [Fireeye] HackTool.UDP.Rubeus.[nonce 2] rev 1 2020-12-08
snort ET CURRENT_EVENTS [Fireeye] POSSIBLE HackTool.TCP.Rubeus.[User32LogonProcesss] rev 2 2020-12-08
snort ET CURRENT_EVENTS [Fireeye] HackTool.UDP.Rubeus.[nonce 2] rev 2 2020-12-08
snort ET CURRENT_EVENTS [Fireeye] HackTool.TCP.Rubeus.[nonce 2] rev 2 2020-12-08
snort ET CURRENT_EVENTS [Fireeye] HackTool.UDP.Rubeus.[nonce] rev 2 2020-12-08
snort ET CURRENT_EVENTS [Fireeye] HackTool.TCP.Rubeus.[nonce] rev 2 2020-12-08
suricata ET CURRENT_EVENTS [Fireeye] HackTool.TCP.Rubeus.[nonce 2] rev 1 2020-12-08
suricata ET CURRENT_EVENTS [Fireeye] HackTool.TCP.Rubeus.[nonce] rev 2 2020-12-08
yara HKTL_NET_GUID_Rubeus — —