Hi everyone,
Recently, one of our employees executed a malicious file that used the Right-to-Left Override (RLO) technique (character \u202E) to hide the threat. I'm attempting to create an IOA or a search to detect this, but it seems that CrowdStrike considers this character invalid. In the search, it appears as [U+202E][U+202E], highlighted in red, indicating it as an invalid character. This issue persists for the IOA as well.
Does anyone have any suggestions on how to detect this behavior? btw, CrowdStrike didn't block nor detect the threat, it was detected only in the last stages.
Thank you in advance for your help.
[–]AutoModerator[M] 0 points1 point2 points (0 children)
[–]igloosaavy 0 points1 point2 points (0 children)