Game Pass: Diese 7 Spiele werden Teil der Flatrate für Xbox One & PC
In den kommenden Tagen und Wochen wird Microsoft sieben neue Xbox One- und PC-Spiele dem Game Pass hinzufügen. Zu den Highlights der Gaming-Flatrate gehören im März unter anderem Titel wie NBA 2K20, Pikuniku und Ori and the Will of the Wi…
In den kommenden Tagen und Wochen wird Microsoft sieben neue Xbox One- und PC-Spiele dem Game Pass hinzufügen. Zu den Highlights der Gaming-Flatrate gehören im März unter anderem Titel wie NBA 2K20, Pikuniku und Ori and the Will of the Wisps. (Weiter lesen)
title: Detect Exploitation - Game Pass: Diese 7 Spiele werden Teil der Flatrate für Xbox One & PC
id: d9a22780-af5a-4525-93ef-49a465b1d8c2
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-27
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_access
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-27"
description = "YARA Signature for "
strings:
$str = "Game Pass: Diese 7 Spiele werd" ascii wide
condition:
any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Game Pass Diese 7 Spiele werden Teil der")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Game Pass Diese 7 Spiele werden Teil der*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Game Pass Diese 7 Spiele werden Teil der"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc
Analyse für identifizierte Bedrohung auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
⚡ Empfohlene Sofortmaßnahmen
1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
Synthetische RAG-Antwort
HAND-OFF
Auf Smartphone übergeben (ADVISORY)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff:
Video von Julian Goldie SEO auf YouTube: Get the Agent OS & Hermes Masterclass 👉 https://www.skool.com/ai-profit-lab-7462/about Want to make money and save…
Video von heise & c't auf YouTube: Wollt ihr auch unabhängig von Google Maps werden? In diesem Video stellen wir euch drei Alternativen vor. ► Zum Artikel…
Video von heise & c't auf YouTube: Wollt ihr auch unabhängig von Google Maps werden? In diesem Video stellen wir euch drei Alternativen vor. ► Zum Artikel…
Video von Julian Goldie SEO auf YouTube: Get the Agent OS & Google AI Tool Masterclass 👉 https://www.skool.com/ai-profit-lab-7462/about Want to make money and…