Rclone - Data Exfiltration
Introduction
Practical
.rclone.exe config create remote mega user [redacted]@outlook.com pass [redacted]config
Initiates the configuration file being created
.rclone.exe configcopy
Command for copying data
Detection
Sigma Rules
Rclone Execution via Command Line or PowerShell
This rule detects the execution of Rclone.
REFERENCES
Last updated