endpoint(opens in a new tab or window)
windows(opens in a new tab or window)
any where host.os.type == "windows" and event.category in ("file", "process") and
(
(event.type == "creation" and file.path : "*\u{202E}*") or
(event.type == "start" and process.name : "*\u{202E}*")
)
Install detection rules in Elastic Security
Detect File with Right-to-Left Override Character (RTLO) Created/Executed in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(opens in a new tab or window).