Uncoder AI feature analyzes a complex CERT-UA#1170 threat report on LITERNAMAGER malware and generates Cortex XSIAM-compatible XQL rule.
Detection capabilities include identifying suspicious command-line executions, registry-based persistence indicators, and network telemetry related to LITERNAMAGER.
AI maps structured indicators to Cortex datasets for process & command line activity, registry keys, and outbound connections to known C2 infrastructure.
Operational benefits include high-fidelity detections based on unique behaviors of LITERNAMAGER, multi-layer coverage, and threat-informed engineering reflected in XQL logic.