Executable Signed with Discord Inc. or Lenovo Code-Signing Certificate
This rule monitors Portable Executable (PE) files to identify those signed with certificates associated with Discord Inc. or Lenovo. Adversaries frequently abuse stolen or fraudulently obtained code-signing certificates from legitimate, reputable companies to bypass security controls like Windows SmartScreen, gain persistence, or increase the likelihood of successful malware execution.
YARA

