EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Winscp Execution From Non Standard Folder

Detects the execution of Winscp from an a non standard folder. This could indicate the execution of Winscp portable.

T1048
Sigmamedium

WinSock2 Autorun Keys Modification

Detects modification of autostart extensibility point (ASEP) in registry.

T1547.001
Sigmamedium

WinSxS Executable File Creation By Non-System Process

Detects the creation of binaries in the WinSxS folder by non-system processes

Sigmamedium

Wlrmdr.EXE Uncommon Argument Or Child Process

Detects the execution of "Wlrmdr.exe" with the "-u" command line flag which allows anything passed to it to be an argument of the ShellExecute API, which would allow an attacker to execute arbitrary binaries. This detection also focuses on any uncommon child processes spawned from "Wlrmdr.exe" as a supplement for those that posses "ParentImage" telemetry.

T1218
Sigmamedium

WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load

Detects signs of the WMI script host process "scrcons.exe" loading scripting DLLs which could indicates WMI ActiveScriptEventConsumers EventConsumers activity.

T1546.003
Sigmamedium

WMI Backdoor Exchange Transport Agent

Detects a WMI backdoor in Exchange Transport Agents via WMI event filters

T1546.003
Sigmacritical

WMI Event Consumer Created Named Pipe

Detects the WMI Event Consumer service scrcons.exe creating a named pipe

T1047
Sigmamedium

WMI Event Subscription

Detects creation of WMI event subscription persistence method

T1546.003
Sigmamedium

WMI Module Loaded By Uncommon Process

Detects WMI modules being loaded by an uncommon process

T1047
Sigmalow

WMI Persistence

Detects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.

T1546.003
Sigmamedium

WMI Persistence - Command Line Event Consumer

Detects WMI command line event consumers

T1546.003
Sigmahigh

WMI Persistence - Script Event Consumer

Detects the execution of a script event consumer. When scrcons.exe launches, it does so in response to the creation of an ActiveScriptEventConsumer instance and will execute registered JScript or VBScript code as a result. Script event consumers are a built-in Windows Management Instrumentation (WMI) class that automatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs. Adversaries often abuse script event consumers to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.

T1546.003
Sigmamedium

WMI Persistence - Script Event Consumer File Write

Detects file writes of WMI script event consumer

T1546.003
Sigmahigh

WMI Persistence - Security

Detects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.

T1546.003
Sigmamedium

WMIC Loading Scripting Libraries

Detects threat actors proxy executing code and bypassing application controls by leveraging wmic and the `/FORMAT` argument switch to download and execute an XSL file (i.e js, vbs, etc). It could be an indicator of SquiblyTwo technique, which uses Windows Management Instrumentation (WMI) to execute malicious code.

T1220
Sigmamedium

WMIC Remote Command Execution

Detects the execution of WMIC to query information on a remote system

T1047
Sigmamedium

WMIC Unquoted Services Path Lookup - PowerShell

Detects known WMI recon method to look for unquoted service paths, often used by pentest inside of powershell scripts attackers enum scripts

T1047
Sigmamedium

Wmiexec Default Output File

Detects the creation of the default output filename used by the wmiexec tool

T1047
Sigmacritical

WMImplant Hack Tool

Detects parameters used by WMImplant

T1047T1059.001
Sigmahigh

WmiPrvSE Spawned A Process

Detects WmiPrvSE spawning a process

T1047
Sigmamedium

Wmiprvse Wbemcomn DLL Hijack

Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.

T1047T1021.002
Sigmahigh

Wmiprvse Wbemcomn DLL Hijack - File

Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.

T1047T1021.002
Sigmacritical

Wow6432Node Classes Autorun Keys Modification

Detects modification of autostart extensibility point (ASEP) in registry.

T1547.001
Sigmamedium

Wow6432Node CurrentVersion Autorun Keys Modification

Detects modification of autostart extensibility point (ASEP) in registry.

T1547.001
Sigmamedium
PreviousPage 136 of 137Next