EXPLORE

EXPLORE DETECTIONS

🔍
2,173 detections found

Windows Suspicious Burst of Password Changes

A regular user account performed rapid, repeated password changes across multiple local accounts within a 2-second window. This pattern is consistent with automated credential manipulation tools that cycle account passwords to deny access to defenders or escalate privileges The speed and volume of changes indicates scripted or tooled activity rather than manual administration, as legitimate password resets do not occur at machine speed across multiple accounts simultaneously.

Splunk

Windows Suspicious C2 Named Pipe

The following analytic detects the creation or connection to known suspicious C2 named pipes. It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by C2 tools. If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.

Splunk

Windows Suspicious Child Process of Consent.EXE

The following analytic detects unexpected child processes spawned by consent.exe, the Windows UAC consent dialog binary. Consent.exe is responsible solely for rendering the UAC elevation prompt and should not spawn child processes under normal operating conditions; child process creation from this parent is a known indicator of UAC bypass and privilege escalation techniques. The detection identifies any executable launched as a child of consent.exe, excluding the expected WerFault.exe error reporting process, which may legitimately appear in crash scenarios. This behavior is associated with UAC bypass exploits and has been observed in multiple post-exploitation frameworks as a means of obtaining elevated privileges without triggering a visible UAC prompt.

Splunk

Windows Suspicious Child Process of TieringEngineService.exe

Detects the RedSun privilege escalation exploit delivering a SYSTEM-level shell to the attacker's session. RedSun replaces the legitimate TieringEngineService.exe with a malicious binary, which launches a process as SYSTEM, usually some sort of shell or shell spawner (conhost.exe, cmd.exe, PowerShell, etc.) in the attacker's active session.

Splunk

Windows Suspicious Child Process Spawned From WebServer

The following analytic identifies the execution of suspicious processes typically associated with WebShell activity on web servers. It detects when processes like `cmd.exe`, `powershell.exe`, or `bash.exe` are spawned by web server processes such as `w3wp.exe` or `nginx.exe`. This behavior is significant as it may indicate an adversary exploiting a web application vulnerability to install a WebShell, providing persistent access and command execution capabilities. If confirmed malicious, this activity could allow attackers to maintain control over the compromised server, execute arbitrary commands, and potentially escalate privileges or exfiltrate sensitive data.

Splunk

Windows Suspicious Defender Engine or Signature Files Created

Detects Windows Defender engine (mpengine.dll) or signature database files (*.vdm) being created by any process that is not a Windows Defender component. BlueHammer extracts these files from the downloaded mpam-fe update package into a UUID-named subdirectory of %TEMP% as part of staging the TOCTOU privilege escalation.

Splunk

Windows Suspicious Defender Update Activity in INetCache

Detects a non-Defender process writing mpam-fe*.exe to the Windows Internet Cache (INetCache). BlueHammer downloads the WD signature update package directly using WinINet as a low-privileged user. The [1].exe naming suffix is produced by Windows HTTP caching and is a reliable artifact of this download method.

Splunk

Windows Suspicious Driver Loaded Path

The following analytic detects the loading of drivers from suspicious paths, which is a technique often used by malicious software such as coin miners (e.g., xmrig). It leverages Sysmon EventCode 6 to identify drivers loaded from non-standard directories. This activity is significant because legitimate drivers typically reside in specific system directories, and deviations may indicate malicious activity. If confirmed malicious, this could allow an attacker to execute code at the kernel level, potentially leading to privilege escalation, persistence, or further system compromise.

Splunk

Windows Suspicious File in EFI Volume

Detects data files in the EFI volume. This is sometimes indicative of an actor attempting to bypass secure boot through vulnerabilities such as CVE-2024-7344. These use vulnerable boot loaders to run malicious system firmware code.

Splunk

Windows Suspicious Named Pipe

The following analytic detects the creation or connection to known suspicious named pipes. It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by malicious or suspicious tools. If confirmed malicious, this could allow an attacker to abuse these to potentially gain privilege escalation, persistence, c2 communications, or further system compromise.

Splunk

Windows Suspicious Process File Path

The following analytic identifies processes running from file paths not typically associated with legitimate software. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on specific process paths within the Endpoint data model. This activity is significant because adversaries often use unconventional file paths to execute malicious code without requiring administrative privileges. If confirmed malicious, this behavior could indicate an attempt to bypass security controls, leading to unauthorized software execution, potential system compromise, and further malicious activities within the environment.

Splunk

Windows Suspicious QEMU Execution

Detects execution of the QEMU binary and an image file with the -nographic flag. This causes it to run in the background without any display. This has been observed as a persistence and initial access technique by some threat actors to install a rogue linux virtual machine

Splunk

Windows Suspicious React or Next.js Child Process

This analytic detects Windows processes such as cmd.exe, PowerShell, and common Windows LOLBINs being spawned by React or Next.js application servers. In the context of CVE-2025-55182 / React2Shell / CVE-2025-66478 for Next.js, successful exploitation can lead to arbitrary JavaScript execution on the server, which in turn is used to invoke Node's child_process APIs (for example child_process.execSync) to run OS-level commands. This detection focuses on suspicious child processes where a Next/React server process spawns an uncommon process. Such activity might be a strong indicator of exploitation of the aforementioned vulnerability.

Splunk

Windows Suspicious VMWare Tools Child Process

The following analytic identifies child processes spawned by vmtoolsd.exe, the VMWare Tools service in Windows, which typically runs with SYSTEM privileges. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and parent process relationships. Monitoring this activity is crucial as it can indicate exploitation attempts, such as CVE-2023-20867. If confirmed malicious, attackers could gain SYSTEM-level access, allowing them to execute arbitrary code, escalate privileges, and potentially compromise the entire system.

Splunk

Windows Svchost.exe Parent Process Anomaly

The following analytic detects an anomaly where an svchost.exe process is spawned by a parent process other than the standard services.exe. In a typical Windows environment, svchost.exe is a system process that hosts Windows service DLLs, and is expected to be a child of services.exe. A process deviation from this hierarchy may indicate suspicious behavior, such as malicious code attempting to masquerade as a legitimate system process or evade detection. It is essential to investigate the parent process and associated behavior for further signs of compromise or unauthorized activity.

Splunk

Windows SymbolicLink-Testing-Tools Utility Execution

Detects the execution of tools from the `symboliclink-testing-tools` toolkit. This toolkit is often used for exploiting Windows symbolic link, junction, and oplock vulnerabilities to achieve local privilege escalation from a standard user to SYSTEM. Symbolic link attacks against Windows exploit a class of logical vulnerability where a SYSTEM or administrator-level process performs a file operation on a path that a low-privileged attacker can redirect using a combination of NTFS junctions, object manager symbolic links, and opportunistic locks (oplocks). By chaining these primitives a standard user can redirect a privileged file write, delete, or read to an arbitrary path, effectively turning a narrow file operation vulnerability into arbitrary write or code execution as SYSTEM.

Splunk

Windows Symlink Evaluation Change via Fsutil

This analytic detects the execution of the Windows built-in tool Fsutil.exe with the "behavior", "set" and "SymlinkEvaluation" parameters. Attackers can abuse this to alter symlink evaluation behavior on Windows, potentially enabling remote traversal over SMB shares or evading defenses. Such changes should be uncommon or even rare in enterprise environments and should be investigated.

Splunk

Windows System Binary Proxy Execution Compiled HTML File Decompile

The following analytic detects the use of the decompile parameter with the HTML Help application (HH.exe). This behavior is identified through Endpoint Detection and Response (EDR) telemetry, focusing on command-line executions involving the decompile parameter. This activity is significant because it is an uncommon command and has been associated with APT41 campaigns, where it was used to unpack HTML help files for further malicious actions. If confirmed malicious, this technique could allow attackers to execute arbitrary commands, potentially leading to further compromise and persistence within the environment.

Splunk

Windows System Discovery Using ldap Nslookup

The following analytic detects the execution of nslookup.exe to query domain information using LDAP. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments. This activity is significant as nslookup.exe can be abused by malware like Qakbot to gather critical domain details, such as SRV records and server names. If confirmed malicious, this behavior could allow attackers to map the network, identify key servers, and plan further attacks, potentially leading to data exfiltration or lateral movement within the network.

Splunk

Windows System Discovery Using Qwinsta

The following analytic detects the execution of "qwinsta.exe" on a Windows operating system. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution logs. The "qwinsta.exe" tool is significant because it can display detailed session information on a remote desktop session host server. This behavior is noteworthy as it is commonly abused by Qakbot malware to gather system information and send it back to its Command and Control (C2) server. If confirmed malicious, this activity could lead to unauthorized data exfiltration and further compromise of the host.

Splunk

Windows System File on Disk

The following analytic detects the creation of new .sys files on disk. It leverages the Endpoint.Filesystem data model to identify and log instances where .sys files are written to the filesystem. This activity is significant because .sys files are often used as kernel mode drivers, and their unauthorized creation can indicate malicious activity such as rootkit installation. If confirmed malicious, this could allow an attacker to gain kernel-level access, leading to full system compromise, persistent control, and the ability to bypass security mechanisms.

Splunk

Windows System LogOff Commandline

The following analytic detects the execution of the Windows command line to log off a host machine. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on processes involving `shutdown.exe` with specific parameters. This activity is significant as it is often associated with Advanced Persistent Threats (APTs) and Remote Access Trojans (RATs) like dcrat, which use this technique to disrupt operations, aid in system destruction, or inhibit recovery. If confirmed malicious, this could lead to system downtime, data loss, or hindered incident response efforts.

Splunk

Windows System Network Config Discovery Display DNS

The following analytic identifies the execution of the "ipconfig /displaydns" command, which retrieves DNS reply information using the built-in Windows tool IPConfig. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process command-line executions. Monitoring this activity is significant as threat actors and post-exploitation tools like WINPEAS often abuse this command to gather network information. If confirmed malicious, this activity could allow attackers to map the network, identify DNS servers, and potentially facilitate further network-based attacks or lateral movement.

Splunk

Windows System Network Connections Discovery Netsh

The following analytic detects the execution of the Windows built-in tool netsh.exe to display the state, configuration, and profile of the host firewall. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions and process metadata. Monitoring this activity is crucial as netsh.exe can be used by adversaries to bypass firewall rules or discover firewall settings. If confirmed malicious, this activity could allow attackers to manipulate firewall configurations, potentially leading to unauthorized network access or data exfiltration.

Splunk
PreviousPage 86 of 91Next