Actor
high
threat
Regsvr32 Silent and Install Parameter DLL Loading
2 rules 2 TTPsDetection of regsvr32.exe being used with the silent and DLL install parameter to load a DLL, a technique used by RATs like Remcos and njRAT to execute arbitrary code.
Splunk Enterprise +2
Remcos
+1
lolbin
dll-loading
regsvr32
2r
2t
high
threat
Excessive Taskkill Usage for Defense Evasion
2 rules 1 TTPAdversaries use excessive calls to `taskkill.exe` (more than 10 times within a minute) to disable security tools or critical processes, evading detection and compromising systems.
Windows
Multiple threat actors (Azorult
+5
taskkill
defense-evasion
2r
1t
high
threat
Windows Time-Based Evasion via Ping Delay
2 rules 1 TTPThis analytic detects potentially malicious processes initiating a ping delay using an invalid IP address, a tactic used by malware like NJRAT to evade detection by delaying actions.
Windows
NJRAT
time-based-evasion
2r
1t