Skip to content
Threat Feed

Product

Windows

382 briefs RSS
high threat

Monitoring High-Risk Sign-ins in Microsoft Entra ID

This brief details the detection of compromised cloud accounts by leveraging Microsoft Identity Protection telemetry to identify high-risk authentication events indicative of credential abuse.

exploited Microsoft Entra ID +3 cloud identity account-compromise
1r 1t
high advisory

OctLurk and SilkLurk Memory-Resident Backdoors Targeting Central Asia

OctLurk and SilkLurk are sophisticated, memory-resident backdoors targeting government and research entities in Central Asia since January 2025, utilizing machine-specific key derivation for payload decryption and modular plugin injection.

Windows backdoor cyber-espionage memory-resident central-asia chinese-speaking
1r 4t 6i
high threat

Toy Ghouls Deploying Custom GenieLocker Ransomware

The Toy Ghouls threat actor is deploying a custom ransomware family called GenieLocker against manufacturing organizations, utilizing compromised VPN credentials and legitimate system tools for lateral movement and encryption.

Windows +6 Toy Ghouls ransomware extortion manufacturing toy-ghouls
1r 4t 1i
high threat

Astaroth Botnet Deploys New WhatsApp Web Spambot Component

Operators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.

Windows +5 Astaroth botnet malware spambot latin-america
1r 9t 8i updated
low advisory

Unusual Process Writing Data to an External Device Detected by Machine Learning

Elastic's Data Exfiltration Detection integration leverages machine learning to identify rare processes writing data to external devices, indicating potential data exfiltration by adversaries using benign-looking processes.

Elastic Defend +15 exfiltration machine-learning elastic-defend endpoint lateral-movement rdp anomaly-detection privilege-escalation +29
22t
low advisory

Uncommon Process Loading RstrtMgr.DLL for Malicious Purposes

Attackers, including ransomware families like Conti and Cactus, and wipers such as BiBi, abuse the legitimate Windows `RstrtMgr.dll` (Restart Manager) by loading it into uncommon processes to terminate applications, including security software and those holding locks on files, facilitating data encryption or destruction.

Windows defense-evasion impact ransomware wiper
1r 2t
high threat

Mirage Kitten Targets Middle East and Africa with New Malware

Mirage Kitten, an advanced persistent threat (APT) group, is deploying new Windows backdoor (NightLedger) and WebSocket tunnelers (ArcBridge, BridgeHead) via spear-phishing campaigns to conduct cyber-espionage and data exfiltration against aerospace, aviation, defense, and telecommunications sectors in the Middle East and Europe.

Windows Mirage Kitten cyber-espionage apt malware backdoor tunneler dll-hijacking websocket spear-phishing
4r 13t 3i
high advisory

Svchost LOLBAS Execution Process Spawn

This brief details the detection of `svchost.exe` spawning Living Off The Land Binaries and Scripts (LOLBAS) processes, indicating potential malicious code execution, privilege escalation, or persistence attempts by adversaries within a Windows environment.

Windows lolbas execution persistence lateral-movement system-binary-proxy-execution
1r 2t
high advisory

Rundll32 UNC Path Execution for Malicious DLL Loading

Threat actors are observed abusing the legitimate Windows utility rundll32.exe to execute malicious DLLs from remote UNC network paths, facilitating execution and lateral movement within compromised environments.

Windows lateral-movement code-execution stealth malware
1r 2t
low advisory

Unusual Hour for a User to Logon

An Elastic machine learning rule detects unusual user logon times, which can indicate credential compromise or unauthorized access, particularly when attackers operate from different time zones or during non-business hours, prompting investigation into the affected user account and related activities.

Elastic Defend +8 identity-and-access-audit threat-detection machine-learning initial-access
1t
medium advisory

Windows Curl Download to Suspicious Path Detection

This analytic detects the use of Windows Curl.exe to download files to suspicious locations, such as AppData, ProgramData, or Public directories, leveraging Endpoint Detection and Response (EDR) data by focusing on command-line executions that include the -O or --output options; this activity is significant as it can indicate an attempt to bypass security controls or establish persistence, potentially leading to unauthorized code execution, data exfiltration, or further system compromise.

Windows endpoint command-and-control defense-evasion
1r 1t updated
high advisory

Autonomous AI Agents Pose New Supply Chain and Data Exfiltration Risks

This content introduces AI Detection and Response (AIDR) as a new cybersecurity category to address emerging threats from autonomous AI agents, including supply chain attacks and unintended data sharing, highlighting their ability to execute with inherited privileges across endpoints, SaaS, and cloud environments.

ClawHub +42 ai agentic-ai aidr supply-chain-attack data-exfiltration cloud-security endpoint-security saas-security
4t 16i updated
critical threat

Microsoft Addresses Two Actively Exploited Zero-Day Vulnerabilities in July 2026 Patch Tuesday

Microsoft's July 2026 Patch Tuesday addressed 622 vulnerabilities, including two actively exploited zero-day elevation of privilege flaws, CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint, allowing local and remote attackers to gain administrative control.

exploited PoC Active Directory Federation Services +23 patch-tuesday zero-day vulnerability microsoft windows sharepoint active-directory-federation-services bitlocker +2
8t 4c 8i updated
high threat

ACR Stealer Campaigns Use ClickFix Lures, WebDAV, and Steganography for Credential Theft

Microsoft Defender Experts observed increased ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering lures in two distinct campaigns to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments via WebDAV-based Python loaders or MSHTA-initiated PowerShell with steganography.

Windows ACR Stealer infostealer malware-as-a-service social-engineering webdav powershell steganography credential-theft data-exfiltration
2r 18t
high advisory

Windows Bind Link Attacks Can Hide Malware From EDR Tools

Bitdefender researchers revealed how attackers can exploit Windows bind links, a legitimate operating system feature, to create conflicting filesystem views that conceal malware from endpoint detection and response (EDR) tools and other security mechanisms, enabling post-compromise evasion despite requiring administrative privileges.

Windows defense-evasion edr-evasion filesystem
3t
medium advisory

Potential System DLL Sideloading From Non System Locations

This brief describes a common defense evasion technique where malicious actors bypass security controls by loading legitimate system DLLs from non-standard directories, enabling arbitrary code execution within trusted processes.

Windows dll-sideloading defense-evasion execution
1r 3t
critical advisory

GigaWiper: Multi-Payload Destructive Backdoor

GigaWiper is a sophisticated, Golang-based destructive backdoor observed since October 2025 by Microsoft Threat Intelligence, that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including physical disk wiping, ransomware-like encryption derived from Crucio, and multi-pass secure wiping reimplemented from FlockWiper.

Windows wiper destructive backdoor ransomware golang
3r 6t 2i
high threat

System File Execution Location Anomaly

This brief describes the detection of Windows system binaries executing from uncommon locations, a defense evasion and stealth technique employed by various threat actors including Lazarus Group and Sidewinder APT, indicating potential malicious activity on an endpoint.

Windows Lazarus Group +5 defense-evasion stealth execution process-anomaly
1r 4t updated
high advisory

New Abuse of the ClickOnce Technology, Part 2: Stop Threat Actors from Clicking Once and Staying Forever

Threat actors are actively exploiting Microsoft's ClickOnce deployment technology, leveraging its low user interaction, lack of privilege requirements, and built-in update mechanisms to deliver malware, establish persistence, and maintain remote access, often executing payloads within legitimate rundll32.exe and dfsvc.exe processes.

PoC ClickOnce +11 microsoft persistence delivery windows endpoint
2r 7t 26i updated
medium advisory

New Abuse of ClickOnce Technology: Understanding Internals

CrowdStrike details the internal mechanisms of Microsoft's ClickOnce technology, a legitimate software deployment method that offers minimal user interaction and no administrative privilege requirements, making it a double-edged sword with significant potential for threat actor abuse in malware distribution and persistence.

.NET Framework +1 clickonce windows deployment-technology abuse-of-feature defense-evasion execution
2t
medium advisory

AI Agents Mimic Adversarial Behavior, Triggering Security Detections

AI coding agents such as Claude Code, Cursor, Codex, and GStack are increasingly exhibiting behaviors on Windows endpoints that mimic adversarial tradecraft, including credential access, LOLBin usage for ingress, command-line obfuscation, and persistence mechanisms, thereby triggering existing security detection rules designed for malicious activity and posing significant false positive challenges for detection engineers.

Claude Code +9 ai detection-engineering false-positive windows behavioral-detection
9t 9i
high advisory

Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE

This brief details the use of the legitimate Windows utility `certutil.exe` by various threat actors to download malicious files from public file-sharing and code-hosting websites, facilitating further compromise and evasion on targeted systems.

Windows lolbin defense-evasion ingress-tool-transfer
1r 2t 35i
medium threat

Uncommon WMIC System Information Discovery by Aurora Stealer

Aurora Stealer has been observed using the Windows Management Instrumentation Command-line (WMIC) utility to perform extensive system reconnaissance, gathering details like OS version, CPU, GPU, disk drives, memory, and display resolution, indicating early-stage information gathering for subsequent data exfiltration or malware deployment.

Windows Aurora Stealer reconnaissance discovery infostealer
1r 1t
medium threat

Computer System Reconnaissance Via Wmic.EXE

This brief details the use of `wmic.exe` with the `computersystem` flag for reconnaissance, a technique observed in campaigns by adversaries such as DEV-0270 (Phosphorus), to gather system information like domain, username, and model.

Windows DEV-0270 +5 discovery reconnaissance ransomware
1r 1t
high advisory

Apple Security Updates — July 2026

Roundup of Apple security advisories published in July 2026.

PoC macOS LaunchAgents +46 roundup
4c 10i updated
high advisory

Cisco Security Updates — July 2026

Roundup of Cisco security advisories published in July 2026.

PoC Cisco devices +54 roundup
5c 55i updated
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +511 roundup
11c 354i updated
high threat

Screening Serpens APT Targets Tech and Defense Sectors with New RATs

The Iranian APT group Screening Serpens targeted the tech and defense sectors in the U.S., Israel, and the UAE between February and April 2026, deploying six new RAT variants from the MiniUpdate and MiniJunk V2 malware families, using tailored social engineering lures and AppDomainManager hijacking.

MiniUpdate +2 Screening Serpens APT Iran RAT MiniJunk DLL Sideloading AppDomainManager Cyberespionage
2r 3t
critical advisory

CVE-2008-4250 - Windows Server Service Buffer Overflow Vulnerability

CVE-2008-4250 is a buffer overflow vulnerability in the Microsoft Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request during path canonicalization.

Windows cve buffer-overflow rpc smbv1
2r 1t 1c
medium advisory

LSASS Memory Dump Handle Access

Detection of handle requests to the LSASS process with specific access masks commonly used by tools to dump memory, indicating potential credential access attempts.

Windows credential-access lsass memdump
2r 1t
high advisory

Multiple Vulnerabilities in Microsoft Windows Products

Multiple vulnerabilities exist in Microsoft Windows products, enabling attackers to execute arbitrary code, escalate privileges, perform denial-of-service attacks, disclose information, or bypass security measures.

Windows vulnerability privilege-escalation execution denial-of-service defense-evasion discovery
2r 5t
high advisory

Multiple Vulnerabilities in Microsoft Developer Tools

Multiple vulnerabilities in Microsoft developer tools and platforms could allow an attacker to achieve arbitrary code execution, data manipulation, privilege escalation, bypassing security measures, information disclosure, and denial of service.

Visual Studio 2017 +11 vulnerability code-execution privilege-escalation denial-of-service windows cloud
3r 6t
high advisory

Privilege Escalation via Named Pipe Impersonation

Adversaries may escalate privileges by abusing named pipe impersonation, a technique often used with tools like Metasploit's meterpreter getsystem command, where a process writes to a named pipe to facilitate a SYSTEM-token handoff.

Microsoft Defender XDR +4 privilege-escalation named-pipe windows
2r 1t
high advisory

Group Policy Abuse for Privilege Addition

Detects modifications to Group Policy Object Attributes that grant privileges to user accounts or add users as local administrators, indicating potential privilege escalation attempts.

Active Directory +1 group-policy privilege-escalation windows
2r 1t
high advisory

Potential Modification of Accessibility Binaries for Persistence

Adversaries may modify or replace Windows accessibility binaries (e.g., sethc.exe, utilman.exe) to execute malicious commands or establish persistence mechanisms before a user logs in, potentially leading to elevated privileges and unauthorized access.

Windows persistence privilege_escalation accessibility_features
2r 1t
high advisory

Potential SharpRDP Behavior

This rule detects potential SharpRDP behavior, a tool used for authenticated command execution against a remote target via Remote Desktop Protocol (RDP) for lateral movement by identifying incoming RDP connections followed by RunMRU registry value modifications and subsequent process execution.

Elastic Defend +1 lateral-movement execution windows sharprdp
2r 3t
high advisory

Incoming DCOM Lateral Movement with MMC

Detection of Distributed Component Object Model (DCOM) abuse to execute commands remotely via the MMC20 Application COM object, potentially indicating lateral movement.

Elastic Defend +1 lateral-movement dcom windows
2r 1t
high advisory

Incoming DCOM Lateral Movement via MSHTA

Detection of Distributed Component Object Model (DCOM) abuse to execute commands from a remote host via the HTA Application COM Object, potentially indicating lateral movement.

Windows lateral-movement dcom mshta
2r 1t
high advisory

Suspicious Kerberos Authentication Ticket Request

This rule detects suspicious Kerberos authentication ticket requests by correlating network connections to the standard Kerberos port (88) from a source machine with a Kerberos authentication ticket request from the target domain controller, which could indicate lateral movement or credential access attempts within a Windows domain.

Elastic Defend +4 lateral-movement threat-detection windows
2r 2t
high advisory

Volume Shadow Copy Deletion via PowerShell

Detects the use of PowerShell to delete volume shadow copies, a tactic commonly employed by ransomware and other destructive attacks to hinder data recovery efforts.

Windows impact powershell volume shadow copy ransomware
2r 1t
medium advisory

GhostLock Tool Abuses Windows API to Block File Access

GhostLock is a proof-of-concept tool that abuses the Windows CreateFileW API to block access to files on local and SMB network shares, causing a denial-of-service condition.

Windows +1 denial-of-service file-access
2r 1t
critical threat

Weaver E-cology Unauthenticated RCE Exploitation

A critical unauthenticated remote code execution vulnerability (CVE-2026-22679) in Weaver E-cology office automation software is being actively exploited to execute system commands and reconnaissance activities on affected servers.

exploited E-cology 10.0 +1 rce weaver-ecology cve-2026-22679 exploitation
2r 2t 1c
high threat

ScarCruft (APT37) Deploying BirdCall Android Backdoor via Compromised Game Platform

The APT37 group (ScarCruft) is distributing an Android version of the BirdCall backdoor via a supply-chain attack targeting a Chinese video game platform, sqgame[.]net, to collect sensitive information from users.

Google Play +2 ScarCruft android malware spyware apt37 supply-chain
2r 5t 1i
medium advisory

Potential Pass-the-Hash (PtH) Attempt Detection

This rule detects potential Pass-the-Hash (PtH) attempts in Windows environments by monitoring successful authentications with specific user IDs (S-1-5-21-* or S-1-12-1-*) and the `seclogo` logon process, where attackers use stolen password hashes to authenticate and move laterally across systems without needing plaintext passwords.

Windows lateral-movement threat-detection
2r 1t
critical advisory

PhantomRPC: Windows RPC Privilege Escalation Vulnerability

A vulnerability in Windows RPC architecture allows an attacker to create a fake RPC server and escalate their privileges to SYSTEM level, leveraging processes with impersonation privileges.

Windows privilege-escalation rpc
2r 1t
high threat

Trigona Ransomware Employing Custom Data Exfiltration Tool

Trigona ransomware is using a custom data exfiltration tool named 'uploader_client.exe' to steal data from compromised environments, enhancing speed and evasion.

Windows +3 Trigona ransomware data exfiltration custom tool
2r 4t 1i
medium advisory

Windows SIP Provider Modification for Defense Evasion

This brief covers the modification of Subject Interface Package (SIP) providers on Windows systems, a technique used by attackers to bypass signature validation checks and inject malicious code into critical processes, ultimately leading to defense evasion.

Windows defense-evasion registry
1r 1t
medium advisory

Powercat PowerShell Implementation Detection

Adversaries may leverage Powercat, a PowerShell implementation of Netcat, to establish command and control channels or perform lateral movement within a compromised network.

Windows command-and-control execution lateral-movement powershell
2r 2t
medium advisory

Local SxS Shared Module DLL Hijacking

Adversaries may abuse shared modules in local Side-by-Side (SxS) folders to execute malicious payloads by instructing the Windows module loader to load DLLs from arbitrary local paths, potentially bypassing security controls.

Windows dll-hijacking execution defense-evasion
2r 2t
medium advisory

Detection of Suspicious PowerShell Arguments

This rule detects suspicious PowerShell arguments often used during malware installation, including encoded commands, file downloads, and obfuscation techniques.

PowerShell +1 malware execution obfuscation
2r 4t
high advisory

Suspicious Process Masquerading as SvcHost.exe

Adversaries are masquerading malicious processes as 'svchost.exe' by naming their binaries 'svchost.exe' and executing them from uncommon locations to evade detection.

Windows process-masquerading defense-evasion svchost
2r 1t
high advisory

Suspicious Windows Command Shell Arguments

This rule identifies suspicious uses of the Windows Command Shell (cmd.exe) with unusual command-line arguments often associated with malware installation, script execution, or system manipulation.

Windows execution command-shell
2r 5t
medium advisory

Persistence via Windows Installer (Msiexec)

Adversaries may establish persistence by abusing the Windows Installer (msiexec.exe) to create scheduled tasks or modify registry run keys, allowing for malicious code execution upon system startup or user logon.

Windows +21 persistence defense-evasion
3r 3t
medium advisory

Service DACL Modification via sc.exe

Adversaries modify a service's DACL (Discretionary Access Control List) via `sc.exe` to deny access to key user groups, potentially making the service unstoppable or hiding it from users and the system, in order to evade defenses and persist.

Windows defense-evasion persistence
2r 2t
medium advisory

Suspicious Execution via Windows Command Debugging Utility (cdb.exe)

Adversaries can abuse the Windows command line debugging utility cdb.exe, specifically when executed from non-standard paths with specific command-line arguments (-cf, -c, -pd), to execute commands or shellcode for defense evasion.

Windows defense-evasion lolbas
2r 2t
high advisory

Detecting Potential PowerShell Pass-the-Hash/Relay Scripts

This rule detects PowerShell scripts associated with NTLM relay or pass-the-hash tooling and SMB/NTLM negotiation artifacts, indicating potential credential access and lateral movement attempts by attackers.

Windows credential-access pass-the-hash ntlm-relay powershell
2r 2t
low advisory

Enumerating Domain Trusts via DSQUERY.EXE

Adversaries may use dsquery.exe to enumerate domain trusts, which can be leveraged for lateral movement in Windows multi-domain environments.

Windows +1 discovery domain-trust
2r 2t
high advisory

Suspicious Execution from INetCache Folder

The rule detects suspicious execution of processes from the INetCache folder, often indicative of malicious payloads delivered via WININET, potentially signaling initial access or command and control activity.

Windows initial-access command-and-control execution inetcache
2r 3t 1c
high advisory

Detection of System Control Panel Item Load from Uncommon Locations

This brief focuses on detecting the loading of system control panel items (.cpl) from unusual locations, potentially indicating DLL sideloading or other exploitation techniques by threat actors to achieve defense evasion, persistence, and privilege escalation on Windows systems.

Windows defense-evasion persistence privilege-escalation dll-sideloading
2r 3t
high advisory

Suspicious Execution of Windows Scripts from WebDAV Share

Adversaries may execute Windows scripts directly from a remote WebDAV share to evade detection and avoid writing malicious files to disk; this activity is detected by monitoring process command lines for suspicious WebDAV paths.

Windows webdav script-execution
2r 5t
medium advisory

Remote File Copy to a Hidden Share

Detects remote file copy attempts to hidden network shares, indicative of lateral movement or data staging, by monitoring command-line tools like cmd.exe and powershell.exe for hidden share patterns.

Windows lateral-movement collection
2r 3t
high advisory

VMkatz Tool for Extracting Windows Credentials from VM Memory Snapshots

VMkatz is a tool designed to extract Windows credentials directly from virtual machine memory snapshots and virtual disks, enabling unauthorized credential access.

Windows +2 credential-access vmware virtual-machine
2r 1t
high advisory

Potential DMSA Abuse for Privilege Escalation

Detection of potential abuse of Default Message Security Agent (DMSA) for privilege escalation on Windows systems, based on registry modifications.

Windows privilege-escalation dmsa
2r 1t
medium advisory

Potential Account Takeover via Mixed Logon Types

Atypical logon patterns, where a high-volume account (e.g., service account) exhibits successful logons using an unusual logon type with low frequency, may indicate account takeover or stolen credentials.

Windows account-takeover privilege-escalation
2r 1t
medium advisory

Suspicious Svchost.exe Spawning Cmd.exe

Detects suspicious activity where svchost.exe spawns cmd.exe, potentially indicating malware masquerading or privilege escalation on Windows systems.

Windows execution svchost cmd
2r 2t
low advisory

Windows USN Journal Deletion via fsutil.exe

Adversaries may delete the USN journal on Windows systems using `fsutil.exe` to remove evidence of file modifications and other activities, hindering forensic investigations and incident response.

Windows defense-evasion anti-forensics fsutil
2r 1t
medium advisory

System Information Discovery Detection

This detection identifies system information discovery techniques by monitoring process execution logs for commands like `wmic qfe`, `systeminfo`, and `hostname`, often used by attackers to gather system configuration details for further exploitation, potentially leading to privilege escalation, persistence, or data exfiltration.

Windows discovery endpoint
2r 1t
medium advisory

Suspicious Windows Process Cluster from Parent Process via Machine Learning

A machine learning model detected a parent process spawning a cluster of suspicious Windows processes with high malicious probability scores, potentially indicating LOLBins usage and defense evasion.

Windows defense-evasion lolbin
2r 2t
high advisory

Suspicious MSHTML/MSHTA Network Execution Without Direct URL

This analytic detects the anomalous execution of mshta.exe or rundll32.exe invoking mshtml.dll without a direct HTTP/HTTPS URL in the command line, potentially indicating obfuscated script execution by threat actors for initial access or payload staging while evading static detections.

Windows mshta mshtml rundll32 lolbas defense-evasion initial-access network-execution
2r 2t
medium advisory

Suspicious Explorer Child Process via DCOM

A suspicious Windows Explorer child process is detected, indicating potential exploitation of explorer.exe to launch malicious scripts or executables from a trusted parent process via DCOM.

Windows explorer.exe dcom initial-access defense-evasion execution
3r 9t
medium advisory

Service Reconnaissance via WMIC.exe

Adversaries use WMIC.exe to enumerate running services on remote devices, potentially identifying valuable targets or misconfigured systems.

Windows attack.execution attack.t1047
2r 1t
medium advisory

Encoded Executable Stored in the Registry

This rule detects registry modifications used to hide encoded portable executables, indicating a defense evasion technique where adversaries avoid storing malicious content directly on disk by writing encoded executables to the Windows Registry.

Windows defense-evasion registry-modification encoded-executable
2r 3t 1i
low advisory

Windows Account Discovery of Administrator Accounts

The rule identifies instances of lower privilege accounts enumerating Administrator accounts or groups using built-in Windows tools like net.exe and wmic.exe, potentially indicating reconnaissance activity by an attacker after initial compromise.

Windows discovery account-discovery
2r 4t
high advisory

Windows TCP/IP Race Condition Privilege Escalation (CVE-2026-27921)

CVE-2026-27921 is a race condition vulnerability in Windows TCP/IP that allows a locally authenticated attacker to elevate privileges.

Windows privilege-escalation race condition
2r 1t 1c
high advisory

Windows SSDP Service Race Condition Privilege Escalation (CVE-2026-32082)

CVE-2026-32082 is a race condition vulnerability in the Windows SSDP Service that allows an authorized attacker to elevate privileges locally.

Windows cve-2026-32082 privilege-escalation
2r 1t 1c
medium advisory

Suspicious Registry Modifications by Scripting Engines

The use of scripting engines like WScript and CScript to modify the Windows registry can indicate an attempt to bypass standard tools and evade defenses, potentially for persistence or other malicious activities.

Windows defense-evasion persistence execution registry-modification
2r 3t
high advisory

Suspicious File Creation via Print Spooler Service

The Print Spooler service is being abused to create suspicious files, potentially leading to privilege escalation.

Windows printspooler privilege-escalation file-creation
2r 1t
medium advisory

Scheduled Task Created or Deleted via Command Line

Detection of scheduled task creation or deletion via command-line, often used for persistence and privilege escalation by threat actors.

Windows persistence privilege_escalation scheduled_task
2r 2t
medium advisory

Potential LSASS Memory Dump Activity

This brief covers the potential for credential access via LSASS memory dumping, a technique used to steal credentials from memory, though specific details are absent from the provided source.

Windows credential-access lsass memory-dump
2r 1t
medium advisory

Potential Evasion via Filter Manager

Adversaries may abuse the Filter Manager Control Program (fltMC.exe) to unload filter drivers, evading defenses like EDR and antivirus.

Windows defense-evasion filter-manager
2r 1t
low advisory

Netsh Helper DLL Persistence via Registry Modification

Attackers may establish persistence by adding a malicious DLL as a Netsh Helper, which executes whenever the Netsh utility is run, often abusing this mechanism to execute malicious payloads.

Windows persistence registry netsh
2r 3t
medium advisory

Local Account TokenFilter Policy Modification for Defense Evasion

Modification of the LocalAccountTokenFilterPolicy registry key to enable high-integrity tokens for local administrator accounts is detected, potentially allowing attackers to bypass User Account Control (UAC) and facilitate lateral movement.

Windows defense-evasion lateral-movement registry-modification
2r 3t
high advisory

Suspicious Startup Shell Folder Modification

This rule detects suspicious modifications to the startup shell folder registry keys, potentially indicating an attempt to establish persistence by pointing to malicious executables and bypassing traditional defenses.

Windows persistence defense-evasion registry-modification
2r 2t
medium advisory

Windows Registry Classes Autorun Keys Modification for Persistence

Adversaries modify Windows Registry Classes keys to establish persistence by executing malicious code when specific file types are opened or actions are performed, potentially leading to privilege escalation and persistent access.

Windows attack.privilege-escalation attack.persistence attack.t1547.001
3r 1t
high advisory

Suspicious PowerShell Execution via Windows Script Host

Adversaries may execute PowerShell commands through the Windows Script Host (wscript.exe or cscript.exe) using suspicious arguments, potentially bypassing traditional PowerShell execution policies and detection mechanisms.

Windows powershell wscript cscript execution scripting
2r 1t
medium advisory

Detection of Obfuscated IP Address Usage in Download Commands

This brief details the use of obfuscated IP addresses within download commands, often employed to evade detection by hiding the true destination of malicious downloads.

Windows discovery evasion obfuscation
2r 2t
high advisory

Pre-Ransomware Active Directory Discovery Burst

Attackers perform a burst of Active Directory discovery commands on a Windows host to gather information prior to ransomware deployment.

Windows +1 active-directory discovery ransomware
3r 3t
medium advisory

Application Compatibility Shim Database Installation for Persistence

Attackers abuse Application Compatibility Shims to establish persistence by installing custom shim databases, allowing for stealthy code execution within legitimate Windows processes.

Windows persistence app-compat
2r 1t
medium advisory

System Language Discovery via Reg.Exe

Adversaries use reg.exe to query system language settings in order to determine the geographic location of victims, customize payloads, or evade detection by avoiding certain locales.

Windows discovery system-language reg.exe
2r 1t
medium advisory

Potential NetNTLMv1 Downgrade Attack via Registry Modification

Attackers modify the Windows registry to weaken NTLM authentication, forcing a downgrade to the less secure NTLMv1 protocol, potentially leading to credential compromise.

Windows ntlm downgrade registry defense-evasion credential-access
2r 2t
medium advisory

Windows Scheduled Tasks AT Command Enabled via Registry Modification

Attackers may enable the deprecated Windows scheduled tasks AT command via registry modification to achieve local persistence or lateral movement on a compromised system.

Windows defense_evasion execution
2r 2t
high advisory

LSASS Memory Dump Creation Detection

This rule detects the creation of LSASS memory dumps, which may indicate a credential access attempt via tools like Task Manager, SQL Dumper, Dumpert, and AndrewSpecial.

Windows credential-access lsass memory-dump
2r 1t
high advisory

Execution via TSClient Mountpoint

The rule detects execution of processes from the Remote Desktop Protocol (RDP) shared mountpoint tsclient on a target host, indicating a potential lateral movement attempt by executing malicious files from the shared mountpoint.

Windows lateral-movement rdp
2r 2t
medium advisory

Network-Level Authentication (NLA) Disabled via Registry Modification

Detection of attempts to disable Network-Level Authentication (NLA) by modifying the registry on Windows systems, potentially enabling persistence methods and unauthorized access.

Windows defense-evasion lateral-movement registry-modification
2r 3t
high advisory

Wireless Credential Dumping using Netsh Command

Attackers may attempt to dump wireless credentials using `netsh.exe` to gain unauthorized network access, potentially leading to lateral movement and data compromise.

Windows credential-access discovery netsh wireless
2r 4t
medium advisory

NTDS Dump via Wbadmin Execution

Adversaries with Backup Operator privileges can abuse the legitimate Windows utility `wbadmin.exe` to dump the NTDS.dit file, enabling credential access and domain compromise.

Windows +1 credential-access defense-evasion
2r 3t
medium advisory

Unusual Process Performing NewCredentials Logon

Anomalous NewCredentials logon events triggered by uncommon processes may indicate access token manipulation for privilege escalation.

Windows privilege-escalation token-manipulation
2r 1t
low advisory

Unusual Group Name Accessed by User via Privileged Access Detection

A machine learning job detected a user accessing an uncommon group name for privileged operations, potentially indicating privilege escalation or unauthorized account manipulation on a Windows system.

Windows privileged-access-detection privilege-escalation
2r 5t
medium advisory

Rare SMB Connection to the Internet

This rule detects rare network connections via the SMB protocol to external networks, where SMB is commonly abused to exfiltrate data or leak NTLM credentials via UNC path injection.

Windows exfiltration credential-access smb
2r 2t
medium advisory

Potential Account Takeover via Logon from New Source IP

Atypical login activity where a user account, normally logging in from a high-volume, single source IP, suddenly authenticates from a different IP address, potentially indicating account takeover or stolen credentials.

Windows account-takeover credential-access
2r 1t
medium advisory

UAC Bypass via Windows Firewall MMC Snap-In Hijack

Attackers bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in to execute code with elevated permissions, potentially leading to system compromise.

Windows uac-bypass privilege-escalation windows-firewall mmc
2r 2t
high advisory

CVE-2026-32150 Function Discovery Service Race Condition Privilege Escalation

CVE-2026-32150 describes a race condition vulnerability in the Function Discovery Service (fdwsd.dll) that allows a locally authorized attacker to elevate privileges on a Windows system.

Windows privilege-escalation race-condition
2r 1t 1c
medium advisory

Process Execution from Unusual Windows Directories

Adversaries may execute processes from unusual Windows directories to masquerade malware as legitimate software and evade defenses.

Windows defense-evasion masquerading
1r 1t
high advisory

Uncommon Svchost Command Line Parameters Indicate Potential Masquerading or Injection

Detection of svchost.exe executing with uncommon command-line parameters, excluding known legitimate patterns, which may indicate file masquerading, process injection, or process hollowing.

Windows defense-evasion privilege-escalation process-injection
2r 2t
medium advisory

Local Account TokenFilter Policy Modification

An adversary modifies the LocalAccountTokenFilterPolicy registry key to weaken security controls and enable privilege escalation, allowing them to bypass User Account Control (UAC) and gain elevated privileges remotely.

Windows defense-evasion lateral-movement
2r 4t
medium advisory

Detection of Persistent Scripts in the Startup Directory

This rule identifies script engines creating files in the Startup folder, or the creation of script files in the Startup folder, enabling adversaries to maintain persistence by placing malicious scripts or shortcuts in the Windows Startup folder, which are then executed during account logon.

Windows persistence startup-folder malware
2r 2t
medium advisory

ProblemChild ML Detection of Suspicious Windows Processes

The ProblemChild machine learning model has detected a user with suspicious Windows processes exhibiting unusually high malicious probability scores, potentially indicating defense evasion via masquerading or LOLbins.

Windows defense-evasion machine-learning
2r 2t
high advisory

NetExec File Creation Detection

This brief covers the detection of NetExec, a post-exploitation and lateral movement tool, through monitoring for unique file creation patterns associated with its execution and file extraction in Windows environments.

Windows +1 netexec crackmapexec lateral-movement post-exploitation hacktool
2r 3t
medium advisory

Detect Suspicious Windows Service Installation

This detection identifies the creation of new Windows services with suspicious command values, often used for privilege escalation and persistence by malicious actors.

Windows persistence privilege_escalation service_creation
2r 1t
high advisory

Web Shell Activity Detection via Process Monitoring

This brief focuses on detecting malicious activity related to web shells on Windows systems by identifying the execution of command interpreters and scripting engines as child processes of common web server processes, potentially indicating unauthorized command execution and persistent access.

Windows +3 webshell persistence initial-access execution
2r 4t
medium advisory

Suspicious Process Execution via Renamed PsExec Executable

The rule identifies suspicious PsExec activity where the psexec service is executed from a renamed executable, possibly to evade detection and enable lateral movement.

PsExec +1 lateral-movement defense-evasion windows
2r 3t
high advisory

Windows Event Log Cleared

Detection of Windows event log clearing using Event IDs 1102 (Security) or 104 (System) which may indicate an attempt to hide malicious activity and impede forensic investigation.

Windows defense-evasion event-logs
2r 1t
medium advisory

Netsh Used to Enable Remote Desktop Protocol (RDP) in Windows Firewall

Adversaries use the `netsh.exe` utility to enable inbound Remote Desktop Protocol (RDP) connections through the Windows Firewall, potentially for unauthorized remote access and lateral movement.

Windows +1 defense-evasion lateral-movement rdp
2r 2t
high advisory

Conhost Spawned By Suspicious Parent Process

The Windows Console Host process (conhost.exe) spawned by a suspicious parent process, such as lsass.exe or explorer.exe, can indicate code injection used to bypass application allowlisting and execute malicious commands.

Windows execution defense-evasion privilege-escalation process-injection
2r 3t
low advisory

Windows User Account Creation via net.exe

Attackers may create new accounts on Windows systems using `net.exe` to maintain access and establish persistence, which this detection identifies.

Windows persistence account-creation
3r 2t
medium advisory

Windows Persistence via Scheduled Job Creation

Adversaries can abuse the Windows Task Scheduler to establish persistence by creating malicious scheduled jobs, which are detected by monitoring for the creation of '.job' files in the 'Windows\Tasks' directory while excluding known legitimate software.

Windows persistence scheduled-task
2r 1t
medium advisory

Execution of Downloaded Windows Script

This rule identifies the creation and execution of a Windows script downloaded from the internet, which adversaries may leverage for initial access and execution by exploiting unusual parent-child process relationships and script attributes.

Windows execution scripting
2r 5t
medium advisory

Werfault ReflectDebugger Persistence Abuse

Attackers can achieve persistence by modifying the ReflectDebugger registry key associated with Windows Error Reporting (Werfault) to execute arbitrary code when Werfault is invoked with the `-pr` parameter.

Windows persistence registry
2r 2t
high advisory

PowerShell Invoke-NinjaCopy Script Detection

The Invoke-NinjaCopy PowerShell script is used by attackers to directly access volume files, such as NTDS.dit or registry hives, for credential dumping.

Windows credential-access powershell ninjacopy
2r 1t
low advisory

Windows Peripheral Device Discovery via fsutil

Adversaries use the Windows file system utility `fsutil.exe` with the `fsinfo drives` argument to enumerate attached peripheral devices for reconnaissance and situational awareness after gaining initial access.

Windows discovery fsutil
2r 1t
high advisory

Windows EventLog Autologger Session Disabled via Registry Modification

Adversaries may attempt to disable Windows EventLog autologger sessions via registry modification to evade detection and prevent security monitoring of early boot activities and system events.

Windows attack.defense-evasion attack.t1562.002
2r 1t
high advisory

WMI Permanent Event Subscription Abuse for Persistence

Attackers use WMI permanent event subscriptions to execute malicious scripts or binaries for persistence by creating event consumers other than the default NTEventLogEventConsumer.

Windows persistence wmi
2r 1t
high advisory

Windows Suspicious Process Execution from Unusual File Paths

Adversaries may execute malicious processes from unusual file paths (e.g., within Windows, Users, or Recycle Bin directories) to evade defenses and potentially compromise systems.

Windows suspicious-process defense-evasion persistence
3r 2t
low advisory

Wallpaper Modification Detection

Detection of unauthorized or suspicious wallpaper modifications on endpoints can indicate malicious activity or policy violations.

Windows endpoint wallpaper modification registry policy violation
3r 1t
medium advisory

Unusual Persistence via Services Registry Modification

Adversaries may modify the Windows services registry keys directly to stealthily persist through abnormal service creation or modification of an existing service, bypassing standard APIs, detected by monitoring registry changes related to service DLLs and image paths.

Windows persistence registry services
2r 3t
critical advisory

Suspicious Raw Disk Access Detected

Detection of processes accessing raw disk volumes outside of normal system paths, often associated with wiper malware and boot sector attacks.

Windows raw-disk-access wiper boot-sector
2r 1t
high advisory

Suspicious PowerShell Arguments Detected

Detection of suspicious arguments used with PowerShell, potentially indicating malicious activity execution.

PowerShell +1 execution suspicious-arguments windows
2r 1t
high advisory

Suspicious LSASS Access via Malicious Secondary Logon Service

An attacker abuses the Secondary Logon service (seclogon.dll) to gain unauthorized access to the LSASS process, potentially leaking credentials.

Windows credential-access lsass seclogon
3r 1t
high advisory

Ransomware Attempting to Disable Windows Recovery via Bcdedit

This brief details the detection of ransomware actors using bcdedit.exe to modify boot settings, specifically disabling automatic repair mode to hinder system recovery.

Windows ransomware bootkit
2r 1t
medium advisory

Potential Application Shimming via Sdbinst

This brief covers the abuse of application shimming in Windows via `sdbinst.exe` to achieve persistence and privilege escalation by executing arbitrary code within legitimate processes.

Windows persistence privilege-escalation application-shimming
3r 2t
high advisory

LSASS Protection Policy Disabled via Registry Modification

Attackers may disable Protected Process Light (PPL) protection for the LSASS process by modifying specific registry keys, allowing for credential dumping and other malicious activities.

Windows credential-access defense-evasion lsass ppl registry
2r 2t
medium advisory

Google Workspace BitLocker Setting Disabled

Detection of Google Workspace administrators disabling the BitLocker setting, potentially allowing adversaries with valid account access to decrypt sensitive data on managed Windows devices.

Google Workspace +2 google_workspace bitlocker defense_evasion
2r 2t
medium advisory

Windows Subsystem for Linux Enabled via Dism Utility

Adversaries may enable Windows Subsystem for Linux (WSL) via the Dism utility to evade detection by running Linux tools on Windows.

Windows +1 defense-evasion wsl
2r 1t
high advisory

Privilege Escalation via Windows Token Theft

An adversary may create a new process with a different token to escalate privileges and bypass access controls by creating a process running as SYSTEM and impersonating a Windows core binary.

Windows privilege-escalation token-theft
2r 1t
medium advisory

Potential Timestomping of Executable Files on Windows

This rule identifies potential timestomping behavior on Windows systems where the creation time of executable files in sensitive system directories is modified, potentially to blend malicious executables with legitimate system files and evade detection.

Windows defense-evasion timestomp
2r 1t
high advisory

Potential System Tampering via File Modification

Attackers may attempt to modify or delete critical Windows boot files such as 'winload.exe' or 'ntoskrnl.exe' to inhibit system recovery and cause data destruction, leading to a denial-of-service condition.

Windows impact defense-evasion
2r 2t
high advisory

Potential Remote Install via MsiExec

Adversaries may abuse Windows Installers via MsiExec to install files from remote servers for initial access and delivery of malware, which is detected by identifying MsiExec processes with network connections and specific command-line arguments.

Windows msiexec defense-evasion remote-install
2r 2t
medium advisory

Ingress Transfer via Windows BITS

Adversaries leverage the Windows Background Intelligent Transfer Service (BITS) to download executable and archive files, potentially delivering malicious payloads while evading traditional security measures.

Windows bits file-transfer command-and-control defense-evasion
2r 2t
medium advisory

Detection of Custom Shim Database Installation for Persistence

Attackers abuse the Application Compatibility Shim functionality in Windows to establish persistence and achieve arbitrary code execution by installing malicious shim databases, which this detection identifies through monitoring registry changes.

Windows +7 persistence app-compat shim
2r 1t
high advisory

Detecting Windows Remote Image Loading for Malicious Activities

This analytic detects instances where a process loads a file from a remote share path, potentially indicating execution, defense evasion, or lateral movement by attackers loading code from attacker-controlled infrastructure.

Windows +3 remote-image-load defense-evasion lateral-movement sysmon
2r 5t
high advisory

Suspicious Download from File Sharing Website via LOLBins

Detection of suspicious downloads from file sharing and content delivery platforms using living-off-the-land binaries (LOLBins) to identify potential initial access, payload staging, or command and control activity.

Windows lolbin file-sharing cisco-nvm
3r 1t 26i
high advisory

VssAdmin Shadow Copy Deletion or Resize

The rule identifies the use of vssadmin.exe to delete or resize shadow copies on Windows endpoints, which is a common tactic used in ransomware attacks to prevent system recovery.

Windows volume-shadow-copy ransomware impact
2r 1t
medium advisory

Process Execution from Suspicious Windows Directories

Adversaries may execute processes from unusual default Windows directories to masquerade malware and evade defenses by blending in with trusted paths, making malicious activity harder to detect.

Windows +2 defense-evasion masquerading
2r 1t
medium advisory

DCOM Lateral Movement via ShellWindows/ShellBrowserWindow

This analytic identifies the use of Distributed Component Object Model (DCOM) to execute commands on a remote host, specifically when launched via ShellBrowserWindow or ShellWindows Application COM objects, indicating potential lateral movement by an attacker.

Windows lateral-movement dcom
2r 2t
medium advisory

Executable File Creation with Multiple Extensions

This rule detects the creation of executable files with multiple extensions, a masquerading technique used to evade defenses by disguising malicious executables as benign files to trick users into executing them.

Windows defense-evasion masquerading file-extension
2r 2t
low advisory

Unusual Time or Day for an RDP Session Detected by Machine Learning

A machine learning job detected an RDP session initiated at an unusual time or day, potentially indicating lateral movement activity within a network.

Windows lateral-movement threat-detection
2r 2t
low advisory

Suspicious Whoami Process Activity

The `whoami` command is being used by an attacker to enumerate user, group, and privilege information on a Windows system, potentially indicating post-exploitation discovery activity after initial compromise or privilege escalation.

Windows discovery
3r 2t
high advisory

Potential Remote Desktop Tunneling Detected via SSH

Detection of SSH utilities establishing RDP tunnels, potentially enabling attackers to route network packets to otherwise unreachable destinations, facilitating command and control or lateral movement.

Windows rdp ssh tunneling command-and-control lateral-movement
2r 2t
medium advisory

Potential Port Monitor or Print Processor Registration Abuse

This rule detects potential abuse of port monitors and print processors for privilege escalation and persistence on Windows systems by identifying registry modifications to load malicious DLLs that execute with SYSTEM privileges during system boot, focusing on modifications made by non-SYSTEM users.

Windows privilege-escalation persistence
2r 4t
medium advisory

Netsh Used to Enable Network Discovery

Adversaries may use the `netsh.exe` command-line tool to enable Network Discovery via the Windows firewall, weakening host defenses and facilitating lateral movement by identifying other systems on the network.

Windows defense-evasion firewall lateral-movement
2r 1t
high advisory

FodHelper UAC Bypass Attempt

Detection of fodhelper.exe execution, which is known to exploit User Account Control (UAC) bypass by leveraging specific registry keys, potentially leading to privilege escalation.

Windows uac-bypass privilege-escalation fodhelper
2r 2t
low advisory

Code Integrity - Unmet Signing Level Requirements

Windows Code Integrity events 3033 and 3034 indicate an attempted file load that failed to meet the configured signing level requirements, potentially due to revoked signatures or expired certificates, signaling a possible attempt to load unsigned or untrusted code.

Windows +1 codeintegrity execution
2r 1t
low advisory

Command Shell Activity Started via RunDLL32

Adversaries abuse RunDLL32, a legitimate Windows utility, to execute command shells (cmd.exe or PowerShell) for malicious purposes, bypassing security controls.

Windows rundll32 command-shell proxy-execution
2r 5t
high advisory

Potential Execution via FileFix Phishing Attack

This rule detects potential execution of Windows commands or downloaded files via the browser's dialog box, indicative of a phishing attack where victims are tricked into copying and pasting malicious commands.

Windows phishing execution
2r 6t
high advisory

Windows Registry Modification to Disable Registry Tools

This analytic detects modifications to the Windows registry, specifically targeting the 'DisableRegistryTools' key, which is a common tactic used by malware for persistence and defense evasion by preventing the removal of malicious entries.

Windows +3 defense-evasion registry-modification persistence
2r 2t
high advisory

Windows Storage Spaces Controller Integer Underflow Vulnerability (CVE-2026-27907)

CVE-2026-27907 is an integer underflow vulnerability in the Windows Storage Spaces Controller, allowing a local attacker with authorization to escalate privileges on the system.

Windows privilege-escalation cve-2026-27907
2r 1t 1c 1i
low advisory

Suspicious Windows Process Cluster Detection via Machine Learning

A machine learning job combination has identified a host with one or more suspicious Windows processes that exhibit unusually high malicious probability scores, potentially indicating masquerading and defense evasion tactics.

Windows defense-evasion masquerading LOLbins
2r 2t
medium advisory

Suspicious Execution via Scheduled Task

This rule identifies execution of suspicious programs via scheduled tasks by looking at process lineage and command line usage, detecting processes such as cscript.exe, powershell.exe, and cmd.exe when executed from suspicious paths like C:\Users\ and C:\ProgramData\.

Windows persistence execution
2r 2t
high threat

CVE-2026-32073 - Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

CVE-2026-32073 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock, enabling a locally authorized attacker to escalate privileges.

exploited Windows vulnerability privilege-escalation
2r 1t 1c
medium advisory

Potential Credential Access via LSASS Handle Duplication

Detection of suspicious LSASS handle access via DuplicateHandle from an unknown call trace module, indicating a potential attempt to bypass the NtOpenProcess API to evade detection and dump LSASS memory for credential access.

Windows credential-access lsass duplicatehandle mirrordump
2r 1t
high advisory

CVE-2026-27922 Windows WinSock Use-After-Free Privilege Escalation

CVE-2026-27922 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock that allows an authenticated attacker to elevate privileges locally.

Windows privilege-escalation use-after-free
2r 1t 1c 1i
high advisory

Control Panel Abuse for Defense Evasion and Execution

Adversaries may abuse the legitimate Windows Control Panel (control.exe) to proxy the execution of malicious code by using unusual arguments such as image file extensions, suspicious paths, or relative path traversal patterns for defense evasion.

Windows defense-evasion execution
3r 2t
low advisory

Windows Account Discovery of Administrator Accounts

Adversaries may execute the `net.exe` or `wmic.exe` commands to enumerate administrator accounts or groups, both locally and within the domain, to gather information for follow-on actions.

M365 Defender +2 discovery account-discovery windows
2r 4t
high advisory

Detecting Remcos RAT Activity Through File and Registry Traces

This brief provides detection strategies for Remcos RAT, focusing on file and registry artifacts indicative of its presence, persistence, and potential cleanup activities on Windows systems, allowing for the identification and remediation of compromised hosts.

Windows remcos rat trojan
3r 3t 6i
medium advisory

Multiple Logon Failures from Single Source Indicate Brute Force Attempt

Detection of multiple consecutive logon failures from a single source IP within a short time interval indicates a potential brute force or password guessing attack targeting Windows systems.

Windows credential-access brute-force
2r 2t
high advisory

Detection of Invoke-Obfuscation via Standard Input

This brief outlines detection strategies for adversaries leveraging Invoke-Obfuscation techniques within PowerShell scripts executed via standard input, a method commonly used to evade traditional detection mechanisms.

Windows defense-evasion obfuscation powershell
2r 2t
high advisory

Adversaries Disabling Important Scheduled Tasks

Adversaries disable crucial scheduled tasks, such as those related to BitLocker, Windows Defender, System Restore and Windows Update, using schtasks.exe to disrupt services and potentially facilitate data destruction or ransomware deployment.

Windows attack.impact attack.t1489
2r 1t
medium advisory

Windows Time-Based Evasion via Choice Exec

Detection of choice.exe used in batch files for time-based evasion, a technique observed in SnakeKeylogger malware, indicating potential stealthy code execution and persistence.

Windows +3 time-based-evasion malware persistence defense-evasion
2r 1t
medium advisory

Windows Processes Gathering Network Information via IP Check Web Services

Detection of Windows processes using IP check web services for reconnaissance, a behavior commonly associated with malware like Trickbot, by monitoring DNS queries.

Windows network-reconnaissance malware-behavior
2r 1t 26i
high advisory

Windows High File Deletion Frequency Indicative of Ransomware

This analytic identifies a high frequency of file deletions by monitoring Sysmon EventCodes 23 and 26 for specific file extensions, which can indicate ransomware activity leading to data loss and operational disruption.

Windows file-deletion ransomware
1r 1t
medium advisory

Windows Folder Options Disabled via Registry Modification

Attackers modify the Windows registry to disable the Folder Options feature, preventing users from showing hidden files and file extensions, commonly used by malware to conceal malicious files and deceive users with fake file extensions.

Splunk Enterprise +3 defense-evasion registry-modification windows
2r
medium advisory

Windows EventLog Reconnaissance Activity Detection

This detection identifies potential reconnaissance activities on Windows systems by adversaries using tools like `wevtutil.exe`, `wmic.exe`, and PowerShell cmdlets to query event logs for sensitive information.

Windows eventlog reconnaissance
3r 1t
low advisory

Windows Event Log Clearing Attempt Detected

Adversaries clear Windows event logs to evade detection and destroy forensic evidence, breaking SIEM detections and covering their tracks.

Windows defense-evasion event-logs
3r 1t
high threat

Windows AutoLogger Session Tampering Detection

Attackers may disable AutoLogger sessions by modifying specific registry values to evade detection and prevent security monitoring of early boot activities and system events, a technique observed in intrusions involving IcedID and XingLocker ransomware.

exploited Windows attack.defense-evasion attack.t1562.002
3r 1t
medium advisory

Unusual Network Activity from Windows System Binaries

Detection of network connections initiated by unusual Windows system binaries, often leveraged by adversaries to proxy execution of malicious code and evade detection, indicating potential defense evasion and command and control activity.

Windows defense-evasion proxy-execution
3r 5t
medium advisory

System Shells Launched via Windows Services

Attackers may configure existing Windows services or create new ones to execute system shells (cmd.exe, powershell.exe) to elevate privileges from administrator to SYSTEM for persistence and further malicious activity.

Windows persistence execution privilege-escalation
2r 4t
medium advisory

Suspicious WMI Reconnaissance via PowerShell

This analytic detects suspicious PowerShell activity leveraging WMI to gather system information, potentially indicating reconnaissance by an attacker.

Windows reconnaissance powershell wmi
2r 2t
high advisory

Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location

The loading of dbgcore.dll or dbghelp.dll from unusual locations like user directories indicates potential credential dumping or EDR evasion attempts by malicious actors.

Windows credential-access defense-evasion dll-injection
2r 2t
high advisory

Suspicious Execution from WebDAV Share

This rule detects attempts to execute content from remote WebDAV shares, where attackers may abuse WebDAV paths, public tunnels, or host@port UNC paths to execute tools or scripts, reducing local staging on the victim's file system.

Windows +5 execution webdav threat_detection
2r 1t
medium advisory

Suspicious .NET Code Compilation via Unusual Parent Processes

The execution of .NET compilers (csc.exe, vbc.exe) with suspicious parent processes (wscript.exe, mshta.exe, etc.) indicates potential attempts to compile code after delivery for defense evasion and execution.

Windows defense-evasion execution dotnet compiler
2r 9t
low advisory

Spike in Special Privilege Use Events

A machine learning job detected an unusual increase in special privilege usage events on Windows, such as privileged operations and service calls, potentially indicating unauthorized privileged access and privilege escalation attempts.

Windows privileged-access-detection privilege-escalation
2r 4t
high advisory

Script Execution via Microsoft HTML Application

Detects the execution of scripts via HTML applications using Windows utilities rundll32.exe or mshta.exe to bypass defenses by proxying execution of malicious content with signed binaries.

Windows +8 defense-evasion script-execution
3r 1t
medium advisory

Remote File Download via PowerShell

Detects PowerShell being used to download executable files from untrusted remote destinations, often used by attackers to transfer malware into a compromised environment.

PowerShell +1 command-and-control file-download windows
2r 2t
medium advisory

Rare Connection to WebDAV Target for Credential Access

Adversaries may inject WebDAV paths into files or features opened by a user to leak NTLM credentials via forced authentication, and this detection identifies rare connections to WebDAV resources using rundll32.exe.

Windows credential-access webdav
2r 2t
medium advisory

Potential Lateral Tool Transfer via SMB Share

This rule identifies the creation or change of a Windows executable file over network shares (SMB), indicating adversaries may transfer tools or other files between systems in a compromised environment.

Windows lateral-movement smb file-creation
3r 2t
medium advisory

Mounting Hidden or WebDav Remote Shares via Net.exe

Adversaries may use net.exe to mount WebDav or hidden remote shares, indicating lateral movement or preparation for data exfiltration within a Windows environment.

Windows lateral-movement net.exe webdav
2r 4t
high threat

Detection of NetExec Hacktool Execution

The threat brief details the detection of NetExec (formerly CrackMapExec), a post-exploitation tool used for Active Directory penetration testing and network enumeration, often employed by threat actors for lateral movement and credential harvesting.

Active Directory +1 pentest post-exploitation lateral-movement active-directory
2r 2t
high advisory

Windows System File Execution from Unusual Location

This rule detects the execution of legitimate Windows system binaries from non-standard locations, potentially indicating malicious activity such as malware execution or defense evasion.

Windows defense-evasion anomaly
2r 1t
medium advisory

Windows Netsh Tool Used for Firewall Discovery

The native Windows `netsh.exe` tool is being abused to discover firewall configurations, potentially to weaken defenses before lateral movement and data exfiltration.

Windows network-discovery firewall netsh
2r 1t
high advisory

Volume Shadow Copy Deletion via WMIC

Attackers use Windows Management Instrumentation Command-line (WMIC) to delete volume shadow copies, inhibiting system recovery in ransomware and destructive attacks.

Windows volume-shadow-copy wmic ransomware impact
2r 2t
high advisory

TelemetryController Scheduled Task Hijack for Persistence and Privilege Escalation

Adversaries can hijack the Microsoft Compatibility Appraiser scheduled task (TelemetryController) to establish persistence and escalate privileges by executing arbitrary code with system-level permissions.

Windows persistence privilege-escalation scheduled-task
2r 2t
medium advisory

Symbolic Link Creation to Shadow Copies for Credential Access

The creation of symbolic links to shadow copies on Windows systems by processes such as cmd.exe or powershell.exe can indicate an attempt to access sensitive files for credential theft.

Windows +1 credential-access defense-evasion
2r 3t
high advisory

Suspicious Script Interpreter Execution from Environment Variable Folders

Malware may execute scripts from suspicious directories accessible via environment variables using script interpreters like cscript, wscript, mshta, and powershell to evade detection.

Windows execution script-execution malware
2r 1t
high advisory

Suspicious Antimalware Scan Interface DLL Creation

The rule detects the creation of the Antimalware Scan Interface (AMSI) DLL in an unusual location, potentially indicating an attempt to bypass AMSI by loading a rogue AMSI module, a technique used for defense evasion.

Windows amsi dll-hijacking defense-evasion
2r 2t
high advisory

Potential Credential Access via Windows Utilities

This brief detects the execution of known Windows utilities such as procdump, ntdsutil, and diskshadow, often abused to dump LSASS memory or the Active Directory database (NTDS.dit) in preparation for credential access, potentially leading to widespread compromise.

Windows +1 credential-access lsass ntdsutil procdump
2r 3t
high advisory

Mimikatz Memssp Module Log File Detection

The creation of 'mimilsa.log', a log file generated by the Mimikatz 'misc::memssp' module, indicates credential access attempts by injecting a malicious Windows Security Support Provider (SSP) to harvest locally authenticated credentials.

Windows +1 credential-access mimikatz
2r 3t
high advisory

Invoke-Obfuscation via Clip.exe

The use of `clip.exe` in conjunction with PowerShell and command-line obfuscation is used to evade detection.

Windows defense-evasion execution obfuscation
2r 2t
medium advisory

UAC Bypass via DiskCleanup Scheduled Task Hijack

Attackers bypass User Account Control (UAC) to stealthily execute code with elevated permissions by hijacking the DiskCleanup Scheduled Task, leveraging specific arguments with non-standard executables.

Windows uac-bypass privilege-escalation
2r 3t
low advisory

Modification of Boot Configuration using Bcdedit

Adversaries may modify the Boot Configuration Data (BCD) store using bcdedit.exe to disable recovery options, which is often associated with ransomware or destructive attacks, preventing system recovery.

Windows impact boot-configuration
2r 1t
medium advisory

Suspicious Non-Interactive PowerShell Process Creation

Detects PowerShell processes spawned by non-interactive parent processes, potentially indicating malicious script execution or automation bypassing user interaction.

Windows +3 powershell execution non-interactive
2r 1t
medium advisory

Registry Persistence via AppCert DLL

Detection of Registry Persistence via AppCert DLL, which involves modifying registry keys to load malicious DLLs upon process creation, enabling persistence and potential privilege escalation.

Windows persistence privilege-escalation
2r 2t
medium advisory

Unusual Network Connection via DllHost

The rule identifies unusual instances of dllhost.exe making outbound network connections to non-local IPs, which may indicate adversarial Command and Control activity and defense evasion.

Elastic Defend +2 defense-evasion command-and-control windows
2r 2t
medium advisory

Suspicious Execution from a Mounted Device

Attackers may use mounted devices as a non-standard working directory to execute signed binaries or script interpreters, evading traditional defense mechanisms, particularly when launched via explorer.exe.

Windows defense-evasion execution mounted-device
2r 9t
medium advisory

Suspicious CertUtil Commands Used for Defense Evasion

Attackers abuse certutil.exe, a native Windows utility, to download/deobfuscate malware for command and control or data exfiltration, evading defenses.

Windows defense-evasion command-and-control credential-access
2r 3t
medium advisory

Detecting Remote Windows Service Installation for Lateral Movement

This rule detects a network logon followed by Windows service creation with the same LogonId on a Windows host, which could indicate lateral movement or persistence by adversaries.

Windows +4 lateral-movement persistence
2r 3t
high advisory

WSASS Tool Execution for LSASS Memory Dumping

The WSASS tool is executed to dump LSASS memory, leveraging WER's WerFaultSecure.EXE to bypass Protected Process Light (PPL) protections, potentially leading to credential access.

Windows credential-access lsass memory-dumping
3r 1t
low advisory

Windows USN Journal Deletion via Fsutil

Adversaries may delete the volume USN Journal on Windows systems using `fsutil.exe` to eliminate evidence of post-exploitation file activity.

Windows defense-evasion fsutil usn journal
2r 1t
medium advisory

Windows System Restore Disabled via Registry Modification

Attackers disable Windows System Restore by modifying specific registry keys to hinder recovery efforts after malicious activity.

Windows impact t1490 persistence
2r 1t
medium advisory

Windows System File Ownership Change via Takeown or Icacls

Adversaries may modify file or directory ownership to evade access control lists (ACLs) and access protected files by using takeown.exe or icacls.exe to grant excessive permissions to system files.

Windows defense-evasion persistence
2r 2t
high advisory

Windows SmartScreen Disabled via Registry Modification

Attackers disable Windows SmartScreen protection by modifying specific registry keys to evade detection and facilitate malware deployment.

Windows defense-evasion registry-modification smartscreen
2r 1t
low advisory

Windows Root Certificate Modification for Defense Evasion

An attacker modifies trusted root certificates in Windows to masquerade malicious files as valid or decrypt SSL traffic, evading defenses and potentially enabling adversary-in-the-middle attacks.

Windows defense-evasion subvert-trust-controls
2r 2t
high advisory

Windows Registry Modification to Disable Task Manager

Attackers modify the Windows registry to disable Task Manager, preventing users from terminating malicious processes and allowing persistence.

Splunk Enterprise +3 defense-evasion privilege-escalation registry-modification
2r
high advisory

Windows Projected File System Double Free Vulnerability (CVE-2026-32069)

CVE-2026-32069 is a double free vulnerability in the Windows Projected File System that allows an authorized local attacker to elevate privileges.

Windows cve-2026-32069 privilege-escalation
2r 1t 1c
medium advisory

Windows Firewall Rule Modification Detection

This detection identifies instances where a Windows Firewall rule has been modified, potentially indicating an attempt to weaken security policies and allow malicious traffic or prevent legitimate communications.

Windows +3 firewall anomaly
2r
medium advisory

Windows Firewall Rule Deletion Detection

Detection of Windows Firewall rule deletion events (Event ID 4948) indicating potential attacker attempts to bypass security controls or malware disabling protections for persistence and command-and-control.

Windows +3 firewall endpoint
2r 1t
medium advisory

Windows Firewall Disabled via Netsh

Attackers use the `netsh.exe` command-line tool to disable or weaken the local Windows firewall, facilitating lateral movement and command and control by bypassing host-based network traffic filtering.

Windows defense-evasion firewall
2r 1t
low advisory

Windows Event Log Clearing Detected

This threat brief covers the detection of adversaries clearing or disabling Windows event logs, a common defense evasion tactic, using tools like wevtutil.exe and PowerShell cmdlets to remove evidence of their activities.

Windows defense-evasion event-logs
2r 2t
high advisory

Windows Defender Evasion via Protected Process Light (PPL) Manipulation

An attacker can potentially evade Windows Defender by manipulating Protected Process Light (PPL) attributes, allowing malicious processes to operate with elevated privileges and avoid security scans.

Windows +1 ppl windows-defender evasion
2r 2t
high advisory

Windows Data Destruction via Recursive Executable File Deletion

A suspicious process recursively deleting executable files (e.g., .exe, .sys, .dll) indicates potential data destruction activity, detected via high-volume file deletion/overwrite events associated with destructive malware families like CaddyWiper and SwiftSlicer.

Windows data-destruction wiper sysmon
2r 1t
high advisory

Windows ComputerDefaults Process Spawning Detection

The ComputerDefaults.exe process, used for managing default application associations in Windows, can be exploited by attackers to bypass User Account Control (UAC) and execute unauthorized code with elevated privileges, which is detected by monitoring abnormal parent-child process relationships.

Windows privilege-escalation uac-bypass
2r 1t
high threat

Windows Command-Line Tool Execution from Non-Shell Process

Detection of command-line tools such as `ipconfig.exe` and `systeminfo.exe` being executed from non-standard parent processes can indicate system discovery activity by threat actors like FIN7 using injected processes.

Windows FIN7 +2 discovery process-injection
2r 1t
high advisory

Windows AutoLogger Session Disabled via Registry Modification

An attacker disables Windows AutoLogger sessions by modifying specific registry values to evade defenses and blind EDR and log ingest tools.

Splunk Enterprise +3 defense-evasion windows registry-abuse
2r 1t
medium advisory

Windows Auditpol ResourceSACL Clearing for Defense Evasion

Adversaries may clear the global object access auditing policy using `auditpol.exe` with the `/resourceSACL` flag and either `/clear` or `/remove` arguments to evade detection by removing audit configurations.

Splunk Enterprise +3 defense-evasion windows
2r
medium advisory

Windows Audit Policy Sub-Category Disabled

This rule detects attempts to disable auditing for security-sensitive audit policy sub-categories on Windows systems, often done by attackers to evade detection and forensic analysis.

Windows defense_evasion audit_policy
2r 3t
high advisory

Windows Audit Policy Disabled via Legacy Auditpol

Adversaries may disable Windows audit policies using the legacy auditpol.exe utility to evade detection by limiting the data available for security monitoring and incident response.

Windows +3 auditpol defense-evasion
2r 1t
high threat

Windows Audit Policy Cleared via Auditpol

The execution of `auditpol.exe` with the `/clear` or `/remove` command-line arguments indicates potential defense evasion by adversaries or Red Teams, aiming to limit data that can be leveraged for detections and audits, potentially leading to full machine compromise or lateral movement.

Windows +3 defense-evasion audit-tampering
2r 1t
high advisory

WDigest Security Provider Registry Modification

Adversaries may modify the WDigest security provider registry key to force the storage of user passwords in cleartext, enabling credential dumping and unauthorized access.

Windows credential-access registry-modification
3r 2t
low advisory

Unusual Scheduled Task Update

This rule detects modifications to scheduled tasks by user accounts, excluding system activity and machine accounts, which adversaries can exploit for persistence by modifying them to execute malicious code.

Windows persistence scheduled-task
2r 1t
medium advisory

Uncommon Registry Persistence Change Detection

This rule detects changes to uncommon registry persistence keys on Windows systems that are not commonly used or modified by legitimate programs, which could indicate an adversary's attempt to persist in a stealthy manner by modifying registry keys for persistence, ensuring malicious code executes on startup or during specific events.

Windows persistence registry
2r 2t
medium advisory

System Process Executables Created in Unusual Locations

The creation of executable files masquerading as legitimate Windows system processes in non-standard directories indicates potential malware installation or defense evasion tactics by threat actors.

Windows defense-evasion file-creation masquerading
3r 1t
medium advisory

Suspicious Script Object Execution via scrobj.dll

Detection of scrobj.dll loaded into unusual Microsoft processes indicates potential malicious scriptlet execution for defense evasion and execution by abusing legitimate system binaries.

Elastic Defend +3 defense-evasion execution windows
2r 2t
high advisory

Suspicious Script Interpreter Execution from Environment Variable Folders

Adversaries may execute script interpreters such as cscript, wscript, mshta, or powershell from suspicious directories accessible via environment variables to evade detection and execute malicious scripts.

Windows attack.execution attack.t1059
2r 1t
high advisory

Suspicious Remote Installation via MsiExec

This rule detects the execution of msiexec.exe to install a file from a remote server, a technique adversaries abuse for initial access and malware delivery by leveraging Windows Installers and initiating network activity.

Windows defense-evasion msiexec
2r 1t
medium advisory

Suspicious Network Connection via Registration Utility

The native Windows tools regsvr32.exe, regsvr64.exe, RegSvcs.exe, or RegAsm.exe making a network connection may indicate an attacker bypassing allowlists or running arbitrary scripts via a signed Microsoft binary.

Windows execution defense evasion regsvr32
2r 4t
medium advisory

Suspicious Mofcomp Activity Leading to WMI Abuse

Attackers may leverage the mofcomp.exe utility to compile malicious MOF files, enabling them to manipulate the Windows Management Instrumentation (WMI) repository for persistence or execution of arbitrary code.

Windows execution persistence wmi mofcomp
2r 3t
high advisory

Suspicious Managed Code Hosting Process

The rule identifies suspicious managed code hosting processes (wscript.exe, cscript.exe, mshta.exe, wmic.exe, svchost.exe, dllhost.exe, cmstp.exe, regsvr32.exe), which could indicate code injection or other forms of suspicious code execution on Windows systems, often used for defense evasion.

Windows defense-evasion execution
2r 7t
high advisory

Suspicious LNK File Creation in Temporary Directories

Detection of processes creating .lnk files in suspicious locations like user directories or temporary folders, often indicative of spear phishing or malware persistence mechanisms.

Windows lnk shortcut persistence phishing
2r 3t
high advisory

Suspicious ImagePath Service Creation

Adversaries may create or modify Windows services with malicious ImagePath values containing command shells or named pipes to establish persistence or escalate privileges, detected through registry modifications.

Windows persistence defense_evasion
2r 2t
medium advisory

Suspicious Copy from or to System Directory

This threat involves the suspicious copying of files from or to Windows system directories (System32, SysWOW64, WinSxS) using command-line tools, often employed by attackers to relocate LOLBINs for defense evasion.

Windows defense-evasion lolbin
3r 1t
high threat

Suspicious Bluetooth Service Installation from Uncommon Location

The creation of a Windows service named 'BluetoothService' with a binary path in user-writable directories, such as %AppData%, indicates potential malware persistence, as seen in the Lotus Blossom Chrysalis backdoor campaign.

Windows Lotus Blossom persistence defense-evasion anomaly
2r 2t
high advisory

Suspicious Alternate Data Stream (ADS) File Creation

The rule identifies the suspicious creation of Alternate Data Streams (ADS) on targeted files using a script or command interpreter, a technique used by adversaries to hide malicious files and evade detection.

Windows +2 defense-evasion alternate-data-stream
2r 1t
medium advisory

Suspicious Access to Windows Product Key Registry

Detection of processes attempting to access the Windows registry to recover product keys, potentially indicating malware activity, unauthorized security bypass, or data exfiltration.

Windows registry product-key malware
2r 1t
high advisory

Shadow Copy Deletion via VSSAdmin or WMIC

Attackers delete shadow copies using vssadmin.exe or wmic.exe to prevent data recovery, often preceding ransomware deployment or data exfiltration.

Windows shadow-copy anti-forensic ransomware
2r 1t
medium advisory

Service Startup Type Modification via WMIC

Adversaries use the Windows Management Instrumentation Command-line (WMIC) utility to modify the startup type of services, setting them to 'Manual' or 'Disabled' to impair defenses or disrupt system operations.

Windows attack.execution attack.t1047 attack.defense-evasion attack.t1562.001
2r 2t
medium advisory

SeDebugPrivilege Enabled by a Suspicious Process

The rule identifies a process running with a non-SYSTEM account that enables the SeDebugPrivilege privilege, which can be used by adversaries to debug and modify other processes to escalate privileges and bypass access controls.

Windows privilege-escalation token-manipulation
2r 1t
medium advisory

Scheduled Task Creation via Group Policy Object

Detects the creation of scheduled tasks within a Group Policy Object (GPO) by monitoring for the creation of the ScheduledTasks.xml file in the SYSVOL share, potentially indicating malicious persistence.

Splunk Enterprise +3 scheduled-task gpo persistence windows
2r 2t
high threat

Rundll32 Execution with Log.DLL

Detects the execution of rundll32 with 'log.dll' as a command-line argument, indicative of Lotus Blossom Chrysalis backdoor activity and DLL sideloading attempts.

Windows +1 Lotus Blossom rundll32 dll-sideloading lotus-blossom chrysalis-backdoor
2r 1t
medium advisory

Right-to-Left Override (RTLO) Masquerading

Adversaries use the Right-to-Left Override (RTLO) character in filenames to disguise malicious files and trick users into executing them, leading to potential malware infection and system compromise.

Windows defense-evasion masquerading rtlo
3r 2t
medium advisory

Remote Scheduled Task Creation via RPC

The creation of scheduled tasks from a remote source via RPC, where the RpcCallClientLocality and ClientProcessId are 0, indicates potential adversary lateral movement within a Windows environment.

Windows lateral-movement execution
2r 2t
high advisory

Regasm.exe Process Spawning Detection

Detection of regasm.exe spawning a child process, an unusual behavior that may indicate attempts to bypass application control and execute arbitrary code.

Windows living-off-the-land application-control-bypass endpoint
2r 1t
medium advisory

Process Created with a Duplicated Token

This rule identifies the creation of a process impersonating the token of another user logon session on Windows, potentially indicating privilege escalation.

Windows privilege-escalation token-impersonation
2r 2t
medium advisory

Privileged Account Brute Force Detection

Multiple consecutive logon failures targeting admin accounts from the same source IP address within a short timeframe indicates potential brute-force activity targeting privileged accounts on Windows systems.

Windows brute-force credential-access
2r 2t
high advisory

Print.exe Used to Dump Sensitive Files for Credential Access

Attackers are abusing the legitimate Windows Print.exe utility to copy sensitive files like NTDS.DIT and SAM in order to extract credentials, enabling local or remote credential access.

Windows credential-dumping credential-access print.exe
2r 2t
high advisory

PowerShell Token Obfuscation via Process Creation

Adversaries employ token obfuscation techniques within PowerShell commands to evade detection by security tools, leveraging methods such as character insertion, string concatenation, and environment variable manipulation to mask their malicious intent.

Windows defense-evasion token-obfuscation powershell
3r 1t
medium advisory

Potential Persistence via Time Provider Modification

The rule detects potential persistence via modification of the Time Provider in Windows by adversaries who register and enable a malicious DLL as a time provider, allowing for persistent code execution.

Windows persistence privilege-escalation
2r 2t
high advisory

Potential Kerberos Relay Attack via Coerced Authentication against a Computer Account

Detects potential Kerberos relay attacks by identifying coercion attempts followed by authentication events using a target server's computer account, originating from a different host, indicating an attacker has captured and relayed Kerberos authentication material to execute code on behalf of the compromised system.

Windows kerberos relay credential_access
3r 1t 1c
medium advisory

Potential Defense Evasion via WSL Child Processes

Adversaries may attempt to evade detection by executing malicious commands or scripts through child processes spawned from the Windows Subsystem for Linux (WSL), potentially bypassing traditional Windows-based security monitoring.

Windows wsl defense-evasion child-process
2r 2t
high advisory

PingID New MFA Method After Credential Reset

Detection of a new MFA device pairing in PingID shortly after a password reset in Windows Event Logs, potentially indicating a social engineering attack and unauthorized account access.

PingID +2 mfa credential-access
2r 3t
high advisory

Password Spray Attack Detection via 3-Sigma Anomaly

This analytic detects password spraying attacks by identifying an unusual volume of failed authentication attempts from a single source using a 3-sigma deviation from the average, leveraging the Authentication Data Model for broad CIM-mapped event coverage.

Windows password-spraying credential-access
2r 1t
high advisory

NTDS or SAM Database File Copied

Detects copy operations of the Active Directory Domain Database (ntds.dit) or Security Account Manager (SAM) files using command-line tools, potentially leading to credential access.

Windows +1 credential-access ntds sam
2r 2t
medium advisory

LSASS Process Access via Windows API

Detects suspicious access to the LSASS process via Windows API calls, potentially indicating credential dumping and subsequent lateral movement.

Windows credential-access lsass process-access
2r 1t
medium advisory

LSA PPL Protection Setting Modification via CommandLine

Attackers modify LSA PPL protection settings via command-line tools like reg.exe and PowerShell to weaken system security and enable credential dumping.

Windows defense-evasion credential-access
2r 1t
high advisory

Kerberos Ticket Dump via Kirbi File Creation

The creation of .kirbi files on Windows systems indicates potential Kerberos ticket dumping using tools like Mimikatz, preceding Pass-The-Ticket attacks.

Windows +1 credential-access kerberos mimikatz pass-the-ticket
2r 2t
high advisory

Invoke-Obfuscation Obfuscated IEX Invocation via PowerShell

Attackers use Invoke-Obfuscation, a PowerShell obfuscation framework, to generate obfuscated IEX (Invoke-Expression) commands, evading detection and executing malicious code.

Windows defense-evasion execution powershell obfuscation
2r 2t
high advisory

Hidden Local Account Creation via Registry Modification

Attackers may create hidden local accounts, appending a dollar sign ($) to the username, to maintain persistence and evade detection by standard enumeration tools by modifying specific registry keys.

Windows persistence defense-evasion
2r 2t
low advisory

Group Policy Discovery via GPResult Utility

This rule detects the execution of gpresult.exe with specific arguments to query group policy objects, potentially indicating reconnaissance activity by attackers aiming to understand the Active Directory environment for privilege escalation or lateral movement.

Windows +1 discovery gpresult active-directory
2r 1t
medium advisory

GPO Scheduled Task Abuse for Privilege Escalation and Lateral Movement

Attackers abuse Group Policy Objects by modifying scheduled task attributes to execute malicious commands across objects controlled by the GPO, potentially leading to privilege escalation and lateral movement.

Active Directory +1 group-policy scheduled-task privilege-escalation lateral-movement
2r 3t
medium advisory

GPO Modification to Add Startup/Logon Scripts

This rule detects the modification of Group Policy Objects (GPO) to add a startup or logon script to user or computer objects, enabling attackers to achieve privilege escalation and persistence by executing arbitrary commands at scale.

Active Directory +1 group-policy privilege-escalation persistence windows
2r 3t
medium advisory

Excessive Usage of SC Service Utility

Detection of anomalous usage of sc.exe, often abused by ransomware and malware to manipulate services for privilege escalation or disabling security measures.

Windows Observed in multiple ransomware families +1 endpoint sc.exe service_control privilege_escalation defense_evasion ransomware
2r 3t
high threat

Excessive Taskkill Usage for Defense Evasion

Adversaries use excessive calls to `taskkill.exe` (more than 10 times within a minute) to disable security tools or critical processes, evading detection and compromising systems.

Windows Multiple threat actors (Azorult +5 taskkill defense-evasion
2r 1t
medium advisory

Enumeration of Privileged Local Groups Membership

An unusual process is enumerating built-in Windows privileged local groups membership, such as Administrators or Remote Desktop users, potentially revealing targets for credential compromise and post-exploitation activities.

Windows discovery privileged-access
2r 1t
medium advisory

Detection of WMI Temporary Event Subscription Creation

Detection of WMI temporary event subscriptions via Windows Event Logs can identify potential attacker command execution, information gathering, or persistence attempts.

Windows wmi persistence execution
2r 2t
high advisory

Detection of Vulnerable Windows Driver Installation

This analytic detects the installation of known vulnerable Windows drivers, potentially indicating persistence or privilege escalation attempts by threat actors exploiting these drivers for elevated privileges and system compromise.

Windows vulnerable-driver privilege-escalation persistence
2r 1t
high threat

Detection of Processes Launching netsh.exe for Malicious Purposes

Detection of netsh.exe execution by unusual processes indicative of potential malicious activity, including persistence and network configuration changes by threat actors.

exploited Splunk Enterprise +3 netsh living-off-the-land persistence network-configuration
2r
medium advisory

Detection of Obfuscated IP Addresses via Command Line Tools

The use of command-line tools like ping.exe or arp.exe with obfuscated IP addresses (hex, octal, etc.) in the command line can indicate reconnaissance activity or attempts to evade security controls by masking the true destination.

Windows reconnaissance evasion command-line
3r 1t
high advisory

Detection of Important Scheduled Task Deletion or Disablement

Adversaries delete or disable critical scheduled tasks, such as those related to system restore, Windows Defender, BitLocker, Windows Backup, or Windows Update, to disrupt operations and potentially conduct data destructive activities.

Windows attack.execution attack.privilege-escalation attack.persistence attack.t1053.005
2r 1t
high advisory

Detection of Hidden Encoded Executables via Registry Modification

Attackers can hide and execute malicious code by storing it in encoded form within the Windows Registry and then executing it, evading traditional file-based detection mechanisms.

Windows defense-evasion registry-modification encoded-executable
3r 3t
medium advisory

Detecting WMIC Systeminfo Discovery Activity

This brief covers detection of adversaries using Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically the `computersystem` class, a technique used for reconnaissance.

Windows wmic discovery
2r 1t
high advisory

Detecting Windows Screen Capture via PowerShell Script

This analytic detects the execution of a PowerShell script designed to capture screen images on a host, leveraging PowerShell Script Block Logging to identify specific script block text patterns associated with screen capture activities, potentially indicating an attempt to exfiltrate sensitive information via desktop screenshots.

Windows +2 screen-capture powershell exfiltration apt
2r 1t
critical advisory

Detecting Windows Raw Access to Master Boot Record

This analytic detects suspicious raw access reads to the drive containing the Master Boot Record (MBR) using Sysmon EventCode 9, which is a common tactic used by attackers to wipe, encrypt, or overwrite the MBR as part of their impact payload.

Windows raw-disk-access mbr sysmon data-destruction
2r 1t
high advisory

Deletion of Critical Scheduled Tasks

Adversaries delete critical scheduled tasks, such as those related to BitLocker, ExploitGuard, System Restore, Windows Defender, and Windows Update, to disrupt security measures and enable data destruction.

Windows attack.impact attack.t1489
2r 1t
high advisory

CVE-2026-32093 Function Discovery Service Race Condition Privilege Escalation

A race condition vulnerability in the Function Discovery Service (fdwsd.dll), tracked as CVE-2026-32093, allows a locally authorized attacker to escalate privileges on a vulnerable Windows system.

Windows privilege-escalation race-condition
2r 1t 1c
high advisory

CVE-2026-32089 Use-After-Free in Windows Speech Brokered API for Privilege Escalation

CVE-2026-32089 is a use-after-free vulnerability in the Windows Speech Brokered API that allows a local attacker to elevate privileges on a vulnerable system.

Windows cve-2026-32089 privilege-escalation
2r 1t 1c
high advisory

CVE-2026-32086 Function Discovery Service Race Condition Privilege Escalation

CVE-2026-32086 is a race condition vulnerability in the Function Discovery Service (fdwsd.dll) that allows an authorized local attacker to elevate privileges on a Windows system.

Windows cve-2026-32086 privilege-escalation race-condition
2r 1t 1c
high threat

CVE-2026-32083 Windows SSDP Service Race Condition Privilege Escalation

CVE-2026-32083 is a race condition vulnerability in the Windows SSDP Service that allows an authorized local attacker to elevate privileges.

exploited Windows privilege-escalation cve-2026-32083
1r 1t 1c
high advisory

CVE-2026-32074 Double Free in Windows Projected File System

CVE-2026-32074 is a double free vulnerability in the Windows Projected File System that allows a local attacker to elevate privileges.

Windows privilege-escalation cve-2026-32074
2r 1t 1c
high advisory

CVE-2026-26180 Windows Kernel Heap Overflow for Privilege Escalation

CVE-2026-26180 is a heap-based buffer overflow vulnerability in the Windows Kernel that allows an authenticated local attacker to elevate privileges.

Windows privilege-escalation cve-2026-26180
2r 1t 1c 1i
high advisory

Credential Guard Bypass Techniques and Detection Strategies

Offensive techniques such as patching, Pass-the-Challenge, downgrade attacks, and SSP negotiation can bypass Credential Guard, requiring robust detection strategies.

Windows credential-guard bypass security authentication
3r 4t 1i
high advisory

Creation or Modification of Domain Backup DPAPI Private Keys

This rule detects the creation or modification of Domain Backup private keys on Windows systems, which adversaries may extract from a Domain Controller (DC) to decrypt domain user master key files and gain credential access.

Windows +1 credential-access dpapi
2r 3t
high advisory

Command Obfuscation via Unicode Modifier Letters

Adversaries evade string-based detections by replacing ASCII characters with visually similar Unicode modifier letters in command lines, leading to execution of malicious commands.

Windows +1 command-obfuscation defense-evasion
2r 1t
medium advisory

Command Execution via ForFiles Utility for Defense Evasion

Adversaries are leveraging the Windows `forfiles` utility to proxy command execution, potentially bypassing security controls by using a trusted process, for defense evasion.

Windows defense-evasion indirect-command-execution
2r 1t
medium advisory

Code Signing Policy Modification Through Registry

Attackers modify the Windows Registry to disable code signing enforcement, allowing the execution of unsigned or self-signed malicious code.

Windows defense-evasion registry-modification code-signing
2r 2t
low advisory

Clearing Windows Console History for Defense Evasion

Adversaries may clear Windows console history to remove evidence of their activity and evade detection.

Windows defense-evasion console-history
2r 1t
medium advisory

Certreq HTTP POST Abuse for File Transfer

Adversaries may abuse the Windows Certreq utility to download files or upload data to a remote URL by making an HTTP POST request, potentially for command and control, defense evasion, or exfiltration.

Windows lolbin certreq command-and-control defense-evasion exfiltration
2r 4t
medium advisory

BITS Job Notify Command Persistence

Adversaries can abuse the Background Intelligent Transfer Service (BITS) SetNotifyCmdLine method to execute arbitrary commands for persistence by configuring a BITS job to execute a program after a transfer completes or enters a specific state.

Windows persistence bits
2r 1t
high advisory

BCDEdit Failure Recovery Modification

Detection of modifications to Windows error recovery boot configurations using bcdedit.exe, a technique commonly used by ransomware to disable system restoration options.

Windows bcdedit boot-configuration ransomware
2r 1t
high advisory

AMSI Disablement via Registry Modification

Attackers disable the Antimalware Scan Interface (AMSI) by modifying the Windows registry value 'AmsiEnable' to '0x00000000' to evade detection, commonly employed by ransomware, RATs, and APTs.

Windows +3 amsi defense-evasion registry-modification ransomware
2r
high advisory

Windows Proxy Execution of .NET Utilities via Scripts

Detects the execution of .NET utilities by script processes from unusual locations, indicative of signed binary proxy execution for defense evasion and code execution.

Windows proxy-execution net-utility defense-evasion execution signed-binary-proxy-execution
2r 2t
medium advisory

Windows Port Forwarding Rule Addition via Registry Modification

This alert detects the creation of a new port forwarding rule in the Windows Registry, a technique used by attackers to bypass network segmentation and establish internal proxies for command and control or lateral movement.

Windows port-forwarding registry-modification lateral-movement
2r 3t
low advisory

Unusual Process Spawned by a User Detected by Machine Learning

A machine learning job detected a suspicious Windows process, predicted to be malicious by the ProblemChild supervised ML model and found to be unusual within the user's context, potentially indicating defense evasion techniques like masquerading or the use of LOLbins.

Windows endpoint defense evasion machine learning lolbins
2r 2t
medium advisory

Suspicious Outbound Scheduled Task Activity via PowerShell

This rule detects PowerShell loading the Task Scheduler COM DLL followed by an outbound RPC network connection, potentially indicating lateral movement or remote discovery via scheduled tasks.

Windows execution lateral-movement
2r 3t
high advisory

Suspicious Cmd Execution via WMI

Detects suspicious command execution via Windows Management Instrumentation (WMI) on a remote host, identifying cmd.exe processes initiated by WmiPrvSE.exe with arguments indicative of remote command execution, potentially signifying adversary lateral movement.

Windows execution lateral-movement
2r 3t
low advisory

ProblemChild ML Model Detects Unusual Process on Windows Host

The ProblemChild machine learning model detected a rare Windows process indicative of defense evasion, potentially involving LOLbins, on a host not commonly associated with malicious activity.

Windows defense-evasion lolbin machine-learning
2r 1t
high advisory

Potential Svchost Masquerading

This rule detects attempts to masquerade as the Service Host process `svchost.exe` to evade detection and blend in with normal system activity by detecting svchost.exe processes running from non-standard locations.

Windows defense-evasion masquerading
2r 1t
medium advisory

Potential Persistence via Time Provider Modification

Adversaries may establish persistence by registering and enabling a malicious DLL as a time provider by modifying registry keys associated with the W32Time service.

Windows +1 persistence privilege-escalation time-provider
2r 2t
high advisory

Potential Modification of Accessibility Binaries for Persistence and Privilege Escalation

Adversaries can modify accessibility binaries to execute malicious code before user login, establishing persistence and potentially escalating privileges by replacing legitimate accessibility tools with backdoored executables.

Windows persistence privilege-escalation
2r 2t
medium advisory

Potential Application Shimming via Sdbinst

Attackers abuse the Application Shim functionality in Windows by using `sdbinst.exe` with malicious arguments to achieve persistence and execute arbitrary code within legitimate Windows processes.

Windows +1 persistence privilege-escalation application-shimming
2r 2t
medium advisory

Persistence via LSA Security Support Provider Registry Modification

Adversaries may establish persistence by modifying the Windows Security Support Provider (SSP) configuration in the registry, allowing malicious code to load during system startup.

Windows persistence registry
2r 2t
medium advisory

LSASS Loading Suspicious DLL

Detection of LSASS loading an unsigned or untrusted DLL, which can indicate credential access attempts by malicious actors targeting sensitive information stored in the LSASS process.

Windows credential-access lsass dll-injection
2r 2t 9i
high advisory

Executable or Script Creation in Suspicious Paths

This analytic identifies the creation of executables or scripts in suspicious file paths on Windows systems, where adversaries often use these paths to evade detection and maintain persistence, potentially leading to unauthorized code execution, privilege escalation, or persistence within the environment.

Windows defense-evasion persistence privilege-escalation execution
2r 1t
high advisory

Disabling LSA Protection via Registry Modification

Attackers may disable LSA protection by modifying the RunAsPPL registry value in order to access LSASS memory and dump credentials, potentially leading to credential compromise and further lateral movement.

Windows defense-evasion credential-access registry-modification
2r 3t
high advisory

Detection of Unauthorized Windows Hosts File Access

This analytic detects processes attempting to access the Windows hosts file, enabling attackers to redirect traffic to malicious sites or block legitimate security websites by modifying DNS resolution.

Windows hosts-file dns-redirection
2r 1t
medium advisory

Detecting Remote Scheduled Task Creation for Lateral Movement

This rule identifies remote scheduled task creations on a target Windows host, potentially indicating lateral movement by adversaries, by monitoring network connections and registry modifications related to task scheduling.

Elastic Defend +2 lateral-movement execution windows scheduled-task
2r 2t
high advisory

Conhost Proxy Execution for Defense Evasion

Adversaries abuse the Console Window Host (conhost.exe) with the `--headless` argument to proxy command execution, evading detection by blending malicious activity with legitimate Windows software.

Windows defense-evasion proxy-execution conhost
2r 4t
high advisory

Credential Acquisition via Registry Hive Dumping

Attackers may dump the SECURITY and/or SAM hives to obtain credentials stored in the host by using the Windows reg.exe tool.

Windows credential-access registry-dump
2r 2t
high advisory

PowerShell PSReflect Script Detection

This rule detects PowerShell script block content containing PSReflect-style helper indicators, such as Add-Win32Type, New-InMemoryModule, or DllImport patterns, that may support dynamic Win32 API invocation from PowerShell.

PowerShell +1 psreflect windows execution
2r 1t
medium advisory

Remote File Download via Script Interpreter

The rule identifies built-in Windows script interpreters, specifically cscript.exe or wscript.exe, being used to download an executable file from a remote destination, often employed by attackers for initial access or to deploy secondary payloads.

Windows command_and_control execution
2r 2t
medium advisory

Account Password Reset Remotely

The rule detects attempts to reset potentially privileged account passwords remotely, a tactic used by adversaries to maintain access, evade password policies, and preserve compromised credentials.

Windows persistence impact
2r 2t
low advisory

Unusual Source IP for Windows Privileged Operations Detected via ML

A machine learning job detected a user performing privileged operations in Windows from an uncommon source IP, potentially indicating account compromise or privilege escalation.

Windows privileged-access-detection machine-learning
2r 2t
medium advisory

Unusual Process For a Windows Host via Machine Learning

This rule detects rare processes running on Windows hosts, potentially indicating unauthorized services, malware, or persistence mechanisms by using machine learning to identify processes that run infrequently compared to other processes on the same host.

Windows persistence execution
2r 2t
low advisory

Unusual Privilege Type Assigned to User via Machine Learning Anomaly

A machine learning job has identified a user leveraging an uncommon privilege type for privileged operations on Windows systems, potentially indicating privileged access activity and requiring investigation for privilege escalation or account manipulation.

Windows privileged-access privilege-escalation
2r 4t
low advisory

Unusual Host Name for Windows Privileged Operations Detected via ML

A machine learning job has identified a user performing privileged operations in Windows from an uncommon device, indicating potential privileged access activity associated with compromised accounts or insider threats.

Windows privileged-access-detection anomaly-detection
2r 2t
high advisory

Suspicious CSC.exe Parent Process

The Csc.exe (C# compiler) process is being launched by unusual parent processes or from suspicious locations, indicating potential malware execution or defense evasion.

Windows attack.execution attack.defense-evasion csc.exe payload-delivery
3r 3t
medium advisory

Startup Folder Persistence by Suspicious Processes

This rule identifies files written to or modified in the startup folder by commonly abused processes on Windows systems, a technique adversaries use to maintain persistence by automatically executing malicious programs upon user login or system startup.

Windows +2 persistence startup-folder
2r 1t
medium advisory

Remote File Download via Desktopimgdownldr Utility

The rule detects the use of desktopimgdownldr.exe to download remote files, which is an abuse of a signed utility often used as an alternative to certutil for transferring malicious tools or malware into a compromised environment.

Windows command-and-control ingress-tool-transfer
2r 1t
high advisory

Potential Remote Desktop Shadowing Activity

This rule detects potential Remote Desktop Shadowing activity by identifying modifications to the RDP Shadow registry or the execution of processes indicative of an active RDP shadowing session that allows adversaries to spy on or control other user's RDP sessions.

Windows +1 lateral-movement rdp-shadowing
3r 3t
high advisory

Persistence via Hidden Run Key

Adversaries achieve persistence by creating hidden, null-terminated registry keys within common Run key locations, evading standard system utilities.

Windows persistence registry defense-evasion
2r 4t
low advisory

First Time Seen Removable Device Activity

This rule detects the first time a removable device is seen on a Windows host by monitoring registry modification events related to USB devices, aiding in the detection of potential data exfiltration or initial access attempts.

Windows initial-access exfiltration
2r 2t
high threat

Suspicious Script Execution from Temporary Directory

This brief covers a detection for suspicious script execution, such as PowerShell, WScript, or MSHTA, originating from common temporary directories, potentially indicating malware activity.

exploited Windows execution script temp
2r 1t
low advisory

Windows Delayed Execution via Ping Followed by Malicious Utilities

Adversaries may use ping to delay execution of malicious commands, scripts, or binaries to evade detection, often observed during malware installation.

Windows execution defense-evasion ping lolbas
2r 14t
high advisory

WScript or CScript Dropper

The WScript or CScript Dropper technique involves using cscript.exe or wscript.exe to write malicious script files (js, jse, vba, vbe, vbs, wsf, wsh) to suspicious locations on a Windows system for later execution.

Windows script-dropper file-creation
2r 2t
medium advisory

Windows WMI Reconnaissance Activity Detection

Detection of Windows Management Instrumentation Command-line (WMIC) usage for reconnaissance by querying common Win32 WMI classes for system information, potentially indicating post-exploitation activity.

Windows wmic reconnaissance post-exploitation
2r 1t
high threat

Windows Time-Based Evasion via Ping Delay

This analytic detects potentially malicious processes initiating a ping delay using an invalid IP address, a tactic used by malware like NJRAT to evade detection by delaying actions.

Windows NJRAT time-based-evasion
2r 1t
medium advisory

Windows Temporarily Scheduled Task Creation and Deletion

Detection of rapid creation and deletion of scheduled tasks on Windows, indicating potential malicious activity abusing the task scheduler for execution and cleanup.

Windows persistence execution
2r 2t
high advisory

Windows Service Creation via Registry Modification

Detection of registry modifications to create Windows services, a common persistence technique used by attackers to maintain access, escalate privileges, or move laterally within a network.

Windows persistence privilege-escalation
2r 1t
low advisory

Windows Scheduled Task Creation for Persistence

Adversaries may create scheduled tasks on Windows systems to establish persistence, move laterally, or escalate privileges, and this detection identifies such activity by monitoring Windows event logs for scheduled task creation events, excluding known benign tasks and those created by system accounts.

OneDrive +5 persistence scheduled-task windows
3r 1t
low advisory

Windows Event Logs Cleared

Attackers attempt to clear Windows event logs to evade detection and remove forensic evidence of their activities.

Windows defense-evasion
2r 1t
medium advisory

Windows Credential Manager Abuse via VaultCmd

Adversaries may abuse VaultCmd to list or dump credentials stored in the Windows Credential Manager to obtain saved usernames and passwords, potentially for lateral movement.

Windows credential-access vaultcmd
2r 2t
medium advisory

Wbadmin Backup Catalog Deletion

Adversaries may delete Windows backup catalogs using wbadmin.exe to inhibit system recovery, often as part of ransomware or other destructive attacks.

Windows impact backup-deletion ransomware
2r 2t
medium advisory

Unusual Service Host Child Process - Childless Service

The rule identifies unusual child processes of Service Host (svchost.exe) instances hosting services that do not traditionally spawn child processes, potentially indicating code injection or exploitation leading to privilege escalation and defense evasion.

Windows process-injection privilege-escalation defense-evasion
2r 2t
medium advisory

Unusual Process Execution via Alternate Data Streams

Adversaries may use Alternate Data Streams (ADS) to hide malicious executables and execute them, evading traditional detection methods by concealing the file's true nature.

Windows defense-evasion malware
2r 1t
medium advisory

Unusual Parent Process for cmd.exe

Atypical parent processes spawning cmd.exe indicate potential malicious command execution on Windows systems, where adversaries leverage cmd.exe from unusual parent processes to execute malicious commands stealthily.

Windows execution process-tree
1r 1t
high advisory

Unusual File Creation via Alternate Data Streams

Detection of suspicious creation of Alternate Data Streams (ADS) on targeted files using command interpreters indicates potential malware hiding or defense evasion.

Windows defense-evasion alternate-data-stream
2r 1t
high advisory

Unusual Executable File Creation by System Critical Process

This rule detects the creation or modification of executable files by Windows system-critical processes, potentially indicating remote code execution or other forms of exploitation for defense evasion, execution, or privilege escalation.

Windows defense-evasion execution privilege-escalation
2r 3t
high advisory

Unusual Child Process from System Virtual Process Indicates Process Injection

The rule detects suspicious child processes of the Windows System process (PID 4), excluding legitimate processes, potentially indicating code injection used for defense evasion.

Windows defense-evasion process-injection
2r 1t
high advisory

UAC Bypass via ICMLuaUtil Elevated COM Interface

Attackers attempt to bypass User Account Control (UAC) to stealthily execute code with elevated permissions by abusing the ICMLuaUtil Elevated COM interface, spawning processes from dllhost.exe with specific arguments.

Windows privilege-escalation uac-bypass
2r 3t
medium advisory

Suspicious Remote Registry Access via SeBackupPrivilege

Detection of remote registry access by an account with SeBackupPrivilege, potentially indicating credential exfiltration attempts via SAM registry hive dumping.

Windows credential-access lateral-movement
2r 3t
high advisory

Suspicious Remote Process Instantiation via WMI

Detection of wmic.exe execution with parameters indicative of spawning a process on a remote system, a technique often used for lateral movement and remote code execution.

Windows wmi lateral-movement remote-execution
2r 1t
high advisory

Suspicious Microsoft HTML Application Child Process

Mshta.exe spawning a suspicious child process, such as cmd.exe or powershell.exe, indicates potential adversarial activity leveraging Mshta to execute malicious scripts and evade detection on Windows systems.

Windows +2 defense-evasion mshta process-creation
2r 1t
high advisory

Suspicious Executable or Script Creation in Uncommon Paths

Detection of executables or scripts being created in unusual directories on Windows systems, which can be indicative of malware installation or persistence attempts.

Windows file-creation persistence
3r 1t
medium advisory

Suspicious Enumeration Commands Spawned via WMIPrvSE

This rule identifies suspicious activity where enumeration commands are spawned via the Windows Management Instrumentation Provider Service (WMIPrvSE) to gather system and network information.

Windows enumeration wmi reconnaissance
2r 13t
high advisory

Remcos RAT Activity Detection

This brief outlines detection strategies for Remcos RAT activity, focusing on file and registry artifacts indicative of installation, persistence, and cleanup on compromised Windows systems.

Windows remcos rat malware
3r 3t
medium advisory

PowerShell Script Block Logging Disabled via Registry Modification

Attackers may disable PowerShell Script Block Logging by modifying the registry to evade detection and conceal their activities on the host, detected by monitoring changes to the `EnableScriptBlockLogging` registry value.

PowerShell +1 defense-evasion windows
2r 2t
high advisory

PowerShell Keylogging Script Detection

This brief documents a high-severity threat involving PowerShell scripts used for keylogging on Windows systems to capture credentials and sensitive user input.

Windows +1 keylogger powershell collection
2r 1t
high advisory

Potential Credential Access via Renamed COM+ Services DLL

Detection of renamed COMSVCS.DLL being loaded by rundll32.exe, potentially used to dump LSASS memory for credential access while evading command-line detection.

Windows credential-access defense-evasion
2r 3t 1i
high advisory

Potential Credential Access via MSBuild Loading Credential Management DLLs

The detection rule identifies a potential credential access attempt via the trusted developer utility MSBuild by detecting instances where it loads DLLs associated with Windows credential management, specifically vaultcli.dll or SAMLib.DLL, which is often used for credential dumping.

MSBuild +2 credential-access defense-evasion windows
2r 1t
medium advisory

Msiexec Arbitrary DLL Execution

Adversaries may abuse the msiexec.exe utility to proxy the execution of malicious DLL payloads, bypassing application control and other defenses.

Windows defense-evasion proxy-execution msiexec
2r 1t
high advisory

MSHTA Executing Inline HTA Script

Detection of mshta.exe executing with inline script protocols like JavaScript or VBScript, often used for malicious script execution and defense evasion.

Windows mshta fileless defense-evasion
2r 1t
medium advisory

MSBuild Started by System Process

Detects instances of MSBuild, the Microsoft Build Engine, started by Explorer or the WMI (Windows Management Instrumentation) subsystem, which is unusual and often used by malicious payloads to evade defenses.

Windows defense-evasion execution
2r 2t
high advisory

Modification of WDigest Security Provider

The rule detects attempts to modify the WDigest security provider in the registry to force the user's password to be stored in clear text in memory, which could lead to credential dumping.

Windows +2 credential-access registry-modification
2r 1t
high advisory

Microsoft Diagnostics Troubleshooting Wizard (MSDT) Proxy Execution Abuse

The Microsoft Diagnostics Troubleshooting Wizard (MSDT) can be abused to proxy malicious command or binary execution via malicious process arguments, potentially leading to defense evasion and arbitrary code execution.

Microsoft Diagnostics Troubleshooting Wizard +1 defense-evasion proxy-execution msdt
2r 3t 1c
medium advisory

LSASS Shtinkering Detection via Full User-Mode Dump Configuration

Detection of the enabling of full user-mode dumps system-wide, a setting change leveraged in LSASS Shtinkering attacks to dump LSASS process memory and steal credentials.

Windows credential-access lsass registry
2r 2t
high advisory

Lateral Movement via Startup Folder File Creation

Adversaries may move laterally by dropping malicious scripts or executables into a remote system's startup folder via RDP or SMB, enabling execution upon reboot or user logon.

Windows lateral-movement persistence
2r 4t
medium advisory

Lanman NullSessionPipe Registry Modification for Lateral Movement

Adversaries may modify the NullSessionPipe registry key to enable anonymous access to named pipes, facilitating lateral movement and defense evasion by allowing unauthorized access to network resources.

Windows lateral-movement defense-evasion
2r 2t
medium advisory

Image File Execution Options (IFEO) Injection for Persistence and Defense Evasion

Adversaries abuse Image File Execution Options (IFEO) in the Windows Registry by modifying Debugger or MonitorProcess keys to intercept legitimate file executions, enabling persistence and defense evasion.

Windows persistence defense-evasion registry
2r 3t
medium advisory

Disable Windows Event and Security Logs Using Built-in Tools

Attackers may attempt to disable Windows event logging to evade detection by using built-in tools like logman, PowerShell, and auditpol.

Windows defense-evasion eventlog
3r 3t
medium advisory

Detection of WMIC System Information Discovery

Adversaries may use Windows Management Instrumentation Command-line (WMIC) to gather system information, specifically using the `computersystem` alias to retrieve details about the system's configuration, which aids in reconnaissance.

Windows discovery wmic
2r 1t
medium advisory

Detection of System Information Discovery Techniques

This brief covers the detection of adversaries using native Windows commands like `wmic qfe`, `systeminfo`, and `hostname` to gather system information for further exploitation.

Windows system-discovery post-exploitation
1r 1t
high advisory

CVE-2026-27923 Use-After-Free in Desktop Window Manager

A use-after-free vulnerability, CVE-2026-27923, in the Desktop Window Manager allows an authorized attacker with local access to escalate privileges.

Windows use-after-free privilege-escalation
2r 1t 1c 1i
low advisory

Component Object Model (COM) Hijacking via Registry Modification

This rule detects Component Object Model (COM) hijacking via registry modification, where adversaries establish persistence by executing malicious content triggered by hijacked references to COM objects.

Windows persistence defense-evasion privilege-escalation com-hijacking
2r 4t
medium advisory

BITS Transfer Job With Uncommon or Suspicious Remote TLD

Adversaries abuse Background Intelligent Transfer Service (BITS) to download malicious payloads from unusual top-level domains, bypassing traditional security measures and establishing persistence on compromised systems.

Windows attack.defense-evasion attack.persistence attack.t1197
2r 2t
medium advisory

AppInit DLL Registry Persistence Detected

Modification of the AppInit DLLs registry keys can be used for persistence and defense evasion on Windows systems.

Windows persistence defense-evasion
2r 2t
medium advisory

Windows Update Client DLL Loading Abuse

Adversaries abuse the Windows Update Auto Update Client (wuauclt.exe) to load arbitrary DLLs from user-writable locations, achieving defense evasion and execution of malicious code.

Windows defense-evasion execution lolbas
2r 2t
medium advisory

Windows Privilege Escalation via Secondary Logon Service

The rule identifies process creation with alternate credentials, which can be used for privilege escalation, by detecting successful logins via the Secondary Logon service (seclogon) from a local source IP address (::1), followed by process creation using the same TargetLogonId.

Windows privilege-escalation access-token-manipulation
2r 2t
medium advisory

Suspicious CertUtil Commands for Defense Evasion and Lateral Movement

This rule detects suspicious use of certutil.exe, a native Windows utility often abused by attackers for downloading/deobfuscating malware and exfiltrating data, by identifying commands involving decoding, encoding, URL caching, CTL verification, and PFX exporting, which are frequently used for command and control and defense evasion.

Windows defense-evasion command-and-control credential-access certutil
2r 3t
medium advisory

Remote Execution via File Shares

This rule identifies potential lateral movement via network file shares by detecting the execution of a file that was created by the virtual system process.

Windows lateral-movement file-share
2r 1t
high advisory

PowerShell Obfuscation via Backtick-Escaped Variable Expansion

PowerShell scripts use backtick-escaped characters inside `${}` variable expansion to reconstruct strings at runtime, enabling attackers to split keywords, hide commands, and evade static analysis and AMSI.

windows +1 powershell obfuscation defense-evasion variable-expansion
2r 1t
medium advisory

Potential Exploitation of Unquoted Service Path Vulnerability

This rule detects potential exploitation of unquoted service paths on Windows systems, which can lead to privilege escalation by identifying suspicious processes starting from common unquoted paths, indicating a potential attempt to execute malicious code.

Windows privilege-escalation unquoted-service-path
2r 1t
medium advisory

Execution of COM object via Xwizard

Adversaries can abuse the legitimate system binary Xwizard to execute Component Object Model (COM) objects, evading defensive countermeasures by running COM objects created in the registry.

Windows execution defense-evasion com xwizard
2r 2t
medium advisory

Execution from Unusual Directory - Command Line

Adversaries may execute commands and scripts from unusual Windows directories to masquerade malware and evade detection, impacting system integrity and security operations.

Windows execution defense-evasion
2r 3t
low advisory

Adding Hidden File Attribute via Attrib.exe

Adversaries can use attrib.exe to add the 'hidden' attribute to files and directories to evade detection and persist on a system by hiding artifacts.

Windows defense-evasion persistence
2r 2t
high advisory

Potential Fake CAPTCHA Phishing Attack via Malicious Copy/Paste

Attackers compromise websites, inject malicious code posing as fake CAPTCHAs, and trick users into copying and pasting malicious commands into the Windows Run dialog box, leading to the execution of PowerShell, Cmd, or MSHTA.

Windows +3 phishing social-engineering malware
2r 5t