Skip to content
Threat Feed

Product

Winlogbeat

7 briefs RSS
low advisory

User Detected with Suspicious Windows Process(es)

A machine learning job combination has identified a user with one or more suspicious Windows processes exhibiting unusually high malicious probability scores, potentially involving LOLbins for defense evasion.

Elastic Defend +3 Domain: Endpoint OS: Windows Use Case: Living off the Land Attack Detection Rule Type: ML Rule Type: Machine Learning Tactic: Defense Evasion Resources: Investigation Guide defense-evasion
2r 2t
low advisory

Suspicious Windows Process Cluster Detected from Parent Process

A machine learning job has identified a parent process spawning one or more suspicious Windows processes exhibiting unusually high malicious probability scores, indicating potential defense evasion tactics like masquerading and LOLBins usage.

Elastic Endpoint +2 defense-evasion windows ml lolbins
2r 2t
low advisory

Host Detected with Suspicious Windows Process(es)

A machine learning job combination has identified a host with one or more suspicious Windows processes that exhibit unusually high malicious probability scores, indicating potential masquerading tactics for defense evasion.

Elastic Defend +1 Use Case: Living off the Land Attack Detection Rule Type: ML Rule Type: Machine Learning Tactic: Defense Evasion Resources: Investigation Guide defense-evasion windows
2r 2t
low advisory

Unusual Process Spawned by a User Detected via Machine Learning

A machine learning job has detected a suspicious Windows process, predicted to be malicious by the ProblemChild supervised ML model and found to be suspicious given its user context by an unsupervised ML model, indicating potential defense evasion activity involving LOLbins.

Elastic Defend +1 defense-evasion machine-learning windows lolbin
2r 2t
low advisory

Unusual Process Spawned by a Parent Process via Machine Learning

This rule detects unusual process spawned by a parent process, potentially indicating malicious activity involving LOLbins by leveraging machine learning to identify anomalous process creation patterns that evade conventional search rules.

Elastic Defend +1 defense-evasion lolbin machine-learning windows
2r 2t
low advisory

Unusual Process Spawned by a Host via Machine Learning

A machine learning job detects unusual Windows processes, potentially Living off the Land binaries, on hosts not commonly associated with malicious activity, indicating possible defense evasion attempts.

Elastic Defend +1 defense-evasion lolbins machine learning windows
2r 1t
medium advisory

Persistence via WMI Event Subscription

Adversaries can leverage Windows Management Instrumentation (WMI) to establish persistence by creating event subscriptions that trigger malicious code execution when specific events occur, using tools like wmic.exe to create event consumers.

Microsoft Defender XDR +7 persistence execution windows wmi
2r 2t