Tag
high
threat
Malicious Termination of Browser Processes via Taskkill
2 rules 1 TTPThe use of taskkill to forcibly terminate browser processes such as Chrome, Firefox, and Edge, often associated with credential-stealing malware like Braodo stealer, is detected, allowing it to unlock and steal sensitive browser data.
Chrome +5
Braodo Stealer
credential-theft
taskkill
braodo-stealer
windows
2r
1t
high
threat
Braodo Stealer Screen Capture in TEMP Directory
2 rules 1 TTPThis analytic detects the creation of screen capture files in the TEMP directory, specifically targeting activity associated with the Braodo stealer malware, which captures screenshots of the victim's desktop as part of its data theft activities.
Splunk Enterprise +2
Braodo Stealer
stealc-stealer
crypto-stealer
braodo-stealer
apt37
hellcat-ransomware
vip-keylogger
screen-capture
malware
2r
1t