Tag
high
advisory
Detection of Data Exfiltration via Native Windows Command-Line Utilities
1 rule 1 TTPAdversaries are leveraging legitimate Windows command-line tools such as PowerShell, curl, and wget to collect system information and exfiltrate data via HTTP POST requests.
data-exfiltration
command-line
living-off-the-land
1r
1t
high
advisory
Long Base64 Encoded Command via Scripting Interpreter
2 rules 5 TTPsDetection of oversized command lines used by Python, PowerShell, Node.js, or Deno interpreters containing base64 decoding or encoded-command patterns, indicating potential evasion and malicious execution.
Elastic Endpoint
defense-evasion
execution
scripting-interpreter
base64
command-line
2r
5t
medium
advisory
Detection of Obfuscated IP Addresses via Command Line Tools
3 rules 1 TTPThe use of command-line tools like ping.exe or arp.exe with obfuscated IP addresses (hex, octal, etc.) in the command line can indicate reconnaissance activity or attempts to evade security controls by masking the true destination.
Windows
reconnaissance
evasion
command-line
3r
1t