Tag
File Creation in World-Writable Directory by Unusual Process
2 rules 1 TTPThis rule detects the creation of files in world-writable directories on Linux systems by an unusual process, which is a common defense evasion tactic for potential lateral movement or malicious payload staging.
Suspicious File Creation via Print Spooler Service
2 rules 1 TTPThe Print Spooler service is being abused to create suspicious files, potentially leading to privilege escalation.
Suspicious File Creation via OpenEDR ITSMService
3 rules 4 TTPsOpenEDR's ITSMService process, used for remote management, is being abused to create suspicious files on compromised systems, potentially leading to unauthorized file uploads, data staging, or malicious file deployment.
Potential Lateral Tool Transfer via SMB Share
3 rules 2 TTPsThis rule identifies the creation or change of a Windows executable file over network shares (SMB), indicating adversaries may transfer tools or other files between systems in a compromised environment.
System Process Executables Created in Unusual Locations
3 rules 1 TTPThe creation of executable files masquerading as legitimate Windows system processes in non-standard directories indicates potential malware installation or defense evasion tactics by threat actors.
Executable or Script Creation in Temporary Paths
2 rules 1 TTPAdversaries may create executables or scripts in temporary directories to evade detection, maintain persistence, and execute unauthorized code on Windows systems.
WScript or CScript Dropper
2 rules 2 TTPsThe WScript or CScript Dropper technique involves using cscript.exe or wscript.exe to write malicious script files (js, jse, vba, vbe, vbs, wsf, wsh) to suspicious locations on a Windows system for later execution.
Suspicious Executable or Script Creation in Uncommon Paths
3 rules 1 TTPDetection of executables or scripts being created in unusual directories on Windows systems, which can be indicative of malware installation or persistence attempts.