Tag
high
advisory
Potential File Download via a Headless Browser
2 rules 1 TTPDetects the execution of headless browsers from suspicious parent processes with arguments indicative of scripted retrieval, bypassing application control policies and restrictions on direct download tools.
command-and-control
headless-browser
file-download
windows
2r
1t
medium
advisory
Remote File Download via PowerShell
2 rules 2 TTPsDetects PowerShell being used to download executable files from untrusted remote destinations, a common technique for attackers to introduce tooling or malware into a compromised environment.
PowerShell
command-and-control
file-download
windows
2r
2t
medium
advisory
Remote File Download via Desktopimgdownldr Utility
3 rules 1 TTPThe desktopimgdownldr utility can be abused to download remote files, potentially bypassing standard download restrictions and acting as an alternative to certutil for malware or tool deployment.
Microsoft Defender XDR +1
command-and-control
file-download
windows
desktopimgdownldr
3r
1t