Tag
Execution of File Written or Modified by Microsoft Office
3 rules 3 TTPsThis rule detects the creation and execution of executable files by Microsoft Office applications, which is often associated with malicious documents containing scripts or exploitation of Microsoft Office vulnerabilities, leading to the execution of arbitrary code.
Windows .Key File Creation in Root Directory
2 rules 1 TTPThis search detects the creation of a .key file in the root directory of the system drive, an activity associated with ransomware execution before file encryption.
Detects Windows XLL File Creation Outside of Typical Location
2 rules 2 TTPsThe creation of an XLL file outside of typical locations can indicate an attempt to abuse Excel COM objects to load and execute a malicious XLL payload, often used in spearphishing attacks to achieve remote code execution.
Adobe RdrCEF.exe Hijack for Persistence
2 rules 2 TTPsAttackers can maintain persistence by replacing the legitimate RdrCEF.exe executable with a malicious one, which is executed every time Adobe Acrobat Reader is launched.