Skip to content
Threat Feed

Tag

LOLbins

8 briefs RSS
low advisory

Parent Process Detected with Suspicious Windows Process(es)

Elastic's machine learning models detect clusters of suspicious Windows processes that share a common parent process and exhibit unusually high malicious probability scores, aiming to uncover stealthy attacks, including those leveraging Living off the Land Binaries (LOLBins) and masquerading techniques, which might otherwise evade traditional detection methods.

endpoint windows machine-learning defense-evasion lolbins masquerading investigation-guide
2t
low advisory

Host Detected with Suspicious Windows Processes via Machine Learning

Elastic's machine learning job, utilizing the ProblemChild supervised model and unsupervised techniques, detects Windows hosts exhibiting clusters of suspicious processes with unusually high malicious probability scores, often indicative of defense evasion through Living Off The Land Binaries (LOLbins) and masquerading techniques.

Elastic Defend +6 defense-evasion masquerading lolbins machine-learning windows ml-detection endpoint-security
2t
high advisory

Stealthy KongTuke C2 Discovered via Multi-Domain Threat Hunting

Unspecified adversaries are using a Traffic Direction System (TDS) redirect for initial access, followed by encoded PowerShell execution to download payloads like `script.ps1` into the `ApplicationData` directory, and establishing command-and-control (C2) communication via `curl.exe` to suspicious IP addresses such as `144.31.221.82` with defense evasion techniques like post-execution cleanup, designed to operate below traditional detection thresholds.

command-and-control defense-evasion execution powershell lolbins threat-hunting
3r 8t 2i
low advisory

Suspicious Windows Process Cluster Detected from Parent Process

A machine learning job has identified a parent process spawning one or more suspicious Windows processes exhibiting unusually high malicious probability scores, indicating potential defense evasion tactics like masquerading and LOLBins usage.

Elastic Endpoint +2 defense-evasion windows ml lolbins
2r 2t
low advisory

Unusual Process Spawned by a Host via Machine Learning

A machine learning job detects unusual Windows processes, potentially Living off the Land binaries, on hosts not commonly associated with malicious activity, indicating possible defense evasion attempts.

Elastic Defend +1 defense-evasion lolbins machine learning windows
2r 1t
low advisory

Unusual Process Spawned by a Parent Process via Machine Learning

A machine learning job detected a suspicious Windows process, predicted malicious by the ProblemChild model and flagged as an unusual child process name for its parent, potentially indicating LOLbins usage and evading traditional detection.

defense-evasion lolbins windows machine-learning
2r 2t
low advisory

Suspicious Windows Process Cluster Detection via Machine Learning

A machine learning job combination has identified a host with one or more suspicious Windows processes that exhibit unusually high malicious probability scores, potentially indicating masquerading and defense evasion tactics.

Windows defense-evasion masquerading LOLbins
2r 2t
low advisory

Unusual Process Spawned by a User Detected by Machine Learning

A machine learning job detected a suspicious Windows process, predicted to be malicious by the ProblemChild supervised ML model and found to be unusual within the user's context, potentially indicating defense evasion techniques like masquerading or the use of LOLbins.

Windows endpoint defense evasion machine learning lolbins
2r 2t