Tag
high
advisory
Suspicious JavaScript Execution Via Mshta.EXE
1 rule 1 TTPDetection of attackers using the Windows mshta.exe utility to execute malicious JavaScript code for living-off-the-land stealth execution.
living-off-the-land
stealth
windows
process-execution
1r
1t
medium
advisory
Detection of Sysinternals PsService Execution
1 rule 3 TTPsThis brief details the detection of Sysinternals PsService, a legitimate utility that can be abused by threat actors for service reconnaissance, manipulation, and persistence on Windows systems, potentially leading to privilege escalation or system disruption.
Sysinternals PsService
sysinternals
process-execution
service-manipulation
windows
1r
3t
medium
advisory
Execution from Unusual Directory - Command Line
2 rules 2 TTPsThis rule identifies process execution from suspicious default Windows directories, which adversaries may abuse to hide malware in trusted paths to evade defenses.
Microsoft Defender XDR +1
execution
defense-evasion
windows
process-execution
2r
2t