Skip to content
Threat Feed

Tag

Sysmon

10 briefs RSS
low advisory

Detection Capability for Executable File Creation via Sysmon

This brief details a detection capability for monitoring the creation of Portable Executable files using Sysmon Event ID 29 to identify unauthorized binary drops.

windows sysmon detection-engineering defensive-telemetry
1r
medium advisory

RemCom Administrative Tool Named Pipe Usage

Detection of the default named pipe used by the RemCom remote administration tool, which is frequently leveraged by attackers for lateral movement and remote command execution.

lateral-movement execution remcom sysmon
1r 2t
medium advisory

Detection of Timestomping on Windows Executables

Detection and mitigation guidance for identifying timestomping activity where adversaries modify creation timestamps of executable files in sensitive system directories to evade detection.

defense-evasion windows sysmon
1r 1t
medium advisory

Detection of Sysmon Configuration Updates for Defense Evasion

This brief describes how to detect an attacker updating or replacing the Sysmon configuration with a bare bones one to avoid monitoring without completely shutting down the service, leveraging Sysmon's `-c` command-line option for defense impairment.

Sysmon windows defense-evasion defense-impairment
1r
high advisory

Threat Brief: Detection of Sysinternals Sysmon Uninstallation

This brief describes the detection of attackers uninstalling Sysinternals Sysmon, a critical endpoint monitoring tool, as a defense evasion technique to obscure malicious activities and maintain stealth.

Sysinternals Sysmon defense-evasion endpoint-security sysmon windows
1r 1t
high advisory

Detecting Windows Remote Image Loading for Malicious Activities

This analytic detects instances where a process loads a file from a remote share path, potentially indicating execution, defense evasion, or lateral movement by attackers loading code from attacker-controlled infrastructure.

Windows +3 remote-image-load defense-evasion lateral-movement sysmon
2r 5t
high advisory

Windows Data Destruction via Recursive Executable File Deletion

A suspicious process recursively deleting executable files (e.g., .exe, .sys, .dll) indicates potential data destruction activity, detected via high-volume file deletion/overwrite events associated with destructive malware families like CaddyWiper and SwiftSlicer.

Windows data-destruction wiper sysmon
2r 1t
medium advisory

Detection of Windows RMM Tool Execution

Detects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.

AnyDesk +28 rmm remote-access sysmon
3r 1t
critical advisory

Detecting Windows Raw Access to Master Boot Record

This analytic detects suspicious raw access reads to the drive containing the Master Boot Record (MBR) using Sysmon EventCode 9, which is a common tactic used by attackers to wipe, encrypt, or overwrite the MBR as part of their impact payload.

Windows raw-disk-access mbr sysmon data-destruction
2r 1t
high threat

Bitdefender Submission Wizard DLL Sideloading

Detection of potential DLL side-loading of Bitdefender Submission Wizard (BDSubmit.exe, bdsw.exe, or renamed BluetoothService.exe) via loading a malicious log.dll from a non-standard path.

Bitdefender Submission Wizard Lotus Blossom dll-sideloading persistence privilege-escalation lotus-blossom sysmon
2r 2t