Skip to content
Threat Feed

Tag

Sysmon

7 briefs RSS
medium advisory

Detection of Sysmon Configuration Updates for Defense Evasion

This brief describes how to detect an attacker updating or replacing the Sysmon configuration with a bare bones one to avoid monitoring without completely shutting down the service, leveraging Sysmon's `-c` command-line option for defense impairment.

Sysmon windows defense-evasion defense-impairment
1r
high advisory

Threat Brief: Detection of Sysinternals Sysmon Uninstallation

This brief describes the detection of attackers uninstalling Sysinternals Sysmon, a critical endpoint monitoring tool, as a defense evasion technique to obscure malicious activities and maintain stealth.

Sysinternals Sysmon defense-evasion endpoint-security sysmon windows
1r 1t
high advisory

Detecting Windows Remote Image Loading for Malicious Activities

This analytic detects instances where a process loads a file from a remote share path, potentially indicating execution, defense evasion, or lateral movement by attackers loading code from attacker-controlled infrastructure.

Windows +3 remote-image-load defense-evasion lateral-movement sysmon
2r 5t
high advisory

Windows Data Destruction via Recursive Executable File Deletion

A suspicious process recursively deleting executable files (e.g., .exe, .sys, .dll) indicates potential data destruction activity, detected via high-volume file deletion/overwrite events associated with destructive malware families like CaddyWiper and SwiftSlicer.

Windows data-destruction wiper sysmon
2r 1t
medium advisory

Detection of Windows RMM Tool Execution

Detects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.

AnyDesk +28 rmm remote-access sysmon
3r 1t
critical advisory

Detecting Windows Raw Access to Master Boot Record

This analytic detects suspicious raw access reads to the drive containing the Master Boot Record (MBR) using Sysmon EventCode 9, which is a common tactic used by attackers to wipe, encrypt, or overwrite the MBR as part of their impact payload.

Windows raw-disk-access mbr sysmon data-destruction
2r 1t
high threat

Bitdefender Submission Wizard DLL Sideloading

Detection of potential DLL side-loading of Bitdefender Submission Wizard (BDSubmit.exe, bdsw.exe, or renamed BluetoothService.exe) via loading a malicious log.dll from a non-standard path.

Bitdefender Submission Wizard Lotus Blossom dll-sideloading persistence privilege-escalation lotus-blossom sysmon
2r 2t