Skip to content
Threat Feed

Tag

Windows-Security

8 briefs RSS
medium advisory

Suspicious wevtutil.exe Usage for Event Log Clearing

Attackers frequently abuse the built-in 'wevtutil.exe' utility to clear Windows event logs, a common defense evasion technique used to disrupt forensic investigations and hide post-compromise activity.

defense-evasion log-manipulation windows-security
1r 1t
high advisory

Detection of Suspicious File Writes by Core Windows Processes

Detection of suspicious file creation events where critical Windows system binaries write files with potentially malicious extensions, indicating potential process masquerading or system compromise.

stealth persistence detection-engineering windows-security
1r 1t
medium advisory

Suspicious Firewall Modification via WMI Provider Host

Detection of unauthorized Windows Firewall rule additions performed by the WMI Provider Host process, a technique associated with defense impairment by ransomware actors.

defense-impairment ransomware windows-security firewall
1r
medium threat

Detection of WinAPI Function Calls via Command Line Interface

Adversaries are leveraging tools like winapiexec to execute Windows API functions directly from the command line to bypass traditional binary-based detection methods.

exploited execution detection-engineering windows-security
1r 1t
high advisory

Abuse of Esentutl.exe for Sensitive Credential File Extraction

Adversaries are leveraging the legitimate Windows binary 'esentutl.exe' to bypass file locks and perform unauthorized copies of system credential databases such as NTDS.dit and SAM.

credential-access lotl windows-security
1r 1t
medium advisory

Detection of Shadow Copy Creation via System Utilities

Adversaries frequently abuse native Windows utilities like vssadmin and wmic to create volume shadow copies, a precursor to offline credential theft via NTDS.dit extraction.

credential-access windows-security living-off-the-land
1r 2t
high advisory

Abuse of PowerShell Disable-WindowsOptionalFeature for Defense Impairment

Adversaries leverage the Disable-WindowsOptionalFeature PowerShell cmdlet to disable security features like Windows Defender, facilitating defense impairment and persistence.

defense-impairment powershell windows-security
1r 1t
medium advisory

AppLocker Audit Events Indicate Potential Policy Violations

This brief describes the detection of Windows AppLocker audit events (Event IDs 8003, 8006, 8021, 8024) that indicate applications, DLLs, scripts, MSIs, or packaged apps would have been blocked by an active AppLocker policy, providing insight into unauthorized software execution attempts or policy violations in audit mode.

AppLocker audit windows-security application-control
1r 6t