Tag
Suspicious wevtutil.exe Usage for Event Log Clearing
1 rule 1 TTPAttackers frequently abuse the built-in 'wevtutil.exe' utility to clear Windows event logs, a common defense evasion technique used to disrupt forensic investigations and hide post-compromise activity.
Detection of Suspicious File Writes by Core Windows Processes
1 rule 1 TTPDetection of suspicious file creation events where critical Windows system binaries write files with potentially malicious extensions, indicating potential process masquerading or system compromise.
Suspicious Firewall Modification via WMI Provider Host
1 ruleDetection of unauthorized Windows Firewall rule additions performed by the WMI Provider Host process, a technique associated with defense impairment by ransomware actors.
Detection of WinAPI Function Calls via Command Line Interface
1 rule 1 TTPAdversaries are leveraging tools like winapiexec to execute Windows API functions directly from the command line to bypass traditional binary-based detection methods.
Abuse of Esentutl.exe for Sensitive Credential File Extraction
1 rule 1 TTPAdversaries are leveraging the legitimate Windows binary 'esentutl.exe' to bypass file locks and perform unauthorized copies of system credential databases such as NTDS.dit and SAM.
Detection of Shadow Copy Creation via System Utilities
1 rule 2 TTPsAdversaries frequently abuse native Windows utilities like vssadmin and wmic to create volume shadow copies, a precursor to offline credential theft via NTDS.dit extraction.
Abuse of PowerShell Disable-WindowsOptionalFeature for Defense Impairment
1 rule 1 TTPAdversaries leverage the Disable-WindowsOptionalFeature PowerShell cmdlet to disable security features like Windows Defender, facilitating defense impairment and persistence.
AppLocker Audit Events Indicate Potential Policy Violations
1 rule 6 TTPsThis brief describes the detection of Windows AppLocker audit events (Event IDs 8003, 8006, 8021, 8024) that indicate applications, DLLs, scripts, MSIs, or packaged apps would have been blocked by an active AppLocker policy, providing insight into unauthorized software execution attempts or policy violations in audit mode.