Tag
Toy Ghouls Deploying Custom HiveMQ and Matrix-Based Backdoors
1 rule 3 TTPs 1 IOCThe threat actor Toy Ghouls is using WinRM to deploy custom 'Bird' backdoors that utilize HiveMQ MQTT brokers and the Matrix protocol for C2, featuring machine-bound encrypted configurations.
Detection of Remote PowerShell Invoke-Command Execution
1 rule 1 TTPAdversaries leverage the PowerShell Invoke-Command cmdlet to perform lateral movement and execute arbitrary code on remote Windows hosts via WinRM.
Detection of WinRM Remote Management Enablement
1 TTPAdversaries may enable Windows Remote Management (WinRM) to facilitate lateral movement and remote code execution on compromised systems.
Suspicious WSMAN Provider Image Loads
1 rule 2 TTPsA detection engineering rule targets suspicious loading of Windows Management (WSMAN) provider DLLs by unusual processes, indicating potential local or remote execution and lateral movement through Windows Remote Management (WinRM) by threat actors.
Incoming Execution via WinRM Remote Shell
2 rules 1 TTPThis rule detects incoming execution via Windows Remote Management (WinRM) remote shell on a target host, which could be an indication of lateral movement by monitoring network traffic on ports 5985 or 5986 and processes initiated by WinRM.