File tree Expand file tree Collapse file tree 1 file changed +2
-1
lines changed Expand file tree Collapse file tree 1 file changed +2
-1
lines changed Original file line number Diff line number Diff line change 300
300
<Image condition =" image" >net1.exe</Image > <!-- Windows: Launched by "net.exe", but it may not detect connections either -->
301
301
<Image condition =" image" >notepad.exe</Image > <!-- Windows: [ https://secrary.com/ReversingMalware/CoinMiner/ ] [ https://blog.cobaltstrike.com/2013/08/08/why-is-notepad-exe-connecting-to-the-internet/ ] -->
302
302
<Image condition =" image" >nslookup.exe</Image > <!-- Windows: Retrieve data over DNS -->
303
- <Image condition =" image" >powershell.exe</Image > <!-- Windows: PowerShell interface-->
303
+ <Image condition =" image" >powershell.exe</Image > <!-- Windows: PowerShell interface-->
304
+ <Image condition =" image" >powershell_ise.exe</Image > <!-- Windows: PowerShell interface-->
304
305
<Image condition =" image" >qprocess.exe</Image > <!-- Windows: [ https://www.first.org/resources/papers/conf2017/APT-Log-Analysis-Tracking-Attack-Tools-by-Audit-Policy-and-Sysmon.pdf ] -->
305
306
<Image condition =" image" >qwinsta.exe</Image > <!-- Windows: Query remote sessions | Credit @ion-storm -->
306
307
<Image condition =" image" >qwinsta.exe</Image > <!-- Windows: Remotely query login sessions on a server or workstation | Credit @ion-storm -->
You can’t perform that action at this time.
0 commit comments