mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Branch was auto-updated.
This commit is contained in:
@@ -10,7 +10,7 @@ description: The following detection identifies the latest behavior utilized by
|
||||
malware families (including TA551, IcedID). This detection identifies any Windows
|
||||
Office Product spawning `bitsadmin.exe`. In malicious instances, the command-line
|
||||
of `bitsadmin.exe` will contain a URL to a remote destination or similar command-line
|
||||
arguments as `/transfer /Download /priority Foreground`. In addition, Threat Research
|
||||
arguments as transfer, Download, priority, Foreground. In addition, Threat Research
|
||||
has released a detections identifying suspicious use of `bitsadmin.exe`. In this
|
||||
instance, we narrow our detection down to the Office suite as a parent process.
|
||||
During triage, review all file modifications. Capture and analyze any artifacts
|
||||
|
||||
Reference in New Issue
Block a user