Branch was auto-updated.

This commit is contained in:
github-actions[bot]
2021-04-29 20:56:16 +00:00
committed by GitHub
@@ -10,7 +10,7 @@ description: The following detection identifies the latest behavior utilized by
malware families (including TA551, IcedID). This detection identifies any Windows
Office Product spawning `bitsadmin.exe`. In malicious instances, the command-line
of `bitsadmin.exe` will contain a URL to a remote destination or similar command-line
arguments as `/transfer /Download /priority Foreground`. In addition, Threat Research
arguments as transfer, Download, priority, Foreground. In addition, Threat Research
has released a detections identifying suspicious use of `bitsadmin.exe`. In this
instance, we narrow our detection down to the Office suite as a parent process.
During triage, review all file modifications. Capture and analyze any artifacts