mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
2.6 KiB
2.6 KiB
| 1 | app | note |
|---|---|---|
| 2 | remcom.exe | ESCU - This process is an open source replacement to psexec and is not typically seen in an enterprise environment. |
| 3 | pwdump.exe | ESCU - This process is associated with a tool used to dump password hashes on a Windows system. |
| 4 | pwdump2.exe | ESCU - This process is associated with a tool used to dump password hashes on a Windows system. |
| 5 | nc.exe | ESCU - This process is an open source tool used for network communications. |
| 6 | wce.exe | ESCU - This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks. |
| 7 | cain.exe | ESCU - This process is associated with a tool used to collect user credentials and execute attacks. |
| 8 | nmap.exe | ESCU - This process is an open source network mapping tool used to identify hosts and listening services on a network. |
| 9 | kidlogger.exe | ESCU - This process is associated with a tool used to collect keyboard input on a host. |
| 10 | isass.exe | ESCU - This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. |
| 11 | svch0st.exe | ESCU - This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. |
| 12 | at.exe | ESCU - This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility. |
| 13 | getmail.exe | ESCU - This process is seen to be used by attackers to extract email files from host machines. |
| 14 | ntdll.exe | ESCU - This process was identified as malicious by DHS Alert TA18-074A. |
| 15 | netpass.exe | ESCU - This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user. |
| 16 | WebBrowserPassView.exe | ESCU - This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers. |
| 17 | OutlookAddressBookView.exe | ESCU - This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook. |
| 18 | mailpv.exe | ESCU - This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients. |
| 19 | NLBrute.exe | ESCU - This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords. |
| 20 | selfdel.exe | ESCU - This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities. |