mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
26 KiB
26 KiB
| 1 | task_name | task_command | task_arguments | tool | tool_category | tool_type | link | severity | comment | reference |
|---|---|---|---|---|---|---|---|---|---|---|
| 2 | *powershell.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 3 | *wscript.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 4 | *cscript.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 5 | *cmd.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 6 | *sh.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 7 | *ksh.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 8 | *zsh.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 9 | *bash.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 10 | *scrcons.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 11 | *pwsh.exe* | shell command use | exploitation | greyware_tool | https://attack.mitre.org/techniques/T1053/005/ | medium | N/A | |||
| 12 | powershell.exe | *-Command whoami* | whoami | Discovery | greyware_tool | https://github.com/mthcht/awesome-lists | medium | N/A | https://github.com/mthcht/awesome-lists | |
| 13 | powershell.exe | -encodedCommand * | powershell | Defense Evasion | greyware_tool | https://github.com/mthcht/awesome-lists | medium | base64 encoded command from a scheduled task | https://github.com/mthcht/awesome-lists | |
| 14 | powershell.exe | -enc * | powershell | Defense Evasion | greyware_tool | https://github.com/mthcht/awesome-lists | medium | base64 encoded command from a scheduled task | https://github.com/mthcht/awesome-lists | |
| 15 | cmd.exe | */c whoami* | whoami | Discovery | greyware_tool | https://github.com/mthcht/awesome-lists | medium | N/A | https://github.com/mthcht/awesome-lists | |
| 16 | \area41 | C:\_Microsoft\Microsoft.exe | CryptInject | Malware | offensive_tool | https://github.com/roadwy/DefenderYara/blob/9bbdb7f9fd3513ce30aa69cd1d88830e3cf596ca/Trojan/Win32/CryptInject/Trojan_Win32_CryptInject_PJ_MTB.yar#L36 | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 17 | \OfficeServicesStatus | *wscript*\public\* | ISMDoor | Malware | offensive_tool | https://unit42.paloaltonetworks.com/unit42-oilrig-uses-ismdoor-variant-possibly-linked-greenbug-threat-group/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 18 | \Business Aviation | *wscript* | Gootloader | Malware | offensive_tool | https://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/ | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 19 | \Destination Branding | *wscript* | Gootloader | Malware | offensive_tool | https://news.sophos.com/en-us/2024/11/06/bengal-cat-lovers-in-australia-get-psspsspssd-in-google-driven-gootloader-campaign/ | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 20 | \InetlSecurityAssistManager | *wscript * | OopsIE | Malware | offensive_tool | https://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 21 | *wevtutil.exe | cl * | wevtutil | Defense Evasion | greyware_tool | https://github.com/mthcht/awesome-lists | high | clearing event logs with wevtutil.exe | https://github.com/mthcht/awesome-lists | |
| 22 | \GoogleUpdateTaskMachineUI | *update.vbs* | Helminth | Malware | offensive_tool | https://unit42.paloaltonetworks.com/the-oilrig-campaign-attacks-on-saudi-arabian-organizations-deliver-helminth-backdoor/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 23 | \Wow64 Subsystem | *programdata*mswow86.exe* | NetSupport Manager | RAT | offensive_tool | https://thedfirreport.com/2023/10/30/netsupport-intrusion-results-in-domain-compromise/ | medium | N/A | https://github.com/mthcht/awesome-lists | |
| 24 | \copy | *powershell.exe* | *Copy-Item*\ProgramData\* | BlackJack | Ransomware | offensive_tool | https://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/blackjack-hacktivists-connection-with-twelve_113959/content.txt#L1515 | high | N/A | https://github.com/mthcht/awesome-lists |
| 25 | \def | *powershell.exe* | *Get-MpPreference* | BlackJack | Ransomware | offensive_tool | https://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/blackjack-hacktivists-connection-with-twelve_113959/content.txt#L1515 | high | N/A | https://github.com/mthcht/awesome-lists |
| 26 | \FJ_load | *madHcCtrl.exe* | Danabot | Infostealer | offensive_tool | https://securelist.com/tusk-infostealers-campaign/113367/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 27 | \shell | *Invoke-PowerShellTcpRun* | Schtasks_latmov.bat | Lateral Movement | offensive_tool | https://github.com/S3cur3Th1sSh1t/Creds/blob/f71e780c51fdc2fdabe4e51831fa6289b1bede96/batch/Schtasks_latmov.bat#L2 | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 28 | *StageProxyOps* | *HTTP-Server.ps1* | HTTP-Server | Persistence | offensive_tool | https://github.com/NullArray/WinBins-Plus/blob/1e4af04ceaa8085b532757a1331113e919a20f4b/Scripts/persist.cmd#L2 | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 29 | \GoogleUpdatesTaskMachineUI | *fireeye.vbs* | Helminth | Malware | offensive_tool | https://unit42.paloaltonetworks.com/unit42-oilrig-actors-provide-glimpse-development-testing-efforts/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 30 | \MicrosoftEdgeUpdateTaskMachineMS | *EdgeBrowser.cmd* | MeshAgent | RAT | offensive_tool | https://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/awaken-likho-apt-new-implant-campaign_114101/content.txt#L831 | high | N/A | https://github.com/mthcht/awesome-lists | |
| 31 | \run1 | *cmd.exe* | */c *\ProgramData\* | BlackJack | Ransomware | offensive_tool | https://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/securelist_com/blackjack-hacktivists-connection-with-twelve_113959/content.txt#L1515 | high | N/A | https://github.com/mthcht/awesome-lists |
| 32 | \SecurityAssist | *Certutil* | OopsIE | Malware | offensive_tool | https://unit42.paloaltonetworks.com/unit42-oopsie-oilrig-uses-threedollars-deliver-new-trojan/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 33 | \mstask | *C:\temp\* | Trojan.Win32.BreakWin | Malware | offensive_tool | https://www.sentinelone.com/labs/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll/ | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 34 | \ReportHealth | *appdata*\srvHealth.exe* | ISMInjector | Malware | offensive_tool | https://unit42.paloaltonetworks.com/unit42-oilrig-group-steps-attacks-new-delivery-documents-new-injector-trojan/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 35 | *\Windows\Debug* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | task in the *\Windows\Debug folder | https://github.com/mthcht/awesome-lists | ||
| 36 | \MicrosoftEdgeUpdateTaskMachineUC | *\users\public\* | autohotkey | keylogger | offensive_tool | https://thedfirreport.com/2023/02/06/collect-exfiltrate-sleep-repeat/ | high | N/A | https://github.com/mthcht/awesome-lists | |
| 37 | *\Users\public* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | task in the Public user profile | https://github.com/mthcht/awesome-lists | ||
| 38 | *\Users*\Downloads* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | task in the users Downloads folder | https://github.com/mthcht/awesome-lists | ||
| 39 | *\Users*\Documents* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | task in the users Documents folder | https://github.com/mthcht/awesome-lists | ||
| 40 | *\Users*\AppData\Roaming* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | task in the roaming folder | https://github.com/mthcht/awesome-lists | ||
| 41 | *\Users*\AppData\Local* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | task in the appdata folder | https://github.com/mthcht/awesome-lists | ||
| 42 | \SystemFailureReporter | *\public\* | SideTwist Backdoor (APT34) | Malware | offensive_tool | https://research.checkpoint.com/2021/irans-apt34-returns-with-an-updated-arsenal/ | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 43 | *\ProgramData* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | task in the ProgramData folder | https://github.com/mthcht/awesome-lists | ||
| 44 | \MEGA\MEGAsync Update Task* | *\MEGAupdater.exe | MEGASync | Data Exfiltration | greyware_tool | https://mega.io/en/desktop | high | N/A | https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/MEGAsync.csv | |
| 45 | \WallPaperChangeApp | *\Autoit3\Autoit3.exe* | OxtaRAT | Malware | offensive_tool | https://research.checkpoint.com/2023/operation-silent-watch-desktop-surveillance-in-azerbaijan-and-armenia/ | critical | N/A | https://github.com/mthcht/awesome-lists | |
| 46 | *\AppData\Local\Temp\* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | high | task in the temp folder | https://github.com/mthcht/awesome-lists | ||
| 47 | \Microsoft_Auto_Scheduler | *\AppData\* | Kube Ransomware | Ransomware | offensive_tool | https://x.com/ShanHolo/status/1880566701009563915/photo/1 | high | N/A | https://github.com/mthcht/awesome-lists | |
| 48 | *:\Windows\Temp\* | suspicious paths | exploitation | greyware_tool | https://github.com/mthcht/awesome-lists | medium | executable from the temp folder | https://github.com/mthcht/awesome-lists | ||
| 49 | *:\windows\system32\calc.exe | POC | exploitation | greyware_tool | https://x.com/hackingforbeer/status/1719402854085951883 | medium | POC schtasks /create /sc minute /tn 'dongs' /tr 'C:\windows\system32\calc.exe' | https://github.com/mthcht/awesome-lists | ||
| 50 | \tMicNet Work40, | *.vbs* | AsyncRAT | Malware | offensive_tool | https://any.run/cybersecurity-blog/asyncrat-open-directories-infection-analysis/ | critical | AsyncRAT’s Infection samples | https://github.com/mthcht/awesome-lists | |
| 51 | \yastcat | Wannamine | Cryptominer | offensive_tool | crowdstrike.com/blog/cryptomining-harmless-nuisance-disruptive-threat/ | critical | Moonero miner - command SCHTASKS /create /RU System /SC DAILY /TN yastcat /f /TR %temp%\y1.bat &&SCHTASKS /run /TN yastcat | https://github.com/mthcht/awesome-lists | ||
| 52 | \OneNote 4726 | Unkown | Malware | offensive_tool | https://x.com/Gi7w0rm/status/1864307803914981837 | medium | N/A | https://github.com/mthcht/awesome-lists | ||
| 53 | \Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeAll | Trojan.Win32.BreakWin | Malware | offensive_tool | https://www.sentinelone.com/labs/meteorexpress-mysterious-wiper-paralyzes-iranian-trains-with-epic-troll/ | critical | N/A | https://github.com/mthcht/awesome-lists | ||
| 54 | \dongs | suspicious names | exploitation | offensive_tool | https://x.com/hackingforbeer/status/1719402854085951883 | medium | POC schtasks /create /sc minute /tn 'dongs' /tr 'C:\windows\system32\calc.exe' | https://github.com/mthcht/awesome-lists | ||
| 55 | \StopVMMSandKillVMWP | StopVMMSandKillVMWP script | Defense evasion | offensive_tool | https://x.com/GroupIB_DFIR/status/1750452267692728516 | high | schtasks /create /tn StopVMMSandKillVMWP /tr 'powershell.exe -Command get-service -name vmms | stop-service -force ; taskkill /f /im vmwp.exe' /sc minute /mo 30 /ru SYSTEM /f | https://github.com/mthcht/awesome-lists | ||
| 56 | \SSH Key Exchange | sshd | Persistence | greyware_tool | https://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/ | medium | compliance | https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/schtasks.csv | ||
| 57 | \SSH Server | sshd | Persistence | greyware_tool | https://www.trellix.com/blogs/research/cactus-ransomware-new-strain-in-the-market/ | medium | compliance | https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/schtasks.csv | ||
| 58 | \MeterpeterC2 | redpill | exploitation | offensive_tool | https://github.com/r00t-3xp10it/redpill/blob/611d39b8bff717ac84d58550dc04e1b312acb19e/bin/SchTasks.ps1#L83 | critical | SchTasks.ps1 | https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/redpill.csv | ||
| 59 | \RedPillTask | redpill | exploitation | offensive_tool | https://github.com/r00t-3xp10it/redpill/blob/611d39b8bff717ac84d58550dc04e1b312acb19e/redpill.ps1#L743 | critical | redpill.ps1 | https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/redpill.csv | ||
| 60 | \SQLC2AgentPS* | PowerUpSQL | C2 | offensive_tool | https://github.com/NetSPI/PowerUpSQL/blob/a83cad211983290bf38708e6e237cacbfe023e32/scripts/pending/SQLC2.ps1#L958 | critical | N/A | https://github.com/mthcht/awesome-lists | ||
| 61 | My Startup Task | Powershell-Scripts-for-Hackers-and-Pentesters | Persistence | offensive_tool | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters/blob/788e89e9584b4b43f982721d59c06c77c0b3b566/PS-020.md?plain=1#L20 | medium | N/A | https://github.com/mthcht/awesome-lists | ||
| 62 | *Set-MpPreference -DisableRealtimeMonitoring * | powershell | Defense Evasion | greyware_tool | https://github.com/mthcht/awesome-lists | high | disabling Defender Real time monitoring | https://github.com/mthcht/awesome-lists | ||
| 63 | \OneDrive Security | Nitrogen | Malware | offensive_tool | https://news.sophos.com/en-us/2023/07/26/into-the-tank-with-nitrogen/ | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 64 | \Demovale | Nightdoor | Malware | offensive_tool | lhttps://github.com/mthcht/ThreatIntel-Reports/blob/3a4f91c1dbdc45f837f74ca4f3265caba6a09f84/Intel%20Reports/www_welivesecurity_com/en_eset-research_evasive-panda-leverages-monlam-festival-target-tibetans/content.txt#L269C143-L269C152 | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 65 | \8766714F94DD | more_eggs | Malware | offensive_tool | https://thedfirreport.com/2024/12/02/the-curious-case-of-an-egg-cellent-resume/n= | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 66 | \Loki | LokiLocker | Ransomware | offensive_tool | https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware | critical | command observed schtasks /CREATE /SC ONLOGON /TN Loki /TR * | https://github.com/mthcht/awesome-lists | ||
| 67 | \LimeRAT-Admin | Lime-RAT | Malware | offensive_tool | https://github.com/NYAN-x-CAT/Lime-RAT/blob/87e189781c0aef0e84cabe2f8c2e7d8f5143e594/Project/Client/C_Installation.vb#L76 | critical | N/A | https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/Lime-RAT.csv | ||
| 68 | \NFUBffk | LemonDuck | Malware | offensive_tool | https://notes.netbytesec.com/2024/10/lemonduck-unleashes-cryptomining.html | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 69 | \K0adic | koadic | C2 | offensive_tool | https://github.com/Averroes/koadic/blob/97886ed570f31efff09d1e06c4a7ece2d9b6bd27/data/implant/persist/schtasks.js#L4C21-L4C27 | critical | N/A | https://github.com/mthcht/awesome-lists | ||
| 70 | \Feedback_API_VS_Services_Client | Keyzetsu clipper variant | Malware | offensive_tool | https://checkmarx.com/blog/new-technique-to-trick-developers-detected-in-an-open-source-supply-chain-attack/ | medium | N/A | https://github.com/mthcht/awesome-lists | ||
| 71 | \Tater | Invoke-Tater | Privilege Escalation | offensive_tool | https://github.com/BC-SECURITY/Empire/blob/8aca42747da6cf2b0def7edede94586f6b3258e8/empire/server/data/module_source/privesc/Invoke-Tater.ps1#L101 | critical | PowerShell implementation of the Hot Potato Windows Privilege Escalation exploit from @breenmachine and @foxglovesec | https://github.com/mthcht/awesome-lists | ||
| 72 | \\Defender | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 73 | \\defender | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 74 | \\Microsoft\\DefenderService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 75 | \\Microsoft\\Windows\\Application Experience\\StartupAppTaskCheck | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 76 | \\Microsoft\\Windows\\Application Experience\\StartupAppTaskCkeck | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 77 | \\Microsoft\\Windows\\ATPUpd | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 78 | \\Microsoft\\Windows\\Data Integrity Scan\Data Integrity Update | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 79 | \\Microsoft\\Windows\\DefenderUPDService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 80 | \\Microsoft\\Windows\\IISUpdateService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 81 | \\Microsoft\\Windows\\Speech\\SpeechModelInstallTask | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 82 | \\Microsoft\\Windows\\WiMSDFS | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 83 | \\Microsoft\\Windows\\Windows Defender\\Defender Update Service | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 84 | \\Microsoft\\Windows\\Windows Defender\\Service Update | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 85 | \\Microsoft\\Windows\\Windows Error Reporting\\CheckReporting | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 86 | \\Microsoft\\Windows\\Windows Error Reporting\\SubmitReporting | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 87 | \\Microsoft\\Windows\\Windows Filtering Platform\\BfeOnServiceStart | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 88 | \\Microsoft\\Windows\\WindowsDefenderService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 89 | \\Microsoft\\Windows\\WindowsDefenderService2 | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 90 | \\Microsoft\\Windows\\WindowsUpdate\\Scheduled AutoCheck | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 91 | \\Microsoft\\Windows\\WindowsUpdate\\Scheduled Check | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 92 | \\WindowUpdate | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 93 | \Defender | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 94 | \defender | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 95 | \Microsoft\DefenderService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 96 | \Microsoft\Windows\Application Experience\StartupAppTaskCheck | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 97 | \Microsoft\Windows\Application Experience\StartupAppTaskCkeck | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 98 | \Microsoft\Windows\ATPUpd | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 99 | \Microsoft\Windows\Data Integrity Scan\Data Integrity Update | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 100 | \Microsoft\Windows\DefenderUPDService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 101 | \Microsoft\Windows\IISUpdateService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 102 | \Microsoft\Windows\Speech\SpeechModelInstallTask | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 103 | \Microsoft\Windows\WiMSDFS | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 104 | \Microsoft\Windows\Windows Defender\Defender Update Service | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 105 | \Microsoft\Windows\Windows Defender\Service Update | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 106 | \Microsoft\Windows\Windows Error Reporting\CheckReporting | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 107 | \Microsoft\Windows\Windows Error Reporting\SubmitReporting | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 108 | \Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStart | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 109 | \Microsoft\Windows\WindowsDefenderService | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 110 | \Microsoft\Windows\WindowsDefenderService2 | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 111 | \Microsoft\Windows\WindowsUpdate\Scheduled AutoCheck | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 112 | \Microsoft\Windows\WindowsUpdate\Scheduled Check | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 113 | \WindowUpdate | GraphicalProton backdoor | Malware | offensive_tool | https://www.ic3.gov/CSA/2023/231213.pdf | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 114 | \InfrSiRfucture Technologies | Gootloader | Malware | offensive_tool | https://thedfirreport.com/2024/02/26/seo-poisoning-to-domain-control-the-gootloader-saga-continues/ | critical | N/A | https://github.com/mthcht/awesome-lists | ||
| 115 | \SynchronizeTimeZone | frp | Data Exfiltration | offensive_tool | https://www.aha.org/system/files/media/file/2021/05/fbi-flash-tlp-white-apt-actors-exploiting-fortinet-vulnerabilities-to-gain-access-for-malicious-activity-5-27-21.pdf | high | APT Actors Exploiting Fortinet Vulnerabilities to Gain Access for Malicious Activity - creating specific scheduled task for exfiltration | https://github.com/mthcht/awesome-lists | ||
| 116 | \CursorSvc | Fentanyl Stealer | Malware | offensive_tool | https://github.com/dekrypted/Fentanyl/blob/2b4a008934f21df4eed7b90fb3019d3395f7c909/fenty.py#L699C53-L699C62 | critical | Similar to Bandit Stealer | https://github.com/mthcht/awesome-lists | ||
| 117 | \DisableBitdefender-* | Dispossesor | Ransomware | offensive_tool | https://vx-underground.org/Archive/Dispossessor%20Leaks | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 118 | \DHARMA | Dharma | Ransomware | offensive_tool | https://www.joesandbox.com/analysis/860608/0/lighthtml | critical | command observed schtasks /CREATE /SC ONLOGON /TN DHARMA /TR C:\ProgramData\harma.exe* | https://github.com/mthcht/awesome-lists | ||
| 119 | \Sorry | Cryptominer | Cryptominer | offensive_tool | https://x.com/cglyer/status/1001463072672886785 | high | schtasks /create /tn 'Sorry' /tr C:\Windows\Temp\taskhost.exe /sc daily /mo 2 /st 22:00:00 /f4 | https://x.com/cglyer/status/1001463072672886785 | ||
| 120 | \shadowdev | CobaltStrike | C2 | offensive_tool | https://cloud.google.com/blog/topics/threat-intelligence/melting-unc2198-icedid-to-ransomware-operations | critical | cmd.exe /c schtasks /create /sc minute /mo 1 /tn shadowdev /tr C:\\ProgramData\\S\u0443sH\u0435\u0430ls\\T\u0430s\u0441host.exe | https://github.com/mthcht/awesome-lists | ||
| 121 | \ClearEventLogs | Cleareventlog script | Defense Evasion | offensive_tool | https://x.com/GroupIB_DFIR/status/1750452304606810175 | high | schtasks /create /tn ClearEventLogs /tr 'powershell.exe -Command wevtutil el | foreach { wevtutil cl $_ }' /sc daily /st 03:00 /ru SYSTEM /f | https://github.com/mthcht/awesome-lists | ||
| 122 | \SC Scheduled Scan | Chafer | Malware | offensive_tool | https://nyotron.com/nyotron-discovers-next-generation-oilrig-attacks/ | high | Chafer activity attributed to OilRig | https://github.com/mthcht/awesome-lists | ||
| 123 | \UpdatMachine | Chafer | Malware | offensive_tool | https://nyotron.com/nyotron-discovers-next-generation-oilrig-attacks/ | high | Chafer activity attributed to OilRig | https://github.com/mthcht/awesome-lists | ||
| 124 | \drogon | BadRabbit | Malware | offensive_tool | https://www.vmray.com/analyses/bad-rabbit-ransomware-flash-analysis/report/overview.html | critical | schtasks /Create /SC once /TN drogon /RU SYSTEM /TR 'C:\Windows\system32\shutdown.exe /r /t 0 /f' /ST 02:34:00 | https://github.com/mthcht/awesome-lists | ||
| 125 | \BaiduUpdateTask1 | BADNEWS | Malware | offensive_tool | https://unit42.paloaltonetworks.com/unit42-patchwork-continues-deliver-badnews-indian-subcontinent/ | high | N/A | https://github.com/mthcht/awesome-lists | ||
| 126 | \AutoRDPwn | AutoRDPwn | C2 | offensive_tool | https://github.com/JoelGMSec/AutoRDPwn/blob/839d6afbd2cfa64b01a188b4e09a3e079c9c81d3/AutoRDPwn.ps1#L678 | critical | N/A | https://github.com/mthcht/awesome-lists | ||
| 127 | \thepiratMicrosoftEdgeUpdateTask | AsyncRAT | Malware | offensive_tool | https://any.run/cybersecurity-blog/asyncrat-open-directories-infection-analysis/ | critical | AsyncRAT’s Infection samples | https://github.com/mthcht/awesome-lists | ||
| 128 | \kbnvmmmhjo | Agent Tesla | Malware | offensive_tool | https://isc.sans.edu/diary/PowerPoint+attachments+Agent+Tesla+and+code+reuse+in+malware/28154 | critical | N/A | https://github.com/mthcht/awesome-lists |