mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
3d25c40bf7
Broke out macros definition into it's own manifest Created macro manifests for all of current macros that we ship Created lookup file manifest Created lookup file manifests for all current lookup files that we ship
2.6 KiB
2.6 KiB
| 1 | app | note |
|---|---|---|
| 2 | remcom.exe | ESCU - This process is an open source replacement to psexec and is not typically seen in an enterprise environment. |
| 3 | pwdump.exe | ESCU - This process is associated with a tool used to dump password hashes on a Windows system. |
| 4 | pwdump2.exe | ESCU - This process is associated with a tool used to dump password hashes on a Windows system. |
| 5 | nc.exe | ESCU - This process is an open source tool used for network communications. |
| 6 | wce.exe | ESCU - This process is associated with a tool used to dump hashes and execute pass-the-hash and pass-the-ticket attacks. |
| 7 | cain.exe | ESCU - This process is associated with a tool used to collect user credentials and execute attacks. |
| 8 | nmap.exe | ESCU - This process is an open source network mapping tool used to identify hosts and listening services on a network. |
| 9 | kidlogger.exe | ESCU - This process is associated with a tool used to collect keyboard input on a host. |
| 10 | isass.exe | ESCU - This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. |
| 11 | svch0st.exe | ESCU - This process name is used by attackers to hide in plain sight and look like a legitimate Windows system process. |
| 12 | at.exe | ESCU - This process is used to schedule other processes to run. schtasks.exe should be used instead as it provides more flexibility. |
| 13 | getmail.exe | ESCU - This process is seen to be used by attackers to extract email files from host machines. |
| 14 | ntdll.exe | ESCU - This process was identified as malicious by DHS Alert TA18-074A. |
| 15 | netpass.exe | ESCU - This process was identified as malicious by DHS Alert TA18-201A and attackers use this tool to recover all network passwords stored on your system for the current logged-on user. |
| 16 | WebBrowserPassView.exe | ESCU - This process was identified as malicious by DHS Alert TA18-201A and is used by attackers as a password recovery tool that reveals the passwords stored in Web Browsers. |
| 17 | OutlookAddressBookView.exe | ESCU - This process was identified as malicious by DHS Alert TA18-201A and is used by attackers to steal the details of all recipients stored in the address books of Microsoft Outlook. |
| 18 | mailpv.exe | ESCU - This process was identified by DHS Alert TA18-201A and attackers use this tool is a password-recovery tool that reveals the passwords and other account details from various email clients. |
| 19 | NLBrute.exe | ESCU - This process was identified in the SamSam Ransomware Campaign and attackers use this tool to brute force RDP instances with a range of commonly used passwords. |
| 20 | selfdel.exe | ESCU - This executable was delivered in the SamSam Ransomware Campain and the attackers levereged this binary to delete its malicilous activities. |