Anitha A

@aanitha
0 followers0 downloads35 copies0 likes66 views

6 detections

This rule detects unauthorized process creation from the SharePoint worker process (w3wp.exe). It specifically monitors for the spawning of command-line shells or scripting engines, which is indicative of exploitation activity such as remote code execution (RCE) attempts against SharePoint services, including deserialization attacks.
Anitha A@aanitha
avatar
Federal Signal Detections
16 days ago
3011
This rule detects unauthorized process creation from the SharePoint worker process (w3wp.exe). It specifically monitors for the spawning of command-line shells or scripting engines, which is indicative of exploitation activity such as remote code execution (RCE) attempts against SharePoint services, including deserialization attacks.
Anitha A@aanitha
avatar
Detections.ai Community
16 days ago
1010
Detects Python processes executing common system and network enumeration tools (e.g., net.exe, tasklist.exe, dsquery, Get-ADUser). This activity is indicative of the SynkLoader system profiler module, used to size the victim environment for ransom-value estimation and lateral movement preparation.
Anitha A@aanitha
avatar
Federal Signal Detections
1 month ago
208
Detects command-line execution (cmd.exe, powershell.exe) originating from a python.exe process tree, correlated with long-running, frequent outbound public network connections from the same python.exe process. This behavior is consistent with the SynkLoader RAT module, where a loader uses a Python process to execute system commands and maintain persistent C2 channels.
Anitha A@aanitha
avatar
Detections.ai Community
1 month ago
14027
Detects Python processes executing common system and network enumeration tools (e.g., net.exe, tasklist.exe, dsquery, Get-ADUser). This activity is indicative of the SynkLoader system profiler module, used to size the victim environment for ransom-value estimation and lateral movement preparation.
Anitha A@aanitha
avatar
Detections.ai Community
1 month ago
504
Detects command-line execution (cmd.exe, powershell.exe) originating from a python.exe process tree, correlated with long-running, frequent outbound public network connections from the same python.exe process. This behavior is consistent with the SynkLoader RAT module, where a loader uses a Python process to execute system commands and maintain persistent C2 channels.
Anitha A@aanitha
avatar
Federal Signal Detections
1 month ago
1006