
Guillermo Lopez
@guillermolg0 followers0 downloads0 copies0 likes6 views
2 detections
Filters
Last updated
All Time
Detection languages
2
Categories
2
2
1
1
1
Platforms
2
Products / Services
2
1
MITRE Techniques
2
2
1
1
Detects the modification of network interface IP addresses using netsh or PowerShell cmdlets. This activity can be associated with unauthorized network configuration changes, static IP assignment for persistence, or evasion techniques.
Detects the inclusion of PowerShell download commands ('irm' or 'Invoke-RestMethod') within the Windows 'RunMRU' registry key. This key is used by Windows Explorer to track recently typed run commands, and adversaries often abuse it to maintain persistence or store malicious one-liner payloads that are intended to be executed at a later time.
