avatar

Guillermo Lopez

@guillermolg
0 followers0 downloads0 copies0 likes6 views

2 detections

Detects the modification of network interface IP addresses using netsh or PowerShell cmdlets. This activity can be associated with unauthorized network configuration changes, static IP assignment for persistence, or evasion techniques.
avatar
Guillermo Lopez@guillermolg
avatar
Detections.ai Community
22 days ago
003
Detects the inclusion of PowerShell download commands ('irm' or 'Invoke-RestMethod') within the Windows 'RunMRU' registry key. This key is used by Windows Explorer to track recently typed run commands, and adversaries often abuse it to maintain persistence or store malicious one-liner payloads that are intended to be executed at a later time.
avatar
Guillermo Lopez@guillermolg
avatar
Detections.ai Community
25 days ago
003