avatar

Sam Harrison

@sect0rcybersec
Completionist
0 followers6 downloads106 copies2 likes580 views

3 detections

Detects when bcdedit or bootcfg is executed and Safeboot registry keys modified within a specified time window
avatar
Sam Harrison@sect0rcybersec
avatar
Detections.ai Community
2 months ago
25032
msiexec.exe running as SYSTEM, spawned by a script/task host, with no installer package.

Procedure is currently being used by Lazarus group in conjunction with CVE-2026-68820

Ref https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
avatar
Sam Harrison@sect0rcybersec
avatar
Detections.ai Community
2 months ago
17174
Looks for Metadata IOCs as listed in the CISA report on BrickStorm C2 malware.
I don't recommend using this query on its own; rather, use it in conjunction with behavioural analysis to look for evidence of BrickStorm activity.

https://media.defense.gov/2025/Dec/04/2003834878/-1/-1/0/MALWARE-ANALYSIS-REPORT-BRICKSTORM-BACKDOOR.PDF
avatar
Sam Harrison@sect0rcybersec
avatar
Detections.ai Community
10 months ago
641474