
Sam Harrison
@sect0rcybersecCompletionist
0 followers6 downloads106 copies2 likes580 views
3 detections
Filters
Last updated
All Time
Detection languages
3
Categories
1
Platforms
3
MITRE Techniques
1
1
1
1
1
Detects when bcdedit or bootcfg is executed and Safeboot registry keys modified within a specified time window
msiexec.exe running as SYSTEM, spawned by a script/task host, with no installer package.
Procedure is currently being used by Lazarus group in conjunction with CVE-2026-68820
Ref https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
Procedure is currently being used by Lazarus group in conjunction with CVE-2026-68820
Ref https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
Looks for Metadata IOCs as listed in the CISA report on BrickStorm C2 malware.
I don't recommend using this query on its own; rather, use it in conjunction with behavioural analysis to look for evidence of BrickStorm activity.
https://media.defense.gov/2025/Dec/04/2003834878/-1/-1/0/MALWARE-ANALYSIS-REPORT-BRICKSTORM-BACKDOOR.PDF
I don't recommend using this query on its own; rather, use it in conjunction with behavioural analysis to look for evidence of BrickStorm activity.
https://media.defense.gov/2025/Dec/04/2003834878/-1/-1/0/MALWARE-ANALYSIS-REPORT-BRICKSTORM-BACKDOOR.PDF
