avatar

Yeji Hwang

@yezyizhere
0 followers0 downloads56 copies1 like161 views

3 detections

Identify outbound connections from PowerShell possibly downloading payload.
avatar
Yeji Hwang@yezyizhere
avatar
Detections.ai Community
1 month ago
26045
Detects potentially suspicious command or script execution directly initiated by an IIS worker process (w3wp.exe) on a specified device and date. The query identifies web-server processes spawning command shells, PowerShell, script interpreters, download utilities, or LOLBins, which may indicate web-shell execution, vulnerable application exploitation, or unauthorized server-side command execution.
avatar
Yeji Hwang@yezyizhere
avatar
Detections.ai Community
1 month ago
23026
Detects potential DLL execution from a WebDAV-over-HTTPS path by identifying command lines containing @SSL and an ordinal-based DLL export pattern such as ,#1. This activity may indicate remote payload execution through tools such as rundll32.exe.
avatar
Yeji Hwang@yezyizhere
avatar
Detections.ai Community
1 month ago
209