
Yeji Hwang
@yezyizhere0 followers0 downloads56 copies1 like161 views
3 detections
Filters
Last updated
All Time
Detection languages
3
Identify outbound connections from PowerShell possibly downloading payload.
Detects potentially suspicious command or script execution directly initiated by an IIS worker process (w3wp.exe) on a specified device and date. The query identifies web-server processes spawning command shells, PowerShell, script interpreters, download utilities, or LOLBins, which may indicate web-shell execution, vulnerable application exploitation, or unauthorized server-side command execution.
Detects potential DLL execution from a WebDAV-over-HTTPS path by identifying command lines containing @SSL and an ordinal-based DLL export pattern such as ,#1. This activity may indicate remote payload execution through tools such as rundll32.exe.
