CB-Threat-Hunting
No description available.
파일 탐색기
최종 버전 다운로드 (.zip)- Querywithinthelast24hours
- README.MD
- Powershell - T1086
- README.MD
- T1002 - Command-Line Creation of a RAR file
- T1003 - Credential Access lsass.exe from taskmanager.md
- T1003 - Credential Dumping - SAM Dumping via Reg.exe
- T1004 - Winlogon Helper DLL
- T1015 - Accessibility Features
- T1016 - System Network Configuration Discovery on Windows.md
- T1021 - Simon Tatham signed Binaries.md
- T1021.001 - Remote Desktop Protocol (RDP).md
- T1021.003 - Distributed Component Object Model (DCOM).md
- T1028 - Children of scrcons.exe
- T1028-T1086 - Powershell Remoting - Destination host
- T1037 - UserInitMprLogonScript
- T1047 - Windows Management Instrumentation - WMIprvse execution destination host
- T1047- Windows Management Instrumentation wmic.md
- T1047- Windows Management Instrumentation- wmic executions
- T1050 - New Service - Powershell or cmd.exe as parent
- T1053 - Scheduled Task.md
- T1055 - Process Injection.md
- T1070 - Delete Volume USN Journal with fsutil
- T1070- Clearing Windows Event Logs with wevtutil
- T1070.004 - File Deletion.md
- T1076 - Remote Desktop Protocol to External IPs
- T1076 - Remote Desktop Protocol.md
- T1082- systeminfo executions.md
- T1085 - Rundll32 Executions
- T1086 - Powershell Executions 6 IEX executions
- T1088 - UAC Bypass Event Viewer
- T1088 - UAC Bypass via WSReset.exe
- T1088- Bypass User Account Control fodhelper.exe and EventViewer.exe
- T1089 - Disabling Security Tools - Sysmon unload
- T1100 - Web Shell - Children of PHP-CGI.exe
- T1100 - Web Shell - Children of w3wp.exe
- T1105 - Ingress Tool Transfer.md
- T1107 - File Deletion WMIC.md
- T1107- File Deletion - VssAdmin
- T1107- Modification of Boot Configuration
- T1114 - T1137 - Ruler Detection 1.md
- T1117 - Regsvr32 detection
- T1117 - Regsvr32 detection 2.md
- T1117- Regsvr32- Suspicious Script Object Execution
- T1118 - InstallUtil.md
- T1121 - Malicious Regasm-RegSVCS.md
- T1123 - Audio Capture via PowerShell
- T1127 - Trusted Developer Utilities
- T1128 - netsh Executions
- T1128 - Netsh Helper DLL 2
- T1134.005 - SID history Injection
- T1135 - Enumeration of Remote Shares
- T1135-Enumeration of Local Shares
- T1136- User Account Creation.md
- T1136.002 - Domain Account Creation.md
- T1138 - Application Shimming
- T1140 - Appcmd disable logging.md
- T1140 - Suspicious Certutil usage.md
- T1158 - Attrib execution.md
- T1170 - Mshta Network Connections
- T1173 - Dynamic Data Exchange
- T1175 - DCOM
- T1178-SID-History Injection
- T1183 - Image File Execution Options Injection 2
- T1183 - Image File Execution Options Injection1.md
- T1191 - CMSTP Executions
- T1196 - Control Panel Items
- T1197 - BITS Jobs
- T1202 - Citrix escape
- T1202 -Indirect Command Execution.md
- T1204 - User Execution - Processes from Documents.md
- T1204 - User Execution - Processes running on Desktop
- T1218 - Microsoft Teams Update Whitelisting Bypass2
- T1218 - Signed Binary Proxy Execution 2
- T1218 - Signed Binary Proxy Execution- atbroker.md
- T1218 - Teams Whitelisting Bypass
- T1218- squirrel.exe download or update
- T1218.010 - Regsvr32 local COM scriptlet execution.md
- T1218.012 - Verclsid.exe outgoing connection
- T1220 - MSXSL.exe executed with with different filename
- T1220 - XSL Script Processing.md
- T1222 - icacls takeown cacls usage.md
- T1222 - File Permissions Modification.md
- T1223 - Compiled HTML File.md
- T1481 - Web Server Suspicious Executions
- T1543.003 - Windows Service.md
- T1547.001 - Registry Run Keys.md
- T1550.002 - Pass the Hash.md
- T1550.003 - Pass the Ticket.md
- T1552.001 - Credentials In Files.md
- T1563.002 - RDP hijacking using tscon
- Findhashes.py
- bitsadmin_download
- dhcp_calloutdll
- Malware_connectback_ports
- office_macro_cmd
- powershell_download
- Readme.md
- Susp_control_dll_load
- Susp_net_execution
- Susp_powershell_parent_combo
- susp_recon_activity
- Susp_regsvr32_anomalies
- Susp_schtask_creation
- Susp_script_execution
- susp_svchost
- uac_bypass_eventvwr
- UAC_bypass_sdclt
- vuln_cve_2017_8759
- webshell_detection
- webshell_spawn
- Windows Binaries connecting to github.com
- Bitsadmin usage
- Clearing Windows Eventlog
- CreateRemoteThread from powershell.exe
- Malicious Shims
- MMC Lateral Movment
- Processes on User Profile
- README.md
- Reg export usage
- Ruler Detection
- Sc.exe executed cmd.exe
- Simon Tatham signed processes to the internet
- Susp_mmc_source
- Suspicious certutil usage
- Suspicious executions of mstsc.exe
- Unsigned Processes running from programdata with network connection
- Windows Update UAC Bypass
- winrs
- Wmic usage
- WMIprvse childrens
// repository documentation
Was this content helpful?
(0 ratings)
