CB-Threat-Hunting

(★ 114)

No description available.

  • Bitsadmin usage
  • Clearing Windows Eventlog
  • CreateRemoteThread from powershell.exe
  • Malicious Shims
  • MMC Lateral Movment
  • Processes on User Profile
  • README.md
  • Reg export usage
  • Ruler Detection
  • Sc.exe executed cmd.exe
  • Simon Tatham signed processes to the internet
  • Susp_mmc_source
  • Suspicious certutil usage
  • Suspicious executions of mstsc.exe
  • Unsigned Processes running from programdata with network connection
  • Windows Update UAC Bypass
  • winrs
  • Wmic usage
  • WMIprvse childrens
// repository documentation