hiding-java-class-file

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


This query was originally published in the threat analytics report, Adwind utilizes Java for cross-platform impact. Adwind is a remote access tool (RAT) that takes advantage of the cross-platform capabilities of the Java framework. It can check which operating system a target is running and adapt accordingly, allowing it to successfully compromise both Windows and macOS devices. The query below checks for attempts to disguise Java class files (i.e., complied code with a .class extension). Althou

Attribute Value
Type Hunting Query
Solution GitHub Only
ID c5196191-609a-407f-a623-f37785eca019
Tactics Defense evasion
Required Connectors MicrosoftThreatProtection
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/Microsoft%20365%20Defender/Defense%20evasion/hiding-java-class-file.yaml)

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceFileEvents ✓ ✗ ✓
DeviceProcessEvents ProcessCommandLine contains ".class"
ProcessCommandLine has "attrib +h +s +r"
✓ ✗ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries