Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Browser exploitation often ends in a command being run. This hunt covers scripting engines and other applications a browser can be abused to launch, including the FileFix technique that tricks a user into pasting an attacker command into File Explorer.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | 59d4df2f-014b-47c0-8008-688d1b41682a |
| Tactics | DefenseEvasion, Execution |
| Techniques | T1059, T1218 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityEvent |
NewProcessName has_any "\\cmd.exe"ParentProcessName has_any "\\chrome.exe" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊