Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This Hunt Package is meant to identify a nuanced method of execution of a .bat file that can be indicative of an unpacking sequence that leads to the deployment of an additional executable.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | 606cd1ac-622d-4645-9553-2b04df7407d8 |
| Tactics | DefenseEvasion |
| Techniques | T1140 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityEvent |
CommandLine contains ".bat"CommandLine contains "/c"CommandLine contains "cmd.exe"CommandLine has_any "AppData" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊