Imminent Ransomware

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query checks for a series of commands that are commonly used by attackers to disable security tools and system recovery tools before deploying Macaw ransomware in an organization.

Attribute Value
Type Analytic Rule
Solution Microsoft Defender XDR
ID bb46dd86-e642-48a4-975c-44f5ac2b5033
Severity High
Status Available
Kind Scheduled
Tactics DefenseEvasion, Persistence
Techniques T1562, T1547
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to Microsoft Defender XDR