{"id":"T1105","name":"Ingress Tool Transfer","url":"https://attack.mitre.org/techniques/T1105","tactics":["command-and-control"],"platforms":["ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0060","stix_id":"x-mitre-detection-strategy--67677c4c-5778-49eb-ae74-1920645b8554","name":"Detect Ingress Tool Transfers via Behavioral Chain","url":"https://attack.mitre.org/detectionstrategies/DET0060","analytics":[{"id":"AN0165","stix_id":"x-mitre-analytic--f20d9241-84cc-4393-b2fb-798241da73fa","name":"Analytic 0165","description":"Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded).","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0165","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessName","description":"Tune for known good updaters (e.g., ChromeUpdate, OneDrive)"},{"field":"DestinationIPCategory","description":"Allow filtering by internal vs external IP blocks"},{"field":"FilePathRegex","description":"Focus on uncommon file drop paths (e.g., C:\\Users\\Public\\)"}],"live":true,"detection_strategies":["DET0060"],"techniques":["T1105"]},{"id":"AN0166","stix_id":"x-mitre-analytic--62d55c57-54a3-4c6f-8d0d-2684fa26c347","name":"Analytic 0166","description":"Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0166","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"connect, execve, write","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"file creation/modification","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"iptables:LOG","channel":"TCP connections","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"iptables-log"}],"mutable_elements":[{"field":"ToolName","description":"Match on curl, wget, rsync, etc. based on environment"},{"field":"DownloadExtension","description":"Tunable filter to limit to suspicious file types (.sh, .bin, .elf)"}],"live":true,"detection_strategies":["DET0060"],"techniques":["T1105"]},{"id":"AN0167","stix_id":"x-mitre-analytic--56552a3e-9934-4809-97a4-67d62f29478c","name":"Analytic 0167","description":"Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0167","platforms":["macOS"],"log_source_references":[{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:unifiedlog","channel":"file write/create","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"connection open","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DirectoryTargeted","description":"Restrict to high-risk directories like /Users/Shared, /tmp/"},{"field":"ProcessPath","description":"May tune based on custom tooling or MDM activity"}],"live":true,"detection_strategies":["DET0060"],"techniques":["T1105"]},{"id":"AN0168","stix_id":"x-mitre-analytic--fac5b2df-a58d-424e-a351-7d7ca05260e8","name":"Analytic 0168","description":"Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0168","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"command execution","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"file write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"ToolName","description":"Tune for wget, curl, netcat, and scripting languages in use"},{"field":"DatastorePath","description":"Filter or prioritize specific paths (e.g., /vmfs/volumes/)"}],"live":true,"detection_strategies":["DET0060"],"techniques":["T1105"]},{"id":"AN0169","stix_id":"x-mitre-analytic--c93951a7-7f78-40cf-a891-30d6c6a9bee6","name":"Analytic 0169","description":"Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks.","url":"https://attack.mitre.org/detectionstrategies/DET0060#AN0169","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"connection metadata","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"},{"name":"snmp:syslog","channel":"firmware write/log event","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"snmp-syslog"}],"mutable_elements":[{"field":"PayloadVolumeThreshold","description":"Tune based on expected update size vs anomalous bulk data transfers"},{"field":"ProtocolUsed","description":"Flag unexpected protocols like TFTP, FTP, HTTP"}],"live":true,"detection_strategies":["DET0060"],"techniques":["T1105"]}],"live":true,"version":"1.0","techniques":["T1105"]}],"sigma_rules":[{"id":"00b90cc1-17ec-402c-96ad-3a8117d7a582","title":"Suspicious Curl File Upload - Linux","author":"Nasreddine Bencherchali (Nextron Systems), Cedric MAURUGEON (Update)","status":"test","level":"medium","date":"2022-09-15","modified":"2023-05-02","description":"Detects a suspicious curl process start the adds a file to a web request","references":["https://twitter.com/d1r4c/status/1279042657508081664","https://medium.com/@petehouston/upload-files-with-curl-93064dcccc76","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-19---curl-upload-file","https://curl.se/docs/manpage.html","https://www.trendmicro.com/en_us/research/22/i/how-malicious-actors-abuse-native-linux-tools-in-their-attacks.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1105"],"path":"rules/linux/process_creation/proc_creation_lnx_susp_curl_fileupload.yml","techniques":["T1567","T1105"],"cves":[]},{"id":"00bca14a-df4e-4649-9054-3f2aa676bc04","title":"Potential Data Exfiltration Via Curl.EXE","author":"Florian Roth (Nextron Systems), Cedric MAURUGEON (Update)","status":"test","level":"medium","date":"2020-07-03","modified":"2023-05-02","description":"Detects the execution of the \"curl\" process with \"upload\" flags. Which might indicate potential data exfiltration","references":["https://twitter.com/d1r4c/status/1279042657508081664","https://medium.com/@petehouston/upload-files-with-curl-93064dcccc76","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-19---curl-upload-file","https://curl.se/docs/manpage.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.exfiltration","attack.command-and-control","attack.t1567","attack.t1105","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_curl_fileupload.yml","techniques":["T1567","T1105"],"cves":[]},{"id":"00d49ed5-4491-4271-a8db-650a4ef6f8c1","title":"Suspicious Download from Office Domain","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2021-12-27","modified":"2022-08-02","description":"Detects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents","references":["https://twitter.com/an0n_r0/status/1474698356635193346?s=12","https://twitter.com/mrd0x/status/1475085452784844803?s=12"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.resource-development","attack.t1105","attack.t1608"],"path":"rules/windows/process_creation/proc_creation_win_susp_download_office_domain.yml","techniques":["T1105","T1608"],"cves":[]},{"id":"02b64f1b-3f33-4e67-aede-ef3b0a5a8fcf","title":"Potential COM Objects Download Cradles Usage - Process Creation","author":"frack113","status":"test","level":"medium","date":"2022-12-25","modified":null,"description":"Detects usage of COM objects that can be abused to download files in PowerShell by CLSID","references":["https://learn.microsoft.com/en-us/dotnet/api/system.type.gettypefromclsid?view=net-7.0","https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=57"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_powershell_download_com_cradles.yml","techniques":["T1105"],"cves":[]},{"id":"04936b66-3915-43ad-a8e5-809eadfd1141","title":"Insensitive Subfolder Search Via Findstr.EXE","author":"Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2020-10-05","modified":"2024-03-05","description":"Detects execution of findstr with the \"s\" and \"i\" flags for a \"subfolder\" and \"insensitive\" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.\n","references":["https://lolbas-project.github.io/lolbas/Binaries/Findstr/","https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.command-and-control","attack.stealth","attack.t1218","attack.t1564.004","attack.t1552.001","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_findstr_subfolder_search.yml","techniques":["T1218","T1564.004","T1552.001","T1105"],"cves":[]},{"id":"04fc4b22-91a6-495a-879d-0144fec5ec03","title":"Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-13","modified":null,"description":"Detects potential exploitation of remote code execution vulnerability CVE-2025-33053\nby monitoring suspicious image loads from WebDAV paths. The exploit involves malicious executables from\nattacker-controlled WebDAV servers loading the Windows system DLLs like gdi32.dll, netapi32.dll, etc.\n","references":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053","https://research.checkpoint.com/2025/stealth-falcon-zero-day/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.command-and-control","attack.execution","attack.stealth","attack.t1218","attack.lateral-movement","attack.t1105","detection.emerging-threats","cve.2025-33053"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-33053/image_load_win_exploit_cve_2025_33053.yml","techniques":["T1218","T1105"],"cves":["CVE-2025-33053"]},{"id":"08249dc0-a28d-4555-8ba5-9255a198e08c","title":"Local Network Connection Initiated By Script Interpreter","author":"frack113","status":"test","level":"medium","date":"2022-08-28","modified":"2024-05-31","description":"Detects a script interpreter (Wscript/Cscript) initiating a local network connection to download or execute a script hosted on a shared folder.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/28d190330fe44de6ff4767fc400cc10fa7cd6540/atomics/T1105/T1105.md"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_wscript_cscript_local_connection.yml","techniques":["T1105"],"cves":[]},{"id":"0a23a62d-c5b3-468b-a072-25064a9a8c87","title":"Axios NPM Compromise Indicators - Linux","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the Linux-specific execution chain of the plain-crypto-js malicious npm dependency by Axios NPM package, including payload download via curl and detached execution using nohup and python3.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\nThe dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.006","attack.t1059.004","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_lnx_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.006","T1059.004","T1105"],"cves":[]},{"id":"0dba975d-a193-4ed1-a067-424df57570d1","title":"Uncommon Network Connection Initiated By Certutil.EXE","author":"frack113, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-09-02","modified":"2024-05-31","description":"Detects a network connection initiated by the certutil.exe utility.\nAttackers can abuse the utility in order to download malware or additional payloads.\n","references":["https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_certutil_initiated_connection.yml","techniques":["T1105"],"cves":[]},{"id":"0e8cfe08-02c9-4815-a2f8-0d157b7ed33e","title":"File Download with Headless Browser","author":"Sreeman, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-01-04","modified":"2025-10-07","description":"Detects execution of chromium based browser in headless mode using the \"dump-dom\" command line to download files","references":["https://twitter.com/mrd0x/status/1478234484881436672?s=12","https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.stealth","attack.t1105","attack.t1564.003"],"path":"rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_file_download.yml","techniques":["T1105","T1564.003"],"cves":[]},{"id":"0f0450f3-8b47-441e-a31b-15a91dc243e2","title":"Potential DLL File Download Via PowerShell Invoke-WebRequest","author":"Florian Roth (Nextron Systems), Hieu Tran","status":"test","level":"medium","date":"2023-03-13","modified":"2025-07-18","description":"Detects potential DLL files being downloaded using the PowerShell Invoke-WebRequest or Invoke-RestMethod cmdlets.","references":["https://www.zscaler.com/blogs/security-research/onenote-growing-threat-malware-distribution"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.execution","attack.t1059.001","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_powershell_download_dll.yml","techniques":["T1059.001","T1105"],"cves":[]},{"id":"13db8d2e-7723-4c2c-93c1-a4d36994f7ef","title":"Potential In-Memory Download And Compile Of Payloads","author":"Sohan G (D4rkCiph3r), Red Canary (idea)","status":"test","level":"medium","date":"2023-08-22","modified":null,"description":"Detects potential in-memory downloading and compiling of applets using curl and osacompile as seen used by XCSSET malware","references":["https://redcanary.com/blog/mac-application-bundles/"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.command-and-control","attack.execution","attack.t1059.007","attack.t1105"],"path":"rules/macos/process_creation/proc_creation_macos_susp_in_memory_download_and_compile.yml","techniques":["T1059.007","T1105"],"cves":[]},{"id":"13e6fe51-d478-4c7e-b0f2-6da9b400a829","title":"Suspicious File Downloaded From Direct IP Via Certutil.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-02-15","modified":"2025-12-01","description":"Detects the execution of certutil with certain flags that allow the utility to download files from direct IPs.","references":["https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil","https://forensicitguy.github.io/agenttesla-vba-certutil-download/","https://news.sophos.com/en-us/2021/04/13/compromised-exchange-server-hosting-cryptojacker-targeting-other-exchange-servers/","https://twitter.com/egre55/status/1087685529016193025","https://lolbas-project.github.io/lolbas/Binaries/Certutil/","https://twitter.com/_JohnHammond/status/1708910264261980634","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1027","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_certutil_download_direct_ip.yml","techniques":["T1027","T1105"],"cves":[]},{"id":"185d7418-f250-42d0-b72e-0c8b70661e93","title":"Suspicious Diantz Download and Compress Into a CAB File","author":"frack113","status":"test","level":"medium","date":"2021-11-26","modified":"2022-08-13","description":"Download and compress a remote file and store it in a cab file on local machine.","references":["https://lolbas-project.github.io/lolbas/Binaries/Diantz/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_diantz_remote_cab.yml","techniques":["T1105"],"cves":[]},{"id":"195c1119-ef07-4909-bb12-e66f5e07bf3c","title":"Download from Suspicious Dyndns Hosts","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-11-08","modified":"2023-05-18","description":"Detects download of certain file types from hosts with dynamic DNS names (selected list)","references":["https://www.alienvault.com/blogs/security-essentials/dynamic-dns-security-and-potential-threats"],"logsource":{"category":"proxy"},"tags":["attack.command-and-control","attack.t1105","attack.t1568"],"path":"rules/web/proxy_generic/proxy_download_susp_dyndns.yml","techniques":["T1105","T1568"],"cves":[]},{"id":"19b08b1c-861d-4e75-a1ef-ea0c1baf202b","title":"Suspicious Download Via Certutil.EXE","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-02-15","modified":"2025-12-01","description":"Detects the execution of certutil with certain flags that allow the utility to download files.","references":["https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil","https://forensicitguy.github.io/agenttesla-vba-certutil-download/","https://news.sophos.com/en-us/2021/04/13/compromised-exchange-server-hosting-cryptojacker-targeting-other-exchange-servers/","https://twitter.com/egre55/status/1087685529016193025","https://lolbas-project.github.io/lolbas/Binaries/Certutil/","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1027","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_certutil_download.yml","techniques":["T1027","T1105"],"cves":[]},{"id":"1a433e1d-03d2-47a6-8063-ece992cf4e73","title":"DarkGate - Autoit3.EXE File Creation By Uncommon Process","author":"Micah Babinski","status":"test","level":"medium","date":"2023-10-15","modified":null,"description":"Detects the usage of curl.exe, KeyScramblerLogon, or other non-standard/suspicious processes used to create Autoit3.exe.\nThis activity has been associated with DarkGate malware, which uses Autoit3.exe to execute shellcode that performs\nprocess injection and connects to the DarkGate command-and-control server. Curl, KeyScramblerLogon, and these other\nprocesses consitute non-standard and suspicious ways to retrieve the Autoit3 executable.\n","references":["https://github.security.telekom.com/2023/08/darkgate-loader.html","https://www.kroll.com/en/insights/publications/cyber/microsoft-teams-used-as-initial-access-for-darkgate-malware","https://github.com/pr0xylife/DarkGate/tree/main"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.execution","attack.t1105","attack.t1059","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/DarkGate/file_event_win_malware_darkgate_autoit3_binary_creation.yml","techniques":["T1105","T1059"],"cves":[]},{"id":"1ac8666b-046f-4201-8aba-1951aaec03a3","title":"Command Line Execution with Suspicious URL and AppData Strings","author":"Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community","status":"test","level":"medium","date":"2019-01-16","modified":"2021-11-27","description":"Detects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)","references":["https://www.hybrid-analysis.com/sample/3a1f01206684410dbe8f1900bbeaaa543adfcd07368ba646b499fa5274b9edf6?environmentId=100","https://www.hybrid-analysis.com/sample/f16c729aad5c74f19784a24257236a8bbe27f7cdc4a89806031ec7f1bebbd475?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.command-and-control","attack.t1059.003","attack.t1059.001","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_cmd_http_appdata.yml","techniques":["T1059.003","T1059.001","T1105"],"cves":[]},{"id":"1cf465a1-2609-4c15-9b66-c32dbe4bfd67","title":"Legitimate Application Writing Files In Uncommon Location","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-12-10","modified":null,"description":"Detects legitimate applications writing any type of file to uncommon or suspicious locations that are not typical for application data storage or execution.\nAdversaries may leverage legitimate applications (Living off the Land Binaries - LOLBins) to drop or download malicious files to uncommon locations on the system to evade detection by security solutions.\n","references":["https://lolbas-project.github.io/#/download"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1218","attack.command-and-control","attack.t1105"],"path":"rules/windows/file/file_event/file_event_win_susp_legitimate_app_dropping_in_uncommon_location.yml","techniques":["T1218","T1105"],"cves":[]},{"id":"1d174d38-8fda-4081-a9b6-56d9763c0cd8","title":"Scheduled Task Creation with Curl and PowerShell Execution Combo","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-02-05","modified":null,"description":"Detects the creation of a scheduled task using schtasks.exe, potentially in combination with curl for downloading payloads and PowerShell for executing them.\nThis facilitates executing malicious payloads or connecting with C&C server persistently without dropping the malware sample on the host.\n","references":["https://tria.ge/241015-l98snsyeje/behavioral2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.stealth","attack.t1053.005","attack.t1218","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_schtasks_curl_and_powershell_combo.yml","techniques":["T1053.005","T1218","T1105"],"cves":[]},{"id":"1edff897-9146-48d2-9066-52e8d8f80a2f","title":"Suspicious Invoke-WebRequest Execution With DirectIP","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-04-21","modified":null,"description":"Detects calls to PowerShell with Invoke-WebRequest cmdlet using direct IP access","references":["https://www.huntress.com/blog/critical-vulnerabilities-in-papercut-print-management-software"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_powershell_invoke_webrequest_direct_ip.yml","techniques":["T1105"],"cves":[]},{"id":"214641c2-c579-4ecb-8427-0cf19df6842e","title":"Remote File Download Via Desktopimgdownldr Utility","author":"Tim Rauch, Elastic (idea)","status":"test","level":"medium","date":"2022-09-27","modified":null,"description":"Detects the desktopimgdownldr utility being used to download a remote file. An adversary may use desktopimgdownldr to download arbitrary files as an alternative to certutil.","references":["https://www.elastic.co/guide/en/security/current/remote-file-download-via-desktopimgdownldr-utility.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_desktopimgdownldr_remote_file_download.yml","techniques":["T1105"],"cves":[]},{"id":"21dd6d38-2b18-4453-9404-a0fe4a0cc288","title":"Curl Download And Execute Combination","author":"Sreeman, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2020-01-13","modified":"2024-03-05","description":"Adversaries can use curl to download payloads remotely and execute them. Curl is included by default in Windows 10 build 17063 and later.","references":["https://medium.com/@reegun/curl-exe-is-the-new-rundll32-exe-lolbin-3f79c5f35983"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_cmd_curl_download_exec_combo.yml","techniques":["T1218","T1105"],"cves":[]},{"id":"222720a7-047f-4054-baa5-bab9be757db0","title":"PowerShell MSI Install via WindowsInstaller COM From Remote Location","author":"Meroujan Antonyan (vx3r)","status":"experimental","level":"medium","date":"2025-06-05","modified":null,"description":"Detects the execution of PowerShell commands that attempt to install MSI packages via the\nWindows Installer COM object (`WindowsInstaller.Installer`) hosted remotely.\nThis could be indication of malicious software deployment or lateral movement attempts using Windows Installer functionality.\nAnd the usage of WindowsInstaller COM object rather than msiexec could be an attempt to bypass the detection.\n","references":["https://informationsecuritybuzz.com/the-real-danger-behind-a-simple-windows-shortcut/","https://redcanary.com/blog/threat-intelligence/intelligence-insights-may-2025/","https://www.virustotal.com/gui/file/f9710b0ba4de5fa0e7ec27da462d4d2fc6838eba83a19f23f6617a466bbad457"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1059.001","attack.t1218","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_powershell_comobject_msi_remote.yml","techniques":["T1059.001","T1218","T1105"],"cves":[]},{"id":"25eabf56-22f0-4915-a1ed-056b8dae0a68","title":"Suspicious Dropbox API Usage","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-20","modified":null,"description":"Detects an executable that isn't dropbox but communicates with the Dropbox API","references":["https://app.any.run/tasks/7e906adc-9d11-447f-8641-5f40375ecebb","https://www.zscaler.com/blogs/security-research/new-espionage-attack-molerats-apt-targeting-users-middle-east"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.exfiltration","attack.t1105","attack.t1567.002"],"path":"rules/windows/network_connection/net_connection_win_domain_dropbox_api.yml","techniques":["T1105","T1567.002"],"cves":[]},{"id":"2db0458c-05c9-4069-a26f-77becd9c8c13","title":"Axios NPM Compromise File Creation Indicators - MacOS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects file creation events linked to the Axios NPM supply chain compromise on macOS devices. Axios is a popular JavaScript HTTP client.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"macos","category":"file_event"},"tags":["attack.initial-access","attack.t1195.002","attack.command-and-control","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/file_event_macos_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1105"],"cves":[]},{"id":"2db93a3f-3249-4f73-9e68-0e77a0f8ae7e","title":"Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server","author":"Ahmed Nosir (@egycondor)","status":"experimental","level":"medium","date":"2025-05-29","modified":null,"description":"Detects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line.\nThese parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID.\nThis technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.\n","references":["https://github.com/amidaware/tacticalrmm","https://apophis133.medium.com/powershell-script-tactical-rmm-installation-45afb639eff3"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1219","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_remote_access_tools_tacticalrmm_agent_registration_via_cli.yml","techniques":["T1219","T1105"],"cves":[]},{"id":"2ddef153-167b-4e89-86b6-757a9e65dcac","title":"File Download Via Bitsadmin To A Suspicious Target Folder","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-28","modified":"2025-12-10","description":"Detects usage of bitsadmin downloading a file to a suspicious target folder","references":["https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin","https://isc.sans.edu/diary/22264","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/","https://blog.talosintelligence.com/breaking-the-silence-recent-truebot-activity/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.stealth","attack.t1197","attack.s0190","attack.t1036.003","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_targetfolder.yml","techniques":["T1197","T1036.003","T1105"],"cves":[]},{"id":"3236fcd0-b7e3-4433-b4f8-86ad61a9af2d","title":"PowerShell Download Via Net.WebClient - PowerShell Classic","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2017-03-05","modified":"2026-04-28","description":"Detects PowerShell download activity, via the .DownloadFile() or .DownloadString() methods of the Net.WebClient class.\nThis technique is often abused by attackers to download additional payloads.\n","references":["https://www.trendmicro.com/en_us/research/22/j/lv-ransomware-exploits-proxyshell-in-attack.html"],"logsource":{"product":"windows","category":"ps_classic_start"},"tags":["attack.execution","attack.command-and-control","attack.t1059.001","attack.t1105"],"path":"rules/windows/powershell/powershell_classic/posh_pc_download_via_webclient.yml","techniques":["T1059.001","T1105"],"cves":[]},{"id":"35a05c60-9012-49b6-a11f-6bab741c9f74","title":"Wget Creating Files in Tmp Directory","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","status":"test","level":"medium","date":"2023-06-02","modified":null,"description":"Detects the use of wget to download content in a temporary directory such as \"/tmp\" or \"/var/tmp\"","references":["https://blogs.jpcert.or.jp/en/2023/05/gobrat.html","https://jstnk9.github.io/jstnk9/research/GobRAT-Malware/","https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection","https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/linux/file_event/file_event_lnx_wget_download_file_in_tmp_dir.yml","techniques":["T1105"],"cves":[]},{"id":"3711eee4-a808-4849-8a14-faf733da3612","title":"Greenbug Espionage Group Indicators","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-05-20","modified":"2023-03-09","description":"Detects tools and process executions used by Greenbug in their May 2020 campaign as reported by Symantec","references":["https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/greenbug-espionage-telco-south-asia"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.g0049","attack.execution","attack.t1059.001","attack.command-and-control","attack.t1105","attack.t1036.005","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/Greenbug/proc_creation_win_apt_greenbug_may20.yml","techniques":["T1059.001","T1105","T1036.005"],"cves":[]},{"id":"3aff0be0-7802-4a7e-a4fa-c60c74bc5e1d","title":"Lolbas OneDriveStandaloneUpdater.exe Proxy Download","author":"frack113","status":"test","level":"high","date":"2022-05-28","modified":"2023-08-17","description":"Detects setting a custom URL for OneDriveStandaloneUpdater.exe to download a file from the Internet without executing any\nanomalous executables with suspicious arguments. The downloaded file will be in C:\\Users\\redacted\\AppData\\Local\\Microsoft\\OneDrive\\StandaloneUpdaterreSignInSettingsConfig.json\n","references":["https://lolbas-project.github.io/lolbas/Binaries/OneDriveStandaloneUpdater/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/registry/registry_set/registry_set_lolbin_onedrivestandaloneupdater.yml","techniques":["T1105"],"cves":[]},{"id":"3b2c1059-ae5f-40b6-b5d4-6106d3ac20fe","title":"Hidden Flag Set On File/Directory Via Chflags - MacOS","author":"Omar Khaled (@beacon_exe)","status":"test","level":"medium","date":"2024-08-21","modified":null,"description":"Detects the execution of the \"chflags\" utility with the \"hidden\" flag, in order to hide files on MacOS.\nWhen a file or directory has this hidden flag set, it becomes invisible to the default file listing commands and in graphical file browsers.\n","references":["https://www.sentinelone.com/labs/apt32-multi-stage-macos-trojan-innovates-on-crimeware-scripting-technique/","https://www.welivesecurity.com/2019/04/09/oceanlotus-macos-malware-update/","https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/reports/Unit_42/unit42-wirelurker.pdf","https://ss64.com/mac/chflags.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.credential-access","attack.command-and-control","attack.stealth","attack.t1218","attack.t1564.004","attack.t1552.001","attack.t1105"],"path":"rules/macos/process_creation/proc_creation_macos_chflags_hidden_flag.yml","techniques":["T1218","T1564.004","T1552.001","T1105"],"cves":[]},{"id":"3c7d1587-3b13-439f-9941-7d14313dbdfe","title":"Potential COM Objects Download Cradles Usage - PS Script","author":"frack113","status":"test","level":"medium","date":"2022-12-25","modified":null,"description":"Detects usage of COM objects that can be abused to download files in PowerShell by CLSID","references":["https://learn.microsoft.com/en-us/dotnet/api/system.type.gettypefromclsid?view=net-7.0","https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse?slide=57"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/powershell/powershell_script/posh_ps_download_com_cradles.yml","techniques":["T1105"],"cves":[]},{"id":"42a5f1e7-9603-4f6d-97ae-3f37d130d794","title":"Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-02-15","modified":"2026-03-29","description":"Detects the execution of certutil with certain flags that allow the utility to download files from file-sharing websites.","references":["https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil","https://forensicitguy.github.io/agenttesla-vba-certutil-download/","https://news.sophos.com/en-us/2021/04/13/compromised-exchange-server-hosting-cryptojacker-targeting-other-exchange-servers/","https://twitter.com/egre55/status/1087685529016193025","https://lolbas-project.github.io/lolbas/Binaries/Certutil/","https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/","https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1027","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_certutil_download_file_sharing_domains.yml","techniques":["T1027","T1105"],"cves":[]},{"id":"44143844-0631-49ab-97a0-96387d6b2d7c","title":"File Download Using Notepad++ GUP Utility","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-10","modified":"2023-03-02","description":"Detects execution of the Notepad++ updater (gup) from a process other than Notepad++ to download files.","references":["https://twitter.com/nas_bench/status/1535322182863179776"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_gup_download.yml","techniques":["T1105"],"cves":[]},{"id":"4480827a-9799-4232-b2c4-ccc6c4e9e12b","title":"Suspicious CertReq Command to Download","author":"Christian Burkard (Nextron Systems)","status":"experimental","level":"high","date":"2021-11-24","modified":"2025-10-29","description":"Detects a suspicious CertReq execution downloading a file.\nThis behavior is often used by attackers to download additional payloads or configuration files.\nCertreq is a built-in Windows utility used to request and retrieve certificates from a certification authority (CA). However, it can be abused by threat actors for malicious purposes.\n","references":["https://lolbas-project.github.io/lolbas/Binaries/Certreq/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_certreq_download.yml","techniques":["T1105"],"cves":[]},{"id":"46123129-1024-423e-9fae-43af4a0fa9a5","title":"File Download Via Windows Defender MpCmpRun.EXE","author":"Matthew Matchen","status":"test","level":"high","date":"2020-09-04","modified":"2023-11-09","description":"Detects the use of Windows Defender MpCmdRun.EXE to download files","references":["https://web.archive.org/web/20200903194959/https://twitter.com/djmtshepana/status/1301608169496612866","https://lolbas-project.github.io/lolbas/Binaries/MpCmdRun/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_mpcmdrun_download_arbitrary_file.yml","techniques":["T1218","T1105"],"cves":[]},{"id":"47e0852a-cf81-4494-a8e6-31864f8c86ed","title":"Pandemic Registry Key","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2017-06-01","modified":"2022-10-09","description":"Detects Pandemic Windows Implant","references":["https://wikileaks.org/vault7/#Pandemic","https://twitter.com/MalwareJake/status/870349480356454401"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.command-and-control","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2017/TA/Pandemic/registry_event_apt_pandemic.yml","techniques":["T1105"],"cves":[]},{"id":"54f0434b-726f-48a1-b2aa-067df14516e4","title":"Password Protected ZIP File Opened (Suspicious Filenames)","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-05-09","modified":null,"description":"Detects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.","references":["https://twitter.com/sbousseaden/status/1523383197513379841"],"logsource":{"product":"windows","service":"security"},"tags":["attack.command-and-control","attack.stealth","attack.t1027","attack.t1105","attack.t1036"],"path":"rules/windows/builtin/security/win_security_susp_opened_encrypted_zip_filename.yml","techniques":["T1027","T1105","T1036"],"cves":[]},{"id":"587254ee-a24b-4335-b3cd-065c0f1f4baa","title":"Remote File Download Via Findstr.EXE","author":"Furkan CALISKAN, @caliskanfurkan_, @oscd_initiative, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2020-10-05","modified":"2024-03-05","description":"Detects execution of \"findstr\" with specific flags and a remote share path. This specific set of CLI flags would allow \"findstr\" to download the content of the file located on the remote share as described in the LOLBAS entry.\n","references":["https://lolbas-project.github.io/lolbas/Binaries/Findstr/","https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/","https://gist.github.com/api0cradle/cdd2d0d0ec9abb686f0e89306e277b8f"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.command-and-control","attack.stealth","attack.t1218","attack.t1564.004","attack.t1552.001","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_findstr_download.yml","techniques":["T1218","T1564.004","T1552.001","T1105"],"cves":[]},{"id":"5b80a791-ad9b-4b75-bcc1-ad4e1e89c200","title":"File With Suspicious Extension Downloaded Via Bitsadmin","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-06-28","modified":"2023-05-30","description":"Detects usage of bitsadmin downloading a file with a suspicious extension","references":["https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin","https://isc.sans.edu/diary/22264","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.stealth","attack.t1197","attack.s0190","attack.t1036.003","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_bitsadmin_download_susp_extensions.yml","techniques":["T1197","T1036.003","T1105"],"cves":[]},{"id":"5e3cc4d8-3e68-43db-8656-eaaeefdec9cc","title":"Suspicious Invoke-WebRequest Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-02","modified":"2025-07-18","description":"Detects a suspicious call to Invoke-WebRequest cmdlet where the and output is located in a suspicious location","references":["https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_powershell_invoke_webrequest_download.yml","techniques":["T1105"],"cves":[]},{"id":"5e51acb2-bcbe-435b-99c6-0e3cd5e2aa59","title":"Cisco Stage Data","author":"Austin Clark","status":"test","level":"low","date":"2019-08-12","modified":"2023-01-04","description":"Various protocols maybe used to put data on the device for exfil or infil","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.collection","attack.lateral-movement","attack.command-and-control","attack.exfiltration","attack.t1074","attack.t1105","attack.t1560.001"],"path":"rules/network/cisco/aaa/cisco_cli_moving_data.yml","techniques":["T1074","T1105","T1560.001"],"cves":[]},{"id":"6c0ce3b6-85e2-49d4-9c3f-6e008ce9796e","title":"Suspicious Deno File Written from Remote Source","author":"Josh Nickels, Michael Taggart","status":"experimental","level":"low","date":"2025-05-22","modified":null,"description":"Detects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL.\nThis behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.\n","references":["https://taggart-tech.com/evildeno/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.t1204","attack.t1059.007","attack.command-and-control","attack.t1105"],"path":"rules/windows/file/file_event/file_event_win_creation_deno.yml","techniques":["T1204","T1059.007","T1105"],"cves":[]},{"id":"6d8a7cf1-8085-423b-b87d-7e880faabbdf","title":"File Download Via Nscurl - MacOS","author":"Daniel Cortez","status":"test","level":"medium","date":"2024-06-04","modified":null,"description":"Detects the execution of the nscurl utility in order to download files.","references":["https://www.loobins.io/binaries/nscurl/","https://www.agnosticdev.com/content/how-diagnose-app-transport-security-issues-using-nscurl-and-openssl","https://gist.github.com/nasbench/ca6ef95db04ae04ffd1e0b1ce709cadd"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/macos/process_creation/proc_creation_macos_nscurl_usage.yml","techniques":["T1105"],"cves":[]},{"id":"6f535e01-ca1f-40be-ab8d-45b19c0c8b7f","title":"Import LDAP Data Interchange Format File Via Ldifde.EXE","author":"@gott_cyber","status":"test","level":"medium","date":"2022-09-02","modified":"2023-03-14","description":"Detects the execution of \"Ldifde.exe\" with the import flag \"-i\". The can be abused to include HTTP-based arguments which will allow the arbitrary download of files from a remote server.\n","references":["https://twitter.com/0gtweet/status/1564968845726580736","https://strontic.github.io/xcyclopedia/library/ldifde.exe-979DE101F5059CEC1D2C56967CA2BAC0.html","https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/cc731033(v=ws.11)"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.stealth","attack.t1218","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_ldifde_file_load.yml","techniques":["T1218","T1105"],"cves":[]},{"id":"70ad0861-d1fe-491c-a45f-fa48148a300d","title":"File Download via CertOC.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-05-16","modified":"2023-10-18","description":"Detects when a user downloads a file by using CertOC.exe","references":["https://lolbas-project.github.io/lolbas/Binaries/Certoc/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_certoc_download.yml","techniques":["T1105"],"cves":[]},{"id":"74a12f18-505c-4114-8d0b-8448dd5485c6","title":"PUA - Nimgrab Execution","author":"frack113","status":"test","level":"high","date":"2022-08-28","modified":"2024-11-23","description":"Detects the usage of nimgrab, a tool bundled with the Nim programming framework and used for downloading files.","references":["https://github.com/redcanaryco/atomic-red-team/blob/28d190330fe44de6ff4767fc400cc10fa7cd6540/atomics/T1105/T1105.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_pua_nimgrab.yml","techniques":["T1105"],"cves":[]},{"id":"7a14080d-a048-4de8-ae58-604ce58a795b","title":"Remote File Copy","author":"Ömer Günal","status":"stable","level":"low","date":"2020-06-18","modified":null,"description":"Detects the use of tools that copy files from or to remote systems","references":["https://www.cisa.gov/stopransomware/ransomware-guide"],"logsource":{"product":"linux"},"tags":["attack.command-and-control","attack.lateral-movement","attack.t1105"],"path":"rules/linux/builtin/lnx_file_copy.yml","techniques":["T1105"],"cves":[]},{"id":"7b434893-c57d-4f41-908d-6a17bf1ae98f","title":"Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2017-03-19","modified":"2026-03-29","description":"Detects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.\n","references":["https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_susp_initiated_uncommon_or_suspicious_locations.yml","techniques":["T1105"],"cves":[]},{"id":"7cff77e1-9663-46a3-8260-17f2e1aa9d0a","title":"AppX Package Installation Attempts Via AppInstaller.EXE","author":"frack113","status":"test","level":"medium","date":"2021-11-24","modified":"2023-11-09","description":"Detects DNS queries made by \"AppInstaller.EXE\". The AppInstaller is the default handler for the \"ms-appinstaller\" URI. It attempts to load/install a package from the referenced URL\n","references":["https://twitter.com/notwhickey/status/1333900137232523264","https://lolbas-project.github.io/lolbas/Binaries/AppInstaller/"],"logsource":{"product":"windows","category":"dns_query"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/dns_query/dns_query_win_appinstaller.yml","techniques":["T1105"],"cves":[]},{"id":"8518ed3d-f7c9-4601-a26c-f361a4256a0c","title":"Suspicious Download From File-Sharing Website Via Bitsadmin","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-06-28","modified":"2026-03-29","description":"Detects usage of bitsadmin downloading a file from a suspicious domain","references":["https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin","https://isc.sans.edu/diary/22264","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker","https://www.cisa.gov/uscert/ncas/alerts/aa22-321a","https://www.microsoft.com/en-us/security/blog/2024/01/17/new-ttps-observed-in-mint-sandstorm-campaign-targeting-high-profile-individuals-at-universities-and-research-orgs/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.stealth","attack.t1197","attack.s0190","attack.t1036.003","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_bitsadmin_download_file_sharing_domains.yml","techniques":["T1197","T1036.003","T1105"],"cves":[]},{"id":"8d7e392e-9b28-49e1-831d-5949c6281228","title":"Network Connection Initiated By IMEWDBLD.EXE","author":"frack113","status":"test","level":"high","date":"2022-01-22","modified":"2023-11-09","description":"Detects a network connection initiated by IMEWDBLD.EXE. This might indicate potential abuse of the utility as a LOLBIN in order to download arbitrary files or additional payloads.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-10---windows---powershell-download","https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_imewdbld.yml","techniques":["T1105"],"cves":[]},{"id":"9292293b-8496-4715-9db6-37028dcda4b3","title":"Replace.exe Usage","author":"frack113","status":"test","level":"medium","date":"2022-03-06","modified":"2024-03-13","description":"Detects the use of Replace.exe which can be used to replace file with another file","references":["https://lolbas-project.github.io/lolbas/Binaries/Replace/","https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/replace"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_replace.yml","techniques":["T1105"],"cves":[]},{"id":"94771a71-ba41-4b6e-a757-b531372eaab6","title":"File Download From Browser Process Via Inline URL","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-01-11","modified":"2025-10-27","description":"Detects execution of a browser process with a URL argument pointing to a file with a potentially interesting extension. This can be abused to download arbitrary files or to hide from the user for example by launching the browser in a minimized state.","references":["https://twitter.com/mrd0x/status/1478116126005641220","https://lolbas-project.github.io/lolbas/Binaries/Msedge/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_browsers_inline_file_download.yml","techniques":["T1105"],"cves":[]},{"id":"9801abb8-e297-4dbf-9fbd-57dde0e830ad","title":"File Download And Execution Via IEExec.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-05-16","modified":"2023-11-09","description":"Detects execution of the IEExec utility to download and execute files","references":["https://lolbas-project.github.io/lolbas/Binaries/Ieexec/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_ieexec_download.yml","techniques":["T1105"],"cves":[]},{"id":"992a6cae-db6a-43c8-9cec-76d7195c96fc","title":"Outbound Network Connection Initiated By Script Interpreter","author":"frack113, Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-08-28","modified":"2024-03-13","description":"Detects a script interpreter wscript/cscript opening a network connection to a non-local network. Adversaries may use script to download malicious payloads.","references":["https://github.com/redcanaryco/atomic-red-team/blob/28d190330fe44de6ff4767fc400cc10fa7cd6540/atomics/T1105/T1105.md"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_wscript_cscript_outbound_connection.yml","techniques":["T1105"],"cves":[]},{"id":"9a2d8b3e-f5a1-4c68-9e21-7d9e1cf8a123","title":"Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-13","modified":null,"description":"Detects potential exploitation of remote code execution vulnerability CVE-2025-33053\nby looking for process access that involves legitimate Windows executables (iediagcmd.exe, CustomShellHost.exe)\naccessing suspicious executables hosted on WebDAV shares. This indicates an attacker may be exploiting\nProcess.Start() search order manipulation to execute malicious code from attacker-controlled WebDAV servers\ninstead of legitimate system binaries. The vulnerability allows unauthorized code execution through\nexternal control of file names or paths via WebDAV.\n","references":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053","https://research.checkpoint.com/2025/stealth-falcon-zero-day/"],"logsource":{"product":"windows","category":"process_access"},"tags":["attack.command-and-control","attack.execution","attack.stealth","attack.t1218","attack.lateral-movement","attack.t1105","detection.emerging-threats","cve.2025-33053"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-33053/proc_access_win_exploit_cve_2025_33053.yml","techniques":["T1218","T1105"],"cves":["CVE-2025-33053"]},{"id":"9a517fca-4ba3-4629-9278-a68694697b81","title":"File Download Via Curl.EXE","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-07-05","modified":"2023-02-21","description":"Detects file download using curl.exe","references":["https://web.archive.org/web/20200128160046/https://twitter.com/reegun21/status/1222093798009790464"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_curl_download.yml","techniques":["T1105"],"cves":[]},{"id":"9e4b7d3a-6f2c-4e9a-8d1b-3c5e7a9f2b4d","title":"Potentially Suspicious File Creation by OpenEDR's ITSMService","author":"@kostastsale","status":"experimental","level":"medium","date":"2026-02-19","modified":null,"description":"Detects the creation of potentially suspicious files by OpenEDR's ITSMService process.\nThe ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features.\nWhile legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.\n","references":["https://kostas-ts.medium.com/detecting-abuse-of-openedrs-permissive-edr-trial-a-security-researcher-s-perspective-fc55bf53972c"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1105","attack.lateral-movement","attack.t1570","attack.t1219"],"path":"rules/windows/file/file_event/file_event_win_comodo_itsm_potentially_suspicious_file_creation.yml","techniques":["T1105","T1570","T1219"],"cves":[]},{"id":"a09ee860-31b3-4586-8a68-0ebd74ce0e5f","title":"Axios NPM Compromise Indicators - macOS","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the macOS-specific execution chain of the plain-crypto-js malicious npm dependency in Axios NPM Package, including AppleScript execution via osascript, payload download, permission modification, execution, and cleanup.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.002","attack.t1059.004","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_macos_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.002","T1059.004","T1105"],"cves":[]},{"id":"aa0b3a82-eacc-4ec3-9150-b5a9a3e3f82f","title":"Potential Download/Upload Activity Using Type Command","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-12-14","modified":null,"description":"Detects usage of the \"type\" command to download/upload data from WebDAV server","references":["https://mr0range.com/a-new-lolbin-using-the-windows-type-command-to-upload-download-files-81d7b6179e22"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_cmd_type_arbitrary_file_download.yml","techniques":["T1105"],"cves":[]},{"id":"aa8e035d-7be4-48d3-a944-102aec04400d","title":"Suspicious Extrac32 Execution","author":"frack113","status":"test","level":"medium","date":"2021-11-26","modified":"2022-08-13","description":"Download or Copy file with Extrac32","references":["https://lolbas-project.github.io/lolbas/Binaries/Extrac32/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_extrac32.yml","techniques":["T1105"],"cves":[]},{"id":"aac2fd97-bcba-491b-ad66-a6edf89c71bf","title":"Executable from Webdav","author":"SOC Prime, Adam Swan","status":"test","level":"medium","date":"2020-05-01","modified":"2021-11-27","description":"Detects executable access via webdav6. Can be seen in APT 29 such as from the emulated APT 29 hackathon https://github.com/OTRF/detection-hackathon-apt29/","references":["http://carnal0wnage.attackresearch.com/2012/06/webdav-server-to-download-custom.html","https://github.com/OTRF/detection-hackathon-apt29"],"logsource":{"product":"zeek","service":"http"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/network/zeek/zeek_http_executable_download_from_webdav.yml","techniques":["T1105"],"cves":[]},{"id":"abe06362-a5b9-4371-8724-ebd00cd48a04","title":"Potential Exploitation of RCE Vulnerability CVE-2025-33053","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-06-13","modified":null,"description":"Detects potential exploitation of remote code execution vulnerability CVE-2025-33053\nwhich involves unauthorized code execution via WebDAV through external control of file names or paths.\nThe exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe  by manipulating\ntheir working directories to point to attacker-controlled WebDAV servers, causing them to execute\nmalicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries\nthrough Process.Start() search order manipulation.\n","references":["https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053","https://research.checkpoint.com/2025/stealth-falcon-zero-day/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.execution","attack.stealth","attack.t1218","attack.lateral-movement","attack.t1105","detection.emerging-threats","cve.2025-33053"],"path":"rules-emerging-threats/2025/Exploits/CVE-2025-33053/proc_creation_win_exploit_cve_2025_33053.yml","techniques":["T1218","T1105"],"cves":["CVE-2025-33053"]},{"id":"af491bca-e752-4b44-9c86-df5680533dbc","title":"Finger.EXE Execution","author":"Florian Roth (Nextron Systems), omkar72, oscd.community","status":"test","level":"high","date":"2021-02-24","modified":"2024-06-27","description":"Detects execution of the \"finger.exe\" utility.\nFinger.EXE or \"TCPIP Finger Command\" is an old utility that is still present on modern Windows installation. It Displays information about users on a specified remote computer (typically a UNIX computer) that is running the finger service or daemon.\nDue to the old nature of this utility and the rareness of machines having the finger service. Any execution of \"finger.exe\" can be considered \"suspicious\" and worth investigating.\n","references":["https://twitter.com/bigmacjpg/status/1349727699863011328?s=12","https://app.any.run/tasks/40115012-a919-4208-bfed-41e82cb3dadf/","http://hyp3rlinx.altervista.org/advisories/Windows_TCPIP_Finger_Command_C2_Channel_and_Bypassing_Security_Software.txt"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_finger_execution.yml","techniques":["T1105"],"cves":[]},{"id":"b7cb840c-11f6-47f7-b3ef-5524739c9077","title":"Axios NPM Compromise File Creation Indicators - Linux","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.trendmicro.com/zh_hk/research/26/c/axios-npm-package-compromised.html","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"linux","category":"file_event"},"tags":["attack.initial-access","attack.t1195.002","attack.command-and-control","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/file_event_lnx_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1105"],"cves":[]},{"id":"b86f6dea-0b2f-41f5-bdcc-a057bd19cd6a","title":"File Download From IP Based URL Via CertOC.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-10-18","modified":null,"description":"Detects when a user downloads a file from an IP based URL using CertOC.exe","references":["https://lolbas-project.github.io/lolbas/Binaries/Certoc/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.execution","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_certoc_download_direct_ip.yml","techniques":["T1105"],"cves":[]},{"id":"bb58aa4a-b80b-415a-a2c0-2f65a4c81009","title":"Suspicious Desktopimgdownldr Command","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-07-03","modified":"2021-11-27","description":"Detects a suspicious Microsoft desktopimgdownldr execution with parameters used to download files from the Internet","references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://twitter.com/SBousseaden/status/1278977301745741825"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_desktopimgdownldr_susp_execution.yml","techniques":["T1105"],"cves":[]},{"id":"bbeaed61-1990-4773-bf57-b81dbad7db2d","title":"Curl.EXE Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"low","date":"2022-07-05","modified":"2023-02-21","description":"Detects a curl process start on Windows, which could indicates a file download from a remote location or a simple web request to a remote server","references":["https://web.archive.org/web/20200128160046/https://twitter.com/reegun21/status/1222093798009790464"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_curl_execution.yml","techniques":["T1105"],"cves":[]},{"id":"bcb03938-9f8b-487d-8d86-e480691e1d71","title":"Network Connection Initiated From Users\\Public Folder","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2024-05-31","modified":null,"description":"Detects a network connection initiated from a process located in the \"C:\\Users\\Public\" folder.\nAttacker are known to drop their malicious payloads and malware in this directory as its writable by everyone.\nUse this rule to hunt for potential suspicious or uncommon activity in your environement.\n","references":["https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1105","detection.threat-hunting"],"path":"rules-threat-hunting/windows/network_connection/net_connection_win_susp_initaited_public_folder.yml","techniques":["T1105"],"cves":[]},{"id":"c3dbbc9f-ef1d-470a-a90a-d343448d5875","title":"Suspicious Non-Browser Network Communication With Telegram API","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-05-19","modified":null,"description":"Detects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2","references":["https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/small-sieve/NCSC-MAR-Small-Sieve.pdf"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.exfiltration","attack.t1102","attack.t1567","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_domain_telegram_api_non_browser_access.yml","techniques":["T1102","T1567","T1105"],"cves":[]},{"id":"cafeeba3-01da-4ab4-b6c4-a31b1d9730c7","title":"PrintBrm ZIP Creation of Extraction","author":"frack113","status":"test","level":"high","date":"2022-05-02","modified":null,"description":"Detects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.","references":["https://lolbas-project.github.io/lolbas/Binaries/PrintBrm/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.stealth","attack.t1105","attack.t1564.004"],"path":"rules/windows/process_creation/proc_creation_win_lolbin_printbrm.yml","techniques":["T1105","T1564.004"],"cves":[]},{"id":"cf610c15-ed71-46e1-bdf8-2bd1a99de6c4","title":"Download File To Potentially Suspicious Directory Via Wget","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","status":"test","level":"medium","date":"2023-06-02","modified":null,"description":"Detects the use of wget to download content to a suspicious directory","references":["https://blogs.jpcert.or.jp/en/2023/05/gobrat.html","https://jstnk9.github.io/jstnk9/research/GobRAT-Malware/","https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection","https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/linux/process_creation/proc_creation_lnx_wget_download_suspicious_directory.yml","techniques":["T1105"],"cves":[]},{"id":"d059842b-6b9d-4ed1-b5c3-5b89143c6ede","title":"File Download Via Bitsadmin","author":"Michael Haag, FPT.EagleEye","status":"test","level":"medium","date":"2017-03-09","modified":"2023-02-15","description":"Detects usage of bitsadmin downloading a file","references":["https://blog.netspi.com/15-ways-to-download-a-file/#bitsadmin","https://isc.sans.edu/diary/22264","https://lolbas-project.github.io/lolbas/Binaries/Bitsadmin/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.execution","attack.stealth","attack.t1197","attack.s0190","attack.t1036.003","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml","techniques":["T1197","T1036.003","T1105"],"cves":[]},{"id":"e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97","title":"Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2018-08-30","modified":"2026-03-29","description":"Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.","references":["https://twitter.com/M_haggis/status/900741347035889665","https://twitter.com/M_haggis/status/1032799638213066752","https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker","https://www.cisa.gov/uscert/ncas/alerts/aa22-321a","https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/exfil/Invoke-ExfilDataToGitHub.ps1"],"logsource":{"product":"windows","category":"network_connection"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/network_connection/net_connection_win_susp_file_sharing_domains_susp_folders.yml","techniques":["T1105"],"cves":[]},{"id":"e218595b-bbe7-4ee5-8a96-f32a24ad3468","title":"Suspicious Curl.EXE Download","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2020-07-03","modified":"2023-02-21","description":"Detects a suspicious curl process start on Windows and outputs the requested document to a local file","references":["https://twitter.com/max_mal_/status/1542461200797163522","https://web.archive.org/web/20200128160046/https://twitter.com/reegun21/status/1222093798009790464","https://github.com/pr0xylife/Qakbot/blob/4f0795d79dabee5bc9dd69f17a626b48852e7869/Qakbot_AA_23.06.2022.txt","https://www.volexity.com/blog/2022/07/28/sharptongue-deploys-clever-mail-stealing-browser-extension-sharpext/","https://github.com/redcanaryco/atomic-red-team/blob/0f229c0e42bfe7ca736a14023836d65baa941ed2/atomics/T1105/T1105.md#atomic-test-18---curl-download-file"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_curl_susp_download.yml","techniques":["T1105"],"cves":[]},{"id":"e5144106-8198-4f6e-bfc2-0a551cc8dd94","title":"Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE","author":"Alejandro Houspanossian ('@lekz86')","status":"test","level":"medium","date":"2024-01-02","modified":null,"description":"Detects the execution of concatenated commands via \"cmd.exe\". Pikabot often executes a combination of multiple commands via the command handler \"cmd /c\" in order to download and execute additional payloads.\nCommands such as \"curl\", \"wget\" in order to download extra payloads. \"ping\" and \"timeout\" are abused to introduce delays in the command execution and \"Rundll32\" is also used to execute malicious DLL files.\nIn the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.\n","references":["https://github.com/pr0xylife/Pikabot/blob/7f7723a74ca325ec54c6e61e076acce9a4b20538/Pikabot_30.10.2023.txt","https://github.com/pr0xylife/Pikabot/blob/7f7723a74ca325ec54c6e61e076acce9a4b20538/Pikabot_22.12.2023.txt"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.execution","attack.stealth","attack.t1059.003","attack.t1105","attack.t1218","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/Pikabot/proc_creation_win_malware_pikabot_combined_commands_execution.yml","techniques":["T1059.003","T1105","T1218"],"cves":[]},{"id":"e890acee-d488-420e-8f20-d9b19b3c3d43","title":"Suspicious File Created by ArcSOC.exe","author":"Micah Babinski","status":"experimental","level":"high","date":"2025-11-25","modified":null,"description":"Detects instances where the ArcGIS Server process ArcSOC.exe, which hosts REST services running on an ArcGIS\nserver, creates a file with suspicious file type, indicating that it may be an executable, script file,\nor otherwise unusual.\n","references":["https://reliaquest.com/blog/threat-spotlight-inside-flax-typhoons-arcgis-compromise/","https://enterprise.arcgis.com/en/server/12.0/administer/windows/inside-an-arcgis-server-site.htm"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.persistence","attack.initial-access","attack.execution","attack.stealth","attack.t1127","attack.t1105","attack.t1133"],"path":"rules/windows/file/file_event/file_event_win_arcsoc_susp_file_created.yml","techniques":["T1127","T1105","T1133"],"cves":[]},{"id":"ea34fb97-e2c4-4afb-810f-785e4459b194","title":"Curl Usage on Linux","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2022-09-15","modified":null,"description":"Detects a curl process start on linux, which indicates a file download from a remote location or a simple web request to a remote server","references":["https://www.trendmicro.com/en_us/research/22/i/how-malicious-actors-abuse-native-linux-tools-in-their-attacks.html"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/linux/process_creation/proc_creation_lnx_curl_usage.yml","techniques":["T1105"],"cves":[]},{"id":"eee00933-a761-4cd0-be70-c42fe91731e7","title":"Arbitrary File Download Via GfxDownloadWrapper.EXE","author":"Victor Sergeev, oscd.community","status":"test","level":"medium","date":"2020-10-09","modified":"2023-10-18","description":"Detects execution of GfxDownloadWrapper.exe with a URL as an argument to download file.","references":["https://lolbas-project.github.io/lolbas/HonorableMentions/GfxDownloadWrapper/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_gfxdownloadwrapper_arbitrary_file_download.yml","techniques":["T1105"],"cves":[]},{"id":"ef9dcfed-690c-4c5d-a9d1-482cd422225c","title":"Browser Execution In Headless Mode","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2023-09-12","modified":null,"description":"Detects execution of Chromium based browser in headless mode","references":["https://twitter.com/mrd0x/status/1478234484881436672?s=12","https://www.trendmicro.com/en_us/research/23/e/managed-xdr-investigation-of-ducktail-in-trend-micro-vision-one.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.command-and-control","attack.stealth","attack.t1105","attack.t1564.003"],"path":"rules/windows/process_creation/proc_creation_win_browsers_chromium_headless_exec.yml","techniques":["T1105","T1564.003"],"cves":[]},{"id":"f6c27ecc-d890-4452-80e6-2e274a10e097","title":"Axios NPM Compromise Indicators - Windows","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2026-04-01","modified":null,"description":"Detects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise.\nOn March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.\nThe dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.\nThe attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.\n","references":["https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan","https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html?m=1","https://www.derp.ca/research/axios-npm-supply-chain-rat/","https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections","https://www.virustotal.com/gui/file/e10b1fa84f1d6481625f741b69892780140d4e0e7769e7491e5f4d894c2e0e09"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1195.002","attack.execution","attack.command-and-control","attack.t1059.003","attack.t1059.005","attack.t1105","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Malware/Axios-NPM-Compromise/proc_creation_win_axios_npm_compromise_indicators.yml","techniques":["T1195.002","T1059.003","T1059.005","T1105"],"cves":[]},{"id":"f7b5f842-a6af-4da5-9e95-e32478f3cd2f","title":"MsiExec Web Install","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2018-02-09","modified":"2022-01-07","description":"Detects suspicious msiexec process starts with web addresses as parameter","references":["https://blog.trendmicro.com/trendlabs-security-intelligence/attack-using-windows-installer-msiexec-exe-leads-lokibot/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1218.007","attack.command-and-control","attack.t1105"],"path":"rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml","techniques":["T1218.007","T1105"],"cves":[]},{"id":"f8de9dd5-7a63-4cfd-9d0c-ae124878b5a9","title":"Process Execution From WebDAV Share","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"low","date":"2025-06-13","modified":null,"description":"Detects execution of processes with image paths starting with WebDAV shares (\\\\), which might indicate malicious file execution from remote web shares.\nExecution of processes from WebDAV shares can be a sign of lateral movement or exploitation attempts, especially if the process is not a known legitimate application.\nExploitation Attempt of vulnerabilities like CVE-2025-33053 also involves executing processes from WebDAV paths.\n","references":["https://research.checkpoint.com/2025/stealth-falcon-zero-day/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.command-and-control","attack.lateral-movement","attack.t1105","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_webdav_process_execution.yml","techniques":["T1105"],"cves":[]},{"id":"fc4f4817-0c53-4683-a4ee-b17a64bc1039","title":"Suspicious Desktopimgdownldr Target File","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2020-07-03","modified":"2022-06-02","description":"Detects a suspicious Microsoft desktopimgdownldr file creation that stores a file to a suspicious location or contains a file with a suspicious extension","references":["https://labs.sentinelone.com/living-off-windows-land-a-new-native-file-downldr/","https://twitter.com/SBousseaden/status/1278977301745741825"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.command-and-control","attack.t1105"],"path":"rules/windows/file/file_event/file_event_win_susp_desktopimgdownldr_file.yml","techniques":["T1105"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-43200","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-31201","state":"stale","mapping_types":["primary_impact"]},{"cveID":"CVE-2025-31200","state":"stale","mapping_types":["primary_impact"]},{"cveID":"CVE-2024-23692","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2024-4978","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-48788","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-29300","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-38203","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-7101","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-22518","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-38831","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-38035","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-3519","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2023-20867","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-34362","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-2868","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-27350","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2023-26360","state":"mapped","mapping_types":["secondary_impact"]},{"cveID":"CVE-2022-30190","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2012-0754","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2010-1297","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2016-0984","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2015-8651","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2010-2861","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2017-11292","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2016-4117","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2016-1019","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2015-5119","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2013-0641","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2012-1535","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2011-0611","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2010-0188","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2018-15982","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-44515","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2021-35394","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}