description |
Match Windows Http API call |
rule |
Str_Win32_Http_API |
description |
Escalate priviledges |
rule |
Escalate_priviledges |
description |
Communications over HTTP |
rule |
Network_HTTP |
description |
Code injection with CreateRemoteThread in a remote process |
rule |
Code_injection |
description |
(no description) |
rule |
DebuggerCheck__GlobalFlags |
description |
(no description) |
rule |
DebuggerCheck__QueryInfo |
description |
(no description) |
rule |
DebuggerCheck__RemoteAPI |
description |
(no description) |
rule |
DebuggerHiding__Thread |
description |
(no description) |
rule |
DebuggerHiding__Active |
description |
(no description) |
rule |
ThreadControl__Context |
description |
(no description) |
rule |
SEH__vectored |
description |
Checks if being debugged |
rule |
anti_dbg |
description |
Bypass DEP |
rule |
disable_dep |
description |
File Downloader |
rule |
Network_Downloader |
description |
Match Windows Inet API call |
rule |
Str_Win32_Internet_API |
description |
Install itself for autorun at Windows startup |
rule |
Persistence |
description |
Match Windows Http API call |
rule |
Str_Win32_Http_API |
description |
Escalate priviledges |
rule |
Escalate_priviledges |
description |
Communications over HTTP |
rule |
Network_HTTP |
description |
Code injection with CreateRemoteThread in a remote process |
rule |
Code_injection |
description |
(no description) |
rule |
DebuggerCheck__GlobalFlags |
description |
(no description) |
rule |
DebuggerCheck__QueryInfo |
description |
(no description) |
rule |
DebuggerCheck__RemoteAPI |
description |
(no description) |
rule |
DebuggerHiding__Thread |
description |
(no description) |
rule |
DebuggerHiding__Active |
description |
(no description) |
rule |
ThreadControl__Context |
description |
(no description) |
rule |
SEH__vectored |
description |
Checks if being debugged |
rule |
anti_dbg |
description |
Bypass DEP |
rule |
disable_dep |
description |
File Downloader |
rule |
Network_Downloader |
description |
Match Windows Inet API call |
rule |
Str_Win32_Internet_API |
description |
Install itself for autorun at Windows startup |
rule |
Persistence |
description |
Match Windows Http API call |
rule |
Str_Win32_Http_API |
description |
Escalate priviledges |
rule |
Escalate_priviledges |
description |
Communications over HTTP |
rule |
Network_HTTP |
description |
Code injection with CreateRemoteThread in a remote process |
rule |
Code_injection |
description |
(no description) |
rule |
DebuggerCheck__GlobalFlags |
description |
(no description) |
rule |
DebuggerCheck__QueryInfo |
description |
(no description) |
rule |
DebuggerCheck__RemoteAPI |
description |
(no description) |
rule |
DebuggerHiding__Thread |
description |
(no description) |
rule |
DebuggerHiding__Active |
description |
(no description) |
rule |
ThreadControl__Context |
description |
(no description) |
rule |
SEH__vectored |
description |
Checks if being debugged |
rule |
anti_dbg |
description |
Bypass DEP |
rule |
disable_dep |
description |
File Downloader |
rule |
Network_Downloader |
description |
Match Windows Inet API call |
rule |
Str_Win32_Internet_API |
description |
Install itself for autorun at Windows startup |
rule |
Persistence |