Skip to content

Commit 9358237

Browse files
authored
.NET ClickOnce detection
1 parent 84ddc82 commit 9358237

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

s1_powerquery_hunting.json

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -404,5 +404,10 @@
404404
"category" : "Malware & Threats",
405405
"name" : "Recent ISO Image Mount Activity Detected",
406406
"query" : "indicator.metadata contains:anycase (\"\\\\Microsoft\\\\Windows\\\\Recent\\\\\") indicator.metadata contains:anycase (\".iso.lnk\", \".img.lnk\", \".vhd.lnk\", \".vhdx.lnk\")\n| group _FirstSeenMs=min(event.time), _LastSeenMs=max(event.time), Count=count() by indicator.name, indicator.metadata, src.process.displayName\n| let _firstSeenNs = _FirstSeenMs * 1000000\n| let _lastSeenNs = _LastSeenMs * 1000000\n| columns \"first.timestamp\" = _firstSeenNs, \"last.timestamp\" = _lastSeenNs, indicator.name, indicator.metadata, src.process.displayName, Count\n| sort -Count\n| limit 100000"
407+
},
408+
{
409+
"category" : "Malware & Threats",
410+
"name" : ".NET ClickOnce installation",
411+
"query" : "src.process.name = \"rundll32.exe\" #cmdline contains:anycase \"ShOpenVerbApplication\" #cmdline contains:anycase (\"http\",\".application\")\n| group _FirstSeenMs=min(event.time), _LastSeenMs=max(event.time), Count=count() by endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.process.cmdline, event.dns.request\n| let _firstSeenNs = _FirstSeenMs * 1000000\n| let _lastSeenNs = _LastSeenMs * 1000000\n| columns \"first.timestamp\" = _firstSeenNs, \"last.timestamp\" = _lastSeenNs, endpoint.name, src.process.user, src.process.parent.name, src.process.name, src.process.cmdline, tgt.process.cmdline, event.dns.request, Count\n| sort -Count\n| limit 100000\n"
407412
}
408413
]

0 commit comments

Comments
 (0)