File Download Using ProtocolHandler.exe (104cdb48-a7a8-4ca7-a453-32942c6e5dcb)
Detects usage of "ProtocolHandler" to download files. Downloaded files will be located in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
File Download Using ProtocolHandler.exe (104cdb48-a7a8-4ca7-a453-32942c6e5dcb) | Sigma-Rules | System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | 1 |