Use Of The SFTP.EXE Binary As A LOLBIN (a85ffc3a-e8fd-4040-93bf-78aff284d801)
Detects the usage of the "sftp.exe" binary as a LOLBIN by abusing the "-D" flag
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Use Of The SFTP.EXE Binary As A LOLBIN (a85ffc3a-e8fd-4040-93bf-78aff284d801) | Sigma-Rules | System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | 1 |