Skip to content

Hide Navigation Hide TOC

Potentially Suspicious Wuauclt Network Connection (c649a6c7-cd8c-4a78-9c04-000fc76df954)

Detects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections. One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.

Cluster A Galaxy A Cluster B Galaxy B Level
System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern Potentially Suspicious Wuauclt Network Connection (c649a6c7-cd8c-4a78-9c04-000fc76df954) Sigma-Rules 1