Potentially Suspicious Wuauclt Network Connection (c649a6c7-cd8c-4a78-9c04-000fc76df954)
Detects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections. One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | Potentially Suspicious Wuauclt Network Connection (c649a6c7-cd8c-4a78-9c04-000fc76df954) | Sigma-Rules | 1 |