Suspicious Curl.EXE Download (e218595b-bbe7-4ee5-8a96-f32a24ad3468)
Detects a suspicious curl process start on Windows and outputs the requested document to a local file
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Suspicious Curl.EXE Download (e218595b-bbe7-4ee5-8a96-f32a24ad3468) | Sigma-Rules | Ingress Tool Transfer - T1105 (e6919abc-99f9-4c6c-95a5-14761e7b2add) | Attack Pattern | 1 |