Paths and filesystem accessors :: Velociraptor - Digging deeper!
Tags
attack-pattern: | Data Server - T1583.004 Server - T1584.004 Software - T1592.002 |
Common Information
Type | Value |
---|---|
UUID | 27f34f1b-505b-4fa4-8ca5-6fbf241233cb |
Fingerprint | 3c2e3acbe2b57086 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | March 20, 2022, midnight |
Added to db | Aug. 31, 2024, 2:05 a.m. |
Last updated | Nov. 19, 2024, 7 p.m. |
Headline | Paths and filesystem accessors |
Title | Paths and filesystem accessors :: Velociraptor - Digging deeper! |
Detected Hints/Tags/Attributes | 21/1/10 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://docs.velociraptor.app/blog/2022/2022-03-21-paths/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 104 | ✔ | Velociraptor Blog | https://docs.velociraptor.app/blog/index.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 73 | schemas.microsoft.com |
|
Details | Domain | 2 | hello.zip |
|
Details | File | 33 | c:\windows\system32\notepad.exe |
|
Details | File | 1263 | explorer.exe |
|
Details | File | 380 | notepad.exe |
|
Details | File | 3 | c:\\windows\\notepad.exe |
|
Details | File | 2 | hello.zip |
|
Details | File | 17 | hello.txt |
|
Details | Url | 1 | http://schemas.microsoft.com/netfx/2009/xaml/presentation |
|
Details | Windows Registry Key | 1 | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework |