Jamf Nation
IP Geo-Location Extension Attribute Closely Resembles Keylogger Behavior
IP Geo-Location Extension Attribute Closely Resembles Keylogger Behavior
pia-daemon emits 'ICMP Flood' behavior every minute. This is a 'latency check' which is used for server selection.
The Block64 Discovery Agent uses Impacket's psexec module, scaring SOC analysts everywhere when it's deployed.
Services created as part of this application installation and usage will create or rename files with a .crypt extension.
Podman Desktop writes .vbs to the Startup folder.
Microsoft loves to look like malware, huh?
Another bin with an identity crisis.
Adobe performs...process injection??
What is it with antivirus and weird DNS?
A little wmic enumeration
Nacho dwm
IBM's pcsnp.exe just...what
TFW the vuln scanner runs offensive tools.
Who needs protection? Not LSA!
Nothing to see here
JetBrains queries security tools.
IBM creates WMI false positives
Cisco enumerates your system.
Windows being sus? Inconceivable!
Windows Config Manager CCM.exe runs b64-encoded powershell.
Do you like giant DNS queries? Sophos does.
Who doesn't love CScript?
How to look like malware, by RingCentral
Not the Bloodhound you're thinking of.
Named after legitimate Windows binaries, in the wrong location.
A little LSASS, as a treat.
Ivanti does some weird stuff
EDRs 🤝 Malware Encoded PowerShell
Yet another PowerShell weirdo.
Bizarre DNS requests on Samsung phones.
Palo Alto GP Firewall HIP check runs whoami.exe as SYSTEM.
Not just bad guys run whoami .
McAfee also loves big DNS queries!
Everybody loves a big DNS query!
EaseUS and bizarre Scheduled Tasks.
Avast scans your network on the sly.
SenseNDR base64 encoding
Whoami? HostedAgent, of course!
Random file extensions from iManage
Base64-encoded PowerShell from Azure's own agent!
Guests are not invited to Everyone shares.
It runs whoami because it's lost.
How much can an EDR look like malware?
Yet another base64-loving process.
The Nim language installer binaries in certain versions trigger Windows Defender.
Windows uses random high service ports for a variety of functions.
Bizarre sub-processes.
Windows Terminal runs wsl on startup. Upon launch, Windows Terminal runs wsl --list to find potential Linux profiles to add to its list.
WMIExec-ish NDCC
Adobe Reader for no reason starts a subprocess using the command line "I run".