redcanaryco / atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.
MIT License
9.56k stars 2.77k forks source link

Update T1564.003.yaml #2884

Closed msdlearn closed 1 month ago

msdlearn commented 1 month ago

Details: Launch conhost.exe in "headless" mode, it means that no visible window will pop up on the victim's machine. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.conhost.exe can be used as proxy the execution of arbitrary commands

Testing: Tested successfully in atomic runner