If you’re not alreadyalerting on
CONHOST.EXE spawning CMD.EXE spawning WGET.EXE
or
CONHOST.EXE spawning CONHOST.EXE spawning CONHOST.EXE
you’re gonna want to close that gap today.
If you’re not alreadyalerting on
CONHOST.EXE spawning CMD.EXE spawning WGET.EXE
or
CONHOST.EXE spawning CONHOST.EXE spawning CONHOST.EXE
you’re gonna want to close that gap today.
@pmelson …wget? Why not curl (which is built-in).
(and I should really update my wget binaries)
@jernej__s @pmelson You will see powershell process downloading data from an external location.
More focus on behaviour - less focus on tooling.