Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 1.05 KB

MATCH-S00348.md

File metadata and controls

33 lines (26 loc) · 1.05 KB

Rules: Curl Start Combination

Description

Adversaries can use curl to download payloads remotely and execute them. Curl is included by default in Windows 10 build 17063 and later.

Additional Details

Detail Value
Type Templated Match
Category Command and Control
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Curl Start Combination
Summary Expression User: {{user_username}} executed cURL with a start command on host: {{device_hostname}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0011, _mitreAttackTechnique:T1105

Vendors and Products

Fields Used

Origin Field
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema user_username