Techniques
Sample rules
VHD Image Download Via Browser
- source: sigma
- technicques:
- t1587
- t1587.001
Description
Detects creation of “.vhd”/".vhdx" files by browser processes. Malware can use mountable Virtual Hard Disk “.vhd” files to encapsulate payloads and evade security controls.
Detection logic
condition: selection
selection:
Image|endswith:
- \brave.exe
- \chrome.exe
- \firefox.exe
- \iexplore.exe
- \maxthon.exe
- \MicrosoftEdge.exe
- \msedge.exe
- \msedgewebview2.exe
- \opera.exe
- \safari.exe
- \seamonkey.exe
- \vivaldi.exe
- \whale.exe
TargetFilename|contains: .vhd