Techniques
Sample rules
VHD Image Download Via Browser
- source: sigma
- technicques:- t1587
- t1587.001
 
Description
Detects creation of “.vhd”/".vhdx" files by browser processes. Malware can use mountable Virtual Hard Disk “.vhd” files to encapsulate payloads and evade security controls.
Detection logic
condition: selection
selection:
  Image|endswith:
  - \brave.exe
  - \chrome.exe
  - \firefox.exe
  - \iexplore.exe
  - \maxthon.exe
  - \MicrosoftEdge.exe
  - \msedge.exe
  - \msedgewebview2.exe
  - \opera.exe
  - \safari.exe
  - \seamonkey.exe
  - \vivaldi.exe
  - \whale.exe
  TargetFilename|contains: .vhd
