LoFP LoFP / legitimate downloads of \".vhd\" files would also trigger this

Techniques

Sample rules

VHD Image Download Via Browser

Description

Detects creation of “.vhd”/".vhdx" files by browser processes. Malware can use mountable Virtual Hard Disk “.vhd” files to encapsulate payloads and evade security controls.

Detection logic

condition: selection
selection:
  Image|endswith:
  - \brave.exe
  - \chrome.exe
  - \firefox.exe
  - \iexplore.exe
  - \maxthon.exe
  - \MicrosoftEdge.exe
  - \msedge.exe
  - \msedgewebview2.exe
  - \opera.exe
  - \safari.exe
  - \seamonkey.exe
  - \vivaldi.exe
  - \whale.exe
  TargetFilename|contains: .vhd