Techniques
Sample rules
DNS Query Request By QuickAssist.EXE
- source: sigma
- technicques:
- t1071
- t1071.001
- t1210
Description
Detects DNS queries initiated by “QuickAssist.exe” to Microsoft Quick Assist primary endpoint that is used to establish a session.
Detection logic
condition: selection
selection:
Image|endswith: \QuickAssist.exe
QueryName|endswith: remoteassistance.support.services.microsoft.com
QuickAssist Execution
- source: sigma
- technicques:
- t1219
Description
Detects the execution of Microsoft Quick Assist tool “QuickAssist.exe”. This utility can be used by attackers to gain remote access.
Detection logic
condition: selection
selection:
Image|endswith: \QuickAssist.exe