Skip to content

Hide Navigation Hide TOC

File Download Using ProtocolHandler.exe (104cdb48-a7a8-4ca7-a453-32942c6e5dcb)

Detects usage of "ProtocolHandler" to download files. Downloaded files will be located in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)

Cluster A Galaxy A Cluster B Galaxy B Level
File Download Using ProtocolHandler.exe (104cdb48-a7a8-4ca7-a453-32942c6e5dcb) Sigma-Rules System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern 1