Skip to content

Hide Navigation Hide TOC

Outbound Network Connection To Public IP Via Winlogon (7610a4ea-c06d-495f-a2ac-0a696abcfd3b)

Detects a "winlogon.exe" process that initiate network communications with public IP addresses

Cluster A Galaxy A Cluster B Galaxy B Level
Outbound Network Connection To Public IP Via Winlogon (7610a4ea-c06d-495f-a2ac-0a696abcfd3b) Sigma-Rules Rundll32 - T1218.011 (045d0922-2310-4e60-b5e4-3302302cb3c5) Attack Pattern 1
Rundll32 - T1218.011 (045d0922-2310-4e60-b5e4-3302302cb3c5) Attack Pattern System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) Attack Pattern 2