Elevate Cyber Defense with Qualys Advanced Hunting
ID: a23184a2-bf6f-58a1-8bd5-89d4892777a1
STIX ID: report--a23184a2-bf6f-58a1-8bd5-89d4892777a1
Feed Name: Qualys Blog
Qualys introduces its EDR Advanced Hunting capability and demonstrates, via a controlled "Detect Only" lab run, how predefined hunting queries can identify a ransomware infection: a downloaded 'WinUpdater.exe' spawns cmd/powershell to create persistence and firewall rules, then launches 'bmatter.exe' which renames files (ransomware behavior). The report provides process/registry/network artifacts, example QQL queries, and investigative steps analysts can use to detect similar threats across endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
