logo

Elevate Cyber Defense with Qualys Advanced Hunting

ID: a23184a2-bf6f-58a1-8bd5-89d4892777a1

STIX ID: report--a23184a2-bf6f-58a1-8bd5-89d4892777a1

Feed Name: Qualys Blog

Threat Score
60/100

Date Published: 2024-11-26

Date Updated: 2026-04-28

Author: Ganesh Vetal

...
...

Qualys introduces its EDR Advanced Hunting capability and demonstrates, via a controlled "Detect Only" lab run, how predefined hunting queries can identify a ransomware infection: a downloaded 'WinUpdater.exe' spawns cmd/powershell to create persistence and firewall rules, then launches 'bmatter.exe' which renames files (ransomware behavior). The report provides process/registry/network artifacts, example QQL queries, and investigative steps analysts can use to detect similar threats across endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.