logo

Embracing offensive tooling: Building detections against Koadic using EQL

ID: 590f84be-bc30-54e2-aba3-d22046f368a9

STIX ID: report--590f84be-bc30-54e2-aba3-d22046f368a9

Feed Name: Elastic Security Labs

Threat Score
30/100

Date Published: 2022-06-01

Date Updated: 2026-04-27

...
...

This blog post analyzes the Koadic post-exploitation framework and demonstrates how defenders can detect its behaviors on Windows hosts using Event Query Language (EQL). It describes Koadic's use of living‑off‑the‑land tools (WSH, COM, mshta, rundll32, wmiprvse), common post‑exploitation actions (discovery, UAC bypass, file-based command redirection), and provides concrete EQL queries and macros to identify those behaviors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.