Embracing offensive tooling: Building detections against Koadic using EQL
ID: 590f84be-bc30-54e2-aba3-d22046f368a9
STIX ID: report--590f84be-bc30-54e2-aba3-d22046f368a9
Feed Name: Elastic Security Labs
Threat Score
This blog post analyzes the Koadic post-exploitation framework and demonstrates how defenders can detect its behaviors on Windows hosts using Event Query Language (EQL). It describes Koadic's use of living‑off‑the‑land tools (WSH, COM, mshta, rundll32, wmiprvse), common post‑exploitation actions (discovery, UAC bypass, file-based command redirection), and provides concrete EQL queries and macros to identify those behaviors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
