Unmasking QakBot: A Deep Dive into Osquery for Enhanced Detection and Response
ID: f02347bf-6192-5127-aee1-de2c0ace7bce
STIX ID: report--f02347bf-6192-5127-aee1-de2c0ace7bce
Feed Name: Halcyon Blog
Threat Score
**Executive summary:** This report describes QakBot (a long-running banking trojan) and offers osquery-based detection and response guidance, including example queries targeting suspicious processes, scheduled tasks, filesystem artifacts, and registry changes tied to known QakBot IOCs; it emphasizes QakBot's role as a dropper for ransomware and the need for continuous adaptation of detection rules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
