logo

Unmasking QakBot: A Deep Dive into Osquery for Enhanced Detection and Response

ID: f02347bf-6192-5127-aee1-de2c0ace7bce

STIX ID: report--f02347bf-6192-5127-aee1-de2c0ace7bce

Feed Name: Halcyon Blog

Threat Score
70/100

Date Published: 2023-05-16

Date Updated: 2026-04-28

...
...

**Executive summary:** This report describes QakBot (a long-running banking trojan) and offers osquery-based detection and response guidance, including example queries targeting suspicious processes, scheduled tasks, filesystem artifacts, and registry changes tied to known QakBot IOCs; it emphasizes QakBot's role as a dropper for ransomware and the need for continuous adaptation of detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.