logo

FalconFriday — Detecting MMC abuse using “GrimResource” with MDE — 0xFF24

ID: 9f56c664-53be-54c4-bbf1-9ec4031a5f01

STIX ID: report--9f56c664-53be-54c4-bbf1-9ec4031a5f01

Feed Name: FalconForce

Threat Score
60/100

Date Published: 2024-06-28

Date Updated: 2026-04-27

Author: Gijs Hollestelle

...
...

This report examines how MMC (.msc) files can be abused—highlighting the GrimResource technique—to load .NET assemblies from memory and deliver/inject payloads for initial access and AppLocker bypass; it provides three MDE detections to identify MMC loading .NET from memory, suspicious .msc launch contexts (downloads, MOTW, ZIP extraction, Downloads folder), and mmc.exe initiating process injection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.