FalconFriday — Detecting MMC abuse using “GrimResource” with MDE — 0xFF24
ID: 9f56c664-53be-54c4-bbf1-9ec4031a5f01
STIX ID: report--9f56c664-53be-54c4-bbf1-9ec4031a5f01
Feed Name: FalconForce
Threat Score
This report examines how MMC (.msc) files can be abused—highlighting the GrimResource technique—to load .NET assemblies from memory and deliver/inject payloads for initial access and AppLocker bypass; it provides three MDE detections to identify MMC loading .NET from memory, suspicious .msc launch contexts (downloads, MOTW, ZIP extraction, Downloads folder), and mmc.exe initiating process injection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
