

Identifies suspicious file creations in the startup folder of a remote system.

Hijack Legit RDP Session To Move Laterally SEKOIA.IO x Symantec Endpoint Protection on ATT&CK Navigator Exfiltration And Tunneling Tools ExecutionĮxecution of well known tools for data exfiltration and tunneling Related Built-in Rulesīenefit from SEKOIA.IO built-in rules and upgrade Symantec Endpoint Protection with the following detection capabilities out-of-the-box. Symantec Endpoint Protection is a client-server solution that protects laptops, desktops, and servers in your network against malware, risks, and vulnerabilities. Symantec/Broadcom Endpoint Security Overview Release(s): Symantec Network Access Control 5.1, Symantec Network Access Control 5.1.5, Symantec Sygate Enterprise Protection 5.0, Symantec Sygate Enterprise Protection 5.Skyhigh Security Secure Web Gateway (SWG) Product(s): Symantec Network Access Control 5.1, Symantec Sygate Enterprise Protection 5.0, Symantec Sygate Enterprise Protection 5.1 UDP Port 1812: add “ =XXX” in conf.properties.TCP Port 9090: change the port in server.xml and add “ =XXX” in conf.properties.

