splApache-2.0from splunk/security_content
Cisco NVM - Suspicious Network Connection Initiated via MsXsl
This analytic identifies the use of `msxsl.exe` initiating a network connection to a non-private IP address. Although `msxsl.exe` is a legitimate Microsoft utility used to apply XSLT transformations, adversaries can abuse it to execute arbitrary code or load external resources in an evasive manner. This detection leverages Cisco NVM telemetry to identify potentially malicious use of `msxsl.exe` making network connections that may indicate command and control (C2) or data exfiltration activity.
Quality
67
FP risk
—
Forks
0
Views
1
Rule source🔒 locked
🔒
Sign in to view the rule source
Free accounts can view the source for the top-ranked rules. Create one in seconds — no credit card required.
Sign in →