Title:Potentially Suspicious Usage Of Qemu Status:test Description:Detects potentially suspicious execution of the Qemu utility in a Windows environment.
Threat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.
References: -https://securelist.com/network-tunneling-with-qemu/111803/ -https://www.qemu.org/docs/master/system/invocation.html#hxtool-5 Author: Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR) Date: 2024-06-03 modified:None Tags: