Initial Access
T1192 html_urls: HTML-document downloads a file
Execution
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
Defense Evasion
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
Discovery
T1497.001 antisandbox_script_timer: Detected script timer window (indicative of sleep style evasion)
T1016.001 system_network_configuration_discovery: System network configuration discovery detected
Command and Control
T1095 network_icmp: Creates ICMP traffic
Other
no_graphical_activity: No graphic activity
suricata_alert: Malicious traffic detected