Execution
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 suspicious_batch: Suspicious batch
T1059.003 url_cmdline: Cmdline of process contains URL
Defense Evasion
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
Discovery
T1518 locates_browser: Attempts to identify where browsers are installed
Command and Control
T1102.003 references_github: Contains links to cloud services of Github (potentially for malicious payload delivery)
Impact
T1489 net_stop: Stops services through the use of net stop
Other
creates_many_processes: Spawns a lot of processes (over 70)
codepage: Checks the system code page
unexpected_exception: Unexpected exception
require_administrator: Requests administrator privileges