This technical guide demonstrates how to detect and hunt AsyncRAT and QuasarRAT infections in enterprise environments. It covers multiple detection methods including identifying default C2 ports (6606, 7707, 8808 for AsyncRAT; 4782 for QuasarRAT), hunting for persistence mechanisms through scheduled tasks and registry run keys,

7m read timeFrom dfir.ch
Post cover image
Table of contents
AsyncRATQuasarRAT

Sort: