Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / MALWARE REVERSE / WINDOWS

API Monitor

ObjectiveEnable APIsMeaning
Network / C2getaddrinfo, connect, send, recv, WSAConnect, WSASend, WSARecvDNS, TCP, beaconing
HTTP / WebInternetOpenUrlW, InternetConnectW, HttpSendRequestW, WinHttpSendRequestHTTP/S traffic
Registry PersistenceRegCreateKeyExW, RegSetValueExW, RegOpenKeyExWRun keys, config
File Drop / ReadCreateFileW, WriteFile, ReadFile, MoveFileExWPayload/file activity
Process SpawnCreateProcessW, ShellExecuteExW, WinExecChild execution
InjectionVirtualAllocEx, WriteProcessMemory, CreateRemoteThread, NtCreateThreadExInjection path
CryptoCryptAcquireContextW, CryptEncrypt, CryptDecrypt, BCryptEncryptEncryption/decryption
Drive DiscoveryGetDriveTypeW, GetLogicalDrivesUSB / storage check
Timing / DelaySleep, WaitForSingleObject, SetWaitableTimerDelay / loop
Service AbuseOpenSCManagerW, CreateServiceW, StartServiceWService persistence
Socket Detailbind, listen, accept, closesocketListener / socket lifecycle