PULSE NAME
IOC - Komari: The “Monitoring” Tool That Didn't Need Weaponising
WHITE celestre 2026-04-30 Modified: 2026-05-30
1
IOCs
LOW VOLUME
Late in the evening on April 16, 2026 (UTC), Huntress registered a cluster of high-severity detections on a single workstation, [REDACTED-WRKSTN], in one of our partner environments. The Huntress Managed EDR signals told the SOC a familiar story—a cmd.exe spawning as a service, an smbexec.py-style service-name pattern, a Microsoft Defender quarantine on svchost.exe-labeled Behavior:Win32/RegDump.SA—but the tail of the detection chain was new: a PowerShell one-liner pulling an installer from raw.githubusercontent[.]com/komari-monitor/komari-agent and wiring it up as a SYSTEM service called “Windows Update Service”.
Indicators of Compromise (1 / 1 total)
All FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 039e659ade3aa8ee7758c11fdb8fbfffd2491920046d638413cea2042f6d584c 2026-04-30