
This engagement extended the existing Wazuh monitoring deployment to include a Windows endpoint with focused detection and containment logic for the XWorm remote access trojan. The objective was to demonstrate end to end detection: collect Windows telemetry, match indicators and behaviors tied to XWorm, and automate containment using Wazuh CDB lists and Active Response. The result is a repeatable pattern for adding tailored malware detection and response capabilities to an open source security stack.
XWorm is a stealthy RAT that uses persistence, obfuscated binaries, and common system utilities to blend into normal activity. Detecting it requires not only signature matching but also behavioral correlation across process, file and registry events. The challenge was to create high fidelity detection logic that minimizes false positives while enabling automatic containment. Key constraints included operating in a mixed environment where Windows telemetry needed to be normalized and false positives could disrupt business operations.
XWorm is a stealthy Windows-based Remote Access Trojan designed to evade traditional defenses through script-based execution, in-memory operations, and multi-stage payload delivery. When launched on a Windows endpoint, it relies heavily on PowerShell to load and decrypt its components, establish persistence, and initiate command-and-control activity.
Typical behavior observed during execution includes:
C:\Users\<USER>\AppData\Local\Adobe-Hub\