Netskope Threat Labs

INDICATOR-SHELLCODE Metasploit payload windows_adduser

IPS-SWG

1 SID: 30471

First seen
September 2022
Last seen
February 2025

Detects Metasploit framework payload activity, indicating use of offensive tooling during an intrusion. Spotting these indicators early helps contain an intrusion before cyberattackers expand access.