Severity level
Low-severity Sigma rules
342 community-maintained Sigma detection rules in the library are classified as low severity. Low-severity rules capture weak or noisy signals, useful for correlation and hunting. Coverage spans windows, linux, macos. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
A Member Was Added to a Security-Enabled Global Group
lowDetects activity when a member is added to a security-enabled global group
windows
A Member Was Removed From a Security-Enabled Global Group
lowDetects activity when a member is removed from a security-enabled global group
windows
A Security-Enabled Global Group Was Deleted
lowDetects activity when a security-enabled global group is deleted
windows
Access To .Reg/.Hive Files By Uncommon Applications
lowDetects file access requests to files ending with either the ".hive"/".reg" extension, usually associated with Windows Registry backups.
windows · file_access
Access To ADMIN$ Network Share
lowDetects access to ADMIN$ network share
windows
Access To Browser Credential Files By Uncommon Applications
lowDetects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
windows · file_access
Access To Browser Credential Files By Uncommon Applications - Security
lowDetects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing This rule requires heavy baselining before usage.
windows
Access To Chromium Browsers Sensitive Files By Uncommon Applications
lowDetects file access requests to chromium based browser sensitive files by uncommon processes. Could indicate potential attempt of stealing sensitive information.
windows · file_access
Access To Windows Outlook Mail Files By Uncommon Applications
lowDetects file access requests to Windows Outlook Mail by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
windows · file_access
Active Directory Certificate Services Denied Certificate Enrollment Request
lowDetects denied requests by Active Directory Certificate Services. Example of these requests denial include issues with permissions on the certificate template or invalid signatures.
windows
Active Directory Computers Enumeration With Get-AdComputer
lowDetects usage of the "Get-AdComputer" to enumerate Computers or properties within Active Directory.
windows · ps_script
Active Directory Group Enumeration With Get-AdGroup
lowDetects usage of the "Get-AdGroup" cmdlet to enumerate Groups within Active Directory
windows · ps_script
AD Groups Or Users Enumeration Using PowerShell - PoshModule
lowAdversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
windows · ps_module
AD Groups Or Users Enumeration Using PowerShell - ScriptBlock
lowAdversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
windows · ps_script
ADCS Certificate Template Configuration Vulnerability
lowDetects certificate creation with template allowing risk permission subject
windows
Add or Remove Computer from DC
lowDetects the creation or removal of a computer. Can be used to detect attacks such as DCShadow via the creation of a new SPN.
windows
Admin User Remote Logon
lowDetect remote login by Administrator user (depending on internal pattern).
windows
ADS Zone.Identifier Deleted
lowDetects the deletion of the "Zone.Identifier" ADS. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
windows · file_delete
Amsi.DLL Load By Uncommon Process
lowDetects loading of Amsi.dll by uncommon processes
windows · image_load
Application Uninstalled
lowAn application has been removed. Check if it is critical.
windows
Audio Capture
lowDetects attempts to record audio using the arecord and ecasound utilities.
linux
Automated Collection Bookmarks Using Get-ChildItem PowerShell
lowAdversaries may enumerate browser bookmarks to learn more about compromised hosts. Browser bookmarks may reveal personal information about users (ex: banking sites, interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
windows · ps_script
AWS EC2 VM Export Failure
lowAn attempt to export an AWS EC2 instance has been detected. A VM Export might indicate an attempt to extract information from an instance.
aws
AWS EKS Cluster Created or Deleted
lowIdentifies when an EKS cluster is created or deleted.
aws
AWS ElastiCache Security Group Created
lowDetects when an ElastiCache security group has been created.
aws
AWS ElastiCache Security Group Modified or Deleted
lowIdentifies when an ElastiCache security group has been modified or deleted.
aws
AWS Glue Development Endpoint Activity
lowDetects possible suspicious glue development endpoint activity.
aws
AWS New Lambda Layer Attached
lowDetects when a user attached a Lambda layer to an existing Lambda function. A malicious Lambda layer could execute arbitrary code in the context of the function's IAM role. This would give an adversary access to resources that the function has access to.
aws
AWS Route 53 Domain Transfer Lock Disabled
lowDetects when a transfer lock was removed from a Route 53 domain. It is recommended to refrain from performing this action unless intending to transfer the domain to a different registrar.
aws
AWS Route 53 Domain Transferred to Another Account
lowDetects when a request has been made to transfer a Route 53 domain to another AWS account.
aws
AWS S3 Data Management Tampering
lowDetects when a user tampers with S3 data management in Amazon Web Services.
aws
AWS STS AssumeRole Misuse
lowIdentifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
aws
AWS STS GetSessionToken Misuse
lowIdentifies the suspicious use of GetSessionToken. Tokens could be created and used by attackers to move laterally and escalate privileges.
aws
Azure AD Only Single Factor Authentication Required
lowDetect when users are authenticating without MFA being required.
azure
Azure Container Registry Created or Deleted
lowDetects when a Container Registry is created or deleted.
azure
Azure Kubernetes Cluster Created or Deleted
lowDetects when a Azure Kubernetes Cluster is created or deleted.
azure
Azure Sign-In With Axios User Agent
lowDetects sign-in attempts in Azure/Entra ID logs where the user agent contains "axios", indicating potential use of automated credential harvesting or AiTM phishing infrastructure. Axios is a Node.js HTTP client abused to intercept and replay stolen credentials and MFA tokens. When triaging results, analysts should: - Check the sign-in risk level, MFA status, and conditional access results for signs of bypass. - Look for sign-ins from unusual locations or IPs, especially if the same IP targets multiple accounts. - Prioritize successful sign-ins over failed ones, as they may indicate a completed credential replay or AiTM attack.
azure
Bash Interactive Shell
lowDetects execution of the bash shell with the interactive flag "-i".
linux · process_creation
Bitbucket Project Secret Scanning Allowlist Added
lowDetects when a secret scanning allowlist rule is added for projects.
bitbucket
Bitbucket Secret Scanning Rule Deleted
lowDetects when secret scanning rule is deleted for the project or repository.
bitbucket
BitLockerTogo.EXE Execution
lowDetects the execution of "BitLockerToGo.EXE". BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system. This is a rarely used application and usage of it at all is worth investigating. Malware such as Lumma stealer has been seen using this process as a target for process hollowing.
windows · process_creation
BITS Client BitsProxy DLL Loaded By Uncommon Process
lowDetects an uncommon process loading the "BitsProxy.dll". This DLL is used when the BITS COM instance or API is used. This detection can be used to hunt for uncommon processes loading this DLL in your environment. Which may indicate potential suspicious activity occurring.
windows · image_load
Browser Execution In Headless Mode
lowDetects execution of Chromium based browser in headless mode
windows · process_creation
bXOR Operator Usage In PowerShell Command Line - PowerShell Classic
lowDetects powershell execution with that make use of to the bxor (Bitwise XOR). Attackers might use as an alternative obfuscation method to Base64 encoded commands. Investigate the CommandLine and process tree to determine if the activity is malicious.
windows · ps_classic_start
Capabilities Discovery - Linux
lowDetects usage of "getcap" binary. This is often used during recon activity to determine potential binaries that can be abused as GTFOBins or other.
linux · process_creation
Change Default File Association Via Assoc
lowDetects file association changes using the builtin "assoc" command. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Applications can modify the file association for a given file extension to call an arbitrary program when a file with the given extension is opened.
windows · process_creation
Cisco BGP Authentication Failures
lowDetects BGP failures which may be indicative of brute force attacks to manipulate routing
cisco
Cisco Collect Data
lowCollect pertinent data from the configuration files
cisco
Cisco Discovery
lowFind information about network devices that is not stored in config files
cisco
Cisco LDP Authentication Failures
lowDetects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
cisco
Cisco Stage Data
lowVarious protocols maybe used to put data on the device for exfil or infil
cisco
Cleartext Protocol Usage
lowEnsure that all account usernames and authentication credentials are transmitted across networks using encrypted channels. Ensure that an encryption is used for all sensitive information in transit. Ensure that an encrypted channels is used for all administrative account access.
firewall
Cleartext Protocol Usage Via Netflow
lowEnsure that all account usernames and authentication credentials are transmitted across networks using encrypted channels Ensure that an encryption is used for all sensitive information in transit. Ensure that an encrypted channels is used for all administrative account access.
Clipboard Collection of Image Data with Xclip Tool
lowDetects attempts to collect image data stored in the clipboard from users with the usage of xclip tool. Xclip has to be installed. Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.
linux
Clipboard Collection with Xclip Tool
lowDetects attempts to collect data stored in the clipboard from users with the usage of xclip tool. Xclip has to be installed. Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.
linux · process_creation
Clipboard Collection with Xclip Tool - Auditd
lowDetects attempts to collect data stored in the clipboard from users with the usage of xclip tool. Xclip has to be installed. Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.
linux
CMD Shell Output Redirect
lowDetects the use of the redirection character ">" to redirect information on the command line. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
windows · process_creation
CodeIntegrity - Unmet Signing Level Requirements By File Under Validation
lowDetects attempted file load events that did not meet the signing level requirements. It often means the file's signature is revoked or a signature with the Lifetime Signing EKU has expired. This event is best correlated with EID 3089 to determine the error of the validation.
windows
CodePage Modification Via MODE.COM
lowDetects a CodePage modification using the "mode.com" utility. This behavior has been used by threat actors behind Dharma ransomware.
windows · process_creation
Command Executed Via Run Dialog Box - Registry
lowDetects execution of commands via the run dialog box on Windows by checking values of the "RunMRU" registry key. This technique was seen being abused by threat actors to deceive users into pasting and executing malicious commands, often disguised as CAPTCHA verification steps.
windows · registry_set
Compress-Archive Cmdlet Execution
lowDetects PowerShell scripts that make use of the "Compress-Archive" cmdlet in order to compress folders and files. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_script
Compressed File Creation Via Tar.EXE
lowDetects execution of "tar.exe" in order to create a compressed file. Adversaries may abuse various utilities to compress or encrypt data before exfiltration.
windows · process_creation
Compressed File Extraction Via Tar.EXE
lowDetects execution of "tar.exe" in order to extract compressed file. Adversaries may abuse various utilities in order to decompress data to avoid detection.
windows · process_creation
Connection Proxy
lowDetects setting proxy configuration
linux · process_creation
Container Residence Discovery Via Proc Virtual FS
lowDetects potential container discovery via listing of certain kernel features in the "/proc" virtual filesystem
linux · process_creation
Container With A hostPath Mount Created
lowDetects creation of a container with a hostPath mount. A hostPath volume mounts a directory or a file from the node to the container. Attackers who have permissions to create a new pod in the cluster may create one with a writable hostPath volume and chroot to escape to the underlying node.
kubernetes · application
Creation Of A Local User Account
lowDetects the creation of a new user account. Such accounts may be used for persistence that do not require persistent remote access tools to be deployed on the system.
macos · process_creation
Creation of an Executable by an Executable
lowDetects the creation of an executable by another executable.
windows · file_event
Crontab Enumeration
lowDetects usage of crontab to list the tasks of the user
linux · process_creation
Curl Usage on Linux
lowDetects a curl process start on linux, which indicates a file download from a remote location or a simple web request to a remote server
linux · process_creation
Curl.EXE Execution
lowDetects a curl process start on Windows, which could indicates a file download from a remote location or a simple web request to a remote server
windows · process_creation
CVE-2023-40477 Potential Exploitation - .REV File Creation
lowDetects the creation of ".rev" files by WinRAR. Could be indicative of potential exploitation of CVE-2023-40477. Look for a suspicious execution shortly after creation or a WinRAR application crash.
windows · file_event
Data Compressed
lowAn adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
linux
Data Copied To Clipboard Via Clip.EXE
lowDetects the execution of clip.exe in order to copy data to the clipboard. Adversaries may collect data stored in the clipboard from users copying information within or between applications.
windows · process_creation
DD File Overwrite
lowDetects potential overwriting and deletion of a file using DD.
linux · process_creation
Decode Base64 Encoded Text
lowDetects usage of base64 utility to decode arbitrary base64-encoded text
linux · process_creation
Decode Base64 Encoded Text -MacOs
lowDetects usage of base64 utility to decode arbitrary base64-encoded text
macos · process_creation
Deployment Deleted From Kubernetes Cluster
lowDetects the removal of a deployment from a Kubernetes cluster. This could indicate disruptive activity aiming to impact business operations.
kubernetes · application
Directory Removal Via Rmdir
lowDetects execution of the builtin "rmdir" command in order to delete directories. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
windows · process_creation
DirLister Execution
lowDetect the usage of "DirLister.exe" a utility for quickly listing folder or drive contents. It was seen used by BlackCat ransomware to create a list of accessible directories and files.
windows · process_creation
Discovery of a System Time
lowIdentifies use of various commands to query a systems time. This technique may be used before executing a scheduled task or to discover the time zone of a target system.
windows · process_creation
DMP/HDMP File Creation
lowDetects the creation of a file with the ".dmp"/".hdmp" extension. Often created by software during a crash. Memory dumps can sometimes contain sensitive information such as credentials. It's best to determine the source of the crash.
windows · file_event
DMSA Link Attributes Modified
lowDetects modification of dMSA link attributes (msDS-ManagedAccountPrecededByLink) via PowerShell scripts. This command line pattern could be an indicator an attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.
windows · ps_script
DNS Events Related To Mining Pools
lowIdentifies clients that may be performing DNS lookups associated with common currency mining pools.
zeek
DNS Query Request By QuickAssist.EXE
lowDetects DNS queries initiated by "QuickAssist.exe" to Microsoft Quick Assist primary endpoint that is used to establish a session.
windows · dns_query
DNS Query Request To OneLaunch Update Service
lowDetects DNS query requests to "update.onelaunch.com". This domain is associated with the OneLaunch adware application. When the OneLaunch application is installed it will attempt to get updates from this domain.
windows · dns_query
DNS Query To Ufile.io
lowDetects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration
windows · dns_query
DNS Query To Ufile.io - DNS Client
lowDetects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration
windows
DNS Request From Windows Script Host
lowDetects unusual domain resolutions originating from CScript/WScript that can identify malicious javascript files executing in an environment, often as a result from a phishing or watering hole attack.
windows · dns_query
DNS Server Discovery Via LDAP Query
lowDetects DNS server discovery via LDAP query requests from uncommon applications
windows · dns_query
Docker Container Discovery Via Dockerenv Listing
lowDetects listing or file reading of ".dockerenv" which can be a sing of potential container discovery
linux · process_creation
Download From Suspicious TLD - Blacklist
lowDetects download of certain file types from hosts in suspicious TLDs
proxy
Download From Suspicious TLD - Whitelist
lowDetects executable downloads from suspicious remote systems
proxy
Dynamic CSharp Compile Artefact
lowWhen C# is compiled dynamically, a .cmdline file will be created as a part of the process. Certain processes are not typically observed compiling C# code, but can do so without touching disk. This can be used to unpack a payload for execution
windows · file_event
End User Consent
lowDetects when an end user consents to an application
azure
ETW Logging Disabled For rpcrt4.dll
lowDetects changes to the "ExtErrorInformation" key in order to disable ETW logging for rpcrt4.dll
windows · registry_set
ETW Logging Disabled For SCM
lowDetects changes to the "TracingDisabled" key in order to disable ETW logging for services.exe (SCM)
windows · registry_set
EvilTokens PhaaS Kit Phishing Related Request - Proxy
lowDetects outbound web proxy requests to URLs matching the EvilTokens Phishing-as-a-Service (PhaaS) kit infrastructure. Specifically Cloudflare Workers and Railway.app domains used in OAuth device code authorization phishing attacks. This indicates a user has clicked a phishing link.
proxy
Exports Registry Key To a File
lowDetects the export of the target Registry key to a file.
windows · process_creation
External Disk Drive Or USB Storage Device Was Recognized By The System
lowDetects external disk drives or plugged-in USB devices.
windows
Failed Authentications From Countries You Do Not Operate Out Of
lowDetect failed authentications from countries you do not operate out of.
azure
File And SubFolder Enumeration Via Dir Command
lowDetects usage of the "dir" command part of Windows CMD with the "/S" command line flag in order to enumerate files in a specified directory and all subdirectories.
windows · process_creation
File Creation Date Changed to Another Year
lowDetects when the file creation time is changed to a year before 2020. Attackers may change the file creation time of a backdoor to make it look like it was installed with the operating system. Note that many processes legitimately change the creation time of a file; it does not necessarily indicate malicious activity. In order to use this rule in production, it is recommended first baseline normal behavior in your environment and then tune the rule accordingly. Hunting Recommendation: Focus on files with creation times set to years significantly before the current date, especially those in user-writable directories. Correlate with process execution logs to identify the source of the modification and investigate any unsigned or suspicious binaries involved.
windows · file_change
File Deletion Via Del
lowDetects execution of the builtin "del"/"erase" commands in order to delete files. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
windows · process_creation
File or Folder Permissions Change
lowDetects file and folder permission changes.
linux
Files Added To An Archive Using Rar.EXE
lowDetects usage of "rar" to add files to an archive for potential compression. An adversary may compress data (e.g. sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · process_creation
Firewall Configuration Discovery Via Netsh.EXE
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
Firewall Rule Modified In The Windows Firewall Exception List
lowDetects when a rule has been modified in the Windows firewall exception list
windows
Fsutil Drive Enumeration
lowAttackers may leverage fsutil to enumerated connected drives.
windows · process_creation
Gatekeeper Bypass via Xattr
lowDetects macOS Gatekeeper bypass via xattr utility
macos · process_creation
Github New Secret Created
lowDetects when a user creates action secret for the organization, environment, codespaces or repository.
github
Github Push Protection Bypass Detected
lowDetects when a user bypasses the push protection on a secret detected by secret scanning.
github
GitHub Repository Archive Status Changed
lowDetects when a GitHub repository is archived or unarchived, which may indicate unauthorized changes to repository status.
github
GitHub Repository Pages Site Changed to Public
lowDetects when a GitHub Pages site of a repository is made public. This usually is part of a publishing process but could indicate or lead to potential unauthorized exposure of sensitive information or code.
github
Github Self Hosted Runner Changes Detected
lowA self-hosted runner is a system that you deploy and manage to execute jobs from GitHub Actions on GitHub.com. This rule detects changes to self-hosted runners configurations in the environment. The self-hosted runner configuration changes once detected, it should be validated from GitHub UI because the log entry may not provide full context.
github
Google Cloud Storage Buckets Enumeration
lowDetects when storage bucket is enumerated in Google Cloud.
gcp
Guest Account Enabled Via Sysadminctl
lowDetects attempts to enable the guest account using the sysadminctl utility
macos · process_creation
GUI Input Capture - macOS
lowDetects attempts to use system dialog prompts to capture user credentials
macos · process_creation
HH.EXE Execution
lowDetects the execution of "hh.exe" to open ".chm" files.
windows · process_creation
Hidden Files and Directories
lowDetects adversary creating hidden file or directory, by detecting directories or files with . as the first character
linux
Host Without Firewall
lowHost Without Firewall. Alert means not complied. Sigma for Qualys vulnerability scanner. Scan type - Vulnerability Management.
qualys
HTML File Opened From Download Folder
lowDetects web browser process opening an HTML file from a user's Downloads folder. This behavior is could be associated with phishing attacks where threat actors send HTML attachments to users. When a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware. During investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.
windows · process_creation
Huawei BGP Authentication Failures
lowDetects BGP failures which may be indicative of brute force attacks to manipulate routing.
huawei
Import New Module Via PowerShell CommandLine
lowDetects usage of the "Import-Module" cmdlet in order to add new Cmdlets to the current PowerShell session
windows · process_creation
Indirect Command Execution By Program Compatibility Wizard
lowDetect indirect command execution via Program Compatibility Assistant pcwrun.exe
windows · process_creation
Insensitive Subfolder Search Via Findstr.EXE
lowDetects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.
windows · process_creation
Install Root Certificate
lowDetects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s
linux · process_creation
Interesting Service Enumeration Via Sc.EXE
lowDetects the enumeration and query of interesting and in some cases sensitive services on the system via "sc.exe". Attackers often try to enumerate the services currently running on a system in order to find different attack vectors.
windows · process_creation
JAMF MDM Execution
lowDetects execution of the "jamf" binary to create user accounts and run commands. For example, the binary can be abused by attackers on the system in order to bypass security controls or remove application control polices.
macos · process_creation
JScript Compiler Execution
lowDetects the execution of the "jsc.exe" (JScript Compiler). Attacker might abuse this in order to compile JScript files on the fly and bypassing application whitelisting.
windows · process_creation
Juniper BGP Missing MD5
lowDetects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.
juniper
Kubernetes Secrets Enumeration
lowDetects enumeration of Kubernetes secrets.
kubernetes · application
Kubernetes Unauthorized or Unauthenticated Access
lowDetects when a request to the Kubernetes API is rejected due to lack of authorization or due to an expired authentication token being used. This may indicate an attacker attempting to leverage credentials they have obtained.
kubernetes
Linux Capabilities Discovery
lowDetects attempts to discover the files with setuid/setgid capability on them. That would allow adversary to escalate their privileges.
linux
Linux Doas Tool Execution
lowDetects the doas tool execution in linux host platform. This utility tool allow standard users to perform tasks as root, the same way sudo does.
linux · process_creation
Linux Network Service Scanning - Auditd
lowDetects enumeration of local or remote network services.
linux
Linux Network Service Scanning Tools Execution
lowDetects execution of network scanning and reconnaisance tools. These tools can be used for the enumeration of local or remote network services for example.
linux · process_creation
Linux Package Uninstall
lowDetects linux package removal using builtin tools such as "yum", "apt", "apt-get" or "dpkg".
linux · process_creation
Linux Remote System Discovery
lowDetects the enumeration of other remote systems.
linux · process_creation
Linux Setgid Capability Set on a Binary via Setcap Utility
lowDetects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
linux · process_creation
Linux Setuid Capability Set on a Binary via Setcap Utility
lowDetects the use of the 'setcap' utility to set the 'setuid' capability (cap_setuid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of user IDs (UIDs), including setting its current UID to a value that would otherwise be restricted (i.e. UID 0, the root user). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
linux · process_creation
Linux Sudo Chroot Execution
lowDetects the execution of 'sudo' command with '--chroot' option, which is used to change the root directory for command execution. Attackers may use this technique to evade detection and execute commands in a modified environment. This can be part of a privilege escalation strategy, as it allows the execution of commands with elevated privileges in a controlled environment as seen in CVE-2025-32463. While investigating, look out for unusual or unexpected use of 'sudo --chroot' in conjunction with other commands or scripts such as execution from temporary directories or unusual user accounts.
linux · process_creation
Load Of RstrtMgr.DLL By An Uncommon Process
lowDetects the load of RstrtMgr DLL (Restart Manager) by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes.
windows · image_load
Local Accounts Discovery
lowLocal accounts, System Owner/User discovery using operating systems utilities
windows · process_creation
Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet
lowDetects execution of "Get-NetFirewallRule" or "Show-NetFirewallRule" to enumerate the local firewall rules on a host.
windows · ps_module
Local Groups Discovery - Linux
lowDetects enumeration of local system groups. Adversaries may attempt to find local system groups and permission settings
linux · process_creation
Local Groups Reconnaissance Via Wmic.EXE
lowDetects the execution of "wmic" with the "group" flag. Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.
windows · process_creation
Local System Accounts Discovery - Linux
lowDetects enumeration of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.
linux · process_creation
Local System Accounts Discovery - MacOs
lowDetects enumeration of local system accounts on MacOS systems. This can be used by attackers to identify accounts for lateral movement or privilege escalation.
macos · process_creation
Local User Creation
lowDetects local user creation on Windows servers, which shouldn't happen in an Active Directory environment. Apply this Sigma Use Case on your Windows server logs and not on your DC logs.
windows
MacOS Network Service Scanning
lowDetects enumeration of local or remote network services.
macos · process_creation
Malicious Windows Script Components File Execution by TAEF Detection
lowWindows Test Authoring and Execution Framework (TAEF) framework allows you to run automation by executing tests files written on different languages (C, C#, Microsoft COM Scripting interfaces Adversaries may execute malicious code (such as WSC file with VBScript, dll and so on) directly by running te.exe
windows · process_creation
MaxMpxCt Registry Value Changed
lowDetects changes to the "MaxMpxCt" registry value. MaxMpxCt specifies the maximum outstanding network requests for the server per client, which is used when negotiating a Server Message Block (SMB) connection with a client. Note if the value is set beyond 125 older Windows 9x clients will fail to negotiate. Ransomware threat actors and operators (specifically BlackCat) were seen increasing this value in order to handle a higher volume of traffic.
windows · registry_set
Microsoft Excel Add-In Loaded
lowDetects Microsoft Excel loading an Add-In (.xll) file
windows · image_load
Microsoft Word Add-In Loaded
lowDetects Microsoft Word loading an Add-In (.wll) file which can be used by threat actors for initial access or persistence.
windows · image_load
Modification of IE Registry Settings
lowDetects modification of the registry settings used for Internet Explorer and other Windows components that use these settings. An attacker can abuse this registry key to add a domain to the trusted sites Zone or insert JavaScript for persistence
windows · registry_set
Msiexec.EXE Initiated Network Connection Over HTTP
lowDetects a network connection initiated by an "Msiexec.exe" process over port 80 or 443. Adversaries might abuse "msiexec.exe" to install and execute remotely hosted packages. Use this rule to hunt for potentially anomalous or suspicious communications.
windows · network_connection
MSSQL Server Failed Logon
lowDetects failed logon attempts from clients to MSSQL server.
windows
Mstsc.EXE Execution With Local RDP File
lowDetects potential RDP connection via Mstsc using a local ".rdp" file
windows · process_creation
Named Pipe Created Via Mkfifo
lowDetects the creation of a new named pipe using the "mkfifo" utility
linux · process_creation
Net.EXE Execution
lowDetects execution of "Net.EXE".
windows · process_creation
Network Connection Initiated By PowerShell Process
lowDetects a network connection that was initiated from a PowerShell process. Often times malicious powershell scripts download additional payloads or communicate back to command and control channels via uncommon ports or IPs. Use this rule as a basis for hunting for anomalies.
windows · network_connection
Network Connection Initiated To Mega.nz
lowDetects a network connection initiated by a binary to "api.mega.co.nz". Attackers were seen abusing file sharing websites similar to "mega.nz" in order to upload/download additional payloads.
windows · network_connection
Network Sniffing - Linux
lowNetwork sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
linux
New BITS Job Created Via Bitsadmin
lowDetects the creation of a new bits job by Bitsadmin
windows
New BITS Job Created Via PowerShell
lowDetects the creation of a new bits job by PowerShell
windows
New Cron File Created
lowDetects the creation of cron files in Cron directories, which could indicate potential persistence mechanisms being established by an attacker. Note that not all cron file creations are malicious - legitimate system administration activities and software installations may also create cron files. This detection should be investigated in context, considering factors such as the user creating the file, the timing of creation, and the contents of the cron job. Focus investigation on unexpected cron files created by non-administrative users or during suspicious timeframes. Additionally, it is recommended to review the contents of the newly created cron files to assess their intent. Furthermore, it is suggested to baseline normal cron file creation and apply additional filters to reduce false positives based on the specific environment.
linux · file_event
New Kind of Network (NKN) Detection
lowNKN is a networking service using blockchain technology to support a decentralized network of peers. While there are legitimate uses for it, it can also be used as a C2 channel. This rule looks for a DNS request to the ma>
zeek
New Kubernetes Service Account Created
lowDetects creation of new Kubernetes service account, which could indicate an attacker's attempt to persist within a cluster.
kubernetes · application
New Network ACL Entry Added
lowDetects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.
aws
New ODBC Driver Registered
lowDetects the registration of a new ODBC driver.
windows · registry_set
New Process Created Via Taskmgr.EXE
lowDetects the creation of a process via the Windows task manager. This might be an attempt to bypass UAC
windows · process_creation
New Service Creation Using PowerShell
lowDetects the creation of a new service using powershell.
windows · process_creation
New Service Creation Using Sc.EXE
lowDetects the creation of a new service using the "sc.exe" utility.
windows · process_creation
New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet
lowDetects calls to the "New-NetFirewallRule" cmdlet from PowerShell in order to add a new firewall rule with an "Allow" action.
windows · process_creation
New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet - ScriptBlock
lowDetects when a powershell script contains calls to the "New-NetFirewallRule" cmdlet in order to add a new firewall rule with an "Allow" action.
windows · ps_script
Nltest.EXE Execution
lowDetects nltest commands that can be used for information discovery
windows · process_creation
No Suitable Encryption Key Found For Generating Kerberos Ticket
lowDetects errors when a target server doesn't have suitable keys for generating kerberos tickets. This issue can occur for example when a service uses a user account or a computer account that is configured for only DES encryption on a computer that is running Windows 7 which has DES encryption for Kerberos authentication disabled.
windows
NodeJS Execution of JavaScript File
lowDetects execution of JavaScript or JSC files using NodeJs binary node.exe, that could be potentially suspicious. Node.js is a popular open-source JavaScript runtime that runs code outside browsers and is widely used for both frontend and backend development. Adversaries have been observed abusing Node.js to disguise malware as legitimate processes, evade security defenses, and maintain persistence within target systems. Because Node.js is commonly used, this rule may generate false positives in some environments. However, if such activity is unusual in your environment, it is highly suspicious and warrants immediate investigation.
windows · process_creation
Non Interactive PowerShell Process Spawned
lowDetects non-interactive PowerShell activity by looking at the "powershell" process with a non-user GUI process such as "explorer.exe" as a parent.
windows · process_creation
Notepad Password Files Discovery
lowDetects the execution of Notepad to open a file that has the string "password" which may indicate unauthorized access to credentials or suspicious activity.
windows · process_creation
NTDS.DIT Created
lowDetects creation of a file named "ntds.dit" (Active Directory Database)
windows · file_event
NTLM Logon
lowDetects logons using NTLM, which could be caused by a legacy source or attackers
windows
Office Macro File Creation
lowDetects the creation of a new office macro files on the systems
windows · file_event
Office Macro File Download
lowDetects the creation of a new office macro files on the system via an application (browser, mail client). This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.
windows · file_event
Okta Password Health Report Query
lowDetects all activities against the endpoint "/reports/password-health/*" which should only be accessed via OKTA Admin Console UI. Use this rule to hunt for potential suspicious requests. Correlate this event with "admin console" login and alert on requests without any corresponding admin console login
okta
Okta Policy Modified or Deleted
lowDetects when an Okta policy is modified or deleted.
okta
OneLogin User Account Locked
lowDetects when an user account is locked or suspended.
onelogin
OneLogin User Assumed Another User
lowDetects when an user assumed another user account.
onelogin
OS Architecture Discovery Via Grep
lowDetects the use of grep to identify information about the operating system architecture. Often combined beforehand with the execution of "uname" or "cat /proc/cpuinfo"
linux · process_creation
Outgoing Logon with New Credentials
lowDetects logon events that specify new credentials
windows
Outlook Task/Note Reminder Received
lowDetects changes to the registry values related to outlook that indicates that a reminder was triggered for a Note or Task item. This could be a sign of exploitation of CVE-2023-23397. Further investigation is required to determine the success of an exploitation.
windows · registry_set
Overwriting the File with Dev Zero or Null
lowDetects overwriting (effectively wiping/deleting) of a file.
linux
Password Policy Discovery - Linux
lowDetects password policy discovery commands
linux
Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy
lowDetetcts PowerShell activity in which Get-Addefaultdomainpasswordpolicy is used to get the default password policy for an Active Directory domain.
windows · ps_script
Password Protected Compressed File Extraction Via 7Zip
lowDetects usage of 7zip utilities (7z.exe, 7za.exe and 7zr.exe) to extract password protected zip files.
windows · process_creation
PFX File Creation
lowDetects the creation of PFX files (Personal Information Exchange format). PFX files contain private keys and certificates bundled together, making them valuable targets for attackers seeking to: - Exfiltrate digital certificates for impersonation or signing malicious code - Establish persistent access through certificate-based authentication - Bypass security controls that rely on certificate validation Analysts should investigate PFX file creation events by examining which process created the PFX file and its parent process chain, as well as unusual locations outside standard certificate stores or development environments.
windows · file_event
Potential 7za.DLL Sideloading
lowDetects potential DLL sideloading of "7za.dll"
windows · image_load
Potential Azure Browser SSO Abuse
lowDetects abusing Azure Browser SSO by requesting OAuth 2.0 refresh tokens for an Azure-AD-authenticated Windows user (i.e. the machine is joined to Azure AD and a user logs in with their Azure AD account) wanting to perform SSO authentication in the browser. An attacker can use this to authenticate to Azure AD in a browser as that user.
windows · image_load
Potential Bucket Enumeration on AWS
lowLooks for potential enumeration of AWS buckets via ListBuckets.
aws
Potential Container Discovery Via Inodes Listing
lowDetects listing of the inodes of the "/" directory to determine if the we are running inside of a container.
linux · process_creation
Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
lowDetects raw disk access using uncommon tools or tools that are located in suspicious locations (heavy filtering is required), which could indicate possible defense evasion attempts
windows · raw_access_thread
Potential Encoded PowerShell Patterns In CommandLine
lowDetects specific combinations of encoding methods in PowerShell via the commandline
windows · process_creation
Potential Executable Run Itself As Sacrificial Process
lowDetects when an executable launches an identical instance of itself, a behavior often used to create a suspended “sacrificial” process for code injection or evasion. Investigate for indicators such as the process being started in suspended mode, rapid parent termination, memory manipulation (e.g., WriteProcessMemory, CreateRemoteThread), or unsigned binaries. Review command-line arguments, process ancestry, and network activity to confirm if this is legitimate behavior or process injection activity.
windows · process_creation
Potential Execution of Sysinternals Tools
lowDetects command lines that contain the 'accepteula' flag which could be a sign of execution of one of the Sysinternals tools
windows · process_creation
Potential Exploitation of CVE-2022-21919 or CVE-2021-34484 for LPE
lowDetects potential exploitation attempts of CVE-2022-21919 or CVE-2021-34484 leading to local privilege escalation via the User Profile Service. During exploitation of this vulnerability, two logs (Provider_Name: Microsoft-Windows-User Profiles Service) with EventID 1511 and 1515 are created (EventID 1515 may generate many false positives). Additionally, the directory \Users\TEMP may be created during exploitation. This behavior was observed on Windows Server 2008.
windows
Potential File Override/Append Via SET Command
lowDetects the use of the "SET" internal command of Cmd.EXE with the /p flag followed directly by an "=" sign. Attackers used this technique along with an append redirection operator ">>" in order to update the content of a file indirectly. Ex: cmd /c >> example.txt set /p="test data". This will append "test data" to contents of "example.txt". The typical use case of the "set /p=" command is to prompt the user for input.
windows · process_creation
Potential PowerShell Obfuscation Using Alias Cmdlets
lowDetects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts
windows · ps_script
Potential PowerShell Obfuscation Using Character Join
lowDetects specific techniques often seen used inside of PowerShell scripts to obfscuate Alias creation
windows · ps_script
Potential Proxy Execution Via Explorer.EXE From Shell Process
lowDetects the creation of a child "explorer.exe" process from a shell like process such as "cmd.exe" or "powershell.exe". Attackers can use "explorer.exe" for evading defense mechanisms by proxying the execution through the latter. While this is often a legitimate action, this rule can be use to hunt for anomalies. Muddy Waters threat actor was seeing using this technique.
windows · process_creation
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
lowDetects registry modifications related to the proxy configuration of the system, potentially associated with the Raspberry Robin malware, as seen in campaigns running in Q1 2024. Raspberry Robin may alter proxy settings to circumvent security measures, ensuring unhindered connection with Command and Control servers for maintaining control over compromised systems if there are any proxy settings that are blocking connections.
windows · registry_set
Potential Suspicious Execution From GUID Like Folder Names
lowDetects potential suspicious execution of a GUID like folder name located in a suspicious location such as %TEMP% as seen being used in IcedID attacks. Use this rule to hunt for potentially suspicious activity stemming from uncommon folders.
windows · process_creation
Potentially Suspicious Long Filename Pattern - Linux
lowDetects the creation of files with unusually long filenames (100 or more characters), which may indicate obfuscation techniques used by malware such as VShell. This is a hunting rule to identify potential threats that use long filenames to evade detection. Keep in mind that on a legitimate system, such long filenames can and are common. Run this detection in the context of threat hunting rather than alerting. Adjust the threshold of filename length as needed based on your environment.
linux · file_event
Potentially Suspicious Network Connection To Notion API
lowDetects a non-browser process communicating with the Notion API. This could indicate potential use of a covert C2 channel such as "OffensiveNotion C2"
windows · network_connection
Potentially Suspicious Shell Script Creation in Profile Folder
lowDetects the creation of shell scripts under the "profile.d" path.
linux · file_event
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
lowDetects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
windows · process_creation
PowerShell Download Via Net.WebClient - PowerShell Classic
lowDetects PowerShell download activity, via the .DownloadFile() or .DownloadString() methods of the Net.WebClient class. This technique is often abused by attackers to download additional payloads.
windows · ps_classic_start
PowerShell Module File Created
lowDetects the creation of a new PowerShell module ".psm1", ".psd1", ".dll", ".ps1", etc.
windows · file_event
PowerShell Script Change Permission Via Set-Acl - PsScript
lowDetects PowerShell scripts set ACL to of a file or a folder
windows · ps_script
PowerShell Script Dropped Via PowerShell.EXE
lowDetects PowerShell creating a PowerShell file (.ps1). While often times this behavior is benign, sometimes it can be a sign of a dropper script trying to achieve persistence.
windows · file_event
PowerShell Script Execution Policy Enabled
lowDetects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.
windows · registry_set
PowerShell Script With File Upload Capabilities
lowDetects PowerShell scripts leveraging the "Invoke-WebRequest" cmdlet to send data via either "PUT" or "POST" method.
windows · ps_script
Powershell Suspicious Win32_PnPEntity
lowAdversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
windows · ps_script
Previously Installed IIS Module Was Removed
lowDetects the removal of a previously installed IIS module.
windows
Privileged Container Deployed
lowDetects the creation of a "privileged" container, an action which could be indicative of a threat actor mounting a container breakout attacks. A privileged container is a container that can access the host with all of the root capabilities of the host machine. This allows it to view, interact and modify processes, network operations, IPC calls, the file system, mount points, SELinux configurations etc. as the root user on the host. Various versions of "privileged" containers can be specified, e.g. by setting the securityContext.privileged flag in the resource specification, setting non-standard Linux capabilities, or configuring the hostNetwork/hostPID fields
kubernetes · application
Process Discovery
lowDetects process discovery commands. Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network
linux · process_creation
Process Execution From WebDAV Share
lowDetects execution of processes with image paths starting with WebDAV shares (\\), which might indicate malicious file execution from remote web shares. Execution of processes from WebDAV shares can be a sign of lateral movement or exploitation attempts, especially if the process is not a known legitimate application. Exploitation Attempt of vulnerabilities like CVE-2025-33053 also involves executing processes from WebDAV paths.
windows · process_creation
Process Terminated Via Taskkill
lowDetects execution of "taskkill.exe" in order to stop a service or a process. Look for suspicious parents executing this command in order to hunt for potential malicious activity. Attackers might leverage this in order to conduct data destruction or data encrypted for impact on the data stores of services like Exchange and SQL Server.
windows · process_creation
PsExec Default Named Pipe
lowDetects PsExec service default pipe creation
windows · pipe_created
PsExec Service File Creation
lowDetects default PsExec service filename which indicates PsExec service installation and execution
windows · file_event
PUA - Adidnsdump Execution
lowThis tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks Python 3 and python.exe must be installed, Usee to Query/modify DNS records for Active Directory integrated DNS via LDAP
windows · process_creation
PUA - Sysinternal Tool Execution - Registry
lowDetects the execution of a Sysinternals Tool via the creation of the "accepteula" registry key
windows · registry_set
Python Image Load By Non-Python Process
lowDetects the image load of "Python Core" by a non-Python process. This might be indicative of a execution of executable that has been bundled from Python code. Various tools like Py2Exe, PyInstaller, and cx_Freeze are used to bundle Python code into standalone executables. Threat actors often use these tools to bundle malicious Python scripts into executables, sometimes to obfuscate the code or to bypass security measures.
windows · image_load
QuickAssist Execution
lowDetects the execution of Microsoft Quick Assist tool "QuickAssist.exe". This utility can be used by attackers to gain remote access.
windows · process_creation
RBAC Permission Enumeration Attempt
lowDetects identities attempting to enumerate their Kubernetes RBAC permissions. In the early stages of a breach, attackers will aim to list the permissions they have within the compromised environment. In a Kubernetes cluster, this can be achieved by interacting with the API server, and querying the SelfSubjectAccessReview API via e.g. a "kubectl auth can-i --list" command. This will enumerate the Role-Based Access Controls (RBAC) rules defining the compromised user's authorization.
kubernetes · application
RegAsm.EXE Execution Without CommandLine Flags or Files
lowDetects the execution of "RegAsm.exe" without a commandline flag or file, which might indicate potential process injection activity. Usually "RegAsm.exe" should point to a dedicated DLL file or call the help with the "/?" flag.
windows · process_creation
Registry Modification Via Regini.EXE
lowDetects the execution of regini.exe which can be used to modify registry keys, the changes are imported from one or more text files.
windows · process_creation
Remote Access Tool - ScreenConnect Command Execution
lowDetects command execution via ScreenConnect RMM
windows
Remote Access Tool - ScreenConnect File Transfer
lowDetects file being transferred via ScreenConnect RMM
windows
Remote Access Tool - ScreenConnect Remote Command Execution
lowDetects the execution of a system command via the ScreenConnect RMM service.
windows · process_creation
Remote Access Tool - ScreenConnect Temporary File
lowDetects the creation of files in a specific location by ScreenConnect RMM. ScreenConnect has feature to remotely execute binaries on a target machine. These binaries will be dropped to ":\Users\<username>\Documents\ConnectWiseControl\Temp\" before execution.
windows · file_event
Remote Access Tool - Team Viewer Session Started On Linux Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
linux · process_creation
Remote Access Tool - Team Viewer Session Started On MacOS Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
macos · process_creation
Remote Access Tool - Team Viewer Session Started On Windows Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
windows · process_creation
Remote File Copy
lowDetects the use of tools that copy files from or to remote systems
linux
Remote PowerShell Session (PS Classic)
lowDetects remote PowerShell sessions
windows · ps_classic_start
Renamed Powershell Under Powershell Channel
lowDetects a renamed Powershell execution, which is a common technique used to circumvent security controls and bypass detection logic that's dependent on process names and process paths.
windows · ps_classic_start
Replace Desktop Wallpaper by Powershell
lowAn adversary may deface systems internal to an organization in an attempt to intimidate or mislead users. This may take the form of modifications to internal websites, or directly to user systems with the replacement of the desktop wallpaper
windows · ps_script
Run Once Task Execution as Configured in Registry
lowThis rule detects the execution of Run Once task as configured in the registry
windows · process_creation
SC.EXE Query Execution
lowDetects execution of "sc.exe" to query information about registered services on the system
windows · process_creation
Scheduled Task Created - FileCreation
lowDetects the creation of a scheduled task via file creation.
windows · file_event
Scheduled Task Created - Registry
lowDetects the creation of a scheduled task via Registry keys.
windows · registry_event
Scheduled Task Creation Via Schtasks.EXE
lowDetects the creation of scheduled tasks by user accounts via the "schtasks" utility.
windows · process_creation
Scheduled Task Deletion
lowDetects scheduled task deletion events. Scheduled tasks are likely to be deleted if not used for persistence. Malicious Software often creates tasks directly under the root node e.g. \TASKNAME
windows
Scheduled Task/Job At
lowDetects the use of at/atd which are utilities that are used to schedule tasks. They are often abused by adversaries to maintain persistence or to perform task scheduling for initial or recurring execution of malicious code
linux · process_creation
Screen Capture - macOS
lowDetects attempts to use screencapture to collect macOS screenshots
macos · process_creation
Screen Capture with Import Tool
lowDetects adversary creating screen capture of a desktop with Import Tool. Highly recommended using rule on servers, due to high usage of screenshot utilities on user workstations. ImageMagick must be installed.
linux
Screen Capture with Xwd
lowDetects adversary creating screen capture of a full with xwd. Highly recommended using rule on servers, due high usage of screenshot utilities on user workstations
linux
Security Software Discovery - Linux
lowDetects usage of system utilities (only grep and egrep for now) to discover security software discovery
linux · process_creation
Service Registry Key Read Access Request
lowDetects "read access" requests on the services registry key. Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for Registry keys related to services to redirect from the originally specified executable to one that they control, in order to launch their own code when a service starts.
windows
Service Reload or Start - Linux
lowDetects the start, reload or restart of a service.
linux
Set Files as System Files Using Attrib.EXE
lowDetects the execution of "attrib" with the "+s" flag to mark files as system files
windows · process_creation
Setuid and Setgid
lowDetects suspicious change of file privileges with chown and chmod commands
linux · process_creation
Share And Session Enumeration Using Net.EXE
lowDetects attempts to enumerate file shares, printer shares and sessions using "net.exe" with the "view" flag.
windows · process_creation
Shell Context Menu Command Tampering
lowDetects changes to shell context menu commands. Use this rule to hunt for potential anomalies and suspicious shell commands.
windows · registry_set
Sign-ins by Unknown Devices
lowMonitor and alert for Sign-ins by unknown devices from non-Trusted locations.
azure
Signed DLL Loaded With Missing PE Version Metadata
lowDetects the loading of a digitally signed DLL whose PE version-info resource is entirely missing. Legitimate signed DLLs from reputable vendors often carry populated metadata fields (Description, Company, Product, OriginalFileName, FileVersion). An attacker who signs a purpose-built or hollowed DLL with a stolen, mis-issued, or cheaply purchased code-signing certificate will often omit these fields, producing a valid signature with no accompanying version info. This pattern is observed in DLL side-loading, search-order hijacking, and certificate-abuse campaigns where signing is used purely to satisfy security-product trust checks. Hunting Hypothesis: - Investigate the signing certificate (issuer, subject, validity window, thumbprint) for disposable or recently issued CAs and cross-reference against known threat-actor certificates. - Examine the DLL's on-disk path relative to the loading process — paths outside standard system directories or inside application folders susceptible to search-order hijacking are high-priority leads. - Correlate with the parent process context; DLLs loaded into high-value targets such as lsass.exe, svchost.exe, or browser processes warrant immediate escalation. Note: The "selection_metadata_null" selection matches fields with a null value. Some backends may interpret null field conditions as "field does not exist" rather than "field has a null value", which would change the detection semantics. If your backend does not support or support null-value matching in different ways than expected, you may need to adjust the rule logic accordingly or remove the "selection_metadata_null" condition.
windows · image_load
SNAKE Malware Installer Name Indicators
lowDetects filename indicators associated with the SNAKE malware as reported by CISA in their report
windows · file_event
Space After Filename - macOS
lowDetects attempts to masquerade as legitimate files by adding a space to the end of the filename.
macos · process_creation
Special File Creation via Mknod Syscall
lowDetects usage of the `mknod` syscall to create special files (e.g., character or block devices). Attackers or malware might use `mknod` to create fake devices, interact with kernel interfaces, or establish covert channels in Linux systems. Monitoring the use of `mknod` is important because this syscall is rarely used by legitimate applications, and it can be abused to bypass file system restrictions or create backdoors.
linux
Split A File Into Pieces
lowDetection use of the command "split" to split files into parts and possible transfer.
macos · process_creation
Split A File Into Pieces - Linux
lowDetection use of the command "split" to split files into parts and possible transfer.
linux
Start Windows Service Via Net.EXE
lowDetects the usage of the "net.exe" command to start a service using the "start" flag
windows · process_creation
Startup Item File Created - MacOS
lowDetects the creation of a startup item plist file, that automatically get executed at boot initialization to establish persistence. Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items.
macos · file_event
Steganography Extract Files with Steghide
lowDetects extraction of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.
linux
Steganography Hide Files with Steghide
lowDetects embedding of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.
linux
Steganography Hide Zip Information in Picture File
lowDetects appending of zip file to image
linux
Steganography Unzip Hidden Information From Picture File
lowDetects extracting of zip file from image file
linux
Stop Windows Service Via Net.EXE
lowDetects the stopping of a Windows service via the "net" utility.
windows · process_creation
Stop Windows Service Via PowerShell Stop-Service
lowDetects the stopping of a Windows service via the PowerShell Cmdlet "Stop-Service"
windows · process_creation
Stop Windows Service Via Sc.EXE
lowDetects the stopping of a Windows service via the "sc.exe" utility
windows · process_creation
Successful Account Login Via WMI
lowDetects successful logon attempts performed with WMI
windows
Successful MSIX/AppX Package Installation
lowDetects successful MSIX/AppX package installations on Windows systems by monitoring EventID 854 in the Microsoft-Windows-AppXDeployment-Server/Operational log. While most installations are legitimate, this can help identify unauthorized or suspicious package installations. It is crucial to monitor such events as threat actors may exploit MSIX/AppX packages to deliver and execute malicious payloads.
windows
Suspicious Connection to Remote Account
lowAdversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism
windows · ps_script
Suspicious Deno File Written from Remote Source
lowDetects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL. This behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.
windows · file_event
Suspicious Execution of Hostname
lowUse of hostname to get information
windows · process_creation
Suspicious Execution of Systeminfo
lowDetects usage of the "systeminfo" command to retrieve information
windows · process_creation
Suspicious File Access to Browser Credential Storage
lowDetects file access to browser credential storage paths by non-browser processes, which may indicate credential access attempts. Adversaries may attempt to access browser credential storage to extract sensitive information such as usernames and passwords or cookies. This behavior is often commonly observed in credential stealing malware.
windows · file_access
Suspicious Get Information for SMB Share
lowAdversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
windows · ps_script
Suspicious Get Information for SMB Share - PowerShell Module
lowAdversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
windows · ps_module
Suspicious Get Local Groups Information
lowDetects the use of PowerShell modules and cmdlets to gather local group information. Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
windows · ps_module
Suspicious Get Local Groups Information - PowerShell
lowDetects the use of PowerShell modules and cmdlets to gather local group information. Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
windows · ps_script
Suspicious GPO Discovery With Get-GPO
lowDetect use of Get-GPO to get one GPO or all the GPOs in a domain.
windows · ps_script
Suspicious Inbox Forwarding
lowDetects when a Microsoft Cloud App Security reported suspicious email forwarding rules, for example, if a user created an inbox rule that forwards a copy of all emails to an external address.
m365
Suspicious Mount-DiskImage
lowAdversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
windows · ps_script
Suspicious Network Command
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
Suspicious Network Communication With IPFS
lowDetects connections to interplanetary file system (IPFS) containing a user's email address which mirrors behaviours observed in recent phishing campaigns leveraging IPFS to host credential harvesting webpages.
proxy
Suspicious PowerShell Get Current User
lowDetects the use of PowerShell to identify the current logged user.
windows · ps_script
Suspicious Process Discovery With Get-Process
lowGet the processes that are running on the local computer.
windows · ps_script
Suspicious Query of MachineGUID
lowUse of reg to get MachineGuid information
windows · process_creation
Suspicious SSL Connection
lowAdversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
windows · ps_script
Suspicious Where Execution
lowAdversaries may enumerate browser bookmarks to learn more about compromised hosts. Browser bookmarks may reveal personal information about users (ex: banking sites, interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
windows · process_creation
Sysinternals Tools AppX Versions Execution
lowDetects execution of Sysinternals tools via an AppX package. Attackers could install the Sysinternals Suite to get access to tools such as psexec and procdump to avoid detection based on System paths.
windows
System Drawing DLL Load
lowDetects processes loading "System.Drawing.ni.dll". This could be an indicator of potential Screen Capture.
windows · image_load
System Info Discovery via Sysinfo Syscall
lowDetects use of the sysinfo system call in Linux, which provides a snapshot of key system statistics such as uptime, load averages, memory usage, and the number of running processes. Malware or reconnaissance tools might leverage sysinfo to fingerprint the system - gathering data to determine if it's a viable target.
linux
System Information Discovery - Auditd
lowDetects System Information Discovery commands
linux
System Information Discovery via Registry Queries
lowDetects attempts to query system information directly from the Windows Registry.
windows · process_creation
System Information Discovery Via Wmic.EXE
lowDetects the use of the WMI command-line (WMIC) utility to identify and display various system information, including OS, CPU, GPU, disk drive names, memory capacity, display resolution, baseboard, BIOS, and GPU driver products/versions.
windows · process_creation
System Integrity Protection (SIP) Enumeration
lowDetects the use of csrutil to view the Configure System Integrity Protection (SIP) status. This technique is used in post-exploit scenarios.
macos · process_creation
System Network Connections Discovery - Linux
lowDetects usage of system utilities to discover system network connections
linux · process_creation
System Network Connections Discovery Via Net.EXE
lowAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
windows · process_creation
System Owner or User Discovery - Linux
lowDetects the execution of host or user discovery utilities such as "whoami", "hostname", "id", etc. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
linux
Tap Driver Installation - Security
lowDetects the installation of a well-known TAP driver service. This could be a sign of potential preparation for data exfiltration using tunnelling techniques.
windows
Task Scheduler DLL Loaded By Application Located In Potentially Suspicious Location
lowDetects the loading of the "taskschd.dll" module from a process that located in a potentially suspicious or uncommon directory. The loading of this DLL might indicate that the application have the capability to create a scheduled task via the "Schedule.Service" COM object. Investigation of the loading application and its behavior is required to determining if its malicious.
windows · image_load
TeamViewer Log File Deleted
lowDetects the deletion of the TeamViewer log files which may indicate an attempt to destroy forensic evidence
windows · file_delete
The Windows Defender Firewall Service Failed To Load Group Policy
lowDetects activity when The Windows Defender Firewall service failed to load Group Policy
windows
Unattend.XML File Access Attempt
lowDetects attempts to access the "unattend.xml" file, where credentials might be stored. This file is used during the unattended windows install process.
windows · file_access
Unauthorized System Time Modification
lowDetect scenarios where a potentially unauthorized application or user is modifying the system time.
windows
Uncommon Process Access Rights For Target Image
lowDetects process access request to uncommon target images with a "PROCESS_ALL_ACCESS" access mask.
windows · process_access
Unmount Share Via Net.EXE
lowDetects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
windows · process_creation
Unusually Long PowerShell CommandLine
lowDetects unusually long PowerShell command lines with a length of 1000 characters or more
windows · process_creation
USB Device Plugged
lowDetects plugged/unplugged USB devices
windows
Use Get-NetTCPConnection
lowAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
windows · ps_classic_start
Use Get-NetTCPConnection - PowerShell Module
lowAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
windows · ps_module
Use Of Hidden Paths Or Files
lowDetects calls to hidden files or files located in hidden directories in NIX systems.
linux
Use Of Remove-Item to Delete File - ScriptBlock
lowPowerShell Remove-Item with -Path to delete a file or a folder with "-Recurse"
windows · ps_script
User with Privileges Logon
lowDetects logon with "Special groups" and "Special Privileges" can be thought of as Administrator groups or privileges.
windows
Userdomain Variable Enumeration
lowDetects suspicious enumeration of the domain the user is associated with.
windows · process_creation
Virtualbox Driver Installation or Starting of VMs
lowAdversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.
windows · process_creation
Volume Shadow Copy Mount
lowDetects volume shadow copy mount via Windows event log
windows
Vulnerable Driver Load By Name
lowDetects the load of known vulnerable drivers via the file name of the drivers.
windows · driver_load
WebDav Put Request
lowA General detection for WebDav user-agent being used to PUT files on a WebDav network share. This could be an indicator of exfiltration.
zeek
Windows Defender Firewall Has Been Reset To Its Default Configuration
lowDetects activity when Windows Defender Firewall has been reset to its default configuration
windows
Windows Defender Submit Sample Feature Disabled
lowDetects disabling of the "Automatic Sample Submission" feature of Windows Defender.
windows
Windows Event Auditing Disabled
lowDetects scenarios where system auditing (i.e.: Windows event log auditing) is disabled. This may be used in a scenario where an entity would want to bypass local logging to evade detection when Windows event logging is enabled and reviewed. Also, it is recommended to turn off "Local Group Policy Object Processing" via GPO, which will make sure that Active Directory GPOs take precedence over local/edited computer policies via something such as "gpedit.msc". Please note, that disabling "Local Group Policy Object Processing" may cause an issue in scenarios of one off specific GPO modifications - however, it is recommended to perform these modifications in Active Directory anyways.
windows
Windows Firewall Settings Have Been Changed
lowDetects activity when the settings of the Windows firewall have been changed
windows
Windows MSIX Package Support Framework AI_STUBS Execution
lowDetects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
windows · process_creation
Windows Processes Suspicious Parent Directory
lowDetect suspicious parent processes of well-known Windows processes
windows · process_creation
Windows Service Terminated With Error
lowDetects Windows services that got terminated for whatever reason
windows
Windows Share Mount Via Net.EXE
lowDetects when a share is mounted using the "net.exe" utility
windows · process_creation
Winget Admin Settings Modification
lowDetects changes to the AppInstaller (winget) admin settings. Such as enabling local manifest installations or disabling installer hash checks
windows · registry_set
WMI Module Loaded By Uncommon Process
lowDetects WMI modules being loaded by an uncommon process
windows · image_load