Severity level
Medium-severity Sigma rules
1509 community-maintained Sigma detection rules in the library are classified as medium severity. Medium-severity rules surface activity worth reviewing in context. Coverage spans windows, linux, azure. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
.Class Extension URI Ending Request
mediumDetects requests to URI ending with the ".class" extension in proxy logs. This could rules can be used to hunt for potential downloads of Java classes as seen for example in Log4shell exploitation attacks against Log4j.
proxy
7Zip Compressing Dump Files
mediumDetects execution of 7z in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows · process_creation
A New Trust Was Created To A Domain
mediumAddition of domains is seldom and should be verified for legitimacy.
windows
A Rule Has Been Deleted From The Windows Firewall Exception List
mediumDetects when a single rules or all of the rules have been deleted from the Windows Defender Firewall
windows
Abusing Print Executable
mediumAttackers can use print.exe for remote file copy
windows · process_creation
Access of Sudoers File Content
mediumDetects the execution of a text-based file access or inspection utilities to read the content of /etc/sudoers in order to potentially list all users that have sudo rights.
linux · process_creation
Access to Browser Login Data
mediumAdversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store.
windows · ps_script
Access To Crypto Currency Wallets By Uncommon Applications
mediumDetects file access requests to crypto currency files by uncommon processes. Could indicate potential attempt of crypto currency wallet stealing.
windows · file_access
Access To Potentially Sensitive Sysvol Files By Uncommon Applications
mediumDetects file access requests to potentially sensitive files hosted on the Windows Sysvol share.
windows · file_access
Access To Sysvol Policies Share By Uncommon Process
mediumDetects file access requests to the Windows Sysvol Policies Share by uncommon processes
windows · file_access
Access To Windows Credential History File By Uncommon Applications
mediumDetects file access requests to the Windows Credential History File by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::credhist" function
windows · file_access
Access To Windows DPAPI Master Keys By Uncommon Applications
mediumDetects file access requests to the the Windows Data Protection API Master keys by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::masterkey" function
windows · file_access
Account Created And Deleted By Non Approved Users
mediumDetects accounts that are created or deleted by non-approved users.
azure
Account Disabled or Blocked for Sign in Attempts
mediumDetects when an account is disabled or blocked for sign in but tried to log in
azure
Account Lockout
mediumIdentifies user account which has been locked because the user tried to sign in too many times with an incorrect user ID or password.
azure
Account Tampering - Suspicious Failed Logon Reasons
mediumThis method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.
windows
Activate Suppression of Windows Security Center Notifications
mediumDetect set Notification_Suppress to 1 to disable the Windows security center notification
windows · registry_set
Active Directory Database Snapshot Via ADExplorer
mediumDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · process_creation
Active Directory Replication from Non Machine Account - DcSync Indicator
mediumDetects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials.
windows
Active Directory Structure Export Via Csvde.EXE
mediumDetects the execution of "csvde.exe" in order to export organizational Active Directory structure.
windows · process_creation
Active Directory Structure Export Via Ldifde.EXE
mediumDetects the execution of "ldifde.exe" in order to export organizational Active Directory structure.
windows · process_creation
Activity from Anonymous IP Addresses
mediumDetects when a Microsoft Cloud App Security reported when users were active from an IP address that has been identified as an anonymous proxy IP address.
m365
Activity from Infrequent Country
mediumDetects when a Microsoft Cloud App Security reported when an activity occurs from a location that wasn't recently or never visited by any user in the organization.
m365
Activity from Suspicious IP Addresses
mediumDetects when a Microsoft Cloud App Security reported users were active from an IP address identified as risky by Microsoft Threat Intelligence. These IP addresses are involved in malicious activities, such as Botnet C&C, and may indicate compromised account.
m365
Activity Performed by Terminated User
mediumDetects when a Microsoft Cloud App Security reported for users whose account were terminated in Azure AD, but still perform activities in other platforms such as AWS or Salesforce. This is especially relevant for users who use another account to manage resources, since these accounts are often not terminated when a user leaves the company.
m365
Add Debugger Entry To AeDebug For Persistence
mediumDetects when an attacker adds a new "Debugger" value to the "AeDebug" key in order to achieve persistence which will get invoked when an application crashes
windows · registry_set
Add DisallowRun Execution to Registry
mediumDetect set DisallowRun to 1 to prevent user running specific computer program
windows · registry_set
Add New Download Source To Winget
mediumDetects usage of winget to add new additional download sources
windows · process_creation
Add Port Monitor Persistence in Registry
mediumAdversaries may use port monitors to run an attacker supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup.
windows · registry_set
Add Potential Suspicious New Download Source To Winget
mediumDetects usage of winget to add new potentially suspicious download sources
windows · process_creation
Add Windows Capability Via PowerShell Cmdlet
mediumDetects usage of the "Add-WindowsCapability" cmdlet to add Windows capabilities. Notable capabilities could be "OpenSSH" and others.
windows · process_creation
Add Windows Capability Via PowerShell Script
mediumDetects usage of the "Add-WindowsCapability" cmdlet to add Windows capabilities. Notable capabilities could be "OpenSSH" and others.
windows · ps_script
Added Owner To Application
mediumDetects when a new owner is added to an application. This gives that account privileges to make modifications and configuration changes to the application.
azure
AddinUtil.EXE Execution From Uncommon Directory
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) from a non-standard directory.
windows · process_creation
Addition of SID History to Active Directory Object
mediumAn attacker can use the SID history attribute to gain additional privileges.
windows
ADExplorer Writing Complete AD Snapshot Into .dat File
mediumDetects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · file_event
ADFS Database Named Pipe Connection By Uncommon Tool
mediumDetects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database). Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
windows · pipe_created
ADS Zone.Identifier Deleted By Uncommon Application
mediumDetects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
windows · file_delete
ADSI-Cache File Creation By Uncommon Tool
mediumDetects the creation of an "Active Directory Schema Cache File" (.sch) file by an uncommon tool.
windows · file_event
Advanced IP Scanner - File Event
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows · file_event
AgentExecutor PowerShell Execution
mediumDetects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
windows · process_creation
Allow RDP Remote Assistance Feature
mediumDetect enable rdp feature to allow specific user to rdp connect on the targeted machine
windows · registry_set
Alternate PowerShell Hosts - PowerShell Module
mediumDetects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
windows · ps_module
Alternate PowerShell Hosts Pipe
mediumDetects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
windows · pipe_created
Always Install Elevated MSI Spawned Cmd And Powershell
mediumDetects Windows Installer service (msiexec.exe) spawning "cmd" or "powershell"
windows · process_creation
Always Install Elevated Windows Installer
mediumDetects Windows Installer service (msiexec.exe) trying to install MSI packages with SYSTEM privilege
windows · process_creation
Amsi.DLL Loaded Via LOLBIN Process
mediumDetects loading of "Amsi.dll" by a living of the land process. This could be an indication of a "PowerShell without PowerShell" attack
windows · image_load
Anydesk Remote Access Software Service Installation
mediumDetects the installation of the anydesk software service. Which could be an indication of anydesk abuse if you the software isn't already used.
windows
Anydesk Temporary Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
Apache Threading Error
mediumDetects an issue in apache logs that reports threading related errors
App Assigned To Azure RBAC/Microsoft Entra Role
mediumDetects when an app is assigned Azure AD roles, such as global administrator, or Azure RBAC roles, such as subscription owner.
azure
Application Removed Via Wmic.EXE
mediumDetects the removal or uninstallation of an application via "Wmic.EXE".
windows · process_creation
Application Termination Attempt via Wmic.EXE
mediumDetects an attempt to terminate a process via "wmic" with the "call terminate" flag. Adversaries may use wmic to terminate security products or other applications on the compromised host. This event is triggered on on attempt and process creation can be either successful or unsuccessful.
windows · process_creation
Application Using Device Code Authentication Flow
mediumDevice code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments. If this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted. This can be a misconfigured application or potentially something malicious.
azure
Applications That Are Using ROPC Authentication Flow
mediumResource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly. The application then uses those credentials to authenticate the user against the identity provider.
azure
AppLocker Application Would Have Been Blocked
mediumDetects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, or Packaged-App would have been blocked if AppLocker "Enforce rules" enforcement mode was enabled.
windows
AppLocker Prevented Application or Script from Running
mediumDetects when AppLocker prevents the execution of an Application, DLL, Script, MSI, or Packaged-App from running.
windows
AppX Located in Uncommon Directory Added to Deployment Pipeline
mediumDetects an appx package that was added to the pipeline of the "to be processed" packages that is located in uncommon locations.
windows
AppX Package Deployment Failed Due to Signing Requirements
mediumDetects an appx package deployment / installation with the error code "0x80073cff" which indicates that the package didn't meet the signing requirements.
windows
AppX Package Installation Attempts Via AppInstaller.EXE
mediumDetects DNS queries made by "AppInstaller.EXE". The AppInstaller is the default handler for the "ms-appinstaller" URI. It attempts to load/install a package from the referenced URL
windows · dns_query
Arbitrary Binary Execution Using GUP Utility
mediumDetects execution of the Notepad++ updater (gup) to launch other commands or executables
windows · process_creation
Arbitrary Command Execution Using WSL
mediumDetects potential abuse of Windows Subsystem for Linux (WSL) binary as a Living of the Land binary in order to execute arbitrary Linux or Windows commands.
windows · process_creation
Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
mediumDetects execution of arbitrary DLLs or unsigned code via a ".csproj" files via Dotnet.EXE.
windows · process_creation
Arbitrary File Download Via ConfigSecurityPolicy.EXE
mediumDetects the execution of "ConfigSecurityPolicy.EXE", a binary part of Windows Defender used to manage settings in Windows Defender. Users can configure different pilot collections for each of the co-management workloads. It can be abused by attackers in order to upload or download files.
windows · process_creation
Arbitrary File Download Via GfxDownloadWrapper.EXE
mediumDetects execution of GfxDownloadWrapper.exe with a URL as an argument to download file.
windows · process_creation
Arbitrary File Download Via MSEDGE_PROXY.EXE
mediumDetects usage of "msedge_proxy.exe" to download arbitrary files
windows · process_creation
Arbitrary File Download Via MSOHTMED.EXE
mediumDetects usage of "MSOHTMED" to download arbitrary files
windows · process_creation
Arbitrary File Download Via MSPUB.EXE
mediumDetects usage of "MSPUB" (Microsoft Publisher) to download arbitrary files
windows · process_creation
Arbitrary File Download Via PresentationHost.EXE
mediumDetects usage of "PresentationHost" which is a utility that runs ".xbap" (Browser Applications) files to download arbitrary files
windows · process_creation
Arbitrary File Download Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" to download arbitrary files. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows · process_creation
Arbitrary MSI Download Via Devinit.EXE
mediumDetects a certain command line flag combination used by "devinit.exe", which can be abused as a LOLBIN to download arbitrary MSI packages on a Windows system
windows · process_creation
Arbitrary Shell Command Execution Via Settingcontent-Ms
mediumThe .SettingContent-ms file type was introduced in Windows 10 and allows a user to create "shortcuts" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.
windows · process_creation
AspNetCompiler Execution
mediumDetects execution of "aspnet_compiler.exe" which can be abused to compile and execute C# code.
windows · process_creation
Assembly DLL Creation Via AspNetCompiler
mediumDetects the creation of new DLL assembly files by "aspnet_compiler.exe", which could be a sign of "aspnet_compiler" abuse to proxy execution through a build provider.
windows · file_event
Assembly Loading Via CL_LoadAssembly.ps1
mediumDetects calls to "LoadAssemblyFromPath" or "LoadAssemblyFromNS" that are part of the "CL_LoadAssembly.ps1" script. This can be abused to load different assemblies and bypass App locker controls.
windows · process_creation
Atbroker Registry Change
mediumDetects creation/modification of Assistive Technology applications and persistence with usage of 'at'
windows · registry_event
Audio Capture via PowerShell
mediumDetects audio capture via PowerShell Cmdlet.
windows · process_creation
Audio Capture via SoundRecorder
mediumDetect attacker collecting audio via SoundRecorder application.
windows · process_creation
Authentications To Important Apps Using Single Factor Authentication
mediumDetect when authentications to important application(s) only required single-factor authentication
azure
Automated Collection Command PowerShell
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · ps_script
Automated Collection Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · process_creation
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows · process_creation
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows · file_event
AWS Bedrock Guardrail Deleted
mediumDetects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety controls and allow unsafe or unauthorized model responses.
aws
AWS Bedrock Guardrail Updated
mediumDetects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety controls and allow unsafe or unauthorized model responses.
aws
AWS Bucket Deleted
mediumDetects the deletion of S3 buckets in AWS CloudTrail logs. Monitoring the deletion of S3 buckets is critical for security and data integrity, as it may indicate potential data loss or unauthorized access attempts.
aws
AWS CloudTrail Important Change
mediumDetects disabling, deleting and updating of a Trail
aws
AWS Console GetSigninToken Potential Abuse
mediumDetects potentially suspicious events involving "GetSigninToken". An adversary using the "aws_consoler" tool can leverage this console API to create temporary federated credential that help obfuscate which AWS credential is compromised (the original access key) and enables the adversary to pivot from the AWS CLI to console sessions without the need for MFA using the new access key issued in this request.
aws
AWS Console Login Monitoring
mediumDetects AWS console logins from countries and IP addresses that are not recognized as legitimate for the organization. This alert can help identify potential unauthorized access attempts from unusual locations, which may indicate compromised credentials or malicious activity.
aws
AWS ConsoleLogin Failed Authentication
mediumDetects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.
aws
AWS EC2 Disable EBS Encryption
mediumIdentifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.
aws
AWS ECS Task Definition That Queries The Credential Endpoint
mediumDetects when an Elastic Container Service (ECS) Task Definition includes a command to query the credential endpoint. This can indicate a potential adversary adding a backdoor to establish persistence or escalate privileges.
aws
AWS EFS Fileshare Modified or Deleted
mediumDetects when a EFS Fileshare is modified or deleted. You can't delete a file system that is in use. If the file system has any mount targets, the adversary must first delete them, so deletion of a mount will occur before deletion of a fileshare.
aws
AWS EFS Fileshare Mount Modified or Deleted
mediumDetects when a EFS Fileshare Mount is modified or deleted. An adversary breaking any file system using the mount target that is being deleted, which might disrupt instances or applications using those mounts.
aws
AWS EnableRegion Command Monitoring
mediumDetects the use of the EnableRegion command in AWS CloudTrail logs. While AWS has 30+ regions, some of them are enabled by default, others must be explicitly enabled in each account separately. There may be situations where security monitoring does not cover some new AWS regions. Monitoring the EnableRegion command is important for identifying potential persistence mechanisms employed by adversaries, as enabling additional regions can facilitate continued access and operations within an AWS environment.
aws
AWS IAM Backdoor Users Keys
mediumDetects AWS API key creation for a user by another user. Backdoored users can be used to obtain persistence in the AWS environment. Also with this alert, you can detect a flow of AWS keys in your org.
aws
AWS Key Pair Import Activity
mediumDetects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.
aws
AWS RDS Master Password Change
mediumDetects the change of database master password. It may be a part of data exfiltration.
aws
AWS Root Credentials
mediumDetects AWS root account usage
aws
AWS S3 Bucket Versioning Disable
mediumDetects when S3 bucket versioning is disabled. Threat actors use this technique during AWS ransomware incidents prior to deleting S3 objects.
aws
AWS SAML Provider Deletion Activity
mediumDetects the deletion of an AWS SAML provider, potentially indicating malicious intent to disrupt administrative or security team access. An attacker can remove the SAML provider for the information security team or a team of system administrators, to make it difficult for them to work and investigate at the time of the attack and after it.
aws
AWS Snapshot Backup Exfiltration
mediumDetects the modification of an EC2 snapshot's permissions to enable access from another account
aws
AWS STS GetCallerIdentity Enumeration Via TruffleHog
mediumDetects the use of TruffleHog for AWS credential validation by identifying GetCallerIdentity API calls where the userAgent indicates TruffleHog. Threat actors leverage TruffleHog to enumerate and validate exposed AWS keys. Successful exploitation allows threat actors to confirm the validity of compromised AWS credentials, facilitating further unauthorized access and actions within the AWS environment.
aws
AWS Successful Console Login Without MFA
mediumDetects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.
aws
AWS Suspicious SAML Activity
mediumIdentifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.
aws
Azure Active Directory Hybrid Health AD FS New Server
mediumThis detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.
azure
Azure Active Directory Hybrid Health AD FS Service Delete
mediumThis detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.
azure
Azure AD Health Monitoring Agent Registry Keys Access
mediumThis detection uses Windows security events to detect suspicious access attempts to the registry key of Azure AD Health monitoring agent. This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object HKLM\SOFTWARE\Microsoft\Microsoft Online\Reporting\MonitoringAgent.
windows
Azure AD Health Service Agents Registry Keys Access
mediumThis detection uses Windows security events to detect suspicious access attempts to the registry key values and sub-keys of Azure AD Health service agents (e.g AD FS). Information from AD Health service agents can be used to potentially abuse some of the features provided by those services in the cloud (e.g. Federation). This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object: HKLM:\SOFTWARE\Microsoft\ADHealthAgent. Make sure you set the SACL to propagate to its sub-keys.
windows
Azure Application Deleted
mediumIdentifies when a application is deleted in Azure.
azure
Azure Application Gateway Modified or Deleted
mediumIdentifies when a application gateway is modified or deleted.
azure
Azure Application Security Group Modified or Deleted
mediumIdentifies when a application security group is modified or deleted.
azure
Azure Device No Longer Managed or Compliant
mediumIdentifies when a device in azure is no longer managed or compliant
azure
Azure Device or Configuration Modified or Deleted
mediumIdentifies when a device or device configuration in azure is modified or deleted.
azure
Azure DNS Zone Modified or Deleted
mediumIdentifies when DNS zone is modified or deleted.
azure
Azure Domain Federation Settings Modified
mediumIdentifies when an user or application modified the federation settings on the domain.
azure
Azure Firewall Modified or Deleted
mediumIdentifies when a firewall is created, modified, or deleted.
azure
Azure Firewall Rule Collection Modified or Deleted
mediumIdentifies when Rule Collections (Application, NAT, and Network) is being modified or deleted.
azure
Azure Firewall Rule Configuration Modified or Deleted
mediumIdentifies when a Firewall Rule Configuration is Modified or Deleted.
azure
Azure Key Vault Modified or Deleted
mediumIdentifies when a key vault is modified or deleted.
azure
Azure Keyvault Key Modified or Deleted
mediumIdentifies when a Keyvault Key is modified or deleted in Azure.
azure
Azure Keyvault Secrets Modified or Deleted
mediumIdentifies when secrets are modified or deleted in Azure.
azure
Azure Kubernetes Admission Controller
mediumIdentifies when an admission controller is executed in Azure Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
azure
Azure Kubernetes CronJob
mediumIdentifies when a Azure Kubernetes CronJob runs in Azure Cloud. Kubernetes Job is a controller that creates one or more pods and ensures that a specified number of them successfully terminate. Kubernetes Job can be used to run containers that perform finite tasks for batch jobs. Kubernetes CronJob is used to schedule Jobs. An Adversary may use Kubernetes CronJob for scheduling execution of malicious code that would run as a container in the cluster.
azure
Azure Kubernetes Events Deleted
mediumDetects when Events are deleted in Azure Kubernetes. An adversary may delete events in Azure Kubernetes in an attempt to evade detection.
azure
Azure Kubernetes Network Policy Change
mediumIdentifies when a Azure Kubernetes network policy is modified or deleted.
azure
Azure Kubernetes Pods Deleted
mediumIdentifies the deletion of Azure Kubernetes Pods.
azure
Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted
mediumDetects the creation or patching of potential malicious RoleBinding/ClusterRoleBinding.
azure
Azure Kubernetes Secret or Config Object Access
mediumIdentifies when a Kubernetes account access a sensitive objects such as configmaps or secrets.
azure
Azure Kubernetes Sensitive Role Access
mediumIdentifies when ClusterRoles/Roles are being modified or deleted.
azure
Azure Kubernetes Service Account Modified or Deleted
mediumIdentifies when a service account is modified or deleted.
azure
Azure Network Firewall Policy Modified or Deleted
mediumIdentifies when a Firewall Policy is Modified or Deleted.
azure
Azure Network Security Configuration Modified or Deleted
mediumIdentifies when a network security configuration is modified or deleted.
azure
Azure New CloudShell Created
mediumIdentifies when a new cloudshell is created inside of Azure portal.
azure
Azure Owner Removed From Application or Service Principal
mediumIdentifies when a owner is was removed from a application or service principal in Azure.
azure
Azure Point-to-site VPN Modified or Deleted
mediumIdentifies when a Point-to-site VPN is Modified or Deleted.
azure
Azure Service Principal Created
mediumIdentifies when a service principal is created in Azure.
azure
Azure Service Principal Removed
mediumIdentifies when a service principal was removed in Azure.
azure
Azure Suppression Rule Created
mediumIdentifies when a suppression rule is created in Azure. Adversary's could attempt this to evade detection.
azure
Azure Unusual Authentication Interruption
mediumDetects when there is a interruption in the authentication process.
azure
Azure Virtual Network Device Modified or Deleted
mediumIdentifies when a virtual network device is being modified or deleted. This can be a network interface, network virtual appliance, virtual hub, or virtual router.
azure
Azure Virtual Network Modified or Deleted
mediumIdentifies when a Virtual Network is modified or deleted in Azure.
azure
Azure VPN Connection Modified or Deleted
mediumIdentifies when a VPN connection is modified or deleted.
azure
Backup Catalog Deleted
mediumDetects backup catalog deletions
windows
Backup Files Deleted
mediumDetects deletion of files with extensions often used for backup files. Adversaries may delete or remove built-in operating system data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
windows · file_delete
Binary Proxy Execution Via Dotnet-Trace.EXE
mediumDetects commandline arguments for executing a child process via dotnet-trace.exe
windows · process_creation
Bitbucket Audit Log Configuration Updated
mediumDetects changes to the bitbucket audit log configuration.
bitbucket
Bitbucket Global Permission Changed
mediumDetects global permissions change activity.
bitbucket
Bitbucket Global Secret Scanning Rule Deleted
mediumDetects Bitbucket global secret scanning rule deletion activity.
bitbucket
Bitbucket Global SSH Settings Changed
mediumDetects Bitbucket global SSH access configuration changes.
bitbucket
Bitbucket User Details Export Attempt Detected
mediumDetects user data export activity.
bitbucket
Bitbucket User Login Failure
mediumDetects user authentication failure events. Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.
bitbucket
Bitbucket User Login Failure Via SSH
mediumDetects SSH user login access failures. Please note that this rule can be noisy and is recommended to use with correlation based on "author.name" field.
bitbucket
Bitbucket User Permissions Export Attempt
mediumDetects user permission data export attempt.
bitbucket
Bitlocker Key Retrieval
mediumMonitor and alert for Bitlocker key retrieval.
azure
BITS Transfer Job Downloading File Potential Suspicious Extension
mediumDetects new BITS transfer job saving local files with potential suspicious extensions
windows
BITS Transfer Job With Uncommon Or Suspicious Remote TLD
mediumDetects a suspicious download using the BITS client from a FQDN that is unusual. Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads.
windows
Bpfdoor TCP Ports Redirect
mediumAll TCP traffic on particular port from attacker is routed to different port. ex. '/sbin/iptables -t nat -D PREROUTING -p tcp -s 192.168.1.1 --dport 22 -j REDIRECT --to-ports 42392' The traffic looks like encrypted SSH communications going to TCP port 22, but in reality is being directed to the shell port once it hits the iptables rule for the attacker host only.
linux
BPFtrace Unsafe Option Usage
mediumDetects the usage of the unsafe bpftrace option
linux · process_creation
Browser Started with Remote Debugging
mediumDetects browsers starting with the remote debugging flags. Which is a technique often used to perform browser injection attacks
windows · process_creation
C# IL Code Compilation Via Ilasm.EXE
mediumDetects the use of "Ilasm.EXE" in order to compile C# intermediate (IL) code to EXE or DLL.
windows · process_creation
CA Policy Removed by Non Approved Actor
mediumMonitor and alert on conditional access changes where non approved actor removed CA Policy.
azure
CA Policy Updated by Non Approved Actor
mediumMonitor and alert on conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare "old" vs "new" value.
azure
Cab File Extraction Via Wusa.EXE
mediumDetects execution of the "wusa.exe" (Windows Update Standalone Installer) utility to extract cab using the "/extract" argument that is no longer supported.
windows · process_creation
Capture Credentials with Rpcping.exe
mediumDetects using Rpcping.exe to send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.
windows · process_creation
Certificate Exported From Local Certificate Store
mediumDetects when an application exports a certificate (and potentially the private key as well) from the local Windows certificate store.
windows
Certificate Exported Via Certutil.EXE
mediumDetects the execution of the certutil with the "exportPFX" flag which allows the utility to export certificates.
windows · process_creation
Certificate Exported Via PowerShell
mediumDetects calls to cmdlets that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
windows · process_creation
Certificate Exported Via PowerShell - ScriptBlock
mediumDetects calls to cmdlets inside of PowerShell scripts that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
windows · ps_script
Certificate Private Key Acquired
mediumDetects when an application acquires a certificate private key
windows
Certificate Use With No Strong Mapping
mediumDetects a user certificate that was valid but could not be mapped to a user in a strong way (such as via explicit mapping, key trust mapping, or a SID) This could be a sign of exploitation of the elevation of privilege vulnerabilities (CVE-2022-34691, CVE-2022-26931, CVE-2022-26923) that can occur when the KDC allows certificate spoofing by not requiring a strong mapping. Events where the AccountName and CN of the Subject do not match, or where the CN ends in a dollar sign indicating a machine, may indicate certificate spoofing.
windows
Certificate-Based Authentication Enabled
mediumDetects when certificate based authentication has been enabled in an Azure Active Directory tenant.
azure
Change PowerShell Policies to an Insecure Level
mediumDetects changing the PowerShell script execution policy to a potentially insecure level using the "-ExecutionPolicy" flag.
windows · process_creation
Change PowerShell Policies to an Insecure Level - PowerShell
mediumDetects changing the PowerShell script execution policy to a potentially insecure level using the "Set-ExecutionPolicy" cmdlet.
windows · ps_script
Change to Authentication Method
mediumChange to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.
azure
Change User Agents with WebRequest
mediumAdversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
windows · ps_script
Changing Existing Service ImagePath Value Via Reg.EXE
mediumAdversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
windows · process_creation
Chmod Targeting Sensitive Directories
mediumDetects chmod targeting files in sensitive directory paths on Linux systems. Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.
linux · process_creation
Chromium Browser Instance Executed With Custom Extension
mediumDetects a Chromium based browser process with the 'load-extension' flag to start a instance with a custom extension
windows · process_creation
Cisco Denial of Service
mediumDetect a system being shutdown or put into different boot mode
cisco
Cisco Dot1x Disabled
mediumDetects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface. Disabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network. This activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.
cisco
Cisco Duo Successful MFA Authentication Via Bypass Code
mediumDetects when a successful MFA authentication occurs due to the use of a bypass code. A bypass code is a temporary passcode created by an administrator for a specific user to access a Duo-protected application. These are generally used as "backup codes," so that enrolled users who are having problems with their mobile devices (e.g., mobile service is disrupted, the device is lost or stolen, etc.) or who temporarily can't use their enrolled devices (on a plane without mobile data services) can still access their Duo-protected systems.
cisco
Cisco File Deletion
mediumSee what files are being deleted from flash file systems
cisco
Cisco Modify Configuration
mediumModifications to a config that will serve an adversary's impacts or persistence
cisco
Cisco Show Commands Input
mediumSee what commands are being input into the device by other people, full credentials can be in the history
cisco
Cisco Sniffing
mediumShow when a monitor or a span/rspan is setup or modified
cisco
Classes Autorun Keys Modification
mediumDetects modification of Windows Registry Classes keys used for persistence. Adversaries modify these autostart extensibility points (ASEP) to execute malicious code when file types are opened or actions are performed. Various legitimate software also uses these keys. Currently, this rule only filters out known legitimate software paths, thus it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
windows · registry_set
Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
mediumDetects the use of the `syslog` syscall with action code 5 (SYSLOG_ACTION_CLEAR), (4 is SYSLOG_ACTION_READ_CLEAR and 6 is SYSLOG_ACTION_CONSOLE_OFF) which clears the kernel ring buffer (dmesg logs). This can be used by attackers to hide traces after exploitation or privilege escalation. A common technique is running `dmesg -c`, which triggers this syscall internally.
linux
Clear PowerShell History - PowerShell
mediumDetects keywords that could indicate clearing PowerShell history
windows · ps_script
Clear PowerShell History - PowerShell Module
mediumDetects keywords that could indicate clearing PowerShell history
windows · ps_module
Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
mediumDetects Clfs.sys being loaded by a process running from a potentially suspicious location. Clfs.sys is loaded as part of many CVEs exploits that targets Common Log File.
windows · image_load
ClickOnce Deployment Execution - Dfsvc.EXE Child Process
mediumDetects child processes of "dfsvc" which indicates a ClickOnce deployment execution.
windows · process_creation
ClickOnce Trust Prompt Tampering
mediumDetects changes to the ClickOnce trust prompt registry key in order to enable an installation from different locations such as the Internet.
windows · registry_set
Clipboard Access Via OSAScript
mediumDetects access to clipboard content via osascript, which may be used for data collection but also occurs in legitimate clipboard utilities and automation scripts
macos · process_creation
Clipboard Data Collection Via Pbpaste
mediumDetects execution of the "pbpaste" utility, which retrieves the contents of the clipboard (a.k.a. pasteboard) and writes them to the standard output (stdout). The utility is often used for creating new files with the clipboard content or for piping clipboard contents to other commands. It can also be used in shell scripts that may require clipboard content as input. Attackers can abuse this utility in order to collect data from the user clipboard, which may contain passwords or sensitive information. Use this rule to hunt for potential abuse of the utility by looking at the parent process and any potentially suspicious command line content.
macos · process_creation
Cloudflared Portable Execution
mediumDetects the execution of the "cloudflared" binary from a non standard location.
windows · process_creation
Cloudflared Quick Tunnel Execution
mediumDetects creation of an ad-hoc Cloudflare Quick Tunnel, which can be used to tunnel local services such as HTTP, RDP, SSH and SMB. The free TryCloudflare Quick Tunnel will generate a random subdomain on trycloudflare[.]com, following a call to api[.]trycloudflare[.]com. The tool has been observed in use by threat groups including Akira ransomware.
windows · process_creation
Cloudflared Tunnel Connections Cleanup
mediumDetects execution of the "cloudflared" tool with the tunnel "cleanup" flag in order to cleanup tunnel connections.
windows · process_creation
Cloudflared Tunnel Execution
mediumDetects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
windows · process_creation
Cloudflared Tunnels Related DNS Requests
mediumDetects DNS requests to Cloudflared tunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
CLR DLL Loaded Via Office Applications
mediumDetects CLR DLL being loaded by an Office Product
windows · image_load
Cmd Launched with Hidden Start Flags to Suspicious Targets
mediumDetects cmd.exe executing commands with the "start" utility using "/b" (no window) or "/min" (minimized) flags. To reduce false positives from standard background tasks, detection is restricted to scenarios where the target is a known script extension or located in suspicious temporary/public directories. This technique was observed in Chaos, DarkSide, and Emotet malware campaigns.
windows · process_creation
Code Execution via Pcwutl.dll
mediumDetects launch of executable by calling the LaunchApplication function from pcwutl.dll library.
windows · process_creation
CodePage Modification Via MODE.COM To Russian Language
mediumDetects a CodePage modification using the "mode.com" utility to Russian language. This behavior has been used by threat actors behind Dharma ransomware.
windows · process_creation
COM Hijacking via TreatAs
mediumDetect modification of TreatAs key to enable "rundll32.exe -sta" command
windows · registry_set
COM Object Execution via Xwizard.EXE
mediumDetects the execution of Xwizard tool with the "RunWizard" flag and a GUID like argument. This utility can be abused in order to run custom COM object created in the registry.
windows · process_creation
Command Line Execution with Suspicious URL and AppData Strings
mediumDetects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)
windows · process_creation
Common Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Communication To Uncommon Destination Ports
mediumDetects programs that connect to uncommon destination ports
windows · network_connection
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
mediumDetects a qlogin.exe command attempting to authenticate as the internal `_+_PublicSharingUser_` using a GUID as the password. This could be an indicator of an attacker exploiting CVE-2025-57788 to gain initial access using leaked credentials.
windows · process_creation
Compress Data and Lock With Password for Exfiltration With 7-ZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows · process_creation
Compress Data and Lock With Password for Exfiltration With WINZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows · process_creation
Computer Discovery And Export Via Get-ADComputer Cmdlet
mediumDetects usage of the Get-ADComputer cmdlet to collect computer information and output it to a file
windows · process_creation
Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell
mediumDetects usage of the Get-ADComputer cmdlet to collect computer information and output it to a file
windows · ps_script
Computer Password Change Via Ksetup.EXE
mediumDetects password change for the computer's domain account or host principal via "ksetup.exe"
windows · process_creation
Computer System Reconnaissance Via Wmic.EXE
mediumDetects execution of wmic utility with the "computersystem" flag in order to obtain information about the machine such as the domain, username, model, etc.
windows · process_creation
Conhost Spawned By Uncommon Parent Process
mediumDetects when the Console Window Host (conhost.exe) process is spawned by an uncommon parent process, which could be indicative of potential code injection activity.
windows · process_creation
Console CodePage Lookup Via CHCP
mediumDetects use of chcp to look up the system locale value as part of host discovery
windows · process_creation
ConvertTo-SecureString Cmdlet Usage Via CommandLine
mediumDetects usage of the "ConvertTo-SecureString" cmdlet via the commandline. Which is fairly uncommon and could indicate potential suspicious activity
windows · process_creation
Copy From Or To Admin Share Or Sysvol Folder
mediumDetects a copy command or a copy utility execution to or from an Admin share or remote
windows · process_creation
Crash Dump Created By Operating System
mediumDetects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
windows
CrashControl CrashDump Disabled
mediumDetects disabling the CrashDump per registry (as used by HermeticWiper)
windows · registry_set
Created Files by Microsoft Sync Center
mediumThis rule detects suspicious files created by Microsoft Sync Center (mobsync)
windows · file_event
CreateRemoteThread API and LoadLibrary
mediumDetects potential use of CreateRemoteThread api and LoadLibrary function to inject DLL into a process
windows · create_remote_thread
Creation of a Diagcab
mediumDetects the creation of diagcab file, which could be caused by some legitimate installer or is a sign of exploitation (review the filename and its location)
windows · file_event
Creation Of a Suspicious ADS File Outside a Browser Download
mediumDetects the creation of a suspicious ADS (Alternate Data Stream) file by software other than browsers
windows · create_stream_hash
Creation Of An User Account
mediumDetects the creation of a new user account. Such accounts may be used for persistence that do not require persistent remote access tools to be deployed on the system.
linux
Creation Of Non-Existent System DLL
mediumDetects creation of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes. Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs. Thus, the creation of such DLLs may indicate preparation for phantom DLL hijacking attacks.
windows · file_event
Creation Of Pod In System Namespace
mediumDetects deployments of pods within the kube-system namespace, which could be intended to imitate system pods. System pods, created by controllers such as Deployments or DaemonSets have random suffixes in their names. Attackers can use this fact and name their backdoor pods as if they were created by these controllers to avoid detection. Deployment of such a backdoor container e.g. named kube-proxy-bv61v, could be attempted in the kube-system namespace alongside the other administrative containers.
kubernetes · application
Creation of WerFault.exe/Wer.dll in Unusual Folder
mediumDetects the creation of a file named "WerFault.exe" or "wer.dll" in an uncommon folder, which could be a sign of WerFault DLL hijacking.
windows · file_event
Credential Manager Access By Uncommon Applications
mediumDetects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
windows · file_access
Credentials from Password Stores - Keychain
mediumDetects passwords dumps from Keychain
macos · process_creation
CredUI.DLL Loaded By Uncommon Process
mediumDetects loading of "credui.dll" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of "CredUIPromptForCredentials" or "CredUnPackAuthenticationBufferW".
windows · image_load
Cscript/Wscript Potentially Suspicious Child Process
mediumDetects potentially suspicious child processes of Wscript/Cscript. These include processes such as rundll32 with uncommon exports or PowerShell spawning rundll32 or regsvr32. Malware such as Pikabot and Qakbot were seen using similar techniques as well as many others.
windows · process_creation
CSExec Service File Creation
mediumDetects default CSExec service filename which indicates CSExec service installation and execution
windows · file_event
CSExec Service Installation
mediumDetects CSExec service installation and execution events
windows
Curl Web Request With Potential Custom User-Agent
mediumDetects execution of "curl.exe" with a potential custom "User-Agent". Attackers can leverage this to download or exfiltrate data via "curl" to a domain that only accept specific "User-Agent" strings
windows · process_creation
Curl.EXE Execution With Custom UserAgent
mediumDetects execution of curl.exe with custom useragent options
windows · process_creation
CurrentControlSet Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
CurrentVersion NT Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
CVE-2022-31659 VMware Workspace ONE Access RCE
mediumDetects possible exploitation of VMware Workspace ONE Access Admin Remote Code Execution vulnerability as described in CVE-2022-31659
webserver
CVE-2023-1389 Potential Exploitation Attempt - Unauthenticated Command Injection In TP-Link Archer AX21
mediumDetects potential exploitation attempt of CVE-2023-1389 an Unauthenticated Command Injection in TP-Link Archer AX21.
proxy
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
windows · process_creation
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
proxy
CVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
webserver
CVE-2023-40477 Potential Exploitation - WinRAR Application Crash
mediumDetects a crash of "WinRAR.exe" where the version is lower than 6.23. This could indicate potential exploitation of CVE-2023-40477
windows
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Proxy
mediumDetects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via proxy logs.
proxy
CVE-2023-4966 Potential Exploitation Attempt - Citrix ADC Sensitive Information Disclosure - Webserver
mediumDetects potential exploitation attempt of CVE-2023-4966 a Citrix ADC and NetScaler Gateway sensitive information disclosure vulnerability via webserver logs.
webserver
CVE-2024-1708 - ScreenConnect Path Traversal Exploitation
mediumThis detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708.
windows · file_event
DarkGate - Autoit3.EXE File Creation By Uncommon Process
mediumDetects the usage of curl.exe, KeyScramblerLogon, or other non-standard/suspicious processes used to create Autoit3.exe. This activity has been associated with DarkGate malware, which uses Autoit3.exe to execute shellcode that performs process injection and connects to the DarkGate command-and-control server. Curl, KeyScramblerLogon, and these other processes consitute non-standard and suspicious ways to retrieve the Autoit3 executable.
windows · file_event
DarkGate - Drop DarkGate Loader In C:\Temp Directory
mediumDetects attackers attempting to save, decrypt and execute the DarkGate Loader in C:\temp folder.
windows · file_event
Data Exfiltration to Unsanctioned Apps
mediumDetects when a Microsoft Cloud App Security reported when a user or IP address uses an app that is not sanctioned to perform an activity that resembles an attempt to exfiltrate information from your organization.
m365
Data Exfiltration with Wget
mediumDetects attempts to post the file with the usage of wget utility. The adversary can bypass the permission restriction with the misconfigured sudo permission for wget utility which could allow them to read files like /etc/shadow.
linux
Data Export From MSSQL Table Via BCP.EXE
mediumDetects the execution of the BCP utility in order to export data from the database. Attackers were seen saving their malware to a database column or table and then later extracting it via "bcp.exe" into a file.
windows · process_creation
Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process
mediumDetects the load of dbghelp/dbgcore DLL by a potentially uncommon or potentially suspicious process. The Dbghelp and Dbgcore DLLs export functions that allow for the dump of process memory. Tools like ProcessHacker, Task Manager and some attacker tradecraft use the MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine. Keep in mind that many legitimate Windows processes and services might load the aforementioned DLLs for debugging or other related purposes. Investigate the CommandLine and the Image location of the process loading the DLL.
windows · image_load
DCERPC SMB Spoolss Named Pipe
mediumDetects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
windows
Default Credentials Usage
mediumBefore deploying any new asset, change all default passwords to have values consistent with administrative level accounts. Sigma detects default credentials usage. Sigma for Qualys vulnerability scanner. Scan type - Vulnerability Management.
qualys
Defrag Deactivation
mediumDetects the deactivation and disabling of the Scheduled defragmentation task as seen by Slingshot APT group
windows · process_creation
Defrag Deactivation - Security
mediumDetects the deactivation and disabling of the Scheduled defragmentation task as seen by Slingshot APT group
windows
Delete Defender Scan ShellEx Context Menu Registry Key
mediumDetects deletion of registry key that adds 'Scan with Defender' option in context menu. Attackers may use this to make it harder for users to scan files that are suspicious.
windows · registry_delete
Deleted Data Overwritten Via Cipher.EXE
mediumDetects usage of the "cipher" built-in utility in order to overwrite deleted data from disk. Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives
windows · process_creation
Denied Access To Remote Desktop
mediumThis event is generated when an authenticated user who is not allowed to log on remotely attempts to connect to this computer through Remote Desktop. Often, this event can be generated by attackers when searching for available windows servers in the network.
windows
Deployment AppX Package Was Blocked By AppLocker
mediumDetects an appx package deployment that was blocked by AppLocker policy.
windows
Deployment Of The AppX Package Was Blocked By The Policy
mediumDetects an appx package deployment that was blocked by the local computer policy. The following events indicate that an AppX package deployment was blocked by a policy: - Event ID 441: The package deployment operation is blocked by the "Allow deployment operations in special profiles" policy - Event ID 442: Deployments to non-system volumes are blocked by the "Disable deployment of Windows Store apps to non-system volumes" policy." - Event ID 453: Package blocked by a platform policy. - Event ID 454: Package blocked by a platform policy.
windows
Desktop.INI Created by Uncommon Process
mediumDetects unusual processes accessing desktop.ini, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
windows · file_event
Detected Windows Software Discovery
mediumAdversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable.
windows · process_creation
Detected Windows Software Discovery - PowerShell
mediumAdversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable.
windows · ps_script
Detection of PowerShell Execution via Sqlps.exe
mediumThis rule detects execution of a PowerShell code through the sqlps.exe utility, which is included in the standard set of utilities supplied with the MSSQL Server. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.
windows · process_creation
Device Installation Blocked
mediumDetects an installation of a device that is forbidden by the system policy
windows
Device Registration or Join Without MFA
mediumMonitor and alert for device registration or join events where MFA was not performed.
azure
DeviceCredentialDeployment Execution
mediumDetects the execution of DeviceCredentialDeployment to hide a process from view.
windows · process_creation
Dfsvc.EXE Network Connection To Non-Local IPs
mediumDetects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs
windows · network_connection
Direct Autorun Keys Modification
mediumDetects direct modification of autostart extensibility point (ASEP) in registry using reg.exe.
windows · process_creation
DirectorySearcher Powershell Exploitation
mediumEnumerates Active Directory to determine computers that are joined to the domain
windows · ps_script
Disable Administrative Share Creation at Startup
mediumAdministrative shares are hidden network shares created by Microsoft Windows NT operating systems that grant system administrators remote access to every disk volume on a network-connected system
windows · registry_set
Disable Exploit Guard Network Protection on Windows Defender
mediumDetects disabling Windows Defender Exploit Guard Network Protection
windows · registry_set
Disable Internal Tools or Feature in Registry
mediumDetects registry modifications that change features of internal Windows tools (malware like Agent Tesla uses this technique)
windows · registry_set
Disable Microsoft Defender Firewall via Registry
mediumAdversaries may disable or modify system firewalls in order to bypass controls limiting network usage
windows · registry_set
Disable Or Stop Services
mediumDetects the usage of utilities such as 'systemctl', 'service'...etc to stop or disable tools and services on Linux systems. Attackers may stop or disable security tools and services to evade detection, maintain persistence, or disrupt system operations.
linux · process_creation
Disable Privacy Settings Experience in Registry
mediumDetects registry modifications that disable Privacy Settings Experience
windows · registry_set
Disable Security Tools
mediumDetects disabling security tools
macos · process_creation
Disable Tamper Protection on Windows Defender
mediumDetects disabling Windows Defender Tamper Protection
windows · registry_set
Disable Windows Firewall by Registry
mediumDetect set EnableFirewall to 0 to disable the Windows firewall
windows · registry_set
Disable Windows Security Center Notifications
mediumDetect set UseActionCenterExperience to 0 to disable the Windows security center notification
windows · registry_set
Disabled MFA to Bypass Authentication Mechanisms
mediumDetection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.
azure
Disabling Security Tools
mediumDetects disabling security tools
linux · process_creation
Disabling Security Tools - Builtin
mediumDetects disabling security tools
linux
Disk Image Creation Via Hdiutil - MacOS
mediumDetects the execution of the hdiutil utility in order to create a disk image.
macos · process_creation
Disk Image Mounting Via Hdiutil - MacOS
mediumDetects the execution of the hdiutil utility in order to mount disk images.
macos · process_creation
Diskshadow Child Process Spawned
mediumDetects any child process spawning from "Diskshadow.exe". This could be due to executing Diskshadow in interpreter mode or script mode and using the "exec" flag to launch other applications.
windows · process_creation
Diskshadow Script Mode - Execution From Potential Suspicious Location
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag where the script is located in a potentially suspicious location.
windows · process_creation
Diskshadow Script Mode - Uncommon Script Extension Execution
mediumDetects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.
windows · process_creation
Diskshadow Script Mode Execution
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag. Attackers often abuse "diskshadow" to execute scripts that deleted the shadow copies on the systems. Investigate the content of the scripts and its location.
windows · process_creation
Dism Remove Online Package
mediumDeployment Image Servicing and Management tool. DISM is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows · process_creation
Displaying Hidden Files Feature Disabled
mediumDetects modifications to the "Hidden" and "ShowSuperHidden" explorer registry values in order to disable showing of hidden files and system files. This technique is abused by several malware families to hide their files from normal users.
windows · registry_set
Django Framework Exceptions
mediumDetects suspicious Django web application framework exceptions that could indicate exploitation attempts
django · application
DLL Call by Ordinal Via Rundll32.EXE
mediumDetects calls of DLLs exports by ordinal numbers via rundll32.dll.
windows · process_creation
DLL Execution via Rasautou.exe
mediumDetects using Rasautou.exe for loading arbitrary .DLL specified in -d option and executes the export specified in -p.
windows · process_creation
DLL Execution Via Register-cimprovider.exe
mediumDetects using register-cimprovider.exe to execute arbitrary dll file.
windows · process_creation
DLL Load By System Process From Suspicious Locations
mediumDetects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as "C:\Users\Public"
windows · image_load
DLL Loaded via CertOC.EXE
mediumDetects when a user installs certificates by using CertOC.exe to loads the target DLL file.
windows · process_creation
DLL Names Used By SVR For GraphicalProton Backdoor
mediumHunts known SVR-specific DLL names.
windows · image_load
Dllhost.EXE Initiated Network Connection To Non-Local IP Address
mediumDetects Dllhost.EXE initiating a network connection to a non-local IP address. Aside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL. An initial baseline is recommended before deployment.
windows · network_connection
DllUnregisterServer Function Call Via Msiexec.EXE
mediumDetects MsiExec loading a DLL and calling its DllUnregisterServer function
windows · process_creation
DMSA Service Account Created in Specific OUs - PowerShell
mediumDetects the creation of a dMSA service account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows · ps_script
DNS Query Request By Regsvr32.EXE
mediumDetects DNS queries initiated by "Regsvr32.exe"
windows · dns_query
DNS Query To AzureWebsites.NET By Non-Browser Process
mediumDetects a DNS query by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
windows · dns_query
DNS Query To Common Malware Hosting and Shortener Services
mediumDetects DNS queries to domains commonly used by threat actors to host malware payloads or redirect through URL shorteners. These include platforms like Cloudflare Workers, TryCloudflare, InfinityFree, and URL shorteners such as tinyurl and lihi.cc. Such DNS activity can indicate potential delivery or command-and-control communication attempts.
windows · dns_query
DNS Query To Devtunnels Domain
mediumDetects DNS query requests to Devtunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
DNS Query To MEGA Hosting Website
mediumDetects DNS queries for subdomains related to MEGA sharing website
windows · dns_query
DNS Query To MEGA Hosting Website - DNS Client
mediumDetects DNS queries for subdomains related to MEGA sharing website
windows
DNS Query To Put.io - DNS Client
mediumDetects DNS queries for subdomains related to "Put.io" sharing website.
windows
DNS Query To Remote Access Software Domain From Non-Browser App
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · dns_query
DNS Query To Visual Studio Code Tunnels Domain
mediumDetects DNS query requests to Visual Studio Code tunnel domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
DNS TOR Proxies
mediumIdentifies IPs performing DNS lookups associated with common Tor proxies.
zeek
DNS-over-HTTPS Enabled by Registry
mediumDetects when a user enables DNS-over-HTTPS. This can be used to hide internet activity or be used to hide the process of exfiltrating data. With this enabled organization will lose visibility into data such as query type, response and originating IP that are used to determine bad actors.
windows · registry_set
Domain Trust Discovery Via Dsquery
mediumDetects execution of "dsquery.exe" for domain trust discovery
windows · process_creation
DotNET Assembly DLL Loaded Via Office Application
mediumDetects any assembly DLL being loaded by an Office Product
windows · image_load
Download File To Potentially Suspicious Directory Via Wget
mediumDetects the use of wget to download content to a suspicious directory
linux · process_creation
Download from Suspicious Dyndns Hosts
mediumDetects download of certain file types from hosts with dynamic DNS names (selected list)
proxy
DPAPI Domain Master Key Backup Attempt
mediumDetects anyone attempting a backup for the DPAPI Master Key. This events gets generated at the source and not the Domain Controller.
windows
Driver/DLL Installation Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "INSTALLDRIVER" which installs a new ODBC driver. Attackers abuse this to install and run malicious DLLs.
windows · process_creation
DriverQuery.EXE Execution
mediumDetect usage of the "driverquery" utility. Which can be used to perform reconnaissance on installed drivers
windows · process_creation
Drop Binaries Into Spool Drivers Color Folder
mediumDetects the creation of suspcious binary files inside the "\windows\system32\spool\drivers\color\" as seen in the blog referenced below
windows · file_event
Dropping Of Password Filter DLL
mediumDetects dropping of dll files in system32 that may be used to retrieve user credentials from LSASS
windows · process_creation
Dump Credentials from Windows Credential Manager With PowerShell
mediumAdversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials.
windows · ps_script
Dump Ntds.dit To Suspicious Location
mediumDetects potential abuse of ntdsutil to dump ntds.dit database to a suspicious location
windows
Dumping Process via Sqldumper.exe
mediumDetects process dump via legitimate sqldumper.exe binary
windows · process_creation
DumpMinitool Execution
mediumDetects the use of "DumpMinitool.exe" a tool that allows the dump of process memory via the use of the "MiniDumpWriteDump"
windows · process_creation
Dynamic .NET Compilation Via Csc.EXE
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows · process_creation
Dynamic .NET Compilation Via Csc.EXE - Hunting
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows · process_creation
Elevated System Shell Spawned
mediumDetects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges. Use this rule to hunt for potential suspicious processes.
windows · process_creation
Elevated System Shell Spawned From Uncommon Parent Location
mediumDetects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges from a uncommon parent location.
windows · process_creation
Enable BPF Kprobes Tracing
mediumDetects common command used to enable bpf kprobes tracing
linux · process_creation
Enable Local Manifest Installation With Winget
mediumDetects changes to the AppInstaller (winget) policy. Specifically the activation of the local manifest installation, which allows a user to install new packages via custom manifests.
windows · registry_set
Enable Microsoft Dynamic Data Exchange
mediumEnable Dynamic Data Exchange protocol (DDE) in all supported editions of Microsoft Word or Excel.
windows · registry_set
Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
mediumDetects enabling of the "AllowAnonymousCallback" registry value, which allows a remote connection between computers that do not have a trust relationship.
windows · registry_set
Enable Windows Remote Management
mediumAdversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
windows · ps_script
Enabling COR Profiler Environment Variables
mediumDetects .NET Framework CLR and .NET Core CLR "cor_enable_profiling" and "cor_profiler" variables being set and configured.
windows · registry_set
End User Consent Blocked
mediumDetects when end user consent is blocked due to risk-based consent.
azure
Enumerate All Information With Whoami.EXE
mediumDetects the execution of "whoami.exe" with the "/all" flag
windows · process_creation
Enumerate Credentials from Windows Credential Manager With PowerShell
mediumAdversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials.
windows · ps_script
Enumeration for 3rd Party Creds From CLI
mediumDetects processes that query known 3rd party registry keys that holds credentials via commandline
windows · process_creation
Enumeration for Credentials in Registry
mediumAdversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services
windows · process_creation
Esentutl Gather Credentials
mediumConti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.
windows · process_creation
Esentutl Steals Browser Information
mediumOne way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
windows · process_creation
ESXi Account Creation Via ESXCLI
mediumDetects user account creation on ESXi system via esxcli
linux · process_creation
ESXi Network Configuration Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "network" flag in order to retrieve information about the network configuration.
linux · process_creation
ESXi Storage Information Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "storage" flag in order to retrieve information about the storage status and other related information. Seen used by malware such as DarkSide and LockBit.
linux · process_creation
ESXi Syslog Configuration Change Via ESXCLI
mediumDetects changes to the ESXi syslog configuration via "esxcli"
linux · process_creation
ESXi System Information Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "system" flag in order to retrieve information about the different component of the system. Such as accounts, modules, NTP, etc.
linux · process_creation
ESXi VM Kill Via ESXCLI
mediumDetects execution of the "esxcli" command with the "vm" and "kill" flag in order to kill/shutdown a specific VM.
linux · process_creation
ESXi VM List Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "vm" flag in order to retrieve information about the installed VMs.
linux · process_creation
ESXi VSAN Information Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "vsan" flag in order to retrieve information about virtual storage. Seen used by malware such as DarkSide.
linux · process_creation
ETW Logging/Processing Option Disabled On IIS Server
mediumDetects changes to of the IIS server configuration in order to disable/remove the ETW logging/processing option.
windows
Eventlog Cleared
mediumOne of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution
windows
EventLog EVTX File Deleted
mediumDetects the deletion of the event log files which may indicate an attempt to destroy forensic evidence
windows · file_delete
EventLog Query Requests By Builtin Utilities
mediumDetect attempts to query the contents of the event log using command line utilities. Attackers use this technique in order to look for sensitive information in the logs such as passwords, usernames, IPs, etc.
windows · process_creation
EVTX Created In Uncommon Location
mediumDetects the creation of new files with the ".evtx" extension in non-common or non-standard location. This could indicate tampering with default EVTX locations in order to evade security controls or simply exfiltration of event log to search for sensitive information within. Note that backup software and legitimate administrator might perform similar actions during troubleshooting.
windows · file_event
Executable from Webdav
mediumDetects executable access via webdav6. Can be seen in APT 29 such as from the emulated APT 29 hackathon https://github.com/OTRF/detection-hackathon-apt29/
zeek
Execute Code with Pester.bat
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows · process_creation
Execute Code with Pester.bat as Parent
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows · process_creation
Execute Files with Msdeploy.exe
mediumDetects file execution using the msdeploy.exe lolbin
windows · process_creation
Execute From Alternate Data Streams
mediumDetects execution from an Alternate Data Stream (ADS). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection
windows · process_creation
Execute Invoke-command on Remote Host
mediumAdversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
windows · ps_script
Execution From Webserver Root Folder
mediumDetects a program executing from a web server root folder. Use this rule to hunt for potential interesting activity such as webshell or backdoors
windows · process_creation
Execution Of Script Located In Potentially Suspicious Directory
mediumDetects executions of scripts located in potentially suspicious locations such as "/tmp" via a shell such as "bash", "sh", etc.
linux · process_creation
Execution of Suspicious File Type Extension
mediumDetects whether the image specified in a process creation event doesn't refer to an ".exe" (or other known executable extension) file. This can be caused by process ghosting or other unorthodox methods to start a process. This rule might require some initial baselining to align with some third party tooling in the user environment.
windows · process_creation
Exploit for CVE-2017-0261
mediumDetects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
windows · process_creation
Explorer Process Tree Break
mediumDetects a command line process that uses explorer.exe to launch arbitrary commands or binaries, which is similar to cmd.exe /c, only it breaks the process tree and makes its parent a new instance of explorer spawning from "svchost"
windows · process_creation
External Remote RDP Logon from Public IP
mediumDetects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
windows
Extracting Information with PowerShell
mediumAdversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
windows · ps_script
F5 BIG-IP iControl Rest API Command Execution - Proxy
mediumDetects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
proxy
F5 BIG-IP iControl Rest API Command Execution - Webserver
mediumDetects POST requests to the F5 BIG-IP iControl Rest API "bash" endpoint, which allows the execution of commands on the BIG-IP
webserver
Failed DNS Zone Transfer
mediumDetects when a DNS zone transfer failed.
windows
Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
mediumDetects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method. Event 5858 in the WMI-Activity operational log is an error event, meaning it is only generated when the WMI operation encounters an error (e.g. access denied, provider failure). It could be an indication of an attacker attempting to clear event logs via WMI, but failing due to insufficient privileges or other issues. Successful clearing operations will NOT produce this event; for those, correlate with Security event 1102 or System event 104.
windows
Failed Logon From Public IP
mediumDetects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
windows
File Access Of Signal Desktop Sensitive Data
mediumDetects access to Signal Desktop's sensitive data files: db.sqlite and config.json. The db.sqlite file in Signal Desktop stores all locally saved messages in an encrypted SQLite database, while the config.json contains the decryption key needed to access that data. Since the key is stored in plain text, a threat actor who gains access to both files can decrypt and read sensitive messages without needing the users credentials. Currently the rule only covers the default Signal installation path in AppData\Roaming. Signal Portable installations may use different paths based on user configuration. Additional paths can be added to the selection as needed.
windows
File Decryption Using Gpg4win
mediumDetects usage of Gpg4win to decrypt files
windows · process_creation
File Deleted Via Sysinternals SDelete
mediumDetects the deletion of files by the Sysinternals SDelete utility. It looks for the common name pattern used to rename files.
windows · file_delete
File Download From Browser Process Via Inline URL
mediumDetects execution of a browser process with a URL argument pointing to a file with a potentially interesting extension. This can be abused to download arbitrary files or to hide from the user for example by launching the browser in a minimized state.
windows · process_creation
File Download From IP URL Via Curl.EXE
mediumDetects file downloads directly from IP address URL using curl.exe
windows · process_creation
File Download Using ProtocolHandler.exe
mediumDetects usage of "ProtocolHandler" to download files. Downloaded files will be located in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)
windows · process_creation
File Download Via Bitsadmin
mediumDetects usage of bitsadmin downloading a file
windows · process_creation
File Download via CertOC.EXE
mediumDetects when a user downloads a file by using CertOC.exe
windows · process_creation
File Download Via Curl.EXE
mediumDetects file download using curl.exe
windows · process_creation
File Download Via InstallUtil.EXE
mediumDetects use of .NET InstallUtil.exe in order to download arbitrary files. The files will be written to "%LOCALAPPDATA%\Microsoft\Windows\INetCache\IE\"
windows · process_creation
File Download Via Nscurl - MacOS
mediumDetects the execution of the nscurl utility in order to download files.
macos · process_creation
File Encoded To Base64 Via Certutil.EXE
mediumDetects the execution of certutil with the "encode" flag to encode a file to base64. This can be abused by threat actors and attackers for data exfiltration
windows · process_creation
File Encryption Using Gpg4win
mediumDetects usage of Gpg4win to encrypt files
windows · process_creation
File or Folder Permissions Modifications
mediumDetects a file or folder's permissions being modified or tampered with.
windows · process_creation
File Recovery From Backup Via Wbadmin.EXE
mediumDetects the recovery of files from backups via "wbadmin.exe". Attackers can restore sensitive files such as NTDS.DIT or Registry Hives from backups in order to potentially extract credentials.
windows · process_creation
File Time Attribute Change
mediumDetect file time attribute change to hide new or changes to existing files
macos · process_creation
File Time Attribute Change - Linux
mediumDetect file time attribute change to hide new or changes to existing files.
linux
Files With System DLL Name In Unsuspected Locations
mediumDetects the creation of a file with the ".dll" extension that has the name of a System DLL in uncommon or unsuspected locations. (Outisde of "System32", "SysWOW64", etc.). It is highly recommended to perform an initial baseline before using this rule in production.
windows · file_event
Files With System Process Name In Unsuspected Locations
mediumDetects the creation of an executable with a system process name in folders other than the system ones (System32, SysWOW64, etc.). It is highly recommended to perform an initial baseline before using this rule in production.
windows · file_event
Filter Driver Unloaded Via Fltmc.EXE
mediumDetect filter driver unloading activity via fltmc.exe
windows · process_creation
Findstr Launching .lnk File
mediumDetects usage of findstr to identify and execute a lnk file as seen within the HHS redirect attack
windows · process_creation
Firewall Disabled via Netsh.EXE
mediumDetects netsh commands that turns off the Windows firewall
windows · process_creation
Firewall Rule Deleted Via Netsh.EXE
mediumDetects the removal of a port or application rule in the Windows Firewall configuration using netsh
windows · process_creation
Firewall Rule Update Via Netsh.EXE
mediumDetects execution of netsh with the "advfirewall" and the "set" option in order to set new values for properties of a existing rule
windows · process_creation
Flush Iptables Ufw Chain
mediumDetect use of iptables to flush all firewall rules, tables and chains and allow all network traffic
linux · process_creation
Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · process_creation
Forest Blizzard APT - JavaScript Constrained File Creation
mediumDetects the creation of JavaScript files inside of the DriverStore directory. Forest Blizzard used this to exploit the CVE-2022-38028 vulnerability in Windows Print Spooler service by modifying a JavaScript constraints file and executing it with SYSTEM-level permissions.
windows · file_event
Forfiles Command Execution
mediumDetects the execution of "forfiles" with the "/c" flag. While this is an expected behavior of the tool, it can be abused in order to proxy execution through it with any binary. Can be used to bypass application whitelisting.
windows · process_creation
FortiGate - Firewall Address Object Added
mediumDetects the addition of firewall address objects on a Fortinet FortiGate Firewall.
fortigate
FortiGate - New Administrator Account Created
mediumDetects the creation of an administrator account on a Fortinet FortiGate Firewall.
fortigate
FortiGate - New Firewall Policy Added
mediumDetects the addition of a new firewall policy on a Fortinet FortiGate Firewall.
fortigate
FortiGate - New Local User Created
mediumDetects the creation of a new local user on a Fortinet FortiGate Firewall. The new local user could be used for VPN connections.
fortigate
FortiGate - New VPN SSL Web Portal Added
mediumDetects the addition of a VPN SSL Web Portal on a Fortinet FortiGate Firewall. This behavior was observed in pair with modification of VPN SSL settings.
fortigate
FortiGate - User Group Modified
mediumDetects the modification of a user group on a Fortinet FortiGate Firewall. The group could be used to grant VPN access to a network.
fortigate
FortiGate - VPN SSL Settings Modified
mediumDetects the modification of VPN SSL Settings (for example, the modification of authentication rules). This behavior was observed in pair with the addition of a VPN SSL Web Portal.
fortigate
FTP Connection Open Attempt Via Winscp CLI
mediumDetects the execution of Winscp with the "-command" and the "open" flags in order to open an FTP connection. Akira ransomware was seen using this technique in order to exfiltrate data.
windows · process_creation
Function Call From Undocumented COM Interface EditionUpgradeManager
mediumDetects function calls from the EditionUpgradeManager COM interface. Which is an interface that is not used by standard executables.
windows · process_access
GatherNetworkInfo.VBS Reconnaissance Script Output
mediumDetects creation of files which are the results of executing the built-in reconnaissance script "C:\Windows\System32\gatherNetworkInfo.vbs".
windows · file_event
GCP Access Policy Deleted
mediumDetects when an access policy that is applied to a GCP cloud resource is deleted. An adversary would be able to remove access policies to gain access to a GCP cloud resource.
gcp
GCP Break-glass Container Workload Deployed
mediumDetects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.
gcp
Get-ADUser Enumeration Using UserAccountControl Flags
mediumDetects AS-REP roasting is an attack that is often-overlooked. It is not very common as you have to explicitly set accounts that do not require pre-authentication.
windows · ps_script
Github Delete Action Invoked
mediumDetects delete action in the Github audit logs for codespaces, environment, project and repo.
github
Github Fork Private Repositories Setting Enabled/Cleared
mediumDetects when the policy allowing forks of private and internal repositories is changed (enabled or cleared).
github
Github Outside Collaborator Detected
mediumDetects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an owner removes an outside collaborator from an organization or when two-factor authentication is required in an organization and an outside collaborator does not use 2FA or disables 2FA.
github
Github Repository/Organization Transferred
mediumDetects when a repository or an organization is being transferred to another location.
github
Github Self-Hosted Runner Execution
mediumDetects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.
windows · process_creation
Github SSH Certificate Configuration Changed
mediumDetects when changes are made to the SSH certificate configuration of the organization.
github
Google Cloud DNS Zone Modified or Deleted
mediumIdentifies when a DNS Zone is modified or deleted in Google Cloud.
gcp
Google Cloud Firewall Modified or Deleted
mediumDetects when a firewall rule is modified or deleted in Google Cloud Platform (GCP).
gcp
Google Cloud Kubernetes Admission Controller
mediumIdentifies when an admission controller is executed in GCP Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
gcp
Google Cloud Kubernetes CronJob
mediumIdentifies when a Google Cloud Kubernetes CronJob runs in Azure Cloud. Kubernetes Job is a controller that creates one or more pods and ensures that a specified number of them successfully terminate. Kubernetes Job can be used to run containers that perform finite tasks for batch jobs. Kubernetes CronJob is used to schedule Jobs. An Adversary may use Kubernetes CronJob for scheduling execution of malicious code that would run as a container in the cluster.
gcp
Google Cloud Kubernetes RoleBinding
mediumDetects the creation or patching of potential malicious RoleBinding. This includes RoleBindings and ClusterRoleBinding.
gcp
Google Cloud Kubernetes Secrets Modified or Deleted
mediumIdentifies when the Secrets are Modified or Deleted.
gcp
Google Cloud Re-identifies Sensitive Information
mediumIdentifies when sensitive information is re-identified in google Cloud.
gcp
Google Cloud Service Account Disabled or Deleted
mediumIdentifies when a service account is disabled or deleted in Google Cloud.
gcp
Google Cloud Service Account Modified
mediumIdentifies when a service account is modified in Google Cloud.
gcp
Google Cloud SQL Database Modified or Deleted
mediumDetect when a Cloud SQL DB has been modified or deleted.
gcp
Google Cloud Storage Buckets Modified or Deleted
mediumDetects when storage bucket is modified or deleted in Google Cloud.
gcp
Google Cloud VPN Tunnel Modified or Deleted
mediumIdentifies when a VPN Tunnel Modified or Deleted in Google Cloud.
gcp
Google Full Network Traffic Packet Capture
mediumIdentifies potential full network packet capture in gcp. This feature can potentially be abused to read sensitive data from unencrypted internal traffic.
gcp
Google Workspace Application Access Level Modified
mediumDetects when an access level is changed for a Google workspace application. An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model. An adversary would be able to remove access levels to gain easier access to Google workspace resources.
gcp
Google Workspace Application Removed
mediumDetects when an an application is removed from Google Workspace.
gcp
Google Workspace Government Attack Warning
mediumDetects a login attempt in Google Workspace flagged as a potential attack by a government-backed threat actor
gcp
Google Workspace Granted Domain API Access
mediumDetects when an API access service account is granted domain authority.
gcp
Google Workspace MFA Disabled
mediumDetects when multi-factor authentication (MFA) is disabled.
gcp
Google Workspace Out Of Domain Email Forwarding
mediumDetects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse.
gcp
Google Workspace Role Modified or Deleted
mediumDetects when an a role is modified or deleted in Google Workspace.
gcp
Google Workspace Role Privilege Deleted
mediumDetects when an a role privilege is deleted in Google Workspace.
gcp
Google Workspace User Granted Admin Privileges
mediumDetects when an Google Workspace user is granted admin privileges.
gcp
GoToAssist Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
Gpresult Display Group Policy Information
mediumDetects cases in which a user uses the built-in Windows utility gpresult to display the Resultant Set of Policy (RSoP) information
windows · process_creation
Gpscript Execution
mediumDetects the execution of the LOLBIN gpscript, which executes logon or startup scripts configured in Group Policy
windows · process_creation
Granting Of Permissions To An Account
mediumIdentifies IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
azure
Greedy File Deletion Using Del
mediumDetects execution of the "del" builtin command to remove files using greedy/wildcard expression. This is often used by malware to delete content of folders that perhaps contains the initial malware infection or to delete evidence.
windows · process_creation
Group Has Been Deleted Via Groupdel
mediumDetects execution of the "groupdel" binary. Which is used to delete a group. This is sometimes abused by threat actors in order to cover their tracks
linux · process_creation
Group Membership Reconnaissance Via Whoami.EXE
mediumDetects the execution of whoami.exe with the /group command line flag to show group membership for the current user, account type, security identifiers (SID), and attributes.
windows · process_creation
Group Policy Abuse for Privilege Addition
mediumDetects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.
windows
Guest User Invited By Non Approved Inviters
mediumDetects when a user that doesn't have permissions to invite a guest user attempts to invite one.
azure
Guest Users Invited To Tenant By Non Approved Inviters
mediumDetects guest users being invited to tenant by non-approved inviters
azure
Gzip Archive Decode Via PowerShell
mediumDetects attempts of decoding encoded Gzip archives via PowerShell.
windows · process_creation
HackTool - Impersonate Execution
mediumDetects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
windows · process_creation
HackTool - Jlaive In-Memory Assembly Execution
mediumDetects the use of Jlaive to execute assemblies in a copied PowerShell
windows · process_creation
HackTool - LaZagne Execution
mediumDetects the execution of the LaZagne. A utility used to retrieve multiple types of passwords stored on a local computer. LaZagne has been leveraged multiple times by threat actors in order to dump credentials.
windows · process_creation
HackTool - SharpLDAPmonitor Execution
mediumDetects execution of the SharpLDAPmonitor. Which can monitor the creation, deletion and changes to LDAP objects.
windows · process_creation
HackTool - WinRM Access Via Evil-WinRM
mediumAdversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
windows · process_creation
Hardware Model Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC with the "csproduct" which is used to obtain information such as hardware models and vendor information
windows · process_creation
Harvesting Of Wifi Credentials Via Netsh.EXE
mediumDetect the harvesting of wifi credentials using netsh.exe
windows · process_creation
Headless Process Launched Via Conhost.EXE
mediumDetects the launch of a child process via "conhost.exe" with the "--headless" flag. The "--headless" flag hides the windows from the user upon execution.
windows · process_creation
HH.EXE Initiated HTTP Network Connection
mediumDetects a network connection initiated by the "hh.exe" process to HTTP destination ports, which could indicate the execution/download of remotely hosted .chm files.
windows · network_connection
Hidden Executable In NTFS Alternate Data Stream
mediumDetects the creation of an ADS (Alternate Data Stream) that contains an executable by looking at a non-empty Imphash
windows · create_stream_hash
Hidden Flag Set On File/Directory Via Chflags - MacOS
mediumDetects the execution of the "chflags" utility with the "hidden" flag, in order to hide files on MacOS. When a file or directory has this hidden flag set, it becomes invisible to the default file listing commands and in graphical file browsers.
macos · process_creation
Hidden Powershell in Link File Pattern
mediumDetects events that appear when a user click on a link file with a powershell command in it
windows · process_creation
Hidden User Creation
mediumDetects creation of a hidden user account on macOS (UserID < 500) or with IsHidden option
macos · process_creation
Hiding Files with Attrib.exe
mediumDetects usage of attrib.exe to hide files from users.
windows · process_creation
Hiding User Account Via SpecialAccounts Registry Key - CommandLine
mediumDetects changes to the registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\Userlist" where the value is set to "0" in order to hide user account from being listed on the logon screen.
windows · process_creation
HTTP Request to Low Reputation TLD or Suspicious File Extension
mediumDetects HTTP requests to low reputation TLDs (e.g. .xyz, .top, .ru) or ending in suspicious file extensions (.exe, .dll, .hta), which may indicate malicious activity.
zeek
HTTP Request With Empty User Agent
mediumDetects a potentially suspicious empty user agent strings in proxy log. Could potentially indicate an uncommon request method.
proxy
IE Change Domain Zone
mediumHides the file extension through modification of the registry
windows · registry_set
Ie4uinit Lolbin Use From Invalid Path
mediumDetect use of ie4uinit.exe to execute commands from a specially prepared ie4uinit.inf file from a directory other than the usual directories
windows · process_creation
IIS Native-Code Module Command Line Installation
mediumDetects suspicious IIS native-code module installations via command line
windows · process_creation
IIS WebServer Access Logs Deleted
mediumDetects the deletion of IIS WebServer access logs which may indicate an attempt to destroy forensic evidence
windows · file_delete
IIS WebServer Log Deletion via CommandLine Utilities
mediumDetects attempts to delete Internet Information Services (IIS) log files via command line utilities, which is a common defense evasion technique used by attackers to cover their tracks. Threat actors often abuse vulnerabilities in web applications hosted on IIS servers to gain initial access and later delete IIS logs to evade detection.
windows · process_creation
Import LDAP Data Interchange Format File Via Ldifde.EXE
mediumDetects the execution of "Ldifde.exe" with the import flag "-i". The can be abused to include HTTP-based arguments which will allow the arbitrary download of files from a remote server.
windows · process_creation
Import PowerShell Modules From Suspicious Directories
mediumDetects powershell scripts that import modules from suspicious directories
windows · ps_script
Import PowerShell Modules From Suspicious Directories - ProcCreation
mediumDetects powershell scripts that import modules from suspicious directories
windows · process_creation
Imports Registry Key From a File
mediumDetects the import of the specified file to the registry with regedit.exe.
windows · process_creation
Inbox Rules Creation Or Update Activity in O365
mediumDetects inbox rule creation or update via O365 Audit logs, a technique commonly observed in Business Email Compromise (BEC) attacks to hide emails. The usage of inbox rules can be a sign of a compromised mailbox, where an attacker is attempting to evade detections by suppressing or redirecting incoming emails. Analysts should review these rules in context, validate whether they reflect normal user behavior, and correlate with other indicators such as unusual login activity or recent mailbox rule modifications.
m365
Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet
mediumDetects inbox rule creation or update via ExchangePowerShell cmdlet, a technique commonly observed in Business Email Compromise (BEC) attacks to hide emails. The usage of inbox rules can be a sign of a compromised mailbox, where an attacker is attempting to evade detections by suppressing or redirecting incoming emails. Analysts should review these rules in context, validate whether they reflect normal user behavior, and correlate with other indicators such as unusual login activity or recent mailbox rule modifications.
windows · ps_script
Indicator Removal on Host - Clear Mac System Logs
mediumDetects deletion of local audit logs
macos · process_creation
Indirect Command Execution From Script File Via Bash.EXE
mediumDetects execution of Microsoft bash launcher without any flags to execute the content of a bash script directly. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
windows · process_creation
Indirect Command Execution via SFTP ProxyCommand
mediumDetects the use of SFTP.exe to execute commands indirectly via ProxyCommand parameter. Threat actors were seen leveraging this legitimate Windows binary to bypass security controls and execute arbitrary commands while evading detection.
windows · process_creation
Indirect Inline Command Execution Via Bash.EXE
mediumDetects execution of Microsoft bash launcher with the "-c" flag. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
windows · process_creation
InfDefaultInstall.exe .inf Execution
mediumExecutes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.
windows · process_creation
Ingress/Egress Security Group Modification
mediumDetects when an account makes changes to the ingress or egress rules of a security group. This can indicate that an attacker is attempting to open up new attack vectors in the account, that they are trying to exfiltrate data over the network, or that they are trying to allow machines in that VPC/Subnet to contact a C&C server.
aws
Insecure Proxy/DOH Transfer Via Curl.EXE
mediumDetects execution of "curl.exe" with the "insecure" flag over proxy or DOH.
windows · process_creation
Insecure Transfer Via Curl.EXE
mediumDetects execution of "curl.exe" with the "--insecure" flag.
windows · process_creation
Install New Package Via Winget Local Manifest
mediumDetects usage of winget to install applications via manifest file. Adversaries can abuse winget to download payloads remotely and execute them. The manifest option enables you to install an application by passing in a YAML file directly to the client. Winget can be used to download and install exe, msi or msix files later.
windows · process_creation
Installation of TeamViewer Desktop
mediumTeamViewer_Desktop.exe is create during install
windows · file_event
Interactive Bash Suspicious Children
mediumDetects suspicious interactive bash as a parent to rather uncommon child processes
linux · process_creation
Interactive Logon to Server Systems
mediumDetects interactive console logons to Server Systems
windows
Internet Explorer Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Internet Explorer DisableFirstRunCustomize Enabled
mediumDetects changes to the Internet Explorer "DisableFirstRunCustomize" value, which prevents Internet Explorer from running the first run wizard the first time a user starts the browser after installing Internet Explorer or Windows.
windows · registry_set
Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe, which can be used for various attacks against the NTDS database (NTDS.DIT)
windows · process_creation
Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the invocation of PowerShell commands with references to classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows · process_creation
Invoke-Obfuscation COMPRESS OBFUSCATION
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · process_creation
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · ps_script
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · ps_module
Invoke-Obfuscation COMPRESS OBFUSCATION - Security
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows
Invoke-Obfuscation COMPRESS OBFUSCATION - System
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · ps_script
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · ps_module
Invoke-Obfuscation RUNDLL LAUNCHER - Security
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows
Invoke-Obfuscation RUNDLL LAUNCHER - System
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows
ISATAP Router Address Was Set
mediumDetects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6. In such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic. This detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.
windows
ISO Image Mounted
mediumDetects the mount of an ISO image on an endpoint
windows
ISO or Image Mount Indicator in Recent Files
mediumDetects the creation of recent element file that points to an .ISO, .IMG, .VHD or .VHDX file as often used in phishing attacks. This can be a false positive on server systems but on workstations users should rarely mount .iso or .img files.
windows · file_event
JAMF MDM Potential Suspicious Child Process
mediumDetects potential suspicious child processes of "jamf". Could be a sign of potential abuse of Jamf as a C2 server as seen by Typhon MythicAgent.
macos · process_creation
Java Running with Remote Debugging
mediumDetects a JAVA process running with remote debugging allowing more than just localhost to connect
windows · process_creation
Kapeka Backdoor Configuration Persistence
mediumDetects registry set activity of a value called "Seed" stored in the "\Cryptography\Providers\" registry key. The Kapeka backdoor leverages this location to register a new SIP provider for backdoor configuration persistence.
windows · registry_set
Kerberoasting Activity - Initial Query
mediumThis rule will collect the data needed to start looking into possible kerberoasting activity. Further analysis or computation within the query is needed focusing on requests from one specific host/IP towards multiple service names within a time period of 5 seconds. You can then set a threshold for the number of requests and time between the requests to turn this into an alert.
windows
Kerberos Network Traffic RC4 Ticket Encryption
mediumDetects kerberos TGS request using RC4 encryption which may be indicative of kerberoasting
zeek
Kubernetes Admission Controller Modification
mediumDetects when a modification (create, update or replace) action is taken that affects mutating or validating webhook configurations, as they can be used by an adversary to achieve persistence or exfiltrate access credentials.
kubernetes
Kubernetes CronJob/Job Modification
mediumDetects when a Kubernetes CronJob or Job is created or modified. A Kubernetes Job creates one or more pods to accomplish a specific task, and a CronJob creates Jobs on a recurring schedule. An adversary can take advantage of this Kubernetes object to schedule Jobs to run containers that execute malicious code within a cluster, allowing them to achieve persistence.
kubernetes
Kubernetes Events Deleted
mediumDetects when events are deleted in Kubernetes. An adversary may delete Kubernetes events in an attempt to evade detection.
kubernetes · application
Kubernetes Potential Enumeration Activity
mediumDetects potential Kubernetes enumeration or attack activity via the audit log. This includes the execution of common shells, utilities, or specialized tools like 'Rakkess' (access_matrix) and 'TruffleHog' via Kubernetes API requests. Attackers use these methods to perform reconnaissance (enumeration), secret harvesting, or execute code (exec) within a cluster.
kubernetes
Kubernetes Rolebinding Modification
mediumDetects when a Kubernetes Rolebinding is created or modified.
kubernetes
Kubernetes Secrets Modified or Deleted
mediumDetects when Kubernetes Secrets are Modified or Deleted.
kubernetes
Launch Agent/Daemon Execution Via Launchctl
mediumDetects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.
macos · process_creation
Launch-VsDevShell.PS1 Proxy Execution
mediumDetects the use of the 'Launch-VsDevShell.ps1' Microsoft signed script to execute commands.
windows · process_creation
Linux Base64 Encoded Pipe to Shell
mediumDetects suspicious process command line that uses base64 encoded input for execution with a shell
linux · process_creation
Linux Base64 Encoded Shebang In CLI
mediumDetects the presence of a base64 version of the shebang in the commandline, which could indicate a malicious payload about to be decoded
linux · process_creation
Linux Doas Conf File Creation
mediumDetects the creation of doas.conf file in linux host platform.
linux · file_event
Linux Logs Clearing Attempts
mediumDetects logs clearing attempts on Linux systems via utilities such as 'rm', 'rmdir', 'shred', and 'unlink' targeting log files and directories. Adversaries often try to clear logs to cover their tracks after performing malicious activities.
linux · process_creation
Linux Shell Pipe to Shell
mediumDetects suspicious process command line that starts with a shell that executes something and finally gets piped into another shell
linux · process_creation
LiveKD Driver Creation
mediumDetects the creation of the LiveKD driver, which is used for live kernel debugging
windows · file_event
LoadBalancer Security Group Modification
mediumDetects changes to the security groups associated with an Elastic Load Balancer (ELB) or Application Load Balancer (ALB). This can indicate that a misconfiguration allowing more traffic into the system than required, or could indicate that an attacker is attempting to enable new connections into a VPC or subnet controlled by the account.
aws
Loaded Module Enumeration Via Tasklist.EXE
mediumDetects the enumeration of a specific DLL or EXE being used by a binary via "tasklist.exe". This is often used by attackers in order to find the specific process identifier (PID) that is using the DLL in question. In order to dump the process memory or perform other nefarious actions.
windows · process_creation
Local File Read Using Curl.EXE
mediumDetects execution of "curl.exe" with the "file://" protocol handler in order to read local files.
windows · process_creation
Local Network Connection Initiated By Script Interpreter
mediumDetects a script interpreter (Wscript/Cscript) initiating a local network connection to download or execute a script hosted on a shared folder.
windows · network_connection
Logged-On User Password Change Via Ksetup.EXE
mediumDetects password change for the logged-on user's via "ksetup.exe"
windows · process_creation
Login to Disabled Account
mediumDetect failed attempts to sign in to disabled accounts.
azure
Logon from a Risky IP Address
mediumDetects when a Microsoft Cloud App Security reported when a user signs into your sanctioned apps from a risky IP address.
m365
LOLBAS Data Exfiltration by DataSvcUtil.exe
mediumDetects when a user performs data exfiltration by using DataSvcUtil.exe
windows · process_creation
LOLBIN Execution From Abnormal Drive
mediumDetects LOLBINs executing from an abnormal or uncommon drive such as a mounted ISO.
windows · process_creation
Lolbin Runexehelper Use As Proxy
mediumDetect usage of the "runexehelper.exe" binary as a proxy to launch other programs
windows · process_creation
Lolbin Unregmp2.exe Use As Proxy
mediumDetect usage of the "unregmp2.exe" binary as a proxy to launch a custom version of "wmpnscfg.exe"
windows · process_creation
Low Reputation Effective Top-Level Domain (eTLD)
mediumDetects DNS queries to domains within known low reputation eTLDs. This rule uses AlphaSOC's threat intelligence data and is updated on a monthly basis.
dns
LSA PPL Protection Setting Modification via CommandLine
mediumDetects modification of LSA PPL protection settings via CommandLine. It may indicate an attempt to disable protection and enable credential dumping tools to access LSASS process memory.
windows · process_creation
LSASS Access From Non System Account
mediumDetects potential mimikatz-like tools accessing LSASS from non system account
windows
LSASS Access From Program In Potentially Suspicious Folder
mediumDetects process access to LSASS memory with suspicious access flags and from a potentially suspicious folder
windows · process_access
MacOS Emond Launch Daemon
mediumDetects additions to the Emond Launch Daemon that adversaries may use to gain persistence and elevate privileges.
macos · file_event
MacOS Scripting Interpreter AppleScript
mediumDetects execution of AppleScript of the macOS scripting language AppleScript.
macos · process_creation
Mail Forwarding/Redirecting Activity In O365
mediumDetects email forwarding or redirecting activity in O365 Audit logs.
m365
Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet
mediumDetects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
windows · ps_script
Malicious Driver Load By Name
mediumDetects loading of known malicious drivers via the file name of the drivers.
windows · driver_load
Malicious PE Execution by Microsoft Visual Studio Debugger
mediumThere is an option for a MS VS Just-In-Time Debugger "vsjitdebugger.exe" to launch specified executable and attach a debugger. This option may be used adversaries to execute malicious code by signed verified binary. The debugger is installed alongside with Microsoft Visual Studio package.
windows · process_creation
Malicious PowerShell Keywords
mediumDetects keywords from well-known PowerShell exploitation frameworks
windows · ps_script
Manipulation of User Computer or Group Security Principals Across AD
mediumAdversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain..
windows · ps_script
Manual Execution of Script Inside of a Compressed File
mediumThis is a threat-hunting query to collect information related to the interactive execution of a script from inside a compressed file (zip/rar). Windows will automatically run the script using scripting interpreters such as wscript and cscript binaries. From the query below, the child process is the script interpreter that will execute the script. The script extension is also a set of standard extensions that Windows OS recognizes. Selections 1-3 contain three different execution scenarios. 1. Compressed file opened using 7zip. 2. Compressed file opened using WinRar. 3. Compressed file opened using native windows File Explorer capabilities. When the malicious script is double-clicked, it will be extracted to the respected directories as signified by the CommandLine on each of the three Selections. It will then be executed using the relevant script interpreter."
windows · process_creation
Masquerading as Linux Crond Process
mediumMasquerading occurs when the name or location of an executable, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. Several different variations of this technique have been observed.
linux
Mesh Agent Service Installation
mediumDetects a Mesh Agent service installation. Mesh Agent is used to remotely manage computers
windows
Microsoft 365 - Impossible Travel Activity
mediumDetects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login associated with an impossible travel.
m365
Microsoft 365 - Potential Ransomware Activity
mediumDetects when a Microsoft Cloud App Security reported when a user uploads files to the cloud that might be infected with ransomware.
m365
Microsoft 365 - Unusual Volume of File Deletion
mediumDetects when a Microsoft Cloud App Security reported a user has deleted a unusual a large volume of files.
m365
Microsoft 365 - User Restricted from Sending Email
mediumDetects when a Security Compliance Center reported a user who exceeded sending limits of the service policies and because of this has been restricted from sending email.
m365
Microsoft Excel Add-In Loaded From Uncommon Location
mediumDetects Microsoft Excel loading an Add-In (.xll) file from an uncommon location
windows · image_load
Microsoft Office Trusted Location Updated
mediumDetects changes to the registry keys related to "Trusted Location" of Microsoft Office. Attackers might add additional trusted locations to avoid macro security restrictions.
windows · registry_set
Microsoft Sync Center Suspicious Network Connections
mediumDetects suspicious connections from Microsoft Sync Center to non-private IPs.
windows · network_connection
Microsoft Teams Sensitive File Access By Uncommon Applications
mediumDetects file access attempts to sensitive Microsoft teams files (leveldb, cookies) by an uncommon process.
windows · file_access
Microsoft VBA For Outlook Addin Loaded Via Outlook
mediumDetects outlvba (Microsoft VBA for Outlook Addin) DLL being loaded by the outlook process
windows · image_load
Microsoft Workflow Compiler Execution
mediumDetects the execution of Microsoft Workflow Compiler, which may permit the execution of arbitrary unsigned code.
windows · process_creation
MITRE BZAR Indicators for Execution
mediumWindows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE
zeek
MITRE BZAR Indicators for Persistence
mediumWindows DCE-RPC functions which indicate a persistence techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE.
zeek
MMC Loading Script Engines DLLs
mediumDetects when the Microsoft Management Console (MMC) loads the DLL libraries like vbscript, jscript etc which might indicate an attempt to execute malicious scripts within a trusted system process for bypassing application whitelisting or defense evasion.
windows · image_load
Modify Group Policy Settings
mediumDetect malicious GPO modifications can be used to implement many other malicious behaviors.
windows · process_creation
Modify Group Policy Settings - ScriptBlockLogging
mediumDetect malicious GPO modifications can be used to implement many other malicious behaviors.
windows · ps_script
Modify System Firewall
mediumDetects the removal of system firewall rules. Adversaries may only delete or modify a specific system firewall rule to bypass controls limiting network usage or access. Detection rules that match only on the disabling of firewalls will miss this.
linux
Modifying Crontab
mediumDetects suspicious modification of crontab file.
linux
Monitoring For Persistence Via BITS
mediumBITS will allow you to schedule a command to execute after a successful download to notify you that the job is finished. When the job runs on the system the command specified in the BITS job will be executed. This can be abused by actors to create a backdoor within the system and for persistence. It will be chained in a BITS job to schedule the download of malware/additional binaries and execute the program after being downloaded.
windows · process_creation
Mount Execution With Hidepid Parameter
mediumDetects execution of the "mount" command with "hidepid" parameter to make invisible processes to other users from the system
linux · process_creation
msDS-ManagedAccountPrecededByLink Attribute Modified
mediumDetects modifications to the msDS-ManagedAccountPrecededByLink attribute, which may indicate an attempted or successful abuse of the BaD-Successor msDS-DelegatedManagedServiceAccount (DMSA) vulnerability. The DMSA is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups. Changes to this attribute by suspicious accounts or outside of normal administrative workflows are a strong signal of an attempted or successful abuse. If it is indeed modified by an account that is not typically responsible for such changes, it could indicate an attempt to exploit the BaD-Successor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows
MSExchange Transport Agent Installation
mediumDetects the Installation of a Exchange Transport Agent
windows · process_creation
MSExchange Transport Agent Installation - Builtin
mediumDetects the Installation of a Exchange Transport Agent
windows
MSI Installation From Suspicious Locations
mediumDetects MSI package installation from suspicious locations
windows
MSI Installation From Web
mediumDetects installation of a remote msi file from web.
windows
Msiexec Quiet Installation
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows · process_creation
MsiExec Web Install
mediumDetects suspicious msiexec process starts with web addresses as parameter
windows · process_creation
MSSQL Destructive Query
mediumDetects the invocation of MS SQL transactions that are destructive towards table or database data, such as "DROP TABLE" or "DROP DATABASE".
windows
MSSQL Server Failed Logon From External Network
mediumDetects failed logon attempts from clients with external network IP to an MSSQL server. This can be a sign of a bruteforce attack.
windows
Msxsl.EXE Execution
mediumDetects the execution of the MSXSL utility. This can be used to execute Extensible Stylesheet Language (XSL) files. These files are commonly used to describe the processing and rendering of data within XML files. Adversaries can abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses.
windows · process_creation
Multi Factor Authentication Disabled For User Account
mediumDetects changes to the "StrongAuthenticationRequirement" value, where the state is set to "0" or "Disabled". Threat actors were seen disabling multi factor authentication for users in order to maintain or achieve access to the account. Also see in SIM Swap attacks.
azure
Multifactor Authentication Denied
mediumUser has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
azure
Multifactor Authentication Interrupted
mediumIdentifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
azure
Netcat The Powershell Version
mediumAdversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
windows · ps_classic_start
Netsh Allow Group Policy on Microsoft Defender Firewall
mediumAdversaries may modify system firewalls in order to bypass controls limiting network usage
windows · process_creation
NetSupport Manager Service Install
mediumDetects NetSupport Manager service installation on the target system.
windows
Network Communication Initiated To Portmap.IO Domain
mediumDetects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
windows · network_connection
Network Connection Initiated By Regsvr32.EXE
mediumDetects a network connection initiated by "Regsvr32.exe"
windows · network_connection
Network Connection Initiated From Users\Public Folder
mediumDetects a network connection initiated from a process located in the "C:\Users\Public" folder. Attacker are known to drop their malicious payloads and malware in this directory as its writable by everyone. Use this rule to hunt for potential suspicious or uncommon activity in your environement.
windows · network_connection
Network Connection Initiated To AzureWebsites.NET By Non-Browser Process
mediumDetects an initiated network connection by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
windows · network_connection
Network Connection Initiated To BTunnels Domains
mediumDetects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To Cloudflared Tunnels Domains
mediumDetects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To DevTunnels Domain
mediumDetects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To Visual Studio Code Tunnels Domain
mediumDetects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
New Agent Skills Installation Attempt Via Node.EXE
mediumDetects the attempt to install new skills for AI agents using the "npx skills" command. Agent skills enhance AI agents with new capabilities, but attackers may abuse this mechanism to inject malicious commands executed by the agent on behalf of the user. The "npx skills" command can install skills for various agents (e.g., Claude Code, Cursor, and others). Analysts should review any installed skills to verify their legitimacy. Note: Tune this rule based on whether AI agent tooling is allowed in your environment. In environments where such tooling is authorized, this detection may reflect normal activity and the alert level should be adjusted accordingly. In environments where AI agent tooling is not permitted, this activity is likely suspicious and may require immediate investigation.
windows · process_creation
New AWS Lambda Function URL Configuration Created
mediumDetects when a user creates a Lambda function URL configuration, which could be used to expose the function to the internet and potentially allow unauthorized access to the function's IAM role for AWS API calls. This could give an adversary access to the privileges associated with the Lambda service role that is attached to that function.
aws
New BgInfo.EXE Custom DB Path Registry Configuration
mediumDetects setting of a new registry database value related to BgInfo configuration. Attackers can for example set this value to save the results of the commands executed by BgInfo in order to exfiltrate information.
windows · registry_set
New BgInfo.EXE Custom VBScript Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom VBScript via "BgInfo.exe"
windows · registry_set
New BgInfo.EXE Custom WMI Query Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom WMI query via "BgInfo.exe"
windows · registry_set
New CA Policy by Non-approved Actor
mediumMonitor and alert on conditional access changes.
azure
New Capture Session Launched Via DXCap.EXE
mediumDetects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.
windows · process_creation
New Custom Shim Database Created
mediumAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time.
windows · file_event
New DLL Added to AppCertDlls Registry Key
mediumDynamic-link libraries (DLLs) that are specified in the AppCertDLLs value in the Registry key can be abused to obtain persistence and privilege escalation by causing a malicious DLL to be loaded and run in the context of separate processes on the computer.
windows · registry_event
New DLL Added to AppInit_DLLs Registry Key
mediumDLLs that are specified in the AppInit_DLLs value in the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows are loaded by user32.dll into every process that loads user32.dll
windows · registry_event
New DLL Registered Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.
windows · process_creation
New DMSA Service Account Created in Specific OUs
mediumDetects the creation of a dMSASvc account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the Cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows · process_creation
New Federated Domain Added
mediumDetects the addition of a new Federated Domain.
m365
New Federated Domain Added - Exchange
mediumDetects the addition of a new Federated Domain.
m365
New File Exclusion Added To Time Machine Via Tmutil - MacOS
mediumDetects the addition of a new file or path exclusion to MacOS Time Machine via the "tmutil" utility. An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.
macos · process_creation
New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE
mediumDetects the addition of a new "Allow" firewall rule by the WMI process (WmiPrvSE.EXE). This can occur if an attacker leverages PowerShell cmdlets such as "New-NetFirewallRule", or directly uses WMI CIM classes such as "MSFT_NetFirewallRule".
windows
New Firewall Rule Added Via Netsh.EXE
mediumDetects the addition of a new rule to the Windows firewall via netsh
windows · process_creation
New Generic Credentials Added Via Cmdkey.EXE
mediumDetects usage of "cmdkey.exe" to add generic credentials. As an example, this can be used before connecting to an RDP session via command line interface.
windows · process_creation
New Kernel Driver Via SC.EXE
mediumDetects creation of a new service (kernel driver) with the type "kernel"
windows · process_creation
New Module Module Added To IIS Server
mediumDetects the addition of a new module to an IIS server.
windows
New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created
mediumDetects the creation of new msDS-DelegatedManagedServiceAccount objects, which could indicate potential abuse of privilege escalation vulnerabilities in Windows Server 2025. The msDS-DelegatedManagedServiceAccount (DMSA) is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups. Attackers may exploit this feature to create unauthorized service accounts with elevated privileges, leading to privilege escalation within the Active Directory environment. It is highly suspicious if an msDS-DelegatedManagedServiceAccount object is created without proper authorization or in an unexpected context, such as by a non-administrative user or outside of normal administrative workflows. So, it's a good idea to look out for accounts that are not typically responsible for service account creation to detect potential abuse of this feature.
windows
New Network Route Added
mediumDetects the addition of a new network route to a route table in AWS.
aws
New Network Trace Capture Started Via Netsh.EXE
mediumDetects the execution of netsh with the "trace" flag in order to start a network capture
windows · process_creation
New or Renamed User Account with '$' Character
mediumDetects the creation of a user with the "$" character. This can be used by attackers to hide a user or trick detection systems that lack the parsing mechanisms.
windows
New Outlook Macro Created
mediumDetects the creation of a macro file for Outlook.
windows · file_event
New PDQDeploy Service - Client Side
mediumDetects PDQDeploy service installation on the target system. When a package is deployed via PDQDeploy it installs a remote service on the target machine with the name "PDQDeployRunner-X" where "X" is an integer starting from 1
windows
New PDQDeploy Service - Server Side
mediumDetects a PDQDeploy service installation which indicates that PDQDeploy was installed on the machines. PDQDeploy can be abused by attackers to remotely install packages or execute commands on target machines
windows
New Port Forwarding Rule Added Via Netsh.EXE
mediumDetects the execution of netsh commands that configure a new port forwarding (PortProxy) rule
windows · process_creation
New PortProxy Registry Entry Added
mediumDetects the modification of the PortProxy registry key which is used for port forwarding.
windows · registry_event
New Remote Desktop Connection Initiated Via Mstsc.EXE
mediumDetects the usage of "mstsc.exe" with the "/v" flag to initiate a connection to a remote server. Adversaries may use valid accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
windows · process_creation
New Root Certificate Authority Added
mediumDetects newly added root certificate authority to an AzureAD tenant to support certificate based authentication.
azure
New Root Certificate Installed Via CertMgr.EXE
mediumDetects execution of "certmgr" with the "add" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
New Root Certificate Installed Via Certutil.EXE
mediumDetects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
New Root or CA or AuthRoot Certificate to Store
mediumDetects the addition of new root, CA or AuthRoot certificates to the Windows registry
windows · registry_set
New Self Extracting Package Created Via IExpress.EXE
mediumDetects the "iexpress.exe" utility creating self-extracting packages. Attackers where seen leveraging "iexpress" to compile packages on the fly via ".sed" files. Investigate the command line options provided to "iexpress" and in case of a ".sed" file, check the contents and legitimacy of it.
windows · process_creation
New User Account Creation Attempt Via ADSI
mediumDetects an attempt to create a new user account via ADSI (Active Directory Service Interfaces) using either the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
windows · ps_script
New User Account Creation Attempt Via ADSI in CommandLine
mediumDetects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
windows · process_creation
New User Created Via Net.EXE
mediumIdentifies the creation of local users via the net.exe command.
windows · process_creation
New Virtual Smart Card Created Via TpmVscMgr.EXE
mediumDetects execution of "Tpmvscmgr.exe" to create a new virtual smart card.
windows · process_creation
Node Process Executions
mediumDetects the execution of other scripts using the Node executable packaged with Adobe Creative Cloud
windows · process_creation
Nohup Execution
mediumDetects usage of nohup which could be leveraged by an attacker to keep a process running or break out from restricted environments
linux · process_creation
Non-DLL Extension File Renamed With DLL Extension
mediumDetects rename operations of files with non-DLL extensions to files with a DLL extension. This is often performed by malware in order to avoid initial detections based on extensions.
windows · file_rename
Notepad++ Updater DNS Query to Uncommon Domains
mediumDetects when the Notepad++ updater (gup.exe) makes DNS queries to domains that are not part of the known legitimate update infrastructure. This could indicate potential exploitation of the updater mechanism or suspicious network activity that warrants further investigation.
windows · dns_query
Nslookup PowerShell Download Cradle
mediumDetects a powershell download cradle using nslookup. This cradle uses nslookup to extract payloads from DNS records.
windows · ps_classic_start
Nslookup PowerShell Download Cradle - ProcessCreation
mediumDetects suspicious powershell download cradle using nslookup. This cradle uses nslookup to extract payloads from DNS records
windows · process_creation
Ntdsutil Abuse
mediumDetects potential abuse of ntdsutil to dump ntds.dit database
windows
NTLM Brute Force
mediumDetects common NTLM brute force device names
windows
NTLMv1 Logon Between Client and Server
mediumDetects the reporting of NTLMv1 being used between a client and server. NTLMv1 is insecure as the underlying encryption algorithms can be brute-forced by modern hardware.
windows
Number Of Resource Creation Or Deployment Activities
mediumNumber of VM creations or deployment activities occur in Azure via the azureactivity log.
azure
Obfuscated IP Download Activity
mediumDetects use of an encoded/obfuscated version of an IP address (hex, octal...) in an URL combined with a download command
windows · process_creation
Obfuscated IP Via CLI
mediumDetects usage of an encoded/obfuscated version of an IP address (hex, octal, etc.) via command line
windows · process_creation
Office Application Initiated Network Connection Over Uncommon Ports
mediumDetects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.
windows · network_connection
Office Application Initiated Network Connection To Non-Local IP
mediumDetects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.
windows · network_connection
Office Application Startup - Office Test
mediumDetects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started
windows · registry_event
Office Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened. There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive. Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
windows · registry_set
Okta 2023 Breach Indicator Of Compromise
mediumDetects new user account creation or activation with specific names related to the Okta Support System 2023 breach. This rule can be enhanced by filtering out known and legitimate username used in your environnement.
okta
Okta Admin Functions Access Through Proxy
mediumDetects access to Okta admin functions through proxy.
okta
Okta Admin Role Assigned to an User or Group
mediumDetects when an the Administrator role is assigned to an user or group.
okta
Okta Admin Role Assignment Created
mediumDetects when a new admin role assignment is created. Which could be a sign of privilege escalation or persistence
okta
Okta API Token Created
mediumDetects when a API token is created
okta
Okta API Token Revoked
mediumDetects when a API Token is revoked.
okta
Okta Application Modified or Deleted
mediumDetects when an application is modified or deleted.
okta
Okta Application Sign-On Policy Modified or Deleted
mediumDetects when an application Sign-on Policy is modified or deleted.
okta
Okta Identity Provider Created
mediumDetects when a new identity provider is created for Okta.
okta
Okta MFA Reset or Deactivated
mediumDetects when an attempt at deactivating or resetting MFA.
okta
Okta Network Zone Deactivated or Deleted
mediumDetects when an Network Zone is Deactivated or Deleted.
okta
Okta Policy Rule Modified or Deleted
mediumDetects when an Policy Rule is Modified or Deleted.
okta
Okta Security Threat Detected
mediumDetects when an security threat is detected in Okta.
okta
Okta Session Impersonation Granted From Untrusted Domain
mediumDetects Okta session impersonation grant event where a user is granted the ability to impersonate another user's session. This event type "user.session.impersonation.grant" signifies that someone has been given temporary access to act on behalf of another user account. Threat actors may abuse this functionality to escalate privileges, access sensitive resources, or perform unauthorized actions while appearing to be the impersonated user. Legitimate use cases are typically limited to Okta support scenarios or authorized administrative troubleshooting.
okta
Okta Unauthorized Access to App
mediumDetects when unauthorized access to app occurs.
okta
Okta User Account Locked Out
mediumDetects when an user account is locked out.
okta
Old TLS1.0/TLS1.1 Protocol Version Enabled
mediumDetects applications or users re-enabling old TLS versions by setting the "Enabled" value to "1" for the "Protocols" registry key.
windows · registry_set
OneNote Attachment File Dropped In Suspicious Location
mediumDetects creation of files with the ".one"/".onepkg" extension in suspicious or uncommon locations. This could be a sign of attackers abusing OneNote attachments
windows · file_event
OpenEDR Spawning Command Shell
mediumDetects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities. This may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool. Threat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.
windows · process_creation
OpenSSH Server Listening On Socket
mediumDetects scenarios where an attacker enables the OpenSSH server and server starts to listening on SSH socket.
windows
Osacompile Execution By Potentially Suspicious Applet/Osascript
mediumDetects potential suspicious applet or osascript executing "osacompile".
macos · process_creation
Outbound Network Connection To Public IP Via Winlogon
mediumDetects a "winlogon.exe" process that initiate network communications with public IP addresses
windows · network_connection
Outlook Security Settings Updated - Registry
mediumDetects changes to the registry values related to outlook security settings
windows · registry_set
PAExec Service Installation
mediumDetects PAExec service installation
windows
Pass the Hash Activity 2
mediumDetects the attack technique pass the hash which is used to move laterally inside the network
windows
Password Policy Enumerated
mediumDetects when the password policy is enumerated.
windows
Password Protected ZIP File Opened
mediumDetects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
windows
Password Provided In Command Line Of Net.EXE
mediumDetects a when net.exe is called with a password in the command line
windows · process_creation
Password Reset By User Account
mediumDetect when a user has reset their password in Azure AD
azure
Password Set to Never Expire via WMI
mediumDetects the use of wmic.exe to modify user account settings and explicitly disable password expiration.
windows · process_creation
Path To Screensaver Binary Modified
mediumDetects value modification of registry key containing path to binary used as screensaver.
windows · registry_event
Path Traversal Exploitation Attempts
mediumDetects path traversal exploitation attempts
webserver
Payload Decoded and Decrypted via Built-in Utilities
mediumDetects when a built-in utility is used to decode and decrypt a payload after a macOS disk image (DMG) is executed. Malware authors may attempt to evade detection and trick users into executing malicious code by encoding and encrypting their payload and placing it in a disk image file. This behavior is consistent with adware or malware families such as Bundlore and Shlayer.
macos · process_creation
PDQ Deploy Remote Adminstartion Tool Execution
mediumDetect use of PDQ Deploy remote admin tool
windows · process_creation
Periodic Backup For System Registry Hives Enabled
mediumDetects the enabling of the "EnablePeriodicBackup" registry value. Once enabled, The OS will backup System registry hives on restarts to the "C:\Windows\System32\config\RegBack" folder. Windows creates a "RegIdleBackup" task to manage subsequent backups. Registry backup was a default behavior on Windows and was disabled as of "Windows 10, version 1803".
windows · registry_set
Perl Inline Command Execution
mediumDetects execution of perl using the "-e"/"-E" flags. This is could be used as a way to launch a reverse shell or execute live perl code.
windows · process_creation
Permission Check Via Accesschk.EXE
mediumDetects the usage of the "Accesschk" utility, an access and privilege audit tool developed by SysInternal and often being abused by attacker to verify process privileges
windows · process_creation
Permission Misconfiguration Reconnaissance Via Findstr.EXE
mediumDetects usage of findstr with the "EVERYONE" or "BUILTIN" keywords. This was seen being used in combination with "icacls" and other utilities to spot misconfigured files or folders permissions.
windows · process_creation
Persistence Via Disk Cleanup Handler - Autorun
mediumDetects when an attacker modifies values of the Disk Cleanup Handler in the registry to achieve persistence via autorun. The disk cleanup manager is part of the operating system. It displays the dialog box […] The user has the option of enabling or disabling individual handlers by selecting or clearing their check box in the disk cleanup manager's UI. Although Windows comes with a number of disk cleanup handlers, they aren't designed to handle files produced by other applications. Instead, the disk cleanup manager is designed to be flexible and extensible by enabling any developer to implement and register their own disk cleanup handler. Any developer can extend the available disk cleanup services by implementing and registering a disk cleanup handler.
windows · registry_set
Persistence Via New SIP Provider
mediumDetects when an attacker register a new SIP provider for persistence and defense evasion
windows · registry_set
Persistence Via Sudoers.d Files
mediumDetects the creation or modification of files within the "sudoers.d" directory on Linux systems. Such activity may indicate an attempt to establish or maintain privilege escalation by granting specific users elevated permissions. Unauthorized changes to sudoers files are a common technique used by attackers to persist administrative access.
linux · file_event
Persistence Via TypedPaths - CommandLine
mediumDetects modification addition to the 'TypedPaths' key in the user or admin registry via the commandline. Which might indicate persistence attempt
windows · process_creation
Php Inline Command Execution
mediumDetects execution of php using the "-r" flag. This is could be used as a way to launch a reverse shell or execute live php code.
windows · process_creation
PktMon.EXE Execution
mediumDetects execution of PktMon, a tool that captures network packets.
windows · process_creation
Pnscan Binary Data Transmission Activity
mediumDetects command line patterns associated with the use of Pnscan for sending and receiving binary data across the network. This behavior has been identified in a Linux malware campaign targeting Docker, Apache Hadoop, Redis, and Confluence and was previously used by the threat actor known as TeamTNT
linux · process_creation
Port Forwarding Activity Via SSH.EXE
mediumDetects port forwarding activity via SSH.exe
windows · process_creation
Portable Gpg.EXE Execution
mediumDetects the execution of "gpg.exe" from uncommon location. Often used by ransomware and loaders to decrypt/encrypt data.
windows · process_creation
Possible DC Shadow Attack
mediumDetects DCShadow via create new SPN
windows
Possible PrintNightmare Print Driver Install - CVE-2021-1675
mediumDetects the remote installation of a print driver which is possible indication of the exploitation of PrintNightmare (CVE-2021-1675). The occurrence of print drivers being installed remotely via RPC functions should be rare, as print drivers are normally installed locally and or through group policy.
zeek
Potential Abuse of Linux Magic System Request Key
mediumDetects the potential abuse of the Linux Magic SysRq (System Request) key by adversaries with root or sufficient privileges to silently manipulate or destabilize a system. By writing to /proc/sysrq-trigger, they can crash the system, kill processes, or disrupt forensic analysis—all while bypassing standard logging. Though intended for recovery and debugging, SysRq can be misused as a stealthy post-exploitation tool. It is controlled via /proc/sys/kernel/sysrq or permanently through /etc/sysctl.conf.
linux
Potential Access Token Abuse
mediumDetects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".
windows
Potential Active Directory Enumeration Using AD Module - ProcCreation
mediumDetects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
windows · process_creation
Potential Active Directory Enumeration Using AD Module - PsModule
mediumDetects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
windows · ps_module
Potential Active Directory Enumeration Using AD Module - PsScript
mediumDetects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
windows · ps_script
Potential Active Directory Reconnaissance/Enumeration Via LDAP
mediumDetects potential Active Directory enumeration via LDAP
windows
Potential AD User Enumeration From Non-Machine Account
mediumDetects read access to a domain user from a non-machine account
windows
Potential Amazon SSM Agent Hijacking
mediumDetects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
windows · process_creation
Potential AMSI Bypass Script Using NULL Bits
mediumDetects usage of special strings/null bits in order to potentially bypass AMSI functionalities
windows · ps_script
Potential AMSI Bypass Using NULL Bits
mediumDetects usage of special strings/null bits in order to potentially bypass AMSI functionalities
windows · process_creation
Potential Antivirus Software DLL Sideloading
mediumDetects potential DLL sideloading of DLLs that are part of antivirus software suchas McAfee, Symantec...etc
windows · image_load
Potential Application Whitelisting Bypass via Dnx.EXE
mediumDetects the execution of Dnx.EXE. The Dnx utility allows for the execution of C# code. Attackers might abuse this in order to bypass application whitelisting.
windows · process_creation
Potential APT FIN7 Exploitation Activity
mediumDetects potential APT FIN7 exploitation activity as reported by Google. In order to obtain initial access, FIN7 used compromised Remote Desktop Protocol (RDP) credentials to login to a target server and initiate specific Windows process chains.
windows · process_creation
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
mediumDetects potential BlueMushroom DLL loading activity via regsvr32 from AppData Local
windows · process_creation
Potential Arbitrary Command Execution Via FTP.EXE
mediumDetects execution of "ftp.exe" script with the "-s" or "/s" flag and any child processes ran by "ftp.exe".
windows · process_creation
Potential Arbitrary DLL Load Using Winword
mediumDetects potential DLL sideloading using the Microsoft Office winword process via the '/l' flag.
windows · process_creation
Potential Arbitrary File Download Via Cmdl32.EXE
mediumDetects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious.
windows · process_creation
Potential AS-REP Roasting via Kerberos TGT Requests
mediumDetects suspicious Kerberos TGT requests with pre-authentication disabled (Pre-Authentication Type = 0) and Ticket Encryption Type (0x17) i.e, RC4-HMAC. This may indicate an AS-REP Roasting attack, where attackers request AS-REP messages for accounts without pre-authentication and attempt to crack the encrypted ticket offline to recover user passwords.
windows
Potential AVKkid.DLL Sideloading
mediumDetects potential DLL sideloading of "AVKkid.dll"
windows · image_load
Potential Base64 Encoded User-Agent
mediumDetects User Agent strings that end with an equal sign, which can be a sign of base64 encoding.
proxy
Potential Binary Impersonating Sysinternals Tools
mediumDetects binaries that use the same name as legitimate sysinternals tools to evade detection. This rule looks for the execution of binaries that are named similarly to Sysinternals tools. Adversary may rename their malicious tools as legitimate Sysinternals tools to evade detection.
windows · process_creation
Potential Binary Or Script Dropper Via PowerShell
mediumDetects PowerShell creating a binary executable or a script file.
windows · file_event
Potential Binary Proxy Execution Via Cdb.EXE
mediumDetects usage of "cdb.exe" to launch arbitrary processes or commands from a debugger script file
windows · process_creation
Potential Binary Proxy Execution Via VSDiagnostics.EXE
mediumDetects execution of "VSDiagnostics.exe" with the "start" command in order to launch and proxy arbitrary binaries.
windows · process_creation
Potential Browser Data Stealing
mediumAdversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store.
windows · process_creation
Potential CCleanerDU.DLL Sideloading
mediumDetects potential DLL sideloading of "CCleanerDU.dll"
windows · image_load
Potential CCleanerReactivator.DLL Sideloading
mediumDetects potential DLL sideloading of "CCleanerReactivator.dll"
windows · image_load
Potential Chrome Frame Helper DLL Sideloading
mediumDetects potential DLL sideloading of "chrome_frame_helper.dll"
windows · image_load
Potential COM Object Hijacking Via TreatAs Subkey - Registry
mediumDetects COM object hijacking via TreatAs subkey
windows · registry_set
Potential COM Objects Download Cradles Usage - Process Creation
mediumDetects usage of COM objects that can be abused to download files in PowerShell by CLSID
windows · process_creation
Potential COM Objects Download Cradles Usage - PS Script
mediumDetects usage of COM objects that can be abused to download files in PowerShell by CLSID
windows · ps_script
Potential Command Line Path Traversal Evasion Attempt
mediumDetects potential evasion or obfuscation attempts using bogus path traversal via the commandline
windows · process_creation
Potential Commandline Obfuscation Using Escape Characters
mediumDetects potential commandline obfuscation using known escape characters
windows · process_creation
Potential CommandLine Obfuscation Using Unicode Characters
mediumDetects potential CommandLine obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
windows · process_creation
Potential Configuration And Service Reconnaissance Via Reg.EXE
mediumDetects the usage of "reg.exe" in order to query reconnaissance information from the registry. Adversaries may interact with the Windows registry to gather information about credentials, the system, configuration, and installed software.
windows · process_creation
Potential Cookies Session Hijacking
mediumDetects execution of "curl.exe" with the "-c" flag in order to save cookie data.
windows · process_creation
Potential Credential Dumping Activity Via LSASS
mediumDetects process access requests to the LSASS process with specific call trace calls and access masks. This behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature.
windows · process_access
Potential Credential Dumping Attempt Using New NetworkProvider - REG
mediumDetects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
windows · registry_set
Potential Credential Dumping Attempt Via PowerShell
mediumDetects a PowerShell process requesting access to "lsass.exe", which can be indicative of potential credential dumping attempts
windows · process_access
Potential CVE-2021-27905 Exploitation Attempt
mediumDetects exploitation attempt of the CVE-2021-27905 which affects all Apache Solr versions prior to and including 8.8.1.
webserver
Potential CVE-2021-42278 Exploitation Attempt
mediumThe attacker creates a computer object using those permissions with a password known to her. After that she clears the attribute ServicePrincipalName on the computer object. Because she created the object (CREATOR OWNER), she gets granted additional permissions and can do many changes to the object.
windows
Potential CVE-2021-42287 Exploitation Attempt
mediumThe attacker creates a computer object using those permissions with a password known to her. After that she clears the attribute ServicePrincipalName on the computer object. Because she created the object (CREATOR OWNER), she gets granted additional permissions and can do many changes to the object.
windows
Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
mediumDetects potential exploitation attempt of CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager. As reported by Morphisec, part of the attack chain, threat actors used PowerShell commands that executed as a child processes of the legitimate Tomcat "prunsrv.exe" process application.
windows · process_creation
Potential CVE-2023-2283 Exploitation
mediumDetects potential exploitation attempt of CVE-2023-2283 an authentication bypass in libSSH. The exploitation method causes an error message stating that keys for curve25519 could not be generated. It is an error message that is a sign of an exploitation attempt. It is not a sign of a successful exploitation.
linux
Potential CVE-2023-23397 Exploitation Attempt - SMB
mediumDetects (failed) outbound connection attempts to internet facing SMB servers. This could be a sign of potential exploitation attempts of CVE-2023-23397.
windows
Potential CVE-2023-27997 Exploitation Indicators
mediumDetects indicators of potential exploitation of CVE-2023-27997 in Frotigate weblogs. To avoid false positives it is best to look for successive requests to the endpoints mentioned as well as weird values of the "enc" parameter
webserver
Potential CVE-2023-36874 Exploitation - Uncommon Report.Wer Location
mediumDetects the creation of a "Report.wer" file in an uncommon folder structure. This could be a sign of potential exploitation of CVE-2023-36874.
windows · file_event
Potential CVE-2023-36884 Exploitation - File Downloads
mediumDetects files seen being requested by RomCom while potentially exploiting CVE-2023-36884
proxy
Potential CVE-2023-36884 Exploitation Dropped File
mediumDetects a specific file being created in the recent folder of Office. These files have been seen being dropped during potential exploitations of CVE-2023-36884
windows · file_event
Potential CVE-2023-46214 Exploitation Attempt
mediumDetects potential exploitation of CVE-2023-46214, a remote code execution (RCE) in Splunk Enterprise through insecure XML parsing
webserver
Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection - File Creation
mediumDetects suspicious file creations in the Palo Alto Networks PAN-OS' parent telemetry folder, which are processed by the vulnerable 'dt_curl' script if device telemetry is enabled. As said script overrides the shell-subprocess restriction, arbitrary command execution may occur by carefully crafting filenames that are escaped through this function.
paloalto · file_event
Potential CVE-2024-35250 Exploitation Activity
mediumDetects potentially suspicious loading of "ksproxy.ax", which may indicate an attempt to exploit CVE-2024-35250.
windows · image_load
Potential Data Exfiltration Over SMTP Via Send-MailMessage Cmdlet
mediumDetects the execution of a PowerShell script with a call to the "Send-MailMessage" cmdlet along with the "-Attachments" flag. This could be a potential sign of data exfiltration via Email. Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
windows · ps_script
Potential Data Exfiltration Via Audio File
mediumDetects potential exfiltration attempt via audio file using PowerShell
windows · ps_script
Potential Data Exfiltration Via Curl.EXE
mediumDetects the execution of the "curl" process with "upload" flags. Which might indicate potential data exfiltration
windows · process_creation
Potential Defense Evasion Via Binary Rename
mediumDetects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
windows · process_creation
Potential Direct Syscall of NtOpenProcess
mediumDetects potential calls to NtOpenProcess directly from NTDLL.
windows · process_access
Potential Discovery Activity Using Find - Linux
mediumDetects usage of "find" binary in a suspicious manner to perform discovery
linux · process_creation
Potential Discovery Activity Using Find - MacOS
mediumDetects usage of "find" binary in a suspicious manner to perform discovery
macos · process_creation
Potential Discovery Activity Via Dnscmd.EXE
mediumDetects an attempt to leverage dnscmd.exe to enumerate the DNS zones of a domain. DNS zones used to host the DNS records for a particular domain.
windows · process_creation
Potential DLL File Download Via PowerShell Invoke-WebRequest
mediumDetects potential DLL files being downloaded using the PowerShell Invoke-WebRequest or Invoke-RestMethod cmdlets.
windows · process_creation
Potential DLL Injection Or Execution Using Tracker.exe
mediumDetects potential DLL injection and execution using "Tracker.exe"
windows · process_creation
Potential DLL Injection Via AccCheckConsole
mediumDetects the execution "AccCheckConsole" a command-line tool for verifying the accessibility implementation of an application's UI. One of the tests that this checker can run are called "verification routine", which tests for things like Consistency, Navigation, etc. The tool allows a user to provide a DLL that can contain a custom "verification routine". An attacker can build such DLLs and pass it via the CLI, which would then be loaded in the context of the "AccCheckConsole" utility.
windows · process_creation
Potential DLL Sideloading Activity Via ExtExport.EXE
mediumDetects the execution of "Extexport.exe".A utility that is part of the Internet Explorer browser and is used to export and import various settings and data, particularly when switching between Internet Explorer and other web browsers like Firefox. It allows users to transfer bookmarks, browsing history, and other preferences from Internet Explorer to Firefox or vice versa. It can be abused as a tool to side load any DLL. If a folder is provided in the command line it'll load any DLL with one of the following names "mozcrt19.dll", "mozsqlite3.dll", or "sqlite.dll". Arbitrary DLLs can also be loaded if a specific number of flags was provided.
windows · process_creation
Potential DLL Sideloading Of DBGCORE.DLL
mediumDetects DLL sideloading of "dbgcore.dll"
windows · image_load
Potential DLL Sideloading Of DBGHELP.DLL
mediumDetects potential DLL sideloading of "dbghelp.dll"
windows · image_load
Potential DLL Sideloading Of DbgModel.DLL
mediumDetects potential DLL sideloading of "DbgModel.dll"
windows · image_load
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
mediumDetects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location
windows · image_load
Potential DLL Sideloading Of MpSvc.DLL
mediumDetects potential DLL sideloading of "MpSvc.dll".
windows · image_load
Potential DLL Sideloading Of MsCorSvc.DLL
mediumDetects potential DLL sideloading of "mscorsvc.dll".
windows · image_load
Potential DLL Sideloading Using Coregen.exe
mediumDetect usage of the "coregen.exe" (Microsoft CoreCLR Native Image Generator) binary to sideload arbitrary DLLs.
windows · image_load
Potential DLL Sideloading Via ClassicExplorer32.dll
mediumDetects potential DLL sideloading using ClassicExplorer32.dll from the Classic Shell software
windows · image_load
Potential DLL Sideloading Via DeviceEnroller.EXE
mediumDetects the use of the PhoneDeepLink parameter to potentially sideload a DLL file that does not exist. This non-existent DLL file is named "ShellChromeAPI.dll". Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
windows · process_creation
Potential DLL Sideloading Via JsSchHlp
mediumDetects potential DLL sideloading using JUSTSYSTEMS Japanese word processor
windows · image_load
Potential Dosfuscation Activity
mediumDetects possible payload obfuscation via the commandline
windows · process_creation
Potential Download/Upload Activity Using Type Command
mediumDetects usage of the "type" command to download/upload data from WebDAV server
windows · process_creation
Potential Dropper Script Execution Via WScript/CScript/MSHTA
mediumDetects wscript/cscript/mshta executions of scripts located in user directories
windows · process_creation
Potential Encrypted Registry Blob Related To SNAKE Malware
mediumDetects the creation of a registry value in the ".wav\OpenWithProgIds" key with an uncommon name. This could be related to SNAKE Malware as reported by CISA
windows · registry_set
Potential Exploitation of CVE-2025-5054 or CVE-2025-4598
mediumDetects attempts of an attacker to enable core dumps for set-user-ID (SUID) processes by modifying the system file /proc/sys/fs/suid_dumpable, typically by setting its value to 1 or 2. Enabling this feature allows memory dumps (core dumps) of SUID processes, which usually run with elevated privileges. These dumps may contain sensitive information such as passwords, cryptographic keys or other secrets. CVE-2025-5054: Information leak via core dumps from SUID binaries using apport. CVE-2025-4598: Information disclosure in systemd-coredump due to insecure handling of SUID process memory dumps.
linux · process_creation
Potential Fake Instance Of Hxtsr.EXE Executed
mediumHxTsr.exe is a Microsoft compressed executable file called Microsoft Outlook Communications. HxTsr.exe is part of Outlook apps, because it resides in a hidden "WindowsApps" subfolder of "C:\Program Files". Any instances of hxtsr.exe not in this folder may be malware camouflaging itself as HxTsr.exe
windows · process_creation
Potential File Download Via MS-AppInstaller Protocol Handler
mediumDetects usage of the "ms-appinstaller" protocol handler via command line to potentially download arbitrary files via AppInstaller.EXE The downloaded files are temporarly stored in ":\Users\%username%\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\<RANDOM-8-CHAR-DIRECTORY>"
windows · process_creation
Potential Goopdate.DLL Sideloading
mediumDetects potential DLL sideloading of "goopdate.dll", a DLL used by googleupdate.exe
windows · image_load
Potential Hello-World Scraper Botnet Activity
mediumDetects network traffic potentially associated with a scraper botnet variant that uses the "Hello-World/1.0" user-agent string.
proxy
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream
mediumDetects the creation of hidden file/folder with the "::$index_allocation" stream. Which can be used as a technique to prevent access to folder and files from tooling such as "explorer.exe" and "powershell.exe"
windows · file_event
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI
mediumDetects command line containing reference to the "::$index_allocation" stream, which can be used as a technique to prevent access to folders or files from tooling such as "explorer.exe" or "powershell.exe"
windows · process_creation
Potential Homoglyph Attack Using Lookalike Characters
mediumDetects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
windows · process_creation
Potential Homoglyph Attack Using Lookalike Characters in Filename
mediumDetects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
windows · file_event
Potential In-Memory Download And Compile Of Payloads
mediumDetects potential in-memory downloading and compiling of applets using curl and osacompile as seen used by XCSSET malware
macos · process_creation
Potential In-Memory Execution Using Reflection.Assembly
mediumDetects usage of "Reflection.Assembly" load functions to dynamically load assemblies in memory
windows · ps_script
Potential Initial Access via DLL Search Order Hijacking
mediumDetects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
windows · file_event
Potential KamiKakaBot Activity - Lure Document Execution
mediumDetects the execution of a Word document via the WinWord Start Menu shortcut. This behavior was observed being used by KamiKakaBot samples in order to initiate the 2nd stage of the infection.
windows · process_creation
Potential KamiKakaBot Activity - Shutdown Schedule Task Creation
mediumDetects the creation of a schedule task that runs weekly and execute the "shutdown /l /f" command. This behavior was observed being used by KamiKakaBot samples in order to achieve persistence on a system.
windows · process_creation
Potential Keylogger Activity
mediumDetects PowerShell scripts that contains reference to keystroke capturing functions
windows · ps_script
Potential Lateral Movement via Windows Remote Shell
mediumDetects a child process spawned by 'winrshost.exe', which suggests remote command execution through Windows Remote Shell (WinRs) and may indicate potential lateral movement activity.
windows · process_creation
Potential Libvlc.DLL Sideloading
mediumDetects potential DLL sideloading of "libvlc.dll", a DLL that is legitimately used by "VLC.exe"
windows · image_load
Potential Linux Amazon SSM Agent Hijacking
mediumDetects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
linux · process_creation
Potential Linux Process Code Injection Via DD Utility
mediumDetects the injection of code by overwriting the memory map of a Linux process using the "dd" Linux command.
linux · process_creation
Potential Malicious AppX Package Installation Attempts
mediumDetects potential installation or installation attempts of known malicious appx packages
windows
Potential Memory Dumping Activity Via LiveKD
mediumDetects execution of LiveKD based on PE metadata or image name
windows · process_creation
Potential Mfdetours.DLL Sideloading
mediumDetects potential DLL sideloading of "mfdetours.dll". While using "mftrace.exe" it can be abused to attach to an arbitrary process and force load any DLL named "mfdetours.dll" from the current directory of execution.
windows · image_load
Potential Mftrace.EXE Abuse
mediumDetects child processes of the "Trace log generation tool for Media Foundation Tools" (Mftrace.exe) which can abused to execute arbitrary binaries.
windows · process_creation
Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE
mediumDetects the execution of "csc.exe" via "w3wp.exe" process. MOVEit affected hosts execute "csc.exe" via the "w3wp.exe" process to dynamically compile malicious DLL files. MOVEit is affected by a critical vulnerability. Exploited hosts show evidence of dynamically compiling a DLL and writing it under C:\\Windows\\Microsoft\.NET\\Framework64\\v4\.0\.30319\\Temporary ASP\.NET Files\\root\\([a-z0-9]{5,12})\\([a-z0-9]{5,12})\\App_Web_[a-z0-9]{5,12}\.dll. Hunting Opportunity Events from IIS dynamically compiling binaries via the csc.exe on behalf of the MOVEit application, especially since May 27th should be investigated.
windows · process_creation
Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
mediumDetects execution of Windows Defender "OfflineScannerShell.exe" from its non standard directory. The "OfflineScannerShell.exe" binary is vulnerable to DLL side loading and will load any DLL named "mpclient.dll" from the current working directory.
windows · process_creation
Potential Network Sniffing Activity Using Network Tools
mediumDetects potential network sniffing via use of network tools such as "tshark", "windump". Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
windows · process_creation
Potential Obfuscated Ordinal Call Via Rundll32
mediumDetects execution of "rundll32" with potential obfuscated ordinal calls
windows · process_creation
Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock
mediumDetects the execution of powershell scripts with calls to the "Start-NetEventSession" cmdlet. Which allows an attacker to start event and packet capture for a network event session. Adversaries may attempt to capture network to gather information over the course of an operation. Data captured via this technique may include user credentials, especially those sent over an insecure, unencrypted protocol.
windows · ps_script
Potential Pass the Hash Activity
mediumDetects the attack technique pass the hash which is used to move laterally inside the network
windows
Potential Password Reconnaissance Via Findstr.EXE
mediumDetects command line usage of "findstr" to search for the "passwords" keyword in a variety of different languages
windows · process_creation
Potential Password Spraying Attempt Using Dsacls.EXE
mediumDetects possible password spraying attempts using Dsacls
windows · process_creation
Potential Peach Sandstorm APT C2 Communication Activity
mediumDetects potential C2 communication activity related to Peach Sandstorm APT
proxy
Potential PendingFileRenameOperations Tampering
mediumDetect changes to the "PendingFileRenameOperations" registry key from uncommon or suspicious images locations to stage currently used files for rename or deletion after reboot.
windows · registry_set
Potential Persistence Attempt Via ErrorHandler.Cmd
mediumDetects creation of a file named "ErrorHandler.cmd" in the "C:\WINDOWS\Setup\Scripts\" directory which could be used as a method of persistence The content of C:\WINDOWS\Setup\Scripts\ErrorHandler.cmd is read whenever some tools under C:\WINDOWS\System32\oobe\ (e.g. Setup.exe) fail to run for any reason.
windows · file_event
Potential Persistence Attempt Via Existing Service Tampering
mediumDetects the modification of an existing service in order to execute an arbitrary payload when the service is started or killed as a potential method for persistence.
windows · process_creation
Potential Persistence Attempt Via Run Keys Using Reg.EXE
mediumDetects suspicious command line reg.exe tool adding key to RUN key in Registry
windows · process_creation
Potential Persistence Using DebugPath
mediumDetects potential persistence using Appx DebugPath
windows · registry_set
Potential Persistence Via AppCompat RegisterAppRestart Layer
mediumDetects the setting of the REGISTERAPPRESTART compatibility layer on an application. This compatibility layer allows an application to register for restart using the "RegisterApplicationRestart" API. This can be potentially abused as a persistence mechanism.
windows · registry_set
Potential Persistence Via Custom Protocol Handler
mediumDetects potential persistence activity via the registering of a new custom protocole handlers. While legitimate applications register protocole handlers often times during installation. And attacker can abuse this by setting a custom handler to be used as a persistence mechanism.
windows · registry_set
Potential Persistence Via Disk Cleanup Handler - Registry
mediumDetects when an attacker modifies values of the Disk Cleanup Handler in the registry to achieve persistence. The disk cleanup manager is part of the operating system. It displays the dialog box […] The user has the option of enabling or disabling individual handlers by selecting or clearing their check box in the disk cleanup manager's UI. Although Windows comes with a number of disk cleanup handlers, they aren't designed to handle files produced by other applications. Instead, the disk cleanup manager is designed to be flexible and extensible by enabling any developer to implement and register their own disk cleanup handler. Any developer can extend the available disk cleanup services by implementing and registering a disk cleanup handler.
windows · registry_add
Potential Persistence Via Event Viewer Events.asp
mediumDetects potential registry persistence technique using the Event Viewer "Events.asp" technique
windows · registry_set
Potential Persistence Via Logon Scripts - Registry
mediumDetects creation of "UserInitMprLogonScript" registry value which can be used as a persistence method by malicious actors
windows · registry_set
Potential Persistence Via Microsoft Compatibility Appraiser
mediumDetects manual execution of the "Microsoft Compatibility Appraiser" task via schtasks. In order to trigger persistence stored in the "\AppCompatFlags\TelemetryController" registry key.
windows · process_creation
Potential Persistence Via Netsh Helper DLL
mediumDetects the execution of netsh with "add helper" flag in order to add a custom helper DLL. This technique can be abused to add a malicious helper DLL that can be used as a persistence proxy that gets called when netsh.exe is executed.
windows · process_creation
Potential Persistence Via Netsh Helper DLL - Registry
mediumDetects changes to the Netsh registry key to add a new DLL value. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
windows · registry_set
Potential Persistence Via New AMSI Providers - Registry
mediumDetects when an attacker adds a new AMSI provider via the Windows Registry to bypass AMSI (Antimalware Scan Interface) protections. Attackers may add custom AMSI providers to persist on the system and evade detection by security software that relies on AMSI for scanning scripts and other content. This technique is often used in conjunction with fileless malware and script-based attacks to maintain persistence while avoiding detection.
windows · registry_set
Potential Persistence Via Notepad++ Plugins
mediumDetects creation of new ".dll" files inside the plugins directory of a notepad++ installation by a process other than "gup.exe". Which could indicates possible persistence
windows · file_event
Potential Persistence Via PowerShell User Profile Using Add-Content
mediumDetects calls to "Add-Content" cmdlet in order to modify the content of the user profile and potentially adding suspicious commands for persistence
windows · ps_script
Potential Persistence Via Scrobj.dll COM Hijacking
mediumDetect use of scrobj.dll as this DLL looks for the ScriptletURL key to get the location of the script to execute
windows · registry_set
Potential Persistence Via Shim Database Modification
mediumAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time
windows · registry_set
Potential Persistence Via Visual Studio Tools for Office
mediumDetects persistence via Visual Studio Tools for Office (VSTO) add-ins in Office applications.
windows · registry_set
Potential Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
mediumDetects execution of the "VMwareToolBoxCmd.exe" with the "script" and "set" flag to setup a specific script to run for a specific VM state
windows · process_creation
Potential PetitPotam Attack Via EFS RPC Calls
mediumDetects usage of the windows RPC library Encrypting File System Remote Protocol (MS-EFSRPC). Variations of this RPC are used within the attack refereed to as PetitPotam. The usage of this RPC function should be rare if ever used at all. Thus usage of this function is uncommon enough that any usage of this RPC function should warrant further investigation to determine if it is legitimate. View surrounding logs (within a few minutes before and after) from the Source IP to. Logs from from the Source IP would include dce_rpc, smb_mapping, smb_files, rdp, ntlm, kerberos, etc..'
zeek
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
mediumDetects the execution of concatenated commands via "cmd.exe". Pikabot often executes a combination of multiple commands via the command handler "cmd /c" in order to download and execute additional payloads. Commands such as "curl", "wget" in order to download extra payloads. "ping" and "timeout" are abused to introduce delays in the command execution and "Rundll32" is also used to execute malicious DLL files. In the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.
windows · process_creation
Potential PowerShell Console History Access Attempt via History File
mediumDetects potential access attempts to the PowerShell console history directly via history file (ConsoleHost_history.txt). This can give access to plaintext passwords used in PowerShell commands or used for general reconnaissance.
windows · process_creation
Potential PowerShell Downgrade Attack
mediumDetects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0
windows · process_creation
Potential PowerShell Execution Policy Tampering
mediumDetects changes to the PowerShell execution policy in order to bypass signing requirements for script execution
windows · registry_set
Potential Privileged System Service Operation - SeLoadDriverPrivilege
mediumDetects the usage of the 'SeLoadDriverPrivilege' privilege. This privilege is required to load or unload a device driver. With this privilege, the user can dynamically load and unload device drivers or other code in to kernel mode. This user right does not apply to Plug and Play device drivers. If you exclude privileged users/admins and processes, which are allowed to do so, you are maybe left with bad programs trying to load malicious kernel drivers. This will detect Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs) and the usage of Sysinternals and various other tools. So you have to work with a whitelist to find the bad stuff.
windows
Potential Process Execution Proxy Via CL_Invocation.ps1
mediumDetects calls to "SyncInvoke" that is part of the "CL_Invocation.ps1" script to proxy execution using "System.Diagnostics.Process"
windows · process_creation
Potential Process Hollowing Activity
mediumDetects when a memory process image does not match the disk image, indicative of process hollowing.
windows · process_tampering
Potential Process Reconnaissance via Wmic.EXE
mediumDetects the execution of "wmic" with the "process" flag, which might indicate an attempt to perform reconnaissance on running processes. Adversaries may use wmic to query for running processes and their details as part of their reconnaissance efforts.
windows · process_creation
Potential Product Class Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC in order to get a list of firewall, antivirus and antispywware products. Adversaries often enumerate security products installed on a system to identify security controls and potential ways to evade detection or disable protection mechanisms. This information helps them plan their next attack steps and choose appropriate techniques to bypass security measures.
windows · process_creation
Potential Product Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC in order to get a list of firewall and antivirus products
windows · process_creation
Potential Provlaunch.EXE Binary Proxy Execution Abuse
mediumDetects child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
windows · process_creation
Potential Python DLL SideLoading
mediumDetects potential DLL sideloading of Python DLL files.
windows · image_load
Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
mediumDetects potential malicious and unauthorized usage of bcdedit.exe
windows · process_creation
Potential RDP Exploit CVE-2019-0708
mediumDetect suspicious error on protocol RDP, potential CVE-2019-0708
windows
Potential RDP Session Hijacking Activity
mediumDetects potential RDP Session Hijacking activity on Windows systems
windows · process_creation
Potential Recon Activity Via Nltest.EXE
mediumDetects nltest commands that can be used for information discovery
windows · process_creation
Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
mediumDetects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
windows · process_creation
Potential ReflectDebugger Content Execution Via WerFault.EXE
mediumDetects execution of "WerFault.exe" with the "-pr" commandline flag that is used to run files stored in the ReflectDebugger key which could be used to store the path to the malware in order to masquerade the execution flow
windows · process_creation
Potential Register_App.Vbs LOLScript Abuse
mediumDetects potential abuse of the "register_app.vbs" script that is part of the Windows SDK. The script offers the capability to register new VSS/VDS Provider as a COM+ application. Attackers can use this to install malicious DLLs for persistence and execution.
windows · process_creation
Potential Registry Persistence Attempt Via DbgManagedDebugger
mediumDetects the addition of the "Debugger" value to the "DbgManagedDebugger" key in order to achieve persistence. Which will get invoked when an application crashes
windows · registry_set
Potential Registry Reconnaissance Via PowerShell Script
mediumDetects PowerShell scripts with potential registry reconnaissance capabilities. Adversaries may interact with the Windows registry to gather information about the system credentials, configuration, and installed software.
windows · ps_script
Potential Regsvr32 Commandline Flag Anomaly
mediumDetects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon.
windows · process_creation
Potential Remote Command Execution In Pod Container
mediumDetects attempts to execute remote commands, within a Pod's container using e.g. the "kubectl exec" command.
kubernetes · application
Potential Remote Desktop Connection to Non-Domain Host
mediumDetects logons using NTLM to hosts that are potentially not part of the domain.
windows
Potential Remote Desktop Tunneling
mediumDetects potential use of an SSH utility to establish RDP over a reverse SSH Tunnel. This can be used by attackers to enable routing of network packets that would otherwise not reach their intended destination.
windows · process_creation
Potential Remote WMI ActiveScriptEventConsumers Activity
mediumDetect potential adversaries leveraging WMI ActiveScriptEventConsumers remotely to move laterally in a network. This event is best correlated and used as an enrichment to determine the potential lateral movement activity.
windows
Potential RjvPlatform.DLL Sideloading From Default Location
mediumDetects loading of "RjvPlatform.dll" by the "SystemResetPlatform.exe" binary which can be abused as a method of DLL side loading since the "$SysReset" directory isn't created by default.
windows · image_load
Potential RoboForm.DLL Sideloading
mediumDetects potential DLL sideloading of "roboform.dll", a DLL used by RoboForm Password Manager
windows · image_load
Potential Ruby Reverse Shell
mediumDetects execution of ruby with the "-e" flag and calls to "socket" related functions. This could be an indication of a potential attempt to setup a reverse shell
linux · process_creation
Potential SAP NetWeaver Webshell Creation
mediumDetects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
windows · file_event
Potential SAP NetWeaver Webshell Creation - Linux
mediumDetects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
linux · file_event
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
mediumDetects the use of the Microsoft signed script "CL_mutexverifiers" to proxy the execution of additional PowerShell script commands
windows · process_creation
Potential Secure Deletion with SDelete
mediumDetects files that have extensions commonly seen while SDelete is used to wipe files.
windows
Potential SentinelOne Shell Context Menu Scan Command Tampering
mediumDetects potentially suspicious changes to the SentinelOne context menu scan command by a process other than SentinelOne.
windows · registry_set
Potential Shellcode Injection
mediumDetects potential shellcode injection as seen used by tools such as Metasploit's migrate and Empire's psinject.
windows · process_access
Potential ShellDispatch.DLL Functionality Abuse
mediumDetects potential "ShellDispatch.dll" functionality abuse to execute arbitrary binaries via "ShellExecute"
windows · process_creation
Potential ShellDispatch.DLL Sideloading
mediumDetects potential DLL sideloading of "ShellDispatch.dll"
windows · image_load
Potential Shim Database Persistence via Sdbinst.EXE
mediumDetects installation of a new shim using sdbinst.exe. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims
windows · process_creation
Potential Sidecar Injection Into Running Deployment
mediumDetects attempts to inject a sidecar container into a running deployment. A sidecar container is an additional container within a pod, that resides alongside the main container. One way to add containers to running resources like Deployments/DeamonSets/StatefulSets, is via a "kubectl patch" operation. By injecting a new container within a legitimate pod, an attacker can run their code and hide their activity, instead of running their own separated pod in the cluster.
kubernetes · application
Potential SolidPDFCreator.DLL Sideloading
mediumDetects potential DLL sideloading of "SolidPDFCreator.dll"
windows · image_load
Potential SPN Enumeration Via Setspn.EXE
mediumDetects service principal name (SPN) enumeration used for Kerberoasting
windows · process_creation
Potential Suspicious Activity Using SeCEdit
mediumDetects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy
windows · process_creation
Potential Suspicious Browser Launch From Document Reader Process
mediumDetects when a browser process or browser tab is launched from an application that handles document files such as Adobe, Microsoft Office, etc. And connects to a web application over http(s), this could indicate a possible phishing attempt.
windows · process_creation
Potential Suspicious Change To Sensitive/Critical Files
mediumDetects changes of sensitive and critical files. Monitors files that you don't expect to change without planning on Linux system. These files include, but are not limited to, system configuration files, authentication files, and critical application files. Attackers often target these files to maintain persistence, escalate privileges, or disrupt system operations.
linux · process_creation
Potential Suspicious PowerShell Keywords
mediumDetects potentially suspicious keywords that could indicate the use of a PowerShell exploitation framework
windows · ps_script
Potential Suspicious PowerShell Module File Created
mediumDetects the creation of a new PowerShell module in the first folder of the module directory structure "\WindowsPowerShell\Modules\malware\malware.psm1". This is somewhat an uncommon practice as legitimate modules often includes a version folder.
windows · file_event
Potential Suspicious Registry File Imported Via Reg.EXE
mediumDetects the import of '.reg' files from suspicious paths using the 'reg.exe' utility
windows · process_creation
Potential Suspicious Windows Feature Enabled
mediumDetects usage of the built-in PowerShell cmdlet "Enable-WindowsOptionalFeature" used as a Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows · ps_script
Potential Suspicious Windows Feature Enabled - ProcCreation
mediumDetects usage of the built-in PowerShell cmdlet "Enable-WindowsOptionalFeature" used as a Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows · process_creation
Potential UAC Bypass Via Sdclt.EXE
mediumA General detection for sdclt being spawned as an elevated process. This could be an indicator of sdclt being used for bypass UAC techniques.
windows · process_creation
Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
mediumDetects the use of the "Get-ADComputer" cmdlet in order to identify systems which are configured for unconstrained delegation.
windows · ps_script
Potential Unquoted Service Path Reconnaissance Via Wmic.EXE
mediumDetects known WMI recon method to look for unquoted service paths using wmic. Often used by pentester and attacker enumeration scripts
windows · process_creation
Potential Vivaldi_elf.DLL Sideloading
mediumDetects potential DLL sideloading of "vivaldi_elf.dll"
windows · image_load
Potential Wazuh Security Platform DLL Sideloading
mediumDetects potential DLL side loading of DLLs that are part of the Wazuh security platform
windows · image_load
Potential Webshell Creation On Static Website
mediumDetects the creation of files with certain extensions on a static web site. This can be indicative of potential uploads of a web shell.
windows · file_event
Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell
mediumDetects Powershell as a child of the WmiPrvSE process. Which could be a sign of lateral movement via WMI.
windows · process_creation
Potential WWlib.DLL Sideloading
mediumDetects potential DLL sideloading of "wwlib.dll"
windows · image_load
Potential XCSSET Malware Infection
mediumIdentifies the execution traces of the XCSSET malware. XCSSET is a macOS trojan that primarily spreads via Xcode projects and maliciously modifies applications. Infected users are also vulnerable to having their credentials, accounts, and other vital data stolen.
macos · process_creation
Potential Xterm Reverse Shell
mediumDetects usage of "xterm" as a potential reverse shell tunnel
linux · process_creation
Potentially Over Permissive Permissions Granted Using Dsacls.EXE
mediumDetects usage of Dsacls to grant over permissive permissions
windows · process_creation
Potentially Suspicious AccessMask Requested From LSASS
mediumDetects process handle on LSASS process with certain access mask
windows
Potentially Suspicious Azure Front Door Connection
mediumDetects connections with Azure Front Door (known legitimate service that can be leveraged for C2) that fall outside of known benign behavioral baseline (not using common apps or common azurefd.net endpoints)
windows · network_connection
Potentially Suspicious Cabinet File Expansion
mediumDetects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks
windows · process_creation
Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript
mediumDetects usage of the WMI class "Win32_NTEventlogFile" in a potentially suspicious way (delete, backup, change permissions, etc.) from a PowerShell script
windows · ps_script
Potentially Suspicious Child Process Of ClickOnce Application
mediumDetects potentially suspicious child processes of a ClickOnce deployment application
windows · process_creation
Potentially Suspicious Child Process Of DiskShadow.EXE
mediumDetects potentially suspicious child processes of "Diskshadow.exe". This could be an attempt to bypass parent/child relationship detection or application whitelisting rules.
windows · process_creation
Potentially Suspicious Child Process of KeyScrambler.exe
mediumDetects potentially suspicious child processes of KeyScrambler.exe
windows · process_creation
Potentially Suspicious Child Process Of VsCode
mediumDetects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.
windows · process_creation
Potentially Suspicious Child Process Of WinRAR.EXE
mediumDetects potentially suspicious child processes of WinRAR.exe.
windows · process_creation
Potentially Suspicious CMD Shell Output Redirect
mediumDetects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
windows · process_creation
Potentially Suspicious Command Targeting Teams Sensitive Files
mediumDetects a commandline containing references to the Microsoft Teams database or cookies files from a process other than Teams. The database might contain authentication tokens and other sensitive information about the logged in accounts.
windows · process_creation
Potentially Suspicious Compression Tool Parameters
mediumDetects potentially suspicious command line arguments of common data compression tools
windows · process_creation
Potentially Suspicious Desktop Background Change Using Reg.EXE
mediumDetects the execution of "reg.exe" to alter registry keys that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows · process_creation
Potentially Suspicious Desktop Background Change Via Registry
mediumDetects registry value settings that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows · registry_set
Potentially Suspicious DMP/HDMP File Creation
mediumDetects the creation of a file with the ".dmp"/".hdmp" extension by a shell or scripting application such as "cmd", "powershell", etc. Often created by software during a crash. Memory dumps can sometimes contain sensitive information such as credentials. It's best to determine the source of the crash.
windows · file_event
Potentially Suspicious Electron Application CommandLine
mediumDetects potentially suspicious CommandLine of electron apps (teams, discord, slack, etc.). This could be a sign of abuse to proxy execution through a signed binary.
windows · process_creation
Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
mediumDetects execution of different log query utilities and commands to search and dump the content of specific event logs or look for specific event IDs. This technique is used by threat actors in order to extract sensitive information from events logs such as usernames, IP addresses, hostnames, etc.
windows · process_creation
Potentially Suspicious Execution From Tmp Folder
mediumDetects a potentially suspicious execution of a process located in the '/tmp/' folder
linux · process_creation
Potentially Suspicious Execution Of PDQDeployRunner
mediumDetects suspicious execution of "PDQDeployRunner" which is part of the PDQDeploy service stack that is responsible for executing commands and packages on a remote machines
windows · process_creation
Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities from a potentially suspicious location
windows · process_creation
Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities with an uncommon extension.
windows · process_creation
Potentially Suspicious Explicit Credential Local Logon
mediumDetects potentially suspicious explicit credential logon events where the user is trying to logon with explicit credentials (username and password) that are different from the current user context. It might indicate an attacker attempting to escalate privileges after obtaining credentials for a different user account.
windows
Potentially Suspicious File Creation by OpenEDR's ITSMService
mediumDetects the creation of potentially suspicious files by OpenEDR's ITSMService process. The ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features. While legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.
windows · file_event
Potentially Suspicious GrantedAccess Flags On LSASS
mediumDetects process access requests to LSASS process with potentially suspicious access flags
windows · process_access
Potentially Suspicious Image Load of Offreg.dll
mediumDetects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API, bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives while evading detection mechanisms that rely on standard registry event logs.
windows · image_load
Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
mediumDetects potentially suspicious inline JavaScript execution using Node.js with specific keywords in the command line.
windows · process_creation
Potentially Suspicious JWT Token Search Via CLI
mediumDetects potentially suspicious search for JWT tokens via CLI by looking for the string "eyJ0eX" or "eyJhbG". JWT tokens are often used for access-tokens across various applications and services like Microsoft 365, Azure, AWS, Google Cloud, and others. Threat actors may search for these tokens to steal them for lateral movement or privilege escalation.
windows · process_creation
Potentially Suspicious Named Pipe Created Via Mkfifo
mediumDetects the creation of a new named pipe using the "mkfifo" utility in a potentially suspicious location
linux · process_creation
Potentially Suspicious NTFS Symlink Behavior Modification
mediumDetects the modification of NTFS symbolic link behavior using fsutil, which could be used to enable remote to local or remote to remote symlinks for potential attacks.
windows · process_creation
Potentially Suspicious Ping/Copy Command Combination
mediumDetects uncommon and potentially suspicious one-liner command containing both "ping" and "copy" at the same time, which is usually used by malware.
windows · process_creation
Potentially Suspicious PowerShell Child Processes
mediumDetects potentially suspicious child processes spawned by PowerShell. Use this rule to hunt for potential anomalies initiating from PowerShell scripts and commands.
windows · process_creation
Potentially Suspicious Powershell Script Execution From Temp Folder
mediumDetects a potentially suspicious powershell script executions from temporary folder
windows · process_creation
Potentially Suspicious Regsvr32 HTTP/FTP Pattern
mediumDetects regsvr32 execution to download/install/register new DLLs that are hosted on Web or FTP servers.
windows · process_creation
Potentially Suspicious Rundll32 Activity
mediumDetects suspicious execution of rundll32, with specific calls to some DLLs with known LOLBIN functionalities
windows · process_creation
Potentially Suspicious Rundll32.EXE Execution of UDL File
mediumDetects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
windows · process_creation
Potentially Suspicious Self Extraction Directive File Created
mediumDetects the creation of a binary file with the ".sed" extension. The ".sed" extension stand for Self Extraction Directive files. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries. Usually ".sed" files are simple ini files and not PE binaries.
windows · file_executable_detected
Potentially Suspicious Usage Of Qemu
mediumDetects potentially suspicious execution of the Qemu utility in a Windows environment. Threat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.
windows · process_creation
Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load
mediumDetects the image load of VSS DLL by uncommon executables
windows · image_load
Potentially Suspicious WDAC Policy File Creation
mediumDetects suspicious Windows Defender Application Control (WDAC) policy file creation from abnormal processes that could be abused by attacker to block EDR/AV components while allowing their own malicious code to run on the system.
windows · file_event
Potentially Suspicious WebDAV LNK Execution
mediumDetects possible execution via LNK file accessed on a WebDAV server.
windows · process_creation
Potentially Suspicious Windows App Activity
mediumDetects potentially suspicious child process of applications launched from inside the WindowsApps directory. This could be a sign of a rogue ".appx" package installation/execution
windows · process_creation
Potentially Suspicious Wuauclt Network Connection
mediumDetects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections. One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.
windows · network_connection
PowerShell Console History Logs Deleted
mediumDetects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence
windows · file_delete
PowerShell Core DLL Loaded By Non PowerShell Process
mediumDetects loading of essential DLLs used by PowerShell by non-PowerShell process. Detects behavior similar to meterpreter's "load powershell" extension.
windows · image_load
PowerShell Core DLL Loaded Via Office Application
mediumDetects PowerShell core DLL being loaded by an Office Product
windows · image_load
PowerShell Create Local User
mediumDetects creation of a local user via PowerShell
windows · ps_script
Powershell Create Scheduled Task
mediumAdversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code
windows · ps_script
Powershell Defender Exclusion
mediumDetects requests to exclude files, folders or processes from Antivirus scanning using PowerShell cmdlets
windows · process_creation
PowerShell Deleted Mounted Share
mediumDetects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
windows · ps_script
Powershell Detect Virtualization Environment
mediumAdversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox
windows · ps_script
Powershell Directory Enumeration
mediumDetects technique used by MAZE ransomware to enumerate directories using Powershell
windows · ps_script
PowerShell Downgrade Attack - PowerShell
mediumDetects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0
windows · ps_classic_start
PowerShell Download Pattern
mediumDetects a Powershell process that contains download commands in its command line string
windows · process_creation
Powershell Execute Batch Script
mediumAdversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple system
windows · ps_script
Powershell Executed From Headless ConHost Process
mediumDetects the use of powershell commands from headless ConHost window. The "--headless" flag hides the windows from the user upon execution.
windows · process_creation
PowerShell Get Clipboard
mediumA General detection for the Get-Clipboard commands in PowerShell logs. This could be an adversary capturing clipboard contents.
windows · ps_module
PowerShell Get-Clipboard Cmdlet Via CLI
mediumDetects usage of the 'Get-Clipboard' cmdlet via CLI
windows · process_creation
PowerShell Hotfix Enumeration
mediumDetects call to "Win32_QuickFixEngineering" in order to enumerate installed hotfixes often used in "enum" scripts by attackers
windows · ps_script
PowerShell ICMP Exfiltration
mediumDetects Exfiltration Over Alternative Protocol - ICMP. Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
windows · ps_script
Powershell Inline Execution From A File
mediumDetects inline execution of PowerShell code from a file
windows · process_creation
Powershell Keylogging
mediumAdversaries may log user keystrokes to intercept credentials as the user types them.
windows · ps_script
Powershell Local Email Collection
mediumAdversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a users local system, such as Outlook storage or cache files.
windows · ps_script
Powershell LocalAccount Manipulation
mediumAdversaries may manipulate accounts to maintain access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups
windows · ps_script
PowerShell Module File Created By Non-PowerShell Process
mediumDetects the creation of a new PowerShell module ".psm1", ".psd1", ".dll", ".ps1", etc. by a non-PowerShell process
windows · file_event
PowerShell MSI Install via WindowsInstaller COM From Remote Location
mediumDetects the execution of PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`) hosted remotely. This could be indication of malicious software deployment or lateral movement attempts using Windows Installer functionality. And the usage of WindowsInstaller COM object rather than msiexec could be an attempt to bypass the detection.
windows · process_creation
Powershell MsXml COM Object
mediumAdversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. (Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code
windows · ps_script
PowerShell Profile Modification
mediumDetects the creation or modification of a powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence
windows · file_event
PowerShell Remote Session Creation
mediumAdversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system
windows · ps_script
PowerShell Script Run in AppData
mediumDetects a suspicious command line execution that invokes PowerShell with reference to an AppData folder
windows · process_creation
PowerShell Script With File Hostname Resolving Capabilities
mediumDetects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.
windows · ps_script
Powershell Sensitive File Discovery
mediumDetect adversaries enumerate sensitive files
windows · ps_script
Powershell Store File In Alternate Data Stream
mediumStoring files in Alternate Data Stream (ADS) similar to Astaroth malware.
windows · ps_script
Powershell Timestomp
mediumAdversaries may modify file time attributes to hide new or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder.
windows · ps_script
Powershell Token Obfuscation - Powershell
mediumDetects TOKEN OBFUSCATION technique from Invoke-Obfuscation in Powershell scripts. Use this rule as a threat-hunting baseline to find obfuscated scripts in your environment. Once tested and tuned, consider deploying a production detection rule based on this hunting rule.
windows · ps_script
Powershell WMI Persistence
mediumAdversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
windows · ps_script
PowerShell WMI Win32_Product Install MSI
mediumDetects the execution of an MSI file using PowerShell and the WMI Win32_Product class
windows · ps_script
PowerShell Write-EventLog Usage
mediumDetects usage of the "Write-EventLog" cmdlet with 'RawData' flag. The cmdlet can be levreage to write malicious payloads to the EventLog and then retrieve them later for later use
windows · ps_script
Powershell XML Execute Command
mediumAdversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. (Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code
windows · ps_script
Print History File Contents
mediumDetects events in which someone prints the contents of history files to the commandline or redirects it to a file for reconnaissance
linux · process_creation
Private Keys Reconnaissance Via CommandLine Tools
mediumAdversaries may search for private key certificate files on compromised systems for insecurely stored credential
windows · process_creation
Privileged Account Creation
mediumDetects when a new admin is created.
azure
Procdump Execution
mediumDetects usage of the SysInternals Procdump utility
windows · process_creation
Process Creation Attempt via Wmic.EXE
mediumDetects the attempt to create a process via "wmic" with the "process call create" flag, which might indicate an attempt to execute a malicious process on the compromised host. Adversaries may use wmic to execute a process on the compromised host as part of their attack. This event is triggered on on attempt and process creation can be either successful or unsuccessful.
windows · process_creation
Process Creation Using Sysnative Folder
mediumDetects process creation events that use the Sysnative folder (common for CobaltStrike spawns)
windows · process_creation
Process Deletion of Its Own Executable
mediumDetects the deletion of a process's executable by itself. This is usually not possible without workarounds and may be used by malware to hide its traces.
windows · file_delete
Process Launched Without Image Name
mediumDetect the use of processes with no name (".exe"), which can be used to evade Image-based detections.
windows · process_creation
Process Memory Dump Via Dotnet-Dump
mediumDetects the execution of "dotnet-dump" with the "collect" flag. The execution could indicate potential process dumping of critical processes such as LSASS.
windows · process_creation
Process Monitor Driver Creation By Non-Sysinternals Binary
mediumDetects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.
windows · file_event
Process Proxy Execution Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" binary to execute arbitrary processes. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows · process_creation
Processes Accessing the Microphone and Webcam
mediumPotential adversaries accessing the microphone and webcam in an endpoint.
windows
Program Executed Using Proxy/Local Command Via SSH.EXE
mediumDetect usage of the "ssh.exe" binary as a proxy to launch other programs.
windows · process_creation
Program Executions in Suspicious Folders
mediumDetects program executions in suspicious non-program folders related to malware or hacking activity
linux
Proxy Execution via Vshadow
mediumDetects the invocation of vshadow.exe with the -exec parameter that executes a specified script or command after the shadow copies are created but before the VShadow tool exits. VShadow is a command-line tool that you can use to create and manage volume shadow copies. While legitimate backup or administrative scripts may use this flag, attackers can leverage this parameter to proxy the execution of malware.
windows · process_creation
Psexec Execution
mediumDetects user accept agreement execution in psexec commandline
windows · process_creation
PsExec Service Execution
mediumDetects launch of the PSEXESVC service, which means that this system was the target of a psexec remote execution
windows · process_creation
PsExec Service Installation
mediumDetects PsExec service installation and execution events
windows
PsExec Tool Execution From Suspicious Locations - PipeName
mediumDetects PsExec default pipe creation where the image executed is located in a suspicious location. Which could indicate that the tool is being used in an attack
windows · pipe_created
PSScriptPolicyTest Creation By Uncommon Process
mediumDetects the creation of the "PSScriptPolicyTest" PowerShell script by an uncommon process. This file is usually generated by Microsoft Powershell to test against Applocker.
windows · file_event
PST Export Alert Using eDiscovery Alert
mediumAlert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content
m365
PST Export Alert Using New-ComplianceSearchAction
mediumAlert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.
m365
PUA - AdFind.EXE Execution
mediumDetects execution of Adfind.exe utility, which can be used for reconnaissance in an Active Directory environment
windows · process_creation
PUA - Advanced IP Scanner Execution
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows · process_creation
PUA - Advanced IP/Port Scanner Update Check
mediumDetect the update check performed by Advanced IP/Port Scanner utilities.
proxy
PUA - Advanced Port Scanner Execution
mediumDetects the use of Advanced Port Scanner.
windows · process_creation
PUA - AdvancedRun Execution
mediumDetects the execution of AdvancedRun utility
windows · process_creation
PUA - AWS TruffleHog Execution
mediumDetects the execution of TruffleHog, a popular open-source tool used for scanning repositories for secrets and sensitive information, within an AWS environment. It has been reported to be used by threat actors for credential harvesting. All detections should be investigated to determine if the usage is authorized by security teams or potentially malicious.
aws
PUA - CSExec Default Named Pipe
mediumDetects default CSExec pipe creation
windows · pipe_created
PUA - Mouse Lock Execution
mediumIn Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
windows · process_creation
PUA - NimScan Execution
mediumDetects usage of NimScan, a portscanner utility. In early 2025, adversaries were observed using this utility to scan for open ports on remote hosts in a compromised environment. This rule identifies the execution of NimScan based on the process image name and specific hash values associated with different versions of the tool.
windows · process_creation
PUA - NirCmd Execution
mediumDetects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity
windows · process_creation
PUA - Nmap/Zenmap Execution
mediumDetects usage of namp/zenmap. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation
windows · process_creation
PUA - PAExec Default Named Pipe
mediumDetects PAExec default named pipe
windows · pipe_created
PUA - PingCastle Execution
mediumDetects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level.
windows · process_creation
PUA - Potential PE Metadata Tamper Using Rcedit
mediumDetects the use of rcedit to potentially alter executable PE metadata properties, which could conceal efforts to rename system utilities for defense evasion.
windows · process_creation
PUA - Process Hacker Execution
mediumDetects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc). Process Hacker is a tool to view and manipulate processes, kernel options and other low level options. Threat actors abused older vulnerable versions to manipulate system processes.
windows · process_creation
PUA - Radmin Viewer Utility Execution
mediumDetects the execution of Radmin which can be abused by an adversary to remotely control Windows machines
windows · process_creation
PUA - RemCom Default Named Pipe
mediumDetects default RemCom pipe creation
windows · pipe_created
PUA - SoftPerfect Netscan Execution
mediumDetects usage of SoftPerfect's "netscan.exe". An application for scanning networks. It is actively used in-the-wild by threat actors to inspect and understand the network architecture of a victim.
windows · process_creation
PUA - Sysinternals Tools Execution - Registry
mediumDetects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the "accepteula" registry key.
windows · registry_set
PUA - System Informer Driver Load
mediumDetects driver load of the System Informer tool
windows · driver_load
PUA - System Informer Execution
mediumDetects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
windows · process_creation
PUA - TruffleHog Execution
mediumDetects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
windows · process_creation
PUA - TruffleHog Execution - Linux
mediumDetects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
linux · process_creation
PUA - WebBrowserPassView Execution
mediumDetects the execution of WebBrowserPassView.exe. A password recovery tool that reveals the passwords stored by the following Web browsers, Internet Explorer (Version 4.0 - 11.0), Mozilla Firefox (All Versions), Google Chrome, Safari, and Opera
windows · process_creation
Publisher Attachment File Dropped In Suspicious Location
mediumDetects creation of files with the ".pub" extension in suspicious or uncommon locations. This could be a sign of attackers abusing Publisher documents
windows · file_event
Pubprn.vbs Proxy Execution
mediumDetects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.
windows · process_creation
Python Initiated Connection
mediumDetects a Python process initiating a network connection. While this often relates to package installation, it can also indicate a potential malicious script communicating with a C&C server.
windows · network_connection
Python Inline Command Execution
mediumDetects execution of python using the "-c" flag. This is could be used as a way to launch a reverse shell or execute live python code.
windows · process_creation
Python Path Configuration File Creation - Linux
mediumDetects creation of a Python path configuration file (.pth) in Python library folders, which can be maliciously abused for code execution and persistence. Modules referenced by these files are run at every Python startup (v3.5+), regardless of whether the module is imported by the calling script. Default paths are '\lib\site-packages\*.pth' (Windows) and '/lib/pythonX.Y/site-packages/*.pth' (Unix and macOS).
linux · file_event
Python Path Configuration File Creation - MacOS
mediumDetects creation of a Python path configuration file (.pth) in Python library folders, which can be maliciously abused for code execution and persistence. Modules referenced by these files are run at every Python startup (v3.5+), regardless of whether the module is imported by the calling script. Default paths are '\lib\site-packages\*.pth' (Windows) and '/lib/pythonX.Y/site-packages/*.pth' (Unix and macOS).
macos · file_event
Python Path Configuration File Creation - Windows
mediumDetects creation of a Python path configuration file (.pth) in Python library folders, which can be maliciously abused for code execution and persistence. Modules referenced by these files are run at every Python startup (v3.5+), regardless of whether the module is imported by the calling script. Default paths are '\lib\site-packages\*.pth' (Windows) and '/lib/pythonX.Y/site-packages/*.pth' (Unix and macOS).
windows · file_event
Python Spawning Pretty TTY Via PTY Module
mediumDetects a python process calling to the PTY module in order to spawn a pretty tty which could be indicative of potential reverse shell activity.
linux · process_creation
Python SQL Exceptions
mediumGeneric rule for SQL exceptions in Python according to PEP 249
python · application
Python WebServer Execution - Linux
mediumDetects the execution of Python web servers via command line interface (CLI). After gaining access to target systems, adversaries may use Python's built-in HTTP server modules to quickly establish a web server without requiring additional software. This technique is commonly used in post-exploitation scenarios as it provides a simple method for transferring files between the compromised host and attacker-controlled systems.
linux · process_creation
Query Usage To Exfil Data
mediumDetects usage of "query.exe" a system binary to exfil information such as "sessions" and "processes" for later use
windows · process_creation
Rare Subscription-level Operations In Azure
mediumIdentifies IPs from which users grant access to other users on azure resources and alerts when a previously unseen source IP address is used.
azure
Rclone Activity via Proxy
mediumDetects the use of rclone, a command-line program to manage files on cloud storage, via its default user-agent string
proxy
Rclone Config File Creation
mediumDetects Rclone config files being created
windows · file_event
RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
mediumDetects enabling or disabling of Remote Desktop Protocol (RDP) using alternate methods such as WMIC or PowerShell. In PowerShell one-liner commands, the "SetAllowTSConnections" method of the "Win32_TerminalServiceSetting" class may be used to enable or disable RDP. In WMIC, the "rdtoggle" alias or "Win32_TerminalServiceSetting" class may be used for the same purpose.
windows · process_creation
RDP Sensitive Settings Changed to Zero
mediumDetects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc.
windows · registry_set
RDS Database Security Group Modification
mediumDetects changes to the security group entries for RDS databases. This can indicate that a misconfiguration has occurred which potentially exposes the database to the public internet, a wider audience within the VPC or that removal of valid rules has occurred which could impact the availability of the database to legitimate services and users.
aws
Read Contents From Stdin Via Cmd.EXE
mediumDetect the use of "<" to read and potentially execute a file via cmd.exe
windows · process_creation
Rebuild Performance Counter Values Via Lodctr.EXE
mediumDetects the execution of "lodctr.exe" to rebuild the performance counter registry values. This can be abused by attackers by providing a malicious config file to overwrite performance counter configuration to confuse and evade monitoring and security solutions.
windows · process_creation
Recon Command Output Piped To Findstr.EXE
mediumDetects the execution of a potential recon command where the results are piped to "findstr". This is meant to trigger on inline calls of "cmd.exe" via the "/c" or "/k" for example. Attackers often time use this technique to extract specific information they require in their reconnaissance phase.
windows · process_creation
Recon Information for Export with Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · process_creation
Recon Information for Export with PowerShell
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data
windows · ps_script
RedTail Cryptominer User-Agent
mediumDetects inbound web requests using the "libredtail-http" User-Agent. libredtail-http is a unique User-Agent string associated with a campaign of automated, malicious scans and attacks targeting exposed container environments and web applications,notably identified in activities stemming from late 2024 through early 2026. It is primarily used by the RedTail cryptominer malware to identify and exploit vulnerabilities for deploying cryptocurrency miners.
webserver
RegAsm.EXE Initiating Network Connection To Public IP
mediumDetects "RegAsm.exe" initiating a network connection to public IP adresses
windows · network_connection
Register New IFiltre For Persistence
mediumDetects when an attacker registers a new IFilter for an extension. Microsoft Windows Search uses filters to extract the content of items for inclusion in a full-text index. You can extend Windows Search to index new or proprietary file types by writing filters to extract the content, and property handlers to extract the properties of files.
windows · registry_set
REGISTER_APP.VBS Proxy Execution
mediumDetects the use of a Microsoft signed script 'REGISTER_APP.VBS' to register a VSS/VDS Provider as a COM+ application.
windows · process_creation
Registry Enumeration via WMI Stdregprov
mediumDetects the usage of wmic.exe to enumerate or read Windows registry via the WMI StdRegProv class read methods (EnumKey, EnumValues, GetStringValue, etc.). While registry reads are common, attackers may use this technique to perform reconnaissance and discover sensitive configuration values, credentials, or installed software. The use of WMI as an alternative to standard tools like reg.exe can indicate an attempt to evade detection focused on traditional registry query commands.
windows · process_creation
Registry Explorer Policy Modification
mediumDetects registry modifications that disable internal tools or functions in explorer (malware like Agent Tesla uses this technique)
windows · registry_set
Registry Hide Function from User
mediumDetects registry modifications that hide internal tools or functions from the user (malware like Agent Tesla, Hermetic Wiper uses this technique)
windows · registry_set
Registry Manipulation via WMI Stdregprov
mediumDetects the usage of wmic.exe to modify Windows registry via the WMI StdRegProv class write methods (CreateKey, DeleteKey, SetStringValue, etc.). This behaviour could be potentially suspicious because it uses an alternative method to modify registry keys instead of legitimate registry tools like reg.exe or regedit.exe. Attackers specifically choose this technique to evade detection and bypass security monitoring focused on traditional registry modification commands.
windows · process_creation
Registry Modification Attempt Via VBScript
mediumDetects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods via common LOLBINs. It could be an attempt to modify the registry for persistence without using straightforward methods like regedit.exe, reg.exe, or PowerShell. Threat Actors may use this technique to evade detection by security solutions that monitor for direct registry modifications through traditional tools.
windows · process_creation
Registry Modification Attempt Via VBScript - PowerShell
mediumDetects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods embedded within PowerShell scripts or commands. Threat actors commonly embed VBScript code within PowerShell to perform registry modifications, attempting to evade detection that monitors for direct registry access through traditional tools. This technique can be used for persistence, defense evasion, and privilege escalation by modifying registry keys without using regedit.exe, reg.exe, or PowerShell's native registry cmdlets.
windows · ps_script
Registry Modification of MS-settings Protocol Handler
mediumDetects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence. Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.
windows · process_creation
Registry Modification to Hidden File Extension
mediumHides the file extension through modification of the registry
windows · registry_set
Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the setting of a registry inside the "\Shell\Open\Command" value with PowerShell classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows · registry_set
Registry Tampering by Potentially Suspicious Processes
mediumDetects suspicious registry modifications made by suspicious processes such as script engine processes such as WScript, or CScript etc. These processes are rarely used for legitimate registry modifications, and their activity may indicate an attempt to modify the registry without using standard tools like regedit.exe or reg.exe, potentially for evasion and persistence.
windows · registry_event
Registry-Free Process Scope COR_PROFILER
mediumAdversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR. The COR_PROFILER is a .NET Framework feature which allows developers to specify an unmanaged (or external of .NET) profiling DLL to be loaded into each .NET process that loads the Common Language Runtime (CLR). These profiliers are designed to monitor, troubleshoot, and debug managed code executed by the .NET CLR. (Citation: Microsoft Profiling Mar 2017) (Citation: Microsoft COR_PROFILER Feb 2013)
windows · ps_script
Regsvr32 DLL Execution With Uncommon Extension
mediumDetects a "regsvr32" execution where the DLL doesn't contain a common file extension.
windows · process_creation
Regsvr32 Execution From Potential Suspicious Location
mediumDetects execution of regsvr32 where the DLL is located in a potentially suspicious location.
windows · process_creation
Regsvr32.EXE Calling of DllRegisterServer Export Function Implicitly
mediumDetects execution of regsvr32 with the silent flag and no other flags on a DLL located in an uncommon or potentially suspicious location. When Regsvr32 is called in such a way, it implicitly calls the DLL export function 'DllRegisterServer'.
windows · process_creation
RemCom Service File Creation
mediumDetects default RemCom service filename which indicates RemCom service installation and execution
windows · file_event
RemCom Service Installation
mediumDetects RemCom service installation and execution events
windows
Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions
mediumDetects the execution of Action1 in order to execute arbitrary code or establish a remote session. Action1 is a powerful Remote Monitoring and Management tool that enables users to execute commands, scripts, and binaries. Through the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed. Hunting Opportunity 1- Weed Out The Noise When threat actors execute a script, a command, or a binary through these new policies and apps, the names of these become visible in the command line during the execution process. Below is an example of the command line that contains the deployment of a binary through a policy with name "test_app_1": ParentCommandLine: "C:\WINDOWS\Action1\action1_agent.exe schedule:Deploy_App__test_app_1_1681327673425 runaction:0" After establishing a baseline, we can split the command to extract the policy name and group all the policy names and inspect the results with a list of frequency occurrences. Hunting Opportunity 2 - Remote Sessions On Out Of Office Hours If you have admins within your environment using remote sessions to administer endpoints, you can create a threat-hunting query and modify the time of the initiated sessions looking for abnormal activity.
windows · process_creation
Remote Access Tool - Ammy Admin Agent Execution
mediumDetects the execution of the Ammy Admin RMM agent for remote management.
windows · process_creation
Remote Access Tool - AnyDesk Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - AnyDesk Execution With Known Revoked Signing Certificate
mediumDetects the execution of an AnyDesk binary with a version prior to 8.0.8. Prior to version 8.0.8, the Anydesk application used a signing certificate that got compromised by threat actors. Use this rule to detect instances of older versions of Anydesk using the compromised certificate This is recommended in order to avoid attackers leveraging the certificate and signing their binaries to bypass detections.
windows · process_creation
Remote Access Tool - AnyDesk Incoming Connection
mediumDetects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.
windows · network_connection
Remote Access Tool - AnyDesk Piped Password Via CLI
mediumDetects piping the password to an anydesk instance via CMD and the '--set-password' flag.
windows · process_creation
Remote Access Tool - Cmd.EXE Execution via AnyViewer
mediumDetects execution of "cmd.exe" via the AnyViewer RMM agent on a remote management sessions.
windows · process_creation
Remote Access Tool - GoToAssist Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - LogMeIn Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - MeshAgent Command Execution via MeshCentral
mediumDetects the use of MeshAgent to execute commands on the target host, particularly when threat actors might abuse it to execute commands directly. MeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.
windows · process_creation
Remote Access Tool - NetSupport Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - NetSupport Execution From Unusual Location
mediumDetects execution of client32.exe (NetSupport RAT) from an unusual location (outside of 'C:\Program Files')
windows · process_creation
Remote Access Tool - Potential MeshAgent Execution - MacOS
mediumDetects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
macos · process_creation
Remote Access Tool - Potential MeshAgent Execution - Windows
mediumDetects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
windows · process_creation
Remote Access Tool - RURAT Execution From Unusual Location
mediumDetects execution of Remote Utilities RAT (RURAT) from an unusual location (outside of 'C:\Program Files')
windows · process_creation
Remote Access Tool - ScreenConnect Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - ScreenConnect Installation Execution
mediumDetects ScreenConnect program starts that establish a remote access to a system.
windows · process_creation
Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
mediumDetects potentially suspicious child processes launched via the ScreenConnect client service.
windows · process_creation
Remote Access Tool - ScreenConnect Remote Command Execution - Hunting
mediumDetects remote binary or command execution via the ScreenConnect Service. Use this rule in order to hunt for potentially anomalous executions originating from ScreenConnect
windows · process_creation
Remote Access Tool - Simple Help Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
mediumDetects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line. These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID. This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
windows · process_creation
Remote Access Tool - UltraViewer Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool Services Have Been Installed - Security
mediumDetects service installation of different remote access tools software. These software are often abused by threat actors to perform
windows
Remote Access Tool Services Have Been Installed - System
mediumDetects service installation of different remote access tools software. These software are often abused by threat actors to perform
windows
Remote Code Execute via Winrm.vbs
mediumDetects an attempt to execute code or create service on remote host via winrm.vbs.
windows · process_creation
Remote DLL Load Via Rundll32.EXE
mediumDetects a remote DLL load event via "rundll32.exe".
windows · image_load
Remote File Download Via Desktopimgdownldr Utility
mediumDetects the desktopimgdownldr utility being used to download a remote file. An adversary may use desktopimgdownldr to download arbitrary files as an alternative to certutil.
windows · process_creation
Remote File Download Via Findstr.EXE
mediumDetects execution of "findstr" with specific flags and a remote share path. This specific set of CLI flags would allow "findstr" to download the content of the file located on the remote share as described in the LOLBAS entry.
windows · process_creation
Remote PowerShell Session Host Process (WinRM)
mediumDetects remote PowerShell sections by monitoring for wsmprovhost (WinRM host process) as a parent or child process (sign of an active PowerShell remote session).
windows · process_creation
Remote Registry Management Using Reg Utility
mediumRemote registry management using REG utility from non-admin workstation
windows
Remote Service Activity via SVCCTL Named Pipe
mediumDetects remote service activity via remote access to the svcctl named pipe
windows
Remote Task Creation via ATSVC Named Pipe
mediumDetects remote task creation via at.exe or API interacting with ATSVC namedpipe
windows
Remote Task Creation via ATSVC Named Pipe - Zeek
mediumDetects remote task creation via at.exe or API interacting with ATSVC namedpipe
zeek
Remote Thread Created In Shell Application
mediumDetects remote thread creation in command shell applications, such as "Cmd.EXE" and "PowerShell.EXE". It is a common technique used by malware, such as IcedID, to inject malicious code and execute it within legitimate processes.
windows · create_remote_thread
Remote Thread Creation By Uncommon Source Image
mediumDetects uncommon processes creating remote threads.
windows · create_remote_thread
Remote Thread Creation In Uncommon Target Image
mediumDetects uncommon target processes for remote thread creation
windows · create_remote_thread
Remote Thread Creation Via PowerShell
mediumDetects the creation of a remote thread from a Powershell process to another process
windows · create_remote_thread
Remote Thread Creation Via PowerShell In Uncommon Target
mediumDetects the creation of a remote thread from a Powershell process in an uncommon target process
windows · create_remote_thread
Remote Utilities Host Service Install
mediumDetects Remote Utilities Host service installation on the target system.
windows
Removal Of Index Value to Hide Schedule Task - Registry
mediumDetects when the "index" value of a scheduled task is removed or deleted from the registry. Which effectively hides it from any tooling such as "schtasks /query"
windows · registry_delete
Removal of Potential COM Hijacking Registry Keys
mediumDetects any deletion of entries in ".*\shell\open\command" registry keys. These registry keys might have been used for COM hijacking activities by a threat actor or an attacker and the deletion could indicate steps to remove its tracks.
windows · registry_delete
Removal Of SD Value to Hide Schedule Task - Registry
mediumRemove SD (Security Descriptor) value in \Schedule\TaskCache\Tree registry hive to hide schedule task. This technique is used by Tarrask malware
windows · registry_delete
Remove Account From Domain Admin Group
mediumAdversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.
windows · ps_script
Remove Immutable File Attribute
mediumDetects usage of the 'chattr' utility to remove immutable file attribute.
linux · process_creation
Remove Immutable File Attribute - Auditd
mediumDetects removing immutable file attribute.
linux
Remove Scheduled Cron Task/Job
mediumDetects usage of the 'crontab' utility to remove the current crontab. This is a common occurrence where cryptocurrency miners compete against each other by removing traces of other miners to hijack the maximum amount of resources possible
linux · process_creation
Renamed AutoHotkey.EXE Execution
mediumDetects execution of a renamed autohotkey.exe binary based on PE metadata fields
windows · process_creation
Renamed BOINC Client Execution
mediumDetects the execution of a renamed BOINC binary.
windows · process_creation
Renamed CURL.EXE Execution
mediumDetects the execution of a renamed "CURL.exe" binary based on the PE metadata fields
windows · process_creation
Renamed FTP.EXE Execution
mediumDetects the execution of a renamed "ftp.exe" binary based on the PE metadata fields
windows · process_creation
Renamed Microsoft Teams Execution
mediumDetects the execution of a renamed Microsoft Teams binary.
windows · process_creation
Renamed Remote Utilities RAT (RURAT) Execution
mediumDetects execution of renamed Remote Utilities (RURAT) via Product PE header field
windows · process_creation
Replace.exe Usage
mediumDetects the use of Replace.exe which can be used to replace file with another file
windows · process_creation
Response File Execution Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with the "-f" flag in order to load a response file which might contain a malicious action.
windows · process_creation
Rhadamanthys Stealer Module Launch Via Rundll32.EXE
mediumDetects the use of Rundll32 to launch an NSIS module that serves as the main stealer capability of Rhadamanthys infostealer, as observed in reports and samples in early 2023
windows · process_creation
Root Account Enable Via Dsenableroot
mediumDetects attempts to enable the root account via "dsenableroot"
macos · process_creation
Root Certificate Installed - PowerShell
mediumAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · ps_script
Ruby Inline Command Execution
mediumDetects execution of ruby using the "-e" flag. This is could be used as a way to launch a reverse shell or execute live ruby code.
windows · process_creation
Ruby on Rails Framework Exceptions
mediumDetects suspicious Ruby on Rails exceptions that could indicate exploitation attempts
ruby_on_rails · application
Run Once Task Configuration in Registry
mediumRule to detect the configuration of Run Once registry key. Configured payload can be run by runonce.exe /AlternateShellStartup
windows · registry_event
Rundll32 Execution With Uncommon DLL Extension
mediumDetects the execution of rundll32 with a command line that doesn't contain a common extension
windows · process_creation
Rundll32 InstallScreenSaver Execution
mediumAn attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver
windows · process_creation
Rundll32 Internet Connection
mediumDetects a rundll32 that communicates with public IP addresses
windows · network_connection
Rundll32 Spawned Via Explorer.EXE
mediumDetects execution of "rundll32.exe" with a parent process of Explorer.exe. This has been observed by variants of Raspberry Robin, as first reported by Red Canary.
windows · process_creation
Rundll32.EXE Calling DllRegisterServer Export Function Explicitly
mediumDetects when the DLL export function 'DllRegisterServer' is called in the commandline by Rundll32 explicitly where the DLL is located in a non-standard path.
windows · process_creation
Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE
mediumDetects Schtask creations that point to a suspicious folder or an environment variable often used by malware
windows · process_creation
Scheduled Cron Task/Job - Linux
mediumDetects abuse of the cron utility to perform task scheduling for initial or recurring execution of malicious code. Detection will focus on crontab jobs uploaded from the tmp folder.
linux · process_creation
Scheduled Cron Task/Job - MacOs
mediumDetects abuse of the cron utility to perform task scheduling for initial or recurring execution of malicious code. Detection will focus on crontab jobs uploaded from the tmp folder.
macos · process_creation
Scheduled Task Creation From Potential Suspicious Parent Location
mediumDetects the execution of "schtasks.exe" from a parent that is located in a potentially suspicious location. Multiple malware strains were seen exhibiting a similar behavior in order to achieve persistence.
windows · process_creation
Scheduled Task Creation with Curl and PowerShell Execution Combo
mediumDetects the creation of a scheduled task using schtasks.exe, potentially in combination with curl for downloading payloads and PowerShell for executing them. This facilitates executing malicious payloads or connecting with C&C server persistently without dropping the malware sample on the host.
windows · process_creation
Scheduled Task Executed From A Suspicious Location
mediumDetects the execution of Scheduled Tasks where the Program being run is located in a suspicious location or it's an unusale program to be run from a Scheduled Task
windows
Scheduled Task Executed Uncommon LOLBIN
mediumDetects the execution of Scheduled Tasks where the program being run is located in a suspicious location or where it is an unusual program to be run from a Scheduled Task
windows
Scheduled Task Executing Payload from Registry
mediumDetects the creation of a schtasks that potentially executes a payload stored in the Windows Registry using PowerShell.
windows · process_creation
SCM Database Handle Failure
mediumDetects non-system users failing to get a handle of the SCM database.
windows
SCM Database Privileged Operation
mediumDetects non-system users performing privileged operation os the SCM database
windows
SCR File Write Event
mediumDetects the creation of screensaver files (.scr) outside of system folders. Attackers may execute an application as an ".SCR" file using "rundll32.exe desk.cpl,InstallScreenSaver" for example.
windows · file_event
Screen Capture Activity Via Psr.EXE
mediumDetects execution of Windows Problem Steps Recorder (psr.exe), a utility used to record the user screen and clicks.
windows · process_creation
ScreenConnect Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
ScreenConnect User Database Modification
mediumDetects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions.
windows · file_event
ScreenConnect User Database Modification - Security
mediumThis detects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory.
windows
ScreenSaver Registry Key Set
mediumDetects registry key established after masqueraded .scr file execution using Rundll32 through desk.cpl
windows · registry_set
Scripted Diagnostics Turn Off Check Enabled - Registry
mediumDetects enabling TurnOffCheck which can be used to bypass defense of MSDT Follina vulnerability
windows · registry_set
Scripting/CommandLine Process Spawned Regsvr32
mediumDetects various command line and scripting engines/processes such as "PowerShell", "Wscript", "Cmd", etc. spawning a "regsvr32" instance.
windows · process_creation
Sdclt Child Processes
mediumA General detection for sdclt spawning new processes. This could be an indicator of sdclt being used for bypass UAC techniques.
windows · process_creation
Security Software Discovery - MacOs
mediumDetects usage of system utilities (only grep for now) to discover security software discovery
macos · process_creation
Security Software Discovery Via Powershell Script
mediumDetects calls to "get-process" where the output is piped to a "where-object" filter to search for security solution processes. Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as firewall rules and anti-virus
windows · ps_script
Security Tools Keyword Lookup Via Findstr.EXE
mediumDetects execution of "findstr" to search for common names of security tools. Attackers often pipe the results of recon commands such as "tasklist" or "whoami" to "findstr" in order to filter out the results. This detection focuses on the keywords that the attacker might use as a filter.
windows · process_creation
Self Extraction Directive File Created In Potentially Suspicious Location
mediumDetects the creation of Self Extraction Directive files (.sed) in a potentially suspicious location. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries.
windows · file_event
Service Binary in User Controlled Folder
mediumDetects the setting of the "ImagePath" value of a service registry key to a path controlled by a non-administrator user such as "\AppData\" or "\ProgramData\". Attackers often use such directories for staging purposes. This rule might also trigger on badly written software, where if an attacker controls an auto starting service, they might achieve persistence or privilege escalation. Note that while ProgramData is a user controlled folder, software might apply strict ACLs which makes them only accessible to admin users. Remove such folders via filters if you experience a lot of noise.
windows · registry_set
Service Installation in Suspicious Folder
mediumDetects service installation in suspicious folder appdata
windows
Service Reconnaissance Via Wmic.EXE
mediumAn adversary might use WMI to check if a certain remote service is running on a remote device. When the test completes, a service information will be displayed on the screen if it exists. A common feedback message is that "No instance(s) Available" if the service queried is not running. A common error message is "Node - (provided IP or default) ERROR Description =The RPC server is unavailable" if the provided remote host is unreachable
windows · process_creation
Service Registry Permissions Weakness Check
mediumAdversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
windows · ps_script
Service Security Descriptor Tampering Via Sc.EXE
mediumDetection of sc.exe utility adding a new service with special permission which hides that service.
windows · process_creation
Service Started/Stopped Via Wmic.EXE
mediumDetects usage of wmic to start or stop a service
windows · process_creation
Service Startup Type Change Via Wmic.EXE
mediumDetects changes to service startup type to 'disabled' or 'manual' using the WMIC command-line utility.
windows · process_creation
Service StartupType Change Via PowerShell Set-Service
mediumDetects the use of the PowerShell "Set-Service" cmdlet to change the startup type of a service to "disabled" or "manual"
windows · process_creation
Service StartupType Change Via Sc.EXE
mediumDetect the use of "sc.exe" to change the startup type of a service to "disabled" or "demand"
windows · process_creation
ServiceDll Hijack
mediumDetects changes to the "ServiceDLL" value related to a service in the registry. This is often used as a method of persistence.
windows · registry_set
SES Identity Has Been Deleted
mediumDetects an instance of an SES identity being deleted via the "DeleteIdentity" event. This may be an indicator of an adversary removing the account that carried out suspicious or malicious activities
aws
Session Manager Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Setup16.EXE Execution With Custom .Lst File
mediumDetects the execution of "Setup16.EXE" and old installation utility with a custom ".lst" file. These ".lst" file can contain references to external program that "Setup16.EXE" will execute. Attackers and adversaries might leverage this as a living of the land utility.
windows · process_creation
Shadow Copies Creation Using Operating Systems Utilities
mediumShadow Copies creation using operating systems utilities, possible credential access
windows · process_creation
SharePoint ToolShell CVE-2025-53770 Exploitation - Web IIS
mediumDetects access to vulnerable SharePoint components potentially being exploited in CVE-2025-53770 through IIS web server logs. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
webserver
Shell Invocation via Apt - Linux
mediumDetects the use of the "apt" and "apt-get" commands to execute a shell or proxy commands. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux · process_creation
Shell Process Spawned by Java.EXE
mediumDetects shell spawned from Java host process, which could be a sign of exploitation (e.g. log4j exploitation)
windows · process_creation
SMB over QUIC Via Net.EXE
mediumDetects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments.
windows · process_creation
SMB over QUIC Via PowerShell Script
mediumDetects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments
windows · ps_script
SMB Spoolss Name Piped Usage
mediumDetects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
zeek
Source Code Enumeration Detection by Keyword
mediumDetects source code enumeration that use GET requests by keyword searches in URL strings
webserver
Spring Framework Exceptions
mediumDetects suspicious Spring framework exceptions that could indicate exploitation attempts
spring · application
SQL Client Tools PowerShell Session Detection
mediumThis rule detects execution of a PowerShell code through the sqltoolsps.exe utility, which is included in the standard set of utilities supplied with the Microsoft SQL Server Management studio. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.
windows · process_creation
SSHD Error Message CVE-2018-15473
mediumDetects exploitation attempt using public exploit code for CVE-2018-15473
linux
Standard User In High Privileged Group
mediumDetect standard users login that are part of high privileged groups such as the Administrator group
windows
Start of NT Virtual DOS Machine
mediumNtvdm.exe allows the execution of 16-bit Windows applications on 32-bit Windows operating systems, as well as the execution of both 16-bit and 32-bit DOS applications
windows · process_creation
Startup Folder File Write
mediumA General detection for files being created in the Windows startup directory. This could be an indicator of persistence.
windows · file_event
Startup/Logon Script Added to Group Policy Object
mediumDetects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
windows
Successful Authentications From Countries You Do Not Operate Out Of
mediumDetect successful authentications from countries you do not operate out of.
azure
Successful IIS Shortname Fuzzing Scan
mediumWhen IIS uses an old .Net Framework it's possible to enumerate folders with the symbol "~"
webserver
Suspicious Access to Sensitive File Extensions
mediumDetects known sensitive file extensions accessed on a network share
windows
Suspicious Access to Sensitive File Extensions - Zeek
mediumDetects known sensitive file extensions via Zeek
zeek
Suspicious Appended Extension
mediumDetects file renames where the target filename uses an uncommon double extension. Could indicate potential ransomware activity renaming files and adding a custom extension to the encrypted files, such as ".jpg.crypted", ".docx.locky", etc.
windows · file_rename
Suspicious Application Installed
mediumDetects suspicious application installed by looking at the added shortcut to the app resolver cache
windows
Suspicious Base64 Encoded User-Agent
mediumDetects suspicious encoded User-Agent strings, as seen used by some malware.
proxy
Suspicious Browser Child Process - MacOS
mediumDetects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.
macos · process_creation
Suspicious C2 Activities
mediumDetects suspicious activities as declared by Florian Roth in its 'Best Practice Auditd Configuration'. This includes the detection of the following commands; wget, curl, base64, nc, netcat, ncat, ssh, socat, wireshark, rawshark, rdesktop, nmap. These commands match a few techniques from the tactics "Command and Control", including not exhaustively the following; Application Layer Protocol (T1071), Non-Application Layer Protocol (T1095), Data Encoding (T1132)
linux
Suspicious Cabinet File Execution Via Msdt.EXE
mediumDetects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190
windows · process_creation
Suspicious Child Process of SAP NetWeaver
mediumDetects suspicious child processes spawned by SAP NetWeaver that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
windows · process_creation
Suspicious Child Process of SAP NetWeaver - Linux
mediumDetects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
linux · process_creation
Suspicious CodePage Switch Via CHCP
mediumDetects a code page switch in command line or batch scripts to a rare language
windows · process_creation
Suspicious Commands Linux
mediumDetects relevant commands often related to malware or hacking activity
linux
Suspicious Computer Machine Password by PowerShell
mediumThe Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain. You can use it to reset the password of the local computer.
windows · ps_module
Suspicious Copy From or To System Directory
mediumDetects a suspicious copy operation that tries to copy a program from system (System32, SysWOW64, WinSxS) directories to another on disk. Often used to move LOLBINs such as 'certutil' or 'desktopimgdownldr' to a different location with a different name in order to bypass detections based on locations.
windows · process_creation
Suspicious Creation of .library-ms File — Potential CVE-2025-24054 Exploit
mediumDetects creation of '.library-ms' files, which may indicate exploitation of CVE-2025-24054. This vulnerability allows an attacker to trigger an automatic outbound SMB or WebDAV authentication request to a remote server upon archive extraction. If the system is unpatched, no user interaction is required beyond extracting a malicious archive—potentially exposing the user's NTLMv2-SSP hash to the attacker.
windows · file_event
Suspicious Creation TXT File in User Desktop
mediumDetects creation of .txt files in user desktop folders via cmd.exe. This behavior may indicate ransomware deploying ransom notes, but can also occur during legitimate administrative tasks. Analysts should investigate for suspicious filenames (e.g., "RANSOM", "DECRYPT", "READ_ME"), bulk file creation patterns, or concurrent encryption activity to determine if this is part of a ransomware attack.
windows · file_event
Suspicious Cross-User Process Spawn
mediumDetects suspicious spawning of a process under a different user context than the parent process. Processes such as notepad.exe, calculator etc. are generally spawned under the same user context and also they are often targeted as sacrificial process or decoy process to check successful privilege escalation.
windows · process_creation
Suspicious CrushFTP Child Process
mediumDetects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities such as CVE-2025-31161, where attackers can achieve RCE through crafted HTTP requests. The detection focuses on commonly abused Windows executables (like powershell.exe, cmd.exe etc.) that attackers typically use post-exploitation to execute malicious commands.
windows · process_creation
Suspicious Csi.exe Usage
mediumCsi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'
windows · process_creation
Suspicious Curl Change User Agents - Linux
mediumDetects a suspicious curl process start on linux with set useragent options
linux · process_creation
Suspicious Curl File Upload - Linux
mediumDetects a suspicious curl process start the adds a file to a web request
linux · process_creation
Suspicious Diantz Alternate Data Stream Execution
mediumCompress target file into a cab file stored in the Alternate Data Stream (ADS) of the target file.
windows · process_creation
Suspicious Diantz Download and Compress Into a CAB File
mediumDownload and compress a remote file and store it in a cab file on local machine.
windows · process_creation
Suspicious Digital Signature Of AppX Package
mediumDetects execution of AppX packages with known suspicious or malicious signature
windows
Suspicious DNS Query for IP Lookup Service APIs
mediumDetects DNS queries for IP lookup services such as "api.ipify.org" originating from a non browser process.
windows · dns_query
Suspicious DNS Query with B64 Encoded String
mediumDetects suspicious DNS queries using base64 encoding
dns
Suspicious DNS Z Flag Bit Set
mediumThe DNS Z flag is bit within the DNS protocol header that is, per the IETF design, meant to be used reserved (unused). Although recently it has been used in DNSSec, the value being set to anything other than 0 should be rare. Otherwise if it is set to non 0 and DNSSec is being used, then excluding the legitimate domains is low effort and high reward. Determine if multiple of these files were accessed in a short period of time to further enhance the possibility of seeing if this was a one off or the possibility of larger sensitive file gathering. This Sigma query is designed to accompany the Corelight Threat Hunting Guide, which can be found here: https://www3.corelight.com/corelights-introductory-guide-to-threat-hunting-with-zeek-bro-logs'
zeek
Suspicious Download Via Certutil.EXE
mediumDetects the execution of certutil with certain flags that allow the utility to download files.
windows · process_creation
Suspicious Driver Install by pnputil.exe
mediumDetects when a possible suspicious driver is being installed via pnputil.exe lolbin
windows · process_creation
Suspicious Electron Application Child Processes
mediumDetects suspicious child processes of electron apps (teams, discord, slack, etc.). This could be a potential sign of ".asar" file tampering (See reference section for more information) or binary execution proxy through specific CLI arguments (see related rule)
windows · process_creation
Suspicious Email Delivered In Microsoft 365
mediumDetects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.
m365
Suspicious Eventlog Clear
mediumDetects usage of known powershell cmdlets such as "Clear-EventLog" to clear the Windows event logs
windows · ps_script
Suspicious Execution of InstallUtil Without Log
mediumUses the .NET InstallUtil.exe application in order to execute image without log
windows · process_creation
Suspicious Execution of Powershell with Base64
mediumCommandline to launch powershell with a base64 payload
windows · process_creation
Suspicious Execution of Shutdown
mediumUse of the commandline to shutdown or reboot windows
windows · process_creation
Suspicious Execution of Shutdown to Log Out
mediumDetects the rare use of the command line tool shutdown to logoff a user
windows · process_creation
Suspicious Execution via macOS Script Editor
mediumDetects when the macOS Script Editor utility spawns an unusual child process.
macos · process_creation
Suspicious Extrac32 Alternate Data Stream Execution
mediumExtract data from cab file and hide it in an alternate data stream
windows · process_creation
Suspicious Extrac32 Execution
mediumDownload or Copy file with Extrac32
windows · process_creation
Suspicious File Characteristics Due to Missing Fields
mediumDetects Executables in the Downloads folder without FileVersion,Description,Product,Company likely created with py2exe
windows · process_creation
Suspicious File Created In PerfLogs
mediumDetects suspicious file based on their extension being created in "C:\PerfLogs\". Note that this directory mostly contains ".etl" files
windows · file_event
Suspicious File Drop by Exchange
mediumDetects suspicious file type dropped by an Exchange component in IIS
windows · file_event
Suspicious File Write to Webapps Root Directory
mediumDetects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers. This may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.
windows · file_event
Suspicious Files in Default GPO Folder
mediumDetects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder
windows · file_event
Suspicious FromBase64String Usage On Gzip Archive - Process Creation
mediumDetects attempts of decoding a base64 Gzip archive via PowerShell. This technique is often used as a method to load malicious content into memory afterward.
windows · process_creation
Suspicious FromBase64String Usage On Gzip Archive - Ps Script
mediumDetects attempts of decoding a base64 Gzip archive in a PowerShell script. This technique is often used as a method to load malicious content into memory afterward.
windows · ps_script
Suspicious Get-ADReplAccount
mediumThe DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
windows · ps_script
Suspicious GetTypeFromCLSID ShellExecute
mediumDetects suspicious Powershell code that execute COM Objects
windows · ps_script
Suspicious Git Clone
mediumDetects execution of "git" in order to clone a remote repository that contain suspicious keywords which might be suspicious
windows · process_creation
Suspicious Git Clone - Linux
mediumDetects execution of "git" in order to clone a remote repository that contain suspicious keywords which might be suspicious
linux · process_creation
Suspicious Group And Account Reconnaissance Activity Using Net.EXE
mediumDetects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)
windows · process_creation
Suspicious History File Operations
mediumDetects commandline operations on shell history files
macos · process_creation
Suspicious History File Operations - Linux
mediumDetects commandline operations on shell history files
linux
Suspicious Hyper-V Cmdlets
mediumAdversaries may carry out malicious operations using a virtual instance to avoid detection
windows · ps_script
Suspicious IIS URL GlobalRules Rewrite Via AppCmd
mediumDetects usage of "appcmd" to create new global URL rewrite rules. This behaviour has been observed being used by threat actors to add new rules so they can access their webshells.
windows · process_creation
Suspicious Installer Package Child Process
mediumDetects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters
macos · process_creation
Suspicious Invoke-Item From Mount-DiskImage
mediumAdversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
windows · ps_script
Suspicious Invoke-WebRequest Execution With DirectIP
mediumDetects calls to PowerShell with Invoke-WebRequest cmdlet using direct IP access
windows · process_creation
Suspicious IO.FileStream
mediumOpen a handle on the drive volume via the \\.\ DOS device path specifier and perform direct access read of the first few bytes of the volume.
windows · ps_script
Suspicious Kerberos RC4 Ticket Encryption
mediumDetects service ticket requests using RC4 encryption type
windows
Suspicious Keyboard Layout Load
mediumDetects the keyboard preload installation with a suspicious keyboard layout, e.g. Chinese, Iranian or Vietnamese layout load in user session on systems maintained by US staff only
windows · registry_set
Suspicious LNK Double Extension File Created
mediumDetects the creation of files with an "LNK" as a second extension. This is sometimes used by malware as a method to abuse the fact that Windows hides the "LNK" extension by default.
windows · file_event
Suspicious Log Entries
mediumDetects suspicious log entries in Linux log files
linux
Suspicious Login Activity Classified By Google
mediumDetects Google Workspace login activity that's classified as suspicious by Google.
gcp
Suspicious Machine Account Replication - DcSync Indicator
mediumDetects suspicious Active Directory Replication Service (ADRS) requests originating from a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller. Under normal operation, only Domain Controllers initiate replication requests carrying the DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account credentials — for example by abusing certificate-based authentication (PKINIT) to impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost), where a temporary machine account is created to request a DC certificate and then used to perform DCSync — they can dump all domain credential material including the krbtgt hash.
windows
Suspicious MacOS Firmware Activity
mediumDetects when a user manipulates with Firmward Password on MacOS. NOTE - this command has been disabled on silicon-based apple computers.
macos · process_creation
Suspicious Msbuild Execution By Uncommon Parent Process
mediumDetects suspicious execution of 'Msbuild.exe' by a uncommon parent process
windows · process_creation
Suspicious MsiExec Embedding Parent
mediumAdversaries may abuse msiexec.exe to proxy the execution of malicious payloads
windows · process_creation
Suspicious Msiexec Execute Arbitrary DLL
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows · process_creation
Suspicious Msiexec Quiet Install From Remote Location
mediumDetects usage of Msiexec.exe to install packages hosted remotely quietly
windows · process_creation
Suspicious Network Connection to IP Lookup Service APIs
mediumDetects external IP address lookups by non-browser processes via services such as "api.ipify.org". This could be indicative of potential post compromise internet test activity.
windows · network_connection
Suspicious New Instance Of An Office COM Object
mediumDetects an svchost process spawning an instance of an office application. This happens when the initial word application creates an instance of one of the Office COM objects such as 'Word.Application', 'Excel.Application', etc. This can be used by malicious actors to create malicious Office documents with macros on the fly. (See vba2clr project in the references)
windows · process_creation
Suspicious New-PSDrive to Admin Share
mediumAdversaries may use to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
windows · ps_script
Suspicious Non PowerShell WSMAN COM Provider
mediumDetects suspicious use of the WSMAN provider without PowerShell.exe as the host application.
windows
Suspicious Non-Browser Network Communication With Google API
mediumDetects a non-browser process interacting with the Google API which could indicate the use of a covert C2 such as Google Sheet C2 (GC2-sheet)
windows · network_connection
Suspicious Non-Browser Network Communication With Telegram API
mediumDetects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2
windows · network_connection
Suspicious OAuth App File Download Activities
mediumDetects when a Microsoft Cloud App Security reported when an app downloads multiple files from Microsoft SharePoint or Microsoft OneDrive in a manner that is unusual for the user.
m365
Suspicious OpenSSH Daemon Error
mediumDetects suspicious SSH / SSHD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
linux
Suspicious Outbound SMTP Connections
mediumAdversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
windows · network_connection
Suspicious Package Installed - Linux
mediumDetects installation of suspicious packages using system installation utilities
linux · process_creation
Suspicious Powercfg Execution To Change Lock Screen Timeout
mediumDetects suspicious execution of 'Powercfg.exe' to change lock screen timeout
windows · process_creation
Suspicious PowerShell Download - PoshModule
mediumDetects suspicious PowerShell download command
windows · ps_module
Suspicious PowerShell Download - Powershell Script
mediumDetects suspicious PowerShell download command
windows · ps_script
Suspicious PowerShell In Registry Run Keys
mediumDetects potential PowerShell commands or code within registry run keys
windows · registry_set
Suspicious PowerShell Invocation From Script Engines
mediumDetects suspicious powershell invocations from interpreters or unusual programs
windows · process_creation
Suspicious PowerShell Invocations - Specific - ProcessCreation
mediumDetects suspicious PowerShell invocation command parameters
windows · process_creation
Suspicious PowerShell WindowStyle Option
mediumAdversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden
windows · ps_script
Suspicious Process Start Locations
mediumDetects suspicious process run from unusual locations
windows · process_creation
Suspicious PROCEXP152.sys File Created In TMP
mediumDetects the creation of the PROCEXP152.sys file in the application-data local temporary folder. This driver is used by Sysinternals Process Explorer but also by KDU (https://github.com/hfiref0x/KDU) or Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU.
windows · file_event
Suspicious RASdial Activity
mediumDetects suspicious process related to rasdial.exe
windows · process_creation
Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet
mediumDetects suspicious reconnaissance command line activity on Windows systems using the PowerShell Get-LocalGroupMember Cmdlet
windows · process_creation
Suspicious Recursive Takeown
mediumAdversaries can interact with the DACLs using built-in Windows commands takeown which can grant adversaries higher permissions on specific files and folders
windows · process_creation
Suspicious Rejected SMB Guest Logon From IP
mediumDetect Attempt PrintNightmare (CVE-2021-1675) Remote code execution in Windows Spooler Service
windows
Suspicious Remote Logon with Explicit Credentials
mediumDetects suspicious processes logging on with explicit credentials
windows
Suspicious RunAs-Like Flag Combination
mediumDetects suspicious command line flags that let the user set a target user and command as e.g. seen in PsExec-like tools
windows · process_creation
Suspicious Rundll32 Setupapi.dll Activity
mediumsetupapi.dll library provide InstallHinfSection function for processing INF files. INF file may contain instructions allowing to create values in the registry, modify files and install drivers. This technique could be used to obtain persistence via modifying one of Run or RunOnce registry keys, run process or use other DLLs chain calls (see references) InstallHinfSection function in setupapi.dll calls runonce.exe executable regardless of actual content of INF file.
windows · process_creation
Suspicious Runscripthelper.exe
mediumDetects execution of powershell scripts via Runscripthelper.exe
windows · process_creation
Suspicious Scan Loop Network
mediumAdversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system
windows · process_creation
Suspicious Scheduled Task Creation via Masqueraded XML File
mediumDetects the creation of a scheduled task using the "-XML" flag with a file without the '.xml' extension. This behavior could be indicative of potential defense evasion attempt during persistence
windows · process_creation
Suspicious Scheduled Task Name As GUID
mediumDetects creation of a scheduled task with a GUID like name
windows · process_creation
Suspicious Schtasks Schedule Type With High Privileges
mediumDetects scheduled task creations or modification to be run with high privileges on a suspicious schedule type
windows · process_creation
Suspicious ScreenSave Change by Reg.exe
mediumAdversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension
windows · process_creation
Suspicious Screensaver Binary File Creation
mediumAdversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension
windows · file_event
Suspicious Service Installed
mediumDetects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders. Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)
windows · registry_set
Suspicious Set Value of MSDT in Registry (CVE-2022-30190)
mediumDetects set value ms-msdt MSProtocol URI scheme in Registry that could be an attempt to exploit CVE-2022-30190.
windows · registry_set
Suspicious Shell Open Command Registry Modification
mediumDetects modifications to shell open registry keys that point to suspicious locations typically used by malware for persistence. Generally, modifications to the `*\shell\open\command` registry key can indicate an attempt to change the default action for opening files, and various UAC bypass or persistence techniques involve modifying these keys to execute malicious scripts or binaries.
windows · registry_set
Suspicious SQL Query
mediumDetects suspicious SQL query keywrods that are often used during recon, exfiltration or destructive activities. Such as dropping tables and selecting wildcard fields
database
Suspicious Start-Process PassThru
mediumPowershell use PassThru option to start in background
windows · ps_script
Suspicious SysAidServer Child
mediumDetects suspicious child processes of SysAidServer (as seen in MERCURY threat actor intrusions)
windows · process_creation
Suspicious SYSVOL Domain Group Policy Access
mediumDetects Access to Domain Group Policies stored in SYSVOL
windows · process_creation
Suspicious TCP Tunnel Via PowerShell Script
mediumDetects powershell scripts that creates sockets/listeners which could be indicative of tunneling activity
windows · ps_script
Suspicious Unblock-File
mediumRemove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.
windows · ps_script
Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe to perform different actions such as restoring snapshots...etc.
windows · process_creation
Suspicious Usage of For Loop with Recursive Directory Search in CMD
mediumDetects suspicious usage of the cmd.exe 'for /f' loop combined with the 'tokens=' parameter and a recursive directory listing. This pattern may indicate an attempt to discover and execute system binaries dynamically, for example powershell, a technique sometimes used by attackers to evade detection. This behavior has been observed in various malicious lnk files.
windows · process_creation
Suspicious Use of /dev/tcp
mediumDetects suspicious command with /dev/tcp
linux
Suspicious Use of PsLogList
mediumDetects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
windows · process_creation
Suspicious User-Agents Related To Recon Tools
mediumDetects known suspicious (default) user-agents related to scanning/recon tools
webserver
Suspicious Userinit Child Process
mediumDetects a suspicious child process of userinit
windows · process_creation
Suspicious VBoxDrvInst.exe Parameters
mediumDetect VBoxDrvInst.exe run with parameters allowing processing INF file. This allows to create values in the registry and install drivers. For example one could use this technique to obtain persistence via modifying one of Run or RunOnce registry keys
windows · process_creation
Suspicious VSFTPD Error Messages
mediumDetects suspicious VSFTPD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts
linux
Suspicious Vsls-Agent Command With AgentExtensionPath Load
mediumDetects Microsoft Visual Studio vsls-agent.exe lolbin execution with a suspicious library load using the --agentExtensionPath parameter
windows · process_creation
Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
mediumDetects the usage of "reg.exe" to add Defender folder exclusions. Qbot has been seen using this technique to add exclusions for folders within AppData and ProgramData.
windows · process_creation
Suspicious WindowsTerminal Child Processes
mediumDetects suspicious children spawned via the Windows Terminal application which could be a sign of persistence via WindowsTerminal (see references section)
windows · process_creation
Suspicious Wordpad Outbound Connections
mediumDetects a network connection initiated by "wordpad.exe" over uncommon destination ports. This might indicate potential process injection activity from a beacon or similar mechanisms.
windows · network_connection
Suspicious Workstation Locking via Rundll32
mediumDetects a suspicious call to the user32.dll function that locks the user workstation
windows · process_creation
Suspicious WSMAN Provider Image Loads
mediumDetects signs of potential use of the WSMAN provider from uncommon processes locally and remote execution.
windows · image_load
Suspicious X509Enrollment - Process Creation
mediumDetect use of X509Enrollment
windows · process_creation
Suspicious X509Enrollment - Ps Script
mediumDetect use of X509Enrollment
windows · ps_script
Suspicious XOR Encoded PowerShell Command
mediumDetects presence of a potentially xor encoded powershell command
windows · process_creation
Suspicious ZipExec Execution
mediumZipExec is a Proof-of-Concept (POC) tool to wrap binary-based tools into a password-protected zip file.
windows · process_creation
SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
mediumDetects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.
windows · ps_module
SyncAppvPublishingServer Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.exe.
windows · process_creation
SyncAppvPublishingServer Execution to Bypass Powershell Restriction
mediumDetects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.
windows · ps_script
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.vbs
windows · process_creation
Sysinternals PsService Execution
mediumDetects usage of Sysinternals PsService which can be abused for service reconnaissance and tampering
windows · process_creation
Sysinternals PsSuspend Execution
mediumDetects usage of Sysinternals PsSuspend which can be abused to suspend critical processes
windows · process_creation
Sysmon Configuration Change
mediumDetects a Sysmon configuration change, which could be the result of a legitimate reconfiguration or someone trying manipulate the configuration
windows
Sysmon Configuration Update
mediumDetects updates to Sysmon's configuration. Attackers might update or replace the Sysmon configuration with a bare bone one to avoid monitoring without shutting down the service completely
windows · process_creation
Sysmon File Executable Creation Detected
mediumTriggers on any Sysmon "FileExecutableDetected" event, which triggers every time a PE that is monitored by the config is created.
windows
Sysprep on AppData Folder
mediumDetects suspicious sysprep process start with AppData folder as target (as used by Trojan Syndicasec in Thrip report by Symantec)
windows · process_creation
System Disk And Volume Reconnaissance Via Wmic.EXE
mediumAn adversary might use WMI to discover information about the system, such as the volume name, size, free space, and other disk information. This can be done using the 'wmic' command-line utility and has been observed being used by threat actors such as Volt Typhoon.
windows · process_creation
System Information Discovery Using Ioreg
mediumDetects the use of "ioreg" which will show I/O Kit registry information. This process is used for system information discovery. It has been observed in-the-wild by calling this process directly or using bash and grep to look for specific strings.
macos · process_creation
System Information Discovery Using sw_vers
mediumDetects the use of "sw_vers" for system information discovery
macos · process_creation
System Information Discovery Using System_Profiler
mediumDetects the execution of "system_profiler" with specific "Data Types" that have been seen being used by threat actors and malware. It provides system hardware and software configuration information. This process is primarily used for system information discovery. However, "system_profiler" can also be used to determine if virtualization software is being run for defense evasion purposes.
macos · process_creation
System Information Discovery Via Sysctl - MacOS
mediumDetects the execution of "sysctl" with specific arguments that have been used by threat actors and malware. It provides system hardware information. This process is primarily used to detect and avoid virtualization and analysis environments.
macos · process_creation
System Integrity Protection (SIP) Disabled
mediumDetects the use of csrutil to disable the Configure System Integrity Protection (SIP). This technique is used in post-exploit scenarios.
macos · process_creation
System Language Discovery via Reg.Exe
mediumDetects the usage of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.
windows · process_creation
System Scripts Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Systemd Service Creation
mediumDetects a creation of systemd services which could be used by adversaries to execute malicious code.
linux
TacticalRMM Service Installation
mediumDetects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.
windows
TanStack Supply-Chain Attack DNS Indicators
mediumDetects DNS queries to attacker-controlled infrastructure used by the Mini Shai-Hulud campaign targeting TanStack npm packages along with other packages such as mistralai, uipath and so on. The domain git-tanstack.com (registered May 9, 2026) hosted secondary payloads including transformers.pyz. The filev2.getsession.org endpoint was used for credential exfiltration via the Session protocol.
windows · dns_query
TanStack Supply-Chain Attack File Creation Indicators - Linux
mediumDetects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026.
linux · file_event
TanStack Supply-Chain Attack File Creation Indicators - Windows
mediumDetects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath, etc reported on early May 2026.
windows · file_event
Tap Driver Installation
mediumWell-known TAP software installation. Possible preparation for data exfiltration using tunnelling techniques
windows
Tap Installer Execution
mediumWell-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques
windows · process_creation
TeamViewer Domain Query By Non-TeamViewer Application
mediumDetects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
windows · dns_query
TeamViewer Remote Session
mediumDetects the creation of log files during a TeamViewer remote session
windows · file_event
Telegram API Access
mediumDetects suspicious requests to Telegram API without the usual Telegram User-Agent
proxy
Telegram Bot API Request
mediumDetects suspicious DNS queries to api.telegram.org used by Telegram Bots of any kind
dns
Terminate Linux Process Via Kill
mediumDetects usage of command line tools such as "kill", "pkill" or "killall" to terminate or signal a running process.
linux · process_creation
Testing Usage of Uncommonly Used Port
mediumAdversaries may communicate using a protocol and port paring that are typically not associated. For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443.
windows · ps_script
Third Party Software DLL Sideloading
mediumDetects DLL sideloading of DLLs that are part of third party software (zoom, discord....etc)
windows · image_load
Time Machine Backup Deletion Attempt Via Tmutil - MacOS
mediumDetects deletion attempts of MacOS Time Machine backups via the native backup utility "tmutil". An adversary may perform this action before launching a ransonware attack to prevent the victim from restoring their files.
macos · process_creation
Time Machine Backup Disabled Via Tmutil - MacOS
mediumDetects disabling of Time Machine (Apple's automated backup utility software) via the native macOS backup utility "tmutil". An attacker can use this to prevent backups from occurring.
macos · process_creation
Tomcat WebServer Logs Deleted
mediumDetects the deletion of tomcat WebServer logs which may indicate an attempt to destroy forensic evidence
windows · file_delete
Touch Suspicious Service File
mediumDetects usage of the "touch" process in service file.
linux · process_creation
Transferring Files with Credential Data via Network Shares
mediumTransferring files with well-known filenames (sensitive files with credential data) using network shares
windows
Transferring Files with Credential Data via Network Shares - Zeek
mediumTransferring files with well-known filenames (sensitive files with credential data) using network shares
zeek
Troubleshooting Pack Cmdlet Execution
mediumDetects execution of "TroubleshootingPack" cmdlets to leverage CVE-2022-30190 or action similar to "msdt" lolbin (as described in LOLBAS)
windows · ps_script
Tunneling Tool Execution
mediumDetects the execution of well known tools that can be abused for data exfiltration and tunneling.
windows · process_creation
UAC Bypass via Windows Firewall Snap-In Hijack
mediumDetects attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in
windows · process_creation
UAC Disabled
mediumDetects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.
windows · registry_set
UAC Notification Disabled
mediumDetects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value. UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users. When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
windows · registry_set
UAC Secure Desktop Prompt Disabled
mediumDetects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value. The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts. When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
windows · registry_set
UFW Disable Attempt
mediumDetects attempts to disable the Uncomplicated Firewall (UFW) on Linux systems. UFW is a popular firewall management tool that provides an easy-to-use interface for configuring firewall rules. Disabling UFW can leave a system vulnerable to attacks, as it may allow unauthorized access to network services and resources.
linux · process_creation
Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
mediumDetects the start of a non built-in assistive technology applications via "Atbroker.EXE".
windows · process_creation
Uncommon AddinUtil.EXE CommandLine Execution
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) with uncommon Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.
windows · process_creation
Uncommon Child Process Of AddinUtil.EXE
mediumDetects uncommon child processes of the Add-In deployment cache updating utility (AddInutil.exe) which could be a sign of potential abuse of the binary to proxy execution via a custom Addins.Store payload.
windows · process_creation
Uncommon Child Process Of Appvlp.EXE
mediumDetects uncommon child processes of Appvlp.EXE Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands. Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder or to mark a file as a system file.
windows · process_creation
Uncommon Child Process Of BgInfo.EXE
mediumDetects uncommon child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
windows · process_creation
Uncommon Child Process Of Conhost.EXE
mediumDetects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.
windows · process_creation
Uncommon Child Process Of Defaultpack.EXE
mediumDetects uncommon child processes of "DefaultPack.EXE" binary as a proxy to launch other programs
windows · process_creation
Uncommon Child Process Spawned By Odbcconf.EXE
mediumDetects an uncommon child process of "odbcconf.exe" binary which normally shouldn't have any child processes.
windows · process_creation
Uncommon Child Processes Of SndVol.exe
mediumDetects potentially uncommon child processes of SndVol.exe (the Windows volume mixer)
windows · process_creation
Uncommon Connection to Active Directory Web Services
mediumDetects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.
windows · network_connection
Uncommon Extension Shim Database Installation Via Sdbinst.EXE
mediumDetects installation of a potentially suspicious new shim with an uncommon extension using sdbinst.exe. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims
windows · process_creation
Uncommon GrantedAccess Flags On LSASS
mediumDetects process access to LSASS memory with uncommon access flags 0x410 and 0x01410
windows · process_access
Uncommon Link.EXE Parent Process
mediumDetects an uncommon parent process of "LINK.EXE". Link.EXE in Microsoft incremental linker. Its a utility usually bundled with Visual Studio installation. Multiple utilities often found in the same folder (editbin.exe, dumpbin.exe, lib.exe, etc) have a hardcode call to the "LINK.EXE" binary without checking its validity. This would allow an attacker to sideload any binary with the name "link.exe" if one of the aforementioned tools get executed from a different location. By filtering the known locations of such utilities we can spot uncommon parent process of LINK.EXE that might be suspicious or malicious.
windows · process_creation
Uncommon New Firewall Rule Added In Windows Firewall Exception List
mediumDetects when a rule has been added to the Windows Firewall exception list
windows
Uncommon Outbound Kerberos Connection
mediumDetects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.
windows · network_connection
Uncommon Outbound Kerberos Connection - Security
mediumDetects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.
windows
Uncommon PowerShell Hosts
mediumDetects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
windows · ps_classic_start
Uncommon Service Installation Image Path
mediumDetects uncommon service installation commands by looking at suspicious or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.
windows
Uncommon Sigverif.EXE Child Process
mediumDetects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.
windows · process_creation
Uncommon Svchost Parent Process
mediumDetects an uncommon svchost parent process
windows · process_creation
Uncommon System Information Discovery Via Wmic.EXE
mediumDetects the use of the WMI command-line (WMIC) utility to identify and display various system information, including OS, CPU, GPU, and disk drive names; memory capacity; display resolution; and baseboard, BIOS, and GPU driver products/versions. Some of these commands were used by Aurora Stealer in late 2022/early 2023.
windows · process_creation
Unix Shell Configuration Modification
mediumDetect unix shell configuration modification. Adversaries may establish persistence through executing malicious commands triggered when a new shell is opened.
linux
Unsigned .node File Loaded
mediumDetects the loading of unsigned .node files. Adversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack. .node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code. This technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.
windows · image_load
Unsigned AppX Installation Attempt Using Add-AppxPackage
mediumDetects usage of the "Add-AppxPackage" or it's alias "Add-AppPackage" to install unsigned AppX packages
windows · process_creation
Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript
mediumDetects usage of the "Add-AppxPackage" or it's alias "Add-AppPackage" to install unsigned AppX packages
windows · ps_script
Unsigned DLL Loaded by Windows Utility
mediumDetects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
windows · image_load
Unsigned Image Loaded Into LSASS Process
mediumLoading unsigned image (DLL, EXE) into LSASS process
windows · image_load
Unsigned Module Loaded by ClickOnce Application
mediumDetects unsigned module load by ClickOnce application.
windows · image_load
Unsigned or Unencrypted SMB Connection to Share Established
mediumDetects SMB server connections to shares without signing or encryption enabled. This could indicate potential lateral movement activity using unsecured SMB shares.
windows
Unusual File Download From File Sharing Websites - File Stream
mediumDetects the download of suspicious file type from a well-known file and paste sharing domain
windows · create_stream_hash
Unusual Parent Process For Cmd.EXE
mediumDetects suspicious parent process for cmd.exe
windows · process_creation
Usage Of Web Request Commands And Cmdlets
mediumDetects the use of various web request commands with commandline tools and Windows PowerShell cmdlets (including aliases) via CommandLine
windows · process_creation
Usage Of Web Request Commands And Cmdlets - ScriptBlock
mediumDetects the use of various web request commands with commandline tools and Windows PowerShell cmdlets (including aliases) via PowerShell scriptblock logs
windows · ps_script
Use Icacls to Hide File to Everyone
mediumDetect use of icacls to deny access for everyone in Users folder sometimes used to hide malicious files
windows · process_creation
Use NTFS Short Name in Command Line
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid command-line detection
windows · process_creation
Use NTFS Short Name in Image
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid Image based detection
windows · process_creation
Use of FSharp Interpreters
mediumDetects the execution of FSharp Interpreters "FsiAnyCpu.exe" and "FSi.exe" Both can be used for AWL bypass and to execute F# code via scripts or inline.
windows · process_creation
Use of OpenConsole
mediumDetects usage of OpenConsole binary as a LOLBIN to launch other binaries to bypass application Whitelisting
windows · process_creation
Use of Pcalua For Execution
mediumDetects execition of commands and binaries from the context of The program compatibility assistant (Pcalua.exe). This can be used as a LOLBIN in order to bypass application whitelisting.
windows · process_creation
Use of Remote.exe
mediumRemote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.
windows · process_creation
Use of Scriptrunner.exe
mediumThe "ScriptRunner.exe" binary can be abused to proxy execution through it and bypass possible whitelisting
windows · process_creation
Use Of The SFTP.EXE Binary As A LOLBIN
mediumDetects the usage of the "sftp.exe" binary as a LOLBIN by abusing the "-D" flag
windows · process_creation
Use of TTDInject.exe
mediumDetects the executiob of TTDInject.exe, which is used by Windows 10 v1809 and newer to debug time travel (underlying call of tttracer.exe)
windows · process_creation
Use of UltraVNC Remote Access Software
mediumAn adversary may use legitimate desktop support and remote access software,to establish an interactive command and control channel to target systems within networks
windows · process_creation
Use of VisualUiaVerifyNative.exe
mediumVisualUiaVerifyNative.exe is a Windows SDK that can be used for AWL bypass and is listed in Microsoft's recommended block rules.
windows · process_creation
Use of VSIISExeLauncher.exe
mediumThe "VSIISExeLauncher.exe" binary part of the Visual Studio/VS Code can be used to execute arbitrary binaries
windows · process_creation
Use of Wfc.exe
mediumThe Workflow Command-line Compiler can be used for AWL bypass and is listed in Microsoft's recommended block rules.
windows · process_creation
Use Short Name Path in Command Line
mediumDetects the use of short name paths (8.3 format) in command lines, which can be used to obfuscate paths or access restricted locations. Windows creates short 8.3 filenames (like PROGRA~1) for compatibility with MS-DOS-based or 16-bit Windows programs. When investigating, examine: - Commands using short paths to access sensitive directories or files - Web servers on Windows (especially Apache) where short filenames could bypass security controls - Correlation with other suspicious behaviors - baseline of short name usage in your environment and look for deviations
windows · process_creation
Use Short Name Path in Image
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid Image detection
windows · process_creation
User Access Blocked by Azure Conditional Access
mediumDetect access has been blocked by Conditional Access policies. The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.
azure
User Added To Admin Group Via Dscl
mediumDetects attempts to create and add an account to the admin group via "dscl"
macos · process_creation
User Added To Admin Group Via DseditGroup
mediumDetects attempts to create and/or add an account to the admin group, thus granting admin privileges.
macos · process_creation
User Added To Admin Group Via Sysadminctl
mediumDetects attempts to create and add an account to the admin group via "sysadminctl"
macos · process_creation
User Added to an Administrator's Azure AD Role
mediumUser Added to an Administrator's Azure AD Role
azure
User Added To Group With CA Policy Modification Access
mediumMonitor and alert on group membership additions of groups that have CA policy modification access
azure
User Added to Local Administrator Group
mediumDetects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity
windows
User Added to Local Administrators Group
mediumDetects addition of users to the local administrator group via "Net" or "Add-LocalGroupMember".
windows · process_creation
User Added To Root/Sudoers Group Using Usermod
mediumDetects usage of the "usermod" binary to add users add users to the root or suoders groups
linux · process_creation
User Discovery And Export Via Get-ADUser Cmdlet
mediumDetects usage of the Get-ADUser cmdlet to collect user information and output it to a file
windows · process_creation
User Discovery And Export Via Get-ADUser Cmdlet - PowerShell
mediumDetects usage of the Get-ADUser cmdlet to collect user information and output it to a file
windows · ps_script
User Has Been Deleted Via Userdel
mediumDetects execution of the "userdel" binary. Which is used to delete a user account and related files. This is sometimes abused by threat actors in order to cover their tracks
linux · process_creation
User Removed From Group With CA Policy Modification Access
mediumMonitor and alert on group membership removal of groups that have CA policy modification access
azure
User State Changed From Guest To Member
mediumDetects the change of user type from "Guest" to "Member" for potential elevation of privilege.
azure
Users Authenticating To Other Azure AD Tenants
mediumDetect when users in your Azure AD tenant are authenticating to other Azure AD Tenants.
azure
UtilityFunctions.ps1 Proxy Dll
mediumDetects the use of a Microsoft signed script executing a managed DLL with PowerShell.
windows · process_creation
Veeam Backup Database Suspicious Query
mediumDetects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
windows · process_creation
Verclsid.exe Runs COM Object
mediumDetects when verclsid.exe is used to run COM object via GUID
windows · process_creation
VHD Image Download Via Browser
mediumDetects creation of ".vhd"/".vhdx" files by browser processes. Malware can use mountable Virtual Hard Disk ".vhd" files to encapsulate payloads and evade security controls.
windows · file_event
Visual Studio Code Tunnel Execution
mediumDetects Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows · process_creation
Visual Studio Code Tunnel Remote File Creation
mediumDetects the creation of file by the "node.exe" process in the ".vscode-server" directory. Could be a sign of remote file creation via VsCode tunnel feature
windows · file_event
Visual Studio Code Tunnel Service Installation
mediumDetects the installation of VsCode tunnel (code-tunnel) as a service.
windows · process_creation
Visual Studio Code Tunnel Shell Execution
mediumDetects the execution of a shell (powershell, bash, wsl...) via Visual Studio Code tunnel. Attackers can abuse this functionality to establish a C2 channel and execute arbitrary commands on the system.
windows · process_creation
Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
mediumDetects child processes of Microsoft.NodejsTools.PressAnyKey.exe that can be used to execute any other binary
windows · process_creation
Visual Studio NodejsTools PressAnyKey Renamed Execution
mediumDetects renamed execution of "Microsoft.NodejsTools.PressAnyKey.exe", which can be abused as a LOLBIN to execute arbitrary binaries
windows · process_creation
VMGuestLib DLL Sideload
mediumDetects DLL sideloading of VMGuestLib.dll by the WmiApSrv service.
windows · image_load
VMMap Signed Dbghelp.DLL Potential Sideloading
mediumDetects potential DLL sideloading of a signed dbghelp.dll by the Sysinternals VMMap.
windows · image_load
VsCode Code Tunnel Execution File Indicator
mediumDetects the creation of a file with the name "code_tunnel.json" which indicate execution and usage of VsCode tunneling utility. Attackers can abuse this functionality to establish a C2 channel
windows · file_event
VsCode Powershell Profile Modification
mediumDetects the creation or modification of a vscode related powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence
windows · file_event
WDAC Policy File Creation In CodeIntegrity Folder
mediumAttackers can craft a custom Windows Defender Application Control (WDAC) policy that blocks Endpoint Detection and Response (EDR) components while allowing their own malicious code. The policy is placed in the privileged Windows Code Integrity folder (C:\Windows\System32\CodeIntegrity\). Upon reboot, the policy prevents EDR drivers from loading, effectively bypassing security measures and may further enable undetected lateral movement within an Active Directory environment.
windows · file_event
Weak or Abused Passwords In CLI
mediumDetects weak passwords or often abused passwords (seen used by threat actors) via the CLI. An example would be a threat actor creating a new user via the net command and providing the password inline
windows · process_creation
WebDav Client Execution Via Rundll32.EXE
mediumDetects "svchost.exe" spawning "rundll32.exe" with command arguments like "C:\windows\system32\davclnt.dll,DavSetCookie". This could be an indicator of exfiltration or use of WebDav to launch code (hosted on a WebDav server).
windows · process_creation
WebDAV Temporary Local File Creation
mediumDetects the creation of WebDAV temporary files with potentially suspicious extensions
windows · file_event
WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze
mediumDetects the loading of dbgcore.dll or dbghelp.dll by WerFaultSecure.exe, which has been observed in EDR-Freeze attacks to suspend processes and evade detection. However, this behavior has also been observed during normal software installations, so further investigation is required to confirm malicious activity. When threat hunting, look for this activity in conjunction with other suspicious processes starting, network connections, or file modifications that occur shortly after the DLL load. Pay special attention to timing - if other malicious activities occur during or immediately after this library loading, it may indicate EDR evasion attempts. Also correlate with any EDR/AV process suspension events or gaps in security monitoring during the timeframe.
windows · image_load
WFP Filter Added via Registry
mediumDetects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.
windows · registry_set
Wget Creating Files in Tmp Directory
mediumDetects the use of wget to download content in a temporary directory such as "/tmp" or "/var/tmp"
linux · file_event
Whoami.EXE Execution Anomaly
mediumDetects the execution of whoami.exe with suspicious parent processes.
windows · process_creation
Whoami.EXE Execution With Output Option
mediumDetects the execution of "whoami.exe" with the "/FO" flag to choose CSV as output format or with redirection options to export the results to a file for later use.
windows · process_creation
WinAPI Function Calls Via PowerShell Scripts
mediumDetects calls to WinAPI functions from PowerShell scripts. Attackers can often leverage these APIs to avoid detection based on typical PowerShell function calls. Use this rule as a basis to hunt for interesting scripts.
windows · ps_script
WinAPI Library Calls Via PowerShell Scripts
mediumDetects calls to WinAPI libraries from PowerShell scripts. Attackers can often leverage these APIs to avoid detection based on typical PowerShell function calls. Use this rule as a basis to hunt for interesting scripts.
windows · ps_script
Windows Admin Share Mount Via Net.EXE
mediumDetects when an admin share is mounted using net.exe
windows · process_creation
Windows AppX Deployment Full Trust Package Installation
mediumDetects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
windows
Windows AppX Deployment Unsigned Package Installation
mediumDetects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
windows
Windows Backup Deleted Via Wbadmin.EXE
mediumDetects the deletion of backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.
windows · process_creation
Windows Binary Executed From WSL
mediumDetects the execution of Windows binaries from within a WSL instance. This could be used to masquerade parent-child relationships
windows · process_creation
Windows Credential Manager Access via VaultCmd
mediumList credentials currently stored in Windows Credential Manager via the native Windows utility vaultcmd.exe
windows · process_creation
Windows Default Domain GPO Modification
mediumDetects modifications to Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may modify these default GPOs to deploy malicious configurations across the domain.
windows
Windows Default Domain GPO Modification via GPME
mediumDetects the use of the Group Policy Management Editor (GPME) to modify Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may leverage GPME to make stealthy changes in these default GPOs to deploy malicious GPOs configurations across the domain without raising suspicion.
windows · process_creation
Windows Defender Exclusion List Modified
mediumDetects modifications to the Windows Defender exclusion registry key. This could indicate a potentially suspicious or even malicious activity by an attacker trying to add a new exclusion in order to bypass security.
windows
Windows Defender Exclusion Registry Key - Write Access Requested
mediumDetects write access requests to the Windows Defender exclusions registry keys. This could be an indication of an attacker trying to request a handle or access the object to write new exclusions in order to bypass security.
windows
Windows Defender Exclusions Added
mediumDetects the Setting of Windows Defender Exclusions
windows
Windows Defender Exclusions Added - PowerShell
mediumDetects modifications to the Windows Defender configuration settings using PowerShell to add exclusions
windows · ps_script
Windows Defender Exclusions Added - Registry
mediumDetects the Setting of Windows Defender Exclusions
windows · registry_set
Windows Defender Real-Time Protection Failure/Restart
mediumDetects issues with Windows Defender Real-Time Protection features
windows
Windows Defender Threat Detection Service Disabled
mediumDetects when the "Windows Defender Threat Protection" service is disabled.
windows
Windows Firewall Disabled via PowerShell
mediumDetects attempts to disable the Windows Firewall using PowerShell
windows · process_creation
Windows Firewall Profile Disabled
mediumDetects when a user disables the Windows Firewall via a Profile to help evade defense.
windows · ps_script
Windows Hotfix Updates Reconnaissance Via Wmic.EXE
mediumDetects the execution of wmic with the "qfe" flag in order to obtain information about installed hotfix updates on the system. This is often used by pentester and attacker enumeration scripts
windows · process_creation
Windows Kernel Debugger Execution
mediumDetects execution of the Windows Kernel Debugger "kd.exe".
windows · process_creation
Windows Mail App Mailbox Access Via PowerShell Script
mediumDetects PowerShell scripts that try to access the default Windows MailApp MailBox. This indicates manipulation of or access to the stored emails of a user. E.g. this could be used by an attacker to exfiltrate or delete the content of the emails.
windows · ps_script
Windows Network Access Suspicious desktop.ini Action
mediumDetects unusual processes accessing desktop.ini remotely over network share, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
windows
Windows Pcap Drivers
mediumDetects Windows Pcap driver installation based on a list of associated .sys files.
windows
Windows PowerShell User Agent
mediumDetects Windows PowerShell Web Access
proxy
Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by deleting the existing "DisableAIDataAnalysis" registry value. Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows · registry_delete
Windows Recall Feature Enabled - Registry
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by setting the value of "DisableAIDataAnalysis" to "0". Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows · registry_set
Windows Recall Feature Enabled Via Reg.EXE
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by deleting the existing "DisableAIDataAnalysis" value, or setting it to 0. Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows · process_creation
Windows Recovery Environment Disabled Via Reagentc
mediumDetects attempts to disable windows recovery environment using Reagentc. ReAgentc.exe is a command-line tool in Windows used to manage the Windows Recovery Environment (WinRE). It allows users to enable, disable, and configure WinRE, which is used for troubleshooting and repairing common boot issues.
windows · process_creation
Windows Registry Trust Record Modification
mediumAlerts on trust record modification within the registry, indicating usage of macros
windows · registry_event
Windows Screen Capture with CopyFromScreen
mediumAdversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations
windows · ps_script
Windows Terminal Profile Settings Modification By Uncommon Process
mediumDetects the creation or modification of the Windows Terminal Profile settings file "settings.json" by an uncommon process.
windows · file_event
Winlogon AllowMultipleTSSessions Enable
mediumDetects when the 'AllowMultipleTSSessions' value is enabled. Which allows for multiple Remote Desktop connection sessions to be opened at once. This is often used by attacker as a way to connect to an RDP session without disconnecting the other users
windows · registry_set
Winlogon Helper DLL
mediumWinlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete. Registry entries in HKLM\Software[Wow6432Node]Microsoft\Windows NT\CurrentVersion\Winlogon\ and HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ are used to manage additional helper programs and functionalities that support Winlogon. Malicious modifications to these Registry keys may cause Winlogon to load and execute malicious DLLs and/or executables.
windows · ps_script
Winrar Compressing Dump Files
mediumDetects execution of WinRAR in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows · process_creation
WinRAR Execution in Non-Standard Folder
mediumDetects a suspicious WinRAR execution in a folder which is not the default installation folder
windows · process_creation
Winscp Execution From Non Standard Folder
mediumDetects the execution of Winscp from an a non standard folder. This could indicate the execution of Winscp portable.
windows · process_creation
WinSock2 Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
WinSxS Executable File Creation By Non-System Process
mediumDetects the creation of binaries in the WinSxS folder by non-system processes
windows · file_event
Wlrmdr.EXE Uncommon Argument Or Child Process
mediumDetects the execution of "Wlrmdr.exe" with the "-u" command line flag which allows anything passed to it to be an argument of the ShellExecute API, which would allow an attacker to execute arbitrary binaries. This detection also focuses on any uncommon child processes spawned from "Wlrmdr.exe" as a supplement for those that posses "ParentImage" telemetry.
windows · process_creation
WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load
mediumDetects signs of the WMI script host process "scrcons.exe" loading scripting DLLs which could indicates WMI ActiveScriptEventConsumers EventConsumers activity.
windows · image_load
WMI Event Consumer Created Named Pipe
mediumDetects the WMI Event Consumer service scrcons.exe creating a named pipe
windows · pipe_created
WMI Event Subscription
mediumDetects creation of WMI event subscription persistence method
windows · wmi_event
WMI Persistence
mediumDetects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.
windows
WMI Persistence - Script Event Consumer
mediumDetects the execution of a script event consumer. When scrcons.exe launches, it does so in response to the creation of an ActiveScriptEventConsumer instance and will execute registered JScript or VBScript code as a result. Script event consumers are a built-in Windows Management Instrumentation (WMI) class that automatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs. Adversaries often abuse script event consumers to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.
windows · process_creation
WMI Persistence - Security
mediumDetects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.
windows
WMIC Loading Scripting Libraries
mediumDetects threat actors proxy executing code and bypassing application controls by leveraging wmic and the `/FORMAT` argument switch to download and execute an XSL file (i.e js, vbs, etc). It could be an indicator of SquiblyTwo technique, which uses Windows Management Instrumentation (WMI) to execute malicious code.
windows · image_load
WMIC Remote Command Execution
mediumDetects the execution of WMIC to query information on a remote system
windows · process_creation
WMIC Unquoted Services Path Lookup - PowerShell
mediumDetects known WMI recon method to look for unquoted service paths, often used by pentest inside of powershell scripts attackers enum scripts
windows · ps_script
WmiPrvSE Spawned A Process
mediumDetects WmiPrvSE spawning a process
windows · process_creation
WordPress Wp2shell REST Batch Endpoint Exploitation
mediumDetects exploitation attempts against the WordPress REST batch endpoint (CVE-2026-63030, CVE-2026-60137) using the wp2shell PoC tool. The tool sends POST requests to the batch endpoint via the ?rest_route=/batch/v1 query parameter, covering all attack phases from initial probe through SQL injection and pre-auth admin creation. A 207 response confirms the endpoint is active on the target.
webserver
Wow6432Node Classes Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Wow6432Node CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Wow6432Node Windows NT CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Write Protect For Storage Disabled
mediumDetects applications trying to modify the registry in order to disable any write-protect property for storage devices. This could be a precursor to a ransomware attack and has been an observed technique used by cypherpunk group.
windows · process_creation
Writing Local Admin Share
mediumAversaries may use to interact with a remote network share using Server Message Block (SMB). This technique is used by post-exploitation frameworks.
windows · file_event
Writing Of Malicious Files To The Fonts Folder
mediumMonitors for the hiding possible malicious files in the C:\Windows\Fonts\ location. This folder doesn't require admin privillege to be written and executed from.
windows · process_creation
Wscript Shell Run In CommandLine
mediumDetects the presence of the keywords "Wscript", "Shell" and "Run" in the command, which could indicate a suspicious activity
windows · process_creation
WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
mediumDetects script file execution (.js, .jse, .vba, .vbe, .vbs, .wsf, .wsh) by Wscript/Cscript.
windows · process_creation
WSL Child Process Anomaly
mediumDetects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL
windows · process_creation
XBAP Execution From Uncommon Locations Via PresentationHost.EXE
mediumDetects the execution of ".xbap" (Browser Applications) files via PresentationHost.EXE from an uncommon location. These files can be abused to run malicious ".xbap" files any bypass AWL
windows · process_creation
XSL Script Execution Via WMIC.EXE
mediumDetects the execution of WMIC with the "format" flag to potentially load local XSL files. Adversaries abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files.
windows · process_creation
Zimbra Collaboration Suite Email Server Unauthenticated RCE
mediumDetects an attempt to leverage the vulnerable servlet "mboximport" for an unauthenticated remote command injection
webserver
Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_module
Zip A Folder With PowerShell For Staging In Temp - PowerShell
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows
Zip A Folder With PowerShell For Staging In Temp - PowerShell Script
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_script