Log source category
create_remote_thread log source Sigma rules
15 Sigma detection rules in the library use the create_remote_thread log source, mostly on windows. The create_remote_thread category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
HackTool - CACTUSTORCH Remote Thread Creation
highDetects remote thread creation from CACTUSTORCH as described in references.
windows
HackTool - Potential CobaltStrike Process Injection
highDetects a potential remote threat creation with certain characteristics which are typical for Cobalt Strike beacons
windows
Password Dumper Remote Thread in LSASS
highDetects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage. The process in field Process is the malicious program. A single execution can lead to hundreds of events.
windows
Potential Bumblebee Remote Thread Creation
highDetects remote thread injection events based on action seen used by bumblebee
windows
Potential Credential Dumping Attempt Via PowerShell Remote Thread
highDetects remote thread creation by PowerShell processes into "lsass.exe"
windows
Rare Remote Thread Creation By Uncommon Source Image
highDetects uncommon processes creating remote threads.
windows
Remote Thread Created In KeePass.EXE
highDetects remote thread creation in "KeePass.exe" which could indicates potential password dumping activity
windows
Remote Thread Creation In Mstsc.Exe From Suspicious Location
highDetects remote thread creation in the "mstsc.exe" process by a process located in a potentially suspicious location. This technique is often used by attackers in order to hook some APIs used by DLLs loaded by "mstsc.exe" during RDP authentications in order to steal credentials.
windows
Remote Thread Creation Ttdinject.exe Proxy
highDetects a remote thread creation of Ttdinject.exe used as proxy
windows
CreateRemoteThread API and LoadLibrary
mediumDetects potential use of CreateRemoteThread api and LoadLibrary function to inject DLL into a process
windows
Remote Thread Created In Shell Application
mediumDetects remote thread creation in command shell applications, such as "Cmd.EXE" and "PowerShell.EXE". It is a common technique used by malware, such as IcedID, to inject malicious code and execute it within legitimate processes.
windows
Remote Thread Creation By Uncommon Source Image
mediumDetects uncommon processes creating remote threads.
windows
Remote Thread Creation In Uncommon Target Image
mediumDetects uncommon target processes for remote thread creation
windows
Remote Thread Creation Via PowerShell
mediumDetects the creation of a remote thread from a Powershell process to another process
windows
Remote Thread Creation Via PowerShell In Uncommon Target
mediumDetects the creation of a remote thread from a Powershell process in an uncommon target process
windows