Log source category
create_stream_hash log source Sigma rules
9 Sigma detection rules in the library use the create_stream_hash log source, mostly on windows. The create_stream_hash category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
Exports Registry Key To an Alternate Data Stream
highExports the target Registry key and hides it in the specified alternate data stream.
windows
HackTool Named File Stream Created
highDetects the creation of a named file stream with the imphash of a well-known hack tool
windows
Potential Suspicious Winget Package Installation
highDetects potential suspicious winget package installation from a suspicious source.
windows
Potentially Suspicious File Download From ZIP TLD
highDetects the download of a file with a potentially suspicious extension from a .zip top level domain.
windows
Suspicious File Download From File Sharing Websites - File Stream
highDetects the download of suspicious file type from a well-known file and paste sharing domain
windows
Unusual File Download from Direct IP Address
highDetects the download of suspicious file type from URLs with IP
windows
Creation Of a Suspicious ADS File Outside a Browser Download
mediumDetects the creation of a suspicious ADS (Alternate Data Stream) file by software other than browsers
windows
Hidden Executable In NTFS Alternate Data Stream
mediumDetects the creation of an ADS (Alternate Data Stream) that contains an executable by looking at a non-empty Imphash
windows
Unusual File Download From File Sharing Websites - File Stream
mediumDetects the download of suspicious file type from a well-known file and paste sharing domain
windows