Log source category
process_creation log source Sigma rules
1632 Sigma detection rules in the library use the process_creation log source, mostly on windows, linux, macos. The process_creation category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
APT27 - Emissary Panda Activity
criticalDetects the execution of DLL side-loading malware used by threat group Emissary Panda aka APT27
windows
APT29 2018 Phishing Campaign CommandLine Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows
APT31 Judgement Panda Activity
criticalDetects APT31 Judgement Panda activity as described in the Crowdstrike 2019 Global Threat Report
windows
COLDSTEEL RAT Cleanup Command Execution
criticalDetects the creation of a "rundll32" process from the ColdSteel persistence service to initiate the cleanup command by calling one of its own exports. This functionality is not present in "MileStone2017" and some "MileStone2016" samples
windows
COLDSTEEL RAT Service Persistence Execution
criticalDetects the creation of an "svchost" process with specific command line flags, that were seen present and used by ColdSteel RAT
windows
DarkSide Ransomware Pattern
criticalDetects DarkSide Ransomware and helpers
windows
DNS RCE CVE-2020-1350
criticalDetects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
windows
Droppers Exploiting CVE-2017-11882
criticalDetects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
windows
DumpStack.log Defender Evasion
criticalDetects the use of the filename DumpStack.log to evade Microsoft Defender
windows
Elise Backdoor Activity
criticalDetects Elise backdoor activity used by APT32
windows
Equation Group DLL_U Export Function Load
criticalDetects a specific export function name used by one of EquationGroup tools
windows
EvilNum APT Golden Chickens Deployment Via OCX Files
criticalDetects Golden Chickens deployment method as used by Evilnum and described in ESET July 2020 report
windows
Exploit for CVE-2015-1641
criticalDetects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641
windows
Exploit for CVE-2017-8759
criticalDetects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
windows
Exploiting CVE-2019-1388
criticalDetects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM
windows
Greenbug Espionage Group Indicators
criticalDetects tools and process executions used by Greenbug in their May 2020 campaign as reported by Symantec
windows
Griffon Malware Attack Pattern
criticalDetects process execution patterns related to Griffon malware as reported by Kaspersky
windows
HackTool - DInjector PowerShell Cradle Execution
criticalDetects the use of the Dinject PowerShell cradle based on the specific flags
windows
HackTool - Dumpert Process Dumper Execution
criticalDetects the use of Dumpert process dumper, which dumps the lsass.exe process memory
windows
HackTool - Empire PowerShell UAC Bypass
criticalDetects some Empire PowerShell UAC bypass methods
windows
HackTool - F-Secure C3 Load by Rundll32
criticalF-Secure C3 produces DLLs with a default exported StartNodeRelay function.
windows
HackTool - Inveigh Execution
criticalDetects the use of Inveigh a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool
windows
HackTool - PurpleSharp Execution
criticalDetects the execution of the PurpleSharp adversary simulation tool
windows
HackTool - Rubeus Execution
criticalDetects the execution of the hacktool Rubeus via PE information of command line parameters
windows
HackTool - SafetyKatz Execution
criticalDetects the execution of the hacktool SafetyKatz via PE information and default Image name
windows
HackTool - SecurityXploded Execution
criticalDetects the execution of SecurityXploded Tools
windows
HackTool - SharpUp PrivEsc Tool Execution
criticalDetects the use of SharpUp, a tool for local privilege escalation
windows
HackTool - Sliver C2 Implant Activity Pattern
criticalDetects process activity patterns as seen being used by Sliver C2 framework implants
windows
HackTool - SysmonEOP Execution
criticalDetects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120
windows
HackTool - Windows Credential Editor (WCE) Execution
criticalDetects the use of Windows Credential Editor (WCE), a popular post-exploitation tool used to extract plaintext passwords, hash, PIN code and Kerberos tickets from memory. It is often used by threat actors for credential dumping and lateral movement within compromised networks.
windows
Hacktool Execution - Imphash
criticalDetects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed
windows
HAFNIUM Exchange Exploitation Activity
criticalDetects activity observed by different researchers to be HAFNIUM group activity (or related) on Exchange servers
windows
Lazarus Group Activity
criticalDetects different process execution behaviors as described in various threat reports on Lazarus group activity
windows
LockerGoga Ransomware Activity
criticalDetects LockerGoga ransomware activity via specific command line.
windows
Mint Sandstorm - AsperaFaspex Suspicious Process Execution
criticalDetects suspicious execution from AsperaFaspex as seen used by Mint Sandstorm
windows
Mint Sandstorm - ManageEngine Suspicious Process Execution
criticalDetects suspicious execution from ManageEngine as seen used by Mint Sandstorm
windows
NotPetya Ransomware Activity
criticalDetects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil
windows
OilRig APT Activity
criticalDetects OilRig activity as reported by Nyotron in their March 2018 report
windows
Persistence Via Sticky Key Backdoor
criticalBy replacing the sticky keys executable with the local admins CMD executable, an attacker is able to access a privileged windows console session without authenticating to the system. When the sticky keys are "activated" the privilleged shell is launched.
windows
Potential Conti Ransomware Activity
criticalDetects a specific command used by the Conti ransomware group
windows
Potential Credential Dumping Via LSASS Process Clone
criticalDetects a suspicious LSASS process process clone that could be a sign of credential dumping activity
windows
Potential CVE-2021-41379 Exploitation Attempt
criticalDetects potential exploitation attempts of CVE-2021-41379 (InstallerFileTakeOver), a local privilege escalation (LPE) vulnerability where the attacker spawns a "cmd.exe" process as a child of Microsoft Edge elevation service "elevation_service" with "LOCAL_SYSTEM" rights
windows
Potential Dridex Activity
criticalDetects potential Dridex acitvity via specific process patterns
windows
Potential Dtrack RAT Activity
criticalDetects potential Dtrack RAT activity via specific process patterns
windows
Potential Emotet Rundll32 Execution
criticalDetecting Emotet DLL loading by looking for rundll32.exe processes with command lines ending in ,RunDLL or ,Control_RunDLL
windows
Potential Maze Ransomware Activity
criticalDetects specific process characteristics of Maze ransomware word document droppers
windows
Potential QBot Activity
criticalDetects potential QBot activity by looking for process executions used previously by QBot
windows
Potential Russian APT Credential Theft Activity
criticalDetects Russian group activity as described in Global Threat Report 2019 by Crowdstrike
windows
Potential SMB Relay Attack Tool Execution
criticalDetects different hacktools used for relay attacks on Windows for privilege escalation
windows
Potential SystemNightmare Exploitation Attempt
criticalDetects an exploitation attempt of SystemNightmare in order to obtain a shell as LOCAL_SYSTEM
windows
Qakbot Rundll32 Exports Execution
criticalDetects specific process tree behavior of a "rundll32" execution with exports linked with Qakbot activity.
windows
Qakbot Rundll32 Fake DLL Extension Execution
criticalDetects specific process tree behavior of a "rundll32" execution where the DLL doesn't have the ".dll" extension. This is often linked with potential Qakbot activity.
windows
Renamed Whoami Execution
criticalDetects the execution of whoami that has been renamed to a different name to avoid detection
windows
REvil Kaseya Incident Malware Patterns
criticalDetects process command line patterns and locations used by REvil group in Kaseya incident (can also match on other malware)
windows
Rorschach Ransomware Execution Activity
criticalDetects Rorschach ransomware execution activity
windows
Serv-U Exploitation CVE-2021-35211 by DEV-0322
criticalDetects patterns as noticed in exploitation of Serv-U CVE-2021-35211 vulnerability by threat group DEV-0322
windows
Sticky Key Like Backdoor Execution
criticalDetects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
windows
Suspicious Child Process Of Veeam Dabatase
criticalDetects suspicious child processes of the Veeam service process. This could indicate potential RCE or SQL Injection.
windows
Suspicious PowerShell Mailbox Export to Share
criticalDetects usage of the powerShell New-MailboxExportRequest Cmdlet to exports a mailbox to a remote or local share, as used in ProxyShell exploitations
windows
TrustedPath UAC Bypass Pattern
criticalDetects indicators of a UAC bypass method by mocking directories
windows
Turla Group Commands May 2020
criticalDetects commands used by Turla group as reported by ESET in May 2020
windows
Turla Group Lateral Movement
criticalDetects automated lateral movement by Turla group
windows
UNC2452 PowerShell Pattern
criticalDetects a specific PowerShell command line pattern used by the UNC2452 actors as mentioned in Microsoft and Symantec reports
windows
UNC4841 - Potential SEASPY Execution
criticalDetects execution of specific named binaries which were used by UNC4841 to deploy their SEASPY backdoor
linux
WannaCry Ransomware Activity
criticalDetects WannaCry ransomware activity
windows
Winnti Malware HK University Campaign
criticalDetects specific process characteristics of Winnti malware noticed in Dec/Jan 2020 in a campaign against Honk Kong universities
windows
Winnti Pipemon Characteristics
criticalDetects specific process characteristics of Winnti Pipemon malware reported by ESET
windows
WMI Backdoor Exchange Transport Agent
criticalDetects a WMI backdoor in Exchange Transport Agents via WMI event filters
windows
ZxShell Malware
criticalDetects a ZxShell start by the called and well-known function name
windows
AADInternals PowerShell Cmdlets Execution - ProccessCreation
highDetects ADDInternals Cmdlet execution. A tool for administering Azure AD and Office 365. Which can be abused by threat actors to attack Azure AD or Office 365.
windows
Abuse of Service Permissions to Hide Services Via Set-Service
highDetects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)
windows
Abused Debug Privilege by Arbitrary Parent Processes
highDetection of unusual child processes by different system processes
windows
Add Insecure Download Source To Winget
highDetects usage of winget to add a new insecure (http) download source. Winget will not allow the addition of insecure sources, hence this could indicate potential suspicious activity (or typos)
windows
Add SafeBoot Keys Via Reg Utility
highDetects execution of "reg.exe" commands with the "add" or "copy" flags on safe boot registry keys. Often used by attacker to allow the ransomware to work in safe mode as some security products do not
windows
Adwind RAT / JRAT
highDetects javaw.exe in AppData folder as used by Adwind / JRAT
windows
All Backups Deleted Via Wbadmin.EXE
highDetects the deletion of all backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.
windows
Allow Service Access Using Security Descriptor Tampering Via Sc.EXE
highDetects suspicious DACL modifications to allow access to a service from a suspicious trustee. This can be used to override access restrictions set by previous ACLs.
windows
Apache Spark Shell Command Injection - ProcessCreation
highDetects attempts to exploit an apache spark server via CVE-2014-6287 from a commandline perspective
linux
Arbitrary File Download Via IMEWDBLD.EXE
highDetects usage of "IMEWDBLD.exe" to download arbitrary files
windows
Atlassian Confluence CVE-2022-26134
highDetects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2022-26134
linux
Atomic MacOS Stealer - FileGrabber Activity
highDetects suspicious activity associated with Atomic MacOS Stealer (Amos) campaigns, including execution of FileGrabber and curl-based POST requests used for data exfiltration. The rule identifies either the execution of FileGrabber targeting /tmp or the use of curl to POST sensitive user data (including files such as /tmp/out.zip) to remote servers, which are key indicators of Amos infostealer activity.
macos
Attempts of Kerberos Coercion Via DNS SPN Spoofing
highDetects the presence of "UWhRC....AAYBAAAA" pattern in command line. The pattern "1UWhRCAAAAA..BAAAA" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure. Attackers can use this technique to coerce authentication from victim systems to attacker-controlled hosts. It is one of the strong indicators of a Kerberos coercion attack, where adversaries manipulate DNS records to spoof Service Principal Names (SPNs) and redirect authentication requests like in CVE-2025-33073. If you see this pattern in the command line, it is likely an attempt to add spoofed Service Principal Names (SPNs) to DNS records, or checking for the presence of such records through the `nslookup` command.
windows
Audit Policy Tampering Via Auditpol
highThreat actors can use auditpol binary to change audit policy configuration to impair detection capability. This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.
windows
Audit Policy Tampering Via NT Resource Kit Auditpol
highThreat actors can use an older version of the auditpol binary available inside the NT resource kit to change audit policy configuration to impair detection capability. This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.
windows
Audit Rules Deleted Via Auditctl
highDetects the execution of 'auditctl' with the '-D' command line parameter, which deletes all configured audit rules and watches on Linux systems. This technique is commonly used by attackers to disable audit logging and cover their tracks by removing monitoring capabilities. Removal of audit rules can significantly impair detection of malicious activities on the affected system.
linux
Authencesn Crypto Module Load via Modprobe - Copy-Fail Indicator
highDetects kernel auto-loading of the authencesn crypto module via modprobe This occurs when user-space code creates an AF_ALG socket and binds the authencesn AEAD cipher (e.g., authencesn(hmac(sha256),cbc(aes))). The kernel invokes modprobe to load the crypto module. This is a key indicator of CVE-2026-31431 (Copy Fail) exploitation, where the authencesn cipher is used to trigger a buffer overflow in the AF_ALG AEAD splice path, corrupting the page cache of SUID binaries for local privilege escalation. On Linux systems, modprobe is typically a symlink to kmod, so the process image will be /usr/bin/kmod (or /bin/kmod) with 'modprobe' appearing in the command line.
linux
Axios NPM Compromise Indicators - Linux
highDetects the Linux-specific execution chain of the plain-crypto-js malicious npm dependency by Axios NPM package, including payload download via curl and detached execution using nohup and python3. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.
linux
Axios NPM Compromise Indicators - macOS
highDetects the macOS-specific execution chain of the plain-crypto-js malicious npm dependency in Axios NPM Package, including AppleScript execution via osascript, payload download, permission modification, execution, and cleanup.
macos
Axios NPM Compromise Indicators - Windows
highDetects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection. The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.
windows
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
highDetects attackers using tooling with bad opsec defaults. E.g. spawning a sacrificial process to inject a capability into the process without taking into account how the process is normally run. One trivial example of this is using rundll32.exe without arguments as a sacrificial process (default in CS, now highlighted by c2lint), running WerFault without arguments (Kraken - credit am0nsec), and other examples.
windows
Base64 Encoded PowerShell Command Detected
highDetects usage of the "FromBase64String" function in the commandline which is used to decode a base64 encoded string
windows
Base64 MZ Header In CommandLine
highDetects encoded base64 MZ header in the commandline
windows
Binary Padding - MacOS
highAdversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.
macos
Blue Mockingbird
highAttempts to detect system changes made by Blue Mockingbird
windows
Boot Configuration Tampering Via Bcdedit.EXE
highDetects the use of the bcdedit command to tamper with the boot configuration data. This technique is often times used by malware or attackers as a destructive way before launching ransomware.
windows
Bypass UAC via CMSTP
highDetect commandline usage of Microsoft Connection Manager Profile Installer (cmstp.exe) to install specially formatted local .INF files
windows
Bypass UAC via Fodhelper.exe
highIdentifies use of Fodhelper.exe to bypass User Account Control. Adversaries use this technique to execute privileged processes.
windows
Bypass UAC via WSReset.exe
highDetects use of WSReset.exe to bypass User Account Control (UAC). Adversaries use this technique to execute privileged processes.
windows
Cab File Extraction Via Wusa.EXE From Potentially Suspicious Paths
highDetects the execution of the "wusa.exe" (Windows Update Standalone Installer) utility to extract ".cab" files using the "/extract" argument from potentially suspicious paths.
windows
Capsh Shell Invocation - Linux
highDetects the use of the "capsh" utility to invoke a shell.
linux
Change Default File Association To Executable Via Assoc
highDetects when a program changes the default file association of any extension to an executable. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Applications can modify the file association for a given file extension to call an arbitrary program when a file with the given extension is opened.
windows
Chopper Webshell Process Pattern
highDetects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
windows
ChromeLoader Malware Execution
highDetects execution of ChromeLoader malware via a registered scheduled task
windows
Chromium Browser Headless Execution To Mockbin Like Site
highDetects the execution of a Chromium based browser process with the "headless" flag and a URL pointing to the mockbin.org service (which can be used to exfiltrate data).
windows
Cmd.EXE Missing Space Characters Execution Anomaly
highDetects Windows command lines that miss a space before or after the /c flag when running a command using the cmd.exe. This could be a sign of obfuscation of a fat finger problem (typo by the developer).
windows
CMSTP Execution Process Creation
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows
CMSTP UAC Bypass via COM Object Access
highDetects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)
windows
CobaltStrike Load by Rundll32
highRundll32 can be use by Cobalt Strike with StartW function to load DLLs from the command line.
windows
COLDSTEEL RAT Anonymous User Process Execution
highDetects the creation of a process executing as user called "ANONYMOUS" seen used by the "MileStone2016" variant of COLDSTEEL
windows
Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791)
highDetects the use of argument injection in the Commvault qlogin command - potential exploitation for CVE-2025-57791. An attacker can inject the `-localadmin` parameter via the password field to bypass authentication and gain a privileged token.
windows
Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790)
highDetects the use of qoperation.exe with the -file argument to write a JSP file to the webroot, indicating a webshell drop. This is a post-authentication step corresponding to CVE-2025-57790.
windows
Conhost.exe CommandLine Path Traversal
highdetects the usage of path traversal in conhost.exe indicating possible command/argument confusion/hijacking
windows
Conti NTDS Exfiltration Command
highDetects a command used by conti to exfiltrate NTDS
windows
Conti Volume Shadow Listing
highDetects a command used by conti to find volume shadow backups
windows
Control Panel Items
highDetects the malicious use of a control panel item
windows
Copy .DMP/.DUMP Files From Remote Share Via Cmd.EXE
highDetects usage of the copy builtin cmd command to copy files with the ".dmp"/".dump" extension from a remote share
windows
Copy From VolumeShadowCopy Via Cmd.EXE
highDetects the execution of the builtin "copy" command that targets a shadow copy (sometimes used to copy registry hives that are in use)
windows
Copy Passwd Or Shadow From TMP Path
highDetects when the file "passwd" or "shadow" is copied from tmp path
linux
Copying Sensitive Files with Credential Data
highFiles with well-known filenames (sensitive files with credential data) copying
windows
CreateDump Process Dump
highDetects uses of the createdump.exe LOLOBIN utility to dump process memory
windows
Credentials In Files
highDetecting attempts to extract passwords with grep and laZagne
macos
Csc.EXE Execution Form Potentially Suspicious Parent
highDetects a potentially suspicious parent of "csc.exe", which could be a sign of payload delivery.
windows
Cscript/Wscript Uncommon Script Extension Execution
highDetects Wscript/Cscript executing a file with an uncommon (i.e. non-script) extension
windows
Curl Download And Execute Combination
highAdversaries can use curl to download payloads remotely and execute them. Curl is included by default in Windows 10 build 17063 and later.
windows
Curl File Upload To File Sharing Websites
highDetects usage of curl to upload files to known file sharing domains, which may indicate data exfiltration.
windows
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
highDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
linux
CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process
highDetects exploitation attempt of CVE-2023-38331 (WinRAR before v6.23), where an attacker can leverage WinRAR to execute arbitrary commands and binaries.
windows
CVE-2024-50623 Exploitation Attempt - Cleo
highDetects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.
windows
DarkGate - Autoit3.EXE Execution Parameters
highDetects execution of the legitimate Autoit3 utility from a suspicious parent process. AutoIt3.exe is used within the DarkGate infection chain to execute shellcode that performs process injection and connects to the DarkGate command-and-control server.
windows
DarkGate - User Created Via Net.EXE
highDetects creation of local users via the net.exe command with the name of "DarkGate"
windows
Delete All Scheduled Tasks
highDetects the usage of schtasks with the delete flag and the asterisk symbol to delete all tasks from the schedule of the local computer, including tasks scheduled by other users.
windows
Delete Important Scheduled Task
highDetects when adversaries stop services or processes by deleting their respective scheduled tasks in order to conduct data destructive activities
windows
Deletion of Volume Shadow Copies via WMI with PowerShell
highDetects deletion of Windows Volume Shadow Copies with PowerShell code and Get-WMIObject. This technique is used by numerous ransomware families such as Sodinokibi/REvil
windows
Deny Service Access Using Security Descriptor Tampering Via Sc.EXE
highDetects suspicious DACL modifications to deny access to a service that affects critical trustees. This can be used to hide services or make them unstoppable.
windows
Devcon Execution Disabling VMware VMCI Device
highDetects execution of devcon.exe with commands that disable the VMware Virtual Machine Communication Interface (VMCI) device. This can be legitimate during VMware Tools troubleshooting or driver conflicts, but may also indicate malware attempting to hijack communication with the hardware via the VMCI device. This has been used to facilitate VMware ESXi vulnerability exploits to escape VMs and execute code on the ESXi host.
windows
Devtoolslauncher.exe Executes Specified Binary
highThe Devtoolslauncher.exe executes other binary
windows
Diamond Sleet APT Process Activity Indicators
highDetects process creation activity indicators related to Diamond Sleet APT
windows
Disable Important Scheduled Task
highDetects when adversaries stop services or processes by disabling their respective scheduled tasks in order to conduct data destructive activities
windows
Disable Windows Defender AV Security Monitoring
highDetects attackers attempting to disable Windows Defender using Powershell
windows
Disable Windows IIS HTTP Logging
highDisables HTTP logging on a Windows IIS web server as seen by Threat Group 3390 (Bronze Union)
windows
Disabled IE Security Features
highDetects command lines that indicate unwanted modifications to registry keys that disable important Internet Explorer security features
windows
Disabled Volume Snapshots
highDetects commands that temporarily turn off Volume Snapshots
windows
Disabling Windows Defender WMI Autologger Session via Reg.exe
highDetects the use of reg.exe to disable the Event Tracing for Windows (ETW) Autologger session for Windows Defender API and Audit events. By setting the 'Start' value to '0' for the 'DefenderApiLogger' or 'DefenderAuditLogger' session, an attacker can prevent these critical security events from being logged, effectively blinding monitoring tools that rely on this data. This is a powerful defense evasion technique.
windows
DLL Sideloading by VMware Xfer Utility
highDetects execution of VMware Xfer utility (VMwareXferlogs.exe) from the non-default directory which may be an attempt to sideload arbitrary DLL
windows
Dllhost.EXE Execution Anomaly
highDetects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.
windows
DNS Exfiltration and Tunneling Tools Execution
highWell-known DNS Exfiltration tools execution
windows
DSInternals Suspicious PowerShell Cmdlets
highDetects execution and usage of the DSInternals PowerShell module. Which can be used to perform what might be considered as suspicious activity such as dumping DPAPI backup keys or manipulating NTDS.DIT files. The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
windows
Dumping of Sensitive Hives Via Reg.EXE
highDetects the usage of "reg.exe" in order to dump sensitive registry hives. This includes SAM, SYSTEM and SECURITY hives.
windows
Email Exifiltration Via Powershell
highDetects email exfiltration via powershell cmdlets
windows
Emotet Loader Execution Via .LNK File
highDetects the Emotet Epoch4 loader as reported by @malware_traffic back in 2022. The ".lnk" file was delivered via phishing campaign.
windows
Enable LM Hash Storage - ProcCreation
highDetects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.
windows
ESXi Admin Permission Assigned To Account Via ESXCLI
highDetects execution of the "esxcli" command with the "system" and "permission" flags in order to assign admin permissions to an account.
linux
ETW Logging Tamper In .NET Processes Via CommandLine
highDetects changes to environment variables related to ETW logging via the CommandLine. This could indicate potential adversaries stopping ETW providers recording loaded .NET assemblies.
windows
ETW Trace Evasion Activity
highDetects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.
windows
Exchange PowerShell Snap-Ins Usage
highDetects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
windows
Execute Pcwrun.EXE To Leverage Follina
highDetects indirect command execution via Program Compatibility Assistant "pcwrun.exe" leveraging the follina (CVE-2022-30190) vulnerability
windows
Execution Of Non-Existing File
highDetects process creation events where the Image field lacks an absolute path, which occurs when the backing file no longer exists on disk at the time of logging - commonly caused by Process Ghosting or other unorthodox process creation techniques.
windows
Execution of Powershell Script in Public Folder
highThis rule detects execution of PowerShell scripts located in the "C:\Users\Public" folder
windows
Execution via stordiag.exe
highDetects the use of stordiag.exe to execute schtasks.exe systeminfo.exe and fltmc.exe
windows
Execution via WorkFolders.exe
highDetects using WorkFolders.exe to execute an arbitrary control.exe
windows
Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
highDetects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe. This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
windows
Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC
highDetects the execution of the commonly used ZeroLogon PoC executable.
windows
Exploited CVE-2020-10189 Zoho ManageEngine
highDetects the exploitation of Zoho ManageEngine Desktop Central Java Deserialization vulnerability reported as CVE-2020-10189
windows
Exploiting SetupComplete.cmd CVE-2019-1378
highDetects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378
windows
Explorer NOUACCHECK Flag
highDetects suspicious starts of explorer.exe that use the /NOUACCHECK flag that allows to run all sub processes of that newly started explorer.exe without any UAC checks
windows
Exports Critical Registry Keys To a File
highDetects the export of a crital Registry key to a file.
windows
FakeUpdates/SocGholish Activity
highDetects initial execution of FakeUpdates/SocGholish malware via wscript that later executes commands via cmd or powershell.
windows
File Decoded From Base64/Hex Via Certutil.EXE
highDetects the execution of certutil with either the "decode" or "decodehex" flags to decode base64 or hex encoded files. This can be abused by attackers to decode an encoded payload before execution
windows
File Download And Execution Via IEExec.EXE
highDetects execution of the IEExec utility to download and execute files
windows
File Download From IP Based URL Via CertOC.EXE
highDetects when a user downloads a file from an IP based URL using CertOC.exe
windows
File Download Using Notepad++ GUP Utility
highDetects execution of the Notepad++ updater (gup) from a process other than Notepad++ to download files.
windows
File Download Via Bitsadmin To A Suspicious Target Folder
highDetects usage of bitsadmin downloading a file to a suspicious target folder
windows
File Download Via Windows Defender MpCmpRun.EXE
highDetects the use of Windows Defender MpCmdRun.EXE to download files
windows
File Download with Headless Browser
highDetects execution of chromium based browser in headless mode using the "dump-dom" command line to download files
windows
File Encryption/Decryption Via Gpg4win From Suspicious Locations
highDetects usage of Gpg4win to encrypt/decrypt files located in potentially suspicious locations.
windows
File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
highDetects the initial execution of "cmd.exe" which spawns "explorer.exe" with the appropriate command line arguments for opening the "My Computer" folder.
windows
File In Suspicious Location Encoded To Base64 Via Certutil.EXE
highDetects the execution of certutil with the "encode" flag to encode a file to base64 where the files are located in potentially suspicious locations
windows
File With Suspicious Extension Downloaded Via Bitsadmin
highDetects usage of bitsadmin downloading a file with a suspicious extension
windows
Findstr GPP Passwords
highLook for the encrypted cpassword value within Group Policy Preference files on the Domain Controller. This value can be decrypted with gpp-decrypt.
windows
Finger.EXE Execution
highDetects execution of the "finger.exe" utility. Finger.EXE or "TCPIP Finger Command" is an old utility that is still present on modern Windows installation. It Displays information about users on a specified remote computer (typically a UNIX computer) that is running the finger service or daemon. Due to the old nature of this utility and the rareness of machines having the finger service. Any execution of "finger.exe" can be considered "suspicious" and worth investigating.
windows
Fireball Archer Install
highDetects Archer malware invocation via rundll32
windows
Forest Blizzard APT - Process Creation Activity
highDetects the execution of specific processes and command line combination. These were seen being created by Forest Blizzard as described by MSFT.
windows
Forfiles.EXE Child Process Masquerading
highDetects the execution of "forfiles" from a non-default location, in order to potentially spawn a custom "cmd.exe" from the current working directory.
windows
Formbook Process Creation
highDetects Formbook like process executions that inject code into a set of files in the System32 folder, which executes a special command command line to delete the dropper from the AppData Temp folder. We avoid false positives by excluding all parent process with command line parameters.
windows
Fsutil Suspicious Invocation
highDetects suspicious parameters of fsutil (deleting USN journal, configuring it with small size, etc). Might be used by ransomwares during the attack (seen by NotPetya and others).
windows
GALLIUM IOCs
highDetects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
windows
Grixba Malware Reconnaissance Activity
highDetects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations. This tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.
windows
HackTool - ADCSPwn Execution
highDetects command line parameters used by ADCSPwn, a tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service
windows
HackTool - Bloodhound/Sharphound Execution
highDetects command line parameters used by Bloodhound and Sharphound hack tools
windows
HackTool - Certify Execution
highDetects Certify a tool for Active Directory certificate abuse based on PE metadata characteristics and common command line arguments.
windows
HackTool - Certipy Execution
highDetects Certipy execution, a tool for Active Directory Certificate Services enumeration and abuse based on PE metadata characteristics and common command line arguments.
windows
HackTool - CoercedPotato Execution
highDetects the use of CoercedPotato, a tool for privilege escalation
windows
HackTool - Covenant PowerShell Launcher
highDetects suspicious command lines used in Covenant luanchers
windows
HackTool - CrackMapExec Execution
highThis rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
windows
HackTool - CrackMapExec Execution Patterns
highDetects various execution patterns of the CrackMapExec pentesting framework
windows
HackTool - CrackMapExec PowerShell Obfuscation
highThe CrachMapExec pentesting framework implements a PowerShell obfuscation with some static strings detected by this rule.
windows
HackTool - CrackMapExec Process Patterns
highDetects suspicious process patterns found in logs when CrackMapExec is used
windows
HackTool - CreateMiniDump Execution
highDetects the use of CreateMiniDump hack tool used to dump the LSASS process memory for credential extraction on the attacker's machine
windows
HackTool - Default PowerSploit/Empire Scheduled Task Creation
highDetects the creation of a schtask via PowerSploit or Empire Default Configuration.
windows
HackTool - Doppelanger LSASS Dumper Execution
highDetects the execution of the Doppelanger hacktool which is used to dump LSASS memory via process cloning while evading common detection methods
windows
Hacktool - EDR-Freeze Execution
highDetects execution of EDR-Freeze, a tool that exploits the MiniDumpWriteDump function and WerFaultSecure.exe to suspend EDR and Antivirus processes on Windows. EDR-Freeze leverages a race-condition attack to put security processes into a dormant state by suspending WerFaultSecure at the moment it freezes the target process. This technique does not require kernel-level exploits or BYOVD, but instead abuses user-mode functionality to temporarily disable monitoring by EDR or Antimalware solutions.
windows
HackTool - EDRSilencer Execution
highDetects the execution of EDRSilencer, a tool that leverages Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server based on PE metadata information.
windows
HackTool - Empire PowerShell Launch Parameters
highDetects suspicious powershell command line parameters used in Empire
windows
HackTool - GMER Rootkit Detector and Remover Execution
highDetects the execution GMER tool based on image and hash fields.
windows
HackTool - HandleKatz LSASS Dumper Execution
highDetects the use of HandleKatz, a tool that demonstrates the usage of cloned handles to Lsass in order to create an obfuscated memory dump of the same
windows
HackTool - Hashcat Password Cracker Execution
highExecute Hashcat.exe with provided SAM file from registry of Windows and Password list to crack against
windows
HackTool - HollowReaper Execution
highDetects usage of HollowReaper, a process hollowing shellcode launcher used for stealth payload execution through process hollowing. It replaces the memory of a legitimate process with custom shellcode, allowing the attacker to execute payloads under the guise of trusted binaries.
windows
HackTool - Htran/NATBypass Execution
highDetects executable names or flags used by Htran or Htran-like tools (e.g. NATBypass)
windows
HackTool - Hydra Password Bruteforce Execution
highDetects command line parameters used by Hydra password guessing hack tool
windows
HackTool - Impacket Tools Execution
highDetects the execution of different compiled Windows binaries of the impacket toolset (based on names or part of their names - could lead to false positives)
windows
HackTool - Koadic Execution
highDetects command line parameters used by Koadic hack tool
windows
HackTool - KrbRelay Execution
highDetects the use of KrbRelay, a Kerberos relaying tool
windows
HackTool - KrbRelayUp Execution
highDetects KrbRelayUp used to perform a universal no-fix local privilege escalation in Windows domain environments where LDAP signing is not enforced
windows
HackTool - LocalPotato Execution
highDetects the execution of the LocalPotato POC based on basic PE metadata information and default CLI examples
windows
HackTool - Mimikatz Execution
highDetection well-known mimikatz command line arguments
windows
HackTool - NetExec Execution
highDetects execution of the hacktool NetExec. NetExec (formerly CrackMapExec) is a widely used post-exploitation tool designed for Active Directory penetration testing and network enumeration In enterprise environments, the use of NetExec is considered suspicious or potentially malicious because it enables attackers to enumerate hosts, exploit network services, and move laterally across systems. Threat actors and red teams commonly use NetExec to identify vulnerable systems, harvest credentials, and execute commands remotely.
windows
HackTool - PCHunter Execution
highDetects suspicious use of PCHunter, a tool like Process Hacker to view and manipulate processes, kernel options and other low level stuff
windows
HackTool - Potential Impacket Lateral Movement Activity
highDetects wmiexec/dcomexec/atexec/smbexec from Impacket framework
windows
HackTool - PowerTool Execution
highDetects the execution of the tool PowerTool which has the ability to kill a process, delete its process file, unload drivers, and delete the driver files
windows
HackTool - PPID Spoofing SelectMyParent Tool Execution
highDetects the use of parent process ID spoofing tools like Didier Stevens tool SelectMyParent
windows
HackTool - Pypykatz Credentials Dumping Activity
highDetects the usage of "pypykatz" to obtain stored credentials. Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database through Windows registry where the SAM database is stored
windows
HackTool - Quarks PwDump Execution
highDetects usage of the Quarks PwDump tool via commandline arguments
windows
HackTool - RedMimicry Winnti Playbook Execution
highDetects actions caused by the RedMimicry Winnti playbook a automated breach emulations utility
windows
HackTool - RemoteKrbRelay Execution
highDetects the use of RemoteKrbRelay, a Kerberos relaying tool via CommandLine flags and PE metadata.
windows
HackTool - SharpChisel Execution
highDetects usage of the Sharp Chisel via the commandline arguments
windows
HackTool - SharpDPAPI Execution
highDetects the execution of the SharpDPAPI tool based on CommandLine flags and PE metadata. SharpDPAPI is a C# port of some DPAPI functionality from the Mimikatz project.
windows
HackTool - SharPersist Execution
highDetects the execution of the hacktool SharPersist - used to deploy various different kinds of persistence mechanisms
windows
HackTool - SharpEvtMute Execution
highDetects the use of SharpEvtHook, a tool that tampers with the Windows event logs
windows
HackTool - SharpImpersonation Execution
highDetects execution of the SharpImpersonation tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
windows
HackTool - SharpLdapWhoami Execution
highDetects SharpLdapWhoami, a whoami alternative that queries the LDAP service on a domain controller
windows
HackTool - SharpMove Tool Execution
highDetects the execution of SharpMove, a .NET utility performing multiple tasks such as "Task Creation", "SCM" query, VBScript execution using WMI via its PE metadata and command line options.
windows
HackTool - SharpView Execution
highAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows
HackTool - SharpWSUS/WSUSpendu Execution
highDetects the execution of SharpWSUS or WSUSpendu, utilities that allow for lateral movement through WSUS. Windows Server Update Services (WSUS) is a critical component of Windows systems and is frequently configured in a way that allows an attacker to circumvent internal networking limitations.
windows
HackTool - SILENTTRINITY Stager Execution
highDetects SILENTTRINITY stager use via PE metadata
windows
HackTool - SOAPHound Execution
highDetects the execution of SOAPHound, a .NET tool for collecting Active Directory data, using specific command-line arguments that may indicate an attempt to extract sensitive AD information.
windows
HackTool - Stracciatella Execution
highDetects Stracciatella which executes a Powershell runspace from within C# (aka SharpPick technique) with AMSI, ETW and Script Block Logging disabled based on PE metadata characteristics.
windows
HackTool - TruffleSnout Execution
highDetects the use of TruffleSnout.exe an iterative AD discovery toolkit for offensive operators, situational awareness and targeted low noise enumeration.
windows
HackTool - UACMe Akagi Execution
highDetects the execution of UACMe, a tool used for UAC bypasses, via default PE metadata
windows
HackTool - winPEAS Execution
highWinPEAS is a script that search for possible paths to escalate privileges on Windows hosts. The checks are explained on book.hacktricks.xyz
windows
HackTool - WinPwn Execution
highDetects commandline keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
windows
HackTool - Wmiexec Default Powershell Command
highDetects the execution of PowerShell with a specific flag sequence that is used by the Wmiexec script
windows
HackTool - WSASS Execution
highDetects execution of WSASS, a tool used to dump LSASS memory on Windows systems by leveraging WER's (Windows Error Reporting) WerFaultSecure.EXE to bypass PPL (Protected Process Light) protections.
windows
HackTool - XORDump Execution
highDetects suspicious use of XORDump process memory dumping utility
windows
Hacktool Execution - PE Metadata
highDetects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed
windows
Hermetic Wiper TG Process Patterns
highDetects process execution patterns found in intrusions related to the Hermetic Wiper malware attacks against Ukraine in February 2022
windows
History File Deletion
highDetects events in which a history file gets deleted, e.g. the ~/bash_history to remove traces of malicious activity
linux
HKTL - SharpSuccessor Privilege Escalation Tool Execution
highDetects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments. Successful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.
windows
HTML Help HH.EXE Suspicious Child Process
highDetects a suspicious child process of a Microsoft HTML Help (HH.exe)
windows
Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
highDetects the tampering of Hypervisor-protected Code Integrity (HVCI) related registry values via command line tool reg.exe. HVCI uses virtualization-based security to protect code integrity by ensuring that only trusted code can run in kernel mode. Adversaries may tamper with HVCI to load malicious or unsigned drivers, which can be used to escalate privileges, maintain persistence, or evade security mechanisms.
windows
IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
highDetects RunDLL32.exe executing a single digit DLL named "1.dll" with the export function "DllRegisterServer". This behaviour was often seen used by malware and especially IcedID
windows
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI
highDetects changes to Internet Explorer's (IE / Windows Internet properties) ZoneMap configuration of the "HTTP" and "HTTPS" protocols to point to the "My Computer" zone. This allows downloaded files from the Internet to be granted the same level of trust as files stored locally.
windows
ImagingDevices Unusual Parent/Child Processes
highDetects unusual parent or children of the ImagingDevices.exe (Windows Contacts) process as seen being used with Bumblebee activity
windows
Imports Registry Key From an ADS
highDetects the import of a alternate datastream to the registry with regedit.exe.
windows
Injected Browser Process Spawning Rundll32 - GuLoader Activity
highDetects the execution of installed GuLoader malware on the host. GuLoader is initiating network connections via the rundll32.exe process that is spawned via a browser parent(injected) process.
windows
Inline Python Execution - Spawn Shell Via OS System Library
highDetects execution of inline Python code via the "-c" in order to call the "system" function from the "os" library, and spawn a shell.
linux
Installation of WSL Kali-Linux
highDetects installation of Kali Linux distribution through Windows Subsystem for Linux (WSL). Attackers may use Kali Linux WSL to leverage its penetration testing tools and capabilities for malicious purposes.
windows
Interactive AT Job
highDetects an interactive AT job, which may be used as a form of privilege escalation.
windows
Invoke-Obfuscation CLIP+ Launcher
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows
Invoke-Obfuscation Obfuscated IEX Invocation
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block
windows
Invoke-Obfuscation STDIN+ Launcher
highDetects Obfuscated use of stdin to execute PowerShell
windows
Invoke-Obfuscation VAR+ Launcher
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows
Invoke-Obfuscation Via Stdin
highDetects Obfuscated Powershell via Stdin in Scripts
windows
Invoke-Obfuscation Via Use Clip
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows
Invoke-Obfuscation Via Use MSHTA
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows
JXA In-memory Execution Via OSAScript
highDetects possible malicious execution of JXA in-memory via OSAScript
macos
Kalambur Backdoor Curl TOR SOCKS Proxy Execution
highDetects the execution of the "curl.exe" command, referencing "SOCKS" and ".onion" domains, which could be indicative of Kalambur backdoor activity.
windows
Kapeka Backdoor Execution Via RunDLL32.EXE
highDetects Kapeka backdoor process execution pattern, where the dropper launch the backdoor binary by calling rundll32 and passing the backdoor's first export ordinal (#1) with a "-d" argument.
windows
Kapeka Backdoor Persistence Activity
highDetects Kapeka backdoor persistence activity. Depending on the process privileges, the Kapeka dropper then sets persistence for the backdoor either as a scheduled task (if admin or SYSTEM) or autorun registry (if not). For the scheduled task, it creates a scheduled task called "Sens Api" via schtasks command, which is set to run upon system startup as SYSTEM. To establish persistence through the autorun utility, it adds an autorun entry called "Sens Api" under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run via the "reg add" command. Both persistence mechanisms are set to launch the binary by calling rundll32 and passing the backdoor's first export ordinal (#1) without any additional argument.
windows
Kaspersky Endpoint Security Stopped Via CommandLine - Linux
highDetects execution of the Kaspersky init.d stop script on Linux systems either directly or via systemctl. This activity may indicate a manual interruption of the antivirus service by an administrator, or it could be a sign of potential tampering or evasion attempts by malicious actors.
linux
Kavremover Dropped Binary LOLBIN Usage
highDetects the execution of a signed binary dropped by Kaspersky Lab Products Remover (kavremover) which can be abused as a LOLBIN to execute arbitrary commands and binaries.
windows
Kernel Memory Dump Via LiveKD
highDetects execution of LiveKD with the "-m" flag to potentially dump the kernel memory
windows
Lace Tempest Cobalt Strike Download
highDetects specific command line execution used by Lace Tempest to download Cobalt Strike as reported by SysAid Team
windows
Lace Tempest Malware Loader Execution
highDetects execution of a specific binary based on filename and hash used by Lace Tempest to load additional malware as reported by SysAid Team
windows
Lazarus System Binary Masquerading
highDetects binaries used by the Lazarus group which use system names but are executed and launched from non-default location
windows
Linux Crypto Mining Indicators
highDetects command line parameters or strings often used by crypto miners
linux
Linux HackTool Execution
highDetects known hacktool execution based on image name.
linux
Linux Recon Indicators
highDetects events with patterns found in commands used for reconnaissance on linux systems
linux
Linux Suspicious Child Process from Node.js - React2Shell
highDetects suspicious child processes spawned from Node.js server processes on Linux systems, potentially indicating remote code execution exploitation such as CVE-2025-55182 (React2Shell). This rule particularly looks for exploitation of vulnerability on Node.js Servers where attackers abuse Node.js child_process module to execute arbitrary system commands. When execSync() or exec() is used, the command line often includes a shell invocation followed by suspicious commands or scripts (e.g., /bin/sh -c <malicious-command>). For other methods, the Image field will show the spawned process directly.
linux
Linux Webshell Indicators
highDetects suspicious sub processes of web server processes
linux
LiteLLM / TeamPCP Supply Chain Attack Indicators
highDetects process executions related to the backdoored versions of LiteLLM (v1.82.7 or v1.82.8). In March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP. The malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.
linux
LOL-Binary Copied From System Directory
highDetects a suspicious copy operation that tries to copy a known LOLBIN from system (System32, SysWOW64, WinSxS) directories to another on disk in order to bypass detections based on locations.
windows
LSASS Dump Keyword In CommandLine
highDetects the presence of the keywords "lsass" and ".dmp" in the commandline, which could indicate a potential attempt to dump or create a dump of the lsass process.
windows
LSASS Process Reconnaissance Via Findstr.EXE
highDetects findstring commands that include the keyword lsass, which indicates recon actviity for the LSASS process PID
windows
Lummac Stealer Activity - Execution Of More.com And Vbc.exe
highDetects the execution of more.com and vbc.exe in the process tree. This behavior was observed by a set of samples related to Lummac Stealer. The Lummac payload is injected into the vbc.exe process.
windows
Malicious Base64 Encoded PowerShell Keywords in Command Lines
highDetects base64 encoded strings used in hidden malicious PowerShell command lines
windows
Malicious PowerShell Commandlets - ProcessCreation
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows
ManageEngine Endpoint Central Dctask64.EXE Potential Abuse
highDetects the execution of "dctask64.exe", a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.
windows
Mask System Power Settings Via Systemctl
highDetects the use of systemctl mask to disable system power management targets such as suspend, hibernate, or hybrid sleep. Adversaries may mask these targets to prevent a system from entering sleep or shutdown states, ensuring their malicious processes remain active and uninterrupted. This behavior can be associated with persistence or defense evasion, as it impairs normal system power operations to maintain long-term access or avoid termination of malicious activity.
linux
Mavinject Inject DLL Into Running Process
highDetects process injection using the signed Windows tool "Mavinject" via the "INJECTRUNNING" flag
windows
MERCURY APT Activity
highDetects suspicious command line patterns seen being used by MERCURY APT
windows
Microsoft IIS Connection Strings Decryption
highDetects use of aspnet_regiis to decrypt Microsoft IIS connection strings. An attacker with Microsoft IIS web server access via a webshell or alike can decrypt and dump any hardcoded connection strings, such as the MSSQL service account password using aspnet_regiis command.
windows
Microsoft IIS Service Account Password Dumped
highDetects the Internet Information Services (IIS) command-line tool, AppCmd, being used to list passwords
windows
Mint Sandstorm - Log4J Wstomcat Process Execution
highDetects Log4J Wstomcat process execution as seen in Mint Sandstorm activity
windows
MMC Executing Files with Reversed Extensions Using RTLO Abuse
highDetects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.
windows
MMC Spawning Windows Shell
highDetects a Windows command line executable started from MMC
windows
MMC20 Lateral Movement
highDetects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of "-Embedding" as a child of svchost.exe
windows
MpiExec Lolbin
highDetects a certain command line flag combination used by mpiexec.exe LOLBIN from HPC pack that can be used to execute any other binary
windows
MSDT Execution Via Answer File
highDetects execution of "msdt.exe" using an answer file which is simulating the legitimate way of calling msdt via "pcwrun.exe" (For example from the compatibility tab).
windows
MSHTA Execution with Suspicious File Extensions
highDetects execution of mshta.exe with file types that looks like they do not typically represent HTA (HTML Application) content, such as .png, .jpg, .zip, .pdf, and others, which are often polyglots. MSHTA is a legitimate Windows utility for executing HTML Applications containing VBScript or JScript. Threat actors often abuse this lolbin utility to download and execute malicious scripts disguised as benign files or hosted under misleading extensions to evade detection.
windows
Mshtml.DLL RunHTMLApplication Suspicious Usage
highDetects execution of commands that leverage the "mshtml.dll" RunHTMLApplication export to run arbitrary code via different protocol handlers (vbscript, javascript, file, http...)
windows
Mstsc.EXE Execution From Uncommon Parent
highDetects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
windows
Mustang Panda Dropper
highDetects specific process parameters as used by Mustang Panda droppers
windows
Net WebClient Casing Anomalies
highDetects PowerShell command line contents that include a suspicious abnormal casing in the Net.Webclient (e.g. nEt.WEbCliEnT) string as used in obfuscation techniques
windows
Network Reconnaissance Activity
highDetects a set of suspicious network related commands often used in recon stages
windows
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
highDetects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
windows
New User Created Via Net.EXE With Never Expire Option
highDetects creation of local users via the net.exe command with the option "never expire"
windows
NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE
highDetects the attempt to create an ActiveScriptEventConsumer via WMIC.EXE. An ActiveScriptEventConsumer is a built-in Windows Management Instrumentation (WMI) class that automatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs. Adversaries often abuse ActiveScriptEventConsumer to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.
windows
Non-privileged Usage of Reg or Powershell
highSearch for usage of reg or Powershell by non-privileged users to modify service configuration in registry
windows
NtdllPipe Like Activity Execution
highDetects command that type the content of ntdll.dll to a different file or a pipe in order to evade AV / EDR detection. As seen being used in the POC NtdllPipe
windows
NTLM Hash Leak Via Curl NTLM Authentication
highDetects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused to leak the currently logged-in user's NTLMv2 challenge-response to an attacker-controlled server, enabling offline cracking or relay attacks. When no credentials are provided, the Microsoft-shipped curl passes a NULL identity to Windows SSPI, which automatically falls back to the current user's logon session credentials stored in LSASS — without requiring a plaintext password. This behavior is exclusive to the curl binary shipped by Microsoft (available since Windows 10 / Windows Server 2019), which is built with SSPI support.
windows
Obfuscated PowerShell MSI Install via WindowsInstaller COM
highDetects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`). The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
windows
Obfuscated PowerShell OneLiner Execution
highDetects the execution of a specific OneLiner to download and execute powershell modules in memory.
windows
Odbcconf.EXE Suspicious DLL Location
highDetects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.
windows
OMIGOD SCX RunAsProvider ExecuteScript
highRule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
linux
OMIGOD SCX RunAsProvider ExecuteShellCommand
highRule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
linux
OneNote.EXE Execution of Malicious Embedded Scripts
highDetects the execution of malicious OneNote documents that contain embedded scripts. When a user clicks on a OneNote attachment and then on the malicious link inside the ".one" file, it exports and executes the malicious embedded script from specific directories.
windows
OpenWith.exe Executes Specified Binary
highThe OpenWith.exe executes other binary
windows
Operation Wocao Activity
highDetects activity mentioned in Operation Wocao report
windows
Operator Bloopers Cobalt Strike Commands
highDetects use of Cobalt Strike commands accidentally entered in the CMD shell
windows
Operator Bloopers Cobalt Strike Modules
highDetects Cobalt Strike module/commands accidentally entered in CMD shell
windows
OSACompile Run-Only Execution
highDetects potential suspicious run-only executions compiled using OSACompile
macos
Outlook EnableUnsafeClientMailRules Setting Enabled
highDetects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros
windows
PaperCut MF/NG Exploitation Related Indicators
highDetects exploitation indicators related to PaperCut MF/NG Exploitation
windows
PaperCut MF/NG Potential Exploitation
highDetects suspicious child processes of "pc-app.exe". Which could indicate potential exploitation of PaperCut
windows
Peach Sandstorm APT Process Activity Indicators
highDetects process creation activity related to Peach Sandstorm APT
windows
Phishing Pattern ISO in Archive
highDetects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is a sign of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web)
windows
Pikabot Fake DLL Extension Execution Via Rundll32.EXE
highDetects specific process tree behavior linked to "rundll32" executions, wherein the associated DLL lacks a common ".dll" extension, often signaling potential Pikabot activity.
windows
Ping Hex IP
highDetects a ping command that uses a hex encoded IP address
windows
Pingback Backdoor Activity
highDetects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report
windows
Possible Privilege Escalation via Weak Service Permissions
highDetection of sc.exe utility spawning by user with Medium integrity level to change service ImagePath or FailureCommand
windows
Potential ACTINIUM Persistence Activity
highDetects specific process parameters as used by ACTINIUM scheduled task persistence creation.
windows
Potential Adplus.EXE Abuse
highDetects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.
windows
Potential AMSI Bypass Via .NET Reflection
highDetects Request to "amsiInitFailed" that can be used to disable AMSI Scanning
windows
Potential APT FIN7 Reconnaissance/POWERTRASH Related Activity
highDetects specific command line execution used by FIN7 as reported by WithSecureLabs for reconnaissance and POWERTRASH execution
windows
Potential APT Mustang Panda Activity Against Australian Gov
highDetects specific command line execution used by Mustang Panda in a targeted attack against the Australian government as reported by Lab52
windows
Potential APT10 Cloud Hopper Activity
highDetects potential process and execution activity related to APT10 Cloud Hopper operation
windows
Potential Arbitrary Code Execution Via Node.EXE
highDetects the execution node.exe which is shipped with multiple software such as VMware, Adobe...etc. In order to execute arbitrary code. For example to establish reverse shell as seen in Log4j attacks...etc
windows
Potential Arbitrary Command Execution Using Msdt.EXE
highDetects processes leveraging the "ms-msdt" handler or the "msdt.exe" binary to execute arbitrary commands as seen in the follina (CVE-2022-30190) vulnerability
windows
Potential Arbitrary File Download Using Office Application
highDetects potential arbitrary file download using a Microsoft Office application
windows
Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
highDetects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
windows
Potential Baby Shark Malware Activity
highDetects activity that could be related to Baby Shark malware
windows
Potential Base64 Decoded From Images
highDetects the use of tail to extract bytes at an offset from an image and then decode the base64 value to create a new file with the decoded content. The detected execution is a bash one-liner.
macos
Potential BearLPE Exploitation
highDetects potential exploitation of the BearLPE exploit using Task Scheduler ".job" import arbitrary DACL write\par
windows
Potential BlackByte Ransomware Activity
highDetects command line patterns used by BlackByte ransomware in different operations
windows
Potential CobaltStrike Process Patterns
highDetects potential process patterns related to Cobalt Strike beacon activity
windows
Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
highDetects potential commandline obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
windows
Potential CommandLine Path Traversal Via Cmd.EXE
highDetects potential path traversal attempt via cmd.exe. Could indicate possible command/argument confusion/hijacking
windows
Potential Compromised 3CXDesktopApp Execution
highDetects execution of known compromised version of 3CXDesktopApp
windows
Potential Compromised 3CXDesktopApp Update Activity
highDetects the 3CXDesktopApp updater downloading a known compromised version of the 3CXDesktopApp software
windows
Potential Conti Ransomware Database Dumping Activity Via SQLCmd
highDetects a command used by conti to dump database
windows
Potential Credential Dumping Attempt Using New NetworkProvider - CLI
highDetects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
windows
Potential Credential Dumping Via WER
highDetects potential credential dumping via Windows Error Reporting LSASS Shtinkering technique which uses the Windows Error Reporting to dump lsass
windows
Potential Crypto Mining Activity
highDetects command line parameters or strings often used by crypto miners
windows
Potential CVE-2021-26857 Exploitation Attempt
highDetects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's Unified Messaging service
windows
Potential CVE-2021-40444 Exploitation Attempt
highDetects potential exploitation of CVE-2021-40444 via suspicious process patterns seen in in-the-wild exploitations
windows
Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon
highDetects potential initial exploitation attempts against VMware Horizon deployments running a vulnerable versions of Log4j.
windows
Potential CVE-2022-26809 Exploitation Attempt
highDetects suspicious remote procedure call (RPC) service anomalies based on the spawned sub processes (long shot to detect the exploitation of vulnerabilities like CVE-2022-26809)
windows
Potential CVE-2022-29072 Exploitation Attempt
highDetects potential exploitation attempts of CVE-2022-29072, a 7-Zip privilege escalation and command execution vulnerability. 7-Zip version 21.07 and earlier on Windows allows privilege escalation (CVE-2022-29072) and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process.
windows
Potential CVE-2023-21554 QueueJumper Exploitation
highDetects potential exploitation of CVE-2023-21554 (dubbed QueueJumper)
windows
Potential CVE-2023-36874 Exploitation - Fake Wermgr Execution
highDetects the execution of a renamed "cmd", "powershell" or "powershell_ise" binary. Attackers were seen using these binaries in a renamed form as "wermgr.exe" in exploitation of CVE-2023-36874
windows
Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI
highDetects potential exploitation of CVE-2026-33829, a vulnerability in the Windows Snipping Tool URI handler (ms-screensketch:). An attacker can abuse the 'filePath' parameter to supply a UNC path or HTTP URL, causing SnippingTool.exe to initiate a connection to a remote resource. When a UNC path is used (e.g. \\attacker.com\share), this triggers an outbound NTLM authentication attempt, allowing the attacker to capture or relay the victim's Net-NTLMv2 hash. HTTP-based paths may result in remote file loading or server-side request forgery (SSRF)-style access. The URI can be delivered via a malicious hyperlink, phishing email, or web page.
windows
Potential Data Exfiltration Activity Via CommandLine Tools
highDetects the use of various CLI utilities exfiltrating data via web requests
windows
Potential Data Stealing Via Chromium Headless Debugging
highDetects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control
windows
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
highDetects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
windows
Potential Defense Evasion Via Right-to-Left Override
highDetects the presence of the "u202+E" character, which causes a terminal, browser, or operating system to render text in a right-to-left sequence. This character is used as an obfuscation and masquerading techniques by adversaries to trick users into opening malicious files.
windows
Potential Devil Bait Malware Reconnaissance
highDetects specific process behavior observed with Devil Bait samples
windows
Potential Emotet Activity
highDetects all Emotet like process executions that are not covered by the more generic rules
windows
Potential EmpireMonkey Activity
highDetects potential EmpireMonkey APT activity
windows
Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp
highDetects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.
windows
Potential Exploitation Attempt From Office Application
highDetects Office applications executing a child process that includes directory traversal patterns. This could be an attempt to exploit CVE-2022-30190 (MSDT RCE) or CVE-2021-40444 (MSHTML RCE)
windows
Potential Exploitation Attempt Of Undocumented WindowsServer RCE
highDetects potential exploitation attempt of undocumented Windows Server Pre Auth Remote Code Execution (RCE)
windows
Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
highDetects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
windows
Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process
highDetects potentially suspicious child process of SSH process (sshd) with a specific execution user. This could be a sign of potential exploitation of CVE-2024-3094.
linux
Potential Exploitation of CVE-2024-37085 - Suspicious Creation Of ESX Admins Group
highDetects execution of the "net.exe" command in order to add a group named "ESX Admins". This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor. VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
windows
Potential Exploitation of GoAnywhere MFT Vulnerability
highDetects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035. This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
windows
Potential Exploitation of RCE Vulnerability CVE-2025-33053
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 which involves unauthorized code execution via WebDAV through external control of file names or paths. The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating their working directories to point to attacker-controlled WebDAV servers, causing them to execute malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries through Process.Start() search order manipulation.
windows
Potential File Overwrite Via Sysinternals SDelete
highDetects the use of SDelete to erase a file not the free space
windows
Potential GobRAT File Discovery Via Grep
highDetects the use of grep to discover specific files created by the GobRAT malware
linux
Potential Goofy Guineapig Backdoor Activity
highDetects a specific broken command that was used by Goofy-Guineapig as described by the NCSC report.
windows
Potential Goofy Guineapig GoolgeUpdate Process Anomaly
highDetects "GoogleUpdate.exe" spawning a new instance of itself in an uncommon location as seen used by the Goofy Guineapig backdoor
windows
Potential Ke3chang/TidePool Malware Activity
highDetects registry modifications potentially related to the Ke3chang/TidePool malware as seen in campaigns running in 2019 and 2020
windows
Potential LethalHTA Technique Execution
highDetects potential LethalHTA technique where the "mshta.exe" is spawned by an "svchost.exe" process
windows
Potential LSASS Process Dump Via Procdump
highDetects potential credential harvesting attempts through LSASS memory dumps using ProcDump. This rule identifies suspicious command-line patterns that combine memory dump flags (-ma, -mm, -mp) with LSASS-related process markers. LSASS (Local Security Authority Subsystem Service) contains sensitive authentication data including plaintext passwords, NTLM hashes, and Kerberos tickets in memory. Attackers commonly dump LSASS memory to extract credentials for lateral movement and privilege escalation.
windows
Potential Manage-bde.wsf Abuse To Proxy Execution
highDetects potential abuse of the "manage-bde.wsf" script as a LOLBIN to proxy execution
windows
Potential Meterpreter/CobaltStrike Activity
highDetects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service starting
windows
Potential Mpclient.DLL Sideloading Via Defender Binaries
highDetects potential sideloading of "mpclient.dll" by Windows Defender processes ("MpCmdRun" and "NisSrv") from their non-default directory.
windows
Potential MsiExec Masquerading
highDetects the execution of msiexec.exe from an uncommon directory
windows
Potential MSTSC Shadowing Activity
highDetects RDP session hijacking by using MSTSC shadowing
windows
Potential MuddyWater APT Activity
highDetects potential Muddywater APT activity
windows
Potential Netcat Reverse Shell Execution
highDetects execution of netcat with the "-e" flag followed by common shells. This could be a sign of a potential reverse shell setup.
linux
Potential Notepad++ CVE-2025-49144 Exploitation
highDetects potential exploitation of CVE-2025-49144, a local privilege escalation vulnerability in Notepad++ installers (v8.8.1 and prior) where the installer calls regsvr32.exe without specifying the full path. This allows an attacker to execute arbitrary code with elevated privileges by placing a malicious regsvr32.exe alongside this Legitimate Notepad++ installer. The vulnerability is triggered when the installer attempts to register the NppShell.dll file, which is a component of Notepad++.
windows
Potential NTLM Coercion Via Certutil.EXE
highDetects possible NTLM coercion via certutil using the 'syncwithWU' flag
windows
Potential Perl Reverse Shell Execution
highDetects execution of the perl binary with the "-e" flag and common strings related to potential reverse shell activity
linux
Potential Persistence Via Logon Scripts - CommandLine
highDetects the addition of a new LogonScript to the registry value "UserInitMprLogonScript" for potential persistence
windows
Potential Persistence Via PlistBuddy
highDetects potential persistence activity using LaunchAgents or LaunchDaemons via the PlistBuddy utility
macos
Potential Persistence Via Powershell Search Order Hijacking - Task
highDetects suspicious powershell execution via a schedule task where the command ends with an suspicious flags to hide the powershell instance instead of executeing scripts or commands. This could be a sign of persistence via PowerShell "Get-Variable" technique as seen being used in Colibri Loader
windows
Potential PHP Reverse Shell
highDetects usage of the PHP CLI with the "-r" flag which allows it to run inline PHP code. The rule looks for calls to the "fsockopen" function which allows the creation of sockets. Attackers often leverage this in combination with functions such as "exec" or "fopen" to initiate a reverse shell connection.
linux
Potential Pikabot Discovery Activity
highDetects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups. The malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).
windows
Potential Pikabot Hollowing Activity
highDetects the execution of rundll32 that leads to the invocation of legitimate Windows binaries. The malware Pikabot has been seen to use this technique for process hollowing through hard-coded Windows binaries
windows
Potential PlugX Activity
highDetects the execution of an executable that is typically used by PlugX for DLL side loading starting from an uncommon location
windows
Potential PowerShell Command Line Obfuscation
highDetects the PowerShell command lines with special characters
windows
Potential PowerShell Execution Policy Tampering - ProcCreation
highDetects changes to the PowerShell execution policy registry key in order to bypass signing requirements for script execution from the CommandLine
windows
Potential PowerShell Execution Via DLL
highDetects potential PowerShell execution from a DLL instead of the usual PowerShell process as seen used in PowerShdll. This detection assumes that PowerShell commands are passed via the CommandLine.
windows
Potential PowerShell Obfuscation Via Reversed Commands
highDetects the presence of reversed PowerShell commands in the CommandLine. This is often used as a method of obfuscation by attackers
windows
Potential PowerShell Obfuscation Via WCHAR/CHAR
highDetects suspicious encoded character syntax often used for defense evasion
windows
Potential Powershell ReverseShell Connection
highDetects usage of the "TcpClient" class. Which can be abused to establish remote connections and reverse-shells. As seen used by the Nishang "Invoke-PowerShellTcpOneLine" reverse shell and other.
windows
Potential Privilege Escalation To LOCAL SYSTEM
highDetects unknown program using commandline flags usually used by tools such as PsExec and PAExec to start programs with SYSTEM Privileges
windows
Potential Privilege Escalation Using Symlink Between Osk and Cmd
highDetects the creation of a symbolic link between "cmd.exe" and the accessibility on-screen keyboard binary (osk.exe) using "mklink". This technique provides an elevated command prompt to the user from the login screen without the need to log in.
windows
Potential Privilege Escalation via Service Permissions Weakness
highDetect modification of services configuration (ImagePath, FailureCommand and ServiceDLL) in registry by processes with Medium integrity level
windows
Potential Process Injection Via Msra.EXE
highDetects potential process injection via Microsoft Remote Asssistance (Msra.exe) by looking at suspicious child processes spawned from the aforementioned process. It has been a target used by many threat actors and used for discovery and persistence tactics
windows
Potential Provisioning Registry Key Abuse For Binary Proxy Execution
highDetects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".
windows
Potential PsExec Remote Execution
highDetects potential psexec command that initiate execution on a remote systems via common commandline flags used by the utility
windows
Potential Qakbot Rundll32 Execution
highDetects specific process tree behavior of a "rundll32" execution often linked with potential Qakbot activity.
windows
Potential Raspberry Robin CPL Execution Activity
highDetects the execution of a ".CPL" file located in the user temp directory via the Shell32 DLL "Control_RunDLL" export function. This behavior was observed in multiple Raspberry-Robin variants.
windows
Potential Raspberry Robin Dot Ending File
highDetects commandline containing reference to files ending with a "." This scheme has been seen used by raspberry-robin
windows
Potential RDP Tunneling Via Plink
highExecution of plink to perform data exfiltration and tunneling
windows
Potential RDP Tunneling Via SSH
highExecution of ssh.exe to perform data exfiltration and tunneling through RDP
windows
Potential Recon Activity Using DriverQuery.EXE
highDetect usage of the "driverquery" utility to perform reconnaissance on installed drivers
windows
Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE
highDetects usage of cmdkey to look for cached credentials on the system
windows
Potential Remote SquiblyTwo Technique Execution
highDetects potential execution of the SquiblyTwo technique that leverages Windows Management Instrumentation (WMI) to execute malicious code remotely. This technique bypasses application whitelisting by using wmic.exe to process malicious XSL (eXtensible Stylesheet Language) scripts that can contain embedded JScript or VBScript. The attack typically works by fetching XSL content from a remote source (using HTTP/HTTPS) and executing it with full trust privileges directly in memory, avoiding disk-based detection mechanisms. This is a common LOLBin (Living Off The Land Binary) technique used for defense evasion and code execution.
windows
Potential Renamed Rundll32 Execution
highDetects when 'DllRegisterServer' is called in the commandline and the image is not rundll32. This could mean that the 'rundll32' utility has been renamed in order to avoid detection
windows
Potential Rundll32 Execution With DLL Stored In ADS
highDetects execution of rundll32 where the DLL being called is stored in an Alternate Data Stream (ADS).
windows
Potential Ryuk Ransomware Activity
highDetects Ryuk ransomware activity
windows
Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
highDetects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
windows
Potential Signing Bypass Via Windows Developer Features
highDetects when a user enable developer features such as "Developer Mode" or "Application Sideloading". Which allows the user to install untrusted packages.
windows
Potential SNAKE Malware Installation Binary Indicator
highDetects a specific binary name seen used by SNAKE malware during its installation as described by CISA in their report
windows
Potential SNAKE Malware Installation CLI Arguments Indicator
highDetects a specific command line arguments sequence seen used by SNAKE malware during its installation as described by CISA in their report
windows
Potential SNAKE Malware Persistence Service Execution
highDetects a specific child/parent process relationship indicative of a "WerFault" process running from the "WinSxS" as a service. This could be indicative of potential SNAKE malware activity as reported by CISA.
windows
Potential Snatch Ransomware Activity
highDetects specific process characteristics of Snatch ransomware word document droppers
windows
Potential SSH Tunnel Persistence Install Using A Scheduled Task
highDetects the creation of new scheduled tasks via commandline, using Schtasks.exe. This rule detects tasks creating that call OpenSSH, which may indicate the creation of reverse SSH tunnel to the attacker's server.
windows
Potential Suspicious Child Process Of 3CXDesktopApp
highDetects potential suspicious child processes of "3CXDesktopApp.exe". Which could be related to the 3CXDesktopApp supply chain compromise
windows
Potential SysInternals ProcDump Evasion
highDetects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name
windows
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
highDetects the execution of "reg.exe" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\Control\Terminal Server' values
windows
Potential Tampering With Security Products Via WMIC
highDetects uninstallation or termination of security products using the WMIC utility
windows
Potential WinAPI Calls Via CommandLine
highDetects the use of WinAPI Functions via the commandline. As seen used by threat actors via the tool winapiexec
windows
Potential Windows Defender AV Bypass Via Dump64.EXE Rename
highDetects when a user is potentially trying to bypass the Windows Defender AV by renaming a tool to dump64.exe and placing it in the Visual Studio folder. Currently the rule is covering only usage of procdump but other utilities can be added in order to increase coverage.
windows
Potential Windows Defender Tampering Via Wmic.EXE
highDetects potential tampering with Windows Defender settings such as adding exclusion using wmic
windows
Potential WizardUpdate Malware Infection
highDetects the execution traces of the WizardUpdate malware. WizardUpdate is a macOS trojan that attempts to infiltrate macOS machines to steal data and it is associated with other types of malicious payloads, increasing the chances of multiple infections on a device.
macos
Potentially Suspicious ASP.NET Compilation Via AspNetCompiler
highDetects execution of "aspnet_compiler.exe" with potentially suspicious paths for compilation.
windows
Potentially Suspicious Call To Win32_NTEventlogFile Class
highDetects usage of the WMI class "Win32_NTEventlogFile" in a potentially suspicious way (delete, backup, change permissions, etc.) from a PowerShell script
windows
Potentially Suspicious Child Process Of Regsvr32
highDetects potentially suspicious child processes of "regsvr32.exe".
windows
Potentially Suspicious Child Processes Spawned by ConHost
highDetects suspicious child processes related to Windows Shell utilities spawned by `conhost.exe`, which could indicate malicious activity using trusted system components.
windows
Potentially Suspicious DLL Registered Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "REGSVR" action where the DLL in question doesn't contain a ".dll" extension. Which is often used as a method to evade defenses.
windows
Potentially Suspicious Event Viewer Child Process
highDetects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt
windows
Potentially Suspicious Execution From Parent Process In Public Folder
highDetects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.
windows
Potentially Suspicious File Download From File Sharing Domain Via PowerShell.EXE
highDetects potentially suspicious file downloads from file sharing domains using PowerShell.exe
windows
Potentially Suspicious GoogleUpdate Child Process
highDetects potentially suspicious child processes of "GoogleUpdate.exe"
windows
Potentially Suspicious Mofcomp Execution
highDetects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline. The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Attackers abuse this utility to install malicious MOF scripts
windows
Potentially Suspicious Office Document Executed From Trusted Location
highDetects the execution of an Office application that points to a document that is located in a trusted location. Attackers often used this to avoid macro security and execute their malicious code.
windows
Potentially Suspicious Regsvr32 HTTP IP Pattern
highDetects regsvr32 execution to download and install DLLs located remotely where the address is an IP address.
windows
PowerShell Base64 Encoded FromBase64String Cmdlet
highDetects usage of a base64 encoded "FromBase64String" cmdlet in a process command line
windows
PowerShell Base64 Encoded IEX Cmdlet
highDetects usage of a base64 encoded "IEX" cmdlet in a process command line
windows
PowerShell Base64 Encoded Invoke Keyword
highDetects UTF-8 and UTF-16 Base64 encoded powershell 'Invoke-' calls
windows
Powershell Base64 Encoded MpPreference Cmdlet
highDetects base64 encoded "MpPreference" PowerShell cmdlet code that tries to modifies or tamper with Windows Defender AV
windows
PowerShell Base64 Encoded Reflective Assembly Load
highDetects base64 encoded .NET reflective loading of Assembly
windows
PowerShell Base64 Encoded WMI Classes
highDetects calls to base64 encoded WMI class such as "Win32_ShadowCopy", "Win32_ScheduledJob", etc.
windows
Powershell Defender Disable Scan Feature
highDetects requests to disable Microsoft Defender features using PowerShell commands
windows
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
highDetects the use of PowerShell to execute the 'Set-MpPreference' cmdlet to configure Windows Defender's threat severity default action to 'Allow' (value '6') or 'NoAction' (value '9'). This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level. An attacker might use this technique via the command line to bypass defenses before executing payloads.
windows
PowerShell Download and Execution Cradles
highDetects PowerShell download and execution cradles.
windows
PowerShell Execution With Potential Decryption Capabilities
highDetects PowerShell commands that decrypt an ".LNK" "file to drop the next stage of the malware.
windows
PowerShell Get-Process LSASS
highDetects a "Get-Process" cmdlet and it's aliases on lsass process, which is in almost all cases a sign of malicious activity
windows
PowerShell SAM Copy
highDetects suspicious PowerShell scripts accessing SAM hives
windows
PowerShell Script Change Permission Via Set-Acl
highDetects PowerShell execution to set the ACL of a file or a folder
windows
PowerShell Set-Acl On Windows Folder
highDetects PowerShell scripts to set the ACL to a file in the Windows folder
windows
Powershell Token Obfuscation - Process Creation
highDetects TOKEN OBFUSCATION technique from Invoke-Obfuscation
windows
PowerShell Web Access Feature Enabled Via DISM
highDetects the use of DISM to enable the PowerShell Web Access feature, which could be used for remote access and potential abuse
windows
PPL Tampering Via WerFaultSecure
highDetects potential abuse of WerFaultSecure.exe to dump Protected Process Light (PPL) processes like LSASS or to freeze security solutions (EDR/antivirus). This technique is used by tools such as EDR-Freeze and WSASS to bypass PPL protections and access sensitive information or disable security software. Distinct command line patterns help identify the specific tool: - WSASS usage typically shows: "WSASS.exe WerFaultSecure.exe [PID]" in ParentCommandLine - EDR-Freeze usage typically shows: "EDR-Freeze_[version].exe [PID] [timeout]" in ParentCommandLine Legitimate debugging operations using WerFaultSecure are rare in production environments and should be investigated.
windows
PrintBrm ZIP Creation of Extraction
highDetects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.
windows
Privilege Escalation via Named Pipe Impersonation
highDetects a remote file copy attempt to a hidden network share. This may indicate lateral movement or data staging activity.
windows
Process Access via TrolleyExpress Exclusion
highDetects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory
windows
Process Execution From A Potentially Suspicious Folder
highDetects a potentially suspicious execution from an uncommon folder.
windows
Process Execution From Shared Memory Directory
highDetects the execution of a binary from the Linux shared memory directory /dev/shm. This directory is a tmpfs mount backed entirely by RAM and is abused by attackers for fileless malware staging because files written there never touch physical disk and may evade disk-based detection.
linux
Process Memory Dump Via Comsvcs.DLL
highDetects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)
windows
Process Memory Dump via RdrLeakDiag.EXE
highDetects the use of the Microsoft Windows Resource Leak Diagnostic tool "rdrleakdiag.exe" to dump process memory
windows
Proxy Execution Via Wuauclt.EXE
highDetects the use of the Windows Update Client binary (wuauclt.exe) for proxy execution.
windows
Ps.exe Renamed SysInternals Tool
highDetects renamed SysInternals tool execution with a binary named ps.exe as used by Dragonfly APT group and documented in TA17-293A report
windows
PsExec Service Child Process Execution as LOCAL SYSTEM
highDetects suspicious launch of the PSEXESVC service on this system and a sub process run as LOCAL_SYSTEM (-s), which means that someone remotely started a command on this system running it with highest privileges and not only the privileges of the login user account (e.g. the administrator account)
windows
PsExec/PAExec Escalation to LOCAL SYSTEM
highDetects suspicious commandline flags used by PsExec and PAExec to escalate a command line to LOCAL_SYSTEM rights
windows
PUA - 3Proxy Execution
highDetects the use of 3proxy, a tiny free proxy server
windows
PUA - AdFind Suspicious Execution
highDetects AdFind execution with common flags seen used during attacks
windows
PUA - AdvancedRun Suspicious Execution
highDetects the execution of AdvancedRun utility in the context of the TrustedInstaller, SYSTEM, Local Service or Network Service accounts
windows
PUA - Chisel Tunneling Tool Execution
highDetects usage of the Chisel tunneling tool via the commandline arguments
windows
PUA - CleanWipe Execution
highDetects the use of CleanWipe a tool usually used to delete Symantec antivirus.
windows
PUA - Crassus Execution
highDetects Crassus, a Windows privilege escalation discovery tool, based on PE metadata characteristics.
windows
PUA - CsExec Execution
highDetects the use of the lesser known remote execution tool named CsExec a PsExec alternative
windows
PUA - DefenderCheck Execution
highDetects the use of DefenderCheck, a tool to evaluate the signatures used in Microsoft Defender. It can be used to figure out the strings / byte chains used in Microsoft Defender to detect a tool and thus used for AV evasion.
windows
PUA - DIT Snapshot Viewer
highDetects the use of Ditsnap tool, an inspection tool for Active Directory database, ntds.dit.
windows
PUA - Fast Reverse Proxy (FRP) Execution
highDetects the use of Fast Reverse Proxy. frp is a fast reverse proxy to help you expose a local server behind a NAT or firewall to the Internet.
windows
PUA - Kernel Driver Utility (KDU) Execution
highDetects execution of the Kernel Driver Utility (KDU) tool. KDU can be used to bypass driver signature enforcement and load unsigned or malicious drivers into the Windows kernel. Potentially allowing for privilege escalation, persistence, or evasion of security controls.
windows
PUA - Memory Dump Mount Via MemProcFS
highDetects execution of MemProcFS a memory forensics tool with the '-device' parameter. MemProcFS mounts physical memory as a virtual file system, allowing direct access to process memory and system structures. Threat actors were seen abusing this utility to mount memory dumps and then extract sensitive information from processes like LSASS or extract registry hives to obtain credentials, LSA secrets, SAM data, and cached domain credentials. MemProcFS usage that is not part of authorized forensic analysis should be treated as suspicious and warrants further investigation.
windows
PUA - Netcat Suspicious Execution
highDetects execution of Netcat. Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
windows
PUA - Ngrok Execution
highDetects the use of Ngrok, a utility used for port forwarding and tunneling, often used by threat actors to make local protected services publicly available. Involved domains are bin.equinox.io for download and *.ngrok.io for connections.
windows
PUA - Nimgrab Execution
highDetects the usage of nimgrab, a tool bundled with the Nim programming framework and used for downloading files.
windows
PUA - NirCmd Execution As LOCAL SYSTEM
highDetects the use of NirCmd tool for command execution as SYSTEM user
windows
PUA - NPS Tunneling Tool Execution
highDetects the use of NPS, a port forwarding and intranet penetration proxy server
windows
PUA - NSudo Execution
highDetects the use of NSudo tool for command execution
windows
PUA - PingCastle Execution From Potentially Suspicious Parent
highDetects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level via a script located in a potentially suspicious or uncommon location.
windows
PUA - Rclone Execution
highDetects execution of RClone utility for exfiltration as used by various ransomwares strains like REvil, Conti, FiveHands, etc
windows
PUA - Restic Backup Tool Execution
highDetects the execution of the Restic backup tool, which can be used for data exfiltration. Threat actors may leverage Restic to back up and exfiltrate sensitive data to remote storage locations, including cloud services. If not legitimately used in the enterprise environment, its presence may indicate malicious activity.
windows
PUA - RunXCmd Execution
highDetects the use of the RunXCmd tool to execute commands with System or TrustedInstaller accounts
windows
PUA - Seatbelt Execution
highDetects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters
windows
PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE
highDetects active directory enumeration activity using known AdFind CLI flags
windows
PUA - Wsudo Suspicious Execution
highDetects usage of wsudo (Windows Sudo Utility). Which is a tool that let the user execute programs with different permissions (System, Trusted Installer, Administrator...etc)
windows
PUA- IOX Tunneling Tool Execution
highDetects the use of IOX - a tool for port forwarding and intranet proxy purposes
windows
Python Function Execution Security Warning Disabled In Excel
highDetects changes to the registry value "PythonFunctionWarnings" that would prevent any warnings or alerts from showing when Python functions are about to be executed. Threat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.
windows
Python One-Liners with Base64 Decoding
highDetects Python one-liners that use base64 decoding functions in command line executions. Malicious scripts or attackers often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.
windows
Python One-Liners with Base64 Decoding - Linux
highDetects the use of Python's base64 decoding functions in command line executions on Linux systems. Malicious scripts often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.
linux
Python Reverse Shell Execution Via PTY And Socket Modules
highDetects the execution of python with calls to the socket and pty module in order to connect and spawn a potential reverse shell.
linux
Python Spawning Pretty TTY on Windows
highDetects python spawning a pretty tty
windows
Qakbot Regsvr32 Calc Pattern
highDetects a specific command line of "regsvr32" where the "calc" keyword is used in conjunction with the "/s" flag. This behavior is often seen used by Qakbot
windows
Qakbot Uninstaller Execution
highDetects the execution of the Qakbot uninstaller file mentioned in the USAO-CDCA document on the disruption of the Qakbot malware and botnet
windows
Raccine Uninstall
highDetects commands that indicate a Raccine removal from an end system. Raccine is a free ransomware protection tool.
windows
Rar Usage with Password and Compression Level
highDetects the use of rar.exe, on the command line, to create an archive with password protection or with a specific compression level. This is pretty indicative of malicious actions.
windows
Raspberry Robin Initial Execution From External Drive
highDetects the initial execution of the Raspberry Robin malware from an external drive using "Cmd.EXE".
windows
Raspberry Robin Subsequent Execution of Commands
highDetects raspberry robin subsequent execution of commands.
windows
RDP Connection Allowed Via Netsh.EXE
highDetects usage of the netsh command to open and allow connections to port 3389 (RDP). As seen used by Sarwent Malware
windows
RDP Port Forwarding Rule Added Via Netsh.EXE
highDetects the execution of netsh to configure a port forwarding of port 3389 (RDP) rule
windows
RedSun - Conhost.exe Spawned by TieringEngineService.exe
highDetects two stages of the RedSun post-exploitation process chain that deliver a SYSTEM-level shell to the attacker's interactive session. Observed process chain services.exe → TieringEngineService.exe → conhost.exe (SYSTEM, CommandLine: bare path, no arguments) → cmd.exe / shell (SYSTEM, TerminalSessionId = attacker's session) Stage 1 — TieringEngineService.exe spawns argument-less conhost.exe: After winning the oplock + Cloud Files mount point race, the malicious TieringEngineService.exe (RedSun.exe copied to System32, started via CoCreateInstance / services.exe) detects it is NT AUTHORITY\SYSTEM and calls LaunchConsoleInSessionId(). This opens \\.\pipe\REDSUN, reads the attacker's session ID, duplicates the SYSTEM token, re-stamps it with that session ID via SetTokenInformation(TokenSessionId), then calls CreateProcessAsUser to spawn conhost.exe with no arguments. Stage 2 — Shell spawned from rogue conhost.exe (EDR sources with GrandParentImage): The rogue SYSTEM conhost.exe spawns a shell (cmd.exe, PowerShell, etc.) as SYSTEM in the attacker's interactive session. On EDR sources that expose GrandParentImage, the full three-level chain (TieringEngineService.exe → conhost.exe → shell) can be matched directly. The legitimate TieringEngineService.exe is a headless COM server that is unlikely to spawn conhost.exe under normal conditions.
windows
Reg Add Suspicious Paths
highDetects when an adversary uses the reg.exe utility to add or modify new keys or subkeys
windows
Regedit as Trusted Installer
highDetects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
windows
Registry Export of Third-Party Credentials
highDetects the use of reg.exe to export registry paths associated with third-party credentials. Credential stealers have been known to use this technique to extract sensitive information from the registry.
windows
Regsvr32 DLL Execution With Suspicious File Extension
highDetects the execution of REGSVR32.exe with DLL files masquerading as other files
windows
Regsvr32 Execution From Highly Suspicious Location
highDetects execution of regsvr32 where the DLL is located in a highly suspicious locations
windows
Remote Access Tool - Anydesk Execution From Suspicious Folder
highAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Access Tool - AnyDesk Silent Installation
highDetects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.
windows
Remote Access Tool - Renamed MeshAgent Execution - MacOS
highDetects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
macos
Remote Access Tool - Renamed MeshAgent Execution - Windows
highDetects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
windows
Remote Access Tool - ScreenConnect Server Web Shell Execution
highDetects potential web shell execution from the ScreenConnect server process.
windows
Remote CHM File Download/Execution Via HH.EXE
highDetects the usage of "hh.exe" to execute/download remotely hosted ".chm" files.
windows
Remote XSL Execution Via Msxsl.EXE
highDetects the execution of the "msxsl" binary with an "http" keyword in the command line. This might indicate a potential remote execution of XSL files.
windows
RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
highDetects calls to the AtomicTestHarnesses "Invoke-ATHRemoteFXvGPUDisablementCommand" which is designed to abuse the "RemoteFXvGPUDisablement.exe" binary to run custom PowerShell code via module load-order hijacking.
windows
Remotely Hosted HTA File Executed Via Mshta.EXE
highDetects execution of the "mshta" utility with an argument containing the "http" keyword, which could indicate that an attacker is executing a remotely hosted malicious hta file
windows
Renamed AdFind Execution
highDetects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.
windows
Renamed AutoIt Execution
highDetects the execution of a renamed AutoIt2.exe or AutoIt3.exe. AutoIt is a scripting language and automation tool for Windows systems. While primarily used for legitimate automation tasks, it can be misused in cyber attacks. Attackers can leverage AutoIt to create and distribute malware, including keyloggers, spyware, and botnets. A renamed AutoIt executable is particularly suspicious.
windows
Renamed BrowserCore.EXE Execution
highDetects process creation with a renamed BrowserCore.exe (used to extract Azure tokens)
windows
Renamed Cloudflared.EXE Execution
highDetects the execution of a renamed "cloudflared" binary.
windows
Renamed CreateDump Utility Execution
highDetects uses of a renamed legitimate createdump.exe LOLOBIN utility to dump process memory
windows
Renamed Gpg.EXE Execution
highDetects the execution of a renamed "gpg.exe". Often used by ransomware and loaders to decrypt/encrypt data.
windows
Renamed Jusched.EXE Execution
highDetects the execution of a renamed "jusched.exe" as seen used by the cobalt group
windows
Renamed Mavinject.EXE Execution
highDetects the execution of a renamed version of the "Mavinject" process. Which can be abused to perform process injection using the "/INJECTRUNNING" flag
windows
Renamed MegaSync Execution
highDetects the execution of a renamed MegaSync.exe as seen used by ransomware families like Nefilim, Sodinokibi, Pysa, and Conti.
windows
Renamed Msdt.EXE Execution
highDetects the execution of a renamed "Msdt.exe" binary
windows
Renamed NetSupport RAT Execution
highDetects the execution of a renamed "client32.exe" (NetSupport RAT) via Imphash, Product and OriginalFileName strings
windows
Renamed NirCmd.EXE Execution
highDetects the execution of a renamed "NirCmd.exe" binary based on the PE metadata fields.
windows
Renamed Office Binary Execution
highDetects the execution of a renamed office binary
windows
Renamed PAExec Execution
highDetects execution of renamed version of PAExec. Often used by attackers
windows
Renamed PingCastle Binary Execution
highDetects the execution of a renamed "PingCastle" binary based on the PE metadata fields.
windows
Renamed Plink Execution
highDetects the execution of a renamed version of the Plink binary
windows
Renamed ProcDump Execution
highDetects the execution of a renamed ProcDump executable. This often done by attackers or malware in order to evade defensive mechanisms.
windows
Renamed PsExec Service Execution
highDetects suspicious launch of a renamed version of the PSEXESVC service with, which is not often used by legitimate administrators
windows
Renamed Schtasks Execution
highDetects the execution of renamed schtasks.exe binary, which is a legitimate Windows utility used for scheduling tasks. One of the very common persistence techniques is schedule malicious tasks using schtasks.exe. Since, it is heavily abused, it is also heavily monitored by security products. To evade detection, threat actors may rename the schtasks.exe binary to schedule their malicious tasks.
windows
Renamed SysInternals DebugView Execution
highDetects suspicious renamed SysInternals DebugView execution
windows
Renamed Sysinternals Sdelete Execution
highDetects the use of a renamed SysInternals Sdelete, which is something an administrator shouldn't do (the renaming)
windows
Renamed Visual Studio Code Tunnel Execution
highDetects renamed Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows
Renamed Vmnat.exe Execution
highDetects renamed vmnat.exe or portable version that can be used for DLL side-loading
windows
Renamed ZOHO Dctask64 Execution
highDetects a renamed "dctask64.exe" execution, a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.
windows
RestrictedAdminMode Registry Value Tampering - ProcCreation
highDetects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise
windows
Root Certificate Installed From Susp Locations
highAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows
Run PowerShell Script from ADS
highDetects PowerShell script execution from Alternate Data Stream (ADS)
windows
Run PowerShell Script from Redirected Input Stream
highDetects PowerShell script execution via input stream redirect
windows
Rundll32 Execution Without CommandLine Parameters
highDetects suspicious start of rundll32.exe without any parameters as found in CobaltStrike beacon activity
windows
Rundll32 Execution Without Parameters
highDetects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
windows
Rundll32 Registered COM Objects
highload malicious registered COM objects
windows
RunDLL32 Spawning Explorer
highDetects RunDLL32.exe spawning explorer.exe as child, which is very uncommon, often observes Gamarue spawning the explorer.exe process in an unusual way
windows
Rundll32 UNC Path Execution
highDetects rundll32 execution where the DLL is located on a remote location (share). Threat actors can abuse the rundll32.exe binary to execute remote DLLs from a UNC pathh.
windows
RunMRU Registry Key Deletion
highDetects deletion of the RunMRU registry key, which stores the history of commands executed via the Run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.
windows
SafeBoot Registry Key Deleted Via Reg.EXE
highDetects execution of "reg.exe" commands with the "delete" flag on safe boot registry keys. Often used by attacker to prevent safeboot execution of security products
windows
Scheduled Task Creation Masquerading as System Processes
highDetects the creation of scheduled tasks that involve system processes, which may indicate malicious actors masquerading as or abusing these processes to execute payloads or maintain persistence.
windows
Scheduled Task Executing Encoded Payload from Registry
highDetects the creation of a schtask that potentially executes a base64 encoded payload stored in the Windows Registry using PowerShell.
windows
Schtasks Creation Or Modification With SYSTEM Privileges
highDetects the creation or update of a scheduled task to run with "NT AUTHORITY\SYSTEM" privileges
windows
Schtasks From Suspicious Folders
highDetects scheduled task creations that have suspicious action command and folder combinations
windows
Script Event Consumer Spawning Process
highDetects a suspicious child process of Script Event Consumer (scrcons.exe).
windows
Script Interpreter Execution From Suspicious Folder
highDetects suspicious script execution from suspicious directories or folders accessible by environment variables that may indicate malware activity. Script interpreters (cscript, wscript, mshta, powershell) executing from folders like Temp, Public, or user profile directories may suggest attempts to evade detection or execute malicious scripts.
windows
Script Interpreter Spawning Credential Scanner - Linux
highDetects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
linux
Script Interpreter Spawning Credential Scanner - Windows
highDetects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
windows
Sdiagnhost Calling Suspicious Child Process
highDetects sdiagnhost.exe calling a suspicious child process (e.g. used in exploits for Follina / CVE-2022-30190)
windows
Security Event Logging Disabled via MiniNt Registry Key - Process
highDetects attempts to disable security event logging by adding the `MiniNt` registry key. This key is used to disable the Windows Event Log service, which collects and stores event logs from the operating system and applications. Adversaries may want to disable this service to prevent logging of security events that could be used to detect their activities.
windows
Security Privileges Enumeration Via Whoami.EXE
highDetects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privileges. This is often used after a privilege escalation attempt.
windows
Security Service Disabled Via Reg.EXE
highDetects execution of "reg.exe" to disable security services such as Windows Defender.
windows
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
highDetects the use of iexpress.exe to create binaries via Self Extraction Directive (SED) files located in potentially suspicious locations. This behavior has been observed in-the-wild by different threat actors.
windows
Sensitive File Access Via Volume Shadow Copy Backup
highDetects a command that accesses the VolumeShadowCopy in order to extract sensitive files such as the Security or SAM registry hives or the AD database (ntds.dit)
windows
Sensitive File Dump Via Print.EXE
highDetects the abuse of the Print.exe utility for credential harvesting which involves using Print.Exe to copy sensitive files such as ntds.dit, SAM, SECURITY, or SYSTEM from the Windows directory in order to extract credentials, locally or remotely.
windows
Sensitive File Dump Via Wbadmin.EXE
highDetects the dump of highly sensitive files such as "NTDS.DIT" and "SECURITY" hive. Attackers can leverage the "wbadmin" utility in order to dump sensitive files that might contain credential or sensitive information.
windows
Sensitive File Recovery From Backup Via Wbadmin.EXE
highDetects the dump of highly sensitive files such as "NTDS.DIT" and "SECURITY" hive. Attackers can leverage the "wbadmin" utility in order to dump sensitive files that might contain credential or sensitive information.
windows
Serpent Backdoor Payload Execution Via Scheduled Task
highDetects post exploitation execution technique of the Serpent backdoor. According to Proofpoint, one of the commands that the backdoor ran was via creating a temporary scheduled task using an unusual method. It creates a fictitious windows event and a trigger in which once the event is created, it executes the payload.
windows
Service DACL Abuse To Hide Services Via Sc.EXE
highDetects usage of the "sc.exe" utility adding a new service with special permission seen used by threat actors which makes the service hidden and unremovable.
windows
Service Registry Key Deleted Via Reg.EXE
highDetects execution of "reg.exe" commands with the "delete" flag on services registry key. Often used by attacker to remove AV software services
windows
Set Suspicious Files as System Files Using Attrib.EXE
highDetects the usage of attrib with the "+s" option to set scripts or executables located in suspicious locations as system files to hide them from users and make them unable to be deleted with simple rights. The rule limits the search to specific extensions and directories to avoid FPs
windows
Shadow Copies Deletion Using Operating Systems Utilities
highShadow Copies deletion using operating systems utilities
windows
Shai-Hulud 2.0 Malicious NPM Package Installation
highDetects the command-line installation of specific malicious npm packages and versions associated with the Shai-Hulud 2.0 supply chain attack.
windows
Shai-Hulud 2.0 Malicious NPM Package Installation - Linux
highDetects the command-line installation of specific malicious npm packages and versions associated with the Shai-Hulud 2.0 supply chain attack.
linux
Shai-Hulud Malicious Bun Execution
highDetects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
windows
Shai-Hulud Malicious Bun Execution - Linux
highDetects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
linux
Shai-Hulud Malware Indicators - Linux
highDetects potential Shai-Hulud malware indicators based on specific command line arguments associated with its execution.
linux
Shai-Hulud Malware Indicators - Windows
highDetects potential Shai-Hulud malware indicators based on specific command line arguments associated with its execution.
windows
Shai-Hulud NPM Package Malicious Exfiltration via Curl
highDetects potential Shai Hulud NPM package attack attempting to exfiltrate data via curl to external webhook sites.
linux
Shell Execution GCC - Linux
highDetects the use of the "gcc" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Shell Execution Of Process Located In Tmp Directory
highDetects execution of shells from a parent process located in a temporary (/tmp) directory
linux
Shell Execution via Find - Linux
highDetects the use of the find command to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or exploitation attempt.
linux
Shell Execution via Flock - Linux
highDetects the use of the "flock" command to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Shell Execution via Git - Linux
highDetects the use of the "git" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Shell Execution via Nice - Linux
highDetects the use of the "nice" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Shell Execution via Rsync - Linux
highDetects the use of the "rsync" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Shell Invocation via Env Command - Linux
highDetects the use of the env command to invoke a shell. This may indicate an attempt to bypass restricted environments, escalate privileges, or execute arbitrary commands.
linux
Shell Invocation Via Ssh - Linux
highDetects the use of the "ssh" utility to execute a shell. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Shell32 DLL Execution in Suspicious Directory
highDetects shell32.dll executing a DLL in a suspicious directory
windows
ShimCache Flush
highDetects actions that clear the local ShimCache and remove forensic evidence
windows
Small Sieve Malware CommandLine Indicator
highDetects specific command line argument being passed to a binary as seen being used by the malware Small Sieve.
windows
Sofacy Trojan Loader Activity
highDetects Trojan loader activity as used by APT28
windows
SOURGUM Actor Behaviours
highSuspicious behaviours related to an actor tracked by Microsoft as SOURGUM
windows
SQLite Chromium Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
windows
SQLite Firefox Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
windows
Sudo Privilege Escalation CVE-2019-14287
highDetects users trying to exploit sudo vulnerability reported in CVE-2019-14287
linux
Suspect Svchost Activity
highIt is extremely abnormal for svchost.exe to spawn without any CLI arguments and is normally observed when a malicious process spawns the process and injects code into the process memory space.
windows
Suspicious Active Directory Database Snapshot Via ADExplorer
highDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database to a suspicious directory. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows
Suspicious AddinUtil.EXE CommandLine Execution
highDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) with suspicious Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.
windows
Suspicious Advpack Call Via Rundll32.EXE
highDetects execution of "rundll32" calling "advpack.dll" with potential obfuscated ordinal calls in order to leverage the "RegisterOCX" function
windows
Suspicious AgentExecutor PowerShell Execution
highDetects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
windows
Suspicious ArcSOC.exe Child Process
highDetects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe. ArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS Server system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding service endpoint and remotely execute code from the ArcSOC.exe process.
windows
Suspicious Autorun Registry Modified via WMI
highDetects suspicious activity where the WMIC process is used to create an autorun registry entry via reg.exe, which is often indicative of persistence mechanisms employed by malware.
windows
Suspicious Binary In User Directory Spawned From Office Application
highDetects an executable in the users directory started from one of the Microsoft Office suite applications (Word, Excel, PowerPoint, Publisher, Visio)
windows
Suspicious BitLocker Access Agent Update Utility Execution
highDetects the execution of the BitLocker Access Agent Update Utility (baaupdate.exe) which is not a common parent process for other processes. Suspicious child processes spawned by baaupdate.exe could indicate an attempt at lateral movement via BitLocker DCOM & COM Hijacking.
windows
Suspicious Calculator Usage
highDetects suspicious use of 'calc.exe' with command line parameters or in a suspicious directory, which is likely caused by some PoC or detection evasion.
windows
Suspicious CertReq Command to Download
highDetects a suspicious CertReq execution downloading a file. This behavior is often used by attackers to download additional payloads or configuration files. Certreq is a built-in Windows utility used to request and retrieve certificates from a certification authority (CA). However, it can be abused by threat actors for malicious purposes.
windows
Suspicious Child Process Created as System
highDetection of child processes spawned with SYSTEM privileges by parents with LOCAL SERVICE or NETWORK SERVICE accounts
windows
Suspicious Child Process of AspNetCompiler
highDetects potentially suspicious child processes of "aspnet_compiler.exe".
windows
Suspicious Child Process Of BgInfo.EXE
highDetects suspicious child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
windows
Suspicious Child Process Of Manage Engine ServiceDesk
highDetects suspicious child processes of the "Manage Engine ServiceDesk Plus" Java web service
windows
Suspicious Child Process of Notepad++ Updater - GUP.Exe
highDetects suspicious child process creation by the Notepad++ updater process (gup.exe). This could indicate potential exploitation of the updater component to deliver unwanted malware.
windows
Suspicious Child Process of SolarWinds WebHelpDesk
highDetects suspicious child processes spawned by SolarWinds WebHelpDesk (WHD) application, which may indicate exploitation activity leveraging RCE vulnerabilities such as CVE-2025-40551, CVE-2025-40536, or CVE-2025-26399
windows
Suspicious Child Process Of SQL Server
highDetects suspicious child processes of the SQLServer process. This could indicate potential RCE or SQL Injection.
windows
Suspicious Child Process Of Wermgr.EXE
highDetects suspicious Windows Error Reporting manager (wermgr.exe) child process
windows
Suspicious Chromium Browser Instance Executed With Custom Extension
highDetects a suspicious process spawning a Chromium based browser process with the 'load-extension' flag to start an instance with a custom extension
windows
Suspicious ClickFix/FileFix Execution Pattern
highDetects suspicious execution patterns where users are tricked into running malicious commands via clipboard manipulation, either through the Windows Run dialog (ClickFix) or File Explorer address bar (FileFix). Attackers leverage social engineering campaigns—such as fake CAPTCHA challenges or urgent alerts—encouraging victims to paste clipboard contents, often executing mshta.exe, powershell.exe, or similar commands to infect systems.
windows
Suspicious Command Patterns In Scheduled Task Creation
highDetects scheduled task creation using "schtasks" that contain potentially suspicious or uncommon commands
windows
Suspicious Control Panel DLL Load
highDetects suspicious Rundll32 execution from control.exe as used by Equation Group and Exploit Kits
windows
Suspicious Curl.EXE Download
highDetects a suspicious curl process start on Windows and outputs the requested document to a local file
windows
Suspicious CustomShellHost Execution
highDetects the execution of CustomShellHost.exe where the child isn't located in 'C:\Windows\explorer.exe'. CustomShellHost is a known LOLBin that can be abused by attackers for defense evasion techniques.
windows
Suspicious Debugger Registration Cmdline
highDetects the registration of a debugger for a program that is available in the logon screen (sticky key backdoor).
windows
Suspicious Desktopimgdownldr Command
highDetects a suspicious Microsoft desktopimgdownldr execution with parameters used to download files from the Internet
windows
Suspicious DLL Loaded via CertOC.EXE
highDetects when a user installs certificates by using CertOC.exe to load the target DLL file.
windows
Suspicious Double Extension File Execution
highDetects suspicious use of an .exe extension after a non-executable file extension like .pdf.exe, a set of spaces or underlines to cloak the executable file in spear phishing campaigns
windows
Suspicious Download and Execute Pattern via Curl/Wget
highDetects suspicious use of command-line tools such as curl or wget to download remote content - particularly scripts - into temporary directories (e.g., /dev/shm, /tmp), followed by immediate execution, indicating potential malicious activity. This pattern is commonly used by malicious scripts, stagers, or downloaders in fileless or multi-stage Linux attacks.
linux
Suspicious Download From Direct IP Via Bitsadmin
highDetects usage of bitsadmin downloading a file using an URL that contains an IP
windows
Suspicious Download From File-Sharing Website Via Bitsadmin
highDetects usage of bitsadmin downloading a file from a suspicious domain
windows
Suspicious Download from Office Domain
highDetects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents
windows
Suspicious Driver/DLL Installation Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "INSTALLDRIVER" action where the driver doesn't contain a ".dll" extension. This is often used as a defense evasion method.
windows
Suspicious DumpMinitool Execution
highDetects suspicious ways to use the "DumpMinitool.exe" binary
windows
Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
highDetects suspicious base64 encoded and obfuscated "LOAD" keyword used in .NET "reflection.assembly"
windows
Suspicious Encoded PowerShell Command Line
highDetects suspicious powershell process starts with base64 encoded commands (e.g. Emotet)
windows
Suspicious Eventlog Clearing or Configuration Change Activity
highDetects the clearing or configuration tampering of EventLog using utilities such as "wevtutil", "powershell" and "wmic". This technique were seen used by threat actors and ransomware strains in order to evade defenses.
windows
Suspicious Execution From Outlook Temporary Folder
highDetects a suspicious program execution in Outlook temp folder
windows
Suspicious Execution Location Of Wermgr.EXE
highDetects suspicious Windows Error Reporting manager (wermgr.exe) execution location.
windows
Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
highDetects process creation with suspicious whitespace padding followed by a '#' character, which may indicate ClickFix or FileFix techniques used to conceal malicious commands from visual inspection. ClickFix and FileFix are social engineering attack techniques where adversaries distribute phishing documents or malicious links that deceive users into opening the Windows Run dialog box or File Explorer search bar. The victims are then instructed to paste commands from their clipboard, which contain extensive whitespace padding using various Unicode space characters to push the actual malicious command far to the right, effectively hiding it from immediate view.
windows
Suspicious File Download From File Sharing Domain Via Curl.EXE
highDetects potentially suspicious file download from file sharing domains using curl.exe
windows
Suspicious File Download From File Sharing Domain Via Wget.EXE
highDetects potentially suspicious file downloads from file sharing domains using wget.exe
windows
Suspicious File Download From IP Via Curl.EXE
highDetects potentially suspicious file downloads directly from IP addresses using curl.exe
windows
Suspicious File Download From IP Via Wget.EXE
highDetects potentially suspicious file downloads directly from IP addresses using Wget.exe
windows
Suspicious File Download From IP Via Wget.EXE - Paths
highDetects potentially suspicious file downloads directly from IP addresses and stored in suspicious locations using Wget.exe
windows
Suspicious File Downloaded From Direct IP Via Certutil.EXE
highDetects the execution of certutil with certain flags that allow the utility to download files from direct IPs.
windows
Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
highDetects the execution of certutil with certain flags that allow the utility to download files from file-sharing websites.
windows
Suspicious File Encoded To Base64 Via Certutil.EXE
highDetects the execution of certutil with the "encode" flag to encode a file to base64 where the extensions of the file is suspicious
windows
Suspicious File Execution From Internet Hosted WebDav Share
highDetects the execution of the "net use" command to mount a WebDAV server and then immediately execute some content in it. As seen being used in malicious LNK files
windows
Suspicious FileFix Execution Pattern
highDetects suspicious FileFix execution patterns where users are tricked into running malicious commands through browser file upload dialog manipulation. This attack typically begins when users visit malicious websites impersonating legitimate services or news platforms, which may display fake CAPTCHA challenges or direct instructions to open file explorer and paste clipboard content. The clipboard content usually contains commands that download and execute malware, such as information stealing tools.
windows
Suspicious Greedy Compression Using Rar.EXE
highDetects RAR usage that creates an archive from a suspicious folder, either a system folder or one of the folders often used by attackers for staging purposes
windows
Suspicious GrpConv Execution
highDetects the suspicious execution of a utility to convert Windows 3.x .grp files or for persistence purposes by malicious software or actors
windows
Suspicious GUP Usage
highDetects execution of the Notepad++ updater in a suspicious directory, which is often used in DLL side-loading attacks
windows
Suspicious HH.EXE Execution
highDetects a suspicious execution of a Microsoft HTML Help (HH.exe)
windows
Suspicious HWP Sub Processes
highDetects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
windows
Suspicious IIS Module Registration
highDetects a suspicious IIS module registration as described in Microsoft threat report on IIS backdoors
windows
Suspicious Invocation of Shell via AWK - Linux
highDetects the execution of "awk" or it's sibling commands, to invoke a shell using the system() function. This behavior is commonly associated with attempts to execute arbitrary commands or escalate privileges, potentially leading to unauthorized access or further exploitation.
linux
Suspicious Invocation of Shell via Rsync
highDetects the execution of a shell as sub process of "rsync" without the expected command line flag "-e" being used, which could be an indication of exploitation as described in CVE-2024-12084. This behavior is commonly associated with attempts to execute arbitrary commands or escalate privileges, potentially leading to unauthorized access or further exploitation.
linux
Suspicious Invoke-WebRequest Execution
highDetects a suspicious call to Invoke-WebRequest cmdlet where the and output is located in a suspicious location
windows
Suspicious Java Children Processes
highDetects java process spawning suspicious children
linux
Suspicious JavaScript Execution Via Mshta.EXE
highDetects execution of javascript code using "mshta.exe".
windows
Suspicious Kerberos Ticket Request via CLI
highDetects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class. Threat actors may use command line interfaces to request Kerberos tickets for service accounts in order to perform offline password cracking attacks commonly known as Kerberoasting or other Kerberos ticket abuse techniques like silver ticket attacks.
windows
Suspicious Kernel Dump Using Dtrace
highDetects suspicious way to dump the kernel on Windows systems using dtrace.exe, which is available on Windows systems since Windows 10 19H1
windows
Suspicious Key Manager Access
highDetects the invocation of the Stored User Names and Passwords dialogue (Key Manager)
windows
Suspicious LNK Command-Line Padding with Whitespace Characters
highDetects exploitation of LNK file command-line length discrepancy, where attackers hide malicious commands beyond the 260-character UI limit while the actual command-line argument field supports 4096 characters using whitespace padding (e.g., 0x20, 0x09-0x0D). Adversaries insert non-printable whitespace characters (e.g., Line Feed \x0A, Carriage Return \x0D) to pad the visible section of the LNK file, pushing malicious commands past the UI-visible boundary. The hidden payload, executed at runtime but invisible in Windows Explorer properties, enables stealthy execution and evasion—commonly used for social engineering attacks. This rule flags suspicious use of such padding observed in real-world attacks.
windows
Suspicious Manipulation Of Default Accounts Via Net.EXE
highDetects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc
windows
Suspicious Microsoft Office Child Process
highDetects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
windows
Suspicious Microsoft Office Child Process - MacOS
highDetects suspicious child processes spawning from microsoft office suite applications such as word or excel. This could indicates malicious macro execution
macos
Suspicious Microsoft OneNote Child Process
highDetects suspicious child processes of the Microsoft OneNote application. This may indicate an attempt to execute malicious embedded objects from a .one file.
windows
Suspicious Modification Of Scheduled Tasks
highDetects when an attacker tries to modify an already existing scheduled tasks to run from a suspicious location Attackers can create a simple looking task in order to avoid detection on creation as it's often the most focused on Instead they modify the task after creation to include their malicious payload
windows
Suspicious MSDT Parent Process
highDetects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation
windows
Suspicious MSHTA Child Process
highDetects a suspicious process spawning from an "mshta.exe" process, which could be indicative of a malicious HTA script execution
windows
Suspicious Mshta.EXE Execution Patterns
highDetects suspicious mshta process execution patterns
windows
Suspicious Mstsc.EXE Execution With Local RDP File
highDetects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
windows
Suspicious New Service Creation
highDetects creation of a new service via "sc" command or the powershell "new-service" cmdlet with suspicious binary paths
windows
Suspicious Nohup Execution
highDetects execution of binaries located in potentially suspicious locations via "nohup"
linux
Suspicious NTLM Authentication on the Printer Spooler Service
highDetects a privilege elevation attempt by coercing NTLM authentication on the Printer Spooler service
windows
Suspicious Obfuscated PowerShell Code
highDetects suspicious UTF16 and base64 encoded and often obfuscated PowerShell code often used in command lines
windows
Suspicious Outlook Child Process
highDetects a suspicious process spawning from an Outlook process.
windows
Suspicious Parent Double Extension File Execution
highDetect execution of suspicious double extension files in ParentCommandLine
windows
Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
highDetects execution of the "VMwareToolBoxCmd.exe" with the "script" and "set" flag to setup a specific script that's located in a potentially suspicious location to run for a specific VM state
windows
Suspicious Ping/Del Command Combination
highDetects a method often used by ransomware. Which combines the "ping" to wait a couple of seconds and then "del" to delete the file in question. Its used to hide the file responsible for the initial infection for example
windows
Suspicious Plink Port Forwarding
highDetects suspicious Plink tunnel port forwarding to a local port
windows
Suspicious PowerShell Download and Execute Pattern
highDetects suspicious PowerShell download patterns that are often used in malicious scripts, stagers or downloaders (make sure that your backend applies the strings case-insensitive)
windows
Suspicious PowerShell Encoded Command Patterns
highDetects PowerShell command line patterns in combincation with encoded commands that often appear in malware infection chains
windows
Suspicious PowerShell IEX Execution Patterns
highDetects suspicious ways to run Invoke-Execution using IEX alias
windows
Suspicious PowerShell Parameter Substring
highDetects suspicious PowerShell invocation with a parameter substring
windows
Suspicious PowerShell Parent Process
highDetects a suspicious or uncommon parent processes of PowerShell
windows
Suspicious PrinterPorts Creation (CVE-2020-1048)
highDetects new commands that add new printer port which point to suspicious file
windows
Suspicious Process By Web Server Process
highDetects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation
windows
Suspicious Process Created Via Wmic.EXE
highDetects WMIC executing "process call create" with suspicious calls to processes such as "rundll32", "regsrv32", etc.
windows
Suspicious Process Execution From Fake Recycle.Bin Folder
highDetects process execution from a fake recycle bin folder, often used to avoid security solution.
windows
Suspicious Process Masquerading As SvcHost.EXE
highDetects a suspicious process that is masquerading as the legitimate "svchost.exe" by naming its binary "svchost.exe" and executing from an uncommon location. Adversaries often disguise their malicious binaries by naming them after legitimate system processes like "svchost.exe" to evade detection.
windows
Suspicious Process Parents
highDetects suspicious parent processes that should not have any children or should only have a single possible child program
windows
Suspicious Process Patterns NTDS.DIT Exfil
highDetects suspicious process patterns used in NTDS.DIT exfiltration
windows
Suspicious Process Spawned by CentreStack Portal AppPool
highDetects unexpected command shell execution (cmd.exe) from w3wp.exe when tied to CentreStack's portal.config, indicating potential exploitation (e.g., CVE-2025-30406)
windows
Suspicious Processes Spawned by Java.EXE
highDetects suspicious processes spawned from a Java host process which could indicate a sign of exploitation (e.g. log4j)
windows
Suspicious Processes Spawned by WinRM
highDetects suspicious processes including shells spawnd from WinRM host process
windows
Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE
highDetects Netsh command execution that whitelists a program located in a suspicious location in the Windows Firewall
windows
Suspicious Program Names
highDetects suspicious patterns in program names or folders that are often found in malicious samples or hacktools
windows
Suspicious Provlaunch.EXE Child Process
highDetects suspicious child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
windows
Suspicious RazerInstaller Explorer Subprocess
highDetects a explorer.exe sub process of the RazerInstaller software which can be invoked from the installer to select a different installation folder but can also be exploited to escalate privileges to LOCAL SYSTEM
windows
Suspicious RDP Redirect Using TSCON
highDetects a suspicious RDP session redirect using tscon.exe
windows
Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
highDetects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
windows
Suspicious Redirection to Local Admin Share
highDetects a suspicious output redirection to the local admins share, this technique is often found in malicious scripts or hacktool stagers
windows
Suspicious Reg Add BitLocker
highDetects suspicious addition to BitLocker related registry keys via the reg.exe utility
windows
Suspicious Registry Modification From ADS Via Regini.EXE
highDetects the import of an alternate data stream with regini.exe, regini.exe can be used to modify registry keys.
windows
Suspicious Regsvr32 Execution From Remote Share
highDetects REGSVR32.exe to execute DLL hosted on remote shares
windows
Suspicious Remote Child Process From Outlook
highDetects a suspicious child process spawning from Outlook where the image is located in a remote location (SMB/WebDav shares).
windows
Suspicious Response File Execution Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "-f" flag in order to load a response file with a non-".rsp" extension.
windows
Suspicious Rundll32 Activity Invoking Sys File
highDetects suspicious process related to rundll32 based on command line that includes a *.sys file as seen being used by UNC2452
windows
Suspicious Rundll32 Execution With Image Extension
highDetects the execution of Rundll32.exe with DLL files masquerading as image files
windows
Suspicious Rundll32 Invoking Inline VBScript
highDetects suspicious process related to rundll32 based on command line that invokes inline VBScript as seen being used by UNC2452
windows
Suspicious Scheduled Task Creation Involving Temp Folder
highDetects the creation of scheduled tasks that involves a temporary folder and runs only once
windows
Suspicious Schtasks Execution AppData Folder
highDetects the creation of a schtask that executes a file from C:\Users\<USER>\AppData\Local
windows
Suspicious Schtasks Schedule Types
highDetects scheduled task creations or modification on a suspicious schedule type
windows
Suspicious Serv-U Process Pattern
highDetects a suspicious process pattern which could be a sign of an exploited Serv-U service
windows
Suspicious Service Binary Directory
highDetects a service binary running in a suspicious directory
windows
Suspicious Service DACL Modification Via Set-Service Cmdlet
highDetects suspicious DACL modifications via the "Set-Service" cmdlet using the "SecurityDescriptorSddl" flag (Only available with PowerShell 7) that can be used to hide services or make them unstopable
windows
Suspicious Service Path Modification
highDetects service path modification via the "sc" binary to a suspicious command or path
windows
Suspicious ShellExec_RunDLL Call Via Ordinal
highDetects suspicious call to the "ShellExec_RunDLL" exported function of SHELL32.DLL through the ordinal number to launch other commands. Adversary might only use the ordinal number in order to bypass existing detection that alert on usage of ShellExec_RunDLL on CommandLine.
windows
Suspicious Shells Spawn by Java Utility Keytool
highDetects suspicious shell spawn from Java utility keytool process (e.g. adselfservice plus exploitation)
windows
Suspicious Speech Runtime Binary Child Process
highDetects suspicious Speech Runtime Binary Execution by monitoring its child processes. Child processes spawned by SpeechRuntime.exe could indicate an attempt for lateral movement via COM & DCOM hijacking.
windows
Suspicious Splwow64 Without Params
highDetects suspicious Splwow64.exe process without any command line parameters
windows
Suspicious Spool Service Child Process
highDetects suspicious print spool service (spoolsv.exe) child processes.
windows
Suspicious Sysmon as Execution Parent
highDetects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)
windows
Suspicious SYSTEM User Process Creation
highDetects a suspicious process creation as SYSTEM user (suspicious program or command line parameter)
windows
Suspicious TSCON Start as SYSTEM
highDetects a tscon.exe start as LOCAL SYSTEM
windows
Suspicious UltraVNC Execution
highDetects suspicious UltraVNC command line flag combination that indicate a auto reconnect upon execution, e.g. startup (as seen being used by Gamaredon threat group)
windows
Suspicious Uninstall of Windows Defender Feature via PowerShell
highDetects the use of PowerShell with Uninstall-WindowsFeature or Remove-WindowsFeature cmdlets to disable or remove the Windows Defender GUI feature, a common technique used by adversaries to evade defenses.
windows
Suspicious Usage Of ShellExec_RunDLL
highDetects suspicious usage of the ShellExec_RunDLL function to launch other commands as seen in the the raspberry-robin attack
windows
Suspicious Use of CSharp Interactive Console
highDetects the execution of CSharp interactive console by PowerShell
windows
Suspicious VBScript UN2452 Pattern
highDetects suspicious inline VBScript keywords as used by UNC2452
windows
Suspicious Velociraptor Child Process
highDetects the suspicious use of the Velociraptor DFIR tool to execute other tools or download additional payloads, as seen in a campaign where it was abused for remote access and to stage further attacks.
windows
Suspicious WebDav Client Execution Via Rundll32.EXE
highDetects "svchost.exe" spawning "rundll32.exe" with command arguments like C:\windows\system32\davclnt.dll,DavSetCookie. This could be an indicator of exfiltration or use of WebDav to launch code (hosted on WebDav Server) or potentially a sign of exploitation of CVE-2023-23397
windows
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
highDetects the usage of "reg.exe" to tamper with different Windows Defender registry keys in order to disable some important features related to protection and detection
windows
Suspicious Windows Service Tampering
highDetects the usage of binaries such as 'net', 'sc' or 'powershell' in order to stop, pause, disable or delete critical or important Windows services such as AV, Backup, etc. As seen being used in some ransomware scripts
windows
Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
highDetects the execution of "logman" utility in order to disable or delete Windows trace sessions
windows
Suspicious Windows Update Agent Empty Cmdline
highDetects suspicious Windows Update Agent activity in which a wuauclt.exe process command line doesn't contain any command line flags
windows
Suspicious WMIC Execution Via Office Process
highOffice application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).
windows
Suspicious WmiPrvSE Child Process
highDetects suspicious and uncommon child processes of WmiPrvSE
windows
Sysinternals PsSuspend Suspicious Execution
highDetects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses
windows
Syslog Clearing or Removal Via System Utilities
highDetects specific commands commonly used to remove or empty the syslog. Which is a technique often used by attacker as a method to hide their tracks
linux
Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE
highDetects usage of "findstr" with the argument "385201". Which could indicate potential discovery of an installed Sysinternals Sysmon service using the default driver altitude (even if the name is changed).
windows
Sysmon Driver Unloaded Via Fltmc.EXE
highDetects possible Sysmon filter driver unloaded via fltmc.exe
windows
System File Execution Location Anomaly
highDetects the execution of a Windows system binary that is usually located in the system folder from an uncommon location.
windows
System Restore Registry Modification via CommandLine
highDetects system restore registry modification via command line, which can be used by adversaries to disable system restore on the computer.
windows
TAIDOOR RAT DLL Load
highDetects specific process characteristics of Chinese TAIDOOR RAT malware load
windows
Tamper Windows Defender Remove-MpPreference
highDetects attempts to remove Windows Defender configurations using the 'MpPreference' cmdlet
windows
TanStack Supply-Chain Attack Execution Indicators - Linux
highDetects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai and uipath reported on early May 2026. The preinstall hook runs setup.mjs, which downloads a platform-specific Bun runtime.
linux
TanStack Supply-Chain Attack Execution Indicators - Windows
highDetects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath reported on early May 2026.
windows
Taskkill Symantec Endpoint Protection
highDetects one of the possible scenarios for disabling Symantec Endpoint Protection. Symantec Endpoint Protection antivirus software services incorrectly implement the protected service mechanism. As a result, the NT AUTHORITY/SYSTEM user can execute the taskkill /im command several times ccSvcHst.exe /f, thereby killing the process belonging to the service, and thus shutting down the service.
windows
Taskmgr as LOCAL_SYSTEM
highDetects the creation of taskmgr.exe process in context of LOCAL_SYSTEM
windows
Tasks Folder Evasion
highThe Tasks folder in system32 and syswow64 are globally writable paths. Adversaries can take advantage of this and load or influence any script hosts or ANY .NET Application in Tasks to load and execute a custom assembly into cscript, wscript, regsvr32, mshta, eventvwr
windows
Terminal Service Process Spawn
highDetects a process spawned by the terminal service server process (this could be an indicator for an exploitation of CVE-2019-0708)
windows
Time Travel Debugging Utility Usage
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows
Tor Client/Browser Execution
highDetects the use of Tor or Tor-Browser to connect to onion routing networks
windows
Trickbot Malware Activity
highDetects Trickbot malware process tree pattern in which "rundll32.exe" is a parent of "wermgr.exe"
windows
Triple Cross eBPF Rootkit Execve Hijack
highDetects execution of a the file "execve_hijack" which is used by the Triple Cross rootkit as a way to elevate privileges
linux
Triple Cross eBPF Rootkit Install Commands
highDetects default install commands of the Triple Cross eBPF rootkit based on the "deployer.sh" script
linux
TropicTrooper Campaign November 2018
highDetects TropicTrooper activity, an actor who targeted high-profile organizations in the energy and food and beverage sectors in Asia
windows
UAC Bypass Abusing Winsat Path Parsing - Process
highDetects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
windows
UAC Bypass Tools Using ComputerDefaults
highDetects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)
windows
UAC Bypass Using ChangePK and SLUI
highDetects an UAC bypass that uses changepk.exe and slui.exe (UACMe 61)
windows
UAC Bypass Using Consent and Comctl32 - Process
highDetects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
windows
UAC Bypass Using Disk Cleanup
highDetects the pattern of UAC Bypass using scheduled tasks and variable expansion of cleanmgr.exe (UACMe 34)
windows
UAC Bypass Using DismHost
highDetects the pattern of UAC Bypass using DismHost DLL hijacking (UACMe 63)
windows
UAC Bypass Using Event Viewer RecentViews
highDetects the pattern of UAC Bypass using Event Viewer RecentViews
windows
UAC Bypass Using IDiagnostic Profile
highDetects the "IDiagnosticProfileUAC" UAC bypass technique
windows
UAC Bypass Using IEInstal - Process
highDetects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)
windows
UAC Bypass Using MSConfig Token Modification - Process
highDetects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
windows
UAC Bypass Using NTFS Reparse Point - Process
highDetects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
windows
UAC Bypass Using PkgMgr and DISM
highDetects the pattern of UAC Bypass using pkgmgr.exe and dism.exe (UACMe 23)
windows
UAC Bypass Using Windows Media Player - Process
highDetects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
windows
UAC Bypass via ICMLuaUtil
highDetects the pattern of UAC Bypass using ICMLuaUtil Elevated COM interface
windows
UAC Bypass WSReset
highDetects the pattern of UAC Bypass via WSReset usable by default sysmon-config
windows
UEFI Persistence Via Wpbbin - ProcessCreation
highDetects execution of the binary "wpbbin" which is used as part of the UEFI based persistence method described in the reference section
windows
UNC2452 Process Creation Patterns
highDetects a specific process creation patterns as seen used by UNC2452 and provided by Microsoft as Microsoft Defender ATP queries
windows
UNC4841 - Download Compressed Files From Temp.sh Using Wget
highDetects execution of "wget" to download a ".zip" or ".rar" files from "temp.sh". As seen used by UNC4841 during their Barracuda ESG zero day exploitation.
linux
UNC4841 - Download Tar File From Untrusted Direct IP Via Wget
highDetects execution of "wget" to download a "tar" from an IP address that doesn't have a trusted certificate. As seen used by UNC4841 during their Barracuda ESG zero day exploitation.
linux
UNC4841 - SSL Certificate Exfiltration Via Openssl
highDetects the execution of "openssl" to connect to an IP address. This techniques was used by UNC4841 to exfiltrate SSL certificates and as a C2 channel with named pipes. Investigate commands executed in the temporal vicinity of this command.
linux
Uncommon Child Process Of Setres.EXE
highDetects uncommon child process of Setres.EXE. Setres.EXE is a Windows server only process and tool that can be used to set the screen resolution. It can potentially be abused in order to launch any arbitrary file with a name containing the word "choice" from the current execution path.
windows
Uncommon FileSystem Load Attempt By Format.com
highDetects the execution of format.com with an uncommon filesystem selection that could indicate a defense evasion activity in which "format.com" is used to load malicious DLL files or other programs.
windows
Uncommon One Time Only Scheduled Task At 00:00
highDetects scheduled task creation events that include suspicious actions, and is run once at 00:00
windows
Uncommon Svchost Command Line Parameter
highDetects instances of svchost.exe running with an unusual or uncommon command line parameter by excluding known legitimate or common patterns. This could point at a file masquerading as svchost, a process injection, or hollowing of a legitimate svchost instance.
windows
Uncommon Userinit Child Process
highDetects uncommon "userinit.exe" child processes, which could be a sign of uncommon shells or login scripts used for persistence.
windows
Uninstall Crowdstrike Falcon Sensor
highAdversaries may disable security tools to avoid possible detection of their tools and activities by uninstalling Crowdstrike Falcon
windows
Uninstall Sysinternals Sysmon
highDetects the removal of Sysmon, which could be a potential attempt at defense evasion
windows
Unusual Child Process of dns.exe
highDetects an unexpected process spawning from dns.exe which may indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows
Ursnif Redirection Of Discovery Commands
highDetects the redirection of Ursnif discovery commands as part of the initial execution of the malware.
windows
Use of W32tm as Timer
highWhen configured with suitable command line arguments, w32tm can act as a delay mechanism
windows
User Added To Highly Privileged Group
highDetects addition of users to highly privileged groups via "Net" or "Add-LocalGroupMember".
windows
User Added to Remote Desktop Users Group
highDetects addition of users to the local Remote Desktop Users group via "Net" or "Add-LocalGroupMember".
windows
User Shell Folders Registry Modification via CommandLine
highDetects modifications to User Shell Folders registry values via reg.exe or PowerShell, which could indicate persistence attempts. Attackers may modify User Shell Folders registry values to point to malicious executables or scripts that will be executed during startup. This technique is often used to maintain persistence on a compromised system by ensuring that malicious payloads are executed automatically.
windows
Using SettingSyncHost.exe as LOLBin
highDetects using SettingSyncHost.exe to run hijacked binary
windows
VeeamBackup Database Credentials Dump Via Sqlcmd.EXE
highDetects dump of credentials in VeeamBackup dbo
windows
Vim GTFOBin Abuse - Linux
highDetects the use of "vim" and it's siblings commands to execute a shell or proxy commands. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Visual Basic Command Line Compiler Usage
highDetects successful code compilation via Visual Basic Command Line Compiler that utilizes Windows Resource to Object Converter.
windows
VMToolsd Suspicious Child Process
highDetects suspicious child process creations of VMware Tools process which may indicate persistence setup
windows
VolumeShadowCopy Symlink Creation Via Mklink
highShadow Copies storage symbolic link creation using operating systems utilities
windows
Vulnerable Driver Blocklist Registry Tampering Via CommandLine
highDetects tampering of the Vulnerable Driver Blocklist registry via command line tools such as PowerShell or REG.EXE. The Vulnerable Driver Blocklist is a security feature that helps prevent the loading of known vulnerable drivers. Disabling this feature may indicate an attempt to bypass security controls, often targeted by threat actors to facilitate the installation of malicious or vulnerable drivers, particularly in scenarios involving Endpoint Detection and Response
windows
Wab Execution From Non Default Location
highDetects execution of wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) from non default locations as seen with bumblebee activity
windows
Wab/Wabmig Unusual Parent Or Child Processes
highDetects unusual parent or children of the wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) processes as seen being used with bumblebee activity
windows
Webshell Detection With Command Line Keywords
highDetects certain command line parameters often used during reconnaissance activity via web shells
windows
Webshell Hacking Activity Patterns
highDetects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system
windows
Webshell Tool Reconnaissance Activity
highDetects processes spawned from web servers (PHP, Tomcat, IIS, etc.) that perform reconnaissance looking for the existence of popular scripting tools (perl, python, wget) on the system via the help commands
windows
WhoAmI as Parameter
highDetects a suspicious process command line that uses whoami as first parameter (as e.g. used by EfsPotato)
windows
Whoami.EXE Execution From Privileged Process
highDetects the execution of "whoami.exe" by privileged accounts that are often abused by threat actors
windows
Windows AMSI Related Registry Tampering Via CommandLine
highDetects tampering of AMSI (Anti-Malware Scan Interface) related registry values via command line tools such as reg.exe or PowerShell. AMSI provides a generic interface for applications and services to integrate with antimalware products. Adversaries may disable AMSI to evade detection of malicious scripts and code execution.
windows
Windows Credential Guard Registry Tampering Via CommandLine
highDetects attempts to add, modify, or delete Windows Credential Guard related registry keys or values via command line tools such as Reg.exe or PowerShell. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation. The rule matches suspicious command lines that target DeviceGuard or LSA registry paths and manipulate keys like EnableVirtualizationBasedSecurity, RequirePlatformSecurityFeatures, or LsaCfgFlags. Such activity may indicate an attempt to disable or tamper with Credential Guard, potentially exposing sensitive credentials for misuse.
windows
Windows Defender Context Menu Removed
highDetects the use of reg.exe or PowerShell to delete the Windows Defender context menu handler registry keys. This action removes the "Scan with Microsoft Defender" option from the right-click menu for files, directories, and drives. Attackers may use this technique to hinder manual, on-demand scans and reduce the visibility of the security product.
windows
Windows Defender Definition Files Removed
highAdversaries may disable security tools to avoid possible detection of their tools and activities by removing Windows Defender Definition Files
windows
Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
highDetects the usage of SystemSettingsAdminFlows.exe to disable Windows Defender. SystemSettingsAdminFlows.exe is a legitimate Windows component used for administrative configuration tasks. However, attackers may abuse it to disable Windows Defender as part of their attack chain, especially in the context of ransomware or other malware campaigns.
windows
Windows EventLog Autologger Session Registry Modification Via CommandLine
highDetects attempts to disable Windows EventLog autologger sessions via registry modification. The AutoLogger event tracing session records events that occur early in the operating system boot process. Applications and device drivers can use the AutoLogger session to capture traces before the user logs in. Adversaries may disable these sessions to evade detection and prevent security monitoring of early boot activities and system events.
windows
Windows Internet Hosted WebDav Share Mount Via Net.EXE
highDetects when an internet hosted webdav share is mounted using the "net.exe" utility
windows
Windows Shell/Scripting Processes Spawning Suspicious Programs
highDetects suspicious child processes of a Windows shell and scripting processes such as wscript, rundll32, powershell, mshta...etc.
windows
Windows Suspicious Child Process from Node.js - React2Shell
highDetects suspicious child processes started by Node.js server processes on Windows, which may indicate exploitation of vulnerabilities like CVE-2025-55182 (React2Shell). Attackers can abuse the Node.js 'child_process' module to run system commands or scripts using methods such as spawn(), exec(), execFile(), fork(), or execSync(). If execSync() or exec() is used in the exploit, the command line often shows a shell (e.g., cmd.exe /d /s /c ...) running a suspicious command unless other shells are explicitly invoked. For other methods, the spawned process appears directly in the Image field unless a shell is explicitly used.
windows
Winrs Local Command Execution
highDetects the execution of Winrs.exe where it is used to execute commands locally. Commands executed this way are launched under Winrshost.exe and can represent proxy execution used for defense evasion or lateral movement.
windows
WSL Kali-Linux Usage
highDetects the use of Kali Linux through Windows Subsystem for Linux
windows
Wusa.EXE Executed By Parent Process Located In Suspicious Location
highDetects execution of the "wusa.exe" (Windows Update Standalone Installer) utility by a parent process that is located in a suspicious location. Attackers could instantiate an instance of "wusa.exe" in order to bypass User Account Control (UAC). They can duplicate the access token from "wusa.exe" to gain elevated privileges.
windows
Xwizard.EXE Execution From Non-Default Location
highDetects the execution of Xwizard tool from a non-default directory. When executed from a non-default directory, this utility can be abused in order to side load a custom version of "xwizards.dll".
windows
7Zip Compressing Dump Files
mediumDetects execution of 7z in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows
Abusing Print Executable
mediumAttackers can use print.exe for remote file copy
windows
Access of Sudoers File Content
mediumDetects the execution of a text-based file access or inspection utilities to read the content of /etc/sudoers in order to potentially list all users that have sudo rights.
linux
Active Directory Database Snapshot Via ADExplorer
mediumDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows
Active Directory Structure Export Via Csvde.EXE
mediumDetects the execution of "csvde.exe" in order to export organizational Active Directory structure.
windows
Active Directory Structure Export Via Ldifde.EXE
mediumDetects the execution of "ldifde.exe" in order to export organizational Active Directory structure.
windows
Add New Download Source To Winget
mediumDetects usage of winget to add new additional download sources
windows
Add Potential Suspicious New Download Source To Winget
mediumDetects usage of winget to add new potentially suspicious download sources
windows
Add Windows Capability Via PowerShell Cmdlet
mediumDetects usage of the "Add-WindowsCapability" cmdlet to add Windows capabilities. Notable capabilities could be "OpenSSH" and others.
windows
AddinUtil.EXE Execution From Uncommon Directory
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) from a non-standard directory.
windows
AgentExecutor PowerShell Execution
mediumDetects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
windows
Always Install Elevated MSI Spawned Cmd And Powershell
mediumDetects Windows Installer service (msiexec.exe) spawning "cmd" or "powershell"
windows
Always Install Elevated Windows Installer
mediumDetects Windows Installer service (msiexec.exe) trying to install MSI packages with SYSTEM privilege
windows
Application Removed Via Wmic.EXE
mediumDetects the removal or uninstallation of an application via "Wmic.EXE".
windows
Application Termination Attempt via Wmic.EXE
mediumDetects an attempt to terminate a process via "wmic" with the "call terminate" flag. Adversaries may use wmic to terminate security products or other applications on the compromised host. This event is triggered on on attempt and process creation can be either successful or unsuccessful.
windows
Arbitrary Binary Execution Using GUP Utility
mediumDetects execution of the Notepad++ updater (gup) to launch other commands or executables
windows
Arbitrary Command Execution Using WSL
mediumDetects potential abuse of Windows Subsystem for Linux (WSL) binary as a Living of the Land binary in order to execute arbitrary Linux or Windows commands.
windows
Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
mediumDetects execution of arbitrary DLLs or unsigned code via a ".csproj" files via Dotnet.EXE.
windows
Arbitrary File Download Via ConfigSecurityPolicy.EXE
mediumDetects the execution of "ConfigSecurityPolicy.EXE", a binary part of Windows Defender used to manage settings in Windows Defender. Users can configure different pilot collections for each of the co-management workloads. It can be abused by attackers in order to upload or download files.
windows
Arbitrary File Download Via GfxDownloadWrapper.EXE
mediumDetects execution of GfxDownloadWrapper.exe with a URL as an argument to download file.
windows
Arbitrary File Download Via MSEDGE_PROXY.EXE
mediumDetects usage of "msedge_proxy.exe" to download arbitrary files
windows
Arbitrary File Download Via MSOHTMED.EXE
mediumDetects usage of "MSOHTMED" to download arbitrary files
windows
Arbitrary File Download Via MSPUB.EXE
mediumDetects usage of "MSPUB" (Microsoft Publisher) to download arbitrary files
windows
Arbitrary File Download Via PresentationHost.EXE
mediumDetects usage of "PresentationHost" which is a utility that runs ".xbap" (Browser Applications) files to download arbitrary files
windows
Arbitrary File Download Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" to download arbitrary files. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows
Arbitrary MSI Download Via Devinit.EXE
mediumDetects a certain command line flag combination used by "devinit.exe", which can be abused as a LOLBIN to download arbitrary MSI packages on a Windows system
windows
Arbitrary Shell Command Execution Via Settingcontent-Ms
mediumThe .SettingContent-ms file type was introduced in Windows 10 and allows a user to create "shortcuts" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.
windows
AspNetCompiler Execution
mediumDetects execution of "aspnet_compiler.exe" which can be abused to compile and execute C# code.
windows
Assembly Loading Via CL_LoadAssembly.ps1
mediumDetects calls to "LoadAssemblyFromPath" or "LoadAssemblyFromNS" that are part of the "CL_LoadAssembly.ps1" script. This can be abused to load different assemblies and bypass App locker controls.
windows
Audio Capture via PowerShell
mediumDetects audio capture via PowerShell Cmdlet.
windows
Audio Capture via SoundRecorder
mediumDetect attacker collecting audio via SoundRecorder application.
windows
Automated Collection Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows
Binary Proxy Execution Via Dotnet-Trace.EXE
mediumDetects commandline arguments for executing a child process via dotnet-trace.exe
windows
BPFtrace Unsafe Option Usage
mediumDetects the usage of the unsafe bpftrace option
linux
Browser Started with Remote Debugging
mediumDetects browsers starting with the remote debugging flags. Which is a technique often used to perform browser injection attacks
windows
C# IL Code Compilation Via Ilasm.EXE
mediumDetects the use of "Ilasm.EXE" in order to compile C# intermediate (IL) code to EXE or DLL.
windows
Cab File Extraction Via Wusa.EXE
mediumDetects execution of the "wusa.exe" (Windows Update Standalone Installer) utility to extract cab using the "/extract" argument that is no longer supported.
windows
Capture Credentials with Rpcping.exe
mediumDetects using Rpcping.exe to send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.
windows
Certificate Exported Via Certutil.EXE
mediumDetects the execution of the certutil with the "exportPFX" flag which allows the utility to export certificates.
windows
Certificate Exported Via PowerShell
mediumDetects calls to cmdlets that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
windows
Change PowerShell Policies to an Insecure Level
mediumDetects changing the PowerShell script execution policy to a potentially insecure level using the "-ExecutionPolicy" flag.
windows
Changing Existing Service ImagePath Value Via Reg.EXE
mediumAdversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
windows
Chmod Targeting Sensitive Directories
mediumDetects chmod targeting files in sensitive directory paths on Linux systems. Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.
linux
Chromium Browser Instance Executed With Custom Extension
mediumDetects a Chromium based browser process with the 'load-extension' flag to start a instance with a custom extension
windows
ClickOnce Deployment Execution - Dfsvc.EXE Child Process
mediumDetects child processes of "dfsvc" which indicates a ClickOnce deployment execution.
windows
Clipboard Access Via OSAScript
mediumDetects access to clipboard content via osascript, which may be used for data collection but also occurs in legitimate clipboard utilities and automation scripts
macos
Clipboard Data Collection Via Pbpaste
mediumDetects execution of the "pbpaste" utility, which retrieves the contents of the clipboard (a.k.a. pasteboard) and writes them to the standard output (stdout). The utility is often used for creating new files with the clipboard content or for piping clipboard contents to other commands. It can also be used in shell scripts that may require clipboard content as input. Attackers can abuse this utility in order to collect data from the user clipboard, which may contain passwords or sensitive information. Use this rule to hunt for potential abuse of the utility by looking at the parent process and any potentially suspicious command line content.
macos
Cloudflared Portable Execution
mediumDetects the execution of the "cloudflared" binary from a non standard location.
windows
Cloudflared Quick Tunnel Execution
mediumDetects creation of an ad-hoc Cloudflare Quick Tunnel, which can be used to tunnel local services such as HTTP, RDP, SSH and SMB. The free TryCloudflare Quick Tunnel will generate a random subdomain on trycloudflare[.]com, following a call to api[.]trycloudflare[.]com. The tool has been observed in use by threat groups including Akira ransomware.
windows
Cloudflared Tunnel Connections Cleanup
mediumDetects execution of the "cloudflared" tool with the tunnel "cleanup" flag in order to cleanup tunnel connections.
windows
Cloudflared Tunnel Execution
mediumDetects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
windows
Cmd Launched with Hidden Start Flags to Suspicious Targets
mediumDetects cmd.exe executing commands with the "start" utility using "/b" (no window) or "/min" (minimized) flags. To reduce false positives from standard background tasks, detection is restricted to scenarios where the target is a known script extension or located in suspicious temporary/public directories. This technique was observed in Chaos, DarkSide, and Emotet malware campaigns.
windows
Code Execution via Pcwutl.dll
mediumDetects launch of executable by calling the LaunchApplication function from pcwutl.dll library.
windows
CodePage Modification Via MODE.COM To Russian Language
mediumDetects a CodePage modification using the "mode.com" utility to Russian language. This behavior has been used by threat actors behind Dharma ransomware.
windows
COM Object Execution via Xwizard.EXE
mediumDetects the execution of Xwizard tool with the "RunWizard" flag and a GUID like argument. This utility can be abused in order to run custom COM object created in the registry.
windows
Command Line Execution with Suspicious URL and AppData Strings
mediumDetects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)
windows
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
mediumDetects a qlogin.exe command attempting to authenticate as the internal `_+_PublicSharingUser_` using a GUID as the password. This could be an indicator of an attacker exploiting CVE-2025-57788 to gain initial access using leaked credentials.
windows
Compress Data and Lock With Password for Exfiltration With 7-ZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows
Compress Data and Lock With Password for Exfiltration With WINZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows
Computer Discovery And Export Via Get-ADComputer Cmdlet
mediumDetects usage of the Get-ADComputer cmdlet to collect computer information and output it to a file
windows
Computer Password Change Via Ksetup.EXE
mediumDetects password change for the computer's domain account or host principal via "ksetup.exe"
windows
Computer System Reconnaissance Via Wmic.EXE
mediumDetects execution of wmic utility with the "computersystem" flag in order to obtain information about the machine such as the domain, username, model, etc.
windows
Conhost Spawned By Uncommon Parent Process
mediumDetects when the Console Window Host (conhost.exe) process is spawned by an uncommon parent process, which could be indicative of potential code injection activity.
windows
Console CodePage Lookup Via CHCP
mediumDetects use of chcp to look up the system locale value as part of host discovery
windows
ConvertTo-SecureString Cmdlet Usage Via CommandLine
mediumDetects usage of the "ConvertTo-SecureString" cmdlet via the commandline. Which is fairly uncommon and could indicate potential suspicious activity
windows
Copy From Or To Admin Share Or Sysvol Folder
mediumDetects a copy command or a copy utility execution to or from an Admin share or remote
windows
Credentials from Password Stores - Keychain
mediumDetects passwords dumps from Keychain
macos
Cscript/Wscript Potentially Suspicious Child Process
mediumDetects potentially suspicious child processes of Wscript/Cscript. These include processes such as rundll32 with uncommon exports or PowerShell spawning rundll32 or regsvr32. Malware such as Pikabot and Qakbot were seen using similar techniques as well as many others.
windows
Curl Web Request With Potential Custom User-Agent
mediumDetects execution of "curl.exe" with a potential custom "User-Agent". Attackers can leverage this to download or exfiltrate data via "curl" to a domain that only accept specific "User-Agent" strings
windows
Curl.EXE Execution With Custom UserAgent
mediumDetects execution of curl.exe with custom useragent options
windows
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
windows
Data Export From MSSQL Table Via BCP.EXE
mediumDetects the execution of the BCP utility in order to export data from the database. Attackers were seen saving their malware to a database column or table and then later extracting it via "bcp.exe" into a file.
windows
Defrag Deactivation
mediumDetects the deactivation and disabling of the Scheduled defragmentation task as seen by Slingshot APT group
windows
Deleted Data Overwritten Via Cipher.EXE
mediumDetects usage of the "cipher" built-in utility in order to overwrite deleted data from disk. Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives
windows
Detected Windows Software Discovery
mediumAdversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable.
windows
Detection of PowerShell Execution via Sqlps.exe
mediumThis rule detects execution of a PowerShell code through the sqlps.exe utility, which is included in the standard set of utilities supplied with the MSSQL Server. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.
windows
DeviceCredentialDeployment Execution
mediumDetects the execution of DeviceCredentialDeployment to hide a process from view.
windows
Direct Autorun Keys Modification
mediumDetects direct modification of autostart extensibility point (ASEP) in registry using reg.exe.
windows
Disable Or Stop Services
mediumDetects the usage of utilities such as 'systemctl', 'service'...etc to stop or disable tools and services on Linux systems. Attackers may stop or disable security tools and services to evade detection, maintain persistence, or disrupt system operations.
linux
Disable Security Tools
mediumDetects disabling security tools
macos
Disabling Security Tools
mediumDetects disabling security tools
linux
Disk Image Creation Via Hdiutil - MacOS
mediumDetects the execution of the hdiutil utility in order to create a disk image.
macos
Disk Image Mounting Via Hdiutil - MacOS
mediumDetects the execution of the hdiutil utility in order to mount disk images.
macos
Diskshadow Child Process Spawned
mediumDetects any child process spawning from "Diskshadow.exe". This could be due to executing Diskshadow in interpreter mode or script mode and using the "exec" flag to launch other applications.
windows
Diskshadow Script Mode - Execution From Potential Suspicious Location
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag where the script is located in a potentially suspicious location.
windows
Diskshadow Script Mode - Uncommon Script Extension Execution
mediumDetects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.
windows
Diskshadow Script Mode Execution
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag. Attackers often abuse "diskshadow" to execute scripts that deleted the shadow copies on the systems. Investigate the content of the scripts and its location.
windows
Dism Remove Online Package
mediumDeployment Image Servicing and Management tool. DISM is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows
DLL Call by Ordinal Via Rundll32.EXE
mediumDetects calls of DLLs exports by ordinal numbers via rundll32.dll.
windows
DLL Execution via Rasautou.exe
mediumDetects using Rasautou.exe for loading arbitrary .DLL specified in -d option and executes the export specified in -p.
windows
DLL Execution Via Register-cimprovider.exe
mediumDetects using register-cimprovider.exe to execute arbitrary dll file.
windows
DLL Loaded via CertOC.EXE
mediumDetects when a user installs certificates by using CertOC.exe to loads the target DLL file.
windows
DllUnregisterServer Function Call Via Msiexec.EXE
mediumDetects MsiExec loading a DLL and calling its DllUnregisterServer function
windows
Domain Trust Discovery Via Dsquery
mediumDetects execution of "dsquery.exe" for domain trust discovery
windows
Download File To Potentially Suspicious Directory Via Wget
mediumDetects the use of wget to download content to a suspicious directory
linux
Driver/DLL Installation Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "INSTALLDRIVER" which installs a new ODBC driver. Attackers abuse this to install and run malicious DLLs.
windows
DriverQuery.EXE Execution
mediumDetect usage of the "driverquery" utility. Which can be used to perform reconnaissance on installed drivers
windows
Dropping Of Password Filter DLL
mediumDetects dropping of dll files in system32 that may be used to retrieve user credentials from LSASS
windows
Dumping Process via Sqldumper.exe
mediumDetects process dump via legitimate sqldumper.exe binary
windows
DumpMinitool Execution
mediumDetects the use of "DumpMinitool.exe" a tool that allows the dump of process memory via the use of the "MiniDumpWriteDump"
windows
Dynamic .NET Compilation Via Csc.EXE
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows
Dynamic .NET Compilation Via Csc.EXE - Hunting
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows
Elevated System Shell Spawned
mediumDetects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges. Use this rule to hunt for potential suspicious processes.
windows
Elevated System Shell Spawned From Uncommon Parent Location
mediumDetects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges from a uncommon parent location.
windows
Enable BPF Kprobes Tracing
mediumDetects common command used to enable bpf kprobes tracing
linux
Enumerate All Information With Whoami.EXE
mediumDetects the execution of "whoami.exe" with the "/all" flag
windows
Enumeration for 3rd Party Creds From CLI
mediumDetects processes that query known 3rd party registry keys that holds credentials via commandline
windows
Enumeration for Credentials in Registry
mediumAdversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services
windows
Esentutl Gather Credentials
mediumConti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.
windows
Esentutl Steals Browser Information
mediumOne way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
windows
ESXi Account Creation Via ESXCLI
mediumDetects user account creation on ESXi system via esxcli
linux
ESXi Network Configuration Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "network" flag in order to retrieve information about the network configuration.
linux
ESXi Storage Information Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "storage" flag in order to retrieve information about the storage status and other related information. Seen used by malware such as DarkSide and LockBit.
linux
ESXi Syslog Configuration Change Via ESXCLI
mediumDetects changes to the ESXi syslog configuration via "esxcli"
linux
ESXi System Information Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "system" flag in order to retrieve information about the different component of the system. Such as accounts, modules, NTP, etc.
linux
ESXi VM Kill Via ESXCLI
mediumDetects execution of the "esxcli" command with the "vm" and "kill" flag in order to kill/shutdown a specific VM.
linux
ESXi VM List Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "vm" flag in order to retrieve information about the installed VMs.
linux
ESXi VSAN Information Discovery Via ESXCLI
mediumDetects execution of the "esxcli" command with the "vsan" flag in order to retrieve information about virtual storage. Seen used by malware such as DarkSide.
linux
EventLog Query Requests By Builtin Utilities
mediumDetect attempts to query the contents of the event log using command line utilities. Attackers use this technique in order to look for sensitive information in the logs such as passwords, usernames, IPs, etc.
windows
Execute Code with Pester.bat
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows
Execute Code with Pester.bat as Parent
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows
Execute Files with Msdeploy.exe
mediumDetects file execution using the msdeploy.exe lolbin
windows
Execute From Alternate Data Streams
mediumDetects execution from an Alternate Data Stream (ADS). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection
windows
Execution From Webserver Root Folder
mediumDetects a program executing from a web server root folder. Use this rule to hunt for potential interesting activity such as webshell or backdoors
windows
Execution Of Script Located In Potentially Suspicious Directory
mediumDetects executions of scripts located in potentially suspicious locations such as "/tmp" via a shell such as "bash", "sh", etc.
linux
Execution of Suspicious File Type Extension
mediumDetects whether the image specified in a process creation event doesn't refer to an ".exe" (or other known executable extension) file. This can be caused by process ghosting or other unorthodox methods to start a process. This rule might require some initial baselining to align with some third party tooling in the user environment.
windows
Exploit for CVE-2017-0261
mediumDetects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
windows
Explorer Process Tree Break
mediumDetects a command line process that uses explorer.exe to launch arbitrary commands or binaries, which is similar to cmd.exe /c, only it breaks the process tree and makes its parent a new instance of explorer spawning from "svchost"
windows
File Decryption Using Gpg4win
mediumDetects usage of Gpg4win to decrypt files
windows
File Download From Browser Process Via Inline URL
mediumDetects execution of a browser process with a URL argument pointing to a file with a potentially interesting extension. This can be abused to download arbitrary files or to hide from the user for example by launching the browser in a minimized state.
windows
File Download From IP URL Via Curl.EXE
mediumDetects file downloads directly from IP address URL using curl.exe
windows
File Download Using ProtocolHandler.exe
mediumDetects usage of "ProtocolHandler" to download files. Downloaded files will be located in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)
windows
File Download Via Bitsadmin
mediumDetects usage of bitsadmin downloading a file
windows
File Download via CertOC.EXE
mediumDetects when a user downloads a file by using CertOC.exe
windows
File Download Via Curl.EXE
mediumDetects file download using curl.exe
windows
File Download Via InstallUtil.EXE
mediumDetects use of .NET InstallUtil.exe in order to download arbitrary files. The files will be written to "%LOCALAPPDATA%\Microsoft\Windows\INetCache\IE\"
windows
File Download Via Nscurl - MacOS
mediumDetects the execution of the nscurl utility in order to download files.
macos
File Encoded To Base64 Via Certutil.EXE
mediumDetects the execution of certutil with the "encode" flag to encode a file to base64. This can be abused by threat actors and attackers for data exfiltration
windows
File Encryption Using Gpg4win
mediumDetects usage of Gpg4win to encrypt files
windows
File or Folder Permissions Modifications
mediumDetects a file or folder's permissions being modified or tampered with.
windows
File Recovery From Backup Via Wbadmin.EXE
mediumDetects the recovery of files from backups via "wbadmin.exe". Attackers can restore sensitive files such as NTDS.DIT or Registry Hives from backups in order to potentially extract credentials.
windows
File Time Attribute Change
mediumDetect file time attribute change to hide new or changes to existing files
macos
Filter Driver Unloaded Via Fltmc.EXE
mediumDetect filter driver unloading activity via fltmc.exe
windows
Findstr Launching .lnk File
mediumDetects usage of findstr to identify and execute a lnk file as seen within the HHS redirect attack
windows
Firewall Disabled via Netsh.EXE
mediumDetects netsh commands that turns off the Windows firewall
windows
Firewall Rule Deleted Via Netsh.EXE
mediumDetects the removal of a port or application rule in the Windows Firewall configuration using netsh
windows
Firewall Rule Update Via Netsh.EXE
mediumDetects execution of netsh with the "advfirewall" and the "set" option in order to set new values for properties of a existing rule
windows
Flush Iptables Ufw Chain
mediumDetect use of iptables to flush all firewall rules, tables and chains and allow all network traffic
linux
Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows
Forfiles Command Execution
mediumDetects the execution of "forfiles" with the "/c" flag. While this is an expected behavior of the tool, it can be abused in order to proxy execution through it with any binary. Can be used to bypass application whitelisting.
windows
FTP Connection Open Attempt Via Winscp CLI
mediumDetects the execution of Winscp with the "-command" and the "open" flags in order to open an FTP connection. Akira ransomware was seen using this technique in order to exfiltrate data.
windows
Github Self-Hosted Runner Execution
mediumDetects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.
windows
Gpresult Display Group Policy Information
mediumDetects cases in which a user uses the built-in Windows utility gpresult to display the Resultant Set of Policy (RSoP) information
windows
Gpscript Execution
mediumDetects the execution of the LOLBIN gpscript, which executes logon or startup scripts configured in Group Policy
windows
Greedy File Deletion Using Del
mediumDetects execution of the "del" builtin command to remove files using greedy/wildcard expression. This is often used by malware to delete content of folders that perhaps contains the initial malware infection or to delete evidence.
windows
Group Has Been Deleted Via Groupdel
mediumDetects execution of the "groupdel" binary. Which is used to delete a group. This is sometimes abused by threat actors in order to cover their tracks
linux
Group Membership Reconnaissance Via Whoami.EXE
mediumDetects the execution of whoami.exe with the /group command line flag to show group membership for the current user, account type, security identifiers (SID), and attributes.
windows
Gzip Archive Decode Via PowerShell
mediumDetects attempts of decoding encoded Gzip archives via PowerShell.
windows
HackTool - Impersonate Execution
mediumDetects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
windows
HackTool - Jlaive In-Memory Assembly Execution
mediumDetects the use of Jlaive to execute assemblies in a copied PowerShell
windows
HackTool - LaZagne Execution
mediumDetects the execution of the LaZagne. A utility used to retrieve multiple types of passwords stored on a local computer. LaZagne has been leveraged multiple times by threat actors in order to dump credentials.
windows
HackTool - SharpLDAPmonitor Execution
mediumDetects execution of the SharpLDAPmonitor. Which can monitor the creation, deletion and changes to LDAP objects.
windows
HackTool - WinRM Access Via Evil-WinRM
mediumAdversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
windows
Hardware Model Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC with the "csproduct" which is used to obtain information such as hardware models and vendor information
windows
Harvesting Of Wifi Credentials Via Netsh.EXE
mediumDetect the harvesting of wifi credentials using netsh.exe
windows
Headless Process Launched Via Conhost.EXE
mediumDetects the launch of a child process via "conhost.exe" with the "--headless" flag. The "--headless" flag hides the windows from the user upon execution.
windows
Hidden Flag Set On File/Directory Via Chflags - MacOS
mediumDetects the execution of the "chflags" utility with the "hidden" flag, in order to hide files on MacOS. When a file or directory has this hidden flag set, it becomes invisible to the default file listing commands and in graphical file browsers.
macos
Hidden Powershell in Link File Pattern
mediumDetects events that appear when a user click on a link file with a powershell command in it
windows
Hidden User Creation
mediumDetects creation of a hidden user account on macOS (UserID < 500) or with IsHidden option
macos
Hiding Files with Attrib.exe
mediumDetects usage of attrib.exe to hide files from users.
windows
Hiding User Account Via SpecialAccounts Registry Key - CommandLine
mediumDetects changes to the registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\Userlist" where the value is set to "0" in order to hide user account from being listed on the logon screen.
windows
Ie4uinit Lolbin Use From Invalid Path
mediumDetect use of ie4uinit.exe to execute commands from a specially prepared ie4uinit.inf file from a directory other than the usual directories
windows
IIS Native-Code Module Command Line Installation
mediumDetects suspicious IIS native-code module installations via command line
windows
IIS WebServer Log Deletion via CommandLine Utilities
mediumDetects attempts to delete Internet Information Services (IIS) log files via command line utilities, which is a common defense evasion technique used by attackers to cover their tracks. Threat actors often abuse vulnerabilities in web applications hosted on IIS servers to gain initial access and later delete IIS logs to evade detection.
windows
Import LDAP Data Interchange Format File Via Ldifde.EXE
mediumDetects the execution of "Ldifde.exe" with the import flag "-i". The can be abused to include HTTP-based arguments which will allow the arbitrary download of files from a remote server.
windows
Import PowerShell Modules From Suspicious Directories - ProcCreation
mediumDetects powershell scripts that import modules from suspicious directories
windows
Imports Registry Key From a File
mediumDetects the import of the specified file to the registry with regedit.exe.
windows
Indicator Removal on Host - Clear Mac System Logs
mediumDetects deletion of local audit logs
macos
Indirect Command Execution From Script File Via Bash.EXE
mediumDetects execution of Microsoft bash launcher without any flags to execute the content of a bash script directly. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
windows
Indirect Command Execution via SFTP ProxyCommand
mediumDetects the use of SFTP.exe to execute commands indirectly via ProxyCommand parameter. Threat actors were seen leveraging this legitimate Windows binary to bypass security controls and execute arbitrary commands while evading detection.
windows
Indirect Inline Command Execution Via Bash.EXE
mediumDetects execution of Microsoft bash launcher with the "-c" flag. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
windows
InfDefaultInstall.exe .inf Execution
mediumExecutes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.
windows
Insecure Proxy/DOH Transfer Via Curl.EXE
mediumDetects execution of "curl.exe" with the "insecure" flag over proxy or DOH.
windows
Insecure Transfer Via Curl.EXE
mediumDetects execution of "curl.exe" with the "--insecure" flag.
windows
Install New Package Via Winget Local Manifest
mediumDetects usage of winget to install applications via manifest file. Adversaries can abuse winget to download payloads remotely and execute them. The manifest option enables you to install an application by passing in a YAML file directly to the client. Winget can be used to download and install exe, msi or msix files later.
windows
Interactive Bash Suspicious Children
mediumDetects suspicious interactive bash as a parent to rather uncommon child processes
linux
Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe, which can be used for various attacks against the NTDS database (NTDS.DIT)
windows
Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the invocation of PowerShell commands with references to classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows
Invoke-Obfuscation COMPRESS OBFUSCATION
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows
JAMF MDM Potential Suspicious Child Process
mediumDetects potential suspicious child processes of "jamf". Could be a sign of potential abuse of Jamf as a C2 server as seen by Typhon MythicAgent.
macos
Java Running with Remote Debugging
mediumDetects a JAVA process running with remote debugging allowing more than just localhost to connect
windows
Launch Agent/Daemon Execution Via Launchctl
mediumDetects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.
macos
Launch-VsDevShell.PS1 Proxy Execution
mediumDetects the use of the 'Launch-VsDevShell.ps1' Microsoft signed script to execute commands.
windows
Linux Base64 Encoded Pipe to Shell
mediumDetects suspicious process command line that uses base64 encoded input for execution with a shell
linux
Linux Base64 Encoded Shebang In CLI
mediumDetects the presence of a base64 version of the shebang in the commandline, which could indicate a malicious payload about to be decoded
linux
Linux Logs Clearing Attempts
mediumDetects logs clearing attempts on Linux systems via utilities such as 'rm', 'rmdir', 'shred', and 'unlink' targeting log files and directories. Adversaries often try to clear logs to cover their tracks after performing malicious activities.
linux
Linux Shell Pipe to Shell
mediumDetects suspicious process command line that starts with a shell that executes something and finally gets piped into another shell
linux
Loaded Module Enumeration Via Tasklist.EXE
mediumDetects the enumeration of a specific DLL or EXE being used by a binary via "tasklist.exe". This is often used by attackers in order to find the specific process identifier (PID) that is using the DLL in question. In order to dump the process memory or perform other nefarious actions.
windows
Local File Read Using Curl.EXE
mediumDetects execution of "curl.exe" with the "file://" protocol handler in order to read local files.
windows
Logged-On User Password Change Via Ksetup.EXE
mediumDetects password change for the logged-on user's via "ksetup.exe"
windows
LOLBAS Data Exfiltration by DataSvcUtil.exe
mediumDetects when a user performs data exfiltration by using DataSvcUtil.exe
windows
LOLBIN Execution From Abnormal Drive
mediumDetects LOLBINs executing from an abnormal or uncommon drive such as a mounted ISO.
windows
Lolbin Runexehelper Use As Proxy
mediumDetect usage of the "runexehelper.exe" binary as a proxy to launch other programs
windows
Lolbin Unregmp2.exe Use As Proxy
mediumDetect usage of the "unregmp2.exe" binary as a proxy to launch a custom version of "wmpnscfg.exe"
windows
LSA PPL Protection Setting Modification via CommandLine
mediumDetects modification of LSA PPL protection settings via CommandLine. It may indicate an attempt to disable protection and enable credential dumping tools to access LSASS process memory.
windows
MacOS Scripting Interpreter AppleScript
mediumDetects execution of AppleScript of the macOS scripting language AppleScript.
macos
Malicious PE Execution by Microsoft Visual Studio Debugger
mediumThere is an option for a MS VS Just-In-Time Debugger "vsjitdebugger.exe" to launch specified executable and attach a debugger. This option may be used adversaries to execute malicious code by signed verified binary. The debugger is installed alongside with Microsoft Visual Studio package.
windows
Manual Execution of Script Inside of a Compressed File
mediumThis is a threat-hunting query to collect information related to the interactive execution of a script from inside a compressed file (zip/rar). Windows will automatically run the script using scripting interpreters such as wscript and cscript binaries. From the query below, the child process is the script interpreter that will execute the script. The script extension is also a set of standard extensions that Windows OS recognizes. Selections 1-3 contain three different execution scenarios. 1. Compressed file opened using 7zip. 2. Compressed file opened using WinRar. 3. Compressed file opened using native windows File Explorer capabilities. When the malicious script is double-clicked, it will be extracted to the respected directories as signified by the CommandLine on each of the three Selections. It will then be executed using the relevant script interpreter."
windows
Microsoft Workflow Compiler Execution
mediumDetects the execution of Microsoft Workflow Compiler, which may permit the execution of arbitrary unsigned code.
windows
Modify Group Policy Settings
mediumDetect malicious GPO modifications can be used to implement many other malicious behaviors.
windows
Monitoring For Persistence Via BITS
mediumBITS will allow you to schedule a command to execute after a successful download to notify you that the job is finished. When the job runs on the system the command specified in the BITS job will be executed. This can be abused by actors to create a backdoor within the system and for persistence. It will be chained in a BITS job to schedule the download of malware/additional binaries and execute the program after being downloaded.
windows
Mount Execution With Hidepid Parameter
mediumDetects execution of the "mount" command with "hidepid" parameter to make invisible processes to other users from the system
linux
MSExchange Transport Agent Installation
mediumDetects the Installation of a Exchange Transport Agent
windows
Msiexec Quiet Installation
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows
MsiExec Web Install
mediumDetects suspicious msiexec process starts with web addresses as parameter
windows
Msxsl.EXE Execution
mediumDetects the execution of the MSXSL utility. This can be used to execute Extensible Stylesheet Language (XSL) files. These files are commonly used to describe the processing and rendering of data within XML files. Adversaries can abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses.
windows
Netsh Allow Group Policy on Microsoft Defender Firewall
mediumAdversaries may modify system firewalls in order to bypass controls limiting network usage
windows
New Agent Skills Installation Attempt Via Node.EXE
mediumDetects the attempt to install new skills for AI agents using the "npx skills" command. Agent skills enhance AI agents with new capabilities, but attackers may abuse this mechanism to inject malicious commands executed by the agent on behalf of the user. The "npx skills" command can install skills for various agents (e.g., Claude Code, Cursor, and others). Analysts should review any installed skills to verify their legitimacy. Note: Tune this rule based on whether AI agent tooling is allowed in your environment. In environments where such tooling is authorized, this detection may reflect normal activity and the alert level should be adjusted accordingly. In environments where AI agent tooling is not permitted, this activity is likely suspicious and may require immediate investigation.
windows
New Capture Session Launched Via DXCap.EXE
mediumDetects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.
windows
New DLL Registered Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.
windows
New DMSA Service Account Created in Specific OUs
mediumDetects the creation of a dMSASvc account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the Cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows
New File Exclusion Added To Time Machine Via Tmutil - MacOS
mediumDetects the addition of a new file or path exclusion to MacOS Time Machine via the "tmutil" utility. An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.
macos
New Firewall Rule Added Via Netsh.EXE
mediumDetects the addition of a new rule to the Windows firewall via netsh
windows
New Generic Credentials Added Via Cmdkey.EXE
mediumDetects usage of "cmdkey.exe" to add generic credentials. As an example, this can be used before connecting to an RDP session via command line interface.
windows
New Kernel Driver Via SC.EXE
mediumDetects creation of a new service (kernel driver) with the type "kernel"
windows
New Network Trace Capture Started Via Netsh.EXE
mediumDetects the execution of netsh with the "trace" flag in order to start a network capture
windows
New Port Forwarding Rule Added Via Netsh.EXE
mediumDetects the execution of netsh commands that configure a new port forwarding (PortProxy) rule
windows
New Remote Desktop Connection Initiated Via Mstsc.EXE
mediumDetects the usage of "mstsc.exe" with the "/v" flag to initiate a connection to a remote server. Adversaries may use valid accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
windows
New Root Certificate Installed Via CertMgr.EXE
mediumDetects execution of "certmgr" with the "add" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows
New Root Certificate Installed Via Certutil.EXE
mediumDetects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows
New Self Extracting Package Created Via IExpress.EXE
mediumDetects the "iexpress.exe" utility creating self-extracting packages. Attackers where seen leveraging "iexpress" to compile packages on the fly via ".sed" files. Investigate the command line options provided to "iexpress" and in case of a ".sed" file, check the contents and legitimacy of it.
windows
New User Account Creation Attempt Via ADSI in CommandLine
mediumDetects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
windows
New User Created Via Net.EXE
mediumIdentifies the creation of local users via the net.exe command.
windows
New Virtual Smart Card Created Via TpmVscMgr.EXE
mediumDetects execution of "Tpmvscmgr.exe" to create a new virtual smart card.
windows
Node Process Executions
mediumDetects the execution of other scripts using the Node executable packaged with Adobe Creative Cloud
windows
Nohup Execution
mediumDetects usage of nohup which could be leveraged by an attacker to keep a process running or break out from restricted environments
linux
Nslookup PowerShell Download Cradle - ProcessCreation
mediumDetects suspicious powershell download cradle using nslookup. This cradle uses nslookup to extract payloads from DNS records
windows
Obfuscated IP Download Activity
mediumDetects use of an encoded/obfuscated version of an IP address (hex, octal...) in an URL combined with a download command
windows
Obfuscated IP Via CLI
mediumDetects usage of an encoded/obfuscated version of an IP address (hex, octal, etc.) via command line
windows
OpenEDR Spawning Command Shell
mediumDetects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities. This may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool. Threat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.
windows
Osacompile Execution By Potentially Suspicious Applet/Osascript
mediumDetects potential suspicious applet or osascript executing "osacompile".
macos
Password Provided In Command Line Of Net.EXE
mediumDetects a when net.exe is called with a password in the command line
windows
Password Set to Never Expire via WMI
mediumDetects the use of wmic.exe to modify user account settings and explicitly disable password expiration.
windows
Payload Decoded and Decrypted via Built-in Utilities
mediumDetects when a built-in utility is used to decode and decrypt a payload after a macOS disk image (DMG) is executed. Malware authors may attempt to evade detection and trick users into executing malicious code by encoding and encrypting their payload and placing it in a disk image file. This behavior is consistent with adware or malware families such as Bundlore and Shlayer.
macos
PDQ Deploy Remote Adminstartion Tool Execution
mediumDetect use of PDQ Deploy remote admin tool
windows
Perl Inline Command Execution
mediumDetects execution of perl using the "-e"/"-E" flags. This is could be used as a way to launch a reverse shell or execute live perl code.
windows
Permission Check Via Accesschk.EXE
mediumDetects the usage of the "Accesschk" utility, an access and privilege audit tool developed by SysInternal and often being abused by attacker to verify process privileges
windows
Permission Misconfiguration Reconnaissance Via Findstr.EXE
mediumDetects usage of findstr with the "EVERYONE" or "BUILTIN" keywords. This was seen being used in combination with "icacls" and other utilities to spot misconfigured files or folders permissions.
windows
Persistence Via TypedPaths - CommandLine
mediumDetects modification addition to the 'TypedPaths' key in the user or admin registry via the commandline. Which might indicate persistence attempt
windows
Php Inline Command Execution
mediumDetects execution of php using the "-r" flag. This is could be used as a way to launch a reverse shell or execute live php code.
windows
PktMon.EXE Execution
mediumDetects execution of PktMon, a tool that captures network packets.
windows
Pnscan Binary Data Transmission Activity
mediumDetects command line patterns associated with the use of Pnscan for sending and receiving binary data across the network. This behavior has been identified in a Linux malware campaign targeting Docker, Apache Hadoop, Redis, and Confluence and was previously used by the threat actor known as TeamTNT
linux
Port Forwarding Activity Via SSH.EXE
mediumDetects port forwarding activity via SSH.exe
windows
Portable Gpg.EXE Execution
mediumDetects the execution of "gpg.exe" from uncommon location. Often used by ransomware and loaders to decrypt/encrypt data.
windows
Potential Active Directory Enumeration Using AD Module - ProcCreation
mediumDetects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
windows
Potential Amazon SSM Agent Hijacking
mediumDetects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
windows
Potential AMSI Bypass Using NULL Bits
mediumDetects usage of special strings/null bits in order to potentially bypass AMSI functionalities
windows
Potential Application Whitelisting Bypass via Dnx.EXE
mediumDetects the execution of Dnx.EXE. The Dnx utility allows for the execution of C# code. Attackers might abuse this in order to bypass application whitelisting.
windows
Potential APT FIN7 Exploitation Activity
mediumDetects potential APT FIN7 exploitation activity as reported by Google. In order to obtain initial access, FIN7 used compromised Remote Desktop Protocol (RDP) credentials to login to a target server and initiate specific Windows process chains.
windows
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
mediumDetects potential BlueMushroom DLL loading activity via regsvr32 from AppData Local
windows
Potential Arbitrary Command Execution Via FTP.EXE
mediumDetects execution of "ftp.exe" script with the "-s" or "/s" flag and any child processes ran by "ftp.exe".
windows
Potential Arbitrary DLL Load Using Winword
mediumDetects potential DLL sideloading using the Microsoft Office winword process via the '/l' flag.
windows
Potential Arbitrary File Download Via Cmdl32.EXE
mediumDetects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious.
windows
Potential Binary Impersonating Sysinternals Tools
mediumDetects binaries that use the same name as legitimate sysinternals tools to evade detection. This rule looks for the execution of binaries that are named similarly to Sysinternals tools. Adversary may rename their malicious tools as legitimate Sysinternals tools to evade detection.
windows
Potential Binary Proxy Execution Via Cdb.EXE
mediumDetects usage of "cdb.exe" to launch arbitrary processes or commands from a debugger script file
windows
Potential Binary Proxy Execution Via VSDiagnostics.EXE
mediumDetects execution of "VSDiagnostics.exe" with the "start" command in order to launch and proxy arbitrary binaries.
windows
Potential Browser Data Stealing
mediumAdversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store.
windows
Potential COM Objects Download Cradles Usage - Process Creation
mediumDetects usage of COM objects that can be abused to download files in PowerShell by CLSID
windows
Potential Command Line Path Traversal Evasion Attempt
mediumDetects potential evasion or obfuscation attempts using bogus path traversal via the commandline
windows
Potential Commandline Obfuscation Using Escape Characters
mediumDetects potential commandline obfuscation using known escape characters
windows
Potential CommandLine Obfuscation Using Unicode Characters
mediumDetects potential CommandLine obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
windows
Potential Configuration And Service Reconnaissance Via Reg.EXE
mediumDetects the usage of "reg.exe" in order to query reconnaissance information from the registry. Adversaries may interact with the Windows registry to gather information about credentials, the system, configuration, and installed software.
windows
Potential Cookies Session Hijacking
mediumDetects execution of "curl.exe" with the "-c" flag in order to save cookie data.
windows
Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
mediumDetects potential exploitation attempt of CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager. As reported by Morphisec, part of the attack chain, threat actors used PowerShell commands that executed as a child processes of the legitimate Tomcat "prunsrv.exe" process application.
windows
Potential Data Exfiltration Via Curl.EXE
mediumDetects the execution of the "curl" process with "upload" flags. Which might indicate potential data exfiltration
windows
Potential Defense Evasion Via Binary Rename
mediumDetects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
windows
Potential Discovery Activity Using Find - Linux
mediumDetects usage of "find" binary in a suspicious manner to perform discovery
linux
Potential Discovery Activity Using Find - MacOS
mediumDetects usage of "find" binary in a suspicious manner to perform discovery
macos
Potential Discovery Activity Via Dnscmd.EXE
mediumDetects an attempt to leverage dnscmd.exe to enumerate the DNS zones of a domain. DNS zones used to host the DNS records for a particular domain.
windows
Potential DLL File Download Via PowerShell Invoke-WebRequest
mediumDetects potential DLL files being downloaded using the PowerShell Invoke-WebRequest or Invoke-RestMethod cmdlets.
windows
Potential DLL Injection Or Execution Using Tracker.exe
mediumDetects potential DLL injection and execution using "Tracker.exe"
windows
Potential DLL Injection Via AccCheckConsole
mediumDetects the execution "AccCheckConsole" a command-line tool for verifying the accessibility implementation of an application's UI. One of the tests that this checker can run are called "verification routine", which tests for things like Consistency, Navigation, etc. The tool allows a user to provide a DLL that can contain a custom "verification routine". An attacker can build such DLLs and pass it via the CLI, which would then be loaded in the context of the "AccCheckConsole" utility.
windows
Potential DLL Sideloading Activity Via ExtExport.EXE
mediumDetects the execution of "Extexport.exe".A utility that is part of the Internet Explorer browser and is used to export and import various settings and data, particularly when switching between Internet Explorer and other web browsers like Firefox. It allows users to transfer bookmarks, browsing history, and other preferences from Internet Explorer to Firefox or vice versa. It can be abused as a tool to side load any DLL. If a folder is provided in the command line it'll load any DLL with one of the following names "mozcrt19.dll", "mozsqlite3.dll", or "sqlite.dll". Arbitrary DLLs can also be loaded if a specific number of flags was provided.
windows
Potential DLL Sideloading Via DeviceEnroller.EXE
mediumDetects the use of the PhoneDeepLink parameter to potentially sideload a DLL file that does not exist. This non-existent DLL file is named "ShellChromeAPI.dll". Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
windows
Potential Dosfuscation Activity
mediumDetects possible payload obfuscation via the commandline
windows
Potential Download/Upload Activity Using Type Command
mediumDetects usage of the "type" command to download/upload data from WebDAV server
windows
Potential Dropper Script Execution Via WScript/CScript/MSHTA
mediumDetects wscript/cscript/mshta executions of scripts located in user directories
windows
Potential Exploitation of CVE-2025-5054 or CVE-2025-4598
mediumDetects attempts of an attacker to enable core dumps for set-user-ID (SUID) processes by modifying the system file /proc/sys/fs/suid_dumpable, typically by setting its value to 1 or 2. Enabling this feature allows memory dumps (core dumps) of SUID processes, which usually run with elevated privileges. These dumps may contain sensitive information such as passwords, cryptographic keys or other secrets. CVE-2025-5054: Information leak via core dumps from SUID binaries using apport. CVE-2025-4598: Information disclosure in systemd-coredump due to insecure handling of SUID process memory dumps.
linux
Potential Fake Instance Of Hxtsr.EXE Executed
mediumHxTsr.exe is a Microsoft compressed executable file called Microsoft Outlook Communications. HxTsr.exe is part of Outlook apps, because it resides in a hidden "WindowsApps" subfolder of "C:\Program Files". Any instances of hxtsr.exe not in this folder may be malware camouflaging itself as HxTsr.exe
windows
Potential File Download Via MS-AppInstaller Protocol Handler
mediumDetects usage of the "ms-appinstaller" protocol handler via command line to potentially download arbitrary files via AppInstaller.EXE The downloaded files are temporarly stored in ":\Users\%username%\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\<RANDOM-8-CHAR-DIRECTORY>"
windows
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI
mediumDetects command line containing reference to the "::$index_allocation" stream, which can be used as a technique to prevent access to folders or files from tooling such as "explorer.exe" or "powershell.exe"
windows
Potential Homoglyph Attack Using Lookalike Characters
mediumDetects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
windows
Potential In-Memory Download And Compile Of Payloads
mediumDetects potential in-memory downloading and compiling of applets using curl and osacompile as seen used by XCSSET malware
macos
Potential KamiKakaBot Activity - Lure Document Execution
mediumDetects the execution of a Word document via the WinWord Start Menu shortcut. This behavior was observed being used by KamiKakaBot samples in order to initiate the 2nd stage of the infection.
windows
Potential KamiKakaBot Activity - Shutdown Schedule Task Creation
mediumDetects the creation of a schedule task that runs weekly and execute the "shutdown /l /f" command. This behavior was observed being used by KamiKakaBot samples in order to achieve persistence on a system.
windows
Potential Lateral Movement via Windows Remote Shell
mediumDetects a child process spawned by 'winrshost.exe', which suggests remote command execution through Windows Remote Shell (WinRs) and may indicate potential lateral movement activity.
windows
Potential Linux Amazon SSM Agent Hijacking
mediumDetects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
linux
Potential Linux Process Code Injection Via DD Utility
mediumDetects the injection of code by overwriting the memory map of a Linux process using the "dd" Linux command.
linux
Potential Memory Dumping Activity Via LiveKD
mediumDetects execution of LiveKD based on PE metadata or image name
windows
Potential Mftrace.EXE Abuse
mediumDetects child processes of the "Trace log generation tool for Media Foundation Tools" (Mftrace.exe) which can abused to execute arbitrary binaries.
windows
Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE
mediumDetects the execution of "csc.exe" via "w3wp.exe" process. MOVEit affected hosts execute "csc.exe" via the "w3wp.exe" process to dynamically compile malicious DLL files. MOVEit is affected by a critical vulnerability. Exploited hosts show evidence of dynamically compiling a DLL and writing it under C:\\Windows\\Microsoft\.NET\\Framework64\\v4\.0\.30319\\Temporary ASP\.NET Files\\root\\([a-z0-9]{5,12})\\([a-z0-9]{5,12})\\App_Web_[a-z0-9]{5,12}\.dll. Hunting Opportunity Events from IIS dynamically compiling binaries via the csc.exe on behalf of the MOVEit application, especially since May 27th should be investigated.
windows
Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
mediumDetects execution of Windows Defender "OfflineScannerShell.exe" from its non standard directory. The "OfflineScannerShell.exe" binary is vulnerable to DLL side loading and will load any DLL named "mpclient.dll" from the current working directory.
windows
Potential Network Sniffing Activity Using Network Tools
mediumDetects potential network sniffing via use of network tools such as "tshark", "windump". Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
windows
Potential Obfuscated Ordinal Call Via Rundll32
mediumDetects execution of "rundll32" with potential obfuscated ordinal calls
windows
Potential Password Reconnaissance Via Findstr.EXE
mediumDetects command line usage of "findstr" to search for the "passwords" keyword in a variety of different languages
windows
Potential Password Spraying Attempt Using Dsacls.EXE
mediumDetects possible password spraying attempts using Dsacls
windows
Potential Persistence Attempt Via Existing Service Tampering
mediumDetects the modification of an existing service in order to execute an arbitrary payload when the service is started or killed as a potential method for persistence.
windows
Potential Persistence Attempt Via Run Keys Using Reg.EXE
mediumDetects suspicious command line reg.exe tool adding key to RUN key in Registry
windows
Potential Persistence Via Microsoft Compatibility Appraiser
mediumDetects manual execution of the "Microsoft Compatibility Appraiser" task via schtasks. In order to trigger persistence stored in the "\AppCompatFlags\TelemetryController" registry key.
windows
Potential Persistence Via Netsh Helper DLL
mediumDetects the execution of netsh with "add helper" flag in order to add a custom helper DLL. This technique can be abused to add a malicious helper DLL that can be used as a persistence proxy that gets called when netsh.exe is executed.
windows
Potential Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
mediumDetects execution of the "VMwareToolBoxCmd.exe" with the "script" and "set" flag to setup a specific script to run for a specific VM state
windows
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
mediumDetects the execution of concatenated commands via "cmd.exe". Pikabot often executes a combination of multiple commands via the command handler "cmd /c" in order to download and execute additional payloads. Commands such as "curl", "wget" in order to download extra payloads. "ping" and "timeout" are abused to introduce delays in the command execution and "Rundll32" is also used to execute malicious DLL files. In the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.
windows
Potential PowerShell Console History Access Attempt via History File
mediumDetects potential access attempts to the PowerShell console history directly via history file (ConsoleHost_history.txt). This can give access to plaintext passwords used in PowerShell commands or used for general reconnaissance.
windows
Potential PowerShell Downgrade Attack
mediumDetects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0
windows
Potential Process Execution Proxy Via CL_Invocation.ps1
mediumDetects calls to "SyncInvoke" that is part of the "CL_Invocation.ps1" script to proxy execution using "System.Diagnostics.Process"
windows
Potential Process Reconnaissance via Wmic.EXE
mediumDetects the execution of "wmic" with the "process" flag, which might indicate an attempt to perform reconnaissance on running processes. Adversaries may use wmic to query for running processes and their details as part of their reconnaissance efforts.
windows
Potential Product Class Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC in order to get a list of firewall, antivirus and antispywware products. Adversaries often enumerate security products installed on a system to identify security controls and potential ways to evade detection or disable protection mechanisms. This information helps them plan their next attack steps and choose appropriate techniques to bypass security measures.
windows
Potential Product Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC in order to get a list of firewall and antivirus products
windows
Potential Provlaunch.EXE Binary Proxy Execution Abuse
mediumDetects child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
windows
Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
mediumDetects potential malicious and unauthorized usage of bcdedit.exe
windows
Potential RDP Session Hijacking Activity
mediumDetects potential RDP Session Hijacking activity on Windows systems
windows
Potential Recon Activity Via Nltest.EXE
mediumDetects nltest commands that can be used for information discovery
windows
Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
mediumDetects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
windows
Potential ReflectDebugger Content Execution Via WerFault.EXE
mediumDetects execution of "WerFault.exe" with the "-pr" commandline flag that is used to run files stored in the ReflectDebugger key which could be used to store the path to the malware in order to masquerade the execution flow
windows
Potential Register_App.Vbs LOLScript Abuse
mediumDetects potential abuse of the "register_app.vbs" script that is part of the Windows SDK. The script offers the capability to register new VSS/VDS Provider as a COM+ application. Attackers can use this to install malicious DLLs for persistence and execution.
windows
Potential Regsvr32 Commandline Flag Anomaly
mediumDetects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon.
windows
Potential Remote Desktop Tunneling
mediumDetects potential use of an SSH utility to establish RDP over a reverse SSH Tunnel. This can be used by attackers to enable routing of network packets that would otherwise not reach their intended destination.
windows
Potential Ruby Reverse Shell
mediumDetects execution of ruby with the "-e" flag and calls to "socket" related functions. This could be an indication of a potential attempt to setup a reverse shell
linux
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
mediumDetects the use of the Microsoft signed script "CL_mutexverifiers" to proxy the execution of additional PowerShell script commands
windows
Potential ShellDispatch.DLL Functionality Abuse
mediumDetects potential "ShellDispatch.dll" functionality abuse to execute arbitrary binaries via "ShellExecute"
windows
Potential Shim Database Persistence via Sdbinst.EXE
mediumDetects installation of a new shim using sdbinst.exe. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims
windows
Potential SPN Enumeration Via Setspn.EXE
mediumDetects service principal name (SPN) enumeration used for Kerberoasting
windows
Potential Suspicious Activity Using SeCEdit
mediumDetects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy
windows
Potential Suspicious Browser Launch From Document Reader Process
mediumDetects when a browser process or browser tab is launched from an application that handles document files such as Adobe, Microsoft Office, etc. And connects to a web application over http(s), this could indicate a possible phishing attempt.
windows
Potential Suspicious Change To Sensitive/Critical Files
mediumDetects changes of sensitive and critical files. Monitors files that you don't expect to change without planning on Linux system. These files include, but are not limited to, system configuration files, authentication files, and critical application files. Attackers often target these files to maintain persistence, escalate privileges, or disrupt system operations.
linux
Potential Suspicious Registry File Imported Via Reg.EXE
mediumDetects the import of '.reg' files from suspicious paths using the 'reg.exe' utility
windows
Potential Suspicious Windows Feature Enabled - ProcCreation
mediumDetects usage of the built-in PowerShell cmdlet "Enable-WindowsOptionalFeature" used as a Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows
Potential UAC Bypass Via Sdclt.EXE
mediumA General detection for sdclt being spawned as an elevated process. This could be an indicator of sdclt being used for bypass UAC techniques.
windows
Potential Unquoted Service Path Reconnaissance Via Wmic.EXE
mediumDetects known WMI recon method to look for unquoted service paths using wmic. Often used by pentester and attacker enumeration scripts
windows
Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell
mediumDetects Powershell as a child of the WmiPrvSE process. Which could be a sign of lateral movement via WMI.
windows
Potential XCSSET Malware Infection
mediumIdentifies the execution traces of the XCSSET malware. XCSSET is a macOS trojan that primarily spreads via Xcode projects and maliciously modifies applications. Infected users are also vulnerable to having their credentials, accounts, and other vital data stolen.
macos
Potential Xterm Reverse Shell
mediumDetects usage of "xterm" as a potential reverse shell tunnel
linux
Potentially Over Permissive Permissions Granted Using Dsacls.EXE
mediumDetects usage of Dsacls to grant over permissive permissions
windows
Potentially Suspicious Cabinet File Expansion
mediumDetects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks
windows
Potentially Suspicious Child Process Of ClickOnce Application
mediumDetects potentially suspicious child processes of a ClickOnce deployment application
windows
Potentially Suspicious Child Process Of DiskShadow.EXE
mediumDetects potentially suspicious child processes of "Diskshadow.exe". This could be an attempt to bypass parent/child relationship detection or application whitelisting rules.
windows
Potentially Suspicious Child Process of KeyScrambler.exe
mediumDetects potentially suspicious child processes of KeyScrambler.exe
windows
Potentially Suspicious Child Process Of VsCode
mediumDetects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.
windows
Potentially Suspicious Child Process Of WinRAR.EXE
mediumDetects potentially suspicious child processes of WinRAR.exe.
windows
Potentially Suspicious CMD Shell Output Redirect
mediumDetects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
windows
Potentially Suspicious Command Targeting Teams Sensitive Files
mediumDetects a commandline containing references to the Microsoft Teams database or cookies files from a process other than Teams. The database might contain authentication tokens and other sensitive information about the logged in accounts.
windows
Potentially Suspicious Compression Tool Parameters
mediumDetects potentially suspicious command line arguments of common data compression tools
windows
Potentially Suspicious Desktop Background Change Using Reg.EXE
mediumDetects the execution of "reg.exe" to alter registry keys that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows
Potentially Suspicious Electron Application CommandLine
mediumDetects potentially suspicious CommandLine of electron apps (teams, discord, slack, etc.). This could be a sign of abuse to proxy execution through a signed binary.
windows
Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
mediumDetects execution of different log query utilities and commands to search and dump the content of specific event logs or look for specific event IDs. This technique is used by threat actors in order to extract sensitive information from events logs such as usernames, IP addresses, hostnames, etc.
windows
Potentially Suspicious Execution From Tmp Folder
mediumDetects a potentially suspicious execution of a process located in the '/tmp/' folder
linux
Potentially Suspicious Execution Of PDQDeployRunner
mediumDetects suspicious execution of "PDQDeployRunner" which is part of the PDQDeploy service stack that is responsible for executing commands and packages on a remote machines
windows
Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities from a potentially suspicious location
windows
Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities with an uncommon extension.
windows
Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
mediumDetects potentially suspicious inline JavaScript execution using Node.js with specific keywords in the command line.
windows
Potentially Suspicious JWT Token Search Via CLI
mediumDetects potentially suspicious search for JWT tokens via CLI by looking for the string "eyJ0eX" or "eyJhbG". JWT tokens are often used for access-tokens across various applications and services like Microsoft 365, Azure, AWS, Google Cloud, and others. Threat actors may search for these tokens to steal them for lateral movement or privilege escalation.
windows
Potentially Suspicious Named Pipe Created Via Mkfifo
mediumDetects the creation of a new named pipe using the "mkfifo" utility in a potentially suspicious location
linux
Potentially Suspicious NTFS Symlink Behavior Modification
mediumDetects the modification of NTFS symbolic link behavior using fsutil, which could be used to enable remote to local or remote to remote symlinks for potential attacks.
windows
Potentially Suspicious Ping/Copy Command Combination
mediumDetects uncommon and potentially suspicious one-liner command containing both "ping" and "copy" at the same time, which is usually used by malware.
windows
Potentially Suspicious PowerShell Child Processes
mediumDetects potentially suspicious child processes spawned by PowerShell. Use this rule to hunt for potential anomalies initiating from PowerShell scripts and commands.
windows
Potentially Suspicious Powershell Script Execution From Temp Folder
mediumDetects a potentially suspicious powershell script executions from temporary folder
windows
Potentially Suspicious Regsvr32 HTTP/FTP Pattern
mediumDetects regsvr32 execution to download/install/register new DLLs that are hosted on Web or FTP servers.
windows
Potentially Suspicious Rundll32 Activity
mediumDetects suspicious execution of rundll32, with specific calls to some DLLs with known LOLBIN functionalities
windows
Potentially Suspicious Rundll32.EXE Execution of UDL File
mediumDetects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
windows
Potentially Suspicious Usage Of Qemu
mediumDetects potentially suspicious execution of the Qemu utility in a Windows environment. Threat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.
windows
Potentially Suspicious WebDAV LNK Execution
mediumDetects possible execution via LNK file accessed on a WebDAV server.
windows
Potentially Suspicious Windows App Activity
mediumDetects potentially suspicious child process of applications launched from inside the WindowsApps directory. This could be a sign of a rogue ".appx" package installation/execution
windows
Powershell Defender Exclusion
mediumDetects requests to exclude files, folders or processes from Antivirus scanning using PowerShell cmdlets
windows
PowerShell Download Pattern
mediumDetects a Powershell process that contains download commands in its command line string
windows
Powershell Executed From Headless ConHost Process
mediumDetects the use of powershell commands from headless ConHost window. The "--headless" flag hides the windows from the user upon execution.
windows
PowerShell Get-Clipboard Cmdlet Via CLI
mediumDetects usage of the 'Get-Clipboard' cmdlet via CLI
windows
Powershell Inline Execution From A File
mediumDetects inline execution of PowerShell code from a file
windows
PowerShell MSI Install via WindowsInstaller COM From Remote Location
mediumDetects the execution of PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`) hosted remotely. This could be indication of malicious software deployment or lateral movement attempts using Windows Installer functionality. And the usage of WindowsInstaller COM object rather than msiexec could be an attempt to bypass the detection.
windows
PowerShell Script Run in AppData
mediumDetects a suspicious command line execution that invokes PowerShell with reference to an AppData folder
windows
Print History File Contents
mediumDetects events in which someone prints the contents of history files to the commandline or redirects it to a file for reconnaissance
linux
Private Keys Reconnaissance Via CommandLine Tools
mediumAdversaries may search for private key certificate files on compromised systems for insecurely stored credential
windows
Procdump Execution
mediumDetects usage of the SysInternals Procdump utility
windows
Process Creation Attempt via Wmic.EXE
mediumDetects the attempt to create a process via "wmic" with the "process call create" flag, which might indicate an attempt to execute a malicious process on the compromised host. Adversaries may use wmic to execute a process on the compromised host as part of their attack. This event is triggered on on attempt and process creation can be either successful or unsuccessful.
windows
Process Creation Using Sysnative Folder
mediumDetects process creation events that use the Sysnative folder (common for CobaltStrike spawns)
windows
Process Launched Without Image Name
mediumDetect the use of processes with no name (".exe"), which can be used to evade Image-based detections.
windows
Process Memory Dump Via Dotnet-Dump
mediumDetects the execution of "dotnet-dump" with the "collect" flag. The execution could indicate potential process dumping of critical processes such as LSASS.
windows
Process Proxy Execution Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" binary to execute arbitrary processes. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows
Program Executed Using Proxy/Local Command Via SSH.EXE
mediumDetect usage of the "ssh.exe" binary as a proxy to launch other programs.
windows
Proxy Execution via Vshadow
mediumDetects the invocation of vshadow.exe with the -exec parameter that executes a specified script or command after the shadow copies are created but before the VShadow tool exits. VShadow is a command-line tool that you can use to create and manage volume shadow copies. While legitimate backup or administrative scripts may use this flag, attackers can leverage this parameter to proxy the execution of malware.
windows
Psexec Execution
mediumDetects user accept agreement execution in psexec commandline
windows
PsExec Service Execution
mediumDetects launch of the PSEXESVC service, which means that this system was the target of a psexec remote execution
windows
PUA - AdFind.EXE Execution
mediumDetects execution of Adfind.exe utility, which can be used for reconnaissance in an Active Directory environment
windows
PUA - Advanced IP Scanner Execution
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows
PUA - Advanced Port Scanner Execution
mediumDetects the use of Advanced Port Scanner.
windows
PUA - AdvancedRun Execution
mediumDetects the execution of AdvancedRun utility
windows
PUA - Mouse Lock Execution
mediumIn Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
windows
PUA - NimScan Execution
mediumDetects usage of NimScan, a portscanner utility. In early 2025, adversaries were observed using this utility to scan for open ports on remote hosts in a compromised environment. This rule identifies the execution of NimScan based on the process image name and specific hash values associated with different versions of the tool.
windows
PUA - NirCmd Execution
mediumDetects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity
windows
PUA - Nmap/Zenmap Execution
mediumDetects usage of namp/zenmap. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation
windows
PUA - PingCastle Execution
mediumDetects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level.
windows
PUA - Potential PE Metadata Tamper Using Rcedit
mediumDetects the use of rcedit to potentially alter executable PE metadata properties, which could conceal efforts to rename system utilities for defense evasion.
windows
PUA - Process Hacker Execution
mediumDetects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc). Process Hacker is a tool to view and manipulate processes, kernel options and other low level options. Threat actors abused older vulnerable versions to manipulate system processes.
windows
PUA - Radmin Viewer Utility Execution
mediumDetects the execution of Radmin which can be abused by an adversary to remotely control Windows machines
windows
PUA - SoftPerfect Netscan Execution
mediumDetects usage of SoftPerfect's "netscan.exe". An application for scanning networks. It is actively used in-the-wild by threat actors to inspect and understand the network architecture of a victim.
windows
PUA - System Informer Execution
mediumDetects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
windows
PUA - TruffleHog Execution
mediumDetects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
windows
PUA - TruffleHog Execution - Linux
mediumDetects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
linux
PUA - WebBrowserPassView Execution
mediumDetects the execution of WebBrowserPassView.exe. A password recovery tool that reveals the passwords stored by the following Web browsers, Internet Explorer (Version 4.0 - 11.0), Mozilla Firefox (All Versions), Google Chrome, Safari, and Opera
windows
Pubprn.vbs Proxy Execution
mediumDetects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.
windows
Python Inline Command Execution
mediumDetects execution of python using the "-c" flag. This is could be used as a way to launch a reverse shell or execute live python code.
windows
Python Spawning Pretty TTY Via PTY Module
mediumDetects a python process calling to the PTY module in order to spawn a pretty tty which could be indicative of potential reverse shell activity.
linux
Python WebServer Execution - Linux
mediumDetects the execution of Python web servers via command line interface (CLI). After gaining access to target systems, adversaries may use Python's built-in HTTP server modules to quickly establish a web server without requiring additional software. This technique is commonly used in post-exploitation scenarios as it provides a simple method for transferring files between the compromised host and attacker-controlled systems.
linux
Query Usage To Exfil Data
mediumDetects usage of "query.exe" a system binary to exfil information such as "sessions" and "processes" for later use
windows
RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
mediumDetects enabling or disabling of Remote Desktop Protocol (RDP) using alternate methods such as WMIC or PowerShell. In PowerShell one-liner commands, the "SetAllowTSConnections" method of the "Win32_TerminalServiceSetting" class may be used to enable or disable RDP. In WMIC, the "rdtoggle" alias or "Win32_TerminalServiceSetting" class may be used for the same purpose.
windows
Read Contents From Stdin Via Cmd.EXE
mediumDetect the use of "<" to read and potentially execute a file via cmd.exe
windows
Rebuild Performance Counter Values Via Lodctr.EXE
mediumDetects the execution of "lodctr.exe" to rebuild the performance counter registry values. This can be abused by attackers by providing a malicious config file to overwrite performance counter configuration to confuse and evade monitoring and security solutions.
windows
Recon Command Output Piped To Findstr.EXE
mediumDetects the execution of a potential recon command where the results are piped to "findstr". This is meant to trigger on inline calls of "cmd.exe" via the "/c" or "/k" for example. Attackers often time use this technique to extract specific information they require in their reconnaissance phase.
windows
Recon Information for Export with Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows
REGISTER_APP.VBS Proxy Execution
mediumDetects the use of a Microsoft signed script 'REGISTER_APP.VBS' to register a VSS/VDS Provider as a COM+ application.
windows
Registry Enumeration via WMI Stdregprov
mediumDetects the usage of wmic.exe to enumerate or read Windows registry via the WMI StdRegProv class read methods (EnumKey, EnumValues, GetStringValue, etc.). While registry reads are common, attackers may use this technique to perform reconnaissance and discover sensitive configuration values, credentials, or installed software. The use of WMI as an alternative to standard tools like reg.exe can indicate an attempt to evade detection focused on traditional registry query commands.
windows
Registry Manipulation via WMI Stdregprov
mediumDetects the usage of wmic.exe to modify Windows registry via the WMI StdRegProv class write methods (CreateKey, DeleteKey, SetStringValue, etc.). This behaviour could be potentially suspicious because it uses an alternative method to modify registry keys instead of legitimate registry tools like reg.exe or regedit.exe. Attackers specifically choose this technique to evade detection and bypass security monitoring focused on traditional registry modification commands.
windows
Registry Modification Attempt Via VBScript
mediumDetects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods via common LOLBINs. It could be an attempt to modify the registry for persistence without using straightforward methods like regedit.exe, reg.exe, or PowerShell. Threat Actors may use this technique to evade detection by security solutions that monitor for direct registry modifications through traditional tools.
windows
Registry Modification of MS-settings Protocol Handler
mediumDetects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence. Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.
windows
Regsvr32 DLL Execution With Uncommon Extension
mediumDetects a "regsvr32" execution where the DLL doesn't contain a common file extension.
windows
Regsvr32 Execution From Potential Suspicious Location
mediumDetects execution of regsvr32 where the DLL is located in a potentially suspicious location.
windows
Regsvr32.EXE Calling of DllRegisterServer Export Function Implicitly
mediumDetects execution of regsvr32 with the silent flag and no other flags on a DLL located in an uncommon or potentially suspicious location. When Regsvr32 is called in such a way, it implicitly calls the DLL export function 'DllRegisterServer'.
windows
Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions
mediumDetects the execution of Action1 in order to execute arbitrary code or establish a remote session. Action1 is a powerful Remote Monitoring and Management tool that enables users to execute commands, scripts, and binaries. Through the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed. Hunting Opportunity 1- Weed Out The Noise When threat actors execute a script, a command, or a binary through these new policies and apps, the names of these become visible in the command line during the execution process. Below is an example of the command line that contains the deployment of a binary through a policy with name "test_app_1": ParentCommandLine: "C:\WINDOWS\Action1\action1_agent.exe schedule:Deploy_App__test_app_1_1681327673425 runaction:0" After establishing a baseline, we can split the command to extract the policy name and group all the policy names and inspect the results with a list of frequency occurrences. Hunting Opportunity 2 - Remote Sessions On Out Of Office Hours If you have admins within your environment using remote sessions to administer endpoints, you can create a threat-hunting query and modify the time of the initiated sessions looking for abnormal activity.
windows
Remote Access Tool - Ammy Admin Agent Execution
mediumDetects the execution of the Ammy Admin RMM agent for remote management.
windows
Remote Access Tool - AnyDesk Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Access Tool - AnyDesk Execution With Known Revoked Signing Certificate
mediumDetects the execution of an AnyDesk binary with a version prior to 8.0.8. Prior to version 8.0.8, the Anydesk application used a signing certificate that got compromised by threat actors. Use this rule to detect instances of older versions of Anydesk using the compromised certificate This is recommended in order to avoid attackers leveraging the certificate and signing their binaries to bypass detections.
windows
Remote Access Tool - AnyDesk Piped Password Via CLI
mediumDetects piping the password to an anydesk instance via CMD and the '--set-password' flag.
windows
Remote Access Tool - Cmd.EXE Execution via AnyViewer
mediumDetects execution of "cmd.exe" via the AnyViewer RMM agent on a remote management sessions.
windows
Remote Access Tool - GoToAssist Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Access Tool - LogMeIn Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Access Tool - MeshAgent Command Execution via MeshCentral
mediumDetects the use of MeshAgent to execute commands on the target host, particularly when threat actors might abuse it to execute commands directly. MeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.
windows
Remote Access Tool - NetSupport Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Access Tool - NetSupport Execution From Unusual Location
mediumDetects execution of client32.exe (NetSupport RAT) from an unusual location (outside of 'C:\Program Files')
windows
Remote Access Tool - Potential MeshAgent Execution - MacOS
mediumDetects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
macos
Remote Access Tool - Potential MeshAgent Execution - Windows
mediumDetects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
windows
Remote Access Tool - RURAT Execution From Unusual Location
mediumDetects execution of Remote Utilities RAT (RURAT) from an unusual location (outside of 'C:\Program Files')
windows
Remote Access Tool - ScreenConnect Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Access Tool - ScreenConnect Installation Execution
mediumDetects ScreenConnect program starts that establish a remote access to a system.
windows
Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
mediumDetects potentially suspicious child processes launched via the ScreenConnect client service.
windows
Remote Access Tool - ScreenConnect Remote Command Execution - Hunting
mediumDetects remote binary or command execution via the ScreenConnect Service. Use this rule in order to hunt for potentially anomalous executions originating from ScreenConnect
windows
Remote Access Tool - Simple Help Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
mediumDetects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line. These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID. This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
windows
Remote Access Tool - UltraViewer Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows
Remote Code Execute via Winrm.vbs
mediumDetects an attempt to execute code or create service on remote host via winrm.vbs.
windows
Remote File Download Via Desktopimgdownldr Utility
mediumDetects the desktopimgdownldr utility being used to download a remote file. An adversary may use desktopimgdownldr to download arbitrary files as an alternative to certutil.
windows
Remote File Download Via Findstr.EXE
mediumDetects execution of "findstr" with specific flags and a remote share path. This specific set of CLI flags would allow "findstr" to download the content of the file located on the remote share as described in the LOLBAS entry.
windows
Remote PowerShell Session Host Process (WinRM)
mediumDetects remote PowerShell sections by monitoring for wsmprovhost (WinRM host process) as a parent or child process (sign of an active PowerShell remote session).
windows
Remove Immutable File Attribute
mediumDetects usage of the 'chattr' utility to remove immutable file attribute.
linux
Remove Scheduled Cron Task/Job
mediumDetects usage of the 'crontab' utility to remove the current crontab. This is a common occurrence where cryptocurrency miners compete against each other by removing traces of other miners to hijack the maximum amount of resources possible
linux
Renamed AutoHotkey.EXE Execution
mediumDetects execution of a renamed autohotkey.exe binary based on PE metadata fields
windows
Renamed BOINC Client Execution
mediumDetects the execution of a renamed BOINC binary.
windows
Renamed CURL.EXE Execution
mediumDetects the execution of a renamed "CURL.exe" binary based on the PE metadata fields
windows
Renamed FTP.EXE Execution
mediumDetects the execution of a renamed "ftp.exe" binary based on the PE metadata fields
windows
Renamed Microsoft Teams Execution
mediumDetects the execution of a renamed Microsoft Teams binary.
windows
Renamed Remote Utilities RAT (RURAT) Execution
mediumDetects execution of renamed Remote Utilities (RURAT) via Product PE header field
windows
Replace.exe Usage
mediumDetects the use of Replace.exe which can be used to replace file with another file
windows
Response File Execution Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with the "-f" flag in order to load a response file which might contain a malicious action.
windows
Rhadamanthys Stealer Module Launch Via Rundll32.EXE
mediumDetects the use of Rundll32 to launch an NSIS module that serves as the main stealer capability of Rhadamanthys infostealer, as observed in reports and samples in early 2023
windows
Root Account Enable Via Dsenableroot
mediumDetects attempts to enable the root account via "dsenableroot"
macos
Ruby Inline Command Execution
mediumDetects execution of ruby using the "-e" flag. This is could be used as a way to launch a reverse shell or execute live ruby code.
windows
Rundll32 Execution With Uncommon DLL Extension
mediumDetects the execution of rundll32 with a command line that doesn't contain a common extension
windows
Rundll32 InstallScreenSaver Execution
mediumAn attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver
windows
Rundll32 Spawned Via Explorer.EXE
mediumDetects execution of "rundll32.exe" with a parent process of Explorer.exe. This has been observed by variants of Raspberry Robin, as first reported by Red Canary.
windows
Rundll32.EXE Calling DllRegisterServer Export Function Explicitly
mediumDetects when the DLL export function 'DllRegisterServer' is called in the commandline by Rundll32 explicitly where the DLL is located in a non-standard path.
windows
Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE
mediumDetects Schtask creations that point to a suspicious folder or an environment variable often used by malware
windows
Scheduled Cron Task/Job - Linux
mediumDetects abuse of the cron utility to perform task scheduling for initial or recurring execution of malicious code. Detection will focus on crontab jobs uploaded from the tmp folder.
linux
Scheduled Cron Task/Job - MacOs
mediumDetects abuse of the cron utility to perform task scheduling for initial or recurring execution of malicious code. Detection will focus on crontab jobs uploaded from the tmp folder.
macos
Scheduled Task Creation From Potential Suspicious Parent Location
mediumDetects the execution of "schtasks.exe" from a parent that is located in a potentially suspicious location. Multiple malware strains were seen exhibiting a similar behavior in order to achieve persistence.
windows
Scheduled Task Creation with Curl and PowerShell Execution Combo
mediumDetects the creation of a scheduled task using schtasks.exe, potentially in combination with curl for downloading payloads and PowerShell for executing them. This facilitates executing malicious payloads or connecting with C&C server persistently without dropping the malware sample on the host.
windows
Scheduled Task Executing Payload from Registry
mediumDetects the creation of a schtasks that potentially executes a payload stored in the Windows Registry using PowerShell.
windows
Screen Capture Activity Via Psr.EXE
mediumDetects execution of Windows Problem Steps Recorder (psr.exe), a utility used to record the user screen and clicks.
windows
Scripting/CommandLine Process Spawned Regsvr32
mediumDetects various command line and scripting engines/processes such as "PowerShell", "Wscript", "Cmd", etc. spawning a "regsvr32" instance.
windows
Sdclt Child Processes
mediumA General detection for sdclt spawning new processes. This could be an indicator of sdclt being used for bypass UAC techniques.
windows
Security Software Discovery - MacOs
mediumDetects usage of system utilities (only grep for now) to discover security software discovery
macos
Security Tools Keyword Lookup Via Findstr.EXE
mediumDetects execution of "findstr" to search for common names of security tools. Attackers often pipe the results of recon commands such as "tasklist" or "whoami" to "findstr" in order to filter out the results. This detection focuses on the keywords that the attacker might use as a filter.
windows
Service Reconnaissance Via Wmic.EXE
mediumAn adversary might use WMI to check if a certain remote service is running on a remote device. When the test completes, a service information will be displayed on the screen if it exists. A common feedback message is that "No instance(s) Available" if the service queried is not running. A common error message is "Node - (provided IP or default) ERROR Description =The RPC server is unavailable" if the provided remote host is unreachable
windows
Service Security Descriptor Tampering Via Sc.EXE
mediumDetection of sc.exe utility adding a new service with special permission which hides that service.
windows
Service Started/Stopped Via Wmic.EXE
mediumDetects usage of wmic to start or stop a service
windows
Service Startup Type Change Via Wmic.EXE
mediumDetects changes to service startup type to 'disabled' or 'manual' using the WMIC command-line utility.
windows
Service StartupType Change Via PowerShell Set-Service
mediumDetects the use of the PowerShell "Set-Service" cmdlet to change the startup type of a service to "disabled" or "manual"
windows
Service StartupType Change Via Sc.EXE
mediumDetect the use of "sc.exe" to change the startup type of a service to "disabled" or "demand"
windows
Setup16.EXE Execution With Custom .Lst File
mediumDetects the execution of "Setup16.EXE" and old installation utility with a custom ".lst" file. These ".lst" file can contain references to external program that "Setup16.EXE" will execute. Attackers and adversaries might leverage this as a living of the land utility.
windows
Shadow Copies Creation Using Operating Systems Utilities
mediumShadow Copies creation using operating systems utilities, possible credential access
windows
Shell Invocation via Apt - Linux
mediumDetects the use of the "apt" and "apt-get" commands to execute a shell or proxy commands. Such behavior may be associated with privilege escalation, unauthorized command execution, or to break out from restricted environments.
linux
Shell Process Spawned by Java.EXE
mediumDetects shell spawned from Java host process, which could be a sign of exploitation (e.g. log4j exploitation)
windows
SMB over QUIC Via Net.EXE
mediumDetects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments.
windows
SQL Client Tools PowerShell Session Detection
mediumThis rule detects execution of a PowerShell code through the sqltoolsps.exe utility, which is included in the standard set of utilities supplied with the Microsoft SQL Server Management studio. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.
windows
Start of NT Virtual DOS Machine
mediumNtvdm.exe allows the execution of 16-bit Windows applications on 32-bit Windows operating systems, as well as the execution of both 16-bit and 32-bit DOS applications
windows
Suspicious Browser Child Process - MacOS
mediumDetects suspicious child processes spawned from browsers. This could be a result of a potential web browser exploitation.
macos
Suspicious Cabinet File Execution Via Msdt.EXE
mediumDetects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190
windows
Suspicious Child Process of SAP NetWeaver
mediumDetects suspicious child processes spawned by SAP NetWeaver that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
windows
Suspicious Child Process of SAP NetWeaver - Linux
mediumDetects suspicious child processes spawned by SAP NetWeaver on Linux systems that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
linux
Suspicious CodePage Switch Via CHCP
mediumDetects a code page switch in command line or batch scripts to a rare language
windows
Suspicious Copy From or To System Directory
mediumDetects a suspicious copy operation that tries to copy a program from system (System32, SysWOW64, WinSxS) directories to another on disk. Often used to move LOLBINs such as 'certutil' or 'desktopimgdownldr' to a different location with a different name in order to bypass detections based on locations.
windows
Suspicious Cross-User Process Spawn
mediumDetects suspicious spawning of a process under a different user context than the parent process. Processes such as notepad.exe, calculator etc. are generally spawned under the same user context and also they are often targeted as sacrificial process or decoy process to check successful privilege escalation.
windows
Suspicious CrushFTP Child Process
mediumDetects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities such as CVE-2025-31161, where attackers can achieve RCE through crafted HTTP requests. The detection focuses on commonly abused Windows executables (like powershell.exe, cmd.exe etc.) that attackers typically use post-exploitation to execute malicious commands.
windows
Suspicious Csi.exe Usage
mediumCsi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'
windows
Suspicious Curl Change User Agents - Linux
mediumDetects a suspicious curl process start on linux with set useragent options
linux
Suspicious Curl File Upload - Linux
mediumDetects a suspicious curl process start the adds a file to a web request
linux
Suspicious Diantz Alternate Data Stream Execution
mediumCompress target file into a cab file stored in the Alternate Data Stream (ADS) of the target file.
windows
Suspicious Diantz Download and Compress Into a CAB File
mediumDownload and compress a remote file and store it in a cab file on local machine.
windows
Suspicious Download Via Certutil.EXE
mediumDetects the execution of certutil with certain flags that allow the utility to download files.
windows
Suspicious Driver Install by pnputil.exe
mediumDetects when a possible suspicious driver is being installed via pnputil.exe lolbin
windows
Suspicious Electron Application Child Processes
mediumDetects suspicious child processes of electron apps (teams, discord, slack, etc.). This could be a potential sign of ".asar" file tampering (See reference section for more information) or binary execution proxy through specific CLI arguments (see related rule)
windows
Suspicious Execution of InstallUtil Without Log
mediumUses the .NET InstallUtil.exe application in order to execute image without log
windows
Suspicious Execution of Powershell with Base64
mediumCommandline to launch powershell with a base64 payload
windows
Suspicious Execution of Shutdown
mediumUse of the commandline to shutdown or reboot windows
windows
Suspicious Execution of Shutdown to Log Out
mediumDetects the rare use of the command line tool shutdown to logoff a user
windows
Suspicious Execution via macOS Script Editor
mediumDetects when the macOS Script Editor utility spawns an unusual child process.
macos
Suspicious Extrac32 Alternate Data Stream Execution
mediumExtract data from cab file and hide it in an alternate data stream
windows
Suspicious Extrac32 Execution
mediumDownload or Copy file with Extrac32
windows
Suspicious File Characteristics Due to Missing Fields
mediumDetects Executables in the Downloads folder without FileVersion,Description,Product,Company likely created with py2exe
windows
Suspicious FromBase64String Usage On Gzip Archive - Process Creation
mediumDetects attempts of decoding a base64 Gzip archive via PowerShell. This technique is often used as a method to load malicious content into memory afterward.
windows
Suspicious Git Clone
mediumDetects execution of "git" in order to clone a remote repository that contain suspicious keywords which might be suspicious
windows
Suspicious Git Clone - Linux
mediumDetects execution of "git" in order to clone a remote repository that contain suspicious keywords which might be suspicious
linux
Suspicious Group And Account Reconnaissance Activity Using Net.EXE
mediumDetects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)
windows
Suspicious History File Operations
mediumDetects commandline operations on shell history files
macos
Suspicious IIS URL GlobalRules Rewrite Via AppCmd
mediumDetects usage of "appcmd" to create new global URL rewrite rules. This behaviour has been observed being used by threat actors to add new rules so they can access their webshells.
windows
Suspicious Installer Package Child Process
mediumDetects the execution of suspicious child processes from macOS installer package parent process. This includes osascript, JXA, curl and wget amongst other interpreters
macos
Suspicious Invoke-WebRequest Execution With DirectIP
mediumDetects calls to PowerShell with Invoke-WebRequest cmdlet using direct IP access
windows
Suspicious MacOS Firmware Activity
mediumDetects when a user manipulates with Firmward Password on MacOS. NOTE - this command has been disabled on silicon-based apple computers.
macos
Suspicious Msbuild Execution By Uncommon Parent Process
mediumDetects suspicious execution of 'Msbuild.exe' by a uncommon parent process
windows
Suspicious MsiExec Embedding Parent
mediumAdversaries may abuse msiexec.exe to proxy the execution of malicious payloads
windows
Suspicious Msiexec Execute Arbitrary DLL
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows
Suspicious Msiexec Quiet Install From Remote Location
mediumDetects usage of Msiexec.exe to install packages hosted remotely quietly
windows
Suspicious New Instance Of An Office COM Object
mediumDetects an svchost process spawning an instance of an office application. This happens when the initial word application creates an instance of one of the Office COM objects such as 'Word.Application', 'Excel.Application', etc. This can be used by malicious actors to create malicious Office documents with macros on the fly. (See vba2clr project in the references)
windows
Suspicious Package Installed - Linux
mediumDetects installation of suspicious packages using system installation utilities
linux
Suspicious Powercfg Execution To Change Lock Screen Timeout
mediumDetects suspicious execution of 'Powercfg.exe' to change lock screen timeout
windows
Suspicious PowerShell Invocation From Script Engines
mediumDetects suspicious powershell invocations from interpreters or unusual programs
windows
Suspicious PowerShell Invocations - Specific - ProcessCreation
mediumDetects suspicious PowerShell invocation command parameters
windows
Suspicious Process Start Locations
mediumDetects suspicious process run from unusual locations
windows
Suspicious RASdial Activity
mediumDetects suspicious process related to rasdial.exe
windows
Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet
mediumDetects suspicious reconnaissance command line activity on Windows systems using the PowerShell Get-LocalGroupMember Cmdlet
windows
Suspicious Recursive Takeown
mediumAdversaries can interact with the DACLs using built-in Windows commands takeown which can grant adversaries higher permissions on specific files and folders
windows
Suspicious RunAs-Like Flag Combination
mediumDetects suspicious command line flags that let the user set a target user and command as e.g. seen in PsExec-like tools
windows
Suspicious Rundll32 Setupapi.dll Activity
mediumsetupapi.dll library provide InstallHinfSection function for processing INF files. INF file may contain instructions allowing to create values in the registry, modify files and install drivers. This technique could be used to obtain persistence via modifying one of Run or RunOnce registry keys, run process or use other DLLs chain calls (see references) InstallHinfSection function in setupapi.dll calls runonce.exe executable regardless of actual content of INF file.
windows
Suspicious Runscripthelper.exe
mediumDetects execution of powershell scripts via Runscripthelper.exe
windows
Suspicious Scan Loop Network
mediumAdversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system
windows
Suspicious Scheduled Task Creation via Masqueraded XML File
mediumDetects the creation of a scheduled task using the "-XML" flag with a file without the '.xml' extension. This behavior could be indicative of potential defense evasion attempt during persistence
windows
Suspicious Scheduled Task Name As GUID
mediumDetects creation of a scheduled task with a GUID like name
windows
Suspicious Schtasks Schedule Type With High Privileges
mediumDetects scheduled task creations or modification to be run with high privileges on a suspicious schedule type
windows
Suspicious ScreenSave Change by Reg.exe
mediumAdversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension
windows
Suspicious SysAidServer Child
mediumDetects suspicious child processes of SysAidServer (as seen in MERCURY threat actor intrusions)
windows
Suspicious SYSVOL Domain Group Policy Access
mediumDetects Access to Domain Group Policies stored in SYSVOL
windows
Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe to perform different actions such as restoring snapshots...etc.
windows
Suspicious Usage of For Loop with Recursive Directory Search in CMD
mediumDetects suspicious usage of the cmd.exe 'for /f' loop combined with the 'tokens=' parameter and a recursive directory listing. This pattern may indicate an attempt to discover and execute system binaries dynamically, for example powershell, a technique sometimes used by attackers to evade detection. This behavior has been observed in various malicious lnk files.
windows
Suspicious Use of PsLogList
mediumDetects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
windows
Suspicious Userinit Child Process
mediumDetects a suspicious child process of userinit
windows
Suspicious VBoxDrvInst.exe Parameters
mediumDetect VBoxDrvInst.exe run with parameters allowing processing INF file. This allows to create values in the registry and install drivers. For example one could use this technique to obtain persistence via modifying one of Run or RunOnce registry keys
windows
Suspicious Vsls-Agent Command With AgentExtensionPath Load
mediumDetects Microsoft Visual Studio vsls-agent.exe lolbin execution with a suspicious library load using the --agentExtensionPath parameter
windows
Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
mediumDetects the usage of "reg.exe" to add Defender folder exclusions. Qbot has been seen using this technique to add exclusions for folders within AppData and ProgramData.
windows
Suspicious WindowsTerminal Child Processes
mediumDetects suspicious children spawned via the Windows Terminal application which could be a sign of persistence via WindowsTerminal (see references section)
windows
Suspicious Workstation Locking via Rundll32
mediumDetects a suspicious call to the user32.dll function that locks the user workstation
windows
Suspicious X509Enrollment - Process Creation
mediumDetect use of X509Enrollment
windows
Suspicious XOR Encoded PowerShell Command
mediumDetects presence of a potentially xor encoded powershell command
windows
Suspicious ZipExec Execution
mediumZipExec is a Proof-of-Concept (POC) tool to wrap binary-based tools into a password-protected zip file.
windows
SyncAppvPublishingServer Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.exe.
windows
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.vbs
windows
Sysinternals PsService Execution
mediumDetects usage of Sysinternals PsService which can be abused for service reconnaissance and tampering
windows
Sysinternals PsSuspend Execution
mediumDetects usage of Sysinternals PsSuspend which can be abused to suspend critical processes
windows
Sysmon Configuration Update
mediumDetects updates to Sysmon's configuration. Attackers might update or replace the Sysmon configuration with a bare bone one to avoid monitoring without shutting down the service completely
windows
Sysprep on AppData Folder
mediumDetects suspicious sysprep process start with AppData folder as target (as used by Trojan Syndicasec in Thrip report by Symantec)
windows
System Disk And Volume Reconnaissance Via Wmic.EXE
mediumAn adversary might use WMI to discover information about the system, such as the volume name, size, free space, and other disk information. This can be done using the 'wmic' command-line utility and has been observed being used by threat actors such as Volt Typhoon.
windows
System Information Discovery Using Ioreg
mediumDetects the use of "ioreg" which will show I/O Kit registry information. This process is used for system information discovery. It has been observed in-the-wild by calling this process directly or using bash and grep to look for specific strings.
macos
System Information Discovery Using sw_vers
mediumDetects the use of "sw_vers" for system information discovery
macos
System Information Discovery Using System_Profiler
mediumDetects the execution of "system_profiler" with specific "Data Types" that have been seen being used by threat actors and malware. It provides system hardware and software configuration information. This process is primarily used for system information discovery. However, "system_profiler" can also be used to determine if virtualization software is being run for defense evasion purposes.
macos
System Information Discovery Via Sysctl - MacOS
mediumDetects the execution of "sysctl" with specific arguments that have been used by threat actors and malware. It provides system hardware information. This process is primarily used to detect and avoid virtualization and analysis environments.
macos
System Integrity Protection (SIP) Disabled
mediumDetects the use of csrutil to disable the Configure System Integrity Protection (SIP). This technique is used in post-exploit scenarios.
macos
System Language Discovery via Reg.Exe
mediumDetects the usage of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.
windows
Tap Installer Execution
mediumWell-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques
windows
Terminate Linux Process Via Kill
mediumDetects usage of command line tools such as "kill", "pkill" or "killall" to terminate or signal a running process.
linux
Time Machine Backup Deletion Attempt Via Tmutil - MacOS
mediumDetects deletion attempts of MacOS Time Machine backups via the native backup utility "tmutil". An adversary may perform this action before launching a ransonware attack to prevent the victim from restoring their files.
macos
Time Machine Backup Disabled Via Tmutil - MacOS
mediumDetects disabling of Time Machine (Apple's automated backup utility software) via the native macOS backup utility "tmutil". An attacker can use this to prevent backups from occurring.
macos
Touch Suspicious Service File
mediumDetects usage of the "touch" process in service file.
linux
Tunneling Tool Execution
mediumDetects the execution of well known tools that can be abused for data exfiltration and tunneling.
windows
UAC Bypass via Windows Firewall Snap-In Hijack
mediumDetects attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in
windows
UFW Disable Attempt
mediumDetects attempts to disable the Uncomplicated Firewall (UFW) on Linux systems. UFW is a popular firewall management tool that provides an easy-to-use interface for configuring firewall rules. Disabling UFW can leave a system vulnerable to attacks, as it may allow unauthorized access to network services and resources.
linux
Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
mediumDetects the start of a non built-in assistive technology applications via "Atbroker.EXE".
windows
Uncommon AddinUtil.EXE CommandLine Execution
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) with uncommon Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.
windows
Uncommon Child Process Of AddinUtil.EXE
mediumDetects uncommon child processes of the Add-In deployment cache updating utility (AddInutil.exe) which could be a sign of potential abuse of the binary to proxy execution via a custom Addins.Store payload.
windows
Uncommon Child Process Of Appvlp.EXE
mediumDetects uncommon child processes of Appvlp.EXE Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands. Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder or to mark a file as a system file.
windows
Uncommon Child Process Of BgInfo.EXE
mediumDetects uncommon child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
windows
Uncommon Child Process Of Conhost.EXE
mediumDetects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.
windows
Uncommon Child Process Of Defaultpack.EXE
mediumDetects uncommon child processes of "DefaultPack.EXE" binary as a proxy to launch other programs
windows
Uncommon Child Process Spawned By Odbcconf.EXE
mediumDetects an uncommon child process of "odbcconf.exe" binary which normally shouldn't have any child processes.
windows
Uncommon Child Processes Of SndVol.exe
mediumDetects potentially uncommon child processes of SndVol.exe (the Windows volume mixer)
windows
Uncommon Extension Shim Database Installation Via Sdbinst.EXE
mediumDetects installation of a potentially suspicious new shim with an uncommon extension using sdbinst.exe. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims
windows
Uncommon Link.EXE Parent Process
mediumDetects an uncommon parent process of "LINK.EXE". Link.EXE in Microsoft incremental linker. Its a utility usually bundled with Visual Studio installation. Multiple utilities often found in the same folder (editbin.exe, dumpbin.exe, lib.exe, etc) have a hardcode call to the "LINK.EXE" binary without checking its validity. This would allow an attacker to sideload any binary with the name "link.exe" if one of the aforementioned tools get executed from a different location. By filtering the known locations of such utilities we can spot uncommon parent process of LINK.EXE that might be suspicious or malicious.
windows
Uncommon Sigverif.EXE Child Process
mediumDetects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.
windows
Uncommon Svchost Parent Process
mediumDetects an uncommon svchost parent process
windows
Uncommon System Information Discovery Via Wmic.EXE
mediumDetects the use of the WMI command-line (WMIC) utility to identify and display various system information, including OS, CPU, GPU, and disk drive names; memory capacity; display resolution; and baseboard, BIOS, and GPU driver products/versions. Some of these commands were used by Aurora Stealer in late 2022/early 2023.
windows
Unsigned AppX Installation Attempt Using Add-AppxPackage
mediumDetects usage of the "Add-AppxPackage" or it's alias "Add-AppPackage" to install unsigned AppX packages
windows
Unusual Parent Process For Cmd.EXE
mediumDetects suspicious parent process for cmd.exe
windows
Usage Of Web Request Commands And Cmdlets
mediumDetects the use of various web request commands with commandline tools and Windows PowerShell cmdlets (including aliases) via CommandLine
windows
Use Icacls to Hide File to Everyone
mediumDetect use of icacls to deny access for everyone in Users folder sometimes used to hide malicious files
windows
Use NTFS Short Name in Command Line
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid command-line detection
windows
Use NTFS Short Name in Image
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid Image based detection
windows
Use of FSharp Interpreters
mediumDetects the execution of FSharp Interpreters "FsiAnyCpu.exe" and "FSi.exe" Both can be used for AWL bypass and to execute F# code via scripts or inline.
windows
Use of OpenConsole
mediumDetects usage of OpenConsole binary as a LOLBIN to launch other binaries to bypass application Whitelisting
windows
Use of Pcalua For Execution
mediumDetects execition of commands and binaries from the context of The program compatibility assistant (Pcalua.exe). This can be used as a LOLBIN in order to bypass application whitelisting.
windows
Use of Remote.exe
mediumRemote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.
windows
Use of Scriptrunner.exe
mediumThe "ScriptRunner.exe" binary can be abused to proxy execution through it and bypass possible whitelisting
windows
Use Of The SFTP.EXE Binary As A LOLBIN
mediumDetects the usage of the "sftp.exe" binary as a LOLBIN by abusing the "-D" flag
windows
Use of TTDInject.exe
mediumDetects the executiob of TTDInject.exe, which is used by Windows 10 v1809 and newer to debug time travel (underlying call of tttracer.exe)
windows
Use of UltraVNC Remote Access Software
mediumAn adversary may use legitimate desktop support and remote access software,to establish an interactive command and control channel to target systems within networks
windows
Use of VisualUiaVerifyNative.exe
mediumVisualUiaVerifyNative.exe is a Windows SDK that can be used for AWL bypass and is listed in Microsoft's recommended block rules.
windows
Use of VSIISExeLauncher.exe
mediumThe "VSIISExeLauncher.exe" binary part of the Visual Studio/VS Code can be used to execute arbitrary binaries
windows
Use of Wfc.exe
mediumThe Workflow Command-line Compiler can be used for AWL bypass and is listed in Microsoft's recommended block rules.
windows
Use Short Name Path in Command Line
mediumDetects the use of short name paths (8.3 format) in command lines, which can be used to obfuscate paths or access restricted locations. Windows creates short 8.3 filenames (like PROGRA~1) for compatibility with MS-DOS-based or 16-bit Windows programs. When investigating, examine: - Commands using short paths to access sensitive directories or files - Web servers on Windows (especially Apache) where short filenames could bypass security controls - Correlation with other suspicious behaviors - baseline of short name usage in your environment and look for deviations
windows
Use Short Name Path in Image
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid Image detection
windows
User Added To Admin Group Via Dscl
mediumDetects attempts to create and add an account to the admin group via "dscl"
macos
User Added To Admin Group Via DseditGroup
mediumDetects attempts to create and/or add an account to the admin group, thus granting admin privileges.
macos
User Added To Admin Group Via Sysadminctl
mediumDetects attempts to create and add an account to the admin group via "sysadminctl"
macos
User Added to Local Administrators Group
mediumDetects addition of users to the local administrator group via "Net" or "Add-LocalGroupMember".
windows
User Added To Root/Sudoers Group Using Usermod
mediumDetects usage of the "usermod" binary to add users add users to the root or suoders groups
linux
User Discovery And Export Via Get-ADUser Cmdlet
mediumDetects usage of the Get-ADUser cmdlet to collect user information and output it to a file
windows
User Has Been Deleted Via Userdel
mediumDetects execution of the "userdel" binary. Which is used to delete a user account and related files. This is sometimes abused by threat actors in order to cover their tracks
linux
UtilityFunctions.ps1 Proxy Dll
mediumDetects the use of a Microsoft signed script executing a managed DLL with PowerShell.
windows
Veeam Backup Database Suspicious Query
mediumDetects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
windows
Verclsid.exe Runs COM Object
mediumDetects when verclsid.exe is used to run COM object via GUID
windows
Visual Studio Code Tunnel Execution
mediumDetects Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows
Visual Studio Code Tunnel Service Installation
mediumDetects the installation of VsCode tunnel (code-tunnel) as a service.
windows
Visual Studio Code Tunnel Shell Execution
mediumDetects the execution of a shell (powershell, bash, wsl...) via Visual Studio Code tunnel. Attackers can abuse this functionality to establish a C2 channel and execute arbitrary commands on the system.
windows
Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
mediumDetects child processes of Microsoft.NodejsTools.PressAnyKey.exe that can be used to execute any other binary
windows
Visual Studio NodejsTools PressAnyKey Renamed Execution
mediumDetects renamed execution of "Microsoft.NodejsTools.PressAnyKey.exe", which can be abused as a LOLBIN to execute arbitrary binaries
windows
Weak or Abused Passwords In CLI
mediumDetects weak passwords or often abused passwords (seen used by threat actors) via the CLI. An example would be a threat actor creating a new user via the net command and providing the password inline
windows
WebDav Client Execution Via Rundll32.EXE
mediumDetects "svchost.exe" spawning "rundll32.exe" with command arguments like "C:\windows\system32\davclnt.dll,DavSetCookie". This could be an indicator of exfiltration or use of WebDav to launch code (hosted on a WebDav server).
windows
Whoami.EXE Execution Anomaly
mediumDetects the execution of whoami.exe with suspicious parent processes.
windows
Whoami.EXE Execution With Output Option
mediumDetects the execution of "whoami.exe" with the "/FO" flag to choose CSV as output format or with redirection options to export the results to a file for later use.
windows
Windows Admin Share Mount Via Net.EXE
mediumDetects when an admin share is mounted using net.exe
windows
Windows Backup Deleted Via Wbadmin.EXE
mediumDetects the deletion of backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.
windows
Windows Binary Executed From WSL
mediumDetects the execution of Windows binaries from within a WSL instance. This could be used to masquerade parent-child relationships
windows
Windows Credential Manager Access via VaultCmd
mediumList credentials currently stored in Windows Credential Manager via the native Windows utility vaultcmd.exe
windows
Windows Default Domain GPO Modification via GPME
mediumDetects the use of the Group Policy Management Editor (GPME) to modify Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may leverage GPME to make stealthy changes in these default GPOs to deploy malicious GPOs configurations across the domain without raising suspicion.
windows
Windows Firewall Disabled via PowerShell
mediumDetects attempts to disable the Windows Firewall using PowerShell
windows
Windows Hotfix Updates Reconnaissance Via Wmic.EXE
mediumDetects the execution of wmic with the "qfe" flag in order to obtain information about installed hotfix updates on the system. This is often used by pentester and attacker enumeration scripts
windows
Windows Kernel Debugger Execution
mediumDetects execution of the Windows Kernel Debugger "kd.exe".
windows
Windows Recall Feature Enabled Via Reg.EXE
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by deleting the existing "DisableAIDataAnalysis" value, or setting it to 0. Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows
Windows Recovery Environment Disabled Via Reagentc
mediumDetects attempts to disable windows recovery environment using Reagentc. ReAgentc.exe is a command-line tool in Windows used to manage the Windows Recovery Environment (WinRE). It allows users to enable, disable, and configure WinRE, which is used for troubleshooting and repairing common boot issues.
windows
Winrar Compressing Dump Files
mediumDetects execution of WinRAR in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows
WinRAR Execution in Non-Standard Folder
mediumDetects a suspicious WinRAR execution in a folder which is not the default installation folder
windows
Winscp Execution From Non Standard Folder
mediumDetects the execution of Winscp from an a non standard folder. This could indicate the execution of Winscp portable.
windows
Wlrmdr.EXE Uncommon Argument Or Child Process
mediumDetects the execution of "Wlrmdr.exe" with the "-u" command line flag which allows anything passed to it to be an argument of the ShellExecute API, which would allow an attacker to execute arbitrary binaries. This detection also focuses on any uncommon child processes spawned from "Wlrmdr.exe" as a supplement for those that posses "ParentImage" telemetry.
windows
WMI Persistence - Script Event Consumer
mediumDetects the execution of a script event consumer. When scrcons.exe launches, it does so in response to the creation of an ActiveScriptEventConsumer instance and will execute registered JScript or VBScript code as a result. Script event consumers are a built-in Windows Management Instrumentation (WMI) class that automatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs. Adversaries often abuse script event consumers to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.
windows
WMIC Remote Command Execution
mediumDetects the execution of WMIC to query information on a remote system
windows
WmiPrvSE Spawned A Process
mediumDetects WmiPrvSE spawning a process
windows
Write Protect For Storage Disabled
mediumDetects applications trying to modify the registry in order to disable any write-protect property for storage devices. This could be a precursor to a ransomware attack and has been an observed technique used by cypherpunk group.
windows
Writing Of Malicious Files To The Fonts Folder
mediumMonitors for the hiding possible malicious files in the C:\Windows\Fonts\ location. This folder doesn't require admin privillege to be written and executed from.
windows
Wscript Shell Run In CommandLine
mediumDetects the presence of the keywords "Wscript", "Shell" and "Run" in the command, which could indicate a suspicious activity
windows
WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
mediumDetects script file execution (.js, .jse, .vba, .vbe, .vbs, .wsf, .wsh) by Wscript/Cscript.
windows
WSL Child Process Anomaly
mediumDetects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL
windows
XBAP Execution From Uncommon Locations Via PresentationHost.EXE
mediumDetects the execution of ".xbap" (Browser Applications) files via PresentationHost.EXE from an uncommon location. These files can be abused to run malicious ".xbap" files any bypass AWL
windows
XSL Script Execution Via WMIC.EXE
mediumDetects the execution of WMIC with the "format" flag to potentially load local XSL files. Adversaries abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files.
windows
Bash Interactive Shell
lowDetects execution of the bash shell with the interactive flag "-i".
linux
BitLockerTogo.EXE Execution
lowDetects the execution of "BitLockerToGo.EXE". BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system. This is a rarely used application and usage of it at all is worth investigating. Malware such as Lumma stealer has been seen using this process as a target for process hollowing.
windows
Browser Execution In Headless Mode
lowDetects execution of Chromium based browser in headless mode
windows
Capabilities Discovery - Linux
lowDetects usage of "getcap" binary. This is often used during recon activity to determine potential binaries that can be abused as GTFOBins or other.
linux
Change Default File Association Via Assoc
lowDetects file association changes using the builtin "assoc" command. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Applications can modify the file association for a given file extension to call an arbitrary program when a file with the given extension is opened.
windows
Clipboard Collection with Xclip Tool
lowDetects attempts to collect data stored in the clipboard from users with the usage of xclip tool. Xclip has to be installed. Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.
linux
CMD Shell Output Redirect
lowDetects the use of the redirection character ">" to redirect information on the command line. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
windows
CodePage Modification Via MODE.COM
lowDetects a CodePage modification using the "mode.com" utility. This behavior has been used by threat actors behind Dharma ransomware.
windows
Compressed File Creation Via Tar.EXE
lowDetects execution of "tar.exe" in order to create a compressed file. Adversaries may abuse various utilities to compress or encrypt data before exfiltration.
windows
Compressed File Extraction Via Tar.EXE
lowDetects execution of "tar.exe" in order to extract compressed file. Adversaries may abuse various utilities in order to decompress data to avoid detection.
windows
Connection Proxy
lowDetects setting proxy configuration
linux
Container Residence Discovery Via Proc Virtual FS
lowDetects potential container discovery via listing of certain kernel features in the "/proc" virtual filesystem
linux
Creation Of A Local User Account
lowDetects the creation of a new user account. Such accounts may be used for persistence that do not require persistent remote access tools to be deployed on the system.
macos
Crontab Enumeration
lowDetects usage of crontab to list the tasks of the user
linux
Curl Usage on Linux
lowDetects a curl process start on linux, which indicates a file download from a remote location or a simple web request to a remote server
linux
Curl.EXE Execution
lowDetects a curl process start on Windows, which could indicates a file download from a remote location or a simple web request to a remote server
windows
Data Copied To Clipboard Via Clip.EXE
lowDetects the execution of clip.exe in order to copy data to the clipboard. Adversaries may collect data stored in the clipboard from users copying information within or between applications.
windows
DD File Overwrite
lowDetects potential overwriting and deletion of a file using DD.
linux
Decode Base64 Encoded Text
lowDetects usage of base64 utility to decode arbitrary base64-encoded text
linux
Decode Base64 Encoded Text -MacOs
lowDetects usage of base64 utility to decode arbitrary base64-encoded text
macos
Directory Removal Via Rmdir
lowDetects execution of the builtin "rmdir" command in order to delete directories. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
windows
DirLister Execution
lowDetect the usage of "DirLister.exe" a utility for quickly listing folder or drive contents. It was seen used by BlackCat ransomware to create a list of accessible directories and files.
windows
Discovery of a System Time
lowIdentifies use of various commands to query a systems time. This technique may be used before executing a scheduled task or to discover the time zone of a target system.
windows
Docker Container Discovery Via Dockerenv Listing
lowDetects listing or file reading of ".dockerenv" which can be a sing of potential container discovery
linux
Exports Registry Key To a File
lowDetects the export of the target Registry key to a file.
windows
File And SubFolder Enumeration Via Dir Command
lowDetects usage of the "dir" command part of Windows CMD with the "/S" command line flag in order to enumerate files in a specified directory and all subdirectories.
windows
File Deletion Via Del
lowDetects execution of the builtin "del"/"erase" commands in order to delete files. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
windows
Files Added To An Archive Using Rar.EXE
lowDetects usage of "rar" to add files to an archive for potential compression. An adversary may compress data (e.g. sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows
Firewall Configuration Discovery Via Netsh.EXE
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows
Fsutil Drive Enumeration
lowAttackers may leverage fsutil to enumerated connected drives.
windows
Gatekeeper Bypass via Xattr
lowDetects macOS Gatekeeper bypass via xattr utility
macos
Guest Account Enabled Via Sysadminctl
lowDetects attempts to enable the guest account using the sysadminctl utility
macos
GUI Input Capture - macOS
lowDetects attempts to use system dialog prompts to capture user credentials
macos
HH.EXE Execution
lowDetects the execution of "hh.exe" to open ".chm" files.
windows
HTML File Opened From Download Folder
lowDetects web browser process opening an HTML file from a user's Downloads folder. This behavior is could be associated with phishing attacks where threat actors send HTML attachments to users. When a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware. During investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.
windows
Import New Module Via PowerShell CommandLine
lowDetects usage of the "Import-Module" cmdlet in order to add new Cmdlets to the current PowerShell session
windows
Indirect Command Execution By Program Compatibility Wizard
lowDetect indirect command execution via Program Compatibility Assistant pcwrun.exe
windows
Insensitive Subfolder Search Via Findstr.EXE
lowDetects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.
windows
Install Root Certificate
lowDetects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s
linux
Interesting Service Enumeration Via Sc.EXE
lowDetects the enumeration and query of interesting and in some cases sensitive services on the system via "sc.exe". Attackers often try to enumerate the services currently running on a system in order to find different attack vectors.
windows
JAMF MDM Execution
lowDetects execution of the "jamf" binary to create user accounts and run commands. For example, the binary can be abused by attackers on the system in order to bypass security controls or remove application control polices.
macos
JScript Compiler Execution
lowDetects the execution of the "jsc.exe" (JScript Compiler). Attacker might abuse this in order to compile JScript files on the fly and bypassing application whitelisting.
windows
Linux Doas Tool Execution
lowDetects the doas tool execution in linux host platform. This utility tool allow standard users to perform tasks as root, the same way sudo does.
linux
Linux Network Service Scanning Tools Execution
lowDetects execution of network scanning and reconnaisance tools. These tools can be used for the enumeration of local or remote network services for example.
linux
Linux Package Uninstall
lowDetects linux package removal using builtin tools such as "yum", "apt", "apt-get" or "dpkg".
linux
Linux Remote System Discovery
lowDetects the enumeration of other remote systems.
linux
Linux Setgid Capability Set on a Binary via Setcap Utility
lowDetects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
linux
Linux Setuid Capability Set on a Binary via Setcap Utility
lowDetects the use of the 'setcap' utility to set the 'setuid' capability (cap_setuid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of user IDs (UIDs), including setting its current UID to a value that would otherwise be restricted (i.e. UID 0, the root user). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
linux
Linux Sudo Chroot Execution
lowDetects the execution of 'sudo' command with '--chroot' option, which is used to change the root directory for command execution. Attackers may use this technique to evade detection and execute commands in a modified environment. This can be part of a privilege escalation strategy, as it allows the execution of commands with elevated privileges in a controlled environment as seen in CVE-2025-32463. While investigating, look out for unusual or unexpected use of 'sudo --chroot' in conjunction with other commands or scripts such as execution from temporary directories or unusual user accounts.
linux
Local Accounts Discovery
lowLocal accounts, System Owner/User discovery using operating systems utilities
windows
Local Groups Discovery - Linux
lowDetects enumeration of local system groups. Adversaries may attempt to find local system groups and permission settings
linux
Local Groups Reconnaissance Via Wmic.EXE
lowDetects the execution of "wmic" with the "group" flag. Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.
windows
Local System Accounts Discovery - Linux
lowDetects enumeration of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.
linux
Local System Accounts Discovery - MacOs
lowDetects enumeration of local system accounts on MacOS systems. This can be used by attackers to identify accounts for lateral movement or privilege escalation.
macos
MacOS Network Service Scanning
lowDetects enumeration of local or remote network services.
macos
Malicious Windows Script Components File Execution by TAEF Detection
lowWindows Test Authoring and Execution Framework (TAEF) framework allows you to run automation by executing tests files written on different languages (C, C#, Microsoft COM Scripting interfaces Adversaries may execute malicious code (such as WSC file with VBScript, dll and so on) directly by running te.exe
windows
Mstsc.EXE Execution With Local RDP File
lowDetects potential RDP connection via Mstsc using a local ".rdp" file
windows
Named Pipe Created Via Mkfifo
lowDetects the creation of a new named pipe using the "mkfifo" utility
linux
Net.EXE Execution
lowDetects execution of "Net.EXE".
windows
New Process Created Via Taskmgr.EXE
lowDetects the creation of a process via the Windows task manager. This might be an attempt to bypass UAC
windows
New Service Creation Using PowerShell
lowDetects the creation of a new service using powershell.
windows
New Service Creation Using Sc.EXE
lowDetects the creation of a new service using the "sc.exe" utility.
windows
New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet
lowDetects calls to the "New-NetFirewallRule" cmdlet from PowerShell in order to add a new firewall rule with an "Allow" action.
windows
Nltest.EXE Execution
lowDetects nltest commands that can be used for information discovery
windows
NodeJS Execution of JavaScript File
lowDetects execution of JavaScript or JSC files using NodeJs binary node.exe, that could be potentially suspicious. Node.js is a popular open-source JavaScript runtime that runs code outside browsers and is widely used for both frontend and backend development. Adversaries have been observed abusing Node.js to disguise malware as legitimate processes, evade security defenses, and maintain persistence within target systems. Because Node.js is commonly used, this rule may generate false positives in some environments. However, if such activity is unusual in your environment, it is highly suspicious and warrants immediate investigation.
windows
Non Interactive PowerShell Process Spawned
lowDetects non-interactive PowerShell activity by looking at the "powershell" process with a non-user GUI process such as "explorer.exe" as a parent.
windows
Notepad Password Files Discovery
lowDetects the execution of Notepad to open a file that has the string "password" which may indicate unauthorized access to credentials or suspicious activity.
windows
OS Architecture Discovery Via Grep
lowDetects the use of grep to identify information about the operating system architecture. Often combined beforehand with the execution of "uname" or "cat /proc/cpuinfo"
linux
Password Protected Compressed File Extraction Via 7Zip
lowDetects usage of 7zip utilities (7z.exe, 7za.exe and 7zr.exe) to extract password protected zip files.
windows
Potential Container Discovery Via Inodes Listing
lowDetects listing of the inodes of the "/" directory to determine if the we are running inside of a container.
linux
Potential Encoded PowerShell Patterns In CommandLine
lowDetects specific combinations of encoding methods in PowerShell via the commandline
windows
Potential Executable Run Itself As Sacrificial Process
lowDetects when an executable launches an identical instance of itself, a behavior often used to create a suspended “sacrificial” process for code injection or evasion. Investigate for indicators such as the process being started in suspended mode, rapid parent termination, memory manipulation (e.g., WriteProcessMemory, CreateRemoteThread), or unsigned binaries. Review command-line arguments, process ancestry, and network activity to confirm if this is legitimate behavior or process injection activity.
windows
Potential Execution of Sysinternals Tools
lowDetects command lines that contain the 'accepteula' flag which could be a sign of execution of one of the Sysinternals tools
windows
Potential File Override/Append Via SET Command
lowDetects the use of the "SET" internal command of Cmd.EXE with the /p flag followed directly by an "=" sign. Attackers used this technique along with an append redirection operator ">>" in order to update the content of a file indirectly. Ex: cmd /c >> example.txt set /p="test data". This will append "test data" to contents of "example.txt". The typical use case of the "set /p=" command is to prompt the user for input.
windows
Potential Proxy Execution Via Explorer.EXE From Shell Process
lowDetects the creation of a child "explorer.exe" process from a shell like process such as "cmd.exe" or "powershell.exe". Attackers can use "explorer.exe" for evading defense mechanisms by proxying the execution through the latter. While this is often a legitimate action, this rule can be use to hunt for anomalies. Muddy Waters threat actor was seeing using this technique.
windows
Potential Suspicious Execution From GUID Like Folder Names
lowDetects potential suspicious execution of a GUID like folder name located in a suspicious location such as %TEMP% as seen being used in IcedID attacks. Use this rule to hunt for potentially suspicious activity stemming from uncommon folders.
windows
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
lowDetects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
windows
Process Discovery
lowDetects process discovery commands. Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network
linux
Process Execution From WebDAV Share
lowDetects execution of processes with image paths starting with WebDAV shares (\\), which might indicate malicious file execution from remote web shares. Execution of processes from WebDAV shares can be a sign of lateral movement or exploitation attempts, especially if the process is not a known legitimate application. Exploitation Attempt of vulnerabilities like CVE-2025-33053 also involves executing processes from WebDAV paths.
windows
Process Terminated Via Taskkill
lowDetects execution of "taskkill.exe" in order to stop a service or a process. Look for suspicious parents executing this command in order to hunt for potential malicious activity. Attackers might leverage this in order to conduct data destruction or data encrypted for impact on the data stores of services like Exchange and SQL Server.
windows
PUA - Adidnsdump Execution
lowThis tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks Python 3 and python.exe must be installed, Usee to Query/modify DNS records for Active Directory integrated DNS via LDAP
windows
QuickAssist Execution
lowDetects the execution of Microsoft Quick Assist tool "QuickAssist.exe". This utility can be used by attackers to gain remote access.
windows
RegAsm.EXE Execution Without CommandLine Flags or Files
lowDetects the execution of "RegAsm.exe" without a commandline flag or file, which might indicate potential process injection activity. Usually "RegAsm.exe" should point to a dedicated DLL file or call the help with the "/?" flag.
windows
Registry Modification Via Regini.EXE
lowDetects the execution of regini.exe which can be used to modify registry keys, the changes are imported from one or more text files.
windows
Remote Access Tool - ScreenConnect Remote Command Execution
lowDetects the execution of a system command via the ScreenConnect RMM service.
windows
Remote Access Tool - Team Viewer Session Started On Linux Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
linux
Remote Access Tool - Team Viewer Session Started On MacOS Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
macos
Remote Access Tool - Team Viewer Session Started On Windows Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
windows
Run Once Task Execution as Configured in Registry
lowThis rule detects the execution of Run Once task as configured in the registry
windows
SC.EXE Query Execution
lowDetects execution of "sc.exe" to query information about registered services on the system
windows
Scheduled Task Creation Via Schtasks.EXE
lowDetects the creation of scheduled tasks by user accounts via the "schtasks" utility.
windows
Scheduled Task/Job At
lowDetects the use of at/atd which are utilities that are used to schedule tasks. They are often abused by adversaries to maintain persistence or to perform task scheduling for initial or recurring execution of malicious code
linux
Screen Capture - macOS
lowDetects attempts to use screencapture to collect macOS screenshots
macos
Security Software Discovery - Linux
lowDetects usage of system utilities (only grep and egrep for now) to discover security software discovery
linux
Set Files as System Files Using Attrib.EXE
lowDetects the execution of "attrib" with the "+s" flag to mark files as system files
windows
Setuid and Setgid
lowDetects suspicious change of file privileges with chown and chmod commands
linux
Share And Session Enumeration Using Net.EXE
lowDetects attempts to enumerate file shares, printer shares and sessions using "net.exe" with the "view" flag.
windows
Space After Filename - macOS
lowDetects attempts to masquerade as legitimate files by adding a space to the end of the filename.
macos
Split A File Into Pieces
lowDetection use of the command "split" to split files into parts and possible transfer.
macos
Start Windows Service Via Net.EXE
lowDetects the usage of the "net.exe" command to start a service using the "start" flag
windows
Stop Windows Service Via Net.EXE
lowDetects the stopping of a Windows service via the "net" utility.
windows
Stop Windows Service Via PowerShell Stop-Service
lowDetects the stopping of a Windows service via the PowerShell Cmdlet "Stop-Service"
windows
Stop Windows Service Via Sc.EXE
lowDetects the stopping of a Windows service via the "sc.exe" utility
windows
Suspicious Execution of Hostname
lowUse of hostname to get information
windows
Suspicious Execution of Systeminfo
lowDetects usage of the "systeminfo" command to retrieve information
windows
Suspicious Network Command
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows
Suspicious Query of MachineGUID
lowUse of reg to get MachineGuid information
windows
Suspicious Where Execution
lowAdversaries may enumerate browser bookmarks to learn more about compromised hosts. Browser bookmarks may reveal personal information about users (ex: banking sites, interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
windows
System Information Discovery via Registry Queries
lowDetects attempts to query system information directly from the Windows Registry.
windows
System Information Discovery Via Wmic.EXE
lowDetects the use of the WMI command-line (WMIC) utility to identify and display various system information, including OS, CPU, GPU, disk drive names, memory capacity, display resolution, baseboard, BIOS, and GPU driver products/versions.
windows
System Integrity Protection (SIP) Enumeration
lowDetects the use of csrutil to view the Configure System Integrity Protection (SIP) status. This technique is used in post-exploit scenarios.
macos
System Network Connections Discovery - Linux
lowDetects usage of system utilities to discover system network connections
linux
System Network Connections Discovery Via Net.EXE
lowAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
windows
Unmount Share Via Net.EXE
lowDetects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
windows
Unusually Long PowerShell CommandLine
lowDetects unusually long PowerShell command lines with a length of 1000 characters or more
windows
Userdomain Variable Enumeration
lowDetects suspicious enumeration of the domain the user is associated with.
windows
Virtualbox Driver Installation or Starting of VMs
lowAdversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.
windows
Windows MSIX Package Support Framework AI_STUBS Execution
lowDetects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
windows
Windows Processes Suspicious Parent Directory
lowDetect suspicious parent processes of well-known Windows processes
windows
Windows Share Mount Via Net.EXE
lowDetects when a share is mounted using the "net.exe" utility
windows
File and Directory Discovery - Linux
informationalDetects usage of system utilities such as "find", "tree", "findmnt", etc, to discover files, directories and network shares.
linux
File and Directory Discovery - MacOS
informationalDetects usage of system utilities to discover files and directories
macos
File Deletion
informationalDetects file deletion using "rm", "shred" or "unlink" commands which are used often by adversaries to delete files left behind by the actions of their intrusion activity
linux
Local Groups Discovery - MacOs
informationalDetects enumeration of local system groups
macos
Macos Remote System Discovery
informationalDetects the enumeration of other remote systems.
macos
Network Sniffing - MacOs
informationalDetects the usage of tooling to sniff network traffic. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
macos
Potential BOINC Software Execution (UC-Berkeley Signature)
informationalDetects the use of software that is related to the University of California, Berkeley via metadata information. This indicates it may be related to BOINC software and can be used maliciously if unauthorized.
windows
Suspicious High IntegrityLevel Conhost Legacy Option
informationalForceV1 asks for information directly from the kernel space. Conhost connects to the console application. High IntegrityLevel means the process is running with elevated privileges, such as an Administrator context.
windows
Suspicious Tasklist Discovery Command
informationalAdversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network
windows
System Information Discovery
informationalDetects system information discovery commands
linux
System Network Connections Discovery - MacOs
informationalDetects usage of system utilities to discover system network connections
macos
System Network Discovery - Linux
informationalDetects enumeration of local network configuration
linux
System Network Discovery - macOS
informationalDetects enumeration of local network configuration
macos
System Shutdown/Reboot - MacOs
informationalAdversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
macos