MITRE ATT&CK technique
Software Deployment Tools detection rulesT1072
Software Deployment Tools (T1072) is a MITRE ATT&CK technique in the Execution tactic. This page lists the 4 community-maintained Sigma detection rules in the library mapped to T1072 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
Restricted Software Access By SRP
highDetects restricted access to applications by the Software Restriction Policies (SRP) policy
windows
PDQ Deploy Remote Adminstartion Tool Execution
mediumDetect use of PDQ Deploy remote admin tool
windows · process_creation
PUA - Radmin Viewer Utility Execution
mediumDetects the execution of Radmin which can be abused by an adversary to remotely control Windows machines
windows · process_creation
Suspicious Csi.exe Usage
mediumCsi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'
windows · process_creation