MITRE ATT&CK technique
Exploitation for Stealth detection rulesT1211
Exploitation for Stealth (T1211) is a MITRE ATT&CK technique in the Stealth tactic. This page lists the 4 community-maintained Sigma detection rules in the library mapped to T1211 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
Audit CVE Event
criticalDetects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
windows
Microsoft Malware Protection Engine Crash
highThis rule detects a suspicious crash of the Microsoft Malware Protection Engine
windows
Microsoft Malware Protection Engine Crash - WER
highThis rule detects a suspicious crash of the Microsoft Malware Protection Engine
windows
Writing Of Malicious Files To The Fonts Folder
mediumMonitors for the hiding possible malicious files in the C:\Windows\Fonts\ location. This folder doesn't require admin privillege to be written and executed from.
windows · process_creation