MITRE ATT&CK technique
Compromise Infrastructure detection rulesT1584
Compromise Infrastructure (T1584) is a MITRE ATT&CK technique in the Resource Development tactic. This page lists the 4 community-maintained Sigma detection rules in the library mapped to T1584 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux.
Tactic
Suspicious External WebDAV Execution
highDetects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
proxy
Program Executions in Suspicious Folders
mediumDetects program executions in suspicious non-program folders related to malware or hacking activity
linux
WebDAV Temporary Local File Creation
mediumDetects the creation of WebDAV temporary files with potentially suspicious extensions
windows · file_event
Windows Update Error
informationalDetects Windows update errors including installation failures and connection issues. Defenders should observe this in case critical update KBs aren't installed.
windows