MITRE ATT&CK technique
Stage Capabilities detection rulesT1608
Stage Capabilities (T1608) is a MITRE ATT&CK technique in the Resource Development tactic. This page lists the 3 community-maintained Sigma detection rules in the library mapped to T1608 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, aws.
Tactic
AWS KMS Imported Key Material Usage
highDetects the import or deletion of key material in AWS KMS, which can be used as part of ransomware attacks. This activity is uncommon and provides a high certainty signal.
aws
HybridConnectionManager Service Installation - Registry
highDetects the installation of the Azure Hybrid Connection Manager service to allow remote code execution from Azure function.
windows · registry_event
Suspicious Download from Office Domain
highDetects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents
windows · process_creation