Platform / product
windows Sigma detection rules
2875 community-maintained Sigma detection rules in the library target the windows platform, covering log sources such as process_creation, registry_set, file_event, ps_script. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
Log sources
AD Object WriteDAC Access
criticalDetects WRITE_DAC access to a domain object
windows · security
APT27 - Emissary Panda Activity
criticalDetects the execution of DLL side-loading malware used by threat group Emissary Panda aka APT27
windows · process_creation
APT29 2018 Phishing Campaign CommandLine Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows · process_creation
APT29 2018 Phishing Campaign File Indicators
criticalDetects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant
windows · file_event
APT31 Judgement Panda Activity
criticalDetects APT31 Judgement Panda activity as described in the Crowdstrike 2019 Global Threat Report
windows · process_creation
Audit CVE Event
criticalDetects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.
windows · application
Bad Opsec Powershell Code Artifacts
criticalfocuses on trivial artifacts observed in variants of prevalent offensive ps1 payloads, including Cobalt Strike Beacon, PoshC2, Powerview, Letmein, Empire, Powersploit, and other attack payloads that often undergo minimal changes by attackers due to bad opsec.
windows · ps_module
Certificate Request Export to Exchange Webserver
criticalDetects a write of an Exchange CSR to an untypical directory or with aspx name suffix which can be used to place a webshell
windows · msexchange-management
CobaltStrike Named Pipe
criticalDetects the creation of a named pipe as used by CobaltStrike
windows · pipe_created
CobaltStrike Named Pipe Pattern Regex
criticalDetects the creation of a named pipe matching a pattern used by CobaltStrike Malleable C2 profiles
windows · pipe_created
CobaltStrike Service Installations - System
criticalDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
windows · system
COLDSTEEL RAT Cleanup Command Execution
criticalDetects the creation of a "rundll32" process from the ColdSteel persistence service to initiate the cleanup command by calling one of its own exports. This functionality is not present in "MileStone2017" and some "MileStone2016" samples
windows · process_creation
COLDSTEEL RAT Service Persistence Execution
criticalDetects the creation of an "svchost" process with specific command line flags, that were seen present and used by ColdSteel RAT
windows · process_creation
CosmicDuke Service Installation
criticalDetects the installation of a service named "javamtsup" on the system. The CosmicDuke info stealer uses Windows services typically named "javamtsup" for persistence.
windows · security
CVE-2021-1675 Print Spooler Exploitation
criticalDetects driver load events print service operational log that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675
windows · printservice-operational
CVE-2021-1675 Print Spooler Exploitation Filename Pattern
criticalDetects the default filename used in PoC code against print spooler vulnerability CVE-2021-1675
windows · file_event
CVE-2021-1675 Print Spooler Exploitation IPC Access
criticalDetects remote printer driver load from Detailed File Share in Security logs that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675 and CVE-2021-34527
windows · security
CVE-2021-31979 CVE-2021-33771 Exploits
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · registry_set
CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum
criticalDetects patterns as noticed in exploitation of Windows CVE-2021-31979 CVE-2021-33771 vulnerability and DevilsTongue malware by threat group Sourgum
windows · file_event
CVE-2023-23397 Exploitation Attempt
criticalDetects outlook initiating connection to a WebDAV or SMB share, which could be a sign of CVE-2023-23397 exploitation.
windows · security
CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security
criticalThis detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory.
windows · security
DarkSide Ransomware Pattern
criticalDetects DarkSide Ransomware and helpers
windows · process_creation
DC Machine Account Network Logon from Non-DC Source IP
criticalDetects a Domain Controller machine account authenticating from a source IP that is not a known Domain Controller. DC machine accounts should only authenticate locally or from other DCs during replication operations. Any logon event for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - Silver Ticket: attacker forged a Kerberos TGS for a DC machine account without requesting a TGT - Pass-the-Ticket: attacker is replaying a captured DC machine account TGS from a non-DC host - Overpass-the-Hash: attacker converted a stolen DC machine account hash into a Kerberos ticket and is authenticating from a non-DC host - Exploitation of certain vulnerabilities such as CVE-2026-54121 (Certighost): attacker obtained a DC certificate via ADCS CDC-chase abuse, authenticates via PKINIT as the DC from their own host, then performs DCSync
windows · security
DiagTrackEoP Default Login Username
criticalDetects the default "UserName" used by the DiagTrackEoP POC
windows · security
Diamond Sleet APT Scheduled Task Creation
criticalDetects registry event related to the creation of a scheduled task used by Diamond Sleet APT during exploitation of Team City CVE-2023-42793 vulnerability
windows · security
DNS RCE CVE-2020-1350
criticalDetects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
windows · process_creation
Droppers Exploiting CVE-2017-11882
criticalDetects exploits that use CVE-2017-11882 to start EQNEDT32.EXE and other sub processes like mshta.exe
windows · process_creation
DumpStack.log Defender Evasion
criticalDetects the use of the filename DumpStack.log to evade Microsoft Defender
windows · process_creation
Elise Backdoor Activity
criticalDetects Elise backdoor activity used by APT32
windows · process_creation
Equation Group DLL_U Export Function Load
criticalDetects a specific export function name used by one of EquationGroup tools
windows · process_creation
EvilNum APT Golden Chickens Deployment Via OCX Files
criticalDetects Golden Chickens deployment method as used by Evilnum and described in ESET July 2020 report
windows · process_creation
Exploit for CVE-2015-1641
criticalDetects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641
windows · process_creation
Exploit for CVE-2017-8759
criticalDetects Winword starting uncommon sub process csc.exe as used in exploits for CVE-2017-8759
windows · process_creation
Exploiting CVE-2019-1388
criticalDetects an exploitation attempt in which the UAC consent dialogue is used to invoke an Internet Explorer process running as LOCAL_SYSTEM
windows · process_creation
FlowCloud Registry Markers
criticalDetects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
windows · registry_event
FoggyWeb Backdoor DLL Loading
criticalDetects DLL hijacking technique used by NOBELIUM in their FoggyWeb backdoor. Which loads a malicious version of the expected "version.dll" dll
windows · image_load
Goofy Guineapig Backdoor Service Creation
criticalDetects service creation persistence used by the Goofy Guineapig backdoor
windows · system
Greenbug Espionage Group Indicators
criticalDetects tools and process executions used by Greenbug in their May 2020 campaign as reported by Symantec
windows · process_creation
Griffon Malware Attack Pattern
criticalDetects process execution patterns related to Griffon malware as reported by Kaspersky
windows · process_creation
HackTool - Credential Dumping Tools Named Pipe Created
criticalDetects well-known credential dumping tools execution via specific named pipe creation
windows · pipe_created
HackTool - DiagTrackEoP Default Named Pipe
criticalDetects creation of default named pipe used by the DiagTrackEoP POC, a tool that abuses "SeImpersonate" privilege.
windows · pipe_created
HackTool - DInjector PowerShell Cradle Execution
criticalDetects the use of the Dinject PowerShell cradle based on the specific flags
windows · process_creation
HackTool - Dumpert Process Dumper Default File
criticalDetects the creation of the default dump file used by Outflank Dumpert tool. A process dumper, which dumps the lsass process memory
windows · file_event
HackTool - Dumpert Process Dumper Execution
criticalDetects the use of Dumpert process dumper, which dumps the lsass.exe process memory
windows · process_creation
HackTool - Empire PowerShell UAC Bypass
criticalDetects some Empire PowerShell UAC bypass methods
windows · process_creation
HackTool - F-Secure C3 Load by Rundll32
criticalF-Secure C3 produces DLLs with a default exported StartNodeRelay function.
windows · process_creation
HackTool - Inveigh Execution
criticalDetects the use of Inveigh a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool
windows · process_creation
HackTool - Inveigh Execution Artefacts
criticalDetects the presence and execution of Inveigh via dropped artefacts
windows · file_event
HackTool - Koh Default Named Pipe
criticalDetects creation of default named pipes used by the Koh tool
windows · pipe_created
HackTool - Mimikatz Kirbi File Creation
criticalDetects the creation of files created by mimikatz such as ".kirbi", "mimilsa.log", etc.
windows · file_event
HackTool - PurpleSharp Execution
criticalDetects the execution of the PurpleSharp adversary simulation tool
windows · process_creation
HackTool - QuarksPwDump Dump File
criticalDetects a dump file written by QuarksPwDump password dumper
windows · file_event
HackTool - Rubeus Execution
criticalDetects the execution of the hacktool Rubeus via PE information of command line parameters
windows · process_creation
HackTool - SafetyKatz Execution
criticalDetects the execution of the hacktool SafetyKatz via PE information and default Image name
windows · process_creation
HackTool - SecurityXploded Execution
criticalDetects the execution of SecurityXploded Tools
windows · process_creation
HackTool - SharpUp PrivEsc Tool Execution
criticalDetects the use of SharpUp, a tool for local privilege escalation
windows · process_creation
HackTool - Sliver C2 Implant Activity Pattern
criticalDetects process activity patterns as seen being used by Sliver C2 framework implants
windows · process_creation
HackTool - SysmonEOP Execution
criticalDetects the execution of the PoC that can be used to exploit Sysmon CVE-2022-41120
windows · process_creation
HackTool - Windows Credential Editor (WCE) Execution
criticalDetects the use of Windows Credential Editor (WCE), a popular post-exploitation tool used to extract plaintext passwords, hash, PIN code and Kerberos tickets from memory. It is often used by threat actors for credential dumping and lateral movement within compromised networks.
windows · process_creation
Hacktool Execution - Imphash
criticalDetects the execution of different Windows based hacktools via their import hash (imphash) even if the files have been renamed
windows · process_creation
HAFNIUM Exchange Exploitation Activity
criticalDetects activity observed by different researchers to be HAFNIUM group activity (or related) on Exchange servers
windows · process_creation
InstallerFileTakeOver LPE CVE-2021-41379 File Create Event
criticalDetects signs of the exploitation of LPE CVE-2021-41379 that include an msiexec process that creates an elevation_service.exe file
windows · file_event
Lazarus Group Activity
criticalDetects different process execution behaviors as described in various threat reports on Lazarus group activity
windows · process_creation
Leviathan Registry Key Activity
criticalDetects registry key used by Leviathan APT in Malaysian focused campaign
windows · registry_event
LockerGoga Ransomware Activity
criticalDetects LockerGoga ransomware activity via specific command line.
windows · process_creation
Mailbox Export to Exchange Webserver
criticalDetects a successful export of an Exchange mailbox to untypical directory or with aspx name suffix which can be used to place a webshell or the needed role assignment for it
windows · msexchange-management
Malicious DLL Load By Compromised 3CXDesktopApp
criticalDetects DLL load activity of known compromised DLLs used in by the compromised 3CXDesktopApp
windows · image_load
Malicious Named Pipe Created
criticalDetects the creation of a named pipe seen used by known APTs or malware.
windows · pipe_created
Mint Sandstorm - AsperaFaspex Suspicious Process Execution
criticalDetects suspicious execution from AsperaFaspex as seen used by Mint Sandstorm
windows · process_creation
Mint Sandstorm - ManageEngine Suspicious Process Execution
criticalDetects suspicious execution from ManageEngine as seen used by Mint Sandstorm
windows · process_creation
Moriya Rootkit - System
criticalDetects the use of Moriya rootkit as described in the securelist's Operation TunnelSnake report
windows · system
Moriya Rootkit File Created
criticalDetects the creation of a file named "MoriyaStreamWatchmen.sys" in a specific location. This filename was reported to be related to the Moriya rootkit as described in the securelist's Operation TunnelSnake report.
windows · file_event
NotPetya Ransomware Activity
criticalDetects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil
windows · process_creation
OceanLotus Registry Activity
criticalDetects registry keys created in OceanLotus (also known as APT32) attacks
windows · registry_event
OilRig APT Activity
criticalDetects OilRig activity as reported by Nyotron in their March 2018 report
windows · process_creation
OilRig APT Registry Persistence
criticalDetects OilRig registry persistence as reported by Nyotron in their March 2018 report
windows · registry_event
OilRig APT Schedule Task Persistence - Security
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows · security
OilRig APT Schedule Task Persistence - System
criticalDetects OilRig schedule task persistence as reported by Nyotron in their March 2018 report
windows · system
Pandemic Registry Key
criticalDetects Pandemic Windows Implant
windows · registry_event
Persistence Via Sticky Key Backdoor
criticalBy replacing the sticky keys executable with the local admins CMD executable, an attacker is able to access a privileged windows console session without authenticating to the system. When the sticky keys are "activated" the privilleged shell is launched.
windows · process_creation
Potential Conti Ransomware Activity
criticalDetects a specific command used by the Conti ransomware group
windows · process_creation
Potential Credential Dumping Via LSASS Process Clone
criticalDetects a suspicious LSASS process process clone that could be a sign of credential dumping activity
windows · process_creation
Potential Credential Dumping Via LSASS SilentProcessExit Technique
criticalDetects changes to the Registry in which a monitor program gets registered to dump the memory of the lsass.exe process
windows · registry_event
Potential CVE-2021-41379 Exploitation Attempt
criticalDetects potential exploitation attempts of CVE-2021-41379 (InstallerFileTakeOver), a local privilege escalation (LPE) vulnerability where the attacker spawns a "cmd.exe" process as a child of Microsoft Edge elevation service "elevation_service" with "LOCAL_SYSTEM" rights
windows · process_creation
Potential DCOM InternetExplorer.Application DLL Hijack
criticalDetects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class over the network
windows · file_event
Potential DCOM InternetExplorer.Application DLL Hijack - Image Load
criticalDetects potential DLL hijack of "iertutil.dll" found in the DCOM InternetExplorer.Application Class
windows · image_load
Potential Dridex Activity
criticalDetects potential Dridex acitvity via specific process patterns
windows · process_creation
Potential Dtrack RAT Activity
criticalDetects potential Dtrack RAT activity via specific process patterns
windows · process_creation
Potential Emotet Rundll32 Execution
criticalDetecting Emotet DLL loading by looking for rundll32.exe processes with command lines ending in ,RunDLL or ,Control_RunDLL
windows · process_creation
Potential Maze Ransomware Activity
criticalDetects specific process characteristics of Maze ransomware word document droppers
windows · process_creation
Potential QBot Activity
criticalDetects potential QBot activity by looking for process executions used previously by QBot
windows · process_creation
Potential Russian APT Credential Theft Activity
criticalDetects Russian group activity as described in Global Threat Report 2019 by Crowdstrike
windows · process_creation
Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
criticalDetects the creation of file such as spinstall0.aspx which may indicate successful exploitation of CVE-2025-53770. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
windows · file_event
Potential SMB Relay Attack Tool Execution
criticalDetects different hacktools used for relay attacks on Windows for privilege escalation
windows · process_creation
Potential SystemNightmare Exploitation Attempt
criticalDetects an exploitation attempt of SystemNightmare in order to obtain a shell as LOCAL_SYSTEM
windows · process_creation
PrinterNightmare Mimikatz Driver Name
criticalDetects static QMS 810 and mimikatz driver name used by Mimikatz as exploited in CVE-2021-1675 and CVE-2021-34527
windows · registry_event
ProxyLogon MSExchange OabVirtualDirectory
criticalDetects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory
windows · msexchange-management
Qakbot Rundll32 Exports Execution
criticalDetects specific process tree behavior of a "rundll32" execution with exports linked with Qakbot activity.
windows · process_creation
Qakbot Rundll32 Fake DLL Extension Execution
criticalDetects specific process tree behavior of a "rundll32" execution where the DLL doesn't have the ".dll" extension. This is often linked with potential Qakbot activity.
windows · process_creation
RedSun - Named Pipe Created
criticalDetects the creation of a named pipe with the hardcoded name "REDSUN". The RedSun exploit tool uses a pipe with this name for synchronisation and command communication between its components during the Cloud Files API + oplock-based AV bypass and privilege escalation chain. RedSun creates the pipe as \\??\pipe\REDSUN. The pipe server listens for the token-duplicated elevated process to connect and respond, completing the privilege escalation from user to SYSTEM. Presence of this pipe name indicates active or recent RedSun execution.
windows · pipe_created
RedSun - TieringEngineService.exe Detected as EICAR Test File
criticalDetects Windows Defender (EventID 1119 - Remediation Action Failed) flagging TieringEngineService.exe dropped in a characteristic RS-{GUID} temporary directory, or the RedSun.exe process itself being present. This covers the staging pattern used by RedSun, a Cloud Files API and opportunistic lock (oplock) based AV bypass/privilege escalation tool. RedSun works as follows: 1. Registers a Cloud Files sync root and creates a Cloud Files placeholder for TieringEngineService.exe under %TEMP%\RS-{GUID}\ 2. The placeholder file carries EICAR test file content (Virus:DOS/EICAR_Test_File) to reliably trigger a Defender scan and remediation attempt 3. Requests a batch oplock (FSCTL_REQUEST_BATCH_OPLOCK) on the placeholder file 4. When Defender attempts to scan/quarantine the file, the oplock triggers - holding the file open 5. During the oplock break window, RedSun swaps the mount point (junction) to redirect \\?\C:\Windows\System32 to the attacker-controlled temp path 6. This races the AV/OS into executing the malicious TieringEngineService.exe with elevated privileges
windows · windefend
RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir
criticalDetects the creation of a file named TieringEngineService.exe inside a directory whose path contains the RS- prefix characteristic of RedSun's staging directory (e.g. %TEMP%\RS-{GUID}\TieringEngineService.exe). RedSun registers a Cloud Files sync root under this RS-prefixed path and drops a masqueraded placeholder there as part of its oplock-based AV bypass and privilege escalation chain. The RS-{GUID} directory name is generated by RedSun itself and has no legitimate system usage, making the combination of this path prefix and the TieringEngineService.exe filename a highly specific indicator of RedSun activity.
windows · file_event
Registry Entries For Azorult Malware
criticalDetects the presence of a registry key created during Azorult execution
windows · registry_event
Renamed Whoami Execution
criticalDetects the execution of whoami that has been renamed to a different name to avoid detection
windows · process_creation
REvil Kaseya Incident Malware Patterns
criticalDetects process command line patterns and locations used by REvil group in Kaseya incident (can also match on other malware)
windows · process_creation
Rorschach Ransomware Execution Activity
criticalDetects Rorschach ransomware execution activity
windows · process_creation
Serv-U Exploitation CVE-2021-35211 by DEV-0322
criticalDetects patterns as noticed in exploitation of Serv-U CVE-2021-35211 vulnerability by threat group DEV-0322
windows · process_creation
Silence.EDA Detection
criticalDetects Silence EmpireDNSAgent as described in the Group-IP report
windows · ps_script
SNAKE Malware Kernel Driver File Indicator
criticalDetects SNAKE malware kernel driver file indicator
windows · file_event
SNAKE Malware Service Persistence
criticalDetects the creation of a service named "WerFaultSvc" which seems to be used by the SNAKE malware as a persistence mechanism as described by CISA in their report
windows · system
Sticky Key Like Backdoor Execution
criticalDetects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
windows · process_creation
Sticky Key Like Backdoor Usage - Registry
criticalDetects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen
windows · registry_event
Suspicious Child Process Of Veeam Dabatase
criticalDetects suspicious child processes of the Veeam service process. This could indicate potential RCE or SQL Injection.
windows · process_creation
Suspicious Cobalt Strike DNS Beaconing - DNS Client
criticalDetects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
windows · dns-client
Suspicious Cobalt Strike DNS Beaconing - Sysmon
criticalDetects a program that invoked suspicious DNS queries known from Cobalt Strike beacons
windows · dns_query
Suspicious PowerShell Mailbox Export to Share
criticalDetects usage of the powerShell New-MailboxExportRequest Cmdlet to exports a mailbox to a remote or local share, as used in ProxyShell exploitations
windows · process_creation
Suspicious PowerShell Mailbox Export to Share - PS
criticalDetects usage of the powerShell New-MailboxExportRequest Cmdlet to exports a mailbox to a remote or local share, as used in ProxyShell exploitations
windows · ps_script
TrustedPath UAC Bypass Pattern
criticalDetects indicators of a UAC bypass method by mocking directories
windows · process_creation
Turla Group Commands May 2020
criticalDetects commands used by Turla group as reported by ESET in May 2020
windows · process_creation
Turla Group Lateral Movement
criticalDetects automated lateral movement by Turla group
windows · process_creation
Turla Group Named Pipes
criticalDetects a named pipe used by Turla group samples
windows · pipe_created
Turla PNG Dropper Service
criticalThis method detects malicious services mentioned in Turla PNG dropper report by NCC Group in November 2018
windows · system
UNC2452 PowerShell Pattern
criticalDetects a specific PowerShell command line pattern used by the UNC2452 actors as mentioned in Microsoft and Symantec reports
windows · process_creation
WannaCry Ransomware Activity
criticalDetects WannaCry ransomware activity
windows · process_creation
WCE wceaux.dll Access
criticalDetects wceaux.dll access while WCE pass-the-hash remote command execution on source host
windows · security
Win Susp Computer Name Containing Samtheadmin
criticalDetects suspicious computer name samtheadmin-{1..100}$ generated by hacktool
windows · security
Windows Credential Editor Registry
criticalDetects the use of Windows Credential Editor (WCE)
windows · registry_event
Winnti Malware HK University Campaign
criticalDetects specific process characteristics of Winnti malware noticed in Dec/Jan 2020 in a campaign against Honk Kong universities
windows · process_creation
Winnti Pipemon Characteristics
criticalDetects specific process characteristics of Winnti Pipemon malware reported by ESET
windows · process_creation
WMI Backdoor Exchange Transport Agent
criticalDetects a WMI backdoor in Exchange Transport Agents via WMI event filters
windows · process_creation
Wmiexec Default Output File
criticalDetects the creation of the default output filename used by the wmiexec tool
windows · file_event
Wmiprvse Wbemcomn DLL Hijack - File
criticalDetects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
windows · file_event
Zerologon Exploitation Using Well-known Tools
criticalThis rule is designed to detect attempts to exploit Zerologon (CVE-2020-1472) vulnerability using mimikatz zerologon module or other exploits from machine with "kali" hostname.
windows · system
ZxShell Malware
criticalDetects a ZxShell start by the called and well-known function name
windows · process_creation
.RDP File Created By Uncommon Application
highDetects creation of a file with an ".rdp" extension by an application that doesn't commonly create such files.
windows · file_event
AADInternals PowerShell Cmdlets Execution - ProccessCreation
highDetects ADDInternals Cmdlet execution. A tool for administering Azure AD and Office 365. Which can be abused by threat actors to attack Azure AD or Office 365.
windows · process_creation
AADInternals PowerShell Cmdlets Execution - PsScript
highDetects ADDInternals Cmdlet execution. A tool for administering Azure AD and Office 365. Which can be abused by threat actors to attack Azure AD or Office 365.
windows · ps_script
Abusable DLL Potential Sideloading From Suspicious Location
highDetects potential DLL sideloading of DLLs that are known to be abused from suspicious locations
windows · image_load
Abuse of Service Permissions to Hide Services Via Set-Service
highDetects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)
windows · process_creation
Abuse of Service Permissions to Hide Services Via Set-Service - PS
highDetects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)
windows · ps_script
Abused Debug Privilege by Arbitrary Parent Processes
highDetection of unusual child processes by different system processes
windows · process_creation
Active Directory User Backdoors
highDetects scenarios where one can control another users or computers account without having to use their credentials.
windows · security
AD Privileged Users or Groups Reconnaissance
highDetect priv users or groups recon based on 4661 eventid and known privileged users or groups SIDs
windows · security
ADCS - Certighost CDC Chase Certificate Request (CVE-2026-54121)
highDetects Active Directory Certificate Services (ADCS) certificate requests that include the 'cdc' (Client DC) request attribute pointing to a domain or IP that is not a known Domain Controller. 'cdc' is an optional MS-WCCE enrollment attribute designed for cross-domain/cross-forest scenarios where a client in a child domain tells the CA which DC to contact for identity lookups when the CA cannot reach that domain directly. Legitimate values are DC hostnames or IPs that resolve to a real Domain Controller computer object in AD with the SERVER_TRUST_ACCOUNT (0x2000) userAccountControl bit set. In an attack, the attacker sets cdc to a domain or IP they control so the CA connects to their rogue SMB and LDAP services instead of a real DC. The rogue server returns a forged DC identity which the pre-patch CA accepts without validation. A malicious event looks like: Requester: DOMAIN\GHOST<random>$ Attributes: cdc:<attacker_ip> rmd:<target_dc_fqdn> SubjectAlternativeName: DNS Name=<target_dc_fqdn> CVE-2026-54121 (Certighost) is the known exploit for this path. The July 2026 patch added _ValidateChaseTargetIsDC which rejects cdc values that do not resolve to a legitimate DC object in Active Directory before following the chase.
windows · security
ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121)
highDetects successful issuance of an ADCS certificate where the request attributes include 'cdc' (Client DC) or 'rmd' (Remote Domain) pointing to a non-DC domain or IP, confirming the CA's chase fallback path was taken against an attacker-controlled target. 'cdc' directs the CA to an address for identity lookup; 'rmd' specifies the principal to look up there. In an attack (CVE-2026-54121, Certighost), cdc points to a rogue host that returns a forged DC identity. A successfully issued certificate at this stage means the attacker has obtained a cert carrying a Domain Controller's SID and DNS identity, enabling PKINIT authentication as that DC followed by DCSync replication.
windows · security
ADCS - Certighost Ghost Machine Account Creation
highDetects the creation of a machine account whose name starts with 'GHOST', which is the naming convention used by the CVE-2026-54121 (Certighost) exploit tooling. The public proof-of-concept for Certighost creates a temporary machine account with a name of the form GHOST<random>$ before enrolling for a DC certificate via the cdc chase path. The attacker-controlled machine account is used as the requester identity in the certificate request; the cdc attribute then redirects the CA to a rogue host that returns a forged Domain Controller identity. The resulting certificate carries the DC's SID and DNS name, enabling full PKINIT authentication as the targeted DC followed by DCSync. A machine account creation event (4741) where TargetUserName starts with 'GHOST' and ends with '$' is a high-fidelity indicator of this attack tool's execution. Legitimate environments very rarely provision machine accounts with this prefix.
windows · security
ADCS Certificate Template Configuration Vulnerability with Risky EKU
highDetects certificate creation with template allowing risk permission subject and risky EKU
windows · security
Add Debugger Entry To Hangs Key For Persistence
highDetects when an attacker adds a new "Debugger" value to the "Hangs" key in order to achieve persistence which will get invoked when an application crashes
windows · registry_set
Add Insecure Download Source To Winget
highDetects usage of winget to add a new insecure (http) download source. Winget will not allow the addition of insecure sources, hence this could indicate potential suspicious activity (or typos)
windows · process_creation
Add SafeBoot Keys Via Reg Utility
highDetects execution of "reg.exe" commands with the "add" or "copy" flags on safe boot registry keys. Often used by attacker to allow the ransomware to work in safe mode as some security products do not
windows · process_creation
Adwind RAT / JRAT
highDetects javaw.exe in AppData folder as used by Adwind / JRAT
windows · process_creation
Adwind RAT / JRAT File Artifact
highDetects javaw.exe in AppData folder as used by Adwind / JRAT
windows · file_event
All Backups Deleted Via Wbadmin.EXE
highDetects the deletion of all backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.
windows · process_creation
All Rules Have Been Deleted From The Windows Firewall Configuration
highDetects when a all the rules have been deleted from the Windows Defender Firewall configuration
windows · firewall-as
Allow Service Access Using Security Descriptor Tampering Via Sc.EXE
highDetects suspicious DACL modifications to allow access to a service from a suspicious trustee. This can be used to override access restrictions set by previous ACLs.
windows · process_creation
AMSI Bypass Pattern Assembly GetType
highDetects code fragments found in small and obfuscated AMSI bypass PowerShell scripts
windows · ps_script
AMSI Disabled via Registry Modification
highDetects attempts to disable AMSI (Anti-Malware Scan Interface) by modifying the AmsiEnable registry value. Anti-Malware Scan Interface (AMSI) is a security feature in Windows that allows applications and services to integrate with anti-malware products for enhanced protection against malicious content. Adversaries may attempt to disable AMSI to evade detection by security software, allowing them to execute malicious scripts or code without being scanned.
windows · registry_set
Antivirus Filter Driver Disallowed On Dev Drive - Registry
highDetects activity that indicates a user disabling the ability for Antivirus mini filter to inspect a "Dev Drive".
windows · registry_set
AppX Located in Known Staging Directory Added to Deployment Pipeline
highDetects an appx package that was added to the pipeline of the "to be processed" packages that is located in a known folder often used as a staging directory.
windows · appxdeployment-server
APT PRIVATELOG Image Load Pattern
highDetects an image load pattern as seen when a tool named PRIVATELOG is used and rarely observed under legitimate circumstances
windows · image_load
Arbitrary File Download Via IMEWDBLD.EXE
highDetects usage of "IMEWDBLD.exe" to download arbitrary files
windows · process_creation
Aruba Network Service Potential DLL Sideloading
highDetects potential DLL sideloading activity via the Aruba Networks Virtual Intranet Access "arubanetsvc.exe" process using DLL Search Order Hijacking
windows · image_load
Atera Agent Installation
highDetects successful installation of Atera Remote Monitoring & Management (RMM) agent as recently found to be used by Conti operators
windows · application
Attempts of Kerberos Coercion Via DNS SPN Spoofing
highDetects the presence of "UWhRC....AAYBAAAA" pattern in command line. The pattern "1UWhRCAAAAA..BAAAA" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure. Attackers can use this technique to coerce authentication from victim systems to attacker-controlled hosts. It is one of the strong indicators of a Kerberos coercion attack, where adversaries manipulate DNS records to spoof Service Principal Names (SPNs) and redirect authentication requests like in CVE-2025-33073. If you see this pattern in the command line, it is likely an attempt to add spoofed Service Principal Names (SPNs) to DNS records, or checking for the presence of such records through the `nslookup` command.
windows · process_creation
Audit Policy Tampering Via Auditpol
highThreat actors can use auditpol binary to change audit policy configuration to impair detection capability. This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.
windows · process_creation
Audit Policy Tampering Via NT Resource Kit Auditpol
highThreat actors can use an older version of the auditpol binary available inside the NT resource kit to change audit policy configuration to impair detection capability. This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.
windows · process_creation
Axios NPM Compromise File Creation Indicators - Windows
highDetects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection. The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.
windows · file_event
Axios NPM Compromise Indicators - Windows
highDetects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection. The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.
windows · process_creation
BaaUpdate.exe Suspicious DLL Load
highDetects BitLocker Access Agent Update Utility (baaupdate.exe) loading DLLs from suspicious locations that are publicly writable which could indicate an attempt to lateral movement via BitLocker DCOM & COM Hijacking. This technique abuses COM Classes configured as INTERACTIVE USER to spawn processes in the context of the logged-on user's session. Specifically, it targets the BDEUILauncher Class (CLSID ab93b6f1-be76-4185-a488-a9001b105b94) which can launch BaaUpdate.exe, which is vulnerable to COM Hijacking when started with input parameters. This allows attackers to execute code in the user's context without needing to steal credentials or use additional techniques to compromise the account.
windows · image_load
Bad Opsec Defaults Sacrificial Processes With Improper Arguments
highDetects attackers using tooling with bad opsec defaults. E.g. spawning a sacrificial process to inject a capability into the process without taking into account how the process is normally run. One trivial example of this is using rundll32.exe without arguments as a sacrificial process (default in CS, now highlighted by c2lint), running WerFault without arguments (Kraken - credit am0nsec), and other examples.
windows · process_creation
Base64 Encoded PowerShell Command Detected
highDetects usage of the "FromBase64String" function in the commandline which is used to decode a base64 encoded string
windows · process_creation
Base64 MZ Header In CommandLine
highDetects encoded base64 MZ header in the commandline
windows · process_creation
BITS Transfer Job Download From Direct IP
highDetects a BITS transfer job downloading file(s) from a direct IP address.
windows · bits-client
BITS Transfer Job Download From File Sharing Domains
highDetects BITS transfer job downloading files from a file sharing domain.
windows · bits-client
BITS Transfer Job Download To Potential Suspicious Folder
highDetects new BITS transfer job where the LocalName/Saved file is stored in a potentially suspicious location
windows · bits-client
Blackbyte Ransomware Registry
highDetects specific windows registry modifications made by BlackByte ransomware variants. BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption. This rule triggers when any of the following registry keys are set to DWORD 1, however all three should be investigated as part of a larger BlackByte ransomware detection and response effort.
windows · registry_set
BloodHound Collection Files
highDetects default file names outputted by the BloodHound collection tool SharpHound
windows · file_event
Blue Mockingbird
highAttempts to detect system changes made by Blue Mockingbird
windows · process_creation
Blue Mockingbird - Registry
highAttempts to detect system changes made by Blue Mockingbird
windows · registry_set
BlueSky Ransomware Artefacts
highDetect access to files and shares with names and extensions used by BlueSky ransomware which could indicate a current or previous encryption attempt.
windows · security
Boot Configuration Tampering Via Bcdedit.EXE
highDetects the use of the bcdedit command to tamper with the boot configuration data. This technique is often times used by malware or attackers as a destructive way before launching ransomware.
windows · process_creation
Bypass UAC Using DelegateExecute
highBypasses User Account Control using a fileless method
windows · registry_set
Bypass UAC Using Event Viewer
highBypasses User Account Control using Event Viewer and a relevant Windows Registry modification
windows · registry_set
Bypass UAC Using SilentCleanup Task
highDetects the setting of the environement variable "windir" to a non default value. Attackers often abuse this variable in order to trigger a UAC bypass via the "SilentCleanup" task. The SilentCleanup task located in %windir%\system32\cleanmgr.exe is an auto-elevated task that can be abused to elevate any file with administrator privileges without prompting UAC.
windows · registry_set
Bypass UAC via CMSTP
highDetect commandline usage of Microsoft Connection Manager Profile Installer (cmstp.exe) to install specially formatted local .INF files
windows · process_creation
Bypass UAC via Fodhelper.exe
highIdentifies use of Fodhelper.exe to bypass User Account Control. Adversaries use this technique to execute privileged processes.
windows · process_creation
Bypass UAC via WSReset.exe
highDetects use of WSReset.exe to bypass User Account Control (UAC). Adversaries use this technique to execute privileged processes.
windows · process_creation
Cab File Extraction Via Wusa.EXE From Potentially Suspicious Paths
highDetects the execution of the "wusa.exe" (Windows Update Standalone Installer) utility to extract ".cab" files using the "/extract" argument from potentially suspicious paths.
windows · process_creation
Certificate Services Outbound SMB or LDAP Connection
highDetects the Windows Certificate Services process (certsrv.exe) initiating an outbound network connection on port 445 (SMB) or 389 (LDAP) to a non-DC host. This behaviour is inherently suspicious: under normal operation the CA resolves subject identities via local RPC against the domain and never initiates outbound SMB or LDAP connections to arbitrary hosts. Any such connection indicates the CA is being coerced into performing a remote identity lookup against an attacker-controlled host. The most direct known trigger is the CA chase fallback (EDITF_ENABLECHASECLIENTDC) where a requester-supplied 'cdc' attribute causes the CA to open SMB and LDAP to a specified address. CVE-2026-54121 (Certighost) exploits this path to redirect the CA to rogue LSA and LDAP services that return a DC's identity, resulting in a forged DC certificate. This rule is not limited to Certighost — any future vulnerability or misconfiguration that causes certsrv.exe to make outbound SMB or LDAP connections is covered.
windows · network_connection
Change Default File Association To Executable Via Assoc
highDetects when a program changes the default file association of any extension to an executable. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Applications can modify the file association for a given file extension to call an arbitrary program when a file with the given extension is opened.
windows · process_creation
Change the Fax Dll
highDetect possible persistence using Fax DLL load when service restart
windows · registry_set
Change User Account Associated with the FAX Service
highDetect change of the user account associated with the FAX service to avoid the escalation problem.
windows · registry_set
Change Winevt Channel Access Permission Via Registry
highDetects tampering with the "ChannelAccess" registry key in order to change access to Windows event channel.
windows · registry_set
Chopper Webshell Process Pattern
highDetects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells
windows · process_creation
ChromeLoader Malware Execution
highDetects execution of ChromeLoader malware via a registered scheduled task
windows · process_creation
Chromium Browser Headless Execution To Mockbin Like Site
highDetects the execution of a Chromium based browser process with the "headless" flag and a URL pointing to the mockbin.org service (which can be used to exfiltrate data).
windows · process_creation
Clearing Windows Console History
highIdentifies when a user attempts to clear console history. An adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
windows · ps_script
Cmd.EXE Missing Space Characters Execution Anomaly
highDetects Windows command lines that miss a space before or after the /c flag when running a command using the cmd.exe. This could be a sign of obfuscation of a fat finger problem (typo by the developer).
windows · process_creation
CMSTP Execution Process Access
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows · process_access
CMSTP Execution Process Creation
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows · process_creation
CMSTP Execution Registry Event
highDetects various indicators of Microsoft Connection Manager Profile Installer execution
windows · registry_event
CMSTP UAC Bypass via COM Object Access
highDetects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)
windows · process_creation
CobaltStrike Load by Rundll32
highRundll32 can be use by Cobalt Strike with StartW function to load DLLs from the command line.
windows · process_creation
CobaltStrike Named Pipe Patterns
highDetects the creation of a named pipe with a pattern found in CobaltStrike malleable C2 profiles
windows · pipe_created
CobaltStrike Service Installations - Security
highDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
windows · security
Code Executed Via Office Add-in XLL File
highAdversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office programs
windows · ps_script
CodeIntegrity - Blocked Driver Load With Revoked Certificate
highDetects blocked load attempts of revoked drivers
windows · codeintegrity-operational
CodeIntegrity - Blocked Image Load With Revoked Certificate
highDetects blocked image load events with revoked certificates by code integrity.
windows · codeintegrity-operational
CodeIntegrity - Blocked Image/Driver Load For Policy Violation
highDetects blocked load events that did not meet the authenticode signing level requirements or violated the code integrity policy.
windows · codeintegrity-operational
CodeIntegrity - Disallowed File For Protected Processes Has Been Blocked
highDetects block events for files that are disallowed by code integrity for protected processes
windows · codeintegrity-operational
CodeIntegrity - Revoked Image Loaded
highDetects image load events with revoked certificates by code integrity.
windows · codeintegrity-operational
CodeIntegrity - Revoked Kernel Driver Loaded
highDetects the load of a revoked kernel driver
windows · codeintegrity-operational
CodeIntegrity - Unmet WHQL Requirements For Loaded Kernel Module
highDetects loaded kernel modules that did not meet the WHQL signing requirements.
windows · codeintegrity-operational
CodeIntegrity - Unsigned Image Loaded
highDetects loaded unsigned image on the system
windows · codeintegrity-operational
CodeIntegrity - Unsigned Kernel Module Loaded
highDetects the presence of a loaded unsigned kernel module on the system.
windows · codeintegrity-operational
COLDSTEEL Persistence Service Creation
highDetects the creation of new services potentially related to COLDSTEEL RAT
windows · system
COLDSTEEL RAT Anonymous User Process Execution
highDetects the creation of a process executing as user called "ANONYMOUS" seen used by the "MileStone2016" variant of COLDSTEEL
windows · process_creation
COM Hijack via Sdclt
highDetects changes to 'HKCU\Software\Classes\Folder\shell\open\command\DelegateExecute'
windows · registry_set
COM Object Hijacking Via Modification Of Default System CLSID Default Value
highDetects potential COM object hijacking via modification of default system CLSID.
windows · registry_set
Communication To LocaltoNet Tunneling Service Initiated
highDetects an executable initiating a network connection to "LocaltoNet" tunneling sub-domains. LocaltoNet is a reverse proxy that enables localhost services to be exposed to the Internet. Attackers have been seen to use this service for command-and-control activities to bypass MFA and perimeter controls.
windows · network_connection
Communication To Ngrok Tunneling Service Initiated
highDetects an executable initiating a network connection to "ngrok" tunneling domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
windows · network_connection
Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791)
highDetects the use of argument injection in the Commvault qlogin command - potential exploitation for CVE-2025-57791. An attacker can inject the `-localadmin` parameter via the password field to bypass authentication and gain a privileged token.
windows · process_creation
Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790)
highDetects the use of qoperation.exe with the -file argument to write a JSP file to the webroot, indicating a webshell drop. This is a post-authentication step corresponding to CVE-2025-57790.
windows · process_creation
Conhost.exe CommandLine Path Traversal
highdetects the usage of path traversal in conhost.exe indicating possible command/argument confusion/hijacking
windows · process_creation
Conti NTDS Exfiltration Command
highDetects a command used by conti to exfiltrate NTDS
windows · process_creation
Conti Volume Shadow Listing
highDetects a command used by conti to find volume shadow backups
windows · process_creation
Control Panel Items
highDetects the malicious use of a control panel item
windows · process_creation
Copy .DMP/.DUMP Files From Remote Share Via Cmd.EXE
highDetects usage of the copy builtin cmd command to copy files with the ".dmp"/".dump" extension from a remote share
windows · process_creation
Copy From VolumeShadowCopy Via Cmd.EXE
highDetects the execution of the builtin "copy" command that targets a shadow copy (sometimes used to copy registry hives that are in use)
windows · process_creation
Copying Sensitive Files with Credential Data
highFiles with well-known filenames (sensitive files with credential data) copying
windows · process_creation
Create Volume Shadow Copy with Powershell
highAdversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information
windows · ps_script
CreateDump Process Dump
highDetects uses of the createdump.exe LOLOBIN utility to dump process memory
windows · process_creation
Creation Exe for Service with Unquoted Path
highAdversaries may execute their own malicious payloads by hijacking vulnerable file path references. Adversaries can take advantage of paths that lack surrounding quotations by placing an executable in a higher level directory within the path, so that Windows will choose the adversary's executable to launch.
windows · file_event
Creation of a Local Hidden User Account by Registry
highSysmon registry detection of a local hidden user account.
windows · registry_event
Cred Dump Tools Dropped Files
highFiles with well-known filenames (parts of credential dump software or files produced by them) creation
windows · file_event
Credential Dumping Activity By Python Based Tool
highDetects LSASS process access for potential credential dumping by a Python-like tool such as LaZagne or Pypykatz.
windows · process_access
Credential Dumping Attempt Via Svchost
highDetects when a process tries to access the memory of svchost to potentially dump credentials.
windows · process_access
Credential Dumping Attempt Via WerFault
highDetects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up.
windows · process_access
Credential Dumping Tools Service Execution - Security
highDetects well-known credential dumping tools execution via service execution events
windows · security
Credential Dumping Tools Service Execution - System
highDetects well-known credential dumping tools execution via service execution events
windows · system
Critical Hive In Suspicious Location Access Bits Cleared
highDetects events from the Kernel-General ETW indicating that the access bits of a hive with a system like hive name located in the temp directory have been reset. This occurs when an application tries to access a hive and the hive has not be recognized since the last 7 days (by default). Registry hive dumping utilities such as QuarksPwDump were seen emitting this behavior.
windows · system
Csc.EXE Execution Form Potentially Suspicious Parent
highDetects a potentially suspicious parent of "csc.exe", which could be a sign of payload delivery.
windows · process_creation
Cscript/Wscript Uncommon Script Extension Execution
highDetects Wscript/Cscript executing a file with an uncommon (i.e. non-script) extension
windows · process_creation
Curl Download And Execute Combination
highAdversaries can use curl to download payloads remotely and execute them. Curl is included by default in Windows 10 build 17063 and later.
windows · process_creation
Curl File Upload To File Sharing Websites
highDetects usage of curl to upload files to known file sharing domains, which may indicate data exfiltration.
windows · process_creation
Custom File Open Handler Executes PowerShell
highDetects the abuse of custom file open handler, executing powershell
windows · registry_set
CVE-2020-0688 Exploitation via Eventlog
highDetects the exploitation of Microsoft Exchange vulnerability as described in CVE-2020-0688
windows · application
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
highDetects changes to the "Ports" registry key with data that includes a Windows path or a file with a suspicious extension. This could be an attempt to exploit CVE-2020-1048 - a Windows Print Spooler elevation of privilege vulnerability.
windows · registry_set
CVE-2021-26858 Exchange Exploitation
highDetects possible successful exploitation for vulnerability described in CVE-2021-26858 by looking for creation of non-standard files on disk by Exchange Server’s Unified Messaging service which could indicate dropping web shells or other malicious content
windows · file_event
CVE-2021-44077 POC Default Dropped File
highDetects the creation of "msiexec.exe" in the "bin" directory of the ManageEngine SupportCenter Plus (Related to CVE-2021-44077) and public POC available (See references section)
windows · file_event
CVE-2022-24527 Microsoft Connected Cache LPE
highDetects files created during the local privilege exploitation of CVE-2022-24527 Microsoft Connected Cache
windows · file_event
CVE-2023-38331 Exploitation Attempt - Suspicious Double Extension File
highDetects the creation of a file with a double extension and a space by WinRAR. This could be a sign of exploitation of CVE-2023-38331
windows · file_event
CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process
highDetects exploitation attempt of CVE-2023-38331 (WinRAR before v6.23), where an attacker can leverage WinRAR to execute arbitrary commands and binaries.
windows · process_creation
CVE-2024-49113 Exploitation Attempt - LDAP Nightmare
highDetects exploitation attempt of CVE-2024-49113 known as LDAP Nightmare, based on "Application Error" log where the faulting application is "lsass.exe" and the faulting module is "WLDAP32.dll".
windows · application
CVE-2024-50623 Exploitation Attempt - Cleo
highDetects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.
windows · process_creation
DarkGate - Autoit3.EXE Execution Parameters
highDetects execution of the legitimate Autoit3 utility from a suspicious parent process. AutoIt3.exe is used within the DarkGate infection chain to execute shellcode that performs process injection and connects to the DarkGate command-and-control server.
windows · process_creation
DarkGate - User Created Via Net.EXE
highDetects creation of local users via the net.exe command with the name of "DarkGate"
windows · process_creation
DC Machine Account TGS Request from Non-DC Source IP
highDetects a Kerberos service ticket request (Event 4769) targeting a Domain Controller machine account's service (e.g. DRSUAPI) originating from an IP address that is not a known Domain Controller. Service tickets for DC machine accounts should only be requested by other DCs during legitimate replication operations. An attacker with a valid TGT (obtained via PKINIT, overpass-the-hash, or stolen TGT) targeting a DC machine account's service from a workstation IP indicates preparation for DCSync or impersonation of a DC. Unlike Silver Ticket attacks (which forge the TGS and bypass this event), this rule catches attacks that go through the KDC legitimately. This rule requires %dc_machine_accounts% and %dc_ip_addresses% to be populated with all known DC machine account names and DC IP addresses respectively.
windows · security
DC Machine Account TGT Request from Non-DC Source IP
highDetects a Kerberos TGT request (Event 4768) for a known Domain Controller machine account originating from an IP address that is not a known Domain Controller. DC machine accounts should only request TGTs from their own IP. Any TGT request for a DC account from a workstation or non-DC host is anomalous and indicates one of the following: - PKINIT abuse (CVE-2026-54121 / Certighost): attacker authenticating as a DC via a forged certificate from their workstation - Overpass-the-Hash: attacker converting a stolen DC machine account NTLM hash into a Kerberos TGT - Pass-the-Hash (RC4): attacker using the DC machine account hash directly with Kerberos
windows · security
DCOM InternetExplorer.Application Iertutil DLL Hijack - Security
highDetects a threat actor creating a file named `iertutil.dll` in the `C:\Program Files\Internet Explorer\` directory over the network for a DCOM InternetExplorer DLL Hijack scenario.
windows · security
Default RDP Port Changed to Non Standard Port
highDetects changes to the default RDP port. Remote desktop is a common feature in operating systems. It allows a user to log into a remote system using an interactive session with a graphical user interface. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).
windows · registry_set
Delete All Scheduled Tasks
highDetects the usage of schtasks with the delete flag and the asterisk symbol to delete all tasks from the schedule of the local computer, including tasks scheduled by other users.
windows · process_creation
Delete Important Scheduled Task
highDetects when adversaries stop services or processes by deleting their respective scheduled tasks in order to conduct data destructive activities
windows · process_creation
Delete Volume Shadow Copies Via WMI With PowerShell
highShadow Copies deletion using operating systems utilities via PowerShell
windows · ps_classic_start
Deletion of Volume Shadow Copies via WMI with PowerShell
highDetects deletion of Windows Volume Shadow Copies with PowerShell code and Get-WMIObject. This technique is used by numerous ransomware families such as Sodinokibi/REvil
windows · process_creation
Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script
highDetects deletion of Windows Volume Shadow Copies with PowerShell code and Get-WMIObject. This technique is used by numerous ransomware families such as Sodinokibi/REvil
windows · ps_script
Deny Service Access Using Security Descriptor Tampering Via Sc.EXE
highDetects suspicious DACL modifications to deny access to a service that affects critical trustees. This can be used to hide services or make them unstoppable.
windows · process_creation
Devcon Execution Disabling VMware VMCI Device
highDetects execution of devcon.exe with commands that disable the VMware Virtual Machine Communication Interface (VMCI) device. This can be legitimate during VMware Tools troubleshooting or driver conflicts, but may also indicate malware attempting to hijack communication with the hardware via the VMCI device. This has been used to facilitate VMware ESXi vulnerability exploits to escape VMs and execute code on the ESXi host.
windows · process_creation
Devtoolslauncher.exe Executes Specified Binary
highThe Devtoolslauncher.exe executes other binary
windows · process_creation
Dfsvc.EXE Initiated Network Connection Over Uncommon Port
highDetects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.
windows · network_connection
DHCP Callout DLL Installation
highDetects the installation of a Callout DLL via CalloutDlls and CalloutEnabled parameter in Registry, which can be used to execute code in context of the DHCP server (restart required)
windows · registry_set
DHCP Server Error Failed Loading the CallOut DLL
highThis rule detects a DHCP server error in which a specified Callout DLL (in registry) could not be loaded
windows · system
DHCP Server Loaded the CallOut DLL
highThis rule detects a DHCP server in which a specified Callout DLL (in registry) was loaded
windows · system
Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
highDetects both of CVE-2022-30190 (Follina) and DogWalk vulnerabilities exploiting msdt.exe binary to load the "sdiageng.dll" library
windows · image_load
Diamond Sleet APT DLL Sideloading Indicators
highDetects DLL sideloading activity seen used by Diamond Sleet APT
windows · image_load
Diamond Sleet APT DNS Communication Indicators
highDetects DNS queries related to Diamond Sleet APT activity
windows · dns_query
Diamond Sleet APT File Creation Indicators
highDetects file creation activity that is related to Diamond Sleet APT activity
windows · file_event
Diamond Sleet APT Process Activity Indicators
highDetects process creation activity indicators related to Diamond Sleet APT
windows · process_creation
Diamond Sleet APT Scheduled Task Creation - Registry
highDetects registry event related to the creation of a scheduled task used by Diamond Sleet APT during exploitation of Team City CVE-2023-42793 vulnerability
windows · registry_event
Directory Service Restore Mode(DSRM) Registry Value Tampering
highDetects changes to "DsrmAdminLogonBehavior" registry value. During a Domain Controller (DC) promotion, administrators create a Directory Services Restore Mode (DSRM) local administrator account with a password that rarely changes. The DSRM account is an “Administrator” account that logs in with the DSRM mode when the server is booting up to restore AD backups or recover the server from a failure. Attackers could abuse DSRM account to maintain their persistence and access to the organization's Active Directory. If the "DsrmAdminLogonBehavior" value is set to "0", the administrator account can only be used if the DC starts in DSRM. If the "DsrmAdminLogonBehavior" value is set to "1", the administrator account can only be used if the local AD DS service is stopped. If the "DsrmAdminLogonBehavior" value is set to "2", the administrator account can always be used.
windows · registry_set
Disable Important Scheduled Task
highDetects when adversaries stop services or processes by disabling their respective scheduled tasks in order to conduct data destructive activities
windows · process_creation
Disable Macro Runtime Scan Scope
highDetects tampering with the MacroRuntimeScanScope registry key to disable runtime scanning of enabled macros
windows · registry_set
Disable of ETW Trace - Powershell
highDetects usage of powershell cmdlets to disable or remove ETW trace sessions
windows · ps_script
Disable Powershell Command History
highDetects scripts or commands that disabled the Powershell command history by removing psreadline module
windows · ps_script
Disable PUA Protection on Windows Defender
highDetects disabling Windows Defender PUA protection
windows · registry_set
Disable Security Events Logging Adding Reg Key MiniNt
highDetects the addition of a key 'MiniNt' to the registry. Upon a reboot, Windows Event Log service will stop writing events.
windows · registry_event
Disable Windows Defender AV Security Monitoring
highDetects attackers attempting to disable Windows Defender using Powershell
windows · process_creation
Disable Windows Defender Functionalities Via Registry Keys
highDetects when attackers or tools disable Windows Defender functionalities via the Windows registry
windows · registry_set
Disable Windows Event Logging Via Registry
highDetects tampering with the "Enabled" registry key in order to disable Windows logging of a Windows event channel
windows · registry_set
Disable Windows IIS HTTP Logging
highDisables HTTP logging on a Windows IIS web server as seen by Threat Group 3390 (Bronze Union)
windows · process_creation
Disable-WindowsOptionalFeature Command PowerShell
highDetect built in PowerShell cmdlet Disable-WindowsOptionalFeature, Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows · ps_script
Disabled IE Security Features
highDetects command lines that indicate unwanted modifications to registry keys that disable important Internet Explorer security features
windows · process_creation
Disabled Volume Snapshots
highDetects commands that temporarily turn off Volume Snapshots
windows · process_creation
Disabled Windows Defender Eventlog
highDetects the disabling of the Windows Defender eventlog as seen in relation to Lockbit 3.0 infections
windows · registry_set
Disabling Windows Defender WMI Autologger Session via Reg.exe
highDetects the use of reg.exe to disable the Event Tracing for Windows (ETW) Autologger session for Windows Defender API and Audit events. By setting the 'Start' value to '0' for the 'DefenderApiLogger' or 'DefenderAuditLogger' session, an attacker can prevent these critical security events from being logged, effectively blinding monitoring tools that rely on this data. This is a powerful defense evasion technique.
windows · process_creation
DLL Load via LSASS
highDetects a method to load DLL via LSASS process using an undocumented Registry key
windows · registry_event
DLL Loaded From Suspicious Location Via Cmspt.EXE
highDetects cmstp loading "dll" or "ocx" files from suspicious locations
windows · image_load
DLL Search Order Hijackig Via Additional Space in Path
highDetects when an attacker create a similar folder structure to windows system folders such as (Windows, Program Files...) but with a space in order to trick DLL load search order and perform a "DLL Search Order Hijacking" attack
windows · file_event
DLL Sideloading by VMware Xfer Utility
highDetects execution of VMware Xfer utility (VMwareXferlogs.exe) from the non-default directory which may be an attempt to sideload arbitrary DLL
windows · process_creation
DLL Sideloading Of ShellChromeAPI.DLL
highDetects processes loading the non-existent DLL "ShellChromeAPI". One known example is the "DeviceEnroller" binary in combination with the "PhoneDeepLink" flag tries to load this DLL. Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
windows · image_load
Dllhost.EXE Execution Anomaly
highDetects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.
windows · process_creation
DNS Exfiltration and Tunneling Tools Execution
highWell-known DNS Exfiltration tools execution
windows · process_creation
DNS HybridConnectionManager Service Bus
highDetects Azure Hybrid Connection Manager services querying the Azure service bus service
windows · dns_query
DNS Query by Finger Utility
highDetects DNS queries made by the finger utility, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such DNS queries can also help identify potential malicious infrastructure used by threat actors for command and control (C2) communication.
windows · dns_query
DNS Query for Anonfiles.com Domain - DNS Client
highDetects DNS queries for anonfiles.com, which is an anonymous file upload platform often used for malicious purposes
windows · dns-client
DNS Query for Anonfiles.com Domain - Sysmon
highDetects DNS queries for "anonfiles.com", which is an anonymous file upload platform often used for malicious purposes
windows · dns_query
DNS Query To Katz Stealer Domains
highDetects DNS queries to domains associated with Katz Stealer malware. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. In Enterprise environments, DNS queries to these domains may indicate potential malicious activity or compromise.
windows · dns_query
DNS Query Tor .Onion Address - Sysmon
highDetects DNS queries to an ".onion" address related to Tor routing networks
windows · dns_query
DNS Server Error Failed Loading the ServerLevelPluginDLL
highDetects a DNS server error in which a specified plugin DLL (in registry) could not be loaded
windows · dns-server
DotNet CLR DLL Loaded By Scripting Applications
highDetects .NET CLR DLLs being loaded by scripting applications such as wscript or cscript. This could be an indication of potential suspicious execution.
windows · image_load
DPAPI Backup Keys And Certificate Export Activity IOC
highDetects file names with specific patterns seen generated and used by tools such as Mimikatz and DSInternals related to exported or stolen DPAPI backup keys and certificates.
windows · file_event
DPAPI Domain Backup Key Extraction
highDetects tools extracting LSA secret DPAPI domain backup key from Domain Controllers
windows · security
DPRK Threat Actor - C2 Communication DNS Indicators
highDetects DNS queries for C2 domains used by DPRK Threat actors.
windows · dns_query
Driver Added To Disallowed Images In HVCI - Registry
highDetects changes to the "HVCIDisallowedImages" registry value to potentially add a driver to the list, in order to prevent it from loading.
windows · registry_set
Driver Load From A Temporary Directory
highDetects a driver load from a temporary directory
windows · driver_load
DSInternals Suspicious PowerShell Cmdlets
highDetects execution and usage of the DSInternals PowerShell module. Which can be used to perform what might be considered as suspicious activity such as dumping DPAPI backup keys or manipulating NTDS.DIT files. The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
windows · process_creation
DSInternals Suspicious PowerShell Cmdlets - ScriptBlock
highDetects execution and usage of the DSInternals PowerShell module. Which can be used to perform what might be considered as suspicious activity such as dumping DPAPI backup keys or manipulating NTDS.DIT files. The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
windows · ps_script
Dumping of Sensitive Hives Via Reg.EXE
highDetects the usage of "reg.exe" in order to dump sensitive registry hives. This includes SAM, SYSTEM and SECURITY hives.
windows · process_creation
Email Exifiltration Via Powershell
highDetects email exfiltration via powershell cmdlets
windows · process_creation
Emotet Loader Execution Via .LNK File
highDetects the Emotet Epoch4 loader as reported by @malware_traffic back in 2022. The ".lnk" file was delivered via phishing campaign.
windows · process_creation
Enable LM Hash Storage
highDetects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.
windows · registry_set
Enable LM Hash Storage - ProcCreation
highDetects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.
windows · process_creation
Enabled User Right in AD to Control User Objects
highDetects scenario where if a user is assigned the SeEnableDelegationPrivilege right in Active Directory it would allow control of other AD user objects.
windows · security
Esentutl Volume Shadow Copy Service Keys
highDetects the volume shadow copy service initialization and processing via esentutl. Registry keys such as HKLM\\System\\CurrentControlSet\\Services\\VSS\\Diag\\VolSnap\\Volume are captured.
windows · registry_event
ETW Logging Disabled In .NET Processes - Registry
highPotential adversaries stopping ETW providers recording loaded .NET assemblies.
windows · security
ETW Logging Disabled In .NET Processes - Sysmon Registry
highPotential adversaries stopping ETW providers recording loaded .NET assemblies.
windows · registry_set
ETW Logging Tamper In .NET Processes Via CommandLine
highDetects changes to environment variables related to ETW logging via the CommandLine. This could indicate potential adversaries stopping ETW providers recording loaded .NET assemblies.
windows · process_creation
ETW Trace Evasion Activity
highDetects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.
windows · process_creation
Exchange PowerShell Cmdlet History Deleted
highDetects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence
windows · file_delete
Exchange PowerShell Snap-Ins Usage
highDetects adding and using Exchange PowerShell snap-ins to export mailbox data. As seen used by HAFNIUM and APT27
windows · process_creation
Exchange Set OabVirtualDirectory ExternalUrl Property
highRule to detect an adversary setting OabVirtualDirectory External URL property to a script in Exchange Management log
windows · msexchange-management
Execute Pcwrun.EXE To Leverage Follina
highDetects indirect command execution via Program Compatibility Assistant "pcwrun.exe" leveraging the follina (CVE-2022-30190) vulnerability
windows · process_creation
Execution DLL of Choice Using WAB.EXE
highThis rule detects that the path to the DLL written in the registry is different from the default one. Launched WAB.exe tries to load the DLL from Registry.
windows · registry_set
Execution Of Non-Existing File
highDetects process creation events where the Image field lacks an absolute path, which occurs when the backing file no longer exists on disk at the time of logging - commonly caused by Process Ghosting or other unorthodox process creation techniques.
windows · process_creation
Execution of Powershell Script in Public Folder
highThis rule detects execution of PowerShell scripts located in the "C:\Users\Public" folder
windows · process_creation
Execution via stordiag.exe
highDetects the use of stordiag.exe to execute schtasks.exe systeminfo.exe and fltmc.exe
windows · process_creation
Execution via WorkFolders.exe
highDetects using WorkFolders.exe to execute an arbitrary control.exe
windows · process_creation
Exploitation Activity of CVE-2025-59287 - WSUS Deserialization
highDetects cast exceptions in Windows Server Update Services (WSUS) application logs that highly indicate exploitation attempts of CVE-2025-59287, a deserialization vulnerability in WSUS.
windows · application
Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process
highDetects the creation of command-line interpreters (cmd.exe, powershell.exe) as child processes of Windows Server Update Services (WSUS) related process wsusservice.exe. This behavior is a key indicator of exploitation for the critical remote code execution vulnerability such as CVE-2025-59287, where attackers spawn shells to conduct reconnaissance and further post-exploitation activities.
windows · process_creation
Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC
highDetects the execution of the commonly used ZeroLogon PoC executable.
windows · process_creation
Exploited CVE-2020-10189 Zoho ManageEngine
highDetects the exploitation of Zoho ManageEngine Desktop Central Java Deserialization vulnerability reported as CVE-2020-10189
windows · process_creation
Exploiting SetupComplete.cmd CVE-2019-1378
highDetects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378
windows · process_creation
Explorer NOUACCHECK Flag
highDetects suspicious starts of explorer.exe that use the /NOUACCHECK flag that allows to run all sub processes of that newly started explorer.exe without any UAC checks
windows · process_creation
Exports Critical Registry Keys To a File
highDetects the export of a crital Registry key to a file.
windows · process_creation
Exports Registry Key To an Alternate Data Stream
highExports the target Registry key and hides it in the specified alternate data stream.
windows · create_stream_hash
External Remote SMB Logon from Public IP
highDetects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
windows · security
Failed MSExchange Transport Agent Installation
highDetects a failed installation of a Exchange Transport Agent
windows · msexchange-management
FakeUpdates/SocGholish Activity
highDetects initial execution of FakeUpdates/SocGholish malware via wscript that later executes commands via cmd or powershell.
windows · process_creation
Fax Service DLL Search Order Hijack
highThe Fax service attempts to load ualapi.dll, which is non-existent. An attacker can then (side)load their own malicious DLL using this service.
windows · image_load
File Creation In Suspicious Directory By Msdt.EXE
highDetects msdt.exe creating files in suspicious directories which could be a sign of exploitation of either Follina or Dogwalk vulnerabilities
windows · file_event
File Creation Related To RAT Clients
highFile .conf created related to VenomRAT, AsyncRAT and Lummac samples observed in the wild.
windows · file_event
File Decoded From Base64/Hex Via Certutil.EXE
highDetects the execution of certutil with either the "decode" or "decodehex" flags to decode base64 or hex encoded files. This can be abused by attackers to decode an encoded payload before execution
windows · process_creation
File Download And Execution Via IEExec.EXE
highDetects execution of the IEExec utility to download and execute files
windows · process_creation
File Download From IP Based URL Via CertOC.EXE
highDetects when a user downloads a file from an IP based URL using CertOC.exe
windows · process_creation
File Download Using Notepad++ GUP Utility
highDetects execution of the Notepad++ updater (gup) from a process other than Notepad++ to download files.
windows · process_creation
File Download Via Bitsadmin To A Suspicious Target Folder
highDetects usage of bitsadmin downloading a file to a suspicious target folder
windows · process_creation
File Download Via Windows Defender MpCmpRun.EXE
highDetects the use of Windows Defender MpCmdRun.EXE to download files
windows · process_creation
File Download with Headless Browser
highDetects execution of chromium based browser in headless mode using the "dump-dom" command line to download files
windows · process_creation
File Encryption/Decryption Via Gpg4win From Suspicious Locations
highDetects usage of Gpg4win to encrypt/decrypt files located in potentially suspicious locations.
windows · process_creation
File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
highDetects the initial execution of "cmd.exe" which spawns "explorer.exe" with the appropriate command line arguments for opening the "My Computer" folder.
windows · process_creation
File In Suspicious Location Encoded To Base64 Via Certutil.EXE
highDetects the execution of certutil with the "encode" flag to encode a file to base64 where the files are located in potentially suspicious locations
windows · process_creation
File With Suspicious Extension Downloaded Via Bitsadmin
highDetects usage of bitsadmin downloading a file with a suspicious extension
windows · process_creation
File With Uncommon Extension Created By An Office Application
highDetects the creation of files with an executable or script extension by an Office application.
windows · file_event
FileFix - Command Evidence in TypedPaths
highDetects commonly-used chained commands and strings in the most recent 'url' value of the 'TypedPaths' key, which could be indicative of a user being targeted by the FileFix technique.
windows · registry_set
Findstr GPP Passwords
highLook for the encrypted cpassword value within Group Policy Preference files on the Domain Controller. This value can be decrypted with gpp-decrypt.
windows · process_creation
Finger.EXE Execution
highDetects execution of the "finger.exe" utility. Finger.EXE or "TCPIP Finger Command" is an old utility that is still present on modern Windows installation. It Displays information about users on a specified remote computer (typically a UNIX computer) that is running the finger service or daemon. Due to the old nature of this utility and the rareness of machines having the finger service. Any execution of "finger.exe" can be considered "suspicious" and worth investigating.
windows · process_creation
Fireball Archer Install
highDetects Archer malware invocation via rundll32
windows · process_creation
First Time Seen Remote Named Pipe
highThis detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes
windows · security
Folder Removed From Exploit Guard ProtectedFolders List - Registry
highDetects the removal of folders from the "ProtectedFolders" list of of exploit guard. This could indicate an attacker trying to launch an encryption process or trying to manipulate data inside of the protected folder
windows · registry_delete
Forest Blizzard APT - Custom Protocol Handler Creation
highDetects the setting of a custom protocol handler with the name "rogue". Seen being created by Forest Blizzard APT as reported by MSFT.
windows · registry_set
Forest Blizzard APT - Custom Protocol Handler DLL Registry Set
highDetects the setting of the DLL that handles the custom protocol handler. Seen being created by Forest Blizzard APT as reported by MSFT.
windows · registry_set
Forest Blizzard APT - File Creation Activity
highDetects the creation of specific files inside of ProgramData directory. These files were seen being created by Forest Blizzard as described by MSFT.
windows · file_event
Forest Blizzard APT - Process Creation Activity
highDetects the execution of specific processes and command line combination. These were seen being created by Forest Blizzard as described by MSFT.
windows · process_creation
Forfiles.EXE Child Process Masquerading
highDetects the execution of "forfiles" from a non-default location, in order to potentially spawn a custom "cmd.exe" from the current working directory.
windows · process_creation
Formbook Process Creation
highDetects Formbook like process executions that inject code into a set of files in the System32 folder, which executes a special command command line to delete the dropper from the AppData Temp folder. We avoid false positives by excluding all parent process with command line parameters.
windows · process_creation
Fsutil Suspicious Invocation
highDetects suspicious parameters of fsutil (deleting USN journal, configuring it with small size, etc). Might be used by ransomwares during the attack (seen by NotPetya and others).
windows · process_creation
FunkLocker Ransomware File Creation
highDetects the creation of files with the ".funksec" extension, which is appended to encrypted files by the FunkLocker ransomware.
windows · file_event
GAC DLL Loaded Via Office Applications
highDetects any GAC DLL being loaded by an Office Product
windows · image_load
GALLIUM Artefacts - Builtin
highDetects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.
windows · dns-server-analytic
GALLIUM IOCs
highDetects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
windows · process_creation
Goofy Guineapig Backdoor IOC
highDetects malicious indicators seen used by the Goofy Guineapig malware
windows · file_event
Grixba Malware Reconnaissance Activity
highDetects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations. This tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.
windows · process_creation
HackTool - ADCSPwn Execution
highDetects command line parameters used by ADCSPwn, a tool to escalate privileges in an active directory network by coercing authenticate from machine accounts and relaying to the certificate service
windows · process_creation
HackTool - Bloodhound/Sharphound Execution
highDetects command line parameters used by Bloodhound and Sharphound hack tools
windows · process_creation
HackTool - CACTUSTORCH Remote Thread Creation
highDetects remote thread creation from CACTUSTORCH as described in references.
windows · create_remote_thread
HackTool - Certify Execution
highDetects Certify a tool for Active Directory certificate abuse based on PE metadata characteristics and common command line arguments.
windows · process_creation
HackTool - Certipy Execution
highDetects Certipy execution, a tool for Active Directory Certificate Services enumeration and abuse based on PE metadata characteristics and common command line arguments.
windows · process_creation
HackTool - CobaltStrike BOF Injection Pattern
highDetects a typical pattern of a CobaltStrike BOF which inject into other processes
windows · process_access
HackTool - CoercedPotato Execution
highDetects the use of CoercedPotato, a tool for privilege escalation
windows · process_creation
HackTool - CoercedPotato Named Pipe Creation
highDetects the pattern of a pipe name as used by the hack tool CoercedPotato
windows · pipe_created
HackTool - Covenant PowerShell Launcher
highDetects suspicious command lines used in Covenant luanchers
windows · process_creation
HackTool - CrackMapExec Execution
highThis rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
windows · process_creation
HackTool - CrackMapExec Execution Patterns
highDetects various execution patterns of the CrackMapExec pentesting framework
windows · process_creation
HackTool - CrackMapExec File Indicators
highDetects file creation events with filename patterns used by CrackMapExec.
windows · file_event
HackTool - CrackMapExec PowerShell Obfuscation
highThe CrachMapExec pentesting framework implements a PowerShell obfuscation with some static strings detected by this rule.
windows · process_creation
HackTool - CrackMapExec Process Patterns
highDetects suspicious process patterns found in logs when CrackMapExec is used
windows · process_creation
HackTool - CreateMiniDump Execution
highDetects the use of CreateMiniDump hack tool used to dump the LSASS process memory for credential extraction on the attacker's machine
windows · process_creation
HackTool - Default PowerSploit/Empire Scheduled Task Creation
highDetects the creation of a schtask via PowerSploit or Empire Default Configuration.
windows · process_creation
HackTool - Doppelanger LSASS Dumper Execution
highDetects the execution of the Doppelanger hacktool which is used to dump LSASS memory via process cloning while evading common detection methods
windows · process_creation
Hacktool - EDR-Freeze Execution
highDetects execution of EDR-Freeze, a tool that exploits the MiniDumpWriteDump function and WerFaultSecure.exe to suspend EDR and Antivirus processes on Windows. EDR-Freeze leverages a race-condition attack to put security processes into a dormant state by suspending WerFaultSecure at the moment it freezes the target process. This technique does not require kernel-level exploits or BYOVD, but instead abuses user-mode functionality to temporarily disable monitoring by EDR or Antimalware solutions.
windows · process_creation
HackTool - EDRSilencer Execution
highDetects the execution of EDRSilencer, a tool that leverages Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server based on PE metadata information.
windows · process_creation
HackTool - EDRSilencer Execution - Filter Added
highDetects execution of EDRSilencer, a tool that abuses the Windows Filtering Platform (WFP) to block the outbound traffic of running EDR agents based on specific hardcoded filter names.
windows · security
HackTool - EfsPotato Named Pipe Creation
highDetects the pattern of a pipe name as used by the hack tool EfsPotato
windows · pipe_created
HackTool - Empire PowerShell Launch Parameters
highDetects suspicious powershell command line parameters used in Empire
windows · process_creation
HackTool - Evil-WinRm Execution - PowerShell Module
highDetects the execution of Evil-WinRM via PowerShell Module logs by leveraging the hardcoded strings inside the utility.
windows · ps_module
HackTool - Generic Process Access
highDetects process access requests from hacktool processes based on their default image name
windows · process_access
HackTool - GMER Rootkit Detector and Remover Execution
highDetects the execution GMER tool based on image and hash fields.
windows · process_creation
HackTool - HandleKatz Duplicating LSASS Handle
highDetects HandleKatz opening LSASS to duplicate its handle to later dump the memory without opening any new handles
windows · process_access
HackTool - HandleKatz LSASS Dumper Execution
highDetects the use of HandleKatz, a tool that demonstrates the usage of cloned handles to Lsass in order to create an obfuscated memory dump of the same
windows · process_creation
HackTool - Hashcat Password Cracker Execution
highExecute Hashcat.exe with provided SAM file from registry of Windows and Password list to crack against
windows · process_creation
HackTool - HollowReaper Execution
highDetects usage of HollowReaper, a process hollowing shellcode launcher used for stealth payload execution through process hollowing. It replaces the memory of a legitimate process with custom shellcode, allowing the attacker to execute payloads under the guise of trusted binaries.
windows · process_creation
HackTool - Htran/NATBypass Execution
highDetects executable names or flags used by Htran or Htran-like tools (e.g. NATBypass)
windows · process_creation
HackTool - Hydra Password Bruteforce Execution
highDetects command line parameters used by Hydra password guessing hack tool
windows · process_creation
HackTool - Impacket File Indicators
highDetects file creation events with filename patterns used by Impacket.
windows · file_event
HackTool - Impacket Tools Execution
highDetects the execution of different compiled Windows binaries of the impacket toolset (based on names or part of their names - could lead to false positives)
windows · process_creation
HackTool - Koadic Execution
highDetects command line parameters used by Koadic hack tool
windows · process_creation
HackTool - KrbRelay Execution
highDetects the use of KrbRelay, a Kerberos relaying tool
windows · process_creation
HackTool - KrbRelayUp Execution
highDetects KrbRelayUp used to perform a universal no-fix local privilege escalation in Windows domain environments where LDAP signing is not enforced
windows · process_creation
HackTool - LittleCorporal Generated Maldoc Injection
highDetects the process injection of a LittleCorporal generated Maldoc.
windows · process_access
HackTool - LocalPotato Execution
highDetects the execution of the LocalPotato POC based on basic PE metadata information and default CLI examples
windows · process_creation
HackTool - Mimikatz Execution
highDetection well-known mimikatz command line arguments
windows · process_creation
HackTool - NetExec Execution
highDetects execution of the hacktool NetExec. NetExec (formerly CrackMapExec) is a widely used post-exploitation tool designed for Active Directory penetration testing and network enumeration In enterprise environments, the use of NetExec is considered suspicious or potentially malicious because it enables attackers to enumerate hosts, exploit network services, and move laterally across systems. Threat actors and red teams commonly use NetExec to identify vulnerable systems, harvest credentials, and execute commands remotely.
windows · process_creation
HackTool - NetExec File Indicators
highDetects file creation events indicating NetExec (nxc.exe) execution on the local machine. NetExec is a PyInstaller-bundled binary that extracts its embedded data files to a "_MEI<random>" directory under the Temp folder upon execution. Files dropped under the "\nxc\" sub-directory of that extraction path are unique to NetExec and serve as reliable on-disk indicators of execution. NetExec (formerly CrackMapExec) is a widely used post-exploitation and lateral movement tool used for Active Directory enumeration, credential harvesting, and remote code execution.
windows · file_event
HackTool - NoFilter Execution
highDetects execution of NoFilter, a tool for abusing the Windows Filtering Platform for privilege escalation via hardcoded policy name indicators
windows · security
HackTool - NPPSpy Hacktool Usage
highDetects the use of NPPSpy hacktool that stores cleartext passwords of users that logged in to a local file
windows · file_event
HackTool - PCHunter Execution
highDetects suspicious use of PCHunter, a tool like Process Hacker to view and manipulate processes, kernel options and other low level stuff
windows · process_creation
HackTool - Potential CobaltStrike Process Injection
highDetects a potential remote threat creation with certain characteristics which are typical for Cobalt Strike beacons
windows · create_remote_thread
HackTool - Potential Impacket Lateral Movement Activity
highDetects wmiexec/dcomexec/atexec/smbexec from Impacket framework
windows · process_creation
HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
highDetects default filenames output from the execution of CrackMapExec and Impacket-secretsdump against an endpoint.
windows · file_event
HackTool - PowerTool Execution
highDetects the execution of the tool PowerTool which has the ability to kill a process, delete its process file, unload drivers, and delete the driver files
windows · process_creation
HackTool - Powerup Write Hijack DLL
highPowerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation. In it's default mode, it builds a self deleting .bat file which executes malicious command. The detection rule relies on creation of the malicious bat file (debug.bat by default).
windows · file_event
HackTool - PPID Spoofing SelectMyParent Tool Execution
highDetects the use of parent process ID spoofing tools like Didier Stevens tool SelectMyParent
windows · process_creation
HackTool - Pypykatz Credentials Dumping Activity
highDetects the usage of "pypykatz" to obtain stored credentials. Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database through Windows registry where the SAM database is stored
windows · process_creation
HackTool - Quarks PwDump Execution
highDetects usage of the Quarks PwDump tool via commandline arguments
windows · process_creation
HackTool - RedMimicry Winnti Playbook Execution
highDetects actions caused by the RedMimicry Winnti playbook a automated breach emulations utility
windows · process_creation
HackTool - RemoteKrbRelay Execution
highDetects the use of RemoteKrbRelay, a Kerberos relaying tool via CommandLine flags and PE metadata.
windows · process_creation
HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
highDetects the creation of file with specific names used by RemoteKrbRelay SMB Relay attack module.
windows · file_event
HackTool - Rubeus Execution - ScriptBlock
highDetects the execution of the hacktool Rubeus using specific command line flags
windows · ps_script
HackTool - SafetyKatz Dump Indicator
highDetects default lsass dump filename generated by SafetyKatz.
windows · file_event
HackTool - SharpChisel Execution
highDetects usage of the Sharp Chisel via the commandline arguments
windows · process_creation
HackTool - SharpDPAPI Execution
highDetects the execution of the SharpDPAPI tool based on CommandLine flags and PE metadata. SharpDPAPI is a C# port of some DPAPI functionality from the Mimikatz project.
windows · process_creation
HackTool - SharPersist Execution
highDetects the execution of the hacktool SharPersist - used to deploy various different kinds of persistence mechanisms
windows · process_creation
HackTool - SharpEvtMute DLL Load
highDetects the load of EvtMuteHook.dll, a key component of SharpEvtHook, a tool that tampers with the Windows event logs
windows · image_load
HackTool - SharpEvtMute Execution
highDetects the use of SharpEvtHook, a tool that tampers with the Windows event logs
windows · process_creation
HackTool - SharpImpersonation Execution
highDetects execution of the SharpImpersonation tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
windows · process_creation
HackTool - SharpLdapWhoami Execution
highDetects SharpLdapWhoami, a whoami alternative that queries the LDAP service on a domain controller
windows · process_creation
HackTool - SharpMove Tool Execution
highDetects the execution of SharpMove, a .NET utility performing multiple tasks such as "Task Creation", "SCM" query, VBScript execution using WMI via its PE metadata and command line options.
windows · process_creation
HackTool - SharpView Execution
highAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
HackTool - SharpWSUS/WSUSpendu Execution
highDetects the execution of SharpWSUS or WSUSpendu, utilities that allow for lateral movement through WSUS. Windows Server Update Services (WSUS) is a critical component of Windows systems and is frequently configured in a way that allows an attacker to circumvent internal networking limitations.
windows · process_creation
HackTool - SILENTTRINITY Stager DLL Load
highDetects SILENTTRINITY stager dll loading activity
windows · image_load
HackTool - SILENTTRINITY Stager Execution
highDetects SILENTTRINITY stager use via PE metadata
windows · process_creation
HackTool - SOAPHound Execution
highDetects the execution of SOAPHound, a .NET tool for collecting Active Directory data, using specific command-line arguments that may indicate an attempt to extract sensitive AD information.
windows · process_creation
HackTool - Stracciatella Execution
highDetects Stracciatella which executes a Powershell runspace from within C# (aka SharpPick technique) with AMSI, ETW and Script Block Logging disabled based on PE metadata characteristics.
windows · process_creation
HackTool - SysmonEnte Execution
highDetects the use of SysmonEnte, a tool to attack the integrity of Sysmon
windows · process_access
HackTool - TruffleSnout Execution
highDetects the use of TruffleSnout.exe an iterative AD discovery toolkit for offensive operators, situational awareness and targeted low noise enumeration.
windows · process_creation
HackTool - Typical HiveNightmare SAM File Export
highDetects files written by the different tools that exploit HiveNightmare
windows · file_event
HackTool - UACMe Akagi Execution
highDetects the execution of UACMe, a tool used for UAC bypasses, via default PE metadata
windows · process_creation
HackTool - winPEAS Execution
highWinPEAS is a script that search for possible paths to escalate privileges on Windows hosts. The checks are explained on book.hacktricks.xyz
windows · process_creation
HackTool - WinPwn Execution
highDetects commandline keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
windows · process_creation
HackTool - WinPwn Execution - ScriptBlock
highDetects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.
windows · ps_script
HackTool - Wmiexec Default Powershell Command
highDetects the execution of PowerShell with a specific flag sequence that is used by the Wmiexec script
windows · process_creation
HackTool - WSASS Execution
highDetects execution of WSASS, a tool used to dump LSASS memory on Windows systems by leveraging WER's (Windows Error Reporting) WerFaultSecure.EXE to bypass PPL (Protected Process Light) protections.
windows · process_creation
HackTool - XORDump Execution
highDetects suspicious use of XORDump process memory dumping utility
windows · process_creation
Hacktool Execution - PE Metadata
highDetects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed
windows · process_creation
HackTool Named File Stream Created
highDetects the creation of a named file stream with the imphash of a well-known hack tool
windows · create_stream_hash
Hacktool Ruler
highThis events that are generated when using the hacktool Ruler by Sensepost
windows · security
HackTool Service Registration or Execution
highDetects installation or execution of services
windows · system
Hermetic Wiper TG Process Patterns
highDetects process execution patterns found in intrusions related to the Hermetic Wiper malware attacks against Ukraine in February 2022
windows · process_creation
Hidden Local User Creation
highDetects the creation of a local hidden user account which should not happen for event ID 4720.
windows · security
Hide Schedule Task Via Index Value Tamper
highDetects when the "index" value of a scheduled task is modified from the registry Which effectively hides it from any tooling such as "schtasks /query" (Read the referenced link for more information about the effects of this technique)
windows · registry_set
Hiding User Account Via SpecialAccounts Registry Key
highDetects modifications to the registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\Userlist" where the value is set to "0" in order to hide user account from being listed on the logon screen.
windows · registry_set
Hijack Legit RDP Session to Move Laterally
highDetects the usage of tsclient share to place a backdoor on the RDP source machine's startup folder
windows · file_event
HKTL - SharpSuccessor Privilege Escalation Tool Execution
highDetects the execution of SharpSuccessor, a tool used to exploit the BadSuccessor attack for privilege escalation in WinServer 2025 Active Directory environments. Successful usage of this tool can let the attackers gain the domain admin privileges by exploiting the BadSuccessor vulnerability.
windows · process_creation
HTML Help HH.EXE Suspicious Child Process
highDetects a suspicious child process of a Microsoft HTML Help (HH.exe)
windows · process_creation
HTTP Logging Disabled On IIS Server
highDetects changes to of the IIS server configuration in order to disable HTTP logging for successful requests.
windows · iis-configuration
HybridConnectionManager Service Installation
highRule to detect the Hybrid Connection Manager service installation.
windows · security
HybridConnectionManager Service Installation - Registry
highDetects the installation of the Azure Hybrid Connection Manager service to allow remote code execution from Azure function.
windows · registry_event
HybridConnectionManager Service Running
highRule to detect the Hybrid Connection Manager service running on an endpoint.
windows · microsoft-servicebus-client
Hypervisor Enforced Paging Translation Disabled
highDetects changes to the "DisableHypervisorEnforcedPagingTranslation" registry value. Where the it is set to "1" in order to disable the Hypervisor Enforced Paging Translation feature.
windows · registry_set
Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
highDetects the tampering of Hypervisor-protected Code Integrity (HVCI) related registry values via command line tool reg.exe. HVCI uses virtualization-based security to protect code integrity by ensuring that only trusted code can run in kernel mode. Adversaries may tamper with HVCI to load malicious or unsigned drivers, which can be used to escalate privileges, maintain persistence, or evade security mechanisms.
windows · process_creation
IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
highDetects RunDLL32.exe executing a single digit DLL named "1.dll" with the export function "DllRegisterServer". This behaviour was often seen used by malware and especially IcedID
windows · process_creation
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols
highDetects changes to Internet Explorer's (IE / Windows Internet properties) ZoneMap configuration of the "HTTP" and "HTTPS" protocols to point to the "My Computer" zone. This allows downloaded files from the Internet to be granted the same level of trust as files stored locally.
windows · registry_set
IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI
highDetects changes to Internet Explorer's (IE / Windows Internet properties) ZoneMap configuration of the "HTTP" and "HTTPS" protocols to point to the "My Computer" zone. This allows downloaded files from the Internet to be granted the same level of trust as files stored locally.
windows · process_creation
ImagingDevices Unusual Parent/Child Processes
highDetects unusual parent or children of the ImagingDevices.exe (Windows Contacts) process as seen being used with Bumblebee activity
windows · process_creation
Impacket PsExec Execution
highDetects execution of Impacket's psexec.py.
windows · security
Important Scheduled Task Deleted or Disabled
highDetects when adversaries try to stop system services or processes by deleting or disabling their respective scheduled tasks in order to conduct data destructive activities
windows · taskscheduler
Important Scheduled Task Deleted/Disabled
highDetects when adversaries stop services or processes by deleting or disabling their respective scheduled tasks in order to conduct data destructive activities
windows · security
Important Windows Event Auditing Disabled
highDetects scenarios where system auditing for important events such as "Process Creation" or "Logon" events is disabled.
windows · security
Important Windows Eventlog Cleared
highDetects the clearing of one of the Windows Core Eventlogs. e.g. caused by "wevtutil cl" command execution
windows · system
Important Windows Service Terminated Unexpectedly
highDetects important or interesting Windows services that got terminated unexpectedly.
windows · system
Important Windows Service Terminated With Error
highDetects important or interesting Windows services that got terminated for whatever reason
windows · system
Imports Registry Key From an ADS
highDetects the import of a alternate datastream to the registry with regedit.exe.
windows · process_creation
Injected Browser Process Spawning Rundll32 - GuLoader Activity
highDetects the execution of installed GuLoader malware on the host. GuLoader is initiating network connections via the rundll32.exe process that is spawned via a browser parent(injected) process.
windows · process_creation
Installation of WSL Kali-Linux
highDetects installation of Kali Linux distribution through Windows Subsystem for Linux (WSL). Attackers may use Kali Linux WSL to leverage its penetration testing tools and capabilities for malicious purposes.
windows · process_creation
Interactive AT Job
highDetects an interactive AT job, which may be used as a form of privilege escalation.
windows · process_creation
Invoke-Obfuscation CLIP+ Launcher
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · process_creation
Invoke-Obfuscation CLIP+ Launcher - PowerShell
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · ps_script
Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · ps_module
Invoke-Obfuscation CLIP+ Launcher - Security
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · security
Invoke-Obfuscation CLIP+ Launcher - System
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · system
Invoke-Obfuscation Obfuscated IEX Invocation
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block
windows · process_creation
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block \u2014
windows · ps_script
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block cited in the reference section below
windows · ps_module
Invoke-Obfuscation Obfuscated IEX Invocation - Security
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block linked in the references
windows · security
Invoke-Obfuscation Obfuscated IEX Invocation - System
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block linked in the references
windows · system
Invoke-Obfuscation STDIN+ Launcher
highDetects Obfuscated use of stdin to execute PowerShell
windows · process_creation
Invoke-Obfuscation STDIN+ Launcher - Powershell
highDetects Obfuscated use of stdin to execute PowerShell
windows · ps_script
Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
highDetects Obfuscated use of stdin to execute PowerShell
windows · ps_module
Invoke-Obfuscation STDIN+ Launcher - Security
highDetects Obfuscated use of stdin to execute PowerShell
windows · security
Invoke-Obfuscation STDIN+ Launcher - System
highDetects Obfuscated use of stdin to execute PowerShell
windows · system
Invoke-Obfuscation VAR+ Launcher
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · process_creation
Invoke-Obfuscation VAR+ Launcher - PowerShell
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · ps_script
Invoke-Obfuscation VAR+ Launcher - PowerShell Module
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · ps_module
Invoke-Obfuscation VAR+ Launcher - Security
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · security
Invoke-Obfuscation VAR+ Launcher - System
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · system
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · process_creation
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · ps_script
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · ps_module
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · security
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · system
Invoke-Obfuscation Via Stdin
highDetects Obfuscated Powershell via Stdin in Scripts
windows · process_creation
Invoke-Obfuscation Via Stdin - Powershell
highDetects Obfuscated Powershell via Stdin in Scripts
windows · ps_script
Invoke-Obfuscation Via Stdin - PowerShell Module
highDetects Obfuscated Powershell via Stdin in Scripts
windows · ps_module
Invoke-Obfuscation Via Stdin - Security
highDetects Obfuscated Powershell via Stdin in Scripts
windows · security
Invoke-Obfuscation Via Stdin - System
highDetects Obfuscated Powershell via Stdin in Scripts
windows · system
Invoke-Obfuscation Via Use Clip
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · process_creation
Invoke-Obfuscation Via Use Clip - Powershell
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · ps_script
Invoke-Obfuscation Via Use Clip - PowerShell Module
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · ps_module
Invoke-Obfuscation Via Use Clip - Security
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · security
Invoke-Obfuscation Via Use Clip - System
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · system
Invoke-Obfuscation Via Use MSHTA
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · process_creation
Invoke-Obfuscation Via Use MSHTA - PowerShell
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · ps_script
Invoke-Obfuscation Via Use MSHTA - PowerShell Module
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · ps_module
Invoke-Obfuscation Via Use MSHTA - Security
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · security
Invoke-Obfuscation Via Use MSHTA - System
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · system
Invoke-Obfuscation Via Use Rundll32 - PowerShell
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows · ps_script
Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows · ps_module
Invoke-Obfuscation Via Use Rundll32 - Security
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows · security
Invoke-Obfuscation Via Use Rundll32 - System
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows · system
ISO File Created Within Temp Folders
highDetects the creation of a ISO file in the Outlook temp folder or in the Appdata temp folder. Typical of Qakbot TTP from end-July 2022.
windows · file_event
Kalambur Backdoor Curl TOR SOCKS Proxy Execution
highDetects the execution of the "curl.exe" command, referencing "SOCKS" and ".onion" domains, which could be indicative of Kalambur backdoor activity.
windows · process_creation
Kapeka Backdoor Autorun Persistence
highDetects the setting of a new value in the Autorun key that is used by the Kapeka backdoor for persistence.
windows · registry_set
Kapeka Backdoor Execution Via RunDLL32.EXE
highDetects Kapeka backdoor process execution pattern, where the dropper launch the backdoor binary by calling rundll32 and passing the backdoor's first export ordinal (#1) with a "-d" argument.
windows · process_creation
Kapeka Backdoor Loaded Via Rundll32.EXE
highDetects the Kapeka Backdoor binary being loaded by rundll32.exe. The Kapeka loader drops a backdoor, which is a DLL with the '.wll' extension masquerading as a Microsoft Word Add-In.
windows · image_load
Kapeka Backdoor Persistence Activity
highDetects Kapeka backdoor persistence activity. Depending on the process privileges, the Kapeka dropper then sets persistence for the backdoor either as a scheduled task (if admin or SYSTEM) or autorun registry (if not). For the scheduled task, it creates a scheduled task called "Sens Api" via schtasks command, which is set to run upon system startup as SYSTEM. To establish persistence through the autorun utility, it adds an autorun entry called "Sens Api" under HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run via the "reg add" command. Both persistence mechanisms are set to launch the binary by calling rundll32 and passing the backdoor's first export ordinal (#1) without any additional argument.
windows · process_creation
Kapeka Backdoor Scheduled Task Creation
highDetects Kapeka backdoor scheduled task creation based on attributes such as paths, commands line flags, etc.
windows · security
Katz Stealer DLL Loaded
highDetects loading of DLLs associated with Katz Stealer malware 2025 variants. Katz Stealer is a malware variant that is known to be used for stealing sensitive information from compromised systems. The process that loads these DLLs are very likely to be malicious.
windows · image_load
Kavremover Dropped Binary LOLBIN Usage
highDetects the execution of a signed binary dropped by Kaspersky Lab Products Remover (kavremover) which can be abused as a LOLBIN to execute arbitrary commands and binaries.
windows · process_creation
Kerberos Manipulation
highDetects failed Kerberos TGT issue operation. This can be a sign of manipulations of TGT messages by an attacker.
windows · security
Kernel Memory Dump Via LiveKD
highDetects execution of LiveKD with the "-m" flag to potentially dump the kernel memory
windows · process_creation
KrbRelayUp Service Installation
highDetects service creation from KrbRelayUp tool used for privilege escalation in Windows domain environments where LDAP signing is not enforced (the default settings)
windows · system
Lace Tempest Cobalt Strike Download
highDetects specific command line execution used by Lace Tempest to download Cobalt Strike as reported by SysAid Team
windows · process_creation
Lace Tempest File Indicators
highDetects PowerShell script file creation with specific names or suffixes which was seen being used often in PowerShell scripts by FIN7
windows · file_event
Lace Tempest Malware Loader Execution
highDetects execution of a specific binary based on filename and hash used by Lace Tempest to load additional malware as reported by SysAid Team
windows · process_creation
Lace Tempest PowerShell Evidence Eraser
highDetects a PowerShell script used by Lace Tempest APT to erase evidence from victim servers by exploiting CVE-2023-47246 as reported by SysAid Team
windows · ps_script
Lace Tempest PowerShell Launcher
highDetects a PowerShell script used by Lace Tempest APT to launch their malware loader by exploiting CVE-2023-47246 as reported by SysAid Team
windows · ps_script
Lazarus APT DLL Sideloading Activity
highDetects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company
windows · image_load
Lazarus System Binary Masquerading
highDetects binaries used by the Lazarus group which use system names but are executed and launched from non-default location
windows · process_creation
Legitimate Application Dropped Archive
highDetects programs on a Windows system that should not write an archive to disk
windows · file_event
Legitimate Application Dropped Executable
highDetects LOLBINs and applications that should not legitimately drop executable or executable-equivalent files to disk. This may indicate malware staging, process injection, or abuse of a trusted binary for payload delivery.
windows · file_event
Legitimate Application Dropped Script
highDetects LOLBINs and applications that should not legitimately drop script files to disk. This may indicate malware staging or abuse of a trusted binary for script-based code execution.
windows · file_event
Legitimate Application Writing Files In Uncommon Location
highDetects legitimate applications writing any type of file to uncommon or suspicious locations that are not typical for application data storage or execution. Adversaries may leverage legitimate applications (Living off the Land Binaries - LOLBins) to drop or download malicious files to uncommon locations on the system to evade detection by security solutions.
windows · file_event
Live Memory Dump Using Powershell
highDetects usage of a PowerShell command to dump the live memory of a Windows machine
windows · ps_script
LiveKD Driver Creation By Uncommon Process
highDetects the creation of the LiveKD driver by a process image other than "livekd.exe".
windows · file_event
LiveKD Kernel Memory Dump File Created
highDetects the creation of a file that has the same name as the default LiveKD kernel memory dump.
windows · file_event
Load Of RstrtMgr.DLL By A Suspicious Process
highDetects the load of RstrtMgr DLL (Restart Manager) by a suspicious process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes.
windows · image_load
Loading Diagcab Package From Remote Path
highDetects loading of diagcab packages from a remote path, as seen in DogWalk vulnerability
windows · diagnosis-scripted
Local Privilege Escalation Indicator TabTip
highDetects the invocation of TabTip via CLSID as seen when JuicyPotatoNG is used on a system in brute force mode
windows · system
LOL-Binary Copied From System Directory
highDetects a suspicious copy operation that tries to copy a known LOLBIN from system (System32, SysWOW64, WinSxS) directories to another on disk in order to bypass detections based on locations.
windows · process_creation
Lolbas OneDriveStandaloneUpdater.exe Proxy Download
highDetects setting a custom URL for OneDriveStandaloneUpdater.exe to download a file from the Internet without executing any anomalous executables with suspicious arguments. The downloaded file will be in C:\Users\redacted\AppData\Local\Microsoft\OneDrive\StandaloneUpdaterreSignInSettingsConfig.json
windows · registry_set
LPE InstallerFileTakeOver PoC CVE-2021-41379
highDetects PoC tool used to exploit LPE vulnerability CVE-2021-41379
windows · application
LSASS Access Detected via Attack Surface Reduction
highDetects Access to LSASS Process
windows · windefend
LSASS Access From Potentially White-Listed Processes
highDetects a possible process memory dump that uses a white-listed filename like TrolleyExpress.exe as a way to dump the LSASS process memory without Microsoft Defender interference
windows · process_access
LSASS Crash Via Netlogon Stack Buffer Overflow - CVE-2026-41089
highDetects a crash of the LSASS process where netlogon.dll is the faulting module and the exception code is STATUS_STACK_BUFFER_OVERRUN (0xc0000409). This crash, especially on Domain Controllers, might indicate the exploitation of CVE-2026-41089, a denial of service (DoS) vulnerability, which exists in the Netlogon component of Windows and can be triggered by sending specially crafted requests to the Netlogon service, leading to a stack-based buffer overflow and subsequent crash of the LSASS process.
windows · application
LSASS Dump Keyword In CommandLine
highDetects the presence of the keywords "lsass" and ".dmp" in the commandline, which could indicate a potential attempt to dump or create a dump of the lsass process.
windows · process_creation
Lsass Full Dump Request Via DumpType Registry Settings
highDetects the setting of the "DumpType" registry value to "2" which stands for a "Full Dump". Technique such as LSASS Shtinkering requires this value to be "2" in order to dump LSASS.
windows · registry_set
LSASS Memory Access by Tool With Dump Keyword In Name
highDetects LSASS process access requests from a source process with the "dump" keyword in its image name.
windows · process_access
Lsass Memory Dump via Comsvcs DLL
highDetects adversaries leveraging the MiniDump export function from comsvcs.dll via rundll32 to perform a memory dump from lsass.
windows · process_access
LSASS Process Crashed - Application
highDetects Windows error reporting events where the process that crashed is LSASS (Local Security Authority Subsystem Service). This could be the cause of a provoked crash by techniques such as Lsass-Shtinkering to dump credentials.
windows · application
LSASS Process Dump Artefact In CrashDumps Folder
highDetects the presence of an LSASS dump file in the "CrashDumps" folder. This could be a sign of LSASS credential dumping. Techniques such as the LSASS Shtinkering have been seen abusing the Windows Error Reporting to dump said process.
windows · file_event
LSASS Process Memory Dump Creation Via Taskmgr.EXE
highDetects the creation of an "lsass.dmp" file by the taskmgr process. This indicates a manual dumping of the LSASS.exe process memory using Windows Task Manager.
windows · file_event
LSASS Process Memory Dump Files
highDetects creation of files with names used by different memory dumping tools to create a memory dump of the LSASS process memory, which contains user credentials.
windows · file_event
LSASS Process Reconnaissance Via Findstr.EXE
highDetects findstring commands that include the keyword lsass, which indicates recon actviity for the LSASS process PID
windows · process_creation
Lummac Stealer Activity - Execution Of More.com And Vbc.exe
highDetects the execution of more.com and vbc.exe in the process tree. This behavior was observed by a set of samples related to Lummac Stealer. The Lummac payload is injected into the vbc.exe process.
windows · process_creation
Macro Enabled In A Potentially Suspicious Document
highDetects registry changes to Office trust records where the path is located in a potentially suspicious location
windows · registry_set
Malicious Base64 Encoded PowerShell Keywords in Command Lines
highDetects base64 encoded strings used in hidden malicious PowerShell command lines
windows · process_creation
Malicious DLL File Dropped in the Teams or OneDrive Folder
highDetects creation of a malicious DLL file in the location where the OneDrive or Team applications Upon execution of the Teams or OneDrive application, the dropped malicious DLL file ("iphlpapi.dll") is sideloaded
windows · file_event
Malicious Driver Load
highDetects loading of known malicious drivers via their hash.
windows · driver_load
Malicious Nishang PowerShell Commandlets
highDetects Commandlet names and arguments from the Nishang exploitation framework
windows · ps_script
Malicious PowerShell Commandlets - PoshModule
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · ps_module
Malicious PowerShell Commandlets - ProcessCreation
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · process_creation
Malicious PowerShell Commandlets - ScriptBlock
highDetects Commandlet names from well-known PowerShell exploitation frameworks
windows · ps_script
Malicious PowerShell Scripts - FileCreation
highDetects the creation of known offensive powershell scripts used for exploitation
windows · file_event
Malicious PowerShell Scripts - PoshModule
highDetects the execution of known offensive powershell scripts used for exploitation or reconnaissance
windows · ps_module
Malicious ShellIntel PowerShell Commandlets
highDetects Commandlet names from ShellIntel exploitation scripts.
windows · ps_script
Malware Shellcode in Verclsid Target Process
highDetects a process access to verclsid.exe that injects shellcode from a Microsoft Office application / VBA macro
windows · process_access
ManageEngine Endpoint Central Dctask64.EXE Potential Abuse
highDetects the execution of "dctask64.exe", a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.
windows · process_creation
Mavinject Inject DLL Into Running Process
highDetects process injection using the signed Windows tool "Mavinject" via the "INJECTRUNNING" flag
windows · process_creation
MERCURY APT Activity
highDetects suspicious command line patterns seen being used by MERCURY APT
windows · process_creation
Metasploit Or Impacket Service Installation Via SMB PsExec
highDetects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation
windows · security
Metasploit SMB Authentication
highAlerts on Metasploit host's authentications on the domain.
windows · security
Meterpreter or Cobalt Strike Getsystem Service Installation - Security
highDetects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation
windows · security
Meterpreter or Cobalt Strike Getsystem Service Installation - System
highDetects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation
windows · system
Microsoft Defender Blocked from Loading Unsigned DLL
highDetects Code Integrity (CI) engine blocking Microsoft Defender's processes (MpCmdRun and NisSrv) from loading unsigned DLLs which may be an attempt to sideload arbitrary DLL
windows · security-mitigations
Microsoft Defender Tamper Protection Trigger
highDetects blocked attempts to change any of Defender's settings such as "Real Time Monitoring" and "Behavior Monitoring"
windows · windefend
Microsoft IIS Connection Strings Decryption
highDetects use of aspnet_regiis to decrypt Microsoft IIS connection strings. An attacker with Microsoft IIS web server access via a webshell or alike can decrypt and dump any hardcoded connection strings, such as the MSSQL service account password using aspnet_regiis command.
windows · process_creation
Microsoft IIS Service Account Password Dumped
highDetects the Internet Information Services (IIS) command-line tool, AppCmd, being used to list passwords
windows · process_creation
Microsoft Malware Protection Engine Crash
highThis rule detects a suspicious crash of the Microsoft Malware Protection Engine
windows · application
Microsoft Malware Protection Engine Crash - WER
highThis rule detects a suspicious crash of the Microsoft Malware Protection Engine
windows · application
Microsoft Office DLL Sideload
highDetects DLL sideloading of DLLs that are part of Microsoft Office from non standard location
windows · image_load
Microsoft Office Protected View Disabled
highDetects changes to Microsoft Office protected view registry keys with which the attacker disables this feature.
windows · registry_set
Mimikatz Use
highThis method detects mimikatz keywords in different Eventlogs (some of them only appear in older Mimikatz version that are however still used by different threat groups)
windows
Mint Sandstorm - Log4J Wstomcat Process Execution
highDetects Log4J Wstomcat process execution as seen in Mint Sandstorm activity
windows · process_creation
MMC Executing Files with Reversed Extensions Using RTLO Abuse
highDetects malicious behavior where the MMC utility (`mmc.exe`) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.
windows · process_creation
MMC Spawning Windows Shell
highDetects a Windows command line executable started from MMC
windows · process_creation
MMC20 Lateral Movement
highDetects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of "-Embedding" as a child of svchost.exe
windows · process_creation
Modify User Shell Folders Startup Value
highDetect modification of the User Shell Folders registry values for Startup or Common Startup which could indicate persistence attempts. Attackers may modify User Shell Folders registry keys to point to malicious executables or scripts that will be executed during startup. This technique is often used to maintain persistence on a compromised system by ensuring that the malicious payload is executed automatically.
windows · registry_set
MpiExec Lolbin
highDetects a certain command line flag combination used by mpiexec.exe LOLBIN from HPC pack that can be used to execute any other binary
windows · process_creation
MSDT Execution Via Answer File
highDetects execution of "msdt.exe" using an answer file which is simulating the legitimate way of calling msdt via "pcwrun.exe" (For example from the compatibility tab).
windows · process_creation
MSHTA Execution with Suspicious File Extensions
highDetects execution of mshta.exe with file types that looks like they do not typically represent HTA (HTML Application) content, such as .png, .jpg, .zip, .pdf, and others, which are often polyglots. MSHTA is a legitimate Windows utility for executing HTML Applications containing VBScript or JScript. Threat actors often abuse this lolbin utility to download and execute malicious scripts disguised as benign files or hosted under misleading extensions to evade detection.
windows · process_creation
Mshtml.DLL RunHTMLApplication Suspicious Usage
highDetects execution of commands that leverage the "mshtml.dll" RunHTMLApplication export to run arbitrary code via different protocol handlers (vbscript, javascript, file, http...)
windows · process_creation
MSMQ Corrupted Packet Encountered
highDetects corrupted packets sent to the MSMQ service. Could potentially be a sign of CVE-2023-21554 exploitation
windows · application
MSSQL Add Account To Sysadmin Role
highDetects when an attacker tries to backdoor the MSSQL server by adding a backdoor account to the sysadmin fixed server role
windows · application
MSSQL Disable Audit Settings
highDetects when an attacker calls the "ALTER SERVER AUDIT" or "DROP SERVER AUDIT" transaction in order to delete or disable audit logs on the server
windows · application
MSSQL Extended Stored Procedure Backdoor Maggie
highThis rule detects the execution of the extended storage procedure backdoor named Maggie in the context of Microsoft SQL server
windows · application
MSSQL SPProcoption Set
highDetects when the a stored procedure is set or cleared for automatic execution in MSSQL. A stored procedure that is set to automatic execution runs every time an instance of SQL Server is started
windows · application
MSSQL XPCmdshell Option Change
highDetects when the MSSQL "xp_cmdshell" stored procedure setting is changed.
windows · application
MSSQL XPCmdshell Suspicious Execution
highDetects when the MSSQL "xp_cmdshell" stored procedure is used to execute commands
windows · application
Mstsc.EXE Execution From Uncommon Parent
highDetects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
windows · process_creation
Mustang Panda Dropper
highDetects specific process parameters as used by Mustang Panda droppers
windows · process_creation
Narrator's Feedback-Hub Persistence
highDetects abusing Windows 10 Narrator's Feedback-Hub
windows · registry_event
NET NGenAssemblyUsageLog Registry Key Tamper
highDetects changes to the NGenAssemblyUsageLog registry key. .NET Usage Log output location can be controlled by setting the NGenAssemblyUsageLog CLR configuration knob in the Registry or by configuring an environment variable (as described in the next section). By simplify specifying an arbitrary value (e.g. fake output location or junk data) for the expected value, a Usage Log file for the .NET execution context will not be created.
windows · registry_set
Net WebClient Casing Anomalies
highDetects PowerShell command line contents that include a suspicious abnormal casing in the Net.Webclient (e.g. nEt.WEbCliEnT) string as used in obfuscation techniques
windows · process_creation
NetNTLM Downgrade Attack
highDetects NetNTLM downgrade attack
windows · security
NetNTLM Downgrade Attack - Registry
highDetects NetNTLM downgrade attack
windows · registry_event
Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder
highDetects executables located in potentially suspicious directories initiating network connections towards file sharing domains.
windows · network_connection
Network Communication With Crypto Mining Pool
highDetects initiated network connections to crypto mining pools. It indicates that the system is likely infected with a crypto miner malware or is being used for crypto mining.
windows · network_connection
Network Connection Initiated By AddinUtil.EXE
highDetects a network connection initiated by the Add-In deployment cache updating utility "AddInutil.exe". This could indicate a potential command and control communication as this tool doesn't usually initiate network activity.
windows · network_connection
Network Connection Initiated By Eqnedt32.EXE
highDetects network connections from the Equation Editor process "eqnedt32.exe".
windows · network_connection
Network Connection Initiated By IMEWDBLD.EXE
highDetects a network connection initiated by IMEWDBLD.EXE. This might indicate potential abuse of the utility as a LOLBIN in order to download arbitrary files or additional payloads.
windows · network_connection
Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location
highDetects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.
windows · network_connection
Network Connection Initiated via Finger.EXE
highDetects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such network connections can also help identify potential malicious infrastructure used by threat actors
windows · network_connection
Network Connection Initiated Via Notepad.EXE
highDetects a network connection that is initiated by the "notepad.exe" process. This might be a sign of process injection from a beacon process or something similar. Notepad rarely initiates a network communication except when printing documents for example.
windows · network_connection
Network Reconnaissance Activity
highDetects a set of suspicious network related commands often used in recon stages
windows · process_creation
New Connection Initiated To Potential Dead Drop Resolver Domain
highDetects an executable, which is not an internet browser or known application, initiating network connections to legit popular websites, which were seen to be used as dead drop resolvers in previous attacks. In this context attackers leverage known websites such as "facebook", "youtube", etc. In order to pass through undetected.
windows · network_connection
New DNS ServerLevelPluginDll Installed
highDetects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
windows · registry_set
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
highDetects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
windows · process_creation
New File Association Using Exefile
highDetects the abuse of the exefile handler in new file association. Used for bypass of security products.
windows · registry_set
New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
highDetects the addition of a new rule to the Windows Firewall exception list for an application located in a potentially suspicious location.
windows · firewall-as
New Netsh Helper DLL Registered From A Suspicious Location
highDetects changes to the Netsh registry key to add a new DLL value that is located on a suspicious location. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
windows · registry_set
New RDP Connection Initiated From Domain Controller
highDetects an RDP connection originating from a domain controller.
windows · network_connection
New RUN Key Pointing to Suspicious Folder
highDetects suspicious new RUN key element pointing to an executable in a suspicious folder
windows · registry_set
New TimeProviders Registered With Uncommon DLL Name
highDetects processes setting a new DLL in DllName in under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider. Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time synchronization across and within domains.
windows · registry_set
New User Created Via Net.EXE With Never Expire Option
highDetects creation of local users via the net.exe command with the option "never expire"
windows · process_creation
NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE
highDetects the attempt to create an ActiveScriptEventConsumer via WMIC.EXE. An ActiveScriptEventConsumer is a built-in Windows Management Instrumentation (WMI) class that automatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs. Adversaries often abuse ActiveScriptEventConsumer to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.
windows · process_creation
Ngrok Usage with Remote Desktop Service
highDetects cases in which ngrok, a reverse proxy tool, forwards events to the local RDP port, which could be a sign of malicious behaviour
windows · terminalservices-localsessionmanager
Non-privileged Usage of Reg or Powershell
highSearch for usage of reg or Powershell by non-privileged users to modify service configuration in registry
windows · process_creation
NtdllPipe Like Activity Execution
highDetects command that type the content of ntdll.dll to a different file or a pipe in order to evade AV / EDR detection. As seen being used in the POC NtdllPipe
windows · process_creation
NTDS Exfiltration Filename Patterns
highDetects creation of files with specific name patterns seen used in various tools that export the NTDS.DIT for exfiltration.
windows · file_event
NTDS.DIT Creation By Uncommon Parent Process
highDetects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon parent process or directory
windows · file_event
NTDS.DIT Creation By Uncommon Process
highDetects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory
windows · file_event
NTFS Alternate Data Stream
highDetects writing data into NTFS alternate data streams from powershell. Needs Script Block Logging.
windows · ps_script
NTFS Vulnerability Exploitation
highThis the exploitation of a NTFS vulnerability as reported without many details via Twitter
windows · system
NTLM Hash Leak Via Curl NTLM Authentication
highDetects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused to leak the currently logged-in user's NTLMv2 challenge-response to an attacker-controlled server, enabling offline cracking or relay attacks. When no credentials are provided, the Microsoft-shipped curl passes a NULL identity to Windows SSPI, which automatically falls back to the current user's logon session credentials stored in LSASS — without requiring a plaintext password. This behavior is exclusive to the curl binary shipped by Microsoft (available since Windows 10 / Windows Server 2019), which is built with SSPI support.
windows · process_creation
Obfuscated PowerShell MSI Install via WindowsInstaller COM
highDetects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`). The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
windows · process_creation
Obfuscated PowerShell OneLiner Execution
highDetects the execution of a specific OneLiner to download and execute powershell modules in memory.
windows · process_creation
Octopus Scanner Malware
highDetects Octopus Scanner Malware.
windows · file_event
Odbcconf.EXE Suspicious DLL Location
highDetects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.
windows · process_creation
Office Macro File Creation From Suspicious Process
highDetects the creation of a office macro file from a a suspicious process
windows · file_event
Office Macros Warning Disabled
highDetects registry changes to Microsoft Office "VBAWarning" to a value of "1" which enables the execution of all macros, whether signed or unsigned.
windows · registry_set
OneNote.EXE Execution of Malicious Embedded Scripts
highDetects the execution of malicious OneNote documents that contain embedded scripts. When a user clicks on a OneNote attachment and then on the malicious link inside the ".one" file, it exports and executes the malicious embedded script from specific directories.
windows · process_creation
Onyx Sleet APT File Creation Indicators
highDetects file creation activity that is related to Onyx Sleet APT activity
windows · file_event
OpenWith.exe Executes Specified Binary
highThe OpenWith.exe executes other binary
windows · process_creation
Operation Wocao Activity
highDetects activity mentioned in Operation Wocao report
windows · process_creation
Operation Wocao Activity - Security
highDetects activity mentioned in Operation Wocao report
windows · security
Operator Bloopers Cobalt Strike Commands
highDetects use of Cobalt Strike commands accidentally entered in the CMD shell
windows · process_creation
Operator Bloopers Cobalt Strike Modules
highDetects Cobalt Strike module/commands accidentally entered in CMD shell
windows · process_creation
Outbound Network Connection Initiated By Cmstp.EXE
highDetects a network connection initiated by Cmstp.EXE Its uncommon for "cmstp.exe" to initiate an outbound network connection. Investigate the source of such requests to determine if they are malicious.
windows · network_connection
Outbound Network Connection Initiated By Microsoft Dialer
highDetects outbound network connection initiated by Microsoft Dialer. The Microsoft Dialer, also known as Phone Dialer, is a built-in utility application included in various versions of the Microsoft Windows operating system. Its primary function is to provide users with a graphical interface for managing phone calls via a modem or a phone line connected to the computer. This is an outdated process in the current conext of it's usage and is a common target for info stealers for process injection, and is used to make C2 connections, common example is "Rhadamanthys"
windows · network_connection
Outbound Network Connection Initiated By Script Interpreter
highDetects a script interpreter wscript/cscript opening a network connection to a non-local network. Adversaries may use script to download malicious payloads.
windows · network_connection
Outbound RDP Connections Over Non-Standard Tools
highDetects Non-Standard tools initiating a connection over port 3389 indicating possible lateral movement. An initial baseline is required before using this utility to exclude third party RDP tooling that you might use.
windows · network_connection
Outlook EnableUnsafeClientMailRules Setting Enabled
highDetects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros
windows · process_creation
Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
highDetects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros
windows · registry_set
Outlook Macro Execution Without Warning Setting Enabled
highDetects the modification of Outlook security setting to allow unprompted execution of macros.
windows · registry_set
PaperCut MF/NG Exploitation Related Indicators
highDetects exploitation indicators related to PaperCut MF/NG Exploitation
windows · process_creation
PaperCut MF/NG Potential Exploitation
highDetects suspicious child processes of "pc-app.exe". Which could indicate potential exploitation of PaperCut
windows · process_creation
Password Change on Directory Service Restore Mode (DSRM) Account
highDetects potential attempts made to set the Directory Services Restore Mode administrator password. The Directory Service Restore Mode (DSRM) account is a local administrator account on Domain Controllers. Attackers may change the password in order to obtain persistence.
windows · security
Password Dumper Activity on LSASS
highDetects process handle on LSASS process with certain access mask and object type SAM_DOMAIN
windows · security
Password Dumper Remote Thread in LSASS
highDetects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage. The process in field Process is the malicious program. A single execution can lead to hundreds of events.
windows · create_remote_thread
Password Protected ZIP File Opened (Email Attachment)
highDetects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
windows · security
Password Protected ZIP File Opened (Suspicious Filenames)
highDetects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.
windows · security
PCRE.NET Package Image Load
highDetects processes loading modules related to PCRE.NET package
windows · image_load
PCRE.NET Package Temp Files
highDetects processes creating temp files related to PCRE.NET package
windows · file_event
PDF File Created By RegEdit.EXE
highDetects the creation of a file with the ".pdf" extension by the "RegEdit.exe" process. This indicates that a user is trying to print/save a registry key as a PDF in order to potentially extract sensitive information and bypass defenses.
windows · file_event
Peach Sandstorm APT Process Activity Indicators
highDetects process creation activity related to Peach Sandstorm APT
windows · process_creation
Persistence and Execution at Scale via GPO Scheduled Task
highDetect lateral movement using GPO scheduled task, usually used to deploy ransomware at scale
windows · security
Persistence Via Hhctrl.ocx
highDetects when an attacker modifies the registry value of the "hhctrl" to point to a custom binary
windows · registry_set
PetitPotam Suspicious Kerberos TGT Request
highDetect suspicious Kerberos TGT requests. Once an attacer obtains a computer certificate by abusing Active Directory Certificate Services in combination with PetitPotam, the next step would be to leverage the certificate for malicious purposes. One way of doing this is to request a Kerberos Ticket Granting Ticket using a tool like Rubeus. This request will generate a 4768 event with some unusual fields depending on the environment. This analytic will require tuning, we recommend filtering Account_Name to the Domain Controller computer accounts.
windows · security
Phishing Pattern ISO in Archive
highDetects cases in which an ISO files is opend within an archiver like 7Zip or Winrar, which is a sign of phishing as threat actors put small ISO files in archives as email attachments to bypass certain filters and protective measures (mark of web)
windows · process_creation
Pikabot Fake DLL Extension Execution Via Rundll32.EXE
highDetects specific process tree behavior linked to "rundll32" executions, wherein the associated DLL lacks a common ".dll" extension, often signaling potential Pikabot activity.
windows · process_creation
Ping Hex IP
highDetects a ping command that uses a hex encoded IP address
windows · process_creation
Pingback Backdoor Activity
highDetects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report
windows · process_creation
Pingback Backdoor DLL Loading Activity
highDetects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report
windows · image_load
Pingback Backdoor File Indicators
highDetects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report
windows · file_event
Possible CVE-2021-1675 Print Spooler Exploitation
highDetects events of driver load errors in print service logs that could be a sign of successful exploitation attempts of print spooler vulnerability CVE-2021-1675
windows · printservice-admin
Possible Exploitation of Exchange RCE CVE-2021-42321
highDetects log entries that appear in exploitation attempts against MS Exchange RCE CVE-2021-42321
windows · msexchange-management
Possible Impacket SecretDump Remote Activity
highDetect AD credential dumping using impacket secretdump HKTL
windows · security
Possible PetitPotam Coerce Authentication Attempt
highDetect PetitPotam coerced authentication activity.
windows · security
Possible Privilege Escalation via Weak Service Permissions
highDetection of sc.exe utility spawning by user with Medium integrity level to change service ImagePath or FailureCommand
windows · process_creation
Possible Shadow Credentials Added
highDetects possible addition of shadow credentials to an active directory object.
windows · security
Potential ACTINIUM Persistence Activity
highDetects specific process parameters as used by ACTINIUM scheduled task persistence creation.
windows · process_creation
Potential Adplus.EXE Abuse
highDetects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.
windows · process_creation
Potential AMSI Bypass Via .NET Reflection
highDetects Request to "amsiInitFailed" that can be used to disable AMSI Scanning
windows · process_creation
Potential AMSI COM Server Hijacking
highDetects changes to the AMSI come server registry key in order disable AMSI scanning functionalities. When AMSI attempts to starts its COM component, it will query its registered CLSID and return a non-existent COM server. This causes a load failure and prevents any scanning methods from being accessed, ultimately rendering AMSI useless
windows · registry_set
Potential appverifUI.DLL Sideloading
highDetects potential DLL sideloading of "appverifUI.dll"
windows · image_load
Potential APT FIN7 POWERHOLD Execution
highDetects execution of the POWERHOLD script seen used by FIN7 as reported by WithSecureLabs
windows · ps_script
Potential APT FIN7 Reconnaissance/POWERTRASH Related Activity
highDetects specific command line execution used by FIN7 as reported by WithSecureLabs for reconnaissance and POWERTRASH execution
windows · process_creation
Potential APT FIN7 Related PowerShell Script Created
highDetects PowerShell script file creation with specific name or suffix which was seen being used often by FIN7 PowerShell scripts
windows · file_event
Potential APT Mustang Panda Activity Against Australian Gov
highDetects specific command line execution used by Mustang Panda in a targeted attack against the Australian government as reported by Lab52
windows · process_creation
Potential APT10 Cloud Hopper Activity
highDetects potential process and execution activity related to APT10 Cloud Hopper operation
windows · process_creation
Potential Arbitrary Code Execution Via Node.EXE
highDetects the execution node.exe which is shipped with multiple software such as VMware, Adobe...etc. In order to execute arbitrary code. For example to establish reverse shell as seen in Log4j attacks...etc
windows · process_creation
Potential Arbitrary Command Execution Using Msdt.EXE
highDetects processes leveraging the "ms-msdt" handler or the "msdt.exe" binary to execute arbitrary commands as seen in the follina (CVE-2022-30190) vulnerability
windows · process_creation
Potential Arbitrary File Download Using Office Application
highDetects potential arbitrary file download using a Microsoft Office application
windows · process_creation
Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
highDetects spawning of suspicious child processes by Atlassian Confluence server which may indicate successful exploitation of CVE-2021-26084
windows · process_creation
Potential Attachment Manager Settings Associations Tamper
highDetects tampering with attachment manager settings policies associations to lower the default file type risks (See reference for more information)
windows · registry_set
Potential Attachment Manager Settings Attachments Tamper
highDetects tampering with attachment manager settings policies attachments (See reference for more information)
windows · registry_set
Potential AutoLogger Sessions Tampering
highDetects tampering with autologger trace sessions which is a technique used by attackers to disable logging. The AutoLogger event tracing session records events up that occur early in the operating system boot process. Applications and device drivers can use the AutoLogger session to capture traces before the user logs in, and also used by security solutions as telemetry source. Adversaries may disable these sessions to evade detection and prevent security monitoring of early boot activities and system events.
windows · registry_set
Potential Baby Shark Malware Activity
highDetects activity that could be related to Baby Shark malware
windows · process_creation
Potential BearLPE Exploitation
highDetects potential exploitation of the BearLPE exploit using Task Scheduler ".job" import arbitrary DACL write\par
windows · process_creation
Potential BlackByte Ransomware Activity
highDetects command line patterns used by BlackByte ransomware in different operations
windows · process_creation
Potential Bumblebee Remote Thread Creation
highDetects remote thread injection events based on action seen used by bumblebee
windows · create_remote_thread
Potential ClickFix Execution Pattern - Registry
highDetects potential ClickFix malware execution patterns by monitoring registry modifications in RunMRU keys containing HTTP/HTTPS links. ClickFix is known to be distributed through phishing campaigns and uses techniques like clipboard hijacking and fake CAPTCHA pages. Through the fakecaptcha pages, the adversary tricks users into opening the Run dialog box and pasting clipboard-hijacked content, such as one-liners that execute remotely hosted malicious files or scripts.
windows · registry_set
Potential CobaltStrike Process Patterns
highDetects potential process patterns related to Cobalt Strike beacon activity
windows · process_creation
Potential CobaltStrike Service Installations - Registry
highDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement.
windows · registry_set
Potential COLDSTEEL Persistence Service DLL Creation
highDetects the creation of a file in a specific location and with a specific name related to COLDSTEEL RAT
windows · file_event
Potential COLDSTEEL Persistence Service DLL Load
highDetects a suspicious DLL load by an "svchost" process based on location and name that might be related to ColdSteel RAT. This DLL location and name has been seen used by ColdSteel as the service DLL for its persistence mechanism
windows · image_load
Potential COLDSTEEL RAT File Indicators
highDetects the creation of a file named "dllhost.exe" in the "C:\users\public\Documents\" directory. Seen being used by the COLDSTEEL RAT in some of its variants.
windows · file_event
Potential COLDSTEEL RAT Windows User Creation
highDetects creation of a new user profile with a specific username, seen being used by some variants of the COLDSTEEL RAT.
windows · registry_set
Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
highDetects potential commandline obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
windows · process_creation
Potential CommandLine Path Traversal Via Cmd.EXE
highDetects potential path traversal attempt via cmd.exe. Could indicate possible command/argument confusion/hijacking
windows · process_creation
Potential Compromised 3CXDesktopApp Beaconing Activity - DNS
highDetects potential beaconing activity to domains related to 3CX 3CXDesktopApp compromise
windows · dns_query
Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon
highDetects potential beaconing activity to domains related to 3CX 3CXDesktopApp compromise
windows · network_connection
Potential Compromised 3CXDesktopApp Execution
highDetects execution of known compromised version of 3CXDesktopApp
windows · process_creation
Potential Compromised 3CXDesktopApp Update Activity
highDetects the 3CXDesktopApp updater downloading a known compromised version of the 3CXDesktopApp software
windows · process_creation
Potential Conti Ransomware Database Dumping Activity Via SQLCmd
highDetects a command used by conti to dump database
windows · process_creation
Potential Credential Dumping Attempt Using New NetworkProvider - CLI
highDetects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
windows · process_creation
Potential Credential Dumping Attempt Via PowerShell Remote Thread
highDetects remote thread creation by PowerShell processes into "lsass.exe"
windows · create_remote_thread
Potential Credential Dumping Via WER
highDetects potential credential dumping via Windows Error Reporting LSASS Shtinkering technique which uses the Windows Error Reporting to dump lsass
windows · process_creation
Potential Crypto Mining Activity
highDetects command line parameters or strings often used by crypto miners
windows · process_creation
Potential CSharp Streamer RAT Loading .NET Executable Image
highDetects potential CSharp Streamer RAT loading .NET executable image by using the default file name and path associated with the tool.
windows · image_load
Potential CVE-2021-26857 Exploitation Attempt
highDetects possible successful exploitation for vulnerability described in CVE-2021-26857 by looking for | abnormal subprocesses spawning by Exchange Server's Unified Messaging service
windows · process_creation
Potential CVE-2021-40444 Exploitation Attempt
highDetects potential exploitation of CVE-2021-40444 via suspicious process patterns seen in in-the-wild exploitations
windows · process_creation
Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon
highDetects potential initial exploitation attempts against VMware Horizon deployments running a vulnerable versions of Log4j.
windows · process_creation
Potential CVE-2022-26809 Exploitation Attempt
highDetects suspicious remote procedure call (RPC) service anomalies based on the spawned sub processes (long shot to detect the exploitation of vulnerabilities like CVE-2022-26809)
windows · process_creation
Potential CVE-2022-29072 Exploitation Attempt
highDetects potential exploitation attempts of CVE-2022-29072, a 7-Zip privilege escalation and command execution vulnerability. 7-Zip version 21.07 and earlier on Windows allows privilege escalation (CVE-2022-29072) and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process under the 7zFM.exe process.
windows · process_creation
Potential CVE-2023-21554 QueueJumper Exploitation
highDetects potential exploitation of CVE-2023-21554 (dubbed QueueJumper)
windows · process_creation
Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReader
highDetects suspicious ".hta" file creation in the startup folder by Foxit Reader. This can be an indication of CVE-2023-27363 exploitation.
windows · file_event
Potential CVE-2023-36874 Exploitation - Fake Wermgr Execution
highDetects the execution of a renamed "cmd", "powershell" or "powershell_ise" binary. Attackers were seen using these binaries in a renamed form as "wermgr.exe" in exploitation of CVE-2023-36874
windows · process_creation
Potential CVE-2023-36874 Exploitation - Fake Wermgr.Exe Creation
highDetects the creation of a file named "wermgr.exe" being created in an uncommon directory. This could be a sign of potential exploitation of CVE-2023-36874.
windows · file_event
Potential CVE-2023-36884 Exploitation - Share Access
highDetects access to a file share with a naming schema seen being used during exploitation of CVE-2023-36884
windows · security
Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI
highDetects potential exploitation of CVE-2026-33829, a vulnerability in the Windows Snipping Tool URI handler (ms-screensketch:). An attacker can abuse the 'filePath' parameter to supply a UNC path or HTTP URL, causing SnippingTool.exe to initiate a connection to a remote resource. When a UNC path is used (e.g. \\attacker.com\share), this triggers an outbound NTLM authentication attempt, allowing the attacker to capture or relay the victim's Net-NTLMv2 hash. HTTP-based paths may result in remote file loading or server-side request forgery (SSRF)-style access. The URI can be delivered via a malicious hyperlink, phishing email, or web page.
windows · process_creation
Potential Data Exfiltration Activity Via CommandLine Tools
highDetects the use of various CLI utilities exfiltrating data via web requests
windows · process_creation
Potential Data Stealing Via Chromium Headless Debugging
highDetects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control
windows · process_creation
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows · process_creation
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows · process_creation
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows · process_creation
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
highDetects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
windows · process_creation
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
highDetects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
windows · process_creation
Potential Defense Evasion Via Right-to-Left Override
highDetects the presence of the "u202+E" character, which causes a terminal, browser, or operating system to render text in a right-to-left sequence. This character is used as an obfuscation and masquerading techniques by adversaries to trick users into opening malicious files.
windows · process_creation
Potential Devil Bait Malware Reconnaissance
highDetects specific process behavior observed with Devil Bait samples
windows · process_creation
Potential Devil Bait Related Indicator
highDetects the creation of ".xml" and ".txt" files in folders of the "\AppData\Roaming\Microsoft" directory by uncommon processes. This behavior was seen common across different Devil Bait samples and stages as described by the NCSC
windows · file_event
Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
highDetects potential DLL side loading of "KeyScramblerIE.dll" by "KeyScrambler.exe". Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe".
windows · image_load
Potential DLL Sideloading Of Non-Existent DLLs From System Folders
highDetects loading of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes, potentially indicating phantom DLL hijacking attempts. Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs.
windows · image_load
Potential DLL Sideloading Via comctl32.dll
highDetects potential DLL sideloading using comctl32.dll to obtain system privileges
windows · image_load
Potential DLL Sideloading Via VMware Xfer
highDetects loading of a DLL by the VMware Xfer utility from the non-default directory which may be an attempt to sideload arbitrary DLL
windows · image_load
Potential EACore.DLL Sideloading
highDetects potential DLL sideloading of "EACore.dll"
windows · image_load
Potential Edputil.DLL Sideloading
highDetects potential DLL sideloading of "edputil.dll"
windows · image_load
Potential Emotet Activity
highDetects all Emotet like process executions that are not covered by the more generic rules
windows · process_creation
Potential EmpireMonkey Activity
highDetects potential EmpireMonkey APT activity
windows · process_creation
Potential EventLog File Location Tampering
highDetects tampering with EventLog service "file" key. In order to change the default location of an Evtx file. This technique is used to tamper with log collection and alerting
windows · registry_set
Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp
highDetects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.
windows · process_creation
Potential Exploitation Attempt From Office Application
highDetects Office applications executing a child process that includes directory traversal patterns. This could be an attempt to exploit CVE-2022-30190 (MSDT RCE) or CVE-2021-40444 (MSHTML RCE)
windows · process_creation
Potential Exploitation Attempt Of Undocumented WindowsServer RCE
highDetects potential exploitation attempt of undocumented Windows Server Pre Auth Remote Code Execution (RCE)
windows · process_creation
Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
highDetects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
windows · process_creation
Potential Exploitation of CVE-2024-37085 - Suspicious Creation Of ESX Admins Group
highDetects execution of the "net.exe" command in order to add a group named "ESX Admins". This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor. VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
windows · process_creation
Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity
highDetects any creation or modification to a windows domain group with the name "ESX Admins". This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor. VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
windows · security
Potential Exploitation of GoAnywhere MFT Vulnerability
highDetects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035. This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
windows · process_creation
Potential Exploitation of RCE Vulnerability CVE-2025-33053
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 which involves unauthorized code execution via WebDAV through external control of file names or paths. The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating their working directories to point to attacker-controlled WebDAV servers, causing them to execute malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries through Process.Start() search order manipulation.
windows · process_creation
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 by monitoring suspicious image loads from WebDAV paths. The exploit involves malicious executables from attacker-controlled WebDAV servers loading the Windows system DLLs like gdi32.dll, netapi32.dll, etc.
windows · image_load
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
highDetects potential exploitation of remote code execution vulnerability CVE-2025-33053 by looking for process access that involves legitimate Windows executables (iediagcmd.exe, CustomShellHost.exe) accessing suspicious executables hosted on WebDAV shares. This indicates an attacker may be exploiting Process.Start() search order manipulation to execute malicious code from attacker-controlled WebDAV servers instead of legitimate system binaries. The vulnerability allows unauthorized code execution through external control of file names or paths via WebDAV.
windows · process_access
Potential File Extension Spoofing Using Right-to-Left Override
highDetects suspicious filenames that contain a right-to-left override character and a potentially spoofed file extensions.
windows · file_event
Potential File Overwrite Via Sysinternals SDelete
highDetects the use of SDelete to erase a file not the free space
windows · process_creation
Potential Goofy Guineapig Backdoor Activity
highDetects a specific broken command that was used by Goofy-Guineapig as described by the NCSC report.
windows · process_creation
Potential Goofy Guineapig GoolgeUpdate Process Anomaly
highDetects "GoogleUpdate.exe" spawning a new instance of itself in an uncommon location as seen used by the Goofy Guineapig backdoor
windows · process_creation
Potential Invoke-Mimikatz PowerShell Script
highDetects Invoke-Mimikatz PowerShell script and alike. Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords.
windows · ps_script
Potential Iviewers.DLL Sideloading
highDetects potential DLL sideloading of "iviewers.dll" (OLE/COM Object Interface Viewer)
windows · image_load
Potential JLI.dll Side-Loading
highDetects potential DLL side-loading of jli.dll. JLI.dll has been observed being side-loaded by Java processes by various threat actors, including APT41, XWorm, and others in order to load malicious payloads in context of legitimate Java processes.
windows · image_load
Potential KamiKakaBot Activity - Winlogon Shell Persistence
highDetects changes to the "Winlogon" registry key where a process will set the value of the "Shell" to a value that was observed being used by KamiKakaBot samples in order to achieve persistence.
windows · registry_set
Potential Kapeka Decrypted Backdoor Indicator
highDetects the presence of a file that is decrypted backdoor binary dropped by the Kapeka Dropper, which disguises itself as a hidden file under a folder named "Microsoft" within "CSIDL_COMMON_APPDATA" or "CSIDL_LOCAL_APPDATA", depending on the process privileges. The file, typically 5-6 characters long with a random combination of consonants and vowels followed by a ".wll" extension to pose as a legitimate file to evade detection.
windows · file_event
Potential KDC RC4-HMAC Downgrade Exploit - CVE-2022-37966
highDetects the exploitation of a security bypass and elevation of privilege vulnerability with Authentication Negotiation by using weak RC4-HMAC negotiation
windows · system
Potential Ke3chang/TidePool Malware Activity
highDetects registry modifications potentially related to the Ke3chang/TidePool malware as seen in campaigns running in 2019 and 2020
windows · process_creation
Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation
highDetects modifications to DNS records in Active Directory where the Distinguished Name (DN) contains a base64-encoded blob matching the pattern "1UWhRCAAAAA...BAAAA". This pattern corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure, commonly used in Kerberos coercion attacks. Adversaries may exploit this to coerce victim systems into authenticating to attacker-controlled hosts by spoofing SPNs via DNS. It is one of the strong indicators of a Kerberos coercion attack,. where adversaries manipulate DNS records to spoof Service Principal Names (SPNs) and redirect authentication requests like CVE-2025-33073. Please investigate the user account that made the changes, as it is likely a low-privileged account that has been compromised.
windows · security
Potential LethalHTA Technique Execution
highDetects potential LethalHTA technique where the "mshta.exe" is spawned by an "svchost.exe" process
windows · process_creation
Potential LSASS Process Dump Via Procdump
highDetects potential credential harvesting attempts through LSASS memory dumps using ProcDump. This rule identifies suspicious command-line patterns that combine memory dump flags (-ma, -mm, -mp) with LSASS-related process markers. LSASS (Local Security Authority Subsystem Service) contains sensitive authentication data including plaintext passwords, NTLM hashes, and Kerberos tickets in memory. Attackers commonly dump LSASS memory to extract credentials for lateral movement and privilege escalation.
windows · process_creation
Potential Manage-bde.wsf Abuse To Proxy Execution
highDetects potential abuse of the "manage-bde.wsf" script as a LOLBIN to proxy execution
windows · process_creation
Potential Meterpreter/CobaltStrike Activity
highDetects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service starting
windows · process_creation
Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity
highDetects file indicators of potential exploitation of MOVEit CVE-2023-34362.
windows · file_event
Potential Mpclient.DLL Sideloading
highDetects potential sideloading of "mpclient.dll" by Windows Defender processes ("MpCmdRun" and "NisSrv") from their non-default directory.
windows · image_load
Potential Mpclient.DLL Sideloading Via Defender Binaries
highDetects potential sideloading of "mpclient.dll" by Windows Defender processes ("MpCmdRun" and "NisSrv") from their non-default directory.
windows · process_creation
Potential MsiExec Masquerading
highDetects the execution of msiexec.exe from an uncommon directory
windows · process_creation
Potential MSTSC Shadowing Activity
highDetects RDP session hijacking by using MSTSC shadowing
windows · process_creation
Potential MuddyWater APT Activity
highDetects potential Muddywater APT activity
windows · process_creation
Potential NetWire RAT Activity - Registry
highDetects registry keys related to NetWire RAT
windows · registry_add
Potential Notepad++ CVE-2025-49144 Exploitation
highDetects potential exploitation of CVE-2025-49144, a local privilege escalation vulnerability in Notepad++ installers (v8.8.1 and prior) where the installer calls regsvr32.exe without specifying the full path. This allows an attacker to execute arbitrary code with elevated privileges by placing a malicious regsvr32.exe alongside this Legitimate Notepad++ installer. The vulnerability is triggered when the installer attempts to register the NppShell.dll file, which is a component of Notepad++.
windows · process_creation
Potential NTLM Coercion Via Certutil.EXE
highDetects possible NTLM coercion via certutil using the 'syncwithWU' flag
windows · process_creation
Potential Persistence Via App Paths Default Property
highDetects changes to the "Default" property for keys located in the \Software\Microsoft\Windows\CurrentVersion\App Paths\ registry. Which might be used as a method of persistence The entries found under App Paths are used primarily for the following purposes. First, to map an application's executable file name to that file's fully qualified path. Second, to prepend information to the PATH environment variable on a per-application, per-process basis.
windows · registry_set
Potential Persistence Via AutodialDLL
highDetects change the the "AutodialDLL" key which could be used as a persistence method to load custom DLL via the "ws2_32" library
windows · registry_set
Potential Persistence Via CHM Helper DLL
highDetects when an attacker modifies the registry key "HtmlHelp Author" to achieve persistence
windows · registry_set
Potential Persistence Via DLLPathOverride
highDetects when an attacker adds a new "DLLPathOverride" value to the "Natural Language" key in order to achieve persistence which will get invoked by "SearchIndexer.exe" process
windows · registry_set
Potential Persistence Via Excel Add-in - Registry
highDetect potential persistence via the creation of an excel add-in (XLL) file to make it run automatically when Excel is started.
windows · registry_set
Potential Persistence Via GlobalFlags
highDetects registry persistence technique using the GlobalFlags and SilentProcessExit keys
windows · registry_set
Potential Persistence Via Logon Scripts - CommandLine
highDetects the addition of a new LogonScript to the registry value "UserInitMprLogonScript" for potential persistence
windows · process_creation
Potential Persistence Via LSA Extensions
highDetects when an attacker modifies the "REG_MULTI_SZ" value named "Extensions" to include a custom DLL to achieve persistence via lsass. The "Extensions" list contains filenames of DLLs being automatically loaded by lsass.exe. Each DLL has its InitializeLsaExtension() method called after loading.
windows · registry_set
Potential Persistence Via Microsoft Office Add-In
highDetects potential persistence activity via startup add-ins that load when Microsoft Office starts (.wll/.xll are simply .dll fit for Word or Excel).
windows · file_event
Potential Persistence Via Microsoft Office Startup Folder
highDetects creation of Microsoft Office files inside of one of the default startup folders in order to achieve persistence.
windows · file_event
Potential Persistence Via Mpnotify
highDetects when an attacker register a new SIP provider for persistence and defense evasion
windows · registry_set
Potential Persistence Via MyComputer Registry Keys
highDetects modification to the "Default" value of the "MyComputer" key and subkeys to point to a custom binary that will be launched whenever the associated action is executed (see reference section for example)
windows · registry_set
Potential Persistence Via Outlook Form
highDetects the creation of a new Outlook form which can contain malicious code
windows · file_event
Potential Persistence Via Outlook Home Page
highDetects potential persistence activity via outlook home page. An attacker can set a home page to achieve code execution and persistence by editing the WebView registry keys.
windows · registry_set
Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
highDetects the modification of Outlook setting "LoadMacroProviderOnBoot" which if enabled allows the automatic loading of any configured VBA project/module
windows · registry_set
Potential Persistence Via Outlook Today Page
highDetects potential persistence activity via outlook today page. An attacker can set a custom page to execute arbitrary code and link to it via the registry values "URL" and "UserDefinedUrl".
windows · registry_set
Potential Persistence Via Powershell Search Order Hijacking - Task
highDetects suspicious powershell execution via a schedule task where the command ends with an suspicious flags to hide the powershell instance instead of executeing scripts or commands. This could be a sign of persistence via PowerShell "Get-Variable" technique as seen being used in Colibri Loader
windows · process_creation
Potential Persistence Via Security Descriptors - ScriptBlock
highDetects usage of certain functions and keywords that are used to manipulate security descriptors in order to potentially set a backdoor. As seen used in the DAMP project.
windows · ps_script
Potential Persistence Via Shim Database In Uncommon Location
highDetects the installation of a new shim database where the file is located in a non-default location
windows · registry_set
Potential Persistence Via TypedPaths
highDetects modification addition to the 'TypedPaths' key in the user or admin registry from a non standard application. Which might indicate persistence attempt
windows · registry_set
Potential Pikabot C2 Activity
highDetects the execution of rundll32 that leads to an external network connection. The malware Pikabot has been seen to use this technique to initiate C2-communication through hard-coded Windows binaries.
windows · network_connection
Potential Pikabot Discovery Activity
highDetects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups. The malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).
windows · process_creation
Potential Pikabot Hollowing Activity
highDetects the execution of rundll32 that leads to the invocation of legitimate Windows binaries. The malware Pikabot has been seen to use this technique for process hollowing through hard-coded Windows binaries
windows · process_creation
Potential PlugX Activity
highDetects the execution of an executable that is typically used by PlugX for DLL side loading starting from an uncommon location
windows · process_creation
Potential PowerShell Command Line Obfuscation
highDetects the PowerShell command lines with special characters
windows · process_creation
Potential PowerShell Execution Policy Tampering - ProcCreation
highDetects changes to the PowerShell execution policy registry key in order to bypass signing requirements for script execution from the CommandLine
windows · process_creation
Potential PowerShell Execution Via DLL
highDetects potential PowerShell execution from a DLL instead of the usual PowerShell process as seen used in PowerShdll. This detection assumes that PowerShell commands are passed via the CommandLine.
windows · process_creation
Potential PowerShell Obfuscation Via Reversed Commands
highDetects the presence of reversed PowerShell commands in the CommandLine. This is often used as a method of obfuscation by attackers
windows · process_creation
Potential PowerShell Obfuscation Via WCHAR/CHAR
highDetects suspicious encoded character syntax often used for defense evasion
windows · process_creation
Potential Powershell ReverseShell Connection
highDetects usage of the "TcpClient" class. Which can be abused to establish remote connections and reverse-shells. As seen used by the Nishang "Invoke-PowerShellTcpOneLine" reverse shell and other.
windows · process_creation
Potential POWERTRASH Script Execution
highDetects potential execution of the PowerShell script POWERTRASH
windows · ps_script
Potential PrintNightmare Exploitation Attempt
highDetect DLL deletions from Spooler Service driver folder. This might be a potential exploitation attempt of CVE-2021-1675
windows · file_delete
Potential Privilege Escalation Attempt Via .Exe.Local Technique
highDetects potential privilege escalation attempt via the creation of the "*.Exe.Local" folder inside the "System32" directory in order to sideload "comctl32.dll"
windows · file_event
Potential Privilege Escalation To LOCAL SYSTEM
highDetects unknown program using commandline flags usually used by tools such as PsExec and PAExec to start programs with SYSTEM Privileges
windows · process_creation
Potential Privilege Escalation Using Symlink Between Osk and Cmd
highDetects the creation of a symbolic link between "cmd.exe" and the accessibility on-screen keyboard binary (osk.exe) using "mklink". This technique provides an elevated command prompt to the user from the login screen without the need to log in.
windows · process_creation
Potential Privilege Escalation via Local Kerberos Relay over LDAP
highDetects a suspicious local successful logon event where the Logon Package is Kerberos, the remote address is set to localhost, and the target user SID is the built-in local Administrator account. This may indicate an attempt to leverage a Kerberos relay attack variant that can be used to elevate privilege locally from a domain joined limited user to local System privileges.
windows · security
Potential Privilege Escalation via Service Permissions Weakness
highDetect modification of services configuration (ImagePath, FailureCommand and ServiceDLL) in registry by processes with Medium integrity level
windows · process_creation
Potential Process Injection Via Msra.EXE
highDetects potential process injection via Microsoft Remote Asssistance (Msra.exe) by looking at suspicious child processes spawned from the aforementioned process. It has been a target used by many threat actors and used for discovery and persistence tactics
windows · process_creation
Potential Provisioning Registry Key Abuse For Binary Proxy Execution
highDetects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".
windows · process_creation
Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
highDetects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".
windows · registry_set
Potential PsExec Remote Execution
highDetects potential psexec command that initiate execution on a remote systems via common commandline flags used by the utility
windows · process_creation
Potential PSFactoryBuffer COM Hijacking
highDetects changes to the PSFactory COM InProcServer32 registry. This technique was used by RomCom to create persistence storing a malicious DLL.
windows · registry_set
Potential Qakbot Registry Activity
highDetects a registry key used by IceID in a campaign that distributes malicious OneNote files
windows · registry_event
Potential Qakbot Rundll32 Execution
highDetects specific process tree behavior of a "rundll32" execution often linked with potential Qakbot activity.
windows · process_creation
Potential Ransomware Activity Using LegalNotice Message
highDetect changes to the "LegalNoticeCaption" or "LegalNoticeText" registry values where the message set contains keywords often used in ransomware ransom messages
windows · registry_set
Potential Raspberry Robin Aclui Dll SideLoading
highDetects potential sideloading of malicious "aclui.dll" by OleView.This behavior was observed in Raspberry-Robin variants reported by chekpoint research on Feburary 2024.
windows · image_load
Potential Raspberry Robin CPL Execution Activity
highDetects the execution of a ".CPL" file located in the user temp directory via the Shell32 DLL "Control_RunDLL" export function. This behavior was observed in multiple Raspberry-Robin variants.
windows · process_creation
Potential Raspberry Robin Dot Ending File
highDetects commandline containing reference to files ending with a "." This scheme has been seen used by raspberry-robin
windows · process_creation
Potential Rcdll.DLL Sideloading
highDetects potential DLL sideloading of rcdll.dll
windows · image_load
Potential RDP Tunneling Via Plink
highExecution of plink to perform data exfiltration and tunneling
windows · process_creation
Potential RDP Tunneling Via SSH
highExecution of ssh.exe to perform data exfiltration and tunneling through RDP
windows · process_creation
Potential Recon Activity Using DriverQuery.EXE
highDetect usage of the "driverquery" utility to perform reconnaissance on installed drivers
windows · process_creation
Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE
highDetects usage of cmdkey to look for cached credentials on the system
windows · process_creation
Potential Registry Persistence Attempt Via Windows Telemetry
highDetects potential persistence behavior using the windows telemetry registry key. Windows telemetry makes use of the binary CompatTelRunner.exe to run a variety of commands and perform the actual telemetry collections. This binary was created to be easily extensible, and to that end, it relies on the registry to instruct on which commands to run. The problem is, it will run any arbitrary command without restriction of location or type.
windows · registry_set
Potential Remote PowerShell Session Initiated
highDetects a process that initiated a network connection over ports 5985 or 5986 from a non-network service account. This could potentially indicates a remote PowerShell connection.
windows · network_connection
Potential Remote SquiblyTwo Technique Execution
highDetects potential execution of the SquiblyTwo technique that leverages Windows Management Instrumentation (WMI) to execute malicious code remotely. This technique bypasses application whitelisting by using wmic.exe to process malicious XSL (eXtensible Stylesheet Language) scripts that can contain embedded JScript or VBScript. The attack typically works by fetching XSL content from a remote source (using HTTP/HTTPS) and executing it with full trust privileges directly in memory, avoiding disk-based detection mechanisms. This is a common LOLBin (Living Off The Land Binary) technique used for defense evasion and code execution.
windows · process_creation
Potential RemoteFXvGPUDisablement.EXE Abuse
highDetects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.
windows · powershell-classic
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
highDetects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.
windows · ps_module
Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
highDetects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.
windows · ps_script
Potential Renamed Rundll32 Execution
highDetects when 'DllRegisterServer' is called in the commandline and the image is not rundll32. This could mean that the 'rundll32' utility has been renamed in order to avoid detection
windows · process_creation
Potential RipZip Attack on Startup Folder
highDetects a phishing attack which expands a ZIP file containing a malicious shortcut. If the victim expands the ZIP file via the explorer process, then the explorer process expands the malicious ZIP file and drops a malicious shortcut redirected to a backdoor into the Startup folder. Additionally, the file name of the malicious shortcut in Startup folder contains {0AFACED1-E828-11D1-9187-B532F1E9575D} meaning the folder shortcut operation.
windows · file_event
Potential RjvPlatform.DLL Sideloading From Non-Default Location
highDetects potential DLL sideloading of "RjvPlatform.dll" by "SystemResetPlatform.exe" located in a non-default location.
windows · image_load
Potential Rundll32 Execution With DLL Stored In ADS
highDetects execution of rundll32 where the DLL being called is stored in an Alternate Data Stream (ADS).
windows · process_creation
Potential Ryuk Ransomware Activity
highDetects Ryuk ransomware activity
windows · process_creation
Potential SAM Database Dump
highDetects the creation of files that look like exports of the local SAM (Security Account Manager)
windows · file_event
Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
highDetects potential exploitation of CVE-2025-53770 by identifying indicators such as suspicious command lines discovered in Post-Exploitation activities. CVE-2025-53770 is a zero-day vulnerability in SharePoint that allows remote code execution.
windows · process_creation
Potential Signing Bypass Via Windows Developer Features
highDetects when a user enable developer features such as "Developer Mode" or "Application Sideloading". Which allows the user to install untrusted packages.
windows · process_creation
Potential Signing Bypass Via Windows Developer Features - Registry
highDetects when the enablement of developer features such as "Developer Mode" or "Application Sideloading". Which allows the user to install untrusted packages.
windows · registry_set
Potential SmadHook.DLL Sideloading
highDetects potential DLL sideloading of "SmadHook.dll", a DLL used by SmadAV antivirus
windows · image_load
Potential SNAKE Malware Installation Binary Indicator
highDetects a specific binary name seen used by SNAKE malware during its installation as described by CISA in their report
windows · process_creation
Potential SNAKE Malware Installation CLI Arguments Indicator
highDetects a specific command line arguments sequence seen used by SNAKE malware during its installation as described by CISA in their report
windows · process_creation
Potential SNAKE Malware Persistence Service Execution
highDetects a specific child/parent process relationship indicative of a "WerFault" process running from the "WinSxS" as a service. This could be indicative of potential SNAKE malware activity as reported by CISA.
windows · process_creation
Potential Snatch Ransomware Activity
highDetects specific process characteristics of Snatch ransomware word document droppers
windows · process_creation
Potential SocGholish Second Stage C2 DNS Query
highDetects a DNS query initiated from a "wscript" process for domains matching a specific pattern that was seen being used by SocGholish for its Command and Control traffic
windows · dns_query
Potential SSH Tunnel Persistence Install Using A Scheduled Task
highDetects the creation of new scheduled tasks via commandline, using Schtasks.exe. This rule detects tasks creating that call OpenSSH, which may indicate the creation of reverse SSH tunnel to the attacker's server.
windows · process_creation
Potential Startup Shortcut Persistence Via PowerShell.EXE
highDetects PowerShell writing startup shortcuts. This procedure was highlighted in Red Canary Intel Insights Oct. 2021, "We frequently observe adversaries using PowerShell to write malicious .lnk files into the startup directory to establish persistence. Accordingly, this detection opportunity is likely to identify persistence mechanisms in multiple threats. In the context of Yellow Cockatoo, this persistence mechanism eventually launches the command-line script that leads to the installation of a malicious DLL"
windows · file_event
Potential Suspicious Child Process Of 3CXDesktopApp
highDetects potential suspicious child processes of "3CXDesktopApp.exe". Which could be related to the 3CXDesktopApp supply chain compromise
windows · process_creation
Potential Suspicious Winget Package Installation
highDetects potential suspicious winget package installation from a suspicious source.
windows · create_stream_hash
Potential SysInternals ProcDump Evasion
highDetects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name
windows · process_creation
Potential System DLL Sideloading From Non System Locations
highDetects DLL sideloading of DLLs usually located in system locations (System32, SysWOW64, etc.).
windows · image_load
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
highDetects the execution of "reg.exe" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\Control\Terminal Server' values
windows · process_creation
Potential Tampering With Security Products Via WMIC
highDetects uninstallation or termination of security products using the WMIC utility
windows · process_creation
Potential Ursnif Malware Activity - Registry
highDetects registry keys related to Ursnif malware.
windows · registry_add
Potential Vcruntime140 DLL Sideloading
highDetects potential DLL sideloading of vcruntime140.dll, a common C++ runtime library. Threat actors have been observed using DLL sideloading techniques to load malicious payloads under the guise of legitimate applications such as SqlWriter, SqlDumper etc. Notably, APT29 has been documented leveraging WinELOADER to sideload vcruntime140.dll for executing malicious code.
windows · image_load
Potential Waveedit.DLL Sideloading
highDetects potential DLL sideloading of "waveedit.dll", which is part of the Nero WaveEditor audio editing software.
windows · image_load
Potential WerFault ReflectDebugger Registry Value Abuse
highDetects potential WerFault "ReflectDebugger" registry value abuse for persistence.
windows · registry_set
Potential WinAPI Calls Via CommandLine
highDetects the use of WinAPI Functions via the commandline. As seen used by threat actors via the tool winapiexec
windows · process_creation
Potential WinAPI Calls Via PowerShell Scripts
highDetects usage of WinAPI functions in PowerShell scripts. It may indicate attempts to perform actions such as process injection, token stealing, or other malicious activities that leverage Windows API calls. These techniques are commonly used to evade traditional file-based detections by loading and executing code directly in memory.
windows · ps_script
Potential Windows Defender AV Bypass Via Dump64.EXE Rename
highDetects when a user is potentially trying to bypass the Windows Defender AV by renaming a tool to dump64.exe and placing it in the Visual Studio folder. Currently the rule is covering only usage of procdump but other utilities can be added in order to increase coverage.
windows · process_creation
Potential Windows Defender Tampering Via Wmic.EXE
highDetects potential tampering with Windows Defender settings such as adding exclusion using wmic
windows · process_creation
Potential Winnti Dropper Activity
highDetects files dropped by Winnti as described in RedMimicry Winnti playbook
windows · file_event
Potential Zerologon (CVE-2020-1472) Exploitation
highDetects potential Netlogon Elevation of Privilege Vulnerability aka Zerologon (CVE-2020-1472)
windows · security
Potentially Suspicious ASP.NET Compilation Via AspNetCompiler
highDetects execution of "aspnet_compiler.exe" with potentially suspicious paths for compilation.
windows · process_creation
Potentially Suspicious Call To Win32_NTEventlogFile Class
highDetects usage of the WMI class "Win32_NTEventlogFile" in a potentially suspicious way (delete, backup, change permissions, etc.) from a PowerShell script
windows · process_creation
Potentially Suspicious Child Process Of Regsvr32
highDetects potentially suspicious child processes of "regsvr32.exe".
windows · process_creation
Potentially Suspicious Child Processes Spawned by ConHost
highDetects suspicious child processes related to Windows Shell utilities spawned by `conhost.exe`, which could indicate malicious activity using trusted system components.
windows · process_creation
Potentially Suspicious Command Executed Via Run Dialog Box - Registry
highDetects execution of commands via the run dialog box on Windows by checking values of the "RunMRU" registry key. This technique was seen being abused by threat actors to deceive users into pasting and executing malicious commands, often disguised as CAPTCHA verification steps.
windows · registry_set
Potentially Suspicious DLL Registered Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "REGSVR" action where the DLL in question doesn't contain a ".dll" extension. Which is often used as a method to evade defenses.
windows · process_creation
Potentially Suspicious Event Viewer Child Process
highDetects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt
windows · process_creation
Potentially Suspicious Execution From Parent Process In Public Folder
highDetects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.
windows · process_creation
Potentially Suspicious File Download From File Sharing Domain Via PowerShell.EXE
highDetects potentially suspicious file downloads from file sharing domains using PowerShell.exe
windows · process_creation
Potentially Suspicious File Download From ZIP TLD
highDetects the download of a file with a potentially suspicious extension from a .zip top level domain.
windows · create_stream_hash
Potentially Suspicious GoogleUpdate Child Process
highDetects potentially suspicious child processes of "GoogleUpdate.exe"
windows · process_creation
Potentially Suspicious Malware Callback Communication
highDetects programs that connect to known malware callback ports based on statistical analysis from two different sandbox system databases
windows · network_connection
Potentially Suspicious Mofcomp Execution
highDetects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline. The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Attackers abuse this utility to install malicious MOF scripts
windows · process_creation
Potentially Suspicious ODBC Driver Registered
highDetects the registration of a new ODBC driver where the driver is located in a potentially suspicious location
windows · registry_set
Potentially Suspicious Office Document Executed From Trusted Location
highDetects the execution of an Office application that points to a document that is located in a trusted location. Attackers often used this to avoid macro security and execute their malicious code.
windows · process_creation
Potentially Suspicious Regsvr32 HTTP IP Pattern
highDetects regsvr32 execution to download and install DLLs located remotely where the address is an IP address.
windows · process_creation
Powershell Add Name Resolution Policy Table Rule
highDetects powershell scripts that adds a Name Resolution Policy Table (NRPT) rule for the specified namespace. This will bypass the default DNS server and uses a specified server for answering the query.
windows · ps_script
PowerShell ADRecon Execution
highDetects execution of ADRecon.ps1 for AD reconnaissance which has been reported to be actively used by FIN7
windows · ps_script
PowerShell as a Service in Registry
highDetects that a powershell code is written to the registry as a service.
windows · registry_set
PowerShell Base64 Encoded FromBase64String Cmdlet
highDetects usage of a base64 encoded "FromBase64String" cmdlet in a process command line
windows · process_creation
PowerShell Base64 Encoded IEX Cmdlet
highDetects usage of a base64 encoded "IEX" cmdlet in a process command line
windows · process_creation
PowerShell Base64 Encoded Invoke Keyword
highDetects UTF-8 and UTF-16 Base64 encoded powershell 'Invoke-' calls
windows · process_creation
Powershell Base64 Encoded MpPreference Cmdlet
highDetects base64 encoded "MpPreference" PowerShell cmdlet code that tries to modifies or tamper with Windows Defender AV
windows · process_creation
PowerShell Base64 Encoded Reflective Assembly Load
highDetects base64 encoded .NET reflective loading of Assembly
windows · process_creation
PowerShell Base64 Encoded WMI Classes
highDetects calls to base64 encoded WMI class such as "Win32_ShadowCopy", "Win32_ScheduledJob", etc.
windows · process_creation
PowerShell Called from an Executable Version Mismatch
highDetects PowerShell called from an executable by the version mismatch method
windows · ps_classic_start
PowerShell Credential Prompt
highDetects PowerShell calling a credential prompt
windows · ps_script
Powershell Defender Disable Scan Feature
highDetects requests to disable Microsoft Defender features using PowerShell commands
windows · process_creation
PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
highDetects the use of PowerShell to execute the 'Set-MpPreference' cmdlet to configure Windows Defender's threat severity default action to 'Allow' (value '6') or 'NoAction' (value '9'). This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level. An attacker might use this technique via the command line to bypass defenses before executing payloads.
windows · process_creation
Powershell DNSExfiltration
highDNSExfiltrator allows for transferring (exfiltrate) a file over a DNS request covert channel
windows · ps_script
PowerShell Download and Execution Cradles
highDetects PowerShell download and execution cradles.
windows · process_creation
PowerShell Execution With Potential Decryption Capabilities
highDetects PowerShell commands that decrypt an ".LNK" "file to drop the next stage of the malware.
windows · process_creation
PowerShell Get-Process LSASS
highDetects a "Get-Process" cmdlet and it's aliases on lsass process, which is in almost all cases a sign of malicious activity
windows · process_creation
PowerShell Get-Process LSASS in ScriptBlock
highDetects a Get-Process command on lsass process, which is in almost all cases a sign of malicious activity
windows · ps_script
Powershell Install a DLL in System Directory
highUses PowerShell to install/copy a file into a system directory such as "System32" or "SysWOW64"
windows · ps_script
PowerShell Logging Disabled Via Registry Key Tampering
highDetects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging
windows · registry_set
PowerShell PSAttack
highDetects the use of PSAttack PowerShell hack tool
windows · ps_script
PowerShell SAM Copy
highDetects suspicious PowerShell scripts accessing SAM hives
windows · process_creation
PowerShell Script Change Permission Via Set-Acl
highDetects PowerShell execution to set the ACL of a file or a folder
windows · process_creation
PowerShell Scripts Installed as Services
highDetects powershell script installed as a Service
windows · system
PowerShell Scripts Installed as Services - Security
highDetects powershell script installed as a Service
windows · security
PowerShell Set-Acl On Windows Folder
highDetects PowerShell scripts to set the ACL to a file in the Windows folder
windows · process_creation
PowerShell Set-Acl On Windows Folder - PsScript
highDetects PowerShell scripts to set the ACL to a file in the Windows folder
windows · ps_script
PowerShell ShellCode
highDetects Base64 encoded Shellcode
windows · ps_script
Powershell Token Obfuscation - Process Creation
highDetects TOKEN OBFUSCATION technique from Invoke-Obfuscation
windows · process_creation
PowerShell Web Access Feature Enabled Via DISM
highDetects the use of DISM to enable the PowerShell Web Access feature, which could be used for remote access and potential abuse
windows · process_creation
PowerShell Web Access Installation - PsScript
highDetects the installation and configuration of PowerShell Web Access, which could be used for remote access and potential abuse
windows · ps_script
Powerview Add-DomainObjectAcl DCSync AD Extend Right
highBackdooring domain object to grant the rights associated with DCSync to a regular user or machine account using Powerview\Add-DomainObjectAcl DCSync Extended Right cmdlet, will allow to re-obtain the pwd hashes of any user/computer
windows · security
PowerView PowerShell Cmdlets - ScriptBlock
highDetects Cmdlet names from PowerView of the PowerSploit exploitation framework.
windows · ps_script
PPL Tampering Via WerFaultSecure
highDetects potential abuse of WerFaultSecure.exe to dump Protected Process Light (PPL) processes like LSASS or to freeze security solutions (EDR/antivirus). This technique is used by tools such as EDR-Freeze and WSASS to bypass PPL protections and access sensitive information or disable security software. Distinct command line patterns help identify the specific tool: - WSASS usage typically shows: "WSASS.exe WerFaultSecure.exe [PID]" in ParentCommandLine - EDR-Freeze usage typically shows: "EDR-Freeze_[version].exe [PID] [timeout]" in ParentCommandLine Legitimate debugging operations using WerFaultSecure are rare in production environments and should be investigated.
windows · process_creation
Prefetch File Deleted
highDetects the deletion of a prefetch file which may indicate an attempt to destroy forensic evidence
windows · file_delete
PrintBrm ZIP Creation of Extraction
highDetects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.
windows · process_creation
Privilege Escalation via Named Pipe Impersonation
highDetects a remote file copy attempt to a hidden network share. This may indicate lateral movement or data staging activity.
windows · process_creation
Process Access via TrolleyExpress Exclusion
highDetects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory
windows · process_creation
Process Execution From A Potentially Suspicious Folder
highDetects a potentially suspicious execution from an uncommon folder.
windows · process_creation
Process Explorer Driver Creation By Non-Sysinternals Binary
highDetects creation of the Process Explorer drivers by processes other than Process Explorer (procexp) itself. Hack tools or malware may use the Process Explorer driver to elevate privileges, drops it to disk for a few moments, runs a service using that driver and removes it afterwards.
windows · file_event
Process Initiated Network Connection To Ngrok Domain
highDetects an executable initiating a network connection to "ngrok" domains. Attackers were seen using this "ngrok" in order to store their second stage payloads and malware. While communication with such domains can be legitimate, often times is a sign of either data exfiltration by malicious actors or additional download.
windows · network_connection
Process Memory Dump Via Comsvcs.DLL
highDetects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)
windows · process_creation
Process Memory Dump via RdrLeakDiag.EXE
highDetects the use of the Microsoft Windows Resource Leak Diagnostic tool "rdrleakdiag.exe" to dump process memory
windows · process_creation
ProcessHacker Privilege Elevation
highDetects a ProcessHacker tool that elevated privileges to a very high level
windows · system
Protected Storage Service Access
highDetects access to a protected_storage service over the network. Potential abuse of DPAPI to extract domain backup keys from Domain Controllers
windows · security
Proxy Execution Via Wuauclt.EXE
highDetects the use of the Windows Update Client binary (wuauclt.exe) for proxy execution.
windows · process_creation
Ps.exe Renamed SysInternals Tool
highDetects renamed SysInternals tool execution with a binary named ps.exe as used by Dragonfly APT group and documented in TA17-293A report
windows · process_creation
PSAsyncShell - Asynchronous TCP Reverse Shell
highDetects the use of PSAsyncShell an Asynchronous TCP Reverse Shell written in powershell
windows · ps_script
PSExec and WMI Process Creations Block
highDetects blocking of process creations originating from PSExec and WMI commands
windows · windefend
PSEXEC Remote Execution File Artefact
highDetects creation of the PSEXEC key file. Which is created anytime a PsExec command is executed. It gets written to the file system and will be recorded in the USN Journal on the target system
windows · file_event
PsExec Service Child Process Execution as LOCAL SYSTEM
highDetects suspicious launch of the PSEXESVC service on this system and a sub process run as LOCAL_SYSTEM (-s), which means that someone remotely started a command on this system running it with highest privileges and not only the privileges of the login user account (e.g. the administrator account)
windows · process_creation
PsExec/PAExec Escalation to LOCAL SYSTEM
highDetects suspicious commandline flags used by PsExec and PAExec to escalate a command line to LOCAL_SYSTEM rights
windows · process_creation
PUA - 3Proxy Execution
highDetects the use of 3proxy, a tiny free proxy server
windows · process_creation
PUA - AdFind Suspicious Execution
highDetects AdFind execution with common flags seen used during attacks
windows · process_creation
PUA - AdvancedRun Suspicious Execution
highDetects the execution of AdvancedRun utility in the context of the TrustedInstaller, SYSTEM, Local Service or Network Service accounts
windows · process_creation
PUA - Chisel Tunneling Tool Execution
highDetects usage of the Chisel tunneling tool via the commandline arguments
windows · process_creation
PUA - CleanWipe Execution
highDetects the use of CleanWipe a tool usually used to delete Symantec antivirus.
windows · process_creation
PUA - Crassus Execution
highDetects Crassus, a Windows privilege escalation discovery tool, based on PE metadata characteristics.
windows · process_creation
PUA - CsExec Execution
highDetects the use of the lesser known remote execution tool named CsExec a PsExec alternative
windows · process_creation
PUA - DefenderCheck Execution
highDetects the use of DefenderCheck, a tool to evaluate the signatures used in Microsoft Defender. It can be used to figure out the strings / byte chains used in Microsoft Defender to detect a tool and thus used for AV evasion.
windows · process_creation
PUA - DIT Snapshot Viewer
highDetects the use of Ditsnap tool, an inspection tool for Active Directory database, ntds.dit.
windows · process_creation
PUA - Fast Reverse Proxy (FRP) Execution
highDetects the use of Fast Reverse Proxy. frp is a fast reverse proxy to help you expose a local server behind a NAT or firewall to the Internet.
windows · process_creation
PUA - Kernel Driver Utility (KDU) Execution
highDetects execution of the Kernel Driver Utility (KDU) tool. KDU can be used to bypass driver signature enforcement and load unsigned or malicious drivers into the Windows kernel. Potentially allowing for privilege escalation, persistence, or evasion of security controls.
windows · process_creation
PUA - Memory Dump Mount Via MemProcFS
highDetects execution of MemProcFS a memory forensics tool with the '-device' parameter. MemProcFS mounts physical memory as a virtual file system, allowing direct access to process memory and system structures. Threat actors were seen abusing this utility to mount memory dumps and then extract sensitive information from processes like LSASS or extract registry hives to obtain credentials, LSA secrets, SAM data, and cached domain credentials. MemProcFS usage that is not part of authorized forensic analysis should be treated as suspicious and warrants further investigation.
windows · process_creation
PUA - Netcat Suspicious Execution
highDetects execution of Netcat. Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
windows · process_creation
PUA - Ngrok Execution
highDetects the use of Ngrok, a utility used for port forwarding and tunneling, often used by threat actors to make local protected services publicly available. Involved domains are bin.equinox.io for download and *.ngrok.io for connections.
windows · process_creation
PUA - Nimgrab Execution
highDetects the usage of nimgrab, a tool bundled with the Nim programming framework and used for downloading files.
windows · process_creation
PUA - NirCmd Execution As LOCAL SYSTEM
highDetects the use of NirCmd tool for command execution as SYSTEM user
windows · process_creation
PUA - NPS Tunneling Tool Execution
highDetects the use of NPS, a port forwarding and intranet penetration proxy server
windows · process_creation
PUA - NSudo Execution
highDetects the use of NSudo tool for command execution
windows · process_creation
PUA - PingCastle Execution From Potentially Suspicious Parent
highDetects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level via a script located in a potentially suspicious or uncommon location.
windows · process_creation
PUA - Process Hacker Driver Load
highDetects driver load of the Process Hacker tool
windows · driver_load
PUA - Rclone Execution
highDetects execution of RClone utility for exfiltration as used by various ransomwares strains like REvil, Conti, FiveHands, etc
windows · process_creation
PUA - Restic Backup Tool Execution
highDetects the execution of the Restic backup tool, which can be used for data exfiltration. Threat actors may leverage Restic to back up and exfiltrate sensitive data to remote storage locations, including cloud services. If not legitimately used in the enterprise environment, its presence may indicate malicious activity.
windows · process_creation
PUA - RunXCmd Execution
highDetects the use of the RunXCmd tool to execute commands with System or TrustedInstaller accounts
windows · process_creation
PUA - Seatbelt Execution
highDetects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters
windows · process_creation
PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE
highDetects active directory enumeration activity using known AdFind CLI flags
windows · process_creation
PUA - Wsudo Suspicious Execution
highDetects usage of wsudo (Windows Sudo Utility). Which is a tool that let the user execute programs with different permissions (System, Trusted Installer, Administrator...etc)
windows · process_creation
PUA- IOX Tunneling Tool Execution
highDetects the use of IOX - a tool for port forwarding and intranet proxy purposes
windows · process_creation
Python Function Execution Security Warning Disabled In Excel
highDetects changes to the registry value "PythonFunctionWarnings" that would prevent any warnings or alerts from showing when Python functions are about to be executed. Threat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.
windows · process_creation
Python Function Execution Security Warning Disabled In Excel - Registry
highDetects changes to the registry value "PythonFunctionWarnings" that would prevent any warnings or alerts from showing when Python functions are about to be executed. Threat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.
windows · registry_set
Python One-Liners with Base64 Decoding
highDetects Python one-liners that use base64 decoding functions in command line executions. Malicious scripts or attackers often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.
windows · process_creation
Python Spawning Pretty TTY on Windows
highDetects python spawning a pretty tty
windows · process_creation
Qakbot Regsvr32 Calc Pattern
highDetects a specific command line of "regsvr32" where the "calc" keyword is used in conjunction with the "/s" flag. This behavior is often seen used by Qakbot
windows · process_creation
Qakbot Uninstaller Execution
highDetects the execution of the Qakbot uninstaller file mentioned in the USAO-CDCA document on the disruption of the Qakbot malware and botnet
windows · process_creation
Query Tor Onion Address - DNS Client
highDetects DNS resolution of an .onion address related to Tor routing networks
windows · dns-client
Raccine Uninstall
highDetects commands that indicate a Raccine removal from an end system. Raccine is a free ransomware protection tool.
windows · process_creation
Rar Usage with Password and Compression Level
highDetects the use of rar.exe, on the command line, to create an archive with password protection or with a specific compression level. This is pretty indicative of malicious actions.
windows · process_creation
Rare Remote Thread Creation By Uncommon Source Image
highDetects uncommon processes creating remote threads.
windows · create_remote_thread
Raspberry Robin Initial Execution From External Drive
highDetects the initial execution of the Raspberry Robin malware from an external drive using "Cmd.EXE".
windows · process_creation
Raspberry Robin Subsequent Execution of Commands
highDetects raspberry robin subsequent execution of commands.
windows · process_creation
RDP Connection Allowed Via Netsh.EXE
highDetects usage of the netsh command to open and allow connections to port 3389 (RDP). As seen used by Sarwent Malware
windows · process_creation
RDP Login from Localhost
highRDP login with localhost source address may be a tunnelled login
windows · security
RDP Over Reverse SSH Tunnel
highDetects svchost hosting RDP termsvcs communicating with the loopback address and on TCP port 3389
windows · network_connection
RDP over Reverse SSH Tunnel WFP
highDetects svchost hosting RDP termsvcs communicating with the loopback address
windows · security
RDP Port Forwarding Rule Added Via Netsh.EXE
highDetects the execution of netsh to configure a port forwarding of port 3389 (RDP) rule
windows · process_creation
RDP Sensitive Settings Changed
highDetects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc. Below is a list of registry keys/values that are monitored by this rule: - Shadow: Used to enable Remote Desktop shadowing, which allows an administrator to view or control a user's session. - DisableRemoteDesktopAntiAlias: Disables anti-aliasing for remote desktop sessions. - DisableSecuritySettings: Disables certain security settings for Remote Desktop connections. - fAllowUnsolicited: Allows unsolicited remote assistance offers. - fAllowUnsolicitedFullControl: Allows unsolicited remote assistance offers with full control. - InitialProgram: Specifies a program to run automatically when a user logs on to a remote computer. - ServiceDll: Used in RDP hijacking techniques to specify a custom DLL to be loaded by the Terminal Services service. - SecurityLayer: Specifies the security layer used for RDP connections.
windows · registry_set
RDP to HTTP or HTTPS Target Ports
highDetects svchost hosting RDP termsvcs communicating to target systems on TCP port 80 or 443
windows · network_connection
Reconnaissance Activity
highDetects activity as "net user administrator /domain" and "net group domain admins /domain"
windows · security
RedMimicry Winnti Playbook Registry Manipulation
highDetects actions caused by the RedMimicry Winnti playbook
windows · registry_event
RedSun - Conhost.exe Spawned by TieringEngineService.exe
highDetects two stages of the RedSun post-exploitation process chain that deliver a SYSTEM-level shell to the attacker's interactive session. Observed process chain services.exe → TieringEngineService.exe → conhost.exe (SYSTEM, CommandLine: bare path, no arguments) → cmd.exe / shell (SYSTEM, TerminalSessionId = attacker's session) Stage 1 — TieringEngineService.exe spawns argument-less conhost.exe: After winning the oplock + Cloud Files mount point race, the malicious TieringEngineService.exe (RedSun.exe copied to System32, started via CoCreateInstance / services.exe) detects it is NT AUTHORITY\SYSTEM and calls LaunchConsoleInSessionId(). This opens \\.\pipe\REDSUN, reads the attacker's session ID, duplicates the SYSTEM token, re-stamps it with that session ID via SetTokenInformation(TokenSessionId), then calls CreateProcessAsUser to spawn conhost.exe with no arguments. Stage 2 — Shell spawned from rogue conhost.exe (EDR sources with GrandParentImage): The rogue SYSTEM conhost.exe spawns a shell (cmd.exe, PowerShell, etc.) as SYSTEM in the attacker's interactive session. On EDR sources that expose GrandParentImage, the full three-level chain (TieringEngineService.exe → conhost.exe → shell) can be matched directly. The legitimate TieringEngineService.exe is a headless COM server that is unlikely to spawn conhost.exe under normal conditions.
windows · process_creation
Reg Add Suspicious Paths
highDetects when an adversary uses the reg.exe utility to add or modify new keys or subkeys
windows · process_creation
Regedit as Trusted Installer
highDetects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe
windows · process_creation
Register new Logon Process by Rubeus
highDetects potential use of Rubeus via registered new trusted logon process
windows · security
Registry Disable System Restore
highDetects the modification of the registry to disable a system restore on the computer
windows · registry_set
Registry Export of Third-Party Credentials
highDetects the use of reg.exe to export registry paths associated with third-party credentials. Credential stealers have been known to use this technique to extract sensitive information from the registry.
windows · process_creation
Registry Hive File Staged Outside Standard User Profile Path
highDetects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard user profile path. These files generally contain various user-specific registry settings and are typically located in the user's profile directory. Staging these files outside of the standard path can be indicative of an attacker attempting to manipulate user registry settings for persistence, privilege escalation, or dump user registry hives for credential harvesting.
windows · file_event
Registry Modification for OCI DLL Redirection
highDetects registry modifications related to 'OracleOciLib' and 'OracleOciLibPath' under 'MSDTC' settings. Threat actors may modify these registry keys to redirect the loading of 'oci.dll' to a malicious DLL, facilitating phantom DLL hijacking via the MSDTC service.
windows · registry_set
Registry Persistence Mechanisms in Recycle Bin
highDetects persistence registry keys for Recycle Bin
windows · registry_event
Registry Persistence via Explorer Run Key
highDetects a possible persistence mechanism using RUN key for Windows Explorer and pointing to a suspicious folder
windows · registry_set
Registry Persistence via Service in Safe Mode
highDetects the modification of the registry to allow a driver or service to persist in Safe Mode.
windows · registry_set
Regsvr32 DLL Execution With Suspicious File Extension
highDetects the execution of REGSVR32.exe with DLL files masquerading as other files
windows · process_creation
Regsvr32 Execution From Highly Suspicious Location
highDetects execution of regsvr32 where the DLL is located in a highly suspicious locations
windows · process_creation
Relevant Anti-Virus Signature Keywords In Application Log
highDetects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.
windows · application
Remote Access Tool - Anydesk Execution From Suspicious Folder
highAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - AnyDesk Silent Installation
highDetects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.
windows · process_creation
Remote Access Tool - Renamed MeshAgent Execution - Windows
highDetects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.
windows · process_creation
Remote Access Tool - ScreenConnect Server Web Shell Execution
highDetects potential web shell execution from the ScreenConnect server process.
windows · process_creation
Remote AppX Package Downloaded from File Sharing or CDN Domain
highDetects an appx package that was added to the pipeline of the "to be processed" packages which was downloaded from a file sharing or CDN domain.
windows · appxdeployment-server
Remote CHM File Download/Execution Via HH.EXE
highDetects the usage of "hh.exe" to execute/download remotely hosted ".chm" files.
windows · process_creation
Remote LSASS Process Access Through Windows Remote Management
highDetects remote access to the LSASS process via WinRM. This could be a sign of credential dumping from tools like mimikatz.
windows · process_access
Remote PowerShell Session (PS Module)
highDetects remote PowerShell sessions
windows · ps_module
Remote PowerShell Sessions Network Connections (WinRM)
highDetects basic PowerShell Remoting (WinRM) by monitoring for network inbound connections to ports 5985 OR 5986
windows · security
Remote Thread Created In KeePass.EXE
highDetects remote thread creation in "KeePass.exe" which could indicates potential password dumping activity
windows · create_remote_thread
Remote Thread Creation In Mstsc.Exe From Suspicious Location
highDetects remote thread creation in the "mstsc.exe" process by a process located in a potentially suspicious location. This technique is often used by attackers in order to hook some APIs used by DLLs loaded by "mstsc.exe" during RDP authentications in order to steal credentials.
windows · create_remote_thread
Remote Thread Creation Ttdinject.exe Proxy
highDetects a remote thread creation of Ttdinject.exe used as proxy
windows · create_remote_thread
Remote XSL Execution Via Msxsl.EXE
highDetects the execution of the "msxsl" binary with an "http" keyword in the command line. This might indicate a potential remote execution of XSL files.
windows · process_creation
RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
highDetects calls to the AtomicTestHarnesses "Invoke-ATHRemoteFXvGPUDisablementCommand" which is designed to abuse the "RemoteFXvGPUDisablement.exe" binary to run custom PowerShell code via module load-order hijacking.
windows · process_creation
Remotely Hosted HTA File Executed Via Mshta.EXE
highDetects execution of the "mshta" utility with an argument containing the "http" keyword, which could indicate that an attacker is executing a remotely hosted malicious hta file
windows · process_creation
Removal Of AMSI Provider Registry Keys
highDetects the deletion of AMSI provider registry key entries in HKLM\Software\Microsoft\AMSI. This technique could be used by an attacker in order to disable AMSI inspection.
windows · registry_delete
Remove Exported Mailbox from Exchange Webserver
highDetects removal of an exported Exchange mailbox which could be to cover tracks from ProxyShell exploit
windows · msexchange-management
Renamed AdFind Execution
highDetects the use of a renamed Adfind.exe. AdFind continues to be seen across majority of breaches. It is used to domain trust discovery to plan out subsequent steps in the attack chain.
windows · process_creation
Renamed AutoIt Execution
highDetects the execution of a renamed AutoIt2.exe or AutoIt3.exe. AutoIt is a scripting language and automation tool for Windows systems. While primarily used for legitimate automation tasks, it can be misused in cyber attacks. Attackers can leverage AutoIt to create and distribute malware, including keyloggers, spyware, and botnets. A renamed AutoIt executable is particularly suspicious.
windows · process_creation
Renamed BrowserCore.EXE Execution
highDetects process creation with a renamed BrowserCore.exe (used to extract Azure tokens)
windows · process_creation
Renamed Cloudflared.EXE Execution
highDetects the execution of a renamed "cloudflared" binary.
windows · process_creation
Renamed CreateDump Utility Execution
highDetects uses of a renamed legitimate createdump.exe LOLOBIN utility to dump process memory
windows · process_creation
Renamed Gpg.EXE Execution
highDetects the execution of a renamed "gpg.exe". Often used by ransomware and loaders to decrypt/encrypt data.
windows · process_creation
Renamed Jusched.EXE Execution
highDetects the execution of a renamed "jusched.exe" as seen used by the cobalt group
windows · process_creation
Renamed Mavinject.EXE Execution
highDetects the execution of a renamed version of the "Mavinject" process. Which can be abused to perform process injection using the "/INJECTRUNNING" flag
windows · process_creation
Renamed MegaSync Execution
highDetects the execution of a renamed MegaSync.exe as seen used by ransomware families like Nefilim, Sodinokibi, Pysa, and Conti.
windows · process_creation
Renamed Msdt.EXE Execution
highDetects the execution of a renamed "Msdt.exe" binary
windows · process_creation
Renamed NetSupport RAT Execution
highDetects the execution of a renamed "client32.exe" (NetSupport RAT) via Imphash, Product and OriginalFileName strings
windows · process_creation
Renamed NirCmd.EXE Execution
highDetects the execution of a renamed "NirCmd.exe" binary based on the PE metadata fields.
windows · process_creation
Renamed Office Binary Execution
highDetects the execution of a renamed office binary
windows · process_creation
Renamed PAExec Execution
highDetects execution of renamed version of PAExec. Often used by attackers
windows · process_creation
Renamed PingCastle Binary Execution
highDetects the execution of a renamed "PingCastle" binary based on the PE metadata fields.
windows · process_creation
Renamed Plink Execution
highDetects the execution of a renamed version of the Plink binary
windows · process_creation
Renamed ProcDump Execution
highDetects the execution of a renamed ProcDump executable. This often done by attackers or malware in order to evade defensive mechanisms.
windows · process_creation
Renamed PsExec Service Execution
highDetects suspicious launch of a renamed version of the PSEXESVC service with, which is not often used by legitimate administrators
windows · process_creation
Renamed Schtasks Execution
highDetects the execution of renamed schtasks.exe binary, which is a legitimate Windows utility used for scheduling tasks. One of the very common persistence techniques is schedule malicious tasks using schtasks.exe. Since, it is heavily abused, it is also heavily monitored by security products. To evade detection, threat actors may rename the schtasks.exe binary to schedule their malicious tasks.
windows · process_creation
Renamed SysInternals DebugView Execution
highDetects suspicious renamed SysInternals DebugView execution
windows · process_creation
Renamed Sysinternals Sdelete Execution
highDetects the use of a renamed SysInternals Sdelete, which is something an administrator shouldn't do (the renaming)
windows · process_creation
Renamed Visual Studio Code Tunnel Execution
highDetects renamed Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows · process_creation
Renamed Vmnat.exe Execution
highDetects renamed vmnat.exe or portable version that can be used for DLL side-loading
windows · process_creation
Renamed VsCode Code Tunnel Execution - File Indicator
highDetects the creation of a file with the name "code_tunnel.json" which indicate execution and usage of VsCode tunneling utility by an "Image" or "Process" other than VsCode.
windows · file_event
Renamed ZOHO Dctask64 Execution
highDetects a renamed "dctask64.exe" execution, a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.
windows · process_creation
Replay Attack Detected
highDetects possible Kerberos Replay Attack on the domain controllers when "KRB_AP_ERR_REPEAT" Kerberos response is sent to the client
windows · security
Restricted Software Access By SRP
highDetects restricted access to applications by the Software Restriction Policies (SRP) policy
windows · application
RestrictedAdminMode Registry Value Tampering
highDetects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise
windows · registry_set
RestrictedAdminMode Registry Value Tampering - ProcCreation
highDetects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise
windows · process_creation
Root Certificate Installed From Susp Locations
highAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
RottenPotato Like Attack Pattern
highDetects logon events that have characteristics of events generated during an attack with RottenPotato and the like
windows · security
RTCore Suspicious Service Installation
highDetects the installation of RTCore service. Which could be an indication of Micro-Star MSI Afterburner vulnerable driver abuse
windows · system
Run PowerShell Script from ADS
highDetects PowerShell script execution from Alternate Data Stream (ADS)
windows · process_creation
Run PowerShell Script from Redirected Input Stream
highDetects PowerShell script execution via input stream redirect
windows · process_creation
Rundll32 Execution Without CommandLine Parameters
highDetects suspicious start of rundll32.exe without any parameters as found in CobaltStrike beacon activity
windows · process_creation
Rundll32 Execution Without Parameters
highDetects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
windows · process_creation
Rundll32 Registered COM Objects
highload malicious registered COM objects
windows · process_creation
RunDLL32 Spawning Explorer
highDetects RunDLL32.exe spawning explorer.exe as child, which is very uncommon, often observes Gamarue spawning the explorer.exe process in an unusual way
windows · process_creation
Rundll32 UNC Path Execution
highDetects rundll32 execution where the DLL is located on a remote location (share). Threat actors can abuse the rundll32.exe binary to execute remote DLLs from a UNC pathh.
windows · process_creation
RunMRU Registry Key Deletion
highDetects deletion of the RunMRU registry key, which stores the history of commands executed via the Run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.
windows · process_creation
RunMRU Registry Key Deletion - Registry
highDetects attempts to delete the RunMRU registry key, which stores the history of commands executed via the run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.
windows · registry_delete
Running Chrome VPN Extensions via the Registry 2 VPN Extension
highRunning Chrome VPN Extensions via the Registry install 2 vpn extension
windows · registry_set
SafeBoot Registry Key Deleted Via Reg.EXE
highDetects execution of "reg.exe" commands with the "delete" flag on safe boot registry keys. Often used by attacker to prevent safeboot execution of security products
windows · process_creation
SAM Registry Hive Handle Request
highDetects handles requested to SAM registry hive
windows · security
Scanner PoC for CVE-2019-0708 RDP RCE Vuln
highDetects the use of a scanner by zerosum0x0 that discovers targets vulnerable to CVE-2019-0708 RDP RCE aka BlueKeep
windows · security
Scheduled Task Creation Masquerading as System Processes
highDetects the creation of scheduled tasks that involve system processes, which may indicate malicious actors masquerading as or abusing these processes to execute payloads or maintain persistence.
windows · process_creation
Scheduled Task Executing Encoded Payload from Registry
highDetects the creation of a schtask that potentially executes a base64 encoded payload stored in the Windows Registry using PowerShell.
windows · process_creation
Scheduled TaskCache Change by Uncommon Program
highMonitor the creation of a new key under 'TaskCache' when a new scheduled task is registered by a process that is not svchost.exe, which is suspicious
windows · registry_set
Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor
highHunts for known SVR-specific scheduled task names
windows · security
Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor - Task Scheduler
highHunts for known SVR-specific scheduled task names
windows · taskscheduler
Schtasks Creation Or Modification With SYSTEM Privileges
highDetects the creation or update of a scheduled task to run with "NT AUTHORITY\SYSTEM" privileges
windows · process_creation
Schtasks From Suspicious Folders
highDetects scheduled task creations that have suspicious action command and folder combinations
windows · process_creation
ScreenConnect - SlashAndGrab Exploitation Indicators
highDetects indicators of exploitation by threat actors during exploitation of the "SlashAndGrab" vulnerability related to ScreenConnect as reported Team Huntress
windows · file_event
Script Event Consumer Spawning Process
highDetects a suspicious child process of Script Event Consumer (scrcons.exe).
windows · process_creation
Script Interpreter Execution From Suspicious Folder
highDetects suspicious script execution from suspicious directories or folders accessible by environment variables that may indicate malware activity. Script interpreters (cscript, wscript, mshta, powershell) executing from folders like Temp, Public, or user profile directories may suggest attempts to evade detection or execute malicious scripts.
windows · process_creation
Script Interpreter Spawning Credential Scanner - Windows
highDetects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
windows · process_creation
Sdiagnhost Calling Suspicious Child Process
highDetects sdiagnhost.exe calling a suspicious child process (e.g. used in exploits for Follina / CVE-2022-30190)
windows · process_creation
Security Event Logging Disabled via MiniNt Registry Key - Process
highDetects attempts to disable security event logging by adding the `MiniNt` registry key. This key is used to disable the Windows Event Log service, which collects and stores event logs from the operating system and applications. Adversaries may want to disable this service to prevent logging of security events that could be used to detect their activities.
windows · process_creation
Security Event Logging Disabled via MiniNt Registry Key - Registry Set
highDetects the addition of the 'MiniNt' key to the registry. Upon a reboot, Windows Event Log service will stop writing events. Windows Event Log is a service that collects and stores event logs from the operating system and applications. It is an important component of Windows security and auditing. Adversary may want to disable this service to disable logging of security events which could be used to detect their activities.
windows · registry_set
Security Eventlog Cleared
highOne of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution
windows · security
Security Privileges Enumeration Via Whoami.EXE
highDetects a whoami.exe executed with the /priv command line flag instructing the tool to show all current user privileges. This is often used after a privilege escalation attempt.
windows · process_creation
Security Service Disabled Via Reg.EXE
highDetects execution of "reg.exe" to disable security services such as Windows Defender.
windows · process_creation
Security Support Provider (SSP) Added to LSA Configuration
highDetects the addition of a SSP to the registry. Upon a reboot or API call, SSP DLLs gain access to encrypted and plaintext passwords stored in Windows.
windows · registry_event
Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
highDetects the use of iexpress.exe to create binaries via Self Extraction Directive (SED) files located in potentially suspicious locations. This behavior has been observed in-the-wild by different threat actors.
windows · process_creation
Sensitive File Access Via Volume Shadow Copy Backup
highDetects a command that accesses the VolumeShadowCopy in order to extract sensitive files such as the Security or SAM registry hives or the AD database (ntds.dit)
windows · process_creation
Sensitive File Dump Via Print.EXE
highDetects the abuse of the Print.exe utility for credential harvesting which involves using Print.Exe to copy sensitive files such as ntds.dit, SAM, SECURITY, or SYSTEM from the Windows directory in order to extract credentials, locally or remotely.
windows · process_creation
Sensitive File Dump Via Wbadmin.EXE
highDetects the dump of highly sensitive files such as "NTDS.DIT" and "SECURITY" hive. Attackers can leverage the "wbadmin" utility in order to dump sensitive files that might contain credential or sensitive information.
windows · process_creation
Sensitive File Recovery From Backup Via Wbadmin.EXE
highDetects the dump of highly sensitive files such as "NTDS.DIT" and "SECURITY" hive. Attackers can leverage the "wbadmin" utility in order to dump sensitive files that might contain credential or sensitive information.
windows · process_creation
Serpent Backdoor Payload Execution Via Scheduled Task
highDetects post exploitation execution technique of the Serpent backdoor. According to Proofpoint, one of the commands that the backdoor ran was via creating a temporary scheduled task using an unusual method. It creates a fictitious windows event and a trigger in which once the event is created, it executes the payload.
windows · process_creation
Service Binary in Suspicious Folder
highDetect the creation of a service with a service binary located in a suspicious directory
windows · registry_set
Service DACL Abuse To Hide Services Via Sc.EXE
highDetects usage of the "sc.exe" utility adding a new service with special permission seen used by threat actors which makes the service hidden and unremovable.
windows · process_creation
Service Installation with Suspicious Folder Pattern
highDetects service installation with suspicious folder patterns
windows · system
Service Installed By Unusual Client - Security
highDetects a service installed by a client which has PID 0 or whose parent has PID 0
windows · security
Service Installed By Unusual Client - System
highDetects a service installed by a client which has PID 0 or whose parent has PID 0
windows · system
Service Registry Key Deleted Via Reg.EXE
highDetects execution of "reg.exe" commands with the "delete" flag on services registry key. Often used by attacker to remove AV software services
windows · process_creation
Set Suspicious Files as System Files Using Attrib.EXE
highDetects the usage of attrib with the "+s" option to set scripts or executables located in suspicious locations as system files to hide them from users and make them unable to be deleted with simple rights. The rule limits the search to specific extensions and directories to avoid FPs
windows · process_creation
Shadow Copies Deletion Using Operating Systems Utilities
highShadow Copies deletion using operating systems utilities
windows · process_creation
Shai-Hulud 2.0 Malicious NPM Package Installation
highDetects the command-line installation of specific malicious npm packages and versions associated with the Shai-Hulud 2.0 supply chain attack.
windows · process_creation
Shai-Hulud Malicious Bun Execution
highDetects the execution of `bun_environment.js` via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a `setup_bun.js` script to install the Bun runtime if not present, and then executes the malicious `bun_environment.js` payload.
windows · process_creation
Shai-Hulud Malware Indicators - Windows
highDetects potential Shai-Hulud malware indicators based on specific command line arguments associated with its execution.
windows · process_creation
Shell Open Registry Keys Manipulation
highDetects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)
windows · registry_event
Shell32 DLL Execution in Suspicious Directory
highDetects shell32.dll executing a DLL in a suspicious directory
windows · process_creation
ShimCache Flush
highDetects actions that clear the local ShimCache and remove forensic evidence
windows · process_creation
Silenttrinity Stager Msbuild Activity
highDetects a possible remote connections to Silenttrinity c2
windows · network_connection
Sliver C2 Default Service Installation
highDetects known malicious service installation that appear in cases in which a Sliver implants execute the PsExec commands
windows · system
Small Sieve Malware CommandLine Indicator
highDetects specific command line argument being passed to a binary as seen being used by the malware Small Sieve.
windows · process_creation
Small Sieve Malware File Indicator Creation
highDetects filename indicators that contain a specific typo seen used by the Small Sieve malware.
windows · file_event
Small Sieve Malware Registry Persistence
highDetects registry value with specific intentional typo and strings seen used by the Small Sieve malware
windows · registry_set
SMB Create Remote File Admin Share
highLook for non-system accounts SMB accessing a file with write (0x2) access mask via administrative share (i.e C$).
windows · security
smbexec.py Service Installation
highDetects the use of smbexec.py tool by detecting a specific service installation
windows · system
SNAKE Malware Covert Store Registry Key
highDetects any registry event that targets the key 'SECURITY\Policy\Secrets\n' which is a key related to SNAKE malware as described by CISA
windows · registry_event
SNAKE Malware WerFault Persistence File Creation
highDetects the creation of a file named "WerFault.exe" in the WinSxS directory by a non-system process, which can be indicative of potential SNAKE malware activity
windows · file_event
Sofacy Trojan Loader Activity
highDetects Trojan loader activity as used by APT28
windows · process_creation
SOURGUM Actor Behaviours
highSuspicious behaviours related to an actor tracked by Microsoft as SOURGUM
windows · process_creation
SQLite Chromium Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.
windows · process_creation
SQLite Firefox Profile Data DB Access
highDetect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.
windows · process_creation
StoneDrill Service Install
highThis method detects a service install of the malicious Microsoft Network Realtime Inspection Service service described in StoneDrill report by Kaspersky
windows · system
Successful Overpass the Hash Attempt
highDetects successful logon with logon type 9 (NewCredentials) which matches the Overpass the Hash behavior of e.g Mimikatz's sekurlsa::pth module.
windows · security
Suspect Svchost Activity
highIt is extremely abnormal for svchost.exe to spawn without any CLI arguments and is normally observed when a malicious process spawns the process and injects code into the process memory space.
windows · process_creation
Suspicious Active Directory Database Snapshot Via ADExplorer
highDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database to a suspicious directory. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · process_creation
Suspicious AddinUtil.EXE CommandLine Execution
highDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) with suspicious Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.
windows · process_creation
Suspicious Advpack Call Via Rundll32.EXE
highDetects execution of "rundll32" calling "advpack.dll" with potential obfuscated ordinal calls in order to leverage the "RegisterOCX" function
windows · process_creation
Suspicious AgentExecutor PowerShell Execution
highDetects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
windows · process_creation
Suspicious Application Allowed Through Exploit Guard
highDetects applications being added to the "allowed applications" list of exploit guard in order to bypass controlled folder settings
windows · registry_set
Suspicious ArcSOC.exe Child Process
highDetects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe. ArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS Server system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding service endpoint and remotely execute code from the ArcSOC.exe process.
windows · process_creation
Suspicious ASPX File Drop by Exchange
highDetects suspicious file type dropped by an Exchange component in IIS into a suspicious folder
windows · file_event
Suspicious Autorun Registry Modified via WMI
highDetects suspicious activity where the WMIC process is used to create an autorun registry entry via reg.exe, which is often indicative of persistence mechanisms employed by malware.
windows · process_creation
Suspicious Binaries and Scripts in Public Folder
highDetects the creation of a file with a suspicious extension in the public folder, which could indicate potential malicious activity.
windows · file_event
Suspicious Binary In User Directory Spawned From Office Application
highDetects an executable in the users directory started from one of the Microsoft Office suite applications (Word, Excel, PowerPoint, Publisher, Visio)
windows · process_creation
Suspicious Binary Writes Via AnyDesk
highDetects AnyDesk writing binary files to disk other than "gcapi.dll". According to RedCanary research it is highly abnormal for AnyDesk to write executable files to disk besides gcapi.dll, which is a legitimate DLL that is part of the Google Chrome web browser used to interact with the Google Cloud API. (See reference section for more details)
windows · file_event
Suspicious BitLocker Access Agent Update Utility Execution
highDetects the execution of the BitLocker Access Agent Update Utility (baaupdate.exe) which is not a common parent process for other processes. Suspicious child processes spawned by baaupdate.exe could indicate an attempt at lateral movement via BitLocker DCOM & COM Hijacking.
windows · process_creation
Suspicious Calculator Usage
highDetects suspicious use of 'calc.exe' with command line parameters or in a suspicious directory, which is likely caused by some PoC or detection evasion.
windows · process_creation
Suspicious Camera and Microphone Access
highDetects Processes accessing the camera and microphone from suspicious folder
windows · registry_event
Suspicious CertReq Command to Download
highDetects a suspicious CertReq execution downloading a file. This behavior is often used by attackers to download additional payloads or configuration files. Certreq is a built-in Windows utility used to request and retrieve certificates from a certification authority (CA). However, it can be abused by threat actors for malicious purposes.
windows · process_creation
Suspicious Child Process Created as System
highDetection of child processes spawned with SYSTEM privileges by parents with LOCAL SERVICE or NETWORK SERVICE accounts
windows · process_creation
Suspicious Child Process of AspNetCompiler
highDetects potentially suspicious child processes of "aspnet_compiler.exe".
windows · process_creation
Suspicious Child Process Of BgInfo.EXE
highDetects suspicious child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
windows · process_creation
Suspicious Child Process Of Manage Engine ServiceDesk
highDetects suspicious child processes of the "Manage Engine ServiceDesk Plus" Java web service
windows · process_creation
Suspicious Child Process of Notepad++ Updater - GUP.Exe
highDetects suspicious child process creation by the Notepad++ updater process (gup.exe). This could indicate potential exploitation of the updater component to deliver unwanted malware.
windows · process_creation
Suspicious Child Process of SolarWinds WebHelpDesk
highDetects suspicious child processes spawned by SolarWinds WebHelpDesk (WHD) application, which may indicate exploitation activity leveraging RCE vulnerabilities such as CVE-2025-40551, CVE-2025-40536, or CVE-2025-26399
windows · process_creation
Suspicious Child Process Of SQL Server
highDetects suspicious child processes of the SQLServer process. This could indicate potential RCE or SQL Injection.
windows · process_creation
Suspicious Child Process Of Wermgr.EXE
highDetects suspicious Windows Error Reporting manager (wermgr.exe) child process
windows · process_creation
Suspicious Chromium Browser Instance Executed With Custom Extension
highDetects a suspicious process spawning a Chromium based browser process with the 'load-extension' flag to start an instance with a custom extension
windows · process_creation
Suspicious ClickFix/FileFix Execution Pattern
highDetects suspicious execution patterns where users are tricked into running malicious commands via clipboard manipulation, either through the Windows Run dialog (ClickFix) or File Explorer address bar (FileFix). Attackers leverage social engineering campaigns—such as fake CAPTCHA challenges or urgent alerts—encouraging victims to paste clipboard contents, often executing mshta.exe, powershell.exe, or similar commands to infect systems.
windows · process_creation
Suspicious Command Patterns In Scheduled Task Creation
highDetects scheduled task creation using "schtasks" that contain potentially suspicious or uncommon commands
windows · process_creation
Suspicious Computer Account Name Change CVE-2021-42287
highDetects the renaming of an existing computer account to a account name that doesn't contain a $ symbol as seen in attacks against CVE-2021-42287
windows · security
Suspicious Control Panel DLL Load
highDetects suspicious Rundll32 execution from control.exe as used by Equation Group and Exploit Kits
windows · process_creation
Suspicious Creation with Colorcpl
highOnce executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
windows · file_event
Suspicious Curl.EXE Download
highDetects a suspicious curl process start on Windows and outputs the requested document to a local file
windows · process_creation
Suspicious CustomShellHost Execution
highDetects the execution of CustomShellHost.exe where the child isn't located in 'C:\Windows\explorer.exe'. CustomShellHost is a known LOLBin that can be abused by attackers for defense evasion techniques.
windows · process_creation
Suspicious Debugger Registration Cmdline
highDetects the registration of a debugger for a program that is available in the logon screen (sticky key backdoor).
windows · process_creation
Suspicious Desktopimgdownldr Command
highDetects a suspicious Microsoft desktopimgdownldr execution with parameters used to download files from the Internet
windows · process_creation
Suspicious Desktopimgdownldr Target File
highDetects a suspicious Microsoft desktopimgdownldr file creation that stores a file to a suspicious location or contains a file with a suspicious extension
windows · file_event
Suspicious DLL Loaded via CertOC.EXE
highDetects when a user installs certificates by using CertOC.exe to load the target DLL file.
windows · process_creation
Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
highDetects DNS queries containing patterns associated with Kerberos coercion attacks via DNS object spoofing. The pattern "1UWhRCAAAAA..BAAAA" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure. Attackers can use this technique to coerce authentication from victim systems to attacker-controlled hosts. It is one of the strong indicators of a Kerberos coercion attack, where adversaries manipulate DNS records to spoof Service Principal Names (SPNs) and redirect authentication requests like CVE-2025-33073.
windows · dns_query
Suspicious DotNET CLR Usage Log Artifact
highDetects the creation of Usage Log files by the CLR (clr.dll). These files are named after the executing process once the assembly is finished executing for the first time in the (user) session context.
windows · file_event
Suspicious Double Extension File Execution
highDetects suspicious use of an .exe extension after a non-executable file extension like .pdf.exe, a set of spaces or underlines to cloak the executable file in spear phishing campaigns
windows · process_creation
Suspicious Double Extension Files
highDetects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.
windows · file_event
Suspicious Download From Direct IP Via Bitsadmin
highDetects usage of bitsadmin downloading a file using an URL that contains an IP
windows · process_creation
Suspicious Download From File-Sharing Website Via Bitsadmin
highDetects usage of bitsadmin downloading a file from a suspicious domain
windows · process_creation
Suspicious Download from Office Domain
highDetects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents
windows · process_creation
Suspicious Driver/DLL Installation Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "INSTALLDRIVER" action where the driver doesn't contain a ".dll" extension. This is often used as a defense evasion method.
windows · process_creation
Suspicious Dropbox API Usage
highDetects an executable that isn't dropbox but communicates with the Dropbox API
windows · network_connection
Suspicious DumpMinitool Execution
highDetects suspicious ways to use the "DumpMinitool.exe" binary
windows · process_creation
Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
highDetects suspicious base64 encoded and obfuscated "LOAD" keyword used in .NET "reflection.assembly"
windows · process_creation
Suspicious Encoded PowerShell Command Line
highDetects suspicious powershell process starts with base64 encoded commands (e.g. Emotet)
windows · process_creation
Suspicious Encoded Scripts in a WMI Consumer
highDetects suspicious encoded payloads in WMI Event Consumers
windows · wmi_event
Suspicious Environment Variable Has Been Registered
highDetects the creation of user-specific or system-wide environment variables via the registry. Which contains suspicious commands and strings
windows · registry_set
Suspicious Eventlog Clearing or Configuration Change Activity
highDetects the clearing or configuration tampering of EventLog using utilities such as "wevtutil", "powershell" and "wmic". This technique were seen used by threat actors and ransomware strains in order to evade defenses.
windows · process_creation
Suspicious Executable File Creation
highDetect creation of suspicious executable file names. Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.
windows · file_event
Suspicious Execution From Outlook Temporary Folder
highDetects a suspicious program execution in Outlook temp folder
windows · process_creation
Suspicious Execution Location Of Wermgr.EXE
highDetects suspicious Windows Error Reporting manager (wermgr.exe) execution location.
windows · process_creation
Suspicious Execution Of Renamed Sysinternals Tools - Registry
highDetects the creation of the "accepteula" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)
windows · registry_set
Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
highDetects process creation with suspicious whitespace padding followed by a '#' character, which may indicate ClickFix or FileFix techniques used to conceal malicious commands from visual inspection. ClickFix and FileFix are social engineering attack techniques where adversaries distribute phishing documents or malicious links that deceive users into opening the Windows Run dialog box or File Explorer search bar. The victims are then instructed to paste commands from their clipboard, which contain extensive whitespace padding using various Unicode space characters to push the actual malicious command far to the right, effectively hiding it from immediate view.
windows · process_creation
Suspicious File Created by ArcSOC.exe
highDetects instances where the ArcGIS Server process ArcSOC.exe, which hosts REST services running on an ArcGIS server, creates a file with suspicious file type, indicating that it may be an executable, script file, or otherwise unusual.
windows · file_event
Suspicious File Created in Outlook Temporary Directory
highDetects the creation of files with suspicious file extensions in the temporary directory that Outlook uses when opening attachments. This can be used to detect spear-phishing campaigns that use suspicious files as attachments, which may contain malicious code.
windows · file_event
Suspicious File Created Via OneNote Application
highDetects suspicious files created via the OneNote application. This could indicate a potential malicious ".one"/".onepkg" file was executed as seen being used in malware activity in the wild
windows · file_event
Suspicious File Creation Activity From Fake Recycle.Bin Folder
highDetects file write event from/to a fake recycle bin folder that is often used as a staging directory for malware
windows · file_event
Suspicious File Creation In Uncommon AppData Folder
highDetects the creation of suspicious files and folders inside the user's AppData folder but not inside any of the common and well known directories (Local, Romaing, LocalLow). This method could be used as a method to bypass detection who exclude the AppData folder in fear of FPs
windows · file_event
Suspicious File Download From File Sharing Domain Via Curl.EXE
highDetects potentially suspicious file download from file sharing domains using curl.exe
windows · process_creation
Suspicious File Download From File Sharing Domain Via Wget.EXE
highDetects potentially suspicious file downloads from file sharing domains using wget.exe
windows · process_creation
Suspicious File Download From File Sharing Websites - File Stream
highDetects the download of suspicious file type from a well-known file and paste sharing domain
windows · create_stream_hash
Suspicious File Download From IP Via Curl.EXE
highDetects potentially suspicious file downloads directly from IP addresses using curl.exe
windows · process_creation
Suspicious File Download From IP Via Wget.EXE
highDetects potentially suspicious file downloads directly from IP addresses using Wget.exe
windows · process_creation
Suspicious File Download From IP Via Wget.EXE - Paths
highDetects potentially suspicious file downloads directly from IP addresses and stored in suspicious locations using Wget.exe
windows · process_creation
Suspicious File Downloaded From Direct IP Via Certutil.EXE
highDetects the execution of certutil with certain flags that allow the utility to download files from direct IPs.
windows · process_creation
Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
highDetects the execution of certutil with certain flags that allow the utility to download files from file-sharing websites.
windows · process_creation
Suspicious File Encoded To Base64 Via Certutil.EXE
highDetects the execution of certutil with the "encode" flag to encode a file to base64 where the extensions of the file is suspicious
windows · process_creation
Suspicious File Execution From Internet Hosted WebDav Share
highDetects the execution of the "net use" command to mount a WebDAV server and then immediately execute some content in it. As seen being used in malicious LNK files
windows · process_creation
Suspicious File Write to SharePoint Layouts Directory
highDetects suspicious file writes to SharePoint layouts directory which could indicate webshell activity or post-exploitation. This behavior has been observed in the exploitation of SharePoint vulnerabilities such as CVE-2025-49704, CVE-2025-49706 or CVE-2025-53770.
windows · file_event
Suspicious FileFix Execution Pattern
highDetects suspicious FileFix execution patterns where users are tricked into running malicious commands through browser file upload dialog manipulation. This attack typically begins when users visit malicious websites impersonating legitimate services or news platforms, which may display fake CAPTCHA challenges or direct instructions to open file explorer and paste clipboard content. The clipboard content usually contains commands that download and execute malware, such as information stealing tools.
windows · process_creation
Suspicious Get-ADDBAccount Usage
highDetects suspicious invocation of the Get-ADDBAccount script that reads from a ntds.dit file and may be used to get access to credentials without using any credential dumpers
windows · ps_module
Suspicious Get-Variable.exe Creation
highGet-Variable is a valid PowerShell cmdlet WindowsApps is by default in the path where PowerShell is executed. So when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.
windows · file_event
Suspicious Greedy Compression Using Rar.EXE
highDetects RAR usage that creates an archive from a suspicious folder, either a system folder or one of the folders often used by attackers for staging purposes
windows · process_creation
Suspicious GrpConv Execution
highDetects the suspicious execution of a utility to convert Windows 3.x .grp files or for persistence purposes by malicious software or actors
windows · process_creation
Suspicious GUP Usage
highDetects execution of the Notepad++ updater in a suspicious directory, which is often used in DLL side-loading attacks
windows · process_creation
Suspicious HH.EXE Execution
highDetects a suspicious execution of a Microsoft HTML Help (HH.exe)
windows · process_creation
Suspicious HWP Sub Processes
highDetects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation
windows · process_creation
Suspicious IIS Module Registration
highDetects a suspicious IIS module registration as described in Microsoft threat report on IIS backdoors
windows · process_creation
Suspicious Interactive PowerShell as SYSTEM
highDetects the creation of files that indicator an interactive use of PowerShell in the SYSTEM user context
windows · file_event
Suspicious Invoke-WebRequest Execution
highDetects a suspicious call to Invoke-WebRequest cmdlet where the and output is located in a suspicious location
windows · process_creation
Suspicious JavaScript Execution Via Mshta.EXE
highDetects execution of javascript code using "mshta.exe".
windows · process_creation
Suspicious Kerberos Ticket Request via CLI
highDetects suspicious Kerberos ticket requests via command line using System.IdentityModel.Tokens.KerberosRequestorSecurityToken class. Threat actors may use command line interfaces to request Kerberos tickets for service accounts in order to perform offline password cracking attacks commonly known as Kerberoasting or other Kerberos ticket abuse techniques like silver ticket attacks.
windows · process_creation
Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock
highDetects PowerShell scripts that utilize native PowerShell Identity modules to request Kerberos tickets. This behavior is typically seen during a Kerberos or silver ticket attack. A successful execution will output the SPNs for the endpoint in question.
windows · ps_script
Suspicious Kernel Dump Using Dtrace
highDetects suspicious way to dump the kernel on Windows systems using dtrace.exe, which is available on Windows systems since Windows 10 19H1
windows · process_creation
Suspicious Key Manager Access
highDetects the invocation of the Stored User Names and Passwords dialogue (Key Manager)
windows · process_creation
Suspicious LDAP-Attributes Used
highDetects the usage of particular AttributeLDAPDisplayNames, which are known for data exchange via LDAP by the tool LDAPFragger and are additionally not commonly used in companies.
windows · security
Suspicious LNK Command-Line Padding with Whitespace Characters
highDetects exploitation of LNK file command-line length discrepancy, where attackers hide malicious commands beyond the 260-character UI limit while the actual command-line argument field supports 4096 characters using whitespace padding (e.g., 0x20, 0x09-0x0D). Adversaries insert non-printable whitespace characters (e.g., Line Feed \x0A, Carriage Return \x0D) to pad the visible section of the LNK file, pushing malicious commands past the UI-visible boundary. The hidden payload, executed at runtime but invisible in Windows Explorer properties, enables stealthy execution and evasion—commonly used for social engineering attacks. This rule flags suspicious use of such padding observed in real-world attacks.
windows · process_creation
Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
highDetects loading of dbgcore.dll or dbghelp.dll from uncommon locations such as user directories. These DLLs contain the MiniDumpWriteDump function, which can be abused for credential dumping purposes or in some cases for evading EDR/AV detection by suspending processes.
windows · image_load
Suspicious LSASS Access Via MalSecLogon
highDetects suspicious access to LSASS handle via a call trace to "seclogon.dll" with a suspicious access right.
windows · process_access
Suspicious Manipulation Of Default Accounts Via Net.EXE
highDetects suspicious manipulations of default accounts such as 'administrator' and 'guest'. For example 'enable' or 'disable' accounts or change the password...etc
windows · process_creation
Suspicious Microsoft Office Child Process
highDetects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
windows · process_creation
Suspicious Microsoft OneNote Child Process
highDetects suspicious child processes of the Microsoft OneNote application. This may indicate an attempt to execute malicious embedded objects from a .one file.
windows · process_creation
Suspicious Modification Of Scheduled Tasks
highDetects when an attacker tries to modify an already existing scheduled tasks to run from a suspicious location Attackers can create a simple looking task in order to avoid detection on creation as it's often the most focused on Instead they modify the task after creation to include their malicious payload
windows · process_creation
Suspicious MSDT Parent Process
highDetects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation
windows · process_creation
Suspicious MSExchangeMailboxReplication ASPX Write
highDetects suspicious activity in which the MSExchangeMailboxReplication process writes .asp and .apsx files to disk, which could be a sign of ProxyShell exploitation
windows · file_event
Suspicious MSHTA Child Process
highDetects a suspicious process spawning from an "mshta.exe" process, which could be indicative of a malicious HTA script execution
windows · process_creation
Suspicious Mshta.EXE Execution Patterns
highDetects suspicious mshta process execution patterns
windows · process_creation
Suspicious Mstsc.EXE Execution With Local RDP File
highDetects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
windows · process_creation
Suspicious Network Connection Binary No CommandLine
highDetects suspicious network connections made by a well-known Windows binary run with no command line parameters
windows · network_connection
Suspicious New Service Creation
highDetects creation of a new service via "sc" command or the powershell "new-service" cmdlet with suspicious binary paths
windows · process_creation
Suspicious NTLM Authentication on the Printer Spooler Service
highDetects a privilege elevation attempt by coercing NTLM authentication on the Printer Spooler service
windows · process_creation
Suspicious Obfuscated PowerShell Code
highDetects suspicious UTF16 and base64 encoded and often obfuscated PowerShell code often used in command lines
windows · process_creation
Suspicious Outlook Child Process
highDetects a suspicious process spawning from an Outlook process.
windows · process_creation
Suspicious Outlook Macro Created
highDetects the creation of a macro file for Outlook.
windows · file_event
Suspicious Parent Double Extension File Execution
highDetect execution of suspicious double extension files in ParentCommandLine
windows · process_creation
Suspicious Path In Keyboard Layout IME File Registry Value
highDetects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message. Before doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named "Ime File" with a DLL path. IMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.
windows · registry_set
Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
highDetects execution of the "VMwareToolBoxCmd.exe" with the "script" and "set" flag to setup a specific script that's located in a potentially suspicious location to run for a specific VM state
windows · process_creation
Suspicious Ping/Del Command Combination
highDetects a method often used by ransomware. Which combines the "ping" to wait a couple of seconds and then "del" to delete the file in question. Its used to hide the file responsible for the initial infection for example
windows · process_creation
Suspicious Plink Port Forwarding
highDetects suspicious Plink tunnel port forwarding to a local port
windows · process_creation
Suspicious PowerShell Download and Execute Pattern
highDetects suspicious PowerShell download patterns that are often used in malicious scripts, stagers or downloaders (make sure that your backend applies the strings case-insensitive)
windows · process_creation
Suspicious PowerShell Encoded Command Patterns
highDetects PowerShell command line patterns in combincation with encoded commands that often appear in malware infection chains
windows · process_creation
Suspicious PowerShell IEX Execution Patterns
highDetects suspicious ways to run Invoke-Execution using IEX alias
windows · process_creation
Suspicious PowerShell Invocations - Generic
highDetects suspicious PowerShell invocation command parameters
windows · ps_script
Suspicious PowerShell Invocations - Generic - PowerShell Module
highDetects suspicious PowerShell invocation command parameters
windows · ps_module
Suspicious PowerShell Invocations - Specific
highDetects suspicious PowerShell invocation command parameters
windows · ps_script
Suspicious PowerShell Invocations - Specific - PowerShell Module
highDetects suspicious PowerShell invocation command parameters
windows · ps_module
Suspicious PowerShell Parameter Substring
highDetects suspicious PowerShell invocation with a parameter substring
windows · process_creation
Suspicious PowerShell Parent Process
highDetects a suspicious or uncommon parent processes of PowerShell
windows · process_creation
Suspicious Printer Driver Empty Manufacturer
highDetects a suspicious printer driver installation with an empty Manufacturer value
windows · registry_set
Suspicious PrinterPorts Creation (CVE-2020-1048)
highDetects new commands that add new printer port which point to suspicious file
windows · process_creation
Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
highDetects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.
windows · process_access
Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
highDetects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace. These DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll, dbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.
windows · process_access
Suspicious Process By Web Server Process
highDetects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation
windows · process_creation
Suspicious Process Created Via Wmic.EXE
highDetects WMIC executing "process call create" with suspicious calls to processes such as "rundll32", "regsrv32", etc.
windows · process_creation
Suspicious Process Execution From Fake Recycle.Bin Folder
highDetects process execution from a fake recycle bin folder, often used to avoid security solution.
windows · process_creation
Suspicious Process Masquerading As SvcHost.EXE
highDetects a suspicious process that is masquerading as the legitimate "svchost.exe" by naming its binary "svchost.exe" and executing from an uncommon location. Adversaries often disguise their malicious binaries by naming them after legitimate system processes like "svchost.exe" to evade detection.
windows · process_creation
Suspicious Process Parents
highDetects suspicious parent processes that should not have any children or should only have a single possible child program
windows · process_creation
Suspicious Process Patterns NTDS.DIT Exfil
highDetects suspicious process patterns used in NTDS.DIT exfiltration
windows · process_creation
Suspicious Process Spawned by CentreStack Portal AppPool
highDetects unexpected command shell execution (cmd.exe) from w3wp.exe when tied to CentreStack's portal.config, indicating potential exploitation (e.g., CVE-2025-30406)
windows · process_creation
Suspicious Processes Spawned by Java.EXE
highDetects suspicious processes spawned from a Java host process which could indicate a sign of exploitation (e.g. log4j)
windows · process_creation
Suspicious Processes Spawned by WinRM
highDetects suspicious processes including shells spawnd from WinRM host process
windows · process_creation
Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE
highDetects Netsh command execution that whitelists a program located in a suspicious location in the Windows Firewall
windows · process_creation
Suspicious Program Names
highDetects suspicious patterns in program names or folders that are often found in malicious samples or hacktools
windows · process_creation
Suspicious Provlaunch.EXE Child Process
highDetects suspicious child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
windows · process_creation
Suspicious PsExec Execution
highdetects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if attacker uses a different psexec client other than sysinternal one
windows · security
Suspicious RazerInstaller Explorer Subprocess
highDetects a explorer.exe sub process of the RazerInstaller software which can be invoked from the installer to select a different installation folder but can also be exploited to escalate privileges to LOCAL SYSTEM
windows · process_creation
Suspicious RDP Redirect Using TSCON
highDetects a suspicious RDP session redirect using tscon.exe
windows · process_creation
Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
highDetects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
windows · process_creation
Suspicious Redirection to Local Admin Share
highDetects a suspicious output redirection to the local admins share, this technique is often found in malicious scripts or hacktool stagers
windows · process_creation
Suspicious Reg Add BitLocker
highDetects suspicious addition to BitLocker related registry keys via the reg.exe utility
windows · process_creation
Suspicious Registry Modification From ADS Via Regini.EXE
highDetects the import of an alternate data stream with regini.exe, regini.exe can be used to modify registry keys.
windows · process_creation
Suspicious Regsvr32 Execution From Remote Share
highDetects REGSVR32.exe to execute DLL hosted on remote shares
windows · process_creation
Suspicious Remote Child Process From Outlook
highDetects a suspicious child process spawning from Outlook where the image is located in a remote location (SMB/WebDav shares).
windows · process_creation
Suspicious Renamed Comsvcs DLL Loaded By Rundll32
highDetects rundll32 loading a renamed comsvcs.dll to dump process memory
windows · image_load
Suspicious Response File Execution Via Odbcconf.EXE
highDetects execution of "odbcconf" with the "-f" flag in order to load a response file with a non-".rsp" extension.
windows · process_creation
Suspicious Run Key from Download
highDetects the suspicious RUN keys created by software located in Download or temporary Outlook/Internet Explorer directories
windows · registry_event
Suspicious Rundll32 Activity Invoking Sys File
highDetects suspicious process related to rundll32 based on command line that includes a *.sys file as seen being used by UNC2452
windows · process_creation
Suspicious Rundll32 Execution With Image Extension
highDetects the execution of Rundll32.exe with DLL files masquerading as image files
windows · process_creation
Suspicious Rundll32 Invoking Inline VBScript
highDetects suspicious process related to rundll32 based on command line that invokes inline VBScript as seen being used by UNC2452
windows · process_creation
Suspicious Scheduled Task Creation
highDetects suspicious scheduled task creation events. Based on attributes such as paths, commands line flags, etc.
windows · security
Suspicious Scheduled Task Creation Involving Temp Folder
highDetects the creation of scheduled tasks that involves a temporary folder and runs only once
windows · process_creation
Suspicious Scheduled Task Update
highDetects update to a scheduled task event that contain suspicious keywords.
windows · security
Suspicious Scheduled Task Write to System32 Tasks
highDetects the creation of tasks from processes executed from suspicious locations
windows · file_event
Suspicious Schtasks Execution AppData Folder
highDetects the creation of a schtask that executes a file from C:\Users\<USER>\AppData\Local
windows · process_creation
Suspicious Schtasks Schedule Types
highDetects scheduled task creations or modification on a suspicious schedule type
windows · process_creation
Suspicious Scripting in a WMI Consumer
highDetects suspicious commands that are related to scripting/powershell in WMI Event Consumers
windows · wmi_event
Suspicious Serv-U Process Pattern
highDetects a suspicious process pattern which could be a sign of an exploited Serv-U service
windows · process_creation
Suspicious Service Binary Directory
highDetects a service binary running in a suspicious directory
windows · process_creation
Suspicious Service DACL Modification Via Set-Service Cmdlet
highDetects suspicious DACL modifications via the "Set-Service" cmdlet using the "SecurityDescriptorSddl" flag (Only available with PowerShell 7) that can be used to hide services or make them unstopable
windows · process_creation
Suspicious Service DACL Modification Via Set-Service Cmdlet - PS
highDetects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)
windows · ps_script
Suspicious Service Installation
highDetects suspicious service installation commands
windows · system
Suspicious Service Installation Script
highDetects suspicious service installation scripts
windows · system
Suspicious Service Path Modification
highDetects service path modification via the "sc" binary to a suspicious command or path
windows · process_creation
Suspicious ShellExec_RunDLL Call Via Ordinal
highDetects suspicious call to the "ShellExec_RunDLL" exported function of SHELL32.DLL through the ordinal number to launch other commands. Adversary might only use the ordinal number in order to bypass existing detection that alert on usage of ShellExec_RunDLL on CommandLine.
windows · process_creation
Suspicious Shells Spawn by Java Utility Keytool
highDetects suspicious shell spawn from Java utility keytool process (e.g. adselfservice plus exploitation)
windows · process_creation
Suspicious Shim Database Patching Activity
highDetects installation of new shim databases that try to patch sections of known processes for potential process injection or persistence.
windows · registry_set
Suspicious Space Characters in RunMRU Registry Path - ClickFix
highDetects the occurrence of numerous space characters in RunMRU registry paths, which may indicate execution via phishing lures using clickfix techniques to hide malicious commands in the Windows Run dialog box from naked eyes.
windows · registry_set
Suspicious Space Characters in TypedPaths Registry Path - FileFix
highDetects the occurrence of numerous space characters in TypedPaths registry paths, which may indicate execution via phishing lures using file-fix techniques to hide malicious commands.
windows · registry_set
Suspicious Speech Runtime Binary Child Process
highDetects suspicious Speech Runtime Binary Execution by monitoring its child processes. Child processes spawned by SpeechRuntime.exe could indicate an attempt for lateral movement via COM & DCOM hijacking.
windows · process_creation
Suspicious Splwow64 Without Params
highDetects suspicious Splwow64.exe process without any command line parameters
windows · process_creation
Suspicious Spool Service Child Process
highDetects suspicious print spool service (spoolsv.exe) child processes.
windows · process_creation
Suspicious Startup Folder Persistence
highDetects the creation of potentially malicious script and executable files in Windows startup folders, which is a common persistence technique used by threat actors. These files (.ps1, .vbs, .js, .bat, etc.) are automatically executed when a user logs in, making the Startup folder an attractive target for attackers. This technique is frequently observed in malvertising campaigns and malware distribution where attackers attempt to maintain long-term access to compromised systems.
windows · file_event
Suspicious Svchost Process Access
highDetects suspicious access to the "svchost" process such as that used by Invoke-Phantom to kill the thread of the Windows event logging service.
windows · process_access
Suspicious Sysmon as Execution Parent
highDetects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)
windows · process_creation
Suspicious SYSTEM User Process Creation
highDetects a suspicious process creation as SYSTEM user (suspicious program or command line parameter)
windows · process_creation
Suspicious Teams Application Related ObjectAcess Event
highDetects an access to authentication tokens and accounts of Microsoft Teams desktop application.
windows · security
Suspicious TSCON Start as SYSTEM
highDetects a tscon.exe start as LOCAL SYSTEM
windows · process_creation
Suspicious UltraVNC Execution
highDetects suspicious UltraVNC command line flag combination that indicate a auto reconnect upon execution, e.g. startup (as seen being used by Gamaredon threat group)
windows · process_creation
Suspicious Uninstall of Windows Defender Feature via PowerShell
highDetects the use of PowerShell with Uninstall-WindowsFeature or Remove-WindowsFeature cmdlets to disable or remove the Windows Defender GUI feature, a common technique used by adversaries to evade defenses.
windows · process_creation
Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded
highDetects the load of dbghelp/dbgcore DLL (used to make memory dumps) by suspicious processes. Tools like ProcessHacker and some attacker tradecract use MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine.
windows · image_load
Suspicious Unsigned Thor Scanner Execution
highDetects loading and execution of an unsigned thor scanner binary.
windows · image_load
Suspicious Usage Of ShellExec_RunDLL
highDetects suspicious usage of the ShellExec_RunDLL function to launch other commands as seen in the the raspberry-robin attack
windows · process_creation
Suspicious Use of CSharp Interactive Console
highDetects the execution of CSharp interactive console by PowerShell
windows · process_creation
Suspicious VBScript UN2452 Pattern
highDetects suspicious inline VBScript keywords as used by UNC2452
windows · process_creation
Suspicious Velociraptor Child Process
highDetects the suspicious use of the Velociraptor DFIR tool to execute other tools or download additional payloads, as seen in a campaign where it was abused for remote access and to stage further attacks.
windows · process_creation
Suspicious Volume Shadow Copy VSS_PS.dll Load
highDetects the image load of vss_ps.dll by uncommon executables. This DLL is used by the Volume Shadow Copy Service (VSS) to manage shadow copies of files and volumes. It is often abused by attackers to delete or manipulate shadow copies, which can hinder forensic investigations and data recovery efforts. The fact that it is loaded by processes that are not typically associated with VSS operations can indicate suspicious activity.
windows · image_load
Suspicious Volume Shadow Copy Vssapi.dll Load
highDetects the image load of VSS DLL by uncommon executables
windows · image_load
Suspicious WebDav Client Execution Via Rundll32.EXE
highDetects "svchost.exe" spawning "rundll32.exe" with command arguments like C:\windows\system32\davclnt.dll,DavSetCookie. This could be an indicator of exfiltration or use of WebDav to launch code (hosted on WebDav Server) or potentially a sign of exploitation of CVE-2023-23397
windows · process_creation
Suspicious Windows ANONYMOUS LOGON Local Account Created
highDetects the creation of suspicious accounts similar to ANONYMOUS LOGON, such as using additional spaces. Created as an covering detection for exclusion of Logon Type 3 from ANONYMOUS LOGON accounts.
windows · security
Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
highDetects the usage of "reg.exe" to tamper with different Windows Defender registry keys in order to disable some important features related to protection and detection
windows · process_creation
Suspicious Windows Service Tampering
highDetects the usage of binaries such as 'net', 'sc' or 'powershell' in order to stop, pause, disable or delete critical or important Windows services such as AV, Backup, etc. As seen being used in some ransomware scripts
windows · process_creation
Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
highDetects the execution of "logman" utility in order to disable or delete Windows trace sessions
windows · process_creation
Suspicious Windows Update Agent Empty Cmdline
highDetects suspicious Windows Update Agent activity in which a wuauclt.exe process command line doesn't contain any command line flags
windows · process_creation
Suspicious WMIC Execution Via Office Process
highOffice application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).
windows · process_creation
Suspicious WmiPrvSE Child Process
highDetects suspicious and uncommon child processes of WmiPrvSE
windows · process_creation
Suspicious Word Cab File Write CVE-2021-40444
highDetects file creation patterns noticeable during the exploitation of CVE-2021-40444
windows · file_event
Sysinternals PsSuspend Suspicious Execution
highDetects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses
windows · process_creation
SysKey Registry Keys Access
highDetects handle requests and access operations to specific registry keys to calculate the SysKey
windows · security
Sysmon Application Crashed
highDetects application popup reporting a failure of the Sysmon service
windows · system
Sysmon Blocked Executable
highTriggers on any Sysmon "FileBlockExecutable" event, which indicates a violation of the configured block policy
windows · sysmon
Sysmon Blocked File Shredding
highTriggers on any Sysmon "FileBlockShredding" event, which indicates a violation of the configured shredding policy.
windows · sysmon
Sysmon Channel Reference Deletion
highPotential threat actor tampering with Sysmon manifest and eventually disabling it
windows · security
Sysmon Configuration Error
highDetects when an adversary is trying to hide it's action from Sysmon logging based on error messages
windows · sysmon_error
Sysmon Configuration Modification
highDetects when an attacker tries to hide from Sysmon by disabling or stopping it
windows · sysmon_status
Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE
highDetects usage of "findstr" with the argument "385201". Which could indicate potential discovery of an installed Sysinternals Sysmon service using the default driver altitude (even if the name is changed).
windows · process_creation
Sysmon Driver Altitude Change
highDetects changes in Sysmon driver altitude value. If the Sysmon driver is configured to load at an altitude of another registered service, it will fail to load at boot.
windows · registry_set
Sysmon Driver Unloaded Via Fltmc.EXE
highDetects possible Sysmon filter driver unloaded via fltmc.exe
windows · process_creation
System Control Panel Item Loaded From Uncommon Location
highDetects image load events of system control panel items (.cpl) from uncommon or non-system locations that may indicate DLL sideloading or other abuse techniques.
windows · image_load
System File Execution Location Anomaly
highDetects the execution of a Windows system binary that is usually located in the system folder from an uncommon location.
windows · process_creation
System Restore Registry Modification via CommandLine
highDetects system restore registry modification via command line, which can be used by adversaries to disable system restore on the computer.
windows · process_creation
T1047 Wmiprvse Wbemcomn DLL Hijack
highDetects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network for a WMI DLL Hijack scenario.
windows · security
TAIDOOR RAT DLL Load
highDetects specific process characteristics of Chinese TAIDOOR RAT malware load
windows · process_creation
Tamper Windows Defender - PSClassic
highAttempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.
windows · ps_classic_provider_start
Tamper Windows Defender - ScriptBlockLogging
highDetects PowerShell scripts attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.
windows · ps_script
Tamper Windows Defender Remove-MpPreference
highDetects attempts to remove Windows Defender configurations using the 'MpPreference' cmdlet
windows · process_creation
Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
highDetects attempts to remove Windows Defender configuration using the 'MpPreference' cmdlet
windows · ps_script
Tamper With Sophos AV Registry Keys
highDetects tamper attempts to sophos av functionality via registry key modification
windows · registry_set
TanStack Supply-Chain Attack Execution Indicators - Windows
highDetects process execution indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath reported on early May 2026.
windows · process_creation
Taskkill Symantec Endpoint Protection
highDetects one of the possible scenarios for disabling Symantec Endpoint Protection. Symantec Endpoint Protection antivirus software services incorrectly implement the protected service mechanism. As a result, the NT AUTHORITY/SYSTEM user can execute the taskkill /im command several times ccSvcHst.exe /f, thereby killing the process belonging to the service, and thus shutting down the service.
windows · process_creation
Taskmgr as LOCAL_SYSTEM
highDetects the creation of taskmgr.exe process in context of LOCAL_SYSTEM
windows · process_creation
Tasks Folder Evasion
highThe Tasks folder in system32 and syswow64 are globally writable paths. Adversaries can take advantage of this and load or influence any script hosts or ANY .NET Application in Tasks to load and execute a custom assembly into cscript, wscript, regsvr32, mshta, eventvwr
windows · process_creation
Terminal Server Client Connection History Cleared - Registry
highDetects the deletion of registry keys containing the MSTSC connection history
windows · registry_delete
Terminal Service Process Spawn
highDetects a process spawned by the terminal service server process (this could be an indicator for an exploitation of CVE-2019-0708)
windows · process_creation
Time Travel Debugging Utility Usage
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows · process_creation
Time Travel Debugging Utility Usage - Image
highDetects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.
windows · image_load
Tor Client/Browser Execution
highDetects the use of Tor or Tor-Browser to connect to onion routing networks
windows · process_creation
Trickbot Malware Activity
highDetects Trickbot malware process tree pattern in which "rundll32.exe" is a parent of "wermgr.exe"
windows · process_creation
TropicTrooper Campaign November 2018
highDetects TropicTrooper activity, an actor who targeted high-profile organizations in the energy and food and beverage sectors in Asia
windows · process_creation
Trust Access Disable For VBApplications
highDetects registry changes to Microsoft Office "AccessVBOM" to a value of "1" which disables trust access for VBA on the victim machine and lets attackers execute malicious macros without any Microsoft Office warnings.
windows · registry_set
Trusted Path Bypass via Windows Directory Spoofing
highDetects DLLs loading from a spoofed Windows directory path with an extra space (e.g "C:\Windows \System32") which can bypass Windows trusted path verification. This technique tricks Windows into treating the path as trusted, allowing malicious DLLs to load with high integrity privileges bypassing UAC.
windows · image_load
Turla Service Install
highThis method detects a service install of malicious services mentioned in Carbon Paper - Turla report by ESET
windows · system
UAC Bypass Abusing Winsat Path Parsing - File
highDetects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
windows · file_event
UAC Bypass Abusing Winsat Path Parsing - Process
highDetects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
windows · process_creation
UAC Bypass Abusing Winsat Path Parsing - Registry
highDetects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)
windows · registry_set
UAC Bypass Tools Using ComputerDefaults
highDetects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)
windows · process_creation
UAC Bypass Using .NET Code Profiler on MMC
highDetects the pattern of UAC Bypass using .NET Code Profiler and mmc.exe DLL hijacking (UACMe 39)
windows · file_event
UAC Bypass Using ChangePK and SLUI
highDetects an UAC bypass that uses changepk.exe and slui.exe (UACMe 61)
windows · process_creation
UAC Bypass Using Consent and Comctl32 - File
highDetects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
windows · file_event
UAC Bypass Using Consent and Comctl32 - Process
highDetects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)
windows · process_creation
UAC Bypass Using Disk Cleanup
highDetects the pattern of UAC Bypass using scheduled tasks and variable expansion of cleanmgr.exe (UACMe 34)
windows · process_creation
UAC Bypass Using DismHost
highDetects the pattern of UAC Bypass using DismHost DLL hijacking (UACMe 63)
windows · process_creation
UAC Bypass Using Event Viewer RecentViews
highDetects the pattern of UAC Bypass using Event Viewer RecentViews
windows · process_creation
UAC Bypass Using EventVwr
highDetects the pattern of a UAC bypass using Windows Event Viewer
windows · file_event
UAC Bypass Using IDiagnostic Profile
highDetects the "IDiagnosticProfileUAC" UAC bypass technique
windows · process_creation
UAC Bypass Using IDiagnostic Profile - File
highDetects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique
windows · file_event
UAC Bypass Using IEInstal - File
highDetects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)
windows · file_event
UAC Bypass Using IEInstal - Process
highDetects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)
windows · process_creation
UAC Bypass Using Iscsicpl - ImageLoad
highDetects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%
windows · image_load
UAC Bypass Using MSConfig Token Modification - File
highDetects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
windows · file_event
UAC Bypass Using MSConfig Token Modification - Process
highDetects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)
windows · process_creation
UAC Bypass Using NTFS Reparse Point - File
highDetects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
windows · file_event
UAC Bypass Using NTFS Reparse Point - Process
highDetects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)
windows · process_creation
UAC Bypass Using PkgMgr and DISM
highDetects the pattern of UAC Bypass using pkgmgr.exe and dism.exe (UACMe 23)
windows · process_creation
UAC Bypass Using Windows Media Player - File
highDetects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
windows · file_event
UAC Bypass Using Windows Media Player - Process
highDetects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
windows · process_creation
UAC Bypass Using Windows Media Player - Registry
highDetects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)
windows · registry_set
UAC Bypass Using WOW64 Logger DLL Hijack
highDetects the pattern of UAC Bypass using a WoW64 logger DLL hijack (UACMe 30)
windows · process_access
UAC Bypass via Event Viewer
highDetects UAC bypass method using Windows event viewer
windows · registry_set
UAC Bypass via ICMLuaUtil
highDetects the pattern of UAC Bypass using ICMLuaUtil Elevated COM interface
windows · process_creation
UAC Bypass via Sdclt
highDetects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)
windows · registry_set
UAC Bypass Via Wsreset
highUnfixed method for UAC bypass from Windows 10. WSReset.exe file associated with the Windows Store. It will run a binary file contained in a low-privilege registry.
windows · registry_event
UAC Bypass With Fake DLL
highAttempts to load dismcore.dll after dropping it
windows · image_load
UAC Bypass WSReset
highDetects the pattern of UAC Bypass via WSReset usable by default sysmon-config
windows · process_creation
UEFI Persistence Via Wpbbin - FileCreation
highDetects creation of a file named "wpbbin" in the "%systemroot%\system32\" directory. Which could be indicative of UEFI based persistence method
windows · file_event
UEFI Persistence Via Wpbbin - ProcessCreation
highDetects execution of the binary "wpbbin" which is used as part of the UEFI based persistence method described in the reference section
windows · process_creation
UNC2452 Process Creation Patterns
highDetects a specific process creation patterns as seen used by UNC2452 and provided by Microsoft as Microsoft Defender ATP queries
windows · process_creation
Uncommon Child Process Of Setres.EXE
highDetects uncommon child process of Setres.EXE. Setres.EXE is a Windows server only process and tool that can be used to set the screen resolution. It can potentially be abused in order to launch any arbitrary file with a name containing the word "choice" from the current execution path.
windows · process_creation
Uncommon Extension In Keyboard Layout IME File Registry Value
highDetects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message. Before doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named "Ime File" with a DLL path. IMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.
windows · registry_set
Uncommon File Created by Notepad++ Updater Gup.EXE
highDetects when the Notepad++ updater (gup.exe) creates files in suspicious or uncommon locations. This could indicate potential exploitation of the updater component to deliver unwanted malware or unwarranted files.
windows · file_event
Uncommon File Created In Office Startup Folder
highDetects the creation of a file with an uncommon extension in an Office application startup folder
windows · file_event
Uncommon File Creation By Mysql Daemon Process
highDetects the creation of files with scripting or executable extensions by Mysql daemon. Which could be an indicator of "User Defined Functions" abuse to download malware.
windows · file_event
Uncommon FileSystem Load Attempt By Format.com
highDetects the execution of format.com with an uncommon filesystem selection that could indicate a defense evasion activity in which "format.com" is used to load malicious DLL files or other programs.
windows · process_creation
Uncommon Microsoft Office Trusted Location Added
highDetects changes to registry keys related to "Trusted Location" of Microsoft Office where the path is set to something uncommon. Attackers might add additional trusted locations to avoid macro security restrictions.
windows · registry_set
Uncommon Network Connection Initiated By Certutil.EXE
highDetects a network connection initiated by the certutil.exe utility. Attackers can abuse the utility in order to download malware or additional payloads.
windows · network_connection
Uncommon One Time Only Scheduled Task At 00:00
highDetects scheduled task creation events that include suspicious actions, and is run once at 00:00
windows · process_creation
Uncommon Svchost Command Line Parameter
highDetects instances of svchost.exe running with an unusual or uncommon command line parameter by excluding known legitimate or common patterns. This could point at a file masquerading as svchost, a process injection, or hollowing of a legitimate svchost instance.
windows · process_creation
Uncommon Userinit Child Process
highDetects uncommon "userinit.exe" child processes, which could be a sign of uncommon shells or login scripts used for persistence.
windows · process_creation
Uninstall Crowdstrike Falcon Sensor
highAdversaries may disable security tools to avoid possible detection of their tools and activities by uninstalling Crowdstrike Falcon
windows · process_creation
Uninstall Sysinternals Sysmon
highDetects the removal of Sysmon, which could be a potential attempt at defense evasion
windows · process_creation
Unsigned Binary Loaded From Suspicious Location
highDetects Code Integrity (CI) engine blocking processes from loading unsigned DLLs residing in suspicious locations
windows · security-mitigations
Unsigned Mfdetours.DLL Sideloading
highDetects DLL sideloading of unsigned "mfdetours.dll". Executing "mftrace.exe" can be abused to attach to an arbitrary process and force load any DLL named "mfdetours.dll" from the current directory of execution.
windows · image_load
Unusual Child Process of dns.exe
highDetects an unexpected process spawning from dns.exe which may indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows · process_creation
Unusual File Deletion by Dns.exe
highDetects an unexpected file being deleted by dns.exe which my indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows · file_delete
Unusual File Download from Direct IP Address
highDetects the download of suspicious file type from URLs with IP
windows · create_stream_hash
Unusual File Modification by dns.exe
highDetects an unexpected file being modified by dns.exe which my indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
windows · file_change
Ursnif Redirection Of Discovery Commands
highDetects the redirection of Ursnif discovery commands as part of the initial execution of the malware.
windows · process_creation
Usage of Renamed Sysinternals Tools - RegistrySet
highDetects non-sysinternals tools setting the "accepteula" key which normally is set on sysinternals tool execution
windows · registry_set
Use of W32tm as Timer
highWhen configured with suitable command line arguments, w32tm can act as a delay mechanism
windows · process_creation
User Added To Highly Privileged Group
highDetects addition of users to highly privileged groups via "Net" or "Add-LocalGroupMember".
windows · process_creation
User Added to Remote Desktop Users Group
highDetects addition of users to the local Remote Desktop Users group via "Net" or "Add-LocalGroupMember".
windows · process_creation
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'
highThe 'LsaRegisterLogonProcess' function verifies that the application making the function call is a logon process by checking that it has the SeTcbPrivilege privilege set. Possible Rubeus tries to get a handle to LSA.
windows · security
User Shell Folders Registry Modification via CommandLine
highDetects modifications to User Shell Folders registry values via reg.exe or PowerShell, which could indicate persistence attempts. Attackers may modify User Shell Folders registry values to point to malicious executables or scripts that will be executed during startup. This technique is often used to maintain persistence on a compromised system by ensuring that malicious payloads are executed automatically.
windows · process_creation
Using SettingSyncHost.exe as LOLBin
highDetects using SettingSyncHost.exe to run hijacked binary
windows · process_creation
VBA DLL Loaded Via Office Application
highDetects VB DLL's loaded by an office application. Which could indicate the presence of VBA Macros.
windows · image_load
VBScript Payload Stored in Registry
highDetects VBScript content stored into registry keys as seen being used by UNC2452 group
windows · registry_set
Veeam Backup Servers Credential Dumping Script Execution
highDetects execution of a PowerShell script that contains calls to the "Veeam.Backup" class, in order to dump stored credentials.
windows · ps_script
VeeamBackup Database Credentials Dump Via Sqlcmd.EXE
highDetects dump of credentials in VeeamBackup dbo
windows · process_creation
Visual Basic Command Line Compiler Usage
highDetects successful code compilation via Visual Basic Command Line Compiler that utilizes Windows Resource to Object Converter.
windows · process_creation
VMMap Unsigned Dbghelp.DLL Potential Sideloading
highDetects potential DLL sideloading of an unsigned dbghelp.dll by the Sysinternals VMMap.
windows · image_load
VMToolsd Suspicious Child Process
highDetects suspicious child process creations of VMware Tools process which may indicate persistence setup
windows · process_creation
VolumeShadowCopy Symlink Creation Via Mklink
highShadow Copies storage symbolic link creation using operating systems utilities
windows · process_creation
Vulnerable Driver Blocklist Registry Tampering Via CommandLine
highDetects tampering of the Vulnerable Driver Blocklist registry via command line tools such as PowerShell or REG.EXE. The Vulnerable Driver Blocklist is a security feature that helps prevent the loading of known vulnerable drivers. Disabling this feature may indicate an attempt to bypass security controls, often targeted by threat actors to facilitate the installation of malicious or vulnerable drivers, particularly in scenarios involving Endpoint Detection and Response
windows · process_creation
Vulnerable Driver Load
highDetects loading of known vulnerable drivers via their hash.
windows · driver_load
Vulnerable HackSys Extreme Vulnerable Driver Load
highDetects the load of HackSys Extreme Vulnerable Driver which is an intentionally vulnerable Windows driver developed for security enthusiasts to learn and polish their exploitation skills at Kernel level and often abused by threat actors
windows · driver_load
Vulnerable Netlogon Secure Channel Connection Allowed
highDetects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.
windows · system
Vulnerable WinRing0 Driver Load
highDetects the load of a signed WinRing0 driver often used by threat actors, crypto miners (XMRIG) or malware for privilege escalation
windows · driver_load
Wab Execution From Non Default Location
highDetects execution of wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) from non default locations as seen with bumblebee activity
windows · process_creation
Wab/Wabmig Unusual Parent Or Child Processes
highDetects unusual parent or children of the wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) processes as seen being used with bumblebee activity
windows · process_creation
Wdigest CredGuard Registry Modification
highDetects potential malicious modification of the property value of IsCredGuardEnabled from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to disable Cred Guard on a system. This is usually used with UseLogonCredential to manipulate the caching credentials.
windows · registry_event
Wdigest Enable UseLogonCredential
highDetects potential malicious modification of the property value of UseLogonCredential from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to enable clear-text credentials
windows · registry_set
Weak Encryption Enabled and Kerberoast
highDetects scenario where weak encryption is enabled for a user profile which could be used for hash/password cracking.
windows · security
Webshell Detection With Command Line Keywords
highDetects certain command line parameters often used during reconnaissance activity via web shells
windows · process_creation
Webshell Hacking Activity Patterns
highDetects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system
windows · process_creation
Webshell Tool Reconnaissance Activity
highDetects processes spawned from web servers (PHP, Tomcat, IIS, etc.) that perform reconnaissance looking for the existence of popular scripting tools (perl, python, wget) on the system via the help commands
windows · process_creation
WerFault LSASS Process Memory Dump
highDetects WerFault creating a dump file with a name that indicates that the dump file could be an LSASS process memory, which contains user credentials
windows · file_event
WhoAmI as Parameter
highDetects a suspicious process command line that uses whoami as first parameter (as e.g. used by EfsPotato)
windows · process_creation
Whoami.EXE Execution From Privileged Process
highDetects the execution of "whoami.exe" by privileged accounts that are often abused by threat actors
windows · process_creation
Win Defender Restored Quarantine File
highDetects the restoration of files from the defender quarantine
windows · windefend
WinDivert Driver Load
highDetects the load of the Windiver driver, a powerful user-mode capture/sniffing/modification/blocking/re-injection package for Windows
windows · driver_load
Windows AMSI Related Registry Tampering Via CommandLine
highDetects tampering of AMSI (Anti-Malware Scan Interface) related registry values via command line tools such as reg.exe or PowerShell. AMSI provides a generic interface for applications and services to integrate with antimalware products. Adversaries may disable AMSI to evade detection of malicious scripts and code execution.
windows · process_creation
Windows Binaries Write Suspicious Extensions
highDetects Windows executables that write files with suspicious extensions
windows · file_event
Windows Credential Guard Disabled - Registry
highDetects attempts to disable Windows Credential Guard by setting registry values to 0. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.
windows · registry_set
Windows Credential Guard Registry Tampering Via CommandLine
highDetects attempts to add, modify, or delete Windows Credential Guard related registry keys or values via command line tools such as Reg.exe or PowerShell. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation. The rule matches suspicious command lines that target DeviceGuard or LSA registry paths and manipulate keys like EnableVirtualizationBasedSecurity, RequirePlatformSecurityFeatures, or LsaCfgFlags. Such activity may indicate an attempt to disable or tamper with Credential Guard, potentially exposing sensitive credentials for misuse.
windows · process_creation
Windows Credential Guard Related Registry Value Deleted - Registry
highDetects attempts to disable Windows Credential Guard by deleting registry values. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.
windows · registry_delete
Windows Defender AMSI Trigger Detected
highDetects triggering of AMSI by Windows Defender.
windows · windefend
Windows Defender Configuration Changes
highDetects suspicious changes to the Windows Defender configuration
windows · windefend
Windows Defender Context Menu Removed
highDetects the use of reg.exe or PowerShell to delete the Windows Defender context menu handler registry keys. This action removes the "Scan with Microsoft Defender" option from the right-click menu for files, directories, and drives. Attackers may use this technique to hinder manual, on-demand scans and reduce the visibility of the security product.
windows · process_creation
Windows Defender Definition Files Removed
highAdversaries may disable security tools to avoid possible detection of their tools and activities by removing Windows Defender Definition Files
windows · process_creation
Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
highDetects the usage of SystemSettingsAdminFlows.exe to disable Windows Defender. SystemSettingsAdminFlows.exe is a legitimate Windows component used for administrative configuration tasks. However, attackers may abuse it to disable Windows Defender as part of their attack chain, especially in the context of ransomware or other malware campaigns.
windows · process_creation
Windows Defender Exploit Guard Tamper
highDetects when someone is adding or removing applications or folders from exploit guard "ProtectedFolders" or "AllowedApplications"
windows · windefend
Windows Defender Grace Period Expired
highDetects the expiration of the grace period of Windows Defender. This means protection against viruses, spyware, and other potentially unwanted software is disabled.
windows · windefend
Windows Defender Malware And PUA Scanning Disabled
highDetects disabling of the Windows Defender feature of scanning for malware and other potentially unwanted software
windows · windefend
Windows Defender Real-time Protection Disabled
highDetects disabling of Windows Defender Real-time Protection. As this event doesn't contain a lot of information on who initiated this action you might want to reduce it to a "medium" level if this occurs too many times in your environment
windows · windefend
Windows Defender Service Disabled - Registry
highDetects when an attacker or tool disables the Windows Defender service (WinDefend) via the registry
windows · registry_set
Windows Defender Threat Detected
highDetects actions taken by Windows Defender malware detection engines
windows · windefend
Windows Defender Threat Severity Default Action Modified
highDetects modifications or creations of Windows Defender's default threat action settings based on severity to 'allow' or take 'no action'. This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level, allowing malicious software to run unimpeded. An attacker might use this technique to bypass defenses before executing payloads.
windows · registry_event
Windows Defender Virus Scanning Feature Disabled
highDetects disabling of the Windows Defender virus scanning feature
windows · windefend
Windows Event Log Access Tampering Via Registry
highDetects changes to the Windows EventLog channel permission values. It focuses on changes to the Security Descriptor Definition Language (SDDL) string, as modifications to these values can restrict access to specific users or groups, potentially aiding in defense evasion by controlling who can view or modify a event log channel. Upon execution, the user shouldn't be able to access the event log channel via the event viewer or via utilities such as "Get-EventLog" or "wevtutil".
windows · registry_set
Windows EventLog Autologger Session Registry Modification Via CommandLine
highDetects attempts to disable Windows EventLog autologger sessions via registry modification. The AutoLogger event tracing session records events that occur early in the operating system boot process. Applications and device drivers can use the AutoLogger session to capture traces before the user logs in. Adversaries may disable these sessions to evade detection and prevent security monitoring of early boot activities and system events.
windows · process_creation
Windows Filtering Platform Blocked Connection From EDR Agent Binary
highDetects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents. Adversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.
windows · security
Windows Hypervisor Enforced Code Integrity Disabled
highDetects changes to the HypervisorEnforcedCodeIntegrity registry key and the "Enabled" value being set to 0 in order to disable the Hypervisor Enforced Code Integrity feature. This allows an attacker to load unsigned and untrusted code to be run in the kernel
windows · registry_set
Windows Internet Hosted WebDav Share Mount Via Net.EXE
highDetects when an internet hosted webdav share is mounted using the "net.exe" utility
windows · process_creation
Windows Shell/Scripting Application File Write to Suspicious Folder
highDetects Windows shells and scripting applications that write files to suspicious folders
windows · file_event
Windows Shell/Scripting Processes Spawning Suspicious Programs
highDetects suspicious child processes of a Windows shell and scripting processes such as wscript, rundll32, powershell, mshta...etc.
windows · process_creation
Windows Suspicious Child Process from Node.js - React2Shell
highDetects suspicious child processes started by Node.js server processes on Windows, which may indicate exploitation of vulnerabilities like CVE-2025-55182 (React2Shell). Attackers can abuse the Node.js 'child_process' module to run system commands or scripts using methods such as spawn(), exec(), execFile(), fork(), or execSync(). If execSync() or exec() is used in the exploit, the command line often shows a shell (e.g., cmd.exe /d /s /c ...) running a suspicious command unless other shells are explicitly invoked. For other methods, the spawned process appears directly in the Image field unless a shell is explicitly used.
windows · process_creation
Windows Vulnerable Driver Blocklist Disabled
highDetects when the Windows Vulnerable Driver Blocklist is set to disabled. This setting is crucial for preventing the loading of known vulnerable drivers, and its modification may indicate an attempt to bypass security controls. It is often targeted by threat actors to facilitate the installation of malicious or vulnerable drivers, particularly in scenarios involving Endpoint Detection and Response (EDR) bypass techniques. This rule applies to systems that support the Vulnerable Driver Blocklist feature, including Windows 10 version 1903 and later, and Windows Server 2022 and later. Note that this change will require a reboot to take effect, and this rule only detects the registry modification action.
windows · registry_set
WINEKEY Registry Modification
highDetects potential malicious modification of run keys by winekey or team9 backdoor
windows · registry_event
Winlogon Notify Key Logon Persistence
highAdversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete.
windows · registry_set
WinRAR Creating Files in Startup Locations
highDetects WinRAR creating files in Windows startup locations, which may indicate an attempt to establish persistence by adding malicious files to the Startup folder. This kind of behaviour has been associated with exploitation of WinRAR path traversal vulnerability CVE-2025-6218 or CVE-2025-8088.
windows · file_event
Winrs Local Command Execution
highDetects the execution of Winrs.exe where it is used to execute commands locally. Commands executed this way are launched under Winrshost.exe and can represent proxy execution used for defense evasion or lateral movement.
windows · process_creation
WMI Persistence - Command Line Event Consumer
highDetects WMI command line event consumers
windows · image_load
WMI Persistence - Script Event Consumer File Write
highDetects file writes of WMI script event consumer
windows · file_event
WMImplant Hack Tool
highDetects parameters used by WMImplant
windows · ps_script
Wmiprvse Wbemcomn DLL Hijack
highDetects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network and loading it for a WMI DLL Hijack scenario.
windows · image_load
WScript or CScript Dropper - File
highDetects a file ending in jse, vbe, js, vba, vbs, wsf, wsh written by cscript.exe or wscript.exe
windows · file_event
WSL Kali-Linux Usage
highDetects the use of Kali Linux through Windows Subsystem for Linux
windows · process_creation
Wusa.EXE Executed By Parent Process Located In Suspicious Location
highDetects execution of the "wusa.exe" (Windows Update Standalone Installer) utility by a parent process that is located in a suspicious location. Attackers could instantiate an instance of "wusa.exe" in order to bypass User Account Control (UAC). They can duplicate the access token from "wusa.exe" to gain elevated privileges.
windows · process_creation
Xwizard.EXE Execution From Non-Default Location
highDetects the execution of Xwizard tool from a non-default directory. When executed from a non-default directory, this utility can be abused in order to side load a custom version of "xwizards.dll".
windows · process_creation
7Zip Compressing Dump Files
mediumDetects execution of 7z in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows · process_creation
A New Trust Was Created To A Domain
mediumAddition of domains is seldom and should be verified for legitimacy.
windows · security
A Rule Has Been Deleted From The Windows Firewall Exception List
mediumDetects when a single rules or all of the rules have been deleted from the Windows Defender Firewall
windows · firewall-as
Abusing Print Executable
mediumAttackers can use print.exe for remote file copy
windows · process_creation
Access to Browser Login Data
mediumAdversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store.
windows · ps_script
Access To Crypto Currency Wallets By Uncommon Applications
mediumDetects file access requests to crypto currency files by uncommon processes. Could indicate potential attempt of crypto currency wallet stealing.
windows · file_access
Access To Potentially Sensitive Sysvol Files By Uncommon Applications
mediumDetects file access requests to potentially sensitive files hosted on the Windows Sysvol share.
windows · file_access
Access To Sysvol Policies Share By Uncommon Process
mediumDetects file access requests to the Windows Sysvol Policies Share by uncommon processes
windows · file_access
Access To Windows Credential History File By Uncommon Applications
mediumDetects file access requests to the Windows Credential History File by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::credhist" function
windows · file_access
Access To Windows DPAPI Master Keys By Uncommon Applications
mediumDetects file access requests to the the Windows Data Protection API Master keys by an uncommon application. This can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::masterkey" function
windows · file_access
Account Tampering - Suspicious Failed Logon Reasons
mediumThis method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.
windows · security
Activate Suppression of Windows Security Center Notifications
mediumDetect set Notification_Suppress to 1 to disable the Windows security center notification
windows · registry_set
Active Directory Database Snapshot Via ADExplorer
mediumDetects the execution of Sysinternals ADExplorer with the "-snapshot" flag in order to save a local copy of the active directory database. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · process_creation
Active Directory Replication from Non Machine Account - DcSync Indicator
mediumDetects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials.
windows · security
Active Directory Structure Export Via Csvde.EXE
mediumDetects the execution of "csvde.exe" in order to export organizational Active Directory structure.
windows · process_creation
Active Directory Structure Export Via Ldifde.EXE
mediumDetects the execution of "ldifde.exe" in order to export organizational Active Directory structure.
windows · process_creation
Add Debugger Entry To AeDebug For Persistence
mediumDetects when an attacker adds a new "Debugger" value to the "AeDebug" key in order to achieve persistence which will get invoked when an application crashes
windows · registry_set
Add DisallowRun Execution to Registry
mediumDetect set DisallowRun to 1 to prevent user running specific computer program
windows · registry_set
Add New Download Source To Winget
mediumDetects usage of winget to add new additional download sources
windows · process_creation
Add Port Monitor Persistence in Registry
mediumAdversaries may use port monitors to run an attacker supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup.
windows · registry_set
Add Potential Suspicious New Download Source To Winget
mediumDetects usage of winget to add new potentially suspicious download sources
windows · process_creation
Add Windows Capability Via PowerShell Cmdlet
mediumDetects usage of the "Add-WindowsCapability" cmdlet to add Windows capabilities. Notable capabilities could be "OpenSSH" and others.
windows · process_creation
Add Windows Capability Via PowerShell Script
mediumDetects usage of the "Add-WindowsCapability" cmdlet to add Windows capabilities. Notable capabilities could be "OpenSSH" and others.
windows · ps_script
AddinUtil.EXE Execution From Uncommon Directory
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) from a non-standard directory.
windows · process_creation
Addition of SID History to Active Directory Object
mediumAn attacker can use the SID history attribute to gain additional privileges.
windows · security
ADExplorer Writing Complete AD Snapshot Into .dat File
mediumDetects the dual use tool ADExplorer writing a complete AD snapshot into a .dat file. This can be used by attackers to extract data for Bloodhound, usernames for password spraying or use the meta data for social engineering. The snapshot doesn't contain password hashes but there have been cases, where administrators put passwords in the comment field.
windows · file_event
ADFS Database Named Pipe Connection By Uncommon Tool
mediumDetects suspicious local connections via a named pipe to the AD FS configuration database (Windows Internal Database). Used to access information such as the AD FS configuration settings which contains sensitive information used to sign SAML tokens.
windows · pipe_created
ADS Zone.Identifier Deleted By Uncommon Application
mediumDetects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
windows · file_delete
ADSI-Cache File Creation By Uncommon Tool
mediumDetects the creation of an "Active Directory Schema Cache File" (.sch) file by an uncommon tool.
windows · file_event
Advanced IP Scanner - File Event
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows · file_event
AgentExecutor PowerShell Execution
mediumDetects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument
windows · process_creation
Allow RDP Remote Assistance Feature
mediumDetect enable rdp feature to allow specific user to rdp connect on the targeted machine
windows · registry_set
Alternate PowerShell Hosts - PowerShell Module
mediumDetects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
windows · ps_module
Alternate PowerShell Hosts Pipe
mediumDetects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
windows · pipe_created
Always Install Elevated MSI Spawned Cmd And Powershell
mediumDetects Windows Installer service (msiexec.exe) spawning "cmd" or "powershell"
windows · process_creation
Always Install Elevated Windows Installer
mediumDetects Windows Installer service (msiexec.exe) trying to install MSI packages with SYSTEM privilege
windows · process_creation
Amsi.DLL Loaded Via LOLBIN Process
mediumDetects loading of "Amsi.dll" by a living of the land process. This could be an indication of a "PowerShell without PowerShell" attack
windows · image_load
Anydesk Remote Access Software Service Installation
mediumDetects the installation of the anydesk software service. Which could be an indication of anydesk abuse if you the software isn't already used.
windows · system
Anydesk Temporary Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
Application Removed Via Wmic.EXE
mediumDetects the removal or uninstallation of an application via "Wmic.EXE".
windows · process_creation
Application Termination Attempt via Wmic.EXE
mediumDetects an attempt to terminate a process via "wmic" with the "call terminate" flag. Adversaries may use wmic to terminate security products or other applications on the compromised host. This event is triggered on on attempt and process creation can be either successful or unsuccessful.
windows · process_creation
AppLocker Application Would Have Been Blocked
mediumDetects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, or Packaged-App would have been blocked if AppLocker "Enforce rules" enforcement mode was enabled.
windows · applocker
AppLocker Prevented Application or Script from Running
mediumDetects when AppLocker prevents the execution of an Application, DLL, Script, MSI, or Packaged-App from running.
windows · applocker
AppX Located in Uncommon Directory Added to Deployment Pipeline
mediumDetects an appx package that was added to the pipeline of the "to be processed" packages that is located in uncommon locations.
windows · appxdeployment-server
AppX Package Deployment Failed Due to Signing Requirements
mediumDetects an appx package deployment / installation with the error code "0x80073cff" which indicates that the package didn't meet the signing requirements.
windows · appxdeployment-server
AppX Package Installation Attempts Via AppInstaller.EXE
mediumDetects DNS queries made by "AppInstaller.EXE". The AppInstaller is the default handler for the "ms-appinstaller" URI. It attempts to load/install a package from the referenced URL
windows · dns_query
Arbitrary Binary Execution Using GUP Utility
mediumDetects execution of the Notepad++ updater (gup) to launch other commands or executables
windows · process_creation
Arbitrary Command Execution Using WSL
mediumDetects potential abuse of Windows Subsystem for Linux (WSL) binary as a Living of the Land binary in order to execute arbitrary Linux or Windows commands.
windows · process_creation
Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
mediumDetects execution of arbitrary DLLs or unsigned code via a ".csproj" files via Dotnet.EXE.
windows · process_creation
Arbitrary File Download Via ConfigSecurityPolicy.EXE
mediumDetects the execution of "ConfigSecurityPolicy.EXE", a binary part of Windows Defender used to manage settings in Windows Defender. Users can configure different pilot collections for each of the co-management workloads. It can be abused by attackers in order to upload or download files.
windows · process_creation
Arbitrary File Download Via GfxDownloadWrapper.EXE
mediumDetects execution of GfxDownloadWrapper.exe with a URL as an argument to download file.
windows · process_creation
Arbitrary File Download Via MSEDGE_PROXY.EXE
mediumDetects usage of "msedge_proxy.exe" to download arbitrary files
windows · process_creation
Arbitrary File Download Via MSOHTMED.EXE
mediumDetects usage of "MSOHTMED" to download arbitrary files
windows · process_creation
Arbitrary File Download Via MSPUB.EXE
mediumDetects usage of "MSPUB" (Microsoft Publisher) to download arbitrary files
windows · process_creation
Arbitrary File Download Via PresentationHost.EXE
mediumDetects usage of "PresentationHost" which is a utility that runs ".xbap" (Browser Applications) files to download arbitrary files
windows · process_creation
Arbitrary File Download Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" to download arbitrary files. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows · process_creation
Arbitrary MSI Download Via Devinit.EXE
mediumDetects a certain command line flag combination used by "devinit.exe", which can be abused as a LOLBIN to download arbitrary MSI packages on a Windows system
windows · process_creation
Arbitrary Shell Command Execution Via Settingcontent-Ms
mediumThe .SettingContent-ms file type was introduced in Windows 10 and allows a user to create "shortcuts" to various Windows 10 setting pages. These files are simply XML and contain paths to various Windows 10 settings binaries.
windows · process_creation
AspNetCompiler Execution
mediumDetects execution of "aspnet_compiler.exe" which can be abused to compile and execute C# code.
windows · process_creation
Assembly DLL Creation Via AspNetCompiler
mediumDetects the creation of new DLL assembly files by "aspnet_compiler.exe", which could be a sign of "aspnet_compiler" abuse to proxy execution through a build provider.
windows · file_event
Assembly Loading Via CL_LoadAssembly.ps1
mediumDetects calls to "LoadAssemblyFromPath" or "LoadAssemblyFromNS" that are part of the "CL_LoadAssembly.ps1" script. This can be abused to load different assemblies and bypass App locker controls.
windows · process_creation
Atbroker Registry Change
mediumDetects creation/modification of Assistive Technology applications and persistence with usage of 'at'
windows · registry_event
Audio Capture via PowerShell
mediumDetects audio capture via PowerShell Cmdlet.
windows · process_creation
Audio Capture via SoundRecorder
mediumDetect attacker collecting audio via SoundRecorder application.
windows · process_creation
Automated Collection Command PowerShell
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · ps_script
Automated Collection Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · process_creation
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows · process_creation
AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
mediumDetects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)
windows · file_event
Azure AD Health Monitoring Agent Registry Keys Access
mediumThis detection uses Windows security events to detect suspicious access attempts to the registry key of Azure AD Health monitoring agent. This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object HKLM\SOFTWARE\Microsoft\Microsoft Online\Reporting\MonitoringAgent.
windows · security
Azure AD Health Service Agents Registry Keys Access
mediumThis detection uses Windows security events to detect suspicious access attempts to the registry key values and sub-keys of Azure AD Health service agents (e.g AD FS). Information from AD Health service agents can be used to potentially abuse some of the features provided by those services in the cloud (e.g. Federation). This detection requires an access control entry (ACE) on the system access control list (SACL) of the following securable object: HKLM:\SOFTWARE\Microsoft\ADHealthAgent. Make sure you set the SACL to propagate to its sub-keys.
windows · security
Backup Catalog Deleted
mediumDetects backup catalog deletions
windows · application
Backup Files Deleted
mediumDetects deletion of files with extensions often used for backup files. Adversaries may delete or remove built-in operating system data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
windows · file_delete
Binary Proxy Execution Via Dotnet-Trace.EXE
mediumDetects commandline arguments for executing a child process via dotnet-trace.exe
windows · process_creation
BITS Transfer Job Downloading File Potential Suspicious Extension
mediumDetects new BITS transfer job saving local files with potential suspicious extensions
windows · bits-client
BITS Transfer Job With Uncommon Or Suspicious Remote TLD
mediumDetects a suspicious download using the BITS client from a FQDN that is unusual. Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads.
windows · bits-client
Browser Started with Remote Debugging
mediumDetects browsers starting with the remote debugging flags. Which is a technique often used to perform browser injection attacks
windows · process_creation
C# IL Code Compilation Via Ilasm.EXE
mediumDetects the use of "Ilasm.EXE" in order to compile C# intermediate (IL) code to EXE or DLL.
windows · process_creation
Cab File Extraction Via Wusa.EXE
mediumDetects execution of the "wusa.exe" (Windows Update Standalone Installer) utility to extract cab using the "/extract" argument that is no longer supported.
windows · process_creation
Capture Credentials with Rpcping.exe
mediumDetects using Rpcping.exe to send a RPC test connection to the target server (-s) and force the NTLM hash to be sent in the process.
windows · process_creation
Certificate Exported From Local Certificate Store
mediumDetects when an application exports a certificate (and potentially the private key as well) from the local Windows certificate store.
windows · certificateservicesclient-lifecycle-system
Certificate Exported Via Certutil.EXE
mediumDetects the execution of the certutil with the "exportPFX" flag which allows the utility to export certificates.
windows · process_creation
Certificate Exported Via PowerShell
mediumDetects calls to cmdlets that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
windows · process_creation
Certificate Exported Via PowerShell - ScriptBlock
mediumDetects calls to cmdlets inside of PowerShell scripts that are used to export certificates from the local certificate store. Threat actors were seen abusing this to steal private keys from compromised machines.
windows · ps_script
Certificate Private Key Acquired
mediumDetects when an application acquires a certificate private key
windows · capi2
Certificate Use With No Strong Mapping
mediumDetects a user certificate that was valid but could not be mapped to a user in a strong way (such as via explicit mapping, key trust mapping, or a SID) This could be a sign of exploitation of the elevation of privilege vulnerabilities (CVE-2022-34691, CVE-2022-26931, CVE-2022-26923) that can occur when the KDC allows certificate spoofing by not requiring a strong mapping. Events where the AccountName and CN of the Subject do not match, or where the CN ends in a dollar sign indicating a machine, may indicate certificate spoofing.
windows · system
Change PowerShell Policies to an Insecure Level
mediumDetects changing the PowerShell script execution policy to a potentially insecure level using the "-ExecutionPolicy" flag.
windows · process_creation
Change PowerShell Policies to an Insecure Level - PowerShell
mediumDetects changing the PowerShell script execution policy to a potentially insecure level using the "Set-ExecutionPolicy" cmdlet.
windows · ps_script
Change User Agents with WebRequest
mediumAdversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
windows · ps_script
Changing Existing Service ImagePath Value Via Reg.EXE
mediumAdversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
windows · process_creation
Chromium Browser Instance Executed With Custom Extension
mediumDetects a Chromium based browser process with the 'load-extension' flag to start a instance with a custom extension
windows · process_creation
Classes Autorun Keys Modification
mediumDetects modification of Windows Registry Classes keys used for persistence. Adversaries modify these autostart extensibility points (ASEP) to execute malicious code when file types are opened or actions are performed. Various legitimate software also uses these keys. Currently, this rule only filters out known legitimate software paths, thus it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
windows · registry_set
Clear PowerShell History - PowerShell
mediumDetects keywords that could indicate clearing PowerShell history
windows · ps_script
Clear PowerShell History - PowerShell Module
mediumDetects keywords that could indicate clearing PowerShell history
windows · ps_module
Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
mediumDetects Clfs.sys being loaded by a process running from a potentially suspicious location. Clfs.sys is loaded as part of many CVEs exploits that targets Common Log File.
windows · image_load
ClickOnce Deployment Execution - Dfsvc.EXE Child Process
mediumDetects child processes of "dfsvc" which indicates a ClickOnce deployment execution.
windows · process_creation
ClickOnce Trust Prompt Tampering
mediumDetects changes to the ClickOnce trust prompt registry key in order to enable an installation from different locations such as the Internet.
windows · registry_set
Cloudflared Portable Execution
mediumDetects the execution of the "cloudflared" binary from a non standard location.
windows · process_creation
Cloudflared Quick Tunnel Execution
mediumDetects creation of an ad-hoc Cloudflare Quick Tunnel, which can be used to tunnel local services such as HTTP, RDP, SSH and SMB. The free TryCloudflare Quick Tunnel will generate a random subdomain on trycloudflare[.]com, following a call to api[.]trycloudflare[.]com. The tool has been observed in use by threat groups including Akira ransomware.
windows · process_creation
Cloudflared Tunnel Connections Cleanup
mediumDetects execution of the "cloudflared" tool with the tunnel "cleanup" flag in order to cleanup tunnel connections.
windows · process_creation
Cloudflared Tunnel Execution
mediumDetects execution of the "cloudflared" tool to connect back to a tunnel. This was seen used by threat actors to maintain persistence and remote access to compromised networks.
windows · process_creation
Cloudflared Tunnels Related DNS Requests
mediumDetects DNS requests to Cloudflared tunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
CLR DLL Loaded Via Office Applications
mediumDetects CLR DLL being loaded by an Office Product
windows · image_load
Cmd Launched with Hidden Start Flags to Suspicious Targets
mediumDetects cmd.exe executing commands with the "start" utility using "/b" (no window) or "/min" (minimized) flags. To reduce false positives from standard background tasks, detection is restricted to scenarios where the target is a known script extension or located in suspicious temporary/public directories. This technique was observed in Chaos, DarkSide, and Emotet malware campaigns.
windows · process_creation
Code Execution via Pcwutl.dll
mediumDetects launch of executable by calling the LaunchApplication function from pcwutl.dll library.
windows · process_creation
CodePage Modification Via MODE.COM To Russian Language
mediumDetects a CodePage modification using the "mode.com" utility to Russian language. This behavior has been used by threat actors behind Dharma ransomware.
windows · process_creation
COM Hijacking via TreatAs
mediumDetect modification of TreatAs key to enable "rundll32.exe -sta" command
windows · registry_set
COM Object Execution via Xwizard.EXE
mediumDetects the execution of Xwizard tool with the "RunWizard" flag and a GUID like argument. This utility can be abused in order to run custom COM object created in the registry.
windows · process_creation
Command Line Execution with Suspicious URL and AppData Strings
mediumDetects a suspicious command line execution that includes an URL and AppData string in the command line parameters as used by several droppers (js/vbs > powershell)
windows · process_creation
Common Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Communication To Uncommon Destination Ports
mediumDetects programs that connect to uncommon destination ports
windows · network_connection
Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
mediumDetects a qlogin.exe command attempting to authenticate as the internal `_+_PublicSharingUser_` using a GUID as the password. This could be an indicator of an attacker exploiting CVE-2025-57788 to gain initial access using leaked credentials.
windows · process_creation
Compress Data and Lock With Password for Exfiltration With 7-ZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows · process_creation
Compress Data and Lock With Password for Exfiltration With WINZIP
mediumAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party utilities
windows · process_creation
Computer Discovery And Export Via Get-ADComputer Cmdlet
mediumDetects usage of the Get-ADComputer cmdlet to collect computer information and output it to a file
windows · process_creation
Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell
mediumDetects usage of the Get-ADComputer cmdlet to collect computer information and output it to a file
windows · ps_script
Computer Password Change Via Ksetup.EXE
mediumDetects password change for the computer's domain account or host principal via "ksetup.exe"
windows · process_creation
Computer System Reconnaissance Via Wmic.EXE
mediumDetects execution of wmic utility with the "computersystem" flag in order to obtain information about the machine such as the domain, username, model, etc.
windows · process_creation
Conhost Spawned By Uncommon Parent Process
mediumDetects when the Console Window Host (conhost.exe) process is spawned by an uncommon parent process, which could be indicative of potential code injection activity.
windows · process_creation
Console CodePage Lookup Via CHCP
mediumDetects use of chcp to look up the system locale value as part of host discovery
windows · process_creation
ConvertTo-SecureString Cmdlet Usage Via CommandLine
mediumDetects usage of the "ConvertTo-SecureString" cmdlet via the commandline. Which is fairly uncommon and could indicate potential suspicious activity
windows · process_creation
Copy From Or To Admin Share Or Sysvol Folder
mediumDetects a copy command or a copy utility execution to or from an Admin share or remote
windows · process_creation
Crash Dump Created By Operating System
mediumDetects "BugCheck" errors indicating the system rebooted due to a crash, capturing the bugcheck code, dump file path, and report ID.
windows · system
CrashControl CrashDump Disabled
mediumDetects disabling the CrashDump per registry (as used by HermeticWiper)
windows · registry_set
Created Files by Microsoft Sync Center
mediumThis rule detects suspicious files created by Microsoft Sync Center (mobsync)
windows · file_event
CreateRemoteThread API and LoadLibrary
mediumDetects potential use of CreateRemoteThread api and LoadLibrary function to inject DLL into a process
windows · create_remote_thread
Creation of a Diagcab
mediumDetects the creation of diagcab file, which could be caused by some legitimate installer or is a sign of exploitation (review the filename and its location)
windows · file_event
Creation Of a Suspicious ADS File Outside a Browser Download
mediumDetects the creation of a suspicious ADS (Alternate Data Stream) file by software other than browsers
windows · create_stream_hash
Creation Of Non-Existent System DLL
mediumDetects creation of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes. Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs. Thus, the creation of such DLLs may indicate preparation for phantom DLL hijacking attacks.
windows · file_event
Creation of WerFault.exe/Wer.dll in Unusual Folder
mediumDetects the creation of a file named "WerFault.exe" or "wer.dll" in an uncommon folder, which could be a sign of WerFault DLL hijacking.
windows · file_event
Credential Manager Access By Uncommon Applications
mediumDetects suspicious processes based on name and location that access the windows credential manager and vault. Which can be a sign of credential stealing. Example case would be usage of mimikatz "dpapi::cred" function
windows · file_access
CredUI.DLL Loaded By Uncommon Process
mediumDetects loading of "credui.dll" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of "CredUIPromptForCredentials" or "CredUnPackAuthenticationBufferW".
windows · image_load
Cscript/Wscript Potentially Suspicious Child Process
mediumDetects potentially suspicious child processes of Wscript/Cscript. These include processes such as rundll32 with uncommon exports or PowerShell spawning rundll32 or regsvr32. Malware such as Pikabot and Qakbot were seen using similar techniques as well as many others.
windows · process_creation
CSExec Service File Creation
mediumDetects default CSExec service filename which indicates CSExec service installation and execution
windows · file_event
CSExec Service Installation
mediumDetects CSExec service installation and execution events
windows · system
Curl Web Request With Potential Custom User-Agent
mediumDetects execution of "curl.exe" with a potential custom "User-Agent". Attackers can leverage this to download or exfiltrate data via "curl" to a domain that only accept specific "User-Agent" strings
windows · process_creation
Curl.EXE Execution With Custom UserAgent
mediumDetects execution of curl.exe with custom useragent options
windows · process_creation
CurrentControlSet Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
CurrentVersion NT Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
mediumDetects exploitation attempt of CVE-2023-22518 (Confluence Data Center / Confluence Server), where an attacker can exploit vulnerable endpoints to e.g. create admin accounts and execute arbitrary commands.
windows · process_creation
CVE-2023-40477 Potential Exploitation - WinRAR Application Crash
mediumDetects a crash of "WinRAR.exe" where the version is lower than 6.23. This could indicate potential exploitation of CVE-2023-40477
windows · application
CVE-2024-1708 - ScreenConnect Path Traversal Exploitation
mediumThis detects file modifications to ASPX and ASHX files within the root of the App_Extensions directory, which is allowed by a ZipSlip vulnerability in versions prior to 23.9.8. This occurs during exploitation of CVE-2024-1708.
windows · file_event
DarkGate - Autoit3.EXE File Creation By Uncommon Process
mediumDetects the usage of curl.exe, KeyScramblerLogon, or other non-standard/suspicious processes used to create Autoit3.exe. This activity has been associated with DarkGate malware, which uses Autoit3.exe to execute shellcode that performs process injection and connects to the DarkGate command-and-control server. Curl, KeyScramblerLogon, and these other processes consitute non-standard and suspicious ways to retrieve the Autoit3 executable.
windows · file_event
DarkGate - Drop DarkGate Loader In C:\Temp Directory
mediumDetects attackers attempting to save, decrypt and execute the DarkGate Loader in C:\temp folder.
windows · file_event
Data Export From MSSQL Table Via BCP.EXE
mediumDetects the execution of the BCP utility in order to export data from the database. Attackers were seen saving their malware to a database column or table and then later extracting it via "bcp.exe" into a file.
windows · process_creation
Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process
mediumDetects the load of dbghelp/dbgcore DLL by a potentially uncommon or potentially suspicious process. The Dbghelp and Dbgcore DLLs export functions that allow for the dump of process memory. Tools like ProcessHacker, Task Manager and some attacker tradecraft use the MiniDumpWriteDump API found in dbghelp.dll or dbgcore.dll. As an example, SilentTrynity C2 Framework has a module that leverages this API to dump the contents of Lsass.exe and transfer it over the network back to the attacker's machine. Keep in mind that many legitimate Windows processes and services might load the aforementioned DLLs for debugging or other related purposes. Investigate the CommandLine and the Image location of the process loading the DLL.
windows · image_load
DCERPC SMB Spoolss Named Pipe
mediumDetects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
windows · security
Defrag Deactivation
mediumDetects the deactivation and disabling of the Scheduled defragmentation task as seen by Slingshot APT group
windows · process_creation
Defrag Deactivation - Security
mediumDetects the deactivation and disabling of the Scheduled defragmentation task as seen by Slingshot APT group
windows · security
Delete Defender Scan ShellEx Context Menu Registry Key
mediumDetects deletion of registry key that adds 'Scan with Defender' option in context menu. Attackers may use this to make it harder for users to scan files that are suspicious.
windows · registry_delete
Deleted Data Overwritten Via Cipher.EXE
mediumDetects usage of the "cipher" built-in utility in order to overwrite deleted data from disk. Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives
windows · process_creation
Denied Access To Remote Desktop
mediumThis event is generated when an authenticated user who is not allowed to log on remotely attempts to connect to this computer through Remote Desktop. Often, this event can be generated by attackers when searching for available windows servers in the network.
windows · security
Deployment AppX Package Was Blocked By AppLocker
mediumDetects an appx package deployment that was blocked by AppLocker policy.
windows · appxdeployment-server
Deployment Of The AppX Package Was Blocked By The Policy
mediumDetects an appx package deployment that was blocked by the local computer policy. The following events indicate that an AppX package deployment was blocked by a policy: - Event ID 441: The package deployment operation is blocked by the "Allow deployment operations in special profiles" policy - Event ID 442: Deployments to non-system volumes are blocked by the "Disable deployment of Windows Store apps to non-system volumes" policy." - Event ID 453: Package blocked by a platform policy. - Event ID 454: Package blocked by a platform policy.
windows · appxdeployment-server
Desktop.INI Created by Uncommon Process
mediumDetects unusual processes accessing desktop.ini, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
windows · file_event
Detected Windows Software Discovery
mediumAdversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable.
windows · process_creation
Detected Windows Software Discovery - PowerShell
mediumAdversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised system has a version of software that is vulnerable.
windows · ps_script
Detection of PowerShell Execution via Sqlps.exe
mediumThis rule detects execution of a PowerShell code through the sqlps.exe utility, which is included in the standard set of utilities supplied with the MSSQL Server. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.
windows · process_creation
Device Installation Blocked
mediumDetects an installation of a device that is forbidden by the system policy
windows · security
DeviceCredentialDeployment Execution
mediumDetects the execution of DeviceCredentialDeployment to hide a process from view.
windows · process_creation
Dfsvc.EXE Network Connection To Non-Local IPs
mediumDetects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs
windows · network_connection
Direct Autorun Keys Modification
mediumDetects direct modification of autostart extensibility point (ASEP) in registry using reg.exe.
windows · process_creation
DirectorySearcher Powershell Exploitation
mediumEnumerates Active Directory to determine computers that are joined to the domain
windows · ps_script
Disable Administrative Share Creation at Startup
mediumAdministrative shares are hidden network shares created by Microsoft Windows NT operating systems that grant system administrators remote access to every disk volume on a network-connected system
windows · registry_set
Disable Exploit Guard Network Protection on Windows Defender
mediumDetects disabling Windows Defender Exploit Guard Network Protection
windows · registry_set
Disable Internal Tools or Feature in Registry
mediumDetects registry modifications that change features of internal Windows tools (malware like Agent Tesla uses this technique)
windows · registry_set
Disable Microsoft Defender Firewall via Registry
mediumAdversaries may disable or modify system firewalls in order to bypass controls limiting network usage
windows · registry_set
Disable Privacy Settings Experience in Registry
mediumDetects registry modifications that disable Privacy Settings Experience
windows · registry_set
Disable Tamper Protection on Windows Defender
mediumDetects disabling Windows Defender Tamper Protection
windows · registry_set
Disable Windows Firewall by Registry
mediumDetect set EnableFirewall to 0 to disable the Windows firewall
windows · registry_set
Disable Windows Security Center Notifications
mediumDetect set UseActionCenterExperience to 0 to disable the Windows security center notification
windows · registry_set
Diskshadow Child Process Spawned
mediumDetects any child process spawning from "Diskshadow.exe". This could be due to executing Diskshadow in interpreter mode or script mode and using the "exec" flag to launch other applications.
windows · process_creation
Diskshadow Script Mode - Execution From Potential Suspicious Location
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag where the script is located in a potentially suspicious location.
windows · process_creation
Diskshadow Script Mode - Uncommon Script Extension Execution
mediumDetects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.
windows · process_creation
Diskshadow Script Mode Execution
mediumDetects execution of "Diskshadow.exe" in script mode using the "/s" flag. Attackers often abuse "diskshadow" to execute scripts that deleted the shadow copies on the systems. Investigate the content of the scripts and its location.
windows · process_creation
Dism Remove Online Package
mediumDeployment Image Servicing and Management tool. DISM is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows · process_creation
Displaying Hidden Files Feature Disabled
mediumDetects modifications to the "Hidden" and "ShowSuperHidden" explorer registry values in order to disable showing of hidden files and system files. This technique is abused by several malware families to hide their files from normal users.
windows · registry_set
DLL Call by Ordinal Via Rundll32.EXE
mediumDetects calls of DLLs exports by ordinal numbers via rundll32.dll.
windows · process_creation
DLL Execution via Rasautou.exe
mediumDetects using Rasautou.exe for loading arbitrary .DLL specified in -d option and executes the export specified in -p.
windows · process_creation
DLL Execution Via Register-cimprovider.exe
mediumDetects using register-cimprovider.exe to execute arbitrary dll file.
windows · process_creation
DLL Load By System Process From Suspicious Locations
mediumDetects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as "C:\Users\Public"
windows · image_load
DLL Loaded via CertOC.EXE
mediumDetects when a user installs certificates by using CertOC.exe to loads the target DLL file.
windows · process_creation
DLL Names Used By SVR For GraphicalProton Backdoor
mediumHunts known SVR-specific DLL names.
windows · image_load
Dllhost.EXE Initiated Network Connection To Non-Local IP Address
mediumDetects Dllhost.EXE initiating a network connection to a non-local IP address. Aside from Microsoft own IP range that needs to be excluded. Network communication from Dllhost will depend entirely on the hosted DLL. An initial baseline is recommended before deployment.
windows · network_connection
DllUnregisterServer Function Call Via Msiexec.EXE
mediumDetects MsiExec loading a DLL and calling its DllUnregisterServer function
windows · process_creation
DMSA Service Account Created in Specific OUs - PowerShell
mediumDetects the creation of a dMSA service account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows · ps_script
DNS Query Request By Regsvr32.EXE
mediumDetects DNS queries initiated by "Regsvr32.exe"
windows · dns_query
DNS Query To AzureWebsites.NET By Non-Browser Process
mediumDetects a DNS query by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
windows · dns_query
DNS Query To Common Malware Hosting and Shortener Services
mediumDetects DNS queries to domains commonly used by threat actors to host malware payloads or redirect through URL shorteners. These include platforms like Cloudflare Workers, TryCloudflare, InfinityFree, and URL shorteners such as tinyurl and lihi.cc. Such DNS activity can indicate potential delivery or command-and-control communication attempts.
windows · dns_query
DNS Query To Devtunnels Domain
mediumDetects DNS query requests to Devtunnels domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
DNS Query To MEGA Hosting Website
mediumDetects DNS queries for subdomains related to MEGA sharing website
windows · dns_query
DNS Query To MEGA Hosting Website - DNS Client
mediumDetects DNS queries for subdomains related to MEGA sharing website
windows · dns-client
DNS Query To Put.io - DNS Client
mediumDetects DNS queries for subdomains related to "Put.io" sharing website.
windows · dns-client
DNS Query To Remote Access Software Domain From Non-Browser App
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · dns_query
DNS Query To Visual Studio Code Tunnels Domain
mediumDetects DNS query requests to Visual Studio Code tunnel domains. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · dns_query
DNS-over-HTTPS Enabled by Registry
mediumDetects when a user enables DNS-over-HTTPS. This can be used to hide internet activity or be used to hide the process of exfiltrating data. With this enabled organization will lose visibility into data such as query type, response and originating IP that are used to determine bad actors.
windows · registry_set
Domain Trust Discovery Via Dsquery
mediumDetects execution of "dsquery.exe" for domain trust discovery
windows · process_creation
DotNET Assembly DLL Loaded Via Office Application
mediumDetects any assembly DLL being loaded by an Office Product
windows · image_load
DPAPI Domain Master Key Backup Attempt
mediumDetects anyone attempting a backup for the DPAPI Master Key. This events gets generated at the source and not the Domain Controller.
windows · security
Driver/DLL Installation Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "INSTALLDRIVER" which installs a new ODBC driver. Attackers abuse this to install and run malicious DLLs.
windows · process_creation
DriverQuery.EXE Execution
mediumDetect usage of the "driverquery" utility. Which can be used to perform reconnaissance on installed drivers
windows · process_creation
Drop Binaries Into Spool Drivers Color Folder
mediumDetects the creation of suspcious binary files inside the "\windows\system32\spool\drivers\color\" as seen in the blog referenced below
windows · file_event
Dropping Of Password Filter DLL
mediumDetects dropping of dll files in system32 that may be used to retrieve user credentials from LSASS
windows · process_creation
Dump Credentials from Windows Credential Manager With PowerShell
mediumAdversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials.
windows · ps_script
Dump Ntds.dit To Suspicious Location
mediumDetects potential abuse of ntdsutil to dump ntds.dit database to a suspicious location
windows · application
Dumping Process via Sqldumper.exe
mediumDetects process dump via legitimate sqldumper.exe binary
windows · process_creation
DumpMinitool Execution
mediumDetects the use of "DumpMinitool.exe" a tool that allows the dump of process memory via the use of the "MiniDumpWriteDump"
windows · process_creation
Dynamic .NET Compilation Via Csc.EXE
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows · process_creation
Dynamic .NET Compilation Via Csc.EXE - Hunting
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows · process_creation
Elevated System Shell Spawned
mediumDetects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges. Use this rule to hunt for potential suspicious processes.
windows · process_creation
Elevated System Shell Spawned From Uncommon Parent Location
mediumDetects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges from a uncommon parent location.
windows · process_creation
Enable Local Manifest Installation With Winget
mediumDetects changes to the AppInstaller (winget) policy. Specifically the activation of the local manifest installation, which allows a user to install new packages via custom manifests.
windows · registry_set
Enable Microsoft Dynamic Data Exchange
mediumEnable Dynamic Data Exchange protocol (DDE) in all supported editions of Microsoft Word or Excel.
windows · registry_set
Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
mediumDetects enabling of the "AllowAnonymousCallback" registry value, which allows a remote connection between computers that do not have a trust relationship.
windows · registry_set
Enable Windows Remote Management
mediumAdversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
windows · ps_script
Enabling COR Profiler Environment Variables
mediumDetects .NET Framework CLR and .NET Core CLR "cor_enable_profiling" and "cor_profiler" variables being set and configured.
windows · registry_set
Enumerate All Information With Whoami.EXE
mediumDetects the execution of "whoami.exe" with the "/all" flag
windows · process_creation
Enumerate Credentials from Windows Credential Manager With PowerShell
mediumAdversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials.
windows · ps_script
Enumeration for 3rd Party Creds From CLI
mediumDetects processes that query known 3rd party registry keys that holds credentials via commandline
windows · process_creation
Enumeration for Credentials in Registry
mediumAdversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can be used by the system or other programs. Adversaries may query the Registry looking for credentials and passwords that have been stored for use by other programs or services
windows · process_creation
Esentutl Gather Credentials
mediumConti recommendation to its affiliates to use esentutl to access NTDS dumped file. Trickbot also uses this utilities to get MSEdge info via its module pwgrab.
windows · process_creation
Esentutl Steals Browser Information
mediumOne way Qbot steals sensitive information is by extracting browser data from Internet Explorer and Microsoft Edge by using the built-in utility esentutl.exe
windows · process_creation
ETW Logging/Processing Option Disabled On IIS Server
mediumDetects changes to of the IIS server configuration in order to disable/remove the ETW logging/processing option.
windows · iis-configuration
Eventlog Cleared
mediumOne of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution
windows · system
EventLog EVTX File Deleted
mediumDetects the deletion of the event log files which may indicate an attempt to destroy forensic evidence
windows · file_delete
EventLog Query Requests By Builtin Utilities
mediumDetect attempts to query the contents of the event log using command line utilities. Attackers use this technique in order to look for sensitive information in the logs such as passwords, usernames, IPs, etc.
windows · process_creation
EVTX Created In Uncommon Location
mediumDetects the creation of new files with the ".evtx" extension in non-common or non-standard location. This could indicate tampering with default EVTX locations in order to evade security controls or simply exfiltration of event log to search for sensitive information within. Note that backup software and legitimate administrator might perform similar actions during troubleshooting.
windows · file_event
Execute Code with Pester.bat
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows · process_creation
Execute Code with Pester.bat as Parent
mediumDetects code execution via Pester.bat (Pester - Powershell Modulte for testing)
windows · process_creation
Execute Files with Msdeploy.exe
mediumDetects file execution using the msdeploy.exe lolbin
windows · process_creation
Execute From Alternate Data Streams
mediumDetects execution from an Alternate Data Stream (ADS). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection
windows · process_creation
Execute Invoke-command on Remote Host
mediumAdversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
windows · ps_script
Execution From Webserver Root Folder
mediumDetects a program executing from a web server root folder. Use this rule to hunt for potential interesting activity such as webshell or backdoors
windows · process_creation
Execution of Suspicious File Type Extension
mediumDetects whether the image specified in a process creation event doesn't refer to an ".exe" (or other known executable extension) file. This can be caused by process ghosting or other unorthodox methods to start a process. This rule might require some initial baselining to align with some third party tooling in the user environment.
windows · process_creation
Exploit for CVE-2017-0261
mediumDetects Winword starting uncommon sub process FLTLDR.exe as used in exploits for CVE-2017-0261 and CVE-2017-0262
windows · process_creation
Explorer Process Tree Break
mediumDetects a command line process that uses explorer.exe to launch arbitrary commands or binaries, which is similar to cmd.exe /c, only it breaks the process tree and makes its parent a new instance of explorer spawning from "svchost"
windows · process_creation
External Remote RDP Logon from Public IP
mediumDetects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
windows · security
Extracting Information with PowerShell
mediumAdversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
windows · ps_script
Failed DNS Zone Transfer
mediumDetects when a DNS zone transfer failed.
windows · dns-server
Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
mediumDetects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method. Event 5858 in the WMI-Activity operational log is an error event, meaning it is only generated when the WMI operation encounters an error (e.g. access denied, provider failure). It could be an indication of an attacker attempting to clear event logs via WMI, but failing due to insufficient privileges or other issues. Successful clearing operations will NOT produce this event; for those, correlate with Security event 1102 or System event 104.
windows · wmi
Failed Logon From Public IP
mediumDetects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
windows · security
File Access Of Signal Desktop Sensitive Data
mediumDetects access to Signal Desktop's sensitive data files: db.sqlite and config.json. The db.sqlite file in Signal Desktop stores all locally saved messages in an encrypted SQLite database, while the config.json contains the decryption key needed to access that data. Since the key is stored in plain text, a threat actor who gains access to both files can decrypt and read sensitive messages without needing the users credentials. Currently the rule only covers the default Signal installation path in AppData\Roaming. Signal Portable installations may use different paths based on user configuration. Additional paths can be added to the selection as needed.
windows · security
File Decryption Using Gpg4win
mediumDetects usage of Gpg4win to decrypt files
windows · process_creation
File Deleted Via Sysinternals SDelete
mediumDetects the deletion of files by the Sysinternals SDelete utility. It looks for the common name pattern used to rename files.
windows · file_delete
File Download From Browser Process Via Inline URL
mediumDetects execution of a browser process with a URL argument pointing to a file with a potentially interesting extension. This can be abused to download arbitrary files or to hide from the user for example by launching the browser in a minimized state.
windows · process_creation
File Download From IP URL Via Curl.EXE
mediumDetects file downloads directly from IP address URL using curl.exe
windows · process_creation
File Download Using ProtocolHandler.exe
mediumDetects usage of "ProtocolHandler" to download files. Downloaded files will be located in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)
windows · process_creation
File Download Via Bitsadmin
mediumDetects usage of bitsadmin downloading a file
windows · process_creation
File Download via CertOC.EXE
mediumDetects when a user downloads a file by using CertOC.exe
windows · process_creation
File Download Via Curl.EXE
mediumDetects file download using curl.exe
windows · process_creation
File Download Via InstallUtil.EXE
mediumDetects use of .NET InstallUtil.exe in order to download arbitrary files. The files will be written to "%LOCALAPPDATA%\Microsoft\Windows\INetCache\IE\"
windows · process_creation
File Encoded To Base64 Via Certutil.EXE
mediumDetects the execution of certutil with the "encode" flag to encode a file to base64. This can be abused by threat actors and attackers for data exfiltration
windows · process_creation
File Encryption Using Gpg4win
mediumDetects usage of Gpg4win to encrypt files
windows · process_creation
File or Folder Permissions Modifications
mediumDetects a file or folder's permissions being modified or tampered with.
windows · process_creation
File Recovery From Backup Via Wbadmin.EXE
mediumDetects the recovery of files from backups via "wbadmin.exe". Attackers can restore sensitive files such as NTDS.DIT or Registry Hives from backups in order to potentially extract credentials.
windows · process_creation
Files With System DLL Name In Unsuspected Locations
mediumDetects the creation of a file with the ".dll" extension that has the name of a System DLL in uncommon or unsuspected locations. (Outisde of "System32", "SysWOW64", etc.). It is highly recommended to perform an initial baseline before using this rule in production.
windows · file_event
Files With System Process Name In Unsuspected Locations
mediumDetects the creation of an executable with a system process name in folders other than the system ones (System32, SysWOW64, etc.). It is highly recommended to perform an initial baseline before using this rule in production.
windows · file_event
Filter Driver Unloaded Via Fltmc.EXE
mediumDetect filter driver unloading activity via fltmc.exe
windows · process_creation
Findstr Launching .lnk File
mediumDetects usage of findstr to identify and execute a lnk file as seen within the HHS redirect attack
windows · process_creation
Firewall Disabled via Netsh.EXE
mediumDetects netsh commands that turns off the Windows firewall
windows · process_creation
Firewall Rule Deleted Via Netsh.EXE
mediumDetects the removal of a port or application rule in the Windows Firewall configuration using netsh
windows · process_creation
Firewall Rule Update Via Netsh.EXE
mediumDetects execution of netsh with the "advfirewall" and the "set" option in order to set new values for properties of a existing rule
windows · process_creation
Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · process_creation
Forest Blizzard APT - JavaScript Constrained File Creation
mediumDetects the creation of JavaScript files inside of the DriverStore directory. Forest Blizzard used this to exploit the CVE-2022-38028 vulnerability in Windows Print Spooler service by modifying a JavaScript constraints file and executing it with SYSTEM-level permissions.
windows · file_event
Forfiles Command Execution
mediumDetects the execution of "forfiles" with the "/c" flag. While this is an expected behavior of the tool, it can be abused in order to proxy execution through it with any binary. Can be used to bypass application whitelisting.
windows · process_creation
FTP Connection Open Attempt Via Winscp CLI
mediumDetects the execution of Winscp with the "-command" and the "open" flags in order to open an FTP connection. Akira ransomware was seen using this technique in order to exfiltrate data.
windows · process_creation
Function Call From Undocumented COM Interface EditionUpgradeManager
mediumDetects function calls from the EditionUpgradeManager COM interface. Which is an interface that is not used by standard executables.
windows · process_access
GatherNetworkInfo.VBS Reconnaissance Script Output
mediumDetects creation of files which are the results of executing the built-in reconnaissance script "C:\Windows\System32\gatherNetworkInfo.vbs".
windows · file_event
Get-ADUser Enumeration Using UserAccountControl Flags
mediumDetects AS-REP roasting is an attack that is often-overlooked. It is not very common as you have to explicitly set accounts that do not require pre-authentication.
windows · ps_script
Github Self-Hosted Runner Execution
mediumDetects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.
windows · process_creation
GoToAssist Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
Gpresult Display Group Policy Information
mediumDetects cases in which a user uses the built-in Windows utility gpresult to display the Resultant Set of Policy (RSoP) information
windows · process_creation
Gpscript Execution
mediumDetects the execution of the LOLBIN gpscript, which executes logon or startup scripts configured in Group Policy
windows · process_creation
Greedy File Deletion Using Del
mediumDetects execution of the "del" builtin command to remove files using greedy/wildcard expression. This is often used by malware to delete content of folders that perhaps contains the initial malware infection or to delete evidence.
windows · process_creation
Group Membership Reconnaissance Via Whoami.EXE
mediumDetects the execution of whoami.exe with the /group command line flag to show group membership for the current user, account type, security identifiers (SID), and attributes.
windows · process_creation
Group Policy Abuse for Privilege Addition
mediumDetects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.
windows · security
Gzip Archive Decode Via PowerShell
mediumDetects attempts of decoding encoded Gzip archives via PowerShell.
windows · process_creation
HackTool - Impersonate Execution
mediumDetects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively
windows · process_creation
HackTool - Jlaive In-Memory Assembly Execution
mediumDetects the use of Jlaive to execute assemblies in a copied PowerShell
windows · process_creation
HackTool - LaZagne Execution
mediumDetects the execution of the LaZagne. A utility used to retrieve multiple types of passwords stored on a local computer. LaZagne has been leveraged multiple times by threat actors in order to dump credentials.
windows · process_creation
HackTool - SharpLDAPmonitor Execution
mediumDetects execution of the SharpLDAPmonitor. Which can monitor the creation, deletion and changes to LDAP objects.
windows · process_creation
HackTool - WinRM Access Via Evil-WinRM
mediumAdversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
windows · process_creation
Hardware Model Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC with the "csproduct" which is used to obtain information such as hardware models and vendor information
windows · process_creation
Harvesting Of Wifi Credentials Via Netsh.EXE
mediumDetect the harvesting of wifi credentials using netsh.exe
windows · process_creation
Headless Process Launched Via Conhost.EXE
mediumDetects the launch of a child process via "conhost.exe" with the "--headless" flag. The "--headless" flag hides the windows from the user upon execution.
windows · process_creation
HH.EXE Initiated HTTP Network Connection
mediumDetects a network connection initiated by the "hh.exe" process to HTTP destination ports, which could indicate the execution/download of remotely hosted .chm files.
windows · network_connection
Hidden Executable In NTFS Alternate Data Stream
mediumDetects the creation of an ADS (Alternate Data Stream) that contains an executable by looking at a non-empty Imphash
windows · create_stream_hash
Hidden Powershell in Link File Pattern
mediumDetects events that appear when a user click on a link file with a powershell command in it
windows · process_creation
Hiding Files with Attrib.exe
mediumDetects usage of attrib.exe to hide files from users.
windows · process_creation
Hiding User Account Via SpecialAccounts Registry Key - CommandLine
mediumDetects changes to the registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\Userlist" where the value is set to "0" in order to hide user account from being listed on the logon screen.
windows · process_creation
IE Change Domain Zone
mediumHides the file extension through modification of the registry
windows · registry_set
Ie4uinit Lolbin Use From Invalid Path
mediumDetect use of ie4uinit.exe to execute commands from a specially prepared ie4uinit.inf file from a directory other than the usual directories
windows · process_creation
IIS Native-Code Module Command Line Installation
mediumDetects suspicious IIS native-code module installations via command line
windows · process_creation
IIS WebServer Access Logs Deleted
mediumDetects the deletion of IIS WebServer access logs which may indicate an attempt to destroy forensic evidence
windows · file_delete
IIS WebServer Log Deletion via CommandLine Utilities
mediumDetects attempts to delete Internet Information Services (IIS) log files via command line utilities, which is a common defense evasion technique used by attackers to cover their tracks. Threat actors often abuse vulnerabilities in web applications hosted on IIS servers to gain initial access and later delete IIS logs to evade detection.
windows · process_creation
Import LDAP Data Interchange Format File Via Ldifde.EXE
mediumDetects the execution of "Ldifde.exe" with the import flag "-i". The can be abused to include HTTP-based arguments which will allow the arbitrary download of files from a remote server.
windows · process_creation
Import PowerShell Modules From Suspicious Directories
mediumDetects powershell scripts that import modules from suspicious directories
windows · ps_script
Import PowerShell Modules From Suspicious Directories - ProcCreation
mediumDetects powershell scripts that import modules from suspicious directories
windows · process_creation
Imports Registry Key From a File
mediumDetects the import of the specified file to the registry with regedit.exe.
windows · process_creation
Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet
mediumDetects inbox rule creation or update via ExchangePowerShell cmdlet, a technique commonly observed in Business Email Compromise (BEC) attacks to hide emails. The usage of inbox rules can be a sign of a compromised mailbox, where an attacker is attempting to evade detections by suppressing or redirecting incoming emails. Analysts should review these rules in context, validate whether they reflect normal user behavior, and correlate with other indicators such as unusual login activity or recent mailbox rule modifications.
windows · ps_script
Indirect Command Execution From Script File Via Bash.EXE
mediumDetects execution of Microsoft bash launcher without any flags to execute the content of a bash script directly. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
windows · process_creation
Indirect Command Execution via SFTP ProxyCommand
mediumDetects the use of SFTP.exe to execute commands indirectly via ProxyCommand parameter. Threat actors were seen leveraging this legitimate Windows binary to bypass security controls and execute arbitrary commands while evading detection.
windows · process_creation
Indirect Inline Command Execution Via Bash.EXE
mediumDetects execution of Microsoft bash launcher with the "-c" flag. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.
windows · process_creation
InfDefaultInstall.exe .inf Execution
mediumExecutes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.
windows · process_creation
Insecure Proxy/DOH Transfer Via Curl.EXE
mediumDetects execution of "curl.exe" with the "insecure" flag over proxy or DOH.
windows · process_creation
Insecure Transfer Via Curl.EXE
mediumDetects execution of "curl.exe" with the "--insecure" flag.
windows · process_creation
Install New Package Via Winget Local Manifest
mediumDetects usage of winget to install applications via manifest file. Adversaries can abuse winget to download payloads remotely and execute them. The manifest option enables you to install an application by passing in a YAML file directly to the client. Winget can be used to download and install exe, msi or msix files later.
windows · process_creation
Installation of TeamViewer Desktop
mediumTeamViewer_Desktop.exe is create during install
windows · file_event
Interactive Logon to Server Systems
mediumDetects interactive console logons to Server Systems
windows · security
Internet Explorer Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Internet Explorer DisableFirstRunCustomize Enabled
mediumDetects changes to the Internet Explorer "DisableFirstRunCustomize" value, which prevents Internet Explorer from running the first run wizard the first time a user starts the browser after installing Internet Explorer or Windows.
windows · registry_set
Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe, which can be used for various attacks against the NTDS database (NTDS.DIT)
windows · process_creation
Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the invocation of PowerShell commands with references to classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows · process_creation
Invoke-Obfuscation COMPRESS OBFUSCATION
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · process_creation
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · ps_script
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · ps_module
Invoke-Obfuscation COMPRESS OBFUSCATION - Security
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · security
Invoke-Obfuscation COMPRESS OBFUSCATION - System
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · system
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · ps_script
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · ps_module
Invoke-Obfuscation RUNDLL LAUNCHER - Security
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · security
Invoke-Obfuscation RUNDLL LAUNCHER - System
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · system
ISATAP Router Address Was Set
mediumDetects the configuration of a new ISATAP router on a Windows host. While ISATAP is a legitimate Microsoft technology for IPv6 transition, unexpected or unauthorized ISATAP router configurations could indicate a potential IPv6 DNS Takeover attack using tools like mitm6. In such attacks, adversaries advertise themselves as DHCPv6 servers and set malicious ISATAP routers to intercept traffic. This detection should be correlated with network baselines and known legitimate ISATAP deployments in your environment.
windows · system
ISO Image Mounted
mediumDetects the mount of an ISO image on an endpoint
windows · security
ISO or Image Mount Indicator in Recent Files
mediumDetects the creation of recent element file that points to an .ISO, .IMG, .VHD or .VHDX file as often used in phishing attacks. This can be a false positive on server systems but on workstations users should rarely mount .iso or .img files.
windows · file_event
Java Running with Remote Debugging
mediumDetects a JAVA process running with remote debugging allowing more than just localhost to connect
windows · process_creation
Kapeka Backdoor Configuration Persistence
mediumDetects registry set activity of a value called "Seed" stored in the "\Cryptography\Providers\" registry key. The Kapeka backdoor leverages this location to register a new SIP provider for backdoor configuration persistence.
windows · registry_set
Kerberoasting Activity - Initial Query
mediumThis rule will collect the data needed to start looking into possible kerberoasting activity. Further analysis or computation within the query is needed focusing on requests from one specific host/IP towards multiple service names within a time period of 5 seconds. You can then set a threshold for the number of requests and time between the requests to turn this into an alert.
windows · security
Launch-VsDevShell.PS1 Proxy Execution
mediumDetects the use of the 'Launch-VsDevShell.ps1' Microsoft signed script to execute commands.
windows · process_creation
LiveKD Driver Creation
mediumDetects the creation of the LiveKD driver, which is used for live kernel debugging
windows · file_event
Loaded Module Enumeration Via Tasklist.EXE
mediumDetects the enumeration of a specific DLL or EXE being used by a binary via "tasklist.exe". This is often used by attackers in order to find the specific process identifier (PID) that is using the DLL in question. In order to dump the process memory or perform other nefarious actions.
windows · process_creation
Local File Read Using Curl.EXE
mediumDetects execution of "curl.exe" with the "file://" protocol handler in order to read local files.
windows · process_creation
Local Network Connection Initiated By Script Interpreter
mediumDetects a script interpreter (Wscript/Cscript) initiating a local network connection to download or execute a script hosted on a shared folder.
windows · network_connection
Logged-On User Password Change Via Ksetup.EXE
mediumDetects password change for the logged-on user's via "ksetup.exe"
windows · process_creation
LOLBAS Data Exfiltration by DataSvcUtil.exe
mediumDetects when a user performs data exfiltration by using DataSvcUtil.exe
windows · process_creation
LOLBIN Execution From Abnormal Drive
mediumDetects LOLBINs executing from an abnormal or uncommon drive such as a mounted ISO.
windows · process_creation
Lolbin Runexehelper Use As Proxy
mediumDetect usage of the "runexehelper.exe" binary as a proxy to launch other programs
windows · process_creation
Lolbin Unregmp2.exe Use As Proxy
mediumDetect usage of the "unregmp2.exe" binary as a proxy to launch a custom version of "wmpnscfg.exe"
windows · process_creation
LSA PPL Protection Setting Modification via CommandLine
mediumDetects modification of LSA PPL protection settings via CommandLine. It may indicate an attempt to disable protection and enable credential dumping tools to access LSASS process memory.
windows · process_creation
LSASS Access From Non System Account
mediumDetects potential mimikatz-like tools accessing LSASS from non system account
windows · security
LSASS Access From Program In Potentially Suspicious Folder
mediumDetects process access to LSASS memory with suspicious access flags and from a potentially suspicious folder
windows · process_access
Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet
mediumDetects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
windows · ps_script
Malicious Driver Load By Name
mediumDetects loading of known malicious drivers via the file name of the drivers.
windows · driver_load
Malicious PE Execution by Microsoft Visual Studio Debugger
mediumThere is an option for a MS VS Just-In-Time Debugger "vsjitdebugger.exe" to launch specified executable and attach a debugger. This option may be used adversaries to execute malicious code by signed verified binary. The debugger is installed alongside with Microsoft Visual Studio package.
windows · process_creation
Malicious PowerShell Keywords
mediumDetects keywords from well-known PowerShell exploitation frameworks
windows · ps_script
Manipulation of User Computer or Group Security Principals Across AD
mediumAdversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain..
windows · ps_script
Manual Execution of Script Inside of a Compressed File
mediumThis is a threat-hunting query to collect information related to the interactive execution of a script from inside a compressed file (zip/rar). Windows will automatically run the script using scripting interpreters such as wscript and cscript binaries. From the query below, the child process is the script interpreter that will execute the script. The script extension is also a set of standard extensions that Windows OS recognizes. Selections 1-3 contain three different execution scenarios. 1. Compressed file opened using 7zip. 2. Compressed file opened using WinRar. 3. Compressed file opened using native windows File Explorer capabilities. When the malicious script is double-clicked, it will be extracted to the respected directories as signified by the CommandLine on each of the three Selections. It will then be executed using the relevant script interpreter."
windows · process_creation
Mesh Agent Service Installation
mediumDetects a Mesh Agent service installation. Mesh Agent is used to remotely manage computers
windows · system
Microsoft Excel Add-In Loaded From Uncommon Location
mediumDetects Microsoft Excel loading an Add-In (.xll) file from an uncommon location
windows · image_load
Microsoft Office Trusted Location Updated
mediumDetects changes to the registry keys related to "Trusted Location" of Microsoft Office. Attackers might add additional trusted locations to avoid macro security restrictions.
windows · registry_set
Microsoft Sync Center Suspicious Network Connections
mediumDetects suspicious connections from Microsoft Sync Center to non-private IPs.
windows · network_connection
Microsoft Teams Sensitive File Access By Uncommon Applications
mediumDetects file access attempts to sensitive Microsoft teams files (leveldb, cookies) by an uncommon process.
windows · file_access
Microsoft VBA For Outlook Addin Loaded Via Outlook
mediumDetects outlvba (Microsoft VBA for Outlook Addin) DLL being loaded by the outlook process
windows · image_load
Microsoft Workflow Compiler Execution
mediumDetects the execution of Microsoft Workflow Compiler, which may permit the execution of arbitrary unsigned code.
windows · process_creation
MMC Loading Script Engines DLLs
mediumDetects when the Microsoft Management Console (MMC) loads the DLL libraries like vbscript, jscript etc which might indicate an attempt to execute malicious scripts within a trusted system process for bypassing application whitelisting or defense evasion.
windows · image_load
Modify Group Policy Settings
mediumDetect malicious GPO modifications can be used to implement many other malicious behaviors.
windows · process_creation
Modify Group Policy Settings - ScriptBlockLogging
mediumDetect malicious GPO modifications can be used to implement many other malicious behaviors.
windows · ps_script
Monitoring For Persistence Via BITS
mediumBITS will allow you to schedule a command to execute after a successful download to notify you that the job is finished. When the job runs on the system the command specified in the BITS job will be executed. This can be abused by actors to create a backdoor within the system and for persistence. It will be chained in a BITS job to schedule the download of malware/additional binaries and execute the program after being downloaded.
windows · process_creation
msDS-ManagedAccountPrecededByLink Attribute Modified
mediumDetects modifications to the msDS-ManagedAccountPrecededByLink attribute, which may indicate an attempted or successful abuse of the BaD-Successor msDS-DelegatedManagedServiceAccount (DMSA) vulnerability. The DMSA is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups. Changes to this attribute by suspicious accounts or outside of normal administrative workflows are a strong signal of an attempted or successful abuse. If it is indeed modified by an account that is not typically responsible for such changes, it could indicate an attempt to exploit the BaD-Successor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows · security
MSExchange Transport Agent Installation
mediumDetects the Installation of a Exchange Transport Agent
windows · process_creation
MSExchange Transport Agent Installation - Builtin
mediumDetects the Installation of a Exchange Transport Agent
windows · msexchange-management
MSI Installation From Suspicious Locations
mediumDetects MSI package installation from suspicious locations
windows · application
MSI Installation From Web
mediumDetects installation of a remote msi file from web.
windows · application
Msiexec Quiet Installation
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows · process_creation
MsiExec Web Install
mediumDetects suspicious msiexec process starts with web addresses as parameter
windows · process_creation
MSSQL Destructive Query
mediumDetects the invocation of MS SQL transactions that are destructive towards table or database data, such as "DROP TABLE" or "DROP DATABASE".
windows · application
MSSQL Server Failed Logon From External Network
mediumDetects failed logon attempts from clients with external network IP to an MSSQL server. This can be a sign of a bruteforce attack.
windows · application
Msxsl.EXE Execution
mediumDetects the execution of the MSXSL utility. This can be used to execute Extensible Stylesheet Language (XSL) files. These files are commonly used to describe the processing and rendering of data within XML files. Adversaries can abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses.
windows · process_creation
Netcat The Powershell Version
mediumAdversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network
windows · ps_classic_start
Netsh Allow Group Policy on Microsoft Defender Firewall
mediumAdversaries may modify system firewalls in order to bypass controls limiting network usage
windows · process_creation
NetSupport Manager Service Install
mediumDetects NetSupport Manager service installation on the target system.
windows · system
Network Communication Initiated To Portmap.IO Domain
mediumDetects an executable accessing the portmap.io domain, which could be a sign of forbidden C2 traffic or data exfiltration by malicious actors
windows · network_connection
Network Connection Initiated By Regsvr32.EXE
mediumDetects a network connection initiated by "Regsvr32.exe"
windows · network_connection
Network Connection Initiated From Users\Public Folder
mediumDetects a network connection initiated from a process located in the "C:\Users\Public" folder. Attacker are known to drop their malicious payloads and malware in this directory as its writable by everyone. Use this rule to hunt for potential suspicious or uncommon activity in your environement.
windows · network_connection
Network Connection Initiated To AzureWebsites.NET By Non-Browser Process
mediumDetects an initiated network connection by a non browser process on the system to "azurewebsites.net". The latter was often used by threat actors as a malware hosting and exfiltration site.
windows · network_connection
Network Connection Initiated To BTunnels Domains
mediumDetects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To Cloudflared Tunnels Domains
mediumDetects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To DevTunnels Domain
mediumDetects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
Network Connection Initiated To Visual Studio Code Tunnels Domain
mediumDetects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.
windows · network_connection
New Agent Skills Installation Attempt Via Node.EXE
mediumDetects the attempt to install new skills for AI agents using the "npx skills" command. Agent skills enhance AI agents with new capabilities, but attackers may abuse this mechanism to inject malicious commands executed by the agent on behalf of the user. The "npx skills" command can install skills for various agents (e.g., Claude Code, Cursor, and others). Analysts should review any installed skills to verify their legitimacy. Note: Tune this rule based on whether AI agent tooling is allowed in your environment. In environments where such tooling is authorized, this detection may reflect normal activity and the alert level should be adjusted accordingly. In environments where AI agent tooling is not permitted, this activity is likely suspicious and may require immediate investigation.
windows · process_creation
New BgInfo.EXE Custom DB Path Registry Configuration
mediumDetects setting of a new registry database value related to BgInfo configuration. Attackers can for example set this value to save the results of the commands executed by BgInfo in order to exfiltrate information.
windows · registry_set
New BgInfo.EXE Custom VBScript Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom VBScript via "BgInfo.exe"
windows · registry_set
New BgInfo.EXE Custom WMI Query Registry Configuration
mediumDetects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom WMI query via "BgInfo.exe"
windows · registry_set
New Capture Session Launched Via DXCap.EXE
mediumDetects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.
windows · process_creation
New Custom Shim Database Created
mediumAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time.
windows · file_event
New DLL Added to AppCertDlls Registry Key
mediumDynamic-link libraries (DLLs) that are specified in the AppCertDLLs value in the Registry key can be abused to obtain persistence and privilege escalation by causing a malicious DLL to be loaded and run in the context of separate processes on the computer.
windows · registry_event
New DLL Added to AppInit_DLLs Registry Key
mediumDLLs that are specified in the AppInit_DLLs value in the Registry key HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows are loaded by user32.dll into every process that loads user32.dll
windows · registry_event
New DLL Registered Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.
windows · process_creation
New DMSA Service Account Created in Specific OUs
mediumDetects the creation of a dMSASvc account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the Cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.
windows · process_creation
New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE
mediumDetects the addition of a new "Allow" firewall rule by the WMI process (WmiPrvSE.EXE). This can occur if an attacker leverages PowerShell cmdlets such as "New-NetFirewallRule", or directly uses WMI CIM classes such as "MSFT_NetFirewallRule".
windows · firewall-as
New Firewall Rule Added Via Netsh.EXE
mediumDetects the addition of a new rule to the Windows firewall via netsh
windows · process_creation
New Generic Credentials Added Via Cmdkey.EXE
mediumDetects usage of "cmdkey.exe" to add generic credentials. As an example, this can be used before connecting to an RDP session via command line interface.
windows · process_creation
New Kernel Driver Via SC.EXE
mediumDetects creation of a new service (kernel driver) with the type "kernel"
windows · process_creation
New Module Module Added To IIS Server
mediumDetects the addition of a new module to an IIS server.
windows · iis-configuration
New MsDS-DelegatedManagedServiceAccount (DMSA) Object Created
mediumDetects the creation of new msDS-DelegatedManagedServiceAccount objects, which could indicate potential abuse of privilege escalation vulnerabilities in Windows Server 2025. The msDS-DelegatedManagedServiceAccount (DMSA) is a new object class introduced in Windows Server 2025 that allows administrators to delegate the management of service accounts to other users or groups. Attackers may exploit this feature to create unauthorized service accounts with elevated privileges, leading to privilege escalation within the Active Directory environment. It is highly suspicious if an msDS-DelegatedManagedServiceAccount object is created without proper authorization or in an unexpected context, such as by a non-administrative user or outside of normal administrative workflows. So, it's a good idea to look out for accounts that are not typically responsible for service account creation to detect potential abuse of this feature.
windows · security
New Network Trace Capture Started Via Netsh.EXE
mediumDetects the execution of netsh with the "trace" flag in order to start a network capture
windows · process_creation
New or Renamed User Account with '$' Character
mediumDetects the creation of a user with the "$" character. This can be used by attackers to hide a user or trick detection systems that lack the parsing mechanisms.
windows · security
New Outlook Macro Created
mediumDetects the creation of a macro file for Outlook.
windows · file_event
New PDQDeploy Service - Client Side
mediumDetects PDQDeploy service installation on the target system. When a package is deployed via PDQDeploy it installs a remote service on the target machine with the name "PDQDeployRunner-X" where "X" is an integer starting from 1
windows · system
New PDQDeploy Service - Server Side
mediumDetects a PDQDeploy service installation which indicates that PDQDeploy was installed on the machines. PDQDeploy can be abused by attackers to remotely install packages or execute commands on target machines
windows · system
New Port Forwarding Rule Added Via Netsh.EXE
mediumDetects the execution of netsh commands that configure a new port forwarding (PortProxy) rule
windows · process_creation
New PortProxy Registry Entry Added
mediumDetects the modification of the PortProxy registry key which is used for port forwarding.
windows · registry_event
New Remote Desktop Connection Initiated Via Mstsc.EXE
mediumDetects the usage of "mstsc.exe" with the "/v" flag to initiate a connection to a remote server. Adversaries may use valid accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user.
windows · process_creation
New Root Certificate Installed Via CertMgr.EXE
mediumDetects execution of "certmgr" with the "add" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
New Root Certificate Installed Via Certutil.EXE
mediumDetects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · process_creation
New Root or CA or AuthRoot Certificate to Store
mediumDetects the addition of new root, CA or AuthRoot certificates to the Windows registry
windows · registry_set
New Self Extracting Package Created Via IExpress.EXE
mediumDetects the "iexpress.exe" utility creating self-extracting packages. Attackers where seen leveraging "iexpress" to compile packages on the fly via ".sed" files. Investigate the command line options provided to "iexpress" and in case of a ".sed" file, check the contents and legitimacy of it.
windows · process_creation
New User Account Creation Attempt Via ADSI
mediumDetects an attempt to create a new user account via ADSI (Active Directory Service Interfaces) using either the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
windows · ps_script
New User Account Creation Attempt Via ADSI in CommandLine
mediumDetects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands such as "net user", "New-LocalUser" or "New-ADUser".
windows · process_creation
New User Created Via Net.EXE
mediumIdentifies the creation of local users via the net.exe command.
windows · process_creation
New Virtual Smart Card Created Via TpmVscMgr.EXE
mediumDetects execution of "Tpmvscmgr.exe" to create a new virtual smart card.
windows · process_creation
Node Process Executions
mediumDetects the execution of other scripts using the Node executable packaged with Adobe Creative Cloud
windows · process_creation
Non-DLL Extension File Renamed With DLL Extension
mediumDetects rename operations of files with non-DLL extensions to files with a DLL extension. This is often performed by malware in order to avoid initial detections based on extensions.
windows · file_rename
Notepad++ Updater DNS Query to Uncommon Domains
mediumDetects when the Notepad++ updater (gup.exe) makes DNS queries to domains that are not part of the known legitimate update infrastructure. This could indicate potential exploitation of the updater mechanism or suspicious network activity that warrants further investigation.
windows · dns_query
Nslookup PowerShell Download Cradle
mediumDetects a powershell download cradle using nslookup. This cradle uses nslookup to extract payloads from DNS records.
windows · ps_classic_start
Nslookup PowerShell Download Cradle - ProcessCreation
mediumDetects suspicious powershell download cradle using nslookup. This cradle uses nslookup to extract payloads from DNS records
windows · process_creation
Ntdsutil Abuse
mediumDetects potential abuse of ntdsutil to dump ntds.dit database
windows · application
NTLM Brute Force
mediumDetects common NTLM brute force device names
windows · ntlm
NTLMv1 Logon Between Client and Server
mediumDetects the reporting of NTLMv1 being used between a client and server. NTLMv1 is insecure as the underlying encryption algorithms can be brute-forced by modern hardware.
windows · system
Obfuscated IP Download Activity
mediumDetects use of an encoded/obfuscated version of an IP address (hex, octal...) in an URL combined with a download command
windows · process_creation
Obfuscated IP Via CLI
mediumDetects usage of an encoded/obfuscated version of an IP address (hex, octal, etc.) via command line
windows · process_creation
Office Application Initiated Network Connection Over Uncommon Ports
mediumDetects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.
windows · network_connection
Office Application Initiated Network Connection To Non-Local IP
mediumDetects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.
windows · network_connection
Office Application Startup - Office Test
mediumDetects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started
windows · registry_event
Office Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened. There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive. Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
windows · registry_set
Old TLS1.0/TLS1.1 Protocol Version Enabled
mediumDetects applications or users re-enabling old TLS versions by setting the "Enabled" value to "1" for the "Protocols" registry key.
windows · registry_set
OneNote Attachment File Dropped In Suspicious Location
mediumDetects creation of files with the ".one"/".onepkg" extension in suspicious or uncommon locations. This could be a sign of attackers abusing OneNote attachments
windows · file_event
OpenEDR Spawning Command Shell
mediumDetects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities. This may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool. Threat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.
windows · process_creation
OpenSSH Server Listening On Socket
mediumDetects scenarios where an attacker enables the OpenSSH server and server starts to listening on SSH socket.
windows · openssh
Outbound Network Connection To Public IP Via Winlogon
mediumDetects a "winlogon.exe" process that initiate network communications with public IP addresses
windows · network_connection
Outlook Security Settings Updated - Registry
mediumDetects changes to the registry values related to outlook security settings
windows · registry_set
PAExec Service Installation
mediumDetects PAExec service installation
windows · system
Pass the Hash Activity 2
mediumDetects the attack technique pass the hash which is used to move laterally inside the network
windows · security
Password Policy Enumerated
mediumDetects when the password policy is enumerated.
windows · security
Password Protected ZIP File Opened
mediumDetects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
windows · security
Password Provided In Command Line Of Net.EXE
mediumDetects a when net.exe is called with a password in the command line
windows · process_creation
Password Set to Never Expire via WMI
mediumDetects the use of wmic.exe to modify user account settings and explicitly disable password expiration.
windows · process_creation
Path To Screensaver Binary Modified
mediumDetects value modification of registry key containing path to binary used as screensaver.
windows · registry_event
PDQ Deploy Remote Adminstartion Tool Execution
mediumDetect use of PDQ Deploy remote admin tool
windows · process_creation
Periodic Backup For System Registry Hives Enabled
mediumDetects the enabling of the "EnablePeriodicBackup" registry value. Once enabled, The OS will backup System registry hives on restarts to the "C:\Windows\System32\config\RegBack" folder. Windows creates a "RegIdleBackup" task to manage subsequent backups. Registry backup was a default behavior on Windows and was disabled as of "Windows 10, version 1803".
windows · registry_set
Perl Inline Command Execution
mediumDetects execution of perl using the "-e"/"-E" flags. This is could be used as a way to launch a reverse shell or execute live perl code.
windows · process_creation
Permission Check Via Accesschk.EXE
mediumDetects the usage of the "Accesschk" utility, an access and privilege audit tool developed by SysInternal and often being abused by attacker to verify process privileges
windows · process_creation
Permission Misconfiguration Reconnaissance Via Findstr.EXE
mediumDetects usage of findstr with the "EVERYONE" or "BUILTIN" keywords. This was seen being used in combination with "icacls" and other utilities to spot misconfigured files or folders permissions.
windows · process_creation
Persistence Via Disk Cleanup Handler - Autorun
mediumDetects when an attacker modifies values of the Disk Cleanup Handler in the registry to achieve persistence via autorun. The disk cleanup manager is part of the operating system. It displays the dialog box […] The user has the option of enabling or disabling individual handlers by selecting or clearing their check box in the disk cleanup manager's UI. Although Windows comes with a number of disk cleanup handlers, they aren't designed to handle files produced by other applications. Instead, the disk cleanup manager is designed to be flexible and extensible by enabling any developer to implement and register their own disk cleanup handler. Any developer can extend the available disk cleanup services by implementing and registering a disk cleanup handler.
windows · registry_set
Persistence Via New SIP Provider
mediumDetects when an attacker register a new SIP provider for persistence and defense evasion
windows · registry_set
Persistence Via TypedPaths - CommandLine
mediumDetects modification addition to the 'TypedPaths' key in the user or admin registry via the commandline. Which might indicate persistence attempt
windows · process_creation
Php Inline Command Execution
mediumDetects execution of php using the "-r" flag. This is could be used as a way to launch a reverse shell or execute live php code.
windows · process_creation
PktMon.EXE Execution
mediumDetects execution of PktMon, a tool that captures network packets.
windows · process_creation
Port Forwarding Activity Via SSH.EXE
mediumDetects port forwarding activity via SSH.exe
windows · process_creation
Portable Gpg.EXE Execution
mediumDetects the execution of "gpg.exe" from uncommon location. Often used by ransomware and loaders to decrypt/encrypt data.
windows · process_creation
Possible DC Shadow Attack
mediumDetects DCShadow via create new SPN
windows · security
Potential Access Token Abuse
mediumDetects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".
windows · security
Potential Active Directory Enumeration Using AD Module - ProcCreation
mediumDetects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
windows · process_creation
Potential Active Directory Enumeration Using AD Module - PsModule
mediumDetects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
windows · ps_module
Potential Active Directory Enumeration Using AD Module - PsScript
mediumDetects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
windows · ps_script
Potential Active Directory Reconnaissance/Enumeration Via LDAP
mediumDetects potential Active Directory enumeration via LDAP
windows · ldap
Potential AD User Enumeration From Non-Machine Account
mediumDetects read access to a domain user from a non-machine account
windows · security
Potential Amazon SSM Agent Hijacking
mediumDetects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.
windows · process_creation
Potential AMSI Bypass Script Using NULL Bits
mediumDetects usage of special strings/null bits in order to potentially bypass AMSI functionalities
windows · ps_script
Potential AMSI Bypass Using NULL Bits
mediumDetects usage of special strings/null bits in order to potentially bypass AMSI functionalities
windows · process_creation
Potential Antivirus Software DLL Sideloading
mediumDetects potential DLL sideloading of DLLs that are part of antivirus software suchas McAfee, Symantec...etc
windows · image_load
Potential Application Whitelisting Bypass via Dnx.EXE
mediumDetects the execution of Dnx.EXE. The Dnx utility allows for the execution of C# code. Attackers might abuse this in order to bypass application whitelisting.
windows · process_creation
Potential APT FIN7 Exploitation Activity
mediumDetects potential APT FIN7 exploitation activity as reported by Google. In order to obtain initial access, FIN7 used compromised Remote Desktop Protocol (RDP) credentials to login to a target server and initiate specific Windows process chains.
windows · process_creation
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
mediumDetects potential BlueMushroom DLL loading activity via regsvr32 from AppData Local
windows · process_creation
Potential Arbitrary Command Execution Via FTP.EXE
mediumDetects execution of "ftp.exe" script with the "-s" or "/s" flag and any child processes ran by "ftp.exe".
windows · process_creation
Potential Arbitrary DLL Load Using Winword
mediumDetects potential DLL sideloading using the Microsoft Office winword process via the '/l' flag.
windows · process_creation
Potential Arbitrary File Download Via Cmdl32.EXE
mediumDetects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious.
windows · process_creation
Potential AS-REP Roasting via Kerberos TGT Requests
mediumDetects suspicious Kerberos TGT requests with pre-authentication disabled (Pre-Authentication Type = 0) and Ticket Encryption Type (0x17) i.e, RC4-HMAC. This may indicate an AS-REP Roasting attack, where attackers request AS-REP messages for accounts without pre-authentication and attempt to crack the encrypted ticket offline to recover user passwords.
windows · security
Potential AVKkid.DLL Sideloading
mediumDetects potential DLL sideloading of "AVKkid.dll"
windows · image_load
Potential Binary Impersonating Sysinternals Tools
mediumDetects binaries that use the same name as legitimate sysinternals tools to evade detection. This rule looks for the execution of binaries that are named similarly to Sysinternals tools. Adversary may rename their malicious tools as legitimate Sysinternals tools to evade detection.
windows · process_creation
Potential Binary Or Script Dropper Via PowerShell
mediumDetects PowerShell creating a binary executable or a script file.
windows · file_event
Potential Binary Proxy Execution Via Cdb.EXE
mediumDetects usage of "cdb.exe" to launch arbitrary processes or commands from a debugger script file
windows · process_creation
Potential Binary Proxy Execution Via VSDiagnostics.EXE
mediumDetects execution of "VSDiagnostics.exe" with the "start" command in order to launch and proxy arbitrary binaries.
windows · process_creation
Potential Browser Data Stealing
mediumAdversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store.
windows · process_creation
Potential CCleanerDU.DLL Sideloading
mediumDetects potential DLL sideloading of "CCleanerDU.dll"
windows · image_load
Potential CCleanerReactivator.DLL Sideloading
mediumDetects potential DLL sideloading of "CCleanerReactivator.dll"
windows · image_load
Potential Chrome Frame Helper DLL Sideloading
mediumDetects potential DLL sideloading of "chrome_frame_helper.dll"
windows · image_load
Potential COM Object Hijacking Via TreatAs Subkey - Registry
mediumDetects COM object hijacking via TreatAs subkey
windows · registry_set
Potential COM Objects Download Cradles Usage - Process Creation
mediumDetects usage of COM objects that can be abused to download files in PowerShell by CLSID
windows · process_creation
Potential COM Objects Download Cradles Usage - PS Script
mediumDetects usage of COM objects that can be abused to download files in PowerShell by CLSID
windows · ps_script
Potential Command Line Path Traversal Evasion Attempt
mediumDetects potential evasion or obfuscation attempts using bogus path traversal via the commandline
windows · process_creation
Potential Commandline Obfuscation Using Escape Characters
mediumDetects potential commandline obfuscation using known escape characters
windows · process_creation
Potential CommandLine Obfuscation Using Unicode Characters
mediumDetects potential CommandLine obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
windows · process_creation
Potential Configuration And Service Reconnaissance Via Reg.EXE
mediumDetects the usage of "reg.exe" in order to query reconnaissance information from the registry. Adversaries may interact with the Windows registry to gather information about credentials, the system, configuration, and installed software.
windows · process_creation
Potential Cookies Session Hijacking
mediumDetects execution of "curl.exe" with the "-c" flag in order to save cookie data.
windows · process_creation
Potential Credential Dumping Activity Via LSASS
mediumDetects process access requests to the LSASS process with specific call trace calls and access masks. This behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature.
windows · process_access
Potential Credential Dumping Attempt Using New NetworkProvider - REG
mediumDetects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
windows · registry_set
Potential Credential Dumping Attempt Via PowerShell
mediumDetects a PowerShell process requesting access to "lsass.exe", which can be indicative of potential credential dumping attempts
windows · process_access
Potential CVE-2021-42278 Exploitation Attempt
mediumThe attacker creates a computer object using those permissions with a password known to her. After that she clears the attribute ServicePrincipalName on the computer object. Because she created the object (CREATOR OWNER), she gets granted additional permissions and can do many changes to the object.
windows · system
Potential CVE-2021-42287 Exploitation Attempt
mediumThe attacker creates a computer object using those permissions with a password known to her. After that she clears the attribute ServicePrincipalName on the computer object. Because she created the object (CREATOR OWNER), she gets granted additional permissions and can do many changes to the object.
windows · system
Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
mediumDetects potential exploitation attempt of CVE-2022-22954, a remote code execution vulnerability in VMware Workspace ONE Access and Identity Manager. As reported by Morphisec, part of the attack chain, threat actors used PowerShell commands that executed as a child processes of the legitimate Tomcat "prunsrv.exe" process application.
windows · process_creation
Potential CVE-2023-23397 Exploitation Attempt - SMB
mediumDetects (failed) outbound connection attempts to internet facing SMB servers. This could be a sign of potential exploitation attempts of CVE-2023-23397.
windows · smbclient-connectivity
Potential CVE-2023-36874 Exploitation - Uncommon Report.Wer Location
mediumDetects the creation of a "Report.wer" file in an uncommon folder structure. This could be a sign of potential exploitation of CVE-2023-36874.
windows · file_event
Potential CVE-2023-36884 Exploitation Dropped File
mediumDetects a specific file being created in the recent folder of Office. These files have been seen being dropped during potential exploitations of CVE-2023-36884
windows · file_event
Potential CVE-2024-35250 Exploitation Activity
mediumDetects potentially suspicious loading of "ksproxy.ax", which may indicate an attempt to exploit CVE-2024-35250.
windows · image_load
Potential Data Exfiltration Over SMTP Via Send-MailMessage Cmdlet
mediumDetects the execution of a PowerShell script with a call to the "Send-MailMessage" cmdlet along with the "-Attachments" flag. This could be a potential sign of data exfiltration via Email. Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
windows · ps_script
Potential Data Exfiltration Via Audio File
mediumDetects potential exfiltration attempt via audio file using PowerShell
windows · ps_script
Potential Data Exfiltration Via Curl.EXE
mediumDetects the execution of the "curl" process with "upload" flags. Which might indicate potential data exfiltration
windows · process_creation
Potential Defense Evasion Via Binary Rename
mediumDetects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
windows · process_creation
Potential Direct Syscall of NtOpenProcess
mediumDetects potential calls to NtOpenProcess directly from NTDLL.
windows · process_access
Potential Discovery Activity Via Dnscmd.EXE
mediumDetects an attempt to leverage dnscmd.exe to enumerate the DNS zones of a domain. DNS zones used to host the DNS records for a particular domain.
windows · process_creation
Potential DLL File Download Via PowerShell Invoke-WebRequest
mediumDetects potential DLL files being downloaded using the PowerShell Invoke-WebRequest or Invoke-RestMethod cmdlets.
windows · process_creation
Potential DLL Injection Or Execution Using Tracker.exe
mediumDetects potential DLL injection and execution using "Tracker.exe"
windows · process_creation
Potential DLL Injection Via AccCheckConsole
mediumDetects the execution "AccCheckConsole" a command-line tool for verifying the accessibility implementation of an application's UI. One of the tests that this checker can run are called "verification routine", which tests for things like Consistency, Navigation, etc. The tool allows a user to provide a DLL that can contain a custom "verification routine". An attacker can build such DLLs and pass it via the CLI, which would then be loaded in the context of the "AccCheckConsole" utility.
windows · process_creation
Potential DLL Sideloading Activity Via ExtExport.EXE
mediumDetects the execution of "Extexport.exe".A utility that is part of the Internet Explorer browser and is used to export and import various settings and data, particularly when switching between Internet Explorer and other web browsers like Firefox. It allows users to transfer bookmarks, browsing history, and other preferences from Internet Explorer to Firefox or vice versa. It can be abused as a tool to side load any DLL. If a folder is provided in the command line it'll load any DLL with one of the following names "mozcrt19.dll", "mozsqlite3.dll", or "sqlite.dll". Arbitrary DLLs can also be loaded if a specific number of flags was provided.
windows · process_creation
Potential DLL Sideloading Of DBGCORE.DLL
mediumDetects DLL sideloading of "dbgcore.dll"
windows · image_load
Potential DLL Sideloading Of DBGHELP.DLL
mediumDetects potential DLL sideloading of "dbghelp.dll"
windows · image_load
Potential DLL Sideloading Of DbgModel.DLL
mediumDetects potential DLL sideloading of "DbgModel.dll"
windows · image_load
Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
mediumDetects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location
windows · image_load
Potential DLL Sideloading Of MpSvc.DLL
mediumDetects potential DLL sideloading of "MpSvc.dll".
windows · image_load
Potential DLL Sideloading Of MsCorSvc.DLL
mediumDetects potential DLL sideloading of "mscorsvc.dll".
windows · image_load
Potential DLL Sideloading Using Coregen.exe
mediumDetect usage of the "coregen.exe" (Microsoft CoreCLR Native Image Generator) binary to sideload arbitrary DLLs.
windows · image_load
Potential DLL Sideloading Via ClassicExplorer32.dll
mediumDetects potential DLL sideloading using ClassicExplorer32.dll from the Classic Shell software
windows · image_load
Potential DLL Sideloading Via DeviceEnroller.EXE
mediumDetects the use of the PhoneDeepLink parameter to potentially sideload a DLL file that does not exist. This non-existent DLL file is named "ShellChromeAPI.dll". Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter
windows · process_creation
Potential DLL Sideloading Via JsSchHlp
mediumDetects potential DLL sideloading using JUSTSYSTEMS Japanese word processor
windows · image_load
Potential Dosfuscation Activity
mediumDetects possible payload obfuscation via the commandline
windows · process_creation
Potential Download/Upload Activity Using Type Command
mediumDetects usage of the "type" command to download/upload data from WebDAV server
windows · process_creation
Potential Dropper Script Execution Via WScript/CScript/MSHTA
mediumDetects wscript/cscript/mshta executions of scripts located in user directories
windows · process_creation
Potential Encrypted Registry Blob Related To SNAKE Malware
mediumDetects the creation of a registry value in the ".wav\OpenWithProgIds" key with an uncommon name. This could be related to SNAKE Malware as reported by CISA
windows · registry_set
Potential Fake Instance Of Hxtsr.EXE Executed
mediumHxTsr.exe is a Microsoft compressed executable file called Microsoft Outlook Communications. HxTsr.exe is part of Outlook apps, because it resides in a hidden "WindowsApps" subfolder of "C:\Program Files". Any instances of hxtsr.exe not in this folder may be malware camouflaging itself as HxTsr.exe
windows · process_creation
Potential File Download Via MS-AppInstaller Protocol Handler
mediumDetects usage of the "ms-appinstaller" protocol handler via command line to potentially download arbitrary files via AppInstaller.EXE The downloaded files are temporarly stored in ":\Users\%username%\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache\<RANDOM-8-CHAR-DIRECTORY>"
windows · process_creation
Potential Goopdate.DLL Sideloading
mediumDetects potential DLL sideloading of "goopdate.dll", a DLL used by googleupdate.exe
windows · image_load
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream
mediumDetects the creation of hidden file/folder with the "::$index_allocation" stream. Which can be used as a technique to prevent access to folder and files from tooling such as "explorer.exe" and "powershell.exe"
windows · file_event
Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI
mediumDetects command line containing reference to the "::$index_allocation" stream, which can be used as a technique to prevent access to folders or files from tooling such as "explorer.exe" or "powershell.exe"
windows · process_creation
Potential Homoglyph Attack Using Lookalike Characters
mediumDetects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
windows · process_creation
Potential Homoglyph Attack Using Lookalike Characters in Filename
mediumDetects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
windows · file_event
Potential In-Memory Execution Using Reflection.Assembly
mediumDetects usage of "Reflection.Assembly" load functions to dynamically load assemblies in memory
windows · ps_script
Potential Initial Access via DLL Search Order Hijacking
mediumDetects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.
windows · file_event
Potential KamiKakaBot Activity - Lure Document Execution
mediumDetects the execution of a Word document via the WinWord Start Menu shortcut. This behavior was observed being used by KamiKakaBot samples in order to initiate the 2nd stage of the infection.
windows · process_creation
Potential KamiKakaBot Activity - Shutdown Schedule Task Creation
mediumDetects the creation of a schedule task that runs weekly and execute the "shutdown /l /f" command. This behavior was observed being used by KamiKakaBot samples in order to achieve persistence on a system.
windows · process_creation
Potential Keylogger Activity
mediumDetects PowerShell scripts that contains reference to keystroke capturing functions
windows · ps_script
Potential Lateral Movement via Windows Remote Shell
mediumDetects a child process spawned by 'winrshost.exe', which suggests remote command execution through Windows Remote Shell (WinRs) and may indicate potential lateral movement activity.
windows · process_creation
Potential Libvlc.DLL Sideloading
mediumDetects potential DLL sideloading of "libvlc.dll", a DLL that is legitimately used by "VLC.exe"
windows · image_load
Potential Malicious AppX Package Installation Attempts
mediumDetects potential installation or installation attempts of known malicious appx packages
windows · appxdeployment-server
Potential Memory Dumping Activity Via LiveKD
mediumDetects execution of LiveKD based on PE metadata or image name
windows · process_creation
Potential Mfdetours.DLL Sideloading
mediumDetects potential DLL sideloading of "mfdetours.dll". While using "mftrace.exe" it can be abused to attach to an arbitrary process and force load any DLL named "mfdetours.dll" from the current directory of execution.
windows · image_load
Potential Mftrace.EXE Abuse
mediumDetects child processes of the "Trace log generation tool for Media Foundation Tools" (Mftrace.exe) which can abused to execute arbitrary binaries.
windows · process_creation
Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE
mediumDetects the execution of "csc.exe" via "w3wp.exe" process. MOVEit affected hosts execute "csc.exe" via the "w3wp.exe" process to dynamically compile malicious DLL files. MOVEit is affected by a critical vulnerability. Exploited hosts show evidence of dynamically compiling a DLL and writing it under C:\\Windows\\Microsoft\.NET\\Framework64\\v4\.0\.30319\\Temporary ASP\.NET Files\\root\\([a-z0-9]{5,12})\\([a-z0-9]{5,12})\\App_Web_[a-z0-9]{5,12}\.dll. Hunting Opportunity Events from IIS dynamically compiling binaries via the csc.exe on behalf of the MOVEit application, especially since May 27th should be investigated.
windows · process_creation
Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
mediumDetects execution of Windows Defender "OfflineScannerShell.exe" from its non standard directory. The "OfflineScannerShell.exe" binary is vulnerable to DLL side loading and will load any DLL named "mpclient.dll" from the current working directory.
windows · process_creation
Potential Network Sniffing Activity Using Network Tools
mediumDetects potential network sniffing via use of network tools such as "tshark", "windump". Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.
windows · process_creation
Potential Obfuscated Ordinal Call Via Rundll32
mediumDetects execution of "rundll32" with potential obfuscated ordinal calls
windows · process_creation
Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock
mediumDetects the execution of powershell scripts with calls to the "Start-NetEventSession" cmdlet. Which allows an attacker to start event and packet capture for a network event session. Adversaries may attempt to capture network to gather information over the course of an operation. Data captured via this technique may include user credentials, especially those sent over an insecure, unencrypted protocol.
windows · ps_script
Potential Pass the Hash Activity
mediumDetects the attack technique pass the hash which is used to move laterally inside the network
windows · security
Potential Password Reconnaissance Via Findstr.EXE
mediumDetects command line usage of "findstr" to search for the "passwords" keyword in a variety of different languages
windows · process_creation
Potential Password Spraying Attempt Using Dsacls.EXE
mediumDetects possible password spraying attempts using Dsacls
windows · process_creation
Potential PendingFileRenameOperations Tampering
mediumDetect changes to the "PendingFileRenameOperations" registry key from uncommon or suspicious images locations to stage currently used files for rename or deletion after reboot.
windows · registry_set
Potential Persistence Attempt Via ErrorHandler.Cmd
mediumDetects creation of a file named "ErrorHandler.cmd" in the "C:\WINDOWS\Setup\Scripts\" directory which could be used as a method of persistence The content of C:\WINDOWS\Setup\Scripts\ErrorHandler.cmd is read whenever some tools under C:\WINDOWS\System32\oobe\ (e.g. Setup.exe) fail to run for any reason.
windows · file_event
Potential Persistence Attempt Via Existing Service Tampering
mediumDetects the modification of an existing service in order to execute an arbitrary payload when the service is started or killed as a potential method for persistence.
windows · process_creation
Potential Persistence Attempt Via Run Keys Using Reg.EXE
mediumDetects suspicious command line reg.exe tool adding key to RUN key in Registry
windows · process_creation
Potential Persistence Using DebugPath
mediumDetects potential persistence using Appx DebugPath
windows · registry_set
Potential Persistence Via AppCompat RegisterAppRestart Layer
mediumDetects the setting of the REGISTERAPPRESTART compatibility layer on an application. This compatibility layer allows an application to register for restart using the "RegisterApplicationRestart" API. This can be potentially abused as a persistence mechanism.
windows · registry_set
Potential Persistence Via Custom Protocol Handler
mediumDetects potential persistence activity via the registering of a new custom protocole handlers. While legitimate applications register protocole handlers often times during installation. And attacker can abuse this by setting a custom handler to be used as a persistence mechanism.
windows · registry_set
Potential Persistence Via Disk Cleanup Handler - Registry
mediumDetects when an attacker modifies values of the Disk Cleanup Handler in the registry to achieve persistence. The disk cleanup manager is part of the operating system. It displays the dialog box […] The user has the option of enabling or disabling individual handlers by selecting or clearing their check box in the disk cleanup manager's UI. Although Windows comes with a number of disk cleanup handlers, they aren't designed to handle files produced by other applications. Instead, the disk cleanup manager is designed to be flexible and extensible by enabling any developer to implement and register their own disk cleanup handler. Any developer can extend the available disk cleanup services by implementing and registering a disk cleanup handler.
windows · registry_add
Potential Persistence Via Event Viewer Events.asp
mediumDetects potential registry persistence technique using the Event Viewer "Events.asp" technique
windows · registry_set
Potential Persistence Via Logon Scripts - Registry
mediumDetects creation of "UserInitMprLogonScript" registry value which can be used as a persistence method by malicious actors
windows · registry_set
Potential Persistence Via Microsoft Compatibility Appraiser
mediumDetects manual execution of the "Microsoft Compatibility Appraiser" task via schtasks. In order to trigger persistence stored in the "\AppCompatFlags\TelemetryController" registry key.
windows · process_creation
Potential Persistence Via Netsh Helper DLL
mediumDetects the execution of netsh with "add helper" flag in order to add a custom helper DLL. This technique can be abused to add a malicious helper DLL that can be used as a persistence proxy that gets called when netsh.exe is executed.
windows · process_creation
Potential Persistence Via Netsh Helper DLL - Registry
mediumDetects changes to the Netsh registry key to add a new DLL value. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
windows · registry_set
Potential Persistence Via New AMSI Providers - Registry
mediumDetects when an attacker adds a new AMSI provider via the Windows Registry to bypass AMSI (Antimalware Scan Interface) protections. Attackers may add custom AMSI providers to persist on the system and evade detection by security software that relies on AMSI for scanning scripts and other content. This technique is often used in conjunction with fileless malware and script-based attacks to maintain persistence while avoiding detection.
windows · registry_set
Potential Persistence Via Notepad++ Plugins
mediumDetects creation of new ".dll" files inside the plugins directory of a notepad++ installation by a process other than "gup.exe". Which could indicates possible persistence
windows · file_event
Potential Persistence Via PowerShell User Profile Using Add-Content
mediumDetects calls to "Add-Content" cmdlet in order to modify the content of the user profile and potentially adding suspicious commands for persistence
windows · ps_script
Potential Persistence Via Scrobj.dll COM Hijacking
mediumDetect use of scrobj.dll as this DLL looks for the ScriptletURL key to get the location of the script to execute
windows · registry_set
Potential Persistence Via Shim Database Modification
mediumAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time
windows · registry_set
Potential Persistence Via Visual Studio Tools for Office
mediumDetects persistence via Visual Studio Tools for Office (VSTO) add-ins in Office applications.
windows · registry_set
Potential Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
mediumDetects execution of the "VMwareToolBoxCmd.exe" with the "script" and "set" flag to setup a specific script to run for a specific VM state
windows · process_creation
Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
mediumDetects the execution of concatenated commands via "cmd.exe". Pikabot often executes a combination of multiple commands via the command handler "cmd /c" in order to download and execute additional payloads. Commands such as "curl", "wget" in order to download extra payloads. "ping" and "timeout" are abused to introduce delays in the command execution and "Rundll32" is also used to execute malicious DLL files. In the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.
windows · process_creation
Potential PowerShell Console History Access Attempt via History File
mediumDetects potential access attempts to the PowerShell console history directly via history file (ConsoleHost_history.txt). This can give access to plaintext passwords used in PowerShell commands or used for general reconnaissance.
windows · process_creation
Potential PowerShell Downgrade Attack
mediumDetects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0
windows · process_creation
Potential PowerShell Execution Policy Tampering
mediumDetects changes to the PowerShell execution policy in order to bypass signing requirements for script execution
windows · registry_set
Potential Privileged System Service Operation - SeLoadDriverPrivilege
mediumDetects the usage of the 'SeLoadDriverPrivilege' privilege. This privilege is required to load or unload a device driver. With this privilege, the user can dynamically load and unload device drivers or other code in to kernel mode. This user right does not apply to Plug and Play device drivers. If you exclude privileged users/admins and processes, which are allowed to do so, you are maybe left with bad programs trying to load malicious kernel drivers. This will detect Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs) and the usage of Sysinternals and various other tools. So you have to work with a whitelist to find the bad stuff.
windows · security
Potential Process Execution Proxy Via CL_Invocation.ps1
mediumDetects calls to "SyncInvoke" that is part of the "CL_Invocation.ps1" script to proxy execution using "System.Diagnostics.Process"
windows · process_creation
Potential Process Hollowing Activity
mediumDetects when a memory process image does not match the disk image, indicative of process hollowing.
windows · process_tampering
Potential Process Reconnaissance via Wmic.EXE
mediumDetects the execution of "wmic" with the "process" flag, which might indicate an attempt to perform reconnaissance on running processes. Adversaries may use wmic to query for running processes and their details as part of their reconnaissance efforts.
windows · process_creation
Potential Product Class Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC in order to get a list of firewall, antivirus and antispywware products. Adversaries often enumerate security products installed on a system to identify security controls and potential ways to evade detection or disable protection mechanisms. This information helps them plan their next attack steps and choose appropriate techniques to bypass security measures.
windows · process_creation
Potential Product Reconnaissance Via Wmic.EXE
mediumDetects the execution of WMIC in order to get a list of firewall and antivirus products
windows · process_creation
Potential Provlaunch.EXE Binary Proxy Execution Abuse
mediumDetects child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.
windows · process_creation
Potential Python DLL SideLoading
mediumDetects potential DLL sideloading of Python DLL files.
windows · image_load
Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
mediumDetects potential malicious and unauthorized usage of bcdedit.exe
windows · process_creation
Potential RDP Exploit CVE-2019-0708
mediumDetect suspicious error on protocol RDP, potential CVE-2019-0708
windows · system
Potential RDP Session Hijacking Activity
mediumDetects potential RDP Session Hijacking activity on Windows systems
windows · process_creation
Potential Recon Activity Via Nltest.EXE
mediumDetects nltest commands that can be used for information discovery
windows · process_creation
Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
mediumDetects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine
windows · process_creation
Potential ReflectDebugger Content Execution Via WerFault.EXE
mediumDetects execution of "WerFault.exe" with the "-pr" commandline flag that is used to run files stored in the ReflectDebugger key which could be used to store the path to the malware in order to masquerade the execution flow
windows · process_creation
Potential Register_App.Vbs LOLScript Abuse
mediumDetects potential abuse of the "register_app.vbs" script that is part of the Windows SDK. The script offers the capability to register new VSS/VDS Provider as a COM+ application. Attackers can use this to install malicious DLLs for persistence and execution.
windows · process_creation
Potential Registry Persistence Attempt Via DbgManagedDebugger
mediumDetects the addition of the "Debugger" value to the "DbgManagedDebugger" key in order to achieve persistence. Which will get invoked when an application crashes
windows · registry_set
Potential Registry Reconnaissance Via PowerShell Script
mediumDetects PowerShell scripts with potential registry reconnaissance capabilities. Adversaries may interact with the Windows registry to gather information about the system credentials, configuration, and installed software.
windows · ps_script
Potential Regsvr32 Commandline Flag Anomaly
mediumDetects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon.
windows · process_creation
Potential Remote Desktop Connection to Non-Domain Host
mediumDetects logons using NTLM to hosts that are potentially not part of the domain.
windows · ntlm
Potential Remote Desktop Tunneling
mediumDetects potential use of an SSH utility to establish RDP over a reverse SSH Tunnel. This can be used by attackers to enable routing of network packets that would otherwise not reach their intended destination.
windows · process_creation
Potential Remote WMI ActiveScriptEventConsumers Activity
mediumDetect potential adversaries leveraging WMI ActiveScriptEventConsumers remotely to move laterally in a network. This event is best correlated and used as an enrichment to determine the potential lateral movement activity.
windows · security
Potential RjvPlatform.DLL Sideloading From Default Location
mediumDetects loading of "RjvPlatform.dll" by the "SystemResetPlatform.exe" binary which can be abused as a method of DLL side loading since the "$SysReset" directory isn't created by default.
windows · image_load
Potential RoboForm.DLL Sideloading
mediumDetects potential DLL sideloading of "roboform.dll", a DLL used by RoboForm Password Manager
windows · image_load
Potential SAP NetWeaver Webshell Creation
mediumDetects the creation of suspicious files (jsp, java, class) in SAP NetWeaver directories, which may indicate exploitation attempts of vulnerabilities such as CVE-2025-31324.
windows · file_event
Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
mediumDetects the use of the Microsoft signed script "CL_mutexverifiers" to proxy the execution of additional PowerShell script commands
windows · process_creation
Potential Secure Deletion with SDelete
mediumDetects files that have extensions commonly seen while SDelete is used to wipe files.
windows · security
Potential SentinelOne Shell Context Menu Scan Command Tampering
mediumDetects potentially suspicious changes to the SentinelOne context menu scan command by a process other than SentinelOne.
windows · registry_set
Potential Shellcode Injection
mediumDetects potential shellcode injection as seen used by tools such as Metasploit's migrate and Empire's psinject.
windows · process_access
Potential ShellDispatch.DLL Functionality Abuse
mediumDetects potential "ShellDispatch.dll" functionality abuse to execute arbitrary binaries via "ShellExecute"
windows · process_creation
Potential ShellDispatch.DLL Sideloading
mediumDetects potential DLL sideloading of "ShellDispatch.dll"
windows · image_load
Potential Shim Database Persistence via Sdbinst.EXE
mediumDetects installation of a new shim using sdbinst.exe. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims
windows · process_creation
Potential SolidPDFCreator.DLL Sideloading
mediumDetects potential DLL sideloading of "SolidPDFCreator.dll"
windows · image_load
Potential SPN Enumeration Via Setspn.EXE
mediumDetects service principal name (SPN) enumeration used for Kerberoasting
windows · process_creation
Potential Suspicious Activity Using SeCEdit
mediumDetects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy
windows · process_creation
Potential Suspicious Browser Launch From Document Reader Process
mediumDetects when a browser process or browser tab is launched from an application that handles document files such as Adobe, Microsoft Office, etc. And connects to a web application over http(s), this could indicate a possible phishing attempt.
windows · process_creation
Potential Suspicious PowerShell Keywords
mediumDetects potentially suspicious keywords that could indicate the use of a PowerShell exploitation framework
windows · ps_script
Potential Suspicious PowerShell Module File Created
mediumDetects the creation of a new PowerShell module in the first folder of the module directory structure "\WindowsPowerShell\Modules\malware\malware.psm1". This is somewhat an uncommon practice as legitimate modules often includes a version folder.
windows · file_event
Potential Suspicious Registry File Imported Via Reg.EXE
mediumDetects the import of '.reg' files from suspicious paths using the 'reg.exe' utility
windows · process_creation
Potential Suspicious Windows Feature Enabled
mediumDetects usage of the built-in PowerShell cmdlet "Enable-WindowsOptionalFeature" used as a Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows · ps_script
Potential Suspicious Windows Feature Enabled - ProcCreation
mediumDetects usage of the built-in PowerShell cmdlet "Enable-WindowsOptionalFeature" used as a Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images
windows · process_creation
Potential UAC Bypass Via Sdclt.EXE
mediumA General detection for sdclt being spawned as an elevated process. This could be an indicator of sdclt being used for bypass UAC techniques.
windows · process_creation
Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
mediumDetects the use of the "Get-ADComputer" cmdlet in order to identify systems which are configured for unconstrained delegation.
windows · ps_script
Potential Unquoted Service Path Reconnaissance Via Wmic.EXE
mediumDetects known WMI recon method to look for unquoted service paths using wmic. Often used by pentester and attacker enumeration scripts
windows · process_creation
Potential Vivaldi_elf.DLL Sideloading
mediumDetects potential DLL sideloading of "vivaldi_elf.dll"
windows · image_load
Potential Wazuh Security Platform DLL Sideloading
mediumDetects potential DLL side loading of DLLs that are part of the Wazuh security platform
windows · image_load
Potential Webshell Creation On Static Website
mediumDetects the creation of files with certain extensions on a static web site. This can be indicative of potential uploads of a web shell.
windows · file_event
Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell
mediumDetects Powershell as a child of the WmiPrvSE process. Which could be a sign of lateral movement via WMI.
windows · process_creation
Potential WWlib.DLL Sideloading
mediumDetects potential DLL sideloading of "wwlib.dll"
windows · image_load
Potentially Over Permissive Permissions Granted Using Dsacls.EXE
mediumDetects usage of Dsacls to grant over permissive permissions
windows · process_creation
Potentially Suspicious AccessMask Requested From LSASS
mediumDetects process handle on LSASS process with certain access mask
windows · security
Potentially Suspicious Azure Front Door Connection
mediumDetects connections with Azure Front Door (known legitimate service that can be leveraged for C2) that fall outside of known benign behavioral baseline (not using common apps or common azurefd.net endpoints)
windows · network_connection
Potentially Suspicious Cabinet File Expansion
mediumDetects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks
windows · process_creation
Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript
mediumDetects usage of the WMI class "Win32_NTEventlogFile" in a potentially suspicious way (delete, backup, change permissions, etc.) from a PowerShell script
windows · ps_script
Potentially Suspicious Child Process Of ClickOnce Application
mediumDetects potentially suspicious child processes of a ClickOnce deployment application
windows · process_creation
Potentially Suspicious Child Process Of DiskShadow.EXE
mediumDetects potentially suspicious child processes of "Diskshadow.exe". This could be an attempt to bypass parent/child relationship detection or application whitelisting rules.
windows · process_creation
Potentially Suspicious Child Process of KeyScrambler.exe
mediumDetects potentially suspicious child processes of KeyScrambler.exe
windows · process_creation
Potentially Suspicious Child Process Of VsCode
mediumDetects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.
windows · process_creation
Potentially Suspicious Child Process Of WinRAR.EXE
mediumDetects potentially suspicious child processes of WinRAR.exe.
windows · process_creation
Potentially Suspicious CMD Shell Output Redirect
mediumDetects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
windows · process_creation
Potentially Suspicious Command Targeting Teams Sensitive Files
mediumDetects a commandline containing references to the Microsoft Teams database or cookies files from a process other than Teams. The database might contain authentication tokens and other sensitive information about the logged in accounts.
windows · process_creation
Potentially Suspicious Compression Tool Parameters
mediumDetects potentially suspicious command line arguments of common data compression tools
windows · process_creation
Potentially Suspicious Desktop Background Change Using Reg.EXE
mediumDetects the execution of "reg.exe" to alter registry keys that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows · process_creation
Potentially Suspicious Desktop Background Change Via Registry
mediumDetects registry value settings that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.
windows · registry_set
Potentially Suspicious DMP/HDMP File Creation
mediumDetects the creation of a file with the ".dmp"/".hdmp" extension by a shell or scripting application such as "cmd", "powershell", etc. Often created by software during a crash. Memory dumps can sometimes contain sensitive information such as credentials. It's best to determine the source of the crash.
windows · file_event
Potentially Suspicious Electron Application CommandLine
mediumDetects potentially suspicious CommandLine of electron apps (teams, discord, slack, etc.). This could be a sign of abuse to proxy execution through a signed binary.
windows · process_creation
Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
mediumDetects execution of different log query utilities and commands to search and dump the content of specific event logs or look for specific event IDs. This technique is used by threat actors in order to extract sensitive information from events logs such as usernames, IP addresses, hostnames, etc.
windows · process_creation
Potentially Suspicious Execution Of PDQDeployRunner
mediumDetects suspicious execution of "PDQDeployRunner" which is part of the PDQDeploy service stack that is responsible for executing commands and packages on a remote machines
windows · process_creation
Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities from a potentially suspicious location
windows · process_creation
Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
mediumDetects potentially suspicious execution of the Regasm/Regsvcs utilities with an uncommon extension.
windows · process_creation
Potentially Suspicious Explicit Credential Local Logon
mediumDetects potentially suspicious explicit credential logon events where the user is trying to logon with explicit credentials (username and password) that are different from the current user context. It might indicate an attacker attempting to escalate privileges after obtaining credentials for a different user account.
windows · security
Potentially Suspicious File Creation by OpenEDR's ITSMService
mediumDetects the creation of potentially suspicious files by OpenEDR's ITSMService process. The ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features. While legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.
windows · file_event
Potentially Suspicious GrantedAccess Flags On LSASS
mediumDetects process access requests to LSASS process with potentially suspicious access flags
windows · process_access
Potentially Suspicious Image Load of Offreg.dll
mediumDetects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API, bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives while evading detection mechanisms that rely on standard registry event logs.
windows · image_load
Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
mediumDetects potentially suspicious inline JavaScript execution using Node.js with specific keywords in the command line.
windows · process_creation
Potentially Suspicious JWT Token Search Via CLI
mediumDetects potentially suspicious search for JWT tokens via CLI by looking for the string "eyJ0eX" or "eyJhbG". JWT tokens are often used for access-tokens across various applications and services like Microsoft 365, Azure, AWS, Google Cloud, and others. Threat actors may search for these tokens to steal them for lateral movement or privilege escalation.
windows · process_creation
Potentially Suspicious NTFS Symlink Behavior Modification
mediumDetects the modification of NTFS symbolic link behavior using fsutil, which could be used to enable remote to local or remote to remote symlinks for potential attacks.
windows · process_creation
Potentially Suspicious Ping/Copy Command Combination
mediumDetects uncommon and potentially suspicious one-liner command containing both "ping" and "copy" at the same time, which is usually used by malware.
windows · process_creation
Potentially Suspicious PowerShell Child Processes
mediumDetects potentially suspicious child processes spawned by PowerShell. Use this rule to hunt for potential anomalies initiating from PowerShell scripts and commands.
windows · process_creation
Potentially Suspicious Powershell Script Execution From Temp Folder
mediumDetects a potentially suspicious powershell script executions from temporary folder
windows · process_creation
Potentially Suspicious Regsvr32 HTTP/FTP Pattern
mediumDetects regsvr32 execution to download/install/register new DLLs that are hosted on Web or FTP servers.
windows · process_creation
Potentially Suspicious Rundll32 Activity
mediumDetects suspicious execution of rundll32, with specific calls to some DLLs with known LOLBIN functionalities
windows · process_creation
Potentially Suspicious Rundll32.EXE Execution of UDL File
mediumDetects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.
windows · process_creation
Potentially Suspicious Self Extraction Directive File Created
mediumDetects the creation of a binary file with the ".sed" extension. The ".sed" extension stand for Self Extraction Directive files. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries. Usually ".sed" files are simple ini files and not PE binaries.
windows · file_executable_detected
Potentially Suspicious Usage Of Qemu
mediumDetects potentially suspicious execution of the Qemu utility in a Windows environment. Threat actors have leveraged this utility and this technique for achieving network access as reported by Kaspersky.
windows · process_creation
Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load
mediumDetects the image load of VSS DLL by uncommon executables
windows · image_load
Potentially Suspicious WDAC Policy File Creation
mediumDetects suspicious Windows Defender Application Control (WDAC) policy file creation from abnormal processes that could be abused by attacker to block EDR/AV components while allowing their own malicious code to run on the system.
windows · file_event
Potentially Suspicious WebDAV LNK Execution
mediumDetects possible execution via LNK file accessed on a WebDAV server.
windows · process_creation
Potentially Suspicious Windows App Activity
mediumDetects potentially suspicious child process of applications launched from inside the WindowsApps directory. This could be a sign of a rogue ".appx" package installation/execution
windows · process_creation
Potentially Suspicious Wuauclt Network Connection
mediumDetects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections. One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.
windows · network_connection
PowerShell Console History Logs Deleted
mediumDetects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence
windows · file_delete
PowerShell Core DLL Loaded By Non PowerShell Process
mediumDetects loading of essential DLLs used by PowerShell by non-PowerShell process. Detects behavior similar to meterpreter's "load powershell" extension.
windows · image_load
PowerShell Core DLL Loaded Via Office Application
mediumDetects PowerShell core DLL being loaded by an Office Product
windows · image_load
PowerShell Create Local User
mediumDetects creation of a local user via PowerShell
windows · ps_script
Powershell Create Scheduled Task
mediumAdversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code
windows · ps_script
Powershell Defender Exclusion
mediumDetects requests to exclude files, folders or processes from Antivirus scanning using PowerShell cmdlets
windows · process_creation
PowerShell Deleted Mounted Share
mediumDetects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
windows · ps_script
Powershell Detect Virtualization Environment
mediumAdversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox
windows · ps_script
Powershell Directory Enumeration
mediumDetects technique used by MAZE ransomware to enumerate directories using Powershell
windows · ps_script
PowerShell Downgrade Attack - PowerShell
mediumDetects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0
windows · ps_classic_start
PowerShell Download Pattern
mediumDetects a Powershell process that contains download commands in its command line string
windows · process_creation
Powershell Execute Batch Script
mediumAdversaries may abuse the Windows command shell for execution. The Windows command shell ([cmd](https://attack.mitre.org/software/S0106)) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. Batch files (ex: .bat or .cmd) also provide the shell with a list of sequential commands to run, as well as normal scripting operations such as conditionals and loops. Common uses of batch files include long or repetitive tasks, or the need to run the same set of commands on multiple system
windows · ps_script
Powershell Executed From Headless ConHost Process
mediumDetects the use of powershell commands from headless ConHost window. The "--headless" flag hides the windows from the user upon execution.
windows · process_creation
PowerShell Get Clipboard
mediumA General detection for the Get-Clipboard commands in PowerShell logs. This could be an adversary capturing clipboard contents.
windows · ps_module
PowerShell Get-Clipboard Cmdlet Via CLI
mediumDetects usage of the 'Get-Clipboard' cmdlet via CLI
windows · process_creation
PowerShell Hotfix Enumeration
mediumDetects call to "Win32_QuickFixEngineering" in order to enumerate installed hotfixes often used in "enum" scripts by attackers
windows · ps_script
PowerShell ICMP Exfiltration
mediumDetects Exfiltration Over Alternative Protocol - ICMP. Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
windows · ps_script
Powershell Inline Execution From A File
mediumDetects inline execution of PowerShell code from a file
windows · process_creation
Powershell Keylogging
mediumAdversaries may log user keystrokes to intercept credentials as the user types them.
windows · ps_script
Powershell Local Email Collection
mediumAdversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a users local system, such as Outlook storage or cache files.
windows · ps_script
Powershell LocalAccount Manipulation
mediumAdversaries may manipulate accounts to maintain access to victim systems. Account manipulation may consist of any action that preserves adversary access to a compromised account, such as modifying credentials or permission groups
windows · ps_script
PowerShell Module File Created By Non-PowerShell Process
mediumDetects the creation of a new PowerShell module ".psm1", ".psd1", ".dll", ".ps1", etc. by a non-PowerShell process
windows · file_event
PowerShell MSI Install via WindowsInstaller COM From Remote Location
mediumDetects the execution of PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`) hosted remotely. This could be indication of malicious software deployment or lateral movement attempts using Windows Installer functionality. And the usage of WindowsInstaller COM object rather than msiexec could be an attempt to bypass the detection.
windows · process_creation
Powershell MsXml COM Object
mediumAdversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. (Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code
windows · ps_script
PowerShell Profile Modification
mediumDetects the creation or modification of a powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence
windows · file_event
PowerShell Remote Session Creation
mediumAdversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system
windows · ps_script
PowerShell Script Run in AppData
mediumDetects a suspicious command line execution that invokes PowerShell with reference to an AppData folder
windows · process_creation
PowerShell Script With File Hostname Resolving Capabilities
mediumDetects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.
windows · ps_script
Powershell Sensitive File Discovery
mediumDetect adversaries enumerate sensitive files
windows · ps_script
Powershell Store File In Alternate Data Stream
mediumStoring files in Alternate Data Stream (ADS) similar to Astaroth malware.
windows · ps_script
Powershell Timestomp
mediumAdversaries may modify file time attributes to hide new or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder.
windows · ps_script
Powershell Token Obfuscation - Powershell
mediumDetects TOKEN OBFUSCATION technique from Invoke-Obfuscation in Powershell scripts. Use this rule as a threat-hunting baseline to find obfuscated scripts in your environment. Once tested and tuned, consider deploying a production detection rule based on this hunting rule.
windows · ps_script
Powershell WMI Persistence
mediumAdversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
windows · ps_script
PowerShell WMI Win32_Product Install MSI
mediumDetects the execution of an MSI file using PowerShell and the WMI Win32_Product class
windows · ps_script
PowerShell Write-EventLog Usage
mediumDetects usage of the "Write-EventLog" cmdlet with 'RawData' flag. The cmdlet can be levreage to write malicious payloads to the EventLog and then retrieve them later for later use
windows · ps_script
Powershell XML Execute Command
mediumAdversaries may abuse PowerShell commands and scripts for execution. PowerShell is a powerful interactive command-line interface and scripting environment included in the Windows operating system. (Citation: TechNet PowerShell) Adversaries can use PowerShell to perform a number of actions, including discovery of information and execution of code
windows · ps_script
Private Keys Reconnaissance Via CommandLine Tools
mediumAdversaries may search for private key certificate files on compromised systems for insecurely stored credential
windows · process_creation
Procdump Execution
mediumDetects usage of the SysInternals Procdump utility
windows · process_creation
Process Creation Attempt via Wmic.EXE
mediumDetects the attempt to create a process via "wmic" with the "process call create" flag, which might indicate an attempt to execute a malicious process on the compromised host. Adversaries may use wmic to execute a process on the compromised host as part of their attack. This event is triggered on on attempt and process creation can be either successful or unsuccessful.
windows · process_creation
Process Creation Using Sysnative Folder
mediumDetects process creation events that use the Sysnative folder (common for CobaltStrike spawns)
windows · process_creation
Process Deletion of Its Own Executable
mediumDetects the deletion of a process's executable by itself. This is usually not possible without workarounds and may be used by malware to hide its traces.
windows · file_delete
Process Launched Without Image Name
mediumDetect the use of processes with no name (".exe"), which can be used to evade Image-based detections.
windows · process_creation
Process Memory Dump Via Dotnet-Dump
mediumDetects the execution of "dotnet-dump" with the "collect" flag. The execution could indicate potential process dumping of critical processes such as LSASS.
windows · process_creation
Process Monitor Driver Creation By Non-Sysinternals Binary
mediumDetects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.
windows · file_event
Process Proxy Execution Via Squirrel.EXE
mediumDetects the usage of the "Squirrel.exe" binary to execute arbitrary processes. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)
windows · process_creation
Processes Accessing the Microphone and Webcam
mediumPotential adversaries accessing the microphone and webcam in an endpoint.
windows · security
Program Executed Using Proxy/Local Command Via SSH.EXE
mediumDetect usage of the "ssh.exe" binary as a proxy to launch other programs.
windows · process_creation
Proxy Execution via Vshadow
mediumDetects the invocation of vshadow.exe with the -exec parameter that executes a specified script or command after the shadow copies are created but before the VShadow tool exits. VShadow is a command-line tool that you can use to create and manage volume shadow copies. While legitimate backup or administrative scripts may use this flag, attackers can leverage this parameter to proxy the execution of malware.
windows · process_creation
Psexec Execution
mediumDetects user accept agreement execution in psexec commandline
windows · process_creation
PsExec Service Execution
mediumDetects launch of the PSEXESVC service, which means that this system was the target of a psexec remote execution
windows · process_creation
PsExec Service Installation
mediumDetects PsExec service installation and execution events
windows · system
PsExec Tool Execution From Suspicious Locations - PipeName
mediumDetects PsExec default pipe creation where the image executed is located in a suspicious location. Which could indicate that the tool is being used in an attack
windows · pipe_created
PSScriptPolicyTest Creation By Uncommon Process
mediumDetects the creation of the "PSScriptPolicyTest" PowerShell script by an uncommon process. This file is usually generated by Microsoft Powershell to test against Applocker.
windows · file_event
PUA - AdFind.EXE Execution
mediumDetects execution of Adfind.exe utility, which can be used for reconnaissance in an Active Directory environment
windows · process_creation
PUA - Advanced IP Scanner Execution
mediumDetects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
windows · process_creation
PUA - Advanced Port Scanner Execution
mediumDetects the use of Advanced Port Scanner.
windows · process_creation
PUA - AdvancedRun Execution
mediumDetects the execution of AdvancedRun utility
windows · process_creation
PUA - CSExec Default Named Pipe
mediumDetects default CSExec pipe creation
windows · pipe_created
PUA - Mouse Lock Execution
mediumIn Kaspersky's 2020 Incident Response Analyst Report they listed legitimate tool "Mouse Lock" as being used for both credential access and collection in security incidents.
windows · process_creation
PUA - NimScan Execution
mediumDetects usage of NimScan, a portscanner utility. In early 2025, adversaries were observed using this utility to scan for open ports on remote hosts in a compromised environment. This rule identifies the execution of NimScan based on the process image name and specific hash values associated with different versions of the tool.
windows · process_creation
PUA - NirCmd Execution
mediumDetects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity
windows · process_creation
PUA - Nmap/Zenmap Execution
mediumDetects usage of namp/zenmap. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation
windows · process_creation
PUA - PAExec Default Named Pipe
mediumDetects PAExec default named pipe
windows · pipe_created
PUA - PingCastle Execution
mediumDetects the execution of PingCastle, a tool designed to quickly assess the Active Directory security level.
windows · process_creation
PUA - Potential PE Metadata Tamper Using Rcedit
mediumDetects the use of rcedit to potentially alter executable PE metadata properties, which could conceal efforts to rename system utilities for defense evasion.
windows · process_creation
PUA - Process Hacker Execution
mediumDetects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc). Process Hacker is a tool to view and manipulate processes, kernel options and other low level options. Threat actors abused older vulnerable versions to manipulate system processes.
windows · process_creation
PUA - Radmin Viewer Utility Execution
mediumDetects the execution of Radmin which can be abused by an adversary to remotely control Windows machines
windows · process_creation
PUA - RemCom Default Named Pipe
mediumDetects default RemCom pipe creation
windows · pipe_created
PUA - SoftPerfect Netscan Execution
mediumDetects usage of SoftPerfect's "netscan.exe". An application for scanning networks. It is actively used in-the-wild by threat actors to inspect and understand the network architecture of a victim.
windows · process_creation
PUA - Sysinternals Tools Execution - Registry
mediumDetects the execution of some potentially unwanted tools such as PsExec, Procdump, etc. (part of the Sysinternals suite) via the creation of the "accepteula" registry key.
windows · registry_set
PUA - System Informer Driver Load
mediumDetects driver load of the System Informer tool
windows · driver_load
PUA - System Informer Execution
mediumDetects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
windows · process_creation
PUA - TruffleHog Execution
mediumDetects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.
windows · process_creation
PUA - WebBrowserPassView Execution
mediumDetects the execution of WebBrowserPassView.exe. A password recovery tool that reveals the passwords stored by the following Web browsers, Internet Explorer (Version 4.0 - 11.0), Mozilla Firefox (All Versions), Google Chrome, Safari, and Opera
windows · process_creation
Publisher Attachment File Dropped In Suspicious Location
mediumDetects creation of files with the ".pub" extension in suspicious or uncommon locations. This could be a sign of attackers abusing Publisher documents
windows · file_event
Pubprn.vbs Proxy Execution
mediumDetects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.
windows · process_creation
Python Initiated Connection
mediumDetects a Python process initiating a network connection. While this often relates to package installation, it can also indicate a potential malicious script communicating with a C&C server.
windows · network_connection
Python Inline Command Execution
mediumDetects execution of python using the "-c" flag. This is could be used as a way to launch a reverse shell or execute live python code.
windows · process_creation
Python Path Configuration File Creation - Windows
mediumDetects creation of a Python path configuration file (.pth) in Python library folders, which can be maliciously abused for code execution and persistence. Modules referenced by these files are run at every Python startup (v3.5+), regardless of whether the module is imported by the calling script. Default paths are '\lib\site-packages\*.pth' (Windows) and '/lib/pythonX.Y/site-packages/*.pth' (Unix and macOS).
windows · file_event
Query Usage To Exfil Data
mediumDetects usage of "query.exe" a system binary to exfil information such as "sessions" and "processes" for later use
windows · process_creation
Rclone Config File Creation
mediumDetects Rclone config files being created
windows · file_event
RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
mediumDetects enabling or disabling of Remote Desktop Protocol (RDP) using alternate methods such as WMIC or PowerShell. In PowerShell one-liner commands, the "SetAllowTSConnections" method of the "Win32_TerminalServiceSetting" class may be used to enable or disable RDP. In WMIC, the "rdtoggle" alias or "Win32_TerminalServiceSetting" class may be used for the same purpose.
windows · process_creation
RDP Sensitive Settings Changed to Zero
mediumDetects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc.
windows · registry_set
Read Contents From Stdin Via Cmd.EXE
mediumDetect the use of "<" to read and potentially execute a file via cmd.exe
windows · process_creation
Rebuild Performance Counter Values Via Lodctr.EXE
mediumDetects the execution of "lodctr.exe" to rebuild the performance counter registry values. This can be abused by attackers by providing a malicious config file to overwrite performance counter configuration to confuse and evade monitoring and security solutions.
windows · process_creation
Recon Command Output Piped To Findstr.EXE
mediumDetects the execution of a potential recon command where the results are piped to "findstr". This is meant to trigger on inline calls of "cmd.exe" via the "/c" or "/k" for example. Attackers often time use this technique to extract specific information they require in their reconnaissance phase.
windows · process_creation
Recon Information for Export with Command Prompt
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
windows · process_creation
Recon Information for Export with PowerShell
mediumOnce established within a system or network, an adversary may use automated techniques for collecting internal data
windows · ps_script
RegAsm.EXE Initiating Network Connection To Public IP
mediumDetects "RegAsm.exe" initiating a network connection to public IP adresses
windows · network_connection
Register New IFiltre For Persistence
mediumDetects when an attacker registers a new IFilter for an extension. Microsoft Windows Search uses filters to extract the content of items for inclusion in a full-text index. You can extend Windows Search to index new or proprietary file types by writing filters to extract the content, and property handlers to extract the properties of files.
windows · registry_set
REGISTER_APP.VBS Proxy Execution
mediumDetects the use of a Microsoft signed script 'REGISTER_APP.VBS' to register a VSS/VDS Provider as a COM+ application.
windows · process_creation
Registry Enumeration via WMI Stdregprov
mediumDetects the usage of wmic.exe to enumerate or read Windows registry via the WMI StdRegProv class read methods (EnumKey, EnumValues, GetStringValue, etc.). While registry reads are common, attackers may use this technique to perform reconnaissance and discover sensitive configuration values, credentials, or installed software. The use of WMI as an alternative to standard tools like reg.exe can indicate an attempt to evade detection focused on traditional registry query commands.
windows · process_creation
Registry Explorer Policy Modification
mediumDetects registry modifications that disable internal tools or functions in explorer (malware like Agent Tesla uses this technique)
windows · registry_set
Registry Hide Function from User
mediumDetects registry modifications that hide internal tools or functions from the user (malware like Agent Tesla, Hermetic Wiper uses this technique)
windows · registry_set
Registry Manipulation via WMI Stdregprov
mediumDetects the usage of wmic.exe to modify Windows registry via the WMI StdRegProv class write methods (CreateKey, DeleteKey, SetStringValue, etc.). This behaviour could be potentially suspicious because it uses an alternative method to modify registry keys instead of legitimate registry tools like reg.exe or regedit.exe. Attackers specifically choose this technique to evade detection and bypass security monitoring focused on traditional registry modification commands.
windows · process_creation
Registry Modification Attempt Via VBScript
mediumDetects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods via common LOLBINs. It could be an attempt to modify the registry for persistence without using straightforward methods like regedit.exe, reg.exe, or PowerShell. Threat Actors may use this technique to evade detection by security solutions that monitor for direct registry modifications through traditional tools.
windows · process_creation
Registry Modification Attempt Via VBScript - PowerShell
mediumDetects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods embedded within PowerShell scripts or commands. Threat actors commonly embed VBScript code within PowerShell to perform registry modifications, attempting to evade detection that monitors for direct registry access through traditional tools. This technique can be used for persistence, defense evasion, and privilege escalation by modifying registry keys without using regedit.exe, reg.exe, or PowerShell's native registry cmdlets.
windows · ps_script
Registry Modification of MS-settings Protocol Handler
mediumDetects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence. Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.
windows · process_creation
Registry Modification to Hidden File Extension
mediumHides the file extension through modification of the registry
windows · registry_set
Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the setting of a registry inside the "\Shell\Open\Command" value with PowerShell classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows · registry_set
Registry Tampering by Potentially Suspicious Processes
mediumDetects suspicious registry modifications made by suspicious processes such as script engine processes such as WScript, or CScript etc. These processes are rarely used for legitimate registry modifications, and their activity may indicate an attempt to modify the registry without using standard tools like regedit.exe or reg.exe, potentially for evasion and persistence.
windows · registry_event
Registry-Free Process Scope COR_PROFILER
mediumAdversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR. The COR_PROFILER is a .NET Framework feature which allows developers to specify an unmanaged (or external of .NET) profiling DLL to be loaded into each .NET process that loads the Common Language Runtime (CLR). These profiliers are designed to monitor, troubleshoot, and debug managed code executed by the .NET CLR. (Citation: Microsoft Profiling Mar 2017) (Citation: Microsoft COR_PROFILER Feb 2013)
windows · ps_script
Regsvr32 DLL Execution With Uncommon Extension
mediumDetects a "regsvr32" execution where the DLL doesn't contain a common file extension.
windows · process_creation
Regsvr32 Execution From Potential Suspicious Location
mediumDetects execution of regsvr32 where the DLL is located in a potentially suspicious location.
windows · process_creation
Regsvr32.EXE Calling of DllRegisterServer Export Function Implicitly
mediumDetects execution of regsvr32 with the silent flag and no other flags on a DLL located in an uncommon or potentially suspicious location. When Regsvr32 is called in such a way, it implicitly calls the DLL export function 'DllRegisterServer'.
windows · process_creation
RemCom Service File Creation
mediumDetects default RemCom service filename which indicates RemCom service installation and execution
windows · file_event
RemCom Service Installation
mediumDetects RemCom service installation and execution events
windows · system
Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions
mediumDetects the execution of Action1 in order to execute arbitrary code or establish a remote session. Action1 is a powerful Remote Monitoring and Management tool that enables users to execute commands, scripts, and binaries. Through the web interface of action1, the administrator must create a new policy or an app to establish remote execution and then points that the agent is installed. Hunting Opportunity 1- Weed Out The Noise When threat actors execute a script, a command, or a binary through these new policies and apps, the names of these become visible in the command line during the execution process. Below is an example of the command line that contains the deployment of a binary through a policy with name "test_app_1": ParentCommandLine: "C:\WINDOWS\Action1\action1_agent.exe schedule:Deploy_App__test_app_1_1681327673425 runaction:0" After establishing a baseline, we can split the command to extract the policy name and group all the policy names and inspect the results with a list of frequency occurrences. Hunting Opportunity 2 - Remote Sessions On Out Of Office Hours If you have admins within your environment using remote sessions to administer endpoints, you can create a threat-hunting query and modify the time of the initiated sessions looking for abnormal activity.
windows · process_creation
Remote Access Tool - Ammy Admin Agent Execution
mediumDetects the execution of the Ammy Admin RMM agent for remote management.
windows · process_creation
Remote Access Tool - AnyDesk Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - AnyDesk Execution With Known Revoked Signing Certificate
mediumDetects the execution of an AnyDesk binary with a version prior to 8.0.8. Prior to version 8.0.8, the Anydesk application used a signing certificate that got compromised by threat actors. Use this rule to detect instances of older versions of Anydesk using the compromised certificate This is recommended in order to avoid attackers leveraging the certificate and signing their binaries to bypass detections.
windows · process_creation
Remote Access Tool - AnyDesk Incoming Connection
mediumDetects incoming connections to AnyDesk. This could indicate a potential remote attacker trying to connect to a listening instance of AnyDesk and use it as potential command and control channel.
windows · network_connection
Remote Access Tool - AnyDesk Piped Password Via CLI
mediumDetects piping the password to an anydesk instance via CMD and the '--set-password' flag.
windows · process_creation
Remote Access Tool - Cmd.EXE Execution via AnyViewer
mediumDetects execution of "cmd.exe" via the AnyViewer RMM agent on a remote management sessions.
windows · process_creation
Remote Access Tool - GoToAssist Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - LogMeIn Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - MeshAgent Command Execution via MeshCentral
mediumDetects the use of MeshAgent to execute commands on the target host, particularly when threat actors might abuse it to execute commands directly. MeshAgent can execute commands on the target host by leveraging win-console to obscure their activities and win-dispatcher to run malicious code through IPC with child processes.
windows · process_creation
Remote Access Tool - NetSupport Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - NetSupport Execution From Unusual Location
mediumDetects execution of client32.exe (NetSupport RAT) from an unusual location (outside of 'C:\Program Files')
windows · process_creation
Remote Access Tool - Potential MeshAgent Execution - Windows
mediumDetects potential execution of MeshAgent which is a tool used for remote access. Historical data shows that threat actors rename MeshAgent binary to evade detection. Matching command lines with the '--meshServiceName' argument can indicate that the MeshAgent is being used for remote access.
windows · process_creation
Remote Access Tool - RURAT Execution From Unusual Location
mediumDetects execution of Remote Utilities RAT (RURAT) from an unusual location (outside of 'C:\Program Files')
windows · process_creation
Remote Access Tool - ScreenConnect Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - ScreenConnect Installation Execution
mediumDetects ScreenConnect program starts that establish a remote access to a system.
windows · process_creation
Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
mediumDetects potentially suspicious child processes launched via the ScreenConnect client service.
windows · process_creation
Remote Access Tool - ScreenConnect Remote Command Execution - Hunting
mediumDetects remote binary or command execution via the ScreenConnect Service. Use this rule in order to hunt for potentially anomalous executions originating from ScreenConnect
windows · process_creation
Remote Access Tool - Simple Help Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
mediumDetects TacticalRMM agent installations where the --api, --auth, and related flags are used on the command line. These parameters configure the agent to connect to a specific RMM server with authentication, client ID, and site ID. This technique could indicate a threat actor attempting to register the agent with an attacker-controlled RMM infrastructure silently.
windows · process_creation
Remote Access Tool - UltraViewer Execution
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · process_creation
Remote Access Tool Services Have Been Installed - Security
mediumDetects service installation of different remote access tools software. These software are often abused by threat actors to perform
windows · security
Remote Access Tool Services Have Been Installed - System
mediumDetects service installation of different remote access tools software. These software are often abused by threat actors to perform
windows · system
Remote Code Execute via Winrm.vbs
mediumDetects an attempt to execute code or create service on remote host via winrm.vbs.
windows · process_creation
Remote DLL Load Via Rundll32.EXE
mediumDetects a remote DLL load event via "rundll32.exe".
windows · image_load
Remote File Download Via Desktopimgdownldr Utility
mediumDetects the desktopimgdownldr utility being used to download a remote file. An adversary may use desktopimgdownldr to download arbitrary files as an alternative to certutil.
windows · process_creation
Remote File Download Via Findstr.EXE
mediumDetects execution of "findstr" with specific flags and a remote share path. This specific set of CLI flags would allow "findstr" to download the content of the file located on the remote share as described in the LOLBAS entry.
windows · process_creation
Remote PowerShell Session Host Process (WinRM)
mediumDetects remote PowerShell sections by monitoring for wsmprovhost (WinRM host process) as a parent or child process (sign of an active PowerShell remote session).
windows · process_creation
Remote Registry Management Using Reg Utility
mediumRemote registry management using REG utility from non-admin workstation
windows · security
Remote Service Activity via SVCCTL Named Pipe
mediumDetects remote service activity via remote access to the svcctl named pipe
windows · security
Remote Task Creation via ATSVC Named Pipe
mediumDetects remote task creation via at.exe or API interacting with ATSVC namedpipe
windows · security
Remote Thread Created In Shell Application
mediumDetects remote thread creation in command shell applications, such as "Cmd.EXE" and "PowerShell.EXE". It is a common technique used by malware, such as IcedID, to inject malicious code and execute it within legitimate processes.
windows · create_remote_thread
Remote Thread Creation By Uncommon Source Image
mediumDetects uncommon processes creating remote threads.
windows · create_remote_thread
Remote Thread Creation In Uncommon Target Image
mediumDetects uncommon target processes for remote thread creation
windows · create_remote_thread
Remote Thread Creation Via PowerShell
mediumDetects the creation of a remote thread from a Powershell process to another process
windows · create_remote_thread
Remote Thread Creation Via PowerShell In Uncommon Target
mediumDetects the creation of a remote thread from a Powershell process in an uncommon target process
windows · create_remote_thread
Remote Utilities Host Service Install
mediumDetects Remote Utilities Host service installation on the target system.
windows · system
Removal Of Index Value to Hide Schedule Task - Registry
mediumDetects when the "index" value of a scheduled task is removed or deleted from the registry. Which effectively hides it from any tooling such as "schtasks /query"
windows · registry_delete
Removal of Potential COM Hijacking Registry Keys
mediumDetects any deletion of entries in ".*\shell\open\command" registry keys. These registry keys might have been used for COM hijacking activities by a threat actor or an attacker and the deletion could indicate steps to remove its tracks.
windows · registry_delete
Removal Of SD Value to Hide Schedule Task - Registry
mediumRemove SD (Security Descriptor) value in \Schedule\TaskCache\Tree registry hive to hide schedule task. This technique is used by Tarrask malware
windows · registry_delete
Remove Account From Domain Admin Group
mediumAdversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts.
windows · ps_script
Renamed AutoHotkey.EXE Execution
mediumDetects execution of a renamed autohotkey.exe binary based on PE metadata fields
windows · process_creation
Renamed BOINC Client Execution
mediumDetects the execution of a renamed BOINC binary.
windows · process_creation
Renamed CURL.EXE Execution
mediumDetects the execution of a renamed "CURL.exe" binary based on the PE metadata fields
windows · process_creation
Renamed FTP.EXE Execution
mediumDetects the execution of a renamed "ftp.exe" binary based on the PE metadata fields
windows · process_creation
Renamed Microsoft Teams Execution
mediumDetects the execution of a renamed Microsoft Teams binary.
windows · process_creation
Renamed Remote Utilities RAT (RURAT) Execution
mediumDetects execution of renamed Remote Utilities (RURAT) via Product PE header field
windows · process_creation
Replace.exe Usage
mediumDetects the use of Replace.exe which can be used to replace file with another file
windows · process_creation
Response File Execution Via Odbcconf.EXE
mediumDetects execution of "odbcconf" with the "-f" flag in order to load a response file which might contain a malicious action.
windows · process_creation
Rhadamanthys Stealer Module Launch Via Rundll32.EXE
mediumDetects the use of Rundll32 to launch an NSIS module that serves as the main stealer capability of Rhadamanthys infostealer, as observed in reports and samples in early 2023
windows · process_creation
Root Certificate Installed - PowerShell
mediumAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
windows · ps_script
Ruby Inline Command Execution
mediumDetects execution of ruby using the "-e" flag. This is could be used as a way to launch a reverse shell or execute live ruby code.
windows · process_creation
Run Once Task Configuration in Registry
mediumRule to detect the configuration of Run Once registry key. Configured payload can be run by runonce.exe /AlternateShellStartup
windows · registry_event
Rundll32 Execution With Uncommon DLL Extension
mediumDetects the execution of rundll32 with a command line that doesn't contain a common extension
windows · process_creation
Rundll32 InstallScreenSaver Execution
mediumAn attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver
windows · process_creation
Rundll32 Internet Connection
mediumDetects a rundll32 that communicates with public IP addresses
windows · network_connection
Rundll32 Spawned Via Explorer.EXE
mediumDetects execution of "rundll32.exe" with a parent process of Explorer.exe. This has been observed by variants of Raspberry Robin, as first reported by Red Canary.
windows · process_creation
Rundll32.EXE Calling DllRegisterServer Export Function Explicitly
mediumDetects when the DLL export function 'DllRegisterServer' is called in the commandline by Rundll32 explicitly where the DLL is located in a non-standard path.
windows · process_creation
Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE
mediumDetects Schtask creations that point to a suspicious folder or an environment variable often used by malware
windows · process_creation
Scheduled Task Creation From Potential Suspicious Parent Location
mediumDetects the execution of "schtasks.exe" from a parent that is located in a potentially suspicious location. Multiple malware strains were seen exhibiting a similar behavior in order to achieve persistence.
windows · process_creation
Scheduled Task Creation with Curl and PowerShell Execution Combo
mediumDetects the creation of a scheduled task using schtasks.exe, potentially in combination with curl for downloading payloads and PowerShell for executing them. This facilitates executing malicious payloads or connecting with C&C server persistently without dropping the malware sample on the host.
windows · process_creation
Scheduled Task Executed From A Suspicious Location
mediumDetects the execution of Scheduled Tasks where the Program being run is located in a suspicious location or it's an unusale program to be run from a Scheduled Task
windows · taskscheduler
Scheduled Task Executed Uncommon LOLBIN
mediumDetects the execution of Scheduled Tasks where the program being run is located in a suspicious location or where it is an unusual program to be run from a Scheduled Task
windows · taskscheduler
Scheduled Task Executing Payload from Registry
mediumDetects the creation of a schtasks that potentially executes a payload stored in the Windows Registry using PowerShell.
windows · process_creation
SCM Database Handle Failure
mediumDetects non-system users failing to get a handle of the SCM database.
windows · security
SCM Database Privileged Operation
mediumDetects non-system users performing privileged operation os the SCM database
windows · security
SCR File Write Event
mediumDetects the creation of screensaver files (.scr) outside of system folders. Attackers may execute an application as an ".SCR" file using "rundll32.exe desk.cpl,InstallScreenSaver" for example.
windows · file_event
Screen Capture Activity Via Psr.EXE
mediumDetects execution of Windows Problem Steps Recorder (psr.exe), a utility used to record the user screen and clicks.
windows · process_creation
ScreenConnect Temporary Installation Artefact
mediumAn adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)
windows · file_event
ScreenConnect User Database Modification
mediumDetects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions.
windows · file_event
ScreenConnect User Database Modification - Security
mediumThis detects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory.
windows · security
ScreenSaver Registry Key Set
mediumDetects registry key established after masqueraded .scr file execution using Rundll32 through desk.cpl
windows · registry_set
Scripted Diagnostics Turn Off Check Enabled - Registry
mediumDetects enabling TurnOffCheck which can be used to bypass defense of MSDT Follina vulnerability
windows · registry_set
Scripting/CommandLine Process Spawned Regsvr32
mediumDetects various command line and scripting engines/processes such as "PowerShell", "Wscript", "Cmd", etc. spawning a "regsvr32" instance.
windows · process_creation
Sdclt Child Processes
mediumA General detection for sdclt spawning new processes. This could be an indicator of sdclt being used for bypass UAC techniques.
windows · process_creation
Security Software Discovery Via Powershell Script
mediumDetects calls to "get-process" where the output is piped to a "where-object" filter to search for security solution processes. Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment. This may include things such as firewall rules and anti-virus
windows · ps_script
Security Tools Keyword Lookup Via Findstr.EXE
mediumDetects execution of "findstr" to search for common names of security tools. Attackers often pipe the results of recon commands such as "tasklist" or "whoami" to "findstr" in order to filter out the results. This detection focuses on the keywords that the attacker might use as a filter.
windows · process_creation
Self Extraction Directive File Created In Potentially Suspicious Location
mediumDetects the creation of Self Extraction Directive files (.sed) in a potentially suspicious location. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries.
windows · file_event
Service Binary in User Controlled Folder
mediumDetects the setting of the "ImagePath" value of a service registry key to a path controlled by a non-administrator user such as "\AppData\" or "\ProgramData\". Attackers often use such directories for staging purposes. This rule might also trigger on badly written software, where if an attacker controls an auto starting service, they might achieve persistence or privilege escalation. Note that while ProgramData is a user controlled folder, software might apply strict ACLs which makes them only accessible to admin users. Remove such folders via filters if you experience a lot of noise.
windows · registry_set
Service Installation in Suspicious Folder
mediumDetects service installation in suspicious folder appdata
windows · system
Service Reconnaissance Via Wmic.EXE
mediumAn adversary might use WMI to check if a certain remote service is running on a remote device. When the test completes, a service information will be displayed on the screen if it exists. A common feedback message is that "No instance(s) Available" if the service queried is not running. A common error message is "Node - (provided IP or default) ERROR Description =The RPC server is unavailable" if the provided remote host is unreachable
windows · process_creation
Service Registry Permissions Weakness Check
mediumAdversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
windows · ps_script
Service Security Descriptor Tampering Via Sc.EXE
mediumDetection of sc.exe utility adding a new service with special permission which hides that service.
windows · process_creation
Service Started/Stopped Via Wmic.EXE
mediumDetects usage of wmic to start or stop a service
windows · process_creation
Service Startup Type Change Via Wmic.EXE
mediumDetects changes to service startup type to 'disabled' or 'manual' using the WMIC command-line utility.
windows · process_creation
Service StartupType Change Via PowerShell Set-Service
mediumDetects the use of the PowerShell "Set-Service" cmdlet to change the startup type of a service to "disabled" or "manual"
windows · process_creation
Service StartupType Change Via Sc.EXE
mediumDetect the use of "sc.exe" to change the startup type of a service to "disabled" or "demand"
windows · process_creation
ServiceDll Hijack
mediumDetects changes to the "ServiceDLL" value related to a service in the registry. This is often used as a method of persistence.
windows · registry_set
Session Manager Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Setup16.EXE Execution With Custom .Lst File
mediumDetects the execution of "Setup16.EXE" and old installation utility with a custom ".lst" file. These ".lst" file can contain references to external program that "Setup16.EXE" will execute. Attackers and adversaries might leverage this as a living of the land utility.
windows · process_creation
Shadow Copies Creation Using Operating Systems Utilities
mediumShadow Copies creation using operating systems utilities, possible credential access
windows · process_creation
Shell Process Spawned by Java.EXE
mediumDetects shell spawned from Java host process, which could be a sign of exploitation (e.g. log4j exploitation)
windows · process_creation
SMB over QUIC Via Net.EXE
mediumDetects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments.
windows · process_creation
SMB over QUIC Via PowerShell Script
mediumDetects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments
windows · ps_script
SQL Client Tools PowerShell Session Detection
mediumThis rule detects execution of a PowerShell code through the sqltoolsps.exe utility, which is included in the standard set of utilities supplied with the Microsoft SQL Server Management studio. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.
windows · process_creation
Standard User In High Privileged Group
mediumDetect standard users login that are part of high privileged groups such as the Administrator group
windows · lsa-server
Start of NT Virtual DOS Machine
mediumNtvdm.exe allows the execution of 16-bit Windows applications on 32-bit Windows operating systems, as well as the execution of both 16-bit and 32-bit DOS applications
windows · process_creation
Startup Folder File Write
mediumA General detection for files being created in the Windows startup directory. This could be an indicator of persistence.
windows · file_event
Startup/Logon Script Added to Group Policy Object
mediumDetects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.
windows · security
Suspicious Access to Sensitive File Extensions
mediumDetects known sensitive file extensions accessed on a network share
windows · security
Suspicious Appended Extension
mediumDetects file renames where the target filename uses an uncommon double extension. Could indicate potential ransomware activity renaming files and adding a custom extension to the encrypted files, such as ".jpg.crypted", ".docx.locky", etc.
windows · file_rename
Suspicious Application Installed
mediumDetects suspicious application installed by looking at the added shortcut to the app resolver cache
windows · shell-core
Suspicious Cabinet File Execution Via Msdt.EXE
mediumDetects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190
windows · process_creation
Suspicious Child Process of SAP NetWeaver
mediumDetects suspicious child processes spawned by SAP NetWeaver that could indicate potential exploitation of vulnerability that allows arbitrary execution via webshells such as CVE-2025-31324.
windows · process_creation
Suspicious CodePage Switch Via CHCP
mediumDetects a code page switch in command line or batch scripts to a rare language
windows · process_creation
Suspicious Computer Machine Password by PowerShell
mediumThe Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain. You can use it to reset the password of the local computer.
windows · ps_module
Suspicious Copy From or To System Directory
mediumDetects a suspicious copy operation that tries to copy a program from system (System32, SysWOW64, WinSxS) directories to another on disk. Often used to move LOLBINs such as 'certutil' or 'desktopimgdownldr' to a different location with a different name in order to bypass detections based on locations.
windows · process_creation
Suspicious Creation of .library-ms File — Potential CVE-2025-24054 Exploit
mediumDetects creation of '.library-ms' files, which may indicate exploitation of CVE-2025-24054. This vulnerability allows an attacker to trigger an automatic outbound SMB or WebDAV authentication request to a remote server upon archive extraction. If the system is unpatched, no user interaction is required beyond extracting a malicious archive—potentially exposing the user's NTLMv2-SSP hash to the attacker.
windows · file_event
Suspicious Creation TXT File in User Desktop
mediumDetects creation of .txt files in user desktop folders via cmd.exe. This behavior may indicate ransomware deploying ransom notes, but can also occur during legitimate administrative tasks. Analysts should investigate for suspicious filenames (e.g., "RANSOM", "DECRYPT", "READ_ME"), bulk file creation patterns, or concurrent encryption activity to determine if this is part of a ransomware attack.
windows · file_event
Suspicious Cross-User Process Spawn
mediumDetects suspicious spawning of a process under a different user context than the parent process. Processes such as notepad.exe, calculator etc. are generally spawned under the same user context and also they are often targeted as sacrificial process or decoy process to check successful privilege escalation.
windows · process_creation
Suspicious CrushFTP Child Process
mediumDetects suspicious child processes spawned by the CrushFTP service that may indicate exploitation of remote code execution vulnerabilities such as CVE-2025-31161, where attackers can achieve RCE through crafted HTTP requests. The detection focuses on commonly abused Windows executables (like powershell.exe, cmd.exe etc.) that attackers typically use post-exploitation to execute malicious commands.
windows · process_creation
Suspicious Csi.exe Usage
mediumCsi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'
windows · process_creation
Suspicious Diantz Alternate Data Stream Execution
mediumCompress target file into a cab file stored in the Alternate Data Stream (ADS) of the target file.
windows · process_creation
Suspicious Diantz Download and Compress Into a CAB File
mediumDownload and compress a remote file and store it in a cab file on local machine.
windows · process_creation
Suspicious Digital Signature Of AppX Package
mediumDetects execution of AppX packages with known suspicious or malicious signature
windows · appxpackaging-om
Suspicious DNS Query for IP Lookup Service APIs
mediumDetects DNS queries for IP lookup services such as "api.ipify.org" originating from a non browser process.
windows · dns_query
Suspicious Download Via Certutil.EXE
mediumDetects the execution of certutil with certain flags that allow the utility to download files.
windows · process_creation
Suspicious Driver Install by pnputil.exe
mediumDetects when a possible suspicious driver is being installed via pnputil.exe lolbin
windows · process_creation
Suspicious Electron Application Child Processes
mediumDetects suspicious child processes of electron apps (teams, discord, slack, etc.). This could be a potential sign of ".asar" file tampering (See reference section for more information) or binary execution proxy through specific CLI arguments (see related rule)
windows · process_creation
Suspicious Eventlog Clear
mediumDetects usage of known powershell cmdlets such as "Clear-EventLog" to clear the Windows event logs
windows · ps_script
Suspicious Execution of InstallUtil Without Log
mediumUses the .NET InstallUtil.exe application in order to execute image without log
windows · process_creation
Suspicious Execution of Powershell with Base64
mediumCommandline to launch powershell with a base64 payload
windows · process_creation
Suspicious Execution of Shutdown
mediumUse of the commandline to shutdown or reboot windows
windows · process_creation
Suspicious Execution of Shutdown to Log Out
mediumDetects the rare use of the command line tool shutdown to logoff a user
windows · process_creation
Suspicious Extrac32 Alternate Data Stream Execution
mediumExtract data from cab file and hide it in an alternate data stream
windows · process_creation
Suspicious Extrac32 Execution
mediumDownload or Copy file with Extrac32
windows · process_creation
Suspicious File Characteristics Due to Missing Fields
mediumDetects Executables in the Downloads folder without FileVersion,Description,Product,Company likely created with py2exe
windows · process_creation
Suspicious File Created In PerfLogs
mediumDetects suspicious file based on their extension being created in "C:\PerfLogs\". Note that this directory mostly contains ".etl" files
windows · file_event
Suspicious File Drop by Exchange
mediumDetects suspicious file type dropped by an Exchange component in IIS
windows · file_event
Suspicious File Write to Webapps Root Directory
mediumDetects suspicious file writes to the root directory of web applications, particularly Apache web servers or Tomcat servers. This may indicate an attempt to deploy malicious files such as web shells or other unauthorized scripts.
windows · file_event
Suspicious Files in Default GPO Folder
mediumDetects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder
windows · file_event
Suspicious FromBase64String Usage On Gzip Archive - Process Creation
mediumDetects attempts of decoding a base64 Gzip archive via PowerShell. This technique is often used as a method to load malicious content into memory afterward.
windows · process_creation
Suspicious FromBase64String Usage On Gzip Archive - Ps Script
mediumDetects attempts of decoding a base64 Gzip archive in a PowerShell script. This technique is often used as a method to load malicious content into memory afterward.
windows · ps_script
Suspicious Get-ADReplAccount
mediumThe DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory. These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
windows · ps_script
Suspicious GetTypeFromCLSID ShellExecute
mediumDetects suspicious Powershell code that execute COM Objects
windows · ps_script
Suspicious Git Clone
mediumDetects execution of "git" in order to clone a remote repository that contain suspicious keywords which might be suspicious
windows · process_creation
Suspicious Group And Account Reconnaissance Activity Using Net.EXE
mediumDetects suspicious reconnaissance command line activity on Windows systems using Net.EXE Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)
windows · process_creation
Suspicious Hyper-V Cmdlets
mediumAdversaries may carry out malicious operations using a virtual instance to avoid detection
windows · ps_script
Suspicious IIS URL GlobalRules Rewrite Via AppCmd
mediumDetects usage of "appcmd" to create new global URL rewrite rules. This behaviour has been observed being used by threat actors to add new rules so they can access their webshells.
windows · process_creation
Suspicious Invoke-Item From Mount-DiskImage
mediumAdversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
windows · ps_script
Suspicious Invoke-WebRequest Execution With DirectIP
mediumDetects calls to PowerShell with Invoke-WebRequest cmdlet using direct IP access
windows · process_creation
Suspicious IO.FileStream
mediumOpen a handle on the drive volume via the \\.\ DOS device path specifier and perform direct access read of the first few bytes of the volume.
windows · ps_script
Suspicious Kerberos RC4 Ticket Encryption
mediumDetects service ticket requests using RC4 encryption type
windows · security
Suspicious Keyboard Layout Load
mediumDetects the keyboard preload installation with a suspicious keyboard layout, e.g. Chinese, Iranian or Vietnamese layout load in user session on systems maintained by US staff only
windows · registry_set
Suspicious LNK Double Extension File Created
mediumDetects the creation of files with an "LNK" as a second extension. This is sometimes used by malware as a method to abuse the fact that Windows hides the "LNK" extension by default.
windows · file_event
Suspicious Machine Account Replication - DcSync Indicator
mediumDetects suspicious Active Directory Replication Service (ADRS) requests originating from a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller. Under normal operation, only Domain Controllers initiate replication requests carrying the DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account credentials — for example by abusing certificate-based authentication (PKINIT) to impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost), where a temporary machine account is created to request a DC certificate and then used to perform DCSync — they can dump all domain credential material including the krbtgt hash.
windows · security
Suspicious Msbuild Execution By Uncommon Parent Process
mediumDetects suspicious execution of 'Msbuild.exe' by a uncommon parent process
windows · process_creation
Suspicious MsiExec Embedding Parent
mediumAdversaries may abuse msiexec.exe to proxy the execution of malicious payloads
windows · process_creation
Suspicious Msiexec Execute Arbitrary DLL
mediumAdversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)
windows · process_creation
Suspicious Msiexec Quiet Install From Remote Location
mediumDetects usage of Msiexec.exe to install packages hosted remotely quietly
windows · process_creation
Suspicious Network Connection to IP Lookup Service APIs
mediumDetects external IP address lookups by non-browser processes via services such as "api.ipify.org". This could be indicative of potential post compromise internet test activity.
windows · network_connection
Suspicious New Instance Of An Office COM Object
mediumDetects an svchost process spawning an instance of an office application. This happens when the initial word application creates an instance of one of the Office COM objects such as 'Word.Application', 'Excel.Application', etc. This can be used by malicious actors to create malicious Office documents with macros on the fly. (See vba2clr project in the references)
windows · process_creation
Suspicious New-PSDrive to Admin Share
mediumAdversaries may use to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the logged-on user.
windows · ps_script
Suspicious Non PowerShell WSMAN COM Provider
mediumDetects suspicious use of the WSMAN provider without PowerShell.exe as the host application.
windows · powershell-classic
Suspicious Non-Browser Network Communication With Google API
mediumDetects a non-browser process interacting with the Google API which could indicate the use of a covert C2 such as Google Sheet C2 (GC2-sheet)
windows · network_connection
Suspicious Non-Browser Network Communication With Telegram API
mediumDetects an a non-browser process interacting with the Telegram API which could indicate use of a covert C2
windows · network_connection
Suspicious Outbound SMTP Connections
mediumAdversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel. The data may also be sent to an alternate network location from the main command and control server.
windows · network_connection
Suspicious Powercfg Execution To Change Lock Screen Timeout
mediumDetects suspicious execution of 'Powercfg.exe' to change lock screen timeout
windows · process_creation
Suspicious PowerShell Download - PoshModule
mediumDetects suspicious PowerShell download command
windows · ps_module
Suspicious PowerShell Download - Powershell Script
mediumDetects suspicious PowerShell download command
windows · ps_script
Suspicious PowerShell In Registry Run Keys
mediumDetects potential PowerShell commands or code within registry run keys
windows · registry_set
Suspicious PowerShell Invocation From Script Engines
mediumDetects suspicious powershell invocations from interpreters or unusual programs
windows · process_creation
Suspicious PowerShell Invocations - Specific - ProcessCreation
mediumDetects suspicious PowerShell invocation command parameters
windows · process_creation
Suspicious PowerShell WindowStyle Option
mediumAdversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden
windows · ps_script
Suspicious Process Start Locations
mediumDetects suspicious process run from unusual locations
windows · process_creation
Suspicious PROCEXP152.sys File Created In TMP
mediumDetects the creation of the PROCEXP152.sys file in the application-data local temporary folder. This driver is used by Sysinternals Process Explorer but also by KDU (https://github.com/hfiref0x/KDU) or Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU.
windows · file_event
Suspicious RASdial Activity
mediumDetects suspicious process related to rasdial.exe
windows · process_creation
Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet
mediumDetects suspicious reconnaissance command line activity on Windows systems using the PowerShell Get-LocalGroupMember Cmdlet
windows · process_creation
Suspicious Recursive Takeown
mediumAdversaries can interact with the DACLs using built-in Windows commands takeown which can grant adversaries higher permissions on specific files and folders
windows · process_creation
Suspicious Rejected SMB Guest Logon From IP
mediumDetect Attempt PrintNightmare (CVE-2021-1675) Remote code execution in Windows Spooler Service
windows · smbclient-security
Suspicious Remote Logon with Explicit Credentials
mediumDetects suspicious processes logging on with explicit credentials
windows · security
Suspicious RunAs-Like Flag Combination
mediumDetects suspicious command line flags that let the user set a target user and command as e.g. seen in PsExec-like tools
windows · process_creation
Suspicious Rundll32 Setupapi.dll Activity
mediumsetupapi.dll library provide InstallHinfSection function for processing INF files. INF file may contain instructions allowing to create values in the registry, modify files and install drivers. This technique could be used to obtain persistence via modifying one of Run or RunOnce registry keys, run process or use other DLLs chain calls (see references) InstallHinfSection function in setupapi.dll calls runonce.exe executable regardless of actual content of INF file.
windows · process_creation
Suspicious Runscripthelper.exe
mediumDetects execution of powershell scripts via Runscripthelper.exe
windows · process_creation
Suspicious Scan Loop Network
mediumAdversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system
windows · process_creation
Suspicious Scheduled Task Creation via Masqueraded XML File
mediumDetects the creation of a scheduled task using the "-XML" flag with a file without the '.xml' extension. This behavior could be indicative of potential defense evasion attempt during persistence
windows · process_creation
Suspicious Scheduled Task Name As GUID
mediumDetects creation of a scheduled task with a GUID like name
windows · process_creation
Suspicious Schtasks Schedule Type With High Privileges
mediumDetects scheduled task creations or modification to be run with high privileges on a suspicious schedule type
windows · process_creation
Suspicious ScreenSave Change by Reg.exe
mediumAdversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension
windows · process_creation
Suspicious Screensaver Binary File Creation
mediumAdversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension
windows · file_event
Suspicious Service Installed
mediumDetects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders. Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)
windows · registry_set
Suspicious Set Value of MSDT in Registry (CVE-2022-30190)
mediumDetects set value ms-msdt MSProtocol URI scheme in Registry that could be an attempt to exploit CVE-2022-30190.
windows · registry_set
Suspicious Shell Open Command Registry Modification
mediumDetects modifications to shell open registry keys that point to suspicious locations typically used by malware for persistence. Generally, modifications to the `*\shell\open\command` registry key can indicate an attempt to change the default action for opening files, and various UAC bypass or persistence techniques involve modifying these keys to execute malicious scripts or binaries.
windows · registry_set
Suspicious Start-Process PassThru
mediumPowershell use PassThru option to start in background
windows · ps_script
Suspicious SysAidServer Child
mediumDetects suspicious child processes of SysAidServer (as seen in MERCURY threat actor intrusions)
windows · process_creation
Suspicious SYSVOL Domain Group Policy Access
mediumDetects Access to Domain Group Policies stored in SYSVOL
windows · process_creation
Suspicious TCP Tunnel Via PowerShell Script
mediumDetects powershell scripts that creates sockets/listeners which could be indicative of tunneling activity
windows · ps_script
Suspicious Unblock-File
mediumRemove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.
windows · ps_script
Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)
mediumDetects execution of ntdsutil.exe to perform different actions such as restoring snapshots...etc.
windows · process_creation
Suspicious Usage of For Loop with Recursive Directory Search in CMD
mediumDetects suspicious usage of the cmd.exe 'for /f' loop combined with the 'tokens=' parameter and a recursive directory listing. This pattern may indicate an attempt to discover and execute system binaries dynamically, for example powershell, a technique sometimes used by attackers to evade detection. This behavior has been observed in various malicious lnk files.
windows · process_creation
Suspicious Use of PsLogList
mediumDetects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
windows · process_creation
Suspicious Userinit Child Process
mediumDetects a suspicious child process of userinit
windows · process_creation
Suspicious VBoxDrvInst.exe Parameters
mediumDetect VBoxDrvInst.exe run with parameters allowing processing INF file. This allows to create values in the registry and install drivers. For example one could use this technique to obtain persistence via modifying one of Run or RunOnce registry keys
windows · process_creation
Suspicious Vsls-Agent Command With AgentExtensionPath Load
mediumDetects Microsoft Visual Studio vsls-agent.exe lolbin execution with a suspicious library load using the --agentExtensionPath parameter
windows · process_creation
Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
mediumDetects the usage of "reg.exe" to add Defender folder exclusions. Qbot has been seen using this technique to add exclusions for folders within AppData and ProgramData.
windows · process_creation
Suspicious WindowsTerminal Child Processes
mediumDetects suspicious children spawned via the Windows Terminal application which could be a sign of persistence via WindowsTerminal (see references section)
windows · process_creation
Suspicious Wordpad Outbound Connections
mediumDetects a network connection initiated by "wordpad.exe" over uncommon destination ports. This might indicate potential process injection activity from a beacon or similar mechanisms.
windows · network_connection
Suspicious Workstation Locking via Rundll32
mediumDetects a suspicious call to the user32.dll function that locks the user workstation
windows · process_creation
Suspicious WSMAN Provider Image Loads
mediumDetects signs of potential use of the WSMAN provider from uncommon processes locally and remote execution.
windows · image_load
Suspicious X509Enrollment - Process Creation
mediumDetect use of X509Enrollment
windows · process_creation
Suspicious X509Enrollment - Ps Script
mediumDetect use of X509Enrollment
windows · ps_script
Suspicious XOR Encoded PowerShell Command
mediumDetects presence of a potentially xor encoded powershell command
windows · process_creation
Suspicious ZipExec Execution
mediumZipExec is a Proof-of-Concept (POC) tool to wrap binary-based tools into a password-protected zip file.
windows · process_creation
SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
mediumDetects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.
windows · ps_module
SyncAppvPublishingServer Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.exe.
windows · process_creation
SyncAppvPublishingServer Execution to Bypass Powershell Restriction
mediumDetects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.
windows · ps_script
SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
mediumExecutes arbitrary PowerShell code using SyncAppvPublishingServer.vbs
windows · process_creation
Sysinternals PsService Execution
mediumDetects usage of Sysinternals PsService which can be abused for service reconnaissance and tampering
windows · process_creation
Sysinternals PsSuspend Execution
mediumDetects usage of Sysinternals PsSuspend which can be abused to suspend critical processes
windows · process_creation
Sysmon Configuration Change
mediumDetects a Sysmon configuration change, which could be the result of a legitimate reconfiguration or someone trying manipulate the configuration
windows · sysmon
Sysmon Configuration Update
mediumDetects updates to Sysmon's configuration. Attackers might update or replace the Sysmon configuration with a bare bone one to avoid monitoring without shutting down the service completely
windows · process_creation
Sysmon File Executable Creation Detected
mediumTriggers on any Sysmon "FileExecutableDetected" event, which triggers every time a PE that is monitored by the config is created.
windows · sysmon
Sysprep on AppData Folder
mediumDetects suspicious sysprep process start with AppData folder as target (as used by Trojan Syndicasec in Thrip report by Symantec)
windows · process_creation
System Disk And Volume Reconnaissance Via Wmic.EXE
mediumAn adversary might use WMI to discover information about the system, such as the volume name, size, free space, and other disk information. This can be done using the 'wmic' command-line utility and has been observed being used by threat actors such as Volt Typhoon.
windows · process_creation
System Language Discovery via Reg.Exe
mediumDetects the usage of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.
windows · process_creation
System Scripts Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
TacticalRMM Service Installation
mediumDetects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.
windows · system
TanStack Supply-Chain Attack DNS Indicators
mediumDetects DNS queries to attacker-controlled infrastructure used by the Mini Shai-Hulud campaign targeting TanStack npm packages along with other packages such as mistralai, uipath and so on. The domain git-tanstack.com (registered May 9, 2026) hosted secondary payloads including transformers.pyz. The filev2.getsession.org endpoint was used for credential exfiltration via the Session protocol.
windows · dns_query
TanStack Supply-Chain Attack File Creation Indicators - Windows
mediumDetects file creation indicators associated with the Mini Shai-Hulud supply-chain campaign targeting TanStack npm packages and others such as mistralai, uipath, etc reported on early May 2026.
windows · file_event
Tap Driver Installation
mediumWell-known TAP software installation. Possible preparation for data exfiltration using tunnelling techniques
windows · system
Tap Installer Execution
mediumWell-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques
windows · process_creation
TeamViewer Domain Query By Non-TeamViewer Application
mediumDetects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)
windows · dns_query
TeamViewer Remote Session
mediumDetects the creation of log files during a TeamViewer remote session
windows · file_event
Testing Usage of Uncommonly Used Port
mediumAdversaries may communicate using a protocol and port paring that are typically not associated. For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443.
windows · ps_script
Third Party Software DLL Sideloading
mediumDetects DLL sideloading of DLLs that are part of third party software (zoom, discord....etc)
windows · image_load
Tomcat WebServer Logs Deleted
mediumDetects the deletion of tomcat WebServer logs which may indicate an attempt to destroy forensic evidence
windows · file_delete
Transferring Files with Credential Data via Network Shares
mediumTransferring files with well-known filenames (sensitive files with credential data) using network shares
windows · security
Troubleshooting Pack Cmdlet Execution
mediumDetects execution of "TroubleshootingPack" cmdlets to leverage CVE-2022-30190 or action similar to "msdt" lolbin (as described in LOLBAS)
windows · ps_script
Tunneling Tool Execution
mediumDetects the execution of well known tools that can be abused for data exfiltration and tunneling.
windows · process_creation
UAC Bypass via Windows Firewall Snap-In Hijack
mediumDetects attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in
windows · process_creation
UAC Disabled
mediumDetects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.
windows · registry_set
UAC Notification Disabled
mediumDetects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value. UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users. When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
windows · registry_set
UAC Secure Desktop Prompt Disabled
mediumDetects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value. The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts. When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.
windows · registry_set
Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
mediumDetects the start of a non built-in assistive technology applications via "Atbroker.EXE".
windows · process_creation
Uncommon AddinUtil.EXE CommandLine Execution
mediumDetects execution of the Add-In deployment cache updating utility (AddInutil.exe) with uncommon Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.
windows · process_creation
Uncommon Child Process Of AddinUtil.EXE
mediumDetects uncommon child processes of the Add-In deployment cache updating utility (AddInutil.exe) which could be a sign of potential abuse of the binary to proxy execution via a custom Addins.Store payload.
windows · process_creation
Uncommon Child Process Of Appvlp.EXE
mediumDetects uncommon child processes of Appvlp.EXE Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands. Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder or to mark a file as a system file.
windows · process_creation
Uncommon Child Process Of BgInfo.EXE
mediumDetects uncommon child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript
windows · process_creation
Uncommon Child Process Of Conhost.EXE
mediumDetects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.
windows · process_creation
Uncommon Child Process Of Defaultpack.EXE
mediumDetects uncommon child processes of "DefaultPack.EXE" binary as a proxy to launch other programs
windows · process_creation
Uncommon Child Process Spawned By Odbcconf.EXE
mediumDetects an uncommon child process of "odbcconf.exe" binary which normally shouldn't have any child processes.
windows · process_creation
Uncommon Child Processes Of SndVol.exe
mediumDetects potentially uncommon child processes of SndVol.exe (the Windows volume mixer)
windows · process_creation
Uncommon Connection to Active Directory Web Services
mediumDetects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.
windows · network_connection
Uncommon Extension Shim Database Installation Via Sdbinst.EXE
mediumDetects installation of a potentially suspicious new shim with an uncommon extension using sdbinst.exe. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims
windows · process_creation
Uncommon GrantedAccess Flags On LSASS
mediumDetects process access to LSASS memory with uncommon access flags 0x410 and 0x01410
windows · process_access
Uncommon Link.EXE Parent Process
mediumDetects an uncommon parent process of "LINK.EXE". Link.EXE in Microsoft incremental linker. Its a utility usually bundled with Visual Studio installation. Multiple utilities often found in the same folder (editbin.exe, dumpbin.exe, lib.exe, etc) have a hardcode call to the "LINK.EXE" binary without checking its validity. This would allow an attacker to sideload any binary with the name "link.exe" if one of the aforementioned tools get executed from a different location. By filtering the known locations of such utilities we can spot uncommon parent process of LINK.EXE that might be suspicious or malicious.
windows · process_creation
Uncommon New Firewall Rule Added In Windows Firewall Exception List
mediumDetects when a rule has been added to the Windows Firewall exception list
windows · firewall-as
Uncommon Outbound Kerberos Connection
mediumDetects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.
windows · network_connection
Uncommon Outbound Kerberos Connection - Security
mediumDetects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.
windows · security
Uncommon PowerShell Hosts
mediumDetects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
windows · ps_classic_start
Uncommon Service Installation Image Path
mediumDetects uncommon service installation commands by looking at suspicious or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.
windows · system
Uncommon Sigverif.EXE Child Process
mediumDetects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.
windows · process_creation
Uncommon Svchost Parent Process
mediumDetects an uncommon svchost parent process
windows · process_creation
Uncommon System Information Discovery Via Wmic.EXE
mediumDetects the use of the WMI command-line (WMIC) utility to identify and display various system information, including OS, CPU, GPU, and disk drive names; memory capacity; display resolution; and baseboard, BIOS, and GPU driver products/versions. Some of these commands were used by Aurora Stealer in late 2022/early 2023.
windows · process_creation
Unsigned .node File Loaded
mediumDetects the loading of unsigned .node files. Adversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack. .node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code. This technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.
windows · image_load
Unsigned AppX Installation Attempt Using Add-AppxPackage
mediumDetects usage of the "Add-AppxPackage" or it's alias "Add-AppPackage" to install unsigned AppX packages
windows · process_creation
Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript
mediumDetects usage of the "Add-AppxPackage" or it's alias "Add-AppPackage" to install unsigned AppX packages
windows · ps_script
Unsigned DLL Loaded by Windows Utility
mediumDetects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.
windows · image_load
Unsigned Image Loaded Into LSASS Process
mediumLoading unsigned image (DLL, EXE) into LSASS process
windows · image_load
Unsigned Module Loaded by ClickOnce Application
mediumDetects unsigned module load by ClickOnce application.
windows · image_load
Unsigned or Unencrypted SMB Connection to Share Established
mediumDetects SMB server connections to shares without signing or encryption enabled. This could indicate potential lateral movement activity using unsecured SMB shares.
windows · smbserver-connectivity
Unusual File Download From File Sharing Websites - File Stream
mediumDetects the download of suspicious file type from a well-known file and paste sharing domain
windows · create_stream_hash
Unusual Parent Process For Cmd.EXE
mediumDetects suspicious parent process for cmd.exe
windows · process_creation
Usage Of Web Request Commands And Cmdlets
mediumDetects the use of various web request commands with commandline tools and Windows PowerShell cmdlets (including aliases) via CommandLine
windows · process_creation
Usage Of Web Request Commands And Cmdlets - ScriptBlock
mediumDetects the use of various web request commands with commandline tools and Windows PowerShell cmdlets (including aliases) via PowerShell scriptblock logs
windows · ps_script
Use Icacls to Hide File to Everyone
mediumDetect use of icacls to deny access for everyone in Users folder sometimes used to hide malicious files
windows · process_creation
Use NTFS Short Name in Command Line
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid command-line detection
windows · process_creation
Use NTFS Short Name in Image
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid Image based detection
windows · process_creation
Use of FSharp Interpreters
mediumDetects the execution of FSharp Interpreters "FsiAnyCpu.exe" and "FSi.exe" Both can be used for AWL bypass and to execute F# code via scripts or inline.
windows · process_creation
Use of OpenConsole
mediumDetects usage of OpenConsole binary as a LOLBIN to launch other binaries to bypass application Whitelisting
windows · process_creation
Use of Pcalua For Execution
mediumDetects execition of commands and binaries from the context of The program compatibility assistant (Pcalua.exe). This can be used as a LOLBIN in order to bypass application whitelisting.
windows · process_creation
Use of Remote.exe
mediumRemote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.
windows · process_creation
Use of Scriptrunner.exe
mediumThe "ScriptRunner.exe" binary can be abused to proxy execution through it and bypass possible whitelisting
windows · process_creation
Use Of The SFTP.EXE Binary As A LOLBIN
mediumDetects the usage of the "sftp.exe" binary as a LOLBIN by abusing the "-D" flag
windows · process_creation
Use of TTDInject.exe
mediumDetects the executiob of TTDInject.exe, which is used by Windows 10 v1809 and newer to debug time travel (underlying call of tttracer.exe)
windows · process_creation
Use of UltraVNC Remote Access Software
mediumAn adversary may use legitimate desktop support and remote access software,to establish an interactive command and control channel to target systems within networks
windows · process_creation
Use of VisualUiaVerifyNative.exe
mediumVisualUiaVerifyNative.exe is a Windows SDK that can be used for AWL bypass and is listed in Microsoft's recommended block rules.
windows · process_creation
Use of VSIISExeLauncher.exe
mediumThe "VSIISExeLauncher.exe" binary part of the Visual Studio/VS Code can be used to execute arbitrary binaries
windows · process_creation
Use of Wfc.exe
mediumThe Workflow Command-line Compiler can be used for AWL bypass and is listed in Microsoft's recommended block rules.
windows · process_creation
Use Short Name Path in Command Line
mediumDetects the use of short name paths (8.3 format) in command lines, which can be used to obfuscate paths or access restricted locations. Windows creates short 8.3 filenames (like PROGRA~1) for compatibility with MS-DOS-based or 16-bit Windows programs. When investigating, examine: - Commands using short paths to access sensitive directories or files - Web servers on Windows (especially Apache) where short filenames could bypass security controls - Correlation with other suspicious behaviors - baseline of short name usage in your environment and look for deviations
windows · process_creation
Use Short Name Path in Image
mediumDetect use of the Windows 8.3 short name. Which could be used as a method to avoid Image detection
windows · process_creation
User Added to Local Administrator Group
mediumDetects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity
windows · security
User Added to Local Administrators Group
mediumDetects addition of users to the local administrator group via "Net" or "Add-LocalGroupMember".
windows · process_creation
User Discovery And Export Via Get-ADUser Cmdlet
mediumDetects usage of the Get-ADUser cmdlet to collect user information and output it to a file
windows · process_creation
User Discovery And Export Via Get-ADUser Cmdlet - PowerShell
mediumDetects usage of the Get-ADUser cmdlet to collect user information and output it to a file
windows · ps_script
UtilityFunctions.ps1 Proxy Dll
mediumDetects the use of a Microsoft signed script executing a managed DLL with PowerShell.
windows · process_creation
Veeam Backup Database Suspicious Query
mediumDetects potentially suspicious SQL queries using SQLCmd targeting the Veeam backup databases in order to steal information.
windows · process_creation
Verclsid.exe Runs COM Object
mediumDetects when verclsid.exe is used to run COM object via GUID
windows · process_creation
VHD Image Download Via Browser
mediumDetects creation of ".vhd"/".vhdx" files by browser processes. Malware can use mountable Virtual Hard Disk ".vhd" files to encapsulate payloads and evade security controls.
windows · file_event
Visual Studio Code Tunnel Execution
mediumDetects Visual Studio Code tunnel execution. Attackers can abuse this functionality to establish a C2 channel
windows · process_creation
Visual Studio Code Tunnel Remote File Creation
mediumDetects the creation of file by the "node.exe" process in the ".vscode-server" directory. Could be a sign of remote file creation via VsCode tunnel feature
windows · file_event
Visual Studio Code Tunnel Service Installation
mediumDetects the installation of VsCode tunnel (code-tunnel) as a service.
windows · process_creation
Visual Studio Code Tunnel Shell Execution
mediumDetects the execution of a shell (powershell, bash, wsl...) via Visual Studio Code tunnel. Attackers can abuse this functionality to establish a C2 channel and execute arbitrary commands on the system.
windows · process_creation
Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
mediumDetects child processes of Microsoft.NodejsTools.PressAnyKey.exe that can be used to execute any other binary
windows · process_creation
Visual Studio NodejsTools PressAnyKey Renamed Execution
mediumDetects renamed execution of "Microsoft.NodejsTools.PressAnyKey.exe", which can be abused as a LOLBIN to execute arbitrary binaries
windows · process_creation
VMGuestLib DLL Sideload
mediumDetects DLL sideloading of VMGuestLib.dll by the WmiApSrv service.
windows · image_load
VMMap Signed Dbghelp.DLL Potential Sideloading
mediumDetects potential DLL sideloading of a signed dbghelp.dll by the Sysinternals VMMap.
windows · image_load
VsCode Code Tunnel Execution File Indicator
mediumDetects the creation of a file with the name "code_tunnel.json" which indicate execution and usage of VsCode tunneling utility. Attackers can abuse this functionality to establish a C2 channel
windows · file_event
VsCode Powershell Profile Modification
mediumDetects the creation or modification of a vscode related powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence
windows · file_event
WDAC Policy File Creation In CodeIntegrity Folder
mediumAttackers can craft a custom Windows Defender Application Control (WDAC) policy that blocks Endpoint Detection and Response (EDR) components while allowing their own malicious code. The policy is placed in the privileged Windows Code Integrity folder (C:\Windows\System32\CodeIntegrity\). Upon reboot, the policy prevents EDR drivers from loading, effectively bypassing security measures and may further enable undetected lateral movement within an Active Directory environment.
windows · file_event
Weak or Abused Passwords In CLI
mediumDetects weak passwords or often abused passwords (seen used by threat actors) via the CLI. An example would be a threat actor creating a new user via the net command and providing the password inline
windows · process_creation
WebDav Client Execution Via Rundll32.EXE
mediumDetects "svchost.exe" spawning "rundll32.exe" with command arguments like "C:\windows\system32\davclnt.dll,DavSetCookie". This could be an indicator of exfiltration or use of WebDav to launch code (hosted on a WebDav server).
windows · process_creation
WebDAV Temporary Local File Creation
mediumDetects the creation of WebDAV temporary files with potentially suspicious extensions
windows · file_event
WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze
mediumDetects the loading of dbgcore.dll or dbghelp.dll by WerFaultSecure.exe, which has been observed in EDR-Freeze attacks to suspend processes and evade detection. However, this behavior has also been observed during normal software installations, so further investigation is required to confirm malicious activity. When threat hunting, look for this activity in conjunction with other suspicious processes starting, network connections, or file modifications that occur shortly after the DLL load. Pay special attention to timing - if other malicious activities occur during or immediately after this library loading, it may indicate EDR evasion attempts. Also correlate with any EDR/AV process suspension events or gaps in security monitoring during the timeframe.
windows · image_load
WFP Filter Added via Registry
mediumDetects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.
windows · registry_set
Whoami.EXE Execution Anomaly
mediumDetects the execution of whoami.exe with suspicious parent processes.
windows · process_creation
Whoami.EXE Execution With Output Option
mediumDetects the execution of "whoami.exe" with the "/FO" flag to choose CSV as output format or with redirection options to export the results to a file for later use.
windows · process_creation
WinAPI Function Calls Via PowerShell Scripts
mediumDetects calls to WinAPI functions from PowerShell scripts. Attackers can often leverage these APIs to avoid detection based on typical PowerShell function calls. Use this rule as a basis to hunt for interesting scripts.
windows · ps_script
WinAPI Library Calls Via PowerShell Scripts
mediumDetects calls to WinAPI libraries from PowerShell scripts. Attackers can often leverage these APIs to avoid detection based on typical PowerShell function calls. Use this rule as a basis to hunt for interesting scripts.
windows · ps_script
Windows Admin Share Mount Via Net.EXE
mediumDetects when an admin share is mounted using net.exe
windows · process_creation
Windows AppX Deployment Full Trust Package Installation
mediumDetects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions
windows · appxdeployment-server
Windows AppX Deployment Unsigned Package Installation
mediumDetects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events
windows · appxdeployment-server
Windows Backup Deleted Via Wbadmin.EXE
mediumDetects the deletion of backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.
windows · process_creation
Windows Binary Executed From WSL
mediumDetects the execution of Windows binaries from within a WSL instance. This could be used to masquerade parent-child relationships
windows · process_creation
Windows Credential Manager Access via VaultCmd
mediumList credentials currently stored in Windows Credential Manager via the native Windows utility vaultcmd.exe
windows · process_creation
Windows Default Domain GPO Modification
mediumDetects modifications to Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may modify these default GPOs to deploy malicious configurations across the domain.
windows · security
Windows Default Domain GPO Modification via GPME
mediumDetects the use of the Group Policy Management Editor (GPME) to modify Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may leverage GPME to make stealthy changes in these default GPOs to deploy malicious GPOs configurations across the domain without raising suspicion.
windows · process_creation
Windows Defender Exclusion List Modified
mediumDetects modifications to the Windows Defender exclusion registry key. This could indicate a potentially suspicious or even malicious activity by an attacker trying to add a new exclusion in order to bypass security.
windows · security
Windows Defender Exclusion Registry Key - Write Access Requested
mediumDetects write access requests to the Windows Defender exclusions registry keys. This could be an indication of an attacker trying to request a handle or access the object to write new exclusions in order to bypass security.
windows · security
Windows Defender Exclusions Added
mediumDetects the Setting of Windows Defender Exclusions
windows · windefend
Windows Defender Exclusions Added - PowerShell
mediumDetects modifications to the Windows Defender configuration settings using PowerShell to add exclusions
windows · ps_script
Windows Defender Exclusions Added - Registry
mediumDetects the Setting of Windows Defender Exclusions
windows · registry_set
Windows Defender Real-Time Protection Failure/Restart
mediumDetects issues with Windows Defender Real-Time Protection features
windows · windefend
Windows Defender Threat Detection Service Disabled
mediumDetects when the "Windows Defender Threat Protection" service is disabled.
windows · system
Windows Firewall Disabled via PowerShell
mediumDetects attempts to disable the Windows Firewall using PowerShell
windows · process_creation
Windows Firewall Profile Disabled
mediumDetects when a user disables the Windows Firewall via a Profile to help evade defense.
windows · ps_script
Windows Hotfix Updates Reconnaissance Via Wmic.EXE
mediumDetects the execution of wmic with the "qfe" flag in order to obtain information about installed hotfix updates on the system. This is often used by pentester and attacker enumeration scripts
windows · process_creation
Windows Kernel Debugger Execution
mediumDetects execution of the Windows Kernel Debugger "kd.exe".
windows · process_creation
Windows Mail App Mailbox Access Via PowerShell Script
mediumDetects PowerShell scripts that try to access the default Windows MailApp MailBox. This indicates manipulation of or access to the stored emails of a user. E.g. this could be used by an attacker to exfiltrate or delete the content of the emails.
windows · ps_script
Windows Network Access Suspicious desktop.ini Action
mediumDetects unusual processes accessing desktop.ini remotely over network share, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.
windows · security
Windows Pcap Drivers
mediumDetects Windows Pcap driver installation based on a list of associated .sys files.
windows · security
Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by deleting the existing "DisableAIDataAnalysis" registry value. Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows · registry_delete
Windows Recall Feature Enabled - Registry
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by setting the value of "DisableAIDataAnalysis" to "0". Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows · registry_set
Windows Recall Feature Enabled Via Reg.EXE
mediumDetects the enabling of the Windows Recall feature via registry manipulation. Windows Recall can be enabled by deleting the existing "DisableAIDataAnalysis" value, or setting it to 0. Adversaries may enable Windows Recall as part of post-exploitation discovery and collection activities. This rule assumes that Recall is already explicitly disabled on the host, and subsequently enabled by the adversary.
windows · process_creation
Windows Recovery Environment Disabled Via Reagentc
mediumDetects attempts to disable windows recovery environment using Reagentc. ReAgentc.exe is a command-line tool in Windows used to manage the Windows Recovery Environment (WinRE). It allows users to enable, disable, and configure WinRE, which is used for troubleshooting and repairing common boot issues.
windows · process_creation
Windows Registry Trust Record Modification
mediumAlerts on trust record modification within the registry, indicating usage of macros
windows · registry_event
Windows Screen Capture with CopyFromScreen
mediumAdversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations
windows · ps_script
Windows Terminal Profile Settings Modification By Uncommon Process
mediumDetects the creation or modification of the Windows Terminal Profile settings file "settings.json" by an uncommon process.
windows · file_event
Winlogon AllowMultipleTSSessions Enable
mediumDetects when the 'AllowMultipleTSSessions' value is enabled. Which allows for multiple Remote Desktop connection sessions to be opened at once. This is often used by attacker as a way to connect to an RDP session without disconnecting the other users
windows · registry_set
Winlogon Helper DLL
mediumWinlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete. Registry entries in HKLM\Software[Wow6432Node]Microsoft\Windows NT\CurrentVersion\Winlogon\ and HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ are used to manage additional helper programs and functionalities that support Winlogon. Malicious modifications to these Registry keys may cause Winlogon to load and execute malicious DLLs and/or executables.
windows · ps_script
Winrar Compressing Dump Files
mediumDetects execution of WinRAR in order to compress a file with a ".dmp"/".dump" extension, which could be a step in a process of dump file exfiltration.
windows · process_creation
WinRAR Execution in Non-Standard Folder
mediumDetects a suspicious WinRAR execution in a folder which is not the default installation folder
windows · process_creation
Winscp Execution From Non Standard Folder
mediumDetects the execution of Winscp from an a non standard folder. This could indicate the execution of Winscp portable.
windows · process_creation
WinSock2 Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
WinSxS Executable File Creation By Non-System Process
mediumDetects the creation of binaries in the WinSxS folder by non-system processes
windows · file_event
Wlrmdr.EXE Uncommon Argument Or Child Process
mediumDetects the execution of "Wlrmdr.exe" with the "-u" command line flag which allows anything passed to it to be an argument of the ShellExecute API, which would allow an attacker to execute arbitrary binaries. This detection also focuses on any uncommon child processes spawned from "Wlrmdr.exe" as a supplement for those that posses "ParentImage" telemetry.
windows · process_creation
WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load
mediumDetects signs of the WMI script host process "scrcons.exe" loading scripting DLLs which could indicates WMI ActiveScriptEventConsumers EventConsumers activity.
windows · image_load
WMI Event Consumer Created Named Pipe
mediumDetects the WMI Event Consumer service scrcons.exe creating a named pipe
windows · pipe_created
WMI Event Subscription
mediumDetects creation of WMI event subscription persistence method
windows · wmi_event
WMI Persistence
mediumDetects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.
windows · wmi
WMI Persistence - Script Event Consumer
mediumDetects the execution of a script event consumer. When scrcons.exe launches, it does so in response to the creation of an ActiveScriptEventConsumer instance and will execute registered JScript or VBScript code as a result. Script event consumers are a built-in Windows Management Instrumentation (WMI) class that automatically executes a predefined script (in VBScript or JScript) whenever a specific system event occurs. Adversaries often abuse script event consumers to maintain persistence on a compromised host by executing a malicious script whenever a specific event occurs.
windows · process_creation
WMI Persistence - Security
mediumDetects suspicious WMI event filter and command line event consumer based on WMI and Security Logs.
windows · security
WMIC Loading Scripting Libraries
mediumDetects threat actors proxy executing code and bypassing application controls by leveraging wmic and the `/FORMAT` argument switch to download and execute an XSL file (i.e js, vbs, etc). It could be an indicator of SquiblyTwo technique, which uses Windows Management Instrumentation (WMI) to execute malicious code.
windows · image_load
WMIC Remote Command Execution
mediumDetects the execution of WMIC to query information on a remote system
windows · process_creation
WMIC Unquoted Services Path Lookup - PowerShell
mediumDetects known WMI recon method to look for unquoted service paths, often used by pentest inside of powershell scripts attackers enum scripts
windows · ps_script
WmiPrvSE Spawned A Process
mediumDetects WmiPrvSE spawning a process
windows · process_creation
Wow6432Node Classes Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Wow6432Node CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Wow6432Node Windows NT CurrentVersion Autorun Keys Modification
mediumDetects modification of autostart extensibility point (ASEP) in registry.
windows · registry_set
Write Protect For Storage Disabled
mediumDetects applications trying to modify the registry in order to disable any write-protect property for storage devices. This could be a precursor to a ransomware attack and has been an observed technique used by cypherpunk group.
windows · process_creation
Writing Local Admin Share
mediumAversaries may use to interact with a remote network share using Server Message Block (SMB). This technique is used by post-exploitation frameworks.
windows · file_event
Writing Of Malicious Files To The Fonts Folder
mediumMonitors for the hiding possible malicious files in the C:\Windows\Fonts\ location. This folder doesn't require admin privillege to be written and executed from.
windows · process_creation
Wscript Shell Run In CommandLine
mediumDetects the presence of the keywords "Wscript", "Shell" and "Run" in the command, which could indicate a suspicious activity
windows · process_creation
WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
mediumDetects script file execution (.js, .jse, .vba, .vbe, .vbs, .wsf, .wsh) by Wscript/Cscript.
windows · process_creation
WSL Child Process Anomaly
mediumDetects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL
windows · process_creation
XBAP Execution From Uncommon Locations Via PresentationHost.EXE
mediumDetects the execution of ".xbap" (Browser Applications) files via PresentationHost.EXE from an uncommon location. These files can be abused to run malicious ".xbap" files any bypass AWL
windows · process_creation
XSL Script Execution Via WMIC.EXE
mediumDetects the execution of WMIC with the "format" flag to potentially load local XSL files. Adversaries abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files.
windows · process_creation
Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_module
Zip A Folder With PowerShell For Staging In Temp - PowerShell
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · powershell-classic
Zip A Folder With PowerShell For Staging In Temp - PowerShell Script
mediumDetects PowerShell scripts that make use of the "Compress-Archive" Cmdlet in order to compress folders and files where the output is stored in a potentially suspicious location that is used often by malware for exfiltration. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_script
A Member Was Added to a Security-Enabled Global Group
lowDetects activity when a member is added to a security-enabled global group
windows · security
A Member Was Removed From a Security-Enabled Global Group
lowDetects activity when a member is removed from a security-enabled global group
windows · security
A Security-Enabled Global Group Was Deleted
lowDetects activity when a security-enabled global group is deleted
windows · security
Access To .Reg/.Hive Files By Uncommon Applications
lowDetects file access requests to files ending with either the ".hive"/".reg" extension, usually associated with Windows Registry backups.
windows · file_access
Access To ADMIN$ Network Share
lowDetects access to ADMIN$ network share
windows · security
Access To Browser Credential Files By Uncommon Applications
lowDetects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
windows · file_access
Access To Browser Credential Files By Uncommon Applications - Security
lowDetects file access requests to browser credential stores by uncommon processes. Could indicate potential attempt of credential stealing This rule requires heavy baselining before usage.
windows · security
Access To Chromium Browsers Sensitive Files By Uncommon Applications
lowDetects file access requests to chromium based browser sensitive files by uncommon processes. Could indicate potential attempt of stealing sensitive information.
windows · file_access
Access To Windows Outlook Mail Files By Uncommon Applications
lowDetects file access requests to Windows Outlook Mail by uncommon processes. Could indicate potential attempt of credential stealing. Requires heavy baselining before usage
windows · file_access
Active Directory Certificate Services Denied Certificate Enrollment Request
lowDetects denied requests by Active Directory Certificate Services. Example of these requests denial include issues with permissions on the certificate template or invalid signatures.
windows · system
Active Directory Computers Enumeration With Get-AdComputer
lowDetects usage of the "Get-AdComputer" to enumerate Computers or properties within Active Directory.
windows · ps_script
Active Directory Group Enumeration With Get-AdGroup
lowDetects usage of the "Get-AdGroup" cmdlet to enumerate Groups within Active Directory
windows · ps_script
AD Groups Or Users Enumeration Using PowerShell - PoshModule
lowAdversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
windows · ps_module
AD Groups Or Users Enumeration Using PowerShell - ScriptBlock
lowAdversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
windows · ps_script
ADCS Certificate Template Configuration Vulnerability
lowDetects certificate creation with template allowing risk permission subject
windows · security
Add or Remove Computer from DC
lowDetects the creation or removal of a computer. Can be used to detect attacks such as DCShadow via the creation of a new SPN.
windows · security
Admin User Remote Logon
lowDetect remote login by Administrator user (depending on internal pattern).
windows · security
ADS Zone.Identifier Deleted
lowDetects the deletion of the "Zone.Identifier" ADS. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.
windows · file_delete
Amsi.DLL Load By Uncommon Process
lowDetects loading of Amsi.dll by uncommon processes
windows · image_load
Application Uninstalled
lowAn application has been removed. Check if it is critical.
windows · application
Automated Collection Bookmarks Using Get-ChildItem PowerShell
lowAdversaries may enumerate browser bookmarks to learn more about compromised hosts. Browser bookmarks may reveal personal information about users (ex: banking sites, interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
windows · ps_script
BitLockerTogo.EXE Execution
lowDetects the execution of "BitLockerToGo.EXE". BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system. This is a rarely used application and usage of it at all is worth investigating. Malware such as Lumma stealer has been seen using this process as a target for process hollowing.
windows · process_creation
BITS Client BitsProxy DLL Loaded By Uncommon Process
lowDetects an uncommon process loading the "BitsProxy.dll". This DLL is used when the BITS COM instance or API is used. This detection can be used to hunt for uncommon processes loading this DLL in your environment. Which may indicate potential suspicious activity occurring.
windows · image_load
Browser Execution In Headless Mode
lowDetects execution of Chromium based browser in headless mode
windows · process_creation
bXOR Operator Usage In PowerShell Command Line - PowerShell Classic
lowDetects powershell execution with that make use of to the bxor (Bitwise XOR). Attackers might use as an alternative obfuscation method to Base64 encoded commands. Investigate the CommandLine and process tree to determine if the activity is malicious.
windows · ps_classic_start
Change Default File Association Via Assoc
lowDetects file association changes using the builtin "assoc" command. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Applications can modify the file association for a given file extension to call an arbitrary program when a file with the given extension is opened.
windows · process_creation
CMD Shell Output Redirect
lowDetects the use of the redirection character ">" to redirect information on the command line. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.
windows · process_creation
CodeIntegrity - Unmet Signing Level Requirements By File Under Validation
lowDetects attempted file load events that did not meet the signing level requirements. It often means the file's signature is revoked or a signature with the Lifetime Signing EKU has expired. This event is best correlated with EID 3089 to determine the error of the validation.
windows · codeintegrity-operational
CodePage Modification Via MODE.COM
lowDetects a CodePage modification using the "mode.com" utility. This behavior has been used by threat actors behind Dharma ransomware.
windows · process_creation
Command Executed Via Run Dialog Box - Registry
lowDetects execution of commands via the run dialog box on Windows by checking values of the "RunMRU" registry key. This technique was seen being abused by threat actors to deceive users into pasting and executing malicious commands, often disguised as CAPTCHA verification steps.
windows · registry_set
Compress-Archive Cmdlet Execution
lowDetects PowerShell scripts that make use of the "Compress-Archive" cmdlet in order to compress folders and files. An adversary might compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · ps_script
Compressed File Creation Via Tar.EXE
lowDetects execution of "tar.exe" in order to create a compressed file. Adversaries may abuse various utilities to compress or encrypt data before exfiltration.
windows · process_creation
Compressed File Extraction Via Tar.EXE
lowDetects execution of "tar.exe" in order to extract compressed file. Adversaries may abuse various utilities in order to decompress data to avoid detection.
windows · process_creation
Creation of an Executable by an Executable
lowDetects the creation of an executable by another executable.
windows · file_event
Curl.EXE Execution
lowDetects a curl process start on Windows, which could indicates a file download from a remote location or a simple web request to a remote server
windows · process_creation
CVE-2023-40477 Potential Exploitation - .REV File Creation
lowDetects the creation of ".rev" files by WinRAR. Could be indicative of potential exploitation of CVE-2023-40477. Look for a suspicious execution shortly after creation or a WinRAR application crash.
windows · file_event
Data Copied To Clipboard Via Clip.EXE
lowDetects the execution of clip.exe in order to copy data to the clipboard. Adversaries may collect data stored in the clipboard from users copying information within or between applications.
windows · process_creation
Directory Removal Via Rmdir
lowDetects execution of the builtin "rmdir" command in order to delete directories. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
windows · process_creation
DirLister Execution
lowDetect the usage of "DirLister.exe" a utility for quickly listing folder or drive contents. It was seen used by BlackCat ransomware to create a list of accessible directories and files.
windows · process_creation
Discovery of a System Time
lowIdentifies use of various commands to query a systems time. This technique may be used before executing a scheduled task or to discover the time zone of a target system.
windows · process_creation
DMP/HDMP File Creation
lowDetects the creation of a file with the ".dmp"/".hdmp" extension. Often created by software during a crash. Memory dumps can sometimes contain sensitive information such as credentials. It's best to determine the source of the crash.
windows · file_event
DMSA Link Attributes Modified
lowDetects modification of dMSA link attributes (msDS-ManagedAccountPrecededByLink) via PowerShell scripts. This command line pattern could be an indicator an attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.
windows · ps_script
DNS Query Request By QuickAssist.EXE
lowDetects DNS queries initiated by "QuickAssist.exe" to Microsoft Quick Assist primary endpoint that is used to establish a session.
windows · dns_query
DNS Query Request To OneLaunch Update Service
lowDetects DNS query requests to "update.onelaunch.com". This domain is associated with the OneLaunch adware application. When the OneLaunch application is installed it will attempt to get updates from this domain.
windows · dns_query
DNS Query To Ufile.io
lowDetects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration
windows · dns_query
DNS Query To Ufile.io - DNS Client
lowDetects DNS queries to "ufile.io", which was seen abused by malware and threat actors as a method for data exfiltration
windows · dns-client
DNS Request From Windows Script Host
lowDetects unusual domain resolutions originating from CScript/WScript that can identify malicious javascript files executing in an environment, often as a result from a phishing or watering hole attack.
windows · dns_query
DNS Server Discovery Via LDAP Query
lowDetects DNS server discovery via LDAP query requests from uncommon applications
windows · dns_query
Dynamic CSharp Compile Artefact
lowWhen C# is compiled dynamically, a .cmdline file will be created as a part of the process. Certain processes are not typically observed compiling C# code, but can do so without touching disk. This can be used to unpack a payload for execution
windows · file_event
ETW Logging Disabled For rpcrt4.dll
lowDetects changes to the "ExtErrorInformation" key in order to disable ETW logging for rpcrt4.dll
windows · registry_set
ETW Logging Disabled For SCM
lowDetects changes to the "TracingDisabled" key in order to disable ETW logging for services.exe (SCM)
windows · registry_set
Exports Registry Key To a File
lowDetects the export of the target Registry key to a file.
windows · process_creation
External Disk Drive Or USB Storage Device Was Recognized By The System
lowDetects external disk drives or plugged-in USB devices.
windows · security
File And SubFolder Enumeration Via Dir Command
lowDetects usage of the "dir" command part of Windows CMD with the "/S" command line flag in order to enumerate files in a specified directory and all subdirectories.
windows · process_creation
File Creation Date Changed to Another Year
lowDetects when the file creation time is changed to a year before 2020. Attackers may change the file creation time of a backdoor to make it look like it was installed with the operating system. Note that many processes legitimately change the creation time of a file; it does not necessarily indicate malicious activity. In order to use this rule in production, it is recommended first baseline normal behavior in your environment and then tune the rule accordingly. Hunting Recommendation: Focus on files with creation times set to years significantly before the current date, especially those in user-writable directories. Correlate with process execution logs to identify the source of the modification and investigate any unsigned or suspicious binaries involved.
windows · file_change
File Deletion Via Del
lowDetects execution of the builtin "del"/"erase" commands in order to delete files. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.
windows · process_creation
Files Added To An Archive Using Rar.EXE
lowDetects usage of "rar" to add files to an archive for potential compression. An adversary may compress data (e.g. sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.
windows · process_creation
Firewall Configuration Discovery Via Netsh.EXE
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
Firewall Rule Modified In The Windows Firewall Exception List
lowDetects when a rule has been modified in the Windows firewall exception list
windows · firewall-as
Fsutil Drive Enumeration
lowAttackers may leverage fsutil to enumerated connected drives.
windows · process_creation
HH.EXE Execution
lowDetects the execution of "hh.exe" to open ".chm" files.
windows · process_creation
HTML File Opened From Download Folder
lowDetects web browser process opening an HTML file from a user's Downloads folder. This behavior is could be associated with phishing attacks where threat actors send HTML attachments to users. When a user opens such an attachment, it can lead to the execution of malicious scripts or the download of malware. During investigation, analyze the HTML file for embedded scripts or links, check for any subsequent downloads or process executions, and investigate the source of the email or message containing the attachment.
windows · process_creation
Import New Module Via PowerShell CommandLine
lowDetects usage of the "Import-Module" cmdlet in order to add new Cmdlets to the current PowerShell session
windows · process_creation
Indirect Command Execution By Program Compatibility Wizard
lowDetect indirect command execution via Program Compatibility Assistant pcwrun.exe
windows · process_creation
Insensitive Subfolder Search Via Findstr.EXE
lowDetects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.
windows · process_creation
Interesting Service Enumeration Via Sc.EXE
lowDetects the enumeration and query of interesting and in some cases sensitive services on the system via "sc.exe". Attackers often try to enumerate the services currently running on a system in order to find different attack vectors.
windows · process_creation
JScript Compiler Execution
lowDetects the execution of the "jsc.exe" (JScript Compiler). Attacker might abuse this in order to compile JScript files on the fly and bypassing application whitelisting.
windows · process_creation
Load Of RstrtMgr.DLL By An Uncommon Process
lowDetects the load of RstrtMgr DLL (Restart Manager) by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes.
windows · image_load
Local Accounts Discovery
lowLocal accounts, System Owner/User discovery using operating systems utilities
windows · process_creation
Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet
lowDetects execution of "Get-NetFirewallRule" or "Show-NetFirewallRule" to enumerate the local firewall rules on a host.
windows · ps_module
Local Groups Reconnaissance Via Wmic.EXE
lowDetects the execution of "wmic" with the "group" flag. Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.
windows · process_creation
Local User Creation
lowDetects local user creation on Windows servers, which shouldn't happen in an Active Directory environment. Apply this Sigma Use Case on your Windows server logs and not on your DC logs.
windows · security
Malicious Windows Script Components File Execution by TAEF Detection
lowWindows Test Authoring and Execution Framework (TAEF) framework allows you to run automation by executing tests files written on different languages (C, C#, Microsoft COM Scripting interfaces Adversaries may execute malicious code (such as WSC file with VBScript, dll and so on) directly by running te.exe
windows · process_creation
MaxMpxCt Registry Value Changed
lowDetects changes to the "MaxMpxCt" registry value. MaxMpxCt specifies the maximum outstanding network requests for the server per client, which is used when negotiating a Server Message Block (SMB) connection with a client. Note if the value is set beyond 125 older Windows 9x clients will fail to negotiate. Ransomware threat actors and operators (specifically BlackCat) were seen increasing this value in order to handle a higher volume of traffic.
windows · registry_set
Microsoft Excel Add-In Loaded
lowDetects Microsoft Excel loading an Add-In (.xll) file
windows · image_load
Microsoft Word Add-In Loaded
lowDetects Microsoft Word loading an Add-In (.wll) file which can be used by threat actors for initial access or persistence.
windows · image_load
Modification of IE Registry Settings
lowDetects modification of the registry settings used for Internet Explorer and other Windows components that use these settings. An attacker can abuse this registry key to add a domain to the trusted sites Zone or insert JavaScript for persistence
windows · registry_set
Msiexec.EXE Initiated Network Connection Over HTTP
lowDetects a network connection initiated by an "Msiexec.exe" process over port 80 or 443. Adversaries might abuse "msiexec.exe" to install and execute remotely hosted packages. Use this rule to hunt for potentially anomalous or suspicious communications.
windows · network_connection
MSSQL Server Failed Logon
lowDetects failed logon attempts from clients to MSSQL server.
windows · application
Mstsc.EXE Execution With Local RDP File
lowDetects potential RDP connection via Mstsc using a local ".rdp" file
windows · process_creation
Net.EXE Execution
lowDetects execution of "Net.EXE".
windows · process_creation
Network Connection Initiated By PowerShell Process
lowDetects a network connection that was initiated from a PowerShell process. Often times malicious powershell scripts download additional payloads or communicate back to command and control channels via uncommon ports or IPs. Use this rule as a basis for hunting for anomalies.
windows · network_connection
Network Connection Initiated To Mega.nz
lowDetects a network connection initiated by a binary to "api.mega.co.nz". Attackers were seen abusing file sharing websites similar to "mega.nz" in order to upload/download additional payloads.
windows · network_connection
New BITS Job Created Via Bitsadmin
lowDetects the creation of a new bits job by Bitsadmin
windows · bits-client
New BITS Job Created Via PowerShell
lowDetects the creation of a new bits job by PowerShell
windows · bits-client
New ODBC Driver Registered
lowDetects the registration of a new ODBC driver.
windows · registry_set
New Process Created Via Taskmgr.EXE
lowDetects the creation of a process via the Windows task manager. This might be an attempt to bypass UAC
windows · process_creation
New Service Creation Using PowerShell
lowDetects the creation of a new service using powershell.
windows · process_creation
New Service Creation Using Sc.EXE
lowDetects the creation of a new service using the "sc.exe" utility.
windows · process_creation
New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet
lowDetects calls to the "New-NetFirewallRule" cmdlet from PowerShell in order to add a new firewall rule with an "Allow" action.
windows · process_creation
New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet - ScriptBlock
lowDetects when a powershell script contains calls to the "New-NetFirewallRule" cmdlet in order to add a new firewall rule with an "Allow" action.
windows · ps_script
Nltest.EXE Execution
lowDetects nltest commands that can be used for information discovery
windows · process_creation
No Suitable Encryption Key Found For Generating Kerberos Ticket
lowDetects errors when a target server doesn't have suitable keys for generating kerberos tickets. This issue can occur for example when a service uses a user account or a computer account that is configured for only DES encryption on a computer that is running Windows 7 which has DES encryption for Kerberos authentication disabled.
windows · system
NodeJS Execution of JavaScript File
lowDetects execution of JavaScript or JSC files using NodeJs binary node.exe, that could be potentially suspicious. Node.js is a popular open-source JavaScript runtime that runs code outside browsers and is widely used for both frontend and backend development. Adversaries have been observed abusing Node.js to disguise malware as legitimate processes, evade security defenses, and maintain persistence within target systems. Because Node.js is commonly used, this rule may generate false positives in some environments. However, if such activity is unusual in your environment, it is highly suspicious and warrants immediate investigation.
windows · process_creation
Non Interactive PowerShell Process Spawned
lowDetects non-interactive PowerShell activity by looking at the "powershell" process with a non-user GUI process such as "explorer.exe" as a parent.
windows · process_creation
Notepad Password Files Discovery
lowDetects the execution of Notepad to open a file that has the string "password" which may indicate unauthorized access to credentials or suspicious activity.
windows · process_creation
NTDS.DIT Created
lowDetects creation of a file named "ntds.dit" (Active Directory Database)
windows · file_event
NTLM Logon
lowDetects logons using NTLM, which could be caused by a legacy source or attackers
windows · ntlm
Office Macro File Creation
lowDetects the creation of a new office macro files on the systems
windows · file_event
Office Macro File Download
lowDetects the creation of a new office macro files on the system via an application (browser, mail client). This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.
windows · file_event
Outgoing Logon with New Credentials
lowDetects logon events that specify new credentials
windows · security
Outlook Task/Note Reminder Received
lowDetects changes to the registry values related to outlook that indicates that a reminder was triggered for a Note or Task item. This could be a sign of exploitation of CVE-2023-23397. Further investigation is required to determine the success of an exploitation.
windows · registry_set
Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy
lowDetetcts PowerShell activity in which Get-Addefaultdomainpasswordpolicy is used to get the default password policy for an Active Directory domain.
windows · ps_script
Password Protected Compressed File Extraction Via 7Zip
lowDetects usage of 7zip utilities (7z.exe, 7za.exe and 7zr.exe) to extract password protected zip files.
windows · process_creation
PFX File Creation
lowDetects the creation of PFX files (Personal Information Exchange format). PFX files contain private keys and certificates bundled together, making them valuable targets for attackers seeking to: - Exfiltrate digital certificates for impersonation or signing malicious code - Establish persistent access through certificate-based authentication - Bypass security controls that rely on certificate validation Analysts should investigate PFX file creation events by examining which process created the PFX file and its parent process chain, as well as unusual locations outside standard certificate stores or development environments.
windows · file_event
Potential 7za.DLL Sideloading
lowDetects potential DLL sideloading of "7za.dll"
windows · image_load
Potential Azure Browser SSO Abuse
lowDetects abusing Azure Browser SSO by requesting OAuth 2.0 refresh tokens for an Azure-AD-authenticated Windows user (i.e. the machine is joined to Azure AD and a user logs in with their Azure AD account) wanting to perform SSO authentication in the browser. An attacker can use this to authenticate to Azure AD in a browser as that user.
windows · image_load
Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
lowDetects raw disk access using uncommon tools or tools that are located in suspicious locations (heavy filtering is required), which could indicate possible defense evasion attempts
windows · raw_access_thread
Potential Encoded PowerShell Patterns In CommandLine
lowDetects specific combinations of encoding methods in PowerShell via the commandline
windows · process_creation
Potential Executable Run Itself As Sacrificial Process
lowDetects when an executable launches an identical instance of itself, a behavior often used to create a suspended “sacrificial” process for code injection or evasion. Investigate for indicators such as the process being started in suspended mode, rapid parent termination, memory manipulation (e.g., WriteProcessMemory, CreateRemoteThread), or unsigned binaries. Review command-line arguments, process ancestry, and network activity to confirm if this is legitimate behavior or process injection activity.
windows · process_creation
Potential Execution of Sysinternals Tools
lowDetects command lines that contain the 'accepteula' flag which could be a sign of execution of one of the Sysinternals tools
windows · process_creation
Potential Exploitation of CVE-2022-21919 or CVE-2021-34484 for LPE
lowDetects potential exploitation attempts of CVE-2022-21919 or CVE-2021-34484 leading to local privilege escalation via the User Profile Service. During exploitation of this vulnerability, two logs (Provider_Name: Microsoft-Windows-User Profiles Service) with EventID 1511 and 1515 are created (EventID 1515 may generate many false positives). Additionally, the directory \Users\TEMP may be created during exploitation. This behavior was observed on Windows Server 2008.
windows · application
Potential File Override/Append Via SET Command
lowDetects the use of the "SET" internal command of Cmd.EXE with the /p flag followed directly by an "=" sign. Attackers used this technique along with an append redirection operator ">>" in order to update the content of a file indirectly. Ex: cmd /c >> example.txt set /p="test data". This will append "test data" to contents of "example.txt". The typical use case of the "set /p=" command is to prompt the user for input.
windows · process_creation
Potential PowerShell Obfuscation Using Alias Cmdlets
lowDetects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts
windows · ps_script
Potential PowerShell Obfuscation Using Character Join
lowDetects specific techniques often seen used inside of PowerShell scripts to obfscuate Alias creation
windows · ps_script
Potential Proxy Execution Via Explorer.EXE From Shell Process
lowDetects the creation of a child "explorer.exe" process from a shell like process such as "cmd.exe" or "powershell.exe". Attackers can use "explorer.exe" for evading defense mechanisms by proxying the execution through the latter. While this is often a legitimate action, this rule can be use to hunt for anomalies. Muddy Waters threat actor was seeing using this technique.
windows · process_creation
Potential Raspberry Robin Registry Set Internet Settings ZoneMap
lowDetects registry modifications related to the proxy configuration of the system, potentially associated with the Raspberry Robin malware, as seen in campaigns running in Q1 2024. Raspberry Robin may alter proxy settings to circumvent security measures, ensuring unhindered connection with Command and Control servers for maintaining control over compromised systems if there are any proxy settings that are blocking connections.
windows · registry_set
Potential Suspicious Execution From GUID Like Folder Names
lowDetects potential suspicious execution of a GUID like folder name located in a suspicious location such as %TEMP% as seen being used in IcedID attacks. Use this rule to hunt for potentially suspicious activity stemming from uncommon folders.
windows · process_creation
Potentially Suspicious Network Connection To Notion API
lowDetects a non-browser process communicating with the Notion API. This could indicate potential use of a covert C2 channel such as "OffensiveNotion C2"
windows · network_connection
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
lowDetects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
windows · process_creation
PowerShell Download Via Net.WebClient - PowerShell Classic
lowDetects PowerShell download activity, via the .DownloadFile() or .DownloadString() methods of the Net.WebClient class. This technique is often abused by attackers to download additional payloads.
windows · ps_classic_start
PowerShell Module File Created
lowDetects the creation of a new PowerShell module ".psm1", ".psd1", ".dll", ".ps1", etc.
windows · file_event
PowerShell Script Change Permission Via Set-Acl - PsScript
lowDetects PowerShell scripts set ACL to of a file or a folder
windows · ps_script
PowerShell Script Dropped Via PowerShell.EXE
lowDetects PowerShell creating a PowerShell file (.ps1). While often times this behavior is benign, sometimes it can be a sign of a dropper script trying to achieve persistence.
windows · file_event
PowerShell Script Execution Policy Enabled
lowDetects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.
windows · registry_set
PowerShell Script With File Upload Capabilities
lowDetects PowerShell scripts leveraging the "Invoke-WebRequest" cmdlet to send data via either "PUT" or "POST" method.
windows · ps_script
Powershell Suspicious Win32_PnPEntity
lowAdversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
windows · ps_script
Previously Installed IIS Module Was Removed
lowDetects the removal of a previously installed IIS module.
windows · iis-configuration
Process Execution From WebDAV Share
lowDetects execution of processes with image paths starting with WebDAV shares (\\), which might indicate malicious file execution from remote web shares. Execution of processes from WebDAV shares can be a sign of lateral movement or exploitation attempts, especially if the process is not a known legitimate application. Exploitation Attempt of vulnerabilities like CVE-2025-33053 also involves executing processes from WebDAV paths.
windows · process_creation
Process Terminated Via Taskkill
lowDetects execution of "taskkill.exe" in order to stop a service or a process. Look for suspicious parents executing this command in order to hunt for potential malicious activity. Attackers might leverage this in order to conduct data destruction or data encrypted for impact on the data stores of services like Exchange and SQL Server.
windows · process_creation
PsExec Default Named Pipe
lowDetects PsExec service default pipe creation
windows · pipe_created
PsExec Service File Creation
lowDetects default PsExec service filename which indicates PsExec service installation and execution
windows · file_event
PUA - Adidnsdump Execution
lowThis tool enables enumeration and exporting of all DNS records in the zone for recon purposes of internal networks Python 3 and python.exe must be installed, Usee to Query/modify DNS records for Active Directory integrated DNS via LDAP
windows · process_creation
PUA - Sysinternal Tool Execution - Registry
lowDetects the execution of a Sysinternals Tool via the creation of the "accepteula" registry key
windows · registry_set
Python Image Load By Non-Python Process
lowDetects the image load of "Python Core" by a non-Python process. This might be indicative of a execution of executable that has been bundled from Python code. Various tools like Py2Exe, PyInstaller, and cx_Freeze are used to bundle Python code into standalone executables. Threat actors often use these tools to bundle malicious Python scripts into executables, sometimes to obfuscate the code or to bypass security measures.
windows · image_load
QuickAssist Execution
lowDetects the execution of Microsoft Quick Assist tool "QuickAssist.exe". This utility can be used by attackers to gain remote access.
windows · process_creation
RegAsm.EXE Execution Without CommandLine Flags or Files
lowDetects the execution of "RegAsm.exe" without a commandline flag or file, which might indicate potential process injection activity. Usually "RegAsm.exe" should point to a dedicated DLL file or call the help with the "/?" flag.
windows · process_creation
Registry Modification Via Regini.EXE
lowDetects the execution of regini.exe which can be used to modify registry keys, the changes are imported from one or more text files.
windows · process_creation
Remote Access Tool - ScreenConnect Command Execution
lowDetects command execution via ScreenConnect RMM
windows · application
Remote Access Tool - ScreenConnect File Transfer
lowDetects file being transferred via ScreenConnect RMM
windows · application
Remote Access Tool - ScreenConnect Remote Command Execution
lowDetects the execution of a system command via the ScreenConnect RMM service.
windows · process_creation
Remote Access Tool - ScreenConnect Temporary File
lowDetects the creation of files in a specific location by ScreenConnect RMM. ScreenConnect has feature to remotely execute binaries on a target machine. These binaries will be dropped to ":\Users\<username>\Documents\ConnectWiseControl\Temp\" before execution.
windows · file_event
Remote Access Tool - Team Viewer Session Started On Windows Host
lowDetects the command line executed when TeamViewer starts a session started by a remote host. Once a connection has been started, an investigator can verify the connection details by viewing the "incoming_connections.txt" log file in the TeamViewer folder.
windows · process_creation
Remote PowerShell Session (PS Classic)
lowDetects remote PowerShell sessions
windows · ps_classic_start
Renamed Powershell Under Powershell Channel
lowDetects a renamed Powershell execution, which is a common technique used to circumvent security controls and bypass detection logic that's dependent on process names and process paths.
windows · ps_classic_start
Replace Desktop Wallpaper by Powershell
lowAn adversary may deface systems internal to an organization in an attempt to intimidate or mislead users. This may take the form of modifications to internal websites, or directly to user systems with the replacement of the desktop wallpaper
windows · ps_script
Run Once Task Execution as Configured in Registry
lowThis rule detects the execution of Run Once task as configured in the registry
windows · process_creation
SC.EXE Query Execution
lowDetects execution of "sc.exe" to query information about registered services on the system
windows · process_creation
Scheduled Task Created - FileCreation
lowDetects the creation of a scheduled task via file creation.
windows · file_event
Scheduled Task Created - Registry
lowDetects the creation of a scheduled task via Registry keys.
windows · registry_event
Scheduled Task Creation Via Schtasks.EXE
lowDetects the creation of scheduled tasks by user accounts via the "schtasks" utility.
windows · process_creation
Scheduled Task Deletion
lowDetects scheduled task deletion events. Scheduled tasks are likely to be deleted if not used for persistence. Malicious Software often creates tasks directly under the root node e.g. \TASKNAME
windows · security
Service Registry Key Read Access Request
lowDetects "read access" requests on the services registry key. Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for Registry keys related to services to redirect from the originally specified executable to one that they control, in order to launch their own code when a service starts.
windows · security
Set Files as System Files Using Attrib.EXE
lowDetects the execution of "attrib" with the "+s" flag to mark files as system files
windows · process_creation
Share And Session Enumeration Using Net.EXE
lowDetects attempts to enumerate file shares, printer shares and sessions using "net.exe" with the "view" flag.
windows · process_creation
Shell Context Menu Command Tampering
lowDetects changes to shell context menu commands. Use this rule to hunt for potential anomalies and suspicious shell commands.
windows · registry_set
Signed DLL Loaded With Missing PE Version Metadata
lowDetects the loading of a digitally signed DLL whose PE version-info resource is entirely missing. Legitimate signed DLLs from reputable vendors often carry populated metadata fields (Description, Company, Product, OriginalFileName, FileVersion). An attacker who signs a purpose-built or hollowed DLL with a stolen, mis-issued, or cheaply purchased code-signing certificate will often omit these fields, producing a valid signature with no accompanying version info. This pattern is observed in DLL side-loading, search-order hijacking, and certificate-abuse campaigns where signing is used purely to satisfy security-product trust checks. Hunting Hypothesis: - Investigate the signing certificate (issuer, subject, validity window, thumbprint) for disposable or recently issued CAs and cross-reference against known threat-actor certificates. - Examine the DLL's on-disk path relative to the loading process — paths outside standard system directories or inside application folders susceptible to search-order hijacking are high-priority leads. - Correlate with the parent process context; DLLs loaded into high-value targets such as lsass.exe, svchost.exe, or browser processes warrant immediate escalation. Note: The "selection_metadata_null" selection matches fields with a null value. Some backends may interpret null field conditions as "field does not exist" rather than "field has a null value", which would change the detection semantics. If your backend does not support or support null-value matching in different ways than expected, you may need to adjust the rule logic accordingly or remove the "selection_metadata_null" condition.
windows · image_load
SNAKE Malware Installer Name Indicators
lowDetects filename indicators associated with the SNAKE malware as reported by CISA in their report
windows · file_event
Start Windows Service Via Net.EXE
lowDetects the usage of the "net.exe" command to start a service using the "start" flag
windows · process_creation
Stop Windows Service Via Net.EXE
lowDetects the stopping of a Windows service via the "net" utility.
windows · process_creation
Stop Windows Service Via PowerShell Stop-Service
lowDetects the stopping of a Windows service via the PowerShell Cmdlet "Stop-Service"
windows · process_creation
Stop Windows Service Via Sc.EXE
lowDetects the stopping of a Windows service via the "sc.exe" utility
windows · process_creation
Successful Account Login Via WMI
lowDetects successful logon attempts performed with WMI
windows · security
Successful MSIX/AppX Package Installation
lowDetects successful MSIX/AppX package installations on Windows systems by monitoring EventID 854 in the Microsoft-Windows-AppXDeployment-Server/Operational log. While most installations are legitimate, this can help identify unauthorized or suspicious package installations. It is crucial to monitor such events as threat actors may exploit MSIX/AppX packages to deliver and execute malicious payloads.
windows · appxdeployment-server
Suspicious Connection to Remote Account
lowAdversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism
windows · ps_script
Suspicious Deno File Written from Remote Source
lowDetects Deno writing a file from a direct HTTP(s) call and writing to the appdata folder or bringing it's own malicious DLL. This behavior may indicate an attempt to execute remotely hosted, potentially malicious files through deno.
windows · file_event
Suspicious Execution of Hostname
lowUse of hostname to get information
windows · process_creation
Suspicious Execution of Systeminfo
lowDetects usage of the "systeminfo" command to retrieve information
windows · process_creation
Suspicious File Access to Browser Credential Storage
lowDetects file access to browser credential storage paths by non-browser processes, which may indicate credential access attempts. Adversaries may attempt to access browser credential storage to extract sensitive information such as usernames and passwords or cookies. This behavior is often commonly observed in credential stealing malware.
windows · file_access
Suspicious Get Information for SMB Share
lowAdversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
windows · ps_script
Suspicious Get Information for SMB Share - PowerShell Module
lowAdversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
windows · ps_module
Suspicious Get Local Groups Information
lowDetects the use of PowerShell modules and cmdlets to gather local group information. Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
windows · ps_module
Suspicious Get Local Groups Information - PowerShell
lowDetects the use of PowerShell modules and cmdlets to gather local group information. Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
windows · ps_script
Suspicious GPO Discovery With Get-GPO
lowDetect use of Get-GPO to get one GPO or all the GPOs in a domain.
windows · ps_script
Suspicious Mount-DiskImage
lowAdversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.
windows · ps_script
Suspicious Network Command
lowAdversaries may look for details about the network configuration and settings of systems they access or through information discovery of remote systems
windows · process_creation
Suspicious PowerShell Get Current User
lowDetects the use of PowerShell to identify the current logged user.
windows · ps_script
Suspicious Process Discovery With Get-Process
lowGet the processes that are running on the local computer.
windows · ps_script
Suspicious Query of MachineGUID
lowUse of reg to get MachineGuid information
windows · process_creation
Suspicious SSL Connection
lowAdversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
windows · ps_script
Suspicious Where Execution
lowAdversaries may enumerate browser bookmarks to learn more about compromised hosts. Browser bookmarks may reveal personal information about users (ex: banking sites, interests, social media, etc.) as well as details about internal network resources such as servers, tools/dashboards, or other related infrastructure.
windows · process_creation
Sysinternals Tools AppX Versions Execution
lowDetects execution of Sysinternals tools via an AppX package. Attackers could install the Sysinternals Suite to get access to tools such as psexec and procdump to avoid detection based on System paths.
windows · appmodel-runtime
System Drawing DLL Load
lowDetects processes loading "System.Drawing.ni.dll". This could be an indicator of potential Screen Capture.
windows · image_load
System Information Discovery via Registry Queries
lowDetects attempts to query system information directly from the Windows Registry.
windows · process_creation
System Information Discovery Via Wmic.EXE
lowDetects the use of the WMI command-line (WMIC) utility to identify and display various system information, including OS, CPU, GPU, disk drive names, memory capacity, display resolution, baseboard, BIOS, and GPU driver products/versions.
windows · process_creation
System Network Connections Discovery Via Net.EXE
lowAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
windows · process_creation
Tap Driver Installation - Security
lowDetects the installation of a well-known TAP driver service. This could be a sign of potential preparation for data exfiltration using tunnelling techniques.
windows · security
Task Scheduler DLL Loaded By Application Located In Potentially Suspicious Location
lowDetects the loading of the "taskschd.dll" module from a process that located in a potentially suspicious or uncommon directory. The loading of this DLL might indicate that the application have the capability to create a scheduled task via the "Schedule.Service" COM object. Investigation of the loading application and its behavior is required to determining if its malicious.
windows · image_load
TeamViewer Log File Deleted
lowDetects the deletion of the TeamViewer log files which may indicate an attempt to destroy forensic evidence
windows · file_delete
The Windows Defender Firewall Service Failed To Load Group Policy
lowDetects activity when The Windows Defender Firewall service failed to load Group Policy
windows · firewall-as
Unattend.XML File Access Attempt
lowDetects attempts to access the "unattend.xml" file, where credentials might be stored. This file is used during the unattended windows install process.
windows · file_access
Unauthorized System Time Modification
lowDetect scenarios where a potentially unauthorized application or user is modifying the system time.
windows · security
Uncommon Process Access Rights For Target Image
lowDetects process access request to uncommon target images with a "PROCESS_ALL_ACCESS" access mask.
windows · process_access
Unmount Share Via Net.EXE
lowDetects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation
windows · process_creation
Unusually Long PowerShell CommandLine
lowDetects unusually long PowerShell command lines with a length of 1000 characters or more
windows · process_creation
USB Device Plugged
lowDetects plugged/unplugged USB devices
windows · driver-framework
Use Get-NetTCPConnection
lowAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
windows · ps_classic_start
Use Get-NetTCPConnection - PowerShell Module
lowAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
windows · ps_module
Use Of Remove-Item to Delete File - ScriptBlock
lowPowerShell Remove-Item with -Path to delete a file or a folder with "-Recurse"
windows · ps_script
User with Privileges Logon
lowDetects logon with "Special groups" and "Special Privileges" can be thought of as Administrator groups or privileges.
windows · security
Userdomain Variable Enumeration
lowDetects suspicious enumeration of the domain the user is associated with.
windows · process_creation
Virtualbox Driver Installation or Starting of VMs
lowAdversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.
windows · process_creation
Volume Shadow Copy Mount
lowDetects volume shadow copy mount via Windows event log
windows · system
Vulnerable Driver Load By Name
lowDetects the load of known vulnerable drivers via the file name of the drivers.
windows · driver_load
Windows Defender Firewall Has Been Reset To Its Default Configuration
lowDetects activity when Windows Defender Firewall has been reset to its default configuration
windows · firewall-as
Windows Defender Submit Sample Feature Disabled
lowDetects disabling of the "Automatic Sample Submission" feature of Windows Defender.
windows · windefend
Windows Event Auditing Disabled
lowDetects scenarios where system auditing (i.e.: Windows event log auditing) is disabled. This may be used in a scenario where an entity would want to bypass local logging to evade detection when Windows event logging is enabled and reviewed. Also, it is recommended to turn off "Local Group Policy Object Processing" via GPO, which will make sure that Active Directory GPOs take precedence over local/edited computer policies via something such as "gpedit.msc". Please note, that disabling "Local Group Policy Object Processing" may cause an issue in scenarios of one off specific GPO modifications - however, it is recommended to perform these modifications in Active Directory anyways.
windows · security
Windows Firewall Settings Have Been Changed
lowDetects activity when the settings of the Windows firewall have been changed
windows · firewall-as
Windows MSIX Package Support Framework AI_STUBS Execution
lowDetects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.
windows · process_creation
Windows Processes Suspicious Parent Directory
lowDetect suspicious parent processes of well-known Windows processes
windows · process_creation
Windows Service Terminated With Error
lowDetects Windows services that got terminated for whatever reason
windows · system
Windows Share Mount Via Net.EXE
lowDetects when a share is mounted using the "net.exe" utility
windows · process_creation
Winget Admin Settings Modification
lowDetects changes to the AppInstaller (winget) admin settings. Such as enabling local manifest installations or disabling installer hash checks
windows · registry_set
WMI Module Loaded By Uncommon Process
lowDetects WMI modules being loaded by an uncommon process
windows · image_load
Failed Code Integrity Checks
informationalDetects code integrity failures such as missing page hashes or corrupted drivers due unauthorized modification. This could be a sign of tampered binaries.
windows · security
Locked Workstation
informationalDetects locked workstation session events that occur automatically after a standard period of inactivity.
windows · security
New Application in AppCompat
informationalA General detection for a new application in AppCompat. This indicates an application executing for the first time on an endpoint.
windows · registry_set
New PowerShell Instance Created
informationalDetects the execution of PowerShell via the creation of a named pipe starting with PSHost
windows · pipe_created
Potential BOINC Software Execution (UC-Berkeley Signature)
informationalDetects the use of software that is related to the University of California, Berkeley via metadata information. This indicates it may be related to BOINC software and can be used maliciously if unauthorized.
windows · process_creation
PowerShell Decompress Commands
informationalA General detection for specific decompress commands in PowerShell logs. This could be an adversary decompressing files.
windows · ps_module
Suspicious High IntegrityLevel Conhost Legacy Option
informationalForceV1 asks for information directly from the kernel space. Conhost connects to the console application. High IntegrityLevel means the process is running with elevated privileges, such as an Administrator context.
windows · process_creation
Suspicious Tasklist Discovery Command
informationalAdversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network
windows · process_creation
User Logoff Event
informationalDetects a user log-off activity. Could be used for example to correlate information during forensic investigations
windows · security
VSSAudit Security Event Source Registration
informationalDetects the registration of the security event source VSSAudit. It would usually trigger when volume shadow copy operations happen.
windows · security
Windows Defender Malware Detection History Deletion
informationalWindows Defender logs when the history of detected infections is deleted.
windows · windefend
Windows Spooler Service Suspicious Binary Load
informationalDetect DLL Load from Spooler Service backup folder. This behavior has been observed during the exploitation of the Print Spooler Vulnerability CVE-2021-1675 and CVE-2021-34527 (PrinterNightmare).
windows · image_load
Windows Update Error
informationalDetects Windows update errors including installation failures and connection issues. Defenders should observe this in case critical update KBs aren't installed.
windows · system