Command and Scripting Interpreter T1059
Tactic: Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Events covered
76 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 1093 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (351 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (9332 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (2291 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 425 rules
- Abusable DLL Potential Sideloading From Suspicious Location
- Add Insecure Download Source To Winget
- Add New Download Source To Winget
- Add Potential Suspicious New Download Source To Winget
- Adwind RAT / JRAT
- Adwind RAT / JRAT File Artifact
- Alternate PowerShell Hosts - PowerShell Module
- Alternate PowerShell Hosts Pipe
- AppLocker Prevented Application or Script from Running
- Atlassian Confluence CVE-2022-26134
- Atomic MacOS Stealer - FileGrabber Activity
- AWS EC2 Startup Shell Script Change
- AWS IAM S3Browser LoginProfile Creation
- AWS IAM S3Browser Templated S3 Bucket Policy Creation
- AWS IAM S3Browser User or AccessKey Creation
- Axios NPM Compromise Indicators - Linux
- Axios NPM Compromise Indicators - macOS
- Axios NPM Compromise Indicators - Windows
- Azure New CloudShell Created
- Bad Opsec Powershell Code Artifacts
- Base64 Encoded PowerShell Command Detected
- BloodHound Collection Files
- BPFDoor Abnormal Process ID or Lock File Accessed
- BPFtrace Unsafe Option Usage
- bXOR Operator Usage In PowerShell Command Line - PowerShell Classic
- Capsh Shell Invocation - Linux
- Certificate Exported Via PowerShell
- Change PowerShell Policies to an Insecure Level
- Change PowerShell Policies to an Insecure Level - PowerShell
- ChromeLoader Malware Execution
- Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
- Clipboard Access Via OSAScript
- Cmd.EXE Missing Space Characters Execution Anomaly
- Command Line Execution with Suspicious URL and AppData Strings
- Conhost Spawned By Uncommon Parent Process
- Conhost.exe CommandLine Path Traversal
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Csc.EXE Execution Form Potentially Suspicious Parent
- Cscript/Wscript Uncommon Script Extension Execution
- CVE-2022-24527 Microsoft Connected Cache LPE
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
- DarkGate - Autoit3.EXE Execution Parameters
- DarkGate - Autoit3.EXE File Creation By Uncommon Process
- DarkGate - Drop DarkGate Loader In C:\Temp Directory
- Detection of PowerShell Execution via Sqlps.exe
- DNS Query by Finger Utility
- DSInternals Suspicious PowerShell Cmdlets
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock
- Elevated System Shell Spawned
- Elevated System Shell Spawned From Uncommon Parent Location
- Elise Backdoor Activity
- Emotet Loader Execution Via .LNK File
- Encoded PowerShell payload deployed (PowerShell)
- Encoded PowerShell payload deployed via process execution
- Equation Group Indicators
- ESXi Account Creation Via ESXCLI
- ESXi Admin Permission Assigned To Account Via ESXCLI
- ESXi Network Configuration Discovery Via ESXCLI
- ESXi Storage Information Discovery Via ESXCLI
- ESXi Syslog Configuration Change Via ESXCLI
- ESXi System Information Discovery Via ESXCLI
- ESXi VM Kill Via ESXCLI
- ESXi VM List Discovery Via ESXCLI
- ESXi VSAN Information Discovery Via ESXCLI
- Exchange PowerShell Snap-Ins Usage
- Execute Code with Pester.bat
- Execute Code with Pester.bat as Parent
- Execution of Powershell Script in Public Folder
- Exploited CVE-2020-10189 Zoho ManageEngine
- Exploiting SetupComplete.cmd CVE-2019-1378
- FakeUpdates/SocGholish Activity
- Forfiles Command Execution
- Greenbug Espionage Group Indicators
- HackTool - Bloodhound/Sharphound Execution
- HackTool - CACTUSTORCH Remote Thread Creation
- HackTool - Covenant PowerShell Launcher
- HackTool - CrackMapExec Execution
- HackTool - CrackMapExec Execution Patterns
- HackTool - CrackMapExec PowerShell Obfuscation
- HackTool - Default PowerSploit/Empire Scheduled Task Creation
- HackTool - Empire PowerShell Launch Parameters
- HackTool - Jlaive In-Memory Assembly Execution
- HackTool - Koadic Execution
- HackTool - NetExec File Indicators
- HackTool - RedMimicry Winnti Playbook Execution
- HackTool - Sliver C2 Implant Activity Pattern
- HackTool - Stracciatella Execution
- Hacktool Ruler
- Headless Process Launched Via Conhost.EXE
- Hidden Powershell in Link File Pattern
- HTML Help HH.EXE Suspicious Child Process
- Import PowerShell Modules From Suspicious Directories
- Import PowerShell Modules From Suspicious Directories - ProcCreation
- Inline Python Execution - Spawn Shell Via OS System Library
- Install New Package Via Winget Local Manifest
- Installation of WSL Kali-Linux
- Interactive Bash Suspicious Children
- Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
- Invoke-Obfuscation CLIP+ Launcher
- Invoke-Obfuscation CLIP+ Launcher - PowerShell
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
- Invoke-Obfuscation CLIP+ Launcher - Security
- Invoke-Obfuscation CLIP+ Launcher - System
- Invoke-Obfuscation COMPRESS OBFUSCATION
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security
- Invoke-Obfuscation COMPRESS OBFUSCATION - System
- Invoke-Obfuscation Obfuscated IEX Invocation
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
- Invoke-Obfuscation RUNDLL LAUNCHER - Security
- Invoke-Obfuscation RUNDLL LAUNCHER - System
- Invoke-Obfuscation STDIN+ Launcher
- Invoke-Obfuscation STDIN+ Launcher - Powershell
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
- Invoke-Obfuscation STDIN+ Launcher - Security
- Invoke-Obfuscation STDIN+ Launcher - System
- Invoke-Obfuscation VAR+ Launcher
- Invoke-Obfuscation VAR+ Launcher - PowerShell
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module
- Invoke-Obfuscation VAR+ Launcher - Security
- Invoke-Obfuscation VAR+ Launcher - System
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
- Invoke-Obfuscation Via Stdin
- Invoke-Obfuscation Via Stdin - Powershell
- Invoke-Obfuscation Via Stdin - PowerShell Module
- Invoke-Obfuscation Via Stdin - Security
- Invoke-Obfuscation Via Stdin - System
- Invoke-Obfuscation Via Use Clip
- Invoke-Obfuscation Via Use Clip - Powershell
- Invoke-Obfuscation Via Use Clip - PowerShell Module
- Invoke-Obfuscation Via Use Clip - Security
- Invoke-Obfuscation Via Use Clip - System
- Invoke-Obfuscation Via Use MSHTA
- Invoke-Obfuscation Via Use MSHTA - PowerShell
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module
- Invoke-Obfuscation Via Use MSHTA - Security
- Invoke-Obfuscation Via Use MSHTA - System
- Invoke-Obfuscation Via Use Rundll32 - PowerShell
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
- Invoke-Obfuscation Via Use Rundll32 - Security
- Invoke-Obfuscation Via Use Rundll32 - System
- JexBoss Command Sequence
- JXA In-memory Execution Via OSAScript
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution
- Lace Tempest PowerShell Evidence Eraser
- Lace Tempest PowerShell Launcher
- Lazarus Group Activity
- Linux Reverse Shell Indicator
- Linux Suspicious Child Process from Node.js - React2Shell
- macOS Network Utility Tools for C2
- MacOS Scripting Interpreter AppleScript
- Malicious Base64 Encoded PowerShell Keywords in Command Lines
- Malicious Nishang PowerShell Commandlets
- Malicious PowerShell Commandlets - PoshModule
- Malicious PowerShell Commandlets - ProcessCreation
- Malicious PowerShell Commandlets - ScriptBlock
- Malicious PowerShell Keywords
- Malicious PowerShell Scripts - FileCreation
- Malicious PowerShell Scripts - PoshModule
- Malicious ShellIntel PowerShell Commandlets
- Manual Execution of Script Inside of a Compressed File
- MERCURY APT Activity
- Metasploit reverse shell injection in SQL Server
- MMC Loading Script Engines DLLs
- MSHTA Execution with Suspicious File Extensions
- Net WebClient Casing Anomalies
- Netcat The Powershell Version
- Network Connection Initiated By PowerShell Process
- Network Connection Initiated via Finger.EXE
- New PowerShell Instance Created
- Node Process Executions
- NodeJS Execution of JavaScript File
- Nohup Execution
- Non Interactive PowerShell Process Spawned
- Nslookup PowerShell Download Cradle
- NTFS Alternate Data Stream
- Obfuscated PowerShell MSI Install via WindowsInstaller COM
- Obfuscated PowerShell OneLiner Execution
- OpenEDR Spawning Command Shell
- Operation Wocao Activity
- Operation Wocao Activity - Security
- Operator Bloopers Cobalt Strike Commands
- Operator Bloopers Cobalt Strike Modules
- Osacompile Execution By Potentially Suspicious Applet/Osascript
- OSACompile Run-Only Execution
- Outlook EnableUnsafeClientMailRules Setting Enabled
- Payload Decoded and Decrypted via Built-in Utilities
- Payload downloaded via PowerShell
- PCRE.NET Package Image Load
- PCRE.NET Package Temp Files
- Perl Inline Command Execution
- Php Inline Command Execution
- PipeShell exfiltration over named pipes
- Potential Abuse of Linux Magic System Request Key
- Potential APT FIN7 Exploitation Activity
- Potential APT FIN7 POWERHOLD Execution
- Potential APT10 Cloud Hopper Activity
- Potential Arbitrary Command Execution Via FTP.EXE
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
- Potential Baby Shark Malware Activity
- Potential BlackByte Ransomware Activity
- Potential Bumblebee Remote Thread Creation
- Potential CobaltStrike Process Patterns
- Potential CommandLine Path Traversal Via Cmd.EXE
- Potential CVE-2021-40444 Exploitation Attempt
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
- Potential Data Exfiltration Activity Via CommandLine Tools
- Potential DLL File Download Via PowerShell Invoke-WebRequest
- Potential Dosfuscation Activity
- Potential Dropper Script Execution Via WScript/CScript/MSHTA
- Potential Emotet Activity
- Potential Encoded PowerShell Patterns In CommandLine
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
- Potential Exploitation of GoAnywhere MFT Vulnerability
- Potential In-Memory Download And Compile Of Payloads
- Potential KamiKakaBot Activity - Lure Document Execution
- Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE
- Potential Netcat Reverse Shell Execution
- Potential Persistence Via Powershell Search Order Hijacking - Task
- Potential Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
- Potential PowerShell Command Line Obfuscation
- Potential PowerShell Downgrade Attack
- Potential PowerShell Obfuscation Using Alias Cmdlets
- Potential PowerShell Obfuscation Using Character Join
- Potential PowerShell Obfuscation Via Reversed Commands
- Potential PowerShell Obfuscation Via WCHAR/CHAR
- Potential Powershell ReverseShell Connection
- Potential POWERTRASH Script Execution
- Potential QBot Activity
- Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
- Potential Remote PowerShell Session Initiated
- Potential Remote SquiblyTwo Technique Execution
- Potential SAP NetWeaver Webshell Creation
- Potential SAP NetWeaver Webshell Creation - Linux
- Potential Suspicious PowerShell Keywords
- Potential WinAPI Calls Via PowerShell Scripts
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell
- Potential Xterm Reverse Shell
- Potentially Suspicious Command Executed Via Run Dialog Box - Registry
- Potentially Suspicious Execution From Parent Process In Public Folder
- Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
- Potentially Suspicious Long Filename Pattern - Linux
- Potentially Suspicious NTFS Symlink Behavior Modification
- Potentially Suspicious PowerShell Child Processes
- Potentially Suspicious Powershell Script Execution From Temp Folder
- Potentially Suspicious WebDAV LNK Execution
- PowerShell ADRecon Execution
- PowerShell Base64 Encoded FromBase64String Cmdlet
- PowerShell Base64 Encoded IEX Cmdlet
- PowerShell Base64 Encoded Invoke Keyword
- PowerShell Base64 Encoded Reflective Assembly Load
- PowerShell Base64 Encoded WMI Classes
- PowerShell Called from an Executable Version Mismatch
- PowerShell Core DLL Loaded By Non PowerShell Process
- PowerShell Create Local User
- PowerShell Credential Prompt
- PowerShell Downgrade Attack - PowerShell
- PowerShell Download and Execution Cradles
- PowerShell Download Pattern
- PowerShell Download Via Net.WebClient - PowerShell Classic
- Powershell Execute Batch Script
- Powershell Executed From Headless ConHost Process
- Powershell Inline Execution From A File
- PowerShell MSI Install via WindowsInstaller COM From Remote Location
- Powershell MsXml COM Object
- PowerShell PSAttack
- PowerShell Remote Session Creation
- PowerShell Script Run in AppData
- PowerShell ShellCode
- PowerShell Web Access Installation - PsScript
- Powershell XML Execute Command
- PowerView PowerShell Cmdlets - ScriptBlock
- Process Signal from Suspicious Parent Process
- PSAsyncShell - Asynchronous TCP Reverse Shell
- PUA - AdvancedRun Execution
- PUA - Wsudo Suspicious Execution
- Python Inline Command Execution
- Python One-Liners with Base64 Decoding
- Python One-Liners with Base64 Decoding - Linux
- Python Path Configuration File Creation - Linux
- Python Path Configuration File Creation - MacOS
- Python Path Configuration File Creation - Windows
- Python Spawning Pretty TTY on Windows
- Python Spawning Pretty TTY Via PTY Module
- Raspberry Robin Initial Execution From External Drive
- Raspberry Robin Subsequent Execution of Commands
- Read Contents From Stdin Via Cmd.EXE
- Registry Modification Attempt Via VBScript
- Registry Modification Attempt Via VBScript - PowerShell
- Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace
- Registry Tampering by Potentially Suspicious Processes
- Remote Access Tool - ScreenConnect Command Execution
- Remote Access Tool - ScreenConnect File Transfer
- Remote Access Tool - ScreenConnect Remote Command Execution
- Remote Access Tool - ScreenConnect Temporary File
- Remote LSASS Process Access Through Windows Remote Management
- Remote PowerShell Session (PS Classic)
- Remote PowerShell Session (PS Module)
- Remote PowerShell Session Host Process (WinRM)
- Remote PowerShell Sessions Network Connections (WinRM)
- Remote Thread Creation Via PowerShell
- Remote Thread Creation Via PowerShell In Uncommon Target
- Renamed CURL.EXE Execution
- Renamed FTP.EXE Execution
- Renamed NirCmd.EXE Execution
- Renamed PingCastle Binary Execution
- Renamed Powershell Under Powershell Channel
- REvil Kaseya Incident Malware Patterns
- Rorschach Ransomware Execution Activity
- Ruby Inline Command Execution
- Run PowerShell Script from Redirected Input Stream
- Scheduled Task Executing Encoded Payload from Registry
- Scheduled Task Executing Payload from Registry
- Script Interpreter Execution From Suspicious Folder
- Script Interpreter Spawning Credential Scanner - Linux
- Script Interpreter Spawning Credential Scanner - Windows
- Serial console process spawning CMD shell (via command)
- Serpent Backdoor Payload Execution Via Scheduled Task
- Shai-Hulud Malware Indicators - Linux
- Shai-Hulud Malware Indicators - Windows
- Shell Execution via Git - Linux
- Shell Execution via Rsync - Linux
- Shell Invocation via Env Command - Linux
- Shell Invocation Via Ssh - Linux
- Silence.EDA Detection
- Sofacy Trojan Loader Activity
- SQL Client Tools PowerShell Session Detection
- Suspicious Activity in Shell Commands
- Suspicious ArcSOC.exe Child Process
- Suspicious Browser Child Process - MacOS
- Suspicious Child Process Of BgInfo.EXE
- Suspicious Child Process of SAP NetWeaver
- Suspicious Child Process of SAP NetWeaver - Linux
- Suspicious Commands Linux
- Suspicious CrushFTP Child Process
- Suspicious Deno File Written from Remote Source
- Suspicious Download and Execute Pattern via Curl/Wget
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
- Suspicious Encoded PowerShell Command Line
- Suspicious Execution of Powershell with Base64
- Suspicious Execution via macOS Script Editor
- Suspicious File Characteristics Due to Missing Fields
- Suspicious File Created In PerfLogs
- Suspicious File Execution From Internet Hosted WebDav Share
- Suspicious Filename with Embedded Base64 Commands
- Suspicious Greedy Compression Using Rar.EXE
- Suspicious HH.EXE Execution
- Suspicious HWP Sub Processes
- Suspicious Installer Package Child Process
- Suspicious Interactive PowerShell as SYSTEM
- Suspicious Invocation of Shell via AWK - Linux
- Suspicious Invocation of Shell via Rsync
- Suspicious Java Children Processes
- Suspicious Microsoft Office Child Process - MacOS
- Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
- Suspicious PowerShell Download - PoshModule
- Suspicious PowerShell Download - Powershell Script
- Suspicious PowerShell Download and Execute Pattern
- Suspicious PowerShell Encoded Command Patterns
- Suspicious PowerShell IEX Execution Patterns
- Suspicious PowerShell Invocation From Script Engines
- Suspicious PowerShell Invocations - Generic
- Suspicious PowerShell Invocations - Generic - PowerShell Module
- Suspicious PowerShell Invocations - Specific
- Suspicious PowerShell Invocations - Specific - PowerShell Module
- Suspicious PowerShell Parameter Substring
- Suspicious PowerShell Parent Process
- Suspicious PrinterPorts Creation (CVE-2020-1048)
- Suspicious Process Spawned by CentreStack Portal AppPool
- Suspicious Program Names
- Suspicious RASdial Activity
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
- Suspicious Remote Child Process From Outlook
- Suspicious Reverse Shell Command Line
- Suspicious Runscripthelper.exe
- Suspicious Scan Loop Network
- Suspicious Schtasks Execution AppData Folder
- Suspicious Scripting in a WMI Consumer
- Suspicious Usage of For Loop with Recursive Directory Search in CMD
- Suspicious WSMAN Provider Image Loads
- Suspicious XOR Encoded PowerShell Command
- Sysprep on AppData Folder
- TropicTrooper Campaign November 2018
- Turla Group Commands May 2020
- Turla Group Lateral Movement
- UNC2452 PowerShell Pattern
- UNC2452 Process Creation Patterns
- Uncommon Child Process Of BgInfo.EXE
- Uncommon PowerShell Hosts
- Unusual Parent Process For Cmd.EXE
- Unusually Long PowerShell CommandLine
- Ursnif Redirection Of Discovery Commands
- Usage Of Web Request Commands And Cmdlets
- Usage Of Web Request Commands And Cmdlets - ScriptBlock
- Use of FSharp Interpreters
- Use of OpenConsole
- Use of Pcalua For Execution
- Vice Society directory crawling script for data exfiltration (via ps_script)
- Vim GTFOBin Abuse - Linux
- VMToolsd Suspicious Child Process
- WinAPI Function Calls Via PowerShell Scripts
- WinAPI Library Calls Via PowerShell Scripts
- Windows Defender AMSI Trigger Detected
- Windows Defender Exclusions Added - PowerShell
- Windows Defender Threat Detected
- Windows Shell/Scripting Application File Write to Suspicious Folder
- Windows Shell/Scripting Processes Spawning Suspicious Programs
- Windows Suspicious Child Process from Node.js - React2Shell
- WMImplant Hack Tool
- Writing Of Malicious Files To The Fonts Folder
- WScript or CScript Dropper - File
- Wscript Shell Run In CommandLine
- WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
- XSL Script Execution Via WMIC.EXE
- ZxShell Malware
Elastic 306 rules
- Anomalous React Server Components Flight Data Patterns
- Anomalous Windows Process Creation
- Apple Script Execution followed by Network Connection
- Apple Scripting Execution with Administrator Privileges
- Attempt to Install or Run Kali Linux via WSL
- AWS CloudShell Environment Created
- AWS EC2 LOLBin Execution via SSM SendCommand
- AWS EC2 Stop, Start, and User Data Modification Correlation
- AWS SSM `SendCommand` with Run Shell Command Parameters
- AWS SSM Session Manager Child Process Execution
- Azure Run Command Correlated with Process Execution
- Azure Run Command Script Child Process
- Base64 Decoded Payload Piped to Interpreter
- Binary Content Copy via Cmd.exe
- Binary Executed from Shared Memory Directory
- Boot File Copy
- BPF filter applied using TC
- Clearing Windows Console History
- Command and Scripting Interpreter via Windows Scripts
- Command Execution via SolarWinds Process
- Command Line Obfuscation via Whitespace Padding
- Command Shell Activity Started via RunDLL32
- Conhost Spawned By Suspicious Parent Process
- Creation of Hidden Login Item via Apple Script
- Cupsd or Foomatic-rip Shell Execution
- Curl Execution via Shell Profile
- Curl or Wget Egress Network Connection via LoLBin
- Decoded Payload Piped to Interpreter Detected via Defend for Containers
- Delayed Execution via Ping
- Deprecated - EggShell Backdoor Execution
- Deprecated - Microsoft Exchange Transport Agent Install Script
- Deprecated - Potential PowerShell Obfuscated Script
- Deprecated - PowerShell Script with Discovery Capabilities
- Deprecated - PowerShell Script with Remote Execution Capabilities via WinRM
- Deprecated - Uncommon Destination Port Connection by Web Server
- Deprecated - Unusual Command Execution from Web Server Parent
- Deprecated - Unusual Process Spawned from Web Server Parent
- Direct Interactive Kubernetes API Request by Common Utilities
- Direct Interactive Kubernetes API Request by Unusual Utilities
- Direct Interactive Kubernetes API Request Detected via Defend for Containers
- Disabling Windows Defender Security Settings via PowerShell
- Dracut Module Creation
- Dynamic IEX Reconstruction via Method String Access
- Dynamic Linker (ld.so) Creation
- Egress Connection from Entrypoint in Container
- Encoded Payload Detected via Defend for Containers
- Entra ID PowerShell Sign-in
- Execution from Unusual Directory - Command Line
- Execution of a Downloaded Windows Script
- Execution of Persistent Suspicious Program
- Execution via Electron Child Process Node.js Module
- Execution via GitHub Actions Runner
- Execution via MS VisualStudio Pre/Post Build Events
- Execution via MSSQL xp_cmdshell Stored Procedure
- Execution via OpenClaw Agent
- Execution via Windows Subsystem for Linux
- Execution with Explicit Credentials via Scripting
- Exporting Exchange Mailbox via PowerShell
- File Creation and Execution Detected via Defend for Containers
- File Creation by Cups or Foomatic-rip Child
- File Creation in /var/log via Suspicious Process
- File Creation, Execution and Self-Deletion in Suspicious Directory
- File Download Detected via Defend for Containers
- File Execution Permission Modification Detected via Defend for Containers
- File Transfer or Listener Established via Netcat
- File Transfer Utility Launched from Unusual Parent
- First Time Python Spawned a Shell on Host
- Forbidden Direct Interactive Kubernetes API Request
- GenAI or MCP Server Child Process Execution
- Git Hook Child Process
- Git Hook Command Execution
- Git Hook Created or Modified
- Git Hook Egress Network Connection
- GitHub Actions Unusual Bot Push to Repository
- GitHub Actions Workflow Modification Blocked
- Github Activity on a Private Repository from an Unusual IP
- GitHub Authentication Token Access via Node.js
- Google Calendar C2 via Script Interpreter
- Host File System Changes via Windows Subsystem for Linux
- Incoming Execution via PowerShell Remoting
- Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers
- Initramfs Unpacking via unmkinitramfs
- Interactive Exec Into Container Detected via Defend for Containers
- Interactive Shell Launched via Unusual Parent Process in a Container
- Interactive Shell Spawn Detected via Defend for Containers
- Interactive Terminal Spawned via Perl
- Interactive Terminal Spawned via Python
- Kill Command Execution
- Kubernetes Direct API Request via Curl or Wget
- Kubernetes Pod Exec Potential Reverse Shell
- Linux Restricted Shell Breakout via Linux Binary(s)
- Long Base64 Encoded Command via Scripting Interpreter
- M365 Security Compliance Admin Signal
- M365 SharePoint/OneDrive File Access via PowerShell
- Manual Dracut Execution
- Memory Swap Modification
- Microsoft Build Engine Started an Unusual Process
- Microsoft Build Engine Started by a Script Process
- Microsoft Exchange Worker Spawning Suspicious Processes
- Microsoft Management Console File from Unusual Path
- Multi-Base64 Decoding Attempt from Suspicious Location
- Netcat File Transfer or Listener Detected via Defend for Containers
- Netcat Listener Established via rlwrap
- Network Connection by Cups or Foomatic-rip Child
- Network Connection from Binary with RWX Memory Region
- Network Connection to OAST Domain via Script Interpreter
- Network Connection via Recently Compiled Executable
- Network Connections Initiated Through XDG Autostart Entry
- NetworkManager Dispatcher Script Creation
- New ActiveSyncAllowedDeviceID Added via PowerShell
- Node.js Pre or Post-Install Script Execution
- Openssl Client or Server Activity
- Outbound Scheduled Task Activity via PowerShell
- Payload Execution via Shell Pipe Detected by Defend for Containers
- Perl Outbound Network Connection
- Persistence via Folder Action Script
- Pod or Container Creation with Suspicious Command-Line
- Potential Antimalware Scan Interface Bypass via PowerShell
- Potential Backdoor Execution Through PAM_EXEC
- Potential Code Execution via Postgresql
- Potential Command Shell via NetCat
- Potential Direct Kubelet Access via Process Arguments
- Potential Direct Kubelet Access via Process Arguments Detected via Defend for Containers
- Potential Dynamic IEX Reconstruction via Environment Variables
- Potential Etherhiding C2 via Blockchain Connection
- Potential Execution via FileFix Phishing Attack
- Potential Execution via SSH Backdoor
- Potential Fake CAPTCHA Phishing Attack
- Potential Git CVE-2025-48384 Exploitation
- Potential Hex Payload Execution via Command-Line
- Potential Hex Payload Execution via Common Utility
- Potential JAVA/JNDI Exploitation Attempt
- Potential Kubeletctl Execution
- Potential Kubeletctl Execution Detected via Defend for Containers
- Potential Malicious PowerShell Based on Alert Correlation
- Potential Malware-Driven SSH Brute Force Attempt
- Potential Meterpreter Reverse Shell
- Potential PowerShell HackTool Script by Author
- Potential PowerShell HackTool Script by Function Names
- Potential PowerShell Obfuscated Script via High Entropy
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
- Potential PowerShell Obfuscation via Character Array Reconstruction
- Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation
- Potential PowerShell Obfuscation via High Numeric Character Proportion
- Potential PowerShell Obfuscation via High Special Character Proportion
- Potential PowerShell Obfuscation via Invalid Escape Sequences
- Potential PowerShell Obfuscation via Reverse Keywords
- Potential PowerShell Obfuscation via Special Character Overuse
- Potential PowerShell Obfuscation via String Concatenation
- Potential PowerShell Obfuscation via String Reordering
- Potential PowerShell Pass-the-Hash/Relay Script
- Potential Privilege Escalation via Python cap_setuid
- Potential Process Injection via PowerShell
- Potential Reverse Shell
- Potential Reverse Shell Activity via Terminal
- Potential Reverse Shell via Background Process
- Potential Reverse Shell via Child
- Potential Reverse Shell via Java
- Potential Reverse Shell via Suspicious Binary
- Potential Reverse Shell via Suspicious Child Process
- Potential Reverse Shell via UDP
- Potential SAP NetWeaver Exploitation
- Potential SAP NetWeaver WebShell Creation
- Potential SharpRDP Behavior
- Potential Shell via Wildcard Injection Detected
- Potential Upgrade of Non-interactive Shell
- Potential Veeam Credential Access Command
- Potentially Suspicious Process Started via tmux or screen
- PowerShell Invoke-NinjaCopy script
- PowerShell Kerberos Ticket Dump
- PowerShell Kerberos Ticket Request
- PowerShell Keylogging Script
- PowerShell Mailbox Collection Script
- PowerShell MiniDump Script
- PowerShell Obfuscation via Negative Index String Reversal
- PowerShell PSReflect Script
- PowerShell Script with Archive Compression Capabilities
- PowerShell Script with Log Clear Capabilities
- PowerShell Script with Password Policy Discovery Capabilities
- PowerShell Script with Token Impersonation Capabilities
- PowerShell Script with Veeam Credential Access Capabilities
- PowerShell Script with Webcam Video Capture Capabilities
- PowerShell Script with Windows Defender Tampering Capabilities
- PowerShell Share Enumeration Script
- PowerShell Suspicious Discovery Related Windows API Functions
- PowerShell Suspicious Payload Encoded and Compressed
- PowerShell Suspicious Script with Audio Capture Capabilities
- PowerShell Suspicious Script with Clipboard Retrieval Capabilities
- PowerShell Suspicious Script with Screenshot Capabilities
- Printer User (lp) Shell Execution
- Privileged Container Creation with Host Directory Mount
- Privileged Docker Container Creation
- Process Activity via Compiled HTML File
- Process Backgrounded by Unusual Parent
- Process Spawned from Message-of-the-Day (MOTD)
- Process Started from Process ID (PID) File
- Process Started with Executable Stack
- Prompt for Credentials with Osascript
- Proxy Execution via Console Window Host
- Proxy Shell Execution via Busybox
- Python Path File (pth) Creation
- Python Site or User Customize File Creation
- Rare Powershell Script
- React2Shell (CVE-2025-55182) Exploitation Attempt
- React2Shell Network Security Alert
- Remote File Download via PowerShell
- Remote File Download via Script Interpreter
- Remote GitHub Actions Runner Registration
- Remote XSL Script Execution via COM
- Renamed Automation Script Interpreter
- Root Network Connection via GDB CAP_SYS_PTRACE
- ROT Encoded Python Script Execution
- Scheduled Task Created by a Windows Script
- ScreenConnect Server Spawning Suspicious Processes
- Script Execution via Microsoft HTML Application
- Script Interpreter Connection to Non-Standard Port
- Service Account Token or Certificate Access Followed by Kubernetes API Request
- Service Control Spawned via Script Interpreter
- Shell Execution via Apple Scripting
- Simple HTTP Web Server Connection
- Simple HTTP Web Server Creation
- Suspicious .NET Code Compilation
- Suspicious .NET Reflection via PowerShell
- Suspicious APT Package Manager Execution
- Suspicious APT Package Manager Network Connection
- Suspicious Automator Workflows Execution
- Suspicious AWS S3 Connection via Script Interpreter
- Suspicious Browser Child Process
- Suspicious Child Execution via Web Server
- Suspicious Cmd Execution via WMI
- Suspicious Command Execution via Web Server
- Suspicious Command Prompt Network Connection
- Suspicious Content Extracted or Decompressed via Funzip
- Suspicious Curl to Jamf Endpoint
- Suspicious Data Encryption via OpenSSL Utility
- Suspicious Echo or Printf Execution Detected via Defend for Containers
- Suspicious Emond Child Process
- Suspicious Execution from a Mounted Device
- Suspicious Execution from VS Code Extension
- Suspicious Execution via Windows Subsystem for Linux
- Suspicious Execution with NodeJS
- Suspicious Explorer Child Process
- Suspicious File Creation via Pkg Install Script
- Suspicious File Made Executable via Chmod Inside A Container
- Suspicious Installer Package Spawns Network Event
- Suspicious Interpreter Execution Detected via Defend for Containers
- Suspicious JavaScript Execution via Deno
- Suspicious JetBrains TeamCity Child Process
- Suspicious macOS MS Office Child Process
- Suspicious Microsoft HTML Application Child Process
- Suspicious Mining Process Creation Event
- Suspicious MS Office Child Process
- Suspicious MS Outlook Child Process
- Suspicious Named Pipe Creation
- Suspicious Network Connection via systemd
- Suspicious Path Invocation from Command Line
- Suspicious Portable Executable Encoded in Powershell Script
- Suspicious PowerShell Engine ImageLoad
- Suspicious Powershell Script
- Suspicious Process Execution Detected via Defend for Containers
- Suspicious Python Shell Command Execution
- Suspicious React Server Child Process
- Suspicious ScreenConnect Client Child Process
- Suspicious Script Object Execution
- Suspicious Shell Execution via Velociraptor
- Suspicious SolarWinds Web Help Desk Java Module Load or Child Process
- Suspicious System Commands Executed by Previously Unknown Executable
- Suspicious Windows Command Shell Arguments
- Suspicious Windows Powershell Arguments
- Suspicious Zoom Child Process
- Svchost spawning Cmd
- System Binary Path File Permission Modification
- System Information Discovery via Windows Command Shell
- System Path File Creation and Execution Detected via Defend for Containers
- System Shells via Services
- Systemd Shell Execution During Boot
- Tampering with RUNNER_TRACKING_ID in GitHub Actions Runners
- Unknown Execution of Binary with RWX Memory Region
- Unusual Base64 Encoding/Decoding Activity
- Unusual Child Execution via Web Server
- Unusual Command Execution via Web Server
- Unusual D-Bus Daemon Child Process
- Unusual Execution from Kernel Thread (kthreadd) Parent
- Unusual Exim4 Child Process
- Unusual File Creation by Web Server
- Unusual Interactive Shell Launched from System User
- Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments
- Unusual Library Load via Python
- Unusual Parent Process for cmd.exe
- Unusual Pkexec Execution
- Unusual Process For MSSQL Service Accounts
- Veeam Backup Library Loaded by Unusual Process
- Volume Shadow Copy Deletion via PowerShell
- Web Server Exploitation Detected via Defend for Containers
- Web Server Potential Command Injection Request
- Web Server Potential SQL Injection Request
- Web Server Spawned via Python
- Web Shell Detection: Script Process Child of Common Web Processes
- Windows Defender Exclusions Added via PowerShell
- Windows Firewall Disabled via PowerShell
- Windows Script Executing PowerShell
- Windows Script Execution from Archive
- Windows Script Interpreter Executing Process via WMI
- Windows Server Update Service Spawning Suspicious Processes
- Windows Subsystem for Linux Distribution Installed
- Windows System Information Discovery
Splunk 280 rules
- 1 or 2 Character Executable (Windows Event Log)
- AutoHotkey Execution (PowerShell)
- AutoHotkey Execution (Sysmon)
- AutoHotkey Execution (Windows Event Log)
- AutoIt Execution (PowerShell)
- AutoIt Execution (Sysmon)
- AutoIt Execution (Windows Event Log)
- Bypass or Unrestricted PowerShell Execution (PowerShell)
- Cisco IOS XE Guestshell Activation and Destroy
- Cisco IOS XE Request Platform Package Describe Shell Pattern
- Cisco NVM - Installation of Typosquatted Python Package
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Cisco NVM - Suspicious File Download via Headless Browser
- Cisco Secure Firewall - Binary File Type Download
- Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt
- Cisco Secure Firewall - Communication Over Suspicious Ports
- Cisco Secure Firewall - High Volume of Intrusion Events Per Host
- Cisco Secure Firewall - Possibly Compromised Host
- Cisco Secure Firewall - Privileged Command Execution via HTTP
- Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity
- Cisco Secure Firewall - Wget or Curl Download
- CMD Carry Out String Command Parameter
- CMD Echo Pipe - Escalation
- CMD execution with _c (PowerShell)
- CMD execution with _c (Sysmon)
- CMD execution with _c (Windows Event Log)
- Command Line .cmd Execution (Sysmon)
- Command Line .cmd Execution (Windows Event Log)
- Command Line Spawned by Archive Utility - Windows (Sysmon)
- Command Line Spawned by Archive Utility - Windows (Windows Event Log)
- Command Line Utility Added to Accessibility Features (PowerShell)
- Command Line Utility Added to Accessibility Features (Sysmon)
- Command Line Utility Added to Accessibility Features (Windows Event Log)
- Command Output Redirected to Localhost (Windows Event Log)
- Command-Line Interface Execution (PowerShell)
- Command-Line Interface Execution (Sysmon)
- Command-Line Interface Execution (Windows Event Log)
- Common Exchange Recon cmdlets (PowerShell)
- Common Reconnaissance Commands (PowerShell)
- Common Reconnaissance Commands (Sysmon)
- Common Reconnaissance Commands (Windows Event Log)
- Conhost.exe Kernel call (Sysmon)
- Conhost.exe Kernel call (Windows Event Log)
- Consent.exe Suspicious Child Process (Sysmon)
- Consent.exe Suspicious Child Process (Windows Event Log)
- CrushFTP Authentication Bypass Exploitation
- Detect Certify With PowerShell Script Block Logging
- Detect Empire with PowerShell Script Block Logging
- Detect Mimikatz With PowerShell Script Block Logging
- Detect Outbound LDAP Traffic
- Detect Prohibited Applications Spawning cmd exe
- Detect Use of cmd exe to Launch Script Interpreters
- Encoded Powershell Command (PowerShell)
- Encoded Powershell Command (Sysmon)
- Encoded Powershell Command (Windows Event Log)
- ESXi Reverse Shell Patterns
- Excessive distinct processes from Windows Temp
- Excessive number of taskhost processes
- Exchange PowerShell Module Usage
- Executable Create Script Process (PowerShell)
- Executable Create Script Process (Sysmon)
- Executable Create Script Process (Windows Event Log)
- Executable Process from Suspicious Folder (PowerShell)
- Executable Process from Suspicious Folder (Sysmon)
- Executable Process from Suspicious Folder (Windows Event Log)
- Execute Javascript With Jscript COM CLSID
- Explorer Child Process with Suspicious Command Line Padding (Sysmon)
- Get-ForestTrust with PowerShell Script Block
- GetLocalUser with PowerShell Script Block
- GetWmiObject User Account with PowerShell Script Block
- Git Hooks Spawn System32 Process (Sysmon)
- Git Spawns System32 Process (Sysmon)
- Git Spawns System32 Process (Windows Event Log)
- Go Run Execution (PowerShell)
- Go Run Execution (Sysmon)
- Go Run Execution (Windows Event Log)
- High Entropy Powershell (PowerShell)
- Impacket atexec.py Execution (PowerShell)
- Impacket atexec.py Execution (Sysmon)
- Impacket atexec.py Execution (Windows Event Log)
- Impacket atexec.py Scheduled Task Creation (Windows Event Log)
- Impacket atexec.py Temp File Creation (Sysmon)
- Impacket atexec.py Temp File Creation (Windows Event Log)
- Impacket SMBexec (Windows Event Log)
- Impacket_Empire's WMIExec (Windows Event Log)
- Invoke-Expression Command (PowerShell)
- Invoke-Expression Command (Sysmon)
- Invoke-Expression Command (Windows Event Log)
- Invoke-WebRequest Command (PowerShell)
- Invoke-WebRequest Command (Sysmon)
- Invoke-WebRequest Command (Windows Event Log)
- Jscript Execution Using Cscript App
- Juniper Networks Remote Code Execution Exploit Detection
- Linux Decode Base64 to Shell
- Linux Docker Shell Execution
- Linux Magic SysRq Key Abuse
- Linux Suspicious React or Next.js Child Process
- Linux Unix Shell Enable All SysRq Functions
- Living Off The Land Detection
- Log4Shell CVE-2021-44228 Exploitation
- MacOS AMOS Stealer - Virtual Machine Check Activity
- MacOS LOLbin
- Malicious PowerShell Process - Execution Policy Bypass
- Malicious PowerShell Process With Obfuscation Techniques
- MCP Filesystem Server Suspicious Extension Write
- MCP Prompt Injection
- Meterpreter Reverse Shell (Windows Event Log)
- Microsoft Build Engine Suspicious Parent Process (Sysmon)
- Microsoft Build Engine Suspicious Parent Process (Windows Event Log)
- Modify Exchange Access Settings (PowerShell)
- MS Scripting Process Loading Ldap Module
- MS Scripting Process Loading WMI Module
- NirCmd Execution (Sysmon)
- NirCmd Execution (Windows Event Log)
- Nishang PowershellTCPOneLine
- Non-MSIExec .msi Installation (PowerShell)
- Non-MSIExec .msi Installation (Windows Event Log)
- Ollama Suspicious Prompt Injection Jailbreak
- Output to File (PowerShell)
- Output to File (Windows Event Log)
- Parent in Public Folder Suspicious Process (Sysmon)
- Parent in Public Folder Suspicious Process (Windows Event Log)
- Possible Lateral Movement PowerShell Spawn
- Potential AutoHotkey .ahk Execution (PowerShell)
- Potential AutoHotkey .ahk Execution (Sysmon)
- Potential AutoHotkey .ahk Execution (Windows Event Log)
- Potential PowerShell Post-Exploitation Activity (Sysmon)
- Potential PowerShell Post-Exploitation Activity (Windows Event Log)
- Potential Proxy Malware via AutoRun Key (PowerShell)
- Potential Proxy Malware via AutoRun Key (Sysmon)
- Potential Proxy Malware via AutoRun Key (Windows Event Log)
- PowerShell - Connect To Internet With Hidden Window
- PowerShell 4104 Hunting
- PowerShell Clipboard Access (PowerShell)
- Powershell COM Hijacking InprocServer32 Modification
- PowerShell CreateDecryptor (PowerShell)
- PowerShell CreateDecryptor (Sysmon)
- PowerShell CreateDecryptor (Windows Event Log)
- Powershell Creating Thread Mutex
- PowerShell Domain Enumeration
- PowerShell Downgrade (PowerShell)
- PowerShell Downgrade (Sysmon)
- PowerShell Downgrade (Windows Event Log)
- PowerShell Download Activity (PowerShell)
- PowerShell DownloadFile_DownloadString (PowerShell)
- PowerShell DownloadFile_DownloadString (Sysmon)
- PowerShell DownloadFile_DownloadString (Windows Event Log)
- PowerShell Enable PowerShell Remoting
- PowerShell Environment Variable Execution
- Powershell Execute COM Object
- Powershell Fileless Process Injection via GetProcAddress
- Powershell Fileless Script Contains Base64 Encoded Content
- PowerShell Hidden Window (PowerShell)
- PowerShell Hidden Window (Windows Event Log)
- Powershell ICMP Data Exfiltration (PowerShell)
- Powershell Load Module in Meterpreter
- PowerShell Loading DotNET into Memory via Reflection
- PowerShell Modifying Registry Values (PowerShell)
- PowerShell Modifying Registry Values (Sysmon)
- PowerShell Modifying Registry Values (Windows Event Log)
- PowerShell PInvoke Process Injection API Chain
- Powershell Processing Stream Of Data
- PowerShell Script Block With URL Chain
- PowerShell Start or Stop Service
- Powershell Using memory As Backing Store
- PowerShell WebRequest Using Memory Stream
- PowerShell XML Retrieval (PowerShell)
- PowerShell XML Retrieval (Sysmon)
- PowerShell XML Retrieval (Windows Event Log)
- PowerView_SharpView Commands (PowerShell)
- Process Writing DynamicWrapperX
- Python Execution (Windows Event Log)
- Rare Process Execution (Sysmon)
- Rare Process Execution (Windows Event Log)
- Recon Using WMI Class
- Remote Admin Tools (EDR)
- Remote Admin Tools (PowerShell)
- Remote Admin Tools (Sysmon)
- Remote Admin Tools (Windows Event Log)
- Ryuk Wake on LAN Command
- Script Connected to External Destination - Windows (Sysmon)
- Script Connected to External Destination - Windows (Windows Event Log)
- Set Default PowerShell Execution Policy To Unrestricted or Bypass
- SharpHound Enumeration (Windows Event Log)
- Sliver C2 Implant Activity Pattern (PowerShell)
- Sliver C2 Implant Activity Pattern (Sysmon)
- Sliver C2 Implant Activity Pattern (Windows Event Log)
- Suspicious Child Process for mshta.exe (Sysmon)
- Suspicious Child Process for mshta.exe (Windows Event Log)
- Suspicious Executable by CMD.exe (Sysmon)
- Suspicious Executable by CMD.exe (Windows Event Log)
- Suspicious Executable by Powershell (EDR)
- Suspicious Executable by Powershell (Sysmon)
- Suspicious Executable by Powershell (Windows Event Log)
- Suspicious Linux Discovery Commands
- Suspicious Powershell (PowerShell)
- Suspicious PowerShell Clipboard Activity (PowerShell)
- Suspicious PowerShell Clipboard Activity (Sysmon)
- Suspicious PowerShell Clipboard Activity (Windows Event Log)
- Suspicious PowerShell Parameter Substring (PowerShell)
- Suspicious PowerShell Parameter Substring (Sysmon)
- Suspicious PowerShell Parameter Substring (Windows Event Log)
- Suspicious Process DNS Query Known Abuse Web Services
- Suspicious Process With Discord DNS Query
- Suspicious reCAPTCHA Command Line (PowerShell)
- Suspicious reCAPTCHA Command Line (Sysmon)
- Unloading AMSI via Reflection
- Vbscript Execution Using Wscript App
- WebDAV LNK Execution (Sysmon)
- WebDAV LNK Execution (Windows Event Log)
- WebLogic CVE-2017-10271 (PowerShell)
- WebLogic CVE-2017-10271 (Sysmon)
- WebLogic CVE-2017-10271 (Windows Event Log)
- Wermgr Process Spawned CMD Or Powershell Process
- Windows Account Access Removal via Logoff Exec
- Windows Apache Benchmark Binary
- Windows AutoIt3 Execution
- Windows Cmdline Tool Execution From Non-Shell Process
- Windows Cobalt Strike PowerShell Loader
- Windows Command and Scripting Interpreter Hunting Path Traversal
- Windows Command and Scripting Interpreter Path Traversal Exec
- Windows Command Shell DCRat ForkBomb Payload
- Windows Common Abused Cmd Shell Risk Behavior
- Windows Copy Files (PowerShell)
- Windows Copy Files (Sysmon)
- Windows Copy Files (Windows Event Log)
- Windows Crowdstrike RTR Script Execution
- Windows Default Cobalt Strike PowerShell Beacon
- Windows Defender ASR Audit Events
- Windows Defender ASR Block Events
- Windows Defender ASR Rules Stacking
- Windows Enable PowerShell Web Access
- Windows Explorer LNK Exploit Process Launch With Padding
- Windows Explorer.exe Spawning PowerShell or Cmd
- Windows File Association Modification via Ftype
- Windows File Download Via PowerShell
- Windows GrimResource - MMC Process Accessing APDS DLL
- Windows Identify Protocol Handlers
- Windows MSExchange Management Mailbox Cmdlet Usage
- Windows Outlook Macro Created by Suspicious Process
- Windows PaperCut NG Spawn Shell
- Windows Powershell Cryptography Namespace
- Windows PowerShell FakeCAPTCHA Clipboard Execution
- Windows PowerShell Get CIMInstance Remote Computer
- Windows Powershell History File Deletion
- Windows Powershell Import Applocker Policy
- Windows PowerShell Invoke-RestMethod IP Information Collection
- Windows PowerShell Invoke-Sqlcmd Execution
- Windows Powershell Logoff User via Quser
- Windows PowerShell Module File Created
- Windows PowerShell MSIX Package Installation
- Windows PowerShell Process Implementing Manual Base64 Decoder
- Windows PowerShell Process With Malicious String
- Windows Powershell RemoteSigned File
- Windows PowerShell ScheduleTask
- Windows PowerShell Script Block With Malicious String
- Windows PowerShell Script From WindowsApps Directory
- Windows PowerShell Script TabExpansion Direct Call
- Windows PowerShell WMI Win32 ScheduledJob
- Windows PowGoop Beacon Decoding
- Windows Process Accessing Windows Recall Directory
- Windows Process Execution From RDP Share
- Windows Remote Image Load
- Windows Scheduled Task Service Spawned Shell
- Windows Shell Process from CrushFTP
- Windows Software Discovery Via PowerShell
- Windows SQL Server Extended Procedure DLL Loading Hunt
- Windows SQLCMD Execution
- Windows SSH Proxy Command
- Windows Suspicious React or Next.js Child Process
- Windows Suspicious VMWare Tools Child Process
- Windows TeamCity Payload Execution from Temp Directory
- Windows TeamCity Plugin Installed
- Windows TinyCC Shellcode Execution
- Windows WinDBG Spawning AutoIt3
- Windows XLL File Creation Outside of Typical Location
- Wscript_Cscript Execution (PowerShell)
- Wscript_Cscript Execution (Sysmon)
- Wscript_Cscript Execution (Windows Event Log)
Kusto 63 rules
- A host is potentially running a hacking tool (ASIM Web Session schema)
- A host is potentially running PowerShell to send HTTP(S) requests (ASIM Web Session schema)
- ApexOne - Suspicious commandline arguments
- App Gateway WAF - SQLi Detection
- Application Gateway WAF - SQLi Detection
- AWS Security Hub - Detect SSM documents public sharing enabled
- AWSCloudTrail - EC2 Startup Shell Script Changed
- Azure Machine Learning Write Operations
- Azure VM Run Command operations executing a unique PowerShell script
- Base64 encoded Windows process command-lines
- Base64 encoded Windows process command-lines (Normalized Process Events)
- BTP - Cloud Integration artifact deployment
- Cisco Cloud Security - Hack Tool User-Agent Detected
- Cisco Cloud Security - Windows PowerShell User-Agent Detected
- CiscoISE - Command executed with the highest privileges from new IP
- CiscoISE - Command executed with the highest privileges by new user
- Critical Risks
- Cross-Cloud Suspicious Compute resource creation in GCP
- Cross-Cloud Suspicious user activity observed in GCP Envourment
- Deimos Component Execution
- Detect Local File Inclusion(LFI) in web requests (ASIM Web Session)
- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Detect port misuse by static threshold (ASIM Network Session schema)
- Detect Suspicious Commands Initiated by Webserver Processes
- Doppelpaymer Stop Services
- Dynatrace - Problem detection
- Dynatrace Application Security - Attack detection
- Dynatrace Application Security - Code-Level runtime vulnerability detection
- Dynatrace Application Security - Non-critical runtime vulnerability detection
- Dynatrace Application Security - Third-Party runtime vulnerability detection
- Exchange Worker Process Making Remote Call
- Execution attempts stateful anomaly on database
- Front Door Premium WAF - SQLi Detection
- Google Threat Intelligence - Threat Hunting Hash
- Java Executing cmd to run Powershell
- Midnight Blizzard - Script payload stored in Registry
- New CloudShell User
- NRT Base64 Encoded Windows Process Command-lines
- NRT Process executed from binary hidden in Base64 encoded file
- Office Apps Launching Wscipt
- Pathlock TDnR - Function Module Tested in Production
- Pathlock TDnR - Logical OS Command Changes
- Pathlock TDnR - SAP Batch Job Events
- Pathlock TDnR - TMS Transport and Import Events
- Potential Ransomware activity related to Cobalt Strike
- Powershell Empire Cmdlets Executed in Command Line
- PowerShell without powershell.exe
- Process Creation with Suspicious CommandLine Arguments
- Process executed from binary hidden in Base64 encoded file
- Process Execution Frequency Anomaly
- Qakbot Discovery Activies
- RecordedFuture Threat Hunting Hash All Actors
- Script Interpreter Loading DotNet Assembly From Memory
- SonicWall - Allowed SSH, Telnet, and RDP Connections
- SUNBURST and SUPERNOVA backdoor hashes
- SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)
- SUNBURST network beacons
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events)
- Suspicious Powershell Commandlet Executed
- TEARDROP memory-only dropper
- Vulerabilities
- Windows Binaries Executed from Non-Default Directory
- Windows Binaries Lolbins Renamed
YARA-L 7 rules
- Base64 Encoded PowerShell Command Detected
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Hacktool - IronSharpPack Execution
- PowerShell DownloadFile
- PowerShell Web Download
- sap execution of sensitive abap program
- W3WP Launching Encoded Powershell
Panther 12 rules
- AWS EC2 Startup Script Change
- AWS WAF Managed Known Bad Inputs Passthrough Rule
- AWS WAF ReactJS RCE Attempt via Body
- Azure Automation Runbook Created or Modified
- Azure Serverless Script Execution
- CrowdStrike MacOS Osascript as Administrator
- Crowdstrike Reverse Shell Tool Executed
- Databricks Global Init Script Changes
- StopInstance FOLLOWED BY ModifyInstanceAttributes
- Teleport Suspicious Commands Executed
- Upwind Runtime Detection Passthrough
- User Logged in as root