Command and Scripting Interpreter T1059
Tactic: Execution
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Events covered
102 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 1506 rules share fields, values, and exclusions.
Fields filtered most (418 distinct)
These fields appear most often in rule filters.
Top indicator values (12798 distinct)
These values appear most often in rule predicates.
Exclusions (6183 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 432 rules
- Abusable DLL Potential Sideloading From Suspicious Location
- Add Insecure Download Source To Winget
- Add New Download Source To Winget
- Add Potential Suspicious New Download Source To Winget
- Adwind RAT / JRAT
- Adwind RAT / JRAT File Artifact
- Alternate PowerShell Hosts - PowerShell Module
- Alternate PowerShell Hosts Pipe
- AppLocker Application Would Have Been Blocked
- AppLocker Prevented Application or Script from Running
- Atlassian Confluence CVE-2022-26134
- Atomic MacOS Stealer - FileGrabber Activity
- AWS EC2 Startup Shell Script Change
- AWS IAM S3Browser LoginProfile Creation
- AWS IAM S3Browser Templated S3 Bucket Policy Creation
- AWS IAM S3Browser User or AccessKey Creation
- Axios NPM Compromise Indicators - Linux
- Axios NPM Compromise Indicators - macOS
- Axios NPM Compromise Indicators - Windows
- Azure New CloudShell Created
- Bad Opsec Powershell Code Artifacts
- Base64 Encoded PowerShell Command Detected
- BloodHound Collection Files
- BPFDoor Abnormal Process ID or Lock File Accessed
- BPFtrace Unsafe Option Usage
- bXOR Operator Usage In PowerShell Command Line - PowerShell Classic
- Capsh Shell Invocation - Linux
- Certificate Exported Via PowerShell
- Change PowerShell Policies to an Insecure Level
- Change PowerShell Policies to an Insecure Level - PowerShell
- ChromeLoader Malware Execution
- Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
- Clipboard Access Via OSAScript
- Cmd.EXE Missing Space Characters Execution Anomaly
- Command Line Execution with Suspicious URL and AppData Strings
- Conhost Spawned By Uncommon Parent Process
- Conhost.exe CommandLine Path Traversal
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Csc.EXE Execution Form Potentially Suspicious Parent
- Cscript/Wscript Uncommon Script Extension Execution
- CVE-2022-24527 Microsoft Connected Cache LPE
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)
- DarkGate - Autoit3.EXE Execution Parameters
- DarkGate - Autoit3.EXE File Creation By Uncommon Process
- DarkGate - Drop DarkGate Loader In C:\Temp Directory
- Detection of PowerShell Execution via Sqlps.exe
- DNS Query by Finger Utility
- DSInternals Suspicious PowerShell Cmdlets
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock
- Elevated System Shell Spawned
- Elevated System Shell Spawned From Uncommon Parent Location
- Elise Backdoor Activity
- Emotet Loader Execution Via .LNK File
- Encoded PowerShell payload deployed (PowerShell)
- Encoded PowerShell payload deployed via process execution
- Equation Group Indicators
- ESXi Account Creation Via ESXCLI
- ESXi Admin Permission Assigned To Account Via ESXCLI
- ESXi Network Configuration Discovery Via ESXCLI
- ESXi Storage Information Discovery Via ESXCLI
- ESXi Syslog Configuration Change Via ESXCLI
- ESXi System Information Discovery Via ESXCLI
- ESXi VM Kill Via ESXCLI
- ESXi VM List Discovery Via ESXCLI
- ESXi VSAN Information Discovery Via ESXCLI
- Exchange PowerShell Snap-Ins Usage
- Execute Code with Pester.bat
- Execute Code with Pester.bat as Parent
- Execution of Powershell Script in Public Folder
- Exploited CVE-2020-10189 Zoho ManageEngine
- Exploiting SetupComplete.cmd CVE-2019-1378
- FakeUpdates/SocGholish Activity
- Forfiles Command Execution
- Greenbug Espionage Group Indicators
- HackTool - Bloodhound/Sharphound Execution
- HackTool - CACTUSTORCH Remote Thread Creation
- HackTool - Covenant PowerShell Launcher
- HackTool - CrackMapExec Execution
- HackTool - CrackMapExec Execution Patterns
- HackTool - CrackMapExec PowerShell Obfuscation
- HackTool - Default PowerSploit/Empire Scheduled Task Creation
- HackTool - Empire PowerShell Launch Parameters
- HackTool - Jlaive In-Memory Assembly Execution
- HackTool - Koadic Execution
- HackTool - NetExec File Indicators
- HackTool - RedMimicry Winnti Playbook Execution
- HackTool - Sliver C2 Implant Activity Pattern
- HackTool - Stracciatella Execution
- Hacktool Ruler
- Headless Process Launched Via Conhost.EXE
- Hidden Powershell in Link File Pattern
- HTML Help HH.EXE Suspicious Child Process
- Import PowerShell Modules From Suspicious Directories
- Import PowerShell Modules From Suspicious Directories - ProcCreation
- Inline Python Execution - Spawn Shell Via OS System Library
- Install New Package Via Winget Local Manifest
- Installation of WSL Kali-Linux
- Interactive Bash Suspicious Children
- Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
- Invoke-Obfuscation CLIP+ Launcher
- Invoke-Obfuscation CLIP+ Launcher - PowerShell
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
- Invoke-Obfuscation CLIP+ Launcher - Security
- Invoke-Obfuscation CLIP+ Launcher - System
- Invoke-Obfuscation COMPRESS OBFUSCATION
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security
- Invoke-Obfuscation COMPRESS OBFUSCATION - System
- Invoke-Obfuscation Obfuscated IEX Invocation
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
- Invoke-Obfuscation RUNDLL LAUNCHER - Security
- Invoke-Obfuscation RUNDLL LAUNCHER - System
- Invoke-Obfuscation STDIN+ Launcher
- Invoke-Obfuscation STDIN+ Launcher - Powershell
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
- Invoke-Obfuscation STDIN+ Launcher - Security
- Invoke-Obfuscation STDIN+ Launcher - System
- Invoke-Obfuscation VAR+ Launcher
- Invoke-Obfuscation VAR+ Launcher - PowerShell
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module
- Invoke-Obfuscation VAR+ Launcher - Security
- Invoke-Obfuscation VAR+ Launcher - System
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
- Invoke-Obfuscation Via Stdin
- Invoke-Obfuscation Via Stdin - Powershell
- Invoke-Obfuscation Via Stdin - PowerShell Module
- Invoke-Obfuscation Via Stdin - Security
- Invoke-Obfuscation Via Stdin - System
- Invoke-Obfuscation Via Use Clip
- Invoke-Obfuscation Via Use Clip - Powershell
- Invoke-Obfuscation Via Use Clip - PowerShell Module
- Invoke-Obfuscation Via Use Clip - Security
- Invoke-Obfuscation Via Use Clip - System
- Invoke-Obfuscation Via Use MSHTA
- Invoke-Obfuscation Via Use MSHTA - PowerShell
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module
- Invoke-Obfuscation Via Use MSHTA - Security
- Invoke-Obfuscation Via Use MSHTA - System
- Invoke-Obfuscation Via Use Rundll32 - PowerShell
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
- Invoke-Obfuscation Via Use Rundll32 - Security
- Invoke-Obfuscation Via Use Rundll32 - System
- JexBoss Command Sequence
- JXA In-memory Execution Via OSAScript
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution
- Lace Tempest PowerShell Evidence Eraser
- Lace Tempest PowerShell Launcher
- Lazarus Group Activity
- Linux Reverse Shell Indicator
- Linux Suspicious Child Process from Node.js - React2Shell
- macOS Network Utility Tools for C2
- MacOS Scripting Interpreter AppleScript
- Malicious Base64 Encoded PowerShell Keywords in Command Lines
- Malicious Nishang PowerShell Commandlets
- Malicious PowerShell Commandlets - PoshModule
- Malicious PowerShell Commandlets - ProcessCreation
- Malicious PowerShell Commandlets - ScriptBlock
- Malicious PowerShell Keywords
- Malicious PowerShell Scripts - FileCreation
- Malicious PowerShell Scripts - PoshModule
- Malicious ShellIntel PowerShell Commandlets
- Manual Execution of Script Inside of a Compressed File
- MERCURY APT Activity
- Metasploit reverse shell injection in SQL Server
- MMC Loading Script Engines DLLs
- MSHTA Execution with Suspicious File Extensions
- Net WebClient Casing Anomalies
- Netcat The Powershell Version
- Network Connection Initiated By PowerShell Process
- Network Connection Initiated via Finger.EXE
- New Agent Skills Installation Attempt Via Node.EXE
- New PowerShell Instance Created
- Node Process Executions
- NodeJS Execution of JavaScript File
- Nohup Execution
- Non Interactive PowerShell Process Spawned
- Nslookup PowerShell Download Cradle
- NTFS Alternate Data Stream
- Obfuscated PowerShell MSI Install via WindowsInstaller COM
- Obfuscated PowerShell OneLiner Execution
- OpenEDR Spawning Command Shell
- Operation Wocao Activity
- Operation Wocao Activity - Security
- Operator Bloopers Cobalt Strike Commands
- Operator Bloopers Cobalt Strike Modules
- Osacompile Execution By Potentially Suspicious Applet/Osascript
- OSACompile Run-Only Execution
- Outlook EnableUnsafeClientMailRules Setting Enabled
- Payload Decoded and Decrypted via Built-in Utilities
- Payload downloaded via PowerShell
- PCRE.NET Package Image Load
- PCRE.NET Package Temp Files
- Perl Inline Command Execution
- Php Inline Command Execution
- PipeShell exfiltration over named pipes
- Potential Abuse of Linux Magic System Request Key
- Potential APT FIN7 Exploitation Activity
- Potential APT FIN7 POWERHOLD Execution
- Potential APT10 Cloud Hopper Activity
- Potential Arbitrary Command Execution Via FTP.EXE
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
- Potential Baby Shark Malware Activity
- Potential BlackByte Ransomware Activity
- Potential Bumblebee Remote Thread Creation
- Potential CobaltStrike Process Patterns
- Potential CommandLine Path Traversal Via Cmd.EXE
- Potential CVE-2021-40444 Exploitation Attempt
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
- Potential Data Exfiltration Activity Via CommandLine Tools
- Potential DLL File Download Via PowerShell Invoke-WebRequest
- Potential Dosfuscation Activity
- Potential Dropper Script Execution Via WScript/CScript/MSHTA
- Potential Emotet Activity
- Potential Encoded PowerShell Patterns In CommandLine
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
- Potential Exploitation of GoAnywhere MFT Vulnerability
- Potential In-Memory Download And Compile Of Payloads
- Potential KamiKakaBot Activity - Lure Document Execution
- Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE
- Potential Netcat Reverse Shell Execution
- Potential Persistence Via Powershell Search Order Hijacking - Task
- Potential Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
- Potential PowerShell Command Line Obfuscation
- Potential PowerShell Downgrade Attack
- Potential PowerShell Obfuscation Using Alias Cmdlets
- Potential PowerShell Obfuscation Using Character Join
- Potential PowerShell Obfuscation Via Reversed Commands
- Potential PowerShell Obfuscation Via WCHAR/CHAR
- Potential Powershell ReverseShell Connection
- Potential POWERTRASH Script Execution
- Potential QBot Activity
- Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
- Potential Remote PowerShell Session Initiated
- Potential Remote SquiblyTwo Technique Execution
- Potential SAP NetWeaver Webshell Creation
- Potential SAP NetWeaver Webshell Creation - Linux
- Potential Suspicious PowerShell Keywords
- Potential WinAPI Calls Via PowerShell Scripts
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell
- Potential Xterm Reverse Shell
- Potentially Suspicious Command Executed Via Run Dialog Box - Registry
- Potentially Suspicious Execution From Parent Process In Public Folder
- Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
- Potentially Suspicious Long Filename Pattern - Linux
- Potentially Suspicious NTFS Symlink Behavior Modification
- Potentially Suspicious PowerShell Child Processes
- Potentially Suspicious Powershell Script Execution From Temp Folder
- Potentially Suspicious WebDAV LNK Execution
- PowerShell ADRecon Execution
- PowerShell Base64 Encoded FromBase64String Cmdlet
- PowerShell Base64 Encoded IEX Cmdlet
- PowerShell Base64 Encoded Invoke Keyword
- PowerShell Base64 Encoded Reflective Assembly Load
- PowerShell Base64 Encoded WMI Classes
- PowerShell Called from an Executable Version Mismatch
- PowerShell Core DLL Loaded By Non PowerShell Process
- PowerShell Create Local User
- PowerShell Credential Prompt
- PowerShell Downgrade Attack - PowerShell
- PowerShell Download and Execution Cradles
- PowerShell Download Pattern
- PowerShell Download Via Net.WebClient - PowerShell Classic
- Powershell Execute Batch Script
- Powershell Executed From Headless ConHost Process
- Powershell Inline Execution From A File
- PowerShell MSI Install via WindowsInstaller COM From Remote Location
- Powershell MsXml COM Object
- PowerShell PSAttack
- PowerShell Remote Session Creation
- PowerShell Script Run in AppData
- PowerShell ShellCode
- PowerShell Web Access Installation - PsScript
- Powershell XML Execute Command
- PowerView PowerShell Cmdlets - ScriptBlock
- Process Signal from Suspicious Parent Process
- PSAsyncShell - Asynchronous TCP Reverse Shell
- PUA - AdvancedRun Execution
- PUA - Wsudo Suspicious Execution
- Python Inline Command Execution
- Python One-Liners with Base64 Decoding
- Python One-Liners with Base64 Decoding - Linux
- Python Path Configuration File Creation - Linux
- Python Path Configuration File Creation - MacOS
- Python Path Configuration File Creation - Windows
- Python Spawning Pretty TTY on Windows
- Python Spawning Pretty TTY Via PTY Module
- Raspberry Robin Initial Execution From External Drive
- Raspberry Robin Subsequent Execution of Commands
- Read Contents From Stdin Via Cmd.EXE
- Registry Modification Attempt Via VBScript
- Registry Modification Attempt Via VBScript - PowerShell
- Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace
- Registry Tampering by Potentially Suspicious Processes
- Remote Access Tool - ScreenConnect Command Execution
- Remote Access Tool - ScreenConnect File Transfer
- Remote Access Tool - ScreenConnect Remote Command Execution
- Remote Access Tool - ScreenConnect Temporary File
- Remote LSASS Process Access Through Windows Remote Management
- Remote PowerShell Session (PS Classic)
- Remote PowerShell Session (PS Module)
- Remote PowerShell Session Host Process (WinRM)
- Remote PowerShell Sessions Network Connections (WinRM)
- Remote Thread Creation Via PowerShell
- Remote Thread Creation Via PowerShell In Uncommon Target
- Renamed CURL.EXE Execution
- Renamed FTP.EXE Execution
- Renamed NirCmd.EXE Execution
- Renamed PingCastle Binary Execution
- Renamed Powershell Under Powershell Channel
- REvil Kaseya Incident Malware Patterns
- Rorschach Ransomware Execution Activity
- Ruby Inline Command Execution
- Run PowerShell Script from Redirected Input Stream
- Scheduled Task Executing Encoded Payload from Registry
- Scheduled Task Executing Payload from Registry
- Script Interpreter Execution From Suspicious Folder
- Script Interpreter Spawning Credential Scanner - Linux
- Script Interpreter Spawning Credential Scanner - Windows
- Serial console process spawning CMD shell (via command)
- Serpent Backdoor Payload Execution Via Scheduled Task
- Shai-Hulud Malware Indicators - Linux
- Shai-Hulud Malware Indicators - Windows
- Shell Execution via Git - Linux
- Shell Execution via Rsync - Linux
- Shell Invocation via Env Command - Linux
- Shell Invocation Via Ssh - Linux
- Silence.EDA Detection
- Sofacy Trojan Loader Activity
- SQL Client Tools PowerShell Session Detection
- Suspicious Activity in Shell Commands
- Suspicious ArcSOC.exe Child Process
- Suspicious Browser Child Process - MacOS
- Suspicious Child Process Of BgInfo.EXE
- Suspicious Child Process of SAP NetWeaver
- Suspicious Child Process of SAP NetWeaver - Linux
- Suspicious Commands Linux
- Suspicious CrushFTP Child Process
- Suspicious Deno File Written from Remote Source
- Suspicious Download and Execute Pattern via Curl/Wget
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
- Suspicious Encoded PowerShell Command Line
- Suspicious Execution of Powershell with Base64
- Suspicious Execution via macOS Script Editor
- Suspicious File Characteristics Due to Missing Fields
- Suspicious File Created In PerfLogs
- Suspicious File Execution From Internet Hosted WebDav Share
- Suspicious Filename with Embedded Base64 Commands
- Suspicious Greedy Compression Using Rar.EXE
- Suspicious HH.EXE Execution
- Suspicious HWP Sub Processes
- Suspicious Installer Package Child Process
- Suspicious Interactive PowerShell as SYSTEM
- Suspicious Invocation of Shell via AWK - Linux
- Suspicious Invocation of Shell via Rsync
- Suspicious Java Children Processes
- Suspicious Microsoft Office Child Process - MacOS
- Suspicious Non PowerShell WSMAN COM Provider
- Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
- Suspicious PowerShell Download - PoshModule
- Suspicious PowerShell Download - Powershell Script
- Suspicious PowerShell Download and Execute Pattern
- Suspicious PowerShell Encoded Command Patterns
- Suspicious PowerShell IEX Execution Patterns
- Suspicious PowerShell Invocation From Script Engines
- Suspicious PowerShell Invocations - Generic
- Suspicious PowerShell Invocations - Generic - PowerShell Module
- Suspicious PowerShell Invocations - Specific
- Suspicious PowerShell Invocations - Specific - PowerShell Module
- Suspicious PowerShell Parameter Substring
- Suspicious PowerShell Parent Process
- Suspicious PrinterPorts Creation (CVE-2020-1048)
- Suspicious Process Spawned by CentreStack Portal AppPool
- Suspicious Program Names
- Suspicious RASdial Activity
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
- Suspicious Remote Child Process From Outlook
- Suspicious Reverse Shell Command Line
- Suspicious Runscripthelper.exe
- Suspicious Scan Loop Network
- Suspicious Schtasks Execution AppData Folder
- Suspicious Scripting in a WMI Consumer
- Suspicious Usage of For Loop with Recursive Directory Search in CMD
- Suspicious WSMAN Provider Image Loads
- Suspicious XOR Encoded PowerShell Command
- Sysprep on AppData Folder
- TanStack Supply-Chain Attack Execution Indicators - Linux
- TanStack Supply-Chain Attack Execution Indicators - Windows
- TanStack Supply-Chain Attack File Creation Indicators - Linux
- TanStack Supply-Chain Attack File Creation Indicators - Windows
- TropicTrooper Campaign November 2018
- Turla Group Commands May 2020
- Turla Group Lateral Movement
- UNC2452 PowerShell Pattern
- UNC2452 Process Creation Patterns
- Uncommon Child Process Of BgInfo.EXE
- Uncommon PowerShell Hosts
- Unusual Parent Process For Cmd.EXE
- Unusually Long PowerShell CommandLine
- Ursnif Redirection Of Discovery Commands
- Usage Of Web Request Commands And Cmdlets
- Usage Of Web Request Commands And Cmdlets - ScriptBlock
- Use of FSharp Interpreters
- Use of OpenConsole
- Use of Pcalua For Execution
- Vice Society directory crawling script for data exfiltration (via ps_script)
- Vim GTFOBin Abuse - Linux
- VMToolsd Suspicious Child Process
- WinAPI Function Calls Via PowerShell Scripts
- WinAPI Library Calls Via PowerShell Scripts
- Windows Defender AMSI Trigger Detected
- Windows Defender Exclusions Added - PowerShell
- Windows Defender Threat Detected
- Windows Shell/Scripting Application File Write to Suspicious Folder
- Windows Shell/Scripting Processes Spawning Suspicious Programs
- Windows Suspicious Child Process from Node.js - React2Shell
- WMImplant Hack Tool
- Writing Of Malicious Files To The Fonts Folder
- WScript or CScript Dropper - File
- Wscript Shell Run In CommandLine
- WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
- XSL Script Execution Via WMIC.EXE
- ZxShell Malware
Elastic 689 rules
- .NET COM object created in non-standard Windows Script Interpreter
- Abnormal Auval Child Process Execution
- Abnormally Large Javascript Evaluation via Nodejs
- Abnormally Large Shell Script Execution via Perl
- Access to Windows Passwords Vault via Powershell
- AMSI Bypass via PowerShell
- Anomalous React Server Components Flight Data Patterns
- Anomalous Windows Process Creation
- Apple Script Execution followed by Network Connection
- Apple Scripting Execution with Administrator Privileges
- AppleScript Decoded via Base64
- Arbitrary Python Code Execution via Nodejs
- At Utility Launched through Udevadm
- Attempt to establish VScode Remote Tunnel
- Attempt to Install or Run Kali Linux via WSL
- AWS Batch Job Submitted with Container Override by Unusual Identity
- AWS Bedrock High Risk Filesystem or Execution Tool Invocation
- AWS CloudShell Environment Created
- AWS EC2 LOLBin Execution via SSM SendCommand
- AWS EC2 Stop, Start, and User Data Modification Correlation
- AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content
- AWS SSM `SendCommand` with Run Shell Command Parameters
- AWS SSM Session Manager Child Process Execution
- Azure Run Command Correlated with Process Execution
- Azure Run Command Script Child Process
- Background Process Execution via Shell
- Background Task Execution via a Hidden Process
- Base64 Decoded Payload Piped to Interpreter
- Base64 Encoded String Execution via Osascript
- Base64 or Xxd Decode Argument Evasion
- Base64 Shebang Payload Decoded via Built-in Utility
- BCDEdit Safe Mode Command Execution
- Binary Content Copy via Cmd.exe
- Binary Executed from Shared Memory Directory
- Bind Shell via Netcat Traditional
- Bind Shell via Node
- Bind Shell via Socket
- Boot File Copy
- BPF filter applied using TC
- BPF Filter Applied using Traffic Control
- Cassandra JavaScript UDF Creation
- Clearing Windows Console History
- Cocoa Applet Binary Execution
- Code Editor Untrusted or Unsigned Child Process Execution
- Command and Scripting Interpreter from Suspicious Parent
- Command and Scripting Interpreter via Windows Scripts
- Command Execution via Screen Session
- Command Execution via SolarWinds Process
- Command Interpreter with IP Address Argument
- Command Line Obfuscation via Whitespace Padding
- Command Shell Activity Started via RunDLL32
- Command Shell Activity Started via RunDLL32
- Command Shell Execution from Untrusted Origin
- Conhost Spawned By Suspicious Parent Process
- Creation of Hidden Login Item via Apple Script
- Cupsd or Foomatic-rip Shell Execution
- Curl Download and Execution of JavaScript Payload
- Curl Execution via Shell Profile
- Curl Hidden Binary Modification via Osascript
- Curl HTTP Fetch Piped to Cmd or Node via Command Shell
- Curl or Wget Egress Network Connection via LoLBin
- Curl Output Piped to Osascript
- Cursor Arbitrary Code Execution via PHP
- Decoded or Decrypted Payload Written to Suspicious Directory
- Decoded Payload Piped to Interpreter
- Decoded Payload Piped to Interpreter Detected via Defend for Containers
- Defense Evasion via Bind Mount
- Defense Evasion via Hidepid Mount
- Delayed Execution via Ping
- Deprecated - Microsoft Exchange Transport Agent Install Script
- Deprecated - Potential PowerShell Obfuscated Script
- Deprecated - PowerShell Script with Discovery Capabilities
- Deprecated - PowerShell Script with Remote Execution Capabilities via WinRM
- Direct Interactive Kubernetes API Request by Common Utilities
- Direct Interactive Kubernetes API Request by Unusual Utilities
- Direct Kubernetes API Request Detected via Defend for Containers
- Direct Process Execution via Background Utility
- Disabling Windows Defender Security Settings via PowerShell
- Discovery of GitHub Actions Runner Process PID
- Disk Image Download and Mount via Hdiutil
- Disown Execution via Shell Command from Volume Mount
- DNS Request to Crypto Miner Service
- DNS Request to Crypto/DHT Services
- DNS Request to Suspicious File Upload/Download Service
- Dracut Module Creation
- Dscl Execution via Osascript
- Dynamic IEX Reconstruction via Method String Access
- Dynamic Linker (ld.so) Creation
- Dynwrapx Image Load via Windows Scripts
- Egress Connection from Entrypoint in Container
- Egress Network Connection by MOTD Child
- Egress Network Connection Followed by Command Execution
- Egress Network Connection from Node.js Descendant
- Elevated Apple Script Execution via Unsigned Parent
- Embedded Executable via Windows Shortcut File
- Empire Stager Execution
- Encoded Payload Detected via Defend for Containers
- Encoded Powershell Execution via MsiExec
- Entra ID PowerShell Sign-in
- Exec Into Container Detected via Defend for Containers
- Executable File Access or Modification via Osascript
- Executable File Extracted to Temporary Directory
- Executable File Modification via SSH
- Execution from Unusual Directory
- Execution from Unusual Directory - Command Line
- Execution from ZIP File via Explorer
- Execution of a Downloaded Windows Script
- Execution of a Downloaded Windows Script via Explorer
- Execution of a File Downloaded via Windows OpenSSH
- Execution of a File Written by Windows Script Host
- Execution of a Windows Script Downloaded from the Internet
- Execution of a Windows Script Downloaded via a LOLBIN
- Execution of a Windows Script File Written by a Suspicious Process
- Execution of a Windows Script with Unusual File Extension
- Execution of Commonly Abused Utilities via Explorer Trampoline
- Execution of Javascript Payload via Osascript
- Execution of JavaScript Payload via Python
- Execution of Non-Executable File via Shell
- Execution of Persistent Suspicious Program
- Execution of Self-Signed Binary from Volume Mount
- Execution via Electron Child Process Node.js Module
- Execution via Electron Child Process Node.js Module
- Execution via GitHub Actions Runner
- Execution via Loki Command and Control
- Execution via MS VisualStudio Pre/Post Build Events
- Execution via MSSQL xp_cmdshell Stored Procedure
- Execution via Obfuscated PowerShell Script
- Execution via Obfuscated Windows Script
- Execution via OpenClaw Agent
- Execution via Outlook Application COM Object
- Execution via Suspicious JavaScript Updates
- Execution via SyncAppvPublishingServer
- Execution via Windows Subsystem for Linux
- Execution via WMI ActiveScript Event Consumer
- Execution with Explicit Credentials via Scripting
- Exporting Exchange Mailbox via PowerShell
- File Creation and Execution Detected via Defend for Containers
- File Creation by Cups or Foomatic-rip Child
- File Creation in /var/log via Suspicious Process
- File Creation, Execution and Self-Deletion in Suspicious Directory
- File Download Detected via Defend for Containers
- File Download from or Upload to Hosting Service
- File Download Piped to Script Interpreter
- File Execution Permission Modification Detected via Defend for Containers
- File Transfer or Listener Established via Netcat
- File Transfer Utility Launched from Unusual Parent
- First Time Python Spawned a Shell on Host
- Forbidden Direct Interactive Kubernetes API Request
- GenAI or MCP Server Child Process Execution
- Git Hook Child Process
- Git Hook Command Execution
- Git Hook Created or Modified
- Git Hook Egress Network Connection
- GitHub Actions Runner with Disabled Telemetry
- GitHub Actions Unusual Bot Push to Repository
- GitHub Actions Workflow Modification Blocked
- Github Activity on a Private Repository from an Unusual IP
- GitHub Authentication Token Access via Node.js
- GKE Pod Exec Potential Reverse Shell
- Google Calendar C2 via Script Interpreter
- Hidden Folder or File Access in Tmp via Python
- Host File System Changes via Windows Subsystem for Linux
- Incoming Execution via PowerShell Remoting
- Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers
- Ingress Tool Transfer via PowerShell
- Inhibit System Recovery via Obfuscated Commands
- Inhibit System Recovery via Signed Binary Proxy
- Inhibit System Recovery via Windows Command Shell
- Initial Access Discovery via Applet Executable
- Initial Access or Execution via Microsoft Office Application
- Initial Access via Audio Unit Plug-in
- Initial Access via macOS Installer Package
- Initial Access via OSA Shell Script Piped to Python Interpreter
- Initramfs Unpacking via unmkinitramfs
- Interactive Shell Launched via Unusual Parent Process in a Container
- Interactive Shell Spawn Detected via Defend for Containers
- Interactive Shell Spawned via Hidden Process
- Interactive Terminal Spawned via Perl
- Interactive Terminal Spawned via Python
- JAVA Application Execution from Suspicious Paths
- JAVA Application with Unusual File Extension
- Java Drop followed by network activity
- JavaScript Execution via Deno on Linux
- Javascript Reverse Shell via Node.js
- Javascript Reverse Shell via Nodejs
- Kerberos Config File Accessed by Osascript
- Keystrokes Input Capture via PowerShell
- Kill Command Executed from Binary in Unusual Location
- Kill Command Execution
- Kubernetes Direct API Request via Curl or Wget
- Kubernetes Pod Exec Potential Reverse Shell
- Linux Background Process Execution via Shell
- Linux Hidden File Mounted
- Linux Hidden Folder or File Execution via Python
- Linux Payload Decoded and Decrypted via Built-in Utility
- Linux Powershell Egress Network Connection
- Linux Powershell Encoded Command
- Linux Powershell Suspicious Child Process
- Linux Reverse Shell
- Linux Reverse Shell via Child
- Linux Reverse Shell via netcat
- Linux Reverse Shell via setsid and nohup
- Linux Reverse Shell via Suspicious Utility
- Linux Reverse Shell via Xterm
- Linux Suspicious Child Process Execution via Interactive Shell
- Lone Binary Execution from Volume Mount
- Long Base64 Command Execution via Interactive Shell
- Long Base64 Encoded Command via Scripting Interpreter
- Long Base64 Encoded Interpreter Command Line
- M365 Security Compliance Admin Signal
- M365 SharePoint/OneDrive File Access via PowerShell
- MacOS Hidden File Mounted
- MacOS Interactive Shell Spawned via Hidden Process
- Managed .NET Code Execution via PowerShell
- Managed .NET Code Execution via Windows Script Interpreter
- Manual Dracut Execution
- Memory Swap Modification
- Microsoft Build Engine Started an Unusual Process
- Microsoft Build Engine Started by a Script Process
- Microsoft Exchange Worker Spawning Suspicious Processes
- Microsoft Management Console File from Unusual Path
- Msiexec Execution via a Windows Script Interpreter
- MSR Write Access Enabled
- Multi-Base64 Decoding Attempt from Suspicious Location
- Netcat File Transfer or Listener Detected via Defend for Containers
- Netcat Listener Established via rlwrap
- Netcat Reverse Shell via Busybox
- Network Connection by Cups or Foomatic-rip Child
- Network Connection Followed by File Creation
- Network Connection from Binary with RWX Memory Region
- Network Connection to OAST Domain via Script Interpreter
- Network Connection via Recently Compiled Executable
- Network Connection via Startup Item
- Network Connections Initiated Through XDG Autostart Entry
- Network File Unzipped via Unsigned or Untrusted Binary
- NetworkManager Dispatcher Script Creation
- New ActiveSyncAllowedDeviceID Added via PowerShell
- New System Kext File and Immediate Load via KextLoad
- Node.js execution followed by network activity
- Node.js Pre or Post-Install Script Execution
- Node.js Recently Dropped Executing File with Unusual Extension
- Nodejs Initial Access via VSCode Auto-run Task
- Nodejs Javascript Execution via Osascript
- Nohup Execution followed by Outbound Network Connection
- Non-interactive Shell Upgrade
- Openssl Client or Server Activity
- OpenSSL Reverse Shell Activity via Named Pipe
- OSA Script Execution via Unsigned or Untrusted Parent
- Osascript Execution via Piped AppleScript
- Outbound Network Connection Followed by Process File Deletion
- Outbound Scheduled Task Activity via PowerShell
- Oversized Windows Script Execution
- Payload Decoded and Decrypted via Built-In Utilities
- Payload Delivery via Curl and Immediate Execution
- Payload Downloaded and Piped to Interpreter
- Payload Downloaded by Interpreter and Piped to Interpreter
- Payload Downloaded via Curl or Wget by Web Server
- Payload Execution by Node.js Web Server
- Payload Execution by Web Server
- Payload Execution via Shell Pipe Detected by Defend for Containers
- Payload Piped to Script Interpreter
- Perl Outbound Network Connection
- Perl Script File Creation or Modification
- Persistence via Folder Action Script
- PHP File Creation in WordPress Plugin Directory
- Pod or Container Creation with Suspicious Command-Line
- Possible JAVA Reverse Shell
- PostgreSQL COPY PROGRAM Command Execution
- Potential AMSI Bypass via RPC Runtime Hooking
- Potential Antimalware Scan Interface Bypass via PowerShell
- Potential Backdoor Execution Through PAM_EXEC
- Potential Code Execution via Postgresql
- Potential Coin Miner Execution
- Potential Coin Miner Execution via Shell
- Potential Command and Control via Windows Scripts
- Potential Command Shell via NetCat
- Potential Credential Harvesting via Python
- Potential Credential Harvesting via Python
- Potential Direct Kubelet Access via Process Arguments
- Potential Direct Kubelet Access via Process Arguments Detected via Defend for Containers
- Potential Dynamic IEX Reconstruction via Environment Variables
- Potential Etherhiding C2 via Blockchain Connection
- Potential Execution via Clickfix Phishing
- Potential Execution via FileFix Phishing Attack
- Potential Execution via Shortcut Modification
- Potential Execution via Sliver Framework
- Potential Execution via SSH Backdoor
- Potential Execution via ZIPExec
- Potential Fake CAPTCHA Phishing Attack
- Potential Fileless Execution via Memory File Descriptor from Interpreter
- Potential Git CVE-2025-48384 Exploitation
- Potential Gsocket Activity
- Potential Hex Payload Execution via Command-Line
- Potential Hex Payload Execution via Common Utility
- Potential JAVA/JNDI Exploitation Attempt
- Potential Kubeletctl Execution
- Potential Kubeletctl Execution Detected via Defend for Containers
- Potential Lateral Movement via SMBExec
- Potential Linux Reverse Shell via Java JAR Execution
- Potential Linux Reverse Shell via Java Shell Execution
- Potential Malicious PowerShell Based on Alert Correlation
- Potential Malware-Driven SSH Brute Force Attempt
- Potential Masquerading as System Binary
- Potential Meterpreter Reverse Shell
- Potential Mining Pool Command Detection
- Potential Netcat File Listener Established
- Potential Obfuscated PowerShell Script
- Potential Obfuscated Script Execution
- Potential Pentesting PowerShell Script
- Potential PowerShell Empire Execution
- Potential PowerShell HackTool Script by Author
- Potential PowerShell HackTool Script by Function Names
- Potential PowerShell Obfuscated Script via High Entropy
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
- Potential PowerShell Obfuscation via Character Array Reconstruction
- Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation
- Potential PowerShell Obfuscation via High Numeric Character Proportion
- Potential PowerShell Obfuscation via High Special Character Proportion
- Potential PowerShell Obfuscation via Invalid Escape Sequences
- Potential PowerShell Obfuscation via Reverse Keywords
- Potential PowerShell Obfuscation via Special Character Overuse
- Potential PowerShell Obfuscation via String Concatenation
- Potential PowerShell Obfuscation via String Reordering
- Potential PowerShell Pass-the-Hash/Relay Script
- Potential Privilege Escalation via Python cap_setuid
- Potential Privilege Escalation via Python Exploit
- Potential Process Injection via PowerShell
- Potential Process Masquerading via Exec
- Potential Proxy Execution via Crash
- Potential Proxy Execution via PHP
- Potential Proxy Execution via Pidstat
- Potential Proxy Execution via Run-parts
- Potential Proxy Execution via Sed
- Potential Proxy Execution via Split
- Potential Proxy Execution via Sysctl
- Potential Proxy Execution via Systemd-run
- Potential Proxy Execution via Tcpdump
- Potential Python Reverse Shell
- Potential Python Stealer
- Potential Redis Lua Use-After-Free RCE Attempt (CVE-2025-49844 / RediShell)
- Potential Remote Code Execution via Database Server
- Potential Remote Code Execution via Langflow
- Potential Remote Code Execution via Mail Server
- Potential Remote Code Execution via URL Encoded Payload
- Potential Reverse Shell
- Potential Reverse Shell Activity via TCP/UDP Socket
- Potential Reverse Shell Activity via Terminal
- Potential Reverse Shell Activity via Terminal
- Potential Reverse Shell via Background Process
- Potential Reverse Shell via Child
- Potential Reverse Shell via Java
- Potential Reverse Shell via Java
- Potential Reverse Shell via Named Pipe
- Potential Reverse Shell via Powershell
- Potential Reverse Shell via Suspicious Binary
- Potential Reverse Shell via Suspicious Child Process
- Potential Reverse Shell via UDP
- Potential SAP NetWeaver Exploitation
- Potential SAP NetWeaver WebShell Creation
- Potential SharpRDP Behavior
- Potential Shell Execution via NetCat
- Potential Shell via Wildcard Injection Detected
- Potential Upgrade of Non-interactive Shell
- Potential Veeam Credential Access Command
- Potential WebShell via ScreenConnect Server
- Potentially Suspicious Process Started via tmux or screen
- PowerShell Empire Script Execution
- Powershell Encoded Command
- PowerShell Engine Loaded via Injection
- PowerShell Execution from WinGet Configuration Remoting Server
- Powershell Execution via Named Pipe
- Powershell Execution via Runscripthelper
- PowerShell Invoke-NinjaCopy script
- PowerShell Kerberos Ticket Dump
- PowerShell Kerberos Ticket Request
- PowerShell Keylogging Script
- PowerShell Mailbox Collection Script
- PowerShell MiniDump Script
- PowerShell Obfuscation Spawned via Microsoft Office
- PowerShell Obfuscation via Negative Index String Reversal
- Powershell Outbound Network Connection
- PowerShell PSReflect Script
- PowerShell Script with Archive Compression Capabilities
- PowerShell Script with Log Clear Capabilities
- PowerShell Script with Password Policy Discovery Capabilities
- PowerShell Script with Passwords Vault Access Capability
- PowerShell Script with Screen Capture Capability
- PowerShell Script with Token Impersonation Capabilities
- PowerShell Script with Veeam Credential Access Capabilities
- PowerShell Script with Webcam Video Capture Capabilities
- PowerShell Script with Windows Defender Tampering Capabilities
- PowerShell Share Enumeration Script
- PowerShell Suspicious Discovery Related Windows API Functions
- PowerShell Suspicious Payload Encoded and Compressed
- PowerShell Suspicious Script with Audio Capture Capabilities
- PowerShell Suspicious Script with Clipboard Retrieval Capabilities
- PowerShell Suspicious Script with Screenshot Capabilities
- Printer User (lp) Shell Execution
- Privilege Escalation Enumeration via LinPEAS
- Privileged Container Creation with Host Directory Mount
- Privileged Docker Container Creation
- Process Activity via Compiled HTML File
- Process Backgrounded by Unusual Parent
- Process Execution from Boot Directory
- Process Masquerading as Kernel Process
- Process Spawned from Message-of-the-Day (MOTD)
- Process Started from Process ID (PID) File
- Process Started with Executable Stack
- Prompt for Credentials with Osascript
- Proxy Execution via Console Window Host
- Proxy Shell Execution via Busybox
- Pseudoterminal (PTY) Creation from Suspicious Executable
- Python Initial Access via Google Drive
- Python Library Load and Delete
- Python Network Connection Followed by Command Execution
- Python Path Configuration File (.pth) with Import Preface
- Python Path File (pth) Creation
- Python Script Execution via Shell and Remote Network Connection
- Python Site or User Customize File Creation
- Rare Powershell Script
- React2Shell (CVE-2025-55182) Exploitation Attempt
- React2Shell Network Security Alert
- Recently Downloaded File Made Executable and Run
- Remote File Download via PowerShell
- Remote File Download via Script Interpreter
- Remote GitHub Actions Runner Registration
- Remote XSL Script Execution via COM
- Renamed Automation Script Interpreter
- Renice or Ulimit Execution from Unusual Parent
- Reverse or Bind Shell via Suspicious Utility
- Reverse Shell via NetworkManager Dispatcher Script
- Root Network Connection via GDB CAP_SYS_PTRACE
- ROT Encoded Python Script Execution
- RunDLL32/Regsvr32 Loads Dropped Executable
- Scheduled Task Created by a Windows Script
- ScreenConnect Server Spawning Suspicious Processes
- Script Executed Through Unusual Parent Process
- Script Execution via APDS XSS Injection
- Script Execution via Microsoft HTML Application
- Script Execution via MSXSL
- Script File Written by Microsoft Office Process
- Script Interpreter Connection to Non-Standard Port
- Script Interpreter Process Writing to Commonly Abused Persistence Locations
- Scriptlet Execution via CMSTP
- Scriptlet Execution via Rundll32
- Scriptlet Proxy Execution via PubPrn
- Self-Deleted Python Script Outbound Network Connection
- Self-Deleting Python Script
- Sensitive File Access via Perl
- Service Account Token or Certificate Access Followed by Kubernetes API Request
- Service Control Spawned via Script Interpreter
- Shared Object Load via LoLBin
- Shell Command Curl Execution via Osascript
- Shell Command Discovery Execution via Untrusted Binary
- Shell Command Execution via Kworker
- Shell Command Piped to Osascript via Shell Script
- Shell Execution of Non-Executable File
- Shell Execution via Apple Scripting
- Shell Execution via Elastic Endpoint
- Shell Execution via Java Parent Process
- Shell Execution via Windows Shortcut File
- Shell Script Execution from abnormal Volume Mount Path
- Shell via NetworkManager Dispatcher Script
- Shellcode Injection via PowerShell
- Silent NPM Package Install Command
- Simple HTTP Web Server Connection
- Simple HTTP Web Server Creation
- Sleep Execution from Suspicious Process Path
- Socat Reverse Shell or Listener Activity
- Startup Persistence via Windows Script Interpreter
- Sudo Heap-Based Buffer Overflow Attempt
- Suspicious .NET Code Compilation
- Suspicious .NET Reflection via PowerShell
- Suspicious API Call from a PowerShell Script
- Suspicious API Call via Windows Script Interpreter
- Suspicious Apple Script Execution
- Suspicious APT Package Manager Execution
- Suspicious APT Package Manager Network Connection
- Suspicious Audio Unit Plug-in File Access
- Suspicious Automator Application Execution
- Suspicious Automator Workflows Execution
- Suspicious Automator Workflows Execution
- Suspicious AWS S3 Connection via Script Interpreter
- Suspicious Base64 String Command-line
- Suspicious Binary Execution via SSH
- Suspicious Browser Child Process
- Suspicious Child Execution via Web Server
- Suspicious Child Process Execution via Interactive Shell
- Suspicious Child Process from WinGet Configuration Remoting Server
- Suspicious Child Process of Expect
- Suspicious Child Process via Azure VM CustomScript Extension
- Suspicious Cmd Execution via WMI
- Suspicious Cmd Execution via WMI
- Suspicious Codesign Execution via Osacompile
- Suspicious Command and Control via Internet Explorer
- Suspicious Command Execution via Busybox Proxy
- Suspicious Command Execution via Web Server
- Suspicious Command Execution via Windows Run
- Suspicious Command Prompt Network Connection
- Suspicious Content Extracted or Decompressed via Funzip
- Suspicious Curl Execution via Automator Workflow
- Suspicious Curl Execution via NodeJS
- Suspicious Curl to Jamf Endpoint
- Suspicious Data Encryption via OpenSSL Utility
- Suspicious DD Execution
- Suspicious Descendant Process Execution via Windows Run
- Suspicious DMG File Creation in Tmp Directory
- Suspicious Dscl Auth Validation
- Suspicious Echo Execution
- Suspicious Echo or Printf Execution Detected via Defend for Containers
- Suspicious Electron Command Execution
- Suspicious Elevated Command Execution
- Suspicious Emond Child Process
- Suspicious Executable Download via Curl
- Suspicious Executable File Creation
- Suspicious Executable File Creation via Python
- Suspicious Execution from a Mounted Device
- Suspicious Execution from a Mounted Device
- Suspicious Execution from a Windows Script
- Suspicious Execution from MSSQL Service
- Suspicious Execution from VS Code Extension
- Suspicious Execution of Unsigned or Untrusted Process via Sudo
- Suspicious Execution via a Hidden Process
- Suspicious Execution via Script Editor
- Suspicious Execution via setsid and nohup
- Suspicious Execution via ShellBrowserWindow/ShellWindow COM
- Suspicious Execution via SQL PowerShell
- Suspicious Execution via Windows Subsystem for Linux
- Suspicious Execution with NodeJS
- Suspicious Explorer Child Process
- Suspicious File Creation via Pkg Install Script
- Suspicious File Creation via Web Server
- Suspicious File Download via Google Drive
- Suspicious File Downloaded by Curl/Wget and Piped to Interpreter
- Suspicious File Made Executable via Chmod Inside A Container
- Suspicious File Overwrite and Modification via Echo
- Suspicious File Rename by an Unusual Process
- Suspicious Image Creation via ScreenCapture
- Suspicious Image Load via Windows Scripts
- Suspicious Installer Package Spawns Network Event
- Suspicious Interactive Shell Execution
- Suspicious Interactive Terminal Spawn
- Suspicious Interpreter Execution Detected via Defend for Containers
- Suspicious Interpreter Execution from Stdin
- Suspicious Java Execution via a Windows Script
- Suspicious JavaScript Execution via Deno
- Suspicious JavaScript Execution via Deno
- Suspicious JetBrains TeamCity Child Process
- Suspicious Large Script Execution via Shell Command
- Suspicious Lua Command Execution
- Suspicious macOS MS Office Child Process
- Suspicious Microsoft HTML Application Child Process
- Suspicious Microsoft IIS Worker Descendant
- Suspicious Mining Process Creation Event
- Suspicious Mining Process Events
- Suspicious MS Office Child Process
- Suspicious MS Outlook Child Process
- Suspicious Named Pipe Creation
- Suspicious Netcat Execution
- Suspicious Network Connection to Gmail via Nodejs
- Suspicious Network Connection via Installer Package
- Suspicious Network Connection via systemd
- Suspicious OpenSSL Execution via macOS Application
- Suspicious Oversized Script Execution
- Suspicious Path Invocation from Command Line
- Suspicious Perl Child Process Execution
- Suspicious Perl Command Execution
- Suspicious Perl File Modification
- Suspicious PHP Command Execution
- Suspicious PHP Script Execution
- Suspicious Portable Executable Encoded in Powershell Script
- Suspicious PowerShell Base64 Decoding
- Suspicious Powershell Child Process
- Suspicious PowerShell Downloads
- Suspicious PowerShell Engine ImageLoad
- Suspicious PowerShell Execution
- Suspicious PowerShell Execution via Windows Scripts
- Suspicious Powershell Script
- Suspicious PowerShell Script with .NET Reflection
- Suspicious Powershell via Windows Power User Menu
- Suspicious Process Execution Detected via Defend for Containers
- Suspicious Python Command Execution
- Suspicious Python Encoded Payload Execution
- Suspicious Python One-Liner with Encoded Payload Execution
- Suspicious Python Package Child Process Execution
- Suspicious Python Path Configuration File (.pth) Creation
- Suspicious Python Script Execution and Network Connection
- Suspicious Python Shell Command Execution
- Suspicious React Server Child Process
- Suspicious Remote Javascript Evaluation via Nodejs
- Suspicious Ruby Command Execution
- Suspicious ScreenConnect Client Child Process
- Suspicious Script Compilation via Osacompile
- Suspicious Script Execution via VBSEdit Launcher
- Suspicious Script Object Execution
- Suspicious Shell Command Execution via Node.js Parent
- Suspicious Shell Execution via Java Application
- Suspicious Shell Execution via Velociraptor
- Suspicious SolarWinds Web Help Desk Java Module Load or Child Process
- Suspicious System Commands Executed by Previously Unknown Executable
- Suspicious Terminal Child Process Execution
- Suspicious TruffleHog Execution via NodeJS
- Suspicious TruffleHog Execution via NodeJS
- Suspicious UID Change to Root via Python
- Suspicious Unsigned Application Execution via Shell
- Suspicious Web Server Child Process
- Suspicious Windows Command Shell Arguments
- Suspicious Windows Command Shell Execution
- Suspicious Windows Component Object Model via DLLHOST
- Suspicious Windows Defender Exclusions Added via PowerShell
- Suspicious Windows Powershell Arguments
- Suspicious Windows Schedule Child Process
- Suspicious Windows Script Base64 Encoding
- Suspicious Windows Script Downloaded from the Internet
- Suspicious Windows Script File Name
- Suspicious Windows Script Interpreter Child Process
- Suspicious Windows Script Process Execution
- Suspicious WMI Enumeration via Windows Scripts
- Suspicious XPC Service Child Process
- Suspicious Zoom Child Process
- Svchost spawning Cmd
- System Binary Path File Permission Modification
- System Binary Proxy Execution via ld.so
- System Information Discovery via Windows Command Shell
- System Path File Creation and Execution Detected via Defend for Containers
- System Shells via Services
- System Utility Execution from Unbacked Memory
- Systemd Shell Execution During Boot
- Tampering with RUNNER_TRACKING_ID in GitHub Actions Runners
- Tclsh Execution followed by immediate Network Connection
- Temporary Binary Execution via Osascript
- Torsocks Execution
- Udev Execution Followed by Egress Network Connection
- Unknown Execution of Binary with RWX Memory Region
- Unsigned or Untrusted Application Launch via XPC
- Unsigned or Untrusted Binary Execution via XPC call
- Unsigned or Untrusted Binary Fork via Python
- Unsigned or Untrusted PyInstaller Binary Execution
- Untrusted or Unsigned binary Execution via Osascript
- Unusual Base64 Encoding/Decoding Activity
- Unusual Bundle Execution via Shell
- Unusual Child Execution via Web Server
- Unusual Command Execution via Cron
- Unusual Command Execution via Systemd Scheduled Task
- Unusual Command Execution via Web Server
- Unusual D-Bus Daemon Child Process
- Unusual Execution from /dev Parent
- Unusual Execution from Kernel Thread (kthreadd) Parent
- Unusual Exim4 Child Process
- Unusual File Creation by Web Server
- Unusual File Creation via Web Server
- Unusual Interactive Shell Launched from System User
- Unusual LD_PRELOAD/LD_LIBRARY_PATH Command Line Arguments
- Unusual Library Load via Python
- Unusual Parent Process for cmd.exe
- Unusual Pkexec Execution
- Unusual PowerShell Engine ImageLoad
- Unusual Process For MSSQL Service Accounts
- Unusually large OSA script execution via Shell Command
- Unusually Large Script Executed by Osascript
- User Discovery Command Execution from Volume Mount
- User TCC DB Access by Osascript
- Veeam Backup Library Loaded by Unusual Process
- Velociraptor Suspicious Shell Execution
- Volume Muted via Osascript
- Volume Shadow Copy Deletion via PowerShell
- VScode Extension Install via URI Handler
- Web Server Exploitation Detected via Defend for Containers
- Web Server Potential Command Injection Request
- Web Server Potential SQL Injection Request
- Web Server Spawned via Python
- Web Shell Detection: Script Process Child of Common Web Processes
- Windows Command Shell Spawned via Microsoft Office
- Windows Console Execution from Unbacked Memory
- Windows Defender Exclusions Added via PowerShell
- Windows Firewall Disabled via PowerShell
- Windows Installer via Windows Script
- Windows Script Executed From a Suspicious Path
- Windows Script Executing PowerShell
- Windows Script Execution from Archive
- Windows Script Execution from Archive File
- Windows Script Execution via MMC Console File
- Windows Script Interpreter Executing Process via WMI
- Windows Server Update Service Spawning Suspicious Processes
- Windows Shortcut File Embedded Object Execution
- Windows Subsystem for Linux Distribution Installed
- Windows System Information Discovery
- World Writeable Directory Exec Remount
- World Writeable Directory File Creation and Outbound Connection
Splunk 298 rules
- 1 or 2 Character Executable (Windows Event Log)
- AutoHotkey Execution (PowerShell)
- AutoHotkey Execution (Sysmon)
- AutoHotkey Execution (Windows Event Log)
- AutoIt Execution (PowerShell)
- AutoIt Execution (Sysmon)
- AutoIt Execution (Windows Event Log)
- Bypass or Unrestricted PowerShell Execution (PowerShell)
- Cisco IOS XE Guestshell Activation and Destroy
- Cisco IOS XE Request Platform Package Describe Shell Pattern
- Cisco NVM - Installation of Typosquatted Python Package
- Cisco NVM - MSHTML or MSHTA Network Execution Without URL in CLI
- Cisco NVM - Susp Script From Archive Triggering Network Activity
- Cisco NVM - Suspicious File Download via Headless Browser
- Cisco Secure Firewall - Binary File Type Download
- Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt
- Cisco Secure Firewall - Communication Over Suspicious Ports
- Cisco Secure Firewall - High Volume of Intrusion Events Per Host
- Cisco Secure Firewall - Possibly Compromised Host
- Cisco Secure Firewall - Privileged Command Execution via HTTP
- Cisco Secure Firewall - Veeam CVE-2023-27532 Exploitation Activity
- Cisco Secure Firewall - Wget or Curl Download
- CMD Carry Out String Command Parameter
- CMD Echo Pipe - Escalation
- CMD execution with _c (PowerShell)
- CMD execution with _c (Sysmon)
- CMD execution with _c (Windows Event Log)
- Command Line .cmd Execution (Sysmon)
- Command Line .cmd Execution (Windows Event Log)
- Command Line Spawned by Archive Utility - Windows (Sysmon)
- Command Line Spawned by Archive Utility - Windows (Windows Event Log)
- Command Line Utility Added to Accessibility Features (PowerShell)
- Command Line Utility Added to Accessibility Features (Sysmon)
- Command Line Utility Added to Accessibility Features (Windows Event Log)
- Command Output Redirected to Localhost (Windows Event Log)
- Command-Line Interface Execution (PowerShell)
- Command-Line Interface Execution (Sysmon)
- Command-Line Interface Execution (Windows Event Log)
- Common Exchange Recon cmdlets (PowerShell)
- Common Reconnaissance Commands (PowerShell)
- Common Reconnaissance Commands (Sysmon)
- Common Reconnaissance Commands (Windows Event Log)
- Conhost.exe Kernel call (Sysmon)
- Conhost.exe Kernel call (Windows Event Log)
- Consent.exe Suspicious Child Process (Sysmon)
- Consent.exe Suspicious Child Process (Windows Event Log)
- CrushFTP Authentication Bypass Exploitation
- Detect Certify With PowerShell Script Block Logging
- Detect Empire with PowerShell Script Block Logging
- Detect Mimikatz With PowerShell Script Block Logging
- Detect Outbound LDAP Traffic
- Detect Prohibited Applications Spawning cmd exe
- Detect Use of cmd exe to Launch Script Interpreters
- Encoded Powershell Command (PowerShell)
- Encoded Powershell Command (Sysmon)
- Encoded Powershell Command (Windows Event Log)
- ESXi Reverse Shell Patterns
- Excessive distinct processes from Windows Temp
- Excessive number of taskhost processes
- Exchange PowerShell Module Usage
- Executable Create Script Process (PowerShell)
- Executable Create Script Process (Sysmon)
- Executable Create Script Process (Windows Event Log)
- Executable Process from Suspicious Folder (PowerShell)
- Executable Process from Suspicious Folder (Sysmon)
- Executable Process from Suspicious Folder (Windows Event Log)
- Execute Javascript With Jscript COM CLSID
- Explorer Child Process with Suspicious Command Line Padding (Sysmon)
- File Execution (Unix)
- File Modified for Execution
- Get-ForestTrust with PowerShell Script Block
- GetLocalUser with PowerShell Script Block
- GetWmiObject User Account with PowerShell Script Block
- Git Hooks Spawn System32 Process (Sysmon)
- Git Spawns System32 Process (Sysmon)
- Git Spawns System32 Process (Windows Event Log)
- Go Run Execution
- Go Run Execution (PowerShell)
- Go Run Execution (Sysmon)
- Go Run Execution (Windows Event Log)
- High Entropy Powershell (PowerShell)
- Impacket atexec.py Execution (PowerShell)
- Impacket atexec.py Execution (Sysmon)
- Impacket atexec.py Execution (Windows Event Log)
- Impacket atexec.py Scheduled Task Creation (Windows Event Log)
- Impacket atexec.py Temp File Creation (Sysmon)
- Impacket atexec.py Temp File Creation (Windows Event Log)
- Impacket SMBexec (Windows Event Log)
- Impacket_Empire's WMIExec (Windows Event Log)
- Invoke-Expression Command (PowerShell)
- Invoke-Expression Command (Sysmon)
- Invoke-Expression Command (Windows Event Log)
- Invoke-WebRequest Command (PowerShell)
- Invoke-WebRequest Command (Sysmon)
- Invoke-WebRequest Command (Windows Event Log)
- Jscript Execution Using Cscript App
- Juniper Networks Remote Code Execution Exploit Detection
- Linux Binary Executed from Shared Memory Directory
- Linux Decode Base64 to Shell
- Linux Docker Shell Execution
- Linux Enumeration Techniques
- Linux Ghostscript Exploitation
- Linux Magic SysRq Key Abuse
- Linux MOTD Script Added
- Linux Netcat Outbound Connection
- Linux Possible System Binary Backdoor
- Linux Shell Pseudo Device Reverse Shell
- Linux Suspicious Privileged Container Execution
- Linux Suspicious React or Next.js Child Process
- Linux Suspicious XDG Autostart
- Linux Unix Shell Enable All SysRq Functions
- Living Off The Land Detection
- Log4Shell CVE-2021-44228 Exploitation
- MacOS AMOS Stealer - Virtual Machine Check Activity
- MacOS LOLbin
- Malicious PowerShell Process - Execution Policy Bypass
- Malicious PowerShell Process With Obfuscation Techniques
- MCP Filesystem Server Suspicious Extension Write
- MCP Prompt Injection
- Meterpreter Reverse Shell (Windows Event Log)
- Microsoft Build Engine Suspicious Parent Process (Sysmon)
- Microsoft Build Engine Suspicious Parent Process (Windows Event Log)
- Modify Exchange Access Settings (PowerShell)
- MS Scripting Process Loading Ldap Module
- MS Scripting Process Loading WMI Module
- NirCmd Execution (PowerShell)
- NirCmd Execution (Sysmon)
- NirCmd Execution (Windows Event Log)
- Nishang PowershellTCPOneLine
- Non-MSIExec .msi Installation (PowerShell)
- Non-MSIExec .msi Installation (Windows Event Log)
- Ollama Suspicious Prompt Injection Jailbreak
- Output to File (PowerShell)
- Output to File (Windows Event Log)
- Parent in Public Folder Suspicious Process (Sysmon)
- Parent in Public Folder Suspicious Process (Windows Event Log)
- Possible Lateral Movement PowerShell Spawn
- Potential AutoHotkey .ahk Execution (PowerShell)
- Potential AutoHotkey .ahk Execution (Sysmon)
- Potential AutoHotkey .ahk Execution (Windows Event Log)
- Potential PowerShell Post-Exploitation Activity (Sysmon)
- Potential PowerShell Post-Exploitation Activity (Windows Event Log)
- Potential Proxy Malware via AutoRun Key (PowerShell)
- Potential Proxy Malware via AutoRun Key (Sysmon)
- Potential Proxy Malware via AutoRun Key (Windows Event Log)
- PowerShell 4104 Hunting
- PowerShell Clipboard Access (PowerShell)
- Powershell COM Hijacking InprocServer32 Modification
- PowerShell CreateDecryptor (PowerShell)
- PowerShell CreateDecryptor (Sysmon)
- PowerShell CreateDecryptor (Windows Event Log)
- Powershell Creating Thread Mutex
- Powershell Defender Threat Actions Set to Allow
- PowerShell Domain Enumeration
- PowerShell Downgrade (PowerShell)
- PowerShell Downgrade (Sysmon)
- PowerShell Downgrade (Windows Event Log)
- PowerShell Download Activity (PowerShell)
- PowerShell DownloadFile_DownloadString (PowerShell)
- PowerShell DownloadFile_DownloadString (Sysmon)
- PowerShell DownloadFile_DownloadString (Windows Event Log)
- PowerShell Enable PowerShell Remoting
- PowerShell Environment Variable Execution
- Powershell Execute COM Object
- Powershell Fileless Process Injection via GetProcAddress
- Powershell Fileless Script Contains Base64 Encoded Content
- PowerShell Hidden Window (PowerShell)
- PowerShell Hidden Window (Windows Event Log)
- Powershell ICMP Data Exfiltration (PowerShell)
- Powershell Load Module in Meterpreter
- PowerShell Loading DotNET into Memory via Reflection
- PowerShell Modifying Registry Values (PowerShell)
- PowerShell Modifying Registry Values (Sysmon)
- PowerShell Modifying Registry Values (Windows Event Log)
- PowerShell PInvoke Process Injection API Chain
- Powershell Processing Stream Of Data
- PowerShell Script Block With URL Chain
- PowerShell Script Keylogger (PowerShell)
- PowerShell Start or Stop Service
- Powershell Using memory As Backing Store
- PowerShell WebRequest Using Memory Stream
- PowerShell XML Retrieval (PowerShell)
- PowerShell XML Retrieval (Sysmon)
- PowerShell XML Retrieval (Windows Event Log)
- PowerShell: SMBExec Script (PowerShell)
- PowerView_SharpView Commands (PowerShell)
- Process Writing DynamicWrapperX
- PTC Windchill Gateway Command Execution
- PTC Windchill GW READY OK Probe
- Python Execution (Windows Event Log)
- Rare Process Execution (Sysmon)
- Rare Process Execution (Windows Event Log)
- Rare shell script execution
- Recon Using WMI Class
- Remote Admin Tools (PowerShell)
- Remote Admin Tools (Sysmon)
- Remote Admin Tools (Windows Event Log)
- Ryuk Wake on LAN Command
- Script Connected to External Destination - Windows (Sysmon)
- Script Connected to External Destination - Windows (Windows Event Log)
- Set Default PowerShell Execution Policy To Unrestricted or Bypass
- SharpHound Enumeration (Windows Event Log)
- Sliver C2 Implant Activity Pattern (PowerShell)
- Sliver C2 Implant Activity Pattern (Sysmon)
- Sliver C2 Implant Activity Pattern (Windows Event Log)
- Suspicious Child Process for mshta.exe (Sysmon)
- Suspicious Child Process for mshta.exe (Windows Event Log)
- Suspicious Executable by CMD.exe (Sysmon)
- Suspicious Executable by CMD.exe (Windows Event Log)
- Suspicious Executable by Powershell (Sysmon)
- Suspicious Executable by Powershell (Windows Event Log)
- Suspicious Linux Discovery Commands
- Suspicious Powershell (PowerShell)
- Suspicious PowerShell Clipboard Activity (PowerShell)
- Suspicious PowerShell Clipboard Activity (Sysmon)
- Suspicious PowerShell Clipboard Activity (Windows Event Log)
- Suspicious PowerShell Parameter Substring (PowerShell)
- Suspicious PowerShell Parameter Substring (Sysmon)
- Suspicious PowerShell Parameter Substring (Windows Event Log)
- Suspicious Process DNS Query Known Abuse Web Services
- Suspicious Process With Discord DNS Query
- Suspicious reCAPTCHA Command Line (PowerShell)
- Suspicious reCAPTCHA Command Line (Sysmon)
- Unloading AMSI via Reflection
- Vbscript Execution Using Wscript App
- WebDAV LNK Execution (Sysmon)
- WebDAV LNK Execution (Windows Event Log)
- WebLogic CVE-2017-10271 (PowerShell)
- WebLogic CVE-2017-10271 (Sysmon)
- WebLogic CVE-2017-10271 (Windows Event Log)
- Wermgr Process Spawned CMD Or Powershell Process
- Windows Account Access Removal via Logoff Exec
- Windows Apache Benchmark Binary
- Windows AutoIt3 Execution
- Windows Cmdline Tool Execution From Non-Shell Process
- Windows Cobalt Strike PowerShell Loader
- Windows Command and Scripting Interpreter Hunting Path Traversal
- Windows Command and Scripting Interpreter Path Traversal Exec
- Windows Command Shell DCRat ForkBomb Payload
- Windows Common Abused Cmd Shell Risk Behavior
- Windows Copy Files (PowerShell)
- Windows Copy Files (Sysmon)
- Windows Copy Files (Windows Event Log)
- Windows Crowdstrike RTR Script Execution
- Windows Default Cobalt Strike PowerShell Beacon
- Windows Defender ASR Audit Events
- Windows Defender ASR Block Events
- Windows Defender ASR Rules Stacking
- Windows Enable PowerShell Web Access
- Windows Explorer LNK Exploit Process Launch With Padding
- Windows Explorer.exe Spawning PowerShell or Cmd
- Windows File Association Modification via Ftype
- Windows File Download Via PowerShell
- Windows GrimResource - MMC Process Accessing APDS DLL
- Windows Identify Protocol Handlers
- Windows MSExchange Management Mailbox Cmdlet Usage
- Windows Outlook Macro Created by Suspicious Process
- Windows PaperCut NG Spawn Shell
- Windows Powershell Commands from DNS TXT
- Windows Powershell Cryptography Namespace
- Windows PowerShell FakeCAPTCHA Clipboard Execution
- Windows PowerShell Get CIMInstance Remote Computer
- Windows Powershell History File Deletion
- Windows Powershell Import Applocker Policy
- Windows PowerShell Invoke-RestMethod IP Information Collection
- Windows PowerShell Invoke-Sqlcmd Execution
- Windows Powershell Logoff User via Quser
- Windows PowerShell Module File Created
- Windows PowerShell MSIX Package Installation
- Windows PowerShell Process Implementing Manual Base64 Decoder
- Windows PowerShell Process With Malicious String
- Windows Powershell RemoteSigned File
- Windows PowerShell ScheduleTask
- Windows PowerShell Script Block With Malicious String
- Windows PowerShell Script From WindowsApps Directory
- Windows PowerShell Script TabExpansion Direct Call
- Windows PowerShell WMI Win32 ScheduledJob
- Windows PowGoop Beacon Decoding
- Windows Process Accessing Windows Recall Directory
- Windows Process Execution From RDP Share
- Windows Remote Image Load
- Windows Scheduled Task Service Spawned Shell
- Windows Shell Process from CrushFTP
- Windows Software Discovery Via PowerShell
- Windows SQL Server Extended Procedure DLL Loading Hunt
- Windows SQLCMD Execution
- Windows SSH Proxy Command
- Windows Suspicious Child Process of Consent.EXE
- Windows Suspicious React or Next.js Child Process
- Windows Suspicious VMWare Tools Child Process
- Windows TeamCity Payload Execution from Temp Directory
- Windows TeamCity Plugin Installed
- Windows TinyCC Shellcode Execution
- Windows WinDBG Spawning AutoIt3
- Windows XLL File Creation Outside of Typical Location
- Wscript_Cscript Execution (PowerShell)
- Wscript_Cscript Execution (Sysmon)
- Wscript_Cscript Execution (Windows Event Log)
Kusto 68 rules
- A host is potentially running a hacking tool (ASIM Web Session schema)
- A host is potentially running PowerShell to send HTTP(S) requests (ASIM Web Session schema)
- ApexOne - Suspicious commandline arguments
- App Gateway WAF - SQLi Detection
- Application Gateway WAF - SQLi Detection
- AWS Security Hub - Detect SSM documents public sharing enabled
- AWSCloudTrail - EC2 Startup Shell Script Changed
- Azure Machine Learning Write Operations
- Azure VM Run Command operations executing a unique PowerShell script
- Base64 encoded Windows process command-lines
- Base64 encoded Windows process command-lines (Normalized Process Events)
- Cisco Cloud Security - Hack Tool User-Agent Detected
- Cisco Cloud Security - Windows PowerShell User-Agent Detected
- CiscoISE - Command executed with the highest privileges from new IP
- CiscoISE - Command executed with the highest privileges by new user
- Critical Risks
- Cross-Cloud Suspicious Compute resource creation in GCP
- Cross-Cloud Suspicious user activity observed in GCP Envourment
- Darktrace Model Alert
- Deimos Component Execution
- Detect Local File Inclusion(LFI) in web requests (ASIM Web Session)
- Detect port misuse by anomaly based detection (ASIM Network Session schema)
- Detect port misuse by static threshold (ASIM Network Session schema)
- Detect Suspicious Commands Initiated by Webserver Processes
- Doppelpaymer Stop Services
- Dynatrace - Problem detection
- Dynatrace Application Security - Attack detection
- Dynatrace Application Security - Code-Level runtime vulnerability detection
- Dynatrace Application Security - Non-critical runtime vulnerability detection
- Dynatrace Application Security - Third-Party runtime vulnerability detection
- Exchange Worker Process Making Remote Call
- Execution attempts stateful anomaly on database
- Front Door Premium WAF - SQLi Detection
- Google SecOps - Single-Event Alert
- Google Threat Intelligence - Threat Hunting Hash
- Java Executing cmd to run Powershell
- Midnight Blizzard - Script payload stored in Registry
- New CloudShell User
- NRT Base64 Encoded Windows Process Command-lines
- NRT Process executed from binary hidden in Base64 encoded file
- Office Apps Launching Wscipt
- Pathlock TDnR - Function Module Tested in Production
- Pathlock TDnR - Logical OS Command Changes
- Pathlock TDnR - SAP Batch Job Events
- Pathlock TDnR - TMS Transport and Import Events
- Potential Ransomware activity related to Cobalt Strike
- Powershell Empire Cmdlets Executed in Command Line
- PowerShell Encoded Command Execution (Living off the Land)
- PowerShell without powershell.exe
- Process Creation with Suspicious CommandLine Arguments
- Process executed from binary hidden in Base64 encoded file
- Process Execution Frequency Anomaly
- Qakbot Discovery Activies
- RecordedFuture Threat Hunting Hash All Actors
- SAP BTP - Cloud Integration artifact deployment
- Script Interpreter Loading DotNet Assembly From Memory
- SonicWall - Allowed SSH, Telnet, and RDP Connections
- SUNBURST and SUPERNOVA backdoor hashes
- SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)
- SUNBURST network beacons
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events)
- Suspicious Powershell Commandlet Executed
- TEARDROP memory-only dropper
- TrendAI Vision One - Create Incident for Workbench Alerts
- Vulerabilities
- Windows Binaries Executed from Non-Default Directory
- Windows Binaries Lolbins Renamed
- WMI Spawning Suspicious Child Process (Living off the Land)
YARA-L 7 rules
- Base64 Encoded PowerShell Command Detected
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Hacktool - IronSharpPack Execution
- PowerShell DownloadFile
- PowerShell Web Download
- sap execution of sensitive abap program
- W3WP Launching Encoded Powershell
Panther 12 rules
- AWS EC2 Startup Script Change
- AWS WAF Managed Known Bad Inputs Passthrough Rule
- AWS WAF ReactJS RCE Attempt via Body
- Azure Automation Runbook Created or Modified
- Azure Serverless Script Execution
- CrowdStrike MacOS Osascript as Administrator
- Crowdstrike Reverse Shell Tool Executed
- Databricks Global Init Script Changes
- StopInstance WITH ModifyInstanceAttributes
- Teleport Suspicious Commands Executed
- Upwind Runtime Detection Passthrough
- User Logged in as root