{"blocks":{"eir-block-01":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml\" target=\"_blank\" rel=\"noopener\">Remote File Download via MpCmdRun</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_rmm_after_msi_install.toml\" target=\"_blank\" rel=\"noopener\">Remote Management Access Launch After MSI Install</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_rmm_netsupport_susp_path.toml\" target=\"_blank\" rel=\"noopener\">NetSupport Manager Execution from an Unusual Path</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_screenconnect_childproc.toml\" target=\"_blank\" rel=\"noopener\">Suspicious ScreenConnect Client Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_tool_transfer_via_curl.toml\" target=\"_blank\" rel=\"noopener\">Potential File Transfer via Curl for Windows</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_tunnel_cloudflared.toml\" target=\"_blank\" rel=\"noopener\">Potential Protocol Tunneling via Cloudflared</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_tunnel_vscode.toml\" target=\"_blank\" rel=\"noopener\">Attempt to Establish VScode Remote Tunnel</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_tunnel_yuze.toml\" target=\"_blank\" rel=\"noopener\">Potential Protocol Tunneling via Yuze</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_velociraptor_shell_execution.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Shell Execution via Velociraptor</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_browsers_unusual_parent.toml\" target=\"_blank\" rel=\"noopener\">Browser Process Spawned from an Unusual Parent</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_cmdline_dump_tool.toml\" target=\"_blank\" rel=\"noopener\">Potential Credential Access via Windows Utilities</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml\" target=\"_blank\" rel=\"noopener\">NTDS or SAM Database File Copied</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_dump_registry_hives.toml\" target=\"_blank\" rel=\"noopener\">Credential Acquisition via Registry Hive Dumping</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_iis_connectionstrings_dumping.toml\" target=\"_blank\" rel=\"noopener\">Microsoft IIS Connection Strings Decryption</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_relay_ntlm_auth_via_http_spoolss.toml\" target=\"_blank\" rel=\"noopener\">Potential Local NTLM Relay via HTTP</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_saved_creds_vaultcmd.toml\" target=\"_blank\" rel=\"noopener\">Searching for Saved Credentials via VaultCmd</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_symbolic_link_to_shadow_copy_created.toml\" target=\"_blank\" rel=\"noopener\">Symbolic Link to Shadow Copy Created</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_veeam_commands.toml\" target=\"_blank\" rel=\"noopener\">Potential Veeam Credential Access Command</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_wbadmin_ntds.toml\" target=\"_blank\" rel=\"noopener\">NTDS Dump via Wbadmin</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_wireless_creds_dumping.toml\" target=\"_blank\" rel=\"noopener\">Wireless Credential Dumping using Netsh Command</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_adding_the_hidden_file_attribute_with_via_attribexe.toml\" target=\"_blank\" rel=\"noopener\">Adding Hidden File Attribute via Attrib</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_clearing_windows_console_history.toml\" target=\"_blank\" rel=\"noopener\">Clearing Windows Console History</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_clearing_windows_event_logs.toml\" target=\"_blank\" rel=\"noopener\">Clearing Windows Event Logs</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_code_signing_policy_modification_builtin_tools.toml\" target=\"_blank\" rel=\"noopener\">Code Signing Policy Modification Through Built-in tools</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_defender_exclusion_via_powershell.toml\" target=\"_blank\" rel=\"noopener\">Windows Defender Exclusions Added via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_delete_volume_usn_journal_with_fsutil.toml\" target=\"_blank\" rel=\"noopener\">Delete Volume USN Journal with Fsutil</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_disable_windows_firewall_rules_with_netsh.toml\" target=\"_blank\" rel=\"noopener\">Disable Windows Firewall Rules via Netsh</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_disabling_windows_defender_powershell.toml\" target=\"_blank\" rel=\"noopener\">Disabling Windows Defender Security Settings via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_disabling_windows_logs.toml\" target=\"_blank\" rel=\"noopener\">Disable Windows Event and Security Logs Using Built-in Tools</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious .NET Code Compilation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_enable_inbound_rdp_with_netsh.toml\" target=\"_blank\" rel=\"noopener\">Remote Desktop Enabled in Windows Firewall by Netsh</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_enable_network_discovery_with_netsh.toml\" target=\"_blank\" rel=\"noopener\">Enable Host Network Discovery via Netsh</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml\" target=\"_blank\" rel=\"noopener\">Control Panel Process with Unusual Arguments</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_lolbas_wuauclt.toml\" target=\"_blank\" rel=\"noopener\">ImageLoad via Windows Update Auto Update Client</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Build Engine Started by an Office Application</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_msbuild_started_by_system_process.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Build Engine Started by a System Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_from_unusual_directory.toml\" target=\"_blank\" rel=\"noopener\">Process Execution from an Unusual Directory</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_iis_httplogging_disabled.toml\" target=\"_blank\" rel=\"noopener\">IIS HTTP Logging Disabled</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_indirect_exec_conhost.toml\" target=\"_blank\" rel=\"noopener\">Proxy Execution via Console Window Host</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_indirect_exec_forfiles.toml\" target=\"_blank\" rel=\"noopener\">Command Execution via ForFiles</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_indirect_exec_openssh.toml\" target=\"_blank\" rel=\"noopener\">Proxy Execution via Windows OpenSSH</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_lolbas_win_cdb_utility.toml\" target=\"_blank\" rel=\"noopener\">Execution via Windows Command Debugging Utility</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_as_elastic_endpoint_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Endpoint Security Parent Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_trusted_directory.toml\" target=\"_blank\" rel=\"noopener\">Program Files Directory Masquerading</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_modify_ownership_os_files.toml\" target=\"_blank\" rel=\"noopener\">System File Ownership Change</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_mshta_susp_child.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Microsoft HTML Application Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msiexec_remote_payload.toml\" target=\"_blank\" rel=\"noopener\">Potential Remote Install via MsiExec</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_obf_args_unicode_modified_letters.toml\" target=\"_blank\" rel=\"noopener\">Command Obfuscation via Unicode Modifier Letters</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_powershell_windows_firewall_disabled.toml\" target=\"_blank\" rel=\"noopener\">Windows Firewall Disabled via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_script_via_html_app.toml\" target=\"_blank\" rel=\"noopener\">Script Execution via Microsoft HTML Application</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_suspicious_certutil_commands.toml\" target=\"_blank\" rel=\"noopener\">Suspicious CertUtil Commands</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_suspicious_zoom_child_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Zoom Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_system_vp_child_program.toml\" target=\"_blank\" rel=\"noopener\">Unusual Child Process from a System Virtual Process</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_via_filter_manager.toml\" target=\"_blank\" rel=\"noopener\">Potential Evasion via Filter Manager</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_workfolders_control_execution.toml\" target=\"_blank\" rel=\"noopener\">Signed Proxy Execution via MS Work Folders</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_child_process.toml\" target=\"_blank\" rel=\"noopener\">Execution via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_enabled_via_dism.toml\" target=\"_blank\" rel=\"noopener\">Windows Subsystem for Linux Enabled via Dism Utility</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_kalilinux.toml\" target=\"_blank\" rel=\"noopener\">Attempt to Install Kali Linux via WSL</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_ad_explorer_execution.toml\" target=\"_blank\" rel=\"noopener\">Active Directory Discovery using AdExplorer</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_adfind_command_activity.toml\" target=\"_blank\" rel=\"noopener\">AdFind Command Activity</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_admin_recon.toml\" target=\"_blank\" rel=\"noopener\">Enumeration of Administrator Accounts</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_enumerating_domain_trusts_via_dsquery.toml\" target=\"_blank\" rel=\"noopener\">Enumerating Domain Trusts via DSQUERY.EXE</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_enumerating_domain_trusts_via_nltest.toml\" target=\"_blank\" rel=\"noopener\">Enumerating Domain Trusts via NLTEST.EXE</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_group_policy_object_discovery.toml\" target=\"_blank\" rel=\"noopener\">Group Policy Discovery via Microsoft GPResult Utility</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_peripheral_device.toml\" target=\"_blank\" rel=\"noopener\">Peripheral Device Discovery</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_whoami_command_activity.toml\" target=\"_blank\" rel=\"noopener\">Whoami Process Activity</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_apt_solarwinds_backdoor_child_cmd_powershell.toml\" target=\"_blank\" rel=\"noopener\">Command Execution via SolarWinds Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_com_object_xwizard.toml\" target=\"_blank\" rel=\"noopener\">Execution of COM object via Xwizard</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_enumeration_via_wmiprvse.toml\" target=\"_blank\" rel=\"noopener\">Enumeration Command Spawned via WMIPrvSE</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_from_unusual_path_cmdline.toml\" target=\"_blank\" rel=\"noopener\">Execution from Unusual Directory - Command Line</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_initial_access_foxmail_exploit.toml\" target=\"_blank\" rel=\"noopener\">Potential Foxmail Exploitation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_mofcomp.toml\" target=\"_blank\" rel=\"noopener\">Mofcomp Activity</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_nodejs_susp_patterns.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution with NodeJS</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_powershell_susp_args_via_winscript.toml\" target=\"_blank\" rel=\"noopener\">Command and Scripting Interpreter via Windows Scripts</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_scripting_remote_webdav.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution from a WebDav Share</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_scripts_archive_file.toml\" target=\"_blank\" rel=\"noopener\">Windows Script Execution from Archive</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_susp_javascript_via_deno.toml\" target=\"_blank\" rel=\"noopener\">Suspicious JavaScript Execution via Deno</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_suspicious_cmd_wmi.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Cmd Execution via WMI</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_suspicious_pdf_reader.toml\" target=\"_blank\" rel=\"noopener\">Suspicious PDF Reader Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_via_compiled_html_file.toml\" target=\"_blank\" rel=\"noopener\">Process Activity via Compiled HTML File</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_via_mmc_console_file_unusual_path.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Management Console File from Unusual Path</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_cmd_shell_susp_args.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Windows Command Shell Arguments</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_fakecaptcha_cmd_ps.toml\" target=\"_blank\" rel=\"noopener\">Potential Fake CAPTCHA Phishing Attack</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_powershell_susp_args.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Windows Powershell Arguments</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/exfiltration_rclone_cloud_upload.toml\" target=\"_blank\" rel=\"noopener\">Potential Data Exfiltration via Rclone</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_deleting_backup_catalogs_with_wbadmin.toml\" target=\"_blank\" rel=\"noopener\">Backup Deletion with Wbadmin</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_modification_of_boot_config.toml\" target=\"_blank\" rel=\"noopener\">Modification of Boot Configuration</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_volume_shadow_copy_deletion_or_resized_via_vssadmin.toml\" target=\"_blank\" rel=\"noopener\">Volume Shadow Copy Deleted or Resized via VssAdmin</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_volume_shadow_copy_deletion_via_powershell.toml\" target=\"_blank\" rel=\"noopener\">Volume Shadow Copy Deletion via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_volume_shadow_copy_deletion_via_wmic.toml\" target=\"_blank\" rel=\"noopener\">Volume Shadow Copy Deletion via WMIC</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_execution_from_inetcache.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution from INET Cache</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_exploit_jetbrains_teamcity.toml\" target=\"_blank\" rel=\"noopener\">Suspicious JetBrains TeamCity Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_rdp_file_mail_attachment.toml\" target=\"_blank\" rel=\"noopener\">Remote Desktop File Opened from Suspicious Path</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_ms_exchange_process.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Exchange Server UM Spawning Suspicious Processes</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_ms_office_child_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious MS Office Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_ms_outlook_child_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious MS Outlook Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_webshell_screenconnect_server.toml\" target=\"_blank\" rel=\"noopener\">ScreenConnect Server Spawning Suspicious Processes</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_from_tsclient_mup.toml\" target=\"_blank\" rel=\"noopener\">Execution via TSClient Mountpoint</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_mount_hidden_or_webdav_share_net.toml\" target=\"_blank\" rel=\"noopener\">Mounting Hidden or WebDav Remote Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_remote_file_copy_hidden_share.toml\" target=\"_blank\" rel=\"noopener\">Remote File Copy to a Hidden Share</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_unusual_dns_service_children.toml\" target=\"_blank\" rel=\"noopener\">Unusual Child Process of dns.exe</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_via_wsus_update.toml\" target=\"_blank\" rel=\"noopener\">Potential WSUS Abuse for Lateral Movement</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_powershell_exch_mailbox_activesync_add_device.toml\" target=\"_blank\" rel=\"noopener\">New ActiveSyncAllowedDeviceID Added via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_system_shells_via_services.toml\" target=\"_blank\" rel=\"noopener\">System Shells via Services</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_user_account_creation.toml\" target=\"_blank\" rel=\"noopener\">User Account Creation</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_application_shimming.toml\" target=\"_blank\" rel=\"noopener\">Potential Application Shimming via Sdbinst</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_telemetrycontroller_scheduledtask_hijack.toml\" target=\"_blank\" rel=\"noopener\">Persistence via TelemetryController Scheduled Task Hijack</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_update_orchestrator_service_hijack.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Update Orchestrator Service Hijack</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml\" target=\"_blank\" rel=\"noopener\">Persistence via WMI Event Subscription</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_create_process_as_different_user.toml\" target=\"_blank\" rel=\"noopener\">Process Creation via Secondary Logon</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4624\">4624</a>: An account was successfully logged on.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4625\">4625</a>: An account failed to log on.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4634\">4634</a>: An account was logged off.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4647\">4647</a>: User initiated logoff.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4648\">4648</a>: A logon was attempted using explicit credentials.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4611\">4611</a>: A trusted logon process has been registered with the Local Security Authority.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4649\">4649</a>: A replay attack was detected.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_named_pipe_impersonation.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Named Pipe Impersonation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_service_control_spawned_script_int.toml\" target=\"_blank\" rel=\"noopener\">Service Control Spawned via Script Interpreter</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_diskcleanup_hijack.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass via DiskCleanup Scheduled Task Hijack</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml\" target=\"_blank\" rel=\"noopener\">Bypass UAC via Event Viewer</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_mock_windir.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass Attempt via Windows Directory Masquerading</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_unquoted_service_path.toml\" target=\"_blank\" rel=\"noopener\">Potential Exploitation of an Unquoted Service Path Vulnerability</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_unusual_parentchild_relationship.toml\" target=\"_blank\" rel=\"noopener\">Unusual Parent-Child Relationship</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_unusual_printspooler_childprocess.toml\" target=\"_blank\" rel=\"noopener\">Unusual Print Spooler Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n","eir-block-02":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/cross-platform/initial_access_execution_susp_react_serv_child.toml\" target=\"_blank\" rel=\"noopener\">Suspicious React Server Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/collection_email_powershell_exchange_mailbox.toml\" target=\"_blank\" rel=\"noopener\">Exporting Exchange Mailbox via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/collection_winrar_encryption.toml\" target=\"_blank\" rel=\"noopener\">Encrypting Files with WinRar or 7z</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_certreq_postdata.toml\" target=\"_blank\" rel=\"noopener\">Potential File Transfer via Certreq</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_dns_tunneling_nslookup.toml\" target=\"_blank\" rel=\"noopener\">Potential DNS Tunneling via NsLookup</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_headless_browser.toml\" target=\"_blank\" rel=\"noopener\">Potential File Download via a Headless Browser</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_iexplore_via_com.toml\" target=\"_blank\" rel=\"noopener\">Potential Command and Control via Internet Explorer</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#7\">7</a>: Image loaded</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_rdp_tunnel_plink.toml\" target=\"_blank\" rel=\"noopener\">Potential Remote Desktop Tunneling Detected</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_remote_file_copy_desktopimgdownldr.toml\" target=\"_blank\" rel=\"noopener\">Remote File Download via Desktopimgdownldr Utility</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_remote_file_copy_mpcmdrun.toml\" target=\"_blank\" rel=\"noopener\">Remote File Download via MpCmdRun</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_rmm_after_msi_install.toml\" target=\"_blank\" rel=\"noopener\">Remote Management Access Launch After MSI Install</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_rmm_netsupport_susp_path.toml\" target=\"_blank\" rel=\"noopener\">NetSupport Manager Execution from an Unusual Path</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_screenconnect_childproc.toml\" target=\"_blank\" rel=\"noopener\">Suspicious ScreenConnect Client Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_tunnel_cloudflared.toml\" target=\"_blank\" rel=\"noopener\">Potential Protocol Tunneling via Cloudflared</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_tunnel_vscode.toml\" target=\"_blank\" rel=\"noopener\">Attempt to Establish VScode Remote Tunnel</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_tunnel_yuze.toml\" target=\"_blank\" rel=\"noopener\">Potential Protocol Tunneling via Yuze</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/command_and_control_velociraptor_shell_execution.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Shell Execution via Velociraptor</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_browsers_unusual_parent.toml\" target=\"_blank\" rel=\"noopener\">Browser Process Spawned from an Unusual Parent</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_cmdline_dump_tool.toml\" target=\"_blank\" rel=\"noopener\">Potential Credential Access via Windows Utilities</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_copy_ntds_sam_volshadowcp_cmdline.toml\" target=\"_blank\" rel=\"noopener\">NTDS or SAM Database File Copied</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_credential_dumping_msbuild.toml\" target=\"_blank\" rel=\"noopener\">Potential Credential Access via Trusted Developer Utility</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_dump_registry_hives.toml\" target=\"_blank\" rel=\"noopener\">Credential Acquisition via Registry Hive Dumping</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_iis_connectionstrings_dumping.toml\" target=\"_blank\" rel=\"noopener\">Microsoft IIS Connection Strings Decryption</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_relay_ntlm_auth_via_http_spoolss.toml\" target=\"_blank\" rel=\"noopener\">Potential Local NTLM Relay via HTTP</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_saved_creds_vaultcmd.toml\" target=\"_blank\" rel=\"noopener\">Searching for Saved Credentials via VaultCmd</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_symbolic_link_to_shadow_copy_created.toml\" target=\"_blank\" rel=\"noopener\">Symbolic Link to Shadow Copy Created</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_veeam_commands.toml\" target=\"_blank\" rel=\"noopener\">Potential Veeam Credential Access Command</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_wbadmin_ntds.toml\" target=\"_blank\" rel=\"noopener\">NTDS Dump via Wbadmin</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/credential_access_wireless_creds_dumping.toml\" target=\"_blank\" rel=\"noopener\">Wireless Credential Dumping using Netsh Command</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_adding_the_hidden_file_attribute_with_via_attribexe.toml\" target=\"_blank\" rel=\"noopener\">Adding Hidden File Attribute via Attrib</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_clearing_windows_console_history.toml\" target=\"_blank\" rel=\"noopener\">Clearing Windows Console History</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_clearing_windows_event_logs.toml\" target=\"_blank\" rel=\"noopener\">Clearing Windows Event Logs</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_code_signing_policy_modification_builtin_tools.toml\" target=\"_blank\" rel=\"noopener\">Code Signing Policy Modification Through Built-in tools</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_communication_apps_suspicious_child_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Communication App Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_defender_exclusion_via_powershell.toml\" target=\"_blank\" rel=\"noopener\">Windows Defender Exclusions Added via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_delete_volume_usn_journal_with_fsutil.toml\" target=\"_blank\" rel=\"noopener\">Delete Volume USN Journal with Fsutil</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_disable_windows_firewall_rules_with_netsh.toml\" target=\"_blank\" rel=\"noopener\">Disable Windows Firewall Rules via Netsh</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_disabling_windows_defender_powershell.toml\" target=\"_blank\" rel=\"noopener\">Disabling Windows Defender Security Settings via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_disabling_windows_logs.toml\" target=\"_blank\" rel=\"noopener\">Disable Windows Event and Security Logs Using Built-in Tools</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_dotnet_compiler_parent_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious .NET Code Compilation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_enable_inbound_rdp_with_netsh.toml\" target=\"_blank\" rel=\"noopener\">Remote Desktop Enabled in Windows Firewall by Netsh</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_enable_network_discovery_with_netsh.toml\" target=\"_blank\" rel=\"noopener\">Enable Host Network Discovery via Netsh</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_control_panel_suspicious_args.toml\" target=\"_blank\" rel=\"noopener\">Control Panel Process with Unusual Arguments</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_lolbas_wuauclt.toml\" target=\"_blank\" rel=\"noopener\">ImageLoad via Windows Update Auto Update Client</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_msbuild_started_by_office_app.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Build Engine Started by an Office Application</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_msbuild_started_by_system_process.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Build Engine Started by a System Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_msbuild_started_renamed.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Build Engine Using an Alternate Name</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_suspicious_explorer_winword.toml\" target=\"_blank\" rel=\"noopener\">Potential DLL Side-Loading via Trusted Microsoft Programs</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_execution_windefend_unusual_path.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Microsoft Antimalware Service Execution</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_from_unusual_directory.toml\" target=\"_blank\" rel=\"noopener\">Process Execution from an Unusual Directory</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_iis_httplogging_disabled.toml\" target=\"_blank\" rel=\"noopener\">IIS HTTP Logging Disabled</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_indirect_exec_conhost.toml\" target=\"_blank\" rel=\"noopener\">Proxy Execution via Console Window Host</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_indirect_exec_forfiles.toml\" target=\"_blank\" rel=\"noopener\">Command Execution via ForFiles</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_indirect_exec_openssh.toml\" target=\"_blank\" rel=\"noopener\">Proxy Execution via Windows OpenSSH</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_installutil_beacon.toml\" target=\"_blank\" rel=\"noopener\">InstallUtil Process Making Network Connections</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_lolbas_win_cdb_utility.toml\" target=\"_blank\" rel=\"noopener\">Execution via Windows Command Debugging Utility</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_as_elastic_endpoint_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Endpoint Security Parent Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_business_apps_installer.toml\" target=\"_blank\" rel=\"noopener\">Potential Masquerading as Business App Installer</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_communication_apps.toml\" target=\"_blank\" rel=\"noopener\">Potential Masquerading as Communication Apps</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_renamed_autoit.toml\" target=\"_blank\" rel=\"noopener\">Renamed Automation Script Interpreter</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_suspicious_werfault_childproc.toml\" target=\"_blank\" rel=\"noopener\">Suspicious WerFault Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_trusted_directory.toml\" target=\"_blank\" rel=\"noopener\">Program Files Directory Masquerading</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_werfault.toml\" target=\"_blank\" rel=\"noopener\">Potential Windows Error Manager Masquerading</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml\" target=\"_blank\" rel=\"noopener\">Network Connection via Signed Binary</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_modify_ownership_os_files.toml\" target=\"_blank\" rel=\"noopener\">System File Ownership Change</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msbuild_making_network_connections.toml\" target=\"_blank\" rel=\"noopener\">MsBuild Making Network Connections</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_mshta_beacon.toml\" target=\"_blank\" rel=\"noopener\">Mshta Making Network Connections</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_mshta_susp_child.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Microsoft HTML Application Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msiexec_child_proc_netcon.toml\" target=\"_blank\" rel=\"noopener\">MsiExec Service Child Process With Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msiexec_remote_payload.toml\" target=\"_blank\" rel=\"noopener\">Potential Remote Install via MsiExec</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msxsl_network.toml\" target=\"_blank\" rel=\"noopener\">Network Connection via MsXsl</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_network_connection_from_windows_binary.toml\" target=\"_blank\" rel=\"noopener\">Unusual Network Activity from a Windows System Binary</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_obf_args_unicode_modified_letters.toml\" target=\"_blank\" rel=\"noopener\">Command Obfuscation via Unicode Modifier Letters</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_parent_process_pid_spoofing.toml\" target=\"_blank\" rel=\"noopener\">Parent Process PID Spoofing</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_powershell_windows_firewall_disabled.toml\" target=\"_blank\" rel=\"noopener\">Windows Firewall Disabled via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_proxy_execution_via_msdt.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Microsoft Diagnostics Wizard Execution</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_run_virt_windowssandbox.toml\" target=\"_blank\" rel=\"noopener\">Windows Sandbox with Sensitive Configuration</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_rundll32_no_arguments.toml\" target=\"_blank\" rel=\"noopener\">Unusual Child Processes of RunDLL32</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_sc_sdset.toml\" target=\"_blank\" rel=\"noopener\">Service DACL Modification via sc.exe</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_script_via_html_app.toml\" target=\"_blank\" rel=\"noopener\">Script Execution via Microsoft HTML Application</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_suspicious_certutil_commands.toml\" target=\"_blank\" rel=\"noopener\">Suspicious CertUtil Commands</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_suspicious_execution_from_mounted_device.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution from a Mounted Device</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_suspicious_short_program_name.toml\" target=\"_blank\" rel=\"noopener\">Renamed Utility Executed with Short Program Name</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_suspicious_wmi_script.toml\" target=\"_blank\" rel=\"noopener\">Suspicious WMIC XSL Script Execution</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_suspicious_zoom_child_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Zoom Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_dir_ads.toml\" target=\"_blank\" rel=\"noopener\">Unusual Process Execution Path - Alternate Data Stream</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_network_connection_via_dllhost.toml\" target=\"_blank\" rel=\"noopener\">Unusual Network Connection via DllHost</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml\" target=\"_blank\" rel=\"noopener\">Unusual Network Connection via RunDLL32</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_process_network_connection.toml\" target=\"_blank\" rel=\"noopener\">Unusual Process Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_system_vp_child_program.toml\" target=\"_blank\" rel=\"noopener\">Unusual Child Process from a System Virtual Process</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_via_filter_manager.toml\" target=\"_blank\" rel=\"noopener\">Potential Evasion via Filter Manager</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_workfolders_control_execution.toml\" target=\"_blank\" rel=\"noopener\">Signed Proxy Execution via MS Work Folders</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_bash_exec.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_child_process.toml\" target=\"_blank\" rel=\"noopener\">Execution via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_enabled_via_dism.toml\" target=\"_blank\" rel=\"noopener\">Windows Subsystem for Linux Enabled via Dism Utility</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_filesystem.toml\" target=\"_blank\" rel=\"noopener\">Host File System Changes via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_kalilinux.toml\" target=\"_blank\" rel=\"noopener\">Attempt to Install Kali Linux via WSL</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_ad_explorer_execution.toml\" target=\"_blank\" rel=\"noopener\">Active Directory Discovery using AdExplorer</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_adfind_command_activity.toml\" target=\"_blank\" rel=\"noopener\">AdFind Command Activity</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_enumerating_domain_trusts_via_dsquery.toml\" target=\"_blank\" rel=\"noopener\">Enumerating Domain Trusts via DSQUERY.EXE</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_enumerating_domain_trusts_via_nltest.toml\" target=\"_blank\" rel=\"noopener\">Enumerating Domain Trusts via NLTEST.EXE</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_group_policy_object_discovery.toml\" target=\"_blank\" rel=\"noopener\">Group Policy Discovery via Microsoft GPResult Utility</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_peripheral_device.toml\" target=\"_blank\" rel=\"noopener\">Peripheral Device Discovery</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_apt_solarwinds_backdoor_child_cmd_powershell.toml\" target=\"_blank\" rel=\"noopener\">Command Execution via SolarWinds Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_apt_solarwinds_backdoor_unusual_child_processes.toml\" target=\"_blank\" rel=\"noopener\">Suspicious SolarWinds Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_com_object_xwizard.toml\" target=\"_blank\" rel=\"noopener\">Execution of COM object via Xwizard</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_command_prompt_connecting_to_the_internet.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Command Prompt Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_command_shell_started_by_unusual_process.toml\" target=\"_blank\" rel=\"noopener\">Unusual Parent Process for cmd.exe</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_command_shell_via_rundll32.toml\" target=\"_blank\" rel=\"noopener\">Command Shell Activity Started via RunDLL32</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_enumeration_via_wmiprvse.toml\" target=\"_blank\" rel=\"noopener\">Enumeration Command Spawned via WMIPrvSE</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_from_unusual_path_cmdline.toml\" target=\"_blank\" rel=\"noopener\">Execution from Unusual Directory - Command Line</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml\" target=\"_blank\" rel=\"noopener\">Network Connection via Compiled HTML File</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_initial_access_foxmail_exploit.toml\" target=\"_blank\" rel=\"noopener\">Potential Foxmail Exploitation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_initial_access_via_msc_file.toml\" target=\"_blank\" rel=\"noopener\">Unusual Execution via Microsoft Common Console File</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_ms_office_written_file.toml\" target=\"_blank\" rel=\"noopener\">Execution of File Written or Modified by Microsoft Office</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_nodejs_susp_patterns.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution with NodeJS</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_notepad_markdown_child_process.toml\" target=\"_blank\" rel=\"noopener\">Potential Notepad Markdown RCE Exploitation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_powershell_susp_args_via_winscript.toml\" target=\"_blank\" rel=\"noopener\">Command and Scripting Interpreter via Windows Scripts</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_psexec_lateral_movement_command.toml\" target=\"_blank\" rel=\"noopener\">PsExec Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_revshell_cmd_via_netcat.toml\" target=\"_blank\" rel=\"noopener\">Potential Command Shell via NetCat</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_scripting_remote_webdav.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution from a WebDav Share</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_scripts_archive_file.toml\" target=\"_blank\" rel=\"noopener\">Windows Script Execution from Archive</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_susp_javascript_via_deno.toml\" target=\"_blank\" rel=\"noopener\">Suspicious JavaScript Execution via Deno</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_suspicious_cmd_wmi.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Cmd Execution via WMI</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_suspicious_pdf_reader.toml\" target=\"_blank\" rel=\"noopener\">Suspicious PDF Reader Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_suspicious_psexesvc.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Process Execution via Renamed PsExec Executable</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_via_compiled_html_file.toml\" target=\"_blank\" rel=\"noopener\">Process Activity via Compiled HTML File</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_via_hidden_shell_conhost.toml\" target=\"_blank\" rel=\"noopener\">Conhost Spawned By Suspicious Parent Process</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_via_mmc_console_file_unusual_path.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Management Console File from Unusual Path</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_cmd_shell_susp_args.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Windows Command Shell Arguments</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_fakecaptcha_cmd_ps.toml\" target=\"_blank\" rel=\"noopener\">Potential Fake CAPTCHA Phishing Attack</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_phish_clickfix.toml\" target=\"_blank\" rel=\"noopener\">Potential Execution via FileFix Phishing Attack</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_powershell_susp_args.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Windows Powershell Arguments</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_script_from_internet.toml\" target=\"_blank\" rel=\"noopener\">Execution of a Downloaded Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/exfiltration_rclone_cloud_upload.toml\" target=\"_blank\" rel=\"noopener\">Potential Data Exfiltration via Rclone</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_deleting_backup_catalogs_with_wbadmin.toml\" target=\"_blank\" rel=\"noopener\">Backup Deletion with Wbadmin</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_modification_of_boot_config.toml\" target=\"_blank\" rel=\"noopener\">Modification of Boot Configuration</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_volume_shadow_copy_deletion_or_resized_via_vssadmin.toml\" target=\"_blank\" rel=\"noopener\">Volume Shadow Copy Deleted or Resized via VssAdmin</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_volume_shadow_copy_deletion_via_powershell.toml\" target=\"_blank\" rel=\"noopener\">Volume Shadow Copy Deletion via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_volume_shadow_copy_deletion_via_wmic.toml\" target=\"_blank\" rel=\"noopener\">Volume Shadow Copy Deletion via WMIC</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_execution_from_inetcache.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution from INET Cache</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_execution_via_office_addins.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution via Microsoft Office Add-Ins</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_exploit_jetbrains_teamcity.toml\" target=\"_blank\" rel=\"noopener\">Suspicious JetBrains TeamCity Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_rdp_file_mail_attachment.toml\" target=\"_blank\" rel=\"noopener\">Remote Desktop File Opened from Suspicious Path</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_script_executing_powershell.toml\" target=\"_blank\" rel=\"noopener\">Windows Script Executing PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_scripts_process_started_via_wmi.toml\" target=\"_blank\" rel=\"noopener\">Windows Script Interpreter Executing Process via WMI</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_ms_exchange_process.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Exchange Server UM Spawning Suspicious Processes</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_ms_exchange_worker_child_process.toml\" target=\"_blank\" rel=\"noopener\">Microsoft Exchange Worker Spawning Suspicious Processes</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_ms_office_child_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious MS Office Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_ms_outlook_child_process.toml\" target=\"_blank\" rel=\"noopener\">Suspicious MS Outlook Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_windows_server_update_svc.toml\" target=\"_blank\" rel=\"noopener\">Windows Server Update Service Spawning Suspicious Processes</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_url_cve_2025_33053.toml\" target=\"_blank\" rel=\"noopener\">Potential CVE-2025-33053 Exploitation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_via_explorer_suspicious_child_parent_args.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Explorer Child Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_webshell_screenconnect_server.toml\" target=\"_blank\" rel=\"noopener\">ScreenConnect Server Spawning Suspicious Processes</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_cmd_service.toml\" target=\"_blank\" rel=\"noopener\">Service Command Lateral Movement</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_dcom_hta.toml\" target=\"_blank\" rel=\"noopener\">Incoming DCOM Lateral Movement via MSHTA</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_dcom_mmc20.toml\" target=\"_blank\" rel=\"noopener\">Incoming DCOM Lateral Movement with MMC</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_dcom_shellwindow_shellbrowserwindow.toml\" target=\"_blank\" rel=\"noopener\">Incoming DCOM Lateral Movement with ShellBrowserWindow or ShellWindows</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_direct_outbound_smb_connection.toml\" target=\"_blank\" rel=\"noopener\">SMB Connections via LOLBin or Untrusted Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_from_tsclient_mup.toml\" target=\"_blank\" rel=\"noopener\">Execution via TSClient Mountpoint</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_via_file_shares_sequence.toml\" target=\"_blank\" rel=\"noopener\">Remote Execution via File Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_incoming_winrm_shell_execution.toml\" target=\"_blank\" rel=\"noopener\">Incoming Execution via WinRM Remote Shell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_mount_hidden_or_webdav_share_net.toml\" target=\"_blank\" rel=\"noopener\">Mounting Hidden or WebDav Remote Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_powershell_remoting_target.toml\" target=\"_blank\" rel=\"noopener\">Incoming Execution via PowerShell Remoting</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_rdp_sharprdp_target.toml\" target=\"_blank\" rel=\"noopener\">Potential SharpRDP Behavior</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_remote_file_copy_hidden_share.toml\" target=\"_blank\" rel=\"noopener\">Remote File Copy to a Hidden Share</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_remote_services.toml\" target=\"_blank\" rel=\"noopener\">Remotely Started Services via RPC</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_unusual_dns_service_children.toml\" target=\"_blank\" rel=\"noopener\">Unusual Child Process of dns.exe</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_via_wsus_update.toml\" target=\"_blank\" rel=\"noopener\">Potential WSUS Abuse for Lateral Movement</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_powershell_exch_mailbox_activesync_add_device.toml\" target=\"_blank\" rel=\"noopener\">New ActiveSyncAllowedDeviceID Added via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_priv_escalation_via_accessibility_features.toml\" target=\"_blank\" rel=\"noopener\">Potential Modification of Accessibility Binaries</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_runtime_run_key_startup_susp_procs.toml\" target=\"_blank\" rel=\"noopener\">Execution of Persistent Suspicious Program</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_unsigned_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Folder Persistence via Unsigned Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_scheduled_task_runtime.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution via Scheduled Task</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_system_shells_via_services.toml\" target=\"_blank\" rel=\"noopener\">System Shells via Services</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_user_account_creation.toml\" target=\"_blank\" rel=\"noopener\">User Account Creation</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_application_shimming.toml\" target=\"_blank\" rel=\"noopener\">Potential Application Shimming via Sdbinst</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_bits_job_notify_command.toml\" target=\"_blank\" rel=\"noopener\">Persistence via BITS Job Notify Cmdline</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_telemetrycontroller_scheduledtask_hijack.toml\" target=\"_blank\" rel=\"noopener\">Persistence via TelemetryController Scheduled Task Hijack</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_update_orchestrator_service_hijack.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Update Orchestrator Service Hijack</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_windows_management_instrumentation_event_subscription.toml\" target=\"_blank\" rel=\"noopener\">Persistence via WMI Event Subscription</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_installertakeover.toml\" target=\"_blank\" rel=\"noopener\">Potential Privilege Escalation via InstallerFileTakeOver</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_msi_repair_via_mshelp_link.toml\" target=\"_blank\" rel=\"noopener\">Potential Escalation via Vulnerable MSI Repair</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_named_pipe_impersonation.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Named Pipe Impersonation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_com_clipup.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass Attempt with IEditionUpgradeManager Elevated COM Interface</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_com_ieinstal.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_com_interface_icmluautil.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass via ICMLuaUtil Elevated COM Interface</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_diskcleanup_hijack.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass via DiskCleanup Scheduled Task Hijack</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_event_viewer.toml\" target=\"_blank\" rel=\"noopener\">Bypass UAC via Event Viewer</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_mock_windir.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass Attempt via Windows Directory Masquerading</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_uac_bypass_winfw_mmc_hijack.toml\" target=\"_blank\" rel=\"noopener\">UAC Bypass via Windows Firewall Snap-In Hijack</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_unquoted_service_path.toml\" target=\"_blank\" rel=\"noopener\">Potential Exploitation of an Unquoted Service Path Vulnerability</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_unusual_parentchild_relationship.toml\" target=\"_blank\" rel=\"noopener\">Unusual Parent-Child Relationship</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4688\">4688</a>: A new process has been created.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_unusual_svchost_childproc_childless.toml\" target=\"_blank\" rel=\"noopener\">Unusual Service Host Child Process - Childless Service</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n","eir-block-03":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_execution_from_vscode_extension.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution from VS Code Extension</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_xsl_script_execution_via_com.toml\" target=\"_blank\" rel=\"noopener\">Remote XSL Script Execution via COM</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#7\">7</a>: Image loaded</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_create_process_with_token_unpriv.toml\" target=\"_blank\" rel=\"noopener\">Process Created with a Duplicated Token</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_ppid_spoofing.toml\" target=\"_blank\" rel=\"noopener\">Privileges Elevation via Parent Process PID Spoofing</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_token_theft.toml\" target=\"_blank\" rel=\"noopener\">Process Created with an Elevated Token</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n","eir-block-04":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_ms_office_written_file.toml\" target=\"_blank\" rel=\"noopener\">Execution of File Written or Modified by Microsoft Office</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_shared_modules_local_sxs_dll.toml\" target=\"_blank\" rel=\"noopener\">Execution via local SxS Shared Module</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_script_from_internet.toml\" target=\"_blank\" rel=\"noopener\">Execution of a Downloaded Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_mod_critical_os_files.toml\" target=\"_blank\" rel=\"noopener\">Potential System Tampering via File Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_file_rename_smb.toml\" target=\"_blank\" rel=\"noopener\">Suspicious File Renamed via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_note_file_over_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Ransomware Note File Dropped via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_evasion_suspicious_htm_file_creation.toml\" target=\"_blank\" rel=\"noopener\">Suspicious HTML File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_executable_tool_transfer_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Lateral Tool Transfer via SMB Share</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_via_file_shares_sequence.toml\" target=\"_blank\" rel=\"noopener\">Remote Execution via File Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_via_startup_folder_rdp_smb.toml\" target=\"_blank\" rel=\"noopener\">Lateral Movement via Startup Folder</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_job_creation.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Scheduled Job Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_office_addins_file.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Office AddIns</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_outlook_vba_template.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Outlook VBA</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_powershell_profiles.toml\" target=\"_blank\" rel=\"noopener\">Persistence via PowerShell profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_suspicious_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Persistence by a Suspicious Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_unsigned_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Folder Persistence via Unsigned Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_scripts.toml\" target=\"_blank\" rel=\"noopener\">Persistent Scripts in the Startup Directory</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_user_mandatory_profile_file.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Mandatory User Profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_web_shell_aspx_write.toml\" target=\"_blank\" rel=\"noopener\">Potential Web Shell ASPX File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_exploit_cve_202238028.toml\" target=\"_blank\" rel=\"noopener\">Potential privilege escalation via CVE-2022-38028</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_gpo_schtask_service_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation or Modification of a new GPO Scheduled Task or Service</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_printspooler_suspicious_spl_file.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Print Spooler SPL File Created</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_rogue_named_pipe.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Rogue Named Pipe Impersonation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n","eir-block-05":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_masquerading_werfault.toml\" target=\"_blank\" rel=\"noopener\">Potential Windows Error Manager Masquerading</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_misc_lolbin_connecting_to_the_internet.toml\" target=\"_blank\" rel=\"noopener\">Network Connection via Signed Binary</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msbuild_making_network_connections.toml\" target=\"_blank\" rel=\"noopener\">MsBuild Making Network Connections</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_mshta_beacon.toml\" target=\"_blank\" rel=\"noopener\">Mshta Making Network Connections</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msiexec_child_proc_netcon.toml\" target=\"_blank\" rel=\"noopener\">MsiExec Service Child Process With Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_msxsl_network.toml\" target=\"_blank\" rel=\"noopener\">Network Connection via MsXsl</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_network_connection_from_windows_binary.toml\" target=\"_blank\" rel=\"noopener\">Unusual Network Activity from a Windows System Binary</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_network_connection_via_dllhost.toml\" target=\"_blank\" rel=\"noopener\">Unusual Network Connection via DllHost</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_network_connection_via_rundll32.toml\" target=\"_blank\" rel=\"noopener\">Unusual Network Connection via RunDLL32</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_unusual_process_network_connection.toml\" target=\"_blank\" rel=\"noopener\">Unusual Process Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_active_directory_webservice.toml\" target=\"_blank\" rel=\"noopener\">Potential Enumeration via Active Directory Web Service</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#7\">7</a>: Image loaded</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/discovery_host_public_ip_address_lookup.toml\" target=\"_blank\" rel=\"noopener\">System Public IP Discovery via DNS Query</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_command_prompt_connecting_to_the_internet.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Command Prompt Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_html_help_executable_program_connecting_to_the_internet.toml\" target=\"_blank\" rel=\"noopener\">Network Connection via Compiled HTML File</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_psexec_lateral_movement_command.toml\" target=\"_blank\" rel=\"noopener\">PsExec Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_register_server_program_connecting_to_the_internet.toml\" target=\"_blank\" rel=\"noopener\">Network Connection via Registration Utility</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_scheduled_task_powershell_source.toml\" target=\"_blank\" rel=\"noopener\">Outbound Scheduled Task Activity via PowerShell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_file_rename_smb.toml\" target=\"_blank\" rel=\"noopener\">Suspicious File Renamed via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_note_file_over_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Ransomware Note File Dropped via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_execution_from_removable_media.toml\" target=\"_blank\" rel=\"noopener\">Execution from a Removable Media with Network Connection</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_execution_remote_via_msiexec.toml\" target=\"_blank\" rel=\"noopener\">Potential Remote File Execution via MSIEXEC</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_cmd_service.toml\" target=\"_blank\" rel=\"noopener\">Service Command Lateral Movement</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_credential_access_kerberos_correlation.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Kerberos Authentication Ticket Request</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4624\">4624</a>: An account was successfully logged on.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4625\">4625</a>: An account failed to log on.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4634\">4634</a>: An account was logged off.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4647\">4647</a>: User initiated logoff.</li><li>Security-Auditing Event ID <a href=\"/microsoft-windows-security-auditing/#4648\">4648</a>: A logon was attempted using explicit credentials.</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_direct_outbound_smb_connection.toml\" target=\"_blank\" rel=\"noopener\">SMB Connections via LOLBin or Untrusted Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_incoming_winrm_shell_execution.toml\" target=\"_blank\" rel=\"noopener\">Incoming Execution via WinRM Remote Shell</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_incoming_wmi.toml\" target=\"_blank\" rel=\"noopener\">WMI Incoming Lateral Movement</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_powershell_remoting_target.toml\" target=\"_blank\" rel=\"noopener\">Incoming Execution via PowerShell Remoting</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_remote_services.toml\" target=\"_blank\" rel=\"noopener\">Remotely Started Services via RPC</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_scheduled_task_target.toml\" target=\"_blank\" rel=\"noopener\">Remote Scheduled Task Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n","eir-block-06":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_execution_remote_via_msiexec.toml\" target=\"_blank\" rel=\"noopener\">Potential Remote File Execution via MSIEXEC</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_suspicious_execution_from_vscode_extension.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Execution from VS Code Extension</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_xsl_script_execution_via_com.toml\" target=\"_blank\" rel=\"noopener\">Remote XSL Script Execution via COM</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#7\">7</a>: Image loaded</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_create_process_with_token_unpriv.toml\" target=\"_blank\" rel=\"noopener\">Process Created with a Duplicated Token</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_ppid_spoofing.toml\" target=\"_blank\" rel=\"noopener\">Privileges Elevation via Parent Process PID Spoofing</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_token_theft.toml\" target=\"_blank\" rel=\"noopener\">Process Created with an Elevated Token</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n","eir-block-07":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_filesystem.toml\" target=\"_blank\" rel=\"noopener\">Host File System Changes via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_ms_office_written_file.toml\" target=\"_blank\" rel=\"noopener\">Execution of File Written or Modified by Microsoft Office</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_shared_modules_local_sxs_dll.toml\" target=\"_blank\" rel=\"noopener\">Execution via local SxS Shared Module</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_script_from_internet.toml\" target=\"_blank\" rel=\"noopener\">Execution of a Downloaded Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_mod_critical_os_files.toml\" target=\"_blank\" rel=\"noopener\">Potential System Tampering via File Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_file_rename_smb.toml\" target=\"_blank\" rel=\"noopener\">Suspicious File Renamed via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_note_file_over_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Ransomware Note File Dropped via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_evasion_suspicious_htm_file_creation.toml\" target=\"_blank\" rel=\"noopener\">Suspicious HTML File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_executable_tool_transfer_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Lateral Tool Transfer via SMB Share</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_via_file_shares_sequence.toml\" target=\"_blank\" rel=\"noopener\">Remote Execution via File Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_via_startup_folder_rdp_smb.toml\" target=\"_blank\" rel=\"noopener\">Lateral Movement via Startup Folder</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_job_creation.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Scheduled Job Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_office_addins_file.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Office AddIns</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_outlook_vba_template.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Outlook VBA</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_powershell_profiles.toml\" target=\"_blank\" rel=\"noopener\">Persistence via PowerShell profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_suspicious_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Persistence by a Suspicious Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_unsigned_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Folder Persistence via Unsigned Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_scripts.toml\" target=\"_blank\" rel=\"noopener\">Persistent Scripts in the Startup Directory</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_user_mandatory_profile_file.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Mandatory User Profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_web_shell_aspx_write.toml\" target=\"_blank\" rel=\"noopener\">Potential Web Shell ASPX File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_exploit_cve_202238028.toml\" target=\"_blank\" rel=\"noopener\">Potential privilege escalation via CVE-2022-38028</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_gpo_schtask_service_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation or Modification of a new GPO Scheduled Task or Service</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_printspooler_suspicious_spl_file.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Print Spooler SPL File Created</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_rogue_named_pipe.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Rogue Named Pipe Impersonation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n","eir-block-08":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_solarwinds_backdoor_service_disabled_via_registry.toml\" target=\"_blank\" rel=\"noopener\">SolarWinds Process Disabling Services via Registry</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_registry_modification.toml\" target=\"_blank\" rel=\"noopener\">Windows Subsystem for Linux Distribution Installed</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_defense_evasion_lanman_nullsessionpipe_modification.toml\" target=\"_blank\" rel=\"noopener\">NullSessionPipe Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_rdp_enabled_registry.toml\" target=\"_blank\" rel=\"noopener\">RDP Enabled via Registry</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_rdp_sharprdp_target.toml\" target=\"_blank\" rel=\"noopener\">Potential SharpRDP Behavior</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_scheduled_task_target.toml\" target=\"_blank\" rel=\"noopener\">Remote Scheduled Task Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_app_compat_shim.toml\" target=\"_blank\" rel=\"noopener\">Installation of Custom Shim Databases</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_appcertdlls_registry.toml\" target=\"_blank\" rel=\"noopener\">Registry Persistence via AppCert DLL</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_appinitdlls_registry.toml\" target=\"_blank\" rel=\"noopener\">Registry Persistence via AppInit DLL</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_hidden_local_account_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation of a Hidden Local User Account</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_registry_ifeo_injection.toml\" target=\"_blank\" rel=\"noopener\">Image File Execution Options Injection</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_registry_startup_shell_folder_modified.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Startup Shell Folder Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_task_scripting.toml\" target=\"_blank\" rel=\"noopener\">Scheduled Task Created by a Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_netsh_helper_dll.toml\" target=\"_blank\" rel=\"noopener\">Netsh Helper DLL</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_registry_uncommon.toml\" target=\"_blank\" rel=\"noopener\">Uncommon Registry Persistence Change</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_run_key_and_startup_broad.toml\" target=\"_blank\" rel=\"noopener\">Startup or Run Key Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_services_registry.toml\" target=\"_blank\" rel=\"noopener\">Unusual Persistence via Services Registry</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_com_hijack_registry.toml\" target=\"_blank\" rel=\"noopener\">Component Object Model Hijacking</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_service_created_registry.toml\" target=\"_blank\" rel=\"noopener\">Suspicious ImagePath Service Creation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_time_provider_mod.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Time Provider Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_hidden_run_key_valuename.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Hidden Run Key Detected</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_lsa_security_support_provider_registry.toml\" target=\"_blank\" rel=\"noopener\">Installation of Security Support Provider</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_wmi_stdregprov_run_services.toml\" target=\"_blank\" rel=\"noopener\">Persistence via WMI Standard Registry Provider</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_werfault_reflectdebugger.toml\" target=\"_blank\" rel=\"noopener\">Werfault ReflectDebugger Persistence</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_disable_uac_registry.toml\" target=\"_blank\" rel=\"noopener\">Disabling User Account Control via Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_lsa_auth_package.toml\" target=\"_blank\" rel=\"noopener\">Potential LSA Authentication Package Abuse</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_port_monitor_print_processor_abuse.toml\" target=\"_blank\" rel=\"noopener\">Potential Port Monitor or Print Processor Registration Abuse</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_reg_service_imagepath_mod.toml\" target=\"_blank\" rel=\"noopener\">Potential Privilege Escalation via Service ImagePath Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_rogue_windir_environment_var.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Windir Environment Variable</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n","eir-block-09":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_solarwinds_backdoor_service_disabled_via_registry.toml\" target=\"_blank\" rel=\"noopener\">SolarWinds Process Disabling Services via Registry</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_registry_modification.toml\" target=\"_blank\" rel=\"noopener\">Windows Subsystem for Linux Distribution Installed</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_defense_evasion_lanman_nullsessionpipe_modification.toml\" target=\"_blank\" rel=\"noopener\">NullSessionPipe Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_rdp_enabled_registry.toml\" target=\"_blank\" rel=\"noopener\">RDP Enabled via Registry</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_rdp_sharprdp_target.toml\" target=\"_blank\" rel=\"noopener\">Potential SharpRDP Behavior</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_scheduled_task_target.toml\" target=\"_blank\" rel=\"noopener\">Remote Scheduled Task Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_app_compat_shim.toml\" target=\"_blank\" rel=\"noopener\">Installation of Custom Shim Databases</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_appcertdlls_registry.toml\" target=\"_blank\" rel=\"noopener\">Registry Persistence via AppCert DLL</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_appinitdlls_registry.toml\" target=\"_blank\" rel=\"noopener\">Registry Persistence via AppInit DLL</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_hidden_local_account_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation of a Hidden Local User Account</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_registry_ifeo_injection.toml\" target=\"_blank\" rel=\"noopener\">Image File Execution Options Injection</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_registry_startup_shell_folder_modified.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Startup Shell Folder Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_task_scripting.toml\" target=\"_blank\" rel=\"noopener\">Scheduled Task Created by a Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_netsh_helper_dll.toml\" target=\"_blank\" rel=\"noopener\">Netsh Helper DLL</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_registry_uncommon.toml\" target=\"_blank\" rel=\"noopener\">Uncommon Registry Persistence Change</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_run_key_and_startup_broad.toml\" target=\"_blank\" rel=\"noopener\">Startup or Run Key Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_services_registry.toml\" target=\"_blank\" rel=\"noopener\">Unusual Persistence via Services Registry</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_com_hijack_registry.toml\" target=\"_blank\" rel=\"noopener\">Component Object Model Hijacking</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_service_created_registry.toml\" target=\"_blank\" rel=\"noopener\">Suspicious ImagePath Service Creation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_time_provider_mod.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Time Provider Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_hidden_run_key_valuename.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Hidden Run Key Detected</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_lsa_security_support_provider_registry.toml\" target=\"_blank\" rel=\"noopener\">Installation of Security Support Provider</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_wmi_stdregprov_run_services.toml\" target=\"_blank\" rel=\"noopener\">Persistence via WMI Standard Registry Provider</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_werfault_reflectdebugger.toml\" target=\"_blank\" rel=\"noopener\">Werfault ReflectDebugger Persistence</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_disable_uac_registry.toml\" target=\"_blank\" rel=\"noopener\">Disabling User Account Control via Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_lsa_auth_package.toml\" target=\"_blank\" rel=\"noopener\">Potential LSA Authentication Package Abuse</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_port_monitor_print_processor_abuse.toml\" target=\"_blank\" rel=\"noopener\">Potential Port Monitor or Print Processor Registration Abuse</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_reg_service_imagepath_mod.toml\" target=\"_blank\" rel=\"noopener\">Potential Privilege Escalation via Service ImagePath Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_rogue_windir_environment_var.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Windir Environment Variable</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#14\">14</a>: RegistryEvent (Key and Value Rename)</li></ul></span></div>\n","eir-block-10":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_solarwinds_backdoor_service_disabled_via_registry.toml\" target=\"_blank\" rel=\"noopener\">SolarWinds Process Disabling Services via Registry</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_registry_modification.toml\" target=\"_blank\" rel=\"noopener\">Windows Subsystem for Linux Distribution Installed</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_defense_evasion_lanman_nullsessionpipe_modification.toml\" target=\"_blank\" rel=\"noopener\">NullSessionPipe Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_rdp_enabled_registry.toml\" target=\"_blank\" rel=\"noopener\">RDP Enabled via Registry</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_rdp_sharprdp_target.toml\" target=\"_blank\" rel=\"noopener\">Potential SharpRDP Behavior</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_scheduled_task_target.toml\" target=\"_blank\" rel=\"noopener\">Remote Scheduled Task Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_app_compat_shim.toml\" target=\"_blank\" rel=\"noopener\">Installation of Custom Shim Databases</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_appcertdlls_registry.toml\" target=\"_blank\" rel=\"noopener\">Registry Persistence via AppCert DLL</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_appinitdlls_registry.toml\" target=\"_blank\" rel=\"noopener\">Registry Persistence via AppInit DLL</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_hidden_local_account_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation of a Hidden Local User Account</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_registry_ifeo_injection.toml\" target=\"_blank\" rel=\"noopener\">Image File Execution Options Injection</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_evasion_registry_startup_shell_folder_modified.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Startup Shell Folder Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_task_scripting.toml\" target=\"_blank\" rel=\"noopener\">Scheduled Task Created by a Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_netsh_helper_dll.toml\" target=\"_blank\" rel=\"noopener\">Netsh Helper DLL</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_registry_uncommon.toml\" target=\"_blank\" rel=\"noopener\">Uncommon Registry Persistence Change</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_run_key_and_startup_broad.toml\" target=\"_blank\" rel=\"noopener\">Startup or Run Key Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_services_registry.toml\" target=\"_blank\" rel=\"noopener\">Unusual Persistence via Services Registry</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_com_hijack_registry.toml\" target=\"_blank\" rel=\"noopener\">Component Object Model Hijacking</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_service_created_registry.toml\" target=\"_blank\" rel=\"noopener\">Suspicious ImagePath Service Creation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_time_provider_mod.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Time Provider Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_hidden_run_key_valuename.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Hidden Run Key Detected</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_lsa_security_support_provider_registry.toml\" target=\"_blank\" rel=\"noopener\">Installation of Security Support Provider</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_via_wmi_stdregprov_run_services.toml\" target=\"_blank\" rel=\"noopener\">Persistence via WMI Standard Registry Provider</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_werfault_reflectdebugger.toml\" target=\"_blank\" rel=\"noopener\">Werfault ReflectDebugger Persistence</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_disable_uac_registry.toml\" target=\"_blank\" rel=\"noopener\">Disabling User Account Control via Registry Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_lsa_auth_package.toml\" target=\"_blank\" rel=\"noopener\">Potential LSA Authentication Package Abuse</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_port_monitor_print_processor_abuse.toml\" target=\"_blank\" rel=\"noopener\">Potential Port Monitor or Print Processor Registration Abuse</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_reg_service_imagepath_mod.toml\" target=\"_blank\" rel=\"noopener\">Potential Privilege Escalation via Service ImagePath Modification</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_rogue_windir_environment_var.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Windir Environment Variable</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#12\">12</a>: RegistryEvent (Object create and delete)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#13\">13</a>: RegistryEvent (Value Set)</li></ul></span></div>\n","eir-block-11":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_filesystem.toml\" target=\"_blank\" rel=\"noopener\">Host File System Changes via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_ms_office_written_file.toml\" target=\"_blank\" rel=\"noopener\">Execution of File Written or Modified by Microsoft Office</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_shared_modules_local_sxs_dll.toml\" target=\"_blank\" rel=\"noopener\">Execution via local SxS Shared Module</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_script_from_internet.toml\" target=\"_blank\" rel=\"noopener\">Execution of a Downloaded Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_mod_critical_os_files.toml\" target=\"_blank\" rel=\"noopener\">Potential System Tampering via File Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_file_rename_smb.toml\" target=\"_blank\" rel=\"noopener\">Suspicious File Renamed via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_note_file_over_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Ransomware Note File Dropped via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_evasion_suspicious_htm_file_creation.toml\" target=\"_blank\" rel=\"noopener\">Suspicious HTML File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_executable_tool_transfer_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Lateral Tool Transfer via SMB Share</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_via_file_shares_sequence.toml\" target=\"_blank\" rel=\"noopener\">Remote Execution via File Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_via_startup_folder_rdp_smb.toml\" target=\"_blank\" rel=\"noopener\">Lateral Movement via Startup Folder</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_job_creation.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Scheduled Job Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_office_addins_file.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Office AddIns</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_outlook_vba_template.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Outlook VBA</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_powershell_profiles.toml\" target=\"_blank\" rel=\"noopener\">Persistence via PowerShell profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_suspicious_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Persistence by a Suspicious Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_unsigned_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Folder Persistence via Unsigned Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_scripts.toml\" target=\"_blank\" rel=\"noopener\">Persistent Scripts in the Startup Directory</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_user_mandatory_profile_file.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Mandatory User Profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_web_shell_aspx_write.toml\" target=\"_blank\" rel=\"noopener\">Potential Web Shell ASPX File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_exploit_cve_202238028.toml\" target=\"_blank\" rel=\"noopener\">Potential privilege escalation via CVE-2022-38028</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_gpo_schtask_service_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation or Modification of a new GPO Scheduled Task or Service</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_printspooler_suspicious_spl_file.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Print Spooler SPL File Created</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_rogue_named_pipe.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Rogue Named Pipe Impersonation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n","eir-block-12":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_filesystem.toml\" target=\"_blank\" rel=\"noopener\">Host File System Changes via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_ms_office_written_file.toml\" target=\"_blank\" rel=\"noopener\">Execution of File Written or Modified by Microsoft Office</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_shared_modules_local_sxs_dll.toml\" target=\"_blank\" rel=\"noopener\">Execution via local SxS Shared Module</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_script_from_internet.toml\" target=\"_blank\" rel=\"noopener\">Execution of a Downloaded Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_mod_critical_os_files.toml\" target=\"_blank\" rel=\"noopener\">Potential System Tampering via File Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_file_rename_smb.toml\" target=\"_blank\" rel=\"noopener\">Suspicious File Renamed via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_note_file_over_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Ransomware Note File Dropped via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_evasion_suspicious_htm_file_creation.toml\" target=\"_blank\" rel=\"noopener\">Suspicious HTML File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_executable_tool_transfer_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Lateral Tool Transfer via SMB Share</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_via_file_shares_sequence.toml\" target=\"_blank\" rel=\"noopener\">Remote Execution via File Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_via_startup_folder_rdp_smb.toml\" target=\"_blank\" rel=\"noopener\">Lateral Movement via Startup Folder</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_job_creation.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Scheduled Job Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_office_addins_file.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Office AddIns</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_outlook_vba_template.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Outlook VBA</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_powershell_profiles.toml\" target=\"_blank\" rel=\"noopener\">Persistence via PowerShell profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_suspicious_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Persistence by a Suspicious Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_unsigned_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Folder Persistence via Unsigned Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_scripts.toml\" target=\"_blank\" rel=\"noopener\">Persistent Scripts in the Startup Directory</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_user_mandatory_profile_file.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Mandatory User Profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_web_shell_aspx_write.toml\" target=\"_blank\" rel=\"noopener\">Potential Web Shell ASPX File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_exploit_cve_202238028.toml\" target=\"_blank\" rel=\"noopener\">Potential privilege escalation via CVE-2022-38028</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_gpo_schtask_service_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation or Modification of a new GPO Scheduled Task or Service</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_printspooler_suspicious_spl_file.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Print Spooler SPL File Created</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_rogue_named_pipe.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Rogue Named Pipe Impersonation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#26\">26</a>: FileDeleteDetected (File Delete logged)</li></ul></span></div>\n","eir-block-13":"<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/defense_evasion_wsl_filesystem.toml\" target=\"_blank\" rel=\"noopener\">Host File System Changes via Windows Subsystem for Linux</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_ms_office_written_file.toml\" target=\"_blank\" rel=\"noopener\">Execution of File Written or Modified by Microsoft Office</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_shared_modules_local_sxs_dll.toml\" target=\"_blank\" rel=\"noopener\">Execution via local SxS Shared Module</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/execution_windows_script_from_internet.toml\" target=\"_blank\" rel=\"noopener\">Execution of a Downloaded Windows Script</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_mod_critical_os_files.toml\" target=\"_blank\" rel=\"noopener\">Potential System Tampering via File Modification</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_file_rename_smb.toml\" target=\"_blank\" rel=\"noopener\">Suspicious File Renamed via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/impact_ransomware_note_file_over_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Ransomware Note File Dropped via SMB</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/initial_access_evasion_suspicious_htm_file_creation.toml\" target=\"_blank\" rel=\"noopener\">Suspicious HTML File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#5\">5</a>: Process terminated</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_executable_tool_transfer_smb.toml\" target=\"_blank\" rel=\"noopener\">Potential Lateral Tool Transfer via SMB Share</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#3\">3</a>: Network connection</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_execution_via_file_shares_sequence.toml\" target=\"_blank\" rel=\"noopener\">Remote Execution via File Shares</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/lateral_movement_via_startup_folder_rdp_smb.toml\" target=\"_blank\" rel=\"noopener\">Lateral Movement via Startup Folder</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_local_scheduled_job_creation.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Scheduled Job Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_office_addins_file.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Office AddIns</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_ms_outlook_vba_template.toml\" target=\"_blank\" rel=\"noopener\">Persistence via Microsoft Outlook VBA</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_powershell_profiles.toml\" target=\"_blank\" rel=\"noopener\">Persistence via PowerShell profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_suspicious_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Persistence by a Suspicious Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_file_written_by_unsigned_process.toml\" target=\"_blank\" rel=\"noopener\">Startup Folder Persistence via Unsigned Process</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#1\">1</a>: Process creation</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_startup_folder_scripts.toml\" target=\"_blank\" rel=\"noopener\">Persistent Scripts in the Startup Directory</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_suspicious_user_mandatory_profile_file.toml\" target=\"_blank\" rel=\"noopener\">Potential Persistence via Mandatory User Profile</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/persistence_web_shell_aspx_write.toml\" target=\"_blank\" rel=\"noopener\">Potential Web Shell ASPX File Creation</a>&nbsp;<span class=\"rule-severity rule-severity--medium\">medium</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_exploit_cve_202238028.toml\" target=\"_blank\" rel=\"noopener\">Potential privilege escalation via CVE-2022-38028</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_gpo_schtask_service_creation.toml\" target=\"_blank\" rel=\"noopener\">Creation or Modification of a new GPO Scheduled Task or Service</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_printspooler_suspicious_spl_file.toml\" target=\"_blank\" rel=\"noopener\">Suspicious Print Spooler SPL File Created</a>&nbsp;<span class=\"rule-severity rule-severity--low\">low</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n<div class=\"inferred-card\"><a href=\"https://github.com/elastic/detection-rules/blob/main/rules/windows/privilege_escalation_via_rogue_named_pipe.toml\" target=\"_blank\" rel=\"noopener\">Privilege Escalation via Rogue Named Pipe Impersonation</a>&nbsp;<span class=\"rule-severity rule-severity--high\">high</span><span class=\"inferred-card-related\">Related:<ul><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#2\">2</a>: A process changed a file creation time</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#11\">11</a>: FileCreate</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#15\">15</a>: FileCreateStreamHash</li><li>Sysmon Event ID <a href=\"/microsoft-windows-sysmon/#23\">23</a>: FileDelete (File Delete archived)</li></ul></span></div>\n"}}