Elastic Inferred Detection Coverage

954 inferred rule mappings across 46 events and 2 providers, covering 398 unique Elastic detection rules.

Most Elastic detection rules don't explicitly filter by Windows event ID. Instead, they query using EQL event categories (like process where or file where) or match on fields that only appear in specific event types. This embeds the connection between a rule and the Windows events it operates on in the query logic rather than stating it directly.

To surface these relationships, this analysis parses each rule's query into an abstract syntax tree and extracts the EQL categories and field names it references. Where a category or field maps to a known set of Windows events, the mappings below link the rule to those events: answering the question: if I collect this Windows event, which Elastic rules could use it as a data source?

For rules that do explicitly reference event IDs, see the Elastic Detection Rules Reference.

Confidence levels
  • Medium: Rule uses an EQL category (e.g., process where, file where) that maps to this event type. The rule fires if this event is collected, though other data sources may also satisfy it.
  • Low: Rule references fields that appear in only a few different events. The rule may use this event, but the mapping is less certain.

Rules group by inference method so you can see exactly which EQL category or field name links each rule to the event.

Microsoft-Windows-Security-Auditing (32 events, 264 rules) #

Channel: Security Event ID 4610: An authentication package has been loaded by the Local Security Authority. (4 low)

Shared field: AuthenticationPackageNamelow confidence: 4 rules
Potential Computer Account NTLM Relay Activity mediumRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Potential Kerberos Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Potential NTLM Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Service Creation via Local Kerberos Authentication highRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.

Channel: Security Event ID 4611: A trusted logon process has been registered with the Local Security Authority. (4 low)

Shared field: LogonProcessNamelow confidence: 4 rules
Potential Pass-the-Hash (PtH) Attempt mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4649: A replay attack was detected.
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4688: A new process has been created.
  • Security-Auditing 4649: A replay attack was detected.
Interactive Logon by an Unusual Process highRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4649: A replay attack was detected.
First Time Seen NewCredentials Logon Process mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4649: A replay attack was detected.

Channel: Security Event ID 4624: An account was successfully logged on. (6 medium, 2 low)

EQL category authentication wheremedium confidence: 6 rules
Multiple Logon Failure Followed by Logon Success mediumRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Suspicious Kerberos Authentication Ticket Request highRelated:
  • Sysmon 3: Network connection
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Remote Windows Service Installed mediumRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Account Password Reset Remotely mediumRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4688: A new process has been created.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
Interactive Logon by an Unusual Process highRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
Shared field: LogonProcessNamelow confidence: 2 rules
Potential Pass-the-Hash (PtH) Attempt mediumRelated:
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
First Time Seen NewCredentials Logon Process mediumRelated:
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.

Channel: Security Event ID 4625: An account failed to log on. (7 medium)

EQL category authentication wheremedium confidence: 7 rules
Multiple Logon Failure Followed by Logon Success mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Suspicious Kerberos Authentication Ticket Request highRelated:
  • Sysmon 3: Network connection
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Remote Windows Service Installed mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Account Password Reset Remotely mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4688: A new process has been created.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
Service Creation via Local Kerberos Authentication highRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Interactive Logon by an Unusual Process highRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.

Channel: Security Event ID 4634: An account was logged off. (10 medium)

EQL category authentication wheremedium confidence: 10 rules
Multiple Logon Failure Followed by Logon Success mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Potential Computer Account NTLM Relay Activity mediumRelated:
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Potential Kerberos Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Potential NTLM Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Suspicious Kerberos Authentication Ticket Request highRelated:
  • Sysmon 3: Network connection
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Remote Windows Service Installed mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Account Password Reset Remotely mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4688: A new process has been created.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
Service Creation via Local Kerberos Authentication highRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Interactive Logon by an Unusual Process highRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.

Channel: Security Event ID 4647: User initiated logoff. (10 medium)

EQL category authentication wheremedium confidence: 10 rules
Multiple Logon Failure Followed by Logon Success mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Potential Computer Account NTLM Relay Activity mediumRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Potential Kerberos Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Potential NTLM Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Suspicious Kerberos Authentication Ticket Request highRelated:
  • Sysmon 3: Network connection
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Remote Windows Service Installed mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Account Password Reset Remotely mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4688: A new process has been created.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
Service Creation via Local Kerberos Authentication highRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Interactive Logon by an Unusual Process highRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.

Channel: Security Event ID 4648: A logon was attempted using explicit credentials. (10 medium)

EQL category authentication wheremedium confidence: 10 rules
Multiple Logon Failure Followed by Logon Success mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
Potential Computer Account NTLM Relay Activity mediumRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Potential Kerberos Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Potential NTLM Relay Attack against a Computer Account highRelated:
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Suspicious Kerberos Authentication Ticket Request highRelated:
  • Sysmon 3: Network connection
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
Remote Windows Service Installed mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
Account Password Reset Remotely mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4688: A new process has been created.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
Service Creation via Local Kerberos Authentication highRelated:
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4610: An authentication package has been loaded by the Local Security Authority.
Interactive Logon by an Unusual Process highRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.

Channel: Security Event ID 4649: A replay attack was detected. (4 low)

Shared field: LogonProcessNamelow confidence: 4 rules
Potential Pass-the-Hash (PtH) Attempt mediumRelated:
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4624: An account was successfully logged on.
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4688: A new process has been created.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
Interactive Logon by an Unusual Process highRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
First Time Seen NewCredentials Logon Process mediumRelated:
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4624: An account was successfully logged on.

Channel: Security Event ID 4657: A registry value was modified. (3 low)

Shared field: OperationTypelow confidence: 3 rules
User account exposed to Kerberoasting mediumRelated:
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Account Configured with Never-Expiring Password mediumRelated:
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
  • Security-Auditing 5137: A directory service object was created.
  • Security-Auditing 5141: A directory service object was deleted.
Modification of the msPKIAccountCredentials mediumRelated:
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 4659: A handle to an object was requested with intent to delete. (2 low)

Shared field: AccessListlow confidence: 2 rules
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 4661: A handle to an object was requested. (4 low)

Channel: Security Event ID 4663: An attempt was made to access an object. (2 low)

Shared field: AccessListlow confidence: 2 rules
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 4688: A new process has been created. (133 medium)

EQL category process where → start medium confidence: 133 rules
Curl or Wget Spawned via Node.js mediumRelated:
  • Sysmon 1: Process creation
Potential Traffic Tunneling using QEMU mediumRelated:
  • Sysmon 1: Process creation
Potential Secret Scanning via Gitleaks mediumRelated:
  • Sysmon 1: Process creation
Credential Access via TruffleHog Execution mediumRelated:
  • Sysmon 1: Process creation
Data Encrypted via OpenSSL Utility lowRelated:
  • Sysmon 1: Process creation
Kubernetes Direct API Request via Curl or Wget mediumRelated:
  • Sysmon 1: Process creation
Remote GitHub Actions Runner Registration mediumRelated:
  • Sysmon 1: Process creation
Execution via GitHub Actions Runner mediumRelated:
  • Sysmon 1: Process creation
Potential Data Exfiltration Through Curl mediumRelated:
  • Sysmon 1: Process creation
Exporting Exchange Mailbox via PowerShell mediumRelated:
  • Sysmon 1: Process creation
Potential File Transfer via Certreq mediumRelated:
  • Sysmon 1: Process creation
Potential DNS Tunneling via NsLookup mediumRelated:
  • Sysmon 1: Process creation
Potential File Download via a Headless Browser highRelated:
  • Sysmon 1: Process creation
Potential Remote Desktop Tunneling Detected highRelated:
  • Sysmon 1: Process creation
Remote File Download via Desktopimgdownldr Utility mediumRelated:
  • Sysmon 1: Process creation
Show all 133 rules (118 more)
Remote File Download via MpCmdRun mediumRelated:
  • Sysmon 1: Process creation
Remote Management Access Launch After MSI Install mediumRelated:
  • Sysmon 1: Process creation
NetSupport Manager Execution from an Unusual Path highRelated:
  • Sysmon 1: Process creation
Suspicious ScreenConnect Client Child Process mediumRelated:
  • Sysmon 1: Process creation
Potential Protocol Tunneling via Cloudflared mediumRelated:
  • Sysmon 1: Process creation
Attempt to Establish VScode Remote Tunnel mediumRelated:
  • Sysmon 1: Process creation
Potential Protocol Tunneling via Yuze mediumRelated:
  • Sysmon 1: Process creation
Suspicious Shell Execution via Velociraptor mediumRelated:
  • Sysmon 1: Process creation
Browser Process Spawned from an Unusual Parent highRelated:
  • Sysmon 1: Process creation
Potential Credential Access via Windows Utilities highRelated:
  • Sysmon 1: Process creation
NTDS or SAM Database File Copied highRelated:
  • Sysmon 1: Process creation
Credential Acquisition via Registry Hive Dumping highRelated:
  • Sysmon 1: Process creation
Microsoft IIS Connection Strings Decryption highRelated:
  • Sysmon 1: Process creation
Potential Local NTLM Relay via HTTP highRelated:
  • Sysmon 1: Process creation
Searching for Saved Credentials via VaultCmd mediumRelated:
  • Sysmon 1: Process creation
Symbolic Link to Shadow Copy Created mediumRelated:
  • Sysmon 1: Process creation
Potential Veeam Credential Access Command mediumRelated:
  • Sysmon 1: Process creation
NTDS Dump via Wbadmin mediumRelated:
  • Sysmon 1: Process creation
Wireless Credential Dumping using Netsh Command highRelated:
  • Sysmon 1: Process creation
Adding Hidden File Attribute via Attrib lowRelated:
  • Sysmon 1: Process creation
Clearing Windows Console History mediumRelated:
  • Sysmon 1: Process creation
Clearing Windows Event Logs lowRelated:
  • Sysmon 1: Process creation
Code Signing Policy Modification Through Built-in tools mediumRelated:
  • Sysmon 1: Process creation
Windows Defender Exclusions Added via PowerShell mediumRelated:
  • Sysmon 1: Process creation
Delete Volume USN Journal with Fsutil lowRelated:
  • Sysmon 1: Process creation
Disable Windows Firewall Rules via Netsh mediumRelated:
  • Sysmon 1: Process creation
Disabling Windows Defender Security Settings via PowerShell mediumRelated:
  • Sysmon 1: Process creation
Suspicious .NET Code Compilation mediumRelated:
  • Sysmon 1: Process creation
Remote Desktop Enabled in Windows Firewall by Netsh mediumRelated:
  • Sysmon 1: Process creation
Enable Host Network Discovery via Netsh mediumRelated:
  • Sysmon 1: Process creation
Control Panel Process with Unusual Arguments highRelated:
  • Sysmon 1: Process creation
ImageLoad via Windows Update Auto Update Client mediumRelated:
  • Sysmon 1: Process creation
Microsoft Build Engine Started by an Office Application highRelated:
  • Sysmon 1: Process creation
Microsoft Build Engine Started by a System Process mediumRelated:
  • Sysmon 1: Process creation
Process Execution from an Unusual Directory mediumRelated:
  • Sysmon 1: Process creation
IIS HTTP Logging Disabled highRelated:
  • Sysmon 1: Process creation
Proxy Execution via Console Window Host highRelated:
  • Sysmon 1: Process creation
Command Execution via ForFiles mediumRelated:
  • Sysmon 1: Process creation
Proxy Execution via Windows OpenSSH highRelated:
  • Sysmon 1: Process creation
Execution via Windows Command Debugging Utility mediumRelated:
  • Sysmon 1: Process creation
Suspicious Endpoint Security Parent Process mediumRelated:
  • Sysmon 1: Process creation
Program Files Directory Masquerading mediumRelated:
  • Sysmon 1: Process creation
System File Ownership Change mediumRelated:
  • Sysmon 1: Process creation
Suspicious Microsoft HTML Application Child Process highRelated:
  • Sysmon 1: Process creation
Potential Remote Install via MsiExec highRelated:
  • Sysmon 1: Process creation
Command Obfuscation via Unicode Modifier Letters highRelated:
  • Sysmon 1: Process creation
Windows Firewall Disabled via PowerShell mediumRelated:
  • Sysmon 1: Process creation
Script Execution via Microsoft HTML Application highRelated:
  • Sysmon 1: Process creation
Suspicious CertUtil Commands mediumRelated:
  • Sysmon 1: Process creation
Suspicious Zoom Child Process mediumRelated:
  • Sysmon 1: Process creation
Unusual Child Process from a System Virtual Process highRelated:
  • Sysmon 1: Process creation
Potential Evasion via Filter Manager mediumRelated:
  • Sysmon 1: Process creation
Signed Proxy Execution via MS Work Folders mediumRelated:
  • Sysmon 1: Process creation
Execution via Windows Subsystem for Linux mediumRelated:
  • Sysmon 1: Process creation
Windows Subsystem for Linux Enabled via Dism Utility mediumRelated:
  • Sysmon 1: Process creation
Attempt to Install Kali Linux via WSL highRelated:
  • Sysmon 1: Process creation
Active Directory Discovery using AdExplorer lowRelated:
  • Sysmon 1: Process creation
AdFind Command Activity lowRelated:
  • Sysmon 1: Process creation
Enumerating Domain Trusts via DSQUERY.EXE lowRelated:
  • Sysmon 1: Process creation
Enumerating Domain Trusts via NLTEST.EXE lowRelated:
  • Sysmon 1: Process creation
Group Policy Discovery via Microsoft GPResult Utility lowRelated:
  • Sysmon 1: Process creation
Peripheral Device Discovery lowRelated:
  • Sysmon 1: Process creation
Command Execution via SolarWinds Process mediumRelated:
  • Sysmon 1: Process creation
Execution of COM object via Xwizard mediumRelated:
  • Sysmon 1: Process creation
Enumeration Command Spawned via WMIPrvSE lowRelated:
  • Sysmon 1: Process creation
Execution from Unusual Directory - Command Line mediumRelated:
  • Sysmon 1: Process creation
Potential Foxmail Exploitation highRelated:
  • Sysmon 1: Process creation
Suspicious Execution with NodeJS highRelated:
  • Sysmon 1: Process creation
Command and Scripting Interpreter via Windows Scripts highRelated:
  • Sysmon 1: Process creation
Suspicious Execution from a WebDav Share highRelated:
  • Sysmon 1: Process creation
Windows Script Execution from Archive mediumRelated:
  • Sysmon 1: Process creation
Suspicious JavaScript Execution via Deno highRelated:
  • Sysmon 1: Process creation
Suspicious Cmd Execution via WMI highRelated:
  • Sysmon 1: Process creation
Suspicious PDF Reader Child Process lowRelated:
  • Sysmon 1: Process creation
Process Activity via Compiled HTML File mediumRelated:
  • Sysmon 1: Process creation
Microsoft Management Console File from Unusual Path mediumRelated:
  • Sysmon 1: Process creation
Suspicious Windows Command Shell Arguments highRelated:
  • Sysmon 1: Process creation
Potential Fake CAPTCHA Phishing Attack highRelated:
  • Sysmon 1: Process creation
Suspicious Windows Powershell Arguments mediumRelated:
  • Sysmon 1: Process creation
Potential Data Exfiltration via Rclone mediumRelated:
  • Sysmon 1: Process creation
Backup Deletion with Wbadmin lowRelated:
  • Sysmon 1: Process creation
Modification of Boot Configuration lowRelated:
  • Sysmon 1: Process creation
Volume Shadow Copy Deleted or Resized via VssAdmin highRelated:
  • Sysmon 1: Process creation
Volume Shadow Copy Deletion via PowerShell highRelated:
  • Sysmon 1: Process creation
Volume Shadow Copy Deletion via WMIC highRelated:
  • Sysmon 1: Process creation
Suspicious Execution from INET Cache highRelated:
  • Sysmon 1: Process creation
Suspicious JetBrains TeamCity Child Process mediumRelated:
  • Sysmon 1: Process creation
Remote Desktop File Opened from Suspicious Path mediumRelated:
  • Sysmon 1: Process creation
Microsoft Exchange Server UM Spawning Suspicious Processes mediumRelated:
  • Sysmon 1: Process creation
Suspicious MS Office Child Process mediumRelated:
  • Sysmon 1: Process creation
Suspicious MS Outlook Child Process lowRelated:
  • Sysmon 1: Process creation
ScreenConnect Server Spawning Suspicious Processes highRelated:
  • Sysmon 1: Process creation
Execution via TSClient Mountpoint highRelated:
  • Sysmon 1: Process creation
Mounting Hidden or WebDav Remote Shares mediumRelated:
  • Sysmon 1: Process creation
Remote File Copy to a Hidden Share mediumRelated:
  • Sysmon 1: Process creation
Unusual Child Process of dns.exe highRelated:
  • Sysmon 1: Process creation
Potential WSUS Abuse for Lateral Movement mediumRelated:
  • Sysmon 1: Process creation
New ActiveSyncAllowedDeviceID Added via PowerShell mediumRelated:
  • Sysmon 1: Process creation
System Shells via Services mediumRelated:
  • Sysmon 1: Process creation
User Account Creation lowRelated:
  • Sysmon 1: Process creation
Potential Application Shimming via Sdbinst lowRelated:
  • Sysmon 1: Process creation
Persistence via TelemetryController Scheduled Task Hijack highRelated:
  • Sysmon 1: Process creation
Persistence via Update Orchestrator Service Hijack highRelated:
  • Sysmon 1: Process creation
Persistence via WMI Event Subscription lowRelated:
  • Sysmon 1: Process creation
Process Creation via Secondary Logon mediumRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
  • Security-Auditing 4611: A trusted logon process has been registered with the Local Security Authority.
  • Security-Auditing 4649: A replay attack was detected.
Privilege Escalation via Named Pipe Impersonation highRelated:
  • Sysmon 1: Process creation
UAC Bypass via DiskCleanup Scheduled Task Hijack mediumRelated:
  • Sysmon 1: Process creation
Bypass UAC via Event Viewer highRelated:
  • Sysmon 1: Process creation
UAC Bypass Attempt via Windows Directory Masquerading highRelated:
  • Sysmon 1: Process creation
Unusual Parent-Child Relationship mediumRelated:
  • Sysmon 1: Process creation

Channel: Security Event ID 4691: Indirect access to an object was requested. (2 low)

Shared field: AccessListlow confidence: 2 rules
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 4700: A scheduled task was enabled. (4 low)

Shared field: RpcCallClientLocalitylow confidence: 1 rule
Remote Scheduled Task Creation via RPC mediumRelated:
  • Security-Auditing 4701: A scheduled task was disabled.
Shared field: TaskNamelow confidence: 2 rules
A scheduled task was created lowRelated:
  • Security-Auditing 4701: A scheduled task was disabled.
Temporarily Scheduled Task Creation mediumRelated:
  • Security-Auditing 4701: A scheduled task was disabled.
Shared field: ParentProcessIdlow confidence: 1 rule
Windows Service Installed via an Unusual Client highRelated:
  • Security-Auditing 4701: A scheduled task was disabled.
  • Sysmon 1: Process creation

Channel: Security Event ID 4701: A scheduled task was disabled. (4 low)

Shared field: RpcCallClientLocalitylow confidence: 1 rule
Remote Scheduled Task Creation via RPC mediumRelated:
  • Security-Auditing 4700: A scheduled task was enabled.
Shared field: TaskNamelow confidence: 2 rules
A scheduled task was created lowRelated:
  • Security-Auditing 4700: A scheduled task was enabled.
Temporarily Scheduled Task Creation mediumRelated:
  • Security-Auditing 4700: A scheduled task was enabled.
Shared field: ParentProcessIdlow confidence: 1 rule
Windows Service Installed via an Unusual Client highRelated:
  • Security-Auditing 4700: A scheduled task was enabled.
  • Sysmon 1: Process creation

Channel: Security Event ID 4720: A user account was created. (1 low)

Shared field: AllowedToDelegateTolow confidence: 1 rule
KRBTGT Delegation Backdoor highRelated:
  • Security-Auditing 4741: A computer account was created.
  • Security-Auditing 4742: A computer account was changed.

Channel: Security Event ID 4741: A computer account was created. (1 low)

Shared field: AllowedToDelegateTolow confidence: 1 rule
KRBTGT Delegation Backdoor highRelated:
  • Security-Auditing 4720: A user account was created.
  • Security-Auditing 4742: A computer account was changed.

Channel: Security Event ID 4742: A computer account was changed. (1 low)

Shared field: AllowedToDelegateTolow confidence: 1 rule
KRBTGT Delegation Backdoor highRelated:
  • Security-Auditing 4720: A user account was created.
  • Security-Auditing 4741: A computer account was created.

Channel: Security Event ID 4798: A user's local group membership was enumerated. (1 low)

Shared field: CallerProcessNamelow confidence: 1 rule
Enumeration of Privileged Local Groups Membership mediumRelated:
  • Security-Auditing 4799: A security-enabled local group membership was enumerated.
  • Security-Auditing 5050: An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected.

Channel: Security Event ID 4799: A security-enabled local group membership was enumerated. (1 low)

Shared field: CallerProcessNamelow confidence: 1 rule
Enumeration of Privileged Local Groups Membership mediumRelated:
  • Security-Auditing 4798: A user's local group membership was enumerated.
  • Security-Auditing 5050: An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected.

Channel: Security Event ID 5050: An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE) interface was rejected. (1 low)

Shared field: CallerProcessNamelow confidence: 1 rule
Enumeration of Privileged Local Groups Membership mediumRelated:
  • Security-Auditing 4798: A user's local group membership was enumerated.
  • Security-Auditing 4799: A security-enabled local group membership was enumerated.

Channel: Security Event ID 5136: A directory service object was modified. (3 low)

Shared field: ObjectDNlow confidence: 3 rules
Potential ADIDNS Poisoning via Wildcard Record Creation highRelated:
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Potential WPAD Spoofing via DNS Record Creation mediumRelated:
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Potential Kerberos Coercion via DNS-Based SPN Spoofing highRelated:
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 5137: A directory service object was created. (2 low)

Shared field: ObjectDNlow confidence: 2 rules
AdminSDHolder Backdoor highRelated:
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Account Configured with Never-Expiring Password mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
  • Security-Auditing 5141: A directory service object was deleted.

Channel: Security Event ID 5140: A network share object was accessed. (2 low)

Shared field: AccessListlow confidence: 2 rules
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 5141: A directory service object was deleted. (5 low)

Shared field: ObjectDNlow confidence: 5 rules
Potential ADIDNS Poisoning via Wildcard Record Creation highRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Potential WPAD Spoofing via DNS Record Creation mediumRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Potential Kerberos Coercion via DNS-Based SPN Spoofing highRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
AdminSDHolder Backdoor highRelated:
  • Security-Auditing 5137: A directory service object was created.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Account Configured with Never-Expiring Password mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
  • Security-Auditing 5137: A directory service object was created.

Channel: Security Event ID 5142: A network share object was added. (2 low)

Shared field: ShareNamelow confidence: 2 rules
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 5143: A network share object was modified. (2 low)

Shared field: ShareNamelow confidence: 2 rules
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 5144: A network share object was deleted. (2 low)

Shared field: ShareNamelow confidence: 2 rules
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 5169: A directory service object was modified. (14 low)

Shared field: ObjectDNlow confidence: 4 rules
Potential ADIDNS Poisoning via Wildcard Record Creation highRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Potential WPAD Spoofing via DNS Record Creation mediumRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Potential Kerberos Coercion via DNS-Based SPN Spoofing highRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
AdminSDHolder Backdoor highRelated:
  • Security-Auditing 5137: A directory service object was created.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Shared field: AttributeLDAPDisplayNamelow confidence: 7 rules
Potential Active Directory Replication Account Backdoor mediumRelated:
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Potential Shadow Credentials added to AD Object highRelated:
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
AdminSDHolder SDProp Exclusion Added highRelated:
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Delegated Managed Service Account Modification by an Unusual User highRelated:
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Group Policy Abuse for Privilege Addition highRelated:
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Shared field: OperationTypelow confidence: 3 rules
User account exposed to Kerberoasting mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
Account Configured with Never-Expiring Password mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.
  • Security-Auditing 5137: A directory service object was created.
  • Security-Auditing 5141: A directory service object was deleted.
Modification of the msPKIAccountCredentials mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5170: A directory service object was modified during a background cleanup task.

Channel: Security Event ID 5170: A directory service object was modified during a background cleanup task. (14 low)

Shared field: ObjectDNlow confidence: 4 rules
Potential ADIDNS Poisoning via Wildcard Record Creation highRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
Potential WPAD Spoofing via DNS Record Creation mediumRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
Potential Kerberos Coercion via DNS-Based SPN Spoofing highRelated:
  • Security-Auditing 5136: A directory service object was modified.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
AdminSDHolder Backdoor highRelated:
  • Security-Auditing 5137: A directory service object was created.
  • Security-Auditing 5141: A directory service object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
Shared field: AttributeLDAPDisplayNamelow confidence: 7 rules
Potential Active Directory Replication Account Backdoor mediumRelated:
  • Security-Auditing 5169: A directory service object was modified.
Potential Shadow Credentials added to AD Object highRelated:
  • Security-Auditing 5169: A directory service object was modified.
AdminSDHolder SDProp Exclusion Added highRelated:
  • Security-Auditing 5169: A directory service object was modified.
Delegated Managed Service Account Modification by an Unusual User highRelated:
  • Security-Auditing 5169: A directory service object was modified.
Startup/Logon Script added to Group Policy Object mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
Group Policy Abuse for Privilege Addition highRelated:
  • Security-Auditing 5169: A directory service object was modified.
Scheduled Task Execution at Scale via GPO mediumRelated:
  • Security-Auditing 4659: A handle to an object was requested with intent to delete.
  • Security-Auditing 4663: An attempt was made to access an object.
  • Security-Auditing 4691: Indirect access to an object was requested.
  • Security-Auditing 5140: A network share object was accessed.
  • Security-Auditing 5142: A network share object was added.
  • Security-Auditing 5143: A network share object was modified.
  • Security-Auditing 5144: A network share object was deleted.
  • Security-Auditing 5169: A directory service object was modified.
Shared field: OperationTypelow confidence: 3 rules
User account exposed to Kerberoasting mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5169: A directory service object was modified.
Account Configured with Never-Expiring Password mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5169: A directory service object was modified.
  • Security-Auditing 5137: A directory service object was created.
  • Security-Auditing 5141: A directory service object was deleted.
Modification of the msPKIAccountCredentials mediumRelated:
  • Security-Auditing 4657: A registry value was modified.
  • Security-Auditing 5169: A directory service object was modified.

Channel: Security Event ID 5380: Vault Find Credential. (1 low)

Shared field: SchemaFriendlyNamelow confidence: 1 rule

Microsoft-Windows-Sysmon (14 events, 690 rules) #

Channel: Operational Event ID 1: Process creation (229 medium, 1 low)

EQL category process where → start medium confidence: 209 rules
Curl or Wget Spawned via Node.js mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Traffic Tunneling using QEMU mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Secret Scanning via Gitleaks mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Credential Access via TruffleHog Execution mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Data Encrypted via OpenSSL Utility lowRelated:
  • Security-Auditing 4688: A new process has been created.
ROT Encoded Python Script Execution mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Kubernetes Direct API Request via Curl or Wget mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Remote GitHub Actions Runner Registration mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Execution via GitHub Actions Runner mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Data Exfiltration Through Curl mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Show all 209 rules (194 more)
Exporting Exchange Mailbox via PowerShell mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential File Transfer via Certreq mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential DNS Tunneling via NsLookup mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential File Download via a Headless Browser highRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Command and Control via Internet Explorer mediumRelated:
  • Sysmon 7: Image loaded
  • Sysmon 3: Network connection
Potential Remote Desktop Tunneling Detected highRelated:
  • Security-Auditing 4688: A new process has been created.
Remote File Download via Desktopimgdownldr Utility mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Remote File Download via MpCmdRun mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Remote Management Access Launch After MSI Install mediumRelated:
  • Security-Auditing 4688: A new process has been created.
NetSupport Manager Execution from an Unusual Path highRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious ScreenConnect Client Child Process mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Protocol Tunneling via Cloudflared mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Attempt to Establish VScode Remote Tunnel mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Protocol Tunneling via Yuze mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Shell Execution via Velociraptor mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Browser Process Spawned from an Unusual Parent highRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Credential Access via Windows Utilities highRelated:
  • Security-Auditing 4688: A new process has been created.
NTDS or SAM Database File Copied highRelated:
  • Security-Auditing 4688: A new process has been created.
Credential Acquisition via Registry Hive Dumping highRelated:
  • Security-Auditing 4688: A new process has been created.
Microsoft IIS Connection Strings Decryption highRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Local NTLM Relay via HTTP highRelated:
  • Security-Auditing 4688: A new process has been created.
Searching for Saved Credentials via VaultCmd mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Symbolic Link to Shadow Copy Created mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Veeam Credential Access Command mediumRelated:
  • Security-Auditing 4688: A new process has been created.
NTDS Dump via Wbadmin mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Wireless Credential Dumping using Netsh Command highRelated:
  • Security-Auditing 4688: A new process has been created.
Adding Hidden File Attribute via Attrib lowRelated:
  • Security-Auditing 4688: A new process has been created.
Clearing Windows Console History mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Clearing Windows Event Logs lowRelated:
  • Security-Auditing 4688: A new process has been created.
Code Signing Policy Modification Through Built-in tools mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Windows Defender Exclusions Added via PowerShell mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Delete Volume USN Journal with Fsutil lowRelated:
  • Security-Auditing 4688: A new process has been created.
Disable Windows Firewall Rules via Netsh mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Disabling Windows Defender Security Settings via PowerShell mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Disable Windows Event and Security Logs Using Built-in Tools lowRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious .NET Code Compilation mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Remote Desktop Enabled in Windows Firewall by Netsh mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Enable Host Network Discovery via Netsh mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Control Panel Process with Unusual Arguments highRelated:
  • Security-Auditing 4688: A new process has been created.
ImageLoad via Windows Update Auto Update Client mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Microsoft Build Engine Started by an Office Application highRelated:
  • Security-Auditing 4688: A new process has been created.
Microsoft Build Engine Started by a System Process mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Process Execution from an Unusual Directory mediumRelated:
  • Security-Auditing 4688: A new process has been created.
IIS HTTP Logging Disabled highRelated:
  • Security-Auditing 4688: A new process has been created.
Proxy Execution via Console Window Host highRelated:
  • Security-Auditing 4688: A new process has been created.
Command Execution via ForFiles mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Proxy Execution via Windows OpenSSH highRelated:
  • Security-Auditing 4688: A new process has been created.
InstallUtil Process Making Network Connections mediumRelated:
  • Sysmon 3: Network connection
Execution via Windows Command Debugging Utility mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Endpoint Security Parent Process mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Program Files Directory Masquerading mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Windows Error Manager Masquerading mediumRelated:
  • Sysmon 3: Network connection
Network Connection via Signed Binary lowRelated:
  • Sysmon 3: Network connection
System File Ownership Change mediumRelated:
  • Security-Auditing 4688: A new process has been created.
MsBuild Making Network Connections mediumRelated:
  • Sysmon 3: Network connection
Mshta Making Network Connections mediumRelated:
  • Sysmon 3: Network connection
Suspicious Microsoft HTML Application Child Process highRelated:
  • Security-Auditing 4688: A new process has been created.
MsiExec Service Child Process With Network Connection mediumRelated:
  • Sysmon 3: Network connection
Potential Remote Install via MsiExec highRelated:
  • Security-Auditing 4688: A new process has been created.
Network Connection via MsXsl lowRelated:
  • Sysmon 3: Network connection
Unusual Network Activity from a Windows System Binary mediumRelated:
  • Sysmon 3: Network connection
Command Obfuscation via Unicode Modifier Letters highRelated:
  • Security-Auditing 4688: A new process has been created.
Windows Firewall Disabled via PowerShell mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Script Execution via Microsoft HTML Application highRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious CertUtil Commands mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Zoom Child Process mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Unusual Network Connection via DllHost mediumRelated:
  • Sysmon 3: Network connection
Unusual Network Connection via RunDLL32 mediumRelated:
  • Sysmon 3: Network connection
Unusual Process Network Connection lowRelated:
  • Sysmon 3: Network connection
Unusual Child Process from a System Virtual Process highRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Evasion via Filter Manager mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Signed Proxy Execution via MS Work Folders mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Execution via Windows Subsystem for Linux mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Windows Subsystem for Linux Enabled via Dism Utility mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Host File System Changes via Windows Subsystem for Linux mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Attempt to Install Kali Linux via WSL highRelated:
  • Security-Auditing 4688: A new process has been created.
Active Directory Discovery using AdExplorer lowRelated:
  • Security-Auditing 4688: A new process has been created.
AdFind Command Activity lowRelated:
  • Security-Auditing 4688: A new process has been created.
Enumerating Domain Trusts via DSQUERY.EXE lowRelated:
  • Security-Auditing 4688: A new process has been created.
Enumerating Domain Trusts via NLTEST.EXE lowRelated:
  • Security-Auditing 4688: A new process has been created.
Group Policy Discovery via Microsoft GPResult Utility lowRelated:
  • Security-Auditing 4688: A new process has been created.
Peripheral Device Discovery lowRelated:
  • Security-Auditing 4688: A new process has been created.
Command Execution via SolarWinds Process mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Execution of COM object via Xwizard mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Command Prompt Network Connection lowRelated:
  • Sysmon 3: Network connection
Enumeration Command Spawned via WMIPrvSE lowRelated:
  • Security-Auditing 4688: A new process has been created.
Execution from Unusual Directory - Command Line mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Network Connection via Compiled HTML File lowRelated:
  • Sysmon 3: Network connection
Potential Foxmail Exploitation highRelated:
  • Security-Auditing 4688: A new process has been created.
Execution of File Written or Modified by Microsoft Office highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Execution with NodeJS highRelated:
  • Security-Auditing 4688: A new process has been created.
Command and Scripting Interpreter via Windows Scripts highRelated:
  • Security-Auditing 4688: A new process has been created.
PsExec Network Connection lowRelated:
  • Sysmon 3: Network connection
Suspicious Execution from a WebDav Share highRelated:
  • Security-Auditing 4688: A new process has been created.
Windows Script Execution from Archive mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious JavaScript Execution via Deno highRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Cmd Execution via WMI highRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious PDF Reader Child Process lowRelated:
  • Security-Auditing 4688: A new process has been created.
Process Activity via Compiled HTML File mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Microsoft Management Console File from Unusual Path mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Windows Command Shell Arguments highRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Fake CAPTCHA Phishing Attack highRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Windows Powershell Arguments mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Execution of a Downloaded Windows Script mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Data Exfiltration via Rclone mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Backup Deletion with Wbadmin lowRelated:
  • Security-Auditing 4688: A new process has been created.
Modification of Boot Configuration lowRelated:
  • Security-Auditing 4688: A new process has been created.
Volume Shadow Copy Deleted or Resized via VssAdmin highRelated:
  • Security-Auditing 4688: A new process has been created.
Volume Shadow Copy Deletion via PowerShell highRelated:
  • Security-Auditing 4688: A new process has been created.
Volume Shadow Copy Deletion via WMIC highRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious Execution from INET Cache highRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious JetBrains TeamCity Child Process mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Remote Desktop File Opened from Suspicious Path mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Microsoft Exchange Server UM Spawning Suspicious Processes mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious MS Office Child Process mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Suspicious MS Outlook Child Process lowRelated:
  • Security-Auditing 4688: A new process has been created.
ScreenConnect Server Spawning Suspicious Processes highRelated:
  • Security-Auditing 4688: A new process has been created.
Service Command Lateral Movement lowRelated:
  • Sysmon 3: Network connection
Incoming DCOM Lateral Movement via MSHTA highRelated:
  • Sysmon 3: Network connection
Incoming DCOM Lateral Movement with MMC highRelated:
  • Sysmon 3: Network connection
SMB Connections via LOLBin or Untrusted Process mediumRelated:
  • Sysmon 3: Network connection
Execution via TSClient Mountpoint highRelated:
  • Security-Auditing 4688: A new process has been created.
Remote Execution via File Shares mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Incoming Execution via WinRM Remote Shell mediumRelated:
  • Sysmon 3: Network connection
Mounting Hidden or WebDav Remote Shares mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Incoming Execution via PowerShell Remoting mediumRelated:
  • Sysmon 3: Network connection
Potential SharpRDP Behavior highRelated:
  • Sysmon 3: Network connection
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Remote File Copy to a Hidden Share mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Remotely Started Services via RPC mediumRelated:
  • Sysmon 3: Network connection
Unusual Child Process of dns.exe highRelated:
  • Security-Auditing 4688: A new process has been created.
Potential WSUS Abuse for Lateral Movement mediumRelated:
  • Security-Auditing 4688: A new process has been created.
New ActiveSyncAllowedDeviceID Added via PowerShell mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Startup Folder Persistence via Unsigned Process mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
System Shells via Services mediumRelated:
  • Security-Auditing 4688: A new process has been created.
User Account Creation lowRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Application Shimming via Sdbinst lowRelated:
  • Security-Auditing 4688: A new process has been created.
Persistence via TelemetryController Scheduled Task Hijack highRelated:
  • Security-Auditing 4688: A new process has been created.
Persistence via Update Orchestrator Service Hijack highRelated:
  • Security-Auditing 4688: A new process has been created.
Persistence via WMI Event Subscription lowRelated:
  • Security-Auditing 4688: A new process has been created.
Privilege Escalation via Named Pipe Impersonation highRelated:
  • Security-Auditing 4688: A new process has been created.
UAC Bypass via DiskCleanup Scheduled Task Hijack mediumRelated:
  • Security-Auditing 4688: A new process has been created.
Bypass UAC via Event Viewer highRelated:
  • Security-Auditing 4688: A new process has been created.
UAC Bypass Attempt via Windows Directory Masquerading highRelated:
  • Security-Auditing 4688: A new process has been created.
Potential Exploitation of an Unquoted Service Path Vulnerability lowRelated:
  • Security-Auditing 4688: A new process has been created.
Unusual Parent-Child Relationship mediumRelated:
  • Security-Auditing 4688: A new process has been created.
EQL category process wheremedium confidence: 20 rules
Potential Cookies Theft via Browser Debugging mediumRelated:
  • Sysmon 5: Process terminated
Suspicious Inter-Process Communication via Outlook mediumRelated:
  • Sysmon 5: Process terminated
Suspicious LSASS Access via MalSecLogon highRelated:
  • Sysmon 5: Process terminated
  • Sysmon 8: CreateRemoteThread
Potential Credential Access via DuplicateHandle in LSASS mediumRelated:
  • Sysmon 5: Process terminated
Potential Credential Access via Renamed COM+ Services DLL highRelated:
  • Sysmon 5: Process terminated
Suspicious Lsass Process Access mediumRelated:
  • Sysmon 5: Process terminated
  • Sysmon 8: CreateRemoteThread
Potential Credential Access via LSASS Memory Dump highRelated:
  • Sysmon 5: Process terminated
  • Sysmon 8: CreateRemoteThread
Process Injection by the Microsoft Build Engine lowRelated:
  • Sysmon 5: Process terminated
Suspicious Process Access via Direct System Call highRelated:
  • Sysmon 5: Process terminated
  • Sysmon 8: CreateRemoteThread
Delayed Execution via Ping lowRelated:
  • Sysmon 5: Process terminated
Suspicious HTML File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 5: Process terminated
Execution from a Removable Media with Network Connection lowRelated:
  • Sysmon 5: Process terminated
  • Sysmon 3: Network connection
Potential Remote File Execution via MSIEXEC lowRelated:
  • Sysmon 5: Process terminated
  • Sysmon 3: Network connection
Show all 20 rules (5 more)
Suspicious Execution from VS Code Extension mediumRelated:
  • Sysmon 5: Process terminated
Remote XSL Script Execution via COM lowRelated:
  • Sysmon 7: Image loaded
  • Sysmon 5: Process terminated
Process Created with a Duplicated Token mediumRelated:
  • Sysmon 5: Process terminated
Privileges Elevation via Parent Process PID Spoofing highRelated:
  • Sysmon 5: Process terminated
Process Created with an Elevated Token highRelated:
  • Sysmon 5: Process terminated
Shared field: ParentProcessIdlow confidence: 1 rule
Windows Service Installed via an Unusual Client highRelated:
  • Security-Auditing 4700: A scheduled task was enabled.
  • Security-Auditing 4701: A scheduled task was disabled.

Channel: Operational Event ID 2: A process changed a file creation time (40 medium)

EQL category file wheremedium confidence: 38 rules
GenAI Process Accessing Sensitive Files highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
ROT Encoded Python Script Execution mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential SAP NetWeaver WebShell Creation highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Initial Access via File Upload Followed by GET Request mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Ingress Transfer via Windows BITS lowRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of Domain Backup DPAPI private key highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
LSASS Memory Dump Creation highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Mimikatz Memssp Log File Detected highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Sensitive Registry Hive Access via RegBack highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Remote Credential Access via Registry highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Antimalware Scan Interface DLL highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Managed Code Hosting Process highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Unusual Executable File Creation by a System Critical Process highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
WDAC Policy File by an Unusual Process highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Host File System Changes via Windows Subsystem for Linux mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Show all 38 rules (23 more)
Execution of File Written or Modified by Microsoft Office highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Execution via local SxS Shared Module mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution of a Downloaded Windows Script mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Potential System Tampering via File Modification highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious File Renamed via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Ransomware Note File Dropped via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious HTML File Creation mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Potential Lateral Tool Transfer via SMB Share mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Remote Execution via File Shares mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Lateral Movement via Startup Folder highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Scheduled Job Creation mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Office AddIns highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Outlook VBA mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via PowerShell profile mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Persistence by a Suspicious Process mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Folder Persistence via Unsigned Process mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistent Scripts in the Startup Directory mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Persistence via Mandatory User Profile mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Web Shell ASPX File Creation mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential privilege escalation via CVE-2022-38028 highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of a new GPO Scheduled Task or Service lowRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Print Spooler SPL File Created lowRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Privilege Escalation via Rogue Named Pipe Impersonation highRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)

Channel: Operational Event ID 3: Network connection (52 medium)

EQL category network wheremedium confidence: 44 rules
Initial Access via File Upload Followed by GET Request mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Command and Control via Internet Explorer mediumRelated:
  • Sysmon 7: Image loaded
  • Sysmon 1: Process creation
Remote File Download via PowerShell mediumRelated:
  • Sysmon 11: FileCreate
Remote File Download via Script Interpreter mediumRelated:
  • Sysmon 11: FileCreate
InstallUtil Process Making Network Connections mediumRelated:
  • Sysmon 1: Process creation
Show all 44 rules (29 more)
Potential Windows Error Manager Masquerading mediumRelated:
  • Sysmon 1: Process creation
Network Connection via Signed Binary lowRelated:
  • Sysmon 1: Process creation
MsBuild Making Network Connections mediumRelated:
  • Sysmon 1: Process creation
Mshta Making Network Connections mediumRelated:
  • Sysmon 1: Process creation
MsiExec Service Child Process With Network Connection mediumRelated:
  • Sysmon 1: Process creation
Network Connection via MsXsl lowRelated:
  • Sysmon 1: Process creation
Unusual Network Activity from a Windows System Binary mediumRelated:
  • Sysmon 1: Process creation
Unusual Network Connection via DllHost mediumRelated:
  • Sysmon 1: Process creation
Unusual Network Connection via RunDLL32 mediumRelated:
  • Sysmon 1: Process creation
Unusual Process Network Connection lowRelated:
  • Sysmon 1: Process creation
Potential Enumeration via Active Directory Web Service mediumRelated:
  • Sysmon 7: Image loaded
Suspicious Command Prompt Network Connection lowRelated:
  • Sysmon 1: Process creation
Network Connection via Compiled HTML File lowRelated:
  • Sysmon 1: Process creation
PsExec Network Connection lowRelated:
  • Sysmon 1: Process creation
Suspicious File Renamed via SMB highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Ransomware Note File Dropped via SMB highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution from a Removable Media with Network Connection lowRelated:
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Potential Remote File Execution via MSIEXEC lowRelated:
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Service Command Lateral Movement lowRelated:
  • Sysmon 1: Process creation
Suspicious Kerberos Authentication Ticket Request highRelated:
  • Security-Auditing 4624: An account was successfully logged on.
  • Security-Auditing 4625: An account failed to log on.
  • Security-Auditing 4634: An account was logged off.
  • Security-Auditing 4647: User initiated logoff.
  • Security-Auditing 4648: A logon was attempted using explicit credentials.
SMB Connections via LOLBin or Untrusted Process mediumRelated:
  • Sysmon 1: Process creation
Incoming Execution via WinRM Remote Shell mediumRelated:
  • Sysmon 1: Process creation
Incoming Execution via PowerShell Remoting mediumRelated:
  • Sysmon 1: Process creation
Remotely Started Services via RPC mediumRelated:
  • Sysmon 1: Process creation
Remote Scheduled Task Creation mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
EQL category network where → start medium confidence: 7 rules
Incoming DCOM Lateral Movement via MSHTA highRelated:
  • Sysmon 1: Process creation
Incoming DCOM Lateral Movement with MMC highRelated:
  • Sysmon 1: Process creation
Potential Lateral Tool Transfer via SMB Share mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential SharpRDP Behavior highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
  • Sysmon 1: Process creation
EQL category network where → protocol medium confidence: 1 rule

Channel: Operational Event ID 5: Process terminated (21 medium)

EQL category process wheremedium confidence: 21 rules
Potential Cookies Theft via Browser Debugging mediumRelated:
  • Sysmon 1: Process creation
Suspicious Inter-Process Communication via Outlook mediumRelated:
  • Sysmon 1: Process creation
Suspicious LSASS Access via MalSecLogon highRelated:
  • Sysmon 1: Process creation
  • Sysmon 8: CreateRemoteThread
Potential Credential Access via DuplicateHandle in LSASS mediumRelated:
  • Sysmon 1: Process creation
Potential Credential Access via Renamed COM+ Services DLL highRelated:
  • Sysmon 1: Process creation
Suspicious Lsass Process Access mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 8: CreateRemoteThread
Potential Credential Access via LSASS Memory Dump highRelated:
  • Sysmon 1: Process creation
  • Sysmon 8: CreateRemoteThread
Process Injection by the Microsoft Build Engine lowRelated:
  • Sysmon 1: Process creation
Suspicious Process Access via Direct System Call highRelated:
  • Sysmon 1: Process creation
  • Sysmon 8: CreateRemoteThread
Delayed Execution via Ping lowRelated:
  • Sysmon 1: Process creation
Suspicious HTML File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Execution from a Removable Media with Network Connection lowRelated:
  • Sysmon 1: Process creation
  • Sysmon 3: Network connection
Show all 21 rules (6 more)
Potential Remote File Execution via MSIEXEC lowRelated:
  • Sysmon 1: Process creation
  • Sysmon 3: Network connection
Suspicious Execution from VS Code Extension mediumRelated:
  • Sysmon 1: Process creation
Remote XSL Script Execution via COM lowRelated:
  • Sysmon 7: Image loaded
  • Sysmon 1: Process creation
Process Created with a Duplicated Token mediumRelated:
  • Sysmon 1: Process creation
Privileges Elevation via Parent Process PID Spoofing highRelated:
  • Sysmon 1: Process creation
Process Created with an Elevated Token highRelated:
  • Sysmon 1: Process creation

Channel: Operational Event ID 6: Driver loaded (2 medium)

EQL category driver wheremedium confidence: 2 rules

Channel: Operational Event ID 7: Image loaded (7 medium)

EQL category library wheremedium confidence: 7 rules
Potential Command and Control via Internet Explorer mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 3: Network connection
Potential Enumeration via Active Directory Web Service mediumRelated:
  • Sysmon 3: Network connection
Remote XSL Script Execution via COM lowRelated:
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated

Channel: Operational Event ID 8: CreateRemoteThread (5 low)

Shared field: TargetImagelow confidence: 5 rules
Suspicious LSASS Access via MalSecLogon highRelated:
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Suspicious Lsass Process Access mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Potential Credential Access via LSASS Memory Dump highRelated:
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Suspicious Process Access via Direct System Call highRelated:
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated

Channel: Operational Event ID 11: FileCreate (51 medium)

EQL category file wheremedium confidence: 39 rules
GenAI Process Accessing Sensitive Files highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
ROT Encoded Python Script Execution mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential SAP NetWeaver WebShell Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Initial Access via File Upload Followed by GET Request mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Ingress Transfer via Windows BITS lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of Domain Backup DPAPI private key highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
LSASS Memory Dump Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Mimikatz Memssp Log File Detected highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Sensitive Registry Hive Access via RegBack highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Remote Credential Access via Registry highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Antimalware Scan Interface DLL highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Managed Code Hosting Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Unusual Executable File Creation by a System Critical Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Timestomp in Executable Files mediumRelated:
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
WDAC Policy File by an Unusual Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Show all 39 rules (24 more)
Host File System Changes via Windows Subsystem for Linux mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution of File Written or Modified by Microsoft Office highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Execution via local SxS Shared Module mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution of a Downloaded Windows Script mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Potential System Tampering via File Modification highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious File Renamed via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Ransomware Note File Dropped via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious HTML File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Potential Lateral Tool Transfer via SMB Share mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Remote Execution via File Shares mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Lateral Movement via Startup Folder highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Scheduled Job Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Office AddIns highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Outlook VBA mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via PowerShell profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Persistence by a Suspicious Process mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Folder Persistence via Unsigned Process mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistent Scripts in the Startup Directory mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Persistence via Mandatory User Profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Web Shell ASPX File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential privilege escalation via CVE-2022-38028 highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of a new GPO Scheduled Task or Service lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Print Spooler SPL File Created lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Privilege Escalation via Rogue Named Pipe Impersonation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)

Channel: Operational Event ID 12: RegistryEvent (Object create and delete) (53 medium)

EQL category registry wheremedium confidence: 9 rules
Outlook Home Page Registry Modification highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Full User-Mode Dumps Enabled System-Wide mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Modification of WDigest Security Provider highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Network-Level Authentication (NLA) Disabled lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Deprecated - Encoded Executable Stored in the Registry mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential NetNTLMv1 Downgrade Attack mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential RemoteMonologue Attack mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Office Test Registry Persistence lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Suspicious Print Spooler Point and Print DLL highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
EQL category registry where → change medium confidence: 44 rules
Port Forwarding Rule Addition mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Network Logon Provider Registry Modification mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Modification of AmsiEnable Registry Key highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Code Signing Policy Modification Through Registry mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Creation or Modification of Root Certificate lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Windows Defender Disabled via Registry Modification lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
PowerShell Script Block Logging Disabled mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
DNS-over-HTTPS Enabled via Registry lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Disabling Lsa Protection via Registry Modification highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Microsoft Windows Defender Tampering mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
MS Office Macro Security Registry Modifications mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Local Account TokenFilter Policy Disabled mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
DNS Global Query Block List Modified or Disabled mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Scheduled Tasks AT Command Enabled mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
SIP Provider Modification mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Show all 44 rules (29 more)
SolarWinds Process Disabling Services via Registry mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Windows Subsystem for Linux Distribution Installed mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
NullSessionPipe Registry Modification mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
RDP Enabled via Registry mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential SharpRDP Behavior highRelated:
  • Sysmon 3: Network connection
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
  • Sysmon 1: Process creation
Remote Scheduled Task Creation mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Installation of Custom Shim Databases mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Registry Persistence via AppCert DLL mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Registry Persistence via AppInit DLL mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Creation of a Hidden Local User Account highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Image File Execution Options Injection mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Suspicious Startup Shell Folder Modification highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Scheduled Task Created by a Windows Script mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Netsh Helper DLL lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Uncommon Registry Persistence Change mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Startup or Run Key Registry Modification lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Unusual Persistence via Services Registry lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Component Object Model Hijacking lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Suspicious ImagePath Service Creation highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential Persistence via Time Provider Modification mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Persistence via Hidden Run Key Detected highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Installation of Security Support Provider mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Persistence via WMI Standard Registry Provider highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Werfault ReflectDebugger Persistence lowRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Disabling User Account Control via Registry Modification mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential LSA Authentication Package Abuse mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential Port Monitor or Print Processor Registration Abuse mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential Privilege Escalation via Service ImagePath Modification mediumRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Privilege Escalation via Windir Environment Variable highRelated:
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 14: RegistryEvent (Key and Value Rename)

Channel: Operational Event ID 13: RegistryEvent (Value Set) (53 medium)

EQL category registry wheremedium confidence: 9 rules
Outlook Home Page Registry Modification highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Full User-Mode Dumps Enabled System-Wide mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Modification of WDigest Security Provider highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Network-Level Authentication (NLA) Disabled lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Deprecated - Encoded Executable Stored in the Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential NetNTLMv1 Downgrade Attack mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential RemoteMonologue Attack mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Office Test Registry Persistence lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Suspicious Print Spooler Point and Print DLL highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
EQL category registry where → change medium confidence: 44 rules
Port Forwarding Rule Addition mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Network Logon Provider Registry Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Modification of AmsiEnable Registry Key highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Code Signing Policy Modification Through Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Creation or Modification of Root Certificate lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Windows Defender Disabled via Registry Modification lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
PowerShell Script Block Logging Disabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
DNS-over-HTTPS Enabled via Registry lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Disabling Lsa Protection via Registry Modification highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Microsoft Windows Defender Tampering mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
MS Office Macro Security Registry Modifications mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Local Account TokenFilter Policy Disabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
DNS Global Query Block List Modified or Disabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Scheduled Tasks AT Command Enabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
SIP Provider Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Show all 44 rules (29 more)
SolarWinds Process Disabling Services via Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Windows Subsystem for Linux Distribution Installed mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
NullSessionPipe Registry Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
RDP Enabled via Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential SharpRDP Behavior highRelated:
  • Sysmon 3: Network connection
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
  • Sysmon 1: Process creation
Remote Scheduled Task Creation mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Installation of Custom Shim Databases mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Registry Persistence via AppCert DLL mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Registry Persistence via AppInit DLL mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Creation of a Hidden Local User Account highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Image File Execution Options Injection mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Suspicious Startup Shell Folder Modification highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Scheduled Task Created by a Windows Script mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Netsh Helper DLL lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Uncommon Registry Persistence Change mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Startup or Run Key Registry Modification lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Unusual Persistence via Services Registry lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Component Object Model Hijacking lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Suspicious ImagePath Service Creation highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential Persistence via Time Provider Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Persistence via Hidden Run Key Detected highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Installation of Security Support Provider mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Persistence via WMI Standard Registry Provider highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Werfault ReflectDebugger Persistence lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Disabling User Account Control via Registry Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential LSA Authentication Package Abuse mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential Port Monitor or Print Processor Registration Abuse mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Potential Privilege Escalation via Service ImagePath Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)
Privilege Escalation via Windir Environment Variable highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 14: RegistryEvent (Key and Value Rename)

Channel: Operational Event ID 14: RegistryEvent (Key and Value Rename) (53 medium)

EQL category registry wheremedium confidence: 9 rules
Outlook Home Page Registry Modification highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Full User-Mode Dumps Enabled System-Wide mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Modification of WDigest Security Provider highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Network-Level Authentication (NLA) Disabled lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Deprecated - Encoded Executable Stored in the Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Potential NetNTLMv1 Downgrade Attack mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Potential RemoteMonologue Attack mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Office Test Registry Persistence lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Suspicious Print Spooler Point and Print DLL highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
EQL category registry where → change medium confidence: 44 rules
Port Forwarding Rule Addition mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Network Logon Provider Registry Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Modification of AmsiEnable Registry Key highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Code Signing Policy Modification Through Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Creation or Modification of Root Certificate lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Windows Defender Disabled via Registry Modification lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
PowerShell Script Block Logging Disabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
DNS-over-HTTPS Enabled via Registry lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Disabling Lsa Protection via Registry Modification highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Microsoft Windows Defender Tampering mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
MS Office Macro Security Registry Modifications mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Local Account TokenFilter Policy Disabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
DNS Global Query Block List Modified or Disabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Scheduled Tasks AT Command Enabled mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
SIP Provider Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Show all 44 rules (29 more)
SolarWinds Process Disabling Services via Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Windows Subsystem for Linux Distribution Installed mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
NullSessionPipe Registry Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
RDP Enabled via Registry mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Potential SharpRDP Behavior highRelated:
  • Sysmon 3: Network connection
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
  • Sysmon 1: Process creation
Remote Scheduled Task Creation mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Installation of Custom Shim Databases mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Registry Persistence via AppCert DLL mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Registry Persistence via AppInit DLL mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Creation of a Hidden Local User Account highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Image File Execution Options Injection mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Suspicious Startup Shell Folder Modification highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Scheduled Task Created by a Windows Script mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Netsh Helper DLL lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Uncommon Registry Persistence Change mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Startup or Run Key Registry Modification lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Unusual Persistence via Services Registry lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Component Object Model Hijacking lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Suspicious ImagePath Service Creation highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Potential Persistence via Time Provider Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Persistence via Hidden Run Key Detected highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Installation of Security Support Provider mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Persistence via WMI Standard Registry Provider highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Werfault ReflectDebugger Persistence lowRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Disabling User Account Control via Registry Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Potential LSA Authentication Package Abuse mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Potential Port Monitor or Print Processor Registration Abuse mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Potential Privilege Escalation via Service ImagePath Modification mediumRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)
Privilege Escalation via Windir Environment Variable highRelated:
  • Sysmon 12: RegistryEvent (Object create and delete)
  • Sysmon 13: RegistryEvent (Value Set)

Channel: Operational Event ID 15: FileCreateStreamHash (39 medium)

EQL category file wheremedium confidence: 39 rules
GenAI Process Accessing Sensitive Files highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
ROT Encoded Python Script Execution mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential SAP NetWeaver WebShell Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Initial Access via File Upload Followed by GET Request mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Ingress Transfer via Windows BITS lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of Domain Backup DPAPI private key highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
LSASS Memory Dump Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Mimikatz Memssp Log File Detected highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Sensitive Registry Hive Access via RegBack highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Remote Credential Access via Registry highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Antimalware Scan Interface DLL highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Managed Code Hosting Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Unusual Executable File Creation by a System Critical Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Timestomp in Executable Files mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
WDAC Policy File by an Unusual Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Show all 39 rules (24 more)
Host File System Changes via Windows Subsystem for Linux mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution of File Written or Modified by Microsoft Office highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Execution via local SxS Shared Module mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution of a Downloaded Windows Script mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Potential System Tampering via File Modification highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious File Renamed via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Ransomware Note File Dropped via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious HTML File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Potential Lateral Tool Transfer via SMB Share mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Remote Execution via File Shares mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Lateral Movement via Startup Folder highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Scheduled Job Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Office AddIns highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Outlook VBA mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via PowerShell profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Persistence by a Suspicious Process mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Folder Persistence via Unsigned Process mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistent Scripts in the Startup Directory mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Persistence via Mandatory User Profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Web Shell ASPX File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential privilege escalation via CVE-2022-38028 highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of a new GPO Scheduled Task or Service lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Print Spooler SPL File Created lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Privilege Escalation via Rogue Named Pipe Impersonation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 26: FileDeleteDetected (File Delete logged)

Channel: Operational Event ID 23: FileDelete (File Delete archived) (42 medium)

EQL category file wheremedium confidence: 39 rules
GenAI Process Accessing Sensitive Files highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
ROT Encoded Python Script Execution mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential SAP NetWeaver WebShell Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Initial Access via File Upload Followed by GET Request mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Ingress Transfer via Windows BITS lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of Domain Backup DPAPI private key highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
LSASS Memory Dump Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Mimikatz Memssp Log File Detected highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Sensitive Registry Hive Access via RegBack highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Remote Credential Access via Registry highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Antimalware Scan Interface DLL highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Managed Code Hosting Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Unusual Executable File Creation by a System Critical Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Timestomp in Executable Files mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
WDAC Policy File by an Unusual Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Show all 39 rules (24 more)
Host File System Changes via Windows Subsystem for Linux mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution of File Written or Modified by Microsoft Office highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Execution via local SxS Shared Module mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Execution of a Downloaded Windows Script mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Potential System Tampering via File Modification highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious File Renamed via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Ransomware Note File Dropped via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious HTML File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Potential Lateral Tool Transfer via SMB Share mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Remote Execution via File Shares mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
  • Sysmon 1: Process creation
Lateral Movement via Startup Folder highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Scheduled Job Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Office AddIns highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via Microsoft Outlook VBA mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistence via PowerShell profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Persistence by a Suspicious Process mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Startup Folder Persistence via Unsigned Process mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Persistent Scripts in the Startup Directory mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Persistence via Mandatory User Profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential Web Shell ASPX File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Potential privilege escalation via CVE-2022-38028 highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Creation or Modification of a new GPO Scheduled Task or Service lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Print Spooler SPL File Created lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Privilege Escalation via Rogue Named Pipe Impersonation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 26: FileDeleteDetected (File Delete logged)
EQL category file where → deletion medium confidence: 3 rules
WebServer Access Logs Deleted mediumRelated:
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Third-party Backup Files Deleted via Unexpected Process mediumRelated:
  • Sysmon 26: FileDeleteDetected (File Delete logged)
Suspicious Print Spooler File Deletion mediumRelated:
  • Sysmon 26: FileDeleteDetected (File Delete logged)

Channel: Operational Event ID 26: FileDeleteDetected (File Delete logged) (42 medium)

EQL category file wheremedium confidence: 39 rules
GenAI Process Accessing Sensitive Files highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
ROT Encoded Python Script Execution mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Potential SAP NetWeaver WebShell Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Initial Access via File Upload Followed by GET Request mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Ingress Transfer via Windows BITS lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Creation or Modification of Domain Backup DPAPI private key highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
LSASS Memory Dump Creation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Mimikatz Memssp Log File Detected highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Sensitive Registry Hive Access via RegBack highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Potential Remote Credential Access via Registry highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Suspicious Antimalware Scan Interface DLL highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Suspicious Managed Code Hosting Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Unusual Executable File Creation by a System Critical Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Potential Timestomp in Executable Files mediumRelated:
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
WDAC Policy File by an Unusual Process highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Show all 39 rules (24 more)
Host File System Changes via Windows Subsystem for Linux mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Execution of File Written or Modified by Microsoft Office highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 1: Process creation
Execution via local SxS Shared Module mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Execution of a Downloaded Windows Script mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 1: Process creation
Potential System Tampering via File Modification highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Suspicious File Renamed via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Potential Ransomware Note File Dropped via SMB highRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Suspicious HTML File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 1: Process creation
  • Sysmon 5: Process terminated
Potential Lateral Tool Transfer via SMB Share mediumRelated:
  • Sysmon 3: Network connection
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Remote Execution via File Shares mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
  • Sysmon 1: Process creation
Lateral Movement via Startup Folder highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Persistence via Scheduled Job Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Persistence via Microsoft Office AddIns highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Persistence via Microsoft Outlook VBA mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Persistence via PowerShell profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Startup Persistence by a Suspicious Process mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Startup Folder Persistence via Unsigned Process mediumRelated:
  • Sysmon 1: Process creation
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Persistent Scripts in the Startup Directory mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Potential Persistence via Mandatory User Profile mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Potential Web Shell ASPX File Creation mediumRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Potential privilege escalation via CVE-2022-38028 highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Creation or Modification of a new GPO Scheduled Task or Service lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Suspicious Print Spooler SPL File Created lowRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
Privilege Escalation via Rogue Named Pipe Impersonation highRelated:
  • Sysmon 2: A process changed a file creation time
  • Sysmon 11: FileCreate
  • Sysmon 15: FileCreateStreamHash
  • Sysmon 23: FileDelete (File Delete archived)
EQL category file where → deletion medium confidence: 3 rules
WebServer Access Logs Deleted mediumRelated:
  • Sysmon 23: FileDelete (File Delete archived)
Third-party Backup Files Deleted via Unexpected Process mediumRelated:
  • Sysmon 23: FileDelete (File Delete archived)
Suspicious Print Spooler File Deletion mediumRelated:
  • Sysmon 23: FileDelete (File Delete archived)