YARA-L rule coverage
29 events across 5 providers with Google SecOps / Chronicle YARA-L detection rules, 285 rule mappings total.
Microsoft-Windows-Sysmon
Event ID 1: Process creation 69 rules
- Base64 Encoded PowerShell Command Detected
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Copy From Or To Admin Share Or Sysvol Folder
- CreateDump Process Dump
- Direct Autorun Keys Modification
- File Download Using Notepad++ GUP Utility
- File Download Via Windows Defender MpCmpRun.EXE
- Finger.EXE Execution
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GCTI Remote Access Tools
- Google Safebrowsing File Process Creation
- Google Safebrowsing With Prevalence
- HackTool - Dumpert Process Dumper Execution
- Hacktool - IronSharpPack Execution
- HackTool - Mimikatz Execution
- Hacktool - SharpSuccessor Execution
- Hacktool - WinPEAS Execution Patterns
- Hash Prevalence
- Impacket WMIExec CISA Report
- IOC Hash Prevalence
- IOC SHA256 Hash
- IOC SHA256 Hash VT
- Local Accounts Discovery
- Low Prevalence Hash On Process Launch Low Prevalence Domain Accessed
- LSASS Dump Keyword In CommandLine
- MITRE ATT&CK T1003 RW Mimikatz
- MITRE ATT&CK T1003.003 RW Utilities Associated With Ntds.dit
- MITRE ATT&CK T1003.003 WMIC Ntds.dit CISA Report
- MITRE ATT&CK T1021.002 Windows Admin Share Basic
- MITRE ATT&CK T1021.002 Windows Admin Share With Asset Entity
- MITRE ATT&CK T1021.002 Windows Admin Share With User Enrichment
- MITRE ATT&CK T1021.002 Windows Admin Share With User Entity
- MITRE ATT&CK T1033 Recon Successful Logon Enumeration Powershell CISA Report
- MITRE ATT&CK T1053.005 Windows Creation Of Scheduled Task
- MITRE ATT&CK T1090 Port Proxy Forwarding CISA Report
- MITRE ATT&CK T1140 Encoded Powershell Command
- MITRE ATT&CK T1570 Suspicious Command PSExec
- New User Created Via Net.EXE
- potential lsass process dump via procdump
- Potential Suspicious Activity Using SeCEdit
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE
- Potential Webshell Process Execution
- PowerShell DownloadFile
- PowerShell Web Download
- PrintBrm ZIP Creation of Extraction
- Process Launch VT Enrichment
- Process Memory Dump Via Comsvcs.DLL
- Process Memory Dump via RdrLeakDiag.exe
- PUA - Nimgrab Execution
- Purple Knight Tool Execution Detected
- Recon Credential Theft CISA Report
- Recon Environment Enumeration Active Directory CISA Report
- Recon Environment Enumeration Network CISA Report
- Recon Environment Enumeration System CISA Report
- Recon Suspicious Commands CISA Report
- Reg Add Suspicious Paths
- Renamed CreateDump Utility Execution
- Safebrowsing Process Creation Hashes Seen More Than 7 Days
- ShimCache Flush
- Suspicious Certreq Command to Download
- Suspicious Curl.EXE Download
- Suspicious Download Via Certutil.EXE
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
- Suspicious Invoke-WebRequest Execution
- Uncommon or Suspicious RMM Tool Execution Detected
- VT Relationships File Executes File
- W3WP Launching Encoded Powershell
- Whoami Execution
- Windows Event Log Cleared
Event ID 3: Network connection 14 rules
- GCTI Benign Binaries Contacts Tor Exit Node
- GCTI Tor Exit Nodes
- Google Safebrowsing File Contacts Tor Exit Node
- High Risk User Download Executable From Macro
- IOC IP Target
- IP Target Prevalence
- Network Connection First Seen In Past Day
- Network Traffic To Specific Country
- Potential Remote PowerShell Session Initiated
- Suspicious ASN
- Suspicious ASN Watchlist
- VT Relationships File Contacts IP
- VT Relationships File Contacts Tor IP
- WHOIS Recently Created Domain Access
Event ID 10: ProcessAccess 5 rules
Event ID 11: FileCreate 20 rules
- Attempted SharePoint Webshell Creation CVE-2025-53770
- Cred Dump Tools Dropped Files
- GCTI Remote Access Tools
- Google Safebrowsing File Process Creation
- HackTool - Dumpert Process Dumper Default File
- Impacket WMIExec CISA Report
- IOC Hash Prevalence
- IOC SHA256 Hash
- IOC SHA256 Hash VT
- LSASS Process Memory Dump Creation Via Taskmgr.exe
- LSASS Process Memory Dump Files
- MITRE ATT&CK T1003.003 WMIC Ntds.dit CISA Report
- Process Launch VT Enrichment
- Safebrowsing Process Creation Hashes Seen More Than 7 Days
- Successful SharePoint Webshell Creation CVE-2025-53770
- Suspicious Filewrites To Sharepoint Layouts
- Suspicious Unusual Location LNK File
- VT Relationships File Downloaded From IP
- VT Relationships File Downloaded From URL
- WHOIS Expired Domain Executable Downloaded
Event ID 13: RegistryEvent (Value Set) 15 rules
- Blackbyte Ransomware Registry
- CurrentControlSet Autorun Keys Modification
- CurrentVersion Autorun Keys Modification
- Default RDP Port Changed to Non Standard Port
- Disable Internal Tools or Feature in Registry
- MITRE ATT&CK T1090 Port Proxy Forwarding CISA Report
- Modify User Shell Folders Startup Value
- New RUN Key Pointing to Suspicious Folder
- Potential Credential Dumping Via LSASS SilentProcessExit Technique
- RDP Sensitive Settings Changed
- RDP Sensitive Settings Changed to Zero
- RestrictedAdminMode Registry Value Tampering
- Session Manager Autorun Keys Modification
- Suspicious Powershell In Registry Run Keys
- Wdigest Enable UseLogonCredential
Microsoft-Windows-Security-Auditing
Event ID 4624: An account was successfully logged on. 12 rules
- ADFS DKM Key Access
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GeoIP User Login From Multiple States Or Countries
- Logins From Terminated Employees
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One With User Entity
- MITRE ATT&CK T1110.003 RW Windows Password Spray
- Okta Multiple Failed Requests To Access Applications
- sap break glass account login
- sap impossible travel
- sap multi terminal logon
- Windows Short Term Account Use
Event ID 4625: An account failed to log on. 12 rules
- ADFS DKM Key Access
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GeoIP User Login From Multiple States Or Countries
- Logins From Terminated Employees
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One With User Entity
- MITRE ATT&CK T1110.003 RW Windows Password Spray
- Okta Multiple Failed Requests To Access Applications
- sap break glass account login
- sap impossible travel
- sap multi terminal logon
- Windows Short Term Account Use
Event ID 4648: A logon was attempted using explicit credentials. 12 rules
- ADFS DKM Key Access
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GeoIP User Login From Multiple States Or Countries
- Logins From Terminated Employees
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One With User Entity
- MITRE ATT&CK T1110.003 RW Windows Password Spray
- Okta Multiple Failed Requests To Access Applications
- sap break glass account login
- sap impossible travel
- sap multi terminal logon
- Windows Short Term Account Use
Event ID 4657: A registry value was modified. 15 rules
- Blackbyte Ransomware Registry
- CurrentControlSet Autorun Keys Modification
- CurrentVersion Autorun Keys Modification
- Default RDP Port Changed to Non Standard Port
- Disable Internal Tools or Feature in Registry
- MITRE ATT&CK T1090 Port Proxy Forwarding CISA Report
- Modify User Shell Folders Startup Value
- New RUN Key Pointing to Suspicious Folder
- Potential Credential Dumping Via LSASS SilentProcessExit Technique
- RDP Sensitive Settings Changed
- RDP Sensitive Settings Changed to Zero
- RestrictedAdminMode Registry Value Tampering
- Session Manager Autorun Keys Modification
- Suspicious Powershell In Registry Run Keys
- Wdigest Enable UseLogonCredential
Event ID 4688: A new process has been created. 69 rules
- Base64 Encoded PowerShell Command Detected
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Copy From Or To Admin Share Or Sysvol Folder
- CreateDump Process Dump
- Direct Autorun Keys Modification
- File Download Using Notepad++ GUP Utility
- File Download Via Windows Defender MpCmpRun.EXE
- Finger.EXE Execution
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GCTI Remote Access Tools
- Google Safebrowsing File Process Creation
- Google Safebrowsing With Prevalence
- HackTool - Dumpert Process Dumper Execution
- Hacktool - IronSharpPack Execution
- HackTool - Mimikatz Execution
- Hacktool - SharpSuccessor Execution
- Hacktool - WinPEAS Execution Patterns
- Hash Prevalence
- Impacket WMIExec CISA Report
- IOC Hash Prevalence
- IOC SHA256 Hash
- IOC SHA256 Hash VT
- Local Accounts Discovery
- Low Prevalence Hash On Process Launch Low Prevalence Domain Accessed
- LSASS Dump Keyword In CommandLine
- MITRE ATT&CK T1003 RW Mimikatz
- MITRE ATT&CK T1003.003 RW Utilities Associated With Ntds.dit
- MITRE ATT&CK T1003.003 WMIC Ntds.dit CISA Report
- MITRE ATT&CK T1021.002 Windows Admin Share Basic
- MITRE ATT&CK T1021.002 Windows Admin Share With Asset Entity
- MITRE ATT&CK T1021.002 Windows Admin Share With User Enrichment
- MITRE ATT&CK T1021.002 Windows Admin Share With User Entity
- MITRE ATT&CK T1033 Recon Successful Logon Enumeration Powershell CISA Report
- MITRE ATT&CK T1053.005 Windows Creation Of Scheduled Task
- MITRE ATT&CK T1090 Port Proxy Forwarding CISA Report
- MITRE ATT&CK T1140 Encoded Powershell Command
- MITRE ATT&CK T1570 Suspicious Command PSExec
- New User Created Via Net.EXE
- potential lsass process dump via procdump
- Potential Suspicious Activity Using SeCEdit
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE
- Potential Webshell Process Execution
- PowerShell DownloadFile
- PowerShell Web Download
- PrintBrm ZIP Creation of Extraction
- Process Launch VT Enrichment
- Process Memory Dump Via Comsvcs.DLL
- Process Memory Dump via RdrLeakDiag.exe
- PUA - Nimgrab Execution
- Purple Knight Tool Execution Detected
- Recon Credential Theft CISA Report
- Recon Environment Enumeration Active Directory CISA Report
- Recon Environment Enumeration Network CISA Report
- Recon Environment Enumeration System CISA Report
- Recon Suspicious Commands CISA Report
- Reg Add Suspicious Paths
- Renamed CreateDump Utility Execution
- Safebrowsing Process Creation Hashes Seen More Than 7 Days
- ShimCache Flush
- Suspicious Certreq Command to Download
- Suspicious Curl.EXE Download
- Suspicious Download Via Certutil.EXE
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
- Suspicious Invoke-WebRequest Execution
- Uncommon or Suspicious RMM Tool Execution Detected
- VT Relationships File Executes File
- W3WP Launching Encoded Powershell
- Whoami Execution
- Windows Event Log Cleared
Event ID 5156: The Windows Filtering Platform has permitted a connection. 14 rules
- GCTI Benign Binaries Contacts Tor Exit Node
- GCTI Tor Exit Nodes
- Google Safebrowsing File Contacts Tor Exit Node
- High Risk User Download Executable From Macro
- IOC IP Target
- IP Target Prevalence
- Network Connection First Seen In Past Day
- Network Traffic To Specific Country
- Potential Remote PowerShell Session Initiated
- Suspicious ASN
- Suspicious ASN Watchlist
- VT Relationships File Contacts IP
- VT Relationships File Contacts Tor IP
- WHOIS Recently Created Domain Access