Elastic rule coverage
51 events across 6 providers with Elastic detection rules, 922 rule mappings total. Each rule links to its own page (predicates, exclusions, shared indicators). For the rule-centric ATT&CK browse across every vendor, see all detection rules; non-Windows Elastic rules are grouped by platform and technique at Elastic non-Windows coverage.
Microsoft-Windows-Security-Auditing
Event ID 4624 An account was successfully logged on. 11 rules
- Account Password Reset Remotely production (source)
- Multiple Logon Failure Followed by Logon Success production (source)
- Potential Account Takeover - Logon from New Source IP production (source)
- Potential Account Takeover - Mixed Logon Types production (source)
- Potential Computer Account NTLM Relay Activity production (source)
- Potential Kerberos Relay Attack against a Computer Account production (source)
- Potential NTLM Relay Attack against a Computer Account production (source)
- Potential Pass-the-Hash (PtH) Attempt production (source)
- Process Creation via Secondary Logon production (source)
- Remote Windows Service Installed production (source)
- Service Creation via Local Kerberos Authentication production (source)
Event ID 4625 An account failed to log on. 6 rules
- Multiple Logon Failure Followed by Logon Success production (source)
- Multiple Logon Failure from the same Source Address production (source)
- Potential Computer Account NTLM Relay Activity production (source)
- Potential Kerberos Relay Attack against a Computer Account production (source)
- Potential NTLM Relay Attack against a Computer Account production (source)
- Privileged Accounts Brute Force production (source)
Event ID 4656 A handle to an object was requested. 1 rule
- LSASS Memory Dump Handle Access production (source)
Event ID 4662 An operation was performed on an object. 6 rules
- Access to a Sensitive LDAP Attribute production (source)
- First Time Seen Account Performing DCSync production (source)
- Potential Credential Access via DCSync production (source)
- Potential Kerberos Coercion via DNS-Based SPN Spoofing production (source)
- Suspicious Access to LDAP Attributes production (source)
- WRITEDAC Access on Active Directory Object production (source)
Event ID 4688 A new process has been created. 259 rules
- Accessing Outlook Data Files production (source)
- Account Discovery Command via SYSTEM Account production (source)
- Active Directory Discovery using AdExplorer production (source)
- Adding Hidden File Attribute via Attrib production (source)
- AdFind Command Activity production (source)
- Alternate Data Stream Creation/Execution at Volume Root Directory production (source)
- At.exe Command Lateral Movement production (source)
- Attempt to Establish VScode Remote Tunnel production (source)
- Attempt to Install or Run Kali Linux via WSL production (source)
- Attempted Private Key Access production (source)
- AWS SSM `SendCommand` with Run Shell Command Parameters production (source)
- Backup Deletion with Wbadmin production (source)
- Binary Content Copy via Cmd.exe production (source)
- Bitsadmin Activity production (source)
- Browser Process Spawned from an Unusual Parent production (source)
- Bypass UAC via Event Viewer production (source)
- Clearing Windows Console History production (source)
- Clearing Windows Event Logs production (source)
- Code Signing Policy Modification Through Built-in tools production (source)
- Command and Scripting Interpreter via Windows Scripts production (source)
- Command Execution via ForFiles production (source)
- Command Execution via SolarWinds Process production (source)
- Command Obfuscation via Unicode Modifier Letters production (source)
- Command Shell Activity Started via RunDLL32 production (source)
- Conhost Spawned By Suspicious Parent Process production (source)
- Control Panel Process with Unusual Arguments production (source)
- Credential Acquisition via Registry Hive Dumping production (source)
- Delayed Execution via Ping production (source)
- Delete Volume USN Journal with Fsutil production (source)
- Disable Windows Event and Security Logs Using Built-in Tools production (source)
- Disable Windows Firewall Rules via Netsh production (source)
- Disabling Windows Defender Security Settings via PowerShell production (source)
- Enable Host Network Discovery via Netsh production (source)
- Encrypting Files with WinRar or 7z production (source)
- Enumerating Domain Trusts via DSQUERY.EXE production (source)
- Enumerating Domain Trusts via NLTEST.EXE production (source)
- Enumeration Command Spawned via WMIPrvSE production (source)
- Enumeration of Administrator Accounts production (source)
- Execution from a Removable Media with Network Connection production (source)
- Execution from Unusual Directory - Command Line production (source)
- Execution of a Downloaded Windows Script production (source)
- Execution of COM object via Xwizard production (source)
- Execution of File Written or Modified by Microsoft Office production (source)
- Execution of Persistent Suspicious Program production (source)
- Execution via Microsoft DotNet ClickOnce Host production (source)
- Execution via MS VisualStudio Pre/Post Build Events production (source)
- Execution via TSClient Mountpoint production (source)
- Execution via Windows Command Debugging Utility production (source)
- Execution via Windows Subsystem for Linux production (source)
- Exporting Exchange Mailbox via PowerShell production (source)
- File and Directory Permissions Modification production (source)
- File or Directory Deletion Command production (source)
- File with Right-to-Left Override Character (RTLO) Created/Executed production (source)
- First Time Seen Remote Monitoring and Management Tool production (source)
- Group Policy Discovery via Microsoft GPResult Utility production (source)
- Host File System Changes via Windows Subsystem for Linux production (source)
- IIS HTTP Logging Disabled production (source)
- ImageLoad via Windows Update Auto Update Client production (source)
- Incoming DCOM Lateral Movement via MSHTA production (source)
- Incoming DCOM Lateral Movement with MMC production (source)
- Incoming DCOM Lateral Movement with ShellBrowserWindow or ShellWindows production (source)
- Incoming Execution via PowerShell Remoting production (source)
- Incoming Execution via WinRM Remote Shell production (source)
- Indirect Command Execution via Forfiles/Pcalua production (source)
- InstallUtil Activity production (source)
- InstallUtil Process Making Network Connections production (source)
- Local Scheduled Task Creation production (source)
- Microsoft Build Engine Started by a System Process production (source)
- Microsoft Build Engine Started by an Office Application production (source)
- Microsoft Build Engine Using an Alternate Name production (source)
- Microsoft Exchange Server UM Spawning Suspicious Processes production (source)
- Microsoft Exchange Worker Spawning Suspicious Processes production (source)
- Microsoft IIS Connection Strings Decryption production (source)
- Microsoft IIS Service Account Password Dumped production (source)
- Microsoft Management Console File from Unusual Path production (source)
- Modification of Boot Configuration production (source)
- Mofcomp Activity production (source)
- Mounting Hidden or WebDav Remote Shares production (source)
- MsBuild Making Network Connections production (source)
- Mshta Making Network Connections production (source)
- MsiExec Service Child Process With Network Connection production (source)
- Multiple Remote Management Tool Vendors on Same Host production (source)
- NetSupport Manager Execution from an Unusual Path production (source)
- Network Connection via Compiled HTML File production (source)
- Network Connection via MsXsl production (source)
- Network Connection via Registration Utility production (source)
- Network Connection via Signed Binary production (source)
- New ActiveSyncAllowedDeviceID Added via PowerShell production (source)
- NTDS Dump via Wbadmin production (source)
- NTDS or SAM Database File Copied production (source)
- Parent Process PID Spoofing production (source)
- Peripheral Device Discovery production (source)
- Persistence via BITS Job Notify Cmdline production (source)
- Persistence via TelemetryController Scheduled Task Hijack production (source)
- Persistence via Update Orchestrator Service Hijack production (source)
- Persistence via WMI Event Subscription production (source)
- Potential Application Shimming via Sdbinst production (source)
- Potential Command and Control via Internet Explorer production (source)
- Potential Command Shell via NetCat production (source)
- Potential Credential Access via Trusted Developer Utility production (source)
- Potential Credential Access via Windows Utilities production (source)
- Potential CVE-2025-33053 Exploitation production (source)
- Potential Data Exfiltration via Rclone production (source)
- Potential Defense Evasion via CMSTP.exe production (source)
- Potential DLL Side-Loading via Trusted Microsoft Programs production (source)
- Potential DNS Tunneling via NsLookup production (source)
- Potential Escalation via Vulnerable MSI Repair production (source)
- Potential Evasion via Filter Manager production (source)
- Potential Execution via FileFix Phishing Attack production (source)
- Potential Exploitation of an Unquoted Service Path Vulnerability production (source)
- Potential Fake CAPTCHA Phishing Attack production (source)
- Potential File Download via a Headless Browser production (source)
- Potential File Transfer via Certreq production (source)
- Potential File Transfer via Curl for Windows production (source)
- Potential Foxmail Exploitation production (source)
- Potential Local NTLM Relay via HTTP production (source)
- Potential LSASS Clone Creation via PssCaptureSnapShot production (source)
- Potential Masquerading as Browser Process production (source)
- Potential Masquerading as Business App Installer production (source)
- Potential Masquerading as Communication Apps production (source)
- Potential Masquerading as System32 Executable production (source)
- Potential Modification of Accessibility Binaries production (source)
- Potential Notepad Markdown RCE Exploitation production (source)
- Potential Privilege Escalation via InstallerFileTakeOver production (source)
- Potential Process Injection from Malicious Document production (source)
- Potential Protocol Tunneling via Cloudflared production (source)
- Potential Protocol Tunneling via Yuze production (source)
- Potential Remote Desktop Shadowing Activity production (source)
- Potential Remote Desktop Tunneling Detected production (source)
- Potential Remote File Execution via MSIEXEC production (source)
- Potential Remote Install via MsiExec production (source)
- Potential SAP NetWeaver Exploitation production (source)
- Potential SharpRDP Behavior production (source)
- Potential Veeam Credential Access Command production (source)
- Potential Windows Error Manager Masquerading production (source)
- Potential WSUS Abuse for Lateral Movement production (source)
- Privilege Escalation via Named Pipe Impersonation production (source)
- Privileges Elevation via Parent Process PID Spoofing production (source)
- Process Activity via Compiled HTML File production (source)
- Process Created with a Duplicated Token production (source)
- Process Created with an Elevated Token production (source)
- Process Creation via Secondary Logon production (source)
- Process Discovery Using Built-in Tools production (source)
- Process Execution from an Unusual Directory production (source)
- Program Files Directory Masquerading production (source)
- Proxy Execution via Console Window Host production (source)
- Proxy Execution via Windows OpenSSH production (source)
- PsExec Network Connection production (source)
- Remote Desktop Enabled in Windows Firewall by Netsh production (source)
- Remote Desktop File Opened from Suspicious Path production (source)
- Remote Execution via File Shares production (source)
- Remote File Copy to a Hidden Share production (source)
- Remote File Download via Desktopimgdownldr Utility production (source)
- Remote File Download via MpCmdRun production (source)
- Remote Management Access Launch After MSI Install production (source)
- Remote System Discovery Commands production (source)
- Remote XSL Script Execution via COM production (source)
- Remotely Started Services via RPC production (source)
- Renamed Automation Script Interpreter production (source)
- Renamed Utility Executed with Short Program Name production (source)
- ROT Encoded Python Script Execution production (source)
- ScreenConnect Server Spawning Suspicious Processes production (source)
- Script Execution via Microsoft HTML Application production (source)
- Searching for Saved Credentials via VaultCmd production (source)
- Security Software Discovery using WMIC production (source)
- Service Command Lateral Movement production (source)
- Service Control Spawned via Script Interpreter production (source)
- Service DACL Modification via sc.exe production (source)
- Signed Proxy Execution via MS Work Folders production (source)
- SMB Connections via LOLBin or Untrusted Process production (source)
- Startup Folder Persistence via Unsigned Process production (source)
- Suspicious .NET Code Compilation production (source)
- Suspicious CertUtil Commands production (source)
- Suspicious Cmd Execution via WMI production (source)
- Suspicious Command Prompt Network Connection production (source)
- Suspicious Communication App Child Process production (source)
- Suspicious Endpoint Security Parent Process production (source)
- Suspicious Execution from a Mounted Device production (source)
- Suspicious Execution from a WebDav Share production (source)
- Suspicious Execution from INET Cache production (source)
- Suspicious Execution from VS Code Extension production (source)
- Suspicious Execution via Microsoft Office Add-Ins production (source)
- Suspicious Execution via MSIEXEC production (source)
- Suspicious Execution via Scheduled Task production (source)
- Suspicious Execution via Windows Subsystem for Linux production (source)
- Suspicious Execution with NodeJS production (source)
- Suspicious Explorer Child Process production (source)
- Suspicious HTML File Creation production (source)
- Suspicious Instance Metadata Service (IMDS) API Command Line Execution production (source)
- Suspicious Inter-Process Communication via Outlook production (source)
- Suspicious JavaScript Execution via Deno production (source)
- Suspicious JetBrains TeamCity Child Process production (source)
- Suspicious Microsoft Antimalware Service Execution production (source)
- Suspicious Microsoft Diagnostics Wizard Execution production (source)
- Suspicious Microsoft HTML Application Child Process production (source)
- Suspicious MS Office Child Process production (source)
- Suspicious MS Outlook Child Process production (source)
- Suspicious Outlook Child Process production (source)
- Suspicious PDF Reader Child Process production (source)
- Suspicious Process Execution via Renamed PsExec Executable production (source)
- Suspicious ScreenConnect Client Child Process production (source)
- Suspicious Shell Execution via Velociraptor production (source)
- Suspicious SolarWinds Child Process production (source)
- Suspicious Troubleshooting Pack Cabinet Execution production (source)
- Suspicious WerFault Child Process production (source)
- Suspicious Windows Command Shell Arguments production (source)
- Suspicious Windows Powershell Arguments production (source)
- Suspicious WMIC XSL Script Execution production (source)
- Suspicious Zoom Child Process production (source)
- Symbolic Link to Shadow Copy Created production (source)
- System File Ownership Change production (source)
- System Information Discovery via Windows Command Shell production (source)
- System Service Discovery through built-in Windows Utilities production (source)
- System Shells via Services production (source)
- System Time Discovery production (source)
- UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer production (source)
- UAC Bypass Attempt via Windows Directory Masquerading production (source)
- UAC Bypass Attempt with IEditionUpgradeManager Elevated COM Interface production (source)
- UAC Bypass via DiskCleanup Scheduled Task Hijack production (source)
- UAC Bypass via ICMLuaUtil Elevated COM Interface production (source)
- UAC Bypass via Windows Firewall Snap-In Hijack production (source)
- Unusual Child Process from a System Virtual Process production (source)
- Unusual Child Process of dns.exe production (source)
- Unusual Child Processes of RunDLL32 production (source)
- Unusual Execution via Microsoft Common Console File production (source)
- Unusual Network Activity from a Windows System Binary production (source)
- Unusual Network Connection via DllHost production (source)
- Unusual Network Connection via RunDLL32 production (source)
- Unusual Parent Process for cmd.exe production (source)
- Unusual Parent-Child Relationship production (source)
- Unusual Print Spooler Child Process production (source)
- Unusual Process Execution on WBEM Path production (source)
- Unusual Process Execution Path - Alternate Data Stream production (source)
- Unusual Process Extension production (source)
- Unusual Process For MSSQL Service Accounts production (source)
- Unusual Process Network Connection production (source)
- Unusual Service Host Child Process - Childless Service production (source)
- User Account Creation production (source)
- Veeam Backup Library Loaded by Unusual Process production (source)
- Volume Shadow Copy Deleted or Resized via VssAdmin production (source)
- Volume Shadow Copy Deletion via PowerShell production (source)
- Volume Shadow Copy Deletion via WMIC production (source)
- Whoami Process Activity production (source)
- Windows Account or Group Discovery production (source)
- Windows Defender Exclusions Added via PowerShell production (source)
- Windows Firewall Disabled via PowerShell production (source)
- Windows Installer with Suspicious Properties production (source)
- Windows Network Enumeration production (source)
- Windows Sandbox with Sensitive Configuration production (source)
- Windows Script Executing PowerShell production (source)
- Windows Script Execution from Archive production (source)
- Windows Script Interpreter Executing Process via WMI production (source)
- Windows Server Update Service Spawning Suspicious Processes production (source)
- Windows Subsystem for Linux Enabled via Dism Utility production (source)
- Windows System Information Discovery production (source)
- Wireless Credential Dumping using Netsh Command production (source)
- WMI Incoming Lateral Movement production (source)
- WMI WBEMTEST Utility Execution production (source)
- WMIC Remote Command production (source)
Event ID 4698 A scheduled task was created. 3 rules
- A scheduled task was created production (source)
- Remote Scheduled Task Creation via RPC production (source)
- Temporarily Scheduled Task Creation production (source)
Event ID 4699 A scheduled task was deleted. 1 rule
- Temporarily Scheduled Task Creation production (source)
Event ID 4702 A scheduled task was updated. 1 rule
- Unusual Scheduled Task Update production (source)
Event ID 4720 A user account was created. 1 rule
- User or Group Creation/Modification production (source)
Event ID 4723 An attempt was made to change an account's password. 1 rule
- User or Group Creation/Modification production (source)
Event ID 4724 An attempt was made to reset an account's password. 1 rule
- Account Password Reset Remotely production (source)
Event ID 4738 A user account was changed. 3 rules
- Account Configured with Never-Expiring Password production (source)
- Kerberos Pre-authentication Disabled for User production (source)
- KRBTGT Delegation Backdoor production (source)
Event ID 5136 A directory service object was modified. 11 rules
- Account Configured with Never-Expiring Password production (source)
- AdminSDHolder Backdoor production (source)
- AdminSDHolder SDProp Exclusion Added production (source)
- Delegated Managed Service Account Modification by an Unusual User production (source)
- Group Policy Abuse for Privilege Addition production (source)
- Modification of the msPKIAccountCredentials production (source)
- Potential Active Directory Replication Account Backdoor production (source)
- Potential Shadow Credentials added to AD Object production (source)
- Scheduled Task Execution at Scale via GPO production (source)
- Startup/Logon Script added to Group Policy Object production (source)
- User account exposed to Kerberoasting production (source)
Event ID 5137 A directory service object was created. 5 rules
- Creation of a DNS-Named Record production (source)
- dMSA Account Creation by an Unusual User production (source)
- Potential ADIDNS Poisoning via Wildcard Record Creation production (source)
- Potential Kerberos Coercion via DNS-Based SPN Spoofing production (source)
- Potential WPAD Spoofing via DNS Record Creation production (source)
Event ID 5145 A network share object was checked to see whether client can be granted desired access. 8 rules
- Active Directory Forced Authentication from Linux Host - SMB Named Pipes production (source)
- Potential Kerberos Relay Attack against a Computer Account production (source)
- Potential Machine Account Relay Attack via SMB production (source)
- Potential Network Share Discovery production (source)
- Potential NTLM Relay Attack against a Computer Account production (source)
- Scheduled Task Execution at Scale via GPO production (source)
- Startup/Logon Script added to Group Policy Object production (source)
- Suspicious Remote Registry Access via SeBackupPrivilege production (source)
Microsoft-Windows-Sysmon
Event ID 1 Process creation 259 rules
- Accessing Outlook Data Files production (source)
- Account Discovery Command via SYSTEM Account production (source)
- Active Directory Discovery using AdExplorer production (source)
- Adding Hidden File Attribute via Attrib production (source)
- AdFind Command Activity production (source)
- Alternate Data Stream Creation/Execution at Volume Root Directory production (source)
- At.exe Command Lateral Movement production (source)
- Attempt to Establish VScode Remote Tunnel production (source)
- Attempt to Install or Run Kali Linux via WSL production (source)
- Attempted Private Key Access production (source)
- AWS SSM `SendCommand` with Run Shell Command Parameters production (source)
- Backup Deletion with Wbadmin production (source)
- Binary Content Copy via Cmd.exe production (source)
- Bitsadmin Activity production (source)
- Browser Process Spawned from an Unusual Parent production (source)
- Bypass UAC via Event Viewer production (source)
- Clearing Windows Console History production (source)
- Clearing Windows Event Logs production (source)
- Code Signing Policy Modification Through Built-in tools production (source)
- Command and Scripting Interpreter via Windows Scripts production (source)
- Command Execution via ForFiles production (source)
- Command Execution via SolarWinds Process production (source)
- Command Obfuscation via Unicode Modifier Letters production (source)
- Command Shell Activity Started via RunDLL32 production (source)
- Conhost Spawned By Suspicious Parent Process production (source)
- Control Panel Process with Unusual Arguments production (source)
- Credential Acquisition via Registry Hive Dumping production (source)
- Delayed Execution via Ping production (source)
- Delete Volume USN Journal with Fsutil production (source)
- Disable Windows Event and Security Logs Using Built-in Tools production (source)
- Disable Windows Firewall Rules via Netsh production (source)
- Disabling Windows Defender Security Settings via PowerShell production (source)
- Enable Host Network Discovery via Netsh production (source)
- Encrypting Files with WinRar or 7z production (source)
- Enumerating Domain Trusts via DSQUERY.EXE production (source)
- Enumerating Domain Trusts via NLTEST.EXE production (source)
- Enumeration Command Spawned via WMIPrvSE production (source)
- Enumeration of Administrator Accounts production (source)
- Execution from a Removable Media with Network Connection production (source)
- Execution from Unusual Directory - Command Line production (source)
- Execution of a Downloaded Windows Script production (source)
- Execution of COM object via Xwizard production (source)
- Execution of File Written or Modified by Microsoft Office production (source)
- Execution of Persistent Suspicious Program production (source)
- Execution via Microsoft DotNet ClickOnce Host production (source)
- Execution via MS VisualStudio Pre/Post Build Events production (source)
- Execution via TSClient Mountpoint production (source)
- Execution via Windows Command Debugging Utility production (source)
- Execution via Windows Subsystem for Linux production (source)
- Exporting Exchange Mailbox via PowerShell production (source)
- File and Directory Permissions Modification production (source)
- File or Directory Deletion Command production (source)
- File with Right-to-Left Override Character (RTLO) Created/Executed production (source)
- First Time Seen Remote Monitoring and Management Tool production (source)
- Group Policy Discovery via Microsoft GPResult Utility production (source)
- Host File System Changes via Windows Subsystem for Linux production (source)
- IIS HTTP Logging Disabled production (source)
- ImageLoad via Windows Update Auto Update Client production (source)
- Incoming DCOM Lateral Movement via MSHTA production (source)
- Incoming DCOM Lateral Movement with MMC production (source)
- Incoming DCOM Lateral Movement with ShellBrowserWindow or ShellWindows production (source)
- Incoming Execution via PowerShell Remoting production (source)
- Incoming Execution via WinRM Remote Shell production (source)
- Indirect Command Execution via Forfiles/Pcalua production (source)
- InstallUtil Activity production (source)
- InstallUtil Process Making Network Connections production (source)
- Local Scheduled Task Creation production (source)
- Microsoft Build Engine Started by a System Process production (source)
- Microsoft Build Engine Started by an Office Application production (source)
- Microsoft Build Engine Using an Alternate Name production (source)
- Microsoft Exchange Server UM Spawning Suspicious Processes production (source)
- Microsoft Exchange Worker Spawning Suspicious Processes production (source)
- Microsoft IIS Connection Strings Decryption production (source)
- Microsoft IIS Service Account Password Dumped production (source)
- Microsoft Management Console File from Unusual Path production (source)
- Modification of Boot Configuration production (source)
- Mofcomp Activity production (source)
- Mounting Hidden or WebDav Remote Shares production (source)
- MsBuild Making Network Connections production (source)
- Mshta Making Network Connections production (source)
- MsiExec Service Child Process With Network Connection production (source)
- Multiple Remote Management Tool Vendors on Same Host production (source)
- NetSupport Manager Execution from an Unusual Path production (source)
- Network Connection via Compiled HTML File production (source)
- Network Connection via MsXsl production (source)
- Network Connection via Registration Utility production (source)
- Network Connection via Signed Binary production (source)
- New ActiveSyncAllowedDeviceID Added via PowerShell production (source)
- NTDS Dump via Wbadmin production (source)
- NTDS or SAM Database File Copied production (source)
- Parent Process PID Spoofing production (source)
- Peripheral Device Discovery production (source)
- Persistence via BITS Job Notify Cmdline production (source)
- Persistence via TelemetryController Scheduled Task Hijack production (source)
- Persistence via Update Orchestrator Service Hijack production (source)
- Persistence via WMI Event Subscription production (source)
- Potential Application Shimming via Sdbinst production (source)
- Potential Command and Control via Internet Explorer production (source)
- Potential Command Shell via NetCat production (source)
- Potential Credential Access via Trusted Developer Utility production (source)
- Potential Credential Access via Windows Utilities production (source)
- Potential CVE-2025-33053 Exploitation production (source)
- Potential Data Exfiltration via Rclone production (source)
- Potential Defense Evasion via CMSTP.exe production (source)
- Potential DLL Side-Loading via Trusted Microsoft Programs production (source)
- Potential DNS Tunneling via NsLookup production (source)
- Potential Escalation via Vulnerable MSI Repair production (source)
- Potential Evasion via Filter Manager production (source)
- Potential Execution via FileFix Phishing Attack production (source)
- Potential Exploitation of an Unquoted Service Path Vulnerability production (source)
- Potential Fake CAPTCHA Phishing Attack production (source)
- Potential File Download via a Headless Browser production (source)
- Potential File Transfer via Certreq production (source)
- Potential File Transfer via Curl for Windows production (source)
- Potential Foxmail Exploitation production (source)
- Potential Local NTLM Relay via HTTP production (source)
- Potential Masquerading as Browser Process production (source)
- Potential Masquerading as Business App Installer production (source)
- Potential Masquerading as Communication Apps production (source)
- Potential Masquerading as System32 Executable production (source)
- Potential Modification of Accessibility Binaries production (source)
- Potential Notepad Markdown RCE Exploitation production (source)
- Potential Privilege Escalation via InstallerFileTakeOver production (source)
- Potential Process Injection from Malicious Document production (source)
- Potential Protocol Tunneling via Cloudflared production (source)
- Potential Protocol Tunneling via Yuze production (source)
- Potential Remote Desktop Shadowing Activity production (source)
- Potential Remote Desktop Tunneling Detected production (source)
- Potential Remote File Execution via MSIEXEC production (source)
- Potential Remote Install via MsiExec production (source)
- Potential SAP NetWeaver Exploitation production (source)
- Potential SharpRDP Behavior production (source)
- Potential Veeam Credential Access Command production (source)
- Potential Windows Error Manager Masquerading production (source)
- Potential WSUS Abuse for Lateral Movement production (source)
- Privilege Escalation via Named Pipe Impersonation production (source)
- Privileges Elevation via Parent Process PID Spoofing production (source)
- Process Activity via Compiled HTML File production (source)
- Process Created with a Duplicated Token production (source)
- Process Created with an Elevated Token production (source)
- Process Creation via Secondary Logon production (source)
- Process Discovery Using Built-in Tools production (source)
- Process Execution from an Unusual Directory production (source)
- Program Files Directory Masquerading production (source)
- Proxy Execution via Console Window Host production (source)
- Proxy Execution via Windows OpenSSH production (source)
- PsExec Network Connection production (source)
- Remote Desktop Enabled in Windows Firewall by Netsh production (source)
- Remote Desktop File Opened from Suspicious Path production (source)
- Remote Execution via File Shares production (source)
- Remote File Copy to a Hidden Share production (source)
- Remote File Download via Desktopimgdownldr Utility production (source)
- Remote File Download via MpCmdRun production (source)
- Remote Management Access Launch After MSI Install production (source)
- Remote System Discovery Commands production (source)
- Remote XSL Script Execution via COM production (source)
- Remotely Started Services via RPC production (source)
- Renamed Automation Script Interpreter production (source)
- Renamed Utility Executed with Short Program Name production (source)
- ROT Encoded Python Script Execution production (source)
- ScreenConnect Server Spawning Suspicious Processes production (source)
- Script Execution via Microsoft HTML Application production (source)
- Searching for Saved Credentials via VaultCmd production (source)
- Security Software Discovery using WMIC production (source)
- Service Command Lateral Movement production (source)
- Service Control Spawned via Script Interpreter production (source)
- Service DACL Modification via sc.exe production (source)
- Signed Proxy Execution via MS Work Folders production (source)
- SMB Connections via LOLBin or Untrusted Process production (source)
- Startup Folder Persistence via Unsigned Process production (source)
- Suspicious .NET Code Compilation production (source)
- Suspicious CertUtil Commands production (source)
- Suspicious Cmd Execution via WMI production (source)
- Suspicious Command Prompt Network Connection production (source)
- Suspicious Communication App Child Process production (source)
- Suspicious Endpoint Security Parent Process production (source)
- Suspicious Execution from a Mounted Device production (source)
- Suspicious Execution from a WebDav Share production (source)
- Suspicious Execution from INET Cache production (source)
- Suspicious Execution from VS Code Extension production (source)
- Suspicious Execution via Microsoft Office Add-Ins production (source)
- Suspicious Execution via MSIEXEC production (source)
- Suspicious Execution via Scheduled Task production (source)
- Suspicious Execution via Windows Subsystem for Linux production (source)
- Suspicious Execution with NodeJS production (source)
- Suspicious Explorer Child Process production (source)
- Suspicious HTML File Creation production (source)
- Suspicious Instance Metadata Service (IMDS) API Command Line Execution production (source)
- Suspicious Inter-Process Communication via Outlook production (source)
- Suspicious JavaScript Execution via Deno production (source)
- Suspicious JetBrains TeamCity Child Process production (source)
- Suspicious Microsoft Antimalware Service Execution production (source)
- Suspicious Microsoft Diagnostics Wizard Execution production (source)
- Suspicious Microsoft HTML Application Child Process production (source)
- Suspicious MS Office Child Process production (source)
- Suspicious MS Outlook Child Process production (source)
- Suspicious Outlook Child Process production (source)
- Suspicious PDF Reader Child Process production (source)
- Suspicious Process Creation CallTrace production (source)
- Suspicious Process Execution via Renamed PsExec Executable production (source)
- Suspicious ScreenConnect Client Child Process production (source)
- Suspicious Shell Execution via Velociraptor production (source)
- Suspicious SolarWinds Child Process production (source)
- Suspicious Troubleshooting Pack Cabinet Execution production (source)
- Suspicious WerFault Child Process production (source)
- Suspicious Windows Command Shell Arguments production (source)
- Suspicious Windows Powershell Arguments production (source)
- Suspicious WMIC XSL Script Execution production (source)
- Suspicious Zoom Child Process production (source)
- Symbolic Link to Shadow Copy Created production (source)
- System File Ownership Change production (source)
- System Information Discovery via Windows Command Shell production (source)
- System Service Discovery through built-in Windows Utilities production (source)
- System Shells via Services production (source)
- System Time Discovery production (source)
- UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer production (source)
- UAC Bypass Attempt via Windows Directory Masquerading production (source)
- UAC Bypass Attempt with IEditionUpgradeManager Elevated COM Interface production (source)
- UAC Bypass via DiskCleanup Scheduled Task Hijack production (source)
- UAC Bypass via ICMLuaUtil Elevated COM Interface production (source)
- UAC Bypass via Windows Firewall Snap-In Hijack production (source)
- Unusual Child Process from a System Virtual Process production (source)
- Unusual Child Process of dns.exe production (source)
- Unusual Child Processes of RunDLL32 production (source)
- Unusual Execution via Microsoft Common Console File production (source)
- Unusual Network Activity from a Windows System Binary production (source)
- Unusual Network Connection via DllHost production (source)
- Unusual Network Connection via RunDLL32 production (source)
- Unusual Parent Process for cmd.exe production (source)
- Unusual Parent-Child Relationship production (source)
- Unusual Print Spooler Child Process production (source)
- Unusual Process Execution on WBEM Path production (source)
- Unusual Process Execution Path - Alternate Data Stream production (source)
- Unusual Process Extension production (source)
- Unusual Process For MSSQL Service Accounts production (source)
- Unusual Process Network Connection production (source)
- Unusual Service Host Child Process - Childless Service production (source)
- User Account Creation production (source)
- Veeam Backup Library Loaded by Unusual Process production (source)
- Volume Shadow Copy Deleted or Resized via VssAdmin production (source)
- Volume Shadow Copy Deletion via PowerShell production (source)
- Volume Shadow Copy Deletion via WMIC production (source)
- Whoami Process Activity production (source)
- Windows Account or Group Discovery production (source)
- Windows Defender Exclusions Added via PowerShell production (source)
- Windows Firewall Disabled via PowerShell production (source)
- Windows Installer with Suspicious Properties production (source)
- Windows Network Enumeration production (source)
- Windows Sandbox with Sensitive Configuration production (source)
- Windows Script Executing PowerShell production (source)
- Windows Script Execution from Archive production (source)
- Windows Script Interpreter Executing Process via WMI production (source)
- Windows Server Update Service Spawning Suspicious Processes production (source)
- Windows Subsystem for Linux Enabled via Dism Utility production (source)
- Windows System Information Discovery production (source)
- Wireless Credential Dumping using Netsh Command production (source)
- WMI Incoming Lateral Movement production (source)
- WMI WBEMTEST Utility Execution production (source)
- WMIC Remote Command production (source)
Event ID 2 A process changed a file creation time 1 rule
- Potential Timestomp in Executable Files production (source)
Event ID 3 Network connection 49 rules
- Connection to Common Large Language Model Endpoints production (source)
- Connection to Commonly Abused Free SSL Certificate Providers production (source)
- Connection to Commonly Abused Web Services production (source)
- Deprecated - SUNBURST Command and Control Activity production (source)
- Execution from a Removable Media with Network Connection production (source)
- Execution via Microsoft DotNet ClickOnce Host production (source)
- GenAI Process Connection to Suspicious Top Level Domain production (source)
- Incoming DCOM Lateral Movement via MSHTA production (source)
- Incoming DCOM Lateral Movement with MMC production (source)
- Incoming DCOM Lateral Movement with ShellBrowserWindow or ShellWindows production (source)
- Incoming Execution via PowerShell Remoting production (source)
- Incoming Execution via WinRM Remote Shell production (source)
- InstallUtil Process Making Network Connections production (source)
- Kerberos Traffic from Unusual Process production (source)
- Mshta Making Network Connections production (source)
- MsiExec Service Child Process With Network Connection production (source)
- Network Activity to a Suspicious Top Level Domain production (source)
- Network Connection via Certutil production (source)
- Network Connection via Compiled HTML File production (source)
- Network Connection via MsXsl production (source)
- Network Connection via Registration Utility production (source)
- Network Connection via Signed Binary production (source)
- Outbound Scheduled Task Activity via PowerShell production (source)
- Potential Command and Control via Internet Explorer production (source)
- Potential Enumeration via Active Directory Web Service production (source)
- Potential Evasion via Windows Filtering Platform production (source)
- Potential Kerberos SPN Spoofing via Suspicious DNS Query production (source)
- Potential Lateral Tool Transfer via SMB Share production (source)
- Potential Outgoing RDP Connection by Unusual Process production (source)
- Potential Ransomware Note File Dropped via SMB production (source)
- Potential Remote File Execution via MSIEXEC production (source)
- Potential SharpRDP Behavior production (source)
- Potential Windows Error Manager Masquerading production (source)
- PsExec Network Connection production (source)
- Remote File Download via PowerShell production (source)
- Remote File Download via Script Interpreter production (source)
- Remote Scheduled Task Creation production (source)
- Remotely Started Services via RPC production (source)
- Service Command Lateral Movement production (source)
- SMB Connections via LOLBin or Untrusted Process production (source)
- Suspicious Command Prompt Network Connection production (source)
- Suspicious File Renamed via SMB production (source)
- Suspicious Instance Metadata Service (IMDS) API Request production (source)
- System Public IP Discovery via DNS Query production (source)
- Unusual Network Activity from a Windows System Binary production (source)
- Unusual Network Connection via DllHost production (source)
- Unusual Network Connection via RunDLL32 production (source)
- Unusual Process Network Connection production (source)
- WMI Incoming Lateral Movement production (source)
Event ID 6 Driver loaded 2 rules
- Expired or Revoked Driver Loaded production (source)
- Untrusted Driver Loaded production (source)
Event ID 7 Image loaded 20 rules
- Compression DLL Loaded by Unusual Process production (source)
- Image Loaded with Invalid Signature production (source)
- Outbound Scheduled Task Activity via PowerShell production (source)
- Potential Command and Control via Internet Explorer production (source)
- Potential Credential Access via Renamed COM+ Services DLL production (source)
- Potential Credential Access via Trusted Developer Utility production (source)
- Potential Enumeration via Active Directory Web Service production (source)
- Potential Masquerading as VLC DLL production (source)
- Potential Windows Session Hijacking via CcmExec production (source)
- Remote XSL Script Execution via COM production (source)
- Suspicious DLL Loaded for Persistence or Privilege Escalation production (source)
- Suspicious Module Loaded by LSASS production (source)
- Suspicious SolarWinds Web Help Desk Java Module Load or Child Process production (source)
- Suspicious WMIC XSL Script Execution production (source)
- Unsigned DLL Loaded by a Trusted Process production (source)
- Unsigned DLL Loaded by Svchost production (source)
- Unsigned DLL Side-Loading from a Suspicious Folder production (source)
- Untrusted DLL Loaded by Azure AD Connect Authentication Agent production (source)
- Veeam Backup Library Loaded by Unusual Process production (source)
- WPS Office Exploitation via DLL Hijack production (source)
Event ID 10 ProcessAccess 7 rules
- Potential Credential Access via DuplicateHandle in LSASS production (source)
- Potential Credential Access via LSASS Memory Dump production (source)
- Potential LSASS Memory Dump via PssCaptureSnapShot production (source)
- Suspicious LSASS Access via MalSecLogon production (source)
- Suspicious Lsass Process Access production (source)
- Suspicious Process Access via Direct System Call production (source)
- Suspicious Process Creation CallTrace production (source)
Event ID 11 FileCreate 34 rules
- Alternate Data Stream Creation/Execution at Volume Root Directory production (source)
- Browser Extension Install production (source)
- Creation of SettingContent-ms Files production (source)
- Deprecated - Adobe Hijack Persistence production (source)
- Deprecated - Suspicious PrintSpooler Service Executable File Creation production (source)
- Downloaded Shortcut Files production (source)
- Downloaded URL Files production (source)
- Executable File Creation with Multiple Extensions production (source)
- Execution of a Downloaded Windows Script production (source)
- File Compressed or Archived into Common Format by Unsigned Process production (source)
- File Staged in Root Folder of Recycle Bin production (source)
- File with Right-to-Left Override Character (RTLO) Created/Executed production (source)
- File with Suspicious Extension Downloaded production (source)
- GenAI Process Accessing Sensitive Files production (source)
- Kirbi File Creation production (source)
- Lateral Movement via Startup Folder production (source)
- Memory Dump File with Unusual Extension production (source)
- Microsoft Exchange Server UM Writing Suspicious Files production (source)
- Persistence via a Windows Installer production (source)
- Potential Credential Access via Memory Dump File Creation production (source)
- Potential Lateral Tool Transfer via SMB Share production (source)
- Potential Persistence via Mandatory User Profile production (source)
- Potential Ransomware Behavior - Note Files by System production (source)
- Potential Ransomware Note File Dropped via SMB production (source)
- Potential Remote Credential Access via Registry production (source)
- Potential SAP NetWeaver WebShell Creation production (source)
- Remote Execution via File Shares production (source)
- Remote File Copy via TeamViewer production (source)
- Remote File Download via PowerShell production (source)
- Remote File Download via Script Interpreter production (source)
- Suspicious HTML File Creation production (source)
- Unusual File Creation - Alternate Data Stream production (source)
- Unusual File Operation by dns.exe production (source)
- Windows Registry File Creation in SMB Share production (source)
Event ID 12 RegistryEvent (Object create and delete) 60 rules
- Code Signing Policy Modification Through Registry production (source)
- Component Object Model Hijacking production (source)
- Creation of a Hidden Local User Account production (source)
- Creation or Modification of Root Certificate production (source)
- Deprecated - Encoded Executable Stored in the Registry production (source)
- Disabling Lsa Protection via Registry Modification production (source)
- Disabling User Account Control via Registry Modification production (source)
- DNS Global Query Block List Modified or Disabled production (source)
- DNS-over-HTTPS Enabled via Registry production (source)
- First Time Seen Removable Device production (source)
- Full User-Mode Dumps Enabled System-Wide production (source)
- Image File Execution Options Injection production (source)
- Installation of Custom Shim Databases production (source)
- Installation of Security Support Provider production (source)
- Local Account TokenFilter Policy Disabled production (source)
- Microsoft Windows Defender Tampering production (source)
- Modification of AmsiEnable Registry Key production (source)
- Modification of WDigest Security Provider production (source)
- MS Office Macro Security Registry Modifications production (source)
- Netsh Helper DLL production (source)
- Network Logon Provider Registry Modification production (source)
- Network-Level Authentication (NLA) Disabled production (source)
- NullSessionPipe Registry Modification production (source)
- Office Test Registry Persistence production (source)
- Outlook Home Page Registry Modification production (source)
- Persistence via a Windows Installer production (source)
- Persistence via Hidden Run Key Detected production (source)
- Persistence via WMI Standard Registry Provider production (source)
- Port Forwarding Rule Addition production (source)
- Potential LSA Authentication Package Abuse production (source)
- Potential NetNTLMv1 Downgrade Attack production (source)
- Potential Persistence via Time Provider Modification production (source)
- Potential Port Monitor or Print Processor Registration Abuse production (source)
- Potential Privilege Escalation via Service ImagePath Modification production (source)
- Potential REMCOS Trojan Execution production (source)
- Potential Remote Desktop Shadowing Activity production (source)
- Potential RemoteMonologue Attack production (source)
- Potential SharpRDP Behavior production (source)
- PowerShell Script Block Logging Disabled production (source)
- Privilege Escalation via Windir Environment Variable production (source)
- RDP Enabled via Registry production (source)
- Registry Persistence via AppCert DLL production (source)
- Registry Persistence via AppInit DLL production (source)
- Remote Scheduled Task Creation production (source)
- Scheduled Task Created by a Windows Script production (source)
- Scheduled Tasks AT Command Enabled production (source)
- Service Disabled via Registry Modification production (source)
- Service Path Modification production (source)
- SIP Provider Modification production (source)
- SolarWinds Process Disabling Services via Registry production (source)
- Startup or Run Key Registry Modification production (source)
- Suspicious ImagePath Service Creation production (source)
- Suspicious Print Spooler Point and Print DLL production (source)
- Suspicious Startup Shell Folder Modification production (source)
- Uncommon Registry Persistence Change production (source)
- Unusual Persistence via Services Registry production (source)
- Werfault ReflectDebugger Persistence production (source)
- Windows Defender Disabled via Registry Modification production (source)
- Windows Installer with Suspicious Properties production (source)
- Windows Subsystem for Linux Distribution Installed production (source)
Event ID 13 RegistryEvent (Value Set) 60 rules
- Code Signing Policy Modification Through Registry production (source)
- Component Object Model Hijacking production (source)
- Creation of a Hidden Local User Account production (source)
- Creation or Modification of Root Certificate production (source)
- Deprecated - Encoded Executable Stored in the Registry production (source)
- Disabling Lsa Protection via Registry Modification production (source)
- Disabling User Account Control via Registry Modification production (source)
- DNS Global Query Block List Modified or Disabled production (source)
- DNS-over-HTTPS Enabled via Registry production (source)
- First Time Seen Removable Device production (source)
- Full User-Mode Dumps Enabled System-Wide production (source)
- Image File Execution Options Injection production (source)
- Installation of Custom Shim Databases production (source)
- Installation of Security Support Provider production (source)
- Local Account TokenFilter Policy Disabled production (source)
- Microsoft Windows Defender Tampering production (source)
- Modification of AmsiEnable Registry Key production (source)
- Modification of WDigest Security Provider production (source)
- MS Office Macro Security Registry Modifications production (source)
- Netsh Helper DLL production (source)
- Network Logon Provider Registry Modification production (source)
- Network-Level Authentication (NLA) Disabled production (source)
- NullSessionPipe Registry Modification production (source)
- Office Test Registry Persistence production (source)
- Outlook Home Page Registry Modification production (source)
- Persistence via a Windows Installer production (source)
- Persistence via Hidden Run Key Detected production (source)
- Persistence via WMI Standard Registry Provider production (source)
- Port Forwarding Rule Addition production (source)
- Potential LSA Authentication Package Abuse production (source)
- Potential NetNTLMv1 Downgrade Attack production (source)
- Potential Persistence via Time Provider Modification production (source)
- Potential Port Monitor or Print Processor Registration Abuse production (source)
- Potential Privilege Escalation via Service ImagePath Modification production (source)
- Potential REMCOS Trojan Execution production (source)
- Potential Remote Desktop Shadowing Activity production (source)
- Potential RemoteMonologue Attack production (source)
- Potential SharpRDP Behavior production (source)
- PowerShell Script Block Logging Disabled production (source)
- Privilege Escalation via Windir Environment Variable production (source)
- RDP Enabled via Registry production (source)
- Registry Persistence via AppCert DLL production (source)
- Registry Persistence via AppInit DLL production (source)
- Remote Scheduled Task Creation production (source)
- Scheduled Task Created by a Windows Script production (source)
- Scheduled Tasks AT Command Enabled production (source)
- Service Disabled via Registry Modification production (source)
- Service Path Modification production (source)
- SIP Provider Modification production (source)
- SolarWinds Process Disabling Services via Registry production (source)
- Startup or Run Key Registry Modification production (source)
- Suspicious ImagePath Service Creation production (source)
- Suspicious Print Spooler Point and Print DLL production (source)
- Suspicious Startup Shell Folder Modification production (source)
- Uncommon Registry Persistence Change production (source)
- Unusual Persistence via Services Registry production (source)
- Werfault ReflectDebugger Persistence production (source)
- Windows Defender Disabled via Registry Modification production (source)
- Windows Installer with Suspicious Properties production (source)
- Windows Subsystem for Linux Distribution Installed production (source)
Event ID 14 RegistryEvent (Key and Value Rename) 60 rules
- Code Signing Policy Modification Through Registry production (source)
- Component Object Model Hijacking production (source)
- Creation of a Hidden Local User Account production (source)
- Creation or Modification of Root Certificate production (source)
- Deprecated - Encoded Executable Stored in the Registry production (source)
- Disabling Lsa Protection via Registry Modification production (source)
- Disabling User Account Control via Registry Modification production (source)
- DNS Global Query Block List Modified or Disabled production (source)
- DNS-over-HTTPS Enabled via Registry production (source)
- First Time Seen Removable Device production (source)
- Full User-Mode Dumps Enabled System-Wide production (source)
- Image File Execution Options Injection production (source)
- Installation of Custom Shim Databases production (source)
- Installation of Security Support Provider production (source)
- Local Account TokenFilter Policy Disabled production (source)
- Microsoft Windows Defender Tampering production (source)
- Modification of AmsiEnable Registry Key production (source)
- Modification of WDigest Security Provider production (source)
- MS Office Macro Security Registry Modifications production (source)
- Netsh Helper DLL production (source)
- Network Logon Provider Registry Modification production (source)
- Network-Level Authentication (NLA) Disabled production (source)
- NullSessionPipe Registry Modification production (source)
- Office Test Registry Persistence production (source)
- Outlook Home Page Registry Modification production (source)
- Persistence via a Windows Installer production (source)
- Persistence via Hidden Run Key Detected production (source)
- Persistence via WMI Standard Registry Provider production (source)
- Port Forwarding Rule Addition production (source)
- Potential LSA Authentication Package Abuse production (source)
- Potential NetNTLMv1 Downgrade Attack production (source)
- Potential Persistence via Time Provider Modification production (source)
- Potential Port Monitor or Print Processor Registration Abuse production (source)
- Potential Privilege Escalation via Service ImagePath Modification production (source)
- Potential REMCOS Trojan Execution production (source)
- Potential Remote Desktop Shadowing Activity production (source)
- Potential RemoteMonologue Attack production (source)
- Potential SharpRDP Behavior production (source)
- PowerShell Script Block Logging Disabled production (source)
- Privilege Escalation via Windir Environment Variable production (source)
- RDP Enabled via Registry production (source)
- Registry Persistence via AppCert DLL production (source)
- Registry Persistence via AppInit DLL production (source)
- Remote Scheduled Task Creation production (source)
- Scheduled Task Created by a Windows Script production (source)
- Scheduled Tasks AT Command Enabled production (source)
- Service Disabled via Registry Modification production (source)
- Service Path Modification production (source)
- SIP Provider Modification production (source)
- SolarWinds Process Disabling Services via Registry production (source)
- Startup or Run Key Registry Modification production (source)
- Suspicious ImagePath Service Creation production (source)
- Suspicious Print Spooler Point and Print DLL production (source)
- Suspicious Startup Shell Folder Modification production (source)
- Uncommon Registry Persistence Change production (source)
- Unusual Persistence via Services Registry production (source)
- Werfault ReflectDebugger Persistence production (source)
- Windows Defender Disabled via Registry Modification production (source)
- Windows Installer with Suspicious Properties production (source)
- Windows Subsystem for Linux Distribution Installed production (source)
Event ID 22 DNSEvent (DNS query) 3 rules
- External IP Lookup from Non-Browser Process production (source)
- First Time Seen DNS Query to RMM Domain production (source)
- MsBuild Making Network Connections production (source)
Event ID 23 FileDelete (File Delete archived) 5 rules
- Potential REMCOS Trojan Execution production (source)
- Potential System Tampering via File Modification production (source)
- Suspicious Print Spooler File Deletion production (source)
- Third-party Backup Files Deleted via Unexpected Process production (source)
- Unusual File Operation by dns.exe production (source)
Event ID 26 FileDeleteDetected (File Delete logged) 5 rules
- Potential REMCOS Trojan Execution production (source)
- Potential System Tampering via File Modification production (source)
- Suspicious Print Spooler File Deletion production (source)
- Third-party Backup Files Deleted via Unexpected Process production (source)
- Unusual File Operation by dns.exe production (source)
Microsoft-Windows-Eventlog
Event ID 104 The LogFileCleared.Channel log file was cleared. 1 rule
- Windows Event Logs Cleared production (source)
Event ID 1102 The audit log was cleared. 1 rule
- Windows Event Logs Cleared production (source)
Microsoft-Windows-PowerShell
Event ID 4104 Creating Scriptblock text (MessageNumber of MessageTotal). 13 rules
- Dynamic IEX Reconstruction via Method String Access production (source)
- Potential Dynamic IEX Reconstruction via Environment Variables production (source)
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion production (source)
- Potential PowerShell Obfuscation via Character Array Reconstruction production (source)
- Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation production (source)
- Potential PowerShell Obfuscation via High Numeric Character Proportion production (source)
- Potential PowerShell Obfuscation via High Special Character Proportion production (source)
- Potential PowerShell Obfuscation via Invalid Escape Sequences production (source)
- Potential PowerShell Obfuscation via Reverse Keywords production (source)
- Potential PowerShell Obfuscation via Special Character Overuse production (source)
- Potential PowerShell Obfuscation via String Concatenation production (source)
- Potential PowerShell Obfuscation via String Reordering production (source)
- PowerShell Obfuscation via Negative Index String Reversal production (source)