14 detection rules reference this event. View event page.Kusto (14)
- Detect .NET runtime being loaded in JScript for code execution severity medium T1204
- DLL Hijacking - HijackLibs
- DLL Hijacking: Loading from an Unusual Directory T1574, T1574.001, T1574.007, T1574.008, T1574.009
- Europium - Hash and IP IOCs - September 2022 severity high T1003, T1071
- Hijack Execution Flow - DLL Side-Loading severity medium T1574, T1574.001
- Mercury - Domain, Hash and IP IOCs - August 2022 severity high T1071
- Potential Lateral Movement via MSI ODBC Driver Install over DCOM
- PowerShell without powershell.exe T1059, T1059.001
- Prestige ransomware IOCs Oct 2022 severity high T1203
- Rare Process as a Service severity medium T1543, T1543.003
- Regsvr32 Rundll32 Image Loads Abnormal Extension severity high T1218, T1218.010, T1218.011
- SUNSPOT malware hashes severity medium T1554
- Suspicious use of CPL file T1218, T1218.002
- WinRM Plugin Lateral Movement T1021, T1021.006