65 detection rules reference this event. View event page.Kusto (65)
- [Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022 severity high T1546
- Access Token Manipulation - Create Process with Token severity medium T1134, T1134.002
- Account Creation severity medium T1136
- Audit policy manipulation using auditpol utility severity medium T1204
- Bitsadmin Activity severity medium T1048, T1105, T1197
- CertUtil Used for File Download (Living off the Land) severity high T1105, T1140, T1218
- Clearing of forensic evidence from event logs using wevtutil severity high T1070
- DCOM Lateral Movement severity medium T1021, T1021.003
- Deletion of data on multiple drives using cipher exe severity medium T1485
- Detect Msiexec executing DLL network connections T1218, T1218.007
- Detect Rare scheduled task created T1053, T1053.005
- Detect Suspicious Commands Initiated by Webserver Processes severity high T1059, T1082, T1087, T1574
- Detect Unknown process launched via WinRM T1021, T1021.006
- Detect Unsigned executable launch from scheduled task T1053, T1053.005
- Detecting UAC bypass - ChangePK and SLUI registry tampering severity medium T1490
- Detecting UAC bypass - elevated COM interface severity medium T1490
- Detecting UAC bypass - modify Windows Store settings severity medium T1490
- Dev-0228 File Path Hashes November 2021 severity high T1003, T1569
- Dev-0270 Malicious Powershell usage severity high T1048, T1685
- DEV-0270 New User Creation severity high T1098
- Dev-0270 Registry IOC - September 2022 severity high T1486
- Dev-0270 WMIC Discovery severity high T1482
- Disable or Modify Windows Defender severity medium T1685
- Disabling Security Services via Registry severity medium T1685
- Doppelpaymer Stop Services severity high T1059, T1685
- DopplePaymer Procdump severity high T1003
- Email access via active sync severity medium T1068, T1078
- Exchange Worker Process Making Remote Call severity medium T1059, T1059.001, T1059.003
- Execution of software vulnerable to webp buffer overflow of CVE-2023-4863 severity informational T1203
- Identify Mango Sandstorm powershell commands severity high T1570
- Ingress Tool Transfer - Certutil severity low T1027, T1105, T1140, T1564, T1564.004
- Java Executing cmd to run Powershell severity high T1059
- LaZagne Credential Theft severity medium T1003
- LSASS Credential Dumping with Procdump severity high T1003
- Match Legitimate Name or Location - 2 severity medium T1036, T1036.005
- Office Apps Launching Wscipt severity medium T1059, T1105, T1203
- Oracle suspicious command execution severity medium T1210, T1611
- Potential Build Process Compromise - MDE severity medium T1554
- Potential Kerberos Relaying Activity - MDE
- Potential Lateral Movement via MSI ODBC Driver Install over DCOM
- PowerShell Encoded Command Execution (Living off the Land) severity medium T1027, T1059, T1059.001
- Probable AdFind Recon Tool Usage severity high T1016, T1018, T1069, T1069.002, T1087, T1087.002
- Process Tree Analysis
- PRT Credential Stealing T1003, T1134, T1134.001, T1555
- Qakbot Campaign Self Deletion severity medium T1070
- Qakbot Discovery Activies severity medium T1010, T1059, T1140
- Rare Process as a Service severity medium T1543, T1543.003
- Regsvr32 Rundll32 with Anomalous Parent Process severity high T1218, T1218.010, T1218.011
- Remote Desktop Protocol - SharpRDP severity medium T1021, T1021.001
- Rename System Utilities severity medium T1036, T1036.003
- Scheduled Task - Suspicious Network Connection
- Security Service Registry ACL Modification severity high T1685
- Shadow Copy Deletions severity medium T1490
- ShieldBreak: Defender AV Privilege Escalation
- SMB/Windows Admin Shares severity medium T1021, T1021.002
- Spearphishing Attachment: ISO Images (Microsoft Defender for Endpoint)
- SQL Server spawning suspicious child process T1505, T1505.001, T1611
- Stopping multiple processes using taskkill severity medium T1685
- SUNBURST suspicious SolarWinds child processes severity medium
- Suspicious parentprocess relationship - Office child processes. severity medium T1566, T1566.002
- Trusted Developer Utilities Proxy Execution severity medium T1127
- Unsigned Windows System Binary T1036, T1036.001, T1036.005
- Unusual identity creation using exchange powershell severity high T1136
- WMI Spawning Suspicious Child Process (Living off the Land) severity high T1021, T1021.006, T1047, T1059, T1059.001, T1059.003
- Zinc Actor IOCs files - October 2022 severity high T1546