1897 detection rules reference this event. View event page.Sigma (735)
- Abusing Print Executable severity medium T1218
- Adwind RAT / JRAT severity high T1059, T1059.005, T1059.007
- Anonymous login (RottenPotatoNG) severity high T1134, T1134.001
- APT27 - Emissary Panda Activity severity critical T1574, T1574.001
- APT29 2018 Phishing Campaign CommandLine Indicators severity critical T1218, T1218.011
- APT31 Judgement Panda Activity severity critical T1003, T1003.001, T1560, T1560.001
- Arbitrary Binary Execution Using GUP Utility severity medium
- Arbitrary File Download Via GfxDownloadWrapper.EXE severity medium T1105
- Arbitrary File Download Via Squirrel.EXE severity medium T1218
- Arbitrary MSI Download Via Devinit.EXE severity medium T1218
- Arbitrary Shell Command Execution Via Settingcontent-Ms severity medium T1204, T1566, T1566.001
- AspNetCompiler Execution severity medium T1127
- Assembly Loading Via CL_LoadAssembly.ps1 severity medium T1216
- Attempts of Kerberos Coercion Via DNS SPN Spoofing severity high T1187, T1557, T1557.001
- Audio Capture via PowerShell severity medium T1123
- Audio Capture via SoundRecorder severity medium T1123
- Audit policy disabled by command line severity high T1685, T1685.001
- Audit policy enumerated severity high T1082
- Audit Policy Tampering Via NT Resource Kit Auditpol severity high T1685, T1685.001
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl severity medium T1216
- Base64 Encoded PowerShell Command Detected severity high T1027, T1059, T1059.001, T1140
- Base64 MZ Header In CommandLine severity high
- BitLocker feature configuration (Reg via command) severity high T1486
- BitLockerTogo.EXE Execution severity low T1218
- BITS payload downloaded via commandline severity medium T1048, T1105, T1197, T1570
- Blue Mockingbird severity high T1047, T1112
- Browser Execution In Headless Mode severity low T1105, T1564, T1564.003
- Browser Started with Remote Debugging severity medium T1185
- Bypass UAC via Fodhelper.exe severity high T1548, T1548.002
- Cab File Extraction Via Wusa.EXE severity medium
- Cab File Extraction Via Wusa.EXE From Potentially Suspicious Paths severity high
- Certificate Exported Via PowerShell severity medium T1059, T1059.001, T1552, T1552.004
- Certutil payload download (command) severity high T1105
- Certutil payload obfuscation (command) severity high T1140
- Certutil payload obfuscation - Tchopper (command) severity high T1140
- Certutil root certificate installation severity high T1553, T1553.004
- Changing Existing Service ImagePath Value Via Reg.EXE severity medium T1574, T1574.011
- Chopper Webshell Process Pattern severity high T1018, T1033, T1087, T1505, T1505.003
- Chromium Browser Headless Execution To Mockbin Like Site severity high
- Chromium Browser Instance Executed With Custom Extension severity medium T1176, T1176.001
- ClickOnce Deployment Execution - Dfsvc.EXE Child Process severity medium
- Cloudflared Portable Execution severity medium T1090, T1090.001
- Cloudflared Tunnel Connections Cleanup severity medium T1090, T1102, T1572
- Cloudflared Tunnel Execution severity medium T1090, T1102, T1572
- Cmd.EXE Missing Space Characters Execution Anomaly severity high T1059, T1059.001
- CMSTP Execution Process Creation severity high T1218, T1218.003
- COLDSTEEL RAT Anonymous User Process Execution severity high
- COLDSTEEL RAT Service Persistence Execution severity critical
- COM Object Execution via Xwizard.EXE severity medium T1218
- Command Line Execution with Suspicious URL and AppData Strings severity medium T1059, T1059.001, T1059.003, T1105
- Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791) severity high T1190
- Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788) severity medium T1078, T1078.001
- Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790) severity high T1505, T1505.003
- Compress Data and Lock With Password for Exfiltration With WINZIP severity medium T1560, T1560.001
- Conti NTDS Exfiltration Command severity high T1560
- Conti Volume Shadow Listing severity high T1587, T1587.001
- Copy From VolumeShadowCopy Via Cmd.EXE severity high T1490
- Cscript/Wscript Potentially Suspicious Child Process severity medium
- Curl Download And Execute Combination severity high T1105, T1218
- DarkGate - User Created Via Net.EXE severity high T1136, T1136.001
- Defrag Deactivation severity medium T1053, T1053.005
- Delete All Scheduled Tasks severity high T1489
- Deletion of Volume Shadow Copies via WMI with PowerShell severity high T1490
- Detected Windows Software Discovery severity medium T1518
- DeviceCredentialDeployment Execution severity medium T1218
- Devtoolslauncher.exe Executes Specified Binary severity high T1218
- Diamond Sleet APT Process Activity Indicators severity high
- Disabled guest or builtin account activated (command) severity high T1098
- Disabled IE Security Features severity high T1685
- Disabled Volume Snapshots severity high T1685
- Discovery of a System Time severity low T1124
- Diskshadow Child Process Spawned severity medium T1218
- Diskshadow command abuse to expose VSS backup severity high T1003
- DLL Execution Via Register-cimprovider.exe severity medium T1574
- DLL ServerLevelPluginDll command installation severity critical T1574, T1574.001
- DLL Sideloading by VMware Xfer Utility severity high T1574, T1574.001
- Dllhost.EXE Execution Anomaly severity high T1055
- DNS Exfiltration and Tunneling Tools Execution severity high T1048, T1048.001, T1071, T1071.004, T1132, T1132.001
- DNS RCE CVE-2020-1350 severity critical T1190, T1569, T1569.002
- DoT (DNS over TLS) activation (command) severity medium T1071, T1071.004
- Droppers Exploiting CVE-2017-11882 severity critical T1203, T1204, T1204.002, T1566, T1566.001
- Dropping Of Password Filter DLL severity medium T1556, T1556.002
- DSInternals Suspicious PowerShell Cmdlets severity high T1059, T1059.001
- DSRM password changed (Reg via command) severity high T1098
- Dumping Process via Sqldumper.exe severity medium T1003, T1003.001
- DumpStack.log Defender Evasion severity critical
- Dynamic .NET Compilation Via Csc.EXE - Hunting severity medium T1027, T1027.004
- EAP service activation by Liontail framework for DLL sideloading (via command) severity medium T1543, T1543.003
- Edge abuse for payload download via console severity high T1204
- Edge/Chrome headless feature abuse for payload download severity high T1204
- Elise Backdoor Activity severity critical T1059, T1059.003
- Email Exifiltration Via Powershell severity high
- Emotet Loader Execution Via .LNK File severity high T1059, T1059.006
- Enable LM Hash Storage - ProcCreation severity high T1112
- Encoded PowerShell payload deployed via process execution severity high T1027, T1059, T1059.003
- Enumeration for 3rd Party Creds From CLI severity medium T1552, T1552.002
- Enumeration for Credentials in Registry severity medium T1552, T1552.002
- Equation Group DLL_U Export Function Load severity critical T1218, T1218.011
- Esentutl Gather Credentials severity medium T1003, T1003.003
- ETW Logging Tamper In .NET Processes Via CommandLine severity high T1685
- ETW Trace Evasion Activity severity high T1070, T1685
- Event log clear attempt (command) severity high T1070, T1685.005
- Event log clear attempt (wmi) severity high T1070, T1685.005
- Event log deactivation or size reduction (command) severity high T1685, T1685.001
- EvilNum APT Golden Chickens Deployment Via OCX Files severity critical T1218, T1218.011
- Execute Code with Pester.bat severity medium T1059, T1059.001, T1216
- Execute Files with Msdeploy.exe severity medium T1218
- Execute From Alternate Data Streams severity medium T1564, T1564.004
- Execute Pcwrun.EXE To Leverage Follina severity high T1218
- Execution From Webserver Root Folder severity medium T1505, T1505.003
- Execution Of Non-Existing File severity high T1055
- Execution of Powershell Script in Public Folder severity high T1059, T1059.001
- Execution of Suspicious File Type Extension severity medium
- Execution via stordiag.exe severity high T1218
- Execution via WorkFolders.exe severity high T1218
- Exploit for CVE-2015-1641 severity critical T1036, T1036.005
- Exploit for CVE-2017-0261 severity medium T1203, T1204, T1204.002, T1566, T1566.001
- Exploit for CVE-2017-8759 severity critical T1203, T1204, T1204.002, T1566, T1566.001
- Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC severity high T1210
- Exploited CVE-2020-10189 Zoho ManageEngine severity high T1059, T1059.001, T1059.003, T1190
- Exploiting CVE-2019-1388 severity critical T1068
- Explorer Process Tree Break severity medium T1036
- File Download From Browser Process Via Inline URL severity medium T1105
- File Download with Headless Browser severity high T1105, T1564, T1564.003
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell severity high T1135
- File or Folder Permissions Modifications severity medium T1222, T1222.001
- Files Added To An Archive Using Rar.EXE severity low T1560, T1560.001
- Fireball Archer Install severity high T1218, T1218.011
- Firewall configuration enumerated (command) severity high T1016
- Firewall deactivation (deprecated command) severity high T1685, T1686
- Firewall deactivation (modern command) severity high T1685, T1686
- Firewall rule creation (command) severity medium T1685, T1686
- Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet severity medium T1074, T1074.001
- Gpresult Display Group Policy Information severity medium T1615
- Greenbug Espionage Group Indicators severity critical T1036, T1036.005, T1059, T1059.001, T1105
- Griffon Malware Attack Pattern severity critical
- Grixba Malware Reconnaissance Activity severity high T1046, T1595, T1595.001
- Group discovery (command) severity medium T1069, T1069.001, T1069.002, T1087, T1087.002
- Gzip Archive Decode Via PowerShell severity medium T1132, T1132.001
- HackTool - ADCSPwn Execution severity high T1557, T1557.001
- HackTool - Covenant PowerShell Launcher severity high T1059, T1059.001, T1564, T1564.003
- HackTool - CrackMapExec Execution severity high T1047, T1053, T1059, T1059.001, T1059.003, T1110
- HackTool - CrackMapExec Execution Patterns severity high T1047, T1053, T1059, T1059.001, T1059.003
- HackTool - CrackMapExec Process Patterns severity high T1003, T1003.001
- HackTool - Default PowerSploit/Empire Scheduled Task Creation severity high T1053, T1053.005, T1059, T1059.001
- HackTool - DInjector PowerShell Cradle Execution severity critical T1055
- HackTool - Empire PowerShell Launch Parameters severity high T1059, T1059.001
- HackTool - Empire PowerShell UAC Bypass severity critical T1548, T1548.002
- HackTool - F-Secure C3 Load by Rundll32 severity critical T1218, T1218.011
- HackTool - Hashcat Password Cracker Execution severity high T1110, T1110.002
- HackTool - HollowReaper Execution severity high T1055, T1055.012
- HackTool - Htran/NATBypass Execution severity high T1090
- HackTool - Hydra Password Bruteforce Execution severity high T1110, T1110.001
- HackTool - Impacket Tools Execution severity high T1557, T1557.001
- HackTool - LaZagne Execution severity medium
- HackTool - Mimikatz Execution severity high T1003, T1003.001, T1003.002, T1003.004, T1003.005, T1003.006
- HackTool - NetExec Execution severity high T1018, T1021
- HackTool - Pypykatz Credentials Dumping Activity severity high T1003, T1003.002
- HackTool - Quarks PwDump Execution severity high T1003, T1003.002
- HackTool - RedMimicry Winnti Playbook Execution severity high T1059, T1059.003, T1106, T1218, T1218.011
- HackTool - SharpWSUS/WSUSpendu Execution severity high T1210
- HackTool - Sliver C2 Implant Activity Pattern severity critical T1059
- HackTool - SOAPHound Execution severity high T1087
- HackTool - WinPwn Execution severity high T1046, T1082, T1106, T1518, T1548, T1548.002
- HackTool - WinRM Access Via Evil-WinRM severity medium T1021, T1021.006
- HackTool - Wmiexec Default Powershell Command severity high
- HackTool - XORDump Execution severity high T1003, T1003.001, T1036
- HAFNIUM Exchange Exploitation Activity severity critical T1053, T1546
- Hermetic Wiper TG Process Patterns severity high T1021, T1021.001
- Hidden Powershell in Link File Pattern severity medium T1059, T1059.001
- Hiding User Account Via SpecialAccounts Registry Key - CommandLine severity medium T1564, T1564.002
- HTML File Opened From Download Folder severity low T1566, T1566.001, T1598, T1598.002
- HTML Help HH.EXE Suspicious Child Process severity high T1047, T1059, T1059.001, T1059.003, T1059.005, T1059.007
- IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32 severity high T1218, T1218.011
- IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI severity high
- IFM creation detected from commandline (installation from media) severity high T1003, T1003.003
- ImagingDevices Unusual Parent/Child Processes severity high
- Impacket DCOMexec process abuse via MMC severity high T1021, T1021.003
- Import PowerShell Modules From Suspicious Directories - ProcCreation severity medium T1059, T1059.001
- Indirect Command Execution By Program Compatibility Wizard severity low T1218
- Indirect Command Execution via SFTP ProxyCommand severity medium T1202
- InfDefaultInstall.exe .inf Execution severity medium T1218
- Injected Browser Process Spawning Rundll32 - GuLoader Activity severity high T1055
- Interactive AT Job severity high T1053, T1053.002
- Interactive privileged shell triggered by schedule task (deprecated) severity high T1053, T1053.005
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) severity medium T1003, T1003.003
- Invoke-Obfuscation CLIP+ Launcher severity high T1027, T1059, T1059.001
- Invoke-Obfuscation COMPRESS OBFUSCATION severity medium T1027, T1059, T1059.001
- Invoke-Obfuscation Obfuscated IEX Invocation severity high T1027, T1059, T1059.001
- Invoke-Obfuscation STDIN+ Launcher severity high T1027, T1059, T1059.001
- Invoke-Obfuscation VAR+ Launcher severity high T1027, T1059, T1059.001
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION severity high T1027, T1059, T1059.001
- Invoke-Obfuscation Via Stdin severity high T1027, T1059, T1059.001
- Invoke-Obfuscation Via Use Clip severity high T1027, T1059, T1059.001
- Invoke-Obfuscation Via Use MSHTA severity high T1027, T1059, T1059.001
- Java Running with Remote Debugging severity medium T1203
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution severity high T1059, T1059.001, T1071, T1071.001, T1090, T1573
- Kavremover Dropped Binary LOLBIN Usage severity high T1127
- Lace Tempest Cobalt Strike Download severity high
- Lateral movement by mounting a network share - net use (command) severity medium T1021, T1021.002
- Launch-VsDevShell.PS1 Proxy Execution severity medium T1216, T1216.001
- Lazarus Group Activity severity critical T1059
- Lazarus System Binary Masquerading severity high T1036, T1036.005
- LockerGoga Ransomware Activity severity critical T1486
- Lolbin Runexehelper Use As Proxy severity medium T1218
- LSASS Dump Keyword In CommandLine severity high T1003, T1003.001
- Malicious PE Execution by Microsoft Visual Studio Debugger severity medium T1218
- Malicious PowerShell Commandlets - ProcessCreation severity high T1059, T1059.001, T1069, T1069.001, T1069.002, T1087
- Manual Execution of Script Inside of a Compressed File severity medium T1059
- Massive processes termination burst severity high T1489
- Massive services deletion burst severity high T1489
- Massive services termination burst severity high T1489
- Mavinject Inject DLL Into Running Process severity high T1055, T1055.001, T1218, T1218.013
- MERCURY APT Activity severity high T1059, T1059.001
- Metasploit reverse shell injection in SQL Server severity high T1059, T1059.003
- Microsoft Defender critical security components disabled (command) severity high T1685
- Microsoft Defender default action changed to allow any threat (command) severity high T1685
- Microsoft Defender security components disabled (command) severity medium T1685
- Microsoft Defender service deactivation attempt (command) severity high T1685
- Mint Sandstorm - AsperaFaspex Suspicious Process Execution severity critical
- Mint Sandstorm - Log4J Wstomcat Process Execution severity high
- Mint Sandstorm - ManageEngine Suspicious Process Execution severity critical
- MMC Spawning Windows Shell severity high T1021, T1021.003
- MMC20 Lateral Movement severity high T1021, T1021.003
- MSDT Execution Via Answer File severity high T1218
- MSExchange Transport Agent Installation severity medium T1505, T1505.002
- Mshtml.DLL RunHTMLApplication Suspicious Usage severity high
- MsiExec Web Install severity medium T1105, T1218, T1218.007
- Msxsl.EXE Execution severity medium T1220
- Mustang Panda Dropper severity high T1587, T1587.001
- Netsh helper DLL abuse (process) severity high T1546, T1546.007
- Network Reconnaissance Activity severity high T1082, T1087
- Network share discovery and/or connection via commandline severity high T1135
- Network share manipulation via commandline severity high T1021, T1021.002
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE severity high T1112, T1574, T1574.001
- New Kernel Driver Via SC.EXE severity medium T1543, T1543.003
- New Process Created Via Taskmgr.EXE severity low T1036
- New Service Creation Using PowerShell severity low T1543, T1543.003
- New Service Creation Using Sc.EXE severity low T1543, T1543.003
- Node Process Executions severity medium T1059, T1059.007, T1127
- Non-privileged Usage of Reg or Powershell severity high T1112
- Notepad Password Files Discovery severity low T1083
- NotPetya Ransomware Activity severity critical T1003, T1003.001, T1218, T1218.011, T1685, T1685.005
- NtdllPipe Like Activity Execution severity high
- NTFS symbolic link configuration change severity medium T1547, T1547.009
- NTFS symbolic link creation severity medium T1547, T1547.009
- Number of oustanding SMB requests increased severity medium T1021, T1021.002
- Obfuscated IP Download Activity severity medium
- Obfuscated IP Via CLI severity medium
- Obfuscated payload transfered via service name - Tchopper (command) severity high T1027
- Obfuscated PowerShell OneLiner Execution severity high T1059, T1059.001, T1685
- OilRig APT Activity severity critical T1053, T1053.005, T1071, T1071.004, T1112, T1543
- OneNote.EXE Execution of Malicious Embedded Scripts severity high T1218, T1218.001
- OpenEDR Spawning Command Shell severity medium T1021, T1021.004, T1059, T1059.003, T1219
- OpenSSH server firewall configuration on Windows (command) severity high T1685, T1686
- OpenWith.exe Executes Specified Binary severity high T1218
- Operation Wocao Activity severity high T1012, T1027, T1036, T1036.004, T1053, T1053.005
- Outlook EnableUnsafeClientMailRules Setting Enabled severity high T1059, T1202
- PaperCut MF/NG Exploitation Related Indicators severity high
- PaperCut MF/NG Potential Exploitation severity high
- Password policy discovery via commandline severity high T1201
- Peach Sandstorm APT Process Activity Indicators severity high
- Persistence Via Sticky Key Backdoor severity critical T1546, T1546.008
- Persistence Via TypedPaths - CommandLine severity medium
- Phishing Pattern ISO in Archive severity high T1566
- Pikabot Fake DLL Extension Execution Via Rundll32.EXE severity high
- Ping Hex IP severity high T1027, T1140
- Pingback Backdoor Activity severity high T1574, T1574.001
- Port Forwarding Activity Via SSH.EXE severity medium T1021, T1021.001, T1021.004, T1572
- Possible Privilege Escalation via Weak Service Permissions severity high T1574, T1574.011
- Potential ACTINIUM Persistence Activity severity high T1053, T1053.005
- Potential Amazon SSM Agent Hijacking severity medium T1219, T1219.002
- Potential AMSI Bypass Using NULL Bits severity medium T1685
- Potential AMSI Bypass Via .NET Reflection severity high T1685
- Potential Application Whitelisting Bypass via Dnx.EXE severity medium T1027, T1027.004, T1218
- Potential APT FIN7 Exploitation Activity severity medium T1059, T1059.001, T1059.003
- Potential APT FIN7 Reconnaissance/POWERTRASH Related Activity severity high
- Potential APT Mustang Panda Activity Against Australian Gov severity high
- Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32 severity medium T1218, T1218.010
- Potential APT10 Cloud Hopper Activity severity high T1059, T1059.005
- Potential Arbitrary Code Execution Via Node.EXE severity high T1127
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt severity high T1059, T1190
- Potential Baby Shark Malware Activity severity high T1012, T1059, T1059.001, T1059.003, T1218, T1218.005
- Potential BlackByte Ransomware Activity severity high T1059, T1059.001, T1140, T1485, T1498
- Potential COM Objects Download Cradles Usage - Process Creation severity medium T1105
- Potential Command Line Path Traversal Evasion Attempt severity medium T1036
- Potential Commandline Obfuscation Using Escape Characters severity medium T1140
- Potential CommandLine Obfuscation Using Unicode Characters severity medium T1027
- Potential Compromised 3CXDesktopApp Update Activity severity high T1218
- Potential Conti Ransomware Activity severity critical T1486
- Potential Conti Ransomware Database Dumping Activity Via SQLCmd severity high T1005
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI severity high T1003
- Potential Credential Dumping Via LSASS Process Clone severity critical T1003, T1003.001
- Potential Crypto Mining Activity severity high T1496
- Potential CVE-2021-26857 Exploitation Attempt severity high T1203
- Potential CVE-2021-40444 Exploitation Attempt severity high T1059
- Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon severity high T1190
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution severity medium T1059, T1059.006, T1190
- Potential CVE-2023-21554 QueueJumper Exploitation severity high
- Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI severity high T1187
- Potential Data Exfiltration Activity Via CommandLine Tools severity high T1059, T1059.001
- Potential Data Stealing Via Chromium Headless Debugging severity high T1185, T1564, T1564.003
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1 severity high
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2 severity high
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3 severity high
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4 severity high
- Potential Defense Evasion Via Right-to-Left Override severity high T1036, T1036.002
- Potential Devil Bait Malware Reconnaissance severity high T1218
- Potential Discovery Activity Via Dnscmd.EXE severity medium
- Potential DLL File Download Via PowerShell Invoke-WebRequest severity medium T1059, T1059.001, T1105
- Potential Dosfuscation Activity severity medium T1059
- Potential Download/Upload Activity Using Type Command severity medium T1105
- Potential Dridex Activity severity critical T1033, T1055, T1135
- Potential Dropper Script Execution Via WScript/CScript/MSHTA severity medium T1059, T1059.005, T1059.007
- Potential Dtrack RAT Activity severity critical T1490
- Potential Emotet Activity severity high T1027, T1059, T1059.001
- Potential EmpireMonkey Activity severity high T1218, T1218.010
- Potential Execution of Sysinternals Tools severity low T1588, T1588.002
- Potential Exploitation Attempt From Office Application severity high
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) severity high T1059, T1059.001, T1059.003, T1068, T1190
- Potential Exploitation of GoAnywhere MFT Vulnerability severity high T1059, T1059.001, T1133, T1190
- Potential Fake Instance Of Hxtsr.EXE Executed severity medium T1036
- Potential File Download Via MS-AppInstaller Protocol Handler severity medium T1218
- Potential Goofy Guineapig Backdoor Activity severity high
- Potential Goofy Guineapig GoolgeUpdate Process Anomaly severity high
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI severity medium T1564, T1564.004
- Potential Homoglyph Attack Using Lookalike Characters severity medium T1036, T1036.003
- Potential KamiKakaBot Activity - Lure Document Execution severity medium T1059
- Potential KamiKakaBot Activity - Shutdown Schedule Task Creation severity medium
- Potential Ke3chang/TidePool Malware Activity severity high T1685
- Potential Lateral Movement via Windows Remote Shell severity medium T1021, T1021.006
- Potential LethalHTA Technique Execution severity high T1218, T1218.005
- Potential LSASS Process Dump Via Procdump severity high T1003, T1003.001, T1036
- Potential Maze Ransomware Activity severity critical T1047, T1204, T1204.002, T1490
- Potential Meterpreter/CobaltStrike Activity severity high T1134, T1134.001, T1134.002
- Potential Mftrace.EXE Abuse severity medium T1127
- Potential Mpclient.DLL Sideloading Via Defender Binaries severity high T1574, T1574.001
- Potential MSTSC Shadowing Activity severity high T1563, T1563.002
- Potential MuddyWater APT Activity severity high
- Potential Network Sniffing Activity Using Network Tools severity medium T1040
- Potential Notepad++ CVE-2025-49144 Exploitation severity high T1574, T1574.008
- Potential Persistence Attempt Via Existing Service Tampering severity medium T1543, T1543.003, T1574, T1574.011
- Potential Persistence Attempt Via Run Keys Using Reg.EXE severity medium T1547, T1547.001
- Potential Persistence Via Logon Scripts - CommandLine severity high T1037, T1037.001
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE severity medium T1059, T1059.003, T1105, T1218
- Potential PlugX Activity severity high T1574, T1574.001
- Potential PowerShell Console History Access Attempt via History File severity medium T1552, T1552.001
- Potential PowerShell Downgrade Attack severity medium T1059, T1059.001
- Potential PowerShell Execution Policy Tampering - ProcCreation severity high
- Potential PowerShell Obfuscation Via WCHAR/CHAR severity high T1027, T1059, T1059.001
- Potential Privilege Escalation To LOCAL SYSTEM severity high T1587, T1587.001
- Potential Privilege Escalation via Service Permissions Weakness severity high T1574, T1574.011
- Potential Process Execution Proxy Via CL_Invocation.ps1 severity medium T1216
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution severity high T1218
- Potential Provlaunch.EXE Binary Proxy Execution Abuse severity medium T1218
- Potential Proxy Execution Via Explorer.EXE From Shell Process severity low T1218
- Potential PsExec Remote Execution severity high T1587, T1587.001
- Potential Qakbot Rundll32 Execution severity high
- Potential QBot Activity severity critical T1059, T1059.005
- Potential Raspberry Robin Dot Ending File severity high
- Potential RDP Tunneling Via Plink severity high T1572
- Potential RDP Tunneling Via SSH severity high T1572
- Potential Regsvr32 Commandline Flag Anomaly severity medium T1218, T1218.010
- Potential Remote Desktop Tunneling severity medium T1021
- Potential Renamed Rundll32 Execution severity high
- Potential Russian APT Credential Theft Activity severity critical T1003, T1003.003, T1552, T1552.001
- Potential Ryuk Ransomware Activity severity high T1547, T1547.001
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1 severity medium T1216
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators severity high T1190
- Potential SMB Relay Attack Tool Execution severity critical T1557, T1557.001
- Potential SNAKE Malware Installation Binary Indicator severity high
- Potential SNAKE Malware Installation CLI Arguments Indicator severity high
- Potential SNAKE Malware Persistence Service Execution severity high
- Potential Snatch Ransomware Activity severity high T1204
- Potential Suspicious Browser Launch From Document Reader Process severity medium T1204, T1204.002
- Potential Suspicious Child Process Of 3CXDesktopApp severity high T1218
- Potential Suspicious Execution From GUID Like Folder Names severity low T1027
- Potential Suspicious Windows Feature Enabled - ProcCreation severity medium
- Potential SysInternals ProcDump Evasion severity high T1003, T1003.001, T1036
- Potential SystemNightmare Exploitation Attempt severity critical T1068
- Potential Tampering With Security Products Via WMIC severity high T1685
- Potential UAC Bypass Via Sdclt.EXE severity medium T1548, T1548.002
- Potential WinAPI Calls Via CommandLine severity high T1106
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler severity high T1127
- Potentially Suspicious Cabinet File Expansion severity medium T1218
- Potentially Suspicious Call To Win32_NTEventlogFile Class severity high
- Potentially Suspicious Child Process Of ClickOnce Application severity medium
- Potentially Suspicious Child Process Of DiskShadow.EXE severity medium T1218
- Potentially Suspicious Child Process Of Regsvr32 severity high T1218, T1218.010
- Potentially Suspicious Child Process Of VsCode severity medium T1202, T1218
- Potentially Suspicious Command Targeting Teams Sensitive Files severity medium T1528
- Potentially Suspicious Event Viewer Child Process severity high T1548, T1548.002
- Potentially Suspicious Execution From Parent Process In Public Folder severity high T1059, T1564
- Potentially Suspicious Execution Of PDQDeployRunner severity medium
- Potentially Suspicious GoogleUpdate Child Process severity high
- Potentially Suspicious JWT Token Search Via CLI severity medium T1528, T1552, T1552.001
- Potentially Suspicious Powershell Script Execution From Temp Folder severity medium T1059, T1059.001
- Potentially Suspicious Usage Of Qemu severity medium T1090, T1572
- Potentially Suspicious WebDAV LNK Execution severity medium T1059, T1059.001, T1204
- Potentially Suspicious Windows App Activity severity medium
- PowerShell Base64 Encoded FromBase64String Cmdlet severity high T1059, T1059.001, T1140
- PowerShell Base64 Encoded IEX Cmdlet severity high T1059, T1059.001
- Powershell Base64 Encoded MpPreference Cmdlet severity high T1685
- PowerShell Base64 Encoded Reflective Assembly Load severity high T1027, T1059, T1059.001, T1620
- Powershell Defender Disable Scan Feature severity high T1685
- Powershell Defender Exclusion severity medium T1685
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction' severity high T1685
- PowerShell Download and Execution Cradles severity high T1059
- PowerShell Get-Clipboard Cmdlet Via CLI severity medium T1115
- PowerShell Get-Process LSASS severity high T1552, T1552.004
- Powershell Inline Execution From A File severity medium T1059, T1059.001
- PowerShell SAM Copy severity high T1003, T1003.002
- PowerShell Script Run in AppData severity medium T1059, T1059.001
- Powershell Token Obfuscation - Process Creation severity high T1027, T1027.009
- PrintBrm ZIP Creation of Extraction severity high T1105, T1564, T1564.004
- Privilege escalation via runas (command) severity medium T1134, T1134.002
- Privilege escalation via RunasCS severity low T1134, T1134.002
- Procdump Execution severity medium T1003, T1003.001, T1036
- Process Creation Using Sysnative Folder severity medium T1055
- Process Execution From A Potentially Suspicious Folder severity high T1036
- Process Execution From WebDAV Share severity low T1105
- Process Launched Without Image Name severity medium
- Process Proxy Execution Via Squirrel.EXE severity medium T1218
- Ps.exe Renamed SysInternals Tool severity high T1036, T1036.003
- PsExec Service Child Process Execution as LOCAL SYSTEM severity high
- PsExec/PAExec Escalation to LOCAL SYSTEM severity high T1587, T1587.001
- PUA - AdFind Suspicious Execution severity high T1018, T1069, T1069.002, T1087, T1087.002, T1482
- PUA - Adidnsdump Execution severity low T1018
- PUA - AdvancedRun Suspicious Execution severity high T1134, T1134.002
- PUA - Chisel Tunneling Tool Execution severity high T1090, T1090.001
- PUA - CleanWipe Execution severity high T1685
- PUA - DIT Snapshot Viewer severity high T1003, T1003.003
- PUA - Netcat Suspicious Execution severity high T1095
- PUA - Ngrok Execution severity high T1572
- PUA - NirCmd Execution As LOCAL SYSTEM severity high T1569, T1569.002
- PUA - Restic Backup Tool Execution severity high T1048, T1567, T1567.002
- PUA - RunXCmd Execution severity high T1569, T1569.002
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE severity high T1087, T1087.002
- PUA - TruffleHog Execution severity medium T1083, T1552, T1552.001
- Pubprn.vbs Proxy Execution severity medium T1216, T1216.001
- Python Function Execution Security Warning Disabled In Excel severity high T1685
- Python Spawning Pretty TTY on Windows severity high T1059
- Qakbot Regsvr32 Calc Pattern severity high
- Qakbot Rundll32 Exports Execution severity critical
- Qakbot Rundll32 Fake DLL Extension Execution severity critical
- Query Usage To Exfil Data severity medium
- QuickAssist Execution severity low T1219, T1219.002
- Raccine Uninstall severity high T1685
- Rar Usage with Password and Compression Level severity high T1560, T1560.001
- Raspberry Robin Subsequent Execution of Commands severity high T1059, T1059.001
- RDP session hijack via TSCON abuse command severity high T1563, T1563.002
- RDP shadow session started (command) severity high T1021, T1021.001, T1113, T1125
- RDP tunneling configuration enabled for port forwarding severity high T1021, T1021.001, T1572
- Recon Command Output Piped To Findstr.EXE severity medium T1057
- Regedit as Trusted Installer severity high T1548
- REGISTER_APP.VBS Proxy Execution severity medium T1218
- Registry Modification Attempt Via VBScript severity medium T1059, T1059.005, T1112
- Remote Access Tool - Ammy Admin Agent Execution severity medium
- Remote Access Tool - AnyDesk Piped Password Via CLI severity medium T1219, T1219.002
- Remote Access Tool - AnyDesk Silent Installation severity high T1219, T1219.002
- Remote Access Tool - MeshAgent Command Execution via MeshCentral severity medium T1219, T1219.002
- Remote Access Tool - Potential MeshAgent Execution - Windows severity medium T1219, T1219.002
- Remote Access Tool - ScreenConnect Installation Execution severity medium T1133
- Remote Access Tool - ScreenConnect Remote Command Execution - Hunting severity medium
- Remote Access Tool - ScreenConnect Server Web Shell Execution severity high T1190
- Remote Access Tool - Simple Help Execution severity medium T1219, T1219.002
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server severity medium T1105, T1219
- Remote Access Tool - Team Viewer Session Started On Windows Host severity low T1133
- Remote File Download Via Desktopimgdownldr Utility severity medium T1105
- Remote PowerShell Session Host Process (WinRM) severity medium T1021, T1021.006, T1059, T1059.001
- Remote XSL Execution Via Msxsl.EXE severity high T1220
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses severity high T1218
- Replace.exe Usage severity medium T1105
- RestrictedAdminMode Registry Value Tampering - ProcCreation severity high T1112
- REvil Kaseya Incident Malware Patterns severity critical T1059
- Root Certificate Installed From Susp Locations severity high T1553, T1553.004
- Rorschach Ransomware Execution Activity severity critical T1059, T1059.001, T1059.003
- Run PowerShell Script from ADS severity high T1564, T1564.004
- Run PowerShell Script from Redirected Input Stream severity high T1059
- Rundll32 Execution Without CommandLine Parameters severity high T1202
- Rundll32 Execution Without Parameters severity high T1021, T1021.002, T1569, T1569.002, T1570
- Scheduled persistent task with SYSTEM privileges creation severity high T1053, T1053.005
- Scheduled Task Creation From Potential Suspicious Parent Location severity medium T1053, T1053.005
- Scheduled Task Creation Via Schtasks.EXE severity low T1053, T1053.005
- Scheduled task creation with command line severity medium T1053, T1053.005
- Scheduled Task Creation with Curl and PowerShell Execution Combo severity medium T1053, T1053.005, T1105, T1218
- Scheduled task enumerated severity medium T1016
- Schtasks Creation Or Modification With SYSTEM Privileges severity high T1053, T1053.005
- Screen Capture Activity Via Psr.EXE severity medium T1113
- Script Event Consumer Spawning Process severity high T1047
- Script Interpreter Spawning Credential Scanner - Windows severity high T1005, T1059, T1059.007, T1552
- Scripting/CommandLine Process Spawned Regsvr32 severity medium T1218, T1218.010
- Sdclt Child Processes severity medium T1548, T1548.002
- Sdiagnhost Calling Suspicious Child Process severity high T1036, T1218
- SearchIndexer suspicious process activity severity medium T1036
- Security package (SSP) added (Reg via command) severity high T1547, T1547.008
- Security Service Disabled Via Reg.EXE severity high T1685
- Sensitive File Access Via Volume Shadow Copy Backup severity high T1490
- Serial console process spawning CMD shell (via command) severity high T1059, T1059.003
- Serpent Backdoor Payload Execution Via Scheduled Task severity high T1053, T1053.005, T1059, T1059.006
- Serv-U Exploitation CVE-2021-35211 by DEV-0322 severity critical T1136, T1136.001
- Service abuse with backdoored "command failure" (Reg via command) severity high T1543, T1543.003
- Service abuse with backdoored "command failure" (service) severity high T1543, T1543.003
- Service abuse with malicious ImagePath (Reg via command) severity high T1574, T1574.010
- Service abuse with malicious ImagePath (service) severity high T1543, T1543.003
- Service creation (command) severity high T1543, T1543.003
- Service deactivation (command) severity high T1489
- Service permissions hijacked for privileges abuse (reg via command) severity high T1543, T1543.003, T1574, T1574.010
- Service permissions hijacked for privileges abuse (service) severity high T1543, T1543.003, T1574, T1574.010
- Shai-Hulud 2.0 Malicious NPM Package Installation severity high T1195, T1195.002
- Shai-Hulud Malicious Bun Execution severity high T1195, T1195.002, T1203
- Shai-Hulud Malware Indicators - Windows severity high T1059
- Shell Process Spawned by Java.EXE severity medium
- ShimCache Flush severity high T1112
- Small Sieve Malware CommandLine Indicator severity high T1574, T1574.001
- Sofacy Trojan Loader Activity severity high T1059, T1059.003, T1218, T1218.011
- SOURGUM Actor Behaviours severity high T1546, T1546.015
- SPN added to an account by command line severity high T1098
- Spool process spawned a CMD shell (PrintNightmare vulnerability - CVE-2021-36958) severity high T1574, T1574.001
- SQL Server database's table enumeration severity medium T1518
- SQL server sqlcmd utility abuse for privilege escalation severity high T1505, T1505.001
- SQL Server started in single mode (command) severity high T1505, T1505.001
- Start of NT Virtual DOS Machine severity medium
- Stickey key called CMD via command execution severity high T1546, T1546.008
- Stickey key IFEO (Reg via command) severity high T1546, T1546.008
- Sticky Key Like Backdoor Execution severity critical T1546, T1546.008
- Sticky key sethc command for replacement by CMD severity high T1546, T1546.008
- Suspect Svchost Activity severity high T1055
- Suspicious ArcSOC.exe Child Process severity high T1059, T1203
- Suspicious Binary In User Directory Spawned From Office Application severity high T1204, T1204.002
- Suspicious BitLocker Access Agent Update Utility Execution severity high T1021, T1021.003, T1218
- Suspicious Calculator Usage severity high T1036
- Suspicious Child Process of AspNetCompiler severity high T1127
- Suspicious Child Process Of BgInfo.EXE severity high T1059, T1059.005, T1202, T1218
- Suspicious Child Process Of Manage Engine ServiceDesk severity high T1102
- Suspicious Child Process of Notepad++ Updater - GUP.Exe severity high T1195, T1195.002, T1557
- Suspicious Child Process Of SQL Server severity high T1190, T1505, T1505.003
- Suspicious Child Process Of Wermgr.EXE severity high T1036, T1055
- Suspicious Chromium Browser Instance Executed With Custom Extension severity high T1176, T1176.001
- Suspicious ClickFix/FileFix Execution Pattern severity high T1204, T1204.001, T1204.004
- Suspicious CodePage Switch Via CHCP severity medium T1036
- Suspicious Command Patterns In Scheduled Task Creation severity high T1053, T1053.005
- Suspicious CrushFTP Child Process severity medium T1059, T1059.001, T1059.003, T1190
- Suspicious CustomShellHost Execution severity high T1216
- Suspicious Debugger Registration Cmdline severity high T1546, T1546.008
- Suspicious Desktopimgdownldr Command severity high T1105
- Suspicious Diantz Alternate Data Stream Execution severity medium T1564, T1564.004
- Suspicious Diantz Download and Compress Into a CAB File severity medium T1105
- Suspicious Double Extension File Execution severity high T1566, T1566.001
- Suspicious Download from Office Domain severity high T1105, T1608
- Suspicious Driver Install by pnputil.exe severity medium T1547
- Suspicious Electron Application Child Processes severity medium
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call severity high T1027, T1059, T1059.001
- Suspicious Execution From Outlook Temporary Folder severity high T1566, T1566.001
- Suspicious Execution Location Of Wermgr.EXE severity high
- Suspicious Execution of Hostname severity low T1082
- Suspicious Execution of InstallUtil Without Log severity medium
- Suspicious Execution of Powershell with Base64 severity medium T1059, T1059.001
- Suspicious Execution of Shutdown severity medium T1529
- Suspicious Execution of Shutdown to Log Out severity medium T1529
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix severity high T1027, T1027.010, T1204, T1204.004
- Suspicious Extrac32 Alternate Data Stream Execution severity medium T1564, T1564.004
- Suspicious FileFix Execution Pattern severity high T1204, T1204.004
- Suspicious FromBase64String Usage On Gzip Archive - Process Creation severity medium T1132, T1132.001
- Suspicious GrpConv Execution severity high T1547
- Suspicious GUP Usage severity high T1574, T1574.001
- Suspicious High IntegrityLevel Conhost Legacy Option severity informational T1202
- Suspicious HWP Sub Processes severity high T1059, T1059.003, T1203, T1566, T1566.001
- Suspicious IIS Module Registration severity high T1505, T1505.004
- Suspicious Kernel Dump Using Dtrace severity high T1082
- Suspicious Modification Of Scheduled Tasks severity high T1053, T1053.005
- Suspicious Msiexec Execute Arbitrary DLL severity medium T1218, T1218.007
- Suspicious Network Command severity low T1016
- Suspicious New Instance Of An Office COM Object severity medium
- Suspicious New Service Creation severity high T1543, T1543.003
- Suspicious Obfuscated PowerShell Code severity high
- Suspicious Outlook Child Process severity high T1204, T1204.002
- Suspicious Ping/Del Command Combination severity high T1070, T1070.004
- Suspicious PowerShell Download and Execute Pattern severity high T1059, T1059.001
- Suspicious PowerShell IEX Execution Patterns severity high T1059, T1059.001
- Suspicious PowerShell Invocations - Specific - ProcessCreation severity medium
- Suspicious PowerShell Mailbox Export to Share severity critical
- Suspicious PowerShell Parameter Substring severity high T1059, T1059.001
- Suspicious PrinterPorts Creation (CVE-2020-1048) severity high T1059, T1059.001
- Suspicious Process Created Via Wmic.EXE severity high T1047
- Suspicious Process Execution From Fake Recycle.Bin Folder severity high
- Suspicious Process Parents severity high T1036
- Suspicious Process Patterns NTDS.DIT Exfil severity high T1003, T1003.003
- Suspicious Process Start Locations severity medium T1036
- Suspicious Processes Spawned by Java.EXE severity high
- Suspicious Processes Spawned by WinRM severity high T1190
- Suspicious Program Names severity high T1059
- Suspicious Provlaunch.EXE Child Process severity high T1218
- Suspicious Query of MachineGUID severity low T1082
- Suspicious RASdial Activity severity medium T1059
- Suspicious RazerInstaller Explorer Subprocess severity high T1553
- Suspicious RDP Redirect Using TSCON severity high T1021, T1021.001, T1563, T1563.002
- Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet severity medium T1087, T1087.001
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS severity high T1059, T1059.005, T1615
- Suspicious Recursive Takeown severity medium T1222, T1222.001
- Suspicious Redirection to Local Admin Share severity high T1048
- Suspicious Reg Add BitLocker severity high T1486
- Suspicious Remote Child Process From Outlook severity high T1059, T1202
- Suspicious RunAs-Like Flag Combination severity medium
- Suspicious Rundll32 Activity Invoking Sys File severity high T1218, T1218.011
- Suspicious Rundll32 Invoking Inline VBScript severity high T1055
- Suspicious Runscripthelper.exe severity medium T1059, T1202
- Suspicious Scan Loop Network severity medium T1018, T1059
- Suspicious Scheduled Task Creation Involving Temp Folder severity high T1053, T1053.005
- Suspicious Scheduled Task Name As GUID severity medium T1053, T1053.005
- Suspicious Schtasks Execution AppData Folder severity high T1053, T1053.005, T1059, T1059.001
- Suspicious ScreenSave Change by Reg.exe severity medium T1546, T1546.002
- Suspicious Serv-U Process Pattern severity high T1555
- Suspicious Service Binary Directory severity high T1202
- Suspicious Service Path Modification severity high T1543, T1543.003
- Suspicious Shells Spawn by Java Utility Keytool severity high
- Suspicious Speech Runtime Binary Child Process severity high T1021, T1021.003, T1218
- Suspicious Splwow64 Without Params severity high T1202
- Suspicious SPN enumeration previous to Kerberoasting attack (native commands) severity high T1087, T1087.002
- Suspicious Sysmon as Execution Parent severity high T1068
- Suspicious SYSVOL Domain Group Policy Access severity medium T1552, T1552.006
- Suspicious TSCON Start as SYSTEM severity high T1219, T1219.002
- Suspicious UltraVNC Execution severity high T1021, T1021.005
- Suspicious Usage Of ShellExec_RunDLL severity high
- Suspicious VBoxDrvInst.exe Parameters severity medium T1112
- Suspicious VBScript UN2452 Pattern severity high T1547, T1547.001
- Suspicious Velociraptor Child Process severity high T1219
- Suspicious Vsls-Agent Command With AgentExtensionPath Load severity medium T1218
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE severity medium T1685
- Suspicious WindowsTerminal Child Processes severity medium
- Suspicious WmiPrvSE Child Process severity high T1047, T1204, T1204.002, T1218, T1218.010
- Suspicious X509Enrollment - Process Creation severity medium T1553, T1553.004
- Suspicious ZipExec Execution severity medium T1202, T1218
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code severity medium T1216, T1218
- Sysprep on AppData Folder severity medium T1059
- System File Execution Location Anomaly severity high T1036
- System Information Discovery via Registry Queries severity low T1082
- SystemNightmare by GentilKiwi - External printer mapped (CVE-2021-1675 / CVE-2021-34527) severity high T1547, T1547.010, T1574, T1574.001
- TAIDOOR RAT DLL Load severity high T1055, T1055.001
- Tamper Windows Defender Remove-MpPreference severity high T1685
- TanStack Supply-Chain Attack Execution Indicators - Windows severity high T1059, T1059.007, T1204, T1204.002
- Tap Installer Execution severity medium T1048
- Task Manager access indicator for potential LSASS dump severity low T1003, T1003.001
- Taskkill Symantec Endpoint Protection severity high T1685
- Taskmgr as LOCAL_SYSTEM severity high T1036
- Tasks Folder Evasion severity high T1574, T1574.001
- Time Travel Debugging Utility Usage severity high T1003, T1003.001, T1218
- TropicTrooper Campaign November 2018 severity high T1059, T1059.001
- TrustedPath UAC Bypass Pattern severity critical T1548, T1548.002
- Tunneling Tool Execution severity medium T1041, T1071, T1071.001, T1572
- Turla Group Commands May 2020 severity critical T1027, T1053, T1053.005, T1059, T1059.001
- Turla Group Lateral Movement severity critical T1021, T1021.002, T1059, T1083, T1135
- UAC Bypass Tools Using ComputerDefaults severity high T1548, T1548.002
- UAC Bypass Using ChangePK and SLUI severity high T1548, T1548.002
- UAC Bypass Using Consent and Comctl32 - Process severity high T1548, T1548.002
- UAC Bypass Using DismHost severity high T1548, T1548.002
- UAC Bypass Using Event Viewer RecentViews severity high
- UAC Bypass Using IEInstal - Process severity high T1548, T1548.002
- UAC Bypass Using MSConfig Token Modification - Process severity high T1548, T1548.002
- UAC Bypass Using PkgMgr and DISM severity high T1548, T1548.002
- UAC Bypass WSReset severity high T1548, T1548.002
- UEFI Persistence Via Wpbbin - ProcessCreation severity high T1542, T1542.001
- UNC2452 PowerShell Pattern severity critical T1047, T1059, T1059.001
- Uncommon Child Process Of AddinUtil.EXE severity medium T1218
- Uncommon Child Process Of Appvlp.EXE severity medium T1218
- Uncommon Child Process Of BgInfo.EXE severity medium T1059, T1059.005, T1202, T1218
- Uncommon Child Process Of Conhost.EXE severity medium T1202
- Uncommon Child Process Of Defaultpack.EXE severity medium T1218
- Uncommon Child Process Of Setres.EXE severity high T1202, T1218
- Uncommon Child Process Spawned By Odbcconf.EXE severity medium T1218, T1218.008
- Uncommon Child Processes Of SndVol.exe severity medium
- Uncommon FileSystem Load Attempt By Format.com severity high
- Uncommon Link.EXE Parent Process severity medium T1218
- Uncommon Sigverif.EXE Child Process severity medium T1216
- Uncommon Svchost Command Line Parameter severity high T1036, T1036.005, T1055, T1055.012
- Uncommon Svchost Parent Process severity medium T1036, T1036.005
- Uncommon Userinit Child Process severity high T1037, T1037.001
- Uninstall Crowdstrike Falcon Sensor severity high T1685
- Unusual Child Process of dns.exe severity high T1133
- Unusual Parent Process For Cmd.EXE severity medium T1059
- Ursnif Redirection Of Discovery Commands severity high T1059
- Usage Of Web Request Commands And Cmdlets severity medium T1059, T1059.001
- Use NTFS Short Name in Command Line severity medium T1564, T1564.004
- Use NTFS Short Name in Image severity medium T1564, T1564.004
- Use of Pcalua For Execution severity medium T1059
- Use Of The SFTP.EXE Binary As A LOLBIN severity medium T1218
- Use Short Name Path in Command Line severity medium T1564, T1564.004
- User added to a group via commandline severity high T1098
- User Added To Highly Privileged Group severity high T1098
- User Added to Local Administrators Group severity medium T1098
- User Added to Remote Desktop Users Group severity high T1021, T1021.001, T1133, T1136, T1136.001
- User creation via commandline severity high T1136, T1136.001, T1136.002
- User enumeration and creation related to Manic Menagerie 2.0 (via cmdline) severity medium T1136, T1136.001
- User properties enumeration via commandline severity high T1087, T1087.001, T1087.002
- UtilityFunctions.ps1 Proxy Dll severity medium T1216
- Veeam Backup Database Suspicious Query severity medium T1005
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE severity high T1005
- Virtualbox Driver Installation or Starting of VMs severity low T1564, T1564.006
- Visual Basic Command Line Compiler Usage severity high T1027, T1027.004
- Visual Studio Code Tunnel Service Installation severity medium T1071, T1071.001
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution severity medium T1218
- VolumeShadowCopy Symlink Creation Via Mklink severity high T1003, T1003.002, T1003.003
- VSS backup deletion (WMI) severity high T1490
- VSS backup deletion or resize severity high T1490
- Wab Execution From Non Default Location severity high
- Wab/Wabmig Unusual Parent Or Child Processes severity high
- WannaCry Ransomware Activity severity critical T1083, T1210, T1222, T1222.001, T1486, T1490
- Wdigest authentication enabled (Reg via command) severity high T1003, T1685
- Weak or Abused Passwords In CLI severity medium
- Webserver IIS module installed (command) severity high T1505, T1505.004
- Webserver IIS module installed (command) severity high T1505, T1505.004
- Webshell Hacking Activity Patterns severity high T1018, T1033, T1087, T1505, T1505.003
- Webshell Tool Reconnaissance Activity severity high T1505, T1505.003
- WhoAmI as Parameter severity high T1033
- Windows native backup deletion severity high T1490
- Windows native backup size re-configuration severity high T1490
- Windows native Pktmon sniffer abuse severity medium T1040
- Windows Processes Suspicious Parent Directory severity low T1036, T1036.003, T1036.005
- Windows Subsystem for Linux (WSL) installation (command) severity medium T1564, T1564.006
- Windows traffic capture abuse severity medium T1040
- Winnti Malware HK University Campaign severity critical T1574, T1574.001
- Winnti Pipemon Characteristics severity critical T1574, T1574.001
- WinRM listening service reconnaissance (process) severity medium T1021, T1021.006
- WinRS usage for remote execution severity high T1021, T1021.006
- WMI Backdoor Exchange Transport Agent severity critical T1546, T1546.003
- WMI Persistence - Script Event Consumer severity medium T1546, T1546.003
- WMI spwaning PowerShell process - WMImplant severity high T1047
- WmiPrvSE Spawned A Process severity medium T1047
- Write Protect For Storage Disabled severity medium T1685
- Writing Of Malicious Files To The Fonts Folder severity medium T1059, T1211
- Wscript Shell Run In CommandLine severity medium T1059
- WSL Child Process Anomaly severity medium T1202, T1218
- WSL Kali-Linux Usage severity high T1202
- Wusa.EXE Executed By Parent Process Located In Suspicious Location severity high
- ZxShell Malware severity critical T1059, T1059.003, T1218, T1218.011
Elastic (257)
- Accessing Outlook Data Files severity low building block T1005, T1114, T1114.001
- Account Discovery Command via SYSTEM Account severity low T1033, T1078, T1078.003, T1087
- Active Directory Discovery using AdExplorer severity low T1016, T1018, T1069, T1069.002, T1087, T1087.002
- Adding Hidden File Attribute via Attrib severity low T1222, T1222.001, T1564, T1564.001
- AdFind Command Activity severity low T1016, T1018, T1069, T1069.002, T1087, T1087.002
- At.exe Command Lateral Movement severity low building block T1021, T1053, T1053.002, T1053.005
- Attempt to Establish VScode Remote Tunnel severity medium T1219
- Attempt to Install or Run Kali Linux via WSL severity high T1059, T1059.004, T1202
- Attempted Private Key Access severity low building block T1005, T1552, T1552.004
- Backup Deletion with Wbadmin severity low T1485, T1490
- Binary Content Copy via Cmd.exe severity low building block T1027, T1059, T1059.003, T1140
- Bitsadmin Activity severity low building block T1105, T1197
- Browser Process Spawned from an Unusual Parent severity high T1185, T1539, T1555, T1555.003
- Bypass UAC via Event Viewer severity high T1548, T1548.002
- Clearing Windows Console History severity medium T1059, T1059.001, T1070, T1070.003
- Clearing Windows Event Logs severity low T1070, T1685, T1685.001, T1685.005
- Code Signing Policy Modification Through Built-in tools severity medium T1553, T1553.006
- Command and Scripting Interpreter via Windows Scripts severity high T1059, T1059.001, T1059.003, T1059.005, T1059.007, T1218
- Command Execution via ForFiles severity medium T1202
- Command Execution via SolarWinds Process severity medium T1059, T1059.001, T1059.003, T1195, T1195.002
- Command Obfuscation via Unicode Modifier Letters severity high T1027, T1027.010
- Command Shell Activity Started via RunDLL32 severity low T1059, T1059.001, T1059.003, T1218, T1218.011, T1552
- Conhost Spawned By Suspicious Parent Process severity high T1036, T1055, T1059
- Control Panel Process with Unusual Arguments severity high T1218, T1218.002
- Credential Acquisition via Registry Hive Dumping severity high T1003, T1003.002, T1003.004
- Delayed Execution via Ping severity low T1047, T1059, T1059.001, T1059.003, T1059.005, T1127
- Delete Volume USN Journal with Fsutil severity low T1070, T1070.004
- Disable Windows Event and Security Logs Using Built-in Tools severity low T1070, T1685, T1685.001, T1685.005
- Disable Windows Firewall Rules via Netsh severity medium T1685, T1686
- Disabling Windows Defender Security Settings via PowerShell severity medium T1059, T1059.001, T1685
- Enable Host Network Discovery via Netsh severity medium T1685, T1686
- Encrypting Files with WinRar or 7z severity medium T1005, T1560, T1560.001
- Enumerating Domain Trusts via DSQUERY.EXE severity low T1018, T1482
- Enumerating Domain Trusts via NLTEST.EXE severity low T1018, T1482
- Enumeration Command Spawned via WMIPrvSE severity low T1007, T1012, T1016, T1016.001, T1018, T1033
- Enumeration of Administrator Accounts severity low T1069, T1069.001, T1069.002, T1087, T1087.001, T1087.002
- Execution from a Removable Media with Network Connection severity low T1091
- Execution from Unusual Directory - Command Line severity medium T1036, T1036.005, T1059, T1059.001, T1059.003, T1218
- Execution of a Downloaded Windows Script severity medium T1059, T1059.001, T1059.003, T1059.005, T1059.007, T1204
- Execution of COM object via Xwizard severity medium T1218, T1559, T1559.001
- Execution of File Written or Modified by Microsoft Office severity high T1203, T1204, T1204.002, T1566, T1566.001, T1566.002
- Execution of Persistent Suspicious Program severity medium T1059, T1059.001, T1127, T1127.001, T1218, T1218.004
- Execution via Microsoft DotNet ClickOnce Host severity low building block T1127, T1127.002, T1218, T1218.011
- Execution via MS VisualStudio Pre/Post Build Events severity low building block T1059, T1059.003, T1127, T1127.001
- Execution via TSClient Mountpoint severity high T1021, T1021.001, T1570
- Execution via Windows Command Debugging Utility severity medium T1036, T1036.005, T1218
- Exporting Exchange Mailbox via PowerShell severity medium T1005, T1059, T1059.001, T1114, T1114.001, T1114.002
- File and Directory Permissions Modification severity low building block T1222, T1222.001
- File or Directory Deletion Command severity low building block T1070, T1070.004, T1112, T1218, T1218.011
- First Time Seen Remote Monitoring and Management Tool severity medium T1219, T1219.002
- First Time Seen RMM Signer Across the Environment severity medium T1219, T1219.002
- Group Policy Discovery via Microsoft GPResult Utility severity low T1615
- Host File System Changes via Windows Subsystem for Linux severity medium T1059, T1059.004, T1202
- IIS HTTP Logging Disabled severity high T1685, T1685.001
- ImageLoad via Windows Update Auto Update Client severity medium T1129, T1218
- Incoming DCOM Lateral Movement via MSHTA severity high T1021, T1021.003, T1218, T1218.005, T1559, T1559.001
- Incoming DCOM Lateral Movement with MMC severity high T1021, T1021.003, T1218, T1218.014, T1559, T1559.001
- Incoming DCOM Lateral Movement with ShellBrowserWindow or ShellWindows severity medium T1021, T1021.003, T1559, T1559.001
- Incoming Execution via PowerShell Remoting severity medium T1021, T1021.006, T1059, T1059.001
- Incoming Execution via WinRM Remote Shell severity medium T1021, T1021.006
- Indirect Command Execution via Forfiles/Pcalua severity low building block T1202
- InstallUtil Activity severity low building block T1218, T1218.004
- InstallUtil Process Making Network Connections severity medium T1218, T1218.004
- Java Dropped and Executed With DNS Lookup severity medium T1071, T1105, T1204, T1204.002
- Local Scheduled Task Creation severity low T1053, T1053.005
- Microsoft Build Engine Started by a System Process severity medium T1047, T1127, T1127.001
- Microsoft Build Engine Started by an Office Application severity high T1127, T1127.001, T1204, T1204.002
- Microsoft Build Engine Using an Alternate Name severity low T1036, T1036.003, T1127, T1127.001
- Microsoft Exchange Server UM Spawning Suspicious Processes severity medium T1190, T1210
- Microsoft Exchange Worker Spawning Suspicious Processes severity high T1059, T1059.001, T1059.003, T1190, T1505, T1505.003
- Microsoft IIS Connection Strings Decryption severity high T1003, T1552, T1552.001
- Microsoft IIS Service Account Password Dumped severity low T1003, T1552, T1552.001
- Microsoft Management Console File from Unusual Path severity medium T1059, T1059.005, T1059.007, T1204, T1204.002, T1218
- Modification of Boot Configuration severity low T1490
- Mofcomp Activity severity low T1047, T1546, T1546.003
- Mounting Hidden or WebDav Remote Shares severity medium T1021, T1021.002, T1078, T1078.003, T1087, T1087.001
- MsBuild Making Network Connections severity medium T1071, T1127, T1127.001
- Mshta Making Network Connections severity medium T1218, T1218.005
- MsiExec Service Child Process With Network Connection severity medium T1218, T1218.007
- Multiple Remote Management Tool Vendors on Same Host severity medium T1219, T1219.002
- NetSupport Manager Execution from an Unusual Path severity high T1219
- Network Connection via Compiled HTML File severity low T1071, T1204, T1204.002, T1218, T1218.001
- Network Connection via MsXsl severity low T1105, T1220
- Network Connection via Registration Utility severity low T1218, T1218.009, T1218.010
- Network Connection via Signed Binary severity low T1218
- New ActiveSyncAllowedDeviceID Added via PowerShell severity medium T1059, T1059.001, T1098, T1098.002, T1114, T1114.002
- NTDS Dump via Wbadmin severity medium T1003, T1003.002, T1003.003, T1006
- NTDS or SAM Database File Copied severity high T1003, T1003.002, T1003.003
- Parent Process PID Spoofing severity high T1134, T1134.004
- Peripheral Device Discovery severity low T1120
- Persistence via BITS Job Notify Cmdline severity medium T1197
- Persistence via TelemetryController Scheduled Task Hijack severity high T1053, T1053.005, T1574
- Persistence via Update Orchestrator Service Hijack severity high T1068, T1543, T1543.003, T1574, T1574.011
- Persistence via WMI Event Subscription severity low T1047, T1546, T1546.003
- Potential Application Shimming via Sdbinst severity low T1546, T1546.011
- Potential Command and Control via Internet Explorer severity medium T1071, T1071.004, T1218, T1218.010, T1218.011, T1559
- Potential Command Shell via NetCat severity high T1059, T1059.001, T1059.003, T1095
- Potential Credential Access via Renamed COM+ Services DLL severity high T1003, T1003.001, T1036, T1036.003, T1218, T1218.011
- Potential Credential Access via Trusted Developer Utility severity high T1003, T1003.002, T1127, T1127.001, T1555, T1555.004
- Potential Credential Access via Windows Utilities severity high T1003, T1003.001, T1003.003, T1218, T1218.011
- Potential CVE-2025-33053 Exploitation severity high T1036, T1036.005, T1203, T1218, T1566, T1566.001
- Potential Data Exfiltration via Rclone severity medium T1036, T1036.003, T1048, T1567, T1567.002
- Potential Defense Evasion via CMSTP.exe severity low building block T1218, T1218.003
- Potential DLL Side-Loading via Trusted Microsoft Programs severity medium T1036, T1574, T1574.001
- Potential DNS Tunneling via NsLookup severity medium T1071, T1071.004, T1572
- Potential EDR-Freeze via WerFaultSecure Abuse severity high T1685
- Potential Escalation via Vulnerable MSI Repair severity high T1068, T1218, T1218.007
- Potential Evasion via Filter Manager severity medium T1685
- Potential Execution via FileFix Phishing Attack severity high T1059, T1059.001, T1059.003, T1204, T1204.002, T1204.004
- Potential Exploitation of an Unquoted Service Path Vulnerability severity low T1574, T1574.009
- Potential Fake CAPTCHA Phishing Attack severity high T1059, T1059.001, T1059.003, T1189, T1204, T1204.004
- Potential File Download via a Headless Browser severity high T1105
- Potential File Transfer via Certreq severity medium T1071, T1071.001, T1105, T1218, T1567
- Potential File Transfer via Curl for Windows severity low T1071, T1071.001, T1105, T1567
- Potential Foxmail Exploitation severity high T1203, T1566, T1566.001
- Potential Local NTLM Relay via HTTP severity high T1187, T1212, T1218, T1218.011, T1557
- Potential LSASS Clone Creation via PssCaptureSnapShot severity high T1003, T1003.001
- Potential Masquerading as Browser Process severity low building block T1036, T1036.001, T1036.005, T1554
- Potential Masquerading as Business App Installer severity low T1036, T1036.001, T1036.005, T1189, T1204, T1204.002
- Potential Masquerading as Communication Apps severity medium T1036, T1036.001, T1036.005, T1554
- Potential Masquerading as System32 Executable severity low building block T1036, T1036.001, T1036.005, T1553, T1553.002, T1554
- Potential Modification of Accessibility Binaries severity high T1546, T1546.008
- Potential Notepad Markdown RCE Exploitation severity high T1203, T1204, T1204.002
- Potential Privilege Escalation via InstallerFileTakeOver severity high T1036, T1036.005, T1068, T1574
- Potential Process Injection from Malicious Document severity low building block T1055, T1566, T1566.001
- Potential Protocol Tunneling via Cloudflared severity medium T1090, T1090.002, T1572
- Potential Protocol Tunneling via Yuze severity medium T1090, T1218, T1218.011, T1572
- Potential Remote Desktop Tunneling Detected severity high T1021, T1021.001, T1021.004, T1572
- Potential Remote File Execution via MSIEXEC severity low T1105, T1218, T1218.007, T1566, T1566.002
- Potential Remote Install via MsiExec severity high T1105, T1218, T1218.007
- Potential SharpRDP Behavior severity high T1021, T1021.001, T1059, T1059.001, T1059.003
- Potential SSH Reverse Port Forwarding severity low T1021, T1021.004, T1090, T1090.002, T1572
- Potential Veeam Credential Access Command severity medium T1003, T1059, T1059.001, T1213, T1555
- Potential Windows Error Manager Masquerading severity medium T1036, T1036.005
- Potential WSUS Abuse for Lateral Movement severity medium T1072, T1210
- Privilege Escalation via Named Pipe Impersonation severity high T1134, T1134.001
- Privileges Elevation via Parent Process PID Spoofing severity high T1134, T1134.002, T1134.004
- Process Activity via Compiled HTML File severity medium T1059, T1059.001, T1059.003, T1204, T1204.002, T1218
- Process Created with a Duplicated Token severity medium T1134, T1134.001, T1134.002
- Process Created with an Elevated Token severity high T1134, T1134.002
- Process Creation via Secondary Logon severity medium T1134, T1134.002, T1134.003
- Process Discovery Using Built-in Tools severity low building block T1057
- Process Execution from an Unusual Directory severity medium T1036, T1036.005
- Program Files Directory Masquerading severity medium T1036, T1036.005
- Proxy Execution via Console Window Host severity high T1059, T1059.001, T1059.003, T1202
- Proxy Execution via Windows OpenSSH severity high T1202
- PsExec Network Connection severity low T1021, T1021.002, T1569, T1569.002, T1570
- Remote Desktop Enabled in Windows Firewall by Netsh severity medium T1021, T1021.001, T1685, T1686
- Remote Desktop File Opened from Suspicious Path severity medium T1204, T1204.002, T1566, T1566.001
- Remote Execution via File Shares severity medium T1021, T1021.002, T1570
- Remote File Copy to a Hidden Share severity medium T1021, T1021.002, T1074, T1074.002, T1570
- Remote File Download via Desktopimgdownldr Utility severity medium T1105
- Remote File Download via MpCmdRun severity medium T1105
- Remote Management Access Launch After MSI Install severity medium T1219, T1219.002
- Remote System Discovery Commands severity low building block T1016, T1018, T1069, T1069.002
- Remote XSL Script Execution via COM severity low T1059, T1059.005, T1059.007, T1220, T1559, T1559.001
- Remotely Started Services via RPC severity medium T1021, T1569, T1569.002
- Renamed Automation Script Interpreter severity high T1036, T1036.003, T1059, T1059.010
- Renamed Utility Executed with Short Program Name severity medium T1036, T1036.003
- ScreenConnect Server Spawning Suspicious Processes severity high T1059, T1059.001, T1059.003, T1190, T1505, T1505.003
- Script Execution via Microsoft HTML Application severity high T1059, T1059.005, T1059.007, T1218, T1218.005, T1218.011
- Searching for Saved Credentials via VaultCmd severity medium T1003, T1555, T1555.004
- Security Software Discovery using WMIC severity medium building block T1047, T1518, T1518.001
- Service Command Lateral Movement severity low T1021, T1021.002, T1543, T1543.003, T1569, T1569.002
- Service Control Spawned via Script Interpreter severity low T1047, T1059, T1059.001, T1059.003, T1059.005, T1218
- Service DACL Modification via sc.exe severity medium T1543, T1543.003, T1564
- Signed Proxy Execution via MS Work Folders severity medium T1036, T1036.005, T1218, T1574, T1574.008
- SMB Connections via LOLBin or Untrusted Process severity medium T1021, T1021.002
- Startup Folder Persistence via Unsigned Process severity medium T1036, T1036.001, T1547, T1547.001
- Suspicious .NET Code Compilation severity medium T1027, T1027.004, T1047, T1059, T1059.005, T1059.007
- Suspicious CertUtil Commands severity medium T1105, T1140, T1552, T1552.004
- Suspicious Child Process via Azure VM CustomScript Extension severity medium T1059, T1059.001, T1059.003, T1218, T1651
- Suspicious Cmd Execution via WMI severity high T1021, T1021.003, T1047, T1059, T1059.003
- Suspicious Command Prompt Network Connection severity low T1059, T1059.003, T1071, T1105
- Suspicious Communication App Child Process severity medium T1036, T1036.001, T1036.005, T1055, T1203, T1554
- Suspicious Endpoint Security Parent Process severity medium T1036, T1036.005, T1055, T1055.012
- Suspicious Execution from a Mounted Device severity medium T1047, T1059, T1059.001, T1059.003, T1127, T1127.001
- Suspicious Execution from a WebDav Share severity high T1021, T1021.002, T1071, T1071.001, T1105, T1204
- Suspicious Execution from INET Cache severity high T1105, T1204, T1204.002, T1566, T1566.001
- Suspicious Execution from VS Code Extension severity medium T1059, T1059.001, T1059.003, T1059.007, T1105, T1195
- Suspicious Execution via Microsoft Office Add-Ins severity medium T1129, T1137, T1137.006, T1204, T1204.002, T1566
- Suspicious Execution via MSIEXEC severity low building block T1218, T1218.007
- Suspicious Execution via Scheduled Task severity medium T1053, T1053.005
- Suspicious Execution via Windows Subsystem for Linux severity low T1003, T1003.008, T1059, T1059.004, T1202
- Suspicious Execution with NodeJS severity high T1027, T1027.010, T1059, T1059.007
- Suspicious Explorer Child Process severity medium T1059, T1059.001, T1059.003, T1059.005, T1218, T1218.005
- Suspicious HTML File Creation severity medium T1027, T1027.006, T1204, T1204.002, T1566, T1566.001
- Suspicious Inter-Process Communication via Outlook severity medium T1114, T1114.001, T1559, T1559.001
- Suspicious JavaScript Execution via Deno severity high T1027, T1059, T1059.007, T1105
- Suspicious JetBrains TeamCity Child Process severity medium T1016, T1033, T1049, T1057, T1059, T1059.001
- Suspicious Microsoft Antimalware Service Execution severity high T1036, T1036.003, T1036.005, T1574, T1574.001
- Suspicious Microsoft Diagnostics Wizard Execution severity high T1036, T1036.003, T1218
- Suspicious Microsoft HTML Application Child Process severity high T1059, T1059.001, T1059.003, T1218, T1218.005, T1218.007
- Suspicious MS Office Child Process severity medium T1016, T1033, T1049, T1057, T1059, T1059.001
- Suspicious MS Outlook Child Process severity low T1059, T1059.001, T1059.003, T1204, T1204.002, T1218
- Suspicious Outlook Child Process severity low building block T1036, T1036.001, T1036.005, T1055, T1203, T1554
- Suspicious PDF Reader Child Process severity low T1016, T1016.001, T1033, T1057, T1082, T1203
- Suspicious Process Execution via Renamed PsExec Executable severity medium T1021, T1021.002, T1036, T1036.003, T1569, T1569.002
- Suspicious ScreenConnect Client Child Process severity medium T1047, T1053, T1053.005, T1059, T1059.001, T1059.003
- Suspicious Shell Execution via Velociraptor severity medium T1059, T1059.001, T1059.003, T1218, T1218.011, T1219
- Suspicious SolarWinds Child Process severity medium T1106, T1195, T1195.002
- Suspicious Troubleshooting Pack Cabinet Execution severity low building block T1204, T1204.002, T1218
- Suspicious WerFault Child Process severity medium T1036, T1546, T1546.012
- Suspicious Windows Command Shell Arguments severity high T1027, T1059, T1059.003, T1105, T1218, T1218.005
- Suspicious Windows Powershell Arguments severity medium T1027, T1027.010, T1059, T1059.001, T1105, T1140
- Suspicious WMIC XSL Script Execution severity medium T1047, T1218, T1220
- Suspicious Zoom Child Process severity medium T1036, T1055, T1059, T1059.001, T1059.003, T1203
- Symbolic Link to Shadow Copy Created severity medium T1003, T1003.002, T1003.003, T1006
- System File Ownership Change severity medium T1222, T1222.001
- System Information Discovery via Windows Command Shell severity low building block T1059, T1059.003, T1082, T1083
- System Service Discovery through built-in Windows Utilities severity low building block T1007, T1057, T1135
- System Shells via Services severity medium T1059, T1059.001, T1059.003, T1543, T1543.003, T1569
- System Time Discovery severity low building block T1124, T1614
- UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer severity medium T1218, T1548, T1548.002, T1559, T1559.001
- UAC Bypass Attempt via Windows Directory Masquerading severity high T1036, T1036.005, T1548, T1548.002
- UAC Bypass Attempt with IEditionUpgradeManager Elevated COM Interface severity high T1548, T1548.002, T1559, T1559.001
- UAC Bypass via DiskCleanup Scheduled Task Hijack severity medium T1053, T1053.005, T1548, T1548.002
- UAC Bypass via ICMLuaUtil Elevated COM Interface severity high T1548, T1548.002, T1559, T1559.001
- UAC Bypass via Windows Firewall Snap-In Hijack severity medium T1218, T1218.014, T1548, T1548.002
- Unusual Child Process from a System Virtual Process severity high T1055
- Unusual Child Process of dns.exe severity high T1190, T1210
- Unusual Child Processes of RunDLL32 severity high T1218, T1218.011
- Unusual Execution via Microsoft Common Console File severity high T1204, T1204.002, T1218, T1218.014, T1566, T1566.001
- Unusual Network Activity from a Windows System Binary severity medium T1036, T1036.005, T1127, T1127.001, T1218, T1218.002
- Unusual Network Connection via DllHost severity medium T1071, T1218
- Unusual Network Connection via RunDLL32 severity medium T1071, T1071.001, T1218, T1218.011
- Unusual Parent Process for cmd.exe severity medium T1059
- Unusual Parent-Child Relationship severity medium T1036, T1036.009, T1055, T1055.012, T1134, T1134.004
- Unusual Print Spooler Child Process severity medium T1068
- Unusual Process Execution on WBEM Path severity low building block T1036, T1036.005
- Unusual Process Execution Path - Alternate Data Stream severity medium T1564, T1564.004
- Unusual Process Extension severity low building block T1036, T1036.008
- Unusual Process For MSSQL Service Accounts severity low building block T1059, T1190, T1210, T1505, T1505.001
- Unusual Process Network Connection severity low T1127, T1218, T1218.003, T1218.008
- Unusual Service Host Child Process - Childless Service severity medium T1055, T1055.012
- User Account Creation severity low T1136, T1136.001, T1136.002
- Veeam Backup Library Loaded by Unusual Process severity medium T1003, T1059, T1059.001, T1555
- Volume Shadow Copy Deleted or Resized via VssAdmin severity high T1490
- Volume Shadow Copy Deletion via PowerShell severity high T1047, T1059, T1059.001, T1490
- Volume Shadow Copy Deletion via WMIC severity high T1047, T1490
- Whoami Process Activity severity low T1033, T1069
- Windows Account or Group Discovery severity low building block T1033, T1069, T1069.001, T1069.002, T1087, T1087.001
- Windows Defender Exclusions Added via PowerShell severity medium T1059, T1059.001, T1685
- Windows Firewall Disabled via PowerShell severity medium T1059, T1059.001, T1685, T1686
- Windows Installer with Suspicious Properties severity low building block T1218, T1218.007
- Windows Network Enumeration severity medium building block T1018, T1039, T1135
- Windows Sandbox with Sensitive Configuration severity medium T1564, T1564.006
- Windows Script Executing PowerShell severity low T1059, T1059.001, T1059.005, T1059.007, T1566, T1566.001
- Windows Script Execution from Archive severity medium T1059, T1059.005, T1059.007, T1204, T1204.002
- Windows Script Interpreter Executing Process via WMI severity medium T1047, T1059, T1059.005, T1059.007, T1566, T1566.001
- Windows Server Update Service Spawning Suspicious Processes severity high T1059, T1059.001, T1059.003, T1190, T1218, T1218.011
- Windows Subsystem for Linux Enabled via Dism Utility severity medium T1202
- Windows System Information Discovery severity low building block T1047, T1059, T1059.003, T1082
- Wireless Credential Dumping using Netsh Command severity high T1003, T1016, T1082, T1552, T1552.001, T1555
- WMI Incoming Lateral Movement severity medium T1021, T1021.003, T1047
- WMI WBEMTEST Utility Execution severity low building block T1047
- WMIC Remote Command severity low building block T1021, T1021.003, T1021.006, T1047
Splunk (789)
- .msc Executed from Unusual Location (Windows Event Log) T1218, T1218.014
- 1 or 2 Character Executable (Windows Event Log) T1036, T1059
- 3CXDesktopApp.exe Execution (Windows Event Log) T1195, T1204, T1204.002, T1218
- 7zip CommandLine To SMB Share Path T1560, T1560.001
- Abuse EQNEDT32.EXE (Windows Event Log) T1203
- Access Common Package Config file (Windows Event Log) T1546
- Account Password Changed from Command Line - Windows (Windows Event Log) T1531
- Account set to active via Net.exe (Windows Event Log) T1078, T1078.001, T1098
- Add or Set Windows Defender Exclusion severity medium T1685
- ADExplorer Execution (Windows Event Log) T1003, T1003.003, T1552, T1552.001
- ADExplorer Snapshot Creation (Windows Event Log) T1003, T1003.003, T1552, T1552.001
- Adfind Commands (Windows Event Log) T1016, T1018, T1069, T1069.002, T1087, T1087.002
- Adfind Execution (Windows Event Log) T1016, T1018, T1069, T1069.002, T1087, T1087.002
- Advanced IP or Port Scanner Execution severity low T1046, T1135
- Advanced IP Scanner Execution (Windows Event Log) T1046
- Advanced Port Scanner Execution (Windows Event Log) T1046
- Allow File And Printing Sharing In Firewall severity medium T1686, T1686.001
- Allow Network Discovery In Firewall severity medium T1686, T1686.001
- Anomalous usage of 7zip severity low T1560, T1560.001
- AnyDesk Command Line Execution (Windows Event Log) T1219
- AnyDesk Execution from Suspicious Folder (Windows Event Log) T1219
- AnyDesk Silent Install (Windows Event Log) T1219
- Application Discovery - Windows (Windows Event Log) T1518
- ATBroker.exe Execution (Windows Event Log) T1218
- Attacker Tools On Endpoint severity medium T1003, T1036, T1036.005, T1595
- Attempted Veeam Database Credential Dump (Windows Event Log) T1552, T1552.001
- Attrib.exe Metasploit File Dropper (Windows Event Log) T1564
- AutoHotkey Execution (Windows Event Log) T1059
- AutoIt Execution (Windows Event Log) T1059
- Bash -c Execution - Windows (Windows Event Log) T1216, T1218
- Bcdedit Command Back To Normal Mode Boot severity medium T1490
- BCDEdit Failure Recovery Modification severity medium T1490
- BITS Job Persistence severity medium T1197
- BITSAdmin Download File severity medium T1105, T1197
- BITSadmin Execution (Windows Event Log) T1048, T1048.003, T1105, T1197, T1570
- BitsAdmin NetCat PowerCat File Transfer (Windows Event Log) T1071, T1071.002, T1197
- Browser Started with Remote Debugging - Windows (Windows Event Log) T1185
- CDB Execution (Windows Event Log) T1127
- Certificate Abuse - Windows (Windows Event Log) T1649
- Certificate Enumeration - Windows (Windows Event Log) T1649
- Certutil De-Obfuscate_Decode Files (Windows Event Log) T1140
- Certutil exe certificate extraction severity medium T1649
- Certutil Execution (Windows Event Log) T1027, T1105, T1132, T1140
- Certutil File Download (Windows Event Log) T1027, T1105
- Certutil Obfuscate_Encode Files (Windows Event Log) T1027, T1132
- Certutil Root Certificate Install (Windows Event Log) T1553, T1553.004
- CertUtil With Decode Argument severity medium T1140
- Change To Safe Mode With Network Config severity medium T1490
- Check Elevated CMD using whoami severity medium T1033
- Child Processes of Spoolsv exe severity medium T1068
- Cipher.exe Execution (Windows Event Log) T1485
- Clear Unallocated Sector Using Cipher App severity medium T1070, T1070.004
- Clop Common Exec Parameter severity medium T1204
- CMD Carry Out String Command Parameter T1059, T1059.003
- CMD Echo Pipe - Escalation severity medium T1059, T1059.003, T1543, T1543.003
- CMD execution with _c (Windows Event Log) T1059, T1059.003
- Cmstp Execution (Windows Event Log) T1218, T1218.003
- Command Line .cmd Execution (Windows Event Log) T1059, T1059.003
- Command Line Homoglyphs - Windows (Windows Event Log) T1027, T1027.010
- Command Line lsass request (Windows Event Log) T1003
- Command Line Spawned by Archive Utility - Windows (Windows Event Log) T1059, T1204, T1204.002
- Command Line Utility Added to Accessibility Features (Windows Event Log) T1059, T1546, T1546.008
- Command Output Redirected to Localhost (Windows Event Log) T1059, T1074
- Command-Line Interface Execution (Windows Event Log) T1059, T1059.001, T1059.003
- Common Active Directory Commands (Windows Event Log) T1007, T1087, T1087.002
- Common LSASS Memory Dump Behavior (Windows Event Log) T1003, T1003.001
- Common Recon Commands in Short Burst (Windows Event Log) T1007, T1033, T1049, T1057, T1082, T1087
- Common Reconnaissance Commands (Windows Event Log) T1007, T1033, T1057, T1059, T1059.003, T1059.004
- Compressed File Execution (Windows Event Log) T1027
- ComputerDefaults UAC Bypass (Windows Event Log) T1548, T1548.002
- comsvcs.dll Lsass Memory Dump (Windows Event Log) T1003, T1003.001
- Conhost.exe Kernel call (Windows Event Log) T1059, T1202, T1211
- Consent.exe Suspicious Child Process (Windows Event Log) T1059, T1068
- ConsentPromptBehaviorAdmin Registry Value Modified (Windows Event Log) T1548, T1548.002
- Conti Common Exec parameter severity medium T1204
- Control Loading from World Writable Directory severity medium T1218, T1218.002
- Control Panel Abuse (Windows Event Log) T1218, T1218.002
- Control_RunDLL Call from Command Line (Windows Event Log) T1218, T1218.002, T1218.011
- Create or delete windows shares using net exe severity medium T1070, T1070.005
- Create_Add Local_Domain User (Windows Event Log) T1098, T1136, T1136.001, T1136.002
- Create_Modify Schtasks (Windows Event Log) T1053, T1053.005
- Creation of Shadow Copy severity medium T1003, T1003.003
- Creation of Shadow Copy with wmic and powershell severity medium T1003, T1003.003
- Credential Dumping via Copy Command from Shadow Copy severity medium T1003, T1003.003
- Credential Dumping via Symlink to Shadow Copy severity medium T1003, T1003.003
- Credentials in Registry (Windows Event Log) T1552, T1552.002
- CSC Execution (Windows Event Log) T1027, T1027.004
- CSC Net On The Fly Compilation T1027, T1027.004
- CSVDE Export Active Directory (Windows Event Log) T1087, T1087.001, T1087.002
- Curl Execution with Percent Encoded URL severity low T1027, T1105
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Windows Event Log) T1204, T1204.002
- Data Exfiltration via AWS CLI - Windows (Windows Event Log) T1567
- Data Staged to File (Windows Event Log) T1074, T1074.001
- Defender Registry Values Modified (Windows Event Log) T1112, T1685
- Deleting Shadow Copies severity medium T1490
- Detect AzureHound Command-Line Arguments severity medium T1069, T1069.001, T1069.002, T1087, T1087.001, T1087.002
- Detect Certify Command Line Arguments severity medium T1105, T1649
- Detect HTML Help Renamed T1218, T1218.001
- Detect HTML Help Spawn Child Process severity medium T1218, T1218.001
- Detect HTML Help URL in Command Line severity medium T1218, T1218.001
- Detect HTML Help Using InfoTech Storage Handlers severity medium T1218, T1218.001
- Detect mshta inline hta execution severity medium T1218, T1218.005
- Detect mshta renamed T1218, T1218.005
- Detect MSHTA Url in Command Line severity medium T1218, T1218.005
- Detect Path Interception By Creation Of program exe severity medium T1574, T1574.009
- Detect Prohibited Applications Spawning cmd exe T1059, T1059.003
- Detect PsExec With accepteula Flag severity medium T1021, T1021.002
- Detect Rare Executables severity low T1204
- Detect RClone Command-Line Usage severity medium T1020
- Detect Regasm Spawning a Process severity medium T1218, T1218.009
- Detect Regasm with no Command Line Arguments severity medium T1218, T1218.009
- Detect Regsvcs Spawning a Process severity medium T1218, T1218.009
- Detect Regsvcs with No Command Line Arguments severity medium T1218, T1218.009
- Detect Regsvr32 Application Control Bypass severity medium T1218, T1218.010
- Detect Remote Access Software Usage Process severity low T1219
- Detect Renamed 7-Zip T1560, T1560.001
- Detect Renamed PSExec T1569, T1569.002
- Detect Renamed RClone T1020
- Detect Renamed WinRAR T1560, T1560.001
- Detect RTLO In Process severity medium T1036, T1036.002
- Detect Rundll32 Inline HTA Execution severity medium T1218, T1218.005
- Detect SharpHound Command-Line Arguments severity medium T1069, T1069.001, T1069.002, T1087, T1087.001, T1087.002
- Detect SharpHound Usage severity medium T1069, T1069.001, T1069.002, T1087, T1087.001, T1087.002
- Detect Use of cmd exe to Launch Script Interpreters severity low T1059, T1059.003
- Detection of tools built by NirSoft severity low T1072
- Disable Logs Using WevtUtil severity medium T1685, T1685.005
- Disable Schedule Task severity low T1685
- Disabled Pre-Authentication Accounts Discovery - PowerShell (Sysmon) T1087, T1133
- Disabled Pre-Authentication Accounts Discovery - PowerShell (Windows Event Log) T1087, T1133
- Disabling Firewall with Netsh severity low T1685
- Discovery using CHCP (Windows Event Log) T1614, T1614.001
- DLL Called with RS32 (Windows Event Log) T1218, T1218.011
- DLL Called with Uncommon Function (Windows Event Log) T1218, T1218.011
- DLL Concatenation (Windows Event Log) T1027, T1027.001, T1036
- DLL Execution from Uncommon Process (Windows Event Log) T1218, T1218.011
- DLLRegisterServer Called from Command Line (Windows Event Log) T1218, T1218.011
- DNS Exfiltration Using Nslookup App severity medium T1048
- DNX.exe Proxy Execution (Windows Event Log) T1218
- Domain Account Discovery with Dsquery severity low T1087, T1087.002
- Domain Account Discovery with Wmic severity medium T1087, T1087.002
- Domain Controller Discovery with Nltest severity medium T1018
- Domain Controller Discovery with Wmic T1018
- Domain Controller Enumeration via nltest (Windows Event Log) T1016, T1018
- Domain Group Discovery With Dsquery severity low T1069, T1069.002
- Domain Group Discovery With Wmic T1069, T1069.002
- Domain Trust Discovery Commands - Windows (Windows Event Log) T1482
- Dotnet.exe Execution (Windows Event Log) T1218
- Driver as Command Parameter (Windows Event Log) T1068, T1218
- DSQuery Domain Discovery severity medium T1482
- Dump File Identified (Windows Event Log) T1003
- Dump LSASS via comsvcs DLL severity medium T1003, T1003.001
- Dump LSASS via procdump severity medium T1003, T1003.001
- Dxcap Proxy Execution (Windows Event Log) T1218
- Elevated Group Discovery With Wmic severity medium T1069, T1069.002
- EnableLUA Registry Value Modified (Windows Event Log) T1548, T1548.002
- Encoded Powershell Command (Windows Event Log) T1027, T1059, T1059.001
- Esentutl Execution (Windows Event Log) T1003, T1003.002, T1003.003, T1105, T1564, T1570
- Esentutl SAM Copy T1003, T1003.002
- Event Logs Queried for RDP Sessions (Windows Event Log) T1082
- Excessive Attempt To Disable Services severity low T1489
- Excessive distinct processes from Windows Temp severity low T1059
- Excessive number of service control start as disabled severity low T1685
- Excessive number of taskhost processes severity low T1059
- Excessive Usage Of Cacls App severity low T1222
- Excessive Usage of NSLOOKUP App severity low T1048
- Excessive Usage Of Taskkill severity low T1685
- Executable Create Script Process (Windows Event Log) T1020, T1059, T1059.003, T1119
- Executable Process from Suspicious Folder (Windows Event Log) T1059, T1059.005, T1059.007, T1204, T1218, T1218.011
- Execute Javascript With Jscript COM CLSID severity medium T1059, T1059.005
- Execution from Startup Folder (Windows Event Log) T1547, T1547.001
- Execution of File with Multiple Extensions severity medium T1036, T1036.003
- Exfiltration via curl.exe - Windows (Windows Event Log) T1048
- Expand.exe Execution (Windows Event Log) T1105, T1564, T1564.004
- File and Directory Discovery Output to File - Windows (Windows Event Log) T1083
- File Download or Read to Pipe Execution severity medium T1105
- File Executed from INetCache (Windows Event Log) T1105
- File_Folder Hidden - Windows (Windows Event Log) T1222, T1222.001
- Finger Execution (Windows Event Log) T1105
- Firewall Allowed Program Enable severity low T1686
- First Time Seen Child Process of Zoom severity low T1068
- FodHelper UAC Bypass severity medium T1112, T1548, T1548.002
- FScan.exe Network Scan (Windows Event Log) T1018, T1046
- Fsutil fsinfo execution (Windows Event Log) T1120
- Fsutil Zeroing File severity medium T1070
- Full Control Permissions Granted to Everyone - Windows (Windows Event Log) T1222, T1222.001
- Get ADDefaultDomainPasswordPolicy with Powershell T1201
- Get ADUser with PowerShell T1087, T1087.002
- Get ADUserResultantPasswordPolicy with Powershell severity medium T1201
- Get DomainPolicy with Powershell severity medium T1201
- Get DomainUser with PowerShell severity medium T1087, T1087.002
- Get WMIObject Group Discovery T1069, T1069.001
- Get-DomainTrust with PowerShell severity medium T1482
- Get-ForestTrust with PowerShell severity medium T1482
- GetAdComputer with PowerShell T1018
- GetAdGroup with PowerShell T1069, T1069.002
- GetCurrent User with PowerShell T1033
- GetDomainComputer with PowerShell severity medium T1018
- GetDomainController with PowerShell T1018
- GetDomainGroup with PowerShell severity medium T1069, T1069.002
- GetLocalUser with PowerShell T1087, T1087.001
- GetNetTcpconnection with PowerShell T1049
- GetWmiObject Ds Computer with PowerShell severity low T1018
- GetWmiObject Ds Group with PowerShell severity low T1069, T1069.002
- GetWmiObject DS User with PowerShell severity low T1087, T1087.002
- GetWmiObject User Account with PowerShell T1087, T1087.001
- Git Spawns System32 Process (Windows Event Log) T1059
- Git Submodule Cloned - Windows (Windows Event Log) T1105
- Go Run Execution (Windows Event Log) T1059
- Group Policy Editor Execution (Windows Event Log) T1218, T1218.014
- Headless Browser Mockbin or Mocky Request severity medium T1564, T1564.003
- Headless Browser Usage severity low T1497, T1564, T1564.003
- hh.exe Execution (Windows Event Log) T1218, T1218.001
- hh.exe Remote File Execution (Windows Event Log) T1218, T1218.001
- Hidden User Created - Windows (Windows Event Log) T1564, T1564.002
- Hiding Files And Directories With Attrib exe severity medium T1222, T1222.001
- HTTP_HTTPS Default Security Zone Modified to Local Machine (Windows Event Log) T1112
- Hunting 3CXDesktopApp Software T1195, T1195.002
- Icacls Deny Command severity low T1222
- ICACLS Grant Command severity low T1222
- IcedID Discovery Commands (Windows Event Log) T1069, T1069.002, T1082, T1087, T1119, T1135
- IIS Worker (W3WP) Spawn Command Line (Windows Event Log) T1218, T1505, T1505.004
- Impacket atexec.py Execution (Windows Event Log) T1027, T1053, T1053.005, T1059, T1059.003
- Impacket Lateral Movement Activity (Windows Event Log) T1021, T1021.002, T1210
- Impacket Lateral Movement Commandline Parameters severity medium T1021, T1021.002, T1021.003, T1047, T1543, T1543.003
- Impacket Lateral Movement smbexec CommandLine Parameters severity medium T1021, T1021.002, T1021.003, T1047, T1543, T1543.003
- Impacket Lateral Movement WMIExec Commandline Parameters severity medium T1021, T1021.002, T1021.003, T1047, T1543, T1543.003
- Impacket PSexec (Windows Event Log) T1021, T1569, T1569.002
- Impacket SMBexec (Windows Event Log) T1021, T1021.006, T1059, T1569, T1569.002
- Impacket_Empire's WMIExec (Windows Event Log) T1047, T1059, T1059.001
- Indirect Command Execution (Windows Event Log) T1202, T1548
- Invoke-DCOM.ps1 - PowerShell (Windows Event Log) T1021, T1021.003
- Invoke-Expression Command (Windows Event Log) T1059, T1059.001
- Invoke-WebRequest Command (Windows Event Log) T1059, T1059.001, T1105
- Known Process Injection Commands (Windows Event Log) T1055
- Live Sysinternals Execution (Windows Event Log) T1105
- Local Account Discovery With Wmic T1087, T1087.001
- LocalAccountTokenFilterPolicy Registry Value Modified (Windows Event Log) T1112, T1550, T1550.002
- Locate Credentials (Windows Event Log) T1552, T1552.001
- Logon Script Registry Key added (Windows Event Log) T1037, T1037.001
- LSA Authentication Packages Registry Key Modified (Windows Event Log) T1547, T1547.002
- Malicious Document Execution (Windows Event Log) T1204, T1204.001, T1204.002, T1566, T1566.001
- Malicious PowerShell Process - Encoded Command T1027
- Malicious PowerShell Process - Execution Policy Bypass severity low T1059, T1059.001
- masscan Execution - Windows (Windows Event Log) T1046
- Mavinject Execution (Windows Event Log) T1055, T1055.001, T1056, T1056.004, T1218
- Mega Utility Execution - Windows (Windows Event Log) T1567
- Microsoft Build Engine Suspicious Parent Process (Windows Event Log) T1059, T1059.001, T1059.003, T1059.005, T1127, T1127.001
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (Windows Event Log) T1204
- Microsoft SQL Server Suspicious Child Process - Windows (Windows Event Log) T1190, T1505, T1505.001
- Mimikatz (Windows Event Log) T1003, T1003.001, T1003.002, T1003.004, T1003.006, T1552
- Mimikatz Execution (Windows Event Log) T1003, T1552
- Mimikatz PassTheTicket CommandLine Parameters severity medium T1550, T1550.003
- Mmc LOLBAS Execution Process Spawn severity medium T1021, T1021.003, T1218, T1218.014
- Mock System Directory - Windows (Windows Event Log) T1036, T1548, T1548.002
- Modify ACL permission To Files Or Folder severity low T1222
- Modify Windows Defender (Windows Event Log) T1685
- MSBuild Suspicious Spawned By Script Process severity medium T1127, T1127.001
- Mshta spawning Rundll32 OR Regsvr32 Process severity medium T1218, T1218.005
- MSHTA.exe execution (Windows Event Log) T1218, T1218.005
- mshta.exe File Download (Windows Event Log) T1105, T1218, T1218.005
- MSI Installation via Appcert (Windows Event Log) T1218, T1218.007
- Msiexec Abuse (Windows Event Log) T1218, T1218.007
- MSIExec.exe Execution (Windows Event Log) T1218, T1218.007
- MSTSC Execution (Windows Event Log) T1021, T1021.001
- Msxsl Execution (Windows Event Log) T1220
- MultiDump.exe Execution (Windows Event Log) T1003, T1003.001, T1003.002
- Multiple nslookup commands (Windows Event Log) T1016, T1018
- Native Archive Commands (Windows Event Log) T1074, T1074.001, T1560
- Net.exe Use with URL (Windows Event Log) T1021, T1021.002
- Network Connection Discovery With Arp T1049
- Network Connection Discovery With Netstat T1049
- Network Discovery Using Route Windows App T1016, T1016.001
- New AutoRun Registry Key (Windows Event Log) T1547, T1547.001
- ngen.exe File Download (Windows Event Log) T1105
- ngrok Execution - Windows (Windows Event Log) T1572
- NirCmd Execution (Windows Event Log) T1059, T1070, T1113
- Nishang PowershellTCPOneLine severity medium T1059, T1059.001
- NLTest Domain Trust Discovery severity medium T1482
- NMAP Execution (Windows Event Log) T1018
- Non-MSIExec .msi Installation (Windows Event Log) T1059
- Notepad with no Command Line Arguments severity medium T1055
- Nslookup Execution (Windows Event Log) T1016, T1218
- ntds.dit Access from Unexpected Location (Windows Event Log) T1003, T1003.003
- ntds.dit Command Line (Windows Event Log) T1003, T1003.003
- Ntdsutil Export NTDS severity medium T1003, T1003.003
- NTDSUtil.exe execution (Windows Event Log) T1003, T1003.003
- Office Binary Download Remote File (Windows Event Log) T1105
- Office Spawns Suspicious Child Process (Windows Event Log) T1204, T1204.002
- Output to File (Windows Event Log) T1036, T1059, T1059.003, T1074, T1074.001
- Package installation (Windows Event Log) T1105
- Parent in Public Folder Suspicious Process (Windows Event Log) T1059, T1564
- Permission Groups Discovery: Domain Groups (Windows Event Log) T1069, T1069.002
- Permission Groups Discovery: Local Groups (Windows Event Log) T1069
- Permission Modification using Takeown App severity low T1222
- Permissions Replaced by icacls - Windows (Windows Event Log) T1222, T1222.001
- Possible Browser Pass View Parameter T1555, T1555.003
- Possible Credential Dumping via Windows Network Providers (Windows Event Log) T1003, T1112
- Potential AutoHotkey .ahk Execution (Windows Event Log) T1059
- Potential Cryptomining Commands (Windows Event Log) T1496
- Potential CVE-2023-23397 (Windows Event Log) T1048, T1048.003, T1055, T1055.001
- Potential Executable Masquerading as Document - Windows (Windows Event Log) T1036, T1036.007
- Potential fodhelper UAC Bypass Attempt (Windows Event Log) T1548, T1548.002
- Potential LSA password filter (Windows Event Log) T1547, T1547.002, T1556, T1556.002
- Potential Ping Sweep (Windows Event Log) T1018
- Potential PowerShell Post-Exploitation Activity (Windows Event Log) T1059, T1059.001, T1082, T1087
- Potential Proxy Malware via AutoRun Key (Windows Event Log) T1059, T1059.001, T1547, T1547.001
- Potential Sysinternals Tool Execution (Windows Event Log) T1218
- Potential System Network Configuration Discovery Activity severity low T1016
- Potential Telegram API Request Via CommandLine severity low T1041, T1102, T1102.002
- PowerHuntShares Commands (Windows Event Log) T1018, T1087, T1135
- PowerShell CreateDecryptor (Windows Event Log) T1027, T1059, T1059.001
- Powershell Defender Threat Actions Set to Allow severity medium T1059, T1059.001
- Powershell Disable Security Monitoring severity medium T1685
- PowerShell Downgrade (Sysmon) T1059, T1059.001, T1059.003
- PowerShell Downgrade (Windows Event Log) T1059, T1059.001, T1059.003
- PowerShell DownloadFile_DownloadString (Windows Event Log) T1059, T1059.001, T1105
- PowerShell Get LocalGroup Discovery T1069, T1069.001
- PowerShell Hidden Window (Windows Event Log) T1059, T1564, T1564.003
- PowerShell Modifying Registry Values (Windows Event Log) T1059, T1059.001, T1112
- PowerShell Start-BitsTransfer severity medium T1197
- PowerShell XML Retrieval (Windows Event Log) T1059, T1059.001
- Prevent Automatic Repair Mode using Bcdedit severity medium T1490
- ProcDump Credential Harvest (Windows Event Log) T1003, T1003.001
- Process Creation Using Sysnative Folder (Windows Event Log) T1218
- Process Executed from Downloads Folder - Windows (Windows Event Log) T1204
- Process Executed with Null Command Line (Windows Event Log) T1055
- Process Execution From Suspicious Folder (Windows Event Log) T1036
- Process Execution via WMI severity medium T1047
- Process Kill Base On File Path severity medium T1685
- PromptOnSecureDesktop Registry Value Modified (Windows Event Log) T1548, T1548.002
- ProtocolHandler.exe File Download (Windows Event Log) T1105
- Proxy Execution via Appcert (Windows Event Log) T1127
- PuTTY Secure Copy Client Execution (Windows Event Log) T1048
- pypykatz commands (Windows Event Log) T1003, T1003.001
- Python Execution (Windows Event Log) T1059, T1059.006
- QEMU Network Tunneling - Windows (Windows Event Log) T1095, T1572
- Query Registry (Windows Event Log) T1012
- Radmin execution (Windows Event Log) T1072
- Rare executable from Microsoft Office (Windows Event Log) T1204, T1204.002
- Rare Process Execution (Windows Event Log) T1059, T1059.003, T1204, T1204.002
- Rclone Execution (Windows Event Log) T1030, T1048, T1048.003, T1567, T1567.002
- RDP Enabled (Windows Event Log) T1021, T1021.001, T1112
- RDP File Executed from Outlook Temp Directory (Windows Event Log) T1021, T1021.001, T1566, T1566.001
- RDP Hijacking (Windows Event Log) T1133, T1563, T1563.002
- RdrLeakDiag.exe Memory Dump (Windows Event Log) T1003, T1003.001
- Read-Only Attribute Removed - Windows (Windows Event Log) T1222, T1222.001
- Recursive Delete of Directory In Batch CMD severity medium T1070, T1070.004
- Reg exe Manipulating Windows Services Registry Keys severity medium T1574, T1574.011
- Reg.exe Process Execution (Windows Event Log) T1012, T1112
- Regini.exe Execution (Windows Event Log) T1112
- Registry key added with reg.exe (Windows Event Log) T1112
- regsvr32 Execution (Windows Event Log) T1218, T1218.010
- regsvr32 Referencing Unusual Paths (Windows Event Log) T1218, T1218.010
- Regsvr32 Silent and Install Param Dll Loading severity low T1218, T1218.010
- Remote .msi Installation (Windows Event Log) T1218, T1218.007
- Remote .msi Installation (Windows Event Log) T1218, T1218.007
- Remote Access Software Execution (Windows Event Log) T1219
- Remote Admin Tools (Windows Event Log) T1021, T1059, T1059.003, T1569, T1569.002, T1570
- Remote Desktop Process Running On System T1021, T1021.001
- Remote Process Instantiation via DCOM and PowerShell severity medium T1021, T1021.003
- Remote Process Instantiation via WinRM and PowerShell severity medium T1021, T1021.006
- Remote Process Instantiation via WinRM and Winrs severity medium T1021, T1021.006
- Remote Process Instantiation via WMI severity medium T1047
- Remote Process Instantiation via WMI and PowerShell severity medium T1047
- Remote Share Directory Listing - Windows (Windows Event Log) T1083
- Remote System Discovery with Dsquery severity low T1018
- Remote System Discovery with Wmic severity medium T1018
- Remote WMI Command Attempt severity medium T1047
- Remote WMIC Query (Windows Event Log) T1047
- Resize ShadowStorage volume severity medium T1490
- Revil Common Exec Parameter severity medium T1204
- Rubeus Command Line Parameters severity medium T1550, T1550.003, T1558, T1558.003, T1558.004
- Rubeus Commands (Windows Event Log) T1558, T1558.001, T1558.002, T1558.003
- Runas Execution in CommandLine T1134, T1134.001
- RunDLL Loading DLL By Ordinal severity medium T1218, T1218.011
- Rundll32 Command Line (Windows Event Log) T1218, T1218.011
- Rundll32 Control RunDLL Hunt T1218, T1218.011
- Rundll32 Control RunDLL World Writable Directory severity medium T1218, T1218.011
- Rundll32 LockWorkStation severity low T1218, T1218.011
- Rundll32 Shimcache Flush severity medium T1112
- Rundll32 Spawned by Disk Cleanup (Windows Event Log) T1546, T1546.015
- Rundll32 Suspicious Command Line (Windows Event Log) T1218, T1218.011
- rundll32 Suspicious Parent Process (Windows Event Log) T1218, T1218.011
- rundll32 with No DLL in Command Line (Windows Event Log) T1218, T1218.011
- Rundll32.exe as Parent Process (Windows Event Log) T1218, T1218.011
- rundll32.exe Executing DLL from Non-standard Directory (Windows Event Log) T1218, T1218.011
- Ryuk Wake on LAN Command severity medium T1059, T1059.003
- Scheduled Task Creation on Remote Endpoint using At severity medium T1053, T1053.002
- Scheduled Task Deleted Or Created via CMD severity low T1053, T1053.005
- Scheduled Task Initiation on Remote Endpoint severity medium T1053, T1053.005
- Scheduled Task with Potential SSH Tunnel - Windows (Windows Event Log) T1053, T1572
- Schtasks Run Task On Demand severity low T1053
- Schtasks scheduling job on remote system severity medium T1053, T1053.005
- Schtasks used for forcing a reboot severity medium T1053, T1053.005
- Script Execution via WMI severity medium T1047
- Sdelete Application Execution severity medium T1070, T1070.004, T1485
- SecretDumps Offline NTDS Dumping Tool severity medium T1003, T1003.003
- Security Software Discovery via Findstr.exe (Windows Event Log) T1518, T1518.001
- Security Software Discovery via WMI (Windows Event Log) T1518, T1518.001
- Service Stop Commands (Windows Event Log) T1489, T1685
- ServicePrincipalNames Discovery with SetSPN severity medium T1558, T1558.003
- Services Escalate Exe severity medium T1548
- Services LOLBAS Execution Process Spawn severity medium T1543, T1543.003
- Shell Spawned by Web Server - Windows (Windows Event Log) T1218, T1505, T1505.003, T1505.004
- Shim Database Installation With Suspicious Parameters severity medium T1546, T1546.011
- SimpleHelp Remote Access Tool Execution (Windows Event Log) T1219
- Single Letter Process On Endpoint severity medium T1204, T1204.002
- Sliver C2 Implant Activity Pattern (Windows Event Log) T1059
- SLUI RunAs Elevated severity medium T1548, T1548.002
- SLUI Spawning a Process severity medium T1548, T1548.002
- SoftPerfect Network Scanner Execution (Windows Event Log) T1046
- Spoolsv Spawning Rundll32 severity medium T1547, T1547.012
- Spoolsv Writing a DLL severity medium T1547, T1547.012
- ssh.exe Execution (Windows Event Log) T1202, T1572
- Startup Folder Location Modified - Windows (Windows Event Log) T1547, T1547.001
- Suspicious AteraAgent Installation - Windows (Windows Event Log) T1219
- Suspicious Child Process for hh.exe (Windows Event Log) T1218, T1218.001
- Suspicious Child Process for lsass.exe (Windows Event Log) T1036, T1036.004, T1055
- Suspicious Child Process for mshta.exe (Windows Event Log) T1059, T1218, T1218.005
- Suspicious ComputerDefaults.exe Execution (Windows Event Log) T1548, T1548.002
- Suspicious Confluence Child Process - Windows (Windows Event Log) T1190
- Suspicious Conhost.exe Commands (Windows Event Log) T1202, T1211
- Suspicious Copy on System32 severity low T1036, T1036.003
- Suspicious csc.exe Source File Folder (Windows Event Log) T1027, T1027.004
- Suspicious Curl Network Connection severity medium T1105
- Suspicious DLLhost Execution (Windows Event Log) T1546, T1546.015
- Suspicious DLLHost no Command Line Arguments severity medium T1055
- Suspicious Executable by CMD.exe (Windows Event Log) T1059
- Suspicious Executable by Powershell (Windows Event Log) T1059, T1059.001, T1059.003
- Suspicious Execution of Accessibility Tool Debuggers (Windows Event Log) T1546, T1546.008
- Suspicious Execution via Microsoft Common Console (Windows Event Log) T1218, T1218.014
- Suspicious GPUpdate no Command Line Arguments severity medium T1055
- Suspicious IcedID Rundll32 Cmdline severity medium T1218, T1218.011
- Suspicious InprocServer32 Registry Modification (Windows Event Log) T1546, T1546.015
- Suspicious microsoft workflow compiler rename T1036, T1036.003, T1127
- Suspicious microsoft workflow compiler usage severity medium T1127
- Suspicious msbuild path severity medium T1036, T1036.003, T1127, T1127.001
- Suspicious MSBuild Rename T1036, T1036.003, T1127, T1127.001
- Suspicious MSBuild Spawn severity medium T1127, T1127.001
- Suspicious mshta child process severity medium T1218, T1218.005
- Suspicious mshta spawn severity medium T1218, T1218.005
- Suspicious ntds.dit Commands (Windows Event Log) T1003, T1003.003
- Suspicious Parent Process for lsass.exe or services.exe (Windows Event Log) T1036, T1036.004, T1055
- Suspicious Parent Process for msiexec.exe (Windows Event Log) T1218, T1218.007
- Suspicious Parent Process for spoolsv.exe (Windows Event Log) T1036, T1036.004, T1055
- Suspicious PlistBuddy Usage severity medium T1543, T1543.001
- Suspicious PowerShell Clipboard Activity (Windows Event Log) T1059, T1059.001, T1115
- Suspicious PowerShell Parameter Substring (Windows Event Log) T1059, T1059.001
- Suspicious Process Executed From Container File severity medium T1036, T1036.008, T1204, T1204.002
- Suspicious process Spawned by Java (Windows Event Log) T1203
- Suspicious Reg exe Process severity low T1112
- Suspicious Regsvr32 Register Suspicious Path severity medium T1218, T1218.010
- Suspicious Rundll32 dllregisterserver severity medium T1218, T1218.011
- Suspicious Rundll32 no Command Line Arguments severity medium T1218, T1218.011
- Suspicious Rundll32 PluginInit severity medium T1218, T1218.011
- Suspicious Rundll32 StartW severity medium T1218, T1218.011
- Suspicious Scheduled Task from Public Directory severity low T1053, T1053.005
- Suspicious SearchProtocolHost no Command Line Arguments severity medium T1055
- Suspicious SQLite3 LSQuarantine Behavior severity medium T1074
- Suspicious WAV file in Appdata Folder severity medium T1113
- Suspicious wevtutil Usage severity medium T1685, T1685.005
- Symbolic OR Hard File Link Created (Windows Event Log) T1204, T1204.002, T1547, T1547.009
- SyncAppvPublishingServer Execution (Windows Event Log) T1218
- System Enumeration with WMIC (Windows Event Log) T1047, T1082
- System Info Gathering Using Dxdiag Application T1592
- System Information Discovery - Windows (Windows Event Log) T1082
- System Information Discovery Detection severity medium T1082
- System Network Connections Discovery - Windows (Windows Event Log) T1049
- System Owner_User Discovery - Windows (Windows Event Log) T1033
- System Processes Run From Unexpected Locations severity low T1036, T1036.003
- System Time enumeration (Windows Event Log) T1124
- System User Discovery With Query T1033
- System User Discovery With Whoami T1033
- Task Manager lsass Dump (Windows Event Log) T1003, T1003.001
- Temporary File Executed from Public Folder (Windows Event Log) T1080, T1105
- Timestamp Manipulation (Windows Event Log) T1070, T1070.006
- Tunneling Process Created (Windows Event Log) T1095, T1572
- Uninstall App Using MsiExec severity medium T1218, T1218.007
- Unload Sysmon Filter Driver severity medium T1685
- Unusual AppCert Child Process (Windows Event Log) T1127
- Unusual svchost Child Process (Windows Event Log) T1055
- Unusual winlogon.exe Child Process (Windows Event Log) T1547, T1547.004
- Unusually Long Command Line severity low
- User Discovery With Env Vars PowerShell T1033
- User_Domain Enumeration Tool - Windows (Windows Event Log) T1087, T1087.002, T1136, T1136.002
- USN Journal Deletion severity medium T1070
- Utility Archive Data (Windows Event Log) T1560, T1560.001
- Verclsid CLSID Execution T1218, T1218.012
- Visio.exe File Download (Windows Event Log) T1105
- Visual Studio Code Tunnel Execution (Windows Event Log) T1071, T1071.001
- WBAdmin Delete System Backups severity medium T1490
- WDigest Forced Credential Caching (Windows Event Log) T1003, T1003.005, T1112
- WebDAV LNK Execution (Windows Event Log) T1059, T1059.001, T1059.003, T1204
- WebLogic CVE-2017-10271 (Windows Event Log) T1059, T1059.001, T1190
- Wermgr Process Spawned CMD Or Powershell Process severity medium T1059
- Windows - Service Stop (Windows Event Log) T1489, T1685
- Windows AdFind Exe severity medium T1018
- Windows Advanced Installer MSIX with AI_STUBS Execution severity medium T1204, T1204.002, T1218, T1553, T1553.005
- Windows Alternate DataStream - Process Execution severity medium T1564, T1564.004
- Windows Apache Benchmark Binary severity low T1059
- Windows AppCertDLL Modification Via Command Line severity low T1546, T1546.009
- Windows Application Whitelisting Bypass Attempt via Rundll32 severity medium T1218, T1218.011
- Windows Archive Collected Data via Rar severity low T1560, T1560.001
- Windows Attempt To Stop Security Service severity medium T1685
- Windows Audit Policy Auditing Option Disabled via Auditpol severity medium T1685, T1685.001
- Windows Audit Policy Cleared via Auditpol severity medium T1685, T1685.001
- Windows Audit Policy Disabled via Auditpol severity low T1685, T1685.001
- Windows Audit Policy Disabled via Legacy Auditpol severity low T1685, T1685.001
- Windows Audit Policy Excluded Category via Auditpol severity low T1685, T1685.001
- Windows Audit Policy Restored via Auditpol severity low T1685, T1685.001
- Windows Audit Policy Security Descriptor Tampering via Auditpol severity low T1685, T1685.001
- Windows AutoIt3 Execution severity medium T1059
- Windows Azure Storage Utility Execution Via CLI severity low T1567, T1567.002
- Windows Binary Proxy Execution Mavinject DLL Injection severity medium T1218, T1218.013
- Windows BitLocker Suspicious Command Usage severity medium T1486, T1490
- Windows BitLockerToGo Process Execution T1218
- Windows Bypass UAC via Pkgmgr Tool severity low T1548, T1548.002
- Windows Cabinet File Extraction Via Expand severity medium T1105
- Windows Cached Domain Credentials Reg Query severity low T1003, T1003.005
- Windows Certutil Root Certificate Addition severity medium T1587, T1587.003
- Windows Change File Association Command To Notepad severity medium T1546, T1546.001
- Windows Chrome Enable Extension Loading via Command-Line severity low T1185
- Windows Chromium Browser Launched with Small Window Size severity medium T1497
- Windows Chromium Browser No Security Sandbox Process severity medium T1497
- Windows Chromium Browser with Custom User Data Directory severity low T1497
- Windows Chromium process Launched with Disable Popup Blocking severity low T1497
- Windows Chromium Process Launched with Logging Disabled severity low T1497
- Windows Chromium Process Loaded Extension via Command-Line severity low T1185
- Windows Chromium Process with Disabled Extensions severity low T1497
- Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc severity low T1685
- Windows Cisco Secure Endpoint Unblock File Via Sfc severity low T1685
- Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc severity low T1685
- Windows Cmdline Tool Execution From Non-Shell Process severity low T1059, T1059.007
- Windows COM Hijacking InprocServer32 Modification severity medium T1546, T1546.015
- Windows Command and Scripting Interpreter Hunting Path Traversal T1059
- Windows Command and Scripting Interpreter Path Traversal Exec severity medium T1059
- Windows Command Obfuscation with Environment Variable Substrings severity low T1027, T1027.010
- Windows Compatibility Telemetry Suspicious Child Process severity medium T1053, T1053.005, T1546
- Windows ConHost with Headless Argument severity medium T1564, T1564.003, T1564.006
- Windows Copy Files (Windows Event Log) T1005, T1039, T1059
- Windows Create Local Administrator Account Via Net severity low T1136, T1136.001
- Windows Credential Dumping LSASS Memory Createdump severity medium T1003, T1003.001
- Windows Credentials from Password Stores Creation severity medium T1555
- Windows Credentials from Password Stores Deletion severity medium T1555
- Windows Credentials from Password Stores Query severity low T1555
- Windows Credentials in Registry Reg Query severity low T1552, T1552.002
- Windows Curl Download to Suspicious Path severity medium T1105
- Windows Curl Upload to Remote Destination severity medium T1105
- Windows Debugger Tool Execution T1036
- Windows Default Group Policy Object Modified with GPME severity medium T1484, T1484.001
- Windows Defender ASR or Threat Configuration Tamper severity medium T1685
- Windows Defender Disabled Detection (Windows Event Log) T1685
- Windows Delete or Modify System Firewall T1686
- Windows Devtunnels Execution severity low T1090
- Windows Dir Piped to Findstr Activity T1119
- Windows Disable Internet Explorer Addons severity low T1176, T1176.001
- Windows Disable or Modify Tools Via Taskkill severity low T1685
- Windows Disable Windows Event Logging Disable HTTP Logging severity medium T1505, T1505.004, T1685, T1685.001
- Windows DiskCryptor Usage T1486
- Windows Diskshadow Proxy Execution severity medium T1218
- Windows DISM Install PowerShell Web Access severity medium T1548, T1548.002
- Windows DISM Remove Defender severity medium T1685
- Windows DLL Search Order Hijacking with iscsicpl severity medium T1574, T1574.001
- Windows DLL Side-Loading Process Child Of Calc severity low T1574, T1574.001
- Windows DNS Gather Network Info severity low T1590, T1590.002
- Windows DotNet Binary in Non Standard Path severity medium T1036, T1036.003, T1218, T1218.004
- Windows EDRSilencer Execution severity low T1685
- Windows EFI Volume Mount Attempt Via Mountvol severity low T1204, T1204.002, T1542, T1688
- Windows Entra User Management Via Azure CLI severity low T1078, T1078.004, T1098, T1136
- Windows ESX Admins Group Creation via Net severity medium T1136, T1136.001, T1136.002
- Windows Eventlog Cleared Via Wevtutil severity low T1685, T1685.005
- Windows EventLog Recon Activity Using Log Query Utilities severity low T1654
- Windows Excel Spawning Microsoft Project Application severity low T1021, T1021.003
- Windows Excessive Service Stop Attempt severity medium T1489
- Windows Excessive Usage Of Net App severity low T1531
- Windows Execute Arbitrary Commands with MSDT severity medium T1218
- Windows Execution of Microsoft MSC File In Suspicious Path severity low T1218, T1218.014
- Windows Explorer LNK Exploit Process Launch With Padding severity medium T1059, T1059.001, T1204, T1204.002
- Windows Explorer.exe Spawning PowerShell or Cmd T1059, T1059.001, T1204, T1204.002
- Windows FFmpeg Audio and Video Device Discovery severity low T1125
- Windows FFmpeg DirectShow Video Capture severity low T1125
- Windows File and Directory Enable ReadOnly Permissions severity medium T1222, T1222.001
- Windows File and Directory Permissions Enable Inheritance T1222, T1222.001
- Windows File and Directory Permissions Remove Inheritance severity low T1222, T1222.001
- Windows File Association Modification via Ftype severity low T1059, T1059.003
- Windows File Collection Via Copy Utilities severity low T1119
- Windows File Download Via CertUtil severity medium T1105
- Windows File Download Via PowerShell severity low T1059, T1059.001, T1105
- Windows Files and Dirs Access Rights Modification Via Icacls severity low T1222, T1222.001
- Windows Findstr GPP Discovery severity medium T1552, T1552.006
- Windows Firewall Disabled (Windows Event Log) T1685, T1686
- Windows Firewall Rule Creation (Windows Event Log) T1685, T1686
- Windows FTP Exfiltration (Windows Event Log) T1048, T1071, T1071.002
- Windows Gdrive Binary Activity severity medium T1567
- Windows Get-Variable.EXE Execution from WindowsApps Folder severity low T1574, T1574.008
- Windows Global Object Access Audit List Cleared Via Auditpol severity medium T1685, T1685.001
- Windows Group Discovery Via Net T1069, T1069.001, T1069.002
- Windows Guest Account Enabled Via Net.EXE severity medium T1078, T1078.001
- Windows Identify Protocol Handlers T1059
- Windows IIS Components Add New Module severity low T1505, T1505.004
- Windows Impair Defense Add Xml Applocker Rules T1685
- Windows Indicator Removal Via Rmdir severity low T1070
- Windows Indirect Command Execution Via Series Of Forfiles severity low T1202
- Windows Information Discovery Fsutil severity low T1082
- Windows Ingress Tool Transfer Using Explorer severity low T1105
- Windows InstallUtil in Non Standard Path severity medium T1036, T1036.003, T1218, T1218.004
- Windows InstallUtil Uninstall Option severity medium T1218, T1218.004
- Windows InstallUtil URL in Command Line severity medium T1218, T1218.004
- Windows IOBit Unlocker Extension DLL Registration via Regsvr32 severity medium T1218, T1218.010
- Windows Ldifde Directory Object Behavior severity medium T1069, T1069.002, T1105
- Windows List ENV Variables Via SET Command From Uncommon Parent severity low T1055
- Windows Local LLM Framework Execution T1543
- Windows LOLBAS Executed As Renamed File severity medium T1036, T1036.003, T1218, T1218.011
- Windows LOLBAS Executed Outside Expected Path severity low T1036, T1036.005, T1218, T1218.011
- Windows Masquerading Explorer As Child Process severity medium T1574, T1574.001
- Windows Masquerading Msdtc Process severity medium T1036
- Windows Metasploit Confluence Plugin Execution severity medium T1190, T1505, T1505.003, T1608
- Windows Mimikatz Binary Execution severity medium T1003
- Windows Modify Registry Regedit Silent Reg Import severity low T1112
- Windows Modify System Firewall with Notable Process Path severity medium T1686
- Windows MOF Event Triggered Execution via WMI severity medium T1546, T1546.003
- Windows MpCmdRun RemoveDefinitions Execution severity low T1685
- Windows MSC EvilTwin Directory Path Manipulation severity medium T1036, T1036.005, T1203, T1218
- Windows MSIExec DLLRegisterServer severity medium T1218, T1218.007
- Windows MsiExec HideWindow Rundll32 Execution severity medium T1218, T1218.007
- Windows MSIExec Remote Download severity low T1218, T1218.007
- Windows MSIExec Spawn Discovery Command severity low T1218, T1218.007
- Windows MSIExec Spawn WinDBG severity medium T1218, T1218.007
- Windows MSIExec Unregister DLLRegisterServer severity medium T1218, T1218.007
- Windows MSTSC RDP Commandline severity low T1021, T1021.001
- Windows Mustang Panda USB Tool Execution severity medium T1020, T1204, T1204.002, T1574, T1574.001
- Windows Net System Service Discovery T1007
- Windows Netspy Network Scanner Execution severity medium T1018, T1595
- Windows Network Connection Discovery Via Net T1049
- Windows Network Share Interaction Via Net T1039, T1135
- Windows Network Sniffing Tool Executed severity low T1040
- Windows New Deny Permission Set On Service SD Via Sc.EXE severity low T1564
- Windows New Service Security Descriptor Set Via Sc.EXE severity low T1564
- Windows Ngrok Reverse Proxy Usage severity low T1090, T1102, T1572
- Windows NirSoft AdvancedRun severity medium T1588, T1588.002
- Windows NirSoft Utilities T1588, T1588.002
- Windows NorthStar C2 Agent Execution severity medium T1204, T1204.002, T1547, T1547.001, T1608
- Windows Odbcconf Hunting T1218, T1218.008
- Windows Odbcconf Load DLL severity medium T1218, T1218.008
- Windows Odbcconf Load Response File severity medium T1218, T1218.008
- Windows Office Product Dropped Cab or Inf File severity medium T1566, T1566.001
- Windows Office Product Spawned Child Process For Download severity medium T1566, T1566.001
- Windows Office Product Spawned Control severity medium T1566, T1566.001
- Windows Office Product Spawned MSDT severity medium T1566, T1566.001
- Windows Office Product Spawned Rundll32 With No DLL severity medium T1566, T1566.001
- Windows Office Product Spawned Uncommon Process severity medium T1566, T1566.001
- Windows OneDrive Share Mounted via Net severity low T1567, T1567.002
- Windows PaperCut NG Spawn Shell severity medium T1059, T1133, T1190
- Windows Parent PID Spoofing with Explorer severity medium T1134, T1134.004
- Windows Password Managers Discovery severity low T1555, T1555.005
- Windows Password Policy Discovery with Net T1201
- Windows Phishing PDF File Executes URL Link severity low T1566, T1566.001
- Windows Potato Privilege Escalation Tool Execution severity medium T1068
- Windows Potential Cloudflared Tunnel Execution severity medium T1572
- Windows PowerShell FakeCAPTCHA Clipboard Execution severity medium T1059, T1059.001, T1059.003, T1204, T1204.001
- Windows PowerShell Process Implementing Manual Base64 Decoder severity low T1027, T1027.010, T1059, T1059.001
- Windows PowerShell Process With Malicious String severity medium T1059, T1059.001
- Windows Powershell RemoteSigned File severity low T1059, T1059.001
- Windows PowerShell Script From WindowsApps Directory severity medium T1059, T1059.001, T1204, T1204.002
- Windows Private Keys Discovery severity low T1552, T1552.004
- Windows Privilege Escalation Attempt Via MSI Rollback severity medium T1068
- Windows Process Commandline Discovery T1057
- Windows Process Copied from System Folder (Windows Event Log) T1036, T1036.003
- Windows Process Execution From ProgramData T1036, T1036.005
- Windows Process Execution From RDP Share severity low T1021, T1021.001, T1059, T1105
- Windows Process Execution in Temp Dir severity low T1036, T1036.005, T1543
- Windows Process Injection In Non-Service SearchIndexer severity medium T1055
- Windows Process Injection Wermgr Child Process severity low T1055
- Windows Process Outside of System Folder (Windows Event Log) T1036, T1036.004, T1036.005
- Windows Process With NamedPipe CommandLine severity low T1055
- Windows Process With NetExec Command Line Parameters severity medium T1550, T1550.003, T1558, T1558.003, T1558.004
- Windows Protocol Tunneling with Plink severity medium T1021, T1021.004, T1572
- Windows Proxy Execution of .NET Utilities via Scripts severity low T1218
- Windows Proxy Via Netsh severity low T1090, T1090.001
- Windows PsTools Recon Usage severity low T1018, T1046, T1082
- Windows PuTTY Suite Utility Execution severity low T1021, T1021.004
- Windows Raccine Scheduled Task Deletion severity medium T1685
- Windows Rasautou DLL Execution severity medium T1055, T1055.001, T1218
- Windows RDP File Execution severity medium T1021, T1021.001, T1598, T1598.002
- Windows Registry Entries Exported Via Reg T1012
- Windows Registry Entries Restored Via Reg T1012
- Windows Regsvr32 Renamed Binary severity medium T1218, T1218.010
- Windows Remote Assistance Spawning Process severity medium T1055
- Windows Remote Create Service severity low T1543, T1543.003
- Windows Remote Host Computer Management Access severity low T1021, T1021.006
- Windows Remote Management Execute Shell severity low T1021, T1021.006
- Windows Remote Service Rdpwinst Tool Execution severity medium T1021, T1021.001
- Windows Remote Services Allow Rdp In Firewall severity low T1021, T1021.001
- Windows Rundll32 Apply User Settings Changes severity low T1218, T1218.011
- Windows Rundll32 Execution With Log.DLL severity low T1574
- Windows Rundll32 WebDAV Request T1048, T1048.003
- Windows Rundll32 with Non-Standard File Extension severity low T1218, T1218.011
- Windows Scheduled Task Created Via XML severity low T1053, T1053.005
- Windows Scheduled Task with Highest Privileges severity medium T1053, T1053.005
- Windows Schtasks Create Run As System severity medium T1053, T1053.005
- Windows ScManager Security Descriptor Tampering Via Sc.EXE severity medium T1569, T1569.002
- Windows Security Account Manager Stopped severity medium T1489
- Windows Security Support Provider Reg Query severity low T1547, T1547.005
- Windows Sensitive Group Discovery With Net severity low T1069, T1069.002
- Windows Sensitive Registry Hive Dump Via CommandLine severity medium T1003, T1003.002
- Windows Server Software Component GACUtil Install to GAC severity medium T1505, T1505.004
- Windows Service Create Kernel Mode Driver severity medium T1068, T1543, T1543.003
- Windows Service Create with Tscon severity medium T1543, T1543.003, T1563, T1563.002
- Windows Service Created (Windows Event Log) T1543, T1569, T1569.002
- Windows Service Creation on Remote Endpoint severity medium T1543, T1543.003
- Windows Service Execution RemCom severity medium T1569, T1569.002
- Windows Service Initiation on Remote Endpoint severity medium T1543, T1543.003
- Windows Service Started (Windows Event Log) T1569, T1569.002
- Windows Service Stop Attempt T1489
- Windows Service Stop By Deletion T1489
- Windows Set Account Password Policy To Unlimited Via Net severity low T1489
- Windows Set Custom DNS ServerLevelPlugin Via Dnscmd severity medium T1574
- Windows Shell Process from CrushFTP severity medium T1059, T1059.001, T1059.003, T1190, T1505
- Windows SOAPHound Binary Execution severity medium T1069, T1069.001, T1069.002, T1087, T1087.001, T1087.002
- Windows Spearphishing Attachment Onenote Spawn Mshta severity medium T1566, T1566.001
- Windows SpeechRuntime Suspicious Child Process severity medium T1021, T1021.003
- Windows SQL Spawning CertUtil severity medium T1105
- Windows SQLCMD Execution T1059, T1059.003
- Windows Sqlservr Spawning Shell T1505, T1505.001
- Windows Steal Authentication Certificates CertUtil Backup severity low T1649
- Windows Steal Authentication Certificates Export Certificate severity low T1649
- Windows Steal Authentication Certificates Export PfxCertificate severity low T1649
- Windows Steal or Forge Kerberos Tickets Klist T1558
- Windows SubInAcl Execution severity low T1222, T1222.001
- Windows Suspicious Child Process of Consent.EXE severity low T1059, T1068, T1548, T1548.002
- Windows Suspicious Child Process of TieringEngineService.exe severity medium T1068
- Windows Suspicious Child Process Spawned From WebServer severity informational T1505, T1505.003
- Windows Suspicious Process File Path severity medium T1036, T1036.005, T1543
- Windows Suspicious VMWare Tools Child Process severity medium T1059
- Windows Svchost.exe Parent Process Anomaly severity low T1036, T1036.009
- Windows SymbolicLink-Testing-Tools Utility Execution severity medium T1222, T1564, T1564.004
- Windows Symlink Evaluation Change via Fsutil severity low T1222, T1222.001
- Windows System Binary Proxy Execution Compiled HTML File Decompile severity medium T1218, T1218.001
- Windows System Discovery Using ldap Nslookup severity low T1033
- Windows System Discovery Using Qwinsta T1033
- Windows System LogOff Commandline severity low T1529
- Windows System Network Config Discovery Display DNS severity low T1016
- Windows System Network Connections Discovery Netsh severity low T1049
- Windows System Reboot CommandLine T1529
- Windows System Remote Discovery With Query T1033
- Windows System Script Proxy Execution Syncappvpublishingserver severity medium T1216, T1218
- Windows System Shutdown CommandLine severity low T1529
- Windows System Time Discovery W32tm Delay severity low T1124
- Windows System User Discovery Via Quser T1033
- Windows System User Privilege Discovery T1033
- Windows TeamCity Payload Execution from Temp Directory severity medium T1059, T1190, T1505, T1505.003
- Windows Time Based Evasion via Choice Exec severity low T1497, T1497.003
- Windows TinyCC Shellcode Execution severity medium T1027, T1036, T1059, T1059.003
- Windows TOR Client Execution severity low T1090, T1090.003
- Windows UAC Bypass Suspicious Child Process severity medium T1548, T1548.002
- Windows Unusual SysWOW64 Process Run System32 Executable severity low T1036, T1036.009
- Windows User Deletion Via Net severity low T1531
- Windows User Disabled Via Net severity low T1531
- Windows User Discovery Via Net T1087, T1087.001, T1087.002
- Windows WBAdmin File Recovery From Backup severity low T1490, T1565, T1565.001
- Windows WinDBG Spawning AutoIt3 severity medium T1059
- Windows WinRAR Launched Outside Default Installation Directory severity low T1047
- Windows WMI Process And Service List severity low T1047
- Windows WMI Process Call Create T1047
- Windows WMI Reconnaissance Class Query severity low T1047
- Windows Wmic CPU Discovery severity low T1082
- Windows Wmic DiskDrive Discovery severity low T1082
- Windows Wmic Memory Chip Discovery severity low T1082
- Windows Wmic Network Discovery severity low T1082
- Windows Wmic Systeminfo Discovery severity low T1082
- Windows WSUS Spawning Shell severity medium T1190, T1505, T1505.003
- Winhlp32 Spawning a Process severity medium T1055
- WinRAR Spawning Shell Application severity medium T1105
- WinRM Spawning a Process severity medium T1190
- WinRM Tools (Windows Event Log) T1021, T1021.006, T1047
- WinSCP Execution (Windows Event Log) T1048, T1048.003
- WMI subscription execution (Windows Event Log) T1047, T1546, T1546.003
- WMIC Explicit Credentials (Windows Event Log) T1047, T1078
- Wmic Group Discovery severity low T1069, T1069.001
- WMIC Host Reconniassance (Windows Event Log) T1047, T1082
- Wmic NonInteractive App Uninstallation T1685
- WMIC XSL Execution via URL severity medium T1220
- Wmiprvse LOLBAS Execution Process Spawn severity medium T1047
- WmiPrvSE Suspicious Child Process (Windows Event Log) T1047
- Wow6432Node Classes Autorun Keys Modification (Windows Event Log) T1547, T1547.001
- Wscript Or Cscript Suspicious Child Process severity low T1055, T1134, T1134.004, T1543
- Wscript_Cscript Execution (Windows Event Log) T1059, T1059.005, T1059.007
- Wsmprovhost LOLBAS Execution Process Spawn severity medium T1021, T1021.006
- XSL Script Execution With WMIC severity medium T1220
Kusto (47)
- Base64 encoded Windows process command-lines severity medium T1027, T1059, T1140
- Base64 encoded Windows process command-lines (Normalized Process Events) severity medium T1027, T1059, T1140
- Caramel Tsunami Actor IOC - July 2021 severity high T1546
- CertUtil Used for File Download (Living off the Land) severity high T1105, T1140, T1218
- Chia_Crypto_Mining IOC - June 2021 severity low T1496
- Detect Malicious Usage of Recovery Tools to Delete Backup Files severity high T1490
- Dev-0228 File Path Hashes November 2021 (ASIM Version) severity high T1003, T1569
- Dev-0270 Malicious Powershell usage severity high T1048, T1685
- DEV-0270 New User Creation severity high T1098
- Dev-0270 Registry IOC - September 2022 severity high T1486
- Dev-0270 WMIC Discovery severity high T1482
- Email access via active sync severity medium T1068, T1078
- Gain Code Execution on ADFS Server via Remote WMI Execution severity medium T1210
- Gain Code Execution on ADFS Server via SMB + Remote Service or Scheduled Task severity medium T1210
- Identify Mango Sandstorm powershell commands severity high T1570
- Identify SysAid Server web shell creation severity high T1190
- Imminent Ransomware severity high T1547, T1685
- Malware in the recycle bin severity medium T1564
- Malware in the recycle bin (Normalized Process Events) severity medium T1564
- Midnight Blizzard - Script payload stored in Registry severity medium T1059
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript severity medium T1547
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events) severity medium T1547
- Network endpoint to host executable correlation severity medium T1204
- New EXE deployed via Default Domain or Default Domain Controller Policies severity high T1072, T1570
- New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version) severity high T1072, T1570
- NRT Base64 Encoded Windows Process Command-lines severity medium T1027, T1059, T1140
- NRT Process executed from binary hidden in Base64 encoded file severity medium T1027, T1059, T1140
- Potential Build Process Compromise severity medium T1554
- Potential Fodhelper UAC Bypass severity medium T1548, T1548.002
- Potential Fodhelper UAC Bypass (ASIM Version) severity medium T1548, T1548.002
- Potential re-named sdelete usage severity low T1036, T1485
- Potential re-named sdelete usage (ASIM Version) severity low T1036, T1485
- Powershell Empire Cmdlets Executed in Command Line severity medium T1003, T1003.001, T1016, T1021, T1021.003, T1021.004
- PowerShell Encoded Command Execution (Living off the Land) severity medium T1027, T1059, T1059.001
- Probable AdFind Recon Tool Usage (Normalized Process Events) severity high T1018
- Process Creation with Suspicious CommandLine Arguments severity medium T1027, T1059
- Process executed from binary hidden in Base64 encoded file severity medium T1027, T1059, T1140
- Process Execution Frequency Anomaly severity medium T1059
- Sdelete deployed via GPO and run recursively severity medium T1485
- Sdelete deployed via GPO and run recursively (ASIM Version) severity medium T1485
- Security Service Registry ACL Modification severity high T1685
- Silk Typhoon New UM Service Child Process severity medium T1190
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events) severity medium T1059, T1543
- Unusual identity creation using exchange powershell severity high T1136
- Windows Binaries Executed from Non-Default Directory severity medium T1059
- WMI Spawning Suspicious Child Process (Living off the Land) severity high T1021, T1021.006, T1047, T1059, T1059.001, T1059.003
- Zinc Actor IOCs files - October 2022 severity high T1546
YARA-L (69)
- Base64 Encoded PowerShell Command Detected severity high T1059, T1059.001
- ConvertTo-SecureString Cmdlet Usage Via CommandLine severity medium T1059, T1059.001
- Copy From Or To Admin Share Or Sysvol Folder severity medium T1021, T1021.002
- CreateDump Process Dump severity high T1003, T1003.001
- Direct Autorun Keys Modification severity medium T1547, T1547.001
- File Download Using Notepad++ GUP Utility severity high T1105
- File Download Via Windows Defender MpCmpRun.EXE severity high T1105
- Finger.EXE Execution severity high T1105
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage T1550, T1550.001
- GCTI Remote Access Tools severity high T1219
- Google Safebrowsing File Process Creation severity critical
- Google Safebrowsing With Prevalence severity critical
- HackTool - Dumpert Process Dumper Execution severity critical T1003, T1003.001
- Hacktool - IronSharpPack Execution T1059
- HackTool - Mimikatz Execution severity high T1003, T1003.001
- Hacktool - SharpSuccessor Execution severity high T1068
- Hacktool - WinPEAS Execution Patterns T1082
- Hash Prevalence severity low
- Impacket WMIExec CISA Report severity medium T1047
- IOC Hash Prevalence severity high
- IOC SHA256 Hash severity medium
- IOC SHA256 Hash VT severity medium
- Local Accounts Discovery severity low T1033
- Low Prevalence Hash On Process Launch Low Prevalence Domain Accessed severity low
- LSASS Dump Keyword In CommandLine severity high T1003, T1003.001
- MITRE ATT&CK T1003 RW Mimikatz severity critical T1003
- MITRE ATT&CK T1003.003 RW Utilities Associated With Ntds.dit severity high T1003, T1003.003
- MITRE ATT&CK T1003.003 WMIC Ntds.dit CISA Report severity high T1003, T1003.003
- MITRE ATT&CK T1021.002 Windows Admin Share Basic severity low T1021, T1021.002
- MITRE ATT&CK T1021.002 Windows Admin Share With Asset Entity severity low T1021, T1021.002
- MITRE ATT&CK T1021.002 Windows Admin Share With User Enrichment severity low T1021, T1021.002
- MITRE ATT&CK T1021.002 Windows Admin Share With User Entity severity low T1021, T1021.002
- MITRE ATT&CK T1033 Recon Successful Logon Enumeration Powershell CISA Report severity info T1033
- MITRE ATT&CK T1053.005 Windows Creation Of Scheduled Task severity info T1053, T1053.005
- MITRE ATT&CK T1090 Port Proxy Forwarding CISA Report severity low T1090
- MITRE ATT&CK T1140 Encoded Powershell Command severity info T1140
- MITRE ATT&CK T1570 Suspicious Command PSExec severity info T1570
- New User Created Via Net.EXE severity medium T1136, T1136.001
- potential lsass process dump via procdump severity high T1003, T1003.001
- Potential Suspicious Activity Using SeCEdit severity medium T1547, T1547.001
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE severity high T1112
- Potential Webshell Process Execution severity medium T1505, T1505.003
- PowerShell DownloadFile severity high T1059, T1059.001
- PowerShell Web Download severity medium T1059, T1059.001
- PrintBrm ZIP Creation of Extraction severity high T1105
- Process Launch VT Enrichment severity high
- Process Memory Dump Via Comsvcs.DLL severity high T1003, T1003.001
- Process Memory Dump via RdrLeakDiag.exe severity high T1003, T1003.001
- PUA - Nimgrab Execution severity high T1105
- Purple Knight Tool Execution Detected T1087
- Recon Credential Theft CISA Report severity low T1555
- Recon Environment Enumeration Active Directory CISA Report severity low T1069, T1069.002
- Recon Environment Enumeration Network CISA Report severity low T1016
- Recon Environment Enumeration System CISA Report severity low T1082
- Recon Suspicious Commands CISA Report severity low
- Reg Add Suspicious Paths severity high T1685
- Renamed CreateDump Utility Execution severity high T1003, T1003.001
- Safebrowsing Process Creation Hashes Seen More Than 7 Days severity medium
- ShimCache Flush severity high T1112
- Suspicious Certreq Command to Download severity high T1105
- Suspicious Curl.EXE Download severity high T1105
- Suspicious Download Via Certutil.EXE severity medium T1027
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE severity high T1027
- Suspicious Invoke-WebRequest Execution severity high T1105
- Uncommon or Suspicious RMM Tool Execution Detected T1219
- VT Relationships File Executes File severity high
- W3WP Launching Encoded Powershell severity medium T1059, T1059.001
- Whoami Execution severity info T1033
- Windows Event Log Cleared severity medium T1070, T1685.005