Detection rules › By event
Microsoft-Windows-Security-Auditing Event ID 4656
Sigma (18)
- Azure AD Health Monitoring Agent Registry Keys Access
- Azure AD Health Service Agents Registry Keys Access
- BlueSky Ransomware Artefacts
- CVE-2023-23397 Exploitation Attempt
- LSASS Access From Non System Account
- LSASS credential dump with LSASSY (kernel access)
- LSASS process dump by a non system account
- Password Dumper Activity on LSASS
- Potential Secure Deletion with SDelete
- Potentially Suspicious AccessMask Requested From LSASS
- Processes Accessing the Microphone and Webcam
- SAM Registry Hive Handle Request
- SCM Database Handle Failure
- Sticky key sethc file failed replacement
- SysKey Registry Keys Access
- WCE wceaux.dll Access
- Windows Defender Exclusion Registry Key - Write Access Requested
- WinRM listening service reconnaissance (WS-Management)
Elastic (1)
Splunk (15)
- Browser Credential File Accessed - Windows (Windows Event Log)
- Common LSASS Memory Dump Behavior (Windows Event Log)
- Executable File Written to Disk (Windows Event Log)
- File Written to Startup Folder - Windows (Windows Event Log)
- Impacket atexec.py Temp File Creation (Windows Event Log)
- ISO File in Temp Folder (Windows Event Log)
- LSASS Handle request (Windows Event Log)
- Mimikatz (Windows Event Log)
- Potential Credential Dumping of LSASS (Windows Event Log)
- Potential nanodump execution (Windows Event Log)
- RDP File Written by Outlook (Windows Event Log)
- Service Stop Commands (Windows Event Log)
- Suspicious File written to Disk (Windows Event Log)
- Task Manager lsass Dump (Windows Event Log)
- Windows - Service Stop (Windows Event Log)