Detection rules › By event
Microsoft-Windows-Security-Auditing Event ID 4657
Sigma (5)
Splunk (14)
- Command Line Utility Added to Accessibility Features (Windows Event Log)
- ComputerDefaults UAC Bypass (Windows Event Log)
- ConsentPromptBehaviorAdmin Registry Value Modified (Windows Event Log)
- Defender Registry Values Modified (Windows Event Log)
- EnableLUA Registry Value Modified (Windows Event Log)
- Executable Running as NT AUTHORITY_SYSTEM Registered in BAM (Windows Event Log)
- Hidden User Created - Windows (Windows Event Log)
- LocalAccountTokenFilterPolicy Registry Value Modified (Windows Event Log)
- Modify Registry Key (Windows Event Log)
- Possible Credential Dumping via Windows Network Providers (Windows Event Log)
- Potential fodhelper UAC Bypass Attempt (Windows Event Log)
- PromptOnSecureDesktop Registry Value Modified (Windows Event Log)
- Suspicious Registry Key Created (Windows Event Log)
- Wow6432Node Classes Autorun Keys Modification (Windows Event Log)
Kusto (12)
- COM Registry Key Modified to Point to File in Color Profile Folder
- Component Object Model Hijacking - Vault7 trick
- Detect Print Processors Registry Driver Key Creation/Modification
- Detect Registry Run Key Creation/Modification
- Detect Windows Allow Firewall Rule Addition/Modification
- Detect Windows Update Disabled from Registry
- MosaicLoader
- Potential Fodhelper UAC Bypass
- Potential Fodhelper UAC Bypass (ASIM Version)
- Registry Run Keys - Suspicious Registry Run Keys
- Scheduled Task Hide
- Spearphishing Attachment: ISO Images (Microsoft Defender for Endpoint)
YARA-L (15)
- Blackbyte Ransomware Registry
- CurrentControlSet Autorun Keys Modification
- CurrentVersion Autorun Keys Modification
- Default RDP Port Changed to Non Standard Port
- Disable Internal Tools or Feature in Registry
- MITRE ATT&CK T1090 Port Proxy Forwarding CISA Report
- Modify User Shell Folders Startup Value
- New RUN Key Pointing to Suspicious Folder
- Potential Credential Dumping Via LSASS SilentProcessExit Technique
- RDP Sensitive Settings Changed
- RDP Sensitive Settings Changed to Zero
- RestrictedAdminMode Registry Value Tampering
- Session Manager Autorun Keys Modification
- Suspicious Powershell In Registry Run Keys
- Wdigest Enable UseLogonCredential