Detection rules › By event
Microsoft-Windows-Security-Auditing Event ID 4663
Sigma (22)
- Access To Browser Credential Files By Uncommon Applications - Security
- Azure AD Health Monitoring Agent Registry Keys Access
- Azure AD Health Service Agents Registry Keys Access
- BlueSky Ransomware Artefacts
- CVE-2023-23397 Exploitation Attempt
- CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security
- File Access Of Signal Desktop Sensitive Data
- ISO Image Mounted
- LSASS Access From Non System Account
- LSASS credential dump with LSASSY (kernel access)
- LSASS process dump by a non system account
- Potential Secure Deletion with SDelete
- Potentially Suspicious AccessMask Requested From LSASS
- Processes Accessing the Microphone and Webcam
- ScreenConnect User Database Modification - Security
- Service Registry Key Read Access Request
- Suspicious Teams Application Related ObjectAcess Event
- SysKey Registry Keys Access
- Sysmon Channel Reference Deletion
- Task Manager used for LSASS dump (kernel)
- WCE wceaux.dll Access
- Windows Defender Exclusion Registry Key - Write Access Requested
Splunk (30)
- Browser Credential File Accessed - Windows (Windows Event Log)
- ConnectWise ScreenConnect Path Traversal Windows SACL
- ISO File in Temp Folder (Windows Event Log)
- ISO Image Mounted - Windows (Windows Event Log)
- Non Chrome Process Accessing Chrome Default Dir
- Non Firefox Process Access Firefox Profile Dir
- Potential Credential Dumping of LSASS (Windows Event Log)
- Potential nanodump execution (Windows Event Log)
- Rare dll called by Spoolsv.exe (Windows Event Log)
- RDP File Written by Outlook (Windows Event Log)
- Rename System Utilities (Windows Event Log)
- SAM Database File Access Attempt
- SAM, System, Security Files Accessed (Windows Event Log)
- Task Manager lsass Dump (Windows Event Log)
- Temporary ConnectWise xml File Activity (Windows Event Log)
- Windows Credential Access From Browser Password Store
- Windows Credentials from Password Stores Chrome Extension Access
- Windows Credentials from Password Stores Chrome LocalState Access
- Windows Credentials from Password Stores Chrome Login Data Access
- Windows GrimResource - MMC Process Accessing APDS DLL
- Windows Hosts File Access
- Windows Increase in Group or Object Modification Activity
- Windows Non Discord App Access Discord LevelDB
- Windows Process Accessing Windows Recall Directory
- Windows Product Key Registry Query
- Windows Query Registry Browser List Application
- Windows Query Registry UnInstall Program List
- Windows Unsecured Outlook Credentials Access In Registry
- Windows Unusual FileZilla XML Config Access
- Windows Unusual Intelliform Storage Registry Access
Kusto (26)
- Detect executable drops via Azure custom script extension
- Detect Print Processors Registry Driver Key Creation/Modification
- Detect Registry Run Key Creation/Modification
- Detect Windows Allow Firewall Rule Addition/Modification
- Detect Windows Update Disabled from Registry
- Dev-0530 File Extension Rename
- Files Copied to USB Drives
- Google Threat Intelligence - Threat Hunting Hash
- Identify SysAid Server web shell creation
- Microsoft Entra ID Health Monitoring Agent Registry Keys Access
- Microsoft Entra ID Health Service Agents Registry Keys Access
- Microsoft Entra ID Local Device Join Information and Transport Key Registry Keys Access
- Microsoft Recommended Driver Block List
- PE file dropped in Color Profile Folder
- Potential Build Process Compromise
- Potential Fodhelper UAC Bypass (ASIM Version)
- RecordedFuture Threat Hunting Hash All Actors
- Remote File Creation with PsExec
- Spearphishing Attachment: ISO Images (Microsoft Defender for Endpoint)
- SUNBURST and SUPERNOVA backdoor hashes
- SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)
- Suspicious access of BEC related documents
- Suspicious MSC File Launched
- Suspicious office child process created
- VTI - High Severity SHA1 Collision Detection
- WinRM Plugin Lateral Movement