Detection rules › By event
Microsoft-Windows-Security-Auditing Event ID 4688
Sigma (735)
- Abusing Print Executable
- Adwind RAT / JRAT
- Anonymous login (RottenPotatoNG)
- APT27 - Emissary Panda Activity
- APT29 2018 Phishing Campaign CommandLine Indicators
- APT31 Judgement Panda Activity
- Arbitrary Binary Execution Using GUP Utility
- Arbitrary File Download Via GfxDownloadWrapper.EXE
- Arbitrary File Download Via Squirrel.EXE
- Arbitrary MSI Download Via Devinit.EXE
- Arbitrary Shell Command Execution Via Settingcontent-Ms
- AspNetCompiler Execution
- Assembly Loading Via CL_LoadAssembly.ps1
- Attempts of Kerberos Coercion Via DNS SPN Spoofing
- Audio Capture via PowerShell
- Audio Capture via SoundRecorder
- Audit policy disabled by command line
- Audit policy enumerated
- Audit Policy Tampering Via NT Resource Kit Auditpol
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
- Base64 Encoded PowerShell Command Detected
- Base64 MZ Header In CommandLine
- BitLocker feature configuration (Reg via command)
- BitLockerTogo.EXE Execution
- BITS payload downloaded via commandline
- Blue Mockingbird
- Browser Execution In Headless Mode
- Browser Started with Remote Debugging
- Bypass UAC via Fodhelper.exe
- Cab File Extraction Via Wusa.EXE
- Cab File Extraction Via Wusa.EXE From Potentially Suspicious Paths
- Certificate Exported Via PowerShell
- Certutil payload download (command)
- Certutil payload obfuscation (command)
- Certutil payload obfuscation - Tchopper (command)
- Certutil root certificate installation
- Changing Existing Service ImagePath Value Via Reg.EXE
- Chopper Webshell Process Pattern
- Chromium Browser Headless Execution To Mockbin Like Site
- Chromium Browser Instance Executed With Custom Extension
- ClickOnce Deployment Execution - Dfsvc.EXE Child Process
- Cloudflared Portable Execution
- Cloudflared Tunnel Connections Cleanup
- Cloudflared Tunnel Execution
- Cmd.EXE Missing Space Characters Execution Anomaly
- CMSTP Execution Process Creation
- COLDSTEEL RAT Anonymous User Process Execution
- COLDSTEEL RAT Service Persistence Execution
- COM Object Execution via Xwizard.EXE
- Command Line Execution with Suspicious URL and AppData Strings
- Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791)
- Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)
- Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790)
- Compress Data and Lock With Password for Exfiltration With WINZIP
- Conti NTDS Exfiltration Command
- Conti Volume Shadow Listing
- Copy From VolumeShadowCopy Via Cmd.EXE
- Cscript/Wscript Potentially Suspicious Child Process
- Curl Download And Execute Combination
- DarkGate - User Created Via Net.EXE
- Defrag Deactivation
- Delete All Scheduled Tasks
- Deletion of Volume Shadow Copies via WMI with PowerShell
- Detected Windows Software Discovery
- DeviceCredentialDeployment Execution
- Devtoolslauncher.exe Executes Specified Binary
- Diamond Sleet APT Process Activity Indicators
- Disabled guest or builtin account activated (command)
- Disabled IE Security Features
- Disabled Volume Snapshots
- Discovery of a System Time
- Diskshadow Child Process Spawned
- Diskshadow command abuse to expose VSS backup
- DLL Execution Via Register-cimprovider.exe
- DLL ServerLevelPluginDll command installation
- DLL Sideloading by VMware Xfer Utility
- Dllhost.EXE Execution Anomaly
- DNS Exfiltration and Tunneling Tools Execution
- DNS RCE CVE-2020-1350
- DoT (DNS over TLS) activation (command)
- Droppers Exploiting CVE-2017-11882
- Dropping Of Password Filter DLL
- DSInternals Suspicious PowerShell Cmdlets
- DSRM password changed (Reg via command)
- Dumping Process via Sqldumper.exe
- DumpStack.log Defender Evasion
- Dynamic .NET Compilation Via Csc.EXE - Hunting
- EAP service activation by Liontail framework for DLL sideloading (via command)
- Edge abuse for payload download via console
- Edge/Chrome headless feature abuse for payload download
- Elise Backdoor Activity
- Email Exifiltration Via Powershell
- Emotet Loader Execution Via .LNK File
- Enable LM Hash Storage - ProcCreation
- Encoded PowerShell payload deployed via process execution
- Enumeration for 3rd Party Creds From CLI
- Enumeration for Credentials in Registry
- Equation Group DLL_U Export Function Load
- Esentutl Gather Credentials
- ETW Logging Tamper In .NET Processes Via CommandLine
- ETW Trace Evasion Activity
- Event log clear attempt (command)
- Event log clear attempt (wmi)
- Event log deactivation or size reduction (command)
- EvilNum APT Golden Chickens Deployment Via OCX Files
- Execute Code with Pester.bat
- Execute Files with Msdeploy.exe
- Execute From Alternate Data Streams
- Execute Pcwrun.EXE To Leverage Follina
- Execution From Webserver Root Folder
- Execution Of Non-Existing File
- Execution of Powershell Script in Public Folder
- Execution of Suspicious File Type Extension
- Execution via stordiag.exe
- Execution via WorkFolders.exe
- Exploit for CVE-2015-1641
- Exploit for CVE-2017-0261
- Exploit for CVE-2017-8759
- Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC
- Exploited CVE-2020-10189 Zoho ManageEngine
- Exploiting CVE-2019-1388
- Explorer Process Tree Break
- File Download From Browser Process Via Inline URL
- File Download with Headless Browser
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
- File or Folder Permissions Modifications
- Files Added To An Archive Using Rar.EXE
- Fireball Archer Install
- Firewall configuration enumerated (command)
- Firewall deactivation (deprecated command)
- Firewall deactivation (modern command)
- Firewall rule creation (command)
- Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
- Gpresult Display Group Policy Information
- Greenbug Espionage Group Indicators
- Griffon Malware Attack Pattern
- Grixba Malware Reconnaissance Activity
- Group discovery (command)
- Gzip Archive Decode Via PowerShell
- HackTool - ADCSPwn Execution
- HackTool - Covenant PowerShell Launcher
- HackTool - CrackMapExec Execution
- HackTool - CrackMapExec Execution Patterns
- HackTool - CrackMapExec Process Patterns
- HackTool - Default PowerSploit/Empire Scheduled Task Creation
- HackTool - DInjector PowerShell Cradle Execution
- HackTool - Empire PowerShell Launch Parameters
- HackTool - Empire PowerShell UAC Bypass
- HackTool - F-Secure C3 Load by Rundll32
- HackTool - Hashcat Password Cracker Execution
- HackTool - HollowReaper Execution
- HackTool - Htran/NATBypass Execution
- HackTool - Hydra Password Bruteforce Execution
- HackTool - Impacket Tools Execution
- HackTool - LaZagne Execution
- HackTool - Mimikatz Execution
- HackTool - NetExec Execution
- HackTool - Pypykatz Credentials Dumping Activity
- HackTool - Quarks PwDump Execution
- HackTool - RedMimicry Winnti Playbook Execution
- HackTool - SharpWSUS/WSUSpendu Execution
- HackTool - Sliver C2 Implant Activity Pattern
- HackTool - SOAPHound Execution
- HackTool - WinPwn Execution
- HackTool - WinRM Access Via Evil-WinRM
- HackTool - Wmiexec Default Powershell Command
- HackTool - XORDump Execution
- HAFNIUM Exchange Exploitation Activity
- Hermetic Wiper TG Process Patterns
- Hidden Powershell in Link File Pattern
- Hiding User Account Via SpecialAccounts Registry Key - CommandLine
- HTML File Opened From Download Folder
- HTML Help HH.EXE Suspicious Child Process
- IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32
- IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI
- IFM creation detected from commandline (installation from media)
- ImagingDevices Unusual Parent/Child Processes
- Impacket DCOMexec process abuse via MMC
- Import PowerShell Modules From Suspicious Directories - ProcCreation
- Indirect Command Execution By Program Compatibility Wizard
- Indirect Command Execution via SFTP ProxyCommand
- InfDefaultInstall.exe .inf Execution
- Injected Browser Process Spawning Rundll32 - GuLoader Activity
- Interactive AT Job
- Interactive privileged shell triggered by schedule task (deprecated)
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)
- Invoke-Obfuscation CLIP+ Launcher
- Invoke-Obfuscation COMPRESS OBFUSCATION
- Invoke-Obfuscation Obfuscated IEX Invocation
- Invoke-Obfuscation STDIN+ Launcher
- Invoke-Obfuscation VAR+ Launcher
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
- Invoke-Obfuscation Via Stdin
- Invoke-Obfuscation Via Use Clip
- Invoke-Obfuscation Via Use MSHTA
- Java Running with Remote Debugging
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution
- Kavremover Dropped Binary LOLBIN Usage
- Lace Tempest Cobalt Strike Download
- Lateral movement by mounting a network share - net use (command)
- Launch-VsDevShell.PS1 Proxy Execution
- Lazarus Group Activity
- Lazarus System Binary Masquerading
- LockerGoga Ransomware Activity
- Lolbin Runexehelper Use As Proxy
- LSASS Dump Keyword In CommandLine
- Malicious PE Execution by Microsoft Visual Studio Debugger
- Malicious PowerShell Commandlets - ProcessCreation
- Manual Execution of Script Inside of a Compressed File
- Massive processes termination burst
- Massive services deletion burst
- Massive services termination burst
- Mavinject Inject DLL Into Running Process
- MERCURY APT Activity
- Metasploit reverse shell injection in SQL Server
- Microsoft Defender critical security components disabled (command)
- Microsoft Defender default action changed to allow any threat (command)
- Microsoft Defender security components disabled (command)
- Microsoft Defender service deactivation attempt (command)
- Mint Sandstorm - AsperaFaspex Suspicious Process Execution
- Mint Sandstorm - Log4J Wstomcat Process Execution
- Mint Sandstorm - ManageEngine Suspicious Process Execution
- MMC Spawning Windows Shell
- MMC20 Lateral Movement
- MSDT Execution Via Answer File
- MSExchange Transport Agent Installation
- Mshtml.DLL RunHTMLApplication Suspicious Usage
- MsiExec Web Install
- Msxsl.EXE Execution
- Mustang Panda Dropper
- Netsh helper DLL abuse (process)
- Network Reconnaissance Activity
- Network share discovery and/or connection via commandline
- Network share manipulation via commandline
- New ActiveScriptEventConsumer Created Via Wmic.EXE
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
- New Kernel Driver Via SC.EXE
- New Process Created Via Taskmgr.EXE
- New Service Creation Using PowerShell
- New Service Creation Using Sc.EXE
- Node Process Executions
- Non-privileged Usage of Reg or Powershell
- Notepad Password Files Discovery
- NotPetya Ransomware Activity
- NtdllPipe Like Activity Execution
- NTFS symbolic link configuration change
- NTFS symbolic link creation
- Number of oustanding SMB requests increased
- Obfuscated IP Download Activity
- Obfuscated IP Via CLI
- Obfuscated payload transfered via service name - Tchopper (command)
- Obfuscated PowerShell OneLiner Execution
- OilRig APT Activity
- OneNote.EXE Execution of Malicious Embedded Scripts
- OpenEDR Spawning Command Shell
- OpenSSH server firewall configuration on Windows (command)
- OpenWith.exe Executes Specified Binary
- Operation Wocao Activity
- Outlook EnableUnsafeClientMailRules Setting Enabled
- PaperCut MF/NG Exploitation Related Indicators
- PaperCut MF/NG Potential Exploitation
- Password policy discovery via commandline
- Peach Sandstorm APT Process Activity Indicators
- Persistence Via Sticky Key Backdoor
- Persistence Via TypedPaths - CommandLine
- Phishing Pattern ISO in Archive
- Pikabot Fake DLL Extension Execution Via Rundll32.EXE
- Ping Hex IP
- Pingback Backdoor Activity
- Port Forwarding Activity Via SSH.EXE
- Possible Privilege Escalation via Weak Service Permissions
- Potential ACTINIUM Persistence Activity
- Potential Amazon SSM Agent Hijacking
- Potential AMSI Bypass Using NULL Bits
- Potential AMSI Bypass Via .NET Reflection
- Potential Application Whitelisting Bypass via Dnx.EXE
- Potential APT FIN7 Exploitation Activity
- Potential APT FIN7 Reconnaissance/POWERTRASH Related Activity
- Potential APT Mustang Panda Activity Against Australian Gov
- Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
- Potential APT10 Cloud Hopper Activity
- Potential Arbitrary Code Execution Via Node.EXE
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt
- Potential Baby Shark Malware Activity
- Potential BlackByte Ransomware Activity
- Potential COM Objects Download Cradles Usage - Process Creation
- Potential Command Line Path Traversal Evasion Attempt
- Potential Commandline Obfuscation Using Escape Characters
- Potential CommandLine Obfuscation Using Unicode Characters
- Potential Compromised 3CXDesktopApp Update Activity
- Potential Conti Ransomware Activity
- Potential Conti Ransomware Database Dumping Activity Via SQLCmd
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI
- Potential Credential Dumping Via LSASS Process Clone
- Potential Crypto Mining Activity
- Potential CVE-2021-26857 Exploitation Attempt
- Potential CVE-2021-40444 Exploitation Attempt
- Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution
- Potential CVE-2023-21554 QueueJumper Exploitation
- Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI
- Potential Data Exfiltration Activity Via CommandLine Tools
- Potential Data Stealing Via Chromium Headless Debugging
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
- Potential Defense Evasion Via Right-to-Left Override
- Potential Devil Bait Malware Reconnaissance
- Potential Discovery Activity Via Dnscmd.EXE
- Potential DLL File Download Via PowerShell Invoke-WebRequest
- Potential Dosfuscation Activity
- Potential Download/Upload Activity Using Type Command
- Potential Dridex Activity
- Potential Dropper Script Execution Via WScript/CScript/MSHTA
- Potential Dtrack RAT Activity
- Potential Emotet Activity
- Potential EmpireMonkey Activity
- Potential Execution of Sysinternals Tools
- Potential Exploitation Attempt From Office Application
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
- Potential Exploitation of GoAnywhere MFT Vulnerability
- Potential Fake Instance Of Hxtsr.EXE Executed
- Potential File Download Via MS-AppInstaller Protocol Handler
- Potential Goofy Guineapig Backdoor Activity
- Potential Goofy Guineapig GoolgeUpdate Process Anomaly
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI
- Potential Homoglyph Attack Using Lookalike Characters
- Potential KamiKakaBot Activity - Lure Document Execution
- Potential KamiKakaBot Activity - Shutdown Schedule Task Creation
- Potential Ke3chang/TidePool Malware Activity
- Potential Lateral Movement via Windows Remote Shell
- Potential LethalHTA Technique Execution
- Potential LSASS Process Dump Via Procdump
- Potential Maze Ransomware Activity
- Potential Meterpreter/CobaltStrike Activity
- Potential Mftrace.EXE Abuse
- Potential Mpclient.DLL Sideloading Via Defender Binaries
- Potential MSTSC Shadowing Activity
- Potential MuddyWater APT Activity
- Potential Network Sniffing Activity Using Network Tools
- Potential Notepad++ CVE-2025-49144 Exploitation
- Potential Persistence Attempt Via Existing Service Tampering
- Potential Persistence Attempt Via Run Keys Using Reg.EXE
- Potential Persistence Via Logon Scripts - CommandLine
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE
- Potential PlugX Activity
- Potential PowerShell Console History Access Attempt via History File
- Potential PowerShell Downgrade Attack
- Potential PowerShell Execution Policy Tampering - ProcCreation
- Potential PowerShell Obfuscation Via WCHAR/CHAR
- Potential Privilege Escalation To LOCAL SYSTEM
- Potential Privilege Escalation via Service Permissions Weakness
- Potential Process Execution Proxy Via CL_Invocation.ps1
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution
- Potential Provlaunch.EXE Binary Proxy Execution Abuse
- Potential Proxy Execution Via Explorer.EXE From Shell Process
- Potential PsExec Remote Execution
- Potential Qakbot Rundll32 Execution
- Potential QBot Activity
- Potential Raspberry Robin Dot Ending File
- Potential RDP Tunneling Via Plink
- Potential RDP Tunneling Via SSH
- Potential Regsvr32 Commandline Flag Anomaly
- Potential Remote Desktop Tunneling
- Potential Renamed Rundll32 Execution
- Potential Russian APT Credential Theft Activity
- Potential Ryuk Ransomware Activity
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators
- Potential SMB Relay Attack Tool Execution
- Potential SNAKE Malware Installation Binary Indicator
- Potential SNAKE Malware Installation CLI Arguments Indicator
- Potential SNAKE Malware Persistence Service Execution
- Potential Snatch Ransomware Activity
- Potential Suspicious Browser Launch From Document Reader Process
- Potential Suspicious Child Process Of 3CXDesktopApp
- Potential Suspicious Execution From GUID Like Folder Names
- Potential Suspicious Windows Feature Enabled - ProcCreation
- Potential SysInternals ProcDump Evasion
- Potential SystemNightmare Exploitation Attempt
- Potential Tampering With Security Products Via WMIC
- Potential UAC Bypass Via Sdclt.EXE
- Potential WinAPI Calls Via CommandLine
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler
- Potentially Suspicious Cabinet File Expansion
- Potentially Suspicious Call To Win32_NTEventlogFile Class
- Potentially Suspicious Child Process Of ClickOnce Application
- Potentially Suspicious Child Process Of DiskShadow.EXE
- Potentially Suspicious Child Process Of Regsvr32
- Potentially Suspicious Child Process Of VsCode
- Potentially Suspicious Command Targeting Teams Sensitive Files
- Potentially Suspicious Event Viewer Child Process
- Potentially Suspicious Execution From Parent Process In Public Folder
- Potentially Suspicious Execution Of PDQDeployRunner
- Potentially Suspicious GoogleUpdate Child Process
- Potentially Suspicious JWT Token Search Via CLI
- Potentially Suspicious Powershell Script Execution From Temp Folder
- Potentially Suspicious Usage Of Qemu
- Potentially Suspicious WebDAV LNK Execution
- Potentially Suspicious Windows App Activity
- PowerShell Base64 Encoded FromBase64String Cmdlet
- PowerShell Base64 Encoded IEX Cmdlet
- Powershell Base64 Encoded MpPreference Cmdlet
- PowerShell Base64 Encoded Reflective Assembly Load
- Powershell Defender Disable Scan Feature
- Powershell Defender Exclusion
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
- PowerShell Download and Execution Cradles
- PowerShell Get-Clipboard Cmdlet Via CLI
- PowerShell Get-Process LSASS
- Powershell Inline Execution From A File
- PowerShell SAM Copy
- PowerShell Script Run in AppData
- Powershell Token Obfuscation - Process Creation
- PrintBrm ZIP Creation of Extraction
- Privilege escalation via runas (command)
- Privilege escalation via RunasCS
- Procdump Execution
- Process Creation Using Sysnative Folder
- Process Execution From A Potentially Suspicious Folder
- Process Execution From WebDAV Share
- Process Launched Without Image Name
- Process Proxy Execution Via Squirrel.EXE
- Ps.exe Renamed SysInternals Tool
- PsExec Service Child Process Execution as LOCAL SYSTEM
- PsExec/PAExec Escalation to LOCAL SYSTEM
- PUA - AdFind Suspicious Execution
- PUA - Adidnsdump Execution
- PUA - AdvancedRun Suspicious Execution
- PUA - Chisel Tunneling Tool Execution
- PUA - CleanWipe Execution
- PUA - DIT Snapshot Viewer
- PUA - Netcat Suspicious Execution
- PUA - Ngrok Execution
- PUA - NirCmd Execution As LOCAL SYSTEM
- PUA - Restic Backup Tool Execution
- PUA - RunXCmd Execution
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE
- PUA - TruffleHog Execution
- Pubprn.vbs Proxy Execution
- Python Function Execution Security Warning Disabled In Excel
- Python Spawning Pretty TTY on Windows
- Qakbot Regsvr32 Calc Pattern
- Qakbot Rundll32 Exports Execution
- Qakbot Rundll32 Fake DLL Extension Execution
- Query Usage To Exfil Data
- QuickAssist Execution
- Raccine Uninstall
- Rar Usage with Password and Compression Level
- Raspberry Robin Subsequent Execution of Commands
- RDP session hijack via TSCON abuse command
- RDP shadow session started (command)
- RDP tunneling configuration enabled for port forwarding
- Recon Command Output Piped To Findstr.EXE
- Regedit as Trusted Installer
- REGISTER_APP.VBS Proxy Execution
- Registry Modification Attempt Via VBScript
- Remote Access Tool - Ammy Admin Agent Execution
- Remote Access Tool - AnyDesk Piped Password Via CLI
- Remote Access Tool - AnyDesk Silent Installation
- Remote Access Tool - MeshAgent Command Execution via MeshCentral
- Remote Access Tool - Potential MeshAgent Execution - Windows
- Remote Access Tool - ScreenConnect Installation Execution
- Remote Access Tool - ScreenConnect Remote Command Execution - Hunting
- Remote Access Tool - ScreenConnect Server Web Shell Execution
- Remote Access Tool - Simple Help Execution
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
- Remote Access Tool - Team Viewer Session Started On Windows Host
- Remote File Download Via Desktopimgdownldr Utility
- Remote PowerShell Session Host Process (WinRM)
- Remote XSL Execution Via Msxsl.EXE
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
- Replace.exe Usage
- RestrictedAdminMode Registry Value Tampering - ProcCreation
- REvil Kaseya Incident Malware Patterns
- Root Certificate Installed From Susp Locations
- Rorschach Ransomware Execution Activity
- Run PowerShell Script from ADS
- Run PowerShell Script from Redirected Input Stream
- Rundll32 Execution Without CommandLine Parameters
- Rundll32 Execution Without Parameters
- Scheduled persistent task with SYSTEM privileges creation
- Scheduled Task Creation From Potential Suspicious Parent Location
- Scheduled Task Creation Via Schtasks.EXE
- Scheduled task creation with command line
- Scheduled Task Creation with Curl and PowerShell Execution Combo
- Scheduled task enumerated
- Schtasks Creation Or Modification With SYSTEM Privileges
- Screen Capture Activity Via Psr.EXE
- Script Event Consumer Spawning Process
- Script Interpreter Spawning Credential Scanner - Windows
- Scripting/CommandLine Process Spawned Regsvr32
- Sdclt Child Processes
- Sdiagnhost Calling Suspicious Child Process
- SearchIndexer suspicious process activity
- Security package (SSP) added (Reg via command)
- Security Service Disabled Via Reg.EXE
- Sensitive File Access Via Volume Shadow Copy Backup
- Serial console process spawning CMD shell (via command)
- Serpent Backdoor Payload Execution Via Scheduled Task
- Serv-U Exploitation CVE-2021-35211 by DEV-0322
- Service abuse with backdoored "command failure" (Reg via command)
- Service abuse with backdoored "command failure" (service)
- Service abuse with malicious ImagePath (Reg via command)
- Service abuse with malicious ImagePath (service)
- Service creation (command)
- Service deactivation (command)
- Service permissions hijacked for privileges abuse (reg via command)
- Service permissions hijacked for privileges abuse (service)
- Shai-Hulud 2.0 Malicious NPM Package Installation
- Shai-Hulud Malicious Bun Execution
- Shai-Hulud Malware Indicators - Windows
- Shell Process Spawned by Java.EXE
- ShimCache Flush
- Small Sieve Malware CommandLine Indicator
- Sofacy Trojan Loader Activity
- SOURGUM Actor Behaviours
- SPN added to an account by command line
- Spool process spawned a CMD shell (PrintNightmare vulnerability - CVE-2021-36958)
- SQL Server database's table enumeration
- SQL server sqlcmd utility abuse for privilege escalation
- SQL Server started in single mode (command)
- Start of NT Virtual DOS Machine
- Stickey key called CMD via command execution
- Stickey key IFEO (Reg via command)
- Sticky Key Like Backdoor Execution
- Sticky key sethc command for replacement by CMD
- Suspect Svchost Activity
- Suspicious ArcSOC.exe Child Process
- Suspicious Binary In User Directory Spawned From Office Application
- Suspicious BitLocker Access Agent Update Utility Execution
- Suspicious Calculator Usage
- Suspicious Child Process of AspNetCompiler
- Suspicious Child Process Of BgInfo.EXE
- Suspicious Child Process Of Manage Engine ServiceDesk
- Suspicious Child Process of Notepad++ Updater - GUP.Exe
- Suspicious Child Process Of SQL Server
- Suspicious Child Process Of Wermgr.EXE
- Suspicious Chromium Browser Instance Executed With Custom Extension
- Suspicious ClickFix/FileFix Execution Pattern
- Suspicious CodePage Switch Via CHCP
- Suspicious Command Patterns In Scheduled Task Creation
- Suspicious CrushFTP Child Process
- Suspicious CustomShellHost Execution
- Suspicious Debugger Registration Cmdline
- Suspicious Desktopimgdownldr Command
- Suspicious Diantz Alternate Data Stream Execution
- Suspicious Diantz Download and Compress Into a CAB File
- Suspicious Double Extension File Execution
- Suspicious Download from Office Domain
- Suspicious Driver Install by pnputil.exe
- Suspicious Electron Application Child Processes
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
- Suspicious Execution From Outlook Temporary Folder
- Suspicious Execution Location Of Wermgr.EXE
- Suspicious Execution of Hostname
- Suspicious Execution of InstallUtil Without Log
- Suspicious Execution of Powershell with Base64
- Suspicious Execution of Shutdown
- Suspicious Execution of Shutdown to Log Out
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
- Suspicious Extrac32 Alternate Data Stream Execution
- Suspicious FileFix Execution Pattern
- Suspicious FromBase64String Usage On Gzip Archive - Process Creation
- Suspicious GrpConv Execution
- Suspicious GUP Usage
- Suspicious High IntegrityLevel Conhost Legacy Option
- Suspicious HWP Sub Processes
- Suspicious IIS Module Registration
- Suspicious Kernel Dump Using Dtrace
- Suspicious Modification Of Scheduled Tasks
- Suspicious Msiexec Execute Arbitrary DLL
- Suspicious Network Command
- Suspicious New Instance Of An Office COM Object
- Suspicious New Service Creation
- Suspicious Obfuscated PowerShell Code
- Suspicious Outlook Child Process
- Suspicious Ping/Del Command Combination
- Suspicious PowerShell Download and Execute Pattern
- Suspicious PowerShell IEX Execution Patterns
- Suspicious PowerShell Invocations - Specific - ProcessCreation
- Suspicious PowerShell Mailbox Export to Share
- Suspicious PowerShell Parameter Substring
- Suspicious PrinterPorts Creation (CVE-2020-1048)
- Suspicious Process Created Via Wmic.EXE
- Suspicious Process Execution From Fake Recycle.Bin Folder
- Suspicious Process Parents
- Suspicious Process Patterns NTDS.DIT Exfil
- Suspicious Process Start Locations
- Suspicious Processes Spawned by Java.EXE
- Suspicious Processes Spawned by WinRM
- Suspicious Program Names
- Suspicious Provlaunch.EXE Child Process
- Suspicious Query of MachineGUID
- Suspicious RASdial Activity
- Suspicious RazerInstaller Explorer Subprocess
- Suspicious RDP Redirect Using TSCON
- Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
- Suspicious Recursive Takeown
- Suspicious Redirection to Local Admin Share
- Suspicious Reg Add BitLocker
- Suspicious Remote Child Process From Outlook
- Suspicious RunAs-Like Flag Combination
- Suspicious Rundll32 Activity Invoking Sys File
- Suspicious Rundll32 Invoking Inline VBScript
- Suspicious Runscripthelper.exe
- Suspicious Scan Loop Network
- Suspicious Scheduled Task Creation Involving Temp Folder
- Suspicious Scheduled Task Name As GUID
- Suspicious Schtasks Execution AppData Folder
- Suspicious ScreenSave Change by Reg.exe
- Suspicious Serv-U Process Pattern
- Suspicious Service Binary Directory
- Suspicious Service Path Modification
- Suspicious Shells Spawn by Java Utility Keytool
- Suspicious Speech Runtime Binary Child Process
- Suspicious Splwow64 Without Params
- Suspicious SPN enumeration previous to Kerberoasting attack (native commands)
- Suspicious Sysmon as Execution Parent
- Suspicious SYSVOL Domain Group Policy Access
- Suspicious TSCON Start as SYSTEM
- Suspicious UltraVNC Execution
- Suspicious Usage Of ShellExec_RunDLL
- Suspicious VBoxDrvInst.exe Parameters
- Suspicious VBScript UN2452 Pattern
- Suspicious Velociraptor Child Process
- Suspicious Vsls-Agent Command With AgentExtensionPath Load
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
- Suspicious WindowsTerminal Child Processes
- Suspicious WmiPrvSE Child Process
- Suspicious X509Enrollment - Process Creation
- Suspicious ZipExec Execution
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
- Sysprep on AppData Folder
- System File Execution Location Anomaly
- System Information Discovery via Registry Queries
- SystemNightmare by GentilKiwi - External printer mapped (CVE-2021-1675 / CVE-2021-34527)
- TAIDOOR RAT DLL Load
- Tamper Windows Defender Remove-MpPreference
- Tap Installer Execution
- Task Manager access indicator for potential LSASS dump
- Taskkill Symantec Endpoint Protection
- Taskmgr as LOCAL_SYSTEM
- Tasks Folder Evasion
- Time Travel Debugging Utility Usage
- TropicTrooper Campaign November 2018
- TrustedPath UAC Bypass Pattern
- Tunneling Tool Execution
- Turla Group Commands May 2020
- Turla Group Lateral Movement
- UAC Bypass Tools Using ComputerDefaults
- UAC Bypass Using ChangePK and SLUI
- UAC Bypass Using Consent and Comctl32 - Process
- UAC Bypass Using DismHost
- UAC Bypass Using Event Viewer RecentViews
- UAC Bypass Using IEInstal - Process
- UAC Bypass Using MSConfig Token Modification - Process
- UAC Bypass Using PkgMgr and DISM
- UAC Bypass WSReset
- UEFI Persistence Via Wpbbin - ProcessCreation
- UNC2452 PowerShell Pattern
- Uncommon Child Process Of AddinUtil.EXE
- Uncommon Child Process Of Appvlp.EXE
- Uncommon Child Process Of BgInfo.EXE
- Uncommon Child Process Of Conhost.EXE
- Uncommon Child Process Of Defaultpack.EXE
- Uncommon Child Process Of Setres.EXE
- Uncommon Child Process Spawned By Odbcconf.EXE
- Uncommon Child Processes Of SndVol.exe
- Uncommon FileSystem Load Attempt By Format.com
- Uncommon Link.EXE Parent Process
- Uncommon Sigverif.EXE Child Process
- Uncommon Svchost Command Line Parameter
- Uncommon Svchost Parent Process
- Uncommon Userinit Child Process
- Uninstall Crowdstrike Falcon Sensor
- Unusual Child Process of dns.exe
- Unusual Parent Process For Cmd.EXE
- Ursnif Redirection Of Discovery Commands
- Usage Of Web Request Commands And Cmdlets
- Use NTFS Short Name in Command Line
- Use NTFS Short Name in Image
- Use of Pcalua For Execution
- Use Of The SFTP.EXE Binary As A LOLBIN
- Use Short Name Path in Command Line
- User added to a group via commandline
- User Added To Highly Privileged Group
- User Added to Local Administrators Group
- User Added to Remote Desktop Users Group
- User creation via commandline
- User enumeration and creation related to Manic Menagerie 2.0 (via cmdline)
- User properties enumeration via commandline
- UtilityFunctions.ps1 Proxy Dll
- Veeam Backup Database Suspicious Query
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE
- Virtualbox Driver Installation or Starting of VMs
- Visual Basic Command Line Compiler Usage
- Visual Studio Code Tunnel Service Installation
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
- VolumeShadowCopy Symlink Creation Via Mklink
- VSS backup deletion (WMI)
- VSS backup deletion or resize
- Wab Execution From Non Default Location
- Wab/Wabmig Unusual Parent Or Child Processes
- WannaCry Ransomware Activity
- Wdigest authentication enabled (Reg via command)
- Weak or Abused Passwords In CLI
- Webserver IIS module installed (command)
- Webserver IIS module installed (command)
- Webshell Hacking Activity Patterns
- Webshell Tool Reconnaissance Activity
- WhoAmI as Parameter
- Windows native backup deletion
- Windows native backup size re-configuration
- Windows native Pktmon sniffer abuse
- Windows Processes Suspicious Parent Directory
- Windows Subsystem for Linux (WSL) installation (command)
- Windows traffic capture abuse
- Winnti Malware HK University Campaign
- Winnti Pipemon Characteristics
- WinRM listening service reconnaissance (process)
- WinRS usage for remote execution
- WMI Backdoor Exchange Transport Agent
- WMI Persistence - Script Event Consumer
- WMI spwaning PowerShell process - WMImplant
- WmiPrvSE Spawned A Process
- Write Protect For Storage Disabled
- Writing Of Malicious Files To The Fonts Folder
- Wscript Shell Run In CommandLine
- WSL Child Process Anomaly
- WSL Kali-Linux Usage
- Wusa.EXE Executed By Parent Process Located In Suspicious Location
- ZxShell Malware
Elastic (259)
- Accessing Outlook Data Files
- Account Discovery Command via SYSTEM Account
- Active Directory Discovery using AdExplorer
- Adding Hidden File Attribute via Attrib
- AdFind Command Activity
- Alternate Data Stream Creation/Execution at Volume Root Directory
- At.exe Command Lateral Movement
- Attempt to Establish VScode Remote Tunnel
- Attempt to Install or Run Kali Linux via WSL
- Attempted Private Key Access
- AWS SSM `SendCommand` with Run Shell Command Parameters
- Backup Deletion with Wbadmin
- Binary Content Copy via Cmd.exe
- Bitsadmin Activity
- Browser Process Spawned from an Unusual Parent
- Bypass UAC via Event Viewer
- Clearing Windows Console History
- Clearing Windows Event Logs
- Code Signing Policy Modification Through Built-in tools
- Command and Scripting Interpreter via Windows Scripts
- Command Execution via ForFiles
- Command Execution via SolarWinds Process
- Command Obfuscation via Unicode Modifier Letters
- Command Shell Activity Started via RunDLL32
- Conhost Spawned By Suspicious Parent Process
- Control Panel Process with Unusual Arguments
- Credential Acquisition via Registry Hive Dumping
- Delayed Execution via Ping
- Delete Volume USN Journal with Fsutil
- Disable Windows Event and Security Logs Using Built-in Tools
- Disable Windows Firewall Rules via Netsh
- Disabling Windows Defender Security Settings via PowerShell
- Enable Host Network Discovery via Netsh
- Encrypting Files with WinRar or 7z
- Enumerating Domain Trusts via DSQUERY.EXE
- Enumerating Domain Trusts via NLTEST.EXE
- Enumeration Command Spawned via WMIPrvSE
- Enumeration of Administrator Accounts
- Execution from a Removable Media with Network Connection
- Execution from Unusual Directory - Command Line
- Execution of a Downloaded Windows Script
- Execution of COM object via Xwizard
- Execution of File Written or Modified by Microsoft Office
- Execution of Persistent Suspicious Program
- Execution via Microsoft DotNet ClickOnce Host
- Execution via MS VisualStudio Pre/Post Build Events
- Execution via TSClient Mountpoint
- Execution via Windows Command Debugging Utility
- Execution via Windows Subsystem for Linux
- Exporting Exchange Mailbox via PowerShell
- File and Directory Permissions Modification
- File or Directory Deletion Command
- File with Right-to-Left Override Character (RTLO) Created/Executed
- First Time Seen Remote Monitoring and Management Tool
- Group Policy Discovery via Microsoft GPResult Utility
- Host File System Changes via Windows Subsystem for Linux
- IIS HTTP Logging Disabled
- ImageLoad via Windows Update Auto Update Client
- Incoming DCOM Lateral Movement via MSHTA
- Incoming DCOM Lateral Movement with MMC
- Incoming DCOM Lateral Movement with ShellBrowserWindow or ShellWindows
- Incoming Execution via PowerShell Remoting
- Incoming Execution via WinRM Remote Shell
- Indirect Command Execution via Forfiles/Pcalua
- InstallUtil Activity
- InstallUtil Process Making Network Connections
- Local Scheduled Task Creation
- Microsoft Build Engine Started by a System Process
- Microsoft Build Engine Started by an Office Application
- Microsoft Build Engine Using an Alternate Name
- Microsoft Exchange Server UM Spawning Suspicious Processes
- Microsoft Exchange Worker Spawning Suspicious Processes
- Microsoft IIS Connection Strings Decryption
- Microsoft IIS Service Account Password Dumped
- Microsoft Management Console File from Unusual Path
- Modification of Boot Configuration
- Mofcomp Activity
- Mounting Hidden or WebDav Remote Shares
- MsBuild Making Network Connections
- Mshta Making Network Connections
- MsiExec Service Child Process With Network Connection
- Multiple Remote Management Tool Vendors on Same Host
- NetSupport Manager Execution from an Unusual Path
- Network Connection via Compiled HTML File
- Network Connection via MsXsl
- Network Connection via Registration Utility
- Network Connection via Signed Binary
- New ActiveSyncAllowedDeviceID Added via PowerShell
- NTDS Dump via Wbadmin
- NTDS or SAM Database File Copied
- Parent Process PID Spoofing
- Peripheral Device Discovery
- Persistence via BITS Job Notify Cmdline
- Persistence via TelemetryController Scheduled Task Hijack
- Persistence via Update Orchestrator Service Hijack
- Persistence via WMI Event Subscription
- Potential Application Shimming via Sdbinst
- Potential Command and Control via Internet Explorer
- Potential Command Shell via NetCat
- Potential Credential Access via Trusted Developer Utility
- Potential Credential Access via Windows Utilities
- Potential CVE-2025-33053 Exploitation
- Potential Data Exfiltration via Rclone
- Potential Defense Evasion via CMSTP.exe
- Potential DLL Side-Loading via Trusted Microsoft Programs
- Potential DNS Tunneling via NsLookup
- Potential Escalation via Vulnerable MSI Repair
- Potential Evasion via Filter Manager
- Potential Execution via FileFix Phishing Attack
- Potential Exploitation of an Unquoted Service Path Vulnerability
- Potential Fake CAPTCHA Phishing Attack
- Potential File Download via a Headless Browser
- Potential File Transfer via Certreq
- Potential File Transfer via Curl for Windows
- Potential Foxmail Exploitation
- Potential Local NTLM Relay via HTTP
- Potential LSASS Clone Creation via PssCaptureSnapShot
- Potential Masquerading as Browser Process
- Potential Masquerading as Business App Installer
- Potential Masquerading as Communication Apps
- Potential Masquerading as System32 Executable
- Potential Modification of Accessibility Binaries
- Potential Notepad Markdown RCE Exploitation
- Potential Privilege Escalation via InstallerFileTakeOver
- Potential Process Injection from Malicious Document
- Potential Protocol Tunneling via Cloudflared
- Potential Protocol Tunneling via Yuze
- Potential Remote Desktop Shadowing Activity
- Potential Remote Desktop Tunneling Detected
- Potential Remote File Execution via MSIEXEC
- Potential Remote Install via MsiExec
- Potential SAP NetWeaver Exploitation
- Potential SharpRDP Behavior
- Potential Veeam Credential Access Command
- Potential Windows Error Manager Masquerading
- Potential WSUS Abuse for Lateral Movement
- Privilege Escalation via Named Pipe Impersonation
- Privileges Elevation via Parent Process PID Spoofing
- Process Activity via Compiled HTML File
- Process Created with a Duplicated Token
- Process Created with an Elevated Token
- Process Creation via Secondary Logon
- Process Discovery Using Built-in Tools
- Process Execution from an Unusual Directory
- Program Files Directory Masquerading
- Proxy Execution via Console Window Host
- Proxy Execution via Windows OpenSSH
- PsExec Network Connection
- Remote Desktop Enabled in Windows Firewall by Netsh
- Remote Desktop File Opened from Suspicious Path
- Remote Execution via File Shares
- Remote File Copy to a Hidden Share
- Remote File Download via Desktopimgdownldr Utility
- Remote File Download via MpCmdRun
- Remote Management Access Launch After MSI Install
- Remote System Discovery Commands
- Remote XSL Script Execution via COM
- Remotely Started Services via RPC
- Renamed Automation Script Interpreter
- Renamed Utility Executed with Short Program Name
- ROT Encoded Python Script Execution
- ScreenConnect Server Spawning Suspicious Processes
- Script Execution via Microsoft HTML Application
- Searching for Saved Credentials via VaultCmd
- Security Software Discovery using WMIC
- Service Command Lateral Movement
- Service Control Spawned via Script Interpreter
- Service DACL Modification via sc.exe
- Signed Proxy Execution via MS Work Folders
- SMB Connections via LOLBin or Untrusted Process
- Startup Folder Persistence via Unsigned Process
- Suspicious .NET Code Compilation
- Suspicious CertUtil Commands
- Suspicious Cmd Execution via WMI
- Suspicious Command Prompt Network Connection
- Suspicious Communication App Child Process
- Suspicious Endpoint Security Parent Process
- Suspicious Execution from a Mounted Device
- Suspicious Execution from a WebDav Share
- Suspicious Execution from INET Cache
- Suspicious Execution from VS Code Extension
- Suspicious Execution via Microsoft Office Add-Ins
- Suspicious Execution via MSIEXEC
- Suspicious Execution via Scheduled Task
- Suspicious Execution via Windows Subsystem for Linux
- Suspicious Execution with NodeJS
- Suspicious Explorer Child Process
- Suspicious HTML File Creation
- Suspicious Instance Metadata Service (IMDS) API Command Line Execution
- Suspicious Inter-Process Communication via Outlook
- Suspicious JavaScript Execution via Deno
- Suspicious JetBrains TeamCity Child Process
- Suspicious Microsoft Antimalware Service Execution
- Suspicious Microsoft Diagnostics Wizard Execution
- Suspicious Microsoft HTML Application Child Process
- Suspicious MS Office Child Process
- Suspicious MS Outlook Child Process
- Suspicious Outlook Child Process
- Suspicious PDF Reader Child Process
- Suspicious Process Execution via Renamed PsExec Executable
- Suspicious ScreenConnect Client Child Process
- Suspicious Shell Execution via Velociraptor
- Suspicious SolarWinds Child Process
- Suspicious Troubleshooting Pack Cabinet Execution
- Suspicious WerFault Child Process
- Suspicious Windows Command Shell Arguments
- Suspicious Windows Powershell Arguments
- Suspicious WMIC XSL Script Execution
- Suspicious Zoom Child Process
- Symbolic Link to Shadow Copy Created
- System File Ownership Change
- System Information Discovery via Windows Command Shell
- System Service Discovery through built-in Windows Utilities
- System Shells via Services
- System Time Discovery
- UAC Bypass Attempt via Elevated COM Internet Explorer Add-On Installer
- UAC Bypass Attempt via Windows Directory Masquerading
- UAC Bypass Attempt with IEditionUpgradeManager Elevated COM Interface
- UAC Bypass via DiskCleanup Scheduled Task Hijack
- UAC Bypass via ICMLuaUtil Elevated COM Interface
- UAC Bypass via Windows Firewall Snap-In Hijack
- Unusual Child Process from a System Virtual Process
- Unusual Child Process of dns.exe
- Unusual Child Processes of RunDLL32
- Unusual Execution via Microsoft Common Console File
- Unusual Network Activity from a Windows System Binary
- Unusual Network Connection via DllHost
- Unusual Network Connection via RunDLL32
- Unusual Parent Process for cmd.exe
- Unusual Parent-Child Relationship
- Unusual Print Spooler Child Process
- Unusual Process Execution on WBEM Path
- Unusual Process Execution Path - Alternate Data Stream
- Unusual Process Extension
- Unusual Process For MSSQL Service Accounts
- Unusual Process Network Connection
- Unusual Service Host Child Process - Childless Service
- User Account Creation
- Veeam Backup Library Loaded by Unusual Process
- Volume Shadow Copy Deleted or Resized via VssAdmin
- Volume Shadow Copy Deletion via PowerShell
- Volume Shadow Copy Deletion via WMIC
- Whoami Process Activity
- Windows Account or Group Discovery
- Windows Defender Exclusions Added via PowerShell
- Windows Firewall Disabled via PowerShell
- Windows Installer with Suspicious Properties
- Windows Network Enumeration
- Windows Sandbox with Sensitive Configuration
- Windows Script Executing PowerShell
- Windows Script Execution from Archive
- Windows Script Interpreter Executing Process via WMI
- Windows Server Update Service Spawning Suspicious Processes
- Windows Subsystem for Linux Enabled via Dism Utility
- Windows System Information Discovery
- Wireless Credential Dumping using Netsh Command
- WMI Incoming Lateral Movement
- WMI WBEMTEST Utility Execution
- WMIC Remote Command
Splunk (812)
- .msc Executed from Unusual Location (Windows Event Log)
- 1 or 2 Character Executable (Windows Event Log)
- 3CXDesktopApp.exe Execution (EDR)
- 3CXDesktopApp.exe Execution (Windows Event Log)
- 7zip CommandLine To SMB Share Path
- Abuse EQNEDT32.EXE (EDR)
- Abuse EQNEDT32.EXE (Windows Event Log)
- Access Common Package Config file (EDR)
- Access Common Package Config file (Windows Event Log)
- Account Password Changed from Command Line - Windows (Windows Event Log)
- Account set to active via Net.exe (EDR)
- Account set to active via Net.exe (Windows Event Log)
- Add or Set Windows Defender Exclusion
- ADExplorer Execution (Windows Event Log)
- ADExplorer Snapshot Creation (Windows Event Log)
- Adfind Commands (Windows Event Log)
- Adfind Execution (EDR)
- Adfind Execution (Windows Event Log)
- Advanced IP or Port Scanner Execution
- Advanced IP Scanner Execution (Windows Event Log)
- Advanced Port Scanner Execution (Windows Event Log)
- Allow File And Printing Sharing In Firewall
- Allow Network Discovery In Firewall
- Anomalous usage of 7zip
- AnyDesk Command Line Execution (Windows Event Log)
- AnyDesk Execution from Suspicious Folder (Windows Event Log)
- AnyDesk Silent Install (Windows Event Log)
- Application Discovery - Windows (Windows Event Log)
- ATBroker.exe Execution (Windows Event Log)
- Attacker Tools On Endpoint
- Attempted Veeam Database Credential Dump (Windows Event Log)
- Attrib.exe Metasploit File Dropper (EDR)
- Attrib.exe Metasploit File Dropper (Windows Event Log)
- AutoHotkey Execution (Windows Event Log)
- AutoIt Execution (Windows Event Log)
- Bash -c Execution - Windows (Windows Event Log)
- Bcdedit Command Back To Normal Mode Boot
- BCDEdit Failure Recovery Modification
- BITS Job Persistence
- BITSAdmin Download File
- BITSadmin Execution (Windows Event Log)
- BitsAdmin NetCat PowerCat File Transfer (EDR)
- BitsAdmin NetCat PowerCat File Transfer (Windows Event Log)
- Browser Started with Remote Debugging - Windows (Windows Event Log)
- CDB Execution (Windows Event Log)
- Certificate Abuse - Windows (Windows Event Log)
- Certificate Enumeration - Windows (Windows Event Log)
- Certutil De-Obfuscate_Decode Files (Windows Event Log)
- Certutil exe certificate extraction
- Certutil Execution (Windows Event Log)
- Certutil File Download (Windows Event Log)
- Certutil Obfuscate_Encode Files (EDR)
- Certutil Obfuscate_Encode Files (Windows Event Log)
- Certutil Root Certificate Install (Windows Event Log)
- CertUtil With Decode Argument
- Change To Safe Mode With Network Config
- Check Elevated CMD using whoami
- Child Processes of Spoolsv exe
- Cipher.exe Execution (Windows Event Log)
- Clear Unallocated Sector Using Cipher App
- Clop Common Exec Parameter
- CMD Carry Out String Command Parameter
- CMD Echo Pipe - Escalation
- CMD execution with _c (Windows Event Log)
- Cmstp Execution (Windows Event Log)
- Command Line .cmd Execution (Windows Event Log)
- Command Line Homoglyphs - Windows (Windows Event Log)
- Command Line lsass request (Windows Event Log)
- Command Line Spawned by Archive Utility - Windows (Windows Event Log)
- Command Line Utility Added to Accessibility Features (Windows Event Log)
- Command Output Redirected to Localhost (Windows Event Log)
- Command-Line Interface Execution (Windows Event Log)
- Common Active Directory Commands (Windows Event Log)
- Common LSASS Memory Dump Behavior (Windows Event Log)
- Common Recon Commands in Short Burst (Windows Event Log)
- Common Reconnaissance Commands (Windows Event Log)
- Compressed File Execution (Windows Event Log)
- ComputerDefaults UAC Bypass (Windows Event Log)
- comsvcs.dll Lsass Memory Dump (Windows Event Log)
- Conhost.exe Kernel call (Windows Event Log)
- Consent.exe Suspicious Child Process (Windows Event Log)
- ConsentPromptBehaviorAdmin Registry Value Modified (Windows Event Log)
- Conti Common Exec parameter
- Control Loading from World Writable Directory
- Control Panel Abuse (Windows Event Log)
- Control_RunDLL Call from Command Line (Windows Event Log)
- Create or delete windows shares using net exe
- Create_Add Local_Domain User (EDR)
- Create_Add Local_Domain User (Windows Event Log)
- Create_Modify Schtasks (Windows Event Log)
- Creation of Shadow Copy
- Creation of Shadow Copy with wmic and powershell
- Credential Dumping via Copy Command from Shadow Copy
- Credential Dumping via Symlink to Shadow Copy
- Credentials in Registry (Windows Event Log)
- CSC Execution (EDR)
- CSC Execution (Windows Event Log)
- CSC Net On The Fly Compilation
- CSVDE Export Active Directory (Windows Event Log)
- Curl Execution with Percent Encoded URL
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (EDR)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Windows Event Log)
- Data Exfiltration via AWS CLI - Windows (Windows Event Log)
- Data Staged to File (Windows Event Log)
- Defender Registry Values Modified (Windows Event Log)
- Deleting Shadow Copies
- Detect AzureHound Command-Line Arguments
- Detect Certify Command Line Arguments
- Detect HTML Help Renamed
- Detect HTML Help Spawn Child Process
- Detect HTML Help URL in Command Line
- Detect HTML Help Using InfoTech Storage Handlers
- Detect mshta inline hta execution
- Detect mshta renamed
- Detect MSHTA Url in Command Line
- Detect Path Interception By Creation Of program exe
- Detect Prohibited Applications Spawning cmd exe
- Detect PsExec With accepteula Flag
- Detect Rare Executables
- Detect RClone Command-Line Usage
- Detect Regasm Spawning a Process
- Detect Regasm with no Command Line Arguments
- Detect Regsvcs Spawning a Process
- Detect Regsvcs with No Command Line Arguments
- Detect Regsvr32 Application Control Bypass
- Detect Remote Access Software Usage Process
- Detect Renamed 7-Zip
- Detect Renamed PSExec
- Detect Renamed RClone
- Detect Renamed WinRAR
- Detect RTLO In Process
- Detect Rundll32 Inline HTA Execution
- Detect SharpHound Command-Line Arguments
- Detect SharpHound Usage
- Detect Use of cmd exe to Launch Script Interpreters
- Detection of tools built by NirSoft
- Disable Logs Using WevtUtil
- Disable Schedule Task
- Disabled Pre-Authentication Accounts Discovery - PowerShell (Sysmon)
- Disabled Pre-Authentication Accounts Discovery - PowerShell (Windows Event Log)
- Disabling Firewall with Netsh
- Discovery using CHCP (Windows Event Log)
- DLL Called with RS32 (Windows Event Log)
- DLL Called with Uncommon Function (Windows Event Log)
- DLL Concatenation (Windows Event Log)
- DLL Execution from Uncommon Process (Windows Event Log)
- DLLRegisterServer Called from Command Line (Windows Event Log)
- DNS Exfiltration Using Nslookup App
- DNX.exe Proxy Execution (Windows Event Log)
- Domain Account Discovery with Dsquery
- Domain Account Discovery with Wmic
- Domain Controller Discovery with Nltest
- Domain Controller Discovery with Wmic
- Domain Controller Enumeration via nltest (Windows Event Log)
- Domain Group Discovery With Dsquery
- Domain Group Discovery With Wmic
- Domain Trust Discovery Commands - Windows (Windows Event Log)
- Dotnet.exe Execution (Windows Event Log)
- Driver as Command Parameter (Windows Event Log)
- DSQuery Domain Discovery
- Dump File Identified (Windows Event Log)
- Dump LSASS via comsvcs DLL
- Dump LSASS via procdump
- Dxcap Proxy Execution (Windows Event Log)
- Elevated Group Discovery With Wmic
- EnableLUA Registry Value Modified (Windows Event Log)
- Encoded Powershell Command (Windows Event Log)
- Esentutl Execution (Windows Event Log)
- Esentutl SAM Copy
- Event Logs Queried for RDP Sessions (Windows Event Log)
- Excessive Attempt To Disable Services
- Excessive distinct processes from Windows Temp
- Excessive number of service control start as disabled
- Excessive number of taskhost processes
- Excessive Usage Of Cacls App
- Excessive Usage of NSLOOKUP App
- Excessive Usage Of Taskkill
- Executable Create Script Process (Windows Event Log)
- Executable Process from Suspicious Folder (Windows Event Log)
- Execute Javascript With Jscript COM CLSID
- Execution from Startup Folder (Windows Event Log)
- Execution of File with Multiple Extensions
- Exfiltration via curl.exe - Windows (Windows Event Log)
- Expand.exe Execution (Windows Event Log)
- File and Directory Discovery Output to File - Windows (Windows Event Log)
- File Download or Read to Pipe Execution
- File Executed from INetCache (Windows Event Log)
- File_Folder Hidden - Windows (Windows Event Log)
- Finger Execution (Windows Event Log)
- Firewall Allowed Program Enable
- First Time Seen Child Process of Zoom
- FodHelper UAC Bypass
- FScan.exe Network Scan (Windows Event Log)
- Fsutil fsinfo execution (EDR)
- Fsutil fsinfo execution (Windows Event Log)
- Fsutil Zeroing File
- Full Control Permissions Granted to Everyone - Windows (Windows Event Log)
- Get ADDefaultDomainPasswordPolicy with Powershell
- Get ADUser with PowerShell
- Get ADUserResultantPasswordPolicy with Powershell
- Get DomainPolicy with Powershell
- Get DomainUser with PowerShell
- Get WMIObject Group Discovery
- Get-DomainTrust with PowerShell
- Get-ForestTrust with PowerShell
- GetAdComputer with PowerShell
- GetAdGroup with PowerShell
- GetCurrent User with PowerShell
- GetDomainComputer with PowerShell
- GetDomainController with PowerShell
- GetDomainGroup with PowerShell
- GetLocalUser with PowerShell
- GetNetTcpconnection with PowerShell
- GetWmiObject Ds Computer with PowerShell
- GetWmiObject Ds Group with PowerShell
- GetWmiObject DS User with PowerShell
- GetWmiObject User Account with PowerShell
- Git Spawns System32 Process (Windows Event Log)
- Git Submodule Cloned - Windows (Windows Event Log)
- Go Run Execution (Windows Event Log)
- Group Policy Editor Execution (Windows Event Log)
- Headless Browser Mockbin or Mocky Request
- Headless Browser Usage
- hh.exe Execution (Windows Event Log)
- hh.exe Remote File Execution (Windows Event Log)
- Hidden User Created - Windows (Windows Event Log)
- Hiding Files And Directories With Attrib exe
- HTTP_HTTPS Default Security Zone Modified to Local Machine (Windows Event Log)
- Hunting 3CXDesktopApp Software
- Icacls Deny Command
- ICACLS Grant Command
- IcedID Discovery Commands (EDR)
- IcedID Discovery Commands (Windows Event Log)
- IIS Worker (W3WP) Spawn Command Line (Windows Event Log)
- Impacket atexec.py Execution (Windows Event Log)
- Impacket Lateral Movement Activity (Windows Event Log)
- Impacket Lateral Movement Commandline Parameters
- Impacket Lateral Movement smbexec CommandLine Parameters
- Impacket Lateral Movement WMIExec Commandline Parameters
- Impacket PSexec (Windows Event Log)
- Impacket SMBexec (Windows Event Log)
- Impacket_Empire's WMIExec (Windows Event Log)
- Indirect Command Execution (Windows Event Log)
- Invoke-DCOM.ps1 - PowerShell (Windows Event Log)
- Invoke-Expression Command (Windows Event Log)
- Invoke-WebRequest Command (Windows Event Log)
- Known Process Injection Commands (Windows Event Log)
- Live Sysinternals Execution (Windows Event Log)
- Local Account Discovery With Wmic
- LocalAccountTokenFilterPolicy Registry Value Modified (Windows Event Log)
- Locate Credentials (Windows Event Log)
- Logon Script Registry Key added (EDR)
- Logon Script Registry Key added (Windows Event Log)
- LSA Authentication Packages Registry Key Modified (Windows Event Log)
- Malicious Document Execution (Windows Event Log)
- Malicious PowerShell Process - Encoded Command
- Malicious PowerShell Process - Execution Policy Bypass
- masscan Execution - Windows (Windows Event Log)
- Mavinject Execution (EDR)
- Mavinject Execution (Windows Event Log)
- Mega Utility Execution - Windows (Windows Event Log)
- Microsoft Build Engine Suspicious Parent Process (Windows Event Log)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (EDR)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (Windows Event Log)
- Microsoft SQL Server Suspicious Child Process - Windows (Windows Event Log)
- Mimikatz (Windows Event Log)
- Mimikatz Execution (Windows Event Log)
- Mimikatz PassTheTicket CommandLine Parameters
- Mmc LOLBAS Execution Process Spawn
- Mock System Directory - Windows (Windows Event Log)
- Modify ACL permission To Files Or Folder
- Modify Windows Defender (EDR)
- Modify Windows Defender (Windows Event Log)
- MSBuild Suspicious Spawned By Script Process
- Mshta spawning Rundll32 OR Regsvr32 Process
- MSHTA.exe execution (Windows Event Log)
- mshta.exe File Download (Windows Event Log)
- MSI Installation via Appcert (Windows Event Log)
- Msiexec Abuse (Windows Event Log)
- MSIExec.exe Execution (Windows Event Log)
- MSTSC Execution (EDR)
- MSTSC Execution (Windows Event Log)
- Msxsl Execution (EDR)
- Msxsl Execution (Windows Event Log)
- MultiDump.exe Execution (Windows Event Log)
- Multiple nslookup commands (Windows Event Log)
- Native Archive Commands (Windows Event Log)
- Net.exe Use with URL (Windows Event Log)
- Network Connection Discovery With Arp
- Network Connection Discovery With Netstat
- Network Discovery Using Route Windows App
- ngen.exe File Download (Windows Event Log)
- ngrok Execution - Windows (Windows Event Log)
- NirCmd Execution (Windows Event Log)
- Nishang PowershellTCPOneLine
- NLTest Domain Trust Discovery
- NMAP Execution (EDR)
- NMAP Execution (Windows Event Log)
- Non-MSIExec .msi Installation (Windows Event Log)
- Notepad with no Command Line Arguments
- Nslookup Execution (Windows Event Log)
- ntds.dit Access from Unexpected Location (Windows Event Log)
- ntds.dit Command Line (Windows Event Log)
- Ntdsutil Export NTDS
- NTDSUtil.exe execution (Windows Event Log)
- Office Binary Download Remote File (Windows Event Log)
- Office Spawns Suspicious Child Process (Windows Event Log)
- Output to File (Windows Event Log)
- Package installation (Windows Event Log)
- Parent in Public Folder Suspicious Process (Windows Event Log)
- Password Spraying Windows (Windows Event Log)
- Permission Groups Discovery: Domain Groups (Windows Event Log)
- Permission Groups Discovery: Local Groups (Windows Event Log)
- Permission Modification using Takeown App
- Permissions Replaced by icacls - Windows (Windows Event Log)
- Possible Browser Pass View Parameter
- Possible Credential Dumping via Windows Network Providers (Windows Event Log)
- Potential AutoHotkey .ahk Execution (Windows Event Log)
- Potential Cryptomining Commands (Windows Event Log)
- Potential CVE-2023-23397 (EDR)
- Potential CVE-2023-23397 (Windows Event Log)
- Potential Executable Masquerading as Document - Windows (Windows Event Log)
- Potential fodhelper UAC Bypass Attempt (Windows Event Log)
- Potential LSA password filter (Windows Event Log)
- Potential Ping Sweep (Windows Event Log)
- Potential PowerShell Post-Exploitation Activity (Windows Event Log)
- Potential Proxy Malware via AutoRun Key (Windows Event Log)
- Potential Sysinternals Tool Execution (Windows Event Log)
- Potential System Network Configuration Discovery Activity
- Potential Telegram API Request Via CommandLine
- PowerHuntShares Commands (Windows Event Log)
- PowerShell - Connect To Internet With Hidden Window
- PowerShell CreateDecryptor (Windows Event Log)
- Powershell Disable Security Monitoring
- PowerShell Downgrade (Sysmon)
- PowerShell Downgrade (Windows Event Log)
- PowerShell DownloadFile_DownloadString (Windows Event Log)
- PowerShell Get LocalGroup Discovery
- PowerShell Hidden Window (Windows Event Log)
- PowerShell Modifying Registry Values (Windows Event Log)
- PowerShell Start-BitsTransfer
- PowerShell XML Retrieval (Windows Event Log)
- Prevent Automatic Repair Mode using Bcdedit
- ProcDump Credential Harvest (Windows Event Log)
- Process Creation Using Sysnative Folder (Windows Event Log)
- Process Executed from Downloads Folder - Windows (Windows Event Log)
- Process Executed with Null Command Line (Windows Event Log)
- Process Execution From Suspicious Folder (Windows Event Log)
- Process Execution via WMI
- Process Kill Base On File Path
- PromptOnSecureDesktop Registry Value Modified (Windows Event Log)
- ProtocolHandler.exe File Download (Windows Event Log)
- Proxy Execution via Appcert (Windows Event Log)
- PuTTY Secure Copy Client Execution (Windows Event Log)
- pypykatz commands (Windows Event Log)
- Python Execution (Windows Event Log)
- QEMU Network Tunneling - Windows (Windows Event Log)
- Query Registry (Windows Event Log)
- Radmin execution (EDR)
- Radmin execution (Windows Event Log)
- Rare executable from Microsoft Office (Windows Event Log)
- Rare Process Execution (Windows Event Log)
- Rclone Execution (Windows Event Log)
- RDP Enabled (Windows Event Log)
- RDP File Executed from Outlook Temp Directory (Windows Event Log)
- RDP Hijacking (Windows Event Log)
- RdrLeakDiag.exe Memory Dump (Windows Event Log)
- Read-Only Attribute Removed - Windows (Windows Event Log)
- Recursive Delete of Directory In Batch CMD
- Reg exe Manipulating Windows Services Registry Keys
- Reg.exe Process Execution (Windows Event Log)
- Regini.exe Execution (Windows Event Log)
- Registry key added with reg.exe (Windows Event Log)
- regsvr32 Execution (Windows Event Log)
- regsvr32 Referencing Unusual Paths (Windows Event Log)
- Regsvr32 Silent and Install Param Dll Loading
- Regsvr32 with Known Silent Switch Cmdline
- Remote .msi Installation (Windows Event Log)
- Remote .msi Installation (Windows Event Log)
- Remote Access Software Execution (Windows Event Log)
- Remote Admin Tools (EDR)
- Remote Admin Tools (Windows Event Log)
- Remote Desktop Process Running On System
- Remote Process Instantiation via DCOM and PowerShell
- Remote Process Instantiation via WinRM and PowerShell
- Remote Process Instantiation via WinRM and Winrs
- Remote Process Instantiation via WMI
- Remote Process Instantiation via WMI and PowerShell
- Remote Share Directory Listing - Windows (Windows Event Log)
- Remote System Discovery with Dsquery
- Remote System Discovery with Wmic
- Remote WMI Command Attempt
- Remote WMIC Query (Windows Event Log)
- Resize ShadowStorage volume
- Revil Common Exec Parameter
- Rubeus Command Line Parameters
- Rubeus Commands (Windows Event Log)
- Runas Execution in CommandLine
- RunDLL Loading DLL By Ordinal
- Rundll32 Command Line (Windows Event Log)
- Rundll32 Control RunDLL Hunt
- Rundll32 Control RunDLL World Writable Directory
- Rundll32 LockWorkStation
- Rundll32 Shimcache Flush
- Rundll32 Spawned by Disk Cleanup (Windows Event Log)
- Rundll32 Suspicious Command Line (Windows Event Log)
- rundll32 Suspicious Parent Process (Windows Event Log)
- rundll32 with No DLL in Command Line (Windows Event Log)
- Rundll32.exe as Parent Process (Windows Event Log)
- rundll32.exe Executing DLL from Non-standard Directory (Windows Event Log)
- Ryuk Wake on LAN Command
- Scheduled Task Creation on Remote Endpoint using At
- Scheduled Task Deleted Or Created via CMD
- Scheduled Task Initiation on Remote Endpoint
- Scheduled Task with Potential SSH Tunnel - Windows (Windows Event Log)
- Schtasks Run Task On Demand
- Schtasks scheduling job on remote system
- Schtasks used for forcing a reboot
- Script Execution via WMI
- Sdelete Application Execution
- SecretDumps Offline NTDS Dumping Tool
- Security Software Discovery via Findstr.exe (Windows Event Log)
- Security Software Discovery via WMI (Windows Event Log)
- Service Stop Commands (Windows Event Log)
- ServicePrincipalNames Discovery with SetSPN
- Services Escalate Exe
- Services LOLBAS Execution Process Spawn
- Shell Spawned by Web Server - Windows (Windows Event Log)
- Shim Database Installation With Suspicious Parameters
- SimpleHelp Remote Access Tool Execution (Windows Event Log)
- Single Letter Process On Endpoint
- Sliver C2 Implant Activity Pattern (Windows Event Log)
- SLUI RunAs Elevated
- SLUI Spawning a Process
- SoftPerfect Network Scanner Execution (Windows Event Log)
- Spoolsv Spawning Rundll32
- Spoolsv Writing a DLL
- ssh.exe Execution (Windows Event Log)
- Startup Folder Location Modified - Windows (Windows Event Log)
- Suspicious AteraAgent Installation - Windows (Windows Event Log)
- Suspicious Child Process for hh.exe (Windows Event Log)
- Suspicious Child Process for lsass.exe (Windows Event Log)
- Suspicious Child Process for mshta.exe (Windows Event Log)
- Suspicious ComputerDefaults.exe Execution (Windows Event Log)
- Suspicious Confluence Child Process - Windows (Windows Event Log)
- Suspicious Conhost.exe Commands (Windows Event Log)
- Suspicious Copy on System32
- Suspicious csc.exe Source File Folder (Windows Event Log)
- Suspicious Curl Network Connection
- Suspicious DLLhost Execution (EDR)
- Suspicious DLLhost Execution (Windows Event Log)
- Suspicious DLLHost no Command Line Arguments
- Suspicious Executable by CMD.exe (Windows Event Log)
- Suspicious Executable by Powershell (EDR)
- Suspicious Executable by Powershell (Windows Event Log)
- Suspicious Execution of Accessibility Tool Debuggers (Windows Event Log)
- Suspicious Execution via Microsoft Common Console (Windows Event Log)
- Suspicious GPUpdate no Command Line Arguments
- Suspicious IcedID Rundll32 Cmdline
- Suspicious InprocServer32 Registry Modification (Windows Event Log)
- Suspicious microsoft workflow compiler rename
- Suspicious microsoft workflow compiler usage
- Suspicious msbuild path
- Suspicious MSBuild Rename
- Suspicious MSBuild Spawn
- Suspicious mshta child process
- Suspicious mshta spawn
- Suspicious ntds.dit Commands (Windows Event Log)
- Suspicious Parent Process for lsass.exe or services.exe (Windows Event Log)
- Suspicious Parent Process for msiexec.exe (Windows Event Log)
- Suspicious Parent Process for spoolsv.exe (Windows Event Log)
- Suspicious PlistBuddy Usage
- Suspicious PowerShell Clipboard Activity (Windows Event Log)
- Suspicious PowerShell Parameter Substring (Windows Event Log)
- Suspicious Process Executed From Container File
- Suspicious process Spawned by Java (Windows Event Log)
- Suspicious Reg exe Process
- Suspicious Regsvr32 Register Suspicious Path
- Suspicious Rundll32 dllregisterserver
- Suspicious Rundll32 no Command Line Arguments
- Suspicious Rundll32 PluginInit
- Suspicious Rundll32 StartW
- Suspicious Scheduled Task from Public Directory
- Suspicious SearchProtocolHost no Command Line Arguments
- Suspicious SQLite3 LSQuarantine Behavior
- Suspicious WAV file in Appdata Folder
- Suspicious wevtutil Usage
- Svchost LOLBAS Execution Process Spawn
- Symbolic OR Hard File Link Created (Windows Event Log)
- SyncAppvPublishingServer Execution (Windows Event Log)
- System Enumeration with WMIC (Windows Event Log)
- System Info Gathering Using Dxdiag Application
- System Information Discovery - Windows (Windows Event Log)
- System Information Discovery Detection
- System Network Connections Discovery - Windows (Windows Event Log)
- System Owner_User Discovery - Windows (Windows Event Log)
- System Processes Run From Unexpected Locations
- System Time enumeration (Windows Event Log)
- System User Discovery With Query
- System User Discovery With Whoami
- Task Manager lsass Dump (Windows Event Log)
- Temporary File Executed from Public Folder (Windows Event Log)
- Timestamp Manipulation (Windows Event Log)
- Tunneling Process Created (Windows Event Log)
- Uninstall App Using MsiExec
- Unload Sysmon Filter Driver
- Unusual AppCert Child Process (Windows Event Log)
- Unusual svchost Child Process (Windows Event Log)
- Unusual winlogon.exe Child Process (Windows Event Log)
- Unusually Long Command Line
- User Discovery With Env Vars PowerShell
- User_Domain Enumeration Tool - Windows (Windows Event Log)
- USN Journal Deletion
- Utility Archive Data (Windows Event Log)
- Verclsid CLSID Execution
- Visio.exe File Download (Windows Event Log)
- Visual Studio Code Tunnel Execution (Windows Event Log)
- WBAdmin Delete System Backups
- WDigest Forced Credential Caching (Windows Event Log)
- WebDAV LNK Execution (Windows Event Log)
- WebLogic CVE-2017-10271 (Windows Event Log)
- Wermgr Process Spawned CMD Or Powershell Process
- Windows - Service Stop (Windows Event Log)
- Windows AdFind Exe
- Windows Advanced Installer MSIX with AI_STUBS Execution
- Windows Alternate DataStream - Process Execution
- Windows Apache Benchmark Binary
- Windows AppCertDLL Modification Via Command Line
- Windows Application Whitelisting Bypass Attempt via Rundll32
- Windows Archive Collected Data via Rar
- Windows Attempt To Stop Security Service
- Windows Audit Policy Auditing Option Disabled via Auditpol
- Windows Audit Policy Cleared via Auditpol
- Windows Audit Policy Disabled via Auditpol
- Windows Audit Policy Disabled via Legacy Auditpol
- Windows Audit Policy Excluded Category via Auditpol
- Windows Audit Policy Restored via Auditpol
- Windows Audit Policy Security Descriptor Tampering via Auditpol
- Windows AutoIt3 Execution
- Windows Azure Storage Utility Execution Via CLI
- Windows Binary Proxy Execution Mavinject DLL Injection
- Windows BitLocker Suspicious Command Usage
- Windows BitLockerToGo Process Execution
- Windows Bypass UAC via Pkgmgr Tool
- Windows C$ Share Access (EDR)
- Windows Cabinet File Extraction Via Expand
- Windows Cached Domain Credentials Reg Query
- Windows Certutil Root Certificate Addition
- Windows Change File Association Command To Notepad
- Windows Chrome Enable Extension Loading via Command-Line
- Windows Chromium Browser Launched with Small Window Size
- Windows Chromium Browser No Security Sandbox Process
- Windows Chromium Browser with Custom User Data Directory
- Windows Chromium process Launched with Disable Popup Blocking
- Windows Chromium Process Launched with Logging Disabled
- Windows Chromium Process Loaded Extension via Command-Line
- Windows Chromium Process with Disabled Extensions
- Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc
- Windows Cisco Secure Endpoint Unblock File Via Sfc
- Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc
- Windows Cmdline Tool Execution From Non-Shell Process
- Windows COM Hijacking InprocServer32 Modification
- Windows Command and Scripting Interpreter Hunting Path Traversal
- Windows Command and Scripting Interpreter Path Traversal Exec
- Windows Command Obfuscation with Environment Variable Substrings
- Windows Compatibility Telemetry Suspicious Child Process
- Windows ConHost with Headless Argument
- Windows Copy Files (Windows Event Log)
- Windows Create Local Administrator Account Via Net
- Windows Credential Dumping LSASS Memory Createdump
- Windows Credentials from Password Stores Creation
- Windows Credentials from Password Stores Deletion
- Windows Credentials from Password Stores Query
- Windows Credentials in Registry Reg Query
- Windows Curl Download to Suspicious Path
- Windows Curl Upload to Remote Destination
- Windows Debugger Tool Execution
- Windows Default Group Policy Object Modified with GPME
- Windows Defender ASR or Threat Configuration Tamper
- Windows Defender Disabled Detection (EDR)
- Windows Defender Disabled Detection (Windows Event Log)
- Windows Delete or Modify System Firewall
- Windows Devtunnels Execution
- Windows Disable Internet Explorer Addons
- Windows Disable or Modify Tools Via Taskkill
- Windows Disable Windows Event Logging Disable HTTP Logging
- Windows DiskCryptor Usage
- Windows Diskshadow Proxy Execution
- Windows DISM Install PowerShell Web Access
- Windows DISM Remove Defender
- Windows DLL Search Order Hijacking with iscsicpl
- Windows DLL Side-Loading Process Child Of Calc
- Windows DNS Gather Network Info
- Windows DotNet Binary in Non Standard Path
- Windows EDRSilencer Execution
- Windows EFI Volume Mount Attempt Via Mountvol
- Windows Entra User Management Via Azure CLI
- Windows ESX Admins Group Creation via Net
- Windows Eventlog Cleared Via Wevtutil
- Windows EventLog Recon Activity Using Log Query Utilities
- Windows Excel Spawning Microsoft Project Application
- Windows Excessive Service Stop Attempt
- Windows Excessive Usage Of Net App
- Windows Execute Arbitrary Commands with MSDT
- Windows Execution of Microsoft MSC File In Suspicious Path
- Windows Explorer LNK Exploit Process Launch With Padding
- Windows Explorer.exe Spawning PowerShell or Cmd
- Windows File and Directory Enable ReadOnly Permissions
- Windows File and Directory Permissions Enable Inheritance
- Windows File and Directory Permissions Remove Inheritance
- Windows File Association Modification via Ftype
- Windows File Collection Via Copy Utilities
- Windows File Download Via CertUtil
- Windows File Download Via PowerShell
- Windows Files and Dirs Access Rights Modification Via Icacls
- Windows Findstr GPP Discovery
- Windows Firewall Disabled (Windows Event Log)
- Windows Firewall Rule Creation (Windows Event Log)
- Windows FTP Exfiltration (Windows Event Log)
- Windows Gdrive Binary Activity
- Windows Get-Variable.EXE Execution from WindowsApps Folder
- Windows Global Object Access Audit List Cleared Via Auditpol
- Windows Group Discovery Via Net
- Windows Guest Account Enabled Via Net.EXE
- Windows Identify Protocol Handlers
- Windows IIS Components Add New Module
- Windows Impair Defense Add Xml Applocker Rules
- Windows Indicator Removal Via Rmdir
- Windows Indirect Command Execution Via Series Of Forfiles
- Windows Information Discovery Fsutil
- Windows Ingress Tool Transfer Using Explorer
- Windows InstallUtil in Non Standard Path
- Windows InstallUtil Uninstall Option
- Windows InstallUtil URL in Command Line
- Windows IOBit Unlocker Extension DLL Registration via Regsvr32
- Windows Ldifde Directory Object Behavior
- Windows List ENV Variables Via SET Command From Uncommon Parent
- Windows Local LLM Framework Execution
- Windows LOLBAS Executed As Renamed File
- Windows LOLBAS Executed Outside Expected Path
- Windows Masquerading Explorer As Child Process
- Windows Masquerading Msdtc Process
- Windows Metasploit Confluence Plugin Execution
- Windows Mimikatz Binary Execution
- Windows Modify Registry Regedit Silent Reg Import
- Windows Modify System Firewall with Notable Process Path
- Windows MOF Event Triggered Execution via WMI
- Windows MpCmdRun RemoveDefinitions Execution
- Windows MSC EvilTwin Directory Path Manipulation
- Windows MSIExec DLLRegisterServer
- Windows MsiExec HideWindow Rundll32 Execution
- Windows MSIExec Remote Download
- Windows MSIExec Spawn Discovery Command
- Windows MSIExec Spawn WinDBG
- Windows MSIExec Unregister DLLRegisterServer
- Windows MSTSC RDP Commandline
- Windows Mustang Panda USB Tool Execution
- Windows Net System Service Discovery
- Windows Netspy Network Scanner Execution
- Windows Network Connection Discovery Via Net
- Windows Network Share Interaction Via Net
- Windows New Deny Permission Set On Service SD Via Sc.EXE
- Windows New Service Security Descriptor Set Via Sc.EXE
- Windows Ngrok Reverse Proxy Usage
- Windows NirSoft AdvancedRun
- Windows NirSoft Utilities
- Windows NorthStar C2 Agent Execution
- Windows Odbcconf Hunting
- Windows Odbcconf Load DLL
- Windows Odbcconf Load Response File
- Windows Office Product Dropped Cab or Inf File
- Windows Office Product Spawned Child Process For Download
- Windows Office Product Spawned Control
- Windows Office Product Spawned MSDT
- Windows Office Product Spawned Rundll32 With No DLL
- Windows Office Product Spawned Uncommon Process
- Windows OneDrive Share Mounted via Net
- Windows PaperCut NG Spawn Shell
- Windows Parent PID Spoofing with Explorer
- Windows Password Managers Discovery
- Windows Password Policy Discovery with Net
- Windows Phishing PDF File Executes URL Link
- Windows Potato Privilege Escalation Tool Execution
- Windows Potential Cloudflared Tunnel Execution
- Windows PowerShell FakeCAPTCHA Clipboard Execution
- Windows PowerShell Process Implementing Manual Base64 Decoder
- Windows PowerShell Process With Malicious String
- Windows Powershell RemoteSigned File
- Windows PowerShell Script From WindowsApps Directory
- Windows Private Keys Discovery
- Windows Privilege Escalation Attempt Via MSI Rollback
- Windows Process Commandline Discovery
- Windows Process Copied from System Folder (Windows Event Log)
- Windows Process Execution From ProgramData
- Windows Process Execution From RDP Share
- Windows Process Execution in Temp Dir
- Windows Process Injection In Non-Service SearchIndexer
- Windows Process Injection Wermgr Child Process
- Windows Process Outside of System Folder (Windows Event Log)
- Windows Process With NamedPipe CommandLine
- Windows Process With NetExec Command Line Parameters
- Windows Protocol Tunneling with Plink
- Windows Proxy Execution of .NET Utilities via Scripts
- Windows Proxy Via Netsh
- Windows PsTools Recon Usage
- Windows PuTTY Suite Utility Execution
- Windows Raccine Scheduled Task Deletion
- Windows Rasautou DLL Execution
- Windows RDP File Execution
- Windows Registry Entries Exported Via Reg
- Windows Registry Entries Restored Via Reg
- Windows Regsvr32 Renamed Binary
- Windows Remote Assistance Spawning Process
- Windows Remote Create Service
- Windows Remote Host Computer Management Access
- Windows Remote Management Execute Shell
- Windows Remote Service Rdpwinst Tool Execution
- Windows Remote Services Allow Rdp In Firewall
- Windows Rundll32 Apply User Settings Changes
- Windows Rundll32 Execution With Log.DLL
- Windows Rundll32 WebDAV Request
- Windows Rundll32 with Non-Standard File Extension
- Windows Scheduled Task Created Via XML
- Windows Scheduled Task with Highest Privileges
- Windows Schtasks Create Run As System
- Windows ScManager Security Descriptor Tampering Via Sc.EXE
- Windows Security Account Manager Stopped
- Windows Security Support Provider Reg Query
- Windows Sensitive Group Discovery With Net
- Windows Sensitive Registry Hive Dump Via CommandLine
- Windows Server Software Component GACUtil Install to GAC
- Windows Service Create Kernel Mode Driver
- Windows Service Create with Tscon
- Windows Service Created (Windows Event Log)
- Windows Service Creation on Remote Endpoint
- Windows Service Execution RemCom
- Windows Service Initiation on Remote Endpoint
- Windows Service Started (Windows Event Log)
- Windows Service Stop Attempt
- Windows Service Stop By Deletion
- Windows Set Account Password Policy To Unlimited Via Net
- Windows Set Custom DNS ServerLevelPlugin Via Dnscmd
- Windows Shell Process from CrushFTP
- Windows SOAPHound Binary Execution
- Windows Spearphishing Attachment Onenote Spawn Mshta
- Windows SpeechRuntime Suspicious Child Process
- Windows SQL Spawning CertUtil
- Windows SQLCMD Execution
- Windows Sqlservr Spawning Shell
- Windows Steal Authentication Certificates CertUtil Backup
- Windows Steal Authentication Certificates Export Certificate
- Windows Steal Authentication Certificates Export PfxCertificate
- Windows Steal or Forge Kerberos Tickets Klist
- Windows SubInAcl Execution
- Windows Suspicious Child Process Spawned From WebServer
- Windows Suspicious Process File Path
- Windows Suspicious VMWare Tools Child Process
- Windows Svchost.exe Parent Process Anomaly
- Windows SymbolicLink-Testing-Tools Utility Execution
- Windows Symlink Evaluation Change via Fsutil
- Windows System Binary Proxy Execution Compiled HTML File Decompile
- Windows System Discovery Using ldap Nslookup
- Windows System Discovery Using Qwinsta
- Windows System LogOff Commandline
- Windows System Network Config Discovery Display DNS
- Windows System Network Connections Discovery Netsh
- Windows System Reboot CommandLine
- Windows System Remote Discovery With Query
- Windows System Script Proxy Execution Syncappvpublishingserver
- Windows System Shutdown CommandLine
- Windows System Time Discovery W32tm Delay
- Windows System User Discovery Via Quser
- Windows System User Privilege Discovery
- Windows TeamCity Payload Execution from Temp Directory
- Windows Time Based Evasion via Choice Exec
- Windows TinyCC Shellcode Execution
- Windows TOR Client Execution
- Windows UAC Bypass Suspicious Child Process
- Windows Unusual SysWOW64 Process Run System32 Executable
- Windows User Deletion Via Net
- Windows User Disabled Via Net
- Windows User Discovery Via Net
- Windows WBAdmin File Recovery From Backup
- Windows WinDBG Spawning AutoIt3
- Windows WinRAR Launched Outside Default Installation Directory
- Windows WMI Process And Service List
- Windows WMI Process Call Create
- Windows WMI Reconnaissance Class Query
- Windows Wmic CPU Discovery
- Windows Wmic DiskDrive Discovery
- Windows Wmic Memory Chip Discovery
- Windows Wmic Network Discovery
- Windows Wmic Systeminfo Discovery
- Windows WSUS Spawning Shell
- Winhlp32 Spawning a Process
- WinRAR Spawning Shell Application
- WinRM Spawning a Process
- WinRM Tools (Windows Event Log)
- WinSCP Execution (Windows Event Log)
- WMI subscription execution (Windows Event Log)
- WMIC Explicit Credentials (Windows Event Log)
- Wmic Group Discovery
- WMIC Host Reconniassance (Windows Event Log)
- Wmic NonInteractive App Uninstallation
- WMIC XSL Execution via URL
- Wmiprvse LOLBAS Execution Process Spawn
- WmiPrvSE Suspicious Child Process (Windows Event Log)
- Wow6432Node Classes Autorun Keys Modification (Windows Event Log)
- Wscript Or Cscript Suspicious Child Process
- Wscript_Cscript Execution (Windows Event Log)
- Wsmprovhost LOLBAS Execution Process Spawn
- XSL Script Execution With WMIC
Kusto (93)
- Access Token Manipulation - Create Process with Token
- Account Creation
- Base64 encoded Windows process command-lines
- Base64 encoded Windows process command-lines (Normalized Process Events)
- Bitsadmin Activity
- Caramel Tsunami Actor IOC - July 2021
- Chia_Crypto_Mining IOC - June 2021
- Clearing of forensic evidence from event logs using wevtutil
- Deletion of data on multiple drives using cipher exe
- Detect Malicious Usage of Recovery Tools to Delete Backup Files
- Detect Rare scheduled task created
- Detect Suspicious Commands Initiated by Webserver Processes
- Detect Unknown process launched via WinRM
- Detect Unsigned executable launch from scheduled task
- Detecting UAC bypass - ChangePK and SLUI registry tampering
- Detecting UAC bypass - elevated COM interface
- Detecting UAC bypass - modify Windows Store settings
- Dev-0228 File Path Hashes November 2021
- Dev-0228 File Path Hashes November 2021 (ASIM Version)
- Dev-0270 Malicious Powershell usage
- DEV-0270 New User Creation
- Dev-0270 Registry IOC - September 2022
- Dev-0270 WMIC Discovery
- Disable or Modify Windows Defender
- Disabling Security Services via Registry
- Doppelpaymer Stop Services
- DopplePaymer Procdump
- Email access via active sync
- Exchange Worker Process Making Remote Call
- Execution of software vulnerable to webp buffer overflow of CVE-2023-4863
- Gain Code Execution on ADFS Server via Remote WMI Execution
- Gain Code Execution on ADFS Server via SMB + Remote Service or Scheduled Task
- Identify Mango Sandstorm powershell commands
- Identify SysAid Server web shell creation
- Imminent Ransomware
- Ingress Tool Transfer - Certutil
- Java Executing cmd to run Powershell
- LaZagne Credential Theft
- LSASS Credential Dumping with Procdump
- Malware in the recycle bin
- Malware in the recycle bin (Normalized Process Events)
- Masquerading Renamed executables of interest
- Match Legitimate Name or Location - 2
- Midnight Blizzard - Script payload stored in Registry
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events)
- Network endpoint to host executable correlation
- New EXE deployed via Default Domain or Default Domain Controller Policies
- New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version)
- NRT Base64 Encoded Windows Process Command-lines
- NRT Process executed from binary hidden in Base64 encoded file
- Office Apps Launching Wscipt
- Oracle suspicious command execution
- Persistence Via Scheduled Tasks
- Potential Build Process Compromise
- Potential Build Process Compromise - MDE
- Potential Fodhelper UAC Bypass
- Potential Kerberos Relaying Activity - MDE
- Potential Lateral Movement via MSI ODBC Driver Install over DCOM
- Potential re-named sdelete usage
- Potential re-named sdelete usage (ASIM Version)
- Powershell Empire Cmdlets Executed in Command Line
- Probable AdFind Recon Tool Usage
- Probable AdFind Recon Tool Usage (Normalized Process Events)
- Process Creation with Suspicious CommandLine Arguments
- Process executed from binary hidden in Base64 encoded file
- Process Execution Frequency Anomaly
- Process Tree Analysis
- PRT Credential Stealing
- Qakbot Campaign Self Deletion
- Qakbot Discovery Activies
- Rare Process as a Service
- Regsvr32 Rundll32 with Anomalous Parent Process
- Remote Desktop Protocol - SharpRDP
- Rename System Utilities
- Scheduled Task - Suspicious Network Connection
- Sdelete deployed via GPO and run recursively
- Sdelete deployed via GPO and run recursively (ASIM Version)
- Security Service Registry ACL Modification
- Shadow Copy Deletions
- Silk Typhoon New UM Service Child Process
- SQL Server spawning suspicious child process
- Stopping multiple processes using taskkill
- SUNBURST suspicious SolarWinds child processes
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events)
- Suspicious MSC File Launched
- Suspicious office child process created
- Suspicious parentprocess relationship - Office child processes.
- Trusted Developer Utilities Proxy Execution
- Unsigned Windows System Binary
- Unusual identity creation using exchange powershell
- Windows Binaries Executed from Non-Default Directory
- Zinc Actor IOCs files - October 2022
YARA-L (69)
- Base64 Encoded PowerShell Command Detected
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Copy From Or To Admin Share Or Sysvol Folder
- CreateDump Process Dump
- Direct Autorun Keys Modification
- File Download Using Notepad++ GUP Utility
- File Download Via Windows Defender MpCmpRun.EXE
- Finger.EXE Execution
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GCTI Remote Access Tools
- Google Safebrowsing File Process Creation
- Google Safebrowsing With Prevalence
- HackTool - Dumpert Process Dumper Execution
- Hacktool - IronSharpPack Execution
- HackTool - Mimikatz Execution
- Hacktool - SharpSuccessor Execution
- Hacktool - WinPEAS Execution Patterns
- Hash Prevalence
- Impacket WMIExec CISA Report
- IOC Hash Prevalence
- IOC SHA256 Hash
- IOC SHA256 Hash VT
- Local Accounts Discovery
- Low Prevalence Hash On Process Launch Low Prevalence Domain Accessed
- LSASS Dump Keyword In CommandLine
- MITRE ATT&CK T1003 RW Mimikatz
- MITRE ATT&CK T1003.003 RW Utilities Associated With Ntds.dit
- MITRE ATT&CK T1003.003 WMIC Ntds.dit CISA Report
- MITRE ATT&CK T1021.002 Windows Admin Share Basic
- MITRE ATT&CK T1021.002 Windows Admin Share With Asset Entity
- MITRE ATT&CK T1021.002 Windows Admin Share With User Enrichment
- MITRE ATT&CK T1021.002 Windows Admin Share With User Entity
- MITRE ATT&CK T1033 Recon Successful Logon Enumeration Powershell CISA Report
- MITRE ATT&CK T1053.005 Windows Creation Of Scheduled Task
- MITRE ATT&CK T1090 Port Proxy Forwarding CISA Report
- MITRE ATT&CK T1140 Encoded Powershell Command
- MITRE ATT&CK T1570 Suspicious Command PSExec
- New User Created Via Net.EXE
- potential lsass process dump via procdump
- Potential Suspicious Activity Using SeCEdit
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE
- Potential Webshell Process Execution
- PowerShell DownloadFile
- PowerShell Web Download
- PrintBrm ZIP Creation of Extraction
- Process Launch VT Enrichment
- Process Memory Dump Via Comsvcs.DLL
- Process Memory Dump via RdrLeakDiag.exe
- PUA - Nimgrab Execution
- Purple Knight Tool Execution Detected
- Recon Credential Theft CISA Report
- Recon Environment Enumeration Active Directory CISA Report
- Recon Environment Enumeration Network CISA Report
- Recon Environment Enumeration System CISA Report
- Recon Suspicious Commands CISA Report
- Reg Add Suspicious Paths
- Renamed CreateDump Utility Execution
- Safebrowsing Process Creation Hashes Seen More Than 7 Days
- ShimCache Flush
- Suspicious Certreq Command to Download
- Suspicious Curl.EXE Download
- Suspicious Download Via Certutil.EXE
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
- Suspicious Invoke-WebRequest Execution
- Uncommon or Suspicious RMM Tool Execution Detected
- VT Relationships File Executes File
- W3WP Launching Encoded Powershell
- Whoami Execution
- Windows Event Log Cleared