Kusto rule coverage
118 events across 11 providers with Microsoft Sentinel and Defender XDR Kusto detection rules, 527 rule mappings total.
Microsoft-Windows-Security-Auditing
Event ID 501: AD FS proxy authentication request. 1 rule
- AD FS Remote Auth Sync Connection available
Event ID 4624: An account was successfully logged on. 19 rules
- Brute force attack against user credentials (Uses Authentication Normalization)
- Detection Opportunities for Certighost (CVE-2026-54121)
- EatonForeseer - Unauthorized Logins available
- Failed AzureAD logons but success logon to host
- Gain Code Execution on ADFS Server via Remote WMI Execution
- Gain Code Execution on ADFS Server via SMB + Remote Service or Scheduled Task available
- Multiple RDP connections from Single System
- Non Domain Controller Active Directory Replication available
- Password Spray
- Potential Password Spray Attack (Uses Authentication Normalization)
- Potential Remote Desktop Tunneling available
- Potentially Relayed NTLM Authentication - Microsoft Sentinel
- Potentially Relayed NTLM Authentication - Microsoft Sentinel
- Rare RDP Connections
- RDP Nesting
- SecurityEvent - Multiple authentication failures followed by a success available
- Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization)
- Starting or Stopping HealthService to Avoid Detection available
- User login from different countries within 3 hours (Uses Authentication Normalization)
Event ID 4625: An account failed to log on. 11 rules
- Brute force attack against user credentials (Uses Authentication Normalization)
- EatonForeseer - Unauthorized Logins available
- Excessive Windows Logon Failures available
- Failed host logons but success logon to AzureAD
- Failed logon attempts by valid accounts within 10 mins
- Password Spray
- Potential Password Spray Attack (Uses Authentication Normalization)
- Potential Remote Desktop Tunneling available
- SecurityEvent - Multiple authentication failures followed by a success available
- Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization)
- User login from different countries within 3 hours (Uses Authentication Normalization)
Event ID 4634: An account was logged off. 5 rules
- Brute force attack against user credentials (Uses Authentication Normalization)
- EatonForeseer - Unauthorized Logins available
- Potential Password Spray Attack (Uses Authentication Normalization)
- Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization)
- User login from different countries within 3 hours (Uses Authentication Normalization)
Event ID 4647: User initiated logoff. 1 rule
- EatonForeseer - Unauthorized Logins available
Event ID 4648: A logon was attempted using explicit credentials. 1 rule
- EatonForeseer - Unauthorized Logins available
Event ID 4657: A registry value was modified. 8 rules
- COM Registry Key Modified to Point to File in Color Profile Folder
- Detect Print Processors Registry Driver Key Creation/Modification available
- Detect Registry Run Key Creation/Modification available
- Detect Windows Allow Firewall Rule Addition/Modification available
- Detect Windows Update Disabled from Registry available
- Potential Fodhelper UAC Bypass available
- Potential Fodhelper UAC Bypass (ASIM Version)
- Scheduled Task Hide available
Event ID 4663: An attempt was made to access an object. 18 rules
- Detect Print Processors Registry Driver Key Creation/Modification available
- Detect Registry Run Key Creation/Modification available
- Detect Windows Allow Firewall Rule Addition/Modification available
- Detect Windows Update Disabled from Registry available
- Dev-0530 File Extension Rename
- Europium - Hash and IP IOCs - September 2022
- Google Threat Intelligence - Threat Hunting Hash
- Identify SysAid Server web shell creation
- Mercury - Domain, Hash and IP IOCs - August 2022
- Microsoft Entra ID Health Monitoring Agent Registry Keys Access
- Microsoft Entra ID Health Service Agents Registry Keys Access
- Microsoft Entra ID Local Device Join Information and Transport Key Registry Keys Access available
- Potential Build Process Compromise
- Potential Fodhelper UAC Bypass (ASIM Version)
- Prestige ransomware IOCs Oct 2022
- RecordedFuture Threat Hunting Hash All Actors
- SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)
- Suspicious access of BEC related documents
Event ID 4675: SIDs were filtered. 1 rule
- EatonForeseer - Unauthorized Logins available
Event ID 4688: A new process has been created. 47 rules
- Base64 encoded Windows process command-lines available
- Base64 encoded Windows process command-lines (Normalized Process Events)
- Caramel Tsunami Actor IOC - July 2021 available
- CertUtil Used for File Download (Living off the Land) available
- Chia_Crypto_Mining IOC - June 2021 available
- Detect Malicious Usage of Recovery Tools to Delete Backup Files available
- Dev-0228 File Path Hashes November 2021 (ASIM Version)
- Dev-0270 Malicious Powershell usage available
- DEV-0270 New User Creation available
- Dev-0270 Registry IOC - September 2022 available
- Dev-0270 WMIC Discovery available
- Email access via active sync
- Gain Code Execution on ADFS Server via Remote WMI Execution
- Gain Code Execution on ADFS Server via SMB + Remote Service or Scheduled Task available
- Identify Mango Sandstorm powershell commands
- Identify SysAid Server web shell creation
- Imminent Ransomware available
- Malware in the recycle bin available
- Malware in the recycle bin (Normalized Process Events)
- Midnight Blizzard - Script payload stored in Registry
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events)
- Network endpoint to host executable correlation available
- New EXE deployed via Default Domain or Default Domain Controller Policies available
- New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version)
- NRT Base64 Encoded Windows Process Command-lines available
- NRT Process executed from binary hidden in Base64 encoded file available
- Potential Build Process Compromise
- Potential Fodhelper UAC Bypass available
- Potential Fodhelper UAC Bypass (ASIM Version)
- Potential re-named sdelete usage available
- Potential re-named sdelete usage (ASIM Version)
- Powershell Empire Cmdlets Executed in Command Line available
- PowerShell Encoded Command Execution (Living off the Land) available
- Probable AdFind Recon Tool Usage (Normalized Process Events)
- Process Creation with Suspicious CommandLine Arguments available
- Process executed from binary hidden in Base64 encoded file available
- Process Execution Frequency Anomaly available
- Sdelete deployed via GPO and run recursively available
- Sdelete deployed via GPO and run recursively (ASIM Version)
- Security Service Registry ACL Modification
- Silk Typhoon New UM Service Child Process
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events)
- Unusual identity creation using exchange powershell
- Windows Binaries Executed from Non-Default Directory available
- WMI Spawning Suspicious Child Process (Living off the Land) available
- Zinc Actor IOCs files - October 2022 available
Event ID 4689: A process has exited. 14 rules
- Base64 encoded Windows process command-lines (Normalized Process Events)
- Detect Malicious Usage of Recovery Tools to Delete Backup Files available
- Dev-0228 File Path Hashes November 2021 (ASIM Version)
- Identify Mango Sandstorm powershell commands
- Imminent Ransomware available
- Malware in the recycle bin (Normalized Process Events)
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events)
- New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version)
- Potential Fodhelper UAC Bypass (ASIM Version)
- Potential re-named sdelete usage (ASIM Version)
- Probable AdFind Recon Tool Usage (Normalized Process Events)
- Process Creation with Suspicious CommandLine Arguments available
- Sdelete deployed via GPO and run recursively (ASIM Version)
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events)
Event ID 5136: A directory service object was modified. 18 rules
- AdminSDHolder Modifications
- Exchange OAB Virtual Directory Attribute Containing Potential Webshell available
- Possible Resource-Based Constrained Delegation Abuse
- PROD (TM001.1) - GROUP - Added to Group Outside the Object Tier Level available
- PROD (TM004.1) - OBJECT - Enabled, Disabled, Unlocked, or Password Reset of a Tier Level Object available
- PROD (TM005.1) - GPO - Linked, Unlinked, or Enforced at Tier Level OU available
- PROD (TM006.1) - ACL - Modified at Tier Level OU available
- PROD (TM008.1) - GPO - Linked, Unlinked, or Enforced at Root of Domain available
- PROD (TM009.1) - ACL - Modified at Root of the Domain available
- PROD (TM011.1) - LAPS - Tier Level Computer Object LAPS Password Expiration Time Set Manually available
- PROD (TM012.1) - GPO - Enforced Outside of Tier Model available
- PROD (TM013.1) - OU - Block Inheritance was Enabled on an OU available
- PROD (TM014.1) - GPO - Linked, Unlinked, or Enforced at the AD Site Level available
- PROD (TM015.1) - ACL - Modified at KRBTGT or AdminSDHolder Object Level available
- PROD (TM016.1) - GROUP - Added to Well-Known or Tier Model Group available
- PROD (TM017.1) - GROUP - Tier 0 Added to Allow RODC Password Replication Group available
- Service Principal Name (SPN) Assigned to User Account
- Shadow Credentials Added to Account
Event ID 5137: A directory service object was created. 5 rules
- PROD (TM002.1) - OBJECT - Created or Deleted a Tier Level Object available
- PROD (TM007.1) - OU - Created or Deleted at Tier Level available
- PROD (TM010.1) - BITLOCKER - Stored Bitlocker Recovery Key to Tier Level Computer Object available
- PROD (TM018.1) - DOMAIN - Child Domain promoted within the Forest available
- PROD (TM019.1) - TRUST - A new AD Trust has been established available
Event ID 5152: The Windows Filtering Platform blocked a packet. 17 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Event ID 5154: The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections. 17 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Event ID 5155: The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections. 17 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Event ID 5156: The Windows Filtering Platform has permitted a connection. 19 rules
- AD FS Remote Auth Sync Connection available
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- RITA Beacon Analyzer for Windows Firewall Events
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Event ID 5157: The Windows Filtering Platform has blocked a connection. 17 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Event ID 5158: The Windows Filtering Platform has permitted a bind to a local port. 17 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Event ID 5159: The Windows Filtering Platform has blocked a bind to a local port. 17 rules
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
McAfee-ePolicy-Orchestrator
Event ID 1003: Error starting task 1 rule
- McAfee ePO - Task error available
Event ID 1029: File added to the exceptions list 1 rule
- McAfee ePO - File added to exceptions available
Event ID 1040: Activity log error 1 rule
- McAfee ePO - Logging error occurred available
Event ID 1062: Error sending alert 1 rule
- McAfee ePO - Error sending alert available
Event ID 1067: Unable to start scheduled task 1 rule
- McAfee ePO - Task error available
Event ID 1119: Update failed 1 rule
- McAfee ePO - Update failed available
Event ID 1123: Update failed 1 rule
- McAfee ePO - Update failed available
Event ID 1127: On-access scan engine disabled 1 rule
- McAfee ePO - Scanning engine disabled available
Event ID 2005: File added to the exceptions list 1 rule
- McAfee ePO - File added to exceptions available
Event ID 2015: File added to the exceptions list 1 rule
- McAfee ePO - File added to exceptions available
Event ID 2402: Update failed 1 rule
- McAfee ePO - Update failed available
Event ID 2412: Deployment failed 1 rule
- McAfee ePO - Deployment failed available
Event ID 3032: Error opening or creating the activity log file 1 rule
- McAfee ePO - Logging error occurred available
Event ID 3033: Activity log file maximum size reached 1 rule
- McAfee ePO - Logging error occurred available
Event ID 3034: Unable to write the activity log file 1 rule
- McAfee ePO - Logging error occurred available
Event ID 3036: Error initializing the activity log file 1 rule
- McAfee ePO - Logging error occurred available
Event ID 3038: Error writing to the activity log 1 rule
- McAfee ePO - Logging error occurred available
Event ID 4650: Spam email detected 1 rule
- McAfee ePO - Spam Email detected available
Event ID 16025: Agent Handler is down 1 rule
- McAfee ePO - Agent Handler down available
Event ID 35009: Endpoint firewall disabled 1 rule
- McAfee ePO - Firewall disabled available
Microsoft-Windows-Sysmon
Event ID 1: Process creation 30 rules
- [Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022 available
- Audit policy manipulation using auditpol utility
- Base64 encoded Windows process command-lines (Normalized Process Events)
- COM Event System Loading New DLL
- Detect Malicious Usage of Recovery Tools to Delete Backup Files available
- Detecting Macro Invoking ShellBrowserWindow COM Objects available
- Dev-0228 File Path Hashes November 2021 (ASIM Version)
- Email access via active sync
- Europium - Hash and IP IOCs - September 2022
- Gain Code Execution on ADFS Server via Remote WMI Execution
- Identify Mango Sandstorm powershell commands
- Imminent Ransomware available
- Lateral Movement via DCOM available
- Malware in the recycle bin (Normalized Process Events)
- Mercury - Domain, Hash and IP IOCs - August 2022
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events)
- Modification of Accessibility Features
- New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version)
- Potential Fodhelper UAC Bypass (ASIM Version)
- Potential re-named sdelete usage (ASIM Version)
- Prestige ransomware IOCs Oct 2022
- Probable AdFind Recon Tool Usage (Normalized Process Events)
- Process Creation with Suspicious CommandLine Arguments available
- Process Tree Analysis
- Sdelete deployed via GPO and run recursively (ASIM Version)
- Spearphishing Attachment: ISO Images (Microsoft Sentinel)
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events)
- T1566.002 Spearphishing Link - Rare URL Clicks
- Windows Binaries Lolbins Renamed available
- Zinc Actor IOCs files - October 2022 available
Event ID 3: Network connection 25 rules
- [Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022 available
- AD FS Remote HTTP Network Connection available
- Anomaly found in Network Session Traffic (ASIM Network Session schema) available
- Anomaly in SMB Traffic(ASIM Network Session schema) available
- Detect port misuse by anomaly based detection (ASIM Network Session schema) available
- Detect port misuse by static threshold (ASIM Network Session schema) available
- Europium - Hash and IP IOCs - September 2022
- Excessive number of failed connections from a single source (ASIM Network Session schema) available
- Google Threat Intelligence - Threat Hunting IP
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema) available
- HoneyLabs TI Map IP Entity to Network Session (ASIM)
- Log4j vulnerability exploit aka Log4Shell IP IOC available
- Mercury - Domain, Hash and IP IOCs - August 2022
- Network Port Sweep from External Network (ASIM Network Session schema) available
- Port scan detected (ASIM Network Session schema) available
- Possible Phishing with CSL and Network Sessions available
- Potential beaconing activity (ASIM Network Session schema) available
- RecordedFuture Threat Hunting IP All Actors
- Remote Desktop Network Brute force (ASIM Network Session schema) available
- Server Network Connection Anomalies
- Spearphishing Attachment: ISO Images (Microsoft Sentinel)
- Suspicious Network Beacons - Sysmon
- ThreatConnect TI map IP entity to Network Session Events (ASIM Network Session schema)
- TI Map IP entity to Network Session Events (ASIM Network Session schema) available
- TI map IP entity to Network Session Events (ASIM Network Session schema) available
Event ID 5: Process terminated 14 rules
- Base64 encoded Windows process command-lines (Normalized Process Events)
- Detect Malicious Usage of Recovery Tools to Delete Backup Files available
- Dev-0228 File Path Hashes November 2021 (ASIM Version)
- Identify Mango Sandstorm powershell commands
- Imminent Ransomware available
- Malware in the recycle bin (Normalized Process Events)
- Midnight Blizzard - suspicious rundll32.exe execution of vbscript (Normalized Process Events)
- New EXE deployed via Default Domain or Default Domain Controller Policies (ASIM Version)
- Potential Fodhelper UAC Bypass (ASIM Version)
- Potential re-named sdelete usage (ASIM Version)
- Probable AdFind Recon Tool Usage (Normalized Process Events)
- Process Creation with Suspicious CommandLine Arguments available
- Sdelete deployed via GPO and run recursively (ASIM Version)
- SUNBURST suspicious SolarWinds child processes (Normalized Process Events)
Event ID 10: ProcessAccess 1 rule
- Dumping LSASS Process Into a File available
Event ID 11: FileCreate 11 rules
- Credential Dumping Tools - File Artifacts available
- Dev-0530 File Extension Rename
- Europium - Hash and IP IOCs - September 2022
- Google Threat Intelligence - Threat Hunting Hash
- Identify SysAid Server web shell creation
- Mercury - Domain, Hash and IP IOCs - August 2022
- Prestige ransomware IOCs Oct 2022
- RecordedFuture Threat Hunting Hash All Actors
- Spearphishing Attachment: ISO Images (Microsoft Sentinel)
- SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)
- Suspicious access of BEC related documents
Event ID 13: RegistryEvent (Value Set) 10 rules
- Detect Print Processors Registry Driver Key Creation/Modification available
- Detect Registry Run Key Creation/Modification available
- Detect Windows Allow Firewall Rule Addition/Modification available
- Detect Windows Update Disabled from Registry available
- DSRM Account Abuse
- Potential Fodhelper UAC Bypass (ASIM Version)
- Registry Persistence via AppCert DLL Modification available
- Registry Persistence via AppInit DLLs Modification available
- Spearphishing Attachment: ISO Images (Microsoft Sentinel)
- WDigest downgrade attack available
Event ID 22: DNSEvent (DNS query) 21 rules
- Detect DNS queries reporting multiple errors from different clients - Anomaly Based (ASIM DNS Solution) available
- Detect DNS queries reporting multiple errors from different clients - Static threshold based (ASIM DNS Solution) available
- Detect excessive NXDOMAIN DNS queries - Anomaly based (ASIM DNS Solution) available
- Detect excessive NXDOMAIN DNS queries - Static threshold based (ASIM DNS Solution) available
- DNS events related to mining pools (ASIM DNS Schema)
- DNS events related to ToR proxies (ASIM DNS Schema)
- Excessive NXDOMAIN DNS Queries (ASIM DNS Schema)
- Google Threat Intelligence - Threat Hunting Domain
- Known Forest Blizzard group domains - July 2019
- Ngrok Reverse Proxy on Network (ASIM DNS Solution) available
- Potential DGA detected (ASIM DNS Schema)
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Anomaly based (ASIM DNS Solution) available
- Potential DGA(Domain Generation Algorithm) detected via Repetitive Failures - Static threshold based (ASIM DNS Solution) available
- Rare client observed with high reverse DNS lookup count - Anomaly based (ASIM DNS Solution) available
- Rare client observed with high reverse DNS lookup count - Static threshold based (ASIM DNS Solution) available
- RecordedFuture Threat Hunting Domain All Actors
- Star Blizzard C2 Domains August 2022
- TI Map Domain entity to Dns Events (ASIM DNS Schema)
- TI map Domain entity to Dns Events (ASIM DNS Schema)
- TI Map IP entity to DNS Events (ASIM DNS schema)
- TI map IP entity to DNS Events (ASIM DNS schema)
Event ID 23: FileDelete (File Delete archived) 9 rules
- Dev-0530 File Extension Rename
- Europium - Hash and IP IOCs - September 2022
- Google Threat Intelligence - Threat Hunting Hash
- Identify SysAid Server web shell creation
- Mercury - Domain, Hash and IP IOCs - August 2022
- Prestige ransomware IOCs Oct 2022
- RecordedFuture Threat Hunting Hash All Actors
- SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)
- Suspicious access of BEC related documents
Event ID 26: FileDeleteDetected (File Delete logged) 9 rules
- Dev-0530 File Extension Rename
- Europium - Hash and IP IOCs - September 2022
- Google Threat Intelligence - Threat Hunting Hash
- Identify SysAid Server web shell creation
- Mercury - Domain, Hash and IP IOCs - August 2022
- Prestige ransomware IOCs Oct 2022
- RecordedFuture Threat Hunting Hash All Actors
- SUNBURST and SUPERNOVA backdoor hashes (Normalized File Events)
- Suspicious access of BEC related documents
Microsoft-Windows-AppLocker
Microsoft-Windows-Windows-Defender
Semperis-Operation-Log
Event ID 20002: DSP failed logon 1 rule
- Semperis DSP Failed Logons available
Event ID 20012: DSP RBAC change 1 rule
- Semperis DSP RBAC Changes available
AD-FS-Auditing
MOVEit-DMZ-Audit
Microsoft-Windows-Eventlog
Event ID 1102: The audit log was cleared. 2 rules
- NRT Security Event log cleared available
- Security Event log cleared available