Sigma rule coverage
328 events across 69 providers with Sigma detection rules, 4302 rule mappings total.
Microsoft-Windows-Security-Auditing
Event ID 675: Pre-authentication failed (legacy Windows 2003 Kerberos event; superseded by 4771). 1 rule
Event ID 4611: A trusted logon process has been registered with the Local Security Authority. 1 rule
Event ID 4616: The system time was changed. 2 rules
- System time changed experimental
- Unauthorized System Time Modification test
Event ID 4622: A security package has been loaded by the Local Security Authority. 1 rule
- Security package (SSP) loaded into LSA (native) experimental
Event ID 4624: An account was successfully logged on. 29 rules
- Active Directory honeypot used for lateral movement experimental
- Admin User Remote Logon test
- Administrator login impersonation with forged Golden ticket stable
- Anonymous access performed to multiple targets experimental
- Anonymous login (RottenPotatoNG) experimental
- Azure Windows virtual machine login via serial console experimental
- Detection of default a Windows host name in login attempts experimental
- DiagTrackEoP Default Login Username test
- Exchange server impersonation via PrivExchange relay attack experimental
- External Remote RDP Logon from Public IP test
- External Remote SMB Logon from Public IP test
- Hacktool Ruler test
- Metasploit SMB Authentication test
- Mimikatz Pass-the-hash login experimental
- NetSYnc attack experimental
- Network login performed to multiple targets experimental
- Outgoing Logon with New Credentials test
- Pass the Hash Activity 2 stable
- Potential Access Token Abuse test
- Potential Privilege Escalation via Local Kerberos Relay over LDAP test
- Potential Remote WMI ActiveScriptEventConsumers Activity test
- Privilege escalation via runas (command) experimental
- RDP Login from Localhost test
- RottenPotato Like Attack Pattern test
- Success login attempt on a Windows OpenSSH server experimental
- Successful Account Login Via WMI stable
- Successful Overpass the Hash Attempt test
- Suspicious anonymous login (domain specified) experimental
- User password change without previous password known - SetNTLM (Mimikatz) experimental
Event ID 4625: An account failed to log on. 11 rules
- Account Tampering - Suspicious Failed Logon Reasons test
- Active Directory honeypot used for lateral movement experimental
- Brutforce enumeration on Windows OpenSSH server with non existing user experimental
- Brutforce enumeration with non existing users (login) experimental
- Brutforce on Windows OpenSSH server with valid users experimental
- Brutforce with denied access due to account restrictions policies experimental
- Detection of default a Windows host name in login attempts experimental
- Failed Logon From Public IP test
- Hacktool Ruler test
- Metasploit SMB Authentication test
- Scanner PoC for CVE-2019-0708 RDP RCE Vuln test
Event ID 4656: A handle to an object was requested. 18 rules
- Azure AD Health Monitoring Agent Registry Keys Access test
- Azure AD Health Service Agents Registry Keys Access test
- BlueSky Ransomware Artefacts test
- CVE-2023-23397 Exploitation Attempt test
- LSASS Access From Non System Account test
- LSASS credential dump with LSASSY (kernel access) experimental
- LSASS process dump by a non system account experimental
- Password Dumper Activity on LSASS test
- Potential Secure Deletion with SDelete test
- Potentially Suspicious AccessMask Requested From LSASS test
- Processes Accessing the Microphone and Webcam test
- SAM Registry Hive Handle Request test
- SCM Database Handle Failure test
- Sticky key sethc file failed replacement experimental
- SysKey Registry Keys Access test
- WCE wceaux.dll Access test
- Windows Defender Exclusion Registry Key - Write Access Requested test
- WinRM listening service reconnaissance (WS-Management) experimental
Event ID 4661: A handle to an object was requested. 9 rules
- AD Privileged Users or Groups Reconnaissance test
- Domain password policy enumeration experimental
- Local domain group enumeration experimental
- Massive SAM users/groups enumeration (native) experimental
- Password Policy Enumerated test
- Potential SAM database user credentials dumped with DCshadow experimental
- Reconnaissance Activity test
- SAM database user credentials dump with Mimikatz experimental
- Sensitive SAM domain user & groups discovery (native) experimental
Event ID 4662: An operation was performed on an object. 13 rules
- Account accessed to attributes related to DCshadow experimental
- Active Directory honeypot enumerated by a suspicious host (Bloodhound) experimental
- Active Directory Replication from Non Machine Account - DcSync Indicator test
- AD Object WriteDAC Access test
- Domain group enumeration experimental
- DPAPI Domain Backup Key Extraction test
- Group Managed Service Accounts password dump - GoldenGMSA experimental
- Potential AD User Enumeration From Non-Machine Account test
- Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation experimental
- Replication privileges accessed to perform DCSync attack experimental
- Suspicious Active Directory DPAPI attributes accessed (Mimikatz, DCSync, RiskySPN) experimental
- Suspicious Machine Account Replication - DcSync Indicator test
- WMI Persistence - Security test
Event ID 4663: An attempt was made to access an object. 22 rules
- Access To Browser Credential Files By Uncommon Applications - Security test
- Azure AD Health Monitoring Agent Registry Keys Access test
- Azure AD Health Service Agents Registry Keys Access test
- BlueSky Ransomware Artefacts test
- CVE-2023-23397 Exploitation Attempt test
- CVE-2024-1708 - ScreenConnect Path Traversal Exploitation - Security test
- File Access Of Signal Desktop Sensitive Data experimental
- ISO Image Mounted test
- LSASS Access From Non System Account test
- LSASS credential dump with LSASSY (kernel access) experimental
- LSASS process dump by a non system account experimental
- Potential Secure Deletion with SDelete test
- Potentially Suspicious AccessMask Requested From LSASS test
- Processes Accessing the Microphone and Webcam test
- ScreenConnect User Database Modification - Security test
- Service Registry Key Read Access Request test
- Suspicious Teams Application Related ObjectAcess Event test
- SysKey Registry Keys Access test
- Sysmon Channel Reference Deletion test
- Task Manager used for LSASS dump (kernel) experimental
- WCE wceaux.dll Access test
- Windows Defender Exclusion Registry Key - Write Access Requested test
Event ID 4664: An attempt was made to create a hard link. 1 rule
- NTFS hard link creation experimental
Event ID 4674: An operation was attempted on a privileged object. 4 rules
- Backdoor introduction via registry permission change through WMI (DAMP) experimental
- Impacket DCOMexec privilege abuse via MMC experimental
- PSexec service installation experimental
- SCM Database Privileged Operation test
Event ID 4688: A new process has been created. 735 rules
- Abusing Print Executable test
- Adwind RAT / JRAT test
- Anonymous login (RottenPotatoNG) experimental
- APT27 - Emissary Panda Activity test
- APT29 2018 Phishing Campaign CommandLine Indicators stable
- APT31 Judgement Panda Activity test
- Arbitrary Binary Execution Using GUP Utility test
- Arbitrary File Download Via GfxDownloadWrapper.EXE test
- Arbitrary File Download Via Squirrel.EXE test
- Arbitrary MSI Download Via Devinit.EXE test
- Arbitrary Shell Command Execution Via Settingcontent-Ms test
- AspNetCompiler Execution test
- Assembly Loading Via CL_LoadAssembly.ps1 test
- Attempts of Kerberos Coercion Via DNS SPN Spoofing experimental
- Audio Capture via PowerShell test
- Audio Capture via SoundRecorder test
- Audit policy disabled by command line experimental
- Audit policy enumerated experimental
- Audit Policy Tampering Via NT Resource Kit Auditpol test
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl test
- Base64 Encoded PowerShell Command Detected test
- Base64 MZ Header In CommandLine test
- BitLocker feature configuration (Reg via command) experimental
- BitLockerTogo.EXE Execution test
- BITS payload downloaded via commandline experimental
- Blue Mockingbird test
- Browser Execution In Headless Mode test
- Browser Started with Remote Debugging test
- Bypass UAC via Fodhelper.exe test
- Cab File Extraction Via Wusa.EXE test
- Cab File Extraction Via Wusa.EXE From Potentially Suspicious Paths test
- Certificate Exported Via PowerShell test
- Certutil payload download (command) experimental
- Certutil payload obfuscation (command) experimental
- Certutil payload obfuscation - Tchopper (command) experimental
- Certutil root certificate installation experimental
- Changing Existing Service ImagePath Value Via Reg.EXE test
- Chopper Webshell Process Pattern test
- Chromium Browser Headless Execution To Mockbin Like Site test
- Chromium Browser Instance Executed With Custom Extension test
- ClickOnce Deployment Execution - Dfsvc.EXE Child Process test
- Cloudflared Portable Execution test
- Cloudflared Tunnel Connections Cleanup test
- Cloudflared Tunnel Execution test
- Cmd.EXE Missing Space Characters Execution Anomaly test
- CMSTP Execution Process Creation stable
- COLDSTEEL RAT Anonymous User Process Execution test
- COLDSTEEL RAT Service Persistence Execution test
- COM Object Execution via Xwizard.EXE test
- Command Line Execution with Suspicious URL and AppData Strings test
- Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791) experimental
- Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788) experimental
- Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790) experimental
- Compress Data and Lock With Password for Exfiltration With WINZIP test
- Conti NTDS Exfiltration Command test
- Conti Volume Shadow Listing test
- Copy From VolumeShadowCopy Via Cmd.EXE test
- Cscript/Wscript Potentially Suspicious Child Process test
- Curl Download And Execute Combination test
- DarkGate - User Created Via Net.EXE test
- Defrag Deactivation test
- Delete All Scheduled Tasks test
- Deletion of Volume Shadow Copies via WMI with PowerShell test
- Detected Windows Software Discovery test
- DeviceCredentialDeployment Execution test
- Devtoolslauncher.exe Executes Specified Binary test
- Diamond Sleet APT Process Activity Indicators test
- Disabled guest or builtin account activated (command)
- Disabled IE Security Features test
- Disabled Volume Snapshots test
- Discovery of a System Time test
- Diskshadow Child Process Spawned test
- Diskshadow command abuse to expose VSS backup experimental
- DLL Execution Via Register-cimprovider.exe test
- DLL ServerLevelPluginDll command installation experimental
- DLL Sideloading by VMware Xfer Utility test
- Dllhost.EXE Execution Anomaly test
- DNS Exfiltration and Tunneling Tools Execution test
- DNS RCE CVE-2020-1350 test
- DoT (DNS over TLS) activation (command) stable
- Droppers Exploiting CVE-2017-11882 stable
- Dropping Of Password Filter DLL test
- DSInternals Suspicious PowerShell Cmdlets test
- DSRM password changed (Reg via command) experimental
- Dumping Process via Sqldumper.exe test
- DumpStack.log Defender Evasion test
- Dynamic .NET Compilation Via Csc.EXE - Hunting test
- EAP service activation by Liontail framework for DLL sideloading (via command) stable
- Edge abuse for payload download via console experimental
- Edge/Chrome headless feature abuse for payload download experimental
- Elise Backdoor Activity test
- Email Exifiltration Via Powershell test
- Emotet Loader Execution Via .LNK File test
- Enable LM Hash Storage - ProcCreation test
- Encoded PowerShell payload deployed via process execution experimental
- Enumeration for 3rd Party Creds From CLI test
- Enumeration for Credentials in Registry test
- Equation Group DLL_U Export Function Load stable
- Esentutl Gather Credentials test
- ETW Logging Tamper In .NET Processes Via CommandLine test
- ETW Trace Evasion Activity test
- Event log clear attempt (command) experimental
- Event log clear attempt (wmi) experimental
- Event log deactivation or size reduction (command) experimental
- EvilNum APT Golden Chickens Deployment Via OCX Files test
- Execute Code with Pester.bat test
- Execute Files with Msdeploy.exe test
- Execute From Alternate Data Streams test
- Execute Pcwrun.EXE To Leverage Follina test
- Execution From Webserver Root Folder test
- Execution Of Non-Existing File test
- Execution of Powershell Script in Public Folder test
- Execution of Suspicious File Type Extension test
- Execution via stordiag.exe test
- Execution via WorkFolders.exe test
- Exploit for CVE-2015-1641 stable
- Exploit for CVE-2017-0261 test
- Exploit for CVE-2017-8759 test
- Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC test
- Exploited CVE-2020-10189 Zoho ManageEngine test
- Exploiting CVE-2019-1388 stable
- Explorer Process Tree Break test
- File Download From Browser Process Via Inline URL test
- File Download with Headless Browser test
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell test
- File or Folder Permissions Modifications test
- Files Added To An Archive Using Rar.EXE test
- Fireball Archer Install test
- Firewall configuration enumerated (command) experimental
- Firewall deactivation (deprecated command) experimental
- Firewall deactivation (modern command) experimental
- Firewall rule creation (command) experimental
- Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet test
- Gpresult Display Group Policy Information test
- Greenbug Espionage Group Indicators test
- Griffon Malware Attack Pattern test
- Grixba Malware Reconnaissance Activity experimental
- Group discovery (command)
- Gzip Archive Decode Via PowerShell test
- HackTool - ADCSPwn Execution test
- HackTool - Covenant PowerShell Launcher test
- HackTool - CrackMapExec Execution test
- HackTool - CrackMapExec Execution Patterns stable
- HackTool - CrackMapExec Process Patterns test
- HackTool - Default PowerSploit/Empire Scheduled Task Creation test
- HackTool - DInjector PowerShell Cradle Execution test
- HackTool - Empire PowerShell Launch Parameters test
- HackTool - Empire PowerShell UAC Bypass stable
- HackTool - F-Secure C3 Load by Rundll32 test
- HackTool - Hashcat Password Cracker Execution test
- HackTool - HollowReaper Execution experimental
- HackTool - Htran/NATBypass Execution test
- HackTool - Hydra Password Bruteforce Execution test
- HackTool - Impacket Tools Execution test
- HackTool - LaZagne Execution experimental
- HackTool - Mimikatz Execution test
- HackTool - NetExec Execution experimental
- HackTool - Pypykatz Credentials Dumping Activity test
- HackTool - Quarks PwDump Execution test
- HackTool - RedMimicry Winnti Playbook Execution test
- HackTool - SharpWSUS/WSUSpendu Execution test
- HackTool - Sliver C2 Implant Activity Pattern test
- HackTool - SOAPHound Execution test
- HackTool - WinPwn Execution test
- HackTool - WinRM Access Via Evil-WinRM test
- HackTool - Wmiexec Default Powershell Command test
- HackTool - XORDump Execution test
- HAFNIUM Exchange Exploitation Activity test
- Hermetic Wiper TG Process Patterns test
- Hidden Powershell in Link File Pattern test
- Hiding User Account Via SpecialAccounts Registry Key - CommandLine test
- HTML File Opened From Download Folder experimental
- HTML Help HH.EXE Suspicious Child Process test
- IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32 test
- IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI test
- IFM creation detected from commandline (installation from media) experimental
- ImagingDevices Unusual Parent/Child Processes test
- Impacket DCOMexec process abuse via MMC experimental
- Import PowerShell Modules From Suspicious Directories - ProcCreation test
- Indirect Command Execution By Program Compatibility Wizard test
- Indirect Command Execution via SFTP ProxyCommand experimental
- InfDefaultInstall.exe .inf Execution test
- Injected Browser Process Spawning Rundll32 - GuLoader Activity test
- Interactive AT Job test
- Interactive privileged shell triggered by schedule task (deprecated) experimental
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) test
- Invoke-Obfuscation CLIP+ Launcher test
- Invoke-Obfuscation COMPRESS OBFUSCATION test
- Invoke-Obfuscation Obfuscated IEX Invocation test
- Invoke-Obfuscation STDIN+ Launcher test
- Invoke-Obfuscation VAR+ Launcher test
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION test
- Invoke-Obfuscation Via Stdin test
- Invoke-Obfuscation Via Use Clip test
- Invoke-Obfuscation Via Use MSHTA test
- Java Running with Remote Debugging test
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution experimental
- Kavremover Dropped Binary LOLBIN Usage test
- Lace Tempest Cobalt Strike Download test
- Lateral movement by mounting a network share - net use (command) experimental
- Launch-VsDevShell.PS1 Proxy Execution test
- Lazarus Group Activity test
- Lazarus System Binary Masquerading test
- LockerGoga Ransomware Activity stable
- Lolbin Runexehelper Use As Proxy test
- LSASS Dump Keyword In CommandLine test
- Malicious PE Execution by Microsoft Visual Studio Debugger test
- Malicious PowerShell Commandlets - ProcessCreation test
- Manual Execution of Script Inside of a Compressed File test
- Massive processes termination burst experimental
- Massive services deletion burst experimental
- Massive services termination burst experimental
- Mavinject Inject DLL Into Running Process test
- MERCURY APT Activity test
- Metasploit reverse shell injection in SQL Server experimental
- Microsoft Defender critical security components disabled (command) experimental
- Microsoft Defender default action changed to allow any threat (command) experimental
- Microsoft Defender security components disabled (command) experimental
- Microsoft Defender service deactivation attempt (command) experimental
- Mint Sandstorm - AsperaFaspex Suspicious Process Execution test
- Mint Sandstorm - Log4J Wstomcat Process Execution test
- Mint Sandstorm - ManageEngine Suspicious Process Execution test
- MMC Spawning Windows Shell test
- MMC20 Lateral Movement test
- MSDT Execution Via Answer File test
- MSExchange Transport Agent Installation test
- Mshtml.DLL RunHTMLApplication Suspicious Usage test
- MsiExec Web Install test
- Msxsl.EXE Execution test
- Mustang Panda Dropper test
- Netsh helper DLL abuse (process) experimental
- Network Reconnaissance Activity test
- Network share discovery and/or connection via commandline
- Network share manipulation via commandline
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE test
- New Kernel Driver Via SC.EXE test
- New Process Created Via Taskmgr.EXE test
- New Service Creation Using PowerShell test
- New Service Creation Using Sc.EXE test
- Node Process Executions test
- Non-privileged Usage of Reg or Powershell test
- Notepad Password Files Discovery experimental
- NotPetya Ransomware Activity test
- NtdllPipe Like Activity Execution test
- NTFS symbolic link configuration change experimental
- NTFS symbolic link creation experimental
- Number of oustanding SMB requests increased experimental
- Obfuscated IP Download Activity test
- Obfuscated IP Via CLI test
- Obfuscated payload transfered via service name - Tchopper (command) experimental
- Obfuscated PowerShell OneLiner Execution test
- OilRig APT Activity test
- OneNote.EXE Execution of Malicious Embedded Scripts test
- OpenEDR Spawning Command Shell experimental
- OpenSSH server firewall configuration on Windows (command) experimental
- OpenWith.exe Executes Specified Binary test
- Operation Wocao Activity test
- Outlook EnableUnsafeClientMailRules Setting Enabled test
- PaperCut MF/NG Exploitation Related Indicators test
- PaperCut MF/NG Potential Exploitation test
- Password policy discovery via commandline
- Peach Sandstorm APT Process Activity Indicators test
- Persistence Via Sticky Key Backdoor test
- Persistence Via TypedPaths - CommandLine test
- Phishing Pattern ISO in Archive test
- Pikabot Fake DLL Extension Execution Via Rundll32.EXE test
- Ping Hex IP test
- Pingback Backdoor Activity test
- Port Forwarding Activity Via SSH.EXE test
- Possible Privilege Escalation via Weak Service Permissions test
- Potential ACTINIUM Persistence Activity test
- Potential Amazon SSM Agent Hijacking test
- Potential AMSI Bypass Using NULL Bits test
- Potential AMSI Bypass Via .NET Reflection test
- Potential Application Whitelisting Bypass via Dnx.EXE test
- Potential APT FIN7 Exploitation Activity test
- Potential APT FIN7 Reconnaissance/POWERTRASH Related Activity test
- Potential APT Mustang Panda Activity Against Australian Gov test
- Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32 test
- Potential APT10 Cloud Hopper Activity test
- Potential Arbitrary Code Execution Via Node.EXE test
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt test
- Potential Baby Shark Malware Activity test
- Potential BlackByte Ransomware Activity test
- Potential COM Objects Download Cradles Usage - Process Creation test
- Potential Command Line Path Traversal Evasion Attempt test
- Potential Commandline Obfuscation Using Escape Characters test
- Potential CommandLine Obfuscation Using Unicode Characters test
- Potential Compromised 3CXDesktopApp Update Activity test
- Potential Conti Ransomware Activity test
- Potential Conti Ransomware Database Dumping Activity Via SQLCmd test
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI test
- Potential Credential Dumping Via LSASS Process Clone test
- Potential Crypto Mining Activity stable
- Potential CVE-2021-26857 Exploitation Attempt stable
- Potential CVE-2021-40444 Exploitation Attempt test
- Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon test
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution test
- Potential CVE-2023-21554 QueueJumper Exploitation test
- Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI test
- Potential Data Exfiltration Activity Via CommandLine Tools test
- Potential Data Stealing Via Chromium Headless Debugging test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1 test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2 test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3 test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4 test
- Potential Defense Evasion Via Right-to-Left Override test
- Potential Devil Bait Malware Reconnaissance test
- Potential Discovery Activity Via Dnscmd.EXE test
- Potential DLL File Download Via PowerShell Invoke-WebRequest test
- Potential Dosfuscation Activity test
- Potential Download/Upload Activity Using Type Command test
- Potential Dridex Activity stable
- Potential Dropper Script Execution Via WScript/CScript/MSHTA test
- Potential Dtrack RAT Activity stable
- Potential Emotet Activity stable
- Potential EmpireMonkey Activity test
- Potential Execution of Sysinternals Tools test
- Potential Exploitation Attempt From Office Application test
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) experimental
- Potential Exploitation of GoAnywhere MFT Vulnerability experimental
- Potential Fake Instance Of Hxtsr.EXE Executed test
- Potential File Download Via MS-AppInstaller Protocol Handler test
- Potential Goofy Guineapig Backdoor Activity test
- Potential Goofy Guineapig GoolgeUpdate Process Anomaly test
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI test
- Potential Homoglyph Attack Using Lookalike Characters test
- Potential KamiKakaBot Activity - Lure Document Execution test
- Potential KamiKakaBot Activity - Shutdown Schedule Task Creation test
- Potential Ke3chang/TidePool Malware Activity test
- Potential Lateral Movement via Windows Remote Shell experimental
- Potential LethalHTA Technique Execution test
- Potential LSASS Process Dump Via Procdump stable
- Potential Maze Ransomware Activity test
- Potential Meterpreter/CobaltStrike Activity test
- Potential Mftrace.EXE Abuse test
- Potential Mpclient.DLL Sideloading Via Defender Binaries test
- Potential MSTSC Shadowing Activity test
- Potential MuddyWater APT Activity test
- Potential Network Sniffing Activity Using Network Tools test
- Potential Notepad++ CVE-2025-49144 Exploitation experimental
- Potential Persistence Attempt Via Existing Service Tampering test
- Potential Persistence Attempt Via Run Keys Using Reg.EXE test
- Potential Persistence Via Logon Scripts - CommandLine test
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE test
- Potential PlugX Activity test
- Potential PowerShell Console History Access Attempt via History File experimental
- Potential PowerShell Downgrade Attack test
- Potential PowerShell Execution Policy Tampering - ProcCreation test
- Potential PowerShell Obfuscation Via WCHAR/CHAR test
- Potential Privilege Escalation To LOCAL SYSTEM test
- Potential Privilege Escalation via Service Permissions Weakness test
- Potential Process Execution Proxy Via CL_Invocation.ps1 test
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution test
- Potential Provlaunch.EXE Binary Proxy Execution Abuse test
- Potential Proxy Execution Via Explorer.EXE From Shell Process test
- Potential PsExec Remote Execution test
- Potential Qakbot Rundll32 Execution test
- Potential QBot Activity stable
- Potential Raspberry Robin Dot Ending File test
- Potential RDP Tunneling Via Plink test
- Potential RDP Tunneling Via SSH test
- Potential Regsvr32 Commandline Flag Anomaly test
- Potential Remote Desktop Tunneling test
- Potential Renamed Rundll32 Execution test
- Potential Russian APT Credential Theft Activity stable
- Potential Ryuk Ransomware Activity stable
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1 test
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators experimental
- Potential SMB Relay Attack Tool Execution test
- Potential SNAKE Malware Installation Binary Indicator test
- Potential SNAKE Malware Installation CLI Arguments Indicator test
- Potential SNAKE Malware Persistence Service Execution test
- Potential Snatch Ransomware Activity stable
- Potential Suspicious Browser Launch From Document Reader Process test
- Potential Suspicious Child Process Of 3CXDesktopApp test
- Potential Suspicious Execution From GUID Like Folder Names test
- Potential Suspicious Windows Feature Enabled - ProcCreation test
- Potential SysInternals ProcDump Evasion test
- Potential SystemNightmare Exploitation Attempt test
- Potential Tampering With Security Products Via WMIC test
- Potential UAC Bypass Via Sdclt.EXE test
- Potential WinAPI Calls Via CommandLine test
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler test
- Potentially Suspicious Cabinet File Expansion test
- Potentially Suspicious Call To Win32_NTEventlogFile Class test
- Potentially Suspicious Child Process Of ClickOnce Application test
- Potentially Suspicious Child Process Of DiskShadow.EXE test
- Potentially Suspicious Child Process Of Regsvr32 test
- Potentially Suspicious Child Process Of VsCode test
- Potentially Suspicious Command Targeting Teams Sensitive Files test
- Potentially Suspicious Event Viewer Child Process test
- Potentially Suspicious Execution From Parent Process In Public Folder test
- Potentially Suspicious Execution Of PDQDeployRunner test
- Potentially Suspicious GoogleUpdate Child Process test
- Potentially Suspicious JWT Token Search Via CLI test
- Potentially Suspicious Powershell Script Execution From Temp Folder test
- Potentially Suspicious Usage Of Qemu test
- Potentially Suspicious WebDAV LNK Execution test
- Potentially Suspicious Windows App Activity test
- PowerShell Base64 Encoded FromBase64String Cmdlet test
- PowerShell Base64 Encoded IEX Cmdlet test
- Powershell Base64 Encoded MpPreference Cmdlet test
- PowerShell Base64 Encoded Reflective Assembly Load test
- Powershell Defender Disable Scan Feature test
- Powershell Defender Exclusion test
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction' experimental
- PowerShell Download and Execution Cradles test
- PowerShell Get-Clipboard Cmdlet Via CLI test
- PowerShell Get-Process LSASS test
- Powershell Inline Execution From A File test
- PowerShell SAM Copy test
- PowerShell Script Run in AppData test
- Powershell Token Obfuscation - Process Creation test
- PrintBrm ZIP Creation of Extraction test
- Privilege escalation via runas (command) experimental
- Privilege escalation via RunasCS experimental
- Procdump Execution test
- Process Creation Using Sysnative Folder test
- Process Execution From A Potentially Suspicious Folder test
- Process Execution From WebDAV Share experimental
- Process Launched Without Image Name test
- Process Proxy Execution Via Squirrel.EXE test
- Ps.exe Renamed SysInternals Tool test
- PsExec Service Child Process Execution as LOCAL SYSTEM test
- PsExec/PAExec Escalation to LOCAL SYSTEM test
- PUA - AdFind Suspicious Execution test
- PUA - Adidnsdump Execution test
- PUA - AdvancedRun Suspicious Execution test
- PUA - Chisel Tunneling Tool Execution test
- PUA - CleanWipe Execution test
- PUA - DIT Snapshot Viewer test
- PUA - Netcat Suspicious Execution test
- PUA - Ngrok Execution test
- PUA - NirCmd Execution As LOCAL SYSTEM test
- PUA - Restic Backup Tool Execution experimental
- PUA - RunXCmd Execution test
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE test
- PUA - TruffleHog Execution experimental
- Pubprn.vbs Proxy Execution test
- Python Function Execution Security Warning Disabled In Excel test
- Python Spawning Pretty TTY on Windows test
- Qakbot Regsvr32 Calc Pattern test
- Qakbot Rundll32 Exports Execution test
- Qakbot Rundll32 Fake DLL Extension Execution test
- Query Usage To Exfil Data test
- QuickAssist Execution experimental
- Raccine Uninstall test
- Rar Usage with Password and Compression Level test
- Raspberry Robin Subsequent Execution of Commands test
- RDP session hijack via TSCON abuse command experimental
- RDP shadow session started (command) experimental
- RDP tunneling configuration enabled for port forwarding experimental
- Recon Command Output Piped To Findstr.EXE test
- Regedit as Trusted Installer test
- REGISTER_APP.VBS Proxy Execution test
- Registry Modification Attempt Via VBScript experimental
- Remote Access Tool - Ammy Admin Agent Execution test
- Remote Access Tool - AnyDesk Piped Password Via CLI test
- Remote Access Tool - AnyDesk Silent Installation test
- Remote Access Tool - MeshAgent Command Execution via MeshCentral test
- Remote Access Tool - Potential MeshAgent Execution - Windows experimental
- Remote Access Tool - ScreenConnect Installation Execution test
- Remote Access Tool - ScreenConnect Remote Command Execution - Hunting test
- Remote Access Tool - ScreenConnect Server Web Shell Execution test
- Remote Access Tool - Simple Help Execution test
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server experimental
- Remote Access Tool - Team Viewer Session Started On Windows Host test
- Remote File Download Via Desktopimgdownldr Utility test
- Remote PowerShell Session Host Process (WinRM) test
- Remote XSL Execution Via Msxsl.EXE test
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses test
- Replace.exe Usage test
- RestrictedAdminMode Registry Value Tampering - ProcCreation test
- REvil Kaseya Incident Malware Patterns test
- Root Certificate Installed From Susp Locations test
- Rorschach Ransomware Execution Activity test
- Run PowerShell Script from ADS test
- Run PowerShell Script from Redirected Input Stream test
- Rundll32 Execution Without CommandLine Parameters test
- Rundll32 Execution Without Parameters test
- Scheduled persistent task with SYSTEM privileges creation experimental
- Scheduled Task Creation From Potential Suspicious Parent Location test
- Scheduled Task Creation Via Schtasks.EXE test
- Scheduled task creation with command line experimental
- Scheduled Task Creation with Curl and PowerShell Execution Combo experimental
- Scheduled task enumerated experimental
- Schtasks Creation Or Modification With SYSTEM Privileges test
- Screen Capture Activity Via Psr.EXE test
- Script Event Consumer Spawning Process test
- Script Interpreter Spawning Credential Scanner - Windows experimental
- Scripting/CommandLine Process Spawned Regsvr32 test
- Sdclt Child Processes test
- Sdiagnhost Calling Suspicious Child Process test
- SearchIndexer suspicious process activity experimental
- Security package (SSP) added (Reg via command) experimental
- Security Service Disabled Via Reg.EXE test
- Sensitive File Access Via Volume Shadow Copy Backup test
- Serial console process spawning CMD shell (via command) experimental
- Serpent Backdoor Payload Execution Via Scheduled Task test
- Serv-U Exploitation CVE-2021-35211 by DEV-0322 test
- Service abuse with backdoored "command failure" (Reg via command) experimental
- Service abuse with backdoored "command failure" (service) experimental
- Service abuse with malicious ImagePath (Reg via command) experimental
- Service abuse with malicious ImagePath (service) experimental
- Service creation (command) experimental
- Service deactivation (command) experimental
- Service permissions hijacked for privileges abuse (reg via command) experimental
- Service permissions hijacked for privileges abuse (service) experimental
- Shai-Hulud 2.0 Malicious NPM Package Installation experimental
- Shai-Hulud Malicious Bun Execution experimental
- Shai-Hulud Malware Indicators - Windows experimental
- Shell Process Spawned by Java.EXE test
- ShimCache Flush stable
- Small Sieve Malware CommandLine Indicator test
- Sofacy Trojan Loader Activity test
- SOURGUM Actor Behaviours test
- SPN added to an account by command line experimental
- Spool process spawned a CMD shell (PrintNightmare vulnerability - CVE-2021-36958) experimental
- SQL Server database's table enumeration experimental
- SQL server sqlcmd utility abuse for privilege escalation experimental
- SQL Server started in single mode (command) experimental
- Start of NT Virtual DOS Machine test
- Stickey key called CMD via command execution experimental
- Stickey key IFEO (Reg via command) experimental
- Sticky Key Like Backdoor Execution test
- Sticky key sethc command for replacement by CMD experimental
- Suspect Svchost Activity test
- Suspicious ArcSOC.exe Child Process experimental
- Suspicious Binary In User Directory Spawned From Office Application test
- Suspicious BitLocker Access Agent Update Utility Execution experimental
- Suspicious Calculator Usage test
- Suspicious Child Process of AspNetCompiler test
- Suspicious Child Process Of BgInfo.EXE test
- Suspicious Child Process Of Manage Engine ServiceDesk test
- Suspicious Child Process of Notepad++ Updater - GUP.Exe experimental
- Suspicious Child Process Of SQL Server test
- Suspicious Child Process Of Wermgr.EXE test
- Suspicious Chromium Browser Instance Executed With Custom Extension test
- Suspicious ClickFix/FileFix Execution Pattern experimental
- Suspicious CodePage Switch Via CHCP test
- Suspicious Command Patterns In Scheduled Task Creation test
- Suspicious CrushFTP Child Process experimental
- Suspicious CustomShellHost Execution test
- Suspicious Debugger Registration Cmdline test
- Suspicious Desktopimgdownldr Command test
- Suspicious Diantz Alternate Data Stream Execution test
- Suspicious Diantz Download and Compress Into a CAB File test
- Suspicious Double Extension File Execution stable
- Suspicious Download from Office Domain test
- Suspicious Driver Install by pnputil.exe test
- Suspicious Electron Application Child Processes test
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call test
- Suspicious Execution From Outlook Temporary Folder test
- Suspicious Execution Location Of Wermgr.EXE test
- Suspicious Execution of Hostname test
- Suspicious Execution of InstallUtil Without Log test
- Suspicious Execution of Powershell with Base64 test
- Suspicious Execution of Shutdown test
- Suspicious Execution of Shutdown to Log Out test
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix experimental
- Suspicious Extrac32 Alternate Data Stream Execution test
- Suspicious FileFix Execution Pattern experimental
- Suspicious FromBase64String Usage On Gzip Archive - Process Creation test
- Suspicious GrpConv Execution test
- Suspicious GUP Usage test
- Suspicious High IntegrityLevel Conhost Legacy Option test
- Suspicious HWP Sub Processes test
- Suspicious IIS Module Registration test
- Suspicious Kernel Dump Using Dtrace test
- Suspicious Modification Of Scheduled Tasks test
- Suspicious Msiexec Execute Arbitrary DLL test
- Suspicious Network Command test
- Suspicious New Instance Of An Office COM Object test
- Suspicious New Service Creation test
- Suspicious Obfuscated PowerShell Code test
- Suspicious Outlook Child Process test
- Suspicious Ping/Del Command Combination test
- Suspicious PowerShell Download and Execute Pattern test
- Suspicious PowerShell IEX Execution Patterns test
- Suspicious PowerShell Invocations - Specific - ProcessCreation test
- Suspicious PowerShell Mailbox Export to Share test
- Suspicious PowerShell Parameter Substring test
- Suspicious PrinterPorts Creation (CVE-2020-1048) test
- Suspicious Process Created Via Wmic.EXE test
- Suspicious Process Execution From Fake Recycle.Bin Folder test
- Suspicious Process Parents test
- Suspicious Process Patterns NTDS.DIT Exfil test
- Suspicious Process Start Locations test
- Suspicious Processes Spawned by Java.EXE test
- Suspicious Processes Spawned by WinRM test
- Suspicious Program Names test
- Suspicious Provlaunch.EXE Child Process test
- Suspicious Query of MachineGUID test
- Suspicious RASdial Activity test
- Suspicious RazerInstaller Explorer Subprocess test
- Suspicious RDP Redirect Using TSCON test
- Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet test
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS test
- Suspicious Recursive Takeown test
- Suspicious Redirection to Local Admin Share test
- Suspicious Reg Add BitLocker test
- Suspicious Remote Child Process From Outlook test
- Suspicious RunAs-Like Flag Combination test
- Suspicious Rundll32 Activity Invoking Sys File test
- Suspicious Rundll32 Invoking Inline VBScript test
- Suspicious Runscripthelper.exe test
- Suspicious Scan Loop Network test
- Suspicious Scheduled Task Creation Involving Temp Folder test
- Suspicious Scheduled Task Name As GUID test
- Suspicious Schtasks Execution AppData Folder test
- Suspicious ScreenSave Change by Reg.exe test
- Suspicious Serv-U Process Pattern test
- Suspicious Service Binary Directory test
- Suspicious Service Path Modification test
- Suspicious Shells Spawn by Java Utility Keytool test
- Suspicious Speech Runtime Binary Child Process experimental
- Suspicious Splwow64 Without Params test
- Suspicious SPN enumeration previous to Kerberoasting attack (native commands) experimental
- Suspicious Sysmon as Execution Parent test
- Suspicious SYSVOL Domain Group Policy Access test
- Suspicious TSCON Start as SYSTEM test
- Suspicious UltraVNC Execution test
- Suspicious Usage Of ShellExec_RunDLL test
- Suspicious VBoxDrvInst.exe Parameters test
- Suspicious VBScript UN2452 Pattern test
- Suspicious Velociraptor Child Process experimental
- Suspicious Vsls-Agent Command With AgentExtensionPath Load test
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE test
- Suspicious WindowsTerminal Child Processes test
- Suspicious WmiPrvSE Child Process test
- Suspicious X509Enrollment - Process Creation test
- Suspicious ZipExec Execution test
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code test
- Sysprep on AppData Folder test
- System File Execution Location Anomaly test
- System Information Discovery via Registry Queries experimental
- SystemNightmare by GentilKiwi - External printer mapped (CVE-2021-1675 / CVE-2021-34527) experimental
- TAIDOOR RAT DLL Load test
- Tamper Windows Defender Remove-MpPreference test
- TanStack Supply-Chain Attack Execution Indicators - Windows experimental
- Tap Installer Execution test
- Task Manager access indicator for potential LSASS dump experimental
- Taskkill Symantec Endpoint Protection test
- Taskmgr as LOCAL_SYSTEM test
- Tasks Folder Evasion test
- Time Travel Debugging Utility Usage test
- TropicTrooper Campaign November 2018 stable
- TrustedPath UAC Bypass Pattern test
- Tunneling Tool Execution test
- Turla Group Commands May 2020 test
- Turla Group Lateral Movement test
- UAC Bypass Tools Using ComputerDefaults test
- UAC Bypass Using ChangePK and SLUI test
- UAC Bypass Using Consent and Comctl32 - Process test
- UAC Bypass Using DismHost test
- UAC Bypass Using Event Viewer RecentViews test
- UAC Bypass Using IEInstal - Process test
- UAC Bypass Using MSConfig Token Modification - Process test
- UAC Bypass Using PkgMgr and DISM test
- UAC Bypass WSReset test
- UEFI Persistence Via Wpbbin - ProcessCreation test
- UNC2452 PowerShell Pattern test
- Uncommon Child Process Of AddinUtil.EXE test
- Uncommon Child Process Of Appvlp.EXE test
- Uncommon Child Process Of BgInfo.EXE test
- Uncommon Child Process Of Conhost.EXE test
- Uncommon Child Process Of Defaultpack.EXE test
- Uncommon Child Process Of Setres.EXE test
- Uncommon Child Process Spawned By Odbcconf.EXE test
- Uncommon Child Processes Of SndVol.exe test
- Uncommon FileSystem Load Attempt By Format.com test
- Uncommon Link.EXE Parent Process test
- Uncommon Sigverif.EXE Child Process test
- Uncommon Svchost Command Line Parameter experimental
- Uncommon Svchost Parent Process test
- Uncommon Userinit Child Process test
- Uninstall Crowdstrike Falcon Sensor test
- Unusual Child Process of dns.exe test
- Unusual Parent Process For Cmd.EXE test
- Ursnif Redirection Of Discovery Commands test
- Usage Of Web Request Commands And Cmdlets test
- Use NTFS Short Name in Command Line test
- Use NTFS Short Name in Image test
- Use of Pcalua For Execution test
- Use Of The SFTP.EXE Binary As A LOLBIN test
- Use Short Name Path in Command Line test
- User added to a group via commandline
- User Added To Highly Privileged Group test
- User Added to Local Administrators Group test
- User Added to Remote Desktop Users Group test
- User creation via commandline
- User enumeration and creation related to Manic Menagerie 2.0 (via cmdline)
- User properties enumeration via commandline
- UtilityFunctions.ps1 Proxy Dll test
- Veeam Backup Database Suspicious Query test
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE test
- Virtualbox Driver Installation or Starting of VMs test
- Visual Basic Command Line Compiler Usage test
- Visual Studio Code Tunnel Service Installation test
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution test
- VolumeShadowCopy Symlink Creation Via Mklink stable
- VSS backup deletion (WMI) experimental
- VSS backup deletion or resize experimental
- Wab Execution From Non Default Location test
- Wab/Wabmig Unusual Parent Or Child Processes test
- WannaCry Ransomware Activity test
- Wdigest authentication enabled (Reg via command) experimental
- Weak or Abused Passwords In CLI test
- Webserver IIS module installed (command) experimental
- Webserver IIS module installed (command) experimental
- Webshell Hacking Activity Patterns test
- Webshell Tool Reconnaissance Activity test
- WhoAmI as Parameter test
- Windows native backup deletion experimental
- Windows native backup size re-configuration experimental
- Windows native Pktmon sniffer abuse experimental
- Windows Processes Suspicious Parent Directory test
- Windows Subsystem for Linux (WSL) installation (command) experimental
- Windows traffic capture abuse experimental
- Winnti Malware HK University Campaign test
- Winnti Pipemon Characteristics stable
- WinRM listening service reconnaissance (process) experimental
- WinRS usage for remote execution
- WMI Backdoor Exchange Transport Agent test
- WMI Persistence - Script Event Consumer test
- WMI spwaning PowerShell process - WMImplant experimental
- WmiPrvSE Spawned A Process stable
- Write Protect For Storage Disabled test
- Writing Of Malicious Files To The Fonts Folder test
- Wscript Shell Run In CommandLine test
- WSL Child Process Anomaly test
- WSL Kali-Linux Usage experimental
- Wusa.EXE Executed By Parent Process Located In Suspicious Location test
- ZxShell Malware test
Event ID 4697: A service was installed in the system. 27 rules
- CobaltStrike Service Installations - Security test
- CosmicDuke Service Installation test
- Credential Dumping Tools Service Execution - Security test
- Encoded PowerShell payload deployed via service experimental
- HybridConnectionManager Service Installation test
- Impacket SMBexec service registration (native) experimental
- Invoke-Obfuscation CLIP+ Launcher - Security test
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security test
- Invoke-Obfuscation Obfuscated IEX Invocation - Security test
- Invoke-Obfuscation RUNDLL LAUNCHER - Security test
- Invoke-Obfuscation STDIN+ Launcher - Security test
- Invoke-Obfuscation VAR+ Launcher - Security test
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security test
- Invoke-Obfuscation Via Stdin - Security test
- Invoke-Obfuscation Via Use Clip - Security test
- Invoke-Obfuscation Via Use MSHTA - Security test
- Invoke-Obfuscation Via Use Rundll32 - Security test
- Metasploit Or Impacket Service Installation Via SMB PsExec test
- Meterpreter or Cobalt Strike Getsystem Service Installation - Security test
- Mimikatz driver deployed via service experimental
- PowerShell Scripts Installed as Services - Security test
- PSexec service installation experimental
- RDP session hijack via service creation abuse experimental
- Remote Access Tool Services Have Been Installed - Security test
- Service Installed By Unusual Client - Security test
- Tap Driver Installation - Security test
- Windows Pcap Drivers test
Event ID 4698: A scheduled task was created. 7 rules
- Diamond Sleet APT Scheduled Task Creation test
- Fortinet APT group abuse on Windows (task) experimental
- Kapeka Backdoor Scheduled Task Creation test
- OilRig APT Schedule Task Persistence - Security test
- Scheduled task created and deleted fastly (ATexec.py) experimental
- Scheduled Tasks Names Used By SVR For GraphicalProton Backdoor test
- Suspicious Scheduled Task Creation test
Event ID 4720: A user account was created. 8 rules
- Fortinet APT group abuse on Windows (user) experimental
- Hidden account creation (with fast deletion) experimental
- Hidden Local User Creation test
- Local User Creation test
- New or Renamed User Account with '$' Character test
- Suspicious Windows ANONYMOUS LOGON Local Account Created test
- User account created by a computer account experimental
- User account creation disguised in a computer account experimental
Event ID 4722: A user account was enabled. 1 rule
- Disabled guest or builtin account activated experimental
Event ID 4723: An attempt was made to change an account's password. 2 rules
- Bruteforce via password reset experimental
- User password change using current hash password - ChangeNTLM (Mimikatz) experimental
Event ID 4726: A user account was deleted. 1 rule
- Hidden account creation (with fast deletion) experimental
Event ID 4728: A member was added to a security-enabled global group. 12 rules
- A Member Was Added to a Security-Enabled Global Group stable
- Exchange group membership change to perform DCsync attack experimental
- High risk Active Directory group membership change experimental
- Massive group membership changes detected experimental
- Medium risk Active Directory group membership change experimental
- Member added to DNSadmin group experimental
- New member added to a "OCS/Lync/Skype for Business" administration group (low risk) experimental
- New member added to a "OCS/Lync/Skype for Business" administration group (medium risk) experimental
- New member added to an "OCS/Lync/Skype for Business" administration group (high risk) experimental
- New member added to an Exchange administration group (high risk) experimental
- New member added to an Exchange administration group (medium risk) experimental
- Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity test
Event ID 4732: A member was added to a security-enabled local group. 11 rules
- Exchange group membership change to perform DCsync attack experimental
- High risk local/domain local group membership change experimental
- Massive group membership changes detected experimental
- Medium risk local/domain local group membership change experimental
- Member added to DNSadmin group experimental
- New member added to a "OCS/Lync/Skype for Business" administration group (low risk) experimental
- New member added to a "OCS/Lync/Skype for Business" administration group (medium risk) experimental
- New member added to an "OCS/Lync/Skype for Business" administration group (high risk) experimental
- New member added to an Exchange administration group (high risk) experimental
- New member added to an Exchange administration group (medium risk) experimental
- User Added to Local Administrator Group stable
Event ID 4738: A user account was changed. 9 rules
- Account marked as sensitive and cannot be delegated had its protection removed (weakness introduction) experimental
- Account password set to never expire. experimental
- Account set with Kerberos DES encryption activated (weakness introduction) experimental
- Account set with Kerberos pre-authentication not required (AS-REP Roasting) experimental
- Account set with password not required (weakness introduction) experimental
- Account set with reversible encryption (weakness introduction) experimental
- Active Directory User Backdoors test
- Addition of SID History to Active Directory Object stable
- Weak Encryption Enabled and Kerberoast test
Event ID 4741: A computer account was created. 4 rules
- ADCS - Certighost Ghost Machine Account Creation experimental
- Add or Remove Computer from DC test
- Computer account created with privileges experimental
- Suspicious computer account created by a computer account experimental
Event ID 4742: A computer account was changed. 9 rules
- Host constrained delegation settings changed for potential abuse (Rubeus) - Any protocol experimental
- Host constrained delegation settings changed for potential abuse (Rubeus) - Kerberos only experimental
- Host set with constrained delegation experimental
- Host set with unconstrained delegation experimental
- Host unconstrained delegation settings changed for potential abuse (Rubeus) experimental
- Possible DC Shadow Attack test
- Remote domain controller password reset (Zerologon) experimental
- Suspicious modification of a computer account SPN experimental
- Suspicious modification of a fake domain controller SPN (DCshadow) experimental
Event ID 4756: A member was added to a security-enabled universal group. 11 rules
- Exchange group membership change to perform DCsync attack experimental
- High risk Active Directory group membership change experimental
- Massive group membership changes detected experimental
- Medium risk Active Directory group membership change experimental
- Member added to DNSadmin group experimental
- New member added to a "OCS/Lync/Skype for Business" administration group (low risk) experimental
- New member added to a "OCS/Lync/Skype for Business" administration group (medium risk) experimental
- New member added to an "OCS/Lync/Skype for Business" administration group (high risk) experimental
- New member added to an Exchange administration group (high risk) experimental
- New member added to an Exchange administration group (medium risk) experimental
- Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity test
Event ID 4768: A Kerberos authentication ticket (TGT) was requested. 10 rules
- Active Directory honeypot used for lateral movement experimental
- Brutforce enumeration with unexisting users (Kerberos) experimental
- Kerberos AS-REP Roasting ticket request detected experimental
- Kerberos enumeration with existing/unexisting users (Kerbrute) experimental
- Kerberos Manipulation test
- Kerberos TGS ticket request related to a potential Golden ticket experimental
- Kerberos ticket without a trailing $ (CVE-2021-42278/42287) experimental
- PetitPotam Suspicious Kerberos TGT Request test
- Potential AS-REP Roasting via Kerberos TGT Requests experimental
- Suspicious Kerberos proxiable/S4U2self ticket (CVE-2021-42278/42287) experimental
Event ID 4769: A Kerberos service ticket was requested. 10 rules
- Active Directory honeypot used for lateral movement experimental
- Kerberoast ticket request detected experimental
- Kerberoasting Activity - Initial Query test
- Kerberos key list attack for credential dumping experimental
- Kerberos Manipulation test
- Kerberos ticket without a trailing $ (CVE-2021-42278/42287) experimental
- Rubeus Kerberos constrained delegation abuse (S4U2Proxy) experimental
- Rubeus Kerberos unconstrained delegation abuse experimental
- SharpHound host enumeration over Kerberos experimental
- Suspicious Kerberos RC4 Ticket Encryption test
Event ID 4770: A Kerberos service ticket was renewed. 1 rule
- Active Directory honeypot used for lateral movement experimental
Event ID 4781: The name of an account was changed. 5 rules
- Account renamed to admin (or likely) account to evade defense experimental
- Computer account renamed without a trailing $ (CVE-2021-42278/42287) experimental
- New or Renamed User Account with '$' Character test
- Suspicious Computer Account Name Change CVE-2021-42287 test
- User account creation disguised in a computer account experimental
Event ID 4800: The workstation was locked. 1 rule
- Locked Workstation stable
Event ID 4825: A user was denied the access to Remote Desktop. 2 rules
- Denied Access To Remote Desktop test
- Denied RDP login with valid credentials experimental
Event ID 4950: A Windows Firewall setting has changed. 1 rule
- Firewall deactivation (firewall) experimental
Event ID 5038: Code integrity determined that the image hash of a file is not valid. 1 rule
- Failed Code Integrity Checks stable
Event ID 5123: A configuration entry changed in the OCSP Responder Service. 1 rule
- OCSP responder auditing settings changed or disabled experimental
Event ID 5124: A security setting was updated on OCSP Responder Service. 1 rule
- OCSP responder security settings changed experimental
Event ID 5136: A directory service object was modified. 20 rules
- Active Directory User Backdoors test
- AdminSDHolder permissions changed for persistence experimental
- Computer account manipulation for delegation (RBCD) experimental
- Computer account modifying Active Directory permissions experimental
- Computer account modifying Active Directory permissions (PrivExchange) experimental
- Extended rights backdoor obfuscation (via localizationDisplayId attribute) experimental
- Group Policy Abuse for Privilege Addition test
- Permissions changed on a Group Policy (GPO) experimental
- Persistence and Execution at Scale via GPO Scheduled Task test
- Possible DC Shadow Attack test
- Possible Shadow Credentials Added test
- Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation experimental
- Powerview Add-DomainObjectAcl DCSync AD Extend Right test
- Replication privileges granted to perform DCSync attack experimental
- Startup/Logon Script Added to Group Policy Object test
- Suspicious LDAP-Attributes Used test
- Suspicious modification of a fake domain controller SPN (DCshadow) (Directory Services) experimental
- Suspicious modification of a sensitive Group Policy (GPO) experimental
- Suspicious modification of a user account SPN to enable Kerberoast attack experimental
- Windows Default Domain GPO Modification experimental
Event ID 5142: A network share object was added. 2 rules
- New network file share created experimental
- Shared printer creation (PrintNightmare vulnerability - CVE-2021-36958) experimental
Event ID 5145: A network share object was checked to see whether client can be granted desired access. 43 rules
- Active Directory honeypot used for lateral movement experimental
- Azure Active Directory Connect credentials dump via network share experimental
- BlueSky Ransomware Artefacts test
- CrackMaxpExec share permission enumeration experimental
- Credentials (protected by DPAPI) dump via network share experimental
- CVE-2021-1675 Print Spooler Exploitation IPC Access test
- DCERPC SMB Spoolss Named Pipe test
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security test
- Discovery for print spooler bug abuse (NTLM hash retrivial) via named pipe experimental
- DNS hosts file accessed via network share experimental
- First Time Seen Remote Named Pipe test
- Impacket PsExec Execution test
- Impacket WMIexec execution via SMB admin share experimental
- LSASS credential dump with LSASSY (admin share) experimental
- Massive remote schedule task creation via named pipes (CrackMapExec with ATexec) experimental
- Massive remote service creation via named pipes (TChopper, CME) experimental
- Massive remote service creation via named pipes - Tchopper experimental
- NetSYnc attack experimental
- Persistence and Execution at Scale via GPO Scheduled Task test
- Possible Impacket SecretDump Remote Activity test
- Possible PetitPotam Coerce Authentication Attempt test
- Protected Storage Service Access test
- PSexec execution over SMB share experimental
- Remote schedule task creation via named pipes (ATexec) experimental
- Remote Service Activity via SVCCTL Named Pipe test
- Remote service creation via named pipes experimental
- Remote shell execution via SMB admin share experimental
- Remote Task Creation via ATSVC Named Pipe test
- Secretdump password dumping via SMB admin share experimental
- Shared folder access with forged Golden ticket stable
- SharpHound enumeration via SMB named pipes experimental
- SMB admin share accessed experimental
- SMB Create Remote File Admin Share test
- Startup/Logon Script Added to Group Policy Object test
- Suspicious Access to Sensitive File Extensions test
- Suspicious PsExec Execution test
- T1047 Wmiprvse Wbemcomn DLL Hijack test
- Transferring Files with Credential Data via Network Shares test
- User application credentials dump via network share (DonPapi, Lazagne) experimental
- User browser credentials dump via network share (DonPapi, Lazagne) experimental
- User files dump via network share (DonPapi, Lazagne) experimental
- User password change without previous password known - SetNTLM (Mimikatz) experimental
- Windows Network Access Suspicious desktop.ini Action test
Event ID 5382: Vault credentials were read. 1 rule
- Vault credentials manager accessed experimental
Event ID 6281: Code Integrity determined that the page hashes of an image file are not valid. 1 rule
- Failed Code Integrity Checks stable
Microsoft-Windows-Sysmon
Event ID 1: Process creation 1482 rules
- 7Zip Compressing Dump Files test
- AADInternals PowerShell Cmdlets Execution - ProccessCreation test
- Abuse of Service Permissions to Hide Services Via Set-Service test
- Abused Debug Privilege by Arbitrary Parent Processes test
- Abusing Print Executable test
- Active Directory Database Snapshot Via ADExplorer test
- Active Directory Structure Export Via Csvde.EXE test
- Active Directory Structure Export Via Ldifde.EXE test
- Add Insecure Download Source To Winget test
- Add New Download Source To Winget test
- Add Potential Suspicious New Download Source To Winget test
- Add SafeBoot Keys Via Reg Utility test
- Add Windows Capability Via PowerShell Cmdlet test
- AddinUtil.EXE Execution From Uncommon Directory test
- Adwind RAT / JRAT test
- AgentExecutor PowerShell Execution test
- All Backups Deleted Via Wbadmin.EXE test
- Allow Service Access Using Security Descriptor Tampering Via Sc.EXE test
- Always Install Elevated MSI Spawned Cmd And Powershell test
- Always Install Elevated Windows Installer test
- Application Removed Via Wmic.EXE test
- Application Termination Attempt via Wmic.EXE test
- APT27 - Emissary Panda Activity test
- APT29 2018 Phishing Campaign CommandLine Indicators stable
- APT31 Judgement Panda Activity test
- Arbitrary Binary Execution Using GUP Utility test
- Arbitrary Command Execution Using WSL test
- Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE test
- Arbitrary File Download Via ConfigSecurityPolicy.EXE test
- Arbitrary File Download Via GfxDownloadWrapper.EXE test
- Arbitrary File Download Via IMEWDBLD.EXE test
- Arbitrary File Download Via MSEDGE_PROXY.EXE test
- Arbitrary File Download Via MSOHTMED.EXE test
- Arbitrary File Download Via MSPUB.EXE test
- Arbitrary File Download Via PresentationHost.EXE test
- Arbitrary File Download Via Squirrel.EXE test
- Arbitrary MSI Download Via Devinit.EXE test
- Arbitrary Shell Command Execution Via Settingcontent-Ms test
- AspNetCompiler Execution test
- Assembly Loading Via CL_LoadAssembly.ps1 test
- Attempts of Kerberos Coercion Via DNS SPN Spoofing experimental
- Audio Capture via PowerShell test
- Audio Capture via SoundRecorder test
- Audit policy disabled by command line experimental
- Audit policy enumerated experimental
- Audit Policy Tampering Via Auditpol test
- Audit Policy Tampering Via NT Resource Kit Auditpol test
- Automated Collection Command Prompt test
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl test
- Axios NPM Compromise Indicators - Windows experimental
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments test
- Base64 Encoded PowerShell Command Detected test
- Base64 MZ Header In CommandLine test
- Binary Proxy Execution Via Dotnet-Trace.EXE test
- BitLocker feature configuration (Reg via command) experimental
- BitLockerTogo.EXE Execution test
- BITS payload downloaded via commandline experimental
- Blue Mockingbird test
- Boot Configuration Tampering Via Bcdedit.EXE stable
- Browser Execution In Headless Mode test
- Browser Started with Remote Debugging test
- Bypass UAC via CMSTP test
- Bypass UAC via Fodhelper.exe test
- Bypass UAC via WSReset.exe test
- C# IL Code Compilation Via Ilasm.EXE test
- Cab File Extraction Via Wusa.EXE test
- Cab File Extraction Via Wusa.EXE From Potentially Suspicious Paths test
- Capture Credentials with Rpcping.exe test
- Certificate Exported Via Certutil.EXE test
- Certificate Exported Via PowerShell test
- Certutil payload download (command) experimental
- Certutil payload obfuscation (command) experimental
- Certutil root certificate installation experimental
- Change Default File Association To Executable Via Assoc test
- Change Default File Association Via Assoc test
- Change PowerShell Policies to an Insecure Level test
- Changing Existing Service ImagePath Value Via Reg.EXE test
- Chopper Webshell Process Pattern test
- ChromeLoader Malware Execution test
- Chromium Browser Headless Execution To Mockbin Like Site test
- Chromium Browser Instance Executed With Custom Extension test
- ClickOnce Deployment Execution - Dfsvc.EXE Child Process test
- Cloudflared Portable Execution test
- Cloudflared Quick Tunnel Execution test
- Cloudflared Tunnel Connections Cleanup test
- Cloudflared Tunnel Execution test
- Cmd Launched with Hidden Start Flags to Suspicious Targets experimental
- CMD Shell Output Redirect test
- Cmd.EXE Missing Space Characters Execution Anomaly test
- CMSTP Execution Process Creation stable
- CMSTP UAC Bypass via COM Object Access stable
- CobaltStrike Load by Rundll32 test
- Code Execution via Pcwutl.dll test
- CodePage Modification Via MODE.COM test
- CodePage Modification Via MODE.COM To Russian Language test
- COLDSTEEL RAT Anonymous User Process Execution test
- COLDSTEEL RAT Cleanup Command Execution test
- COLDSTEEL RAT Service Persistence Execution test
- COM Object Execution via Xwizard.EXE test
- Command Line Execution with Suspicious URL and AppData Strings test
- Commvault QLogin Argument Injection Authentication Bypass (CVE-2025-57791) experimental
- Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788) experimental
- Commvault QOperation Path Traversal Webshell Drop (CVE-2025-57790) experimental
- Compress Data and Lock With Password for Exfiltration With 7-ZIP test
- Compress Data and Lock With Password for Exfiltration With WINZIP test
- Compressed File Creation Via Tar.EXE test
- Compressed File Extraction Via Tar.EXE test
- Computer Discovery And Export Via Get-ADComputer Cmdlet test
- Computer Password Change Via Ksetup.EXE test
- Computer System Reconnaissance Via Wmic.EXE test
- Conhost Spawned By Uncommon Parent Process test
- Conhost.exe CommandLine Path Traversal test
- Console CodePage Lookup Via CHCP test
- Conti NTDS Exfiltration Command test
- Conti Volume Shadow Listing test
- Control Panel Items test
- ConvertTo-SecureString Cmdlet Usage Via CommandLine test
- Copy .DMP/.DUMP Files From Remote Share Via Cmd.EXE test
- Copy From Or To Admin Share Or Sysvol Folder test
- Copy From VolumeShadowCopy Via Cmd.EXE test
- Copying Sensitive Files with Credential Data test
- CreateDump Process Dump test
- Csc.EXE Execution Form Potentially Suspicious Parent test
- Cscript/Wscript Potentially Suspicious Child Process test
- Cscript/Wscript Uncommon Script Extension Execution test
- Curl Download And Execute Combination test
- Curl File Upload To File Sharing Websites experimental
- Curl Web Request With Potential Custom User-Agent test
- Curl.EXE Execution test
- Curl.EXE Execution With Custom UserAgent test
- CVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows) test
- CVE-2023-38331 Exploitation Attempt - Suspicious WinRAR Child Process test
- CVE-2024-50623 Exploitation Attempt - Cleo experimental
- DarkGate - Autoit3.EXE Execution Parameters test
- DarkGate - User Created Via Net.EXE test
- DarkSide Ransomware Pattern test
- Data Copied To Clipboard Via Clip.EXE test
- Data Export From MSSQL Table Via BCP.EXE test
- Defrag Deactivation test
- Delete All Scheduled Tasks test
- Delete Important Scheduled Task test
- Deleted Data Overwritten Via Cipher.EXE test
- Deletion of Volume Shadow Copies via WMI with PowerShell test
- Deny Service Access Using Security Descriptor Tampering Via Sc.EXE test
- Detected Windows Software Discovery test
- Detection of PowerShell Execution via Sqlps.exe test
- Devcon Execution Disabling VMware VMCI Device experimental
- DeviceCredentialDeployment Execution test
- Devtoolslauncher.exe Executes Specified Binary test
- Diamond Sleet APT Process Activity Indicators test
- Direct Autorun Keys Modification test
- Directory Removal Via Rmdir test
- DirLister Execution test
- Disable Important Scheduled Task test
- Disable Windows Defender AV Security Monitoring test
- Disable Windows IIS HTTP Logging test
- Disabled IE Security Features test
- Disabled Volume Snapshots test
- Disabling Windows Defender WMI Autologger Session via Reg.exe experimental
- Discovery of a System Time test
- Diskshadow Child Process Spawned test
- Diskshadow Script Mode - Execution From Potential Suspicious Location test
- Diskshadow Script Mode - Uncommon Script Extension Execution test
- Diskshadow Script Mode Execution test
- Dism Remove Online Package test
- DLL Call by Ordinal Via Rundll32.EXE stable
- DLL Execution via Rasautou.exe test
- DLL Execution Via Register-cimprovider.exe test
- DLL Loaded via CertOC.EXE test
- DLL ServerLevelPluginDll command installation experimental
- DLL Sideloading by VMware Xfer Utility test
- Dllhost.EXE Execution Anomaly test
- DllUnregisterServer Function Call Via Msiexec.EXE test
- DNS Exfiltration and Tunneling Tools Execution test
- DNS RCE CVE-2020-1350 test
- Domain Trust Discovery Via Dsquery test
- Driver/DLL Installation Via Odbcconf.EXE test
- DriverQuery.EXE Execution test
- Droppers Exploiting CVE-2017-11882 stable
- Dropping Of Password Filter DLL test
- DSInternals Suspicious PowerShell Cmdlets test
- Dumping of Sensitive Hives Via Reg.EXE test
- Dumping Process via Sqldumper.exe test
- DumpMinitool Execution test
- DumpStack.log Defender Evasion test
- Dynamic .NET Compilation Via Csc.EXE test
- Dynamic .NET Compilation Via Csc.EXE - Hunting test
- EAP service activation by Liontail framework for DLL sideloading (via command) stable
- Elevated System Shell Spawned test
- Elevated System Shell Spawned From Uncommon Parent Location test
- Elise Backdoor Activity test
- Email Exifiltration Via Powershell test
- Emotet Loader Execution Via .LNK File test
- Enable LM Hash Storage - ProcCreation test
- Encoded PowerShell payload deployed via process execution experimental
- Enumerate All Information With Whoami.EXE test
- Enumeration for 3rd Party Creds From CLI test
- Enumeration for Credentials in Registry test
- Equation Group DLL_U Export Function Load stable
- Esentutl Gather Credentials test
- Esentutl Steals Browser Information test
- ETW Logging Tamper In .NET Processes Via CommandLine test
- ETW Trace Evasion Activity test
- Event log clear attempt (command) experimental
- Event log clear attempt (wmi) experimental
- Event log deactivation or size reduction (command) experimental
- EventLog Query Requests By Builtin Utilities test
- EvilNum APT Golden Chickens Deployment Via OCX Files test
- Exchange PowerShell Snap-Ins Usage test
- Execute Code with Pester.bat test
- Execute Code with Pester.bat as Parent test
- Execute Files with Msdeploy.exe test
- Execute From Alternate Data Streams test
- Execute Pcwrun.EXE To Leverage Follina test
- Execution From Webserver Root Folder test
- Execution Of Non-Existing File test
- Execution of Powershell Script in Public Folder test
- Execution of Suspicious File Type Extension test
- Execution via stordiag.exe test
- Execution via WorkFolders.exe test
- Exploit for CVE-2015-1641 stable
- Exploit for CVE-2017-0261 test
- Exploit for CVE-2017-8759 test
- Exploitation Activity of CVE-2025-59287 - WSUS Suspicious Child Process experimental
- Exploitation Attempt Of CVE-2020-1472 - Execution of ZeroLogon PoC test
- Exploited CVE-2020-10189 Zoho ManageEngine test
- Exploiting CVE-2019-1388 stable
- Exploiting SetupComplete.cmd CVE-2019-1378 test
- Explorer NOUACCHECK Flag test
- Explorer Process Tree Break test
- Exports Critical Registry Keys To a File test
- Exports Registry Key To a File test
- FakeUpdates/SocGholish Activity test
- File And SubFolder Enumeration Via Dir Command test
- File Decoded From Base64/Hex Via Certutil.EXE test
- File Decryption Using Gpg4win test
- File Deletion Via Del test
- File Download And Execution Via IEExec.EXE test
- File Download From Browser Process Via Inline URL test
- File Download From IP Based URL Via CertOC.EXE test
- File Download From IP URL Via Curl.EXE test
- File Download Using Notepad++ GUP Utility test
- File Download Using ProtocolHandler.exe test
- File Download Via Bitsadmin test
- File Download Via Bitsadmin To A Suspicious Target Folder test
- File Download via CertOC.EXE test
- File Download Via Curl.EXE test
- File Download Via InstallUtil.EXE test
- File Download Via Windows Defender MpCmpRun.EXE test
- File Download with Headless Browser test
- File Encoded To Base64 Via Certutil.EXE test
- File Encryption Using Gpg4win test
- File Encryption/Decryption Via Gpg4win From Suspicious Locations test
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell test
- File In Suspicious Location Encoded To Base64 Via Certutil.EXE test
- File or Folder Permissions Modifications test
- File Recovery From Backup Via Wbadmin.EXE test
- File With Suspicious Extension Downloaded Via Bitsadmin test
- Files Added To An Archive Using Rar.EXE test
- Filter Driver Unloaded Via Fltmc.EXE test
- Findstr GPP Passwords test
- Findstr Launching .lnk File test
- Finger.EXE Execution test
- Fireball Archer Install test
- Firewall Configuration Discovery Via Netsh.EXE test
- Firewall Disabled via Netsh.EXE test
- Firewall Rule Deleted Via Netsh.EXE test
- Firewall Rule Update Via Netsh.EXE test
- Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet test
- Forest Blizzard APT - Process Creation Activity experimental
- Forfiles Command Execution test
- Forfiles.EXE Child Process Masquerading test
- Formbook Process Creation test
- Fsutil Drive Enumeration test
- Fsutil Suspicious Invocation stable
- FTP Connection Open Attempt Via Winscp CLI experimental
- GALLIUM IOCs test
- Github Self-Hosted Runner Execution test
- Gpresult Display Group Policy Information test
- Gpscript Execution test
- Greedy File Deletion Using Del test
- Greenbug Espionage Group Indicators test
- Griffon Malware Attack Pattern test
- Grixba Malware Reconnaissance Activity experimental
- Group discovery (command)
- Group Membership Reconnaissance Via Whoami.EXE test
- Gzip Archive Decode Via PowerShell test
- HackTool - ADCSPwn Execution test
- HackTool - Bloodhound/Sharphound Execution test
- HackTool - Certify Execution test
- HackTool - Certipy Execution test
- HackTool - CoercedPotato Execution test
- HackTool - Covenant PowerShell Launcher test
- HackTool - CrackMapExec Execution test
- HackTool - CrackMapExec Execution Patterns stable
- HackTool - CrackMapExec PowerShell Obfuscation test
- HackTool - CrackMapExec Process Patterns test
- HackTool - CreateMiniDump Execution test
- HackTool - Default PowerSploit/Empire Scheduled Task Creation test
- HackTool - DInjector PowerShell Cradle Execution test
- HackTool - Doppelanger LSASS Dumper Execution experimental
- HackTool - Dumpert Process Dumper Execution test
- Hacktool - EDR-Freeze Execution experimental
- HackTool - EDRSilencer Execution test
- HackTool - Empire PowerShell Launch Parameters test
- HackTool - Empire PowerShell UAC Bypass stable
- HackTool - F-Secure C3 Load by Rundll32 test
- HackTool - GMER Rootkit Detector and Remover Execution test
- HackTool - HandleKatz LSASS Dumper Execution test
- HackTool - Hashcat Password Cracker Execution test
- HackTool - HollowReaper Execution experimental
- HackTool - Htran/NATBypass Execution test
- HackTool - Hydra Password Bruteforce Execution test
- HackTool - Impacket Tools Execution test
- HackTool - Impersonate Execution test
- HackTool - Inveigh Execution test
- HackTool - Jlaive In-Memory Assembly Execution test
- HackTool - Koadic Execution test
- HackTool - KrbRelay Execution test
- HackTool - KrbRelayUp Execution test
- HackTool - LaZagne Execution experimental
- HackTool - LocalPotato Execution test
- HackTool - Mimikatz Execution test
- HackTool - NetExec Execution experimental
- HackTool - PCHunter Execution test
- HackTool - Potential Impacket Lateral Movement Activity stable
- HackTool - PowerTool Execution test
- HackTool - PPID Spoofing SelectMyParent Tool Execution test
- HackTool - PurpleSharp Execution test
- HackTool - Pypykatz Credentials Dumping Activity test
- HackTool - Quarks PwDump Execution test
- HackTool - RedMimicry Winnti Playbook Execution test
- HackTool - RemoteKrbRelay Execution test
- HackTool - Rubeus Execution stable
- HackTool - SafetyKatz Execution test
- HackTool - SecurityXploded Execution stable
- HackTool - SharpChisel Execution test
- HackTool - SharpDPAPI Execution test
- HackTool - SharPersist Execution test
- HackTool - SharpEvtMute Execution test
- HackTool - SharpImpersonation Execution test
- HackTool - SharpLDAPmonitor Execution test
- HackTool - SharpLdapWhoami Execution test
- HackTool - SharpMove Tool Execution test
- HackTool - SharpUp PrivEsc Tool Execution test
- HackTool - SharpView Execution test
- HackTool - SharpWSUS/WSUSpendu Execution test
- HackTool - SILENTTRINITY Stager Execution test
- HackTool - Sliver C2 Implant Activity Pattern test
- HackTool - SOAPHound Execution test
- HackTool - Stracciatella Execution test
- HackTool - SysmonEOP Execution test
- HackTool - TruffleSnout Execution test
- HackTool - UACMe Akagi Execution test
- HackTool - Windows Credential Editor (WCE) Execution test
- HackTool - winPEAS Execution test
- HackTool - WinPwn Execution test
- HackTool - WinRM Access Via Evil-WinRM test
- HackTool - Wmiexec Default Powershell Command test
- HackTool - WSASS Execution experimental
- HackTool - XORDump Execution test
- Hacktool Execution - Imphash test
- Hacktool Execution - PE Metadata test
- HAFNIUM Exchange Exploitation Activity test
- Hardware Model Reconnaissance Via Wmic.EXE test
- Harvesting Of Wifi Credentials Via Netsh.EXE test
- Headless Process Launched Via Conhost.EXE test
- Hermetic Wiper TG Process Patterns test
- HH.EXE Execution test
- Hidden Powershell in Link File Pattern test
- Hiding Files with Attrib.exe test
- Hiding User Account Via SpecialAccounts Registry Key - CommandLine test
- HKTL - SharpSuccessor Privilege Escalation Tool Execution experimental
- HTML File Opened From Download Folder experimental
- HTML Help HH.EXE Suspicious Child Process test
- Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine experimental
- IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32 test
- IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI test
- Ie4uinit Lolbin Use From Invalid Path test
- IFM creation detected from commandline (installation from media) experimental
- IIS Application Pool credential dumping experimental
- IIS Native-Code Module Command Line Installation test
- IIS WebServer Log Deletion via CommandLine Utilities experimental
- ImagingDevices Unusual Parent/Child Processes test
- Impacket DCOMexec process abuse via MMC experimental
- Impacket WMIexec process execution experimental
- Import LDAP Data Interchange Format File Via Ldifde.EXE test
- Import New Module Via PowerShell CommandLine test
- Import PowerShell Modules From Suspicious Directories - ProcCreation test
- Imports Registry Key From a File test
- Imports Registry Key From an ADS test
- Indirect Command Execution By Program Compatibility Wizard test
- Indirect Command Execution From Script File Via Bash.EXE test
- Indirect Command Execution via SFTP ProxyCommand experimental
- Indirect Inline Command Execution Via Bash.EXE test
- InfDefaultInstall.exe .inf Execution test
- Injected Browser Process Spawning Rundll32 - GuLoader Activity test
- Insecure Proxy/DOH Transfer Via Curl.EXE test
- Insecure Transfer Via Curl.EXE test
- Insensitive Subfolder Search Via Findstr.EXE test
- Install New Package Via Winget Local Manifest test
- Installation of WSL Kali-Linux experimental
- Interactive AT Job test
- Interesting Service Enumeration Via Sc.EXE test
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) test
- Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace test
- Invoke-Obfuscation CLIP+ Launcher test
- Invoke-Obfuscation COMPRESS OBFUSCATION test
- Invoke-Obfuscation Obfuscated IEX Invocation test
- Invoke-Obfuscation STDIN+ Launcher test
- Invoke-Obfuscation VAR+ Launcher test
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION test
- Invoke-Obfuscation Via Stdin test
- Invoke-Obfuscation Via Use Clip test
- Invoke-Obfuscation Via Use MSHTA test
- Java Running with Remote Debugging test
- JScript Compiler Execution test
- Kalambur Backdoor Curl TOR SOCKS Proxy Execution experimental
- Kapeka Backdoor Execution Via RunDLL32.EXE test
- Kapeka Backdoor Persistence Activity test
- Kavremover Dropped Binary LOLBIN Usage test
- Kernel Memory Dump Via LiveKD test
- Lace Tempest Cobalt Strike Download test
- Lace Tempest Malware Loader Execution test
- Launch-VsDevShell.PS1 Proxy Execution test
- Lazarus Group Activity test
- Lazarus System Binary Masquerading test
- Loaded Module Enumeration Via Tasklist.EXE test
- Local Accounts Discovery test
- Local File Read Using Curl.EXE test
- Local Groups Reconnaissance Via Wmic.EXE test
- LockerGoga Ransomware Activity stable
- Logged-On User Password Change Via Ksetup.EXE test
- LOL-Binary Copied From System Directory test
- LOLBAS Data Exfiltration by DataSvcUtil.exe test
- LOLBIN Execution From Abnormal Drive test
- Lolbin Runexehelper Use As Proxy test
- Lolbin Unregmp2.exe Use As Proxy test
- LSA PPL Protection Setting Modification via CommandLine test
- LSASS credential dump with LSASSY (process) experimental
- LSASS Dump Keyword In CommandLine test
- LSASS Process Reconnaissance Via Findstr.EXE test
- Lummac Stealer Activity - Execution Of More.com And Vbc.exe experimental
- Malicious Base64 Encoded PowerShell Keywords in Command Lines test
- Malicious PE Execution by Microsoft Visual Studio Debugger test
- Malicious PowerShell Commandlets - ProcessCreation test
- Malicious Windows Script Components File Execution by TAEF Detection test
- ManageEngine Endpoint Central Dctask64.EXE Potential Abuse test
- Manual Execution of Script Inside of a Compressed File test
- Massive processes termination burst experimental
- Massive services deletion burst experimental
- Massive services termination burst experimental
- Mavinject Inject DLL Into Running Process test
- MERCURY APT Activity test
- Metasploit reverse shell injection in SQL Server experimental
- Microsoft Defender service deactivation attempt (command) experimental
- Microsoft IIS Connection Strings Decryption test
- Microsoft IIS Service Account Password Dumped test
- Microsoft Workflow Compiler Execution test
- Mint Sandstorm - AsperaFaspex Suspicious Process Execution test
- Mint Sandstorm - Log4J Wstomcat Process Execution test
- Mint Sandstorm - ManageEngine Suspicious Process Execution test
- MMC Executing Files with Reversed Extensions Using RTLO Abuse experimental
- MMC Spawning Windows Shell test
- MMC20 Lateral Movement test
- Modify Group Policy Settings test
- Monitoring For Persistence Via BITS test
- MpiExec Lolbin test
- MSDT Execution Via Answer File test
- MSExchange Transport Agent Installation test
- MSHTA Execution with Suspicious File Extensions test
- Mshtml.DLL RunHTMLApplication Suspicious Usage test
- Msiexec Quiet Installation test
- MsiExec Web Install test
- Mstsc.EXE Execution From Uncommon Parent test
- Mstsc.EXE Execution With Local RDP File test
- Msxsl.EXE Execution test
- Mustang Panda Dropper test
- Net WebClient Casing Anomalies test
- Net.EXE Execution test
- Netsh Allow Group Policy on Microsoft Defender Firewall test
- Network Reconnaissance Activity test
- Network share discovery and/or connection via commandline
- New Agent Skills Installation Attempt Via Node.EXE experimental
- New Capture Session Launched Via DXCap.EXE test
- New DLL Registered Via Odbcconf.EXE test
- New DMSA Service Account Created in Specific OUs experimental
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE test
- New Firewall Rule Added Via Netsh.EXE test
- New Generic Credentials Added Via Cmdkey.EXE test
- New Kernel Driver Via SC.EXE test
- New Network Trace Capture Started Via Netsh.EXE test
- New Port Forwarding Rule Added Via Netsh.EXE test
- New Process Created Via Taskmgr.EXE test
- New Remote Desktop Connection Initiated Via Mstsc.EXE test
- New Root Certificate Installed Via CertMgr.EXE test
- New Root Certificate Installed Via Certutil.EXE test
- New Self Extracting Package Created Via IExpress.EXE test
- New Service Creation Using PowerShell test
- New Service Creation Using Sc.EXE test
- New User Created Via Net.EXE test
- New User Created Via Net.EXE With Never Expire Option test
- New Virtual Smart Card Created Via TpmVscMgr.EXE test
- New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet test
- NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE test
- Nltest.EXE Execution test
- Node Process Executions test
- NodeJS Execution of JavaScript File experimental
- Non Interactive PowerShell Process Spawned test
- Non-privileged Usage of Reg or Powershell test
- Notepad Password Files Discovery experimental
- NotPetya Ransomware Activity test
- Nslookup PowerShell Download Cradle - ProcessCreation test
- NtdllPipe Like Activity Execution test
- NTFS symbolic link configuration change experimental
- NTFS symbolic link creation experimental
- NTLM Hash Leak Via Curl NTLM Authentication test
- Number of oustanding SMB requests increased experimental
- Obfuscated IP Download Activity test
- Obfuscated IP Via CLI test
- Obfuscated PowerShell MSI Install via WindowsInstaller COM experimental
- Obfuscated PowerShell OneLiner Execution test
- Odbcconf.EXE Suspicious DLL Location test
- OilRig APT Activity test
- OneNote.EXE Execution of Malicious Embedded Scripts test
- OpenEDR Spawning Command Shell experimental
- OpenWith.exe Executes Specified Binary test
- Operation Wocao Activity test
- Operator Bloopers Cobalt Strike Commands test
- Operator Bloopers Cobalt Strike Modules test
- Outlook EnableUnsafeClientMailRules Setting Enabled test
- PaperCut MF/NG Exploitation Related Indicators test
- PaperCut MF/NG Potential Exploitation test
- Password policy discovery via commandline
- Password Protected Compressed File Extraction Via 7Zip test
- Password Provided In Command Line Of Net.EXE test
- Password Set to Never Expire via WMI experimental
- PDQ Deploy Remote Adminstartion Tool Execution test
- Peach Sandstorm APT Process Activity Indicators test
- Perl Inline Command Execution test
- Permission Check Via Accesschk.EXE test
- Permission Misconfiguration Reconnaissance Via Findstr.EXE test
- Persistence Via Sticky Key Backdoor test
- Persistence Via TypedPaths - CommandLine test
- Phishing Pattern ISO in Archive test
- Php Inline Command Execution test
- Pikabot Fake DLL Extension Execution Via Rundll32.EXE test
- Ping Hex IP test
- Pingback Backdoor Activity test
- PktMon.EXE Execution test
- Port Forwarding Activity Via SSH.EXE test
- Portable Gpg.EXE Execution test
- Possible impact of 'SMOKEDHAM backdoor' with MSDTC service privilege escalation via command line production
- Possible Privilege Escalation via Weak Service Permissions test
- Potential ACTINIUM Persistence Activity test
- Potential Active Directory Enumeration Using AD Module - ProcCreation test
- Potential Adplus.EXE Abuse test
- Potential Amazon SSM Agent Hijacking test
- Potential AMSI Bypass Using NULL Bits test
- Potential AMSI Bypass Via .NET Reflection test
- Potential Application Whitelisting Bypass via Dnx.EXE test
- Potential APT FIN7 Exploitation Activity test
- Potential APT FIN7 Reconnaissance/POWERTRASH Related Activity test
- Potential APT Mustang Panda Activity Against Australian Gov test
- Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32 test
- Potential APT10 Cloud Hopper Activity test
- Potential Arbitrary Code Execution Via Node.EXE test
- Potential Arbitrary Command Execution Using Msdt.EXE test
- Potential Arbitrary Command Execution Via FTP.EXE test
- Potential Arbitrary DLL Load Using Winword test
- Potential Arbitrary File Download Using Office Application test
- Potential Arbitrary File Download Via Cmdl32.EXE test
- Potential Atlassian Confluence CVE-2021-26084 Exploitation Attempt test
- Potential Baby Shark Malware Activity test
- Potential BearLPE Exploitation test
- Potential Binary Impersonating Sysinternals Tools test
- Potential Binary Proxy Execution Via Cdb.EXE test
- Potential Binary Proxy Execution Via VSDiagnostics.EXE test
- Potential BlackByte Ransomware Activity test
- Potential BOINC Software Execution (UC-Berkeley Signature) test
- Potential Browser Data Stealing test
- Potential CobaltStrike Process Patterns test
- Potential COM Objects Download Cradles Usage - Process Creation test
- Potential Command Line Path Traversal Evasion Attempt test
- Potential Commandline Obfuscation Using Escape Characters test
- Potential CommandLine Obfuscation Using Unicode Characters test
- Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image test
- Potential CommandLine Path Traversal Via Cmd.EXE test
- Potential Compromised 3CXDesktopApp Execution test
- Potential Compromised 3CXDesktopApp Update Activity test
- Potential Configuration And Service Reconnaissance Via Reg.EXE test
- Potential Conti Ransomware Activity test
- Potential Conti Ransomware Database Dumping Activity Via SQLCmd test
- Potential Cookies Session Hijacking test
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI test
- Potential Credential Dumping Via LSASS Process Clone test
- Potential Credential Dumping Via WER test
- Potential Crypto Mining Activity stable
- Potential CVE-2021-26857 Exploitation Attempt stable
- Potential CVE-2021-40444 Exploitation Attempt test
- Potential CVE-2021-41379 Exploitation Attempt test
- Potential CVE-2021-44228 Exploitation Attempt - VMware Horizon test
- Potential CVE-2022-22954 Exploitation Attempt - VMware Workspace ONE Access Remote Code Execution test
- Potential CVE-2022-26809 Exploitation Attempt test
- Potential CVE-2022-29072 Exploitation Attempt test
- Potential CVE-2023-21554 QueueJumper Exploitation test
- Potential CVE-2023-36874 Exploitation - Fake Wermgr Execution test
- Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI test
- Potential Data Exfiltration Activity Via CommandLine Tools test
- Potential Data Exfiltration Via Curl.EXE test
- Potential Data Stealing Via Chromium Headless Debugging test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1 test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2 test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3 test
- Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4 test
- Potential Defense Evasion Via Binary Rename test
- Potential Defense Evasion Via Rename Of Highly Relevant Binaries test
- Potential Defense Evasion Via Right-to-Left Override test
- Potential Devil Bait Malware Reconnaissance test
- Potential Discovery Activity Via Dnscmd.EXE test
- Potential DLL File Download Via PowerShell Invoke-WebRequest test
- Potential DLL Injection Or Execution Using Tracker.exe test
- Potential DLL Injection Via AccCheckConsole test
- Potential DLL Sideloading Activity Via ExtExport.EXE test
- Potential DLL Sideloading Via DeviceEnroller.EXE test
- Potential Dosfuscation Activity test
- Potential Download/Upload Activity Using Type Command test
- Potential Dridex Activity stable
- Potential Dropper Script Execution Via WScript/CScript/MSHTA test
- Potential Dtrack RAT Activity stable
- Potential Emotet Activity stable
- Potential Emotet Rundll32 Execution test
- Potential EmpireMonkey Activity test
- Potential Encoded PowerShell Patterns In CommandLine test
- Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp test
- Potential Executable Run Itself As Sacrificial Process experimental
- Potential Execution of Sysinternals Tools test
- Potential Exploitation Attempt From Office Application test
- Potential Exploitation Attempt Of Undocumented WindowsServer RCE test
- Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309) experimental
- Potential Exploitation of CVE-2024-37085 - Suspicious Creation Of ESX Admins Group test
- Potential Exploitation of GoAnywhere MFT Vulnerability experimental
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 experimental
- Potential Fake Instance Of Hxtsr.EXE Executed test
- Potential File Download Via MS-AppInstaller Protocol Handler test
- Potential File Override/Append Via SET Command test
- Potential File Overwrite Via Sysinternals SDelete test
- Potential Goofy Guineapig Backdoor Activity test
- Potential Goofy Guineapig GoolgeUpdate Process Anomaly test
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI test
- Potential Homoglyph Attack Using Lookalike Characters test
- Potential KamiKakaBot Activity - Lure Document Execution test
- Potential KamiKakaBot Activity - Shutdown Schedule Task Creation test
- Potential Ke3chang/TidePool Malware Activity test
- Potential Lateral Movement via Windows Remote Shell experimental
- Potential LethalHTA Technique Execution test
- Potential LSASS Process Dump Via Procdump stable
- Potential Manage-bde.wsf Abuse To Proxy Execution test
- Potential Maze Ransomware Activity test
- Potential Memory Dumping Activity Via LiveKD test
- Potential Meterpreter/CobaltStrike Activity test
- Potential Mftrace.EXE Abuse test
- Potential MOVEit Transfer CVE-2023-34362 Exploitation - Dynamic Compilation Via Csc.EXE test
- Potential Mpclient.DLL Sideloading Via Defender Binaries test
- Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution test
- Potential MsiExec Masquerading test
- Potential MSTSC Shadowing Activity test
- Potential MuddyWater APT Activity test
- Potential Network Sniffing Activity Using Network Tools test
- Potential Notepad++ CVE-2025-49144 Exploitation experimental
- Potential NTLM Coercion Via Certutil.EXE test
- Potential Obfuscated Ordinal Call Via Rundll32 test
- Potential Password Reconnaissance Via Findstr.EXE test
- Potential Password Spraying Attempt Using Dsacls.EXE test
- Potential Persistence Attempt Via Existing Service Tampering test
- Potential Persistence Attempt Via Run Keys Using Reg.EXE test
- Potential Persistence Via Logon Scripts - CommandLine test
- Potential Persistence Via Microsoft Compatibility Appraiser test
- Potential Persistence Via Netsh Helper DLL test
- Potential Persistence Via Powershell Search Order Hijacking - Task test
- Potential Persistence Via VMwareToolBoxCmd.EXE VM State Change Script test
- Potential Pikabot Discovery Activity test
- Potential Pikabot Hollowing Activity test
- Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE test
- Potential PlugX Activity test
- Potential PowerShell Command Line Obfuscation test
- Potential PowerShell Console History Access Attempt via History File experimental
- Potential PowerShell Downgrade Attack test
- Potential PowerShell Execution Policy Tampering - ProcCreation test
- Potential PowerShell Execution Via DLL test
- Potential PowerShell Obfuscation Via Reversed Commands test
- Potential PowerShell Obfuscation Via WCHAR/CHAR test
- Potential Powershell ReverseShell Connection stable
- Potential Privilege Escalation To LOCAL SYSTEM test
- Potential Privilege Escalation Using Symlink Between Osk and Cmd test
- Potential Privilege Escalation via Service Permissions Weakness test
- Potential Process Execution Proxy Via CL_Invocation.ps1 test
- Potential Process Injection Via Msra.EXE test
- Potential Process Reconnaissance via Wmic.EXE test
- Potential Product Class Reconnaissance Via Wmic.EXE test
- Potential Product Reconnaissance Via Wmic.EXE test
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution test
- Potential Provlaunch.EXE Binary Proxy Execution Abuse test
- Potential Proxy Execution Via Explorer.EXE From Shell Process test
- Potential PsExec Remote Execution test
- Potential Qakbot Rundll32 Execution test
- Potential QBot Activity stable
- Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE test
- Potential Raspberry Robin CPL Execution Activity test
- Potential Raspberry Robin Dot Ending File test
- Potential RDP Session Hijacking Activity test
- Potential RDP Tunneling Via Plink test
- Potential RDP Tunneling Via SSH test
- Potential Recon Activity Using DriverQuery.EXE test
- Potential Recon Activity Via Nltest.EXE test
- Potential Reconnaissance Activity Via GatherNetworkInfo.VBS test
- Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE test
- Potential ReflectDebugger Content Execution Via WerFault.EXE test
- Potential Register_App.Vbs LOLScript Abuse test
- Potential Regsvr32 Commandline Flag Anomaly test
- Potential Remote Desktop Tunneling test
- Potential Remote SquiblyTwo Technique Execution test
- Potential Renamed Rundll32 Execution test
- Potential Rundll32 Execution With DLL Stored In ADS test
- Potential Russian APT Credential Theft Activity stable
- Potential Ryuk Ransomware Activity stable
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1 test
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation Indicators experimental
- Potential ShellDispatch.DLL Functionality Abuse test
- Potential Shim Database Persistence via Sdbinst.EXE test
- Potential Signing Bypass Via Windows Developer Features test
- Potential SMB Relay Attack Tool Execution test
- Potential SNAKE Malware Installation Binary Indicator test
- Potential SNAKE Malware Installation CLI Arguments Indicator test
- Potential SNAKE Malware Persistence Service Execution test
- Potential Snatch Ransomware Activity stable
- Potential SPN Enumeration Via Setspn.EXE test
- Potential SSH Tunnel Persistence Install Using A Scheduled Task experimental
- Potential Suspicious Activity Using SeCEdit test
- Potential Suspicious Browser Launch From Document Reader Process test
- Potential Suspicious Child Process Of 3CXDesktopApp test
- Potential Suspicious Execution From GUID Like Folder Names test
- Potential Suspicious Registry File Imported Via Reg.EXE test
- Potential Suspicious Windows Feature Enabled - ProcCreation test
- Potential SysInternals ProcDump Evasion test
- Potential SystemNightmare Exploitation Attempt test
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE test
- Potential Tampering With Security Products Via WMIC test
- Potential UAC Bypass Via Sdclt.EXE test
- Potential Unquoted Service Path Reconnaissance Via Wmic.EXE test
- Potential WinAPI Calls Via CommandLine test
- Potential Windows Defender AV Bypass Via Dump64.EXE Rename test
- Potential Windows Defender Tampering Via Wmic.EXE test
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell stable
- Potentially Over Permissive Permissions Granted Using Dsacls.EXE test
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler test
- Potentially Suspicious Cabinet File Expansion test
- Potentially Suspicious Call To Win32_NTEventlogFile Class test
- Potentially Suspicious Child Process Of ClickOnce Application test
- Potentially Suspicious Child Process Of DiskShadow.EXE test
- Potentially Suspicious Child Process of KeyScrambler.exe test
- Potentially Suspicious Child Process Of Regsvr32 test
- Potentially Suspicious Child Process Of VsCode test
- Potentially Suspicious Child Process Of WinRAR.EXE test
- Potentially Suspicious Child Processes Spawned by ConHost experimental
- Potentially Suspicious CMD Shell Output Redirect test
- Potentially Suspicious Command Targeting Teams Sensitive Files test
- Potentially Suspicious Compression Tool Parameters test
- Potentially Suspicious Desktop Background Change Using Reg.EXE test
- Potentially Suspicious DLL Registered Via Odbcconf.EXE test
- Potentially Suspicious Electron Application CommandLine test
- Potentially Suspicious Event Viewer Child Process test
- Potentially Suspicious EventLog Recon Activity Using Log Query Utilities test
- Potentially Suspicious Execution From Parent Process In Public Folder test
- Potentially Suspicious Execution Of PDQDeployRunner test
- Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location test
- Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension test
- Potentially Suspicious File Download From File Sharing Domain Via PowerShell.EXE test
- Potentially Suspicious GoogleUpdate Child Process test
- Potentially Suspicious Inline JavaScript Execution via NodeJS Binary experimental
- Potentially Suspicious JWT Token Search Via CLI test
- Potentially Suspicious Mofcomp Execution test
- Potentially Suspicious NTFS Symlink Behavior Modification test
- Potentially Suspicious Office Document Executed From Trusted Location test
- Potentially Suspicious Ping/Copy Command Combination test
- Potentially Suspicious PowerShell Child Processes test
- Potentially Suspicious Powershell Script Execution From Temp Folder test
- Potentially Suspicious Regsvr32 HTTP IP Pattern test
- Potentially Suspicious Regsvr32 HTTP/FTP Pattern test
- Potentially Suspicious Rundll32 Activity test
- Potentially Suspicious Rundll32.EXE Execution of UDL File test
- Potentially Suspicious Usage Of Qemu test
- Potentially Suspicious WebDAV LNK Execution test
- Potentially Suspicious Windows App Activity test
- PowerShell Base64 Encoded FromBase64String Cmdlet test
- PowerShell Base64 Encoded IEX Cmdlet test
- PowerShell Base64 Encoded Invoke Keyword test
- Powershell Base64 Encoded MpPreference Cmdlet test
- PowerShell Base64 Encoded Reflective Assembly Load test
- PowerShell Base64 Encoded WMI Classes test
- Powershell Defender Disable Scan Feature test
- Powershell Defender Exclusion test
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction' experimental
- PowerShell Download and Execution Cradles test
- PowerShell Download Pattern test
- Powershell Executed From Headless ConHost Process test
- PowerShell Execution With Potential Decryption Capabilities test
- PowerShell Get-Clipboard Cmdlet Via CLI test
- PowerShell Get-Process LSASS test
- Powershell Inline Execution From A File test
- PowerShell MSI Install via WindowsInstaller COM From Remote Location experimental
- PowerShell SAM Copy test
- PowerShell Script Change Permission Via Set-Acl test
- PowerShell Script Run in AppData test
- PowerShell Set-Acl On Windows Folder test
- Powershell Token Obfuscation - Process Creation test
- PowerShell Web Access Feature Enabled Via DISM test
- PPL Tampering Via WerFaultSecure experimental
- PrintBrm ZIP Creation of Extraction test
- Private Keys Reconnaissance Via CommandLine Tools test
- Privilege Escalation via Named Pipe Impersonation test
- Procdump Execution test
- Process Access via TrolleyExpress Exclusion test
- Process Creation Attempt via Wmic.EXE test
- Process Creation Using Sysnative Folder test
- Process Execution From A Potentially Suspicious Folder test
- Process Execution From WebDAV Share experimental
- Process Launched Without Image Name test
- Process Memory Dump Via Comsvcs.DLL test
- Process Memory Dump Via Dotnet-Dump test
- Process Memory Dump via RdrLeakDiag.EXE test
- Process Proxy Execution Via Squirrel.EXE test
- Process Terminated Via Taskkill test
- Program Executed Using Proxy/Local Command Via SSH.EXE test
- Proxy Execution via Vshadow experimental
- Proxy Execution Via Wuauclt.EXE test
- Ps.exe Renamed SysInternals Tool test
- PSexec application execution experimental
- Psexec Execution test
- PsExec Service Child Process Execution as LOCAL SYSTEM test
- PsExec Service Execution test
- PsExec/PAExec Escalation to LOCAL SYSTEM test
- PUA - 3Proxy Execution test
- PUA - AdFind Suspicious Execution test
- PUA - AdFind.EXE Execution experimental
- PUA - Adidnsdump Execution test
- PUA - Advanced IP Scanner Execution test
- PUA - Advanced Port Scanner Execution test
- PUA - AdvancedRun Execution test
- PUA - AdvancedRun Suspicious Execution test
- PUA - Chisel Tunneling Tool Execution test
- PUA - CleanWipe Execution test
- PUA - Crassus Execution test
- PUA - CsExec Execution test
- PUA - DefenderCheck Execution test
- PUA - DIT Snapshot Viewer test
- PUA - Fast Reverse Proxy (FRP) Execution test
- PUA - Kernel Driver Utility (KDU) Execution experimental
- PUA - Memory Dump Mount Via MemProcFS experimental
- PUA - Mouse Lock Execution test
- PUA - Netcat Suspicious Execution test
- PUA - Ngrok Execution test
- PUA - Nimgrab Execution test
- PUA - NimScan Execution test
- PUA - NirCmd Execution test
- PUA - NirCmd Execution As LOCAL SYSTEM test
- PUA - Nmap/Zenmap Execution test
- PUA - NPS Tunneling Tool Execution test
- PUA - NSudo Execution test
- PUA - PingCastle Execution test
- PUA - PingCastle Execution From Potentially Suspicious Parent test
- PUA - Potential PE Metadata Tamper Using Rcedit test
- PUA - Process Hacker Execution test
- PUA - Radmin Viewer Utility Execution test
- PUA - Rclone Execution test
- PUA - Restic Backup Tool Execution experimental
- PUA - RunXCmd Execution test
- PUA - Seatbelt Execution test
- PUA - SoftPerfect Netscan Execution test
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE test
- PUA - System Informer Execution test
- PUA - TruffleHog Execution experimental
- PUA - WebBrowserPassView Execution test
- PUA - Wsudo Suspicious Execution test
- PUA- IOX Tunneling Tool Execution test
- Pubprn.vbs Proxy Execution test
- Python Function Execution Security Warning Disabled In Excel test
- Python Inline Command Execution test
- Python One-Liners with Base64 Decoding experimental
- Python Spawning Pretty TTY on Windows test
- Qakbot Regsvr32 Calc Pattern test
- Qakbot Rundll32 Exports Execution test
- Qakbot Rundll32 Fake DLL Extension Execution test
- Qakbot Uninstaller Execution test
- Query Usage To Exfil Data test
- QuickAssist Execution experimental
- Raccine Uninstall test
- Rar Usage with Password and Compression Level test
- Raspberry Robin Initial Execution From External Drive test
- Raspberry Robin Subsequent Execution of Commands test
- RDP Connection Allowed Via Netsh.EXE test
- RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class experimental
- RDP Port Forwarding Rule Added Via Netsh.EXE test
- RDP shadow session started (command) experimental
- RDP tunneling configuration enabled for port forwarding experimental
- Read Contents From Stdin Via Cmd.EXE test
- Rebuild Performance Counter Values Via Lodctr.EXE test
- Recon Command Output Piped To Findstr.EXE test
- Recon Information for Export with Command Prompt test
- RedSun - Conhost.exe Spawned by TieringEngineService.exe experimental
- Reg Add Suspicious Paths test
- RegAsm.EXE Execution Without CommandLine Flags or Files experimental
- Regedit as Trusted Installer test
- REGISTER_APP.VBS Proxy Execution test
- Registry Enumeration via WMI Stdregprov experimental
- Registry Export of Third-Party Credentials experimental
- Registry Manipulation via WMI Stdregprov experimental
- Registry Modification Attempt Via VBScript experimental
- Registry Modification of MS-settings Protocol Handler test
- Registry Modification Via Regini.EXE test
- Regsvr32 DLL Execution With Suspicious File Extension test
- Regsvr32 DLL Execution With Uncommon Extension test
- Regsvr32 Execution From Highly Suspicious Location test
- Regsvr32 Execution From Potential Suspicious Location test
- Regsvr32.EXE Calling of DllRegisterServer Export Function Implicitly test
- Remote Access Tool - Action1 Arbitrary Code Execution and Remote Sessions test
- Remote Access Tool - Ammy Admin Agent Execution test
- Remote Access Tool - AnyDesk Execution test
- Remote Access Tool - Anydesk Execution From Suspicious Folder test
- Remote Access Tool - AnyDesk Execution With Known Revoked Signing Certificate test
- Remote Access Tool - AnyDesk Piped Password Via CLI test
- Remote Access Tool - AnyDesk Silent Installation test
- Remote Access Tool - Cmd.EXE Execution via AnyViewer test
- Remote Access Tool - GoToAssist Execution test
- Remote Access Tool - LogMeIn Execution test
- Remote Access Tool - MeshAgent Command Execution via MeshCentral test
- Remote Access Tool - NetSupport Execution test
- Remote Access Tool - NetSupport Execution From Unusual Location test
- Remote Access Tool - Potential MeshAgent Execution - Windows experimental
- Remote Access Tool - Renamed MeshAgent Execution - Windows experimental
- Remote Access Tool - RURAT Execution From Unusual Location test
- Remote Access Tool - ScreenConnect Execution test
- Remote Access Tool - ScreenConnect Installation Execution test
- Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution test
- Remote Access Tool - ScreenConnect Remote Command Execution test
- Remote Access Tool - ScreenConnect Remote Command Execution - Hunting test
- Remote Access Tool - ScreenConnect Server Web Shell Execution test
- Remote Access Tool - Simple Help Execution test
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server experimental
- Remote Access Tool - Team Viewer Session Started On Windows Host test
- Remote Access Tool - UltraViewer Execution test
- Remote CHM File Download/Execution Via HH.EXE test
- Remote Code Execute via Winrm.vbs test
- Remote File Download Via Desktopimgdownldr Utility test
- Remote File Download Via Findstr.EXE test
- Remote PowerShell Session Host Process (WinRM) test
- Remote XSL Execution Via Msxsl.EXE test
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses test
- Remotely Hosted HTA File Executed Via Mshta.EXE test
- Renamed AdFind Execution test
- Renamed AutoHotkey.EXE Execution test
- Renamed AutoIt Execution test
- Renamed BOINC Client Execution test
- Renamed BrowserCore.EXE Execution test
- Renamed Cloudflared.EXE Execution test
- Renamed CreateDump Utility Execution test
- Renamed CURL.EXE Execution test
- Renamed FTP.EXE Execution test
- Renamed Gpg.EXE Execution test
- Renamed Jusched.EXE Execution test
- Renamed Mavinject.EXE Execution test
- Renamed MegaSync Execution test
- Renamed Microsoft Teams Execution test
- Renamed Msdt.EXE Execution test
- Renamed NetSupport RAT Execution test
- Renamed NirCmd.EXE Execution test
- Renamed Office Binary Execution test
- Renamed PAExec Execution test
- Renamed PingCastle Binary Execution test
- Renamed Plink Execution test
- Renamed ProcDump Execution test
- Renamed Procdump tool used for dumping LSASS process experimental
- Renamed PsExec Service Execution test
- Renamed Remote Utilities RAT (RURAT) Execution test
- Renamed Schtasks Execution experimental
- Renamed SysInternals DebugView Execution test
- Renamed Sysinternals Sdelete Execution test
- Renamed Visual Studio Code Tunnel Execution test
- Renamed Vmnat.exe Execution test
- Renamed Whoami Execution test
- Renamed ZOHO Dctask64 Execution test
- Replace.exe Usage test
- Response File Execution Via Odbcconf.EXE test
- RestrictedAdminMode Registry Value Tampering - ProcCreation test
- REvil Kaseya Incident Malware Patterns test
- Rhadamanthys Stealer Module Launch Via Rundll32.EXE test
- Root Certificate Installed From Susp Locations test
- Rorschach Ransomware Execution Activity test
- Ruby Inline Command Execution test
- Run Once Task Execution as Configured in Registry test
- Run PowerShell Script from ADS test
- Run PowerShell Script from Redirected Input Stream test
- Rundll32 Execution With Uncommon DLL Extension test
- Rundll32 Execution Without CommandLine Parameters test
- Rundll32 Execution Without Parameters test
- Rundll32 InstallScreenSaver Execution test
- Rundll32 Registered COM Objects test
- Rundll32 Spawned Via Explorer.EXE test
- RunDLL32 Spawning Explorer test
- Rundll32 UNC Path Execution test
- Rundll32.EXE Calling DllRegisterServer Export Function Explicitly test
- RunMRU Registry Key Deletion experimental
- SafeBoot Registry Key Deleted Via Reg.EXE test
- SC.EXE Query Execution test
- Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE test
- Scheduled persistent task with SYSTEM privileges creation experimental
- Scheduled Task Creation From Potential Suspicious Parent Location test
- Scheduled Task Creation Masquerading as System Processes experimental
- Scheduled Task Creation Via Schtasks.EXE test
- Scheduled task creation with command line experimental
- Scheduled Task Creation with Curl and PowerShell Execution Combo experimental
- Scheduled Task Executing Encoded Payload from Registry test
- Scheduled Task Executing Payload from Registry test
- Schtasks Creation Or Modification With SYSTEM Privileges test
- Schtasks From Suspicious Folders test
- Screen Capture Activity Via Psr.EXE test
- Script Event Consumer Spawning Process test
- Script Interpreter Execution From Suspicious Folder test
- Script Interpreter Spawning Credential Scanner - Windows experimental
- Scripting/CommandLine Process Spawned Regsvr32 test
- Sdclt Child Processes test
- Sdiagnhost Calling Suspicious Child Process test
- SearchIndexer suspicious process activity experimental
- Security Event Logging Disabled via MiniNt Registry Key - Process experimental
- Security package (SSP) added (Reg via command) experimental
- Security Privileges Enumeration Via Whoami.EXE test
- Security Service Disabled Via Reg.EXE test
- Security Tools Keyword Lookup Via Findstr.EXE test
- Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location test
- Sensitive File Access Via Volume Shadow Copy Backup test
- Sensitive File Dump Via Print.EXE test
- Sensitive File Dump Via Wbadmin.EXE test
- Sensitive File Recovery From Backup Via Wbadmin.EXE test
- Serial console process spawning CMD shell (via command) experimental
- Serpent Backdoor Payload Execution Via Scheduled Task test
- Serv-U Exploitation CVE-2021-35211 by DEV-0322 test
- Service abuse with malicious ImagePath (service) experimental
- Service creation (command) experimental
- Service DACL Abuse To Hide Services Via Sc.EXE test
- Service deactivation (command) experimental
- Service permissions hijacked for privileges abuse (service) experimental
- Service Reconnaissance Via Wmic.EXE test
- Service Registry Key Deleted Via Reg.EXE test
- Service Security Descriptor Tampering Via Sc.EXE test
- Service Started/Stopped Via Wmic.EXE test
- Service Startup Type Change Via Wmic.EXE experimental
- Service StartupType Change Via PowerShell Set-Service test
- Service StartupType Change Via Sc.EXE test
- Set Files as System Files Using Attrib.EXE test
- Set Suspicious Files as System Files Using Attrib.EXE test
- Setup16.EXE Execution With Custom .Lst File test
- Shadow Copies Creation Using Operating Systems Utilities test
- Shadow Copies Deletion Using Operating Systems Utilities stable
- Shai-Hulud 2.0 Malicious NPM Package Installation experimental
- Shai-Hulud Malicious Bun Execution experimental
- Shai-Hulud Malware Indicators - Windows experimental
- Share And Session Enumeration Using Net.EXE stable
- Shell Process Spawned by Java.EXE test
- Shell32 DLL Execution in Suspicious Directory test
- ShimCache Flush stable
- Small Sieve Malware CommandLine Indicator test
- SMB over QUIC Via Net.EXE test
- Sofacy Trojan Loader Activity test
- SOURGUM Actor Behaviours test
- SPN added to an account by command line experimental
- Spool process spawned a CMD shell (PrintNightmare vulnerability - CVE-2021-36958) experimental
- SQL Client Tools PowerShell Session Detection test
- SQL Server database's table enumeration experimental
- SQL server sqlcmd utility abuse for privilege escalation experimental
- SQLite Chromium Profile Data DB Access test
- SQLite Firefox Profile Data DB Access test
- Start of NT Virtual DOS Machine test
- Start Windows Service Via Net.EXE test
- Stickey key called CMD via command execution experimental
- Stickey key called CMD via command execution (hash detection) experimental
- Sticky Key Like Backdoor Execution test
- Stop Windows Service Via Net.EXE test
- Stop Windows Service Via PowerShell Stop-Service test
- Stop Windows Service Via Sc.EXE test
- Suspect Svchost Activity test
- Suspicious Active Directory Database Snapshot Via ADExplorer test
- Suspicious AddinUtil.EXE CommandLine Execution test
- Suspicious Advpack Call Via Rundll32.EXE test
- Suspicious AgentExecutor PowerShell Execution test
- Suspicious ArcSOC.exe Child Process experimental
- Suspicious Autorun Registry Modified via WMI experimental
- Suspicious Binary In User Directory Spawned From Office Application test
- Suspicious BitLocker Access Agent Update Utility Execution experimental
- Suspicious Cabinet File Execution Via Msdt.EXE test
- Suspicious Calculator Usage test
- Suspicious CertReq Command to Download experimental
- Suspicious Child Process Created as System test
- Suspicious Child Process of AspNetCompiler test
- Suspicious Child Process Of BgInfo.EXE test
- Suspicious Child Process Of Manage Engine ServiceDesk test
- Suspicious Child Process of Notepad++ Updater - GUP.Exe experimental
- Suspicious Child Process of SAP NetWeaver experimental
- Suspicious Child Process of SolarWinds WebHelpDesk experimental
- Suspicious Child Process Of SQL Server test
- Suspicious Child Process Of Veeam Dabatase test
- Suspicious Child Process Of Wermgr.EXE test
- Suspicious Chromium Browser Instance Executed With Custom Extension test
- Suspicious ClickFix/FileFix Execution Pattern experimental
- Suspicious CodePage Switch Via CHCP test
- Suspicious Command Patterns In Scheduled Task Creation test
- Suspicious Control Panel DLL Load test
- Suspicious Copy From or To System Directory test
- Suspicious Cross-User Process Spawn experimental
- Suspicious CrushFTP Child Process experimental
- Suspicious Csi.exe Usage test
- Suspicious Curl.EXE Download test
- Suspicious CustomShellHost Execution test
- Suspicious Debugger Registration Cmdline test
- Suspicious Desktopimgdownldr Command test
- Suspicious Diantz Alternate Data Stream Execution test
- Suspicious Diantz Download and Compress Into a CAB File test
- Suspicious DLL Loaded via CertOC.EXE test
- Suspicious Double Extension File Execution stable
- Suspicious Download From Direct IP Via Bitsadmin test
- Suspicious Download From File-Sharing Website Via Bitsadmin test
- Suspicious Download from Office Domain test
- Suspicious Download Via Certutil.EXE test
- Suspicious Driver Install by pnputil.exe test
- Suspicious Driver/DLL Installation Via Odbcconf.EXE test
- Suspicious DumpMinitool Execution test
- Suspicious Electron Application Child Processes test
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call test
- Suspicious Encoded PowerShell Command Line test
- Suspicious Eventlog Clearing or Configuration Change Activity stable
- Suspicious Execution From Outlook Temporary Folder test
- Suspicious Execution Location Of Wermgr.EXE test
- Suspicious Execution of Hostname test
- Suspicious Execution of InstallUtil Without Log test
- Suspicious Execution of Powershell with Base64 test
- Suspicious Execution of Shutdown test
- Suspicious Execution of Shutdown to Log Out test
- Suspicious Execution of Systeminfo test
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix experimental
- Suspicious Extrac32 Alternate Data Stream Execution test
- Suspicious Extrac32 Execution test
- Suspicious File Characteristics Due to Missing Fields test
- Suspicious File Download From File Sharing Domain Via Curl.EXE test
- Suspicious File Download From File Sharing Domain Via Wget.EXE test
- Suspicious File Download From IP Via Curl.EXE test
- Suspicious File Download From IP Via Wget.EXE test
- Suspicious File Download From IP Via Wget.EXE - Paths test
- Suspicious File Downloaded From Direct IP Via Certutil.EXE test
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE test
- Suspicious File Encoded To Base64 Via Certutil.EXE test
- Suspicious File Execution From Internet Hosted WebDav Share test
- Suspicious FileFix Execution Pattern experimental
- Suspicious FromBase64String Usage On Gzip Archive - Process Creation test
- Suspicious Git Clone test
- Suspicious Greedy Compression Using Rar.EXE test
- Suspicious Group And Account Reconnaissance Activity Using Net.EXE test
- Suspicious GrpConv Execution test
- Suspicious GUP Usage test
- Suspicious HH.EXE Execution test
- Suspicious High IntegrityLevel Conhost Legacy Option test
- Suspicious HWP Sub Processes test
- Suspicious IIS Module Registration test
- Suspicious IIS URL GlobalRules Rewrite Via AppCmd test
- Suspicious Invoke-WebRequest Execution test
- Suspicious Invoke-WebRequest Execution With DirectIP test
- Suspicious JavaScript Execution Via Mshta.EXE test
- Suspicious Kerberos Ticket Request via CLI experimental
- Suspicious Kernel Dump Using Dtrace test
- Suspicious Key Manager Access test
- Suspicious LNK Command-Line Padding with Whitespace Characters experimental
- Suspicious Manipulation Of Default Accounts Via Net.EXE test
- Suspicious Microsoft Office Child Process test
- Suspicious Microsoft OneNote Child Process test
- Suspicious Modification Of Scheduled Tasks test
- Suspicious Msbuild Execution By Uncommon Parent Process test
- Suspicious MSDT Parent Process test
- Suspicious MSHTA Child Process test
- Suspicious Mshta.EXE Execution Patterns test
- Suspicious MsiExec Embedding Parent test
- Suspicious Msiexec Execute Arbitrary DLL test
- Suspicious Msiexec Quiet Install From Remote Location test
- Suspicious Mstsc.EXE Execution With Local RDP File test
- Suspicious Network Command test
- Suspicious New Instance Of An Office COM Object test
- Suspicious New Service Creation test
- Suspicious NTLM Authentication on the Printer Spooler Service test
- Suspicious Obfuscated PowerShell Code test
- Suspicious Outlook Child Process test
- Suspicious Parent Double Extension File Execution test
- Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script test
- Suspicious Ping/Del Command Combination test
- Suspicious Plink Port Forwarding test
- Suspicious Powercfg Execution To Change Lock Screen Timeout test
- Suspicious PowerShell Download and Execute Pattern test
- Suspicious PowerShell Encoded Command Patterns test
- Suspicious PowerShell IEX Execution Patterns test
- Suspicious PowerShell Invocation From Script Engines test
- Suspicious PowerShell Invocations - Specific - ProcessCreation test
- Suspicious PowerShell Mailbox Export to Share test
- Suspicious PowerShell Parameter Substring test
- Suspicious PowerShell Parent Process test
- Suspicious PrinterPorts Creation (CVE-2020-1048) test
- Suspicious Process By Web Server Process test
- Suspicious Process Created Via Wmic.EXE test
- Suspicious Process Execution From Fake Recycle.Bin Folder test
- Suspicious Process Masquerading As SvcHost.EXE test
- Suspicious Process Parents test
- Suspicious Process Patterns NTDS.DIT Exfil test
- Suspicious Process Spawned by CentreStack Portal AppPool experimental
- Suspicious Process Start Locations test
- Suspicious Processes Spawned by Java.EXE test
- Suspicious Processes Spawned by WinRM test
- Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE test
- Suspicious Program Names test
- Suspicious Provlaunch.EXE Child Process test
- Suspicious Query of MachineGUID test
- Suspicious RASdial Activity test
- Suspicious RazerInstaller Explorer Subprocess test
- Suspicious RDP Redirect Using TSCON test
- Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet test
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS test
- Suspicious Recursive Takeown test
- Suspicious Redirection to Local Admin Share test
- Suspicious Reg Add BitLocker test
- Suspicious Registry Modification From ADS Via Regini.EXE test
- Suspicious Regsvr32 Execution From Remote Share test
- Suspicious Remote Child Process From Outlook test
- Suspicious Response File Execution Via Odbcconf.EXE test
- Suspicious RunAs-Like Flag Combination test
- Suspicious Rundll32 Activity Invoking Sys File test
- Suspicious Rundll32 Execution With Image Extension test
- Suspicious Rundll32 Invoking Inline VBScript test
- Suspicious Rundll32 Setupapi.dll Activity test
- Suspicious Runscripthelper.exe test
- Suspicious Scan Loop Network test
- Suspicious Scheduled Task Creation Involving Temp Folder test
- Suspicious Scheduled Task Creation via Masqueraded XML File test
- Suspicious Scheduled Task Name As GUID test
- Suspicious Schtasks Execution AppData Folder test
- Suspicious Schtasks Schedule Type With High Privileges test
- Suspicious Schtasks Schedule Types test
- Suspicious ScreenSave Change by Reg.exe test
- Suspicious Serv-U Process Pattern test
- Suspicious Service Binary Directory test
- Suspicious Service DACL Modification Via Set-Service Cmdlet test
- Suspicious Service Path Modification test
- Suspicious ShellExec_RunDLL Call Via Ordinal test
- Suspicious Shells Spawn by Java Utility Keytool test
- Suspicious Speech Runtime Binary Child Process experimental
- Suspicious Splwow64 Without Params test
- Suspicious SPN enumeration previous to Kerberoasting attack (native commands) experimental
- Suspicious Spool Service Child Process test
- Suspicious SysAidServer Child test
- Suspicious Sysmon as Execution Parent test
- Suspicious SYSTEM User Process Creation test
- Suspicious SYSVOL Domain Group Policy Access test
- Suspicious Tasklist Discovery Command test
- Suspicious TSCON Start as SYSTEM test
- Suspicious UltraVNC Execution test
- Suspicious Uninstall of Windows Defender Feature via PowerShell experimental
- Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe) test
- Suspicious Usage of For Loop with Recursive Directory Search in CMD experimental
- Suspicious Usage Of ShellExec_RunDLL test
- Suspicious Use of CSharp Interactive Console test
- Suspicious Use of PsLogList test
- Suspicious Userinit Child Process test
- Suspicious VBoxDrvInst.exe Parameters test
- Suspicious VBScript UN2452 Pattern test
- Suspicious Velociraptor Child Process experimental
- Suspicious Vsls-Agent Command With AgentExtensionPath Load test
- Suspicious WebDav Client Execution Via Rundll32.EXE test
- Suspicious Where Execution test
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE test
- Suspicious Windows Defender Registry Key Tampering Via Reg.EXE test
- Suspicious Windows Service Tampering test
- Suspicious Windows Trace ETW Session Tamper Via Logman.EXE test
- Suspicious Windows Update Agent Empty Cmdline test
- Suspicious WindowsTerminal Child Processes test
- Suspicious WMIC Execution Via Office Process test
- Suspicious WmiPrvSE Child Process test
- Suspicious Workstation Locking via Rundll32 test
- Suspicious X509Enrollment - Process Creation test
- Suspicious XOR Encoded PowerShell Command test
- Suspicious ZipExec Execution test
- SyncAppvPublishingServer Execute Arbitrary PowerShell Code test
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code test
- Sysinternals PsService Execution test
- Sysinternals PsSuspend Execution test
- Sysinternals PsSuspend Suspicious Execution test
- Sysmon Configuration Update test
- Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE test
- Sysmon Driver Unloaded Via Fltmc.EXE test
- Sysprep on AppData Folder test
- System Disk And Volume Reconnaissance Via Wmic.EXE test
- System File Execution Location Anomaly test
- System Information Discovery via Registry Queries experimental
- System Information Discovery Via Wmic.EXE test
- System Language Discovery via Reg.Exe experimental
- System Network Connections Discovery Via Net.EXE test
- System Restore Registry Modification via CommandLine experimental
- TAIDOOR RAT DLL Load test
- Tamper Windows Defender Remove-MpPreference test
- TanStack Supply-Chain Attack Execution Indicators - Windows experimental
- Tap Installer Execution test
- Task Manager access indicator for potential LSASS dump experimental
- Taskkill Symantec Endpoint Protection test
- Taskmgr as LOCAL_SYSTEM test
- Tasks Folder Evasion test
- Terminal Service Process Spawn test
- Time Travel Debugging Utility Usage test
- Tor Client/Browser Execution test
- Trickbot Malware Activity stable
- TropicTrooper Campaign November 2018 stable
- TrustedPath UAC Bypass Pattern test
- Tunneling Tool Execution test
- Turla Group Commands May 2020 test
- Turla Group Lateral Movement test
- UAC Bypass Abusing Winsat Path Parsing - Process test
- UAC Bypass Tools Using ComputerDefaults test
- UAC Bypass Using ChangePK and SLUI test
- UAC Bypass Using Consent and Comctl32 - Process test
- UAC Bypass Using Disk Cleanup test
- UAC Bypass Using DismHost test
- UAC Bypass Using Event Viewer RecentViews test
- UAC Bypass Using IDiagnostic Profile test
- UAC Bypass Using IEInstal - Process test
- UAC Bypass Using MSConfig Token Modification - Process test
- UAC Bypass Using NTFS Reparse Point - Process test
- UAC Bypass Using PkgMgr and DISM test
- UAC Bypass Using Windows Media Player - Process test
- UAC Bypass via ICMLuaUtil test
- UAC Bypass via Windows Firewall Snap-In Hijack test
- UAC Bypass WSReset test
- UEFI Persistence Via Wpbbin - ProcessCreation test
- UNC2452 PowerShell Pattern test
- UNC2452 Process Creation Patterns test
- Uncommon Assistive Technology Applications Execution Via AtBroker.EXE test
- Uncommon AddinUtil.EXE CommandLine Execution test
- Uncommon Child Process Of AddinUtil.EXE test
- Uncommon Child Process Of Appvlp.EXE test
- Uncommon Child Process Of BgInfo.EXE test
- Uncommon Child Process Of Conhost.EXE test
- Uncommon Child Process Of Defaultpack.EXE test
- Uncommon Child Process Of Setres.EXE test
- Uncommon Child Process Spawned By Odbcconf.EXE test
- Uncommon Child Processes Of SndVol.exe test
- Uncommon Extension Shim Database Installation Via Sdbinst.EXE test
- Uncommon FileSystem Load Attempt By Format.com test
- Uncommon Link.EXE Parent Process test
- Uncommon One Time Only Scheduled Task At 00:00 test
- Uncommon Sigverif.EXE Child Process test
- Uncommon Svchost Command Line Parameter experimental
- Uncommon Svchost Parent Process test
- Uncommon System Information Discovery Via Wmic.EXE test
- Uncommon Userinit Child Process test
- Uninstall Crowdstrike Falcon Sensor test
- Uninstall Sysinternals Sysmon test
- Unmount Share Via Net.EXE test
- Unsigned AppX Installation Attempt Using Add-AppxPackage test
- Unusual Child Process of dns.exe test
- Unusual Parent Process For Cmd.EXE test
- Unusually Long PowerShell CommandLine test
- Ursnif Redirection Of Discovery Commands test
- Usage Of Web Request Commands And Cmdlets test
- Use Icacls to Hide File to Everyone test
- Use NTFS Short Name in Command Line test
- Use NTFS Short Name in Image test
- Use of FSharp Interpreters test
- Use of OpenConsole test
- Use of Pcalua For Execution test
- Use of Remote.exe test
- Use of Scriptrunner.exe test
- Use Of The SFTP.EXE Binary As A LOLBIN test
- Use of TTDInject.exe test
- Use of UltraVNC Remote Access Software test
- Use of VisualUiaVerifyNative.exe test
- Use of VSIISExeLauncher.exe test
- Use of W32tm as Timer test
- Use of Wfc.exe test
- Use Short Name Path in Command Line test
- Use Short Name Path in Image test
- User added to a group via commandline
- User Added To Highly Privileged Group test
- User Added to Local Administrators Group test
- User Added to Remote Desktop Users Group test
- User creation via commandline
- User Discovery And Export Via Get-ADUser Cmdlet test
- User enumeration and creation related to Manic Menagerie 2.0 (via cmdline)
- User properties enumeration via commandline
- User Shell Folders Registry Modification via CommandLine experimental
- Using SettingSyncHost.exe as LOLBin test
- UtilityFunctions.ps1 Proxy Dll test
- Veeam Backup Database Suspicious Query test
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE test
- Verclsid.exe Runs COM Object test
- Virtualbox Driver Installation or Starting of VMs test
- Visual Basic Command Line Compiler Usage test
- Visual Studio Code Tunnel Execution test
- Visual Studio Code Tunnel Service Installation test
- Visual Studio Code Tunnel Shell Execution test
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution test
- Visual Studio NodejsTools PressAnyKey Renamed Execution test
- VMToolsd Suspicious Child Process test
- VolumeShadowCopy Symlink Creation Via Mklink stable
- VSS backup deletion (WMI) experimental
- Vulnerable Driver Blocklist Registry Tampering Via CommandLine experimental
- Wab Execution From Non Default Location test
- Wab/Wabmig Unusual Parent Or Child Processes test
- WannaCry Ransomware Activity test
- Wdigest authentication enabled (Reg via command) experimental
- Weak or Abused Passwords In CLI test
- WebDav Client Execution Via Rundll32.EXE test
- Webserver IIS module installed (command) experimental
- Webserver IIS module installed (command) experimental
- Webshell Detection With Command Line Keywords test
- Webshell Hacking Activity Patterns test
- Webshell Tool Reconnaissance Activity test
- WhoAmI as Parameter test
- Whoami.EXE Execution Anomaly test
- Whoami.EXE Execution From Privileged Process test
- Whoami.EXE Execution With Output Option test
- Windows Admin Share Mount Via Net.EXE test
- Windows AMSI Related Registry Tampering Via CommandLine experimental
- Windows Backup Deleted Via Wbadmin.EXE test
- Windows Binary Executed From WSL test
- Windows Credential Guard Registry Tampering Via CommandLine experimental
- Windows Credential Manager Access via VaultCmd test
- Windows Default Domain GPO Modification via GPME experimental
- Windows Defender Context Menu Removed experimental
- Windows Defender Definition Files Removed test
- Windows Defender Disabled Via SystemSettingsAdminFlows.EXE experimental
- Windows EventLog Autologger Session Registry Modification Via CommandLine experimental
- Windows Firewall Disabled via PowerShell test
- Windows Hotfix Updates Reconnaissance Via Wmic.EXE test
- Windows Internet Hosted WebDav Share Mount Via Net.EXE test
- Windows Kernel Debugger Execution test
- Windows MSIX Package Support Framework AI_STUBS Execution experimental
- Windows native backup deletion experimental
- Windows native Pktmon sniffer abuse experimental
- Windows Processes Suspicious Parent Directory test
- Windows Recall Feature Enabled Via Reg.EXE test
- Windows Recovery Environment Disabled Via Reagentc experimental
- Windows Share Mount Via Net.EXE test
- Windows Shell/Scripting Processes Spawning Suspicious Programs test
- Windows Subsystem for Linux (WSL) installation (command) experimental
- Windows Suspicious Child Process from Node.js - React2Shell experimental
- Windows traffic capture abuse experimental
- Winlogon process contact to C2 - Blacklotus (Sysmon) experimental
- Winnti Malware HK University Campaign test
- Winnti Pipemon Characteristics stable
- Winrar Compressing Dump Files test
- WinRAR Execution in Non-Standard Folder test
- WinRM listening service reconnaissance (process) experimental
- Winrs Local Command Execution experimental
- WinRS usage for remote execution
- Winscp Execution From Non Standard Folder experimental
- Wlrmdr.EXE Uncommon Argument Or Child Process experimental
- WMI Backdoor Exchange Transport Agent test
- WMI Persistence - Script Event Consumer test
- WMI spwaning PowerShell process - WMImplant experimental
- WMIC Remote Command Execution test
- WmiPrvSE Spawned A Process stable
- Write Protect For Storage Disabled test
- Writing Of Malicious Files To The Fonts Folder test
- Wscript Shell Run In CommandLine test
- WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript test
- WSL Child Process Anomaly test
- WSL Kali-Linux Usage experimental
- Wusa.EXE Executed By Parent Process Located In Suspicious Location test
- XBAP Execution From Uncommon Locations Via PresentationHost.EXE test
- XSL Script Execution Via WMIC.EXE test
- Xwizard.EXE Execution From Non-Default Location test
- ZxShell Malware test
Event ID 3: Network connection 61 rules
- Communication To LocaltoNet Tunneling Service Initiated test
- Communication To Ngrok Tunneling Service Initiated test
- Communication To Uncommon Destination Ports test
- Dfsvc.EXE Initiated Network Connection Over Uncommon Port test
- Dfsvc.EXE Network Connection To Non-Local IPs test
- Dllhost.EXE Initiated Network Connection To Non-Local IP Address test
- HH.EXE Initiated HTTP Network Connection test
- Local Network Connection Initiated By Script Interpreter test
- Microsoft Sync Center Suspicious Network Connections test
- Msiexec.EXE Initiated Network Connection Over HTTP test
- Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder test
- Network Communication Initiated To Portmap.IO Domain test
- Network Communication With Crypto Mining Pool stable
- Network Connection Initiated By AddinUtil.EXE test
- Network Connection Initiated By Eqnedt32.EXE test
- Network Connection Initiated By IMEWDBLD.EXE test
- Network Connection Initiated By PowerShell Process test
- Network Connection Initiated By Regsvr32.EXE test
- Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location test
- Network Connection Initiated From Users\Public Folder test
- Network Connection Initiated To AzureWebsites.NET By Non-Browser Process test
- Network Connection Initiated To BTunnels Domains test
- Network Connection Initiated To Cloudflared Tunnels Domains test
- Network Connection Initiated To DevTunnels Domain test
- Network Connection Initiated To Mega.nz test
- Network Connection Initiated To Visual Studio Code Tunnels Domain test
- Network Connection Initiated via Finger.EXE experimental
- Network Connection Initiated Via Notepad.EXE test
- New Connection Initiated To Potential Dead Drop Resolver Domain test
- Office Application Initiated Network Connection Over Uncommon Ports test
- Office Application Initiated Network Connection To Non-Local IP test
- Outbound Network Connection Initiated By Cmstp.EXE test
- Outbound Network Connection Initiated By Microsoft Dialer test
- Outbound Network Connection Initiated By Script Interpreter test
- Outbound Network Connection To Public IP Via Winlogon test
- Outbound RDP Connections Over Non-Standard Tools test
- Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon test
- Potential Pikabot C2 Activity test
- Potential Remote PowerShell Session Initiated test
- Potentially Suspicious Azure Front Door Connection test
- Potentially Suspicious Malware Callback Communication test
- Potentially Suspicious Network Connection To Notion API test
- Potentially Suspicious Wuauclt Network Connection test
- Process Initiated Network Connection To Ngrok Domain test
- Python Initiated Connection test
- RDP Over Reverse SSH Tunnel test
- RDP to HTTP or HTTPS Target Ports test
- RegAsm.EXE Initiating Network Connection To Public IP test
- Remote Access Tool - AnyDesk Incoming Connection experimental
- Rundll32 Internet Connection test
- Silenttrinity Stager Msbuild Activity test
- Suspicious Dropbox API Usage test
- Suspicious Network Connection Binary No CommandLine test
- Suspicious Network Connection to IP Lookup Service APIs test
- Suspicious Non-Browser Network Communication With Google API experimental
- Suspicious Non-Browser Network Communication With Telegram API test
- Suspicious Outbound SMTP Connections test
- Suspicious Wordpad Outbound Connections test
- Uncommon Connection to Active Directory Web Services test
- Uncommon Network Connection Initiated By Certutil.EXE test
- Uncommon Outbound Kerberos Connection test
Event ID 6: Driver loaded 10 rules
- Driver Load From A Temporary Directory test
- Malicious Driver Load test
- Malicious Driver Load By Name test
- PUA - Process Hacker Driver Load test
- PUA - System Informer Driver Load test
- Vulnerable Driver Load test
- Vulnerable Driver Load By Name test
- Vulnerable HackSys Extreme Vulnerable Driver Load test
- Vulnerable WinRing0 Driver Load test
- WinDivert Driver Load test
Event ID 7: Image loaded 126 rules
- Abusable DLL Potential Sideloading From Suspicious Location test
- Amsi.DLL Load By Uncommon Process test
- Amsi.DLL Loaded Via LOLBIN Process test
- APT PRIVATELOG Image Load Pattern test
- Aruba Network Service Potential DLL Sideloading test
- BaaUpdate.exe Suspicious DLL Load experimental
- BITS Client BitsProxy DLL Loaded By Uncommon Process experimental
- Clfs.SYS Loaded By Process Located In a Potential Suspicious Location experimental
- CLR DLL Loaded Via Office Applications test
- CredUI.DLL Loaded By Uncommon Process test
- Dbghelp/Dbgcore DLL Loaded By Uncommon/Suspicious Process test
- Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE test
- Diamond Sleet APT DLL Sideloading Indicators test
- DLL Load By System Process From Suspicious Locations test
- DLL Loaded From Suspicious Location Via Cmspt.EXE test
- DLL Names Used By SVR For GraphicalProton Backdoor test
- DLL Sideloading Of ShellChromeAPI.DLL test
- DotNET Assembly DLL Loaded Via Office Application test
- DotNet CLR DLL Loaded By Scripting Applications test
- Fax Service DLL Search Order Hijack test
- FoggyWeb Backdoor DLL Loading test
- GAC DLL Loaded Via Office Applications test
- HackTool - SharpEvtMute DLL Load test
- HackTool - SILENTTRINITY Stager DLL Load test
- Kapeka Backdoor Loaded Via Rundll32.EXE test
- Katz Stealer DLL Loaded experimental
- Lazarus APT DLL Sideloading Activity test
- Load Of RstrtMgr.DLL By A Suspicious Process test
- Load Of RstrtMgr.DLL By An Uncommon Process test
- Malicious DLL Load By Compromised 3CXDesktopApp test
- Microsoft Excel Add-In Loaded test
- Microsoft Excel Add-In Loaded From Uncommon Location test
- Microsoft Office DLL Sideload test
- Microsoft VBA For Outlook Addin Loaded Via Outlook test
- Microsoft Word Add-In Loaded test
- MMC Loading Script Engines DLLs experimental
- PCRE.NET Package Image Load test
- Pingback Backdoor DLL Loading Activity test
- Potential 7za.DLL Sideloading test
- Potential Antivirus Software DLL Sideloading test
- Potential appverifUI.DLL Sideloading test
- Potential AVKkid.DLL Sideloading test
- Potential Azure Browser SSO Abuse test
- Potential CCleanerDU.DLL Sideloading test
- Potential CCleanerReactivator.DLL Sideloading test
- Potential Chrome Frame Helper DLL Sideloading test
- Potential COLDSTEEL Persistence Service DLL Load test
- Potential CSharp Streamer RAT Loading .NET Executable Image test
- Potential CVE-2024-35250 Exploitation Activity experimental
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load test
- Potential DLL Sideloading Of DBGCORE.DLL test
- Potential DLL Sideloading Of DBGHELP.DLL test
- Potential DLL Sideloading Of DbgModel.DLL test
- Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE test
- Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE test
- Potential DLL Sideloading Of MpSvc.DLL test
- Potential DLL Sideloading Of MsCorSvc.DLL test
- Potential DLL Sideloading Of Non-Existent DLLs From System Folders test
- Potential DLL Sideloading Using Coregen.exe test
- Potential DLL Sideloading Via ClassicExplorer32.dll test
- Potential DLL Sideloading Via comctl32.dll test
- Potential DLL Sideloading Via JsSchHlp test
- Potential DLL Sideloading Via VMware Xfer test
- Potential EACore.DLL Sideloading test
- Potential Edputil.DLL Sideloading test
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load experimental
- Potential Goopdate.DLL Sideloading test
- Potential Iviewers.DLL Sideloading test
- Potential JLI.dll Side-Loading experimental
- Potential Libvlc.DLL Sideloading test
- Potential Mfdetours.DLL Sideloading test
- Potential Mpclient.DLL Sideloading test
- Potential Python DLL SideLoading test
- Potential Raspberry Robin Aclui Dll SideLoading test
- Potential Rcdll.DLL Sideloading test
- Potential RjvPlatform.DLL Sideloading From Default Location test
- Potential RjvPlatform.DLL Sideloading From Non-Default Location test
- Potential RoboForm.DLL Sideloading test
- Potential ShellDispatch.DLL Sideloading test
- Potential SmadHook.DLL Sideloading test
- Potential SolidPDFCreator.DLL Sideloading test
- Potential System DLL Sideloading From Non System Locations test
- Potential Vcruntime140 DLL Sideloading experimental
- Potential Vivaldi_elf.DLL Sideloading test
- Potential Waveedit.DLL Sideloading test
- Potential Wazuh Security Platform DLL Sideloading test
- Potential WWlib.DLL Sideloading test
- Potentially Suspicious Image Load of Offreg.dll experimental
- Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load test
- PowerShell Core DLL Loaded By Non PowerShell Process test
- PowerShell Core DLL Loaded Via Office Application test
- Python Image Load By Non-Python Process test
- Remote DLL Load Via Rundll32.EXE test
- Signed DLL Loaded With Missing PE Version Metadata experimental
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location experimental
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32 test
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded test
- Suspicious Unsigned Thor Scanner Execution stable
- Suspicious Volume Shadow Copy VSS_PS.dll Load test
- Suspicious Volume Shadow Copy Vssapi.dll Load test
- Suspicious WSMAN Provider Image Loads test
- System Control Panel Item Loaded From Uncommon Location test
- System Drawing DLL Load test
- Task Scheduler DLL Loaded By Application Located In Potentially Suspicious Location test
- Third Party Software DLL Sideloading test
- Time Travel Debugging Utility Usage - Image test
- Trusted Path Bypass via Windows Directory Spoofing experimental
- UAC Bypass Using Iscsicpl - ImageLoad test
- UAC Bypass With Fake DLL test
- Unsigned .node File Loaded experimental
- Unsigned DLL Loaded by Windows Utility test
- Unsigned Image Loaded Into LSASS Process test
- Unsigned Mfdetours.DLL Sideloading test
- Unsigned Module Loaded by ClickOnce Application test
- VBA DLL Loaded Via Office Application test
- VMGuestLib DLL Sideload test
- VMMap Signed Dbghelp.DLL Potential Sideloading test
- VMMap Unsigned Dbghelp.DLL Potential Sideloading test
- WerFaultSecure Loading DbgCore or DbgHelp - EDR-Freeze experimental
- Windows Spooler Service Suspicious Binary Load test
- WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load test
- WMI module loaded by suspicious process experimental
- WMI Module Loaded By Uncommon Process test
- WMI Persistence - Command Line Event Consumer test
- WMIC Loading Scripting Libraries test
- Wmiprvse Wbemcomn DLL Hijack test
Event ID 8: CreateRemoteThread 15 rules
- CreateRemoteThread API and LoadLibrary test
- HackTool - CACTUSTORCH Remote Thread Creation test
- HackTool - Potential CobaltStrike Process Injection test
- Password Dumper Remote Thread in LSASS stable
- Potential Bumblebee Remote Thread Creation test
- Potential Credential Dumping Attempt Via PowerShell Remote Thread test
- Rare Remote Thread Creation By Uncommon Source Image test
- Remote Thread Created In KeePass.EXE test
- Remote Thread Created In Shell Application test
- Remote Thread Creation By Uncommon Source Image test
- Remote Thread Creation In Mstsc.Exe From Suspicious Location test
- Remote Thread Creation In Uncommon Target Image test
- Remote Thread Creation Ttdinject.exe Proxy test
- Remote Thread Creation Via PowerShell test
- Remote Thread Creation Via PowerShell In Uncommon Target test
Event ID 9: RawAccessRead 1 rule
Event ID 10: ProcessAccess 30 rules
- CMSTP Execution Process Access stable
- Credential Dumping Activity By Python Based Tool stable
- Credential Dumping Attempt Via Svchost test
- Credential Dumping Attempt Via WerFault test
- Function Call From Undocumented COM Interface EditionUpgradeManager test
- HackTool - CobaltStrike BOF Injection Pattern test
- HackTool - Generic Process Access test
- HackTool - HandleKatz Duplicating LSASS Handle test
- HackTool - LittleCorporal Generated Maldoc Injection test
- HackTool - SysmonEnte Execution test
- LSASS Access From Potentially White-Listed Processes test
- LSASS Access From Program In Potentially Suspicious Folder test
- LSASS dump via process access experimental
- LSASS Memory Access by Tool With Dump Keyword In Name test
- Lsass Memory Dump via Comsvcs DLL test
- Malware Shellcode in Verclsid Target Process test
- Potential Credential Dumping Activity Via LSASS test
- Potential Credential Dumping Attempt Via PowerShell test
- Potential Direct Syscall of NtOpenProcess test
- Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access experimental
- Potential Shellcode Injection test
- Potentially Suspicious GrantedAccess Flags On LSASS test
- Remote LSASS Process Access Through Windows Remote Management stable
- Suspicious LSASS Access Via MalSecLogon test
- Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze experimental
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs experimental
- Suspicious Svchost Process Access test
- UAC Bypass Using WOW64 Logger DLL Hijack test
- Uncommon GrantedAccess Flags On LSASS test
- Uncommon Process Access Rights For Target Image test
Event ID 11: FileCreate 226 rules
- .RDP File Created By Uncommon Application test
- ADExplorer Writing Complete AD Snapshot Into .dat File experimental
- ADSI-Cache File Creation By Uncommon Tool test
- Advanced IP Scanner - File Event test
- Adwind RAT / JRAT File Artifact test
- Anydesk Temporary Artefact test
- APT29 2018 Phishing Campaign File Indicators stable
- Assembly DLL Creation Via AspNetCompiler test
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File test
- Axios NPM Compromise File Creation Indicators - Windows experimental
- BloodHound Collection Files test
- Created Files by Microsoft Sync Center test
- Creation Exe for Service with Unquoted Path test
- Creation of a Diagcab test
- Creation of an Executable by an Executable test
- Creation Of Non-Existent System DLL test
- Creation of WerFault.exe/Wer.dll in Unusual Folder test
- Cred Dump Tools Dropped Files test
- CSExec Service File Creation test
- CVE-2021-1675 Print Spooler Exploitation Filename Pattern test
- CVE-2021-26858 Exchange Exploitation test
- CVE-2021-31979 CVE-2021-33771 Exploits by Sourgum test
- CVE-2021-44077 POC Default Dropped File test
- CVE-2022-24527 Microsoft Connected Cache LPE test
- CVE-2023-38331 Exploitation Attempt - Suspicious Double Extension File test
- CVE-2023-40477 Potential Exploitation - .REV File Creation test
- CVE-2024-1708 - ScreenConnect Path Traversal Exploitation test
- DarkGate - Autoit3.EXE File Creation By Uncommon Process test
- DarkGate - Drop DarkGate Loader In C:\Temp Directory test
- Desktop.INI Created by Uncommon Process test
- Diamond Sleet APT File Creation Indicators test
- DLL Search Order Hijackig Via Additional Space in Path test
- DMP/HDMP File Creation test
- DNS hosts file modified experimental
- DPAPI Backup Keys And Certificate Export Activity IOC test
- Drop Binaries Into Spool Drivers Color Folder test
- Dynamic CSharp Compile Artefact test
- EVTX Created In Uncommon Location test
- Exchange transport agent injection via configuration file experimental
- File Creation In Suspicious Directory By Msdt.EXE test
- File Creation Related To RAT Clients experimental
- File With Uncommon Extension Created By An Office Application test
- Files With System DLL Name In Unsuspected Locations test
- Files With System Process Name In Unsuspected Locations test
- Forest Blizzard APT - File Creation Activity test
- Forest Blizzard APT - JavaScript Constrained File Creation test
- FunkLocker Ransomware File Creation experimental
- GatherNetworkInfo.VBS Reconnaissance Script Output test
- Goofy Guineapig Backdoor IOC test
- GoToAssist Temporary Installation Artefact test
- HackTool - CrackMapExec File Indicators test
- HackTool - Dumpert Process Dumper Default File test
- HackTool - Impacket File Indicators experimental
- HackTool - Inveigh Execution Artefacts test
- HackTool - Mimikatz Kirbi File Creation test
- HackTool - NetExec File Indicators experimental
- HackTool - NPPSpy Hacktool Usage test
- HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump test
- HackTool - Powerup Write Hijack DLL test
- HackTool - QuarksPwDump Dump File test
- HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators test
- HackTool - SafetyKatz Dump Indicator test
- HackTool - Typical HiveNightmare SAM File Export test
- Hijack Legit RDP Session to Move Laterally test
- Installation of TeamViewer Desktop test
- InstallerFileTakeOver LPE CVE-2021-41379 File Create Event test
- ISO File Created Within Temp Folders test
- ISO or Image Mount Indicator in Recent Files test
- Lace Tempest File Indicators test
- Legitimate Application Dropped Archive test
- Legitimate Application Dropped Executable test
- Legitimate Application Dropped Script test
- Legitimate Application Writing Files In Uncommon Location experimental
- LiveKD Driver Creation test
- LiveKD Driver Creation By Uncommon Process test
- LiveKD Kernel Memory Dump File Created test
- LSASS credentials dump via Task Manager (file) experimental
- LSASS Process Dump Artefact In CrashDumps Folder test
- LSASS Process Memory Dump Creation Via Taskmgr.EXE test
- LSASS Process Memory Dump Files test
- Malicious DLL File Dropped in the Teams or OneDrive Folder test
- Malicious PowerShell Scripts - FileCreation test
- Mimikatz malicious Security package (SSP) exfiltrates cleartext passwords in file experimental
- Moriya Rootkit File Created test
- New Custom Shim Database Created test
- New Outlook Macro Created test
- NTDS Exfiltration Filename Patterns test
- NTDS.DIT Created test
- NTDS.DIT Creation By Uncommon Parent Process test
- NTDS.DIT Creation By Uncommon Process test
- Octopus Scanner Malware test
- Office Macro File Creation test
- Office Macro File Creation From Suspicious Process test
- Office Macro File Download test
- OneNote Attachment File Dropped In Suspicious Location test
- Onyx Sleet APT File Creation Indicators test
- PCRE.NET Package Temp Files test
- PDF File Created By RegEdit.EXE test
- PFX File Creation test
- Pingback Backdoor File Indicators test
- Potential APT FIN7 Related PowerShell Script Created test
- Potential Binary Or Script Dropper Via PowerShell test
- Potential COLDSTEEL Persistence Service DLL Creation test
- Potential COLDSTEEL RAT File Indicators test
- Potential CVE-2023-27363 Exploitation - HTA File Creation By FoxitPDFReader test
- Potential CVE-2023-36874 Exploitation - Fake Wermgr.Exe Creation test
- Potential CVE-2023-36874 Exploitation - Uncommon Report.Wer Location test
- Potential CVE-2023-36884 Exploitation Dropped File test
- Potential DCOM InternetExplorer.Application DLL Hijack test
- Potential Devil Bait Related Indicator test
- Potential File Extension Spoofing Using Right-to-Left Override test
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream test
- Potential Homoglyph Attack Using Lookalike Characters in Filename test
- Potential Initial Access via DLL Search Order Hijacking test
- Potential Kapeka Decrypted Backdoor Indicator test
- Potential MOVEit Transfer CVE-2023-34362 Exploitation - File Activity test
- Potential Persistence Attempt Via ErrorHandler.Cmd test
- Potential Persistence Via Microsoft Office Add-In test
- Potential Persistence Via Microsoft Office Startup Folder test
- Potential Persistence Via Notepad++ Plugins test
- Potential Persistence Via Outlook Form test
- Potential Privilege Escalation Attempt Via .Exe.Local Technique test
- Potential RipZip Attack on Startup Folder test
- Potential SAM Database Dump test
- Potential SAP NetWeaver Webshell Creation experimental
- Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create experimental
- Potential Startup Shortcut Persistence Via PowerShell.EXE test
- Potential Suspicious PowerShell Module File Created test
- Potential Webshell Creation On Static Website test
- Potential Winnti Dropper Activity test
- Potentially Suspicious DMP/HDMP File Creation test
- Potentially Suspicious File Creation by OpenEDR's ITSMService experimental
- Potentially Suspicious WDAC Policy File Creation experimental
- PowerShell Module File Created test
- PowerShell Module File Created By Non-PowerShell Process test
- PowerShell Profile Modification test
- PowerShell Script Dropped Via PowerShell.EXE test
- Process Explorer Driver Creation By Non-Sysinternals Binary test
- Process Monitor Driver Creation By Non-Sysinternals Binary test
- PSEXEC Remote Execution File Artefact test
- PsExec Service File Creation test
- PSScriptPolicyTest Creation By Uncommon Process test
- Publisher Attachment File Dropped In Suspicious Location test
- Python Path Configuration File Creation - Windows test
- Rclone Config File Creation test
- RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir experimental
- Registry Hive File Staged Outside Standard User Profile Path experimental
- RemCom Service File Creation test
- Remote Access Tool - ScreenConnect Temporary File test
- Renamed VsCode Code Tunnel Execution - File Indicator test
- Scheduled Task Created - FileCreation test
- SCR File Write Event test
- ScreenConnect - SlashAndGrab Exploitation Indicators test
- ScreenConnect Temporary Installation Artefact test
- ScreenConnect User Database Modification test
- Self Extraction Directive File Created In Potentially Suspicious Location test
- Small Sieve Malware File Indicator Creation test
- SNAKE Malware Installer Name Indicators test
- SNAKE Malware Kernel Driver File Indicator test
- SNAKE Malware WerFault Persistence File Creation test
- Startup Folder File Write test
- Sticky key file created from CMD copy experimental
- Suspicious ASPX File Drop by Exchange test
- Suspicious Binaries and Scripts in Public Folder experimental
- Suspicious Binary Writes Via AnyDesk test
- Suspicious Creation of .library-ms File — Potential CVE-2025-24054 Exploit experimental
- Suspicious Creation TXT File in User Desktop test
- Suspicious Creation with Colorcpl test
- Suspicious Deno File Written from Remote Source experimental
- Suspicious Desktopimgdownldr Target File test
- Suspicious DotNET CLR Usage Log Artifact test
- Suspicious Double Extension Files test
- Suspicious Executable File Creation test
- Suspicious File Created by ArcSOC.exe experimental
- Suspicious File Created in Outlook Temporary Directory experimental
- Suspicious File Created In PerfLogs test
- Suspicious File Created Via OneNote Application test
- Suspicious File Creation Activity From Fake Recycle.Bin Folder test
- Suspicious File Creation In Uncommon AppData Folder test
- Suspicious File Drop by Exchange test
- Suspicious File Write to SharePoint Layouts Directory experimental
- Suspicious File Write to Webapps Root Directory experimental
- Suspicious Files in Default GPO Folder test
- Suspicious Get-Variable.exe Creation test
- Suspicious Interactive PowerShell as SYSTEM test
- Suspicious LNK Double Extension File Created test
- Suspicious MSExchangeMailboxReplication ASPX Write test
- Suspicious Outlook Macro Created test
- Suspicious PROCEXP152.sys File Created In TMP test
- Suspicious Scheduled Task Write to System32 Tasks test
- Suspicious Screensaver Binary File Creation test
- Suspicious Startup Folder Persistence test
- Suspicious Word Cab File Write CVE-2021-40444 test
- TanStack Supply-Chain Attack File Creation Indicators - Windows experimental
- TeamViewer Remote Session test
- UAC Bypass Abusing Winsat Path Parsing - File test
- UAC Bypass Using .NET Code Profiler on MMC test
- UAC Bypass Using Consent and Comctl32 - File test
- UAC Bypass Using EventVwr test
- UAC Bypass Using IDiagnostic Profile - File test
- UAC Bypass Using IEInstal - File test
- UAC Bypass Using MSConfig Token Modification - File test
- UAC Bypass Using NTFS Reparse Point - File test
- UAC Bypass Using Windows Media Player - File test
- UEFI Persistence Via Wpbbin - FileCreation test
- Uncommon File Created by Notepad++ Updater Gup.EXE experimental
- Uncommon File Created In Office Startup Folder test
- Uncommon File Creation By Mysql Daemon Process test
- VHD Image Download Via Browser test
- Visual Studio Code Tunnel Remote File Creation test
- VsCode Code Tunnel Execution File Indicator test
- VsCode Powershell Profile Modification test
- WDAC Policy File Creation In CodeIntegrity Folder experimental
- WebDAV Temporary Local File Creation test
- Webserver IIS configuration edited (SYSMON) experimental
- WerFault LSASS Process Memory Dump test
- Windows Binaries Write Suspicious Extensions test
- Windows Shell/Scripting Application File Write to Suspicious Folder test
- Windows Terminal Profile Settings Modification By Uncommon Process test
- WinRAR Creating Files in Startup Locations experimental
- WinSxS Executable File Creation By Non-System Process test
- WMI Persistence - Script Event Consumer File Write test
- Wmiexec Default Output File test
- Wmiprvse Wbemcomn DLL Hijack - File test
- Writing Local Admin Share test
- WScript or CScript Dropper - File test
Event ID 12: RegistryEvent (Object create and delete) 50 rules
- Atbroker Registry Change test
- CMSTP Execution Registry Event stable
- Creation of a Local Hidden User Account by Registry test
- Diamond Sleet APT Scheduled Task Creation - Registry test
- Disable Security Events Logging Adding Reg Key MiniNt test
- DLL Load via LSASS test
- Esentutl Volume Shadow Copy Service Keys test
- FlowCloud Registry Markers test
- HybridConnectionManager Service Installation - Registry test
- Impacket SMBexec service creation (registry) experimental
- Leviathan Registry Key Activity test
- Mimikatz driver registration (Reg via Sysmon) experimental
- Narrator's Feedback-Hub Persistence test
- NetNTLM Downgrade Attack - Registry test
- Netsh helper DLL abuse (Reg via Sysmon) experimental
- New DLL Added to AppCertDlls Registry Key test
- New DLL Added to AppInit_DLLs Registry Key test
- New PortProxy Registry Entry Added test
- OceanLotus Registry Activity test
- Office Application Startup - Office Test test
- OilRig APT Registry Persistence test
- Pandemic Registry Key test
- Path To Screensaver Binary Modified test
- Potential Credential Dumping Via LSASS SilentProcessExit Technique test
- Potential NetWire RAT Activity - Registry test
- Potential Persistence Via Disk Cleanup Handler - Registry test
- Potential Qakbot Registry Activity test
- Potential Ursnif Malware Activity - Registry test
- PrinterNightmare Mimikatz Driver Name test
- RDP shadow session configuration enabled (registry) experimental
- RedMimicry Winnti Playbook Registry Manipulation test
- Registry Entries For Azorult Malware test
- Registry Persistence Mechanisms in Recycle Bin test
- Registry Tampering by Potentially Suspicious Processes experimental
- Run Once Task Configuration in Registry test
- Scheduled Task Created - Registry test
- Security Support Provider (SSP) Added to LSA Configuration test
- Shell Open Registry Keys Manipulation test
- SNAKE Malware Covert Store Registry Key test
- Stickey key IFEO registry changed (Reg via Sysmon) experimental
- Sticky Key Like Backdoor Usage - Registry test
- Suspicious Camera and Microphone Access test
- Suspicious Run Key from Download test
- System crash behavior manipulation - WMImplant (registry) experimental
- UAC Bypass Via Wsreset test
- Wdigest CredGuard Registry Modification test
- Windows Credential Editor Registry test
- Windows Defender Threat Severity Default Action Modified experimental
- Windows Registry Trust Record Modification test
- WINEKEY Registry Modification test
Event ID 13: RegistryEvent (Value Set) 276 rules
- Activate Suppression of Windows Security Center Notifications test
- Add Debugger Entry To AeDebug For Persistence test
- Add Debugger Entry To Hangs Key For Persistence test
- Add DisallowRun Execution to Registry test
- Add Port Monitor Persistence in Registry test
- Allow RDP Remote Assistance Feature test
- AMSI Disabled via Registry Modification experimental
- Antivirus Filter Driver Disallowed On Dev Drive - Registry test
- Atbroker Registry Change test
- Blackbyte Ransomware Registry test
- Blue Mockingbird - Registry test
- Bypass UAC Using DelegateExecute test
- Bypass UAC Using Event Viewer test
- Bypass UAC Using SilentCleanup Task test
- Change the Fax Dll test
- Change User Account Associated with the FAX Service test
- Change Winevt Channel Access Permission Via Registry test
- Classes Autorun Keys Modification test
- ClickOnce Trust Prompt Tampering test
- CMSTP Execution Registry Event stable
- COM Hijack via Sdclt test
- COM Hijacking via TreatAs test
- COM Object Hijacking Via Modification Of Default System CLSID Default Value experimental
- Command Executed Via Run Dialog Box - Registry test
- Common Autorun Keys Modification test
- CrashControl CrashDump Disabled test
- Creation of a Local Hidden User Account by Registry test
- CurrentControlSet Autorun Keys Modification test
- CurrentVersion Autorun Keys Modification test
- CurrentVersion NT Autorun Keys Modification test
- Custom File Open Handler Executes PowerShell test
- CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry test
- CVE-2021-31979 CVE-2021-33771 Exploits test
- Default RDP Port Changed to Non Standard Port test
- DHCP Callout DLL Installation test
- Diamond Sleet APT Scheduled Task Creation - Registry test
- Directory Service Restore Mode(DSRM) Registry Value Tampering test
- Disable Administrative Share Creation at Startup test
- Disable Exploit Guard Network Protection on Windows Defender test
- Disable Internal Tools or Feature in Registry test
- Disable Macro Runtime Scan Scope test
- Disable Microsoft Defender Firewall via Registry test
- Disable Privacy Settings Experience in Registry test
- Disable PUA Protection on Windows Defender test
- Disable Security Events Logging Adding Reg Key MiniNt test
- Disable Tamper Protection on Windows Defender test
- Disable Windows Defender Functionalities Via Registry Keys test
- Disable Windows Event Logging Via Registry test
- Disable Windows Firewall by Registry test
- Disable Windows Security Center Notifications test
- Disabled Windows Defender Eventlog test
- Displaying Hidden Files Feature Disabled test
- DLL Load via LSASS test
- DLL ServerLevelPluginDll registration (Reg via Sysmon) experimental
- DNS-over-HTTPS Enabled by Registry test
- Driver Added To Disallowed Images In HVCI - Registry test
- Enable LM Hash Storage test
- Enable Local Manifest Installation With Winget test
- Enable Microsoft Dynamic Data Exchange test
- Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback test
- Enabling COR Profiler Environment Variables test
- Esentutl Volume Shadow Copy Service Keys test
- ETW Logging Disabled For rpcrt4.dll test
- ETW Logging Disabled For SCM test
- ETW Logging Disabled In .NET Processes - Sysmon Registry test
- Execution DLL of Choice Using WAB.EXE test
- FileFix - Command Evidence in TypedPaths experimental
- FlowCloud Registry Markers test
- Forest Blizzard APT - Custom Protocol Handler Creation test
- Forest Blizzard APT - Custom Protocol Handler DLL Registry Set test
- Hide Schedule Task Via Index Value Tamper test
- Hiding User Account Via SpecialAccounts Registry Key test
- HybridConnectionManager Service Installation - Registry test
- Hypervisor Enforced Paging Translation Disabled test
- IE Change Domain Zone test
- IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols test
- Impacket SMBexec service creation (registry) experimental
- Internet Explorer Autorun Keys Modification test
- Internet Explorer DisableFirstRunCustomize Enabled test
- Kapeka Backdoor Autorun Persistence test
- Kapeka Backdoor Configuration Persistence test
- Leviathan Registry Key Activity test
- Lolbas OneDriveStandaloneUpdater.exe Proxy Download test
- Lsass Full Dump Request Via DumpType Registry Settings test
- Macro Enabled In A Potentially Suspicious Document test
- MaxMpxCt Registry Value Changed test
- Microsoft Defender service components status disabled (Registry via Sysmon) experimental
- Microsoft Office Protected View Disabled test
- Microsoft Office Trusted Location Updated test
- Mimikatz driver registration (Reg via Sysmon) experimental
- Modification of IE Registry Settings test
- Modify User Shell Folders Startup Value test
- Narrator's Feedback-Hub Persistence test
- NET NGenAssemblyUsageLog Registry Key Tamper test
- NetNTLM Downgrade Attack - Registry test
- Netsh helper DLL abuse (Reg via Sysmon) experimental
- New Application in AppCompat test
- New BgInfo.EXE Custom DB Path Registry Configuration test
- New BgInfo.EXE Custom VBScript Registry Configuration test
- New BgInfo.EXE Custom WMI Query Registry Configuration test
- New DLL Added to AppCertDlls Registry Key test
- New DLL Added to AppInit_DLLs Registry Key test
- New DNS ServerLevelPluginDll Installed test
- New File Association Using Exefile test
- New Netsh Helper DLL Registered From A Suspicious Location test
- New ODBC Driver Registered test
- New PortProxy Registry Entry Added test
- New Root or CA or AuthRoot Certificate to Store test
- New RUN Key Pointing to Suspicious Folder experimental
- New TimeProviders Registered With Uncommon DLL Name test
- NTLM downgrade attack (Reg via SYSMON) experimental
- OceanLotus Registry Activity test
- Office Application Startup - Office Test test
- Office Autorun Keys Modification test
- Office Macros Warning Disabled test
- OilRig APT Registry Persistence test
- Old TLS1.0/TLS1.1 Protocol Version Enabled test
- Outlook EnableUnsafeClientMailRules Setting Enabled - Registry test
- Outlook Macro Execution Without Warning Setting Enabled test
- Outlook Security Settings Updated - Registry test
- Outlook Task/Note Reminder Received test
- Pandemic Registry Key test
- Path To Screensaver Binary Modified test
- Periodic Backup For System Registry Hives Enabled test
- Persistence Via Disk Cleanup Handler - Autorun test
- Persistence Via Hhctrl.ocx test
- Persistence Via New SIP Provider test
- Potential AMSI COM Server Hijacking test
- Potential Attachment Manager Settings Associations Tamper test
- Potential Attachment Manager Settings Attachments Tamper test
- Potential AutoLogger Sessions Tampering test
- Potential ClickFix Execution Pattern - Registry experimental
- Potential CobaltStrike Service Installations - Registry test
- Potential COLDSTEEL RAT Windows User Creation test
- Potential COM Object Hijacking Via TreatAs Subkey - Registry test
- Potential Credential Dumping Attempt Using New NetworkProvider - REG test
- Potential Credential Dumping Via LSASS SilentProcessExit Technique test
- Potential Encrypted Registry Blob Related To SNAKE Malware test
- Potential EventLog File Location Tampering test
- Potential KamiKakaBot Activity - Winlogon Shell Persistence test
- Potential PendingFileRenameOperations Tampering test
- Potential Persistence Using DebugPath test
- Potential Persistence Via App Paths Default Property test
- Potential Persistence Via AppCompat RegisterAppRestart Layer test
- Potential Persistence Via AutodialDLL test
- Potential Persistence Via CHM Helper DLL test
- Potential Persistence Via Custom Protocol Handler test
- Potential Persistence Via DLLPathOverride test
- Potential Persistence Via Event Viewer Events.asp test
- Potential Persistence Via Excel Add-in - Registry test
- Potential Persistence Via GlobalFlags test
- Potential Persistence Via Logon Scripts - Registry test
- Potential Persistence Via LSA Extensions test
- Potential Persistence Via Mpnotify test
- Potential Persistence Via MyComputer Registry Keys test
- Potential Persistence Via Netsh Helper DLL - Registry test
- Potential Persistence Via New AMSI Providers - Registry test
- Potential Persistence Via Outlook Home Page test
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting test
- Potential Persistence Via Outlook Today Page test
- Potential Persistence Via Scrobj.dll COM Hijacking test
- Potential Persistence Via Shim Database In Uncommon Location test
- Potential Persistence Via Shim Database Modification test
- Potential Persistence Via TypedPaths test
- Potential Persistence Via Visual Studio Tools for Office test
- Potential PowerShell Execution Policy Tampering test
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG test
- Potential PSFactoryBuffer COM Hijacking test
- Potential Qakbot Registry Activity test
- Potential Ransomware Activity Using LegalNotice Message test
- Potential Raspberry Robin Registry Set Internet Settings ZoneMap test
- Potential Registry Persistence Attempt Via DbgManagedDebugger test
- Potential Registry Persistence Attempt Via Windows Telemetry test
- Potential SentinelOne Shell Context Menu Scan Command Tampering test
- Potential Signing Bypass Via Windows Developer Features - Registry test
- Potential WerFault ReflectDebugger Registry Value Abuse test
- Potentially Suspicious Command Executed Via Run Dialog Box - Registry test
- Potentially Suspicious Desktop Background Change Via Registry test
- Potentially Suspicious ODBC Driver Registered test
- PowerShell as a Service in Registry test
- PowerShell Logging Disabled Via Registry Key Tampering test
- PowerShell Script Execution Policy Enabled test
- PrinterNightmare Mimikatz Driver Name test
- PUA - Sysinternal Tool Execution - Registry test
- PUA - Sysinternals Tools Execution - Registry test
- Python Function Execution Security Warning Disabled In Excel - Registry test
- RDP Sensitive Settings Changed test
- RDP Sensitive Settings Changed to Zero test
- RDP shadow session configuration enabled (registry) experimental
- RedMimicry Winnti Playbook Registry Manipulation test
- Register New IFiltre For Persistence test
- Registry Disable System Restore test
- Registry Entries For Azorult Malware test
- Registry Explorer Policy Modification test
- Registry Hide Function from User test
- Registry Modification for OCI DLL Redirection experimental
- Registry Modification to Hidden File Extension test
- Registry Persistence Mechanisms in Recycle Bin test
- Registry Persistence via Explorer Run Key test
- Registry Persistence via Service in Safe Mode test
- Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace test
- Registry Tampering by Potentially Suspicious Processes experimental
- RestrictedAdminMode Registry Value Tampering test
- Run Once Task Configuration in Registry test
- Running Chrome VPN Extensions via the Registry 2 VPN Extension test
- Scheduled Task Created - Registry test
- Scheduled TaskCache Change by Uncommon Program test
- ScreenSaver Registry Key Set test
- Scripted Diagnostics Turn Off Check Enabled - Registry test
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set experimental
- Security Support Provider (SSP) Added to LSA Configuration test
- Service Binary in Suspicious Folder test
- Service Binary in User Controlled Folder test
- ServiceDll Hijack test
- Session Manager Autorun Keys Modification test
- Shell Context Menu Command Tampering test
- Shell Open Registry Keys Manipulation test
- Small Sieve Malware Registry Persistence test
- SNAKE Malware Covert Store Registry Key test
- Stickey key IFEO registry changed (Reg via Sysmon) experimental
- Sticky Key Like Backdoor Usage - Registry test
- Suspicious Application Allowed Through Exploit Guard test
- Suspicious Camera and Microphone Access test
- Suspicious Environment Variable Has Been Registered test
- Suspicious Execution Of Renamed Sysinternals Tools - Registry test
- Suspicious Keyboard Layout Load test
- Suspicious Path In Keyboard Layout IME File Registry Value test
- Suspicious PowerShell In Registry Run Keys test
- Suspicious Printer Driver Empty Manufacturer test
- Suspicious Run Key from Download test
- Suspicious Service Installed test
- Suspicious Set Value of MSDT in Registry (CVE-2022-30190) test
- Suspicious Shell Open Command Registry Modification experimental
- Suspicious Shim Database Patching Activity test
- Suspicious SIP or trust provider registration experimental
- Suspicious Space Characters in RunMRU Registry Path - ClickFix experimental
- Suspicious Space Characters in TypedPaths Registry Path - FileFix experimental
- Sysmon Driver Altitude Change test
- System crash behavior manipulation - WMImplant (registry) experimental
- System Scripts Autorun Keys Modification test
- Tamper With Sophos AV Registry Keys test
- Trust Access Disable For VBApplications test
- UAC Bypass Abusing Winsat Path Parsing - Registry test
- UAC Bypass Using Windows Media Player - Registry test
- UAC Bypass via Event Viewer test
- UAC Bypass via Sdclt test
- UAC Bypass Via Wsreset test
- UAC Disabled stable
- UAC Notification Disabled test
- UAC Secure Desktop Prompt Disabled test
- Uncommon Extension In Keyboard Layout IME File Registry Value test
- Uncommon Microsoft Office Trusted Location Added test
- Usage of Renamed Sysinternals Tools - RegistrySet test
- VBScript Payload Stored in Registry test
- Wdigest authentication enabled (registry) experimental
- Wdigest CredGuard Registry Modification test
- Wdigest Enable UseLogonCredential test
- WFP Filter Added via Registry experimental
- Windows Credential Editor Registry test
- Windows Credential Guard Disabled - Registry experimental
- Windows Defender Exclusions Added - Registry test
- Windows Defender Service Disabled - Registry test
- Windows Defender Threat Severity Default Action Modified experimental
- Windows Event Log Access Tampering Via Registry experimental
- Windows Hypervisor Enforced Code Integrity Disabled test
- Windows Recall Feature Enabled - Registry test
- Windows Registry Trust Record Modification test
- Windows Vulnerable Driver Blocklist Disabled experimental
- WINEKEY Registry Modification test
- Winget Admin Settings Modification test
- Winlogon AllowMultipleTSSessions Enable test
- Winlogon Notify Key Logon Persistence test
- WinSock2 Autorun Keys Modification test
- Wow6432Node Classes Autorun Keys Modification test
- Wow6432Node CurrentVersion Autorun Keys Modification test
- Wow6432Node Windows NT CurrentVersion Autorun Keys Modification test
Event ID 14: RegistryEvent (Key and Value Rename) 55 rules
- Atbroker Registry Change test
- CMSTP Execution Registry Event stable
- Creation of a Local Hidden User Account by Registry test
- Delete Defender Scan ShellEx Context Menu Registry Key experimental
- Diamond Sleet APT Scheduled Task Creation - Registry test
- Disable Security Events Logging Adding Reg Key MiniNt test
- DLL Load via LSASS test
- Esentutl Volume Shadow Copy Service Keys test
- FlowCloud Registry Markers test
- Folder Removed From Exploit Guard ProtectedFolders List - Registry test
- HybridConnectionManager Service Installation - Registry test
- Impacket SMBexec service creation (registry) experimental
- Leviathan Registry Key Activity test
- Mimikatz driver registration (Reg via Sysmon) experimental
- Narrator's Feedback-Hub Persistence test
- NetNTLM Downgrade Attack - Registry test
- Netsh helper DLL abuse (Reg via Sysmon) experimental
- New DLL Added to AppCertDlls Registry Key test
- New DLL Added to AppInit_DLLs Registry Key test
- New PortProxy Registry Entry Added test
- OceanLotus Registry Activity test
- Office Application Startup - Office Test test
- OilRig APT Registry Persistence test
- Pandemic Registry Key test
- Path To Screensaver Binary Modified test
- Potential Credential Dumping Via LSASS SilentProcessExit Technique test
- Potential Qakbot Registry Activity test
- PrinterNightmare Mimikatz Driver Name test
- RDP shadow session configuration enabled (registry) experimental
- RedMimicry Winnti Playbook Registry Manipulation test
- Registry Persistence Mechanisms in Recycle Bin test
- Registry Tampering by Potentially Suspicious Processes experimental
- Removal Of AMSI Provider Registry Keys test
- Removal Of Index Value to Hide Schedule Task - Registry test
- Removal of Potential COM Hijacking Registry Keys test
- Removal Of SD Value to Hide Schedule Task - Registry test
- Run Once Task Configuration in Registry test
- RunMRU Registry Key Deletion - Registry experimental
- Scheduled Task Created - Registry test
- Security Support Provider (SSP) Added to LSA Configuration test
- Shell Open Registry Keys Manipulation test
- SNAKE Malware Covert Store Registry Key test
- Sticky Key Like Backdoor Usage - Registry test
- Suspicious Camera and Microphone Access test
- Suspicious Run Key from Download test
- System crash behavior manipulation - WMImplant (registry) experimental
- Terminal Server Client Connection History Cleared - Registry test
- UAC Bypass Via Wsreset test
- Wdigest CredGuard Registry Modification test
- Windows Credential Editor Registry test
- Windows Credential Guard Related Registry Value Deleted - Registry experimental
- Windows Defender Threat Severity Default Action Modified experimental
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted test
- Windows Registry Trust Record Modification test
- WINEKEY Registry Modification test
Event ID 15: FileCreateStreamHash 9 rules
- Creation Of a Suspicious ADS File Outside a Browser Download test
- Exports Registry Key To an Alternate Data Stream test
- HackTool Named File Stream Created test
- Hidden Executable In NTFS Alternate Data Stream test
- Potential Suspicious Winget Package Installation test
- Potentially Suspicious File Download From ZIP TLD test
- Suspicious File Download From File Sharing Websites - File Stream test
- Unusual File Download from Direct IP Address test
- Unusual File Download From File Sharing Websites - File Stream test
Event ID 17: PipeEvent (Pipe Created) 20 rules
- ADFS Database Named Pipe Connection By Uncommon Tool test
- Alternate PowerShell Hosts Pipe test
- CobaltStrike Named Pipe test
- CobaltStrike Named Pipe Pattern Regex test
- CobaltStrike Named Pipe Patterns test
- HackTool - CoercedPotato Named Pipe Creation test
- HackTool - Credential Dumping Tools Named Pipe Created test
- HackTool - DiagTrackEoP Default Named Pipe test
- HackTool - EfsPotato Named Pipe Creation test
- HackTool - Koh Default Named Pipe test
- Malicious Named Pipe Created test
- New PowerShell Instance Created test
- PsExec Default Named Pipe test
- PsExec Tool Execution From Suspicious Locations - PipeName test
- PUA - CSExec Default Named Pipe test
- PUA - PAExec Default Named Pipe test
- PUA - RemCom Default Named Pipe test
- RedSun - Named Pipe Created experimental
- Turla Group Named Pipes test
- WMI Event Consumer Created Named Pipe test
Event ID 18: PipeEvent (Pipe Connected) 20 rules
- ADFS Database Named Pipe Connection By Uncommon Tool test
- Alternate PowerShell Hosts Pipe test
- CobaltStrike Named Pipe test
- CobaltStrike Named Pipe Pattern Regex test
- CobaltStrike Named Pipe Patterns test
- HackTool - CoercedPotato Named Pipe Creation test
- HackTool - Credential Dumping Tools Named Pipe Created test
- HackTool - DiagTrackEoP Default Named Pipe test
- HackTool - EfsPotato Named Pipe Creation test
- HackTool - Koh Default Named Pipe test
- Malicious Named Pipe Created test
- New PowerShell Instance Created test
- PsExec Default Named Pipe test
- PsExec Tool Execution From Suspicious Locations - PipeName test
- PUA - CSExec Default Named Pipe test
- PUA - PAExec Default Named Pipe test
- PUA - RemCom Default Named Pipe test
- RedSun - Named Pipe Created experimental
- Turla Group Named Pipes test
- WMI Event Consumer Created Named Pipe test
Event ID 22: DNSEvent (DNS query) 28 rules
- AppX Package Installation Attempts Via AppInstaller.EXE test
- Cloudflared Tunnels Related DNS Requests test
- Diamond Sleet APT DNS Communication Indicators test
- DNS HybridConnectionManager Service Bus test
- DNS Query by Finger Utility experimental
- DNS Query for Anonfiles.com Domain - Sysmon test
- DNS Query Request By QuickAssist.EXE experimental
- DNS Query Request By Regsvr32.EXE test
- DNS Query Request To OneLaunch Update Service test
- DNS Query To AzureWebsites.NET By Non-Browser Process test
- DNS Query To Common Malware Hosting and Shortener Services experimental
- DNS Query To Devtunnels Domain test
- DNS Query To Katz Stealer Domains experimental
- DNS Query To MEGA Hosting Website test
- DNS Query To Remote Access Software Domain From Non-Browser App test
- DNS Query To Ufile.io test
- DNS Query To Visual Studio Code Tunnels Domain test
- DNS Query Tor .Onion Address - Sysmon test
- DNS Server Discovery Via LDAP Query test
- DPRK Threat Actor - C2 Communication DNS Indicators test
- Notepad++ Updater DNS Query to Uncommon Domains experimental
- Potential Compromised 3CXDesktopApp Beaconing Activity - DNS test
- Potential SocGholish Second Stage C2 DNS Query test
- Suspicious Cobalt Strike DNS Beaconing - Sysmon test
- Suspicious DNS Query for IP Lookup Service APIs test
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing experimental
- TanStack Supply-Chain Attack DNS Indicators experimental
- TeamViewer Domain Query By Non-TeamViewer Application test
Event ID 23: FileDelete (File Delete archived) 14 rules
- ADS Zone.Identifier Deleted test
- ADS Zone.Identifier Deleted By Uncommon Application test
- Backup Files Deleted test
- EventLog EVTX File Deleted test
- Exchange PowerShell Cmdlet History Deleted test
- File Deleted Via Sysinternals SDelete test
- IIS WebServer Access Logs Deleted test
- Potential PrintNightmare Exploitation Attempt test
- PowerShell Console History Logs Deleted test
- Prefetch File Deleted test
- Process Deletion of Its Own Executable test
- TeamViewer Log File Deleted test
- Tomcat WebServer Logs Deleted test
- Unusual File Deletion by Dns.exe test
Event ID 26: FileDeleteDetected (File Delete logged) 14 rules
- ADS Zone.Identifier Deleted test
- ADS Zone.Identifier Deleted By Uncommon Application test
- Backup Files Deleted test
- EventLog EVTX File Deleted test
- Exchange PowerShell Cmdlet History Deleted test
- File Deleted Via Sysinternals SDelete test
- IIS WebServer Access Logs Deleted test
- Potential PrintNightmare Exploitation Attempt test
- PowerShell Console History Logs Deleted test
- Prefetch File Deleted test
- Process Deletion of Its Own Executable test
- TeamViewer Log File Deleted test
- Tomcat WebServer Logs Deleted test
- Unusual File Deletion by Dns.exe test
Microsoft-Windows-Windows-Defender
Event ID 1013: Product Name has removed history of malware and other potentially unwanted software. 1 rule
Event ID 1116: Product Name has detected malware or other potentially unwanted software. 4 rules
- Microsoft Defender massive host infection experimental
- Microsoft Defender massive virus outbreach experimental
- Windows Defender AMSI Trigger Detected stable
- Windows Defender Threat Detected stable
Event ID 1151: Endpoint Protection client health report (time in UTC). 1 rule
- Microsoft Defender signatures not up to date experimental
Event ID 3002: ProductName Real-Time Protection feature has encountered an error and failed. 2 rules
Event ID 5010: ProductName scanning for spyware and other potentially unwanted software is disabled. 1 rule
Microsoft-Windows-Windows-Firewall-With-Advanced-Security
Event ID 2004: A rule has been added to the Windows Defender Firewall exception list. 6 rules
- Firewall rule added using PowerShell or CMD experimental
- Firewall rule any/any created experimental
- New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application test
- New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE test
- OpenSSH server firewall configuration on Windows (firewall) experimental
- Uncommon New Firewall Rule Added In Windows Firewall Exception List test
Microsoft-Windows-CodeIntegrity
Event ID 3032: Code Integrity determined a revoked image FileNameBuffer is loaded into the system. 1 rule
Event ID 3035: Code Integrity determined a revoked image FileNameBuffer is loaded into the system. 1 rule
Event ID 3037: Code Integrity determined an unsigned image FileNameBuffer is loaded into the system. 1 rule
MSSQLSERVER
Event ID 15457 4 rules
Event ID 18456 2 rules
Event ID 18470 1 rule
Event ID 33205 14 rules
- MSSQL Add Account To Sysadmin Role test
- MSSQL Destructive Query experimental
- MSSQL Disable Audit Settings test
- MSSQL SPProcoption Set test
- MSSQL XPCmdshell Suspicious Execution test
- SQL SA admin user enabled experimental
- SQL Server - Brutforce enumeration with non existing users (login) experimental
- SQL Server - Connection attempt using a disabled account experimental
- SQL Server - Member got new privileges added on a database experimental
- SQL Server - Member got new privileges added on a SQL instance level experimental
- SQL Server - new member added to a database role experimental
- SQL Server - new member added to a server role experimental
- SQL Server auditing deactivated experimental
- SQL Server database auditing deactivated experimental
Microsoft-Windows-AppLocker
Event ID 8003: RuleAndFileData.FilePath was allowed to run but would have been prevented from running if the AppLocker policy were enforced. 1 rule
- AppLocker Application Would Have Been Blocked experimental
Event ID 8006: FilePathBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced. 1 rule
- AppLocker Application Would Have Been Blocked experimental
Event ID 8021: PackageBuffer was allowed to run but would have been prevented from running if the AppLocker policy were enforced. 1 rule
- AppLocker Application Would Have Been Blocked experimental
Microsoft-Windows-AppXDeployment-Server
Event ID 412: error ErrorCode: Deployment of package PackageFullName was blocked by AppLocker. 1 rule
Microsoft-Windows-Kerberos-Key-Distribution-Center
Service-Control-Manager
Event ID 7000: The param1 service failed to start due to the following error: 1 rule
- Massive service failures - Tchopper experimental
Event ID 7009: A timeout was reached (param1 milliseconds) while waiting for the param2 service to connect 1 rule
- Massive service failures - Tchopper experimental
Event ID 7036: The Microsoft Software Shadow Copy Provider service entered the stopped state. 3 rules
Event ID 7045: A service was installed in the system. 55 rules
- Anydesk Remote Access Software Service Installation test
- CobaltStrike Service Installations - System test
- COLDSTEEL Persistence Service Creation test
- Credential Dumping Tools Service Execution - System test
- CSExec Service Installation test
- Encoded PowerShell payload deployed via service experimental
- Goofy Guineapig Backdoor Service Creation test
- HackTool Service Registration or Execution test
- Impacket SMBexec service registration (native) experimental
- Invoke-Obfuscation CLIP+ Launcher - System test
- Invoke-Obfuscation COMPRESS OBFUSCATION - System test
- Invoke-Obfuscation Obfuscated IEX Invocation - System test
- Invoke-Obfuscation RUNDLL LAUNCHER - System test
- Invoke-Obfuscation STDIN+ Launcher - System test
- Invoke-Obfuscation VAR+ Launcher - System test
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System test
- Invoke-Obfuscation Via Stdin - System test
- Invoke-Obfuscation Via Use Clip - System test
- Invoke-Obfuscation Via Use MSHTA - System test
- Invoke-Obfuscation Via Use Rundll32 - System test
- KrbRelayUp Service Installation test
- KrbRelayUp service installation (native) experimental
- Massive service installation - Tchopper experimental
- Mesh Agent Service Installation test
- Meterpreter or Cobalt Strike Getsystem Service Installation - System test
- Mimikatz driver deployed via service experimental
- Moriya Rootkit - System test
- NetSupport Manager Service Install test
- New PDQDeploy Service - Client Side test
- New PDQDeploy Service - Server Side test
- OilRig APT Schedule Task Persistence - System test
- PAExec Service Installation test
- PowerShell Scripts Installed as Services test
- ProcessHacker Privilege Elevation test
- PsExec Service Installation test
- PSexec service installation experimental
- RDP session hijack via service creation abuse experimental
- RemCom Service Installation test
- Remote Access Tool Services Have Been Installed - System test
- Remote Utilities Host Service Install test
- RTCore Suspicious Service Installation test
- Service Installation in Suspicious Folder test
- Service Installation with Suspicious Folder Pattern test
- Service Installed By Unusual Client - System test
- Sliver C2 Default Service Installation test
- smbexec.py Service Installation test
- SNAKE Malware Service Persistence test
- StoneDrill Service Install test
- Suspicious Service Installation test
- Suspicious Service Installation Script test
- TacticalRMM Service Installation test
- Tap Driver Installation test
- Turla PNG Dropper Service test
- Turla Service Install test
- Uncommon Service Installation Image Path test
Microsoft-Windows-SMBClient
Microsoft-Windows-SoftwareRestrictionPolicies
Microsoft-Windows-WindowsUpdateClient
Event ID 16: Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the... 1 rule
- Windows Update Error stable
Event ID 20: Installation Failure: Windows failed to install the following update with error errorCode: updateTitle. 1 rule
- Windows Update Error stable
Event ID 24: Uninstallation Failure: Windows failed to uninstall the following update with error errorCode: updatelist. 1 rule
- Windows Update Error stable
MsiInstaller
Event ID 11724 1 rule
ESENT
Event ID 216 1 rule
- Ntdsutil Abuse test
Event ID 325 3 rules
Event ID 326 2 rules
- IFM detected - ESENT (installation from media) experimental
- Ntdsutil Abuse test
Event ID 327 2 rules
- IFM detected - ESENT (installation from media) experimental
- Ntdsutil Abuse test
Microsoft-Windows-DHCP-Server
Microsoft-Windows-DNS-Server-Service
Event ID 770: A DNS server plugin DLL has been loaded from location param1 on server param2. 2 rules
Microsoft-Windows-PrintService
Microsoft-Windows-TaskScheduler
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Event ID 1149: Remote Desktop Services: User authentication succeeded. 3 rules
- RDP reconnaissance with valid credentials performed on multiple hosts experimental
- RDP tunneling detected experimental
- RDP tunneling via ngrok detected experimental
Event ID 20503: Shadow View Session Started. 1 rule
- RDP shadow session started (native) experimental
Event ID 20504: Shadow View Session Stopped. 1 rule
- RDP shadow session started (native) experimental
Event ID 20508: Shadow View Permission Granted. 1 rule
- RDP shadow session started (native) experimental
LsaSrv
MSExchange-CmdletLogs
Event ID 1 1 rule
Event ID 6 3 rules
Microsoft-ServiceBus-Client
Microsoft-Windows-Bits-Client
Event ID 60: BITS stopped transferring the name transfer job that is associated with the url URL. 1 rule
- File with high volume downloaded via BITS experimental
Event ID 16403: task_016403 5 rules
Microsoft-Windows-DriverFrameworks-UserMode
Event ID 2003: The UMDF Host Process (UMDFHostDeviceArrivalBegin.LifetimeId) has been asked to load drivers for device UMDFHostDeviceArrivalBegin.InstanceId. 1 rule
- USB Device Plugged test
Microsoft-Windows-Eventlog
Event ID 104: The LogFileCleared.Channel log file was cleared. 3 rules
- Event log cleared (native) experimental
- Eventlog Cleared test
- Important Windows Eventlog Cleared test
Event ID 517: The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by 1102). 1 rule
Event ID 1102: The audit log was cleared. 2 rules
- Event log cleared (native) experimental
- Security Eventlog Cleared test
Microsoft-Windows-TerminalServices-LocalSessionManager
Event ID 21: Remote Desktop Services: Session logon succeeded. 2 rules
- Ngrok Usage with Remote Desktop Service test
- RDP tunneling via ngrok detected experimental
Microsoft-Windows-WMI-Activity
NETLOGON
Event ID 5723 1 rule
Event ID 5805 1 rule
PowerShell
Event ID 400 11 rules
- bXOR Operator Usage In PowerShell Command Line - PowerShell Classic test
- Delete Volume Shadow Copies Via WMI With PowerShell stable
- Netcat The Powershell Version test
- Nslookup PowerShell Download Cradle test
- PowerShell Called from an Executable Version Mismatch test
- PowerShell Downgrade Attack - PowerShell test
- PowerShell Download Via Net.WebClient - PowerShell Classic test
- Remote PowerShell Session (PS Classic) test
- Renamed Powershell Under Powershell Channel test
- Uncommon PowerShell Hosts test
- Use Get-NetTCPConnection test
Event ID 600 2 rules
Event ID 800 37 rules
- Active Directory Forest PowerShell class called from a non administrative host experimental
- BITS payload downloaded via PowerShell experimental
- DCOM lateral movement (via MMC20) experimental
- Domain group membership change experimental
- DoT (DNS over TLS) activation (PowerShell) experimental
- DSRM password changed (Reg via PowerShell) experimental
- Encoded PowerShell payload deployed (PowerShell) experimental
- Event log clear attempt (PowerShell) experimental
- Event log cleared using Diagnostics (via PowerShell) stable
- Exchange transport agent installation artifacts (PowerShell) experimental
- Firewall configuration enumerated (PowerShell) experimental
- Firewall deactivation (PowerShell) experimental
- Group discovery (PowerShell)
- Local group membership change experimental
- LSASS credential dump with LSASSY (PowerShell) experimental
- Microsoft Defender critical security components disabled (PowerShell) experimental
- Microsoft Defender default action changed to allow any threat (PowerShell) experimental
- Microsoft Defender security components disabled (PowerShell) experimental
- Microsoft Defender threat exclusion added (PowerShell) experimental
- OpenSSH native server feature installation experimental
- OpenSSH server firewall configuration on Windows (PowerShell) experimental
- OpenSSH service activation on Windows experimental
- Payload downloaded via PowerShell
- PipeShell exfiltration over named pipes experimental
- Print spooler privilege escalation via printer added (CVE-2020-1048) experimental
- Service abuse with backdoored "command failure" (Reg via PowerShell) experimental
- Service abuse with malicious ImagePath (Reg via PowerShell) experimental
- Service creation (PowerShell) experimental
- Service permissions hijacked for privileges abuse (PowerShell) experimental
- Service permissions hijacked for privileges abuse (Reg via PowerShell) experimental
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell) experimental
- System time changed (PowerShell) experimental
- Vault credentials manager accessed experimental
- VSS backup deletion via WMI (Powershell) experimental
- Webserver IIS module installed (PowerShell) experimental
- Webserver IIS module installed via GAC manipulation (PowerShell) experimental
- WMI registration (PowerShell) experimental
Microsoft-Windows-BitLocker-API
Microsoft-Windows-Directory-Services-SAM
Microsoft-Windows-NTLM
Microsoft-Windows-PowerShell
Event ID 4103: Payload Context: ContextInfo User Data: UserData. 71 rules
- Active Directory Forest PowerShell class called from a non administrative host experimental
- AD Groups Or Users Enumeration Using PowerShell - PoshModule test
- Alternate PowerShell Hosts - PowerShell Module test
- Bad Opsec Powershell Code Artifacts test
- BitLocker server feature activation (PowerShell) experimental
- BITS payload downloaded via PowerShell experimental
- Clear PowerShell History - PowerShell Module test
- DCOM lateral movement (via MMC20) experimental
- DoT (DNS over TLS) activation (PowerShell) experimental
- DSRM password changed (Reg via PowerShell) experimental
- Encoded PowerShell payload deployed (PowerShell) experimental
- Event log clear attempt (PowerShell) experimental
- Event log cleared using Diagnostics (via PowerShell) stable
- Exchange transport agent installation artifacts (PowerShell) experimental
- Firewall configuration enumerated (PowerShell) experimental
- Firewall deactivation (PowerShell) experimental
- Group discovery (PowerShell)
- HackTool - Evil-WinRm Execution - PowerShell Module test
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module test
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module test
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module test
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module test
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module test
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module test
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module test
- Invoke-Obfuscation Via Stdin - PowerShell Module test
- Invoke-Obfuscation Via Use Clip - PowerShell Module test
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module test
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module test
- Local Firewall Rules Enumeration Via NetFirewallRule Cmdlet test
- LSASS credential dump with LSASSY (PowerShell) experimental
- Malicious PowerShell Commandlets - PoshModule test
- Malicious PowerShell Scripts - PoshModule test
- Microsoft Defender critical security components disabled (PowerShell) experimental
- Microsoft Defender default action changed to allow any threat (PowerShell) experimental
- Microsoft Defender security components disabled (PowerShell) experimental
- Microsoft Defender threat exclusion added (PowerShell) experimental
- OpenSSH native server feature installation experimental
- OpenSSH server firewall configuration on Windows (PowerShell) experimental
- OpenSSH service activation on Windows experimental
- Payload downloaded via PowerShell
- PipeShell exfiltration over named pipes experimental
- Potential Active Directory Enumeration Using AD Module - PsModule test
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module test
- PowerShell Decompress Commands test
- PowerShell Get Clipboard test
- Print spooler privilege escalation via printer added (CVE-2020-1048) experimental
- Remote PowerShell Session (PS Module) test
- Service abuse with backdoored "command failure" (Reg via PowerShell) experimental
- Service abuse with malicious ImagePath (Reg via PowerShell) experimental
- Service creation (PowerShell) experimental
- Service permissions hijacked for privileges abuse (PowerShell) experimental
- Service permissions hijacked for privileges abuse (Reg via PowerShell) experimental
- Suspicious Computer Machine Password by PowerShell test
- Suspicious Get Information for SMB Share - PowerShell Module test
- Suspicious Get Local Groups Information test
- Suspicious Get-ADDBAccount Usage test
- Suspicious PowerShell Download - PoshModule test
- Suspicious PowerShell Invocations - Generic - PowerShell Module test
- Suspicious PowerShell Invocations - Specific - PowerShell Module test
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell) experimental
- SyncAppvPublishingServer Bypass Powershell Restriction - PS Module test
- System time changed (PowerShell) experimental
- Use Get-NetTCPConnection - PowerShell Module test
- Vault credentials manager accessed experimental
- VSS backup deletion via WMI (Powershell) experimental
- Webserver IIS module installed (PowerShell) experimental
- Webserver IIS module installed via GAC manipulation (PowerShell) experimental
- Windows Subsystem for Linux (WSL) installation (PowerShell) experimental
- WMI registration (PowerShell) experimental
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Module test
Event ID 4104: Creating Scriptblock text (MessageNumber of MessageTotal). 218 rules
- AADInternals PowerShell Cmdlets Execution - PsScript test
- Abuse of Service Permissions to Hide Services Via Set-Service - PS test
- Access to Browser Login Data test
- Active Directory Computers Enumeration With Get-AdComputer test
- Active Directory Forest PowerShell class called from a non administrative host experimental
- Active Directory Group Enumeration With Get-AdGroup test
- AD Groups Or Users Enumeration Using PowerShell - ScriptBlock test
- Add Windows Capability Via PowerShell Script test
- AMSI Bypass Pattern Assembly GetType test
- Automated Collection Bookmarks Using Get-ChildItem PowerShell test
- Automated Collection Command PowerShell test
- BitLocker server feature activation (PowerShell) experimental
- BITS payload downloaded via PowerShell experimental
- Certificate Exported Via PowerShell - ScriptBlock test
- Change PowerShell Policies to an Insecure Level - PowerShell test
- Change User Agents with WebRequest test
- Clear PowerShell History - PowerShell test
- Clearing Windows Console History test
- Code Executed Via Office Add-in XLL File test
- Compress-Archive Cmdlet Execution test
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell test
- Create Volume Shadow Copy with Powershell test
- DCOM lateral movement (via MMC20) experimental
- Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script test
- Detected Windows Software Discovery - PowerShell test
- DirectorySearcher Powershell Exploitation test
- Disable of ETW Trace - Powershell test
- Disable Powershell Command History test
- Disable-WindowsOptionalFeature Command PowerShell test
- DMSA Link Attributes Modified experimental
- DMSA Service Account Created in Specific OUs - PowerShell experimental
- Domain group membership change experimental
- DoT (DNS over TLS) activation (PowerShell) experimental
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock test
- DSRM password changed (Reg via PowerShell) experimental
- Dump Credentials from Windows Credential Manager With PowerShell test
- Enable Windows Remote Management test
- Encoded PowerShell payload deployed (PowerShell) experimental
- Enumerate Credentials from Windows Credential Manager With PowerShell test
- Event log clear attempt (PowerShell) experimental
- Event log cleared using Diagnostics (via PowerShell) stable
- Exchange transport agent installation artifacts (PowerShell) experimental
- Execute Invoke-command on Remote Host test
- Extracting Information with PowerShell test
- Firewall configuration enumerated (PowerShell) experimental
- Firewall deactivation (PowerShell) experimental
- Get-ADUser Enumeration Using UserAccountControl Flags test
- Group discovery (PowerShell)
- HackTool - Rubeus Execution - ScriptBlock test
- HackTool - WinPwn Execution - ScriptBlock test
- Import PowerShell Modules From Suspicious Directories test
- Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet experimental
- Invoke-Obfuscation CLIP+ Launcher - PowerShell test
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell test
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell test
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell test
- Invoke-Obfuscation STDIN+ Launcher - Powershell test
- Invoke-Obfuscation VAR+ Launcher - PowerShell test
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell test
- Invoke-Obfuscation Via Stdin - Powershell test
- Invoke-Obfuscation Via Use Clip - Powershell test
- Invoke-Obfuscation Via Use MSHTA - PowerShell test
- Invoke-Obfuscation Via Use Rundll32 - PowerShell test
- Lace Tempest PowerShell Evidence Eraser test
- Lace Tempest PowerShell Launcher test
- Live Memory Dump Using Powershell test
- Local group membership change experimental
- LSASS credential dump with LSASSY (PowerShell) experimental
- Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet experimental
- Malicious Nishang PowerShell Commandlets test
- Malicious PowerShell Commandlets - ScriptBlock test
- Malicious PowerShell Keywords test
- Malicious ShellIntel PowerShell Commandlets test
- Manipulation of User Computer or Group Security Principals Across AD test
- Microsoft Defender critical security components disabled (PowerShell) experimental
- Microsoft Defender default action changed to allow any threat (PowerShell) experimental
- Microsoft Defender security components disabled (PowerShell) experimental
- Microsoft Defender threat exclusion added (PowerShell) experimental
- Modify Group Policy Settings - ScriptBlockLogging test
- New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet - ScriptBlock test
- NTFS Alternate Data Stream test
- OpenSSH native server feature installation experimental
- OpenSSH server firewall configuration on Windows (PowerShell) experimental
- OpenSSH service activation on Windows experimental
- Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy test
- Payload downloaded via PowerShell
- PipeShell exfiltration over named pipes experimental
- Potential Active Directory Enumeration Using AD Module - PsScript test
- Potential AMSI Bypass Script Using NULL Bits test
- Potential APT FIN7 POWERHOLD Execution test
- Potential COM Objects Download Cradles Usage - PS Script test
- Potential Data Exfiltration Over SMTP Via Send-MailMessage Cmdlet test
- Potential Data Exfiltration Via Audio File test
- Potential In-Memory Execution Using Reflection.Assembly test
- Potential Invoke-Mimikatz PowerShell Script test
- Potential Keylogger Activity test
- Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock test
- Potential Persistence Via PowerShell User Profile Using Add-Content test
- Potential Persistence Via Security Descriptors - ScriptBlock test
- Potential PowerShell Obfuscation Using Alias Cmdlets test
- Potential PowerShell Obfuscation Using Character Join test
- Potential POWERTRASH Script Execution test
- Potential Registry Reconnaissance Via PowerShell Script test
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock test
- Potential Suspicious PowerShell Keywords test
- Potential Suspicious Windows Feature Enabled test
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock experimental
- Potential WinAPI Calls Via PowerShell Scripts test
- Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript test
- Powershell Add Name Resolution Policy Table Rule test
- PowerShell ADRecon Execution test
- PowerShell Create Local User test
- Powershell Create Scheduled Task test
- PowerShell Credential Prompt test
- PowerShell Deleted Mounted Share test
- Powershell Detect Virtualization Environment test
- Powershell Directory Enumeration test
- Powershell DNSExfiltration test
- Powershell Execute Batch Script test
- PowerShell Get-Process LSASS in ScriptBlock test
- PowerShell Hotfix Enumeration test
- PowerShell ICMP Exfiltration test
- Powershell Install a DLL in System Directory test
- Powershell Keylogging test
- Powershell Local Email Collection test
- Powershell LocalAccount Manipulation test
- Powershell MsXml COM Object test
- PowerShell PSAttack test
- PowerShell Remote Session Creation test
- PowerShell Script Change Permission Via Set-Acl - PsScript test
- PowerShell Script With File Hostname Resolving Capabilities test
- PowerShell Script With File Upload Capabilities test
- Powershell Sensitive File Discovery test
- PowerShell Set-Acl On Windows Folder - PsScript test
- PowerShell ShellCode test
- Powershell Store File In Alternate Data Stream test
- Powershell Suspicious Win32_PnPEntity test
- Powershell Timestomp test
- Powershell Token Obfuscation - Powershell test
- PowerShell Web Access Installation - PsScript test
- Powershell WMI Persistence test
- PowerShell WMI Win32_Product Install MSI test
- PowerShell Write-EventLog Usage test
- Powershell XML Execute Command test
- PowerView PowerShell Cmdlets - ScriptBlock test
- Print spooler privilege escalation via printer added (CVE-2020-1048) experimental
- PSAsyncShell - Asynchronous TCP Reverse Shell test
- Recon Information for Export with PowerShell test
- Registry Modification Attempt Via VBScript - PowerShell experimental
- Registry-Free Process Scope COR_PROFILER test
- Remove Account From Domain Admin Group test
- Replace Desktop Wallpaper by Powershell test
- Root Certificate Installed - PowerShell test
- Security Software Discovery Via Powershell Script test
- Service abuse with backdoored "command failure" (Reg via PowerShell) experimental
- Service abuse with malicious ImagePath (Reg via PowerShell) experimental
- Service creation (PowerShell) experimental
- Service permissions hijacked for privileges abuse (PowerShell) experimental
- Service permissions hijacked for privileges abuse (Reg via PowerShell) experimental
- Service Registry Permissions Weakness Check test
- Silence.EDA Detection test
- SMB over QUIC Via PowerShell Script test
- Suspicious Connection to Remote Account test
- Suspicious Eventlog Clear test
- Suspicious FromBase64String Usage On Gzip Archive - Ps Script test
- Suspicious Get Information for SMB Share test
- Suspicious Get Local Groups Information - PowerShell test
- Suspicious Get-ADReplAccount test
- Suspicious GetTypeFromCLSID ShellExecute test
- Suspicious GPO Discovery With Get-GPO test
- Suspicious Hyper-V Cmdlets test
- Suspicious Invoke-Item From Mount-DiskImage test
- Suspicious IO.FileStream test
- Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock test
- Suspicious Mount-DiskImage test
- Suspicious New-PSDrive to Admin Share test
- Suspicious PowerShell Download - Powershell Script test
- Suspicious PowerShell Get Current User test
- Suspicious PowerShell Invocations - Generic test
- Suspicious PowerShell Invocations - Specific test
- Suspicious PowerShell Mailbox Export to Share - PS test
- Suspicious PowerShell WindowStyle Option test
- Suspicious Process Discovery With Get-Process test
- Suspicious Service DACL Modification Via Set-Service Cmdlet - PS test
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell) experimental
- Suspicious SSL Connection test
- Suspicious Start-Process PassThru test
- Suspicious TCP Tunnel Via PowerShell Script test
- Suspicious Unblock-File test
- Suspicious X509Enrollment - Ps Script test
- SyncAppvPublishingServer Execution to Bypass Powershell Restriction test
- System time changed (PowerShell) experimental
- Tamper Windows Defender - ScriptBlockLogging test
- Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging test
- Testing Usage of Uncommonly Used Port test
- Troubleshooting Pack Cmdlet Execution test
- Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript test
- Usage Of Web Request Commands And Cmdlets - ScriptBlock test
- Use Of Remove-Item to Delete File - ScriptBlock test
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell test
- Vault credentials manager accessed experimental
- Veeam Backup Servers Credential Dumping Script Execution test
- Vice Society directory crawling script for data exfiltration (via ps_script) stable
- VSS backup deletion via WMI (Powershell) experimental
- Webserver IIS module installed (PowerShell) experimental
- Webserver IIS module installed via GAC manipulation (PowerShell) experimental
- WinAPI Function Calls Via PowerShell Scripts test
- WinAPI Library Calls Via PowerShell Scripts test
- Windows Defender Exclusions Added - PowerShell test
- Windows Firewall Profile Disabled test
- Windows Mail App Mailbox Access Via PowerShell Script test
- Windows Screen Capture with CopyFromScreen test
- Windows Subsystem for Linux (WSL) installation (PowerShell) experimental
- Winlogon Helper DLL test
- WMI registration (PowerShell) experimental
- WMIC Unquoted Services Path Lookup - PowerShell test
- WMImplant Hack Tool test
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Script test
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Microsoft-Windows-Security-Mitigations
ScreenConnect
TermDD
Event ID 50 1 rule
Event ID 56 1 rule
Application-Error
Event ID 1000: Faulting application name: Faulting_application_name, version: version, time stamp: 0xFaulting_module_name. 5 rules
- CVE-2023-40477 Potential Exploitation - WinRAR Application Crash test
- CVE-2024-49113 Exploitation Attempt - LDAP Nightmare experimental
- LSASS Crash Via Netlogon Stack Buffer Overflow - CVE-2026-41089 experimental
- LSASS Process Crashed - Application experimental
- Microsoft Malware Protection Engine Crash test
Application-Popup
MSExchange-Control-Panel
Microsoft-Windows-AppModel-Runtime
Microsoft-Windows-AppxPackagingOM
Microsoft-Windows-Audit-CVE
Microsoft-Windows-Backup
Microsoft-Windows-CAPI2
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Microsoft-Windows-CertificationAuthority
Microsoft-Windows-DNS-Client
Microsoft-Windows-DNSServer
Microsoft-Windows-Diagnosis-Scripted
Microsoft-Windows-DistributedCOM
Microsoft-Windows-IIS-Configuration
Microsoft-Windows-Iphlpsvc
Microsoft-Windows-Kernel-General
Microsoft-Windows-LDAP-Client
Microsoft-Windows-MSMQ
Microsoft-Windows-Ntfs
Microsoft-Windows-SMBServer
Microsoft-Windows-Servicing
Microsoft-Windows-Shell-Core
Microsoft-Windows-User-Profiles-Service
Microsoft-Windows-WER-SystemErrorReporting
Microsoft-Windows-WinINet-Config
Event ID 5600: task_0 1 rule
- Network proxy configuration changed experimental
Ntfs
OpenSSH
Event ID 4: process: payload. 2 rules
- OpenSSH Server Listening On Socket test
- OpenSSH server listening on socket experimental
RPCFW
Event ID 3: An RPC server function was called. 17 rules
- Possible DCSync Attack test
- Recon Activity via SASec test
- Remote DCOM/WMI Lateral Movement test
- Remote Encrypting File System Abuse test
- Remote Event Log Recon test
- Remote Printing Abuse for Lateral Movement test
- Remote Registry Lateral Movement test
- Remote Registry Recon test
- Remote Schedule Task Lateral Movement via ATSvc test
- Remote Schedule Task Lateral Movement via ITaskSchedulerService test
- Remote Schedule Task Lateral Movement via SASec test
- Remote Schedule Task Recon via AtScv test
- Remote Schedule Task Recon via ITaskSchedulerService test
- Remote Server Service Abuse test
- Remote Server Service Abuse for Lateral Movement test
- SharpHound Recon Account Discovery test
- SharpHound Recon Sessions test