Splunk rule coverage
149 events across 21 providers with Splunk detection rules, 2923 rule mappings total. Each rule links to its own page (predicates, exclusions, shared indicators). For the rule-centric ATT&CK browse across every vendor, see all detection rules; non-Windows Splunk rules are grouped by platform and technique at Splunk non-Windows coverage.
Microsoft-Windows-Security-Auditing
Event ID 4624 An account was successfully logged on. 20 rules
- Detect Password Spray Attack Behavior From Source production (source)
- Detect Password Spray Attack Behavior On User production (source)
- Multiple Host logons (Windows Event Log) (source)
- Pass-the-Hash (Windows Event Log) (source)
- Potential EternalBlue via Metasploit (Windows Event Log) (source)
- Potential Exposed SMB_RDP Port - Windows (Windows Event Log) (source)
- Potential SMB Activity from External IP - Windows (Windows Event Log) (source)
- SecretsDump Credential Harvest (Windows Event Log) (source)
- Suspicious Spool Authentication (Windows Event Log) (source)
- Unusual Number of Remote Endpoint Authentication Events experimental (source)
- Windows AD Domain Controller Promotion production (source)
- Windows AD Replication Request Initiated by User Account production (source)
- Windows AD Replication Request Initiated from Unsanctioned Location production (source)
- Windows AD Short Lived Domain Controller SPN Attribute production (source)
- Windows AD Suspicious Attribute Modification production (source)
- Windows Identify PowerShell Web Access IIS Pool production (source)
- Windows Kerberos Local Successful Logon production (source)
- Windows Local Administrator Credential Stuffing production (source)
- Windows Rapid Authentication On Multiple Hosts production (source)
- Windows RDP Login Session Was Established production (source)
Event ID 4625 An account failed to log on. 15 rules
- Detect Password Spray Attack Behavior From Source production (source)
- Detect Password Spray Attack Behavior On User production (source)
- Detect Password Spray Attempts production (source)
- Meterpreter Reverse Shell (Windows Event Log) (source)
- Multiple Failed Network Logon Attempts from Host (Windows Event Log) (source)
- Password Spraying Windows (Windows Event Log) (source)
- Potential EternalBlue via Metasploit (Windows Event Log) (source)
- RDP Brute-force Detection (Windows Event Log) (source)
- Suspicious Login Failures (Windows Event Log) (source)
- Windows Identify PowerShell Web Access IIS Pool production (source)
- Windows Local Administrator Credential Stuffing production (source)
- Windows Multiple Users Failed To Authenticate From Process production (source)
- Windows Multiple Users Remotely Failed To Authenticate From Host production (source)
- Windows Unusual Count Of Users Failed To Authenticate From Process production (source)
- Windows Unusual Count Of Users Remotely Failed To Auth From Host production (source)
Event ID 4648 A logon was attempted using explicit credentials. 5 rules
- ADExplorer Execution (Windows Event Log) (source)
- Windows Identify PowerShell Web Access IIS Pool production (source)
- Windows Multiple Users Fail To Authenticate Wth ExplicitCredentials production (source)
- Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials production (source)
- WMIC Explicit Credentials (Windows Event Log) (source)
Event ID 4656 A handle to an object was requested. 15 rules
- Browser Credential File Accessed - Windows (Windows Event Log) (source)
- Common LSASS Memory Dump Behavior (Windows Event Log) (source)
- Executable File Written to Disk (Windows Event Log) (source)
- File Written to Startup Folder - Windows (Windows Event Log) (source)
- Impacket atexec.py Temp File Creation (Windows Event Log) (source)
- ISO File in Temp Folder (Windows Event Log) (source)
- LSASS Handle request (Windows Event Log) (source)
- Mimikatz (Windows Event Log) (source)
- Potential Credential Dumping of LSASS (Windows Event Log) (source)
- Potential nanodump execution (Windows Event Log) (source)
- RDP File Written by Outlook (Windows Event Log) (source)
- Service Stop Commands (Windows Event Log) (source)
- Suspicious File written to Disk (Windows Event Log) (source)
- Task Manager lsass Dump (Windows Event Log) (source)
- Windows - Service Stop (Windows Event Log) (source)
Event ID 4657 A registry value was modified. 14 rules
- Command Line Utility Added to Accessibility Features (Windows Event Log) (source)
- ComputerDefaults UAC Bypass (Windows Event Log) (source)
- ConsentPromptBehaviorAdmin Registry Value Modified (Windows Event Log) (source)
- Defender Registry Values Modified (Windows Event Log) (source)
- EnableLUA Registry Value Modified (Windows Event Log) (source)
- Executable Running as NT AUTHORITY_SYSTEM Registered in BAM (Windows Event Log) (source)
- Hidden User Created - Windows (Windows Event Log) (source)
- LocalAccountTokenFilterPolicy Registry Value Modified (Windows Event Log) (source)
- Modify Registry Key (Windows Event Log) (source)
- Possible Credential Dumping via Windows Network Providers (Windows Event Log) (source)
- Potential fodhelper UAC Bypass Attempt (Windows Event Log) (source)
- PromptOnSecureDesktop Registry Value Modified (Windows Event Log) (source)
- Suspicious Registry Key Created (Windows Event Log) (source)
- Wow6432Node Classes Autorun Keys Modification (Windows Event Log) (source)
Event ID 4662 An operation was performed on an object. 7 rules
- Excessive DRSGetNCChanges Requests (Windows Event Log) (source)
- Potential DCSync (Windows Event Log) (source)
- Windows AD Abnormal Object Access Activity production (source)
- Windows AD Privileged Object Access Activity production (source)
- Windows AD Replication Request Initiated by User Account production (source)
- Windows AD Replication Request Initiated from Unsanctioned Location production (source)
- Windows Kerberos Coercion via DNS production (source)
Event ID 4663 An attempt was made to access an object. 30 rules
- Browser Credential File Accessed - Windows (Windows Event Log) (source)
- ConnectWise ScreenConnect Path Traversal Windows SACL production (source)
- ISO File in Temp Folder (Windows Event Log) (source)
- ISO Image Mounted - Windows (Windows Event Log) (source)
- Non Chrome Process Accessing Chrome Default Dir production (source)
- Non Firefox Process Access Firefox Profile Dir production (source)
- Potential Credential Dumping of LSASS (Windows Event Log) (source)
- Potential nanodump execution (Windows Event Log) (source)
- Rare dll called by Spoolsv.exe (Windows Event Log) (source)
- RDP File Written by Outlook (Windows Event Log) (source)
- Rename System Utilities (Windows Event Log) (source)
- SAM Database File Access Attempt production (source)
- SAM, System, Security Files Accessed (Windows Event Log) (source)
- Task Manager lsass Dump (Windows Event Log) (source)
- Temporary ConnectWise xml File Activity (Windows Event Log) (source)
- Windows Credential Access From Browser Password Store production (source)
- Windows Credentials from Password Stores Chrome Extension Access production (source)
- Windows Credentials from Password Stores Chrome LocalState Access production (source)
- Windows Credentials from Password Stores Chrome Login Data Access production (source)
- Windows GrimResource - MMC Process Accessing APDS DLL production (source)
- Windows Hosts File Access production (source)
- Windows Increase in Group or Object Modification Activity production (source)
- Windows Non Discord App Access Discord LevelDB production (source)
- Windows Process Accessing Windows Recall Directory production (source)
- Windows Product Key Registry Query production (source)
- Windows Query Registry Browser List Application production (source)
- Windows Query Registry UnInstall Program List production (source)
- Windows Unsecured Outlook Credentials Access In Registry production (source)
- Windows Unusual FileZilla XML Config Access production (source)
- Windows Unusual Intelliform Storage Registry Access production (source)
Event ID 4688 A new process has been created. 812 rules
- .msc Executed from Unusual Location (Windows Event Log) (source)
- 1 or 2 Character Executable (Windows Event Log) (source)
- 3CXDesktopApp.exe Execution (EDR) (source)
- 3CXDesktopApp.exe Execution (Windows Event Log) (source)
- 7zip CommandLine To SMB Share Path production (source)
- Abuse EQNEDT32.EXE (EDR) (source)
- Abuse EQNEDT32.EXE (Windows Event Log) (source)
- Access Common Package Config file (EDR) (source)
- Access Common Package Config file (Windows Event Log) (source)
- Account Password Changed from Command Line - Windows (Windows Event Log) (source)
- Account set to active via Net.exe (EDR) (source)
- Account set to active via Net.exe (Windows Event Log) (source)
- Add or Set Windows Defender Exclusion production (source)
- ADExplorer Execution (Windows Event Log) (source)
- ADExplorer Snapshot Creation (Windows Event Log) (source)
- Adfind Commands (Windows Event Log) (source)
- Adfind Execution (EDR) (source)
- Adfind Execution (Windows Event Log) (source)
- Advanced IP or Port Scanner Execution production (source)
- Advanced IP Scanner Execution (Windows Event Log) (source)
- Advanced Port Scanner Execution (Windows Event Log) (source)
- Allow File And Printing Sharing In Firewall production (source)
- Allow Network Discovery In Firewall production (source)
- Anomalous usage of 7zip production (source)
- AnyDesk Command Line Execution (Windows Event Log) (source)
- AnyDesk Execution from Suspicious Folder (Windows Event Log) (source)
- AnyDesk Silent Install (Windows Event Log) (source)
- Application Discovery - Windows (Windows Event Log) (source)
- ATBroker.exe Execution (Windows Event Log) (source)
- Attacker Tools On Endpoint production (source)
- Attempted Veeam Database Credential Dump (Windows Event Log) (source)
- Attrib.exe Metasploit File Dropper (EDR) (source)
- Attrib.exe Metasploit File Dropper (Windows Event Log) (source)
- AutoHotkey Execution (Windows Event Log) (source)
- AutoIt Execution (Windows Event Log) (source)
- Bash -c Execution - Windows (Windows Event Log) (source)
- Bcdedit Command Back To Normal Mode Boot production (source)
- BCDEdit Failure Recovery Modification production (source)
- BITS Job Persistence production (source)
- BITSAdmin Download File production (source)
- BITSadmin Execution (Windows Event Log) (source)
- BitsAdmin NetCat PowerCat File Transfer (EDR) (source)
- BitsAdmin NetCat PowerCat File Transfer (Windows Event Log) (source)
- Browser Started with Remote Debugging - Windows (Windows Event Log) (source)
- CDB Execution (Windows Event Log) (source)
- Certificate Abuse - Windows (Windows Event Log) (source)
- Certificate Enumeration - Windows (Windows Event Log) (source)
- Certutil De-Obfuscate_Decode Files (Windows Event Log) (source)
- Certutil exe certificate extraction production (source)
- Certutil Execution (Windows Event Log) (source)
- Certutil File Download (Windows Event Log) (source)
- Certutil Obfuscate_Encode Files (EDR) (source)
- Certutil Obfuscate_Encode Files (Windows Event Log) (source)
- Certutil Root Certificate Install (Windows Event Log) (source)
- CertUtil With Decode Argument production (source)
- Change To Safe Mode With Network Config production (source)
- Check Elevated CMD using whoami production (source)
- Child Processes of Spoolsv exe experimental (source)
- Cipher.exe Execution (Windows Event Log) (source)
- Clear Unallocated Sector Using Cipher App production (source)
- Clop Common Exec Parameter production (source)
- CMD Carry Out String Command Parameter production (source)
- CMD Echo Pipe - Escalation production (source)
- CMD execution with _c (Windows Event Log) (source)
- Cmstp Execution (Windows Event Log) (source)
- Command Line .cmd Execution (Windows Event Log) (source)
- Command Line Homoglyphs - Windows (Windows Event Log) (source)
- Command Line lsass request (Windows Event Log) (source)
- Command Line Spawned by Archive Utility - Windows (Windows Event Log) (source)
- Command Line Utility Added to Accessibility Features (Windows Event Log) (source)
- Command Output Redirected to Localhost (Windows Event Log) (source)
- Command-Line Interface Execution (Windows Event Log) (source)
- Common Active Directory Commands (Windows Event Log) (source)
- Common LSASS Memory Dump Behavior (Windows Event Log) (source)
- Common Recon Commands in Short Burst (Windows Event Log) (source)
- Common Reconnaissance Commands (Windows Event Log) (source)
- Compressed File Execution (Windows Event Log) (source)
- ComputerDefaults UAC Bypass (Windows Event Log) (source)
- comsvcs.dll Lsass Memory Dump (Windows Event Log) (source)
- Conhost.exe Kernel call (Windows Event Log) (source)
- Consent.exe Suspicious Child Process (Windows Event Log) (source)
- ConsentPromptBehaviorAdmin Registry Value Modified (Windows Event Log) (source)
- Conti Common Exec parameter production (source)
- Control Loading from World Writable Directory production (source)
- Control Panel Abuse (Windows Event Log) (source)
- Control_RunDLL Call from Command Line (Windows Event Log) (source)
- Create or delete windows shares using net exe production (source)
- Create_Add Local_Domain User (EDR) (source)
- Create_Add Local_Domain User (Windows Event Log) (source)
- Create_Modify Schtasks (Windows Event Log) (source)
- Creation of Shadow Copy production (source)
- Creation of Shadow Copy with wmic and powershell production (source)
- Credential Dumping via Copy Command from Shadow Copy production (source)
- Credential Dumping via Symlink to Shadow Copy production (source)
- Credentials in Registry (Windows Event Log) (source)
- CSC Execution (EDR) (source)
- CSC Execution (Windows Event Log) (source)
- CSC Net On The Fly Compilation production (source)
- CSVDE Export Active Directory (Windows Event Log) (source)
- Curl Execution with Percent Encoded URL production (source)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (EDR) (source)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Windows Event Log) (source)
- Data Exfiltration via AWS CLI - Windows (Windows Event Log) (source)
- Data Staged to File (Windows Event Log) (source)
- Defender Registry Values Modified (Windows Event Log) (source)
- Deleting Shadow Copies production (source)
- Detect AzureHound Command-Line Arguments production (source)
- Detect Certify Command Line Arguments production (source)
- Detect HTML Help Renamed production (source)
- Detect HTML Help Spawn Child Process production (source)
- Detect HTML Help URL in Command Line production (source)
- Detect HTML Help Using InfoTech Storage Handlers production (source)
- Detect mshta inline hta execution production (source)
- Detect mshta renamed production (source)
- Detect MSHTA Url in Command Line production (source)
- Detect Path Interception By Creation Of program exe production (source)
- Detect Prohibited Applications Spawning cmd exe production (source)
- Detect PsExec With accepteula Flag production (source)
- Detect Rare Executables production (source)
- Detect RClone Command-Line Usage production (source)
- Detect Regasm Spawning a Process production (source)
- Detect Regasm with no Command Line Arguments production (source)
- Detect Regsvcs Spawning a Process production (source)
- Detect Regsvcs with No Command Line Arguments production (source)
- Detect Regsvr32 Application Control Bypass production (source)
- Detect Remote Access Software Usage Process production (source)
- Detect Renamed 7-Zip production (source)
- Detect Renamed PSExec production (source)
- Detect Renamed RClone production (source)
- Detect Renamed WinRAR production (source)
- Detect RTLO In Process production (source)
- Detect Rundll32 Inline HTA Execution production (source)
- Detect SharpHound Command-Line Arguments production (source)
- Detect SharpHound Usage production (source)
- Detect Use of cmd exe to Launch Script Interpreters production (source)
- Detection of tools built by NirSoft experimental (source)
- Disable Logs Using WevtUtil production (source)
- Disable Schedule Task production (source)
- Disabled Pre-Authentication Accounts Discovery - PowerShell (Sysmon) (source)
- Disabled Pre-Authentication Accounts Discovery - PowerShell (Windows Event Log) (source)
- Disabling Firewall with Netsh production (source)
- Discovery using CHCP (Windows Event Log) (source)
- DLL Called with RS32 (Windows Event Log) (source)
- DLL Called with Uncommon Function (Windows Event Log) (source)
- DLL Concatenation (Windows Event Log) (source)
- DLL Execution from Uncommon Process (Windows Event Log) (source)
- DLLRegisterServer Called from Command Line (Windows Event Log) (source)
- DNS Exfiltration Using Nslookup App production (source)
- DNX.exe Proxy Execution (Windows Event Log) (source)
- Domain Account Discovery with Dsquery production (source)
- Domain Account Discovery with Wmic production (source)
- Domain Controller Discovery with Nltest production (source)
- Domain Controller Discovery with Wmic production (source)
- Domain Controller Enumeration via nltest (Windows Event Log) (source)
- Domain Group Discovery With Dsquery production (source)
- Domain Group Discovery With Wmic production (source)
- Domain Trust Discovery Commands - Windows (Windows Event Log) (source)
- Dotnet.exe Execution (Windows Event Log) (source)
- Driver as Command Parameter (Windows Event Log) (source)
- DSQuery Domain Discovery production (source)
- Dump File Identified (Windows Event Log) (source)
- Dump LSASS via comsvcs DLL production (source)
- Dump LSASS via procdump production (source)
- Dxcap Proxy Execution (Windows Event Log) (source)
- Elevated Group Discovery With Wmic production (source)
- EnableLUA Registry Value Modified (Windows Event Log) (source)
- Encoded Powershell Command (Windows Event Log) (source)
- Esentutl Execution (Windows Event Log) (source)
- Esentutl SAM Copy production (source)
- Event Logs Queried for RDP Sessions (Windows Event Log) (source)
- Excessive Attempt To Disable Services production (source)
- Excessive distinct processes from Windows Temp production (source)
- Excessive number of service control start as disabled production (source)
- Excessive number of taskhost processes production (source)
- Excessive Usage Of Cacls App production (source)
- Excessive Usage of NSLOOKUP App production (source)
- Excessive Usage Of Taskkill production (source)
- Executable Create Script Process (Windows Event Log) (source)
- Executable Process from Suspicious Folder (Windows Event Log) (source)
- Execute Javascript With Jscript COM CLSID production (source)
- Execution from Startup Folder (Windows Event Log) (source)
- Execution of File with Multiple Extensions production (source)
- Exfiltration via curl.exe - Windows (Windows Event Log) (source)
- Expand.exe Execution (Windows Event Log) (source)
- File and Directory Discovery Output to File - Windows (Windows Event Log) (source)
- File Download or Read to Pipe Execution production (source)
- File Executed from INetCache (Windows Event Log) (source)
- File_Folder Hidden - Windows (Windows Event Log) (source)
- Finger Execution (Windows Event Log) (source)
- Firewall Allowed Program Enable production (source)
- First Time Seen Child Process of Zoom experimental (source)
- FodHelper UAC Bypass production (source)
- FScan.exe Network Scan (Windows Event Log) (source)
- Fsutil fsinfo execution (EDR) (source)
- Fsutil fsinfo execution (Windows Event Log) (source)
- Fsutil Zeroing File production (source)
- Full Control Permissions Granted to Everyone - Windows (Windows Event Log) (source)
- Get ADDefaultDomainPasswordPolicy with Powershell production (source)
- Get ADUser with PowerShell production (source)
- Get ADUserResultantPasswordPolicy with Powershell production (source)
- Get DomainPolicy with Powershell production (source)
- Get DomainUser with PowerShell production (source)
- Get WMIObject Group Discovery production (source)
- Get-DomainTrust with PowerShell production (source)
- Get-ForestTrust with PowerShell production (source)
- GetAdComputer with PowerShell production (source)
- GetAdGroup with PowerShell production (source)
- GetCurrent User with PowerShell production (source)
- GetDomainComputer with PowerShell production (source)
- GetDomainController with PowerShell production (source)
- GetDomainGroup with PowerShell production (source)
- GetLocalUser with PowerShell production (source)
- GetNetTcpconnection with PowerShell production (source)
- GetWmiObject Ds Computer with PowerShell production (source)
- GetWmiObject Ds Group with PowerShell production (source)
- GetWmiObject DS User with PowerShell production (source)
- GetWmiObject User Account with PowerShell production (source)
- Git Spawns System32 Process (Windows Event Log) (source)
- Git Submodule Cloned - Windows (Windows Event Log) (source)
- Go Run Execution (Windows Event Log) (source)
- Group Policy Editor Execution (Windows Event Log) (source)
- Headless Browser Mockbin or Mocky Request production (source)
- Headless Browser Usage production (source)
- hh.exe Execution (Windows Event Log) (source)
- hh.exe Remote File Execution (Windows Event Log) (source)
- Hidden User Created - Windows (Windows Event Log) (source)
- Hiding Files And Directories With Attrib exe production (source)
- HTTP_HTTPS Default Security Zone Modified to Local Machine (Windows Event Log) (source)
- Hunting 3CXDesktopApp Software production (source)
- Icacls Deny Command production (source)
- ICACLS Grant Command production (source)
- IcedID Discovery Commands (EDR) (source)
- IcedID Discovery Commands (Windows Event Log) (source)
- IIS Worker (W3WP) Spawn Command Line (Windows Event Log) (source)
- Impacket atexec.py Execution (Windows Event Log) (source)
- Impacket Lateral Movement Activity (Windows Event Log) (source)
- Impacket Lateral Movement Commandline Parameters production (source)
- Impacket Lateral Movement smbexec CommandLine Parameters production (source)
- Impacket Lateral Movement WMIExec Commandline Parameters production (source)
- Impacket PSexec (Windows Event Log) (source)
- Impacket SMBexec (Windows Event Log) (source)
- Impacket_Empire's WMIExec (Windows Event Log) (source)
- Indirect Command Execution (Windows Event Log) (source)
- Invoke-DCOM.ps1 - PowerShell (Windows Event Log) (source)
- Invoke-Expression Command (Windows Event Log) (source)
- Invoke-WebRequest Command (Windows Event Log) (source)
- Known Process Injection Commands (Windows Event Log) (source)
- Live Sysinternals Execution (Windows Event Log) (source)
- Local Account Discovery With Wmic production (source)
- LocalAccountTokenFilterPolicy Registry Value Modified (Windows Event Log) (source)
- Locate Credentials (Windows Event Log) (source)
- Logon Script Registry Key added (EDR) (source)
- Logon Script Registry Key added (Windows Event Log) (source)
- LSA Authentication Packages Registry Key Modified (Windows Event Log) (source)
- Malicious Document Execution (Windows Event Log) (source)
- Malicious PowerShell Process - Encoded Command production (source)
- Malicious PowerShell Process - Execution Policy Bypass production (source)
- masscan Execution - Windows (Windows Event Log) (source)
- Mavinject Execution (EDR) (source)
- Mavinject Execution (Windows Event Log) (source)
- Mega Utility Execution - Windows (Windows Event Log) (source)
- Microsoft Build Engine Suspicious Parent Process (Windows Event Log) (source)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (EDR) (source)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (Windows Event Log) (source)
- Microsoft SQL Server Suspicious Child Process - Windows (Windows Event Log) (source)
- Mimikatz (Windows Event Log) (source)
- Mimikatz Execution (Windows Event Log) (source)
- Mimikatz PassTheTicket CommandLine Parameters production (source)
- Mmc LOLBAS Execution Process Spawn production (source)
- Mock System Directory - Windows (Windows Event Log) (source)
- Modify ACL permission To Files Or Folder production (source)
- Modify Windows Defender (EDR) (source)
- Modify Windows Defender (Windows Event Log) (source)
- MSBuild Suspicious Spawned By Script Process production (source)
- Mshta spawning Rundll32 OR Regsvr32 Process production (source)
- MSHTA.exe execution (Windows Event Log) (source)
- mshta.exe File Download (Windows Event Log) (source)
- MSI Installation via Appcert (Windows Event Log) (source)
- Msiexec Abuse (Windows Event Log) (source)
- MSIExec.exe Execution (Windows Event Log) (source)
- MSTSC Execution (EDR) (source)
- MSTSC Execution (Windows Event Log) (source)
- Msxsl Execution (EDR) (source)
- Msxsl Execution (Windows Event Log) (source)
- MultiDump.exe Execution (Windows Event Log) (source)
- Multiple nslookup commands (Windows Event Log) (source)
- Native Archive Commands (Windows Event Log) (source)
- Net.exe Use with URL (Windows Event Log) (source)
- Network Connection Discovery With Arp production (source)
- Network Connection Discovery With Netstat production (source)
- Network Discovery Using Route Windows App production (source)
- ngen.exe File Download (Windows Event Log) (source)
- ngrok Execution - Windows (Windows Event Log) (source)
- NirCmd Execution (Windows Event Log) (source)
- Nishang PowershellTCPOneLine production (source)
- NLTest Domain Trust Discovery production (source)
- NMAP Execution (EDR) (source)
- NMAP Execution (Windows Event Log) (source)
- Non-MSIExec .msi Installation (Windows Event Log) (source)
- Notepad with no Command Line Arguments production (source)
- Nslookup Execution (Windows Event Log) (source)
- ntds.dit Access from Unexpected Location (Windows Event Log) (source)
- ntds.dit Command Line (Windows Event Log) (source)
- Ntdsutil Export NTDS production (source)
- NTDSUtil.exe execution (Windows Event Log) (source)
- Office Binary Download Remote File (Windows Event Log) (source)
- Office Spawns Suspicious Child Process (Windows Event Log) (source)
- Output to File (Windows Event Log) (source)
- Package installation (Windows Event Log) (source)
- Parent in Public Folder Suspicious Process (Windows Event Log) (source)
- Password Spraying Windows (Windows Event Log) (source)
- Permission Groups Discovery: Domain Groups (Windows Event Log) (source)
- Permission Groups Discovery: Local Groups (Windows Event Log) (source)
- Permission Modification using Takeown App production (source)
- Permissions Replaced by icacls - Windows (Windows Event Log) (source)
- Possible Browser Pass View Parameter production (source)
- Possible Credential Dumping via Windows Network Providers (Windows Event Log) (source)
- Potential AutoHotkey .ahk Execution (Windows Event Log) (source)
- Potential Cryptomining Commands (Windows Event Log) (source)
- Potential CVE-2023-23397 (EDR) (source)
- Potential CVE-2023-23397 (Windows Event Log) (source)
- Potential Executable Masquerading as Document - Windows (Windows Event Log) (source)
- Potential fodhelper UAC Bypass Attempt (Windows Event Log) (source)
- Potential LSA password filter (Windows Event Log) (source)
- Potential Ping Sweep (Windows Event Log) (source)
- Potential PowerShell Post-Exploitation Activity (Windows Event Log) (source)
- Potential Proxy Malware via AutoRun Key (Windows Event Log) (source)
- Potential Sysinternals Tool Execution (Windows Event Log) (source)
- Potential System Network Configuration Discovery Activity production (source)
- Potential Telegram API Request Via CommandLine production (source)
- PowerHuntShares Commands (Windows Event Log) (source)
- PowerShell - Connect To Internet With Hidden Window production (source)
- PowerShell CreateDecryptor (Windows Event Log) (source)
- Powershell Disable Security Monitoring production (source)
- PowerShell Downgrade (Sysmon) (source)
- PowerShell Downgrade (Windows Event Log) (source)
- PowerShell DownloadFile_DownloadString (Windows Event Log) (source)
- PowerShell Get LocalGroup Discovery production (source)
- PowerShell Hidden Window (Windows Event Log) (source)
- PowerShell Modifying Registry Values (Windows Event Log) (source)
- PowerShell Start-BitsTransfer production (source)
- PowerShell XML Retrieval (Windows Event Log) (source)
- Prevent Automatic Repair Mode using Bcdedit production (source)
- ProcDump Credential Harvest (Windows Event Log) (source)
- Process Creation Using Sysnative Folder (Windows Event Log) (source)
- Process Executed from Downloads Folder - Windows (Windows Event Log) (source)
- Process Executed with Null Command Line (Windows Event Log) (source)
- Process Execution From Suspicious Folder (Windows Event Log) (source)
- Process Execution via WMI production (source)
- Process Kill Base On File Path production (source)
- PromptOnSecureDesktop Registry Value Modified (Windows Event Log) (source)
- ProtocolHandler.exe File Download (Windows Event Log) (source)
- Proxy Execution via Appcert (Windows Event Log) (source)
- PuTTY Secure Copy Client Execution (Windows Event Log) (source)
- pypykatz commands (Windows Event Log) (source)
- Python Execution (Windows Event Log) (source)
- QEMU Network Tunneling - Windows (Windows Event Log) (source)
- Query Registry (Windows Event Log) (source)
- Radmin execution (EDR) (source)
- Radmin execution (Windows Event Log) (source)
- Rare executable from Microsoft Office (Windows Event Log) (source)
- Rare Process Execution (Windows Event Log) (source)
- Rclone Execution (Windows Event Log) (source)
- RDP Enabled (Windows Event Log) (source)
- RDP File Executed from Outlook Temp Directory (Windows Event Log) (source)
- RDP Hijacking (Windows Event Log) (source)
- RdrLeakDiag.exe Memory Dump (Windows Event Log) (source)
- Read-Only Attribute Removed - Windows (Windows Event Log) (source)
- Recursive Delete of Directory In Batch CMD production (source)
- Reg exe Manipulating Windows Services Registry Keys production (source)
- Reg.exe Process Execution (Windows Event Log) (source)
- Regini.exe Execution (Windows Event Log) (source)
- Registry key added with reg.exe (Windows Event Log) (source)
- regsvr32 Execution (Windows Event Log) (source)
- regsvr32 Referencing Unusual Paths (Windows Event Log) (source)
- Regsvr32 Silent and Install Param Dll Loading production (source)
- Regsvr32 with Known Silent Switch Cmdline production (source)
- Remote .msi Installation (Windows Event Log) (source)
- Remote .msi Installation (Windows Event Log) (source)
- Remote Access Software Execution (Windows Event Log) (source)
- Remote Admin Tools (EDR) (source)
- Remote Admin Tools (Windows Event Log) (source)
- Remote Desktop Process Running On System experimental (source)
- Remote Process Instantiation via DCOM and PowerShell production (source)
- Remote Process Instantiation via WinRM and PowerShell production (source)
- Remote Process Instantiation via WinRM and Winrs production (source)
- Remote Process Instantiation via WMI production (source)
- Remote Process Instantiation via WMI and PowerShell production (source)
- Remote Share Directory Listing - Windows (Windows Event Log) (source)
- Remote System Discovery with Dsquery production (source)
- Remote System Discovery with Wmic production (source)
- Remote WMI Command Attempt production (source)
- Remote WMIC Query (Windows Event Log) (source)
- Resize ShadowStorage volume production (source)
- Revil Common Exec Parameter production (source)
- Rubeus Command Line Parameters production (source)
- Rubeus Commands (Windows Event Log) (source)
- Runas Execution in CommandLine production (source)
- RunDLL Loading DLL By Ordinal production (source)
- Rundll32 Command Line (Windows Event Log) (source)
- Rundll32 Control RunDLL Hunt production (source)
- Rundll32 Control RunDLL World Writable Directory production (source)
- Rundll32 LockWorkStation production (source)
- Rundll32 Shimcache Flush production (source)
- Rundll32 Spawned by Disk Cleanup (Windows Event Log) (source)
- Rundll32 Suspicious Command Line (Windows Event Log) (source)
- rundll32 Suspicious Parent Process (Windows Event Log) (source)
- rundll32 with No DLL in Command Line (Windows Event Log) (source)
- Rundll32.exe as Parent Process (Windows Event Log) (source)
- rundll32.exe Executing DLL from Non-standard Directory (Windows Event Log) (source)
- Ryuk Wake on LAN Command production (source)
- Scheduled Task Creation on Remote Endpoint using At production (source)
- Scheduled Task Deleted Or Created via CMD production (source)
- Scheduled Task Initiation on Remote Endpoint production (source)
- Scheduled Task with Potential SSH Tunnel - Windows (Windows Event Log) (source)
- Schtasks Run Task On Demand production (source)
- Schtasks scheduling job on remote system production (source)
- Schtasks used for forcing a reboot production (source)
- Script Execution via WMI production (source)
- Sdelete Application Execution production (source)
- SecretDumps Offline NTDS Dumping Tool production (source)
- Security Software Discovery via Findstr.exe (Windows Event Log) (source)
- Security Software Discovery via WMI (Windows Event Log) (source)
- Service Stop Commands (Windows Event Log) (source)
- ServicePrincipalNames Discovery with SetSPN production (source)
- Services Escalate Exe production (source)
- Services LOLBAS Execution Process Spawn production (source)
- Shell Spawned by Web Server - Windows (Windows Event Log) (source)
- Shim Database Installation With Suspicious Parameters production (source)
- SimpleHelp Remote Access Tool Execution (Windows Event Log) (source)
- Single Letter Process On Endpoint production (source)
- Sliver C2 Implant Activity Pattern (Windows Event Log) (source)
- SLUI RunAs Elevated production (source)
- SLUI Spawning a Process production (source)
- SoftPerfect Network Scanner Execution (Windows Event Log) (source)
- Spoolsv Spawning Rundll32 production (source)
- Spoolsv Writing a DLL production (source)
- ssh.exe Execution (Windows Event Log) (source)
- Startup Folder Location Modified - Windows (Windows Event Log) (source)
- Suspicious AteraAgent Installation - Windows (Windows Event Log) (source)
- Suspicious Child Process for hh.exe (Windows Event Log) (source)
- Suspicious Child Process for lsass.exe (Windows Event Log) (source)
- Suspicious Child Process for mshta.exe (Windows Event Log) (source)
- Suspicious ComputerDefaults.exe Execution (Windows Event Log) (source)
- Suspicious Confluence Child Process - Windows (Windows Event Log) (source)
- Suspicious Conhost.exe Commands (Windows Event Log) (source)
- Suspicious Copy on System32 production (source)
- Suspicious csc.exe Source File Folder (Windows Event Log) (source)
- Suspicious Curl Network Connection experimental (source)
- Suspicious DLLhost Execution (EDR) (source)
- Suspicious DLLhost Execution (Windows Event Log) (source)
- Suspicious DLLHost no Command Line Arguments production (source)
- Suspicious Executable by CMD.exe (Windows Event Log) (source)
- Suspicious Executable by Powershell (EDR) (source)
- Suspicious Executable by Powershell (Windows Event Log) (source)
- Suspicious Execution of Accessibility Tool Debuggers (Windows Event Log) (source)
- Suspicious Execution via Microsoft Common Console (Windows Event Log) (source)
- Suspicious GPUpdate no Command Line Arguments production (source)
- Suspicious IcedID Rundll32 Cmdline production (source)
- Suspicious InprocServer32 Registry Modification (Windows Event Log) (source)
- Suspicious microsoft workflow compiler rename production (source)
- Suspicious microsoft workflow compiler usage production (source)
- Suspicious msbuild path production (source)
- Suspicious MSBuild Rename production (source)
- Suspicious MSBuild Spawn production (source)
- Suspicious mshta child process production (source)
- Suspicious mshta spawn production (source)
- Suspicious ntds.dit Commands (Windows Event Log) (source)
- Suspicious Parent Process for lsass.exe or services.exe (Windows Event Log) (source)
- Suspicious Parent Process for msiexec.exe (Windows Event Log) (source)
- Suspicious Parent Process for spoolsv.exe (Windows Event Log) (source)
- Suspicious PlistBuddy Usage experimental (source)
- Suspicious PowerShell Clipboard Activity (Windows Event Log) (source)
- Suspicious PowerShell Parameter Substring (Windows Event Log) (source)
- Suspicious Process Executed From Container File production (source)
- Suspicious process Spawned by Java (Windows Event Log) (source)
- Suspicious Reg exe Process production (source)
- Suspicious Regsvr32 Register Suspicious Path production (source)
- Suspicious Rundll32 dllregisterserver production (source)
- Suspicious Rundll32 no Command Line Arguments production (source)
- Suspicious Rundll32 PluginInit production (source)
- Suspicious Rundll32 StartW production (source)
- Suspicious Scheduled Task from Public Directory production (source)
- Suspicious SearchProtocolHost no Command Line Arguments production (source)
- Suspicious SQLite3 LSQuarantine Behavior experimental (source)
- Suspicious WAV file in Appdata Folder production (source)
- Suspicious wevtutil Usage production (source)
- Svchost LOLBAS Execution Process Spawn production (source)
- Symbolic OR Hard File Link Created (Windows Event Log) (source)
- SyncAppvPublishingServer Execution (Windows Event Log) (source)
- System Enumeration with WMIC (Windows Event Log) (source)
- System Info Gathering Using Dxdiag Application production (source)
- System Information Discovery - Windows (Windows Event Log) (source)
- System Information Discovery Detection production (source)
- System Network Connections Discovery - Windows (Windows Event Log) (source)
- System Owner_User Discovery - Windows (Windows Event Log) (source)
- System Processes Run From Unexpected Locations production (source)
- System Time enumeration (Windows Event Log) (source)
- System User Discovery With Query production (source)
- System User Discovery With Whoami production (source)
- Task Manager lsass Dump (Windows Event Log) (source)
- Temporary File Executed from Public Folder (Windows Event Log) (source)
- Timestamp Manipulation (Windows Event Log) (source)
- Tunneling Process Created (Windows Event Log) (source)
- Uninstall App Using MsiExec production (source)
- Unload Sysmon Filter Driver production (source)
- Unusual AppCert Child Process (Windows Event Log) (source)
- Unusual svchost Child Process (Windows Event Log) (source)
- Unusual winlogon.exe Child Process (Windows Event Log) (source)
- Unusually Long Command Line experimental (source)
- User Discovery With Env Vars PowerShell production (source)
- User_Domain Enumeration Tool - Windows (Windows Event Log) (source)
- USN Journal Deletion production (source)
- Utility Archive Data (Windows Event Log) (source)
- Verclsid CLSID Execution production (source)
- Visio.exe File Download (Windows Event Log) (source)
- Visual Studio Code Tunnel Execution (Windows Event Log) (source)
- WBAdmin Delete System Backups production (source)
- WDigest Forced Credential Caching (Windows Event Log) (source)
- WebDAV LNK Execution (Windows Event Log) (source)
- WebLogic CVE-2017-10271 (Windows Event Log) (source)
- Wermgr Process Spawned CMD Or Powershell Process production (source)
- Windows - Service Stop (Windows Event Log) (source)
- Windows AdFind Exe production (source)
- Windows Advanced Installer MSIX with AI_STUBS Execution production (source)
- Windows Alternate DataStream - Process Execution production (source)
- Windows Apache Benchmark Binary production (source)
- Windows AppCertDLL Modification Via Command Line production (source)
- Windows Application Whitelisting Bypass Attempt via Rundll32 production (source)
- Windows Archive Collected Data via Rar production (source)
- Windows Attempt To Stop Security Service production (source)
- Windows Audit Policy Auditing Option Disabled via Auditpol production (source)
- Windows Audit Policy Cleared via Auditpol production (source)
- Windows Audit Policy Disabled via Auditpol production (source)
- Windows Audit Policy Disabled via Legacy Auditpol production (source)
- Windows Audit Policy Excluded Category via Auditpol production (source)
- Windows Audit Policy Restored via Auditpol production (source)
- Windows Audit Policy Security Descriptor Tampering via Auditpol production (source)
- Windows AutoIt3 Execution production (source)
- Windows Azure Storage Utility Execution Via CLI production (source)
- Windows Binary Proxy Execution Mavinject DLL Injection production (source)
- Windows BitLocker Suspicious Command Usage production (source)
- Windows BitLockerToGo Process Execution production (source)
- Windows Bypass UAC via Pkgmgr Tool production (source)
- Windows C$ Share Access (EDR) (source)
- Windows Cabinet File Extraction Via Expand production (source)
- Windows Cached Domain Credentials Reg Query production (source)
- Windows Certutil Root Certificate Addition production (source)
- Windows Change File Association Command To Notepad production (source)
- Windows Chrome Enable Extension Loading via Command-Line production (source)
- Windows Chromium Browser Launched with Small Window Size production (source)
- Windows Chromium Browser No Security Sandbox Process production (source)
- Windows Chromium Browser with Custom User Data Directory production (source)
- Windows Chromium process Launched with Disable Popup Blocking production (source)
- Windows Chromium Process Launched with Logging Disabled production (source)
- Windows Chromium Process Loaded Extension via Command-Line production (source)
- Windows Chromium Process with Disabled Extensions production (source)
- Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc production (source)
- Windows Cisco Secure Endpoint Unblock File Via Sfc production (source)
- Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc production (source)
- Windows Cmdline Tool Execution From Non-Shell Process production (source)
- Windows COM Hijacking InprocServer32 Modification production (source)
- Windows Command and Scripting Interpreter Hunting Path Traversal production (source)
- Windows Command and Scripting Interpreter Path Traversal Exec production (source)
- Windows Command Obfuscation with Environment Variable Substrings production (source)
- Windows Compatibility Telemetry Suspicious Child Process production (source)
- Windows ConHost with Headless Argument production (source)
- Windows Copy Files (Windows Event Log) (source)
- Windows Create Local Administrator Account Via Net production (source)
- Windows Credential Dumping LSASS Memory Createdump production (source)
- Windows Credentials from Password Stores Creation production (source)
- Windows Credentials from Password Stores Deletion production (source)
- Windows Credentials from Password Stores Query production (source)
- Windows Credentials in Registry Reg Query production (source)
- Windows Curl Download to Suspicious Path production (source)
- Windows Curl Upload to Remote Destination production (source)
- Windows Debugger Tool Execution production (source)
- Windows Default Group Policy Object Modified with GPME production (source)
- Windows Defender ASR or Threat Configuration Tamper production (source)
- Windows Defender Disabled Detection (EDR) (source)
- Windows Defender Disabled Detection (Windows Event Log) (source)
- Windows Delete or Modify System Firewall production (source)
- Windows Devtunnels Execution production (source)
- Windows Disable Internet Explorer Addons production (source)
- Windows Disable or Modify Tools Via Taskkill production (source)
- Windows Disable Windows Event Logging Disable HTTP Logging production (source)
- Windows DiskCryptor Usage production (source)
- Windows Diskshadow Proxy Execution production (source)
- Windows DISM Install PowerShell Web Access production (source)
- Windows DISM Remove Defender production (source)
- Windows DLL Search Order Hijacking with iscsicpl production (source)
- Windows DLL Side-Loading Process Child Of Calc production (source)
- Windows DNS Gather Network Info production (source)
- Windows DotNet Binary in Non Standard Path production (source)
- Windows EDRSilencer Execution production (source)
- Windows EFI Volume Mount Attempt Via Mountvol production (source)
- Windows Entra User Management Via Azure CLI production (source)
- Windows ESX Admins Group Creation via Net production (source)
- Windows Eventlog Cleared Via Wevtutil production (source)
- Windows EventLog Recon Activity Using Log Query Utilities production (source)
- Windows Excel Spawning Microsoft Project Application production (source)
- Windows Excessive Service Stop Attempt production (source)
- Windows Excessive Usage Of Net App production (source)
- Windows Execute Arbitrary Commands with MSDT production (source)
- Windows Execution of Microsoft MSC File In Suspicious Path production (source)
- Windows Explorer LNK Exploit Process Launch With Padding production (source)
- Windows Explorer.exe Spawning PowerShell or Cmd production (source)
- Windows File and Directory Enable ReadOnly Permissions production (source)
- Windows File and Directory Permissions Enable Inheritance production (source)
- Windows File and Directory Permissions Remove Inheritance production (source)
- Windows File Association Modification via Ftype production (source)
- Windows File Collection Via Copy Utilities production (source)
- Windows File Download Via CertUtil production (source)
- Windows File Download Via PowerShell production (source)
- Windows Files and Dirs Access Rights Modification Via Icacls production (source)
- Windows Findstr GPP Discovery production (source)
- Windows Firewall Disabled (Windows Event Log) (source)
- Windows Firewall Rule Creation (Windows Event Log) (source)
- Windows FTP Exfiltration (Windows Event Log) (source)
- Windows Gdrive Binary Activity production (source)
- Windows Get-Variable.EXE Execution from WindowsApps Folder production (source)
- Windows Global Object Access Audit List Cleared Via Auditpol production (source)
- Windows Group Discovery Via Net production (source)
- Windows Guest Account Enabled Via Net.EXE production (source)
- Windows Identify Protocol Handlers production (source)
- Windows IIS Components Add New Module production (source)
- Windows Impair Defense Add Xml Applocker Rules production (source)
- Windows Indicator Removal Via Rmdir production (source)
- Windows Indirect Command Execution Via Series Of Forfiles production (source)
- Windows Information Discovery Fsutil production (source)
- Windows Ingress Tool Transfer Using Explorer production (source)
- Windows InstallUtil in Non Standard Path production (source)
- Windows InstallUtil Uninstall Option production (source)
- Windows InstallUtil URL in Command Line production (source)
- Windows IOBit Unlocker Extension DLL Registration via Regsvr32 production (source)
- Windows Ldifde Directory Object Behavior production (source)
- Windows List ENV Variables Via SET Command From Uncommon Parent production (source)
- Windows Local LLM Framework Execution production (source)
- Windows LOLBAS Executed As Renamed File production (source)
- Windows LOLBAS Executed Outside Expected Path production (source)
- Windows Masquerading Explorer As Child Process production (source)
- Windows Masquerading Msdtc Process production (source)
- Windows Metasploit Confluence Plugin Execution production (source)
- Windows Mimikatz Binary Execution production (source)
- Windows Modify Registry Regedit Silent Reg Import production (source)
- Windows Modify System Firewall with Notable Process Path production (source)
- Windows MOF Event Triggered Execution via WMI production (source)
- Windows MpCmdRun RemoveDefinitions Execution production (source)
- Windows MSC EvilTwin Directory Path Manipulation production (source)
- Windows MSIExec DLLRegisterServer production (source)
- Windows MsiExec HideWindow Rundll32 Execution production (source)
- Windows MSIExec Remote Download production (source)
- Windows MSIExec Spawn Discovery Command production (source)
- Windows MSIExec Spawn WinDBG production (source)
- Windows MSIExec Unregister DLLRegisterServer production (source)
- Windows MSTSC RDP Commandline production (source)
- Windows Mustang Panda USB Tool Execution production (source)
- Windows Net System Service Discovery production (source)
- Windows Netspy Network Scanner Execution production (source)
- Windows Network Connection Discovery Via Net production (source)
- Windows Network Share Interaction Via Net production (source)
- Windows New Deny Permission Set On Service SD Via Sc.EXE production (source)
- Windows New Service Security Descriptor Set Via Sc.EXE production (source)
- Windows Ngrok Reverse Proxy Usage production (source)
- Windows NirSoft AdvancedRun production (source)
- Windows NirSoft Utilities production (source)
- Windows NorthStar C2 Agent Execution production (source)
- Windows Odbcconf Hunting production (source)
- Windows Odbcconf Load DLL production (source)
- Windows Odbcconf Load Response File production (source)
- Windows Office Product Dropped Cab or Inf File production (source)
- Windows Office Product Spawned Child Process For Download production (source)
- Windows Office Product Spawned Control production (source)
- Windows Office Product Spawned MSDT production (source)
- Windows Office Product Spawned Rundll32 With No DLL production (source)
- Windows Office Product Spawned Uncommon Process production (source)
- Windows OneDrive Share Mounted via Net production (source)
- Windows PaperCut NG Spawn Shell production (source)
- Windows Parent PID Spoofing with Explorer production (source)
- Windows Password Managers Discovery production (source)
- Windows Password Policy Discovery with Net production (source)
- Windows Phishing PDF File Executes URL Link production (source)
- Windows Potato Privilege Escalation Tool Execution production (source)
- Windows Potential Cloudflared Tunnel Execution production (source)
- Windows PowerShell FakeCAPTCHA Clipboard Execution production (source)
- Windows PowerShell Process Implementing Manual Base64 Decoder production (source)
- Windows PowerShell Process With Malicious String production (source)
- Windows Powershell RemoteSigned File production (source)
- Windows PowerShell Script From WindowsApps Directory production (source)
- Windows Private Keys Discovery production (source)
- Windows Privilege Escalation Attempt Via MSI Rollback production (source)
- Windows Process Commandline Discovery production (source)
- Windows Process Copied from System Folder (Windows Event Log) (source)
- Windows Process Execution From ProgramData production (source)
- Windows Process Execution From RDP Share production (source)
- Windows Process Execution in Temp Dir production (source)
- Windows Process Injection In Non-Service SearchIndexer production (source)
- Windows Process Injection Wermgr Child Process production (source)
- Windows Process Outside of System Folder (Windows Event Log) (source)
- Windows Process With NamedPipe CommandLine production (source)
- Windows Process With NetExec Command Line Parameters production (source)
- Windows Protocol Tunneling with Plink production (source)
- Windows Proxy Execution of .NET Utilities via Scripts production (source)
- Windows Proxy Via Netsh production (source)
- Windows PsTools Recon Usage production (source)
- Windows PuTTY Suite Utility Execution production (source)
- Windows Raccine Scheduled Task Deletion production (source)
- Windows Rasautou DLL Execution production (source)
- Windows RDP File Execution production (source)
- Windows Registry Entries Exported Via Reg production (source)
- Windows Registry Entries Restored Via Reg production (source)
- Windows Regsvr32 Renamed Binary production (source)
- Windows Remote Assistance Spawning Process production (source)
- Windows Remote Create Service production (source)
- Windows Remote Host Computer Management Access production (source)
- Windows Remote Management Execute Shell production (source)
- Windows Remote Service Rdpwinst Tool Execution production (source)
- Windows Remote Services Allow Rdp In Firewall production (source)
- Windows Rundll32 Apply User Settings Changes production (source)
- Windows Rundll32 Execution With Log.DLL production (source)
- Windows Rundll32 WebDAV Request production (source)
- Windows Rundll32 with Non-Standard File Extension production (source)
- Windows Scheduled Task Created Via XML production (source)
- Windows Scheduled Task with Highest Privileges production (source)
- Windows Schtasks Create Run As System production (source)
- Windows ScManager Security Descriptor Tampering Via Sc.EXE production (source)
- Windows Security Account Manager Stopped production (source)
- Windows Security Support Provider Reg Query production (source)
- Windows Sensitive Group Discovery With Net production (source)
- Windows Sensitive Registry Hive Dump Via CommandLine production (source)
- Windows Server Software Component GACUtil Install to GAC production (source)
- Windows Service Create Kernel Mode Driver production (source)
- Windows Service Create with Tscon production (source)
- Windows Service Created (Windows Event Log) (source)
- Windows Service Creation on Remote Endpoint production (source)
- Windows Service Execution RemCom production (source)
- Windows Service Initiation on Remote Endpoint production (source)
- Windows Service Started (Windows Event Log) (source)
- Windows Service Stop Attempt production (source)
- Windows Service Stop By Deletion production (source)
- Windows Set Account Password Policy To Unlimited Via Net production (source)
- Windows Set Custom DNS ServerLevelPlugin Via Dnscmd production (source)
- Windows Shell Process from CrushFTP production (source)
- Windows SOAPHound Binary Execution production (source)
- Windows Spearphishing Attachment Onenote Spawn Mshta production (source)
- Windows SpeechRuntime Suspicious Child Process production (source)
- Windows SQL Spawning CertUtil experimental (source)
- Windows SQLCMD Execution production (source)
- Windows Sqlservr Spawning Shell production (source)
- Windows Steal Authentication Certificates CertUtil Backup production (source)
- Windows Steal Authentication Certificates Export Certificate production (source)
- Windows Steal Authentication Certificates Export PfxCertificate production (source)
- Windows Steal or Forge Kerberos Tickets Klist production (source)
- Windows SubInAcl Execution production (source)
- Windows Suspicious Child Process Spawned From WebServer production (source)
- Windows Suspicious Process File Path production (source)
- Windows Suspicious VMWare Tools Child Process production (source)
- Windows Svchost.exe Parent Process Anomaly production (source)
- Windows SymbolicLink-Testing-Tools Utility Execution production (source)
- Windows Symlink Evaluation Change via Fsutil production (source)
- Windows System Binary Proxy Execution Compiled HTML File Decompile production (source)
- Windows System Discovery Using ldap Nslookup production (source)
- Windows System Discovery Using Qwinsta production (source)
- Windows System LogOff Commandline production (source)
- Windows System Network Config Discovery Display DNS production (source)
- Windows System Network Connections Discovery Netsh production (source)
- Windows System Reboot CommandLine production (source)
- Windows System Remote Discovery With Query production (source)
- Windows System Script Proxy Execution Syncappvpublishingserver production (source)
- Windows System Shutdown CommandLine production (source)
- Windows System Time Discovery W32tm Delay production (source)
- Windows System User Discovery Via Quser production (source)
- Windows System User Privilege Discovery production (source)
- Windows TeamCity Payload Execution from Temp Directory production (source)
- Windows Time Based Evasion via Choice Exec production (source)
- Windows TinyCC Shellcode Execution production (source)
- Windows TOR Client Execution production (source)
- Windows UAC Bypass Suspicious Child Process production (source)
- Windows Unusual SysWOW64 Process Run System32 Executable production (source)
- Windows User Deletion Via Net production (source)
- Windows User Disabled Via Net production (source)
- Windows User Discovery Via Net production (source)
- Windows WBAdmin File Recovery From Backup production (source)
- Windows WinDBG Spawning AutoIt3 production (source)
- Windows WinRAR Launched Outside Default Installation Directory production (source)
- Windows WMI Process And Service List production (source)
- Windows WMI Process Call Create production (source)
- Windows WMI Reconnaissance Class Query production (source)
- Windows Wmic CPU Discovery production (source)
- Windows Wmic DiskDrive Discovery production (source)
- Windows Wmic Memory Chip Discovery production (source)
- Windows Wmic Network Discovery production (source)
- Windows Wmic Systeminfo Discovery production (source)
- Windows WSUS Spawning Shell production (source)
- Winhlp32 Spawning a Process production (source)
- WinRAR Spawning Shell Application production (source)
- WinRM Spawning a Process experimental (source)
- WinRM Tools (Windows Event Log) (source)
- WinSCP Execution (Windows Event Log) (source)
- WMI subscription execution (Windows Event Log) (source)
- WMIC Explicit Credentials (Windows Event Log) (source)
- Wmic Group Discovery production (source)
- WMIC Host Reconniassance (Windows Event Log) (source)
- Wmic NonInteractive App Uninstallation production (source)
- WMIC XSL Execution via URL production (source)
- Wmiprvse LOLBAS Execution Process Spawn production (source)
- WmiPrvSE Suspicious Child Process (Windows Event Log) (source)
- Wow6432Node Classes Autorun Keys Modification (Windows Event Log) (source)
- Wscript Or Cscript Suspicious Child Process production (source)
- Wscript_Cscript Execution (Windows Event Log) (source)
- Wsmprovhost LOLBAS Execution Process Spawn production (source)
- XSL Script Execution With WMIC production (source)
Event ID 4698 A scheduled task was created. 16 rules
- Hidden Scheduled Task Created - Windows (Windows Event Log) (source)
- Impacket atexec.py Scheduled Task Creation (Windows Event Log) (source)
- Randomly Generated Scheduled Task Name experimental (source)
- Rare Schedule Task Created (Windows Event Log) (source)
- Rare Scheduled Task (Windows Event Log) (source)
- Schedule Task with HTTP Command Arguments production (source)
- Schedule Task with Rundll32 Command Trigger production (source)
- Scheduled Task with Potential SSH Tunnel - Windows (Windows Event Log) (source)
- Short Lived Scheduled Task production (source)
- Windows Hidden Schedule Task Settings production (source)
- Windows Level RMM Watchdog Task Created production (source)
- Windows Scheduled Task with Suspicious Command production (source)
- Windows Scheduled Task with Suspicious Name production (source)
- Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr production (source)
- WinEvent Scheduled Task Created to Spawn Shell production (source)
- WinEvent Scheduled Task Created Within Public Path production (source)
Event ID 4699 A scheduled task was deleted. 1 rule
- Short Lived Scheduled Task production (source)
Event ID 4725 A user account was disabled. 2 rules
- Windows Increase in User Modification Activity production (source)
- Windows Multiple Accounts Disabled production (source)
Event ID 4726 A user account was deleted. 3 rules
- Short Lived Windows Accounts production (source)
- Windows Increase in User Modification Activity production (source)
- Windows Multiple Accounts Deleted production (source)
Event ID 4738 A user account was changed. 6 rules
- Kerberos Pre-Authentication Flag Disabled in UserAccountControl production (source)
- Rubeus Password Change (Windows Event Log) (source)
- Windows AD Cross Domain SID History Addition production (source)
- Windows AD Privileged Account SID History Addition production (source)
- Windows AD Same Domain SID History Addition production (source)
- Windows Increase in User Modification Activity production (source)
Event ID 4742 A computer account was changed. 7 rules
- Detect Computer Changed with Anonymous Account production (source)
- Windows AD Cross Domain SID History Addition production (source)
- Windows AD Domain Controller Promotion production (source)
- Windows AD Privileged Account SID History Addition production (source)
- Windows AD Same Domain SID History Addition production (source)
- Windows Computer Account Changed to Domain Controller production (source)
- ZeroLogon CVE-2020-1472 (Windows Event Log) (source)
Event ID 4744 A security-disabled local group was created. 1 rule
- Windows Privileged Group Modification production (source)
Event ID 4749 A security-disabled global group was created. 1 rule
- Windows Privileged Group Modification production (source)
Event ID 4754 A security-enabled universal group was created. 1 rule
- Windows Privileged Group Modification production (source)
Event ID 4756 A member was added to a security-enabled universal group. 1 rule
- Windows Privileged Group Modification production (source)
Event ID 4759 A security-disabled universal group was created. 1 rule
- Windows Privileged Group Modification production (source)
Event ID 4768 A Kerberos authentication ticket (TGT) was requested. 11 rules
- Kerberos TGT Request Using RC4 Encryption production (source)
- Kerberos User Enumeration production (source)
- PetitPotam Suspicious Kerberos TGT Request production (source)
- Suspicious Certificate Authentication (Windows Event Log) (source)
- Suspicious Ticket Granting Ticket Request production (source)
- Windows Computer Account Requesting Kerberos Ticket production (source)
- Windows Multiple Disabled Users Failed To Authenticate Wth Kerberos production (source)
- Windows Multiple Invalid Users Fail To Authenticate Using Kerberos production (source)
- Windows Steal Authentication Certificates - ESC1 Authentication production (source)
- Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos production (source)
- Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos production (source)
Event ID 4769 A Kerberos service ticket was requested. 6 rules
- Kerberoasting spn request with RC4 encryption production (source)
- Kerberos Service Ticket Request Using RC4 Encryption production (source)
- Suspicious Kerberos Service Ticket Request production (source)
- Unusual Number of Computer Service Tickets Requested experimental (source)
- Unusual Number of Kerberos Service Tickets Requested production (source)
- Windows Large Number of Computer Service Tickets Requested production (source)
Event ID 4776 The domain controller attempted to validate the credentials for an account. 5 rules
- Potential EternalBlue via Metasploit (Windows Event Log) (source)
- Windows Multiple Invalid Users Failed To Authenticate Using NTLM production (source)
- Windows Multiple Users Failed To Authenticate From Host Using NTLM production (source)
- Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM production (source)
- Windows Unusual Count Of Users Failed To Authenticate Using NTLM production (source)
Event ID 4781 The name of an account was changed. 2 rules
- Suspicious Computer Account Name Change production (source)
- Suspicious Ticket Granting Ticket Request production (source)
Event ID 4783 A basic application group was created. 1 rule
- Windows Privileged Group Modification production (source)
Event ID 4790 An LDAP query group was created. 1 rule
- Windows Privileged Group Modification production (source)
Event ID 4794 An attempt was made to set the Directory Services Restore Mode administrator password. 1 rule
- Windows AD DSRM Password Reset production (source)
Event ID 4946 A change has been made to Windows Firewall exception list. A rule was added. 1 rule
- Windows Firewall Rule Added production (source)
Event ID 4947 A change has been made to Windows Firewall exception list. A rule was modified. 1 rule
- Windows Firewall Rule Modification production (source)
Event ID 4948 A change has been made to Windows Firewall exception list. A rule was deleted. 1 rule
- Windows Firewall Rule Deletion production (source)
Event ID 5136 A directory service object was modified. 24 rules
- Modify Group Policy (Windows Event Log) (source)
- Windows AD AdminSDHolder ACL Modified production (source)
- Windows AD Dangerous Deny ACL Modification production (source)
- Windows AD Dangerous Group ACL Modification production (source)
- Windows AD Dangerous User ACL Modification production (source)
- Windows AD DCShadow Privileges ACL Addition production (source)
- Windows AD Domain Replication ACL Addition production (source)
- Windows AD Domain Root ACL Deletion production (source)
- Windows AD Domain Root ACL Modification production (source)
- Windows AD GPO Deleted production (source)
- Windows AD GPO Disabled production (source)
- Windows AD GPO New CSE Addition production (source)
- Windows AD Hidden OU Creation production (source)
- Windows AD Object Owner Updated production (source)
- Windows AD Self DACL Assignment production (source)
- Windows AD ServicePrincipalName Added To Domain Account production (source)
- Windows AD Short Lived Domain Account ServicePrincipalName production (source)
- Windows AD Short Lived Domain Controller SPN Attribute production (source)
- Windows AD SID History Attribute Modified production (source)
- Windows AD Suspicious Attribute Modification production (source)
- Windows Default Group Policy Object Modified production (source)
- Windows Group Policy Object Created production (source)
- Windows Kerberos Coercion via DNS production (source)
- Windows Short Lived DNS Record production (source)
Event ID 5140 A network share object was accessed. 8 rules
- Meterpreter Reverse Shell (Windows Event Log) (source)
- Network Share Discovery Via Dir Command production (source)
- Potential SMB Activity from External IP - Windows (Windows Event Log) (source)
- SMB Write Access on Administrative Share (Windows Event Log) (source)
- Windows Admin$ Share Access (Windows Event Log) (source)
- Windows Administrative Shares Accessed On Multiple Hosts production (source)
- Windows C$ Share Access (Windows Event Log) (source)
- Windows IPC$ Share Access (Windows Event Log) (source)
Event ID 5145 A network share object was checked to see whether client can be granted desired access. 16 rules
- Certificate Enumeration - Windows (Windows Event Log) (source)
- Command Output Redirected to Localhost (Windows Event Log) (source)
- Executable File Written in Administrative SMB Share production (source)
- High Frequency Copy Of Files In Network Share production (source)
- Impacket PSexec (Windows Event Log) (source)
- PetitPotam Network Share Access Request production (source)
- Potential SMB Activity from External IP - Windows (Windows Event Log) (source)
- SecretsDump Credential Harvest (Windows Event Log) (source)
- SMB Write Access on Administrative Share (Windows Event Log) (source)
- Suspicious Spool Authentication (Windows Event Log) (source)
- Windows Admin$ Share Access (Windows Event Log) (source)
- Windows Administrative Shares Accessed On Multiple Hosts production (source)
- Windows C$ Share Access (Windows Event Log) (source)
- Windows IPC$ Share Access (Windows Event Log) (source)
- Windows Scheduled Task Created in a Group Policy Object production (source)
- Windows Share Multiple File Access (Windows Event Log) (source)
Event ID 5156 The Windows Filtering Platform has permitted a connection. 13 rules
- Command and Control Detection (Windows Event Log) (source)
- Internal Port Scan - Critical Ports (Windows Event Log) (source)
- Meterpreter Reverse Shell (Windows Event Log) (source)
- Network Connection with Suspicious Folder (Windows Event Log) (source)
- Potential CVE-2024-21413: Outbound SMB from Outlook (Windows Event Log) (source)
- Potential network connection with CVE-2023-21554 (Windows Event Log) (source)
- Process Connection to Mega - Windows (Windows Event Log) (source)
- PuTTY Secure Copy Client Execution (Windows Event Log) (source)
- RDP Brute-force Detection (Windows Event Log) (source)
- RDP Connection (Windows Event Log) (source)
- Script Connected to External Destination - Windows (Windows Event Log) (source)
- Unexpected Network Connection from System Process (Windows Event Log) (source)
- wuauclt.exe Network Connection (Windows Event Log) (source)
Microsoft-Windows-Sysmon
Event ID 1 Process creation 826 rules
- .msc Executed from Unusual Location (Sysmon) (source)
- 3CXDesktopApp.exe Execution (EDR) (source)
- 3CXDesktopApp.exe Execution (Sysmon) (source)
- 7zip CommandLine To SMB Share Path production (source)
- Abuse EQNEDT32.EXE (EDR) (source)
- Abuse EQNEDT32.EXE (Sysmon) (source)
- Access Common Package Config file (EDR) (source)
- Access Common Package Config file (Sysmon) (source)
- Account set to active via Net.exe (EDR) (source)
- Account set to active via Net.exe (Sysmon) (source)
- Add or Set Windows Defender Exclusion production (source)
- ADExplorer Execution (Sysmon) (source)
- ADExplorer Snapshot Creation (Sysmon) (source)
- Adfind Commands (Sysmon) (source)
- Adfind Execution (EDR) (source)
- Adfind Execution (Sysmon) (source)
- Advanced IP or Port Scanner Execution production (source)
- Advanced IP Scanner Execution (Sysmon) (source)
- Advanced Port Scanner Execution (Sysmon) (source)
- Allow File And Printing Sharing In Firewall production (source)
- Allow Network Discovery In Firewall production (source)
- Anomalous usage of 7zip production (source)
- AnyDesk Command Line Execution (Sysmon) (source)
- AnyDesk Execution from Suspicious Folder (Sysmon) (source)
- AnyDesk Silent Install (Sysmon) (source)
- Application Discovery - Windows (Sysmon) (source)
- ATBroker.exe Execution (Sysmon) (source)
- Attacker Tools On Endpoint production (source)
- Attempted Veeam Database Credential Dump (Sysmon) (source)
- Attrib.exe Metasploit File Dropper (EDR) (source)
- Attrib.exe Metasploit File Dropper (Sysmon) (source)
- AutoHotkey Execution (Sysmon) (source)
- AutoIt Execution (Sysmon) (source)
- Bash -c Execution - Windows (Sysmon) (source)
- Bcdedit Command Back To Normal Mode Boot production (source)
- BCDEdit Failure Recovery Modification production (source)
- BITS Job Persistence production (source)
- BITSAdmin Download File production (source)
- BITSadmin Execution (Sysmon) (source)
- BitsAdmin NetCat PowerCat File Transfer (EDR) (source)
- BitsAdmin NetCat PowerCat File Transfer (Sysmon) (source)
- Browser Started with Remote Debugging - Windows (Sysmon) (source)
- CDB Execution (Sysmon) (source)
- Certificate Abuse - Windows (Sysmon) (source)
- Certutil De-Obfuscate_Decode Files (Sysmon) (source)
- Certutil exe certificate extraction production (source)
- Certutil Execution (Sysmon) (source)
- Certutil File Download (Sysmon) (source)
- Certutil Obfuscate_Encode Files (EDR) (source)
- Certutil Obfuscate_Encode Files (Sysmon) (source)
- CertUtil With Decode Argument production (source)
- Change To Safe Mode With Network Config production (source)
- Check Elevated CMD using whoami production (source)
- Child Processes of Spoolsv exe experimental (source)
- Cipher.exe Execution (Sysmon) (source)
- Clear Unallocated Sector Using Cipher App production (source)
- Clop Common Exec Parameter production (source)
- CMD Carry Out String Command Parameter production (source)
- CMD Echo Pipe - Escalation production (source)
- CMD execution with _c (Sysmon) (source)
- Cmstp Execution (Sysmon) (source)
- Command Line .cmd Execution (Sysmon) (source)
- Command Line Homoglyphs - Windows (Sysmon) (source)
- Command Line lsass request (Sysmon) (source)
- Command Line Spawned by Archive Utility - Windows (Sysmon) (source)
- Command Line Utility Added to Accessibility Features (Sysmon) (source)
- Command-Line Interface Execution (Sysmon) (source)
- Common Active Directory Commands (Sysmon) (source)
- Common Recon Commands in Short Burst (Sysmon) (source)
- Common Reconnaissance Commands (Sysmon) (source)
- ComputerDefaults UAC Bypass (Sysmon) (source)
- comsvcs.dll Lsass Memory Dump (Sysmon) (source)
- Conhost.exe Kernel call (Sysmon) (source)
- Consent.exe Suspicious Child Process (Sysmon) (source)
- ConsentPromptBehaviorAdmin Registry Value Modified (Sysmon) (source)
- Conti Common Exec parameter production (source)
- Control Loading from World Writable Directory production (source)
- Control Panel Abuse (Sysmon) (source)
- Control_RunDLL Call from Command Line (Sysmon) (source)
- Create or delete windows shares using net exe production (source)
- Create_Add Local_Domain User (EDR) (source)
- Create_Add Local_Domain User (Sysmon) (source)
- Create_Modify Schtasks (Sysmon) (source)
- Creation of Shadow Copy production (source)
- Creation of Shadow Copy with wmic and powershell production (source)
- Credential Dumping via Copy Command from Shadow Copy production (source)
- Credential Dumping via Symlink to Shadow Copy production (source)
- CSC Execution (EDR) (source)
- CSC Net On The Fly Compilation production (source)
- CSVDE Export Active Directory (Sysmon) (source)
- Curl Execution with Percent Encoded URL production (source)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (EDR) (source)
- CVE-2022-30190: Microsoft Office Code Execution Vulnerability (Sysmon) (source)
- Data Exfiltration via AWS CLI - Windows (Sysmon) (source)
- Data Staged to File (Sysmon) (source)
- Defender Registry Values Modified (Sysmon) (source)
- Deleting Shadow Copies production (source)
- Detect AzureHound Command-Line Arguments production (source)
- Detect Certify Command Line Arguments production (source)
- Detect HTML Help Renamed production (source)
- Detect HTML Help Spawn Child Process production (source)
- Detect HTML Help URL in Command Line production (source)
- Detect HTML Help Using InfoTech Storage Handlers production (source)
- Detect mshta inline hta execution production (source)
- Detect mshta renamed production (source)
- Detect MSHTA Url in Command Line production (source)
- Detect Outlook exe writing a zip file production (source)
- Detect Path Interception By Creation Of program exe production (source)
- Detect Prohibited Applications Spawning cmd exe production (source)
- Detect PsExec With accepteula Flag production (source)
- Detect Rare Executables production (source)
- Detect RClone Command-Line Usage production (source)
- Detect Regasm Spawning a Process production (source)
- Detect Regasm with no Command Line Arguments production (source)
- Detect Regsvcs Spawning a Process production (source)
- Detect Regsvcs with No Command Line Arguments production (source)
- Detect Regsvr32 Application Control Bypass production (source)
- Detect Remote Access Software Usage FileInfo production (source)
- Detect Remote Access Software Usage Process production (source)
- Detect Renamed 7-Zip production (source)
- Detect Renamed PSExec production (source)
- Detect Renamed RClone production (source)
- Detect Renamed WinRAR production (source)
- Detect RTLO In Process production (source)
- Detect Rundll32 Inline HTA Execution production (source)
- Detect SharpHound Command-Line Arguments production (source)
- Detect SharpHound Usage production (source)
- Detect Use of cmd exe to Launch Script Interpreters production (source)
- Detection of tools built by NirSoft experimental (source)
- Disable Logs Using WevtUtil production (source)
- Disable Schedule Task production (source)
- Disabling Firewall with Netsh production (source)
- Discovery using CHCP (Sysmon) (source)
- DLL Called with RS32 (Sysmon) (source)
- DLL Called with Uncommon Function (Sysmon) (source)
- DLL Concatenation (Sysmon) (source)
- DLL Execution from Uncommon Process (Sysmon) (source)
- DLLHost with no Command Line Arguments with Network production (source)
- DLLRegisterServer Called from Command Line (Sysmon) (source)
- DNS Exfiltration Using Nslookup App production (source)
- Domain Account Discovery with Dsquery production (source)
- Domain Account Discovery with Wmic production (source)
- Domain Controller Discovery with Nltest production (source)
- Domain Controller Discovery with Wmic production (source)
- Domain Controller Enumeration via nltest (Sysmon) (source)
- Domain Group Discovery With Dsquery production (source)
- Domain Group Discovery With Wmic production (source)
- DSQuery Domain Discovery production (source)
- Dump File Identified (Sysmon) (source)
- Dump LSASS via comsvcs DLL production (source)
- Dump LSASS via procdump production (source)
- Elevated Group Discovery With Wmic production (source)
- EnableLUA Registry Value Modified (Sysmon) (source)
- Encoded Powershell Command (Sysmon) (source)
- Esentutl Execution (Sysmon) (source)
- Esentutl SAM Copy production (source)
- Esentutl.exe Collecting Browser Data (Sysmon) (source)
- Event Logs Queried for RDP Sessions (Sysmon) (source)
- Excessive Attempt To Disable Services production (source)
- Excessive distinct processes from Windows Temp production (source)
- Excessive number of service control start as disabled production (source)
- Excessive number of taskhost processes production (source)
- Excessive Usage Of Cacls App production (source)
- Excessive Usage of NSLOOKUP App production (source)
- Excessive Usage Of SC Service Utility production (source)
- Excessive Usage Of Taskkill production (source)
- Executable Create Script Process (Sysmon) (source)
- Executable Process from Suspicious Folder (Sysmon) (source)
- Execute Javascript With Jscript COM CLSID production (source)
- Execution from Startup Folder (Sysmon) (source)
- Execution of File with Multiple Extensions production (source)
- Exfiltration via curl.exe - Windows (Sysmon) (source)
- Expand.exe Execution (Sysmon) (source)
- Explorer Child Process with Suspicious Command Line Padding (Sysmon) (source)
- File and Directory Discovery Output to File - Windows (Sysmon) (source)
- File Download or Read to Pipe Execution production (source)
- File Executed from INetCache (Sysmon) (source)
- File_Folder Hidden - Windows (Sysmon) (source)
- Finger Execution (Sysmon) (source)
- Firewall Allowed Program Enable production (source)
- First Time Seen Child Process of Zoom experimental (source)
- FodHelper UAC Bypass production (source)
- FScan.exe Network Scan (Sysmon) (source)
- Fsutil fsinfo execution (EDR) (source)
- Fsutil Zeroing File production (source)
- Full Control Permissions Granted to Everyone - Windows (Sysmon) (source)
- Get ADDefaultDomainPasswordPolicy with Powershell production (source)
- Get ADUser with PowerShell production (source)
- Get ADUserResultantPasswordPolicy with Powershell production (source)
- Get DomainPolicy with Powershell production (source)
- Get DomainUser with PowerShell production (source)
- Get WMIObject Group Discovery production (source)
- Get-DomainTrust with PowerShell production (source)
- Get-ForestTrust with PowerShell production (source)
- GetAdComputer with PowerShell production (source)
- GetAdGroup with PowerShell production (source)
- GetCurrent User with PowerShell production (source)
- GetDomainComputer with PowerShell production (source)
- GetDomainController with PowerShell production (source)
- GetDomainGroup with PowerShell production (source)
- GetLocalUser with PowerShell production (source)
- GetNetTcpconnection with PowerShell production (source)
- GetWmiObject Ds Computer with PowerShell production (source)
- GetWmiObject Ds Group with PowerShell production (source)
- GetWmiObject DS User with PowerShell production (source)
- GetWmiObject User Account with PowerShell production (source)
- Git Hooks Spawn System32 Process (Sysmon) (source)
- Git Spawns System32 Process (Sysmon) (source)
- Git Submodule Cloned - Windows (Sysmon) (source)
- Go Run Execution (Sysmon) (source)
- GPUpdate with no Command Line Arguments with Network production (source)
- Group Policy Editor Execution (Sysmon) (source)
- Headless Browser Mockbin or Mocky Request production (source)
- Headless Browser Usage production (source)
- hh.exe Execution (Sysmon) (source)
- hh.exe Remote File Execution (Sysmon) (source)
- Hidden User Created - Windows (Sysmon) (source)
- Hiding Files And Directories With Attrib exe production (source)
- Hunting 3CXDesktopApp Software production (source)
- Icacls Deny Command production (source)
- ICACLS Grant Command production (source)
- IcedID Discovery Commands (EDR) (source)
- IcedID Discovery Commands (Sysmon) (source)
- Impacket atexec.py Execution (Sysmon) (source)
- Impacket Lateral Movement Activity (Sysmon) (source)
- Impacket Lateral Movement Commandline Parameters production (source)
- Impacket Lateral Movement smbexec CommandLine Parameters production (source)
- Impacket Lateral Movement WMIExec Commandline Parameters production (source)
- Indirect Command Execution (Sysmon) (source)
- Invoke-DCOM.ps1 - PowerShell (Sysmon) (source)
- Invoke-Expression Command (Sysmon) (source)
- Invoke-WebRequest Command (Sysmon) (source)
- Jscript Execution Using Cscript App production (source)
- Known Process Injection Commands (Sysmon) (source)
- Live Sysinternals Execution (Sysmon) (source)
- Local Account Discovery With Wmic production (source)
- LocalAccountTokenFilterPolicy Registry Value Modified (Sysmon) (source)
- Locate Credentials (Sysmon) (source)
- Logon Script Registry Key added (EDR) (source)
- Logon Script Registry Key added (Sysmon) (source)
- MacOS - Re-opened Applications experimental (source)
- Malicious Document Execution (Sysmon) (source)
- Malicious PowerShell Process - Encoded Command production (source)
- Malicious PowerShell Process - Execution Policy Bypass production (source)
- Malicious PowerShell Process With Obfuscation Techniques production (source)
- masscan Execution - Windows (Sysmon) (source)
- Mavinject Execution (EDR) (source)
- Mavinject Execution (Sysmon) (source)
- Mega Utility Execution - Windows (Sysmon) (source)
- Microsoft Build Engine Suspicious Parent Process (Sysmon) (source)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (EDR) (source)
- Microsoft Diagnostic Tool "DogWalk" Package Path Traversal (Sysmon) (source)
- Microsoft SQL Server Suspicious Child Process - Windows (Sysmon) (source)
- Mimikatz (Sysmon) (source)
- Mimikatz PassTheTicket CommandLine Parameters production (source)
- Mmc LOLBAS Execution Process Spawn production (source)
- Mock System Directory - Windows (Sysmon) (source)
- Modify ACL permission To Files Or Folder production (source)
- Modify Windows Defender (EDR) (source)
- Modify Windows Defender (Sysmon) (source)
- MS Exchange Mailbox Replication service writing Active Server Pages experimental (source)
- MSBuild Suspicious Spawned By Script Process production (source)
- Mshta spawning Rundll32 OR Regsvr32 Process production (source)
- MSHTA.exe execution (Sysmon) (source)
- mshta.exe File Download (Sysmon) (source)
- MSI Installation via Appcert (Sysmon) (source)
- Msiexec Abuse (Sysmon) (source)
- MSIExec Install MSI File (Sysmon) (source)
- MSIExec.exe Execution (Sysmon) (source)
- MSTSC Execution (EDR) (source)
- Msxsl Execution (EDR) (source)
- Msxsl Execution (Sysmon) (source)
- MultiDump.exe Execution (Sysmon) (source)
- Multiple nslookup commands (Sysmon) (source)
- Native Archive Commands (Sysmon) (source)
- Net.exe Use with URL (Sysmon) (source)
- Network Connection Discovery With Arp production (source)
- Network Connection Discovery With Netstat production (source)
- Network Discovery Using Route Windows App production (source)
- ngen.exe File Download (Sysmon) (source)
- ngrok Execution - Windows (Sysmon) (source)
- NirCmd Execution (Sysmon) (source)
- Nishang PowershellTCPOneLine production (source)
- NLTest Domain Trust Discovery production (source)
- NMAP Execution (EDR) (source)
- Notepad with no Command Line Arguments production (source)
- ntds.dit Access from Unexpected Location (Sysmon) (source)
- ntds.dit Command Line (Sysmon) (source)
- Ntdsutil Export NTDS production (source)
- NTDSUtil.exe execution (Sysmon) (source)
- Office Spawns Suspicious Child Process (Sysmon) (source)
- Outbound Network Connection from Java Using Default Ports production (source)
- Package installation (Sysmon) (source)
- Parent in Public Folder Suspicious Process (Sysmon) (source)
- Permission Groups Discovery: Domain Groups (Sysmon) (source)
- Permission Groups Discovery: Local Groups (Sysmon) (source)
- Permission Modification using Takeown App production (source)
- Permissions Replaced by icacls - Windows (Sysmon) (source)
- Ping Sleep Batch Command production (source)
- Possible Browser Pass View Parameter production (source)
- Possible Lateral Movement PowerShell Spawn production (source)
- Potential AutoHotkey .ahk Execution (Sysmon) (source)
- Potential Cryptomining Commands (Sysmon) (source)
- Potential CVE-2023-23397 (EDR) (source)
- Potential CVE-2023-23397 (Sysmon) (source)
- Potential Executable Masquerading as Document - Windows (Sysmon) (source)
- Potential fodhelper UAC Bypass Attempt (Sysmon) (source)
- Potential PowerShell Post-Exploitation Activity (Sysmon) (source)
- Potential Proxy Malware via AutoRun Key (Sysmon) (source)
- Potential Sysinternals Tool Execution (Sysmon) (source)
- Potential System Network Configuration Discovery Activity production (source)
- Potential Telegram API Request Via CommandLine production (source)
- PowerHuntShares Commands (Sysmon) (source)
- PowerShell - Connect To Internet With Hidden Window production (source)
- PowerShell CreateDecryptor (Sysmon) (source)
- Powershell Disable Security Monitoring production (source)
- PowerShell DownloadFile_DownloadString (Sysmon) (source)
- PowerShell Get LocalGroup Discovery production (source)
- PowerShell Modifying Registry Values (Sysmon) (source)
- PowerShell Start-BitsTransfer production (source)
- PowerShell XML Retrieval (Sysmon) (source)
- Prevent Automatic Repair Mode using Bcdedit production (source)
- ProcDump Credential Harvest (Sysmon) (source)
- Process Creation Using Sysnative Folder (Sysmon) (source)
- Process Deleting Its Process File Path production (source)
- Process Executed from Downloads Folder - Windows (Sysmon) (source)
- Process Executed with Null Command Line (Sysmon) (source)
- Process Execution From Suspicious Folder (Sysmon) (source)
- Process Execution via WMI production (source)
- Process Kill Base On File Path production (source)
- PromptOnSecureDesktop Registry Value Modified (Sysmon) (source)
- ProtocolHandler.exe File Download (Sysmon) (source)
- Proxy Execution via Appcert (Sysmon) (source)
- PuTTY Secure Copy Client Execution (Sysmon) (source)
- QEMU Network Tunneling - Windows (Sysmon) (source)
- Radmin execution (EDR) (source)
- Radmin execution (Sysmon) (source)
- Rare executable from Microsoft Office (Sysmon) (source)
- Rare Process Execution (Sysmon) (source)
- Rclone Execution (Sysmon) (source)
- RDP Enabled (Sysmon) (source)
- RDP File Executed from Outlook Temp Directory (Sysmon) (source)
- RdrLeakDiag.exe Memory Dump (Sysmon) (source)
- Read-Only Attribute Removed - Windows (Sysmon) (source)
- Recursive Delete of Directory In Batch CMD production (source)
- Reg exe Manipulating Windows Services Registry Keys production (source)
- Reg.exe Process Execution (Sysmon) (source)
- Regini.exe Execution (Sysmon) (source)
- Registry key added with reg.exe (Sysmon) (source)
- regsvr32 Execution (Sysmon) (source)
- regsvr32 Referencing Unusual Paths (Sysmon) (source)
- Regsvr32 Silent and Install Param Dll Loading production (source)
- Regsvr32 with Known Silent Switch Cmdline production (source)
- Remote .msi Installation (Sysmon) (source)
- Remote .msi Installation (Sysmon) (source)
- Remote Access Software Execution (Sysmon) (source)
- Remote Admin Tools (EDR) (source)
- Remote Admin Tools (Sysmon) (source)
- Remote Desktop Process Running On System experimental (source)
- Remote Process Instantiation via DCOM and PowerShell production (source)
- Remote Process Instantiation via WinRM and PowerShell production (source)
- Remote Process Instantiation via WinRM and Winrs production (source)
- Remote Process Instantiation via WMI production (source)
- Remote Process Instantiation via WMI and PowerShell production (source)
- Remote Share Directory Listing - Windows (Sysmon) (source)
- Remote System Discovery with Dsquery production (source)
- Remote System Discovery with Wmic production (source)
- Remote WMI Command Attempt production (source)
- Renamed Process (Sysmon) (source)
- Resize ShadowStorage volume production (source)
- Revil Common Exec Parameter production (source)
- Rubeus Command Line Parameters production (source)
- Rubeus Commands (Sysmon) (source)
- Runas Execution in CommandLine production (source)
- RunDLL Loading DLL By Ordinal production (source)
- Rundll32 Command Line (Sysmon) (source)
- Rundll32 Control RunDLL Hunt production (source)
- Rundll32 Control RunDLL World Writable Directory production (source)
- Rundll32 LockWorkStation production (source)
- Rundll32 Shimcache Flush production (source)
- Rundll32 Spawned by Disk Cleanup (Sysmon) (source)
- Rundll32 Suspicious Command Line (Sysmon) (source)
- rundll32 Suspicious Parent Process (Sysmon) (source)
- Rundll32 with no Command Line Arguments with Network production (source)
- rundll32 with No DLL in Command Line (Sysmon) (source)
- Rundll32.exe as Parent Process (Sysmon) (source)
- rundll32.exe Executing DLL from Non-standard Directory (Sysmon) (source)
- Ryuk Wake on LAN Command production (source)
- Scheduled Task Creation on Remote Endpoint using At production (source)
- Scheduled Task Deleted Or Created via CMD production (source)
- Scheduled Task Initiation on Remote Endpoint production (source)
- Scheduled Task with Potential SSH Tunnel - Windows (Sysmon) (source)
- Schtasks Run Task On Demand production (source)
- Schtasks scheduling job on remote system production (source)
- Schtasks used for forcing a reboot production (source)
- Script Execution via WMI production (source)
- Sdelete Application Execution production (source)
- SearchProtocolHost with no Command Line with Network production (source)
- SecretDumps Offline NTDS Dumping Tool production (source)
- Security Software Discovery via Findstr.exe (Sysmon) (source)
- Security Software Discovery via WMI (Sysmon) (source)
- Service Stop Commands (Sysmon) (source)
- ServicePrincipalNames Discovery with SetSPN production (source)
- Services Escalate Exe production (source)
- Services LOLBAS Execution Process Spawn production (source)
- Shim Database Installation With Suspicious Parameters production (source)
- SimpleHelp Remote Access Tool Execution (Sysmon) (source)
- Single Letter Process On Endpoint production (source)
- Sliver C2 Implant Activity Pattern (Sysmon) (source)
- SLUI RunAs Elevated production (source)
- SLUI Spawning a Process production (source)
- SoftPerfect Network Scanner Execution (Sysmon) (source)
- Spoolsv Spawning Rundll32 production (source)
- Spoolsv Writing a DLL production (source)
- ssh.exe Execution (Sysmon) (source)
- Suspicious AteraAgent Installation - Windows (Sysmon) (source)
- Suspicious Child Process for hh.exe (Sysmon) (source)
- Suspicious Child Process for lsass.exe (Sysmon) (source)
- Suspicious Child Process for mshta.exe (Sysmon) (source)
- Suspicious ComputerDefaults.exe Execution (Sysmon) (source)
- Suspicious Confluence Child Process - Windows (Sysmon) (source)
- Suspicious Conhost.exe Commands (Sysmon) (source)
- Suspicious Copy on System32 production (source)
- Suspicious csc.exe Source File Folder (Sysmon) (source)
- Suspicious Curl Network Connection experimental (source)
- Suspicious DLLhost Execution (EDR) (source)
- Suspicious DLLHost no Command Line Arguments production (source)
- Suspicious Executable by CMD.exe (Sysmon) (source)
- Suspicious Executable by Powershell (EDR) (source)
- Suspicious Executable by Powershell (Sysmon) (source)
- Suspicious Execution of Accessibility Tool Debuggers (Sysmon) (source)
- Suspicious Execution via Microsoft Common Console (Sysmon) (source)
- Suspicious GPUpdate no Command Line Arguments production (source)
- Suspicious IcedID Rundll32 Cmdline production (source)
- Suspicious Image Creation In Appdata Folder production (source)
- Suspicious InprocServer32 Registry Modification (Sysmon) (source)
- Suspicious microsoft workflow compiler rename production (source)
- Suspicious microsoft workflow compiler usage production (source)
- Suspicious msbuild path production (source)
- Suspicious MSBuild Rename production (source)
- Suspicious MSBuild Spawn production (source)
- Suspicious mshta child process production (source)
- Suspicious mshta spawn production (source)
- Suspicious ntds.dit Commands (Sysmon) (source)
- Suspicious Parent Process for lsass.exe or services.exe (Sysmon) (source)
- Suspicious Parent Process for msiexec.exe (Sysmon) (source)
- Suspicious Parent Process for spoolsv.exe (Sysmon) (source)
- Suspicious PlistBuddy Usage experimental (source)
- Suspicious PowerShell Clipboard Activity (Sysmon) (source)
- Suspicious PowerShell Parameter Substring (Sysmon) (source)
- Suspicious Process Executed From Container File production (source)
- Suspicious reCAPTCHA Command Line (Sysmon) (source)
- Suspicious Reg exe Process production (source)
- Suspicious Regsvr32 Register Suspicious Path production (source)
- Suspicious Rundll32 dllregisterserver production (source)
- Suspicious Rundll32 no Command Line Arguments production (source)
- Suspicious Rundll32 PluginInit production (source)
- Suspicious Rundll32 StartW production (source)
- Suspicious Scheduled Task from Public Directory production (source)
- Suspicious SearchProtocolHost no Command Line Arguments production (source)
- Suspicious SQLite3 LSQuarantine Behavior experimental (source)
- Suspicious WAV file in Appdata Folder production (source)
- Suspicious wevtutil Usage production (source)
- Suspicious writes to windows Recycle Bin production (source)
- Svchost LOLBAS Execution Process Spawn production (source)
- System Enumeration with WMIC (Sysmon) (source)
- System Info Gathering Using Dxdiag Application production (source)
- System Information Discovery - Windows (Sysmon) (source)
- System Information Discovery Detection production (source)
- System Network Connections Discovery - Windows (Sysmon) (source)
- System Owner_User Discovery - Windows (Sysmon) (source)
- System Processes Run From Unexpected Locations production (source)
- System User Discovery With Query production (source)
- System User Discovery With Whoami production (source)
- Temporary File Executed from Public Folder (Sysmon) (source)
- Tunneling Process Created (Sysmon) (source)
- Uninstall App Using MsiExec production (source)
- Unknown Process Using The Kerberos Protocol production (source)
- Unload Sysmon Filter Driver production (source)
- Unusual AppCert Child Process (Sysmon) (source)
- Unusual svchost Child Process (Sysmon) (source)
- Unusual winlogon.exe Child Process (Sysmon) (source)
- Unusually Long Command Line experimental (source)
- User Discovery With Env Vars PowerShell production (source)
- User_Domain Enumeration Tool - Windows (Sysmon) (source)
- USN Journal Deletion production (source)
- Vbscript Execution Using Wscript App production (source)
- Verclsid CLSID Execution production (source)
- Visio.exe File Download (Sysmon) (source)
- Visual Studio Code Tunnel Execution (Sysmon) (source)
- WBAdmin Delete System Backups production (source)
- WDigest Forced Credential Caching (Sysmon) (source)
- Web or Application Server Spawning a Shell production (source)
- Web Servers Executing Suspicious Processes experimental (source)
- WebDAV LNK Execution (Sysmon) (source)
- WebLogic CVE-2017-10271 (Sysmon) (source)
- Wermgr Process Spawned CMD Or Powershell Process production (source)
- Windows Account Access Removal via Logoff Exec production (source)
- Windows AdFind Exe production (source)
- Windows Admin$ Share Access (Sysmon) (source)
- Windows Advanced Installer MSIX with AI_STUBS Execution production (source)
- Windows Alternate DataStream - Process Execution production (source)
- Windows Apache Benchmark Binary production (source)
- Windows AppCertDLL Modification Via Command Line production (source)
- Windows Application Whitelisting Bypass Attempt via Rundll32 production (source)
- Windows Archive Collected Data via Rar production (source)
- Windows Attempt To Stop Security Service production (source)
- Windows Audit Policy Auditing Option Disabled via Auditpol production (source)
- Windows Audit Policy Cleared via Auditpol production (source)
- Windows Audit Policy Disabled via Auditpol production (source)
- Windows Audit Policy Disabled via Legacy Auditpol production (source)
- Windows Audit Policy Excluded Category via Auditpol production (source)
- Windows Audit Policy Restored via Auditpol production (source)
- Windows Audit Policy Security Descriptor Tampering via Auditpol production (source)
- Windows AutoIt3 Execution production (source)
- Windows Azure Storage Utility Execution Via CLI production (source)
- Windows Binary Execution from an Archive experimental (source)
- Windows Binary Proxy Execution Mavinject DLL Injection production (source)
- Windows BitLocker Suspicious Command Usage production (source)
- Windows BitLockerToGo Process Execution production (source)
- Windows Browser Process Launched with Unusual Flags production (source)
- Windows Bypass UAC via Pkgmgr Tool production (source)
- Windows C$ Share Access (EDR) (source)
- Windows C$ Share Access (Sysmon) (source)
- Windows Cabinet File Extraction Via Expand production (source)
- Windows Cached Domain Credentials Reg Query production (source)
- Windows Certutil Root Certificate Addition production (source)
- Windows Change File Association Command To Notepad production (source)
- Windows Chrome Enable Extension Loading via Command-Line production (source)
- Windows Chromium Browser Launched with Small Window Size production (source)
- Windows Chromium Browser No Security Sandbox Process production (source)
- Windows Chromium Browser with Custom User Data Directory production (source)
- Windows Chromium process Launched with Disable Popup Blocking production (source)
- Windows Chromium Process Launched with Logging Disabled production (source)
- Windows Chromium Process Loaded Extension via Command-Line production (source)
- Windows Chromium Process with Disabled Extensions production (source)
- Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc production (source)
- Windows Cisco Secure Endpoint Unblock File Via Sfc production (source)
- Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc production (source)
- Windows Cmdline Tool Execution From Non-Shell Process production (source)
- Windows COM Hijacking InprocServer32 Modification production (source)
- Windows Command and Scripting Interpreter Hunting Path Traversal production (source)
- Windows Command and Scripting Interpreter Path Traversal Exec production (source)
- Windows Command Obfuscation with Environment Variable Substrings production (source)
- Windows Command Shell DCRat ForkBomb Payload production (source)
- Windows Compatibility Telemetry Suspicious Child Process production (source)
- Windows ComputerDefaults Spawning a Process production (source)
- Windows ConHost with Headless Argument production (source)
- Windows Copy Files (Sysmon) (source)
- Windows Create Local Administrator Account Via Net production (source)
- Windows Credential Dumping LSASS Memory Createdump production (source)
- Windows Credential Target Information Structure in Commandline production (source)
- Windows Credentials from Password Stores Creation production (source)
- Windows Credentials from Password Stores Deletion production (source)
- Windows Credentials from Password Stores Query production (source)
- Windows Credentials in Registry Reg Query production (source)
- Windows Crowdstrike RTR Script Execution production (source)
- Windows Curl Download to Suspicious Path production (source)
- Windows Curl Upload to Remote Destination production (source)
- Windows Debugger Tool Execution production (source)
- Windows Defacement Modify Transcodedwallpaper File production (source)
- Windows Default Group Policy Object Modified with GPME production (source)
- Windows Default RDP File Creation By Non MSTSC Process production (source)
- Windows Default Rdp File Unhidden production (source)
- Windows Defender ASR or Threat Configuration Tamper production (source)
- Windows Defender Disabled Detection (EDR) (source)
- Windows Delete or Modify System Firewall production (source)
- Windows Deleted Registry By A Non Critical Process File Path production (source)
- Windows Devtunnels Execution production (source)
- Windows Disable Internet Explorer Addons production (source)
- Windows Disable or Modify Tools Via Taskkill production (source)
- Windows Disable or Stop Browser Process production (source)
- Windows Disable Windows Event Logging Disable HTTP Logging production (source)
- Windows DiskCryptor Usage production (source)
- Windows Diskshadow Proxy Execution production (source)
- Windows DISM Install PowerShell Web Access production (source)
- Windows DISM Remove Defender production (source)
- Windows DLL Search Order Hijacking with iscsicpl production (source)
- Windows DLL Side-Loading Process Child Of Calc production (source)
- Windows DNS Gather Network Info production (source)
- Windows DotNet Binary in Non Standard Path production (source)
- Windows EDRSilencer Execution production (source)
- Windows EFI Volume Mount Attempt Via Mountvol production (source)
- Windows Entra User Management Via Azure CLI production (source)
- Windows ESX Admins Group Creation via Net production (source)
- Windows Eventlog Cleared Via Wevtutil production (source)
- Windows EventLog Recon Activity Using Log Query Utilities production (source)
- Windows Excel Spawning Microsoft Project Application production (source)
- Windows Excessive Service Stop Attempt production (source)
- Windows Excessive Usage Of Net App production (source)
- Windows Execute Arbitrary Commands with MSDT production (source)
- Windows Execution of Microsoft MSC File In Suspicious Path production (source)
- Windows Explorer LNK Exploit Process Launch With Padding production (source)
- Windows Explorer.exe Spawning PowerShell or Cmd production (source)
- Windows File and Directory Enable ReadOnly Permissions production (source)
- Windows File and Directory Permissions Enable Inheritance production (source)
- Windows File and Directory Permissions Remove Inheritance production (source)
- Windows File Association Modification via Ftype production (source)
- Windows File Collection Via Copy Utilities production (source)
- Windows File Download Via CertUtil production (source)
- Windows File Download Via PowerShell production (source)
- Windows Files and Dirs Access Rights Modification Via Icacls production (source)
- Windows Findstr GPP Discovery production (source)
- Windows Firewall Disabled (Sysmon) (source)
- Windows FTP Exfiltration (Sysmon) (source)
- Windows Gdrive Binary Activity production (source)
- Windows Get-Variable.EXE Execution from WindowsApps Folder production (source)
- Windows Global Object Access Audit List Cleared Via Auditpol production (source)
- Windows Group Discovery Via Net production (source)
- Windows Guest Account Enabled Via Net.EXE production (source)
- Windows HTTP Network Communication From MSIExec production (source)
- Windows Identify Protocol Handlers production (source)
- Windows IIS Components Add New Module production (source)
- Windows Impair Defense Add Xml Applocker Rules production (source)
- Windows Indicator Removal Via Rmdir production (source)
- Windows Indirect Command Execution Via forfiles production (source)
- Windows Indirect Command Execution Via pcalua production (source)
- Windows Indirect Command Execution Via Series Of Forfiles production (source)
- Windows Information Discovery Fsutil production (source)
- Windows Ingress Tool Transfer Using Explorer production (source)
- Windows InstallUtil in Non Standard Path production (source)
- Windows InstallUtil Remote Network Connection production (source)
- Windows InstallUtil Uninstall Option production (source)
- Windows InstallUtil URL in Command Line production (source)
- Windows IOBit Unlocker Extension DLL Registration via Regsvr32 production (source)
- Windows IPC$ Share Access (Sysmon) (source)
- Windows Ldifde Directory Object Behavior production (source)
- Windows List ENV Variables Via SET Command From Uncommon Parent production (source)
- Windows Local LLM Framework Execution production (source)
- Windows LOLBAS Executed As Renamed File production (source)
- Windows LOLBAS Executed Outside Expected Path production (source)
- Windows Masquerading Explorer As Child Process production (source)
- Windows Masquerading Msdtc Process production (source)
- Windows Metasploit Confluence Plugin Execution production (source)
- Windows Mimikatz Binary Execution production (source)
- Windows Modify Registry Qakbot Binary Data Registry production (source)
- Windows Modify Registry Regedit Silent Reg Import production (source)
- Windows Modify System Firewall with Notable Process Path production (source)
- Windows MOF Event Triggered Execution via WMI production (source)
- Windows MpCmdRun RemoveDefinitions Execution production (source)
- Windows MSC EvilTwin Directory Path Manipulation production (source)
- Windows MSIExec DLLRegisterServer production (source)
- Windows MsiExec HideWindow Rundll32 Execution production (source)
- Windows MSIExec Remote Download production (source)
- Windows MSIExec Spawn Discovery Command production (source)
- Windows MSIExec Spawn WinDBG production (source)
- Windows MSIExec Unregister DLLRegisterServer production (source)
- Windows MSTSC RDP Commandline production (source)
- Windows Mustang Panda USB Tool Execution production (source)
- Windows Net System Service Discovery production (source)
- Windows Netspy Network Scanner Execution production (source)
- Windows Network Connection Discovery Via Net production (source)
- Windows Network Share Interaction Via Net production (source)
- Windows New Deny Permission Set On Service SD Via Sc.EXE production (source)
- Windows New Service Security Descriptor Set Via Sc.EXE production (source)
- Windows Ngrok Reverse Proxy Usage production (source)
- Windows NirSoft AdvancedRun production (source)
- Windows NirSoft Utilities production (source)
- Windows NorthStar C2 Agent Execution production (source)
- Windows Odbcconf Hunting production (source)
- Windows Odbcconf Load DLL production (source)
- Windows Odbcconf Load Response File production (source)
- Windows Office Product Dropped Cab or Inf File production (source)
- Windows Office Product Dropped Uncommon File production (source)
- Windows Office Product Spawned Child Process For Download production (source)
- Windows Office Product Spawned Control production (source)
- Windows Office Product Spawned MSDT production (source)
- Windows Office Product Spawned Rundll32 With No DLL production (source)
- Windows Office Product Spawned Uncommon Process production (source)
- Windows OneDrive Share Mounted via Net production (source)
- Windows PaperCut NG Spawn Shell production (source)
- Windows Parent PID Spoofing with Explorer production (source)
- Windows Password Managers Discovery production (source)
- Windows Password Policy Discovery with Net production (source)
- Windows Phishing Outlook Drop Dll In FORM Dir production (source)
- Windows Phishing PDF File Executes URL Link production (source)
- Windows Potato Privilege Escalation Tool Execution production (source)
- Windows Potential Cloudflared Tunnel Execution production (source)
- Windows PowerShell FakeCAPTCHA Clipboard Execution production (source)
- Windows PowerShell Process Implementing Manual Base64 Decoder production (source)
- Windows PowerShell Process With Malicious String production (source)
- Windows Powershell RemoteSigned File production (source)
- Windows PowerShell Script From WindowsApps Directory production (source)
- Windows PowGoop Beacon Decoding production (source)
- Windows Private Keys Discovery production (source)
- Windows Privilege Escalation Attempt Via MSI Rollback production (source)
- Windows Privilege Escalation Suspicious Process Elevation production (source)
- Windows Privilege Escalation System Process Without System Parent production (source)
- Windows Privilege Escalation User Process Spawn System Process production (source)
- Windows Process Commandline Discovery production (source)
- Windows Process Copied from System Folder (Sysmon) (source)
- Windows Process Executed From Removable Media production (source)
- Windows Process Execution From ProgramData production (source)
- Windows Process Execution From RDP Share production (source)
- Windows Process Execution in Temp Dir production (source)
- Windows Process Injection In Non-Service SearchIndexer production (source)
- Windows Process Injection Wermgr Child Process production (source)
- Windows Process Outside of System Folder (Sysmon) (source)
- Windows Process With NamedPipe CommandLine production (source)
- Windows Process With NetExec Command Line Parameters production (source)
- Windows Protocol Tunneling with Plink production (source)
- Windows Proxy Execution of .NET Utilities via Scripts production (source)
- Windows Proxy Via Netsh production (source)
- Windows PsTools Recon Usage production (source)
- Windows PuTTY Suite Utility Execution production (source)
- Windows Raccine Scheduled Task Deletion production (source)
- Windows Rasautou DLL Execution production (source)
- Windows RDP Client Launched with Admin Session production (source)
- Windows RDP File Execution production (source)
- Windows Registry Entries Exported Via Reg production (source)
- Windows Registry Entries Restored Via Reg production (source)
- Windows Regsvr32 Renamed Binary production (source)
- Windows Remote Assistance Spawning Process production (source)
- Windows Remote Create Service production (source)
- Windows Remote Host Computer Management Access production (source)
- Windows Remote Management Execute Shell production (source)
- Windows Remote Service Rdpwinst Tool Execution production (source)
- Windows Remote Services Allow Rdp In Firewall production (source)
- Windows Renamed Powershell Execution production (source)
- Windows RMM Tool Execution production (source)
- Windows Rundll32 Apply User Settings Changes production (source)
- Windows Rundll32 Execution With Log.DLL production (source)
- Windows Rundll32 Load DLL in Temp Dir production (source)
- Windows Rundll32 WebDAV Request production (source)
- Windows Rundll32 WebDav With Network Connection production (source)
- Windows Rundll32 with Non-Standard File Extension production (source)
- Windows Scheduled Task Created Via XML production (source)
- Windows Scheduled Task Service Spawned Shell production (source)
- Windows Scheduled Task with Highest Privileges production (source)
- Windows Schtasks Create Run As System production (source)
- Windows ScManager Security Descriptor Tampering Via Sc.EXE production (source)
- Windows Security Account Manager Stopped production (source)
- Windows Security Support Provider Reg Query production (source)
- Windows Sensitive Group Discovery With Net production (source)
- Windows Sensitive Registry Hive Dump Via CommandLine production (source)
- Windows Server Software Component GACUtil Install to GAC production (source)
- Windows Service Create Kernel Mode Driver production (source)
- Windows Service Create with Tscon production (source)
- Windows Service Created (Sysmon) (source)
- Windows Service Creation on Remote Endpoint production (source)
- Windows Service Execution RemCom production (source)
- Windows Service Initiation on Remote Endpoint production (source)
- Windows Service Started (Sysmon) (source)
- Windows Service Stop Attempt production (source)
- Windows Service Stop By Deletion production (source)
- Windows Set Account Password Policy To Unlimited Via Net production (source)
- Windows Set Custom DNS ServerLevelPlugin Via Dnscmd production (source)
- Windows Shell or Script Execution From IIS Directory production (source)
- Windows Shell Process from CrushFTP production (source)
- Windows SOAPHound Binary Execution production (source)
- Windows SoftEther VPN Masquerading as Legitimate Binary production (source)
- Windows Spearphishing Attachment Onenote Spawn Mshta production (source)
- Windows SpeechRuntime Suspicious Child Process production (source)
- Windows SQL Spawning CertUtil experimental (source)
- Windows SQLCMD Execution production (source)
- Windows Sqlservr Spawning Shell production (source)
- Windows SSH Proxy Command production (source)
- Windows Steal Authentication Certificates CertUtil Backup production (source)
- Windows Steal Authentication Certificates Export Certificate production (source)
- Windows Steal Authentication Certificates Export PfxCertificate production (source)
- Windows Steal or Forge Kerberos Tickets Klist production (source)
- Windows SubInAcl Execution production (source)
- Windows Suspicious Child Process Spawned From WebServer production (source)
- Windows Suspicious Process File Path production (source)
- Windows Suspicious QEMU Execution production (source)
- Windows Suspicious React or Next.js Child Process production (source)
- Windows Suspicious VMWare Tools Child Process production (source)
- Windows Svchost.exe Parent Process Anomaly production (source)
- Windows SymbolicLink-Testing-Tools Utility Execution production (source)
- Windows Symlink Evaluation Change via Fsutil production (source)
- Windows System Binary Proxy Execution Compiled HTML File Decompile production (source)
- Windows System Discovery Using ldap Nslookup production (source)
- Windows System Discovery Using Qwinsta production (source)
- Windows System LogOff Commandline production (source)
- Windows System Network Config Discovery Display DNS production (source)
- Windows System Network Connections Discovery Netsh production (source)
- Windows System Reboot CommandLine production (source)
- Windows System Remote Discovery With Query production (source)
- Windows System Script Proxy Execution Syncappvpublishingserver production (source)
- Windows System Shutdown CommandLine production (source)
- Windows System Time Discovery W32tm Delay production (source)
- Windows System User Discovery Via Quser production (source)
- Windows System User Privilege Discovery production (source)
- Windows TeamCity Payload Execution from Temp Directory production (source)
- Windows Time Based Evasion production (source)
- Windows Time Based Evasion via Choice Exec production (source)
- Windows TinyCC Shellcode Execution production (source)
- Windows TOR Client Execution production (source)
- Windows UAC Bypass Suspicious Child Process production (source)
- Windows UAC Bypass Suspicious Escalation Behavior production (source)
- Windows Unusual SysWOW64 Process Run System32 Executable production (source)
- Windows User Deletion Via Net production (source)
- Windows User Disabled Via Net production (source)
- Windows User Discovery Via Net production (source)
- Windows Vulnerable 3CX Software production (source)
- Windows WBAdmin File Recovery From Backup production (source)
- Windows WinDBG Spawning AutoIt3 production (source)
- Windows WinLogon with Public Network Connection production (source)
- Windows WinRAR Launched Outside Default Installation Directory production (source)
- Windows WMI Process And Service List production (source)
- Windows WMI Process Call Create production (source)
- Windows WMI Reconnaissance Class Query production (source)
- Windows Wmic CPU Discovery production (source)
- Windows Wmic DiskDrive Discovery production (source)
- Windows Wmic Memory Chip Discovery production (source)
- Windows Wmic Network Discovery production (source)
- Windows WMIC Shadowcopy Delete production (source)
- Windows Wmic Systeminfo Discovery production (source)
- Windows WSUS Spawning Shell production (source)
- Winhlp32 Spawning a Process production (source)
- WinRAR Spawning Shell Application production (source)
- WinRM Spawning a Process experimental (source)
- WinRM Tools (Sysmon) (source)
- WMI subscription execution (Sysmon) (source)
- WMIC Explicit Credentials (Sysmon) (source)
- Wmic Group Discovery production (source)
- WMIC Host Reconniassance (Sysmon) (source)
- Wmic NonInteractive App Uninstallation production (source)
- WMIC XSL Execution via URL production (source)
- Wmiprvse LOLBAS Execution Process Spawn production (source)
- WmiPrvSE Suspicious Child Process (Sysmon) (source)
- Wow6432Node Classes Autorun Keys Modification (Sysmon) (source)
- Wscript Or Cscript Suspicious Child Process production (source)
- Wscript_Cscript Execution (Sysmon) (source)
- Wsmprovhost LOLBAS Execution Process Spawn production (source)
- XSL Script Execution With WMIC production (source)
Event ID 3 Network connection 31 rules
- Detect Regasm with Network Connection production (source)
- Detect Regsvcs with Network Connection production (source)
- DLLHost with no Command Line Arguments with Network production (source)
- GPUpdate with no Command Line Arguments with Network production (source)
- LOLBAS With Network Traffic production (source)
- Network Connection with Suspicious Folder (Sysmon) (source)
- Network Traffic to Active Directory Web Services Protocol production (source)
- Outbound Network Connection from Java Using Default Ports production (source)
- Potential CVE-2024-21413: Outbound SMB from Outlook (Sysmon) (source)
- Potential network connection with CVE-2023-21554 (Sysmon) (source)
- Process Connection to Mega - Windows (Sysmon) (source)
- PuTTY Secure Copy Client Execution (Sysmon) (source)
- RDP Connection (Sysmon) (source)
- Rundll32 with no Command Line Arguments with Network production (source)
- Script Connected to External Destination - Windows (Sysmon) (source)
- SearchProtocolHost with no Command Line with Network production (source)
- Unexpected Network Connection from System Process (Sysmon) (source)
- Unknown Process Using The Kerberos Protocol production (source)
- Unusual HTTP Download (Sysmon) (source)
- Windows Detect Network Scanner Behavior production (source)
- Windows File Transfer Protocol In Non-Common Process Path production (source)
- Windows HTTP Network Communication From MSIExec production (source)
- Windows InstallUtil Remote Network Connection production (source)
- Windows Mail Protocol In Non-Common Process Path production (source)
- Windows Network Connection From Program In Suspect Location production (source)
- Windows Potential Cloudflared Network Connection production (source)
- Windows Remote Desktop Network Bruteforce Attempt production (source)
- Windows Rundll32 WebDav With Network Connection production (source)
- Windows Suspect Process With Authentication Traffic production (source)
- Windows WinLogon with Public Network Connection production (source)
- wuauclt.exe Network Connection (Sysmon) (source)
Event ID 5 Process terminated 2 rules
Event ID 6 Driver loaded 5 rules
Event ID 7 Image loaded 38 rules
- CMLUA Or CMSTPLUA UAC Bypass production (source)
- Loading Of Dynwrapx Module production (source)
- MS Scripting Process Loading Ldap Module production (source)
- MS Scripting Process Loading WMI Module production (source)
- MSI Module Loaded by Non-System Binary production (source)
- Potential Follina_DogWalk Activity - mdst.exe (Sysmon) (source)
- Spoolsv Suspicious Loaded Modules production (source)
- Sunburst Correlation DLL and Network Event experimental (source)
- UAC Bypass MMC Load Unsigned Dll production (source)
- UAC Bypass With Colorui COM Object production (source)
- Wbemprox COM Object Execution production (source)
- Windows BitDefender Submission Wizard DLL Sideloading experimental (source)
- Windows Credentials Access via VaultCli Module production (source)
- Windows Devtunnels Image Loaded production (source)
- Windows DLL Module Loaded in Temp Dir production (source)
- Windows DLL Search Order Hijacking Hunt with Sysmon production (source)
- Windows DLL Side-Loading In Calc production (source)
- Windows Executable in Loaded Modules production (source)
- Windows Gather Victim Identity SAM Info production (source)
- Windows Hijack Execution Flow Version Dll Side Load production (source)
- Windows Input Capture Using Credential UI Dll production (source)
- Windows InstallUtil Credential Theft production (source)
- Windows Known Abused DLL Loaded Suspiciously production (source)
- Windows Known GraphicalProton Loaded Modules production (source)
- Windows MMC Loaded Script Engine DLL production (source)
- Windows NetSupport RMM DLL Loaded By Uncommon Process production (source)
- Windows Office Product Loaded MSHTML Module production (source)
- Windows Office Product Loading Taskschd DLL production (source)
- Windows Office Product Loading VBE7 DLL production (source)
- Windows Remote Access Software BRC4 Loaded Dll production (source)
- Windows Remote Image Load production (source)
- Windows Scheduled Task DLL Module Loaded production (source)
- Windows SpeechRuntime COM Hijacking DLL Load production (source)
- Windows SqlWriter SQLDumper DLL Sideload production (source)
- Windows Unsigned DLL Side-Loading production (source)
- Windows Unsigned DLL Side-Loading In Same Process Path production (source)
- Windows Unsigned MS DLL Side-Loading production (source)
- Windows Unusual Process Load Mozilla NSS-Mozglue Module production (source)
Event ID 8 CreateRemoteThread 11 rules
- Create Remote Thread In Shell Application production (source)
- Create Remote Thread into LSASS production (source)
- Powershell Remote Thread To Known Windows Process production (source)
- Rare Remote Thread (Sysmon) (source)
- Remote Thread Created by Uncommon Process (Sysmon) (source)
- Remote Thread from Suspicious Folder (Sysmon) (source)
- Rundll32 Create Remote Thread To A Process production (source)
- Rundll32 CreateRemoteThread In Browser production (source)
- Windows Process Injection Of Wermgr to Known Browser production (source)
- Windows Process Injection Remote Thread production (source)
- Windows Process Injection With Public Source Path production (source)
Event ID 9 RawAccessRead 2 rules
Event ID 10 ProcessAccess 15 rules
- Access LSASS Memory for Dump Creation production (source)
- Detect Credential Dumping through LSASS access production (source)
- Mimikatz (Sysmon) (source)
- Rubeus Kerberos Ticket Exports Through Winlogon Access production (source)
- Spoolsv Suspicious Process Access production (source)
- Windows Access Token Manipulation Winlogon Duplicate Token Handle production (source)
- Windows Access Token Winlogon Duplicate Handle In Uncommon Path production (source)
- Windows Handle Duplication in Known UAC-Bypass Binaries production (source)
- Windows Hunting System Account Targeting Lsass production (source)
- Windows Non-System Account Targeting Lsass production (source)
- Windows Possible Credential Dumping production (source)
- Windows Process Injection into Commonly Abused Processes production (source)
- Windows Process Injection into Notepad production (source)
- Windows Terminating Lsass Process production (source)
- Windows WMI Impersonate Token production (source)
Event ID 11 FileCreate 94 rules
- Additional dll added to Spool Driver (Sysmon) (source)
- Batch File Write to System32 production (source)
- Common Ransomware Extensions production (source)
- Common Ransomware Notes production (source)
- ConnectWise ScreenConnect Path Traversal production (source)
- Creation of lsass Dump with Taskmgr production (source)
- Detect AzureHound File Modifications production (source)
- Detect Certipy File Modifications production (source)
- Detect Exchange Web Shell production (source)
- Detect Outlook exe writing a zip file production (source)
- Detect Remote Access Software Usage File production (source)
- Detect RTLO In File Name production (source)
- Detect SharpHound File Modifications production (source)
- Drop IcedID License dat production (source)
- Email files written outside of the Outlook directory experimental (source)
- Executable File Written to Disk (Sysmon) (source)
- Executables Or Script Creation In Suspicious Path production (source)
- Executables Or Script Creation In Temp Path production (source)
- File with Samsam Extension production (source)
- File Written to Startup Folder - Windows (Sysmon) (source)
- GitHub Workflow File Creation or Modification production (source)
- IcedID Exfiltrated Archived File Creation production (source)
- Impacket atexec.py Temp File Creation (Sysmon) (source)
- iphlpapi.dll File Write to Appdata_Local_Microsoft (Sysmon) (source)
- LLM Model File Creation production (source)
- MS Exchange Mailbox Replication service writing Active Server Pages experimental (source)
- Msmpeng Application DLL Side Loading production (source)
- Overwriting Accessibility Binaries production (source)
- Process Creating LNK file in Suspicious Location production (source)
- Process Writing DynamicWrapperX production (source)
- Ransomware Notes bulk creation production (source)
- RDP File Written by Outlook (Sysmon) (source)
- Remcos RAT File Creation in Remcos Folder production (source)
- Rundll32 Process Creating Exe Dll Files production (source)
- Ryuk Test Files Detected production (source)
- Samsam Test File Write production (source)
- SchCache Change By App Connect And Create ADSI Object production (source)
- Shai-Hulud 2 Exfiltration Artifact Files production (source)
- Shai-Hulud Workflow File Creation or Modification production (source)
- Shim Database File Creation production (source)
- Spike in File Writes experimental (source)
- Spoolsv Writing a DLL production (source)
- Spoolsv Writing a DLL - Sysmon production (source)
- Sqlite Module In Temp Folder production (source)
- Suspicious .sys Created - Windows (Sysmon) (source)
- Suspicious File Created in Public Folder (Sysmon) (source)
- Suspicious Image Creation In Appdata Folder production (source)
- Suspicious WAV file in Appdata Folder production (source)
- Suspicious writes to windows Recycle Bin production (source)
- Wermgr Process Create Executable File production (source)
- Windows .Key File Creation in Root Directory production (source)
- Windows Admin Permission Discovery production (source)
- Windows Admin$ Share Access (Sysmon) (source)
- Windows Archived Collected Data In TEMP Folder production (source)
- Windows Boot or Logon Autostart Execution In Startup Folder production (source)
- Windows C$ Share Access (Sysmon) (source)
- Windows CAB File on Disk production (source)
- Windows Credentials from Password Stores Chrome Copied in TEMP Dir production (source)
- Windows Credentials from Web Browsers Saved in TEMP Folder production (source)
- Windows Defacement Modify Transcodedwallpaper File production (source)
- Windows Default RDP File Creation By Non MSTSC Process production (source)
- Windows EFI Bootloader File Modification production (source)
- Windows File Without Extension In Critical Folder production (source)
- Windows IPC$ Share Access (Sysmon) (source)
- Windows ISO LNK File Creation production (source)
- Windows Known Abused DLL Created production (source)
- Windows Mimikatz Crypto Export File Extensions production (source)
- Windows Mock Trusted Directory MSC File Creation production (source)
- Windows MOVEit Transfer Writing ASPX production (source)
- Windows MSHTA Writing to World Writable Path production (source)
- Windows NirSoft Tool Bundle File Created production (source)
- Windows Obfuscated Files or Information via RAR SFX production (source)
- Windows Office Product Dropped Cab or Inf File production (source)
- Windows Office Product Dropped Uncommon File production (source)
- Windows Outlook Macro Created by Suspicious Process production (source)
- Windows Phishing Outlook Drop Dll In FORM Dir production (source)
- Windows Potential AppDomainManager Hijack Artifacts Creation production (source)
- Windows Potential Web Shell Creation For VMware Workspace ONE production (source)
- Windows PowerShell Module File Created production (source)
- Windows Process Writing File to World Writable Path production (source)
- Windows RDP Bitmap Cache File Creation production (source)
- Windows Replication Through Removable Media production (source)
- Windows Screen Capture in TEMP folder production (source)
- Windows SharePoint Spinstall0 Webshell File Creation production (source)
- Windows Snake Malware File Modification Crmlog production (source)
- Windows Snake Malware Kernel Driver Comadmin production (source)
- Windows Suspicious File in EFI Volume production (source)
- Windows System File on Disk production (source)
- Windows TeamCity Plugin Installed production (source)
- Windows Theme File Creation in Unusual Location production (source)
- Windows Universal Data Link File Creation production (source)
- Windows Unusual File Creation in Confluence Directory production (source)
- Windows User Execution Malicious URL Shortcut File production (source)
- Windows XLL File Creation Outside of Typical Location production (source)
Event ID 12 RegistryEvent (Object create and delete) 23 rules
- Add DefaultUser And Password In Registry production (source)
- ComputerDefaults UAC Bypass (Sysmon) (source)
- Hidden User Created - Windows (Sysmon) (source)
- LocalAccountTokenFilterPolicy Registry Value Modified (Sysmon) (source)
- Logon Script Registry Key added (Sysmon) (source)
- LSA Authentication Packages Registry Key Modified (Sysmon) (source)
- Malicious InProcServer32 Modification production (source)
- Potential fodhelper UAC Bypass Attempt (Sysmon) (source)
- Remcos client registry install entry production (source)
- Revil Registry Entry production (source)
- Sdclt UAC Bypass production (source)
- Startup Folder Location Modified - Windows (Sysmon) (source)
- Windows CrowdStrike Agent Registry Key Removal production (source)
- Windows Deleted Registry By A Non Critical Process File Path production (source)
- Windows Downdate Registry Activity production (source)
- Windows Modify Registry Delete Firewall Rules production (source)
- Windows RDP Server Registry Deletion production (source)
- Windows Registry Delete Task SD production (source)
- Windows RunMRU Registry Key or Value Deleted production (source)
- Windows USBSTOR Registry Key Modification production (source)
- Windows WPDBusEnum Registry Key Modification production (source)
- WinLogon Registry Key Modified (Sysmon) (source)
- WSReset UAC Bypass production (source)
Event ID 13 RegistryEvent (Value Set) 194 rules
- Active Setup Registry Autostart production (source)
- Add DefaultUser And Password In Registry production (source)
- Add DLL_EXE Registry Value (Sysmon) (source)
- Allow Inbound Traffic By Firewall Rule Registry production (source)
- Allow Operation with Consent Admin production (source)
- Auto Admin Logon Registry Entry production (source)
- Command Line Utility Added to Accessibility Features (Sysmon) (source)
- ComputerDefaults UAC Bypass (Sysmon) (source)
- ConsentPromptBehaviorAdmin Registry Value Modified (Sysmon) (source)
- Defender Registry Values Modified (Sysmon) (source)
- Detect Remote Access Software Usage Registry production (source)
- Disable AMSI Through Registry production (source)
- Disable Defender AntiVirus Registry production (source)
- Disable Defender BlockAtFirstSeen Feature production (source)
- Disable Defender Enhanced Notification production (source)
- Disable Defender MpEngine Registry production (source)
- Disable Defender Spynet Reporting production (source)
- Disable Defender Submit Samples Consent Feature production (source)
- Disable ETW Through Registry production (source)
- Disable Registry Tool production (source)
- Disable Security Logs Using MiniNt Registry production (source)
- Disable Show Hidden Files production (source)
- Disable UAC Remote Restriction production (source)
- Disable Windows App Hotkeys production (source)
- Disable Windows Behavior Monitoring production (source)
- Disable Windows SmartScreen Protection production (source)
- Disabling CMD Application production (source)
- Disabling ControlPanel production (source)
- Disabling Defender Services production (source)
- Disabling FolderOptions Windows Feature production (source)
- Disabling NoRun Windows App production (source)
- Disabling Remote User Account Control production (source)
- Disabling SystemRestore In Registry production (source)
- Disabling Task Manager production (source)
- Disabling Windows Local Security Authority Defences via Registry production (source)
- Enable RDP In Other Port Number production (source)
- Enable WDigest UseLogonCredential Registry production (source)
- EnableLUA Registry Value Modified (Sysmon) (source)
- ETW Registry Disabled production (source)
- Eventvwr UAC Bypass production (source)
- Executable Running as NT AUTHORITY_SYSTEM Registered in BAM (Sysmon) (source)
- Hidden User Created - Windows (Sysmon) (source)
- Hide User Account From Sign-In Screen production (source)
- LocalAccountTokenFilterPolicy Registry Value Modified (Sysmon) (source)
- Logon Script Event Trigger Execution production (source)
- Logon Script Registry Key added (Sysmon) (source)
- LSA Authentication Packages Registry Key Modified (Sysmon) (source)
- Malicious InProcServer32 Modification production (source)
- Modification Of Wallpaper production (source)
- Monitor Registry Keys for Print Monitors production (source)
- NET Profiler UAC bypass production (source)
- Potential fodhelper UAC Bypass Attempt (Sysmon) (source)
- Print Processor Registry Autostart production (source)
- PromptOnSecureDesktop Registry Value Modified (Sysmon) (source)
- Registry Keys for Creating SHIM Databases production (source)
- Registry Keys Used For Persistence production (source)
- Registry Keys Used For Privilege Escalation production (source)
- Remcos client registry install entry production (source)
- Revil Registry Entry production (source)
- Screensaver Event Trigger Execution production (source)
- Sdclt UAC Bypass production (source)
- Set Default PowerShell Execution Policy To Unrestricted or Bypass production (source)
- SilentCleanup UAC Bypass production (source)
- Startup Folder Location Modified - Windows (Sysmon) (source)
- Suspicious InprocServer32 Registry Modification (Sysmon) (source)
- Time Provider Persistence Registry production (source)
- WDigest Forced Credential Caching (Sysmon) (source)
- Windows AD DSRM Account Changes production (source)
- Windows Anomalous Registry Value Length in Environment Key production (source)
- Windows Audit Policy Auditing Option Modified - Registry production (source)
- Windows Autostart Execution LSASS Driver Registry Modification production (source)
- Windows Chrome Auto-Update Disabled via Registry production (source)
- Windows Chrome Extension Allowed Registry Modification production (source)
- Windows Compatibility Telemetry Tampering Through Registry production (source)
- Windows Defender Disabled Detection (Sysmon) (source)
- Windows Defender Exclusion Registry Entry production (source)
- Windows Disable Change Password Through Registry production (source)
- Windows Disable Lock Workstation Feature Through Registry production (source)
- Windows Disable LogOff Button Through Registry production (source)
- Windows Disable Memory Crash Dump production (source)
- Windows Disable Notification Center production (source)
- Windows Disable Shutdown Button Through Registry production (source)
- Windows Disable Windows Group Policy Features Through Registry production (source)
- Windows DisableAntiSpyware Registry production (source)
- Windows Downdate Registry Activity production (source)
- Windows Enable Win32 ScheduledJob via Registry production (source)
- Windows Filtering Platform Policy Added to Block EDR Process production (source)
- Windows Hide Notification Features Through Registry production (source)
- Windows Impair Defense Change Win Defender Health Check Intervals production (source)
- Windows Impair Defense Change Win Defender Quick Scan Interval production (source)
- Windows Impair Defense Change Win Defender Throttle Rate production (source)
- Windows Impair Defense Change Win Defender Tracing Level production (source)
- Windows Impair Defense Configure App Install Control production (source)
- Windows Impair Defense Define Win Defender Threat Action production (source)
- Windows Impair Defense Delete Win Defender Context Menu production (source)
- Windows Impair Defense Delete Win Defender Profile Registry production (source)
- Windows Impair Defense Deny Security Software With Applocker production (source)
- Windows Impair Defense Disable Controlled Folder Access production (source)
- Windows Impair Defense Disable Defender Firewall And Network production (source)
- Windows Impair Defense Disable Defender Protocol Recognition production (source)
- Windows Impair Defense Disable PUA Protection production (source)
- Windows Impair Defense Disable Realtime Signature Delivery production (source)
- Windows Impair Defense Disable Web Evaluation production (source)
- Windows Impair Defense Disable Win Defender App Guard production (source)
- Windows Impair Defense Disable Win Defender Compute File Hashes production (source)
- Windows Impair Defense Disable Win Defender Gen reports production (source)
- Windows Impair Defense Disable Win Defender Network Protection production (source)
- Windows Impair Defense Disable Win Defender Report Infection production (source)
- Windows Impair Defense Disable Win Defender Scan On Update production (source)
- Windows Impair Defense Disable Win Defender Signature Retirement production (source)
- Windows Impair Defense Overide Win Defender Phishing Filter production (source)
- Windows Impair Defense Override SmartScreen Prompt production (source)
- Windows Impair Defense Set Win Defender Smart Screen Level To Warn production (source)
- Windows Impair Defenses Disable Auto Logger Session production (source)
- Windows Impair Defenses Disable AV AutoStart via Registry production (source)
- Windows Impair Defenses Disable HVCI production (source)
- Windows Impair Defenses Disable Win Defender Auto Logging production (source)
- Windows InProcServer32 New Outlook Form production (source)
- Windows LSA Secrets NoLMhash Registry production (source)
- Windows Modify Registry AuthenticationLevelOverride production (source)
- Windows Modify Registry Auto Minor Updates production (source)
- Windows Modify Registry Auto Update Notif production (source)
- Windows Modify Registry Configure BitLocker production (source)
- Windows Modify Registry Default Icon Setting production (source)
- Windows Modify Registry Disable RDP production (source)
- Windows Modify Registry Disable Restricted Admin production (source)
- Windows Modify Registry Disable Toast Notifications production (source)
- Windows Modify Registry Disable Win Defender Raw Write Notif production (source)
- Windows Modify Registry Disable WinDefender Notifications production (source)
- Windows Modify Registry Disable Windows Security Center Notif production (source)
- Windows Modify Registry DisableRemoteDesktopAntiAlias production (source)
- Windows Modify Registry DisableSecuritySettings production (source)
- Windows Modify Registry Disabling WER Settings production (source)
- Windows Modify Registry DisAllow Windows App production (source)
- Windows Modify Registry Do Not Connect To Win Update production (source)
- Windows Modify Registry DontShowUI production (source)
- Windows Modify Registry EnableLinkedConnections production (source)
- Windows Modify Registry LongPathsEnabled production (source)
- Windows Modify Registry MaxConnectionPerServer production (source)
- Windows Modify Registry No Auto Reboot With Logon User production (source)
- Windows Modify Registry No Auto Update production (source)
- Windows Modify Registry NoChangingWallPaper production (source)
- Windows Modify Registry on Smart Card Group Policy production (source)
- Windows Modify Registry ProxyEnable production (source)
- Windows Modify Registry ProxyServer production (source)
- Windows Modify Registry Qakbot Binary Data Registry production (source)
- Windows Modify Registry Suppress Win Defender Notif production (source)
- Windows Modify Registry Tamper Protection production (source)
- Windows Modify Registry to Add or Modify Firewall Rule production (source)
- Windows Modify Registry UpdateServiceUrlAlternate production (source)
- Windows Modify Registry USeWuServer production (source)
- Windows Modify Registry Utilize ProgIDs production (source)
- Windows Modify Registry ValleyRAT C2 Config production (source)
- Windows Modify Registry ValleyRat PWN Reg Entry production (source)
- Windows Modify Registry With MD5 Reg Key Name production (source)
- Windows Modify Registry WuServer production (source)
- Windows Modify Registry wuStatusServer production (source)
- Windows Modify Show Compress Color And Info Tip Registry production (source)
- Windows Mshta Execution In Registry production (source)
- Windows New Custom Security Descriptor Set On EventLog Channel production (source)
- Windows New Default File Association Value Set production (source)
- Windows New EventLog ChannelAccess Registry Value Set production (source)
- Windows New InProcServer32 Added production (source)
- Windows Njrat Fileless Storage via Registry production (source)
- Windows Outlook Dialogs Disabled from Unusual Process production (source)
- Windows Outlook LoadMacroProviderOnBoot Persistence production (source)
- Windows Outlook Macro Security Modified production (source)
- Windows Outlook WebView Registry Modification production (source)
- Windows Phishing Recent ISO Exec Registry production (source)
- Windows Process Executed From Removable Media production (source)
- Windows Proxy Via Registry production (source)
- Windows RDP Server Registry Deletion production (source)
- Windows RDP Server Registry Entry Created production (source)
- Windows Registry BootExecute Modification production (source)
- Windows Registry Certificate Added production (source)
- Windows Registry Dotnet ETW Disabled Via ENV Variable production (source)
- Windows Registry Modification for Safe Mode Persistence production (source)
- Windows Registry Payload Injection production (source)
- Windows Registry SIP Provider Modification production (source)
- Windows Remote Access Software RMS Registry production (source)
- Windows Remote Services Allow Remote Assistance production (source)
- Windows Remote Services Rdp Enable production (source)
- Windows Routing and Remote Access Service Registry Key Change production (source)
- Windows RunMRU Command Execution production (source)
- Windows Service Creation Using Registry Entry production (source)
- Windows Service Deletion In Registry production (source)
- Windows Set Network Profile Category to Private via Registry production (source)
- Windows Snake Malware Registry Modification wav OpenWithProgIds production (source)
- Windows SnappyBee Create Test Registry production (source)
- Windows USBSTOR Registry Key Modification production (source)
- Windows WPDBusEnum Registry Key Modification production (source)
- WinLogon Registry Key Modified (Sysmon) (source)
- Wow6432Node Classes Autorun Keys Modification (Sysmon) (source)
- WSReset UAC Bypass production (source)
Event ID 15 FileCreateStreamHash 4 rules
Event ID 17 PipeEvent (Pipe Created) 10 rules
- Named Pipe Created (Sysmon) (source)
- Trickbot Named Pipe production (source)
- Windows Anonymous Pipe Activity production (source)
- Windows App Layer Protocol Qakbot NamedPipe production (source)
- Windows App Layer Protocol Wermgr Connect To NamedPipe production (source)
- Windows Application Layer Protocol RMS Radmin Tool Namedpipe production (source)
- Windows PUA Named Pipe production (source)
- Windows RMM Named Pipe production (source)
- Windows Suspicious C2 Named Pipe production (source)
- Windows Suspicious Named Pipe production (source)
Event ID 18 PipeEvent (Pipe Connected) 10 rules
- Named Pipe Created (Sysmon) (source)
- Trickbot Named Pipe production (source)
- Windows Anonymous Pipe Activity production (source)
- Windows App Layer Protocol Qakbot NamedPipe production (source)
- Windows App Layer Protocol Wermgr Connect To NamedPipe production (source)
- Windows Application Layer Protocol RMS Radmin Tool Namedpipe production (source)
- Windows PUA Named Pipe production (source)
- Windows RMM Named Pipe production (source)
- Windows Suspicious C2 Named Pipe production (source)
- Windows Suspicious Named Pipe production (source)
Event ID 22 DNSEvent (DNS query) 23 rules
- 3CX Supply Chain Attack Network Indicators production (source)
- AteraAgent Installation - Windows (Sysmon) (source)
- Detect DNS Query to Decommissioned S3 Bucket experimental (source)
- Detect hosts connecting to dynamic domain providers production (source)
- Detect Remote Access Software Usage DNS production (source)
- DNS Kerberos Coercion production (source)
- DNS Query Length With High Standard Deviation production (source)
- Local LLM Framework DNS Query production (source)
- Ngrok Reverse Proxy on Network production (source)
- Rundll32 DNSQuery production (source)
- Sunburst Correlation DLL and Network Event experimental (source)
- Suspicious Process DNS Query Known Abuse Web Services production (source)
- Suspicious Process With Discord DNS Query production (source)
- Wermgr Process Connecting To IP Check Web Services production (source)
- Windows Abused Web Services production (source)
- Windows AI Platform DNS Query production (source)
- Windows BitLockerToGo with Network Activity production (source)
- Windows DNS Query Request by Telegram Bot API production (source)
- Windows DNS Query Request To TinyUrl production (source)
- Windows Gather Victim Network Info Through Ip Check Web Services production (source)
- Windows Multi hop Proxy TOR Website Query production (source)
- Windows Spearphishing Attachment Connect To None MS Office Domain production (source)
- Windows Visual Basic Commandline Compiler DNSQuery production (source)
Event ID 23 FileDelete (File Delete archived) 10 rules
- Additional dll added to Spool Driver (Sysmon) (source)
- Excessive File Deletion In WinDefender Folder production (source)
- Windows ConsoleHost History File Deletion production (source)
- Windows Data Destruction Recursive Exec Files Deletion production (source)
- Windows Default Rdp File Deletion production (source)
- Windows High File Deletion Frequency production (source)
- Windows Mark Of The Web Bypass production (source)
- Windows MSI Rollback Script Deleted By Non-Msiexec Process production (source)
- Windows Rdp AutomaticDestinations Deletion production (source)
- Windows RDP Cache File Deletion production (source)
Event ID 26 FileDeleteDetected (File Delete logged) 7 rules
- Excessive File Deletion In WinDefender Folder production (source)
- Windows ConsoleHost History File Deletion production (source)
- Windows Data Destruction Recursive Exec Files Deletion production (source)
- Windows Default Rdp File Deletion production (source)
- Windows High File Deletion Frequency production (source)
- Windows Rdp AutomaticDestinations Deletion production (source)
- Windows RDP Cache File Deletion production (source)
Microsoft-Windows-Windows-Defender
Event ID 1121 2 rules
- Windows Defender ASR Block Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1122 2 rules
- Windows Defender ASR Audit Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1125 2 rules
- Windows Defender ASR Audit Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1126 3 rules
- Windows Defender ASR Audit Events production (source)
- Windows Defender ASR Block Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1129 2 rules
- Windows Defender ASR Block Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1131 2 rules
- Windows Defender ASR Block Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1132 2 rules
- Windows Defender ASR Audit Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1133 2 rules
- Windows Defender ASR Block Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 1134 2 rules
- Windows Defender ASR Audit Events production (source)
- Windows Defender ASR Rules Stacking production (source)
Event ID 5007 3 rules
- Windows Defender ASR Registry Modification production (source)
- Windows Defender ASR Rule Disabled production (source)
- Windows Defender ASR Rules Stacking production (source)
Microsoft-Windows-AppXDeployment-Server
Microsoft-Windows-Eventlog
Event ID 517 The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by 1102). 1 rule
Microsoft-Windows-PrintService
MsiInstaller
Service-Control-Manager
Event ID 7036 3 rules
Event ID 7040 3 rules
- Windows Event For Service Disabled production (source)
- Windows Excessive Disabled Services Event production (source)
- Windows Service Stop Win Updates production (source)
Event ID 7045 18 rules
- Clop Ransomware Known Service Name production (source)
- Impacket SMBexec (Windows Event Log) (source)
- Kernel Service Installed - Windows (Windows Event Log) (source)
- Malicious Powershell Executed As A Service production (source)
- PSexec Service Creation (Windows Event Log) (source)
- Randomly Generated Windows Service Name experimental (source)
- Service Created containing Command Shell (Windows Event Log) (source)
- Service Installed (Windows Event Log) (source)
- SimpleHelp Remote Access Tool Service Installation (Windows Event Log) (source)
- Windows Bluetooth Service Installed From Uncommon Location production (source)
- Windows Driver Load Non-Standard Path production (source)
- Windows KrbRelayUp Service Creation production (source)
- Windows Service Create RemComSvc production (source)
- Windows Service Create SliverC2 production (source)
- Windows Service Created with Suspicious Service Name production (source)
- Windows Service Created with Suspicious Service Path production (source)
- Windows Snake Malware Service Create production (source)
- Windows Vulnerable Driver Installed production (source)
MSSQLSERVER
Event ID 8128 1 rule
Event ID 15457 3 rules
Microsoft-Windows-CAPI2
Microsoft-Windows-PowerShell
Event ID 4103 Payload Context: ContextInfo User Data: UserData. 111 rules
- Adfind Commands (PowerShell) (source)
- Adfind Execution (PowerShell) (source)
- Application Discovery - Windows (PowerShell) (source)
- ATBroker.exe Execution (PowerShell) (source)
- AutoHotkey Execution (PowerShell) (source)
- BITSadmin Execution (PowerShell) (source)
- Browser Started with Remote Debugging - Windows (PowerShell) (source)
- Bypass or Unrestricted PowerShell Execution (PowerShell) (source)
- Certutil File Download (PowerShell) (source)
- Certutil Obfuscate_Encode Files (PowerShell) (source)
- Command Line Homoglyphs - Windows (PowerShell) (source)
- Command Line lsass request (PowerShell) (source)
- Command Line Utility Added to Accessibility Features (PowerShell) (source)
- Command-Line Interface Execution (PowerShell) (source)
- Common Exchange Recon cmdlets (PowerShell) (source)
- ComputerDefaults UAC Bypass (PowerShell) (source)
- ConsentPromptBehaviorAdmin Registry Value Modified (PowerShell) (source)
- Create_Modify Schtasks (PowerShell) (source)
- Disabled Pre-Authentication Accounts Discovery - PowerShell (PowerShell) (source)
- DLL Concatenation (PowerShell) (source)
- Domain Controller Enumeration via nltest (PowerShell) (source)
- Dump File Identified (PowerShell) (source)
- EnableLUA Registry Value Modified (PowerShell) (source)
- Encoded Powershell Command (PowerShell) (source)
- Esentutl Execution (PowerShell) (source)
- ETW Trace Provider Modified - PowerShell (PowerShell) (source)
- Exchange New Export Request (PowerShell) (source)
- Exfiltration via curl.exe - Windows (PowerShell) (source)
- Expand.exe Execution (PowerShell) (source)
- File and Directory Discovery Output to File - Windows (PowerShell) (source)
- File_Folder Hidden - Windows (PowerShell) (source)
- Group Policy Editor Execution (PowerShell) (source)
- hh.exe Execution (PowerShell) (source)
- hh.exe Remote File Execution (PowerShell) (source)
- Invoke-DCOM.ps1 - PowerShell (PowerShell) (source)
- Invoke-Expression Command (PowerShell) (source)
- Invoke-WebRequest Command (PowerShell) (source)
- ISO Image Mounted - Windows (PowerShell) (source)
- Known Process Injection Commands (PowerShell) (source)
- LocalAccountTokenFilterPolicy Registry Value Modified (PowerShell) (source)
- Locate Credentials (PowerShell) (source)
- LSA Authentication Packages Registry Key Modified (PowerShell) (source)
- masscan Execution - Windows (PowerShell) (source)
- Modify Exchange Access Settings (PowerShell) (source)
- MSHTA.exe execution (PowerShell) (source)
- MSI Installation via Appcert (PowerShell) (source)
- Network Share Connection Removal (PowerShell) (source)
- New AutoRun Registry Key (PowerShell) (source)
- ngen.exe File Download (PowerShell) (source)
- Non-MSIExec .msi Installation (PowerShell) (source)
- ntds.dit Command Line (PowerShell) (source)
- Obfuscated Powershell Techniques (PowerShell) (source)
- Output to File (PowerShell) (source)
- Permission Groups Discovery: Domain Groups (PowerShell) (source)
- Permission Groups Discovery: Local Groups (PowerShell) (source)
- Possible Credential Dumping via Windows Network Providers (PowerShell) (source)
- Potential AutoHotkey .ahk Execution (PowerShell) (source)
- Potential fodhelper UAC Bypass Attempt (PowerShell) (source)
- Potential LSA password filter (PowerShell) (source)
- Potential Target Discovery via PowerShell Event Log Queries (PowerShell) (source)
- PowerHuntShares Commands (PowerShell) (source)
- PowerShell Clipboard Access (PowerShell) (source)
- PowerShell CreateDecryptor (PowerShell) (source)
- PowerShell Downgrade (PowerShell) (source)
- PowerShell Download Activity (PowerShell) (source)
- PowerShell DownloadFile_DownloadString (PowerShell) (source)
- PowerShell Hidden Window (PowerShell) (source)
- Powershell ICMP Data Exfiltration (PowerShell) (source)
- PowerShell Modifying Registry Values (PowerShell) (source)
- PowerShell XML Retrieval (PowerShell) (source)
- PowerView_SharpView Commands (PowerShell) (source)
- PromptOnSecureDesktop Registry Value Modified (PowerShell) (source)
- ProtocolHandler.exe File Download (PowerShell) (source)
- Proxy Execution via Appcert (PowerShell) (source)
- Query Registry (PowerShell) (source)
- Rclone Execution (PowerShell) (source)
- RdrLeakDiag.exe Memory Dump (PowerShell) (source)
- Read-Only Attribute Removed - Windows (PowerShell) (source)
- Registry Entry Created - PowerShell (PowerShell) (source)
- regsvr32 Execution (PowerShell) (source)
- Remote .msi Installation (PowerShell) (source)
- Remote .msi Installation (PowerShell) (source)
- Remote Admin Tools (PowerShell) (source)
- Remote WMIC Query (PowerShell) (source)
- Rundll32 Command Line (PowerShell) (source)
- Scheduled Task with Potential SSH Tunnel - Windows (PowerShell) (source)
- Security Software Discovery via Findstr.exe (PowerShell) (source)
- Security Software Discovery via WMI (PowerShell) (source)
- Sliver C2 Implant Activity Pattern (PowerShell) (source)
- Startup Folder Location Modified - Windows (PowerShell) (source)
- Stored Credentials from Web Browsers - Windows (PowerShell) (source)
- Suspicious AteraAgent Installation - Windows (PowerShell) (source)
- Suspicious DLLhost Execution (PowerShell) (source)
- Suspicious Powershell (PowerShell) (source)
- Suspicious PowerShell Clipboard Activity (PowerShell) (source)
- Suspicious reCAPTCHA Command Line (PowerShell) (source)
- Suspicious Registry Key Created (PowerShell) (source)
- System Information Discovery - Windows (PowerShell) (source)
- System Network Connections Discovery - Windows (PowerShell) (source)
- System Owner_User Discovery - Windows (PowerShell) (source)
- Timestamp Manipulation (PowerShell) (source)
- User Discovery via Environment Variables - PowerShell (PowerShell) (source)
- User_Domain Enumeration Tool - Windows (PowerShell) (source)
- Visio.exe File Download (PowerShell) (source)
- WebLogic CVE-2017-10271 (PowerShell) (source)
- Windows - Service Stop (PowerShell) (source)
- Windows Copy Files (PowerShell) (source)
- Windows Firewall Rule Creation (PowerShell) (source)
- Windows Process Copied from System Folder (PowerShell) (source)
- WinLogon Registry Key Modified (PowerShell) (source)
- Wow6432Node Classes Autorun Keys Modification (PowerShell) (source)
Event ID 4104 Creating Scriptblock text (MessageNumber of MessageTotal). 279 rules
- Access Common Package Config file (PowerShell) (source)
- Account Password Changed from Command Line - Windows (PowerShell) (source)
- Adfind Commands (PowerShell) (source)
- Adfind Execution (PowerShell) (source)
- AdsiSearcher Account Discovery production (source)
- Allow Inbound Traffic In Firewall Rule production (source)
- Application Discovery - Windows (PowerShell) (source)
- ATBroker.exe Execution (PowerShell) (source)
- Attempted Veeam Database Credential Dump (PowerShell) (source)
- AutoHotkey Execution (PowerShell) (source)
- AutoIt Execution (PowerShell) (source)
- BITSadmin Execution (PowerShell) (source)
- Browser Started with Remote Debugging - Windows (PowerShell) (source)
- Bypass or Unrestricted PowerShell Execution (PowerShell) (source)
- Certutil File Download (PowerShell) (source)
- Certutil Obfuscate_Encode Files (PowerShell) (source)
- CMD execution with _c (PowerShell) (source)
- Command Line Homoglyphs - Windows (PowerShell) (source)
- Command Line lsass request (PowerShell) (source)
- Common Active Directory Commands (PowerShell) (source)
- Common Exchange Recon cmdlets (PowerShell) (source)
- Common Reconnaissance Commands (PowerShell) (source)
- ComputerDefaults UAC Bypass (PowerShell) (source)
- ConsentPromptBehaviorAdmin Registry Value Modified (PowerShell) (source)
- Create_Modify Schtasks (PowerShell) (source)
- CSVDE Export Active Directory (PowerShell) (source)
- Data Staged to File (PowerShell) (source)
- Delete ShadowCopy With PowerShell production (source)
- Detect Certify With PowerShell Script Block Logging production (source)
- Detect Copy of ShadowCopy with Script Block Logging production (source)
- Detect Empire with PowerShell Script Block Logging production (source)
- Detect Mimikatz With PowerShell Script Block Logging production (source)
- Disabled Kerberos Pre-Authentication Discovery With Get-ADUser production (source)
- Disabled Kerberos Pre-Authentication Discovery With PowerView production (source)
- Disabled Pre-Authentication Accounts Discovery - PowerShell (PowerShell) (source)
- DLL Called with RS32 (PowerShell) (source)
- DLL Called with Uncommon Function (PowerShell) (source)
- DLL Concatenation (PowerShell) (source)
- DLL Execution from Uncommon Process (PowerShell) (source)
- DLLRegisterServer Called from Command Line (PowerShell) (source)
- Domain Controller Enumeration via nltest (PowerShell) (source)
- Domain Group Discovery with Adsisearcher production (source)
- Domain Trust Discovery Commands - Windows (PowerShell) (source)
- Dump File Identified (PowerShell) (source)
- Elevated Group Discovery with PowerView production (source)
- EnableLUA Registry Value Modified (PowerShell) (source)
- Encoded Powershell Command (PowerShell) (source)
- Esentutl Execution (PowerShell) (source)
- ETW Trace Provider Modified - PowerShell (PowerShell) (source)
- Event Logs Queried for RDP Sessions (PowerShell) (source)
- Exchange New Export Request (PowerShell) (source)
- Exchange PowerShell Module Usage production (source)
- Executable Create Script Process (PowerShell) (source)
- Executable Process from Suspicious Folder (PowerShell) (source)
- Exfiltration via curl.exe - Windows (PowerShell) (source)
- Expand.exe Execution (PowerShell) (source)
- File and Directory Discovery Output to File - Windows (PowerShell) (source)
- File_Folder Hidden - Windows (PowerShell) (source)
- Get ADDefaultDomainPasswordPolicy with Powershell Script Block production (source)
- Get ADUser with PowerShell Script Block production (source)
- Get ADUserResultantPasswordPolicy with Powershell Script Block production (source)
- Get DomainPolicy with Powershell Script Block production (source)
- Get DomainUser with PowerShell Script Block production (source)
- Get WMIObject Group Discovery with Script Block Logging production (source)
- Get-DomainTrust with PowerShell Script Block production (source)
- Get-ForestTrust with PowerShell Script Block production (source)
- GetAdComputer with PowerShell Script Block production (source)
- GetAdGroup with PowerShell Script Block production (source)
- GetCurrent User with PowerShell Script Block production (source)
- GetDomainComputer with PowerShell Script Block production (source)
- GetDomainController with PowerShell Script Block production (source)
- GetDomainGroup with PowerShell Script Block production (source)
- GetLocalUser with PowerShell Script Block production (source)
- GetNetTcpconnection with PowerShell Script Block production (source)
- GetWmiObject Ds Computer with PowerShell Script Block production (source)
- GetWmiObject Ds Group with PowerShell Script Block production (source)
- GetWmiObject DS User with PowerShell Script Block production (source)
- GetWmiObject User Account with PowerShell Script Block production (source)
- Git Clone Repository (PowerShell) (source)
- Go Run Execution (PowerShell) (source)
- Group Policy Editor Execution (PowerShell) (source)
- hh.exe Execution (PowerShell) (source)
- hh.exe Remote File Execution (PowerShell) (source)
- High Entropy Powershell (PowerShell) (source)
- HTTP_HTTPS Default Security Zone Modified to Local Machine (PowerShell) (source)
- Impacket atexec.py Execution (PowerShell) (source)
- Interactive Session on Remote Endpoint with PowerShell production (source)
- Invoke-DCOM.ps1 - PowerShell (PowerShell) (source)
- Invoke-Expression Command (PowerShell) (source)
- Invoke-WebRequest Command (PowerShell) (source)
- ISO Image Mounted - Windows (PowerShell) (source)
- Kerberos Pre-Authentication Flag Disabled with PowerShell production (source)
- Known Process Injection Commands (PowerShell) (source)
- LocalAccountTokenFilterPolicy Registry Value Modified (PowerShell) (source)
- Locate Credentials (PowerShell) (source)
- Logon Script Registry Key added (PowerShell) (source)
- LSA Authentication Packages Registry Key Modified (PowerShell) (source)
- Mailsniper Invoke functions production (source)
- masscan Execution - Windows (PowerShell) (source)
- Modify Exchange Access Settings (PowerShell) (source)
- Modify Windows Defender (PowerShell) (source)
- mshta.exe File Download (PowerShell) (source)
- MSI Installation via Appcert (PowerShell) (source)
- Native Archive Commands (PowerShell) (source)
- Network Share Connection Removal (PowerShell) (source)
- New AutoRun Registry Key (PowerShell) (source)
- ngen.exe File Download (PowerShell) (source)
- ngrok Execution - Windows (PowerShell) (source)
- NMAP Execution (PowerShell) (source)
- Non-MSIExec .msi Installation (PowerShell) (source)
- ntds.dit Command Line (PowerShell) (source)
- Output to File (PowerShell) (source)
- Package installation (PowerShell) (source)
- Permission Groups Discovery: Domain Groups (PowerShell) (source)
- Permission Groups Discovery: Local Groups (PowerShell) (source)
- Permissions Replaced by icacls - Windows (PowerShell) (source)
- Possible Credential Dumping via Windows Network Providers (PowerShell) (source)
- Potential AutoHotkey .ahk Execution (PowerShell) (source)
- Potential Cryptomining Commands (PowerShell) (source)
- Potential fodhelper UAC Bypass Attempt (PowerShell) (source)
- Potential LSA password filter (PowerShell) (source)
- Potential Proxy Malware via AutoRun Key (PowerShell) (source)
- Potential Sysinternals Tool Execution (PowerShell) (source)
- Potential Target Discovery via PowerShell Event Log Queries (PowerShell) (source)
- PowerShell 4104 Hunting production (source)
- PowerShell Clipboard Access (PowerShell) (source)
- Powershell COM Hijacking InprocServer32 Modification production (source)
- PowerShell CreateDecryptor (PowerShell) (source)
- Powershell Creating Thread Mutex production (source)
- Powershell DLL_EXE Injection (PowerShell) (source)
- PowerShell Domain Enumeration production (source)
- PowerShell Downgrade (PowerShell) (source)
- PowerShell Download Activity (PowerShell) (source)
- PowerShell DownloadFile_DownloadString (PowerShell) (source)
- PowerShell Enable PowerShell Remoting production (source)
- Powershell Enable SMB1Protocol Feature production (source)
- PowerShell Environment Variable Execution production (source)
- Powershell Execute COM Object production (source)
- Powershell Fileless Process Injection via GetProcAddress production (source)
- Powershell Fileless Script Contains Base64 Encoded Content production (source)
- Powershell Get LocalGroup Discovery with Script Block Logging production (source)
- PowerShell Hidden Window (PowerShell) (source)
- PowerShell Invoke CIMMethod CIMSession production (source)
- PowerShell Invoke WmiExec Usage production (source)
- Powershell Load Module in Meterpreter production (source)
- PowerShell Loading DotNET into Memory via Reflection production (source)
- PowerShell Modifying Registry Values (PowerShell) (source)
- PowerShell PInvoke Process Injection API Chain production (source)
- Powershell Processing Stream Of Data production (source)
- Powershell Remote Services Add TrustedHost production (source)
- Powershell Remove Windows Defender Directory production (source)
- PowerShell Script Block With URL Chain production (source)
- PowerShell Start or Stop Service production (source)
- Powershell Using memory As Backing Store production (source)
- PowerShell WebRequest Using Memory Stream production (source)
- Powershell Windows Defender Exclusion Commands production (source)
- PowerShell XML Retrieval (PowerShell) (source)
- PowerView_SharpView Commands (PowerShell) (source)
- PromptOnSecureDesktop Registry Value Modified (PowerShell) (source)
- ProtocolHandler.exe File Download (PowerShell) (source)
- Proxy Execution via Appcert (PowerShell) (source)
- PuTTY Secure Copy Client Execution (PowerShell) (source)
- QEMU Network Tunneling - Windows (PowerShell) (source)
- Query Registry (PowerShell) (source)
- Rclone Execution (PowerShell) (source)
- RDP Enabled (PowerShell) (source)
- RdrLeakDiag.exe Memory Dump (PowerShell) (source)
- Read-Only Attribute Removed - Windows (PowerShell) (source)
- Recon AVProduct Through Pwh or WMI production (source)
- Recon Using WMI Class production (source)
- Registry Entry Created - PowerShell (PowerShell) (source)
- regsvr32 Execution (PowerShell) (source)
- Remote .msi Installation (PowerShell) (source)
- Remote .msi Installation (PowerShell) (source)
- Remote Admin Tools (PowerShell) (source)
- Remote Process Instantiation via DCOM and PowerShell Script Block production (source)
- Remote Process Instantiation via WinRM and PowerShell Script Block production (source)
- Remote Process Instantiation via WMI and PowerShell Script Block production (source)
- Remote Share Directory Listing - Windows (PowerShell) (source)
- Remote System Discovery with Adsisearcher production (source)
- Remote WMIC Query (PowerShell) (source)
- Rubeus Commands (PowerShell) (source)
- Rundll32 Command Line (PowerShell) (source)
- Rundll32 Suspicious Command Line (PowerShell) (source)
- rundll32.exe Executing DLL from Non-standard Directory (PowerShell) (source)
- Scheduled Task with Potential SSH Tunnel - Windows (PowerShell) (source)
- Security Software Discovery via Findstr.exe (PowerShell) (source)
- Security Software Discovery via WMI (PowerShell) (source)
- Service Stop Commands (PowerShell) (source)
- ServicePrincipalNames Discovery with PowerShell production (source)
- SharpHound Keywords (PowerShell) (source)
- Shortcut Created in Startup Folder - Windows (PowerShell) (source)
- Sliver C2 Implant Activity Pattern (PowerShell) (source)
- Startup Folder Location Modified - Windows (PowerShell) (source)
- Stored Credentials from Web Browsers - Windows (PowerShell) (source)
- Suspicious DLLhost Execution (PowerShell) (source)
- Suspicious ntds.dit Commands (PowerShell) (source)
- Suspicious PowerShell Clipboard Activity (PowerShell) (source)
- Suspicious PowerShell Parameter Substring (PowerShell) (source)
- Suspicious reCAPTCHA Command Line (PowerShell) (source)
- Suspicious Registry Key Created (PowerShell) (source)
- Symbolic OR Hard File Link Created (PowerShell) (source)
- System Information Discovery - Windows (PowerShell) (source)
- System Network Connections Discovery - Windows (PowerShell) (source)
- System Owner_User Discovery - Windows (PowerShell) (source)
- Timestamp Manipulation (PowerShell) (source)
- Tunneling Process Created (PowerShell) (source)
- Unloading AMSI via Reflection production (source)
- User Discovery via Environment Variables - PowerShell (PowerShell) (source)
- User Discovery With Env Vars PowerShell Script Block production (source)
- User_Domain Enumeration Tool - Windows (PowerShell) (source)
- Utility Archive Data (PowerShell) (source)
- Visio.exe File Download (PowerShell) (source)
- WDigest Forced Credential Caching (PowerShell) (source)
- Windows - Service Stop (PowerShell) (source)
- Windows Account Discovery for None Disable User Account production (source)
- Windows Account Discovery for Sam Account Name production (source)
- Windows Account Discovery With NetUser PreauthNotRequire production (source)
- Windows Archive Collected Data via Powershell production (source)
- Windows Azure PowerShell Module Installation Via PowerShell Script production (source)
- Windows ClipBoard Data via Get-ClipBoard production (source)
- Windows Cobalt Strike PowerShell Loader production (source)
- Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script production (source)
- Windows Copy Files (PowerShell) (source)
- Windows Default Cobalt Strike PowerShell Beacon production (source)
- Windows Defender Disabled Detection (PowerShell) (source)
- Windows Domain Account Discovery Via Get-NetComputer production (source)
- Windows Enable PowerShell Web Access production (source)
- Windows ESX Admins Group Creation via PowerShell production (source)
- Windows Exfiltration Over C2 Via Invoke RestMethod production (source)
- Windows Exfiltration Over C2 Via Powershell UploadString production (source)
- Windows File Share Discovery With Powerview production (source)
- Windows Find Domain Organizational Units with GetDomainOU production (source)
- Windows Find Interesting ACL with FindInterestingDomainAcl production (source)
- Windows Firewall Disabled (PowerShell) (source)
- Windows Firewall Rule Creation (PowerShell) (source)
- Windows Forest Discovery with GetForestDomain production (source)
- Windows FTP Exfiltration (PowerShell) (source)
- Windows Gather Victim Host Information Camera production (source)
- Windows Get Local Admin with FindLocalAdminAccess production (source)
- Windows Get-AdComputer Unconstrained Delegation Discovery production (source)
- Windows LAPS Password Gathering Via PowerShell Script production (source)
- Windows Level RMM PowerShell Script Installer production (source)
- Windows Linked Policies In ADSI Discovery production (source)
- Windows PowerShell Add Module to Global Assembly Cache production (source)
- Windows Powershell Cryptography Namespace production (source)
- Windows PowerShell Disable HTTP Logging production (source)
- Windows PowerShell Export Certificate production (source)
- Windows PowerShell Export PfxCertificate production (source)
- Windows PowerShell Get CIMInstance Remote Computer production (source)
- Windows Powershell History File Deletion production (source)
- Windows PowerShell IIS Components WebGlobalModule Usage production (source)
- Windows Powershell Import Applocker Policy production (source)
- Windows PowerShell Invoke-RestMethod IP Information Collection production (source)
- Windows PowerShell Invoke-Sqlcmd Execution production (source)
- Windows Powershell Logoff User via Quser production (source)
- Windows PowerShell MSIX Package Installation production (source)
- Windows PowerShell ScheduleTask production (source)
- Windows PowerShell Script Block With Malicious String production (source)
- Windows PowerShell Script TabExpansion Direct Call production (source)
- Windows PowerShell WMI Win32 ScheduledJob production (source)
- Windows PowerSploit GPP Discovery production (source)
- Windows PowerView AD Access Control List Enumeration production (source)
- Windows PowerView Constrained Delegation Discovery production (source)
- Windows PowerView Kerberos Service Ticket Request production (source)
- Windows PowerView SPN Discovery production (source)
- Windows PowerView Unconstrained Delegation Discovery production (source)
- Windows Process Copied from System Folder (PowerShell) (source)
- Windows Root Domain linked policies Discovery production (source)
- Windows Screen Capture Via Powershell production (source)
- Windows Service Started (PowerShell) (source)
- Windows Software Discovery Via PowerShell production (source)
- Windows WinPEAS PowerShell Script Execution production (source)
- WinLogon Registry Key Modified (PowerShell) (source)
- WinRM Tools (PowerShell) (source)
- WMI Recon Running Process Or Services production (source)
- WMIC Host Reconniassance (PowerShell) (source)
- Wow6432Node Classes Autorun Keys Modification (PowerShell) (source)
- Wscript_Cscript Execution (PowerShell) (source)
Microsoft-Windows-TaskScheduler
Application-Error
Microsoft-Windows-AppxPackagingOM
Microsoft-Windows-CertificateServicesClient-Lifecycle-System
Event ID 1007 A certificate has been exported. 1 rule
- Windows Export Certificate production (source)