Detection.FYI
open-menu closeme
  • .RDP File Created By Uncommon Application

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects creation of a file with an ".rdp" extension by an application that doesn't commonly create such files.


    Read More
  • A Rule Has Been Deleted From The Windows Firewall Exception List

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects when a single rules or all of the rules have been deleted from the Windows Defender Firewall


    Read More
  • Abuse of Service Permissions to Hide Services Via Set-Service

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)


    Read More
  • Abuse of Service Permissions to Hide Services Via Set-Service - PS

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)


    Read More
  • Abused Debug Privilege by Arbitrary Parent Processes

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detection of unusual child processes by different system processes


    Read More
  • Abusing Print Executable

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Attackers can use print.exe for remote file copy


    Read More
  • Account Created And Deleted Within A Close Time Frame

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when an account was created and deleted in a short period of time.


    Read More
  • Account Disabled or Blocked for Sign in Attempts

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when an account is disabled or blocked for sign in but tried to log in


    Read More
  • Account Tampering - Suspicious Failed Logon Reasons

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.


    Read More
  • Activate Suppression of Windows Security Center Notifications

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect set Notification_Suppress to 1 to disable the Windows security center notification


    Read More
  • Active Directory Certificate Services Denied Certificate Enrollment Request

    calendar Apr 28, 2026 · attack.credential-access attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Detects denied requests by Active Directory Certificate Services. Example of these requests denial include issues with permissions on the certificate template or invalid signatures.


    Read More
  • Activity From Anonymous IP Address

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Identifies that users were active from an IP address that has been identified as an anonymous proxy IP address.


    Read More
  • AD Object WriteDAC Access

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222.001  ·
    Share on: twitter facebook linkedin copy

    Detects WRITE_DAC access to a domain object


    Read More
  • Add DisallowRun Execution to Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect set DisallowRun to 1 to prevent user running specific computer program


    Read More
  • Add Insecure Download Source To Winget

    calendar Apr 28, 2026 · attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects usage of winget to add a new insecure (http) download source. Winget will not allow the addition of insecure sources, hence this could indicate potential suspicious activity (or typos)


    Read More
  • Add New Download Source To Winget

    calendar Apr 28, 2026 · attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects usage of winget to add new additional download sources


    Read More
  • Add or Remove Computer from DC

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1207  ·
    Share on: twitter facebook linkedin copy

    Detects the creation or removal of a computer. Can be used to detect attacks such as DCShadow via the creation of a new SPN.


    Read More
  • Add Potential Suspicious New Download Source To Winget

    calendar Apr 28, 2026 · attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects usage of winget to add new potentially suspicious download sources


    Read More
  • Add SafeBoot Keys Via Reg Utility

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "reg.exe" commands with the "add" or "copy" flags on safe boot registry keys. Often used by attacker to allow the ransomware to work in safe mode as some security products do not


    Read More
  • AddinUtil.EXE Execution From Uncommon Directory

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Add-In deployment cache updating utility (AddInutil.exe) from a non-standard directory.


    Read More
  • Addition of SID History to Active Directory Object

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.stealth attack.t1134.005  ·
    Share on: twitter facebook linkedin copy

    An attacker can use the SID history attribute to gain additional privileges.


    Read More
  • Admin User Remote Logon

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.lateral-movement attack.initial-access attack.stealth attack.t1078.001 attack.t1078.002 attack.t1078.003 car.2016-04-005  ·
    Share on: twitter facebook linkedin copy

    Detect remote login by Administrator user (depending on internal pattern).


    Read More
  • ADS Zone.Identifier Deleted By Uncommon Application

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of the "Zone.Identifier" ADS by an uncommon process. Attackers can leverage this in order to bypass security restrictions that make use of the ADS such as Microsoft Office apps.


    Read More
  • AgentExecutor PowerShell Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument


    Read More
  • All Rules Have Been Deleted From The Windows Firewall Configuration

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects when a all the rules have been deleted from the Windows Defender Firewall configuration


    Read More
  • Allow RDP Remote Assistance Feature

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect enable rdp feature to allow specific user to rdp connect on the targeted machine


    Read More
  • Always Install Elevated MSI Spawned Cmd And Powershell

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects Windows Installer service (msiexec.exe) spawning "cmd" or "powershell"


    Read More
  • Always Install Elevated Windows Installer

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects Windows Installer service (msiexec.exe) trying to install MSI packages with SYSTEM privilege


    Read More
  • AMSI Bypass Pattern Assembly GetType

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects code fragments found in small and obfuscated AMSI bypass PowerShell scripts


    Read More
  • AMSI Disabled via Registry Modification

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to disable AMSI (Anti-Malware Scan Interface) by modifying the AmsiEnable registry value. Anti-Malware Scan Interface (AMSI) is a security feature in Windows that allows applications and services to integrate with anti-malware products for enhanced protection against malicious content. Adversaries may attempt to disable AMSI to evade detection by security software, allowing them to execute malicious scripts or code without being scanned.


    Read More
  • Amsi.DLL Loaded Via LOLBIN Process

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects loading of "Amsi.dll" by a living of the land process. This could be an indication of a "PowerShell without PowerShell" attack


    Read More
  • Antivirus Filter Driver Disallowed On Dev Drive - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects activity that indicates a user disabling the ability for Antivirus mini filter to inspect a "Dev Drive".


    Read More
  • Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 detection.emerging-threats cve.2021-34527 cve.2021-1675  ·
    Share on: twitter facebook linkedin copy

    Detects the suspicious file that is created from PoC code against Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527 (PrinterNightmare), CVE-2021-1675 .


    Read More
  • Application AppID Uri Configuration Changes

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.credential-access attack.privilege-escalation attack.stealth attack.t1552 attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a configuration change is made to an applications AppID URI.


    Read More
  • Application URI Configuration Changes

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1528 attack.t1078.004 attack.persistence attack.credential-access attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Detects when a configuration change is made to an applications URI. URIs for domain names that no longer exist (dangling URIs), not using HTTPS, wildcards at the end of the domain, URIs that are no unique to that app, or URIs that point to domains you do not control should be investigated.


    Read More
  • Application Using Device Code Authentication Flow

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Device code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments. If this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted. This can be a misconfigured application or potentially something malicious.


    Read More
  • Applications That Are Using ROPC Authentication Flow

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Resource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly. The application then uses those credentials to authenticate the user against the identity provider.


    Read More
  • AppX Located in Known Staging Directory Added to Deployment Pipeline

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects an appx package that was added to the pipeline of the "to be processed" packages that is located in a known folder often used as a staging directory.


    Read More
  • AppX Located in Uncommon Directory Added to Deployment Pipeline

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects an appx package that was added to the pipeline of the "to be processed" packages that is located in uncommon locations.


    Read More
  • AppX Package Deployment Failed Due to Signing Requirements

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects an appx package deployment / installation with the error code "0x80073cff" which indicates that the package didn't meet the signing requirements.


    Read More
  • APT PRIVATELOG Image Load Pattern

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects an image load pattern as seen when a tool named PRIVATELOG is used and rarely observed under legitimate circumstances


    Read More
  • APT27 - Emissary Panda Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 attack.g0027 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of DLL side-loading malware used by threat group Emissary Panda aka APT27


    Read More
  • APT29 2018 Phishing Campaign CommandLine Indicators

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant


    Read More
  • APT29 2018 Phishing Campaign File Indicators

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects indicators of APT 29 (Cozy Bear) phishing-campaign as reported by mandiant


    Read More
  • Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of arbitrary DLLs or unsigned code via a ".csproj" files via Dotnet.EXE.


    Read More
  • Arbitrary File Download Via IMEWDBLD.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "IMEWDBLD.exe" to download arbitrary files


    Read More
  • Arbitrary File Download Via MSEDGE_PROXY.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "msedge_proxy.exe" to download arbitrary files


    Read More
  • Arbitrary File Download Via MSOHTMED.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "MSOHTMED" to download arbitrary files


    Read More
  • Arbitrary File Download Via MSPUB.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "MSPUB" (Microsoft Publisher) to download arbitrary files


    Read More
  • Arbitrary File Download Via PresentationHost.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "PresentationHost" which is a utility that runs ".xbap" (Browser Applications) files to download arbitrary files


    Read More
  • Arbitrary File Download Via Squirrel.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of the "Squirrel.exe" to download arbitrary files. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)


    Read More
  • Arbitrary MSI Download Via Devinit.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects a certain command line flag combination used by "devinit.exe", which can be abused as a LOLBIN to download arbitrary MSI packages on a Windows system


    Read More
  • Aruba Network Service Potential DLL Sideloading

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading activity via the Aruba Networks Virtual Intranet Access "arubanetsvc.exe" process using DLL Search Order Hijacking


    Read More
  • ASLR Disabled Via Sysctl or Direct Syscall - Linux

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.defense-impairment attack.t1685 attack.t1055.009  ·
    Share on: twitter facebook linkedin copy

    Detects actions that disable Address Space Layout Randomization (ASLR) in Linux, including:

    • Use of the personality syscall with the ADDR_NO_RANDOMIZE flag (0x0040000)
    • Modification of the /proc/sys/kernel/randomize_va_space file
    • Execution of the sysctl command to set kernel.randomize_va_space=0 Disabling ASLR is often used by attackers during exploit development or to bypass memory protection mechanisms. A successful use of these methods can reduce the effectiveness of ASLR and make memory corruption attacks more reliable.


    Read More
  • AspNetCompiler Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "aspnet_compiler.exe" which can be abused to compile and execute C# code.


    Read More
  • Assembly Loading Via CL_LoadAssembly.ps1

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects calls to "LoadAssemblyFromPath" or "LoadAssemblyFromNS" that are part of the "CL_LoadAssembly.ps1" script. This can be abused to load different assemblies and bypass App locker controls.


    Read More
  • Atbroker Registry Change

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1218 attack.persistence attack.t1547  ·
    Share on: twitter facebook linkedin copy

    Detects creation/modification of Assistive Technology applications and persistence with usage of 'at'


    Read More
  • Atomic MacOS Stealer - Persistence Indicators

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.stealth attack.t1564.001 attack.t1543.004 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects creation of persistence artifacts placed by Atomic MacOS Stealer in macOS systems. Recent Atomic MacOS Stealer variants have been observed dropping these to maintain persistent access after compromise.


    Read More
  • Atypical Travel

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Identifies two sign-ins originating from geographically distant locations, where at least one of the locations may also be atypical for the user, given past behavior.


    Read More
  • Audit CVE Event

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1203 attack.privilege-escalation attack.t1068 attack.t1211 attack.credential-access attack.t1212 attack.lateral-movement attack.t1210 attack.impact attack.t1499.004  ·
    Share on: twitter facebook linkedin copy

    Detects events generated by user-mode applications when they call the CveEventWrite API when a known vulnerability is trying to be exploited. MS started using this log in Jan. 2020 with CVE-2020-0601 (a Windows CryptoAPI vulnerability. Unfortunately, that is about the only instance of CVEs being written to this log.


    Read More
  • Audit Policy Tampering Via Auditpol

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Threat actors can use auditpol binary to change audit policy configuration to impair detection capability. This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.


    Read More
  • Audit Policy Tampering Via NT Resource Kit Auditpol

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Threat actors can use an older version of the auditpol binary available inside the NT resource kit to change audit policy configuration to impair detection capability. This can be carried out by selectively disabling/removing certain audit policies as well as restoring a custom policy owned by the threat actor.


    Read More
  • Audit Rules Deleted Via Auditctl

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.004  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of 'auditctl' with the '-D' command line parameter, which deletes all configured audit rules and watches on Linux systems. This technique is commonly used by attackers to disable audit logging and cover their tracks by removing monitoring capabilities. Removal of audit rules can significantly impair detection of malicious activities on the affected system.


    Read More
  • Auditing Configuration Changes on Linux Host

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detect changes in auditd configuration files


    Read More
  • Authentications To Important Apps Using Single Factor Authentication

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detect when authentications to important application(s) only required single-factor authentication


    Read More
  • AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)


    Read More
  • AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects execution of attacker-controlled WsmPty.xsl or WsmTxt.xsl via winrm.vbs and copied cscript.exe (can be renamed)


    Read More
  • AWS Bucket Deleted

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of S3 buckets in AWS CloudTrail logs. Monitoring the deletion of S3 buckets is critical for security and data integrity, as it may indicate potential data loss or unauthorized access attempts.


    Read More
  • AWS CloudTrail Important Change

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.002  ·
    Share on: twitter facebook linkedin copy

    Detects disabling, deleting and updating of a Trail


    Read More
  • AWS Config Disabling Channel/Recorder

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.002  ·
    Share on: twitter facebook linkedin copy

    Detects AWS Config Service disabling


    Read More
  • AWS Console GetSigninToken Potential Abuse

    calendar Apr 28, 2026 · attack.lateral-movement attack.t1021.007 attack.t1550.001  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious events involving "GetSigninToken". An adversary using the "aws_consoler" tool can leverage this console API to create temporary federated credential that help obfuscate which AWS credential is compromised (the original access key) and enables the adversary to pivot from the AWS CLI to console sessions without the need for MFA using the new access key issued in this request.


    Read More
  • AWS GuardDuty Detector Deleted Or Updated

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685 attack.t1685.002  ·
    Share on: twitter facebook linkedin copy

    Detects successful deletion or disabling of an AWS GuardDuty detector, possibly by an attacker trying to avoid detection of its malicious activities. Upon deletion, GuardDuty stops monitoring the environment and all existing findings are lost. Verify with the user identity that this activity is legitimate.


    Read More
  • AWS GuardDuty Important Change

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects updates of the GuardDuty list of trusted IPs, perhaps to disable security alerts against malicious IPs.


    Read More
  • AWS IAM S3Browser LoginProfile Creation

    calendar Apr 28, 2026 · attack.execution attack.persistence attack.initial-access attack.privilege-escalation attack.stealth attack.t1059.009 attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects S3 Browser utility performing reconnaissance looking for existing IAM Users without a LoginProfile defined then (when found) creating a LoginProfile.


    Read More
  • AWS IAM S3Browser Templated S3 Bucket Policy Creation

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.009 attack.persistence attack.initial-access attack.privilege-escalation attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of "".


    Read More
  • AWS IAM S3Browser User or AccessKey Creation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.initial-access attack.stealth attack.t1059.009 attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects S3 Browser utility creating IAM User or AccessKey.


    Read More
  • AWS Identity Center Identity Provider Change

    calendar Apr 28, 2026 · attack.persistence attack.credential-access attack.defense-impairment attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Detects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider allows an attacker to establish persistent access or escalate privileges via user impersonation.


    Read More
  • AWS Key Pair Import Activity

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Detects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.


    Read More
  • AWS Root Credentials

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects AWS root account usage


    Read More
  • AWS SAML Provider Deletion Activity

    calendar Apr 28, 2026 · attack.stealth attack.t1078.004 attack.privilege-escalation attack.initial-access attack.persistence attack.t1531 attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of an AWS SAML provider, potentially indicating malicious intent to disrupt administrative or security team access. An attacker can remove the SAML provider for the information security team or a team of system administrators, to make it difficult for them to work and investigate at the time of the attack and after it.


    Read More
  • AWS SecurityHub Findings Evasion

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the modification of the findings on SecurityHub.


    Read More
  • AWS STS AssumeRole Misuse

    calendar Apr 28, 2026 · attack.lateral-movement attack.privilege-escalation attack.t1548 attack.t1550 attack.t1550.001  ·
    Share on: twitter facebook linkedin copy

    Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.


    Read More
  • AWS STS GetSessionToken Misuse

    calendar Apr 28, 2026 · attack.lateral-movement attack.privilege-escalation attack.t1548 attack.t1550 attack.t1550.001  ·
    Share on: twitter facebook linkedin copy

    Identifies the suspicious use of GetSessionToken. Tokens could be created and used by attackers to move laterally and escalate privileges.


    Read More
  • AWS Successful Console Login Without MFA

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.


    Read More
  • AWS Suspicious SAML Activity

    calendar Apr 28, 2026 · attack.initial-access attack.lateral-movement attack.persistence attack.privilege-escalation attack.stealth attack.t1078 attack.t1548 attack.t1550 attack.t1550.001  ·
    Share on: twitter facebook linkedin copy

    Identifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.


    Read More
  • AWS VPC Flow Logs Deleted

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of one or more VPC Flow Logs in AWS Elastic Compute Cloud (EC2) through the DeleteFlowLogs API call. Adversaries may delete flow logs to evade detection or remove evidence of network activity, hindering forensic investigations and visibility into malicious operations.


    Read More
  • Axios NPM Compromise Indicators - Linux

    calendar Apr 28, 2026 · attack.initial-access attack.t1195.002 attack.execution attack.command-and-control attack.t1059.006 attack.t1059.004 attack.t1105 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the Linux-specific execution chain of the plain-crypto-js malicious npm dependency by Axios NPM package, including payload download via curl and detached execution using nohup and python3. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection.


    Read More
  • Axios NPM Compromise Indicators - macOS

    calendar Apr 28, 2026 · attack.initial-access attack.t1195.002 attack.execution attack.command-and-control attack.t1059.002 attack.t1059.004 attack.t1105 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the macOS-specific execution chain of the plain-crypto-js malicious npm dependency in Axios NPM Package, including AppleScript execution via osascript, payload download, permission modification, execution, and cleanup.


    Read More
  • Axios NPM Compromise Indicators - Windows

    calendar Apr 28, 2026 · attack.initial-access attack.t1195.002 attack.execution attack.command-and-control attack.t1059.003 attack.t1059.005 attack.t1105 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the specific Windows execution chain and process tree associated with the Axios NPM supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection. The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.


    Read More
  • Azure Active Directory Hybrid Health AD FS New Server

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1578  ·
    Share on: twitter facebook linkedin copy

    This detection uses azureactivity logs (Administrative category) to identify the creation or update of a server instance in an Azure AD Hybrid health AD FS service. A threat actor can create a new AD Health ADFS service and create a fake server instance to spoof AD FS signing logs. There is no need to compromise an on-prem AD FS server. This can be done programmatically via HTTP requests to Azure.


    Read More
  • Azure Active Directory Hybrid Health AD FS Service Delete

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1578.003  ·
    Share on: twitter facebook linkedin copy

    This detection uses azureactivity logs (Administrative category) to identify the deletion of an Azure AD Hybrid health AD FS service instance in a tenant. A threat actor can create a new AD Health ADFS service and create a fake server to spoof AD FS signing logs. The health AD FS service can then be deleted after it is not longer needed via HTTP requests to Azure.


    Read More
  • Azure AD Only Single Factor Authentication Required

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.defense-impairment attack.t1078.004 attack.t1556.006  ·
    Share on: twitter facebook linkedin copy

    Detect when users are authenticating without MFA being required.


    Read More
  • Azure AD Threat Intelligence

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Indicates user activity that is unusual for the user or consistent with known attack patterns.


    Read More
  • Azure Application Deleted

    calendar Apr 28, 2026 · attack.impact attack.t1489  ·
    Share on: twitter facebook linkedin copy

    Identifies when a application is deleted in Azure.


    Read More
  • Azure Domain Federation Settings Modified

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Identifies when an user or application modified the federation settings on the domain.


    Read More
  • Azure Firewall Modified or Deleted

    calendar Apr 28, 2026 · attack.impact attack.defense-impairment attack.t1686.001  ·
    Share on: twitter facebook linkedin copy

    Identifies when a firewall is created, modified, or deleted.


    Read More
  • Azure Firewall Rule Collection Modified or Deleted

    calendar Apr 28, 2026 · attack.impact attack.defense-impairment attack.t1686.001  ·
    Share on: twitter facebook linkedin copy

    Identifies when Rule Collections (Application, NAT, and Network) is being modified or deleted.


    Read More
  • Azure Kubernetes Admission Controller

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078 attack.credential-access attack.t1552 attack.t1552.007  ·
    Share on: twitter facebook linkedin copy

    Identifies when an admission controller is executed in Azure Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.


    Read More
  • Azure Kubernetes Events Deleted

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when Events are deleted in Azure Kubernetes. An adversary may delete events in Azure Kubernetes in an attempt to evade detection.


    Read More
  • Azure Login Bypassing Conditional Access Policies

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects a successful login to the Microsoft Intune Company Portal which could allow bypassing Conditional Access Policies and InTune device trust using a tool like TokenSmith.


    Read More
  • Azure Network Firewall Policy Modified or Deleted

    calendar Apr 28, 2026 · attack.impact attack.defense-impairment attack.t1686.001  ·
    Share on: twitter facebook linkedin copy

    Identifies when a Firewall Policy is Modified or Deleted.


    Read More
  • Azure Owner Removed From Application or Service Principal

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Identifies when a owner is was removed from a application or service principal in Azure.


    Read More
  • Azure Service Principal Created

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Identifies when a service principal is created in Azure.


    Read More
  • Azure Service Principal Removed

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Identifies when a service principal was removed in Azure.


    Read More
  • Azure Subscription Permission Elevation Via ActivityLogs

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.


    Read More
  • Azure Subscription Permission Elevation Via AuditLogs

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.


    Read More
  • Azure Unusual Authentication Interruption

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when there is a interruption in the authentication process.


    Read More
  • BaaUpdate.exe Suspicious DLL Load

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.lateral-movement attack.t1021.003  ·
    Share on: twitter facebook linkedin copy

    Detects BitLocker Access Agent Update Utility (baaupdate.exe) loading DLLs from suspicious locations that are publicly writable which could indicate an attempt to lateral movement via BitLocker DCOM & COM Hijacking. This technique abuses COM Classes configured as INTERACTIVE USER to spawn processes in the context of the logged-on user's session. Specifically, it targets the BDEUILauncher Class (CLSID ab93b6f1-be76-4185-a488-a9001b105b94) which can launch BaaUpdate.exe, which is vulnerable to COM Hijacking when started with input parameters. This allows attackers to execute code in the user's context without needing to steal credentials or use additional techniques to compromise the account.


    Read More
  • Backup Catalog Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects backup catalog deletions


    Read More
  • Bad Opsec Defaults Sacrificial Processes With Improper Arguments

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects attackers using tooling with bad opsec defaults. E.g. spawning a sacrificial process to inject a capability into the process without taking into account how the process is normally run. One trivial example of this is using rundll32.exe without arguments as a sacrificial process (default in CS, now highlighted by c2lint), running WerFault without arguments (Kraken - credit am0nsec), and other examples.


    Read More
  • Base64 Encoded PowerShell Command Detected

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1140 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "FromBase64String" function in the commandline which is used to decode a base64 encoded string


    Read More
  • Binary Padding - Linux

    calendar Apr 28, 2026 · attack.stealth attack.t1027.001  ·
    Share on: twitter facebook linkedin copy

    Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.


    Read More
  • Binary Padding - MacOS

    calendar Apr 28, 2026 · attack.stealth attack.t1027.001  ·
    Share on: twitter facebook linkedin copy

    Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.


    Read More
  • Binary Proxy Execution Via Dotnet-Trace.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects commandline arguments for executing a child process via dotnet-trace.exe


    Read More
  • Bitbucket Audit Log Configuration Updated

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the bitbucket audit log configuration.


    Read More
  • Bitbucket Global Secret Scanning Rule Deleted

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects Bitbucket global secret scanning rule deletion activity.


    Read More
  • Bitbucket Global SSH Settings Changed

    calendar Apr 28, 2026 · attack.lateral-movement attack.defense-impairment attack.t1685 attack.t1021.004  ·
    Share on: twitter facebook linkedin copy

    Detects Bitbucket global SSH access configuration changes.


    Read More
  • Bitbucket Project Secret Scanning Allowlist Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when a secret scanning allowlist rule is added for projects.


    Read More
  • Bitbucket Secret Scanning Exempt Repository Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when a repository is exempted from secret scanning feature.


    Read More
  • Bitbucket Secret Scanning Rule Deleted

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when secret scanning rule is deleted for the project or repository.


    Read More
  • Bitbucket User Login Failure

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1078.004 attack.t1110  ·
    Share on: twitter facebook linkedin copy

    Detects user authentication failure events. Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.


    Read More
  • Bitlocker Key Retrieval

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert for Bitlocker key retrieval.


    Read More
  • BitLockerTogo.EXE Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "BitLockerToGo.EXE". BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system. This is a rarely used application and usage of it at all is worth investigating. Malware such as Lumma stealer has been seen using this process as a target for process hollowing.


    Read More
  • BITS Transfer Job Download From Direct IP

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    Detects a BITS transfer job downloading file(s) from a direct IP address.


    Read More
  • BITS Transfer Job Download From File Sharing Domains

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    Detects BITS transfer job downloading files from a file sharing domain.


    Read More
  • BITS Transfer Job Download To Potential Suspicious Folder

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    Detects new BITS transfer job where the LocalName/Saved file is stored in a potentially suspicious location


    Read More
  • BITS Transfer Job Downloading File Potential Suspicious Extension

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    Detects new BITS transfer job saving local files with potential suspicious extensions


    Read More
  • BITS Transfer Job With Uncommon Or Suspicious Remote TLD

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious download using the BITS client from a FQDN that is unusual. Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads.


    Read More
  • Bitsadmin to Uncommon IP Server Address

    calendar Apr 28, 2026 · attack.command-and-control attack.execution attack.stealth attack.t1071.001 attack.persistence attack.t1197 attack.s0190  ·
    Share on: twitter facebook linkedin copy

    Detects Bitsadmin connections to IP addresses instead of FQDN names


    Read More
  • Bitsadmin to Uncommon TLD

    calendar Apr 28, 2026 · attack.command-and-control attack.execution attack.stealth attack.t1071.001 attack.persistence attack.t1197 attack.s0190  ·
    Share on: twitter facebook linkedin copy

    Detects Bitsadmin connections to domains with uncommon TLDs


    Read More
  • Blackbyte Ransomware Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects specific windows registry modifications made by BlackByte ransomware variants. BlackByte set three different registry values to escalate privileges and begin setting the stage for lateral movement and encryption. This rule triggers when any of the following registry keys are set to DWORD 1, however all three should be investigated as part of a larger BlackByte ransomware detection and response effort.


    Read More
  • Blue Mockingbird

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.defense-impairment attack.t1112 attack.t1047 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Attempts to detect system changes made by Blue Mockingbird


    Read More
  • Blue Mockingbird - Registry

    calendar Apr 28, 2026 · attack.execution attack.persistence attack.defense-impairment attack.t1112 attack.t1047 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Attempts to detect system changes made by Blue Mockingbird


    Read More
  • Bpfdoor TCP Ports Redirect

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686  ·
    Share on: twitter facebook linkedin copy

    All TCP traffic on particular port from attacker is routed to different port. ex. '/sbin/iptables -t nat -D PREROUTING -p tcp -s 192.168.1.1 --dport 22 -j REDIRECT --to-ports 42392' The traffic looks like encrypted SSH communications going to TCP port 22, but in reality is being directed to the shell port once it hits the iptables rule for the attacker host only.


    Read More
  • Browser Execution In Headless Mode

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth attack.t1105 attack.t1564.003  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Chromium based browser in headless mode


    Read More
  • Bypass UAC Using DelegateExecute

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Bypasses User Account Control using a fileless method


    Read More
  • Bypass UAC Using SilentCleanup Task

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the setting of the environement variable "windir" to a non default value. Attackers often abuse this variable in order to trigger a UAC bypass via the "SilentCleanup" task. The SilentCleanup task located in %windir%\system32\cleanmgr.exe is an auto-elevated task that can be abused to elevate any file with administrator privileges without prompting UAC.


    Read More
  • Bypass UAC via CMSTP

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1548.002 attack.t1218.003  ·
    Share on: twitter facebook linkedin copy

    Detect commandline usage of Microsoft Connection Manager Profile Installer (cmstp.exe) to install specially formatted local .INF files


    Read More
  • Bypass UAC via Fodhelper.exe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Identifies use of Fodhelper.exe to bypass User Account Control. Adversaries use this technique to execute privileged processes.


    Read More
  • Bypass UAC via WSReset.exe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects use of WSReset.exe to bypass User Account Control (UAC). Adversaries use this technique to execute privileged processes.


    Read More
  • C# IL Code Compilation Via Ilasm.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects the use of "Ilasm.EXE" in order to compile C# intermediate (IL) code to EXE or DLL.


    Read More
  • CA Policy Removed by Non Approved Actor

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert on conditional access changes where non approved actor removed CA Policy.


    Read More
  • CA Policy Updated by Non Approved Actor

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert on conditional access changes. Is Initiated by (actor) approved to make changes? Review Modified Properties and compare "old" vs "new" value.


    Read More
  • Certificate Exported Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the certutil with the "exportPFX" flag which allows the utility to export certificates.


    Read More
  • Certificate-Based Authentication Enabled

    calendar Apr 28, 2026 · attack.credential-access attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Detects when certificate based authentication has been enabled in an Azure Active Directory tenant.


    Read More
  • Change the Fax Dll

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect possible persistence using Fax DLL load when service restart


    Read More
  • Change to Authentication Method

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.defense-impairment attack.t1556 attack.persistence attack.t1098  ·
    Share on: twitter facebook linkedin copy

    Change to authentication method could be an indicator of an attacker adding an auth method to the account so they can have continued access.


    Read More
  • Change User Account Associated with the FAX Service

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect change of the user account associated with the FAX service to avoid the escalation problem.


    Read More
  • Change Winevt Channel Access Permission Via Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects tampering with the "ChannelAccess" registry key in order to change access to Windows event channel.


    Read More
  • Changes to Device Registration Policy

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1484  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert for changes to the device registration policy.


    Read More
  • Changes To PIM Settings

    calendar Apr 28, 2026 · attack.initial-access attack.privilege-escalation attack.persistence attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when changes are made to PIM roles


    Read More
  • Changing Existing Service ImagePath Value Via Reg.EXE

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services


    Read More
  • Chmod Targeting Sensitive Directories

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222.002  ·
    Share on: twitter facebook linkedin copy

    Detects chmod targeting files in sensitive directory paths on Linux systems. Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.


    Read More
  • Cisco BGP Authentication Failures

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.credential-access attack.collection attack.stealth attack.t1078 attack.t1110 attack.t1557  ·
    Share on: twitter facebook linkedin copy

    Detects BGP failures which may be indicative of brute force attacks to manipulate routing


    Read More
  • Cisco Clear Logs

    calendar Apr 28, 2026 · attack.stealth attack.t1070.003  ·
    Share on: twitter facebook linkedin copy

    Clear command history in network OS which is used for defense evasion


    Read More
  • Cisco Crypto Commands

    calendar Apr 28, 2026 · attack.credential-access attack.defense-impairment attack.t1553.004 attack.t1552.004  ·
    Share on: twitter facebook linkedin copy

    Show when private keys are being exported from the device, or when new certificates are installed


    Read More
  • Cisco Disabling Logging

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Turn off logging locally or remote


    Read More
  • Cisco Dot1x Disabled

    calendar Apr 28, 2026 · attack.persistence attack.credential-access attack.defense-impairment attack.t1685 attack.t1556.004  ·
    Share on: twitter facebook linkedin copy

    Detects the manual disablement of IEEE 802.1X (dot1x) on a Cisco network device interface. Disabling dot1x bypasses Network Access Control (NAC) mechanisms, potentially allowing unauthorized devices to gain access to the internal network. This activity is a common technique used by attackers or malicious insiders to establish persistence or perform lateral movement via rogue devices.


    Read More
  • Cisco Duo Successful MFA Authentication Via Bypass Code

    calendar Apr 28, 2026 · attack.credential-access attack.initial-access attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects when a successful MFA authentication occurs due to the use of a bypass code. A bypass code is a temporary passcode created by an administrator for a specific user to access a Duo-protected application. These are generally used as "backup codes," so that enrolled users who are having problems with their mobile devices (e.g., mobile service is disrupted, the device is lost or stolen, etc.) or who temporarily can't use their enrolled devices (on a plane without mobile data services) can still access their Duo-protected systems.


    Read More
  • Cisco File Deletion

    calendar Apr 28, 2026 · attack.impact attack.stealth attack.t1070.004 attack.t1561.001 attack.t1561.002  ·
    Share on: twitter facebook linkedin copy

    See what files are being deleted from flash file systems


    Read More
  • Cisco LDP Authentication Failures

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.credential-access attack.collection attack.stealth attack.t1078 attack.t1110 attack.t1557  ·
    Share on: twitter facebook linkedin copy

    Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels


    Read More
  • Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.006  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the syslog syscall with action code 5 (SYSLOG_ACTION_CLEAR), (4 is SYSLOG_ACTION_READ_CLEAR and 6 is SYSLOG_ACTION_CONSOLE_OFF) which clears the kernel ring buffer (dmesg logs). This can be used by attackers to hide traces after exploitation or privilege escalation. A common technique is running dmesg -c, which triggers this syscall internally.


    Read More
  • Clearing Windows Console History

    calendar Apr 28, 2026 · attack.stealth attack.t1070 attack.t1070.003  ·
    Share on: twitter facebook linkedin copy

    Identifies when a user attempts to clear console history. An adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.


    Read More
  • ClickOnce Trust Prompt Tampering

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the ClickOnce trust prompt registry key in order to enable an installation from different locations such as the Internet.


    Read More
  • Cmd Launched with Hidden Start Flags to Suspicious Targets

    calendar Apr 28, 2026 · attack.stealth attack.t1564.003  ·
    Share on: twitter facebook linkedin copy

    Detects cmd.exe executing commands with the "start" utility using "/b" (no window) or "/min" (minimized) flags. To reduce false positives from standard background tasks, detection is restricted to scenarios where the target is a known script extension or located in suspicious temporary/public directories. This technique was observed in Chaos, DarkSide, and Emotet malware campaigns.


    Read More
  • CMSTP Execution Process Access

    calendar Apr 28, 2026 · attack.stealth attack.t1218.003 attack.execution attack.t1559.001 attack.g0069 attack.g0080 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects various indicators of Microsoft Connection Manager Profile Installer execution


    Read More
  • CMSTP Execution Process Creation

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.003 attack.g0069 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects various indicators of Microsoft Connection Manager Profile Installer execution


    Read More
  • CMSTP Execution Registry Event

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.003 attack.g0069 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects various indicators of Microsoft Connection Manager Profile Installer execution


    Read More
  • CMSTP UAC Bypass via COM Object Access

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.stealth attack.t1548.002 attack.t1218.003 attack.g0069 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)


    Read More
  • CobaltStrike Load by Rundll32

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Rundll32 can be use by Cobalt Strike with StartW function to load DLLs from the command line.


    Read More
  • CobaltStrike Named Pipe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a named pipe as used by CobaltStrike


    Read More
  • CobaltStrike Named Pipe Pattern Regex

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a named pipe matching a pattern used by CobaltStrike Malleable C2 profiles


    Read More
  • CobaltStrike Named Pipe Patterns

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 stp.1k  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a named pipe with a pattern found in CobaltStrike malleable C2 profiles


    Read More
  • Code Execution via Pcwutl.dll

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects launch of executable by calling the LaunchApplication function from pcwutl.dll library.


    Read More
  • Code Injection by ld.so Preload

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.006  ·
    Share on: twitter facebook linkedin copy

    Detects the ld.so preload persistence file. See man ld.so for more information.


    Read More
  • CodePage Modification Via MODE.COM To Russian Language

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects a CodePage modification using the "mode.com" utility to Russian language. This behavior has been used by threat actors behind Dharma ransomware.


    Read More
  • COLDSTEEL Persistence Service Creation

    calendar Apr 28, 2026 · attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of new services potentially related to COLDSTEEL RAT


    Read More
  • COLDSTEEL RAT Anonymous User Process Execution

    calendar Apr 28, 2026 · attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a process executing as user called "ANONYMOUS" seen used by the "MileStone2016" variant of COLDSTEEL


    Read More
  • COLDSTEEL RAT Cleanup Command Execution

    calendar Apr 28, 2026 · attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a "rundll32" process from the ColdSteel persistence service to initiate the cleanup command by calling one of its own exports. This functionality is not present in "MileStone2017" and some "MileStone2016" samples


    Read More
  • COLDSTEEL RAT Service Persistence Execution

    calendar Apr 28, 2026 · attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of an "svchost" process with specific command line flags, that were seen present and used by ColdSteel RAT


    Read More
  • COM Hijack via Sdclt

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.t1546 attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects changes to 'HKCU\Software\Classes\Folder\shell\open\command\DelegateExecute'


    Read More
  • COM Object Execution via Xwizard.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of Xwizard tool with the "RunWizard" flag and a GUID like argument. This utility can be abused in order to run custom COM object created in the registry.


    Read More
  • Commvault QLogin with PublicSharingUser and GUID Password (CVE-2025-57788)

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.001 detection.emerging-threats cve.2025-57788  ·
    Share on: twitter facebook linkedin copy

    Detects a qlogin.exe command attempting to authenticate as the internal _+_PublicSharingUser_ using a GUID as the password. This could be an indicator of an attacker exploiting CVE-2025-57788 to gain initial access using leaked credentials.


    Read More
  • ComRAT Network Communication

    calendar Apr 28, 2026 · attack.command-and-control attack.t1071.001 attack.g0010 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Turla ComRAT network communication.


    Read More
  • Connection Proxy

    calendar Apr 28, 2026 · attack.command-and-control attack.t1090  ·
    Share on: twitter facebook linkedin copy

    Detects setting proxy configuration


    Read More
  • Control Panel Items

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.stealth attack.t1218.002 attack.persistence attack.t1546  ·
    Share on: twitter facebook linkedin copy

    Detects the malicious use of a control panel item


    Read More
  • ConvertTo-SecureString Cmdlet Usage Via CommandLine

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "ConvertTo-SecureString" cmdlet via the commandline. Which is fairly uncommon and could indicate potential suspicious activity


    Read More
  • CrashControl CrashDump Disabled

    calendar Apr 28, 2026 · attack.persistence attack.stealth attack.defense-impairment attack.t1564 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects disabling the CrashDump per registry (as used by HermeticWiper)


    Read More
  • Created Files by Microsoft Sync Center

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    This rule detects suspicious files created by Microsoft Sync Center (mobsync)


    Read More
  • CreateDump Process Dump

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1003.001 attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects uses of the createdump.exe LOLOBIN utility to dump process memory


    Read More
  • Creation Of a Suspicious ADS File Outside a Browser Download

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a suspicious ADS (Alternate Data Stream) file by software other than browsers


    Read More
  • Creation Of Non-Existent System DLL

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects creation of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes. Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs. Thus, the creation of such DLLs may indicate preparation for phantom DLL hijacking attacks.


    Read More
  • Creation Of Pod In System Namespace

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects deployments of pods within the kube-system namespace, which could be intended to imitate system pods. System pods, created by controllers such as Deployments or DaemonSets have random suffixes in their names. Attackers can use this fact and name their backdoor pods as if they were created by these controllers to avoid detection. Deployment of such a backdoor container e.g. named kube-proxy-bv61v, could be attempted in the kube-system namespace alongside the other administrative containers.


    Read More
  • Creation of WerFault.exe/Wer.dll in Unusual Folder

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file named "WerFault.exe" or "wer.dll" in an uncommon folder, which could be a sign of WerFault DLL hijacking.


    Read More
  • Credential Dumping Attempt Via Svchost

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects when a process tries to access the memory of svchost to potentially dump credentials.


    Read More
  • Csc.EXE Execution Form Potentially Suspicious Parent

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.005 attack.t1059.007 attack.t1218.005 attack.t1027.004  ·
    Share on: twitter facebook linkedin copy

    Detects a potentially suspicious parent of "csc.exe", which could be a sign of payload delivery.


    Read More
  • Curl Download And Execute Combination

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Adversaries can use curl to download payloads remotely and execute them. Curl is included by default in Windows 10 build 17063 and later.


    Read More
  • Custom File Open Handler Executes PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the abuse of custom file open handler, executing powershell


    Read More
  • CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.defense-impairment attack.t1112 cve.2020-1048 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "Ports" registry key with data that includes a Windows path or a file with a suspicious extension. This could be an attempt to exploit CVE-2020-1048 - a Windows Print Spooler elevation of privilege vulnerability.


    Read More
  • Decode Base64 Encoded Text

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects usage of base64 utility to decode arbitrary base64-encoded text


    Read More
  • Decode Base64 Encoded Text -MacOs

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects usage of base64 utility to decode arbitrary base64-encoded text


    Read More
  • Delete Defender Scan ShellEx Context Menu Registry Key

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects deletion of registry key that adds 'Scan with Defender' option in context menu. Attackers may use this to make it harder for users to scan files that are suspicious.


    Read More
  • Deployment AppX Package Was Blocked By AppLocker

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects an appx package deployment that was blocked by AppLocker policy.


    Read More
  • Deployment Of The AppX Package Was Blocked By The Policy

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects an appx package deployment that was blocked by the local computer policy. The following events indicate that an AppX package deployment was blocked by a policy:

    • Event ID 441: The package deployment operation is blocked by the "Allow deployment operations in special profiles" policy
    • Event ID 442: Deployments to non-system volumes are blocked by the "Disable deployment of Windows Store apps to non-system volumes" policy."
    • Event ID 453: Package blocked by a platform policy.
    • Event ID 454: Package blocked by a platform policy.


    Read More
  • Detection of PowerShell Execution via Sqlps.exe

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1127  ·
    Share on: twitter facebook linkedin copy

    This rule detects execution of a PowerShell code through the sqlps.exe utility, which is included in the standard set of utilities supplied with the MSSQL Server. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.


    Read More
  • Devcon Execution Disabling VMware VMCI Device

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1543.003 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of devcon.exe with commands that disable the VMware Virtual Machine Communication Interface (VMCI) device. This can be legitimate during VMware Tools troubleshooting or driver conflicts, but may also indicate malware attempting to hijack communication with the hardware via the VMCI device. This has been used to facilitate VMware ESXi vulnerability exploits to escape VMs and execute code on the ESXi host.


    Read More
  • Device Registration or Join Without MFA

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert for device registration or join events where MFA was not performed.


    Read More
  • DeviceCredentialDeployment Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of DeviceCredentialDeployment to hide a process from view.


    Read More
  • Devtoolslauncher.exe Executes Specified Binary

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    The Devtoolslauncher.exe executes other binary


    Read More
  • DHCP Callout DLL Installation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.defense-impairment attack.t1574.001 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the installation of a Callout DLL via CalloutDlls and CalloutEnabled parameter in Registry, which can be used to execute code in context of the DHCP server (restart required)


    Read More
  • DHCP Server Error Failed Loading the CallOut DLL

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    This rule detects a DHCP server error in which a specified Callout DLL (in registry) could not be loaded


    Read More
  • DHCP Server Loaded the CallOut DLL

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    This rule detects a DHCP server in which a specified Callout DLL (in registry) was loaded


    Read More
  • Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1202 cve.2022-30190  ·
    Share on: twitter facebook linkedin copy

    Detects both of CVE-2022-30190 (Follina) and DogWalk vulnerabilities exploiting msdt.exe binary to load the "sdiageng.dll" library


    Read More
  • Diamond Sleet APT DLL Sideloading Indicators

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects DLL sideloading activity seen used by Diamond Sleet APT


    Read More
  • Diamond Sleet APT Scheduled Task Creation - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects registry event related to the creation of a scheduled task used by Diamond Sleet APT during exploitation of Team City CVE-2023-42793 vulnerability


    Read More
  • Directory Removal Via Rmdir

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the builtin "rmdir" command in order to delete directories. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.


    Read More
  • Directory Service Restore Mode(DSRM) Registry Value Tampering

    calendar Apr 28, 2026 · attack.credential-access attack.persistence attack.defense-impairment attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Detects changes to "DsrmAdminLogonBehavior" registry value. During a Domain Controller (DC) promotion, administrators create a Directory Services Restore Mode (DSRM) local administrator account with a password that rarely changes. The DSRM account is an “Administrator” account that logs in with the DSRM mode when the server is booting up to restore AD backups or recover the server from a failure. Attackers could abuse DSRM account to maintain their persistence and access to the organization's Active Directory. If the "DsrmAdminLogonBehavior" value is set to "0", the administrator account can only be used if the DC starts in DSRM. If the "DsrmAdminLogonBehavior" value is set to "1", the administrator account can only be used if the local AD DS service is stopped. If the "DsrmAdminLogonBehavior" value is set to "2", the administrator account can always be used.


    Read More
  • Disable Administrative Share Creation at Startup

    calendar Apr 28, 2026 · attack.stealth attack.t1070.005  ·
    Share on: twitter facebook linkedin copy

    Administrative shares are hidden network shares created by Microsoft Windows NT operating systems that grant system administrators remote access to every disk volume on a network-connected system


    Read More
  • Disable Exploit Guard Network Protection on Windows Defender

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling Windows Defender Exploit Guard Network Protection


    Read More
  • Disable Internal Tools or Feature in Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications that change features of internal Windows tools (malware like Agent Tesla uses this technique)


    Read More
  • Disable Macro Runtime Scan Scope

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects tampering with the MacroRuntimeScanScope registry key to disable runtime scanning of enabled macros


    Read More
  • Disable Microsoft Defender Firewall via Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Adversaries may disable or modify system firewalls in order to bypass controls limiting network usage


    Read More
  • Disable of ETW Trace - Powershell

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1070 attack.t1685 car.2016-04-002  ·
    Share on: twitter facebook linkedin copy

    Detects usage of powershell cmdlets to disable or remove ETW trace sessions


    Read More
  • Disable Or Stop Services

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685 attack.impact attack.t1489  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of utilities such as 'systemctl', 'service'...etc to stop or disable tools and services on Linux systems. Attackers may stop or disable security tools and services to evade detection, maintain persistence, or disrupt system operations.


    Read More
  • Disable Powershell Command History

    calendar Apr 28, 2026 · attack.stealth attack.t1070.003  ·
    Share on: twitter facebook linkedin copy

    Detects scripts or commands that disabled the Powershell command history by removing psreadline module


    Read More
  • Disable Privacy Settings Experience in Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications that disable Privacy Settings Experience


    Read More
  • Disable PUA Protection on Windows Defender

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling Windows Defender PUA protection


    Read More
  • Disable Security Events Logging Adding Reg Key MiniNt

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685.001 attack.t1112 car.2022-03-001  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a key 'MiniNt' to the registry. Upon a reboot, Windows Event Log service will stop writing events.


    Read More
  • Disable Security Tools

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling security tools


    Read More
  • Disable System Firewall

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686  ·
    Share on: twitter facebook linkedin copy

    Detects disabling of system firewalls which could be used by adversaries to bypass controls that limit usage of the network.


    Read More
  • Disable Tamper Protection on Windows Defender

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling Windows Defender Tamper Protection


    Read More
  • Disable Windows Defender AV Security Monitoring

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attackers attempting to disable Windows Defender using Powershell


    Read More
  • Disable Windows Defender Functionalities Via Registry Keys

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when attackers or tools disable Windows Defender functionalities via the Windows registry


    Read More
  • Disable Windows Event Logging Via Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects tampering with the "Enabled" registry key in order to disable Windows logging of a Windows event channel


    Read More
  • Disable Windows Firewall by Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detect set EnableFirewall to 0 to disable the Windows firewall


    Read More
  • Disable Windows IIS HTTP Logging

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Disables HTTP logging on a Windows IIS web server as seen by Threat Group 3390 (Bronze Union)


    Read More
  • Disable Windows Security Center Notifications

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect set UseActionCenterExperience to 0 to disable the Windows security center notification


    Read More
  • Disable-WindowsOptionalFeature Command PowerShell

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detect built in PowerShell cmdlet Disable-WindowsOptionalFeature, Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images


    Read More
  • Disabled IE Security Features

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects command lines that indicate unwanted modifications to registry keys that disable important Internet Explorer security features


    Read More
  • Disabled MFA to Bypass Authentication Mechanisms

    calendar Apr 28, 2026 · attack.credential-access attack.persistence attack.defense-impairment attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Detection for when multi factor authentication has been disabled, which might indicate a malicious activity to bypass authentication mechanisms.


    Read More
  • Disabled Volume Snapshots

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects commands that temporarily turn off Volume Snapshots


    Read More
  • Disabled Windows Defender Eventlog

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the disabling of the Windows Defender eventlog as seen in relation to Lockbit 3.0 infections


    Read More
  • Disabling Multi Factor Authentication

    calendar Apr 28, 2026 · attack.persistence attack.credential-access attack.defense-impairment attack.t1556.006  ·
    Share on: twitter facebook linkedin copy

    Detects disabling of Multi Factor Authentication.


    Read More
  • Disabling Security Tools

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686  ·
    Share on: twitter facebook linkedin copy

    Detects disabling security tools


    Read More
  • Disabling Security Tools - Builtin

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686  ·
    Share on: twitter facebook linkedin copy

    Detects disabling security tools


    Read More
  • Disabling Windows Defender WMI Autologger Session via Reg.exe

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the use of reg.exe to disable the Event Tracing for Windows (ETW) Autologger session for Windows Defender API and Audit events. By setting the 'Start' value to '0' for the 'DefenderApiLogger' or 'DefenderAuditLogger' session, an attacker can prevent these critical security events from being logged, effectively blinding monitoring tools that rely on this data. This is a powerful defense evasion technique.


    Read More
  • Diskshadow Script Mode - Execution From Potential Suspicious Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "Diskshadow.exe" in script mode using the "/s" flag where the script is located in a potentially suspicious location.


    Read More
  • Diskshadow Script Mode - Uncommon Script Extension Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.


    Read More
  • Dism Remove Online Package

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Deployment Image Servicing and Management tool. DISM is used to enumerate, install, uninstall, configure, and update features and packages in Windows images


    Read More
  • Displaying Hidden Files Feature Disabled

    calendar Apr 28, 2026 · attack.stealth attack.t1564.001  ·
    Share on: twitter facebook linkedin copy

    Detects modifications to the "Hidden" and "ShowSuperHidden" explorer registry values in order to disable showing of hidden files and system files. This technique is abused by several malware families to hide their files from normal users.


    Read More
  • DLL Execution via Rasautou.exe

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects using Rasautou.exe for loading arbitrary .DLL specified in -d option and executes the export specified in -p.


    Read More
  • DLL Execution Via Register-cimprovider.exe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574  ·
    Share on: twitter facebook linkedin copy

    Detects using register-cimprovider.exe to execute arbitrary dll file.


    Read More
  • DLL Load By System Process From Suspicious Locations

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects when a system process (i.e. located in system32, syswow64, etc.) loads a DLL from a suspicious location or a location with permissive permissions such as "C:\Users\Public"


    Read More
  • DLL Loaded From Suspicious Location Via Cmspt.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.003  ·
    Share on: twitter facebook linkedin copy

    Detects cmstp loading "dll" or "ocx" files from suspicious locations


    Read More
  • DLL Loaded via CertOC.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects when a user installs certificates by using CertOC.exe to loads the target DLL file.


    Read More
  • DLL Names Used By SVR For GraphicalProton Backdoor

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Hunts known SVR-specific DLL names.


    Read More
  • DLL Search Order Hijackig Via Additional Space in Path

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker create a similar folder structure to windows system folders such as (Windows, Program Files...) but with a space in order to trick DLL load search order and perform a "DLL Search Order Hijacking" attack


    Read More
  • DLL Sideloading by VMware Xfer Utility

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects execution of VMware Xfer utility (VMwareXferlogs.exe) from the non-default directory which may be an attempt to sideload arbitrary DLL


    Read More
  • DLL Sideloading Of ShellChromeAPI.DLL

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects processes loading the non-existent DLL "ShellChromeAPI". One known example is the "DeviceEnroller" binary in combination with the "PhoneDeepLink" flag tries to load this DLL. Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter


    Read More
  • Dllhost.EXE Execution Anomaly

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects a "dllhost" process spawning with no commandline arguments which is very rare to happen and could indicate process injection activity or malware mimicking similar system processes.


    Read More
  • DllUnregisterServer Function Call Via Msiexec.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.007  ·
    Share on: twitter facebook linkedin copy

    Detects MsiExec loading a DLL and calling its DllUnregisterServer function


    Read More
  • DMSA Link Attributes Modified

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.002 attack.t1098  ·
    Share on: twitter facebook linkedin copy

    Detects modification of dMSA link attributes (msDS-ManagedAccountPrecededByLink) via PowerShell scripts. This command line pattern could be an indicator an attempt to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025.


    Read More
  • DMSA Service Account Created in Specific OUs - PowerShell

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078.002 attack.t1098  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a dMSA service account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.


    Read More
  • DNS Query Request By Regsvr32.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1559.001 attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects DNS queries initiated by "Regsvr32.exe"


    Read More
  • DNS Server Error Failed Loading the ServerLevelPluginDLL

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects a DNS server error in which a specified plugin DLL (in registry) could not be loaded


    Read More
  • DNS-over-HTTPS Enabled by Registry

    calendar Apr 28, 2026 · attack.persistence attack.stealth attack.defense-impairment attack.t1140 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects when a user enables DNS-over-HTTPS. This can be used to hide internet activity or be used to hide the process of exfiltrating data. With this enabled organization will lose visibility into data such as query type, response and originating IP that are used to determine bad actors.


    Read More
  • DotNet CLR DLL Loaded By Scripting Applications

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects .NET CLR DLLs being loaded by scripting applications such as wscript or cscript. This could be an indication of potential suspicious execution.


    Read More
  • Download from Suspicious Dyndns Hosts

    calendar Apr 28, 2026 · attack.command-and-control attack.t1105 attack.t1568  ·
    Share on: twitter facebook linkedin copy

    Detects download of certain file types from hosts with dynamic DNS names (selected list)


    Read More
  • Driver Added To Disallowed Images In HVCI - Registry

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "HVCIDisallowedImages" registry value to potentially add a driver to the list, in order to prevent it from loading.


    Read More
  • Driver/DLL Installation Via Odbcconf.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "odbcconf" with "INSTALLDRIVER" which installs a new ODBC driver. Attackers abuse this to install and run malicious DLLs.


    Read More
  • Drop Binaries Into Spool Drivers Color Folder

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of suspcious binary files inside the "\windows\system32\spool\drivers\color" as seen in the blog referenced below


    Read More
  • Dropping Of Password Filter DLL

    calendar Apr 28, 2026 · attack.persistence attack.credential-access attack.defense-impairment attack.t1556.002  ·
    Share on: twitter facebook linkedin copy

    Detects dropping of dll files in system32 that may be used to retrieve user credentials from LSASS


    Read More
  • DumpMinitool Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1003.001 attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects the use of "DumpMinitool.exe" a tool that allows the dump of process memory via the use of the "MiniDumpWriteDump"


    Read More
  • DumpStack.log Defender Evasion

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the filename DumpStack.log to evade Microsoft Defender


    Read More
  • Dynamic .NET Compilation Via Csc.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.


    Read More
  • Dynamic CSharp Compile Artefact

    calendar Apr 28, 2026 · attack.stealth attack.t1027.004  ·
    Share on: twitter facebook linkedin copy

    When C# is compiled dynamically, a .cmdline file will be created as a part of the process. Certain processes are not typically observed compiling C# code, but can do so without touching disk. This can be used to unpack a payload for execution


    Read More
  • Elevated System Shell Spawned From Uncommon Parent Location

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges from a uncommon parent location.


    Read More
  • Enable BPF Kprobes Tracing

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects common command used to enable bpf kprobes tracing


    Read More
  • Enable LM Hash Storage

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.


    Read More
  • Enable LM Hash Storage - ProcCreation

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "NoLMHash" registry value in order to allow Windows to store LM Hashes. By setting this registry value to "0" (DWORD), Windows will be allowed to store a LAN manager hash of your password in Active Directory and local SAM databases.


    Read More
  • Enable Local Manifest Installation With Winget

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the AppInstaller (winget) policy. Specifically the activation of the local manifest installation, which allows a user to install new packages via custom manifests.


    Read More
  • Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects enabling of the "AllowAnonymousCallback" registry value, which allows a remote connection between computers that do not have a trust relationship.


    Read More
  • Enabling COR Profiler Environment Variables

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.012  ·
    Share on: twitter facebook linkedin copy

    Detects .NET Framework CLR and .NET Core CLR "cor_enable_profiling" and "cor_profiler" variables being set and configured.


    Read More
  • Equation Group DLL_U Export Function Load

    calendar Apr 28, 2026 · attack.stealth attack.g0020 attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects a specific export function name used by one of EquationGroup tools


    Read More
  • ESXi Syslog Configuration Change Via ESXCLI

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1685 attack.t1690 attack.t1059.012  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the ESXi syslog configuration via "esxcli"


    Read More
  • ETW Logging Disabled For rpcrt4.dll

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "ExtErrorInformation" key in order to disable ETW logging for rpcrt4.dll


    Read More
  • ETW Logging Disabled For SCM

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "TracingDisabled" key in order to disable ETW logging for services.exe (SCM)


    Read More
  • ETW Logging Disabled In .NET Processes - Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Potential adversaries stopping ETW providers recording loaded .NET assemblies.


    Read More
  • ETW Logging Disabled In .NET Processes - Sysmon Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Potential adversaries stopping ETW providers recording loaded .NET assemblies.


    Read More
  • ETW Logging Tamper In .NET Processes Via CommandLine

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to environment variables related to ETW logging via the CommandLine. This could indicate potential adversaries stopping ETW providers recording loaded .NET assemblies.


    Read More
  • ETW Logging/Processing Option Disabled On IIS Server

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685.001 attack.t1505.004  ·
    Share on: twitter facebook linkedin copy

    Detects changes to of the IIS server configuration in order to disable/remove the ETW logging/processing option.


    Read More
  • ETW Trace Evasion Activity

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1070 attack.t1685 car.2016-04-002  ·
    Share on: twitter facebook linkedin copy

    Detects command line activity that tries to clear or disable any ETW trace log which could be a sign of logging evasion.


    Read More
  • Eventlog Cleared

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.005 car.2016-04-002  ·
    Share on: twitter facebook linkedin copy

    One of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution


    Read More
  • EventLog EVTX File Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of the event log files which may indicate an attempt to destroy forensic evidence


    Read More
  • EvilNum APT Golden Chickens Deployment Via OCX Files

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Golden Chickens deployment method as used by Evilnum and described in ESET July 2020 report


    Read More
  • EVTX Created In Uncommon Location

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of new files with the ".evtx" extension in non-common or non-standard location. This could indicate tampering with default EVTX locations in order to evade security controls or simply exfiltration of event log to search for sensitive information within. Note that backup software and legitimate administrator might perform similar actions during troubleshooting.


    Read More
  • Exchange PowerShell Cmdlet History Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of the Exchange PowerShell cmdlet History logs which may indicate an attempt to destroy forensic evidence


    Read More
  • Execute Code with Pester.bat

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects code execution via Pester.bat (Pester - Powershell Modulte for testing)


    Read More
  • Execute Code with Pester.bat as Parent

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects code execution via Pester.bat (Pester - Powershell Modulte for testing)


    Read More
  • Execute Files with Msdeploy.exe

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects file execution using the msdeploy.exe lolbin


    Read More
  • Execute From Alternate Data Streams

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution from an Alternate Data Stream (ADS). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection


    Read More
  • Execute Pcwrun.EXE To Leverage Follina

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects indirect command execution via Program Compatibility Assistant "pcwrun.exe" leveraging the follina (CVE-2022-30190) vulnerability


    Read More
  • Execution DLL of Choice Using WAB.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    This rule detects that the path to the DLL written in the registry is different from the default one. Launched WAB.exe tries to load the DLL from Registry.


    Read More
  • Execution Of Non-Existing File

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Checks whether the image specified in a process creation event is not a full, absolute path (caused by process ghosting or other unorthodox methods to start a process)


    Read More
  • Execution of Suspicious File Type Extension

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects whether the image specified in a process creation event doesn't refer to an ".exe" (or other known executable extension) file. This can be caused by process ghosting or other unorthodox methods to start a process. This rule might require some initial baselining to align with some third party tooling in the user environment.


    Read More
  • Execution via stordiag.exe

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the use of stordiag.exe to execute schtasks.exe systeminfo.exe and fltmc.exe


    Read More
  • Execution via WorkFolders.exe

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects using WorkFolders.exe to execute an arbitrary control.exe


    Read More
  • Exploit for CVE-2015-1641

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005 cve.2015-1641 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641


    Read More
  • Exploiting SetupComplete.cmd CVE-2019-1378

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.stealth attack.t1068 attack.execution attack.t1059.003 attack.t1574 cve.2019-1378 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects exploitation attempt of privilege escalation vulnerability via SetupComplete.cmd and PartnerSetupComplete.cmd described in CVE-2019-1378


    Read More
  • Explorer NOUACCHECK Flag

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious starts of explorer.exe that use the /NOUACCHECK flag that allows to run all sub processes of that newly started explorer.exe without any UAC checks


    Read More
  • Explorer Process Tree Break

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects a command line process that uses explorer.exe to launch arbitrary commands or binaries, which is similar to cmd.exe /c, only it breaks the process tree and makes its parent a new instance of explorer spawning from "svchost"


    Read More
  • Exports Registry Key To an Alternate Data Stream

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Exports the target Registry key and hides it in the specified alternate data stream.


    Read More
  • External Remote RDP Logon from Public IP

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1133 attack.t1078 attack.t1110  ·
    Share on: twitter facebook linkedin copy

    Detects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.


    Read More
  • External Remote SMB Logon from Public IP

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1133 attack.t1078 attack.t1110  ·
    Share on: twitter facebook linkedin copy

    Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.


    Read More
  • Failed Authentications From Countries You Do Not Operate Out Of

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1078.004 attack.t1110  ·
    Share on: twitter facebook linkedin copy

    Detect failed authentications from countries you do not operate out of.


    Read More
  • Failed Code Integrity Checks

    calendar Apr 28, 2026 · attack.stealth attack.t1027.001  ·
    Share on: twitter facebook linkedin copy

    Detects code integrity failures such as missing page hashes or corrupted drivers due unauthorized modification. This could be a sign of tampered binaries.


    Read More
  • Failed Logon From Public IP

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078 attack.t1190 attack.t1133  ·
    Share on: twitter facebook linkedin copy

    Detects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.


    Read More
  • Fax Service DLL Search Order Hijack

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    The Fax service attempts to load ualapi.dll, which is non-existent. An attacker can then (side)load their own malicious DLL using this service.


    Read More
  • File Decoded From Base64/Hex Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of certutil with either the "decode" or "decodehex" flags to decode base64 or hex encoded files. This can be abused by attackers to decode an encoded payload before execution


    Read More
  • File Deleted Via Sysinternals SDelete

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of files by the Sysinternals SDelete utility. It looks for the common name pattern used to rename files.


    Read More
  • File Deletion

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects file deletion using "rm", "shred" or "unlink" commands which are used often by adversaries to delete files left behind by the actions of their intrusion activity


    Read More
  • File Deletion Via Del

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the builtin "del"/"erase" commands in order to delete files. Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint.


    Read More
  • File Download Using ProtocolHandler.exe

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "ProtocolHandler" to download files. Downloaded files will be located in the cache folder (for example - %LOCALAPPDATA%\Microsoft\Windows\INetCache\IE)


    Read More
  • File Download Via Bitsadmin

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197 attack.s0190 attack.t1036.003 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects usage of bitsadmin downloading a file


    Read More
  • File Download Via Bitsadmin To A Suspicious Target Folder

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197 attack.s0190 attack.t1036.003 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects usage of bitsadmin downloading a file to a suspicious target folder


    Read More
  • File Download Via InstallUtil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects use of .NET InstallUtil.exe in order to download arbitrary files. The files will be written to "%LOCALAPPDATA%\Microsoft\Windows\INetCache\IE"


    Read More
  • File Download Via Nscurl - MacOS

    calendar Apr 28, 2026 · attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the nscurl utility in order to download files.


    Read More
  • File Download Via Windows Defender MpCmpRun.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Windows Defender MpCmdRun.EXE to download files


    Read More
  • File Download with Headless Browser

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth attack.t1105 attack.t1564.003  ·
    Share on: twitter facebook linkedin copy

    Detects execution of chromium based browser in headless mode using the "dump-dom" command line to download files


    Read More
  • File Encoded To Base64 Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of certutil with the "encode" flag to encode a file to base64. This can be abused by threat actors and attackers for data exfiltration


    Read More
  • File In Suspicious Location Encoded To Base64 Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of certutil with the "encode" flag to encode a file to base64 where the files are located in potentially suspicious locations


    Read More
  • File or Folder Permissions Change

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222.002  ·
    Share on: twitter facebook linkedin copy

    Detects file and folder permission changes.


    Read More
  • File Time Attribute Change

    calendar Apr 28, 2026 · attack.stealth attack.t1070.006  ·
    Share on: twitter facebook linkedin copy

    Detect file time attribute change to hide new or changes to existing files


    Read More
  • File Time Attribute Change - Linux

    calendar Apr 28, 2026 · attack.stealth attack.t1070.006  ·
    Share on: twitter facebook linkedin copy

    Detect file time attribute change to hide new or changes to existing files.


    Read More
  • File With Suspicious Extension Downloaded Via Bitsadmin

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197 attack.s0190 attack.t1036.003 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects usage of bitsadmin downloading a file with a suspicious extension


    Read More
  • Files With System DLL Name In Unsuspected Locations

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file with the ".dll" extension that has the name of a System DLL in uncommon or unsuspected locations. (Outisde of "System32", "SysWOW64", etc.). It is highly recommended to perform an initial baseline before using this rule in production.


    Read More
  • Files With System Process Name In Unsuspected Locations

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of an executable with a system process name in folders other than the system ones (System32, SysWOW64, etc.). It is highly recommended to perform an initial baseline before using this rule in production.


    Read More
  • Filter Driver Unloaded Via Fltmc.EXE

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1070 attack.t1685 attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detect filter driver unloading activity via fltmc.exe


    Read More
  • Findstr Launching .lnk File

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1202 attack.t1027.003  ·
    Share on: twitter facebook linkedin copy

    Detects usage of findstr to identify and execute a lnk file as seen within the HHS redirect attack


    Read More
  • Fireball Archer Install

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Archer malware invocation via rundll32


    Read More
  • Firewall Disabled via Netsh.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003 attack.s0108  ·
    Share on: twitter facebook linkedin copy

    Detects netsh commands that turns off the Windows firewall


    Read More
  • Firewall Rule Deleted Via Netsh.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects the removal of a port or application rule in the Windows Firewall configuration using netsh


    Read More
  • Firewall Rule Update Via Netsh.EXE

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects execution of netsh with the "advfirewall" and the "set" option in order to set new values for properties of a existing rule


    Read More
  • Flash Player Update from Suspicious Location

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1189 attack.execution attack.t1204.002 attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects a flashplayer update from an unofficial location


    Read More
  • FlowCloud Registry Markers

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.


    Read More
  • Flush Iptables Ufw Chain

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686  ·
    Share on: twitter facebook linkedin copy

    Detect use of iptables to flush all firewall rules, tables and chains and allow all network traffic


    Read More
  • Folder Removed From Exploit Guard ProtectedFolders List - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the removal of folders from the "ProtectedFolders" list of of exploit guard. This could indicate an attacker trying to launch an encryption process or trying to manipulate data inside of the protected folder


    Read More
  • Forest Blizzard APT - File Creation Activity

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of specific files inside of ProgramData directory. These files were seen being created by Forest Blizzard as described by MSFT.


    Read More
  • Forest Blizzard APT - JavaScript Constrained File Creation

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of JavaScript files inside of the DriverStore directory. Forest Blizzard used this to exploit the CVE-2022-38028 vulnerability in Windows Print Spooler service by modifying a JavaScript constraints file and executing it with SYSTEM-level permissions.


    Read More
  • Forest Blizzard APT - Process Creation Activity

    calendar Apr 28, 2026 · attack.execution detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of specific processes and command line combination. These were seen being created by Forest Blizzard as described by MSFT.


    Read More
  • Forfiles.EXE Child Process Masquerading

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "forfiles" from a non-default location, in order to potentially spawn a custom "cmd.exe" from the current working directory.


    Read More
  • FortiGate - Firewall Address Object Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of firewall address objects on a Fortinet FortiGate Firewall.


    Read More
  • FortiGate - New Firewall Policy Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new firewall policy on a Fortinet FortiGate Firewall.


    Read More
  • Fsutil Suspicious Invocation

    calendar Apr 28, 2026 · attack.impact attack.stealth attack.t1070 attack.t1485  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious parameters of fsutil (deleting USN journal, configuring it with small size, etc). Might be used by ransomwares during the attack (seen by NotPetya and others).


    Read More
  • Function Call From Undocumented COM Interface EditionUpgradeManager

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects function calls from the EditionUpgradeManager COM interface. Which is an interface that is not used by standard executables.


    Read More
  • Gatekeeper Bypass via Xattr

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.001  ·
    Share on: twitter facebook linkedin copy

    Detects macOS Gatekeeper bypass via xattr utility


    Read More
  • GCP Break-glass Container Workload Deployed

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects the deployment of workloads that are deployed by using the break-glass flag to override Binary Authorization controls.


    Read More
  • Github High Risk Configuration Disabled

    calendar Apr 28, 2026 · attack.credential-access attack.persistence attack.defense-impairment attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Detects when a user disables a critical security feature for an organization.


    Read More
  • Github New Secret Created

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a user creates action secret for the organization, environment, codespaces or repository.


    Read More
  • Github Push Protection Bypass Detected

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when a user bypasses the push protection on a secret detected by secret scanning.


    Read More
  • Github Push Protection Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects if the push protection feature is disabled for an organization, enterprise, repositories or custom pattern rules.


    Read More
  • GitHub Repository Archive Status Changed

    calendar Apr 28, 2026 · attack.persistence attack.impact attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects when a GitHub repository is archived or unarchived, which may indicate unauthorized changes to repository status.


    Read More
  • Github Secret Scanning Feature Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects if the secret scanning feature is disabled for an enterprise or repository.


    Read More
  • Github Self Hosted Runner Changes Detected

    calendar Apr 28, 2026 · attack.impact attack.discovery attack.collection attack.persistence attack.privilege-escalation attack.initial-access attack.stealth attack.t1526 attack.t1213.003 attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    A self-hosted runner is a system that you deploy and manage to execute jobs from GitHub Actions on GitHub.com. This rule detects changes to self-hosted runners configurations in the environment. The self-hosted runner configuration changes once detected, it should be validated from GitHub UI because the log entry may not provide full context.


    Read More
  • Github SSH Certificate Configuration Changed

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when changes are made to the SSH certificate configuration of the organization.


    Read More
  • Goofy Guineapig Backdoor IOC

    calendar Apr 28, 2026 · attack.execution detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects malicious indicators seen used by the Goofy Guineapig malware


    Read More
  • Google Cloud Firewall Modified or Deleted

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when a firewall rule is modified or deleted in Google Cloud Platform (GCP).


    Read More
  • Google Cloud Kubernetes Admission Controller

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078 attack.credential-access attack.t1552 attack.t1552.007  ·
    Share on: twitter facebook linkedin copy

    Identifies when an admission controller is executed in GCP Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.


    Read More
  • Google Workspace Government Attack Warning

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.impact attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects a login attempt in Google Workspace flagged as a potential attack by a government-backed threat actor


    Read More
  • Gpscript Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the LOLBIN gpscript, which executes logon or startup scripts configured in Group Policy


    Read More
  • Greedy File Deletion Using Del

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the "del" builtin command to remove files using greedy/wildcard expression. This is often used by malware to delete content of folders that perhaps contains the initial malware infection or to delete evidence.


    Read More
  • Greenbug Espionage Group Indicators

    calendar Apr 28, 2026 · attack.stealth attack.g0049 attack.execution attack.t1059.001 attack.command-and-control attack.t1105 attack.t1036.005 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects tools and process executions used by Greenbug in their May 2020 campaign as reported by Symantec


    Read More
  • Group Policy Abuse for Privilege Addition

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1484.001  ·
    Share on: twitter facebook linkedin copy

    Detects the first occurrence of a modification to Group Policy Object Attributes to add privileges to user accounts or use them to add users as local admins.


    Read More
  • Guest Account Enabled Via Sysadminctl

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078 attack.t1078.001  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to enable the guest account using the sysadminctl utility


    Read More
  • Guest User Invited By Non Approved Inviters

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a user that doesn't have permissions to invite a guest user attempts to invite one.


    Read More
  • Guest Users Invited To Tenant By Non Approved Inviters

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects guest users being invited to tenant by non-approved inviters


    Read More
  • HackTool - CACTUSTORCH Remote Thread Creation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.stealth attack.t1055.012 attack.t1059.005 attack.t1059.007 attack.t1218.005  ·
    Share on: twitter facebook linkedin copy

    Detects remote thread creation from CACTUSTORCH as described in references.


    Read More
  • HackTool - CobaltStrike BOF Injection Pattern

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1106 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects a typical pattern of a CobaltStrike BOF which inject into other processes


    Read More
  • HackTool - CobaltStrike Malleable Profile Patterns - Proxy

    calendar Apr 28, 2026 · attack.command-and-control attack.t1071.001  ·
    Share on: twitter facebook linkedin copy

    Detects cobalt strike malleable profiles patterns (URI, User-Agents, Methods).


    Read More
  • HackTool - CoercedPotato Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects the use of CoercedPotato, a tool for privilege escalation


    Read More
  • HackTool - CoercedPotato Named Pipe Creation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of a pipe name as used by the hack tool CoercedPotato


    Read More
  • HackTool - Covenant PowerShell Launcher

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1564.003  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious command lines used in Covenant luanchers


    Read More
  • HackTool - CrackMapExec PowerShell Obfuscation

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1027.005  ·
    Share on: twitter facebook linkedin copy

    The CrachMapExec pentesting framework implements a PowerShell obfuscation with some static strings detected by this rule.


    Read More
  • HackTool - DInjector PowerShell Cradle Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the Dinject PowerShell cradle based on the specific flags


    Read More
  • Hacktool - EDR-Freeze Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of EDR-Freeze, a tool that exploits the MiniDumpWriteDump function and WerFaultSecure.exe to suspend EDR and Antivirus processes on Windows. EDR-Freeze leverages a race-condition attack to put security processes into a dormant state by suspending WerFaultSecure at the moment it freezes the target process. This technique does not require kernel-level exploits or BYOVD, but instead abuses user-mode functionality to temporarily disable monitoring by EDR or Antimalware solutions.


    Read More
  • HackTool - EDRSilencer Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of EDRSilencer, a tool that leverages Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server based on PE metadata information.


    Read More
  • HackTool - EDRSilencer Execution - Filter Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of EDRSilencer, a tool that abuses the Windows Filtering Platform (WFP) to block the outbound traffic of running EDR agents based on specific hardcoded filter names.


    Read More
  • HackTool - EfsPotato Named Pipe Creation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of a pipe name as used by the hack tool EfsPotato


    Read More
  • HackTool - Empire PowerShell UAC Bypass

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects some Empire PowerShell UAC bypass methods


    Read More
  • HackTool - Empire UserAgent URI Combo

    calendar Apr 28, 2026 · attack.command-and-control attack.t1071.001  ·
    Share on: twitter facebook linkedin copy

    Detects user agent and URI paths used by empire agents


    Read More
  • HackTool - F-Secure C3 Load by Rundll32

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    F-Secure C3 produces DLLs with a default exported StartNodeRelay function.


    Read More
  • HackTool - GMER Rootkit Detector and Remover Execution

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the execution GMER tool based on image and hash fields.


    Read More
  • HackTool - HandleKatz Duplicating LSASS Handle

    calendar Apr 28, 2026 · attack.execution attack.t1106 attack.t1003.001 attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects HandleKatz opening LSASS to duplicate its handle to later dump the memory without opening any new handles


    Read More
  • HackTool - HollowReaper Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.012  ·
    Share on: twitter facebook linkedin copy

    Detects usage of HollowReaper, a process hollowing shellcode launcher used for stealth payload execution through process hollowing. It replaces the memory of a legitimate process with custom shellcode, allowing the attacker to execute payloads under the guise of trusted binaries.


    Read More
  • HackTool - Impersonate Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.001 attack.t1134.003  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Impersonate tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively


    Read More
  • HackTool - Koh Default Named Pipe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.stealth attack.t1528 attack.t1134.001  ·
    Share on: twitter facebook linkedin copy

    Detects creation of default named pipes used by the Koh tool


    Read More
  • HackTool - KrbRelayUp Execution

    calendar Apr 28, 2026 · attack.credential-access attack.t1558.003 attack.lateral-movement attack.t1550.003  ·
    Share on: twitter facebook linkedin copy

    Detects KrbRelayUp used to perform a universal no-fix local privilege escalation in Windows domain environments where LDAP signing is not enforced


    Read More
  • HackTool - LittleCorporal Generated Maldoc Injection

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.stealth attack.t1204.002 attack.t1055.003  ·
    Share on: twitter facebook linkedin copy

    Detects the process injection of a LittleCorporal generated Maldoc.


    Read More
  • HackTool - LocalPotato Execution

    calendar Apr 28, 2026 · attack.privilege-escalation cve.2023-21746 attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the LocalPotato POC based on basic PE metadata information and default CLI examples


    Read More
  • HackTool - NoFilter Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134 attack.t1134.001  ·
    Share on: twitter facebook linkedin copy

    Detects execution of NoFilter, a tool for abusing the Windows Filtering Platform for privilege escalation via hardcoded policy name indicators


    Read More
  • HackTool - Potential CobaltStrike Process Injection

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.001  ·
    Share on: twitter facebook linkedin copy

    Detects a potential remote threat creation with certain characteristics which are typical for Cobalt Strike beacons


    Read More
  • HackTool - PowerTool Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the tool PowerTool which has the ability to kill a process, delete its process file, unload drivers, and delete the driver files


    Read More
  • HackTool - Powerup Write Hijack DLL

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Powerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation. In it's default mode, it builds a self deleting .bat file which executes malicious command. The detection rule relies on creation of the malicious bat file (debug.bat by default).


    Read More
  • HackTool - PPID Spoofing SelectMyParent Tool Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.004  ·
    Share on: twitter facebook linkedin copy

    Detects the use of parent process ID spoofing tools like Didier Stevens tool SelectMyParent


    Read More
  • HackTool - RedMimicry Winnti Playbook Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1106 attack.t1059.003 attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects actions caused by the RedMimicry Winnti playbook a automated breach emulations utility


    Read More
  • HackTool - Rubeus Execution

    calendar Apr 28, 2026 · attack.credential-access attack.t1003 attack.t1558.003 attack.lateral-movement attack.t1550.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the hacktool Rubeus via PE information of command line parameters


    Read More
  • HackTool - Rubeus Execution - ScriptBlock

    calendar Apr 28, 2026 · attack.credential-access attack.t1003 attack.t1558.003 attack.lateral-movement attack.t1550.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the hacktool Rubeus using specific command line flags


    Read More
  • HackTool - SharpDPAPI Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.001 attack.t1134.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the SharpDPAPI tool based on CommandLine flags and PE metadata. SharpDPAPI is a C# port of some DPAPI functionality from the Mimikatz project.


    Read More
  • HackTool - SharpEvtMute DLL Load

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects the load of EvtMuteHook.dll, a key component of SharpEvtHook, a tool that tampers with the Windows event logs


    Read More
  • HackTool - SharpEvtMute Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects the use of SharpEvtHook, a tool that tampers with the Windows event logs


    Read More
  • HackTool - SharpImpersonation Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.001 attack.t1134.003  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the SharpImpersonation tool. Which can be used to manipulate tokens on a Windows computers remotely (PsExec/WmiExec) or interactively


    Read More
  • HackTool - SharpUp PrivEsc Tool Execution

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.discovery attack.execution attack.stealth attack.t1615 attack.t1569.002 attack.t1574.005  ·
    Share on: twitter facebook linkedin copy

    Detects the use of SharpUp, a tool for local privilege escalation


    Read More
  • HackTool - Stracciatella Execution

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1059 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects Stracciatella which executes a Powershell runspace from within C# (aka SharpPick technique) with AMSI, ETW and Script Block Logging disabled based on PE metadata characteristics.


    Read More
  • HackTool - SysmonEnte Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects the use of SysmonEnte, a tool to attack the integrity of Sysmon


    Read More
  • HackTool - UACMe Akagi Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of UACMe, a tool used for UAC bypasses, via default PE metadata


    Read More
  • HackTool - WinPwn Execution

    calendar Apr 28, 2026 · attack.credential-access attack.discovery attack.execution attack.privilege-escalation attack.t1046 attack.t1082 attack.t1106 attack.t1518 attack.t1548.002 attack.t1552.001 attack.t1555 attack.t1555.003  ·
    Share on: twitter facebook linkedin copy

    Detects commandline keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.


    Read More
  • HackTool - WinPwn Execution - ScriptBlock

    calendar Apr 28, 2026 · attack.credential-access attack.discovery attack.execution attack.privilege-escalation attack.t1046 attack.t1082 attack.t1106 attack.t1518 attack.t1548.002 attack.t1552.001 attack.t1555 attack.t1555.003  ·
    Share on: twitter facebook linkedin copy

    Detects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.


    Read More
  • HackTool - Wmiexec Default Powershell Command

    calendar Apr 28, 2026 · attack.lateral-movement attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of PowerShell with a specific flag sequence that is used by the Wmiexec script


    Read More
  • HackTool - XORDump Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1003.001 attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious use of XORDump process memory dumping utility


    Read More
  • HackTool Named File Stream Created

    calendar Apr 28, 2026 · attack.stealth attack.s0139 attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a named file stream with the imphash of a well-known hack tool


    Read More
  • Hacktool Ruler

    calendar Apr 28, 2026 · attack.discovery attack.execution attack.collection attack.lateral-movement attack.t1087 attack.t1114 attack.t1059 attack.t1550.002  ·
    Share on: twitter facebook linkedin copy

    This events that are generated when using the hacktool Ruler by Sensepost


    Read More
  • HH.EXE Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "hh.exe" to open ".chm" files.


    Read More
  • Hidden Executable In NTFS Alternate Data Stream

    calendar Apr 28, 2026 · attack.stealth attack.s0139 attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of an ADS (Alternate Data Stream) that contains an executable by looking at a non-empty Imphash


    Read More
  • Hidden Files and Directories

    calendar Apr 28, 2026 · attack.stealth attack.t1564.001  ·
    Share on: twitter facebook linkedin copy

    Detects adversary creating hidden file or directory, by detecting directories or files with . as the first character


    Read More
  • Hidden Flag Set On File/Directory Via Chflags - MacOS

    calendar Apr 28, 2026 · attack.credential-access attack.command-and-control attack.stealth attack.t1218 attack.t1564.004 attack.t1552.001 attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the "chflags" utility with the "hidden" flag, in order to hide files on MacOS. When a file or directory has this hidden flag set, it becomes invisible to the default file listing commands and in graphical file browsers.


    Read More
  • Hidden User Creation

    calendar Apr 28, 2026 · attack.stealth attack.t1564.002  ·
    Share on: twitter facebook linkedin copy

    Detects creation of a hidden user account on macOS (UserID < 500) or with IsHidden option


    Read More
  • Hide Schedule Task Via Index Value Tamper

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when the "index" value of a scheduled task is modified from the registry Which effectively hides it from any tooling such as "schtasks /query" (Read the referenced link for more information about the effects of this technique)


    Read More
  • Hiding Files with Attrib.exe

    calendar Apr 28, 2026 · attack.stealth attack.t1564.001  ·
    Share on: twitter facebook linkedin copy

    Detects usage of attrib.exe to hide files from users.


    Read More
  • Hiding User Account Via SpecialAccounts Registry Key

    calendar Apr 28, 2026 · attack.stealth attack.t1564.002  ·
    Share on: twitter facebook linkedin copy

    Detects modifications to the registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\Userlist" where the value is set to "0" in order to hide user account from being listed on the logon screen.


    Read More
  • Hiding User Account Via SpecialAccounts Registry Key - CommandLine

    calendar Apr 28, 2026 · attack.stealth attack.t1564.002  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the registry key "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\Userlist" where the value is set to "0" in order to hide user account from being listed on the logon screen.


    Read More
  • HTML Help HH.EXE Suspicious Child Process

    calendar Apr 28, 2026 · attack.execution attack.initial-access attack.stealth attack.t1047 attack.t1059.001 attack.t1059.003 attack.t1059.005 attack.t1059.007 attack.t1218 attack.t1218.001 attack.t1218.010 attack.t1218.011 attack.t1566 attack.t1566.001  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious child process of a Microsoft HTML Help (HH.exe)


    Read More
  • HTTP Logging Disabled On IIS Server

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685.001 attack.t1505.004  ·
    Share on: twitter facebook linkedin copy

    Detects changes to of the IIS server configuration in order to disable HTTP logging for successful requests.


    Read More
  • HTTP Request With Empty User Agent

    calendar Apr 28, 2026 · attack.command-and-control attack.t1071.001  ·
    Share on: twitter facebook linkedin copy

    Detects a potentially suspicious empty user agent strings in proxy log. Could potentially indicate an uncommon request method.


    Read More
  • Huawei BGP Authentication Failures

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.credential-access attack.collection attack.stealth attack.t1078 attack.t1110 attack.t1557  ·
    Share on: twitter facebook linkedin copy

    Detects BGP failures which may be indicative of brute force attacks to manipulate routing.


    Read More
  • Hypervisor Enforced Paging Translation Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "DisableHypervisorEnforcedPagingTranslation" registry value. Where the it is set to "1" in order to disable the Hypervisor Enforced Paging Translation feature.


    Read More
  • Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the tampering of Hypervisor-protected Code Integrity (HVCI) related registry values via command line tool reg.exe. HVCI uses virtualization-based security to protect code integrity by ensuring that only trusted code can run in kernel mode. Adversaries may tamper with HVCI to load malicious or unsigned drivers, which can be used to escalate privileges, maintain persistence, or evade security mechanisms.


    Read More
  • IcedID Malware Suspicious Single Digit DLL Execution Via Rundll32

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects RunDLL32.exe executing a single digit DLL named "1.dll" with the export function "DllRegisterServer". This behaviour was often seen used by malware and especially IcedID


    Read More
  • IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects changes to Internet Explorer's (IE / Windows Internet properties) ZoneMap configuration of the "HTTP" and "HTTPS" protocols to point to the "My Computer" zone. This allows downloaded files from the Internet to be granted the same level of trust as files stored locally.


    Read More
  • IE ZoneMap Setting Downgraded To MyComputer Zone For HTTP Protocols Via CLI

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects changes to Internet Explorer's (IE / Windows Internet properties) ZoneMap configuration of the "HTTP" and "HTTPS" protocols to point to the "My Computer" zone. This allows downloaded files from the Internet to be granted the same level of trust as files stored locally.


    Read More
  • Ie4uinit Lolbin Use From Invalid Path

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detect use of ie4uinit.exe to execute commands from a specially prepared ie4uinit.inf file from a directory other than the usual directories


    Read More
  • IIS WebServer Access Logs Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of IIS WebServer access logs which may indicate an attempt to destroy forensic evidence


    Read More
  • IIS WebServer Log Deletion via CommandLine Utilities

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to delete Internet Information Services (IIS) log files via command line utilities, which is a common defense evasion technique used by attackers to cover their tracks. Threat actors often abuse vulnerabilities in web applications hosted on IIS servers to gain initial access and later delete IIS logs to evade detection.


    Read More
  • ImagingDevices Unusual Parent/Child Processes

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects unusual parent or children of the ImagingDevices.exe (Windows Contacts) process as seen being used with Bumblebee activity


    Read More
  • Import LDAP Data Interchange Format File Via Ldifde.EXE

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth attack.t1218 attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "Ldifde.exe" with the import flag "-i". The can be abused to include HTTP-based arguments which will allow the arbitrary download of files from a remote server.


    Read More
  • Important Windows Event Auditing Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects scenarios where system auditing for important events such as "Process Creation" or "Logon" events is disabled.


    Read More
  • Important Windows Eventlog Cleared

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.005 car.2016-04-002  ·
    Share on: twitter facebook linkedin copy

    Detects the clearing of one of the Windows Core Eventlogs. e.g. caused by "wevtutil cl" command execution


    Read More
  • Important Windows Service Terminated Unexpectedly

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects important or interesting Windows services that got terminated unexpectedly.


    Read More
  • Important Windows Service Terminated With Error

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects important or interesting Windows services that got terminated for whatever reason


    Read More
  • Imports Registry Key From a File

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the import of the specified file to the registry with regedit.exe.


    Read More
  • Imports Registry Key From an ADS

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the import of a alternate datastream to the registry with regedit.exe.


    Read More
  • Impossible Travel

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Identifies user activities originating from geographically distant locations within a time period shorter than the time it takes to travel from the first location to the second.


    Read More
  • Increased Failed Authentications Of Any Type

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when sign-ins increased by 10% or greater.


    Read More
  • Indicator Removal on Host - Clear Mac System Logs

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.006  ·
    Share on: twitter facebook linkedin copy

    Detects deletion of local audit logs


    Read More
  • Indirect Command Execution By Program Compatibility Wizard

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detect indirect command execution via Program Compatibility Assistant pcwrun.exe


    Read More
  • Indirect Command Execution From Script File Via Bash.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Microsoft bash launcher without any flags to execute the content of a bash script directly. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.


    Read More
  • Indirect Command Execution via SFTP ProxyCommand

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the use of SFTP.exe to execute commands indirectly via ProxyCommand parameter. Threat actors were seen leveraging this legitimate Windows binary to bypass security controls and execute arbitrary commands while evading detection.


    Read More
  • Indirect Inline Command Execution Via Bash.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Microsoft bash launcher with the "-c" flag. This can be used to potentially bypass defenses and execute Linux or Windows-based binaries directly via bash.


    Read More
  • InfDefaultInstall.exe .inf Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Executes SCT script using scrobj.dll from a command in entered into a specially prepared INF file.


    Read More
  • Injected Browser Process Spawning Rundll32 - GuLoader Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of installed GuLoader malware on the host. GuLoader is initiating network connections via the rundll32.exe process that is spawned via a browser parent(injected) process.


    Read More
  • Insensitive Subfolder Search Via Findstr.EXE

    calendar Apr 28, 2026 · attack.credential-access attack.command-and-control attack.stealth attack.t1218 attack.t1564.004 attack.t1552.001 attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects execution of findstr with the "s" and "i" flags for a "subfolder" and "insensitive" search respectively. Attackers sometimes leverage this built-in utility to search the system for interesting files or filter through results of commands.


    Read More
  • Install New Package Via Winget Local Manifest

    calendar Apr 28, 2026 · attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects usage of winget to install applications via manifest file. Adversaries can abuse winget to download payloads remotely and execute them. The manifest option enables you to install an application by passing in a YAML file directly to the client. Winget can be used to download and install exe, msi or msix files later.


    Read More
  • Install Root Certificate

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Detects installation of new certificate on the system which attackers may use to avoid warnings when connecting to controlled web servers or C2s


    Read More
  • Interactive Bash Suspicious Children

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.004 attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious interactive bash as a parent to rather uncommon child processes


    Read More
  • Internet Explorer DisableFirstRunCustomize Enabled

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the Internet Explorer "DisableFirstRunCustomize" value, which prevents Internet Explorer from running the first run wizard the first time a user starts the browser after installing Internet Explorer or Windows.


    Read More
  • Invalid PIM License

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Identifies when an organization doesn't have the proper license for PIM and is out of compliance.


    Read More
  • Invoke-Obfuscation CLIP+ Launcher

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Clip.exe to execute PowerShell


    Read More
  • Invoke-Obfuscation CLIP+ Launcher - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Clip.exe to execute PowerShell


    Read More
  • Invoke-Obfuscation CLIP+ Launcher - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Clip.exe to execute PowerShell


    Read More
  • Invoke-Obfuscation CLIP+ Launcher - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Clip.exe to execute PowerShell


    Read More
  • Invoke-Obfuscation CLIP+ Launcher - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Clip.exe to execute PowerShell


    Read More
  • Invoke-Obfuscation COMPRESS OBFUSCATION

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via COMPRESS OBFUSCATION


    Read More
  • Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via COMPRESS OBFUSCATION


    Read More
  • Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via COMPRESS OBFUSCATION


    Read More
  • Invoke-Obfuscation COMPRESS OBFUSCATION - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via COMPRESS OBFUSCATION


    Read More
  • Invoke-Obfuscation COMPRESS OBFUSCATION - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via COMPRESS OBFUSCATION


    Read More
  • Invoke-Obfuscation Obfuscated IEX Invocation

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block


    Read More
  • Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block \u2014


    Read More
  • Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block cited in the reference section below


    Read More
  • Invoke-Obfuscation Obfuscated IEX Invocation - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block linked in the references


    Read More
  • Invoke-Obfuscation Obfuscated IEX Invocation - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block linked in the references


    Read More
  • Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via RUNDLL LAUNCHER


    Read More
  • Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via RUNDLL LAUNCHER


    Read More
  • Invoke-Obfuscation RUNDLL LAUNCHER - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via RUNDLL LAUNCHER


    Read More
  • Invoke-Obfuscation RUNDLL LAUNCHER - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via RUNDLL LAUNCHER


    Read More
  • Invoke-Obfuscation STDIN+ Launcher

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of stdin to execute PowerShell


    Read More
  • Invoke-Obfuscation STDIN+ Launcher - Powershell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of stdin to execute PowerShell


    Read More
  • Invoke-Obfuscation STDIN+ Launcher - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of stdin to execute PowerShell


    Read More
  • Invoke-Obfuscation STDIN+ Launcher - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of stdin to execute PowerShell


    Read More
  • Invoke-Obfuscation STDIN+ Launcher - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of stdin to execute PowerShell


    Read More
  • Invoke-Obfuscation VAR+ Launcher

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Environment Variables to execute PowerShell


    Read More
  • Invoke-Obfuscation VAR+ Launcher - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Environment Variables to execute PowerShell


    Read More
  • Invoke-Obfuscation VAR+ Launcher - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Environment Variables to execute PowerShell


    Read More
  • Invoke-Obfuscation VAR+ Launcher - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Environment Variables to execute PowerShell


    Read More
  • Invoke-Obfuscation VAR+ Launcher - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated use of Environment Variables to execute PowerShell


    Read More
  • Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via VAR++ LAUNCHER


    Read More
  • Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via VAR++ LAUNCHER


    Read More
  • Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via VAR++ LAUNCHER


    Read More
  • Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via VAR++ LAUNCHER


    Read More
  • Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via VAR++ LAUNCHER


    Read More
  • Invoke-Obfuscation Via Stdin

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via Stdin in Scripts


    Read More
  • Invoke-Obfuscation Via Stdin - Powershell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via Stdin in Scripts


    Read More
  • Invoke-Obfuscation Via Stdin - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via Stdin in Scripts


    Read More
  • Invoke-Obfuscation Via Stdin - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via Stdin in Scripts


    Read More
  • Invoke-Obfuscation Via Stdin - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via Stdin in Scripts


    Read More
  • Invoke-Obfuscation Via Use Clip

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Clip.exe in Scripts


    Read More
  • Invoke-Obfuscation Via Use Clip - Powershell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Clip.exe in Scripts


    Read More
  • Invoke-Obfuscation Via Use Clip - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Clip.exe in Scripts


    Read More
  • Invoke-Obfuscation Via Use Clip - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Clip.exe in Scripts


    Read More
  • Invoke-Obfuscation Via Use Clip - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Clip.exe in Scripts


    Read More
  • Invoke-Obfuscation Via Use MSHTA

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use MSHTA in Scripts


    Read More
  • Invoke-Obfuscation Via Use MSHTA - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use MSHTA in Scripts


    Read More
  • Invoke-Obfuscation Via Use MSHTA - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use MSHTA in Scripts


    Read More
  • Invoke-Obfuscation Via Use MSHTA - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use MSHTA in Scripts


    Read More
  • Invoke-Obfuscation Via Use MSHTA - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use MSHTA in Scripts


    Read More
  • Invoke-Obfuscation Via Use Rundll32 - PowerShell

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Rundll32 in Scripts


    Read More
  • Invoke-Obfuscation Via Use Rundll32 - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Rundll32 in Scripts


    Read More
  • Invoke-Obfuscation Via Use Rundll32 - Security

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Rundll32 in Scripts


    Read More
  • Invoke-Obfuscation Via Use Rundll32 - System

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Obfuscated Powershell via use Rundll32 in Scripts


    Read More
  • JScript Compiler Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the "jsc.exe" (JScript Compiler). Attacker might abuse this in order to compile JScript files on the fly and bypassing application whitelisting.


    Read More
  • Juniper BGP Missing MD5

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.credential-access attack.collection attack.stealth attack.t1078 attack.t1110 attack.t1557  ·
    Share on: twitter facebook linkedin copy

    Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.


    Read More
  • Kapeka Backdoor Configuration Persistence

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1553.003 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects registry set activity of a value called "Seed" stored in the "\Cryptography\Providers" registry key. The Kapeka backdoor leverages this location to register a new SIP provider for backdoor configuration persistence.


    Read More
  • Kapeka Backdoor Execution Via RunDLL32.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Kapeka backdoor process execution pattern, where the dropper launch the backdoor binary by calling rundll32 and passing the backdoor's first export ordinal (#1) with a "-d" argument.


    Read More
  • Kapeka Backdoor Loaded Via Rundll32.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1204.002 attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the Kapeka Backdoor binary being loaded by rundll32.exe. The Kapeka loader drops a backdoor, which is a DLL with the '.wll' extension masquerading as a Microsoft Word Add-In.


    Read More
  • Kaspersky Endpoint Security Stopped Via CommandLine - Linux

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Kaspersky init.d stop script on Linux systems either directly or via systemctl. This activity may indicate a manual interruption of the antivirus service by an administrator, or it could be a sign of potential tampering or evasion attempts by malicious actors.


    Read More
  • Kavremover Dropped Binary LOLBIN Usage

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a signed binary dropped by Kaspersky Lab Products Remover (kavremover) which can be abused as a LOLBIN to execute arbitrary commands and binaries.


    Read More
  • Kernel Memory Dump Via LiveKD

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of LiveKD with the "-m" flag to potentially dump the kernel memory


    Read More
  • Kubernetes Admission Controller Modification

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078 attack.credential-access attack.t1552 attack.t1552.007  ·
    Share on: twitter facebook linkedin copy

    Detects when a modification (create, update or replace) action is taken that affects mutating or validating webhook configurations, as they can be used by an adversary to achieve persistence or exfiltrate access credentials.


    Read More
  • Kubernetes Events Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects when events are deleted in Kubernetes. An adversary may delete Kubernetes events in an attempt to evade detection.


    Read More
  • Launch-VsDevShell.PS1 Proxy Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1216.001  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the 'Launch-VsDevShell.ps1' Microsoft signed script to execute commands.


    Read More
  • Lazarus APT DLL Sideloading Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 attack.g0032 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects sideloading of trojanized DLLs used in Lazarus APT campaign in the case of a Spanish aerospace company


    Read More
  • Lazarus System Binary Masquerading

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects binaries used by the Lazarus group which use system names but are executed and launched from non-default location


    Read More
  • Legitimate Application Dropped Archive

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects programs on a Windows system that should not write an archive to disk


    Read More
  • Legitimate Application Dropped Executable

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects programs on a Windows system that should not write executables to disk


    Read More
  • Legitimate Application Dropped Script

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects programs on a Windows system that should not write scripts to disk


    Read More
  • Legitimate Application Writing Files In Uncommon Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects legitimate applications writing any type of file to uncommon or suspicious locations that are not typical for application data storage or execution. Adversaries may leverage legitimate applications (Living off the Land Binaries - LOLBins) to drop or download malicious files to uncommon locations on the system to evade detection by security solutions.


    Read More
  • Linux Base64 Encoded Pipe to Shell

    calendar Apr 28, 2026 · attack.stealth attack.t1140  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious process command line that uses base64 encoded input for execution with a shell


    Read More
  • Linux Base64 Encoded Shebang In CLI

    calendar Apr 28, 2026 · attack.stealth attack.t1140  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of a base64 version of the shebang in the commandline, which could indicate a malicious payload about to be decoded


    Read More
  • Linux Capabilities Discovery

    calendar Apr 28, 2026 · attack.discovery attack.privilege-escalation attack.t1083 attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to discover the files with setuid/setgid capability on them. That would allow adversary to escalate their privileges.


    Read More
  • Linux Command History Tampering

    calendar Apr 28, 2026 · attack.stealth attack.t1070.003  ·
    Share on: twitter facebook linkedin copy

    Detects commands that try to clear or tamper with the Linux command history. This technique is used by threat actors in order to evade defenses and execute commands without them being recorded in files such as "bash_history" or "zsh_history".


    Read More
  • Linux Doas Conf File Creation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of doas.conf file in linux host platform.


    Read More
  • Linux Doas Tool Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects the doas tool execution in linux host platform. This utility tool allow standard users to perform tasks as root, the same way sudo does.


    Read More
  • Linux Logs Clearing Attempts

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.006  ·
    Share on: twitter facebook linkedin copy

    Detects logs clearing attempts on Linux systems via utilities such as 'rm', 'rmdir', 'shred', and 'unlink' targeting log files and directories. Adversaries often try to clear logs to cover their tracks after performing malicious activities.


    Read More
  • Linux Package Uninstall

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects linux package removal using builtin tools such as "yum", "apt", "apt-get" or "dpkg".


    Read More
  • Linux Setgid Capability Set on a Binary via Setcap Utility

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1548 attack.t1554  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.


    Read More
  • Linux Setuid Capability Set on a Binary via Setcap Utility

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1548 attack.t1554  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the 'setcap' utility to set the 'setuid' capability (cap_setuid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of user IDs (UIDs), including setting its current UID to a value that would otherwise be restricted (i.e. UID 0, the root user). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.


    Read More
  • Linux Shell Pipe to Shell

    calendar Apr 28, 2026 · attack.stealth attack.t1140  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious process command line that starts with a shell that executes something and finally gets piped into another shell


    Read More
  • LiveKD Driver Creation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of the LiveKD driver, which is used for live kernel debugging


    Read More
  • LiveKD Driver Creation By Uncommon Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of the LiveKD driver by a process image other than "livekd.exe".


    Read More
  • LiveKD Kernel Memory Dump File Created

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file that has the same name as the default LiveKD kernel memory dump.


    Read More
  • Load Of RstrtMgr.DLL By A Suspicious Process

    calendar Apr 28, 2026 · attack.impact attack.defense-impairment attack.t1486 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the load of RstrtMgr DLL (Restart Manager) by a suspicious process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes.


    Read More
  • Load Of RstrtMgr.DLL By An Uncommon Process

    calendar Apr 28, 2026 · attack.impact attack.defense-impairment attack.t1486 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the load of RstrtMgr DLL (Restart Manager) by an uncommon process. This library has been used during ransomware campaigns to kill processes that would prevent file encryption by locking them (e.g. Conti ransomware, Cactus ransomware). It has also recently been seen used by the BiBi wiper for Windows. It could also be used for anti-analysis purposes by shut downing specific processes.


    Read More
  • Logging Configuration Changes on Linux Host

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detect changes of syslog daemons configuration files


    Read More
  • Login to Disabled Account

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detect failed attempts to sign in to disabled accounts.


    Read More
  • Logon from a Risky IP Address

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when a Microsoft Cloud App Security reported when a user signs into your sanctioned apps from a risky IP address.


    Read More
  • LOL-Binary Copied From System Directory

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious copy operation that tries to copy a known LOLBIN from system (System32, SysWOW64, WinSxS) directories to another on disk in order to bypass detections based on locations.


    Read More
  • LOLBIN Execution From Abnormal Drive

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects LOLBINs executing from an abnormal or uncommon drive such as a mounted ISO.


    Read More
  • Lolbin Runexehelper Use As Proxy

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detect usage of the "runexehelper.exe" binary as a proxy to launch other programs


    Read More
  • Lolbin Unregmp2.exe Use As Proxy

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detect usage of the "unregmp2.exe" binary as a proxy to launch a custom version of "wmpnscfg.exe"


    Read More
  • LSA PPL Protection Setting Modification via CommandLine

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1689  ·
    Share on: twitter facebook linkedin copy

    Detects modification of LSA PPL protection settings via CommandLine. It may indicate an attempt to disable protection and enable credential dumping tools to access LSASS process memory.


    Read More
  • Lummac Stealer Activity - Execution Of More.com And Vbc.exe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of more.com and vbc.exe in the process tree. This behavior was observed by a set of samples related to Lummac Stealer. The Lummac payload is injected into the vbc.exe process.


    Read More
  • Macro Enabled In A Potentially Suspicious Document

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects registry changes to Office trust records where the path is located in a potentially suspicious location


    Read More
  • Malicious DLL File Dropped in the Teams or OneDrive Folder

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects creation of a malicious DLL file in the location where the OneDrive or Team applications Upon execution of the Teams or OneDrive application, the dropped malicious DLL file ("iphlpapi.dll") is sideloaded


    Read More
  • Malicious DLL Load By Compromised 3CXDesktopApp

    calendar Apr 28, 2026 · detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects DLL load activity of known compromised DLLs used in by the compromised 3CXDesktopApp


    Read More
  • Malicious Named Pipe Created

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a named pipe seen used by known APTs or malware.


    Read More
  • Malicious PE Execution by Microsoft Visual Studio Debugger

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    There is an option for a MS VS Just-In-Time Debugger "vsjitdebugger.exe" to launch specified executable and attach a debugger. This option may be used adversaries to execute malicious code by signed verified binary. The debugger is installed alongside with Microsoft Visual Studio package.


    Read More
  • Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078 attack.t1078.002  ·
    Share on: twitter facebook linkedin copy

    Detects when an instance identity has taken an action that isn't inside SSM. This can indicate that a compromised EC2 instance is being used as a pivot point.


    Read More
  • Malicious Windows Script Components File Execution by TAEF Detection

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Windows Test Authoring and Execution Framework (TAEF) framework allows you to run automation by executing tests files written on different languages (C, C#, Microsoft COM Scripting interfaces Adversaries may execute malicious code (such as WSC file with VBScript, dll and so on) directly by running te.exe


    Read More
  • Malware Shellcode in Verclsid Target Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects a process access to verclsid.exe that injects shellcode from a Microsoft Office application / VBA macro


    Read More
  • ManageEngine Endpoint Central Dctask64.EXE Potential Abuse

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "dctask64.exe", a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.


    Read More
  • Masquerading as Linux Crond Process

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Masquerading occurs when the name or location of an executable, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. Several different variations of this technique have been observed.


    Read More
  • Mavinject Inject DLL Into Running Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.001 attack.t1218.013  ·
    Share on: twitter facebook linkedin copy

    Detects process injection using the signed Windows tool "Mavinject" via the "INJECTRUNNING" flag


    Read More
  • MaxMpxCt Registry Value Changed

    calendar Apr 28, 2026 · attack.stealth attack.t1070.005  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "MaxMpxCt" registry value. MaxMpxCt specifies the maximum outstanding network requests for the server per client, which is used when negotiating a Server Message Block (SMB) connection with a client. Note if the value is set beyond 125 older Windows 9x clients will fail to negotiate. Ransomware threat actors and operators (specifically BlackCat) were seen increasing this value in order to handle a higher volume of traffic.


    Read More
  • Measurable Increase Of Successful Authentications

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when successful sign-ins increased by 10% or greater.


    Read More
  • Meterpreter or Cobalt Strike Getsystem Service Installation - Security

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.001 attack.t1134.002  ·
    Share on: twitter facebook linkedin copy

    Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation


    Read More
  • Meterpreter or Cobalt Strike Getsystem Service Installation - System

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.001 attack.t1134.002  ·
    Share on: twitter facebook linkedin copy

    Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service installation


    Read More
  • Microsoft 365 - Impossible Travel Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login associated with an impossible travel.


    Read More
  • Microsoft Defender Blocked from Loading Unsigned DLL

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects Code Integrity (CI) engine blocking Microsoft Defender's processes (MpCmdRun and NisSrv) from loading unsigned DLLs which may be an attempt to sideload arbitrary DLL


    Read More
  • Microsoft Defender Tamper Protection Trigger

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects blocked attempts to change any of Defender's settings such as "Real Time Monitoring" and "Behavior Monitoring"


    Read More
  • Microsoft Malware Protection Engine Crash

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1211 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    This rule detects a suspicious crash of the Microsoft Malware Protection Engine


    Read More
  • Microsoft Malware Protection Engine Crash - WER

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1211 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    This rule detects a suspicious crash of the Microsoft Malware Protection Engine


    Read More
  • Microsoft Office DLL Sideload

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects DLL sideloading of DLLs that are part of Microsoft Office from non standard location


    Read More
  • Microsoft Office Protected View Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to Microsoft Office protected view registry keys with which the attacker disables this feature.


    Read More
  • Microsoft Sync Center Suspicious Network Connections

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious connections from Microsoft Sync Center to non-private IPs.


    Read More
  • MMC Executing Files with Reversed Extensions Using RTLO Abuse

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1204.002 attack.t1218.014 attack.t1036.002  ·
    Share on: twitter facebook linkedin copy

    Detects malicious behavior where the MMC utility (mmc.exe) executes files with reversed extensions caused by Right-to-Left Override (RLO) abuse, disguising them as document formats.


    Read More
  • MMC Loading Script Engines DLLs

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.005 attack.t1218.014  ·
    Share on: twitter facebook linkedin copy

    Detects when the Microsoft Management Console (MMC) loads the DLL libraries like vbscript, jscript etc which might indicate an attempt to execute malicious scripts within a trusted system process for bypassing application whitelisting or defense evasion.


    Read More
  • Modification of IE Registry Settings

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects modification of the registry settings used for Internet Explorer and other Windows components that use these settings. An attacker can abuse this registry key to add a domain to the trusted sites Zone or insert JavaScript for persistence


    Read More
  • Modification of ld.so.preload

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.006  ·
    Share on: twitter facebook linkedin copy

    Identifies modification of ld.so.preload for shared object injection. This technique is used by attackers to load arbitrary code into processes.


    Read More
  • Modify Group Policy Settings

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1484.001  ·
    Share on: twitter facebook linkedin copy

    Detect malicious GPO modifications can be used to implement many other malicious behaviors.


    Read More
  • Modify Group Policy Settings - ScriptBlockLogging

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1484.001  ·
    Share on: twitter facebook linkedin copy

    Detect malicious GPO modifications can be used to implement many other malicious behaviors.


    Read More
  • Modify System Firewall

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686  ·
    Share on: twitter facebook linkedin copy

    Detects the removal of system firewall rules. Adversaries may only delete or modify a specific system firewall rule to bypass controls limiting network usage or access. Detection rules that match only on the disabling of firewalls will miss this.


    Read More
  • Monitoring For Persistence Via BITS

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    BITS will allow you to schedule a command to execute after a successful download to notify you that the job is finished. When the job runs on the system the command specified in the BITS job will be executed. This can be abused by actors to create a backdoor within the system and for persistence. It will be chained in a BITS job to schedule the download of malware/additional binaries and execute the program after being downloaded.


    Read More
  • Mount Execution With Hidepid Parameter

    calendar Apr 28, 2026 · attack.credential-access attack.stealth attack.t1564  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the "mount" command with "hidepid" parameter to make invisible processes to other users from the system


    Read More
  • MpiExec Lolbin

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects a certain command line flag combination used by mpiexec.exe LOLBIN from HPC pack that can be used to execute any other binary


    Read More
  • MSDT Execution Via Answer File

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "msdt.exe" using an answer file which is simulating the legitimate way of calling msdt via "pcwrun.exe" (For example from the compatibility tab).


    Read More
  • MSHTA Execution with Suspicious File Extensions

    calendar Apr 28, 2026 · attack.stealth attack.t1140 attack.t1218.005 attack.execution attack.t1059.007 cve.2020-1599  ·
    Share on: twitter facebook linkedin copy

    Detects execution of mshta.exe with file types that looks like they do not typically represent HTA (HTML Application) content, such as .png, .jpg, .zip, .pdf, and others, which are often polyglots. MSHTA is a legitimate Windows utility for executing HTML Applications containing VBScript or JScript. Threat actors often abuse this lolbin utility to download and execute malicious scripts disguised as benign files or hosted under misleading extensions to evade detection.


    Read More
  • Mshtml.DLL RunHTMLApplication Suspicious Usage

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of commands that leverage the "mshtml.dll" RunHTMLApplication export to run arbitrary code via different protocol handlers (vbscript, javascript, file, http...)


    Read More
  • MSI Installation From Web

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.t1218.007  ·
    Share on: twitter facebook linkedin copy

    Detects installation of a remote msi file from web.


    Read More
  • Msiexec Quiet Installation

    calendar Apr 28, 2026 · attack.stealth attack.t1218.007  ·
    Share on: twitter facebook linkedin copy

    Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)


    Read More
  • MsiExec Web Install

    calendar Apr 28, 2026 · attack.stealth attack.t1218.007 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious msiexec process starts with web addresses as parameter


    Read More
  • MSSQL Disable Audit Settings

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker calls the "ALTER SERVER AUDIT" or "DROP SERVER AUDIT" transaction in order to delete or disable audit logs on the server


    Read More
  • Msxsl.EXE Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1220  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the MSXSL utility. This can be used to execute Extensible Stylesheet Language (XSL) files. These files are commonly used to describe the processing and rendering of data within XML files. Adversaries can abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses.


    Read More
  • Multifactor Authentication Denied

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1078.004 attack.t1110 attack.t1621  ·
    Share on: twitter facebook linkedin copy

    User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.


    Read More
  • Multifactor Authentication Interrupted

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1078.004 attack.t1110 attack.t1621  ·
    Share on: twitter facebook linkedin copy

    Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.


    Read More
  • NET NGenAssemblyUsageLog Registry Key Tamper

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the NGenAssemblyUsageLog registry key. .NET Usage Log output location can be controlled by setting the NGenAssemblyUsageLog CLR configuration knob in the Registry or by configuring an environment variable (as described in the next section). By simplify specifying an arbitrary value (e.g. fake output location or junk data) for the expected value, a Usage Log file for the .NET execution context will not be created.


    Read More
  • NetNTLM Downgrade Attack

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects NetNTLM downgrade attack


    Read More
  • NetNTLM Downgrade Attack - Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects NetNTLM downgrade attack


    Read More
  • Netsh Allow Group Policy on Microsoft Defender Firewall

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Adversaries may modify system firewalls in order to bypass controls limiting network usage


    Read More
  • Network Connection Initiated By AddinUtil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects a network connection initiated by the Add-In deployment cache updating utility "AddInutil.exe". This could indicate a potential command and control communication as this tool doesn't usually initiate network activity.


    Read More
  • Network Connection Initiated By Regsvr32.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1559.001 attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects a network connection initiated by "Regsvr32.exe"


    Read More
  • Network Connection Initiated Via Notepad.EXE

    calendar Apr 28, 2026 · attack.privilege-escalation attack.command-and-control attack.execution attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects a network connection that is initiated by the "notepad.exe" process. This might be a sign of process injection from a beacon process or something similar. Notepad rarely initiates a network communication except when printing documents for example.


    Read More
  • New BgInfo.EXE Custom DB Path Registry Configuration

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects setting of a new registry database value related to BgInfo configuration. Attackers can for example set this value to save the results of the commands executed by BgInfo in order to exfiltrate information.


    Read More
  • New BgInfo.EXE Custom VBScript Registry Configuration

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom VBScript via "BgInfo.exe"


    Read More
  • New BgInfo.EXE Custom WMI Query Registry Configuration

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects setting of a new registry value related to BgInfo configuration, which can be abused to execute custom WMI query via "BgInfo.exe"


    Read More
  • New BITS Job Created Via Bitsadmin

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a new bits job by Bitsadmin


    Read More
  • New BITS Job Created Via PowerShell

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a new bits job by PowerShell


    Read More
  • New CA Policy by Non-approved Actor

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert on conditional access changes.


    Read More
  • New Capture Session Launched Via DXCap.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.


    Read More
  • New Country

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Detects sign-ins from new countries. The detection considers past activity locations to determine new and infrequent locations.


    Read More
  • New DLL Registered Via Odbcconf.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.


    Read More
  • New DMSA Service Account Created in Specific OUs

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078.002 attack.t1098  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a dMSASvc account using the New-ADServiceAccount cmdlet in certain OUs. The fact that the Cmdlet is used to create a dMSASvc account in a specific OU is highly suspicious. It is a pattern trying to exploit the BadSuccessor privilege escalation vulnerability in Windows Server 2025. On top of that, if the user that is creating the dMSASvc account is not a legitimate administrator or does not have the necessary permissions, it is a strong signal of an attempted or successful abuse of the BaDSuccessor vulnerability for privilege escalation within the Windows Server 2025 Active Directory environment.


    Read More
  • New DNS ServerLevelPluginDll Installed

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.defense-impairment attack.t1574.001 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)


    Read More
  • New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.defense-impairment attack.t1574.001 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)


    Read More
  • New Federated Domain Added

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1484.002  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new Federated Domain.


    Read More
  • New File Association Using Exefile

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the abuse of the exefile handler in new file association. Used for bypass of security products.


    Read More
  • New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new rule to the Windows Firewall exception list for an application located in a potentially suspicious location.


    Read More
  • New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new "Allow" firewall rule by the WMI process (WmiPrvSE.EXE). This can occur if an attacker leverages PowerShell cmdlets such as "New-NetFirewallRule", or directly uses WMI CIM classes such as "MSFT_NetFirewallRule".


    Read More
  • New Firewall Rule Added Via Netsh.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003 attack.s0246  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new rule to the Windows firewall via netsh


    Read More
  • New Module Module Added To IIS Server

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685.001 attack.t1505.004  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new module to an IIS server.


    Read More
  • New Network ACL Entry Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.001  ·
    Share on: twitter facebook linkedin copy

    Detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.


    Read More
  • New Network Route Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.001  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new network route to a route table in AWS.


    Read More
  • New or Renamed User Account with '$' Character

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a user with the "$" character. This can be used by attackers to hide a user or trick detection systems that lack the parsing mechanisms.


    Read More
  • New Port Forwarding Rule Added Via Netsh.EXE

    calendar Apr 28, 2026 · attack.lateral-movement attack.command-and-control attack.t1090  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of netsh commands that configure a new port forwarding (PortProxy) rule


    Read More
  • New PortProxy Registry Entry Added

    calendar Apr 28, 2026 · attack.lateral-movement attack.command-and-control attack.t1090  ·
    Share on: twitter facebook linkedin copy

    Detects the modification of the PortProxy registry key which is used for port forwarding.


    Read More
  • New Process Created Via Taskmgr.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a process via the Windows task manager. This might be an attempt to bypass UAC


    Read More
  • New Root Certificate Authority Added

    calendar Apr 28, 2026 · attack.credential-access attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Detects newly added root certificate authority to an AzureAD tenant to support certificate based authentication.


    Read More
  • New Root Certificate Installed Via CertMgr.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "certmgr" with the "add" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.


    Read More
  • New Root Certificate Installed Via Certutil.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "certutil" with the "addstore" flag in order to install a new certificate on the system. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.


    Read More
  • Node Process Executions

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127 attack.t1059.007  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of other scripts using the Node executable packaged with Adobe Creative Cloud


    Read More
  • Non-privileged Usage of Reg or Powershell

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Search for usage of reg or Powershell by non-privileged users to modify service configuration in registry


    Read More
  • NotPetya Ransomware Activity

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1218.011 attack.t1685.005 attack.credential-access attack.t1003.001 car.2016-04-002 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects NotPetya ransomware activity in which the extracted passwords are passed back to the main module via named pipe, the file system journal of drive C is deleted and Windows eventlogs are cleared using wevtutil


    Read More
  • Nslookup PowerShell Download Cradle - ProcessCreation

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious powershell download cradle using nslookup. This cradle uses nslookup to extract payloads from DNS records


    Read More
  • NtdllPipe Like Activity Execution

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects command that type the content of ntdll.dll to a different file or a pipe in order to evade AV / EDR detection. As seen being used in the POC NtdllPipe


    Read More
  • NTFS Alternate Data Stream

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects writing data into NTFS alternate data streams from powershell. Needs Script Block Logging.


    Read More
  • NTLM Logon

    calendar Apr 28, 2026 · attack.lateral-movement attack.t1550.002  ·
    Share on: twitter facebook linkedin copy

    Detects logons using NTLM, which could be caused by a legacy source or attackers


    Read More
  • NTLMv1 Logon Between Client and Server

    calendar Apr 28, 2026 · attack.lateral-movement attack.t1550.002  ·
    Share on: twitter facebook linkedin copy

    Detects the reporting of NTLMv1 being used between a client and server. NTLMv1 is insecure as the underlying encryption algorithms can be brute-forced by modern hardware.


    Read More
  • Obfuscated PowerShell MSI Install via WindowsInstaller COM

    calendar Apr 28, 2026 · attack.stealth attack.t1027.010 attack.t1218.007 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (WindowsInstaller.Installer). The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of InstallProduct and COM object creation, particularly combined with hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.


    Read More
  • Obfuscated PowerShell OneLiner Execution

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1059.001 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a specific OneLiner to download and execute powershell modules in memory.


    Read More
  • OceanLotus Registry Activity

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects registry keys created in OceanLotus (also known as APT32) attacks


    Read More
  • Odbcconf.EXE Suspicious DLL Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.


    Read More
  • Office Application Initiated Network Connection Over Uncommon Ports

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.


    Read More
  • Office Macros Warning Disabled

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects registry changes to Microsoft Office "VBAWarning" to a value of "1" which enables the execution of all macros, whether signed or unsigned.


    Read More
  • OilRig APT Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.defense-impairment attack.g0049 attack.t1053.005 attack.s0111 attack.t1543.003 attack.t1112 attack.command-and-control attack.t1071.004 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects OilRig activity as reported by Nyotron in their March 2018 report


    Read More
  • OilRig APT Registry Persistence

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.defense-impairment attack.g0049 attack.t1053.005 attack.s0111 attack.t1543.003 attack.t1112 attack.command-and-control attack.t1071.004 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects OilRig registry persistence as reported by Nyotron in their March 2018 report


    Read More
  • OilRig APT Schedule Task Persistence - Security

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.defense-impairment attack.g0049 attack.t1053.005 attack.s0111 attack.t1543.003 attack.t1112 attack.command-and-control attack.t1071.004 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report


    Read More
  • OilRig APT Schedule Task Persistence - System

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.defense-impairment attack.g0049 attack.t1053.005 attack.s0111 attack.t1543.003 attack.t1112 attack.command-and-control attack.t1071.004 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report


    Read More
  • Okta MFA Reset or Deactivated

    calendar Apr 28, 2026 · attack.persistence attack.credential-access attack.defense-impairment attack.t1556.006  ·
    Share on: twitter facebook linkedin copy

    Detects when an attempt at deactivating or resetting MFA.


    Read More
  • Okta New Admin Console Behaviours

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when Okta identifies new activity in the Admin Console.


    Read More
  • Okta User Session Start Via An Anonymising Proxy Service

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when an Okta user session starts where the user is behind an anonymising proxy service.


    Read More
  • Old TLS1.0/TLS1.1 Protocol Version Enabled

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects applications or users re-enabling old TLS versions by setting the "Enabled" value to "1" for the "Protocols" registry key.


    Read More
  • OneNote Attachment File Dropped In Suspicious Location

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects creation of files with the ".one"/".onepkg" extension in suspicious or uncommon locations. This could be a sign of attackers abusing OneNote attachments


    Read More
  • OneNote.EXE Execution of Malicious Embedded Scripts

    calendar Apr 28, 2026 · attack.stealth attack.t1218.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of malicious OneNote documents that contain embedded scripts. When a user clicks on a OneNote attachment and then on the malicious link inside the ".one" file, it exports and executes the malicious embedded script from specific directories.


    Read More
  • OpenCanary - HTTPPROXY Login Attempt

    calendar Apr 28, 2026 · attack.initial-access attack.command-and-control attack.t1090  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an HTTPPROXY service on an OpenCanary node has had an attempt to proxy another page.


    Read More
  • OpenCanary - SSH Login Attempt

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.lateral-movement attack.persistence attack.stealth attack.t1133 attack.t1021 attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an SSH service on an OpenCanary node has had a login attempt.


    Read More
  • OpenCanary - SSH New Connection Attempt

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.lateral-movement attack.persistence attack.stealth attack.t1133 attack.t1021 attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an SSH service on an OpenCanary node has had a connection attempt.


    Read More
  • OpenCanary - Telnet Login Attempt

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.command-and-control attack.stealth attack.t1133 attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects instances where a Telnet service on an OpenCanary node has had a login attempt.


    Read More
  • OpenWith.exe Executes Specified Binary

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    The OpenWith.exe executes other binary


    Read More
  • Operation Wocao Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.discovery attack.stealth attack.t1012 attack.t1036.004 attack.t1027 attack.execution attack.t1053.005 attack.t1059.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects activity mentioned in Operation Wocao report


    Read More
  • Operation Wocao Activity - Security

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.discovery attack.stealth attack.t1012 attack.t1036.004 attack.t1027 attack.execution attack.t1053.005 attack.t1059.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects activity mentioned in Operation Wocao report


    Read More
  • Outbound Network Connection Initiated By Cmstp.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.003  ·
    Share on: twitter facebook linkedin copy

    Detects a network connection initiated by Cmstp.EXE Its uncommon for "cmstp.exe" to initiate an outbound network connection. Investigate the source of such requests to determine if they are malicious.


    Read More
  • Outbound Network Connection To Public IP Via Winlogon

    calendar Apr 28, 2026 · attack.execution attack.command-and-control attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects a "winlogon.exe" process that initiate network communications with public IP addresses


    Read More
  • Outgoing Logon with New Credentials

    calendar Apr 28, 2026 · attack.lateral-movement attack.t1550  ·
    Share on: twitter facebook linkedin copy

    Detects logon events that specify new credentials


    Read More
  • Outlook EnableUnsafeClientMailRules Setting Enabled

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros


    Read More
  • Outlook EnableUnsafeClientMailRules Setting Enabled - Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros


    Read More
  • Pass the Hash Activity 2

    calendar Apr 28, 2026 · attack.lateral-movement attack.t1550.002  ·
    Share on: twitter facebook linkedin copy

    Detects the attack technique pass the hash which is used to move laterally inside the network


    Read More
  • Password Protected ZIP File Opened

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.


    Read More
  • Password Protected ZIP File Opened (Email Attachment)

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1027 attack.t1566.001  ·
    Share on: twitter facebook linkedin copy

    Detects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.


    Read More
  • Password Protected ZIP File Opened (Suspicious Filenames)

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth attack.t1027 attack.t1105 attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.


    Read More
  • Password Provided In Command Line Of Net.EXE

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.lateral-movement attack.stealth attack.t1021.002 attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects a when net.exe is called with a password in the command line


    Read More
  • Password Reset By User Account

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.credential-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detect when a user has reset their password in Azure AD


    Read More
  • Payload Decoded and Decrypted via Built-in Utilities

    calendar Apr 28, 2026 · attack.stealth attack.t1059 attack.t1204 attack.execution attack.t1140 attack.s0482 attack.s0402  ·
    Share on: twitter facebook linkedin copy

    Detects when a built-in utility is used to decode and decrypt a payload after a macOS disk image (DMG) is executed. Malware authors may attempt to evade detection and trick users into executing malicious code by encoding and encrypting their payload and placing it in a disk image file. This behavior is consistent with adware or malware families such as Bundlore and Shlayer.


    Read More
  • PDF File Created By RegEdit.EXE

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file with the ".pdf" extension by the "RegEdit.exe" process. This indicates that a user is trying to print/save a registry key as a PDF in order to potentially extract sensitive information and bypass defenses.


    Read More
  • Persistence Via New SIP Provider

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1553.003  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker register a new SIP provider for persistence and defense evasion


    Read More
  • Persistence Via Sudoers.d Files

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1548.003  ·
    Share on: twitter facebook linkedin copy

    Detects the creation or modification of files within the "sudoers.d" directory on Linux systems. Such activity may indicate an attempt to establish or maintain privilege escalation by granting specific users elevated permissions. Unauthorized changes to sudoers files are a common technique used by attackers to persist administrative access.


    Read More
  • Pikabot Fake DLL Extension Execution Via Rundll32.EXE

    calendar Apr 28, 2026 · attack.execution detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects specific process tree behavior linked to "rundll32" executions, wherein the associated DLL lacks a common ".dll" extension, often signaling potential Pikabot activity.


    Read More
  • PIM Alert Setting Changes To Disabled

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects when PIM alerts are set to disabled.


    Read More
  • PIM Approvals And Deny Elevation

    calendar Apr 28, 2026 · attack.persistence attack.initial-access attack.privilege-escalation attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a PIM elevation is approved or denied. Outside of normal operations should be investigated.


    Read More
  • Ping Hex IP

    calendar Apr 28, 2026 · attack.stealth attack.t1140 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects a ping command that uses a hex encoded IP address


    Read More
  • Pingback Backdoor Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report


    Read More
  • Pingback Backdoor DLL Loading Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report


    Read More
  • Pingback Backdoor File Indicators

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Pingback backdoor that creates ICMP tunnel for C2 as described in the trustwave report


    Read More
  • Possible DC Shadow Attack

    calendar Apr 28, 2026 · attack.credential-access attack.defense-impairment attack.t1207  ·
    Share on: twitter facebook linkedin copy

    Detects DCShadow via create new SPN


    Read More
  • Possible Privilege Escalation via Weak Service Permissions

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detection of sc.exe utility spawning by user with Medium integrity level to change service ImagePath or FailureCommand


    Read More
  • Possible Shadow Credentials Added

    calendar Apr 28, 2026 · attack.persistence attack.credential-access attack.defense-impairment attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Detects possible addition of shadow credentials to an active directory object.


    Read More
  • Potential 7za.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "7za.dll"


    Read More
  • Potential Access Token Abuse

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.001 stp.4u  ·
    Share on: twitter facebook linkedin copy

    Detects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".


    Read More
  • Potential Adplus.EXE Abuse

    calendar Apr 28, 2026 · attack.execution attack.credential-access attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.


    Read More
  • Potential AMSI Bypass Script Using NULL Bits

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects usage of special strings/null bits in order to potentially bypass AMSI functionalities


    Read More
  • Potential AMSI Bypass Using NULL Bits

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects usage of special strings/null bits in order to potentially bypass AMSI functionalities


    Read More
  • Potential AMSI Bypass Via .NET Reflection

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects Request to "amsiInitFailed" that can be used to disable AMSI Scanning


    Read More
  • Potential AMSI COM Server Hijacking

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the AMSI come server registry key in order disable AMSI scanning functionalities. When AMSI attempts to starts its COM component, it will query its registered CLSID and return a non-existent COM server. This causes a load failure and prevents any scanning methods from being accessed, ultimately rendering AMSI useless


    Read More
  • Potential Antivirus Software DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of DLLs that are part of antivirus software suchas McAfee, Symantec...etc


    Read More
  • Potential Application Whitelisting Bypass via Dnx.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.t1027.004  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of Dnx.EXE. The Dnx utility allows for the execution of C# code. Attackers might abuse this in order to bypass application whitelisting.


    Read More
  • Potential appverifUI.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "appverifUI.dll"


    Read More
  • Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential BlueMushroom DLL loading activity via regsvr32 from AppData Local


    Read More
  • Potential Arbitrary Code Execution Via Node.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects the execution node.exe which is shipped with multiple software such as VMware, Adobe...etc. In order to execute arbitrary code. For example to establish reverse shell as seen in Log4j attacks...etc


    Read More
  • Potential Arbitrary Command Execution Using Msdt.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects processes leveraging the "ms-msdt" handler or the "msdt.exe" binary to execute arbitrary commands as seen in the follina (CVE-2022-30190) vulnerability


    Read More
  • Potential Arbitrary Command Execution Via FTP.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "ftp.exe" script with the "-s" or "/s" flag and any child processes ran by "ftp.exe".


    Read More
  • Potential Arbitrary DLL Load Using Winword

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading using the Microsoft Office winword process via the '/l' flag.


    Read More
  • Potential Arbitrary File Download Using Office Application

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects potential arbitrary file download using a Microsoft Office application


    Read More
  • Potential Arbitrary File Download Via Cmdl32.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Cmdl32 with the "/vpn" and "/lan" flags. Attackers can abuse this utility in order to download arbitrary files via a configuration file. Inspect the location and the content of the file passed as an argument in order to determine if it is suspicious.


    Read More
  • Potential Attachment Manager Settings Associations Tamper

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects tampering with attachment manager settings policies associations to lower the default file type risks (See reference for more information)


    Read More
  • Potential Attachment Manager Settings Attachments Tamper

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects tampering with attachment manager settings policies attachments (See reference for more information)


    Read More
  • Potential AutoLogger Sessions Tampering

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects tampering with autologger trace sessions which is a technique used by attackers to disable logging. The AutoLogger event tracing session records events up that occur early in the operating system boot process. Applications and device drivers can use the AutoLogger session to capture traces before the user logs in, and also used by security solutions as telemetry source. Adversaries may disable these sessions to evade detection and prevent security monitoring of early boot activities and system events.


    Read More
  • Potential AVKkid.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "AVKkid.dll"


    Read More
  • Potential Azure Browser SSO Abuse

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects abusing Azure Browser SSO by requesting OAuth 2.0 refresh tokens for an Azure-AD-authenticated Windows user (i.e. the machine is joined to Azure AD and a user logs in with their Azure AD account) wanting to perform SSO authentication in the browser. An attacker can use this to authenticate to Azure AD in a browser as that user.


    Read More
  • Potential Baby Shark Malware Activity

    calendar Apr 28, 2026 · attack.execution attack.discovery attack.stealth attack.t1012 attack.t1059.003 attack.t1059.001 attack.t1218.005 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects activity that could be related to Baby Shark malware


    Read More
  • Potential Base64 Decoded From Images

    calendar Apr 28, 2026 · attack.stealth attack.t1140  ·
    Share on: twitter facebook linkedin copy

    Detects the use of tail to extract bytes at an offset from an image and then decode the base64 value to create a new file with the decoded content. The detected execution is a bash one-liner.


    Read More
  • Potential Binary Impersonating Sysinternals Tools

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218 attack.t1202 attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects binaries that use the same name as legitimate sysinternals tools to evade detection. This rule looks for the execution of binaries that are named similarly to Sysinternals tools. Adversary may rename their malicious tools as legitimate Sysinternals tools to evade detection.


    Read More
  • Potential Binary Proxy Execution Via Cdb.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1106 attack.t1218 attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "cdb.exe" to launch arbitrary processes or commands from a debugger script file


    Read More
  • Potential Binary Proxy Execution Via VSDiagnostics.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "VSDiagnostics.exe" with the "start" command in order to launch and proxy arbitrary binaries.


    Read More
  • Potential BlackByte Ransomware Activity

    calendar Apr 28, 2026 · attack.execution attack.impact attack.stealth attack.t1485 attack.t1498 attack.t1059.001 attack.t1140 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects command line patterns used by BlackByte ransomware in different operations


    Read More
  • Potential Bumblebee Remote Thread Creation

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.011 attack.t1059.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects remote thread injection events based on action seen used by bumblebee


    Read More
  • Potential CCleanerDU.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "CCleanerDU.dll"


    Read More
  • Potential CCleanerReactivator.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "CCleanerReactivator.dll"


    Read More
  • Potential Chrome Frame Helper DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "chrome_frame_helper.dll"


    Read More
  • Potential COLDSTEEL Persistence Service DLL Creation

    calendar Apr 28, 2026 · attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file in a specific location and with a specific name related to COLDSTEEL RAT


    Read More
  • Potential COLDSTEEL Persistence Service DLL Load

    calendar Apr 28, 2026 · attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious DLL load by an "svchost" process based on location and name that might be related to ColdSteel RAT. This DLL location and name has been seen used by ColdSteel as the service DLL for its persistence mechanism


    Read More
  • Potential COLDSTEEL RAT File Indicators

    calendar Apr 28, 2026 · attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file named "dllhost.exe" in the "C:\users\public\Documents" directory. Seen being used by the COLDSTEEL RAT in some of its variants.


    Read More
  • Potential Command Line Path Traversal Evasion Attempt

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects potential evasion or obfuscation attempts using bogus path traversal via the commandline


    Read More
  • Potential Commandline Obfuscation Using Escape Characters

    calendar Apr 28, 2026 · attack.stealth attack.t1140  ·
    Share on: twitter facebook linkedin copy

    Detects potential commandline obfuscation using known escape characters


    Read More
  • Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects potential commandline obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.


    Read More
  • Potential Compromised 3CXDesktopApp Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects execution of known compromised version of 3CXDesktopApp


    Read More
  • Potential Compromised 3CXDesktopApp Update Activity

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the 3CXDesktopApp updater downloading a known compromised version of the 3CXDesktopApp software


    Read More
  • Potential CVE-2023-36884 Exploitation Dropped File

    calendar Apr 28, 2026 · attack.persistence cve.2023-36884 detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects a specific file being created in the recent folder of Office. These files have been seen being dropped during potential exploitations of CVE-2023-36884


    Read More
  • Potential CVE-2024-3400 Exploitation - Palo Alto GlobalProtect OS Command Injection

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation cve.2024-3400 detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potential exploitation attempts of CVE-2024-3400 - an OS command injection in Palo Alto GlobalProtect. This detection looks for suspicious strings that indicate a potential directory traversal attempt or command injection.


    Read More
  • Potential Data Stealing Via Chromium Headless Debugging

    calendar Apr 28, 2026 · attack.credential-access attack.collection attack.stealth attack.t1185 attack.t1564.003  ·
    Share on: twitter facebook linkedin copy

    Detects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control


    Read More
  • Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.


    Read More
  • Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.


    Read More
  • Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.


    Read More
  • Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.


    Read More
  • Potential Defense Evasion Via Binary Rename

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.


    Read More
  • Potential Defense Evasion Via Raw Disk Access By Uncommon Tools

    calendar Apr 28, 2026 · attack.stealth attack.t1006  ·
    Share on: twitter facebook linkedin copy

    Detects raw disk access using uncommon tools or tools that are located in suspicious locations (heavy filtering is required), which could indicate possible defense evasion attempts


    Read More
  • Potential Defense Evasion Via Rename Of Highly Relevant Binaries

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003 car.2013-05-009  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.


    Read More
  • Potential Defense Evasion Via Right-to-Left Override

    calendar Apr 28, 2026 · attack.stealth attack.t1036.002  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of the "u202+E" character, which causes a terminal, browser, or operating system to render text in a right-to-left sequence. This character is used as an obfuscation and masquerading techniques by adversaries to trick users into opening malicious files.


    Read More
  • Potential Devil Bait Malware Reconnaissance

    calendar Apr 28, 2026 · attack.stealth attack.t1218 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects specific process behavior observed with Devil Bait samples


    Read More
  • Potential Devil Bait Related Indicator

    calendar Apr 28, 2026 · detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of ".xml" and ".txt" files in folders of the "\AppData\Roaming\Microsoft" directory by uncommon processes. This behavior was seen common across different Devil Bait samples and stages as described by the NCSC


    Read More
  • Potential DLL Injection Or Execution Using Tracker.exe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL injection and execution using "Tracker.exe"


    Read More
  • Potential DLL Sideloading Of DBGCORE.DLL

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects DLL sideloading of "dbgcore.dll"


    Read More
  • Potential DLL Sideloading Of DBGHELP.DLL

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "dbghelp.dll"


    Read More
  • Potential DLL Sideloading Of DbgModel.DLL

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "DbgModel.dll"


    Read More
  • Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL side loading of "KeyScramblerIE.dll" by "KeyScrambler.exe". Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe".


    Read More
  • Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "libcurl.dll" by the "gup.exe" process from an uncommon location


    Read More
  • Potential DLL Sideloading Of MpSvc.DLL

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "MpSvc.dll".


    Read More
  • Potential DLL Sideloading Of MsCorSvc.DLL

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "mscorsvc.dll".


    Read More
  • Potential DLL Sideloading Of Non-Existent DLLs From System Folders

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects loading of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes, potentially indicating phantom DLL hijacking attempts. Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs.


    Read More
  • Potential DLL Sideloading Using Coregen.exe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1218 attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detect usage of the "coregen.exe" (Microsoft CoreCLR Native Image Generator) binary to sideload arbitrary DLLs.


    Read More
  • Potential DLL Sideloading Via ClassicExplorer32.dll

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading using ClassicExplorer32.dll from the Classic Shell software


    Read More
  • Potential DLL Sideloading Via comctl32.dll

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading using comctl32.dll to obtain system privileges


    Read More
  • Potential DLL Sideloading Via DeviceEnroller.EXE

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the PhoneDeepLink parameter to potentially sideload a DLL file that does not exist. This non-existent DLL file is named "ShellChromeAPI.dll". Adversaries can drop their own renamed DLL and execute it via DeviceEnroller.exe using this parameter


    Read More
  • Potential DLL Sideloading Via JsSchHlp

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading using JUSTSYSTEMS Japanese word processor


    Read More
  • Potential DLL Sideloading Via VMware Xfer

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects loading of a DLL by the VMware Xfer utility from the non-default directory which may be an attempt to sideload arbitrary DLL


    Read More
  • Potential Dridex Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 attack.discovery attack.t1135 attack.t1033 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential Dridex acitvity via specific process patterns


    Read More
  • Potential EACore.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "EACore.dll"


    Read More
  • Potential Edputil.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "edputil.dll"


    Read More
  • Potential Emotet Activity

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1027 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects all Emotet like process executions that are not covered by the more generic rules


    Read More
  • Potential Emotet Rundll32 Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detecting Emotet DLL loading by looking for rundll32.exe processes with command lines ending in ,RunDLL or ,Control_RunDLL


    Read More
  • Potential EmpireMonkey Activity

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential EmpireMonkey APT activity


    Read More
  • Potential Encoded PowerShell Patterns In CommandLine

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects specific combinations of encoding methods in PowerShell via the commandline


    Read More
  • Potential EventLog File Location Tampering

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects tampering with EventLog service "file" key. In order to change the default location of an Evtx file. This technique is used to tamper with log collection and alerting


    Read More
  • Potential Exploitation Attempt From Office Application

    calendar Apr 28, 2026 · attack.execution cve.2021-40444 detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects Office applications executing a child process that includes directory traversal patterns. This could be an attempt to exploit CVE-2022-30190 (MSDT RCE) or CVE-2021-40444 (MSHTML RCE)


    Read More
  • Potential Exploitation of CVE-2025-5054 or CVE-2025-4598

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.t1548 attack.t1003 cve.2025-5054 cve.2025-4598 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects attempts of an attacker to enable core dumps for set-user-ID (SUID) processes by modifying the system file /proc/sys/fs/suid_dumpable, typically by setting its value to 1 or 2. Enabling this feature allows memory dumps (core dumps) of SUID processes, which usually run with elevated privileges. These dumps may contain sensitive information such as passwords, cryptographic keys or other secrets. CVE-2025-5054: Information leak via core dumps from SUID binaries using apport. CVE-2025-4598: Information disclosure in systemd-coredump due to insecure handling of SUID process memory dumps.


    Read More
  • Potential Exploitation of RCE Vulnerability CVE-2025-33053

    calendar Apr 28, 2026 · attack.command-and-control attack.execution attack.stealth attack.t1218 attack.lateral-movement attack.t1105 detection.emerging-threats cve.2025-33053  ·
    Share on: twitter facebook linkedin copy

    Detects potential exploitation of remote code execution vulnerability CVE-2025-33053 which involves unauthorized code execution via WebDAV through external control of file names or paths. The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating their working directories to point to attacker-controlled WebDAV servers, causing them to execute malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries through Process.Start() search order manipulation.


    Read More
  • Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load

    calendar Apr 28, 2026 · attack.command-and-control attack.execution attack.stealth attack.t1218 attack.lateral-movement attack.t1105 detection.emerging-threats cve.2025-33053  ·
    Share on: twitter facebook linkedin copy

    Detects potential exploitation of remote code execution vulnerability CVE-2025-33053 by monitoring suspicious image loads from WebDAV paths. The exploit involves malicious executables from attacker-controlled WebDAV servers loading the Windows system DLLs like gdi32.dll, netapi32.dll, etc.


    Read More
  • Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access

    calendar Apr 28, 2026 · attack.command-and-control attack.execution attack.stealth attack.t1218 attack.lateral-movement attack.t1105 detection.emerging-threats cve.2025-33053  ·
    Share on: twitter facebook linkedin copy

    Detects potential exploitation of remote code execution vulnerability CVE-2025-33053 by looking for process access that involves legitimate Windows executables (iediagcmd.exe, CustomShellHost.exe) accessing suspicious executables hosted on WebDAV shares. This indicates an attacker may be exploiting Process.Start() search order manipulation to execute malicious code from attacker-controlled WebDAV servers instead of legitimate system binaries. The vulnerability allows unauthorized code execution through external control of file names or paths via WebDAV.


    Read More
  • Potential Fake Instance Of Hxtsr.EXE Executed

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    HxTsr.exe is a Microsoft compressed executable file called Microsoft Outlook Communications. HxTsr.exe is part of Outlook apps, because it resides in a hidden "WindowsApps" subfolder of "C:\Program Files". Any instances of hxtsr.exe not in this folder may be malware camouflaging itself as HxTsr.exe


    Read More
  • Potential File Download Via MS-AppInstaller Protocol Handler

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "ms-appinstaller" protocol handler via command line to potentially download arbitrary files via AppInstaller.EXE The downloaded files are temporarly stored in ":\Users%username%\AppData\Local\Packages\Microsoft.DesktopAppInstaller_8wekyb3d8bbwe\AC\INetCache<RANDOM-8-CHAR-DIRECTORY>"


    Read More
  • Potential File Extension Spoofing Using Right-to-Left Override

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1036.002  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious filenames that contain a right-to-left override character and a potentially spoofed file extensions.


    Read More
  • Potential Goofy Guineapig GoolgeUpdate Process Anomaly

    calendar Apr 28, 2026 · detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects "GoogleUpdate.exe" spawning a new instance of itself in an uncommon location as seen used by the Goofy Guineapig backdoor


    Read More
  • Potential Goopdate.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "goopdate.dll", a DLL used by googleupdate.exe


    Read More
  • Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of hidden file/folder with the "::$index_allocation" stream. Which can be used as a technique to prevent access to folder and files from tooling such as "explorer.exe" and "powershell.exe"


    Read More
  • Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects command line containing reference to the "::$index_allocation" stream, which can be used as a technique to prevent access to folders or files from tooling such as "explorer.exe" or "powershell.exe"


    Read More
  • Potential Homoglyph Attack Using Lookalike Characters

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.


    Read More
  • Potential Homoglyph Attack Using Lookalike Characters in Filename

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters. This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.


    Read More
  • Potential In-Memory Execution Using Reflection.Assembly

    calendar Apr 28, 2026 · attack.stealth attack.t1620  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "Reflection.Assembly" load functions to dynamically load assemblies in memory


    Read More
  • Potential Initial Access via DLL Search Order Hijacking

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1566 attack.t1566.001 attack.initial-access attack.t1574 attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to create a DLL file to a known desktop application dependencies folder such as Slack, Teams or OneDrive and by an unusual process. This may indicate an attempt to load a malicious module via DLL search order hijacking.


    Read More
  • Potential Iviewers.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "iviewers.dll" (OLE/COM Object Interface Viewer)


    Read More
  • Potential JLI.dll Side-Loading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL side-loading of jli.dll. JLI.dll has been observed being side-loaded by Java processes by various threat actors, including APT41, XWorm, and others in order to load malicious payloads in context of legitimate Java processes.


    Read More
  • Potential Kapeka Decrypted Backdoor Indicator

    calendar Apr 28, 2026 · detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of a file that is decrypted backdoor binary dropped by the Kapeka Dropper, which disguises itself as a hidden file under a folder named "Microsoft" within "CSIDL_COMMON_APPDATA" or "CSIDL_LOCAL_APPDATA", depending on the process privileges. The file, typically 5-6 characters long with a random combination of consonants and vowels followed by a ".wll" extension to pose as a legitimate file to evade detection.


    Read More
  • Potential Ke3chang/TidePool Malware Activity

    calendar Apr 28, 2026 · attack.defense-impairment attack.g0004 attack.t1685 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications potentially related to the Ke3chang/TidePool malware as seen in campaigns running in 2019 and 2020


    Read More
  • Potential LethalHTA Technique Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218.005  ·
    Share on: twitter facebook linkedin copy

    Detects potential LethalHTA technique where the "mshta.exe" is spawned by an "svchost.exe" process


    Read More
  • Potential Libvlc.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "libvlc.dll", a DLL that is legitimately used by "VLC.exe"


    Read More
  • Potential Linux Process Code Injection Via DD Utility

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.009  ·
    Share on: twitter facebook linkedin copy

    Detects the injection of code by overwriting the memory map of a Linux process using the "dd" Linux command.


    Read More
  • Potential LSASS Process Dump Via Procdump

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.credential-access attack.t1003.001 car.2013-05-009  ·
    Share on: twitter facebook linkedin copy

    Detects potential credential harvesting attempts through LSASS memory dumps using ProcDump. This rule identifies suspicious command-line patterns that combine memory dump flags (-ma, -mm, -mp) with LSASS-related process markers. LSASS (Local Security Authority Subsystem Service) contains sensitive authentication data including plaintext passwords, NTLM hashes, and Kerberos tickets in memory. Attackers commonly dump LSASS memory to extract credentials for lateral movement and privilege escalation.


    Read More
  • Potential Malicious AppX Package Installation Attempts

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potential installation or installation attempts of known malicious appx packages


    Read More
  • Potential Manage-bde.wsf Abuse To Proxy Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects potential abuse of the "manage-bde.wsf" script as a LOLBIN to proxy execution


    Read More
  • Potential Memory Dumping Activity Via LiveKD

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of LiveKD based on PE metadata or image name


    Read More
  • Potential Meterpreter/CobaltStrike Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.001 attack.t1134.002  ·
    Share on: twitter facebook linkedin copy

    Detects the use of getsystem Meterpreter/Cobalt Strike command by detecting a specific service starting


    Read More
  • Potential MFA Bypass Using Legacy Client Authentication

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1078.004 attack.t1110  ·
    Share on: twitter facebook linkedin copy

    Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.


    Read More
  • Potential Mfdetours.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "mfdetours.dll". While using "mftrace.exe" it can be abused to attach to an arbitrary process and force load any DLL named "mfdetours.dll" from the current directory of execution.


    Read More
  • Potential Mftrace.EXE Abuse

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects child processes of the "Trace log generation tool for Media Foundation Tools" (Mftrace.exe) which can abused to execute arbitrary binaries.


    Read More
  • Potential Mpclient.DLL Sideloading

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential sideloading of "mpclient.dll" by Windows Defender processes ("MpCmdRun" and "NisSrv") from their non-default directory.


    Read More
  • Potential Mpclient.DLL Sideloading Via Defender Binaries

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential sideloading of "mpclient.dll" by Windows Defender processes ("MpCmdRun" and "NisSrv") from their non-default directory.


    Read More
  • Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Windows Defender "OfflineScannerShell.exe" from its non standard directory. The "OfflineScannerShell.exe" binary is vulnerable to DLL side loading and will load any DLL named "mpclient.dll" from the current working directory.


    Read More
  • Potential MsiExec Masquerading

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of msiexec.exe from an uncommon directory


    Read More
  • Potential MuddyWater APT Activity

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.g0069 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential Muddywater APT activity


    Read More
  • Potential NetWire RAT Activity - Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects registry keys related to NetWire RAT


    Read More
  • Potential Notepad++ CVE-2025-49144 Exploitation

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.008 cve.2025-49144 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential exploitation of CVE-2025-49144, a local privilege escalation vulnerability in Notepad++ installers (v8.8.1 and prior) where the installer calls regsvr32.exe without specifying the full path. This allows an attacker to execute arbitrary code with elevated privileges by placing a malicious regsvr32.exe alongside this Legitimate Notepad++ installer. The vulnerability is triggered when the installer attempts to register the NppShell.dll file, which is a component of Notepad++.


    Read More
  • Potential NTLM Coercion Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects possible NTLM coercion via certutil using the 'syncwithWU' flag


    Read More
  • Potential Obfuscated Ordinal Call Via Rundll32

    calendar Apr 28, 2026 · attack.stealth attack.t1027.010  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "rundll32" with potential obfuscated ordinal calls


    Read More
  • Potential Password Spraying Attempt Using Dsacls.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects possible password spraying attempts using Dsacls


    Read More
  • Potential PendingFileRenameOperations Tampering

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detect changes to the "PendingFileRenameOperations" registry key from uncommon or suspicious images locations to stage currently used files for rename or deletion after reboot.


    Read More
  • Potential Persistence Attempt Via Existing Service Tampering

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1543.003 attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detects the modification of an existing service in order to execute an arbitrary payload when the service is started or killed as a potential method for persistence.


    Read More
  • Potential Persistence Via Custom Protocol Handler

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects potential persistence activity via the registering of a new custom protocole handlers. While legitimate applications register protocole handlers often times during installation. And attacker can abuse this by setting a custom handler to be used as a persistence mechanism.


    Read More
  • Potential Persistence Via Event Viewer Events.asp

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects potential registry persistence technique using the Event Viewer "Events.asp" technique


    Read More
  • Potential Persistence Via GlobalFlags

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1546.012 car.2013-01-002  ·
    Share on: twitter facebook linkedin copy

    Detects registry persistence technique using the GlobalFlags and SilentProcessExit keys


    Read More
  • Potential Persistence Via Outlook Home Page

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects potential persistence activity via outlook home page. An attacker can set a home page to achieve code execution and persistence by editing the WebView registry keys.


    Read More
  • Potential Persistence Via Outlook Today Page

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects potential persistence activity via outlook today page. An attacker can set a custom page to execute arbitrary code and link to it via the registry values "URL" and "UserDefinedUrl".


    Read More
  • Potential Persistence Via Security Descriptors - ScriptBlock

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects usage of certain functions and keywords that are used to manipulate security descriptors in order to potentially set a backdoor. As seen used in the DAMP project.


    Read More
  • Potential Pikabot Hollowing Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.012 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of rundll32 that leads to the invocation of legitimate Windows binaries. The malware Pikabot has been seen to use this technique for process hollowing through hard-coded Windows binaries


    Read More
  • Potential Pikabot Infection - Suspicious Command Combinations Via Cmd.EXE

    calendar Apr 28, 2026 · attack.command-and-control attack.execution attack.stealth attack.t1059.003 attack.t1105 attack.t1218 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of concatenated commands via "cmd.exe". Pikabot often executes a combination of multiple commands via the command handler "cmd /c" in order to download and execute additional payloads. Commands such as "curl", "wget" in order to download extra payloads. "ping" and "timeout" are abused to introduce delays in the command execution and "Rundll32" is also used to execute malicious DLL files. In the observed Pikabot infections, a combination of the commands described above are used to orchestrate the download and execution of malicious DLL files.


    Read More
  • Potential PlugX Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.s0013 attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of an executable that is typically used by PlugX for DLL side loading starting from an uncommon location


    Read More
  • Potential PowerShell Command Line Obfuscation

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1027 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects the PowerShell command lines with special characters


    Read More
  • Potential PowerShell Downgrade Attack

    calendar Apr 28, 2026 · attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0


    Read More
  • Potential PowerShell Execution Policy Tampering

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the PowerShell execution policy in order to bypass signing requirements for script execution


    Read More
  • Potential PowerShell Execution Policy Tampering - ProcCreation

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the PowerShell execution policy registry key in order to bypass signing requirements for script execution from the CommandLine


    Read More
  • Potential PowerShell Execution Via DLL

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects potential PowerShell execution from a DLL instead of the usual PowerShell process as seen used in PowerShdll. This detection assumes that PowerShell commands are passed via the CommandLine.


    Read More
  • Potential PowerShell Obfuscation Using Alias Cmdlets

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1027 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts


    Read More
  • Potential PowerShell Obfuscation Using Character Join

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1027 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects specific techniques often seen used inside of PowerShell scripts to obfscuate Alias creation


    Read More
  • Potential PowerShell Obfuscation Via Reversed Commands

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of reversed PowerShell commands in the CommandLine. This is often used as a method of obfuscation by attackers


    Read More
  • Potential PowerShell Obfuscation Via WCHAR/CHAR

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious encoded character syntax often used for defense evasion


    Read More
  • Potential PrintNightmare Exploitation Attempt

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574 cve.2021-1675 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detect DLL deletions from Spooler Service driver folder. This might be a potential exploitation attempt of CVE-2021-1675


    Read More
  • Potential Privilege Escalation Attempt Via .Exe.Local Technique

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potential privilege escalation attempt via the creation of the "*.Exe.Local" folder inside the "System32" directory in order to sideload "comctl32.dll"


    Read More
  • Potential Privilege Escalation via Local Kerberos Relay over LDAP

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious local successful logon event where the Logon Package is Kerberos, the remote address is set to localhost, and the target user SID is the built-in local Administrator account. This may indicate an attempt to leverage a Kerberos relay attack variant that can be used to elevate privilege locally from a domain joined limited user to local System privileges.


    Read More
  • Potential Privilege Escalation via Service Permissions Weakness

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detect modification of services configuration (ImagePath, FailureCommand and ServiceDLL) in registry by processes with Medium integrity level


    Read More
  • Potential Privileged System Service Operation - SeLoadDriverPrivilege

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of the 'SeLoadDriverPrivilege' privilege. This privilege is required to load or unload a device driver. With this privilege, the user can dynamically load and unload device drivers or other code in to kernel mode. This user right does not apply to Plug and Play device drivers. If you exclude privileged users/admins and processes, which are allowed to do so, you are maybe left with bad programs trying to load malicious kernel drivers. This will detect Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs) and the usage of Sysinternals and various other tools. So you have to work with a whitelist to find the bad stuff.


    Read More
  • Potential Process Execution Proxy Via CL_Invocation.ps1

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects calls to "SyncInvoke" that is part of the "CL_Invocation.ps1" script to proxy execution using "System.Diagnostics.Process"


    Read More
  • Potential Process Hollowing Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.012  ·
    Share on: twitter facebook linkedin copy

    Detects when a memory process image does not match the disk image, indicative of process hollowing.


    Read More
  • Potential Process Injection Via Msra.EXE

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects potential process injection via Microsoft Remote Asssistance (Msra.exe) by looking at suspicious child processes spawned from the aforementioned process. It has been a target used by many threat actors and used for discovery and persistence tactics


    Read More
  • Potential Provisioning Registry Key Abuse For Binary Proxy Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".


    Read More
  • Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects potential abuse of the provisioning registry key for indirect command execution through "Provlaunch.exe".


    Read More
  • Potential Provlaunch.EXE Binary Proxy Execution Abuse

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.


    Read More
  • Potential Python DLL SideLoading

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of Python DLL files.


    Read More
  • Potential Qakbot Registry Activity

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects a registry key used by IceID in a campaign that distributes malicious OneNote files


    Read More
  • Potential Qakbot Rundll32 Execution

    calendar Apr 28, 2026 · attack.execution detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects specific process tree behavior of a "rundll32" execution often linked with potential Qakbot activity.


    Read More
  • Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1070 attack.persistence attack.t1542.003  ·
    Share on: twitter facebook linkedin copy

    Detects potential malicious and unauthorized usage of bcdedit.exe


    Read More
  • Potential Raspberry Robin Aclui Dll SideLoading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential sideloading of malicious "aclui.dll" by OleView.This behavior was observed in Raspberry-Robin variants reported by chekpoint research on Feburary 2024.


    Read More
  • Potential Raspberry Robin CPL Execution Activity

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a ".CPL" file located in the user temp directory via the Shell32 DLL "Control_RunDLL" export function. This behavior was observed in multiple Raspberry-Robin variants.


    Read More
  • Potential Raspberry Robin Registry Set Internet Settings ZoneMap

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications related to the proxy configuration of the system, potentially associated with the Raspberry Robin malware, as seen in campaigns running in Q1 2024. Raspberry Robin may alter proxy settings to circumvent security measures, ensuring unhindered connection with Command and Control servers for maintaining control over compromised systems if there are any proxy settings that are blocking connections.


    Read More
  • Potential Rcdll.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of rcdll.dll


    Read More
  • Potential ReflectDebugger Content Execution Via WerFault.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "WerFault.exe" with the "-pr" commandline flag that is used to run files stored in the ReflectDebugger key which could be used to store the path to the malware in order to masquerade the execution flow


    Read More
  • Potential Register_App.Vbs LOLScript Abuse

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects potential abuse of the "register_app.vbs" script that is part of the Windows SDK. The script offers the capability to register new VSS/VDS Provider as a COM+ application. Attackers can use this to install malicious DLLs for persistence and execution.


    Read More
  • Potential Registry Persistence Attempt Via DbgManagedDebugger

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of the "Debugger" value to the "DbgManagedDebugger" key in order to achieve persistence. Which will get invoked when an application crashes


    Read More
  • Potential Regsvr32 Commandline Flag Anomaly

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects a potential command line flag anomaly related to "regsvr32" in which the "/i" flag is used without the "/n" which should be uncommon.


    Read More
  • Potential Remote SquiblyTwo Technique Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1047 attack.t1220 attack.execution attack.t1059.005 attack.t1059.007  ·
    Share on: twitter facebook linkedin copy

    Detects potential execution of the SquiblyTwo technique that leverages Windows Management Instrumentation (WMI) to execute malicious code remotely. This technique bypasses application whitelisting by using wmic.exe to process malicious XSL (eXtensible Stylesheet Language) scripts that can contain embedded JScript or VBScript. The attack typically works by fetching XSL content from a remote source (using HTTP/HTTPS) and executing it with full trust privileges directly in memory, avoiding disk-based detection mechanisms. This is a common LOLBin (Living Off The Land Binary) technique used for defense evasion and code execution.


    Read More
  • Potential RemoteFXvGPUDisablement.EXE Abuse

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.


    Read More
  • Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.


    Read More
  • Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell module creation where the module Contents are set to "function Get-VMRemoteFXPhysicalVideoAdapter". This could be a sign of potential abuse of the "RemoteFXvGPUDisablement.exe" binary which is known to be vulnerable to module load-order hijacking.


    Read More
  • Potential RjvPlatform.DLL Sideloading From Default Location

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects loading of "RjvPlatform.dll" by the "SystemResetPlatform.exe" binary which can be abused as a method of DLL side loading since the "$SysReset" directory isn't created by default.


    Read More
  • Potential RjvPlatform.DLL Sideloading From Non-Default Location

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "RjvPlatform.dll" by "SystemResetPlatform.exe" located in a non-default location.


    Read More
  • Potential RoboForm.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "roboform.dll", a DLL used by RoboForm Password Manager


    Read More
  • Potential Rundll32 Execution With DLL Stored In ADS

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects execution of rundll32 where the DLL being called is stored in an Alternate Data Stream (ADS).


    Read More
  • Potential Script Proxy Execution Via CL_Mutexverifiers.ps1

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the Microsoft signed script "CL_mutexverifiers" to proxy the execution of additional PowerShell script commands


    Read More
  • Potential Secure Deletion with SDelete

    calendar Apr 28, 2026 · attack.impact attack.stealth attack.defense-impairment attack.t1070.004 attack.t1027.005 attack.t1485 attack.t1553.002 attack.s0195  ·
    Share on: twitter facebook linkedin copy

    Detects files that have extensions commonly seen while SDelete is used to wipe files.


    Read More
  • Potential ShellDispatch.DLL Functionality Abuse

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potential "ShellDispatch.dll" functionality abuse to execute arbitrary binaries via "ShellExecute"


    Read More
  • Potential ShellDispatch.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "ShellDispatch.dll"


    Read More
  • Potential Signing Bypass Via Windows Developer Features

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects when a user enable developer features such as "Developer Mode" or "Application Sideloading". Which allows the user to install untrusted packages.


    Read More
  • Potential Signing Bypass Via Windows Developer Features - Registry

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects when the enablement of developer features such as "Developer Mode" or "Application Sideloading". Which allows the user to install untrusted packages.


    Read More
  • Potential SmadHook.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "SmadHook.dll", a DLL used by SmadAV antivirus


    Read More
  • Potential SolidPDFCreator.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "SolidPDFCreator.dll"


    Read More
  • Potential Suspicious Activity Using SeCEdit

    calendar Apr 28, 2026 · attack.collection attack.discovery attack.persistence attack.credential-access attack.privilege-escalation attack.execution attack.stealth attack.defense-impairment attack.t1685.001 attack.t1547.001 attack.t1505.005 attack.t1556.002 attack.t1685 attack.t1574.007 attack.t1564.002 attack.t1546.008 attack.t1546.007 attack.t1547.014 attack.t1547.010 attack.t1547.002 attack.t1557 attack.t1082  ·
    Share on: twitter facebook linkedin copy

    Detects potential suspicious behaviour using secedit.exe. Such as exporting or modifying the security policy


    Read More
  • Potential Suspicious BPF Activity - Linux

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of "bpf_probe_write_user" BPF helper-generated warning messages. Which could be a sign of suspicious eBPF activity on the system.


    Read More
  • Potential Suspicious Child Process Of 3CXDesktopApp

    calendar Apr 28, 2026 · attack.command-and-control attack.execution attack.stealth attack.t1218 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential suspicious child processes of "3CXDesktopApp.exe". Which could be related to the 3CXDesktopApp supply chain compromise


    Read More
  • Potential Suspicious Mofcomp Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the "mofcomp" utility as a child of a suspicious shell or script running utility or by having a suspicious path in the commandline. The "mofcomp" utility parses a file containing MOF statements and adds the classes and class instances defined in the file to the WMI repository. Attackers abuse this utility to install malicious MOF scripts


    Read More
  • Potential Suspicious Registry File Imported Via Reg.EXE

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the import of '.reg' files from suspicious paths using the 'reg.exe' utility


    Read More
  • Potential Suspicious Windows Feature Enabled

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the built-in PowerShell cmdlet "Enable-WindowsOptionalFeature" used as a Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images


    Read More
  • Potential Suspicious Windows Feature Enabled - ProcCreation

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the built-in PowerShell cmdlet "Enable-WindowsOptionalFeature" used as a Deployment Image Servicing and Management tool. Similar to DISM.exe, this cmdlet is used to enumerate, install, uninstall, configure, and update features and packages in Windows images


    Read More
  • Potential Suspicious Winget Package Installation

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potential suspicious winget package installation from a suspicious source.


    Read More
  • Potential SysInternals ProcDump Evasion

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1003.001 attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name


    Read More
  • Potential System DLL Sideloading From Non System Locations

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects DLL sideloading of DLLs usually located in system locations (System32, SysWOW64, etc.).


    Read More
  • Potential Tampering With RDP Related Registry Keys Via Reg.EXE

    calendar Apr 28, 2026 · attack.persistence attack.lateral-movement attack.defense-impairment attack.t1021.001 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "reg.exe" for enabling/disabling the RDP service on the host by tampering with the 'CurrentControlSet\Control\Terminal Server' values


    Read More
  • Potential Tampering With Security Products Via WMIC

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects uninstallation or termination of security products using the WMIC utility


    Read More
  • Potential UAC Bypass Via Sdclt.EXE

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    A General detection for sdclt being spawned as an elevated process. This could be an indicator of sdclt being used for bypass UAC techniques.


    Read More
  • Potential Ursnif Malware Activity - Registry

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.defense-impairment attack.t1112 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects registry keys related to Ursnif malware.


    Read More
  • Potential Vcruntime140 DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of vcruntime140.dll, a common C++ runtime library. Threat actors have been observed using DLL sideloading techniques to load malicious payloads under the guise of legitimate applications such as SqlWriter, SqlDumper etc. Notably, APT29 has been documented leveraging WinELOADER to sideload vcruntime140.dll for executing malicious code.


    Read More
  • Potential Vivaldi_elf.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "vivaldi_elf.dll"


    Read More
  • Potential Waveedit.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "waveedit.dll", which is part of the Nero WaveEditor audio editing software.


    Read More
  • Potential Wazuh Security Platform DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL side loading of DLLs that are part of the Wazuh security platform


    Read More
  • Potential WerFault ReflectDebugger Registry Value Abuse

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects potential WerFault "ReflectDebugger" registry value abuse for persistence.


    Read More
  • Potential Windows Defender Tampering Via Wmic.EXE

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1047 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects potential tampering with Windows Defender settings such as adding exclusion using wmic


    Read More
  • Potential Winnti Dropper Activity

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects files dropped by Winnti as described in RedMimicry Winnti playbook


    Read More
  • Potential WWlib.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of "wwlib.dll"


    Read More
  • Potentially Over Permissive Permissions Granted Using Dsacls.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects usage of Dsacls to grant over permissive permissions


    Read More
  • Potentially Suspicious ASP.NET Compilation Via AspNetCompiler

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "aspnet_compiler.exe" with potentially suspicious paths for compilation.


    Read More
  • Potentially Suspicious Cabinet File Expansion

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the expansion or decompression of cabinet files from potentially suspicious or uncommon locations, e.g. seen in Iranian MeteorExpress related attacks


    Read More
  • Potentially Suspicious Call To Win32_NTEventlogFile Class

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the WMI class "Win32_NTEventlogFile" in a potentially suspicious way (delete, backup, change permissions, etc.) from a PowerShell script


    Read More
  • Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the WMI class "Win32_NTEventlogFile" in a potentially suspicious way (delete, backup, change permissions, etc.) from a PowerShell script


    Read More
  • Potentially Suspicious Child Process Of ClickOnce Application

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious child processes of a ClickOnce deployment application


    Read More
  • Potentially Suspicious Child Process Of DiskShadow.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious child processes of "Diskshadow.exe". This could be an attempt to bypass parent/child relationship detection or application whitelisting rules.


    Read More
  • Potentially Suspicious Child Process of KeyScrambler.exe

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.privilege-escalation attack.stealth attack.t1203 attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious child processes of KeyScrambler.exe


    Read More
  • Potentially Suspicious Child Process Of Regsvr32

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious child processes of "regsvr32.exe".


    Read More
  • Potentially Suspicious Child Process Of VsCode

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon or suspicious child processes spawning from a VsCode "code.exe" process. This could indicate an attempt of persistence via VsCode tasks or terminal profiles.


    Read More
  • Potentially Suspicious Child Processes Spawned by ConHost

    calendar Apr 28, 2026 · attack.stealth attack.t1202 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child processes related to Windows Shell utilities spawned by conhost.exe, which could indicate malicious activity using trusted system components.


    Read More
  • Potentially Suspicious CMD Shell Output Redirect

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects inline Windows shell commands redirecting output via the ">" symbol to a suspicious location. This technique is sometimes used by malicious actors in order to redirect the output of reconnaissance commands such as "hostname" and "dir" to files for future exfiltration.


    Read More
  • Potentially Suspicious Desktop Background Change Using Reg.EXE

    calendar Apr 28, 2026 · attack.persistence attack.impact attack.defense-impairment attack.t1112 attack.t1491.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "reg.exe" to alter registry keys that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.


    Read More
  • Potentially Suspicious Desktop Background Change Via Registry

    calendar Apr 28, 2026 · attack.persistence attack.impact attack.defense-impairment attack.t1112 attack.t1491.001  ·
    Share on: twitter facebook linkedin copy

    Detects registry value settings that would replace the user's desktop background. This is a common technique used by malware to change the desktop background to a ransom note or other image.


    Read More
  • Potentially Suspicious DLL Registered Via Odbcconf.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "odbcconf" with the "REGSVR" action where the DLL in question doesn't contain a ".dll" extension. Which is often used as a method to evade defenses.


    Read More
  • Potentially Suspicious DMP/HDMP File Creation

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file with the ".dmp"/".hdmp" extension by a shell or scripting application such as "cmd", "powershell", etc. Often created by software during a crash. Memory dumps can sometimes contain sensitive information such as credentials. It's best to determine the source of the crash.


    Read More
  • Potentially Suspicious Event Viewer Child Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt


    Read More
  • Potentially Suspicious Execution From Parent Process In Public Folder

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1564 attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.


    Read More
  • Potentially Suspicious Execution From Tmp Folder

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects a potentially suspicious execution of a process located in the '/tmp/' folder


    Read More
  • Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218.009  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious execution of the Regasm/Regsvcs utilities from a potentially suspicious location


    Read More
  • Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension

    calendar Apr 28, 2026 · attack.stealth attack.t1218.009  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious execution of the Regasm/Regsvcs utilities with an uncommon extension.


    Read More
  • Potentially Suspicious File Download From ZIP TLD

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the download of a file with a potentially suspicious extension from a .zip top level domain.


    Read More
  • Potentially Suspicious GoogleUpdate Child Process

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious child processes of "GoogleUpdate.exe"


    Read More
  • Potentially Suspicious NTFS Symlink Behavior Modification

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1059 attack.t1222.001  ·
    Share on: twitter facebook linkedin copy

    Detects the modification of NTFS symbolic link behavior using fsutil, which could be used to enable remote to local or remote to remote symlinks for potential attacks.


    Read More
  • Potentially Suspicious Office Document Executed From Trusted Location

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of an Office application that points to a document that is located in a trusted location. Attackers often used this to avoid macro security and execute their malicious code.


    Read More
  • Potentially Suspicious Ping/Copy Command Combination

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon and potentially suspicious one-liner command containing both "ping" and "copy" at the same time, which is usually used by malware.


    Read More
  • Potentially Suspicious Regsvr32 HTTP IP Pattern

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects regsvr32 execution to download and install DLLs located remotely where the address is an IP address.


    Read More
  • Potentially Suspicious Regsvr32 HTTP/FTP Pattern

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects regsvr32 execution to download/install/register new DLLs that are hosted on Web or FTP servers.


    Read More
  • Potentially Suspicious Rundll32 Activity

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious execution of rundll32, with specific calls to some DLLs with known LOLBIN functionalities


    Read More
  • Potentially Suspicious Rundll32.EXE Execution of UDL File

    calendar Apr 28, 2026 · attack.execution attack.command-and-control attack.stealth attack.t1218.011 attack.t1071  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of rundll32.exe with the oledb32.dll library to open a UDL file. Threat actors can abuse this technique as a phishing vector to capture authentication credentials or other sensitive data.


    Read More
  • Potentially Suspicious Self Extraction Directive File Created

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a binary file with the ".sed" extension. The ".sed" extension stand for Self Extraction Directive files. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries. Usually ".sed" files are simple ini files and not PE binaries.


    Read More
  • Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load

    calendar Apr 28, 2026 · attack.impact attack.t1490  ·
    Share on: twitter facebook linkedin copy

    Detects the image load of VSS DLL by uncommon executables


    Read More
  • Potentially Suspicious WDAC Policy File Creation

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious Windows Defender Application Control (WDAC) policy file creation from abnormal processes that could be abused by attacker to block EDR/AV components while allowing their own malicious code to run on the system.


    Read More
  • Potentially Suspicious Windows App Activity

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious child process of applications launched from inside the WindowsApps directory. This could be a sign of a rogue ".appx" package installation/execution


    Read More
  • Potentially Suspicious Wuauclt Network Connection

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the Windows Update Client binary (wuauclt.exe) to proxy execute code and making network connections. One could easily make the DLL spawn a new process and inject to it to proxy the network connection and bypass this rule.


    Read More
  • PowerShell Base64 Encoded FromBase64String Cmdlet

    calendar Apr 28, 2026 · attack.stealth attack.t1140 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects usage of a base64 encoded "FromBase64String" cmdlet in a process command line


    Read More
  • PowerShell Base64 Encoded Invoke Keyword

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects UTF-8 and UTF-16 Base64 encoded powershell 'Invoke-' calls


    Read More
  • Powershell Base64 Encoded MpPreference Cmdlet

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects base64 encoded "MpPreference" PowerShell cmdlet code that tries to modifies or tamper with Windows Defender AV


    Read More
  • PowerShell Base64 Encoded Reflective Assembly Load

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1027 attack.t1620  ·
    Share on: twitter facebook linkedin copy

    Detects base64 encoded .NET reflective loading of Assembly


    Read More
  • PowerShell Base64 Encoded WMI Classes

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects calls to base64 encoded WMI class such as "Win32_ShadowCopy", "Win32_ScheduledJob", etc.


    Read More
  • PowerShell Called from an Executable Version Mismatch

    calendar Apr 28, 2026 · attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell called from an executable by the version mismatch method


    Read More
  • PowerShell Console History Logs Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence


    Read More
  • PowerShell Core DLL Loaded Via Office Application

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell core DLL being loaded by an Office Product


    Read More
  • PowerShell Decompress Commands

    calendar Apr 28, 2026 · attack.stealth attack.t1140  ·
    Share on: twitter facebook linkedin copy

    A General detection for specific decompress commands in PowerShell logs. This could be an adversary decompressing files.


    Read More
  • Powershell Defender Disable Scan Feature

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects requests to disable Microsoft Defender features using PowerShell commands


    Read More
  • Powershell Defender Exclusion

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects requests to exclude files, folders or processes from Antivirus scanning using PowerShell cmdlets


    Read More
  • PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the use of PowerShell to execute the 'Set-MpPreference' cmdlet to configure Windows Defender's threat severity default action to 'Allow' (value '6') or 'NoAction' (value '9'). This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level. An attacker might use this technique via the command line to bypass defenses before executing payloads.


    Read More
  • PowerShell Deleted Mounted Share

    calendar Apr 28, 2026 · attack.stealth attack.t1070.005  ·
    Share on: twitter facebook linkedin copy

    Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation


    Read More
  • Powershell Detect Virtualization Environment

    calendar Apr 28, 2026 · attack.discovery attack.stealth attack.t1497.001  ·
    Share on: twitter facebook linkedin copy

    Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the presence of artifacts indicative of a virtual machine environment (VME) or sandbox


    Read More
  • PowerShell Downgrade Attack - PowerShell

    calendar Apr 28, 2026 · attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0


    Read More
  • Powershell Executed From Headless ConHost Process

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1059.003 attack.t1564.003  ·
    Share on: twitter facebook linkedin copy

    Detects the use of powershell commands from headless ConHost window. The "--headless" flag hides the windows from the user upon execution.


    Read More
  • Powershell Install a DLL in System Directory

    calendar Apr 28, 2026 · attack.persistence attack.credential-access attack.defense-impairment attack.t1556.002  ·
    Share on: twitter facebook linkedin copy

    Uses PowerShell to install/copy a file into a system directory such as "System32" or "SysWOW64"


    Read More
  • PowerShell Logging Disabled Via Registry Key Tampering

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1564.001 attack.t1112 attack.persistence  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging


    Read More
  • PowerShell MSI Install via WindowsInstaller COM From Remote Location

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1218 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (WindowsInstaller.Installer) hosted remotely. This could be indication of malicious software deployment or lateral movement attempts using Windows Installer functionality. And the usage of WindowsInstaller COM object rather than msiexec could be an attempt to bypass the detection.


    Read More
  • PowerShell Script Change Permission Via Set-Acl

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell execution to set the ACL of a file or a folder


    Read More
  • PowerShell Script Change Permission Via Set-Acl - PsScript

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell scripts set ACL to of a file or a folder


    Read More
  • PowerShell Set-Acl On Windows Folder

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell scripts to set the ACL to a file in the Windows folder


    Read More
  • PowerShell Set-Acl On Windows Folder - PsScript

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell scripts to set the ACL to a file in the Windows folder


    Read More
  • PowerShell ShellCode

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Base64 encoded Shellcode


    Read More
  • Powershell Store File In Alternate Data Stream

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Storing files in Alternate Data Stream (ADS) similar to Astaroth malware.


    Read More
  • Powershell Timestomp

    calendar Apr 28, 2026 · attack.stealth attack.t1070.006  ·
    Share on: twitter facebook linkedin copy

    Adversaries may modify file time attributes to hide new or changes to existing files. Timestomping is a technique that modifies the timestamps of a file (the modify, access, create, and change times), often to mimic files that are in the same folder.


    Read More
  • Powershell Token Obfuscation - Process Creation

    calendar Apr 28, 2026 · attack.stealth attack.t1027.009  ·
    Share on: twitter facebook linkedin copy

    Detects TOKEN OBFUSCATION technique from Invoke-Obfuscation


    Read More
  • PowerShell Web Access Feature Enabled Via DISM

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the use of DISM to enable the PowerShell Web Access feature, which could be used for remote access and potential abuse


    Read More
  • PowerShell WMI Win32_Product Install MSI

    calendar Apr 28, 2026 · attack.stealth attack.t1218.007  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of an MSI file using PowerShell and the WMI Win32_Product class


    Read More
  • PowerShell Write-EventLog Usage

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "Write-EventLog" cmdlet with 'RawData' flag. The cmdlet can be levreage to write malicious payloads to the EventLog and then retrieve them later for later use


    Read More
  • PPL Tampering Via WerFaultSecure

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685 attack.credential-access attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential abuse of WerFaultSecure.exe to dump Protected Process Light (PPL) processes like LSASS or to freeze security solutions (EDR/antivirus). This technique is used by tools such as EDR-Freeze and WSASS to bypass PPL protections and access sensitive information or disable security software. Distinct command line patterns help identify the specific tool:

    • WSASS usage typically shows: "WSASS.exe WerFaultSecure.exe [PID]" in ParentCommandLine
    • EDR-Freeze usage typically shows: "EDR-Freeze_[version].exe [PID] [timeout]" in ParentCommandLine Legitimate debugging operations using WerFaultSecure are rare in production environments and should be investigated.


    Read More
  • Prefetch File Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of a prefetch file which may indicate an attempt to destroy forensic evidence


    Read More
  • Previously Installed IIS Module Was Removed

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685.001 attack.t1505.004  ·
    Share on: twitter facebook linkedin copy

    Detects the removal of a previously installed IIS module.


    Read More
  • PrintBrm ZIP Creation of Extraction

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth attack.t1105 attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the LOLBIN PrintBrm.exe, which can be used to create or extract ZIP files. PrintBrm.exe should not be run on a normal workstation.


    Read More
  • Privileged Account Creation

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a new admin is created.


    Read More
  • Procdump Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1003.001 attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the SysInternals Procdump utility


    Read More
  • Process Access via TrolleyExpress Exclusion

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 attack.credential-access attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects a possible process memory dump that uses the white-listed Citrix TrolleyExpress.exe filename as a way to dump the lsass process memory


    Read More
  • Process Creation Using Sysnative Folder

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects process creation events that use the Sysnative folder (common for CobaltStrike spawns)


    Read More
  • Process Deletion of Its Own Executable

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of a process's executable by itself. This is usually not possible without workarounds and may be used by malware to hide its traces.


    Read More
  • Process Execution From A Potentially Suspicious Folder

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects a potentially suspicious execution from an uncommon folder.


    Read More
  • Process Launched Without Image Name

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detect the use of processes with no name (".exe"), which can be used to evade Image-based detections.


    Read More
  • Process Memory Dump Via Comsvcs.DLL

    calendar Apr 28, 2026 · attack.credential-access attack.stealth attack.t1036 attack.t1003.001 car.2013-05-009  ·
    Share on: twitter facebook linkedin copy

    Detects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)


    Read More
  • Process Memory Dump Via Dotnet-Dump

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "dotnet-dump" with the "collect" flag. The execution could indicate potential process dumping of critical processes such as LSASS.


    Read More
  • Process Proxy Execution Via Squirrel.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of the "Squirrel.exe" binary to execute arbitrary processes. This binary is part of multiple Electron based software installations (Slack, Teams, Discord, etc.)


    Read More
  • Program Executed Using Proxy/Local Command Via SSH.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detect usage of the "ssh.exe" binary as a proxy to launch other programs.


    Read More
  • Proxy Execution via Vshadow

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the invocation of vshadow.exe with the -exec parameter that executes a specified script or command after the shadow copies are created but before the VShadow tool exits. VShadow is a command-line tool that you can use to create and manage volume shadow copies. While legitimate backup or administrative scripts may use this flag, attackers can leverage this parameter to proxy the execution of malware.


    Read More
  • Proxy Execution Via Wuauclt.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the Windows Update Client binary (wuauclt.exe) for proxy execution.


    Read More
  • Ps.exe Renamed SysInternals Tool

    calendar Apr 28, 2026 · attack.stealth attack.g0035 attack.t1036.003 car.2013-05-009 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects renamed SysInternals tool execution with a binary named ps.exe as used by Dragonfly APT group and documented in TA17-293A report


    Read More
  • PSScriptPolicyTest Creation By Uncommon Process

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of the "PSScriptPolicyTest" PowerShell script by an uncommon process. This file is usually generated by Microsoft Powershell to test against Applocker.


    Read More
  • PUA - AdvancedRun Execution

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.stealth attack.t1564.003 attack.t1134.002 attack.t1059.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of AdvancedRun utility


    Read More
  • PUA - AdvancedRun Suspicious Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.002  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of AdvancedRun utility in the context of the TrustedInstaller, SYSTEM, Local Service or Network Service accounts


    Read More
  • PUA - CleanWipe Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the use of CleanWipe a tool usually used to delete Symantec antivirus.


    Read More
  • PUA - DefenderCheck Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1027.005  ·
    Share on: twitter facebook linkedin copy

    Detects the use of DefenderCheck, a tool to evaluate the signatures used in Microsoft Defender. It can be used to figure out the strings / byte chains used in Microsoft Defender to detect a tool and thus used for AV evasion.


    Read More
  • PUA - Potential PE Metadata Tamper Using Rcedit

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003 attack.t1036 attack.t1027.005 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the use of rcedit to potentially alter executable PE metadata properties, which could conceal efforts to rename system utilities for defense evasion.


    Read More
  • PUA - Process Hacker Execution

    calendar Apr 28, 2026 · attack.discovery attack.persistence attack.privilege-escalation attack.stealth attack.t1622 attack.t1564 attack.t1543  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc). Process Hacker is a tool to view and manipulate processes, kernel options and other low level options. Threat actors abused older vulnerable versions to manipulate system processes.


    Read More
  • PUA - System Informer Execution

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.discovery attack.stealth attack.t1082 attack.t1564 attack.t1543  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations


    Read More
  • Publisher Attachment File Dropped In Suspicious Location

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects creation of files with the ".pub" extension in suspicious or uncommon locations. This could be a sign of attackers abusing Publisher documents


    Read More
  • Pubprn.vbs Proxy Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1216.001  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the 'Pubprn.vbs' Microsoft signed script to execute commands.


    Read More
  • PwnKit Local Privilege Escalation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.001 detection.emerging-threats cve.2021-4034  ·
    Share on: twitter facebook linkedin copy

    Detects potential PwnKit exploitation CVE-2021-4034 in auth logs


    Read More
  • Python Function Execution Security Warning Disabled In Excel

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the registry value "PythonFunctionWarnings" that would prevent any warnings or alerts from showing when Python functions are about to be executed. Threat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.


    Read More
  • Python Function Execution Security Warning Disabled In Excel - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the registry value "PythonFunctionWarnings" that would prevent any warnings or alerts from showing when Python functions are about to be executed. Threat actors could run malicious code through the new Microsoft Excel feature that allows Python to run within the spreadsheet.


    Read More
  • Python Image Load By Non-Python Process

    calendar Apr 28, 2026 · attack.stealth attack.t1027.002  ·
    Share on: twitter facebook linkedin copy

    Detects the image load of "Python Core" by a non-Python process. This might be indicative of a execution of executable that has been bundled from Python code. Various tools like Py2Exe, PyInstaller, and cx_Freeze are used to bundle Python code into standalone executables. Threat actors often use these tools to bundle malicious Python scripts into executables, sometimes to obfuscate the code or to bypass security measures.


    Read More
  • Python One-Liners with Base64 Decoding

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.006 attack.t1027.010  ·
    Share on: twitter facebook linkedin copy

    Detects Python one-liners that use base64 decoding functions in command line executions. Malicious scripts or attackers often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.


    Read More
  • Python One-Liners with Base64 Decoding - Linux

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.006 attack.t1027.010  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Python's base64 decoding functions in command line executions on Linux systems. Malicious scripts often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.


    Read More
  • Qakbot Regsvr32 Calc Pattern

    calendar Apr 28, 2026 · attack.execution detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects a specific command line of "regsvr32" where the "calc" keyword is used in conjunction with the "/s" flag. This behavior is often seen used by Qakbot


    Read More
  • Qakbot Rundll32 Exports Execution

    calendar Apr 28, 2026 · attack.execution detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects specific process tree behavior of a "rundll32" execution with exports linked with Qakbot activity.


    Read More
  • Qakbot Rundll32 Fake DLL Extension Execution

    calendar Apr 28, 2026 · attack.execution detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects specific process tree behavior of a "rundll32" execution where the DLL doesn't have the ".dll" extension. This is often linked with potential Qakbot activity.


    Read More
  • Raccine Uninstall

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects commands that indicate a Raccine removal from an end system. Raccine is a free ransomware protection tool.


    Read More
  • Rare Remote Thread Creation By Uncommon Source Image

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon processes creating remote threads.


    Read More
  • Raw Paste Service Access

    calendar Apr 28, 2026 · attack.command-and-control attack.t1071.001 attack.t1102.001 attack.t1102.003  ·
    Share on: twitter facebook linkedin copy

    Detects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form


    Read More
  • RDP Connection Allowed Via Netsh.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the netsh command to open and allow connections to port 3389 (RDP). As seen used by Sarwent Malware


    Read More
  • RDP over Reverse SSH Tunnel WFP

    calendar Apr 28, 2026 · attack.command-and-control attack.lateral-movement attack.t1090.001 attack.t1090.002 attack.t1021.001 car.2013-07-002  ·
    Share on: twitter facebook linkedin copy

    Detects svchost hosting RDP termsvcs communicating with the loopback address


    Read More
  • RDP Port Forwarding Rule Added Via Netsh.EXE

    calendar Apr 28, 2026 · attack.lateral-movement attack.command-and-control attack.t1090  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of netsh to configure a port forwarding of port 3389 (RDP) rule


    Read More
  • RDP Sensitive Settings Changed

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc.

    Below is a list of registry keys/values that are monitored by this rule:

    • Shadow: Used to enable Remote Desktop shadowing, which allows an administrator to view or control a user's session.
    • DisableRemoteDesktopAntiAlias: Disables anti-aliasing for remote desktop sessions.
    • DisableSecuritySettings: Disables certain security settings for Remote Desktop connections.
    • fAllowUnsolicited: Allows unsolicited remote assistance offers.
    • fAllowUnsolicitedFullControl: Allows unsolicited remote assistance offers with full control.
    • InitialProgram: Specifies a program to run automatically when a user logs on to a remote computer.
    • ServiceDll: Used in RDP hijacking techniques to specify a custom DLL to be loaded by the Terminal Services service.
    • SecurityLayer: Specifies the security layer used for RDP connections.


    Read More
  • RDP Sensitive Settings Changed to Zero

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects tampering of RDP Terminal Service/Server sensitive settings. Such as allowing unauthorized users access to a system via the 'fAllowUnsolicited' or enabling RDP via 'fDenyTSConnections', etc.


    Read More
  • RedMimicry Winnti Playbook Registry Manipulation

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects actions caused by the RedMimicry Winnti playbook


    Read More
  • RedSun - Conhost.exe Spawned by TieringEngineService.exe

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.002 attack.t1036.005 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects two stages of the RedSun post-exploitation process chain that deliver a SYSTEM-level shell to the attacker's interactive session. Observed process chain services.exe → TieringEngineService.exe → conhost.exe (SYSTEM, CommandLine: bare path, no arguments) → cmd.exe / shell (SYSTEM, TerminalSessionId = attacker's session)

    Stage 1 — TieringEngineService.exe spawns argument-less conhost.exe: After winning the oplock + Cloud Files mount point race, the malicious TieringEngineService.exe (RedSun.exe copied to System32, started via CoCreateInstance / services.exe) detects it is NT AUTHORITY\SYSTEM and calls LaunchConsoleInSessionId(). This opens \.\pipe\REDSUN, reads the attacker's session ID, duplicates the SYSTEM token, re-stamps it with that session ID via SetTokenInformation(TokenSessionId), then calls CreateProcessAsUser to spawn conhost.exe with no arguments.

    Stage 2 — Shell spawned from rogue conhost.exe (EDR sources with GrandParentImage): The rogue SYSTEM conhost.exe spawns a shell (cmd.exe, PowerShell, etc.) as SYSTEM in the attacker's interactive session. On EDR sources that expose GrandParentImage, the full three-level chain (TieringEngineService.exe → conhost.exe → shell) can be matched directly. The legitimate TieringEngineService.exe is a headless COM server that is unlikely to spawn conhost.exe under normal conditions.


    Read More
  • RedSun - Named Pipe Created

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.defense-impairment attack.t1055 attack.t1685 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a named pipe with the hardcoded name "REDSUN". The RedSun exploit tool uses a pipe with this name for synchronisation and command communication between its components during the Cloud Files API + oplock-based AV bypass and privilege escalation chain. RedSun creates the pipe as \??\pipe\REDSUN. The pipe server listens for the token-duplicated elevated process to connect and respond, completing the privilege escalation from user to SYSTEM. Presence of this pipe name indicates active or recent RedSun execution.


    Read More
  • RedSun - TieringEngineService.exe Detected as EICAR Test File

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1036.005 attack.t1685 attack.privilege-escalation attack.t1055 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Windows Defender (EventID 1119 - Remediation Action Failed) flagging TieringEngineService.exe dropped in a characteristic RS-{GUID} temporary directory, or the RedSun.exe process itself being present. This covers the staging pattern used by RedSun, a Cloud Files API and opportunistic lock (oplock) based AV bypass/privilege escalation tool.

    RedSun works as follows:

    1. Registers a Cloud Files sync root and creates a Cloud Files placeholder for TieringEngineService.exe under %TEMP%\RS-{GUID}\
    2. The placeholder file carries EICAR test file content (Virus:DOS/EICAR_Test_File) to reliably trigger a Defender scan and remediation attempt
    3. Requests a batch oplock (FSCTL_REQUEST_BATCH_OPLOCK) on the placeholder file
    4. When Defender attempts to scan/quarantine the file, the oplock triggers - holding the file open
    5. During the oplock break window, RedSun swaps the mount point (junction) to redirect \?\C:\Windows\System32 to the attacker-controlled temp path
    6. This races the AV/OS into executing the malicious TieringEngineService.exe with elevated privileges


    Read More
  • RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file named TieringEngineService.exe inside a directory whose path contains the RS- prefix characteristic of RedSun's staging directory (e.g. %TEMP%\RS-{GUID}\TieringEngineService.exe). RedSun registers a Cloud Files sync root under this RS-prefixed path and drops a masqueraded placeholder there as part of its oplock-based AV bypass and privilege escalation chain.

    The RS-{GUID} directory name is generated by RedSun itself and has no legitimate system usage, making the combination of this path prefix and the TieringEngineService.exe filename a highly specific indicator of RedSun activity.


    Read More
  • Reg Add Suspicious Paths

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when an adversary uses the reg.exe utility to add or modify new keys or subkeys


    Read More
  • RegAsm.EXE Execution Without CommandLine Flags or Files

    calendar Apr 28, 2026 · attack.stealth attack.t1218.009  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "RegAsm.exe" without a commandline flag or file, which might indicate potential process injection activity. Usually "RegAsm.exe" should point to a dedicated DLL file or call the help with the "/?" flag.


    Read More
  • RegAsm.EXE Initiating Network Connection To Public IP

    calendar Apr 28, 2026 · attack.stealth attack.t1218.009  ·
    Share on: twitter facebook linkedin copy

    Detects "RegAsm.exe" initiating a network connection to public IP adresses


    Read More
  • Regedit as Trusted Installer

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects a regedit started with TrustedInstaller privileges or by ProcessHacker.exe


    Read More
  • REGISTER_APP.VBS Proxy Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the use of a Microsoft signed script 'REGISTER_APP.VBS' to register a VSS/VDS Provider as a COM+ application.


    Read More
  • Registry Entries For Azorult Malware

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the presence of a registry key created during Azorult execution


    Read More
  • Registry Explorer Policy Modification

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications that disable internal tools or functions in explorer (malware like Agent Tesla uses this technique)


    Read More
  • Registry Hide Function from User

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications that hide internal tools or functions from the user (malware like Agent Tesla, Hermetic Wiper uses this technique)


    Read More
  • Registry Manipulation via WMI Stdregprov

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.discovery attack.defense-impairment attack.t1047 attack.t1112 attack.t1012  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of wmic.exe to manipulate Windows registry via the WMI StdRegProv class. This behaviour could be potentially suspicious because it uses an alternative method to modify registry keys instead of legitimate registry tools like reg.exe or regedit.exe. Attackers specifically choose this technique to evade detection and bypass security monitoring focused on traditional registry modification commands.


    Read More
  • Registry Modification Attempt Via VBScript

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.defense-impairment attack.t1112 attack.t1059.005  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods via common LOLBINs. It could be an attempt to modify the registry for persistence without using straightforward methods like regedit.exe, reg.exe, or PowerShell. Threat Actors may use this technique to evade detection by security solutions that monitor for direct registry modifications through traditional tools.


    Read More
  • Registry Modification Attempt Via VBScript - PowerShell

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.defense-impairment attack.t1112 attack.t1059.005  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to modify the registry using VBScript's CreateObject("Wscript.shell") and RegWrite methods embedded within PowerShell scripts or commands. Threat actors commonly embed VBScript code within PowerShell to perform registry modifications, attempting to evade detection that monitors for direct registry access through traditional tools. This technique can be used for persistence, defense evasion, and privilege escalation by modifying registry keys without using regedit.exe, reg.exe, or PowerShell's native registry cmdlets.


    Read More
  • Registry Modification for OCI DLL Redirection

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.defense-impairment attack.t1112 attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications related to 'OracleOciLib' and 'OracleOciLibPath' under 'MSDTC' settings. Threat actors may modify these registry keys to redirect the loading of 'oci.dll' to a malicious DLL, facilitating phantom DLL hijacking via the MSDTC service.


    Read More
  • Registry Modification of MS-settings Protocol Handler

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.defense-impairment attack.t1548.002 attack.t1546.001 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications to the 'ms-settings' protocol handler, which is frequently targeted for UAC bypass or persistence. Attackers can modify this registry to execute malicious code with elevated privileges by hijacking the command execution path.


    Read More
  • Registry Modification Via Regini.EXE

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of regini.exe which can be used to modify registry keys, the changes are imported from one or more text files.


    Read More
  • Registry Persistence via Service in Safe Mode

    calendar Apr 28, 2026 · attack.stealth attack.t1564.001  ·
    Share on: twitter facebook linkedin copy

    Detects the modification of the registry to allow a driver or service to persist in Safe Mode.


    Read More
  • Registry Tampering by Potentially Suspicious Processes

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.defense-impairment attack.t1112 attack.t1059.005  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious registry modifications made by suspicious processes such as script engine processes such as WScript, or CScript etc. These processes are rarely used for legitimate registry modifications, and their activity may indicate an attempt to modify the registry without using standard tools like regedit.exe or reg.exe, potentially for evasion and persistence.


    Read More
  • Registry-Free Process Scope COR_PROFILER

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.012  ·
    Share on: twitter facebook linkedin copy

    Adversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR. The COR_PROFILER is a .NET Framework feature which allows developers to specify an unmanaged (or external of .NET) profiling DLL to be loaded into each .NET process that loads the Common Language Runtime (CLR). These profiliers are designed to monitor, troubleshoot, and debug managed code executed by the .NET CLR. (Citation: Microsoft Profiling Mar 2017) (Citation: Microsoft COR_PROFILER Feb 2013)


    Read More
  • Regsvr32 DLL Execution With Suspicious File Extension

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of REGSVR32.exe with DLL files masquerading as other files


    Read More
  • Regsvr32 DLL Execution With Uncommon Extension

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.stealth attack.t1574 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects a "regsvr32" execution where the DLL doesn't contain a common file extension.


    Read More
  • Regsvr32 Execution From Highly Suspicious Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects execution of regsvr32 where the DLL is located in a highly suspicious locations


    Read More
  • Regsvr32 Execution From Potential Suspicious Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects execution of regsvr32 where the DLL is located in a potentially suspicious location.


    Read More
  • Remote Access Tool - NetSupport Execution From Unusual Location

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of client32.exe (NetSupport RAT) from an unusual location (outside of 'C:\Program Files')


    Read More
  • Remote Access Tool - Renamed MeshAgent Execution - MacOS

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth attack.t1219.002 attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.


    Read More
  • Remote Access Tool - Renamed MeshAgent Execution - Windows

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth attack.t1219.002 attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed instance of the Remote Monitoring and Management (RMM) tool, MeshAgent. RMM tools such as MeshAgent are commonly utilized by IT administrators for legitimate remote support and system management. However, malicious actors may exploit these tools by renaming them to bypass detection mechanisms, enabling unauthorized access and control over compromised systems.


    Read More
  • Remote Access Tool - RURAT Execution From Unusual Location

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Remote Utilities RAT (RURAT) from an unusual location (outside of 'C:\Program Files')


    Read More
  • Remote AppX Package Downloaded from File Sharing or CDN Domain

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects an appx package that was added to the pipeline of the "to be processed" packages which was downloaded from a file sharing or CDN domain.


    Read More
  • Remote CHM File Download/Execution Via HH.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.001  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of "hh.exe" to execute/download remotely hosted ".chm" files.


    Read More
  • Remote Code Execute via Winrm.vbs

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects an attempt to execute code or create service on remote host via winrm.vbs.


    Read More
  • Remote File Download Via Findstr.EXE

    calendar Apr 28, 2026 · attack.credential-access attack.command-and-control attack.stealth attack.t1218 attack.t1564.004 attack.t1552.001 attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "findstr" with specific flags and a remote share path. This specific set of CLI flags would allow "findstr" to download the content of the file located on the remote share as described in the LOLBAS entry.


    Read More
  • Remote Registry Lateral Movement

    calendar Apr 28, 2026 · attack.lateral-movement attack.defense-impairment attack.t1112 attack.persistence  ·
    Share on: twitter facebook linkedin copy

    Detects remote RPC calls to modify the registry and possible execute code


    Read More
  • Remote Thread Creation By Uncommon Source Image

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon processes creating remote threads.


    Read More
  • Remote Thread Creation In Uncommon Target Image

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.003  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon target processes for remote thread creation


    Read More
  • Remote Thread Creation Ttdinject.exe Proxy

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects a remote thread creation of Ttdinject.exe used as proxy


    Read More
  • Remote Thread Creation Via PowerShell In Uncommon Target

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.011 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a remote thread from a Powershell process in an uncommon target process


    Read More
  • Remote XSL Execution Via Msxsl.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1220  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the "msxsl" binary with an "http" keyword in the command line. This might indicate a potential remote execution of XSL files.


    Read More
  • RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects calls to the AtomicTestHarnesses "Invoke-ATHRemoteFXvGPUDisablementCommand" which is designed to abuse the "RemoteFXvGPUDisablement.exe" binary to run custom PowerShell code via module load-order hijacking.


    Read More
  • Remotely Hosted HTA File Executed Via Mshta.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.005  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the "mshta" utility with an argument containing the "http" keyword, which could indicate that an attacker is executing a remotely hosted malicious hta file


    Read More
  • Removal Of AMSI Provider Registry Keys

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of AMSI provider registry key entries in HKLM\Software\Microsoft\AMSI. This technique could be used by an attacker in order to disable AMSI inspection.


    Read More
  • Removal Of Index Value to Hide Schedule Task - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when the "index" value of a scheduled task is removed or deleted from the registry. Which effectively hides it from any tooling such as "schtasks /query"


    Read More
  • Removal of Potential COM Hijacking Registry Keys

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects any deletion of entries in ".*\shell\open\command" registry keys. These registry keys might have been used for COM hijacking activities by a threat actor or an attacker and the deletion could indicate steps to remove its tracks.


    Read More
  • Removal Of SD Value to Hide Schedule Task - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Remove SD (Security Descriptor) value in \Schedule\TaskCache\Tree registry hive to hide schedule task. This technique is used by Tarrask malware


    Read More
  • Remove Exported Mailbox from Exchange Webserver

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects removal of an exported Exchange mailbox which could be to cover tracks from ProxyShell exploit


    Read More
  • Remove Immutable File Attribute

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222.002  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the 'chattr' utility to remove immutable file attribute.


    Read More
  • Remove Immutable File Attribute - Auditd

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222.002  ·
    Share on: twitter facebook linkedin copy

    Detects removing immutable file attribute.


    Read More
  • Remove Scheduled Cron Task/Job

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the 'crontab' utility to remove the current crontab. This is a common occurrence where cryptocurrency miners compete against each other by removing traces of other miners to hijack the maximum amount of resources possible


    Read More
  • Renamed AutoHotkey.EXE Execution

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of a renamed autohotkey.exe binary based on PE metadata fields


    Read More
  • Renamed AutoIt Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed AutoIt2.exe or AutoIt3.exe. AutoIt is a scripting language and automation tool for Windows systems. While primarily used for legitimate automation tasks, it can be misused in cyber attacks. Attackers can leverage AutoIt to create and distribute malware, including keyloggers, spyware, and botnets. A renamed AutoIt executable is particularly suspicious.


    Read More
  • Renamed BOINC Client Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed BOINC binary.


    Read More
  • Renamed BrowserCore.EXE Execution

    calendar Apr 28, 2026 · attack.credential-access attack.stealth attack.t1528 attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects process creation with a renamed BrowserCore.exe (used to extract Azure tokens)


    Read More
  • Renamed CreateDump Utility Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1003.001 attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects uses of a renamed legitimate createdump.exe LOLOBIN utility to dump process memory


    Read More
  • Renamed CURL.EXE Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed "CURL.exe" binary based on the PE metadata fields


    Read More
  • Renamed FTP.EXE Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed "ftp.exe" binary based on the PE metadata fields


    Read More
  • Renamed Jusched.EXE Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed "jusched.exe" as seen used by the cobalt group


    Read More
  • Renamed Mavinject.EXE Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.001 attack.t1218.013  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed version of the "Mavinject" process. Which can be abused to perform process injection using the "/INJECTRUNNING" flag


    Read More
  • Renamed MegaSync Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed MegaSync.exe as seen used by ransomware families like Nefilim, Sodinokibi, Pysa, and Conti.


    Read More
  • Renamed Microsoft Teams Execution

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed Microsoft Teams binary.


    Read More
  • Renamed Msdt.EXE Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed "Msdt.exe" binary


    Read More
  • Renamed NetSupport RAT Execution

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed "client32.exe" (NetSupport RAT) via Imphash, Product and OriginalFileName strings


    Read More
  • Renamed NirCmd.EXE Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed "NirCmd.exe" binary based on the PE metadata fields.


    Read More
  • Renamed Office Binary Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed office binary


    Read More
  • Renamed PAExec Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of renamed version of PAExec. Often used by attackers


    Read More
  • Renamed PingCastle Binary Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed "PingCastle" binary based on the PE metadata fields.


    Read More
  • Renamed Plink Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed version of the Plink binary


    Read More
  • Renamed Powershell Under Powershell Channel

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects a renamed Powershell execution, which is a common technique used to circumvent security controls and bypass detection logic that's dependent on process names and process paths.


    Read More
  • Renamed ProcDump Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a renamed ProcDump executable. This often done by attackers or malware in order to evade defensive mechanisms.


    Read More
  • Renamed Remote Utilities RAT (RURAT) Execution

    calendar Apr 28, 2026 · attack.collection attack.command-and-control attack.discovery attack.stealth attack.s0592  ·
    Share on: twitter facebook linkedin copy

    Detects execution of renamed Remote Utilities (RURAT) via Product PE header field


    Read More
  • Renamed Schtasks Execution

    calendar Apr 28, 2026 · attack.execution attack.persistence attack.privilege-escalation attack.stealth attack.t1036.003 attack.t1053.005  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of renamed schtasks.exe binary, which is a legitimate Windows utility used for scheduling tasks. One of the very common persistence techniques is schedule malicious tasks using schtasks.exe. Since, it is heavily abused, it is also heavily monitored by security products. To evade detection, threat actors may rename the schtasks.exe binary to schedule their malicious tasks.


    Read More
  • Renamed Vmnat.exe Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects renamed vmnat.exe or portable version that can be used for DLL side-loading


    Read More
  • Renamed ZOHO Dctask64 Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1036 attack.t1055.001 attack.t1202 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects a renamed "dctask64.exe" execution, a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central. This binary can be abused for DLL injection, arbitrary command and process execution.


    Read More
  • Response File Execution Via Odbcconf.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "odbcconf" with the "-f" flag in order to load a response file which might contain a malicious action.


    Read More
  • Restricted Software Access By SRP

    calendar Apr 28, 2026 · attack.lateral-movement attack.execution attack.t1072  ·
    Share on: twitter facebook linkedin copy

    Detects restricted access to applications by the Software Restriction Policies (SRP) policy


    Read More
  • RestrictedAdminMode Registry Value Tampering

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise


    Read More
  • RestrictedAdminMode Registry Value Tampering - ProcCreation

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the "DisableRestrictedAdmin" registry value in order to disable or enable RestrictedAdmin mode. RestrictedAdmin mode prevents the transmission of reusable credentials to the remote system to which you connect using Remote Desktop. This prevents your credentials from being harvested during the initial connection process if the remote server has been compromise


    Read More
  • Rhadamanthys Stealer Module Launch Via Rundll32.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Rundll32 to launch an NSIS module that serves as the main stealer capability of Rhadamanthys infostealer, as observed in reports and samples in early 2023


    Read More
  • Roles Activated Too Frequently

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Identifies when the same privilege role has multiple activations by the same user.


    Read More
  • Roles Activation Doesn't Require MFA

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Identifies when a privilege role can be activated without performing mfa.


    Read More
  • Roles Are Not Being Used

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Identifies when a user has been assigned a privilege role and are not using that role.


    Read More
  • Roles Assigned Outside PIM

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Identifies when a privilege role assignment has taken place outside of PIM and may indicate an attack.


    Read More
  • Root Account Enable Via Dsenableroot

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1078 attack.t1078.001 attack.t1078.003 attack.initial-access attack.persistence  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to enable the root account via "dsenableroot"


    Read More
  • Root Certificate Installed - PowerShell

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.


    Read More
  • Root Certificate Installed From Susp Locations

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.


    Read More
  • Rorschach Ransomware Execution Activity

    calendar Apr 28, 2026 · attack.execution attack.t1059.003 attack.t1059.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Rorschach ransomware execution activity


    Read More
  • Run Once Task Configuration in Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Rule to detect the configuration of Run Once registry key. Configured payload can be run by runonce.exe /AlternateShellStartup


    Read More
  • Run Once Task Execution as Configured in Registry

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    This rule detects the execution of Run Once task as configured in the registry


    Read More
  • Run PowerShell Script from ADS

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell script execution from Alternate Data Stream (ADS)


    Read More
  • Run PowerShell Script from Redirected Input Stream

    calendar Apr 28, 2026 · attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell script execution via input stream redirect


    Read More
  • Rundll32 Execution With Uncommon DLL Extension

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of rundll32 with a command line that doesn't contain a common extension


    Read More
  • Rundll32 Execution Without CommandLine Parameters

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious start of rundll32.exe without any parameters as found in CobaltStrike beacon activity


    Read More
  • Rundll32 InstallScreenSaver Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    An attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver


    Read More
  • Rundll32 Internet Connection

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects a rundll32 that communicates with public IP addresses


    Read More
  • Rundll32 Spawned Via Explorer.EXE

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "rundll32.exe" with a parent process of Explorer.exe. This has been observed by variants of Raspberry Robin, as first reported by Red Canary.


    Read More
  • RunDLL32 Spawning Explorer

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects RunDLL32.exe spawning explorer.exe as child, which is very uncommon, often observes Gamarue spawning the explorer.exe process in an unusual way


    Read More
  • Rundll32 UNC Path Execution

    calendar Apr 28, 2026 · attack.execution attack.lateral-movement attack.stealth attack.t1021.002 attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects rundll32 execution where the DLL is located on a remote location (share)


    Read More
  • RunMRU Registry Key Deletion

    calendar Apr 28, 2026 · attack.stealth attack.t1070.003  ·
    Share on: twitter facebook linkedin copy

    Detects deletion of the RunMRU registry key, which stores the history of commands executed via the Run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.


    Read More
  • RunMRU Registry Key Deletion - Registry

    calendar Apr 28, 2026 · attack.stealth attack.t1070.003  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to delete the RunMRU registry key, which stores the history of commands executed via the run dialog. In the clickfix techniques, the phishing lures instruct users to open a run dialog through (Win + R) and execute malicious commands. Adversaries may delete this key to cover their tracks after executing commands.


    Read More
  • SafeBoot Registry Key Deleted Via Reg.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "reg.exe" commands with the "delete" flag on safe boot registry keys. Often used by attacker to prevent safeboot execution of security products


    Read More
  • Scheduled Task Creation Masquerading as System Processes

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.stealth attack.t1053.005 attack.t1036.004 attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of scheduled tasks that involve system processes, which may indicate malicious actors masquerading as or abusing these processes to execute payloads or maintain persistence.


    Read More
  • Scheduled Task Creation with Curl and PowerShell Execution Combo

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.stealth attack.t1053.005 attack.t1218 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a scheduled task using schtasks.exe, potentially in combination with curl for downloading payloads and PowerShell for executing them. This facilitates executing malicious payloads or connecting with C&C server persistently without dropping the malware sample on the host.


    Read More
  • SCM Database Privileged Operation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects non-system users performing privileged operation os the SCM database


    Read More
  • SCR File Write Event

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of screensaver files (.scr) outside of system folders. Attackers may execute an application as an ".SCR" file using "rundll32.exe desk.cpl,InstallScreenSaver" for example.


    Read More
  • ScreenConnect - SlashAndGrab Exploitation Indicators

    calendar Apr 28, 2026 · detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects indicators of exploitation by threat actors during exploitation of the "SlashAndGrab" vulnerability related to ScreenConnect as reported Team Huntress


    Read More
  • ScreenConnect User Database Modification - Security

    calendar Apr 28, 2026 · cve.2024-1709 detection.emerging-threats attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    This detects file modifications to the temporary xml user database file indicating local user modification in the ScreenConnect server. This will occur during exploitation of the ScreenConnect Authentication Bypass vulnerability (CVE-2024-1709) in versions <23.9.8, but may also be observed when making legitimate modifications to local users or permissions. This requires an Advanced Auditing policy to log a successful Windows Event ID 4663 events and with a SACL set on the directory.


    Read More
  • ScreenSaver Registry Key Set

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects registry key established after masqueraded .scr file execution using Rundll32 through desk.cpl


    Read More
  • Scripted Diagnostics Turn Off Check Enabled - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects enabling TurnOffCheck which can be used to bypass defense of MSDT Follina vulnerability


    Read More
  • Scripting/CommandLine Process Spawned Regsvr32

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects various command line and scripting engines/processes such as "PowerShell", "Wscript", "Cmd", etc. spawning a "regsvr32" instance.


    Read More
  • Sdclt Child Processes

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    A General detection for sdclt spawning new processes. This could be an indicator of sdclt being used for bypass UAC techniques.


    Read More
  • Sdiagnhost Calling Suspicious Child Process

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects sdiagnhost.exe calling a suspicious child process (e.g. used in exploits for Follina / CVE-2022-30190)


    Read More
  • Security Event Logging Disabled via MiniNt Registry Key - Process

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685.001 attack.t1112 car.2022-03-001  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to disable security event logging by adding the MiniNt registry key. This key is used to disable the Windows Event Log service, which collects and stores event logs from the operating system and applications. Adversaries may want to disable this service to prevent logging of security events that could be used to detect their activities.


    Read More
  • Security Event Logging Disabled via MiniNt Registry Key - Registry Set

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1685.001 attack.t1112 car.2022-03-001  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of the 'MiniNt' key to the registry. Upon a reboot, Windows Event Log service will stop writing events. Windows Event Log is a service that collects and stores event logs from the operating system and applications. It is an important component of Windows security and auditing. Adversary may want to disable this service to disable logging of security events which could be used to detect their activities.


    Read More
  • Security Eventlog Cleared

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.005 car.2016-04-002  ·
    Share on: twitter facebook linkedin copy

    One of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution


    Read More
  • Security Service Disabled Via Reg.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "reg.exe" to disable security services such as Windows Defender.


    Read More
  • Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the use of iexpress.exe to create binaries via Self Extraction Directive (SED) files located in potentially suspicious locations. This behavior has been observed in-the-wild by different threat actors.


    Read More
  • Self Extraction Directive File Created In Potentially Suspicious Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of Self Extraction Directive files (.sed) in a potentially suspicious location. These files are used by the "iexpress.exe" utility in order to create self extracting packages. Attackers were seen abusing this utility and creating PE files with embedded ".sed" entries.


    Read More
  • Sensitive File Dump Via Print.EXE

    calendar Apr 28, 2026 · attack.credential-access attack.stealth attack.t1003.003 attack.t1003.002 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the abuse of the Print.exe utility for credential harvesting which involves using Print.Exe to copy sensitive files such as ntds.dit, SAM, SECURITY, or SYSTEM from the Windows directory in order to extract credentials, locally or remotely.


    Read More
  • Server Side Template Injection Strings

    calendar Apr 28, 2026 · attack.stealth attack.t1221  ·
    Share on: twitter facebook linkedin copy

    Detects SSTI attempts sent via GET requests in access logs


    Read More
  • Service Binary in Suspicious Folder

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect the creation of a service with a service binary located in a suspicious directory


    Read More
  • Service DACL Abuse To Hide Services Via Sc.EXE

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "sc.exe" utility adding a new service with special permission seen used by threat actors which makes the service hidden and unremovable.


    Read More
  • Service Registry Key Deleted Via Reg.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "reg.exe" commands with the "delete" flag on services registry key. Often used by attacker to remove AV software services


    Read More
  • Service Registry Key Read Access Request

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detects "read access" requests on the services registry key. Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for Registry keys related to services to redirect from the originally specified executable to one that they control, in order to launch their own code when a service starts.


    Read More
  • Service Registry Permissions Weakness Check

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.011 stp.2a  ·
    Share on: twitter facebook linkedin copy

    Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, in order to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services


    Read More
  • Service Security Descriptor Tampering Via Sc.EXE

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detection of sc.exe utility adding a new service with special permission which hides that service.


    Read More
  • Service Startup Type Change Via Wmic.EXE

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1047 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to service startup type to 'disabled' or 'manual' using the WMIC command-line utility.


    Read More
  • Service StartupType Change Via PowerShell Set-Service

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the PowerShell "Set-Service" cmdlet to change the startup type of a service to "disabled" or "manual"


    Read More
  • Service StartupType Change Via Sc.EXE

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detect the use of "sc.exe" to change the startup type of a service to "disabled" or "demand"


    Read More
  • SES Identity Has Been Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects an instance of an SES identity being deleted via the "DeleteIdentity" event. This may be an indicator of an adversary removing the account that carried out suspicious or malicious activities


    Read More
  • Set Suspicious Files as System Files Using Attrib.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1564.001  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of attrib with the "+s" option to set scripts or executables located in suspicious locations as system files to hide them from users and make them unable to be deleted with simple rights. The rule limits the search to specific extensions and directories to avoid FPs


    Read More
  • Setuid and Setgid

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.t1548.001  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious change of file privileges with chown and chmod commands


    Read More
  • Setup16.EXE Execution With Custom .Lst File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.005  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "Setup16.EXE" and old installation utility with a custom ".lst" file. These ".lst" file can contain references to external program that "Setup16.EXE" will execute. Attackers and adversaries might leverage this as a living of the land utility.


    Read More
  • Shell Open Registry Keys Manipulation

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.t1548.002 attack.t1546.001  ·
    Share on: twitter facebook linkedin copy

    Detects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)


    Read More
  • Shell32 DLL Execution in Suspicious Directory

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects shell32.dll executing a DLL in a suspicious directory


    Read More
  • ShimCache Flush

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects actions that clear the local ShimCache and remove forensic evidence


    Read More
  • Sign-in Failure Due to Conditional Access Requirements Not Met

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1110 attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Define a baseline threshold for failed sign-ins due to Conditional Access failures


    Read More
  • Sign-ins by Unknown Devices

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert for Sign-ins by unknown devices from non-Trusted locations.


    Read More
  • Sign-ins from Non-Compliant Devices

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert for sign-ins where the device was non-compliant.


    Read More
  • Silenttrinity Stager Msbuild Activity

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127.001  ·
    Share on: twitter facebook linkedin copy

    Detects a possible remote connections to Silenttrinity c2


    Read More
  • Small Sieve Malware CommandLine Indicator

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects specific command line argument being passed to a binary as seen being used by the malware Small Sieve.


    Read More
  • Small Sieve Malware File Indicator Creation

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects filename indicators that contain a specific typo seen used by the Small Sieve malware.


    Read More
  • Sofacy Trojan Loader Activity

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.g0007 attack.t1059.003 attack.t1218.011 car.2013-10-002 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects Trojan loader activity as used by APT28


    Read More
  • Space After Filename - macOS

    calendar Apr 28, 2026 · attack.stealth attack.t1036.006  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to masquerade as legitimate files by adding a space to the end of the filename.


    Read More
  • SQL Client Tools PowerShell Session Detection

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1127  ·
    Share on: twitter facebook linkedin copy

    This rule detects execution of a PowerShell code through the sqltoolsps.exe utility, which is included in the standard set of utilities supplied with the Microsoft SQL Server Management studio. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.


    Read More
  • Stale Accounts In A Privileged Role

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Identifies when an account hasn't signed in during the past n number of days.


    Read More
  • Start of NT Virtual DOS Machine

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Ntvdm.exe allows the execution of 16-bit Windows applications on 32-bit Windows operating systems, as well as the execution of both 16-bit and 32-bit DOS applications


    Read More
  • Startup/Logon Script Added to Group Policy Object

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1484.001 attack.t1547  ·
    Share on: twitter facebook linkedin copy

    Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.


    Read More
  • Steganography Extract Files with Steghide

    calendar Apr 28, 2026 · attack.stealth attack.t1027.003  ·
    Share on: twitter facebook linkedin copy

    Detects extraction of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.


    Read More
  • Steganography Hide Files with Steghide

    calendar Apr 28, 2026 · attack.stealth attack.t1027.003  ·
    Share on: twitter facebook linkedin copy

    Detects embedding of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.


    Read More
  • Steganography Hide Zip Information in Picture File

    calendar Apr 28, 2026 · attack.stealth attack.t1027.003  ·
    Share on: twitter facebook linkedin copy

    Detects appending of zip file to image


    Read More
  • Steganography Unzip Hidden Information From Picture File

    calendar Apr 28, 2026 · attack.stealth attack.t1027.003  ·
    Share on: twitter facebook linkedin copy

    Detects extracting of zip file from image file


    Read More
  • Successful Authentications From Countries You Do Not Operate Out Of

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1078.004 attack.t1110  ·
    Share on: twitter facebook linkedin copy

    Detect successful authentications from countries you do not operate out of.


    Read More
  • Successful Overpass the Hash Attempt

    calendar Apr 28, 2026 · attack.lateral-movement attack.s0002 attack.t1550.002  ·
    Share on: twitter facebook linkedin copy

    Detects successful logon with logon type 9 (NewCredentials) which matches the Overpass the Hash behavior of e.g Mimikatz's sekurlsa::pth module.


    Read More
  • Sudo Privilege Escalation CVE-2019-14287

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1068 attack.t1548.003 cve.2019-14287 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287


    Read More
  • Sudo Privilege Escalation CVE-2019-14287 - Builtin

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1068 attack.t1548.003 cve.2019-14287 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects users trying to exploit sudo vulnerability reported in CVE-2019-14287


    Read More
  • Suspect Svchost Activity

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    It is extremely abnormal for svchost.exe to spawn without any CLI arguments and is normally observed when a malicious process spawns the process and injects code into the process memory space.


    Read More
  • Suspicious Advpack Call Via Rundll32.EXE

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "rundll32" calling "advpack.dll" with potential obfuscated ordinal calls in order to leverage the "RegisterOCX" function


    Read More
  • Suspicious AgentExecutor PowerShell Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the AgentExecutor.exe binary. Which can be abused as a LOLBIN to execute powershell scripts with the ExecutionPolicy "Bypass" or any binary named "powershell.exe" located in the path provided by 6th positional argument


    Read More
  • Suspicious Application Allowed Through Exploit Guard

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects applications being added to the "allowed applications" list of exploit guard in order to bypass controlled folder settings


    Read More
  • Suspicious BitLocker Access Agent Update Utility Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.lateral-movement attack.t1021.003  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of the BitLocker Access Agent Update Utility (baaupdate.exe) which is not a common parent process for other processes. Suspicious child processes spawned by baaupdate.exe could indicate an attempt at lateral movement via BitLocker DCOM & COM Hijacking.


    Read More
  • Suspicious Browser Activity

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Indicates anomalous behavior based on suspicious sign-in activity across multiple tenants from different countries in the same browser


    Read More
  • Suspicious Cabinet File Execution Via Msdt.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190


    Read More
  • Suspicious Calculator Usage

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious use of 'calc.exe' with command line parameters or in a suspicious directory, which is likely caused by some PoC or detection evasion.


    Read More
  • Suspicious Child Process Created as System

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1134.002  ·
    Share on: twitter facebook linkedin copy

    Detection of child processes spawned with SYSTEM privileges by parents with LOCAL SERVICE or NETWORK SERVICE accounts


    Read More
  • Suspicious Child Process of AspNetCompiler

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious child processes of "aspnet_compiler.exe".


    Read More
  • Suspicious Child Process Of BgInfo.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.005 attack.t1218 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript


    Read More
  • Suspicious Child Process Of Wermgr.EXE

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055 attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious Windows Error Reporting manager (wermgr.exe) child process


    Read More
  • Suspicious CodePage Switch Via CHCP

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects a code page switch in command line or batch scripts to a rare language


    Read More
  • Suspicious Computer Account Name Change CVE-2021-42287

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.stealth attack.t1036 attack.t1098 cve.2021-42287 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the renaming of an existing computer account to a account name that doesn't contain a $ symbol as seen in attacks against CVE-2021-42287


    Read More
  • Suspicious Computer Machine Password by PowerShell

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain. You can use it to reset the password of the local computer.


    Read More
  • Suspicious Control Panel DLL Load

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious Rundll32 execution from control.exe as used by Equation Group and Exploit Kits


    Read More
  • Suspicious Copy From or To System Directory

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious copy operation that tries to copy a program from system (System32, SysWOW64, WinSxS) directories to another on disk. Often used to move LOLBINs such as 'certutil' or 'desktopimgdownldr' to a different location with a different name in order to bypass detections based on locations.


    Read More
  • Suspicious Creation with Colorcpl

    calendar Apr 28, 2026 · attack.stealth attack.t1564  ·
    Share on: twitter facebook linkedin copy

    Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\


    Read More
  • Suspicious Csi.exe Usage

    calendar Apr 28, 2026 · attack.lateral-movement attack.execution attack.stealth attack.t1072 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Csi.exe is a signed binary from Microsoft that comes with Visual Studio and provides C# interactive capabilities. It can be used to run C# code from a file passed as a parameter in command line. Early version of this utility provided with Microsoft “Roslyn” Community Technology Preview was named 'rcsi.exe'


    Read More
  • Suspicious CustomShellHost Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of CustomShellHost.exe where the child isn't located in 'C:\Windows\explorer.exe'. CustomShellHost is a known LOLBin that can be abused by attackers for defense evasion techniques.


    Read More
  • Suspicious Diantz Alternate Data Stream Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Compress target file into a cab file stored in the Alternate Data Stream (ADS) of the target file.


    Read More
  • Suspicious Digital Signature Of AppX Package

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of AppX packages with known suspicious or malicious signature


    Read More
  • Suspicious DLL Loaded via CertOC.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects when a user installs certificates by using CertOC.exe to load the target DLL file.


    Read More
  • Suspicious DotNET CLR Usage Log Artifact

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of Usage Log files by the CLR (clr.dll). These files are named after the executing process once the assembly is finished executing for the first time in the (user) session context.


    Read More
  • Suspicious Double Extension Files

    calendar Apr 28, 2026 · attack.stealth attack.t1036.007  ·
    Share on: twitter facebook linkedin copy

    Detects dropped files with double extensions, which is often used by malware as a method to abuse the fact that Windows hide default extensions by default.


    Read More
  • Suspicious Download From Direct IP Via Bitsadmin

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197 attack.s0190 attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Detects usage of bitsadmin downloading a file using an URL that contains an IP


    Read More
  • Suspicious Download From File-Sharing Website Via Bitsadmin

    calendar Apr 28, 2026 · attack.persistence attack.execution attack.stealth attack.t1197 attack.s0190 attack.t1036.003 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects usage of bitsadmin downloading a file from a suspicious domain


    Read More
  • Suspicious Download Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of certutil with certain flags that allow the utility to download files.


    Read More
  • Suspicious Driver/DLL Installation Via Odbcconf.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "odbcconf" with the "INSTALLDRIVER" action where the driver doesn't contain a ".dll" extension. This is often used as a defense evasion method.


    Read More
  • Suspicious DumpMinitool Execution

    calendar Apr 28, 2026 · attack.credential-access attack.stealth attack.t1036 attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious ways to use the "DumpMinitool.exe" binary


    Read More
  • Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious base64 encoded and obfuscated "LOAD" keyword used in .NET "reflection.assembly"


    Read More
  • Suspicious Environment Variable Has Been Registered

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of user-specific or system-wide environment variables via the registry. Which contains suspicious commands and strings


    Read More
  • Suspicious Eventlog Clear

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.005  ·
    Share on: twitter facebook linkedin copy

    Detects usage of known powershell cmdlets such as "Clear-EventLog" to clear the Windows event logs


    Read More
  • Suspicious Eventlog Clearing or Configuration Change Activity

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.005 attack.t1685.001 car.2016-04-002  ·
    Share on: twitter facebook linkedin copy

    Detects the clearing or configuration tampering of EventLog using utilities such as "wevtutil", "powershell" and "wmic". This technique were seen used by threat actors and ransomware strains in order to evade defenses.


    Read More
  • Suspicious Executable File Creation

    calendar Apr 28, 2026 · attack.stealth attack.t1564  ·
    Share on: twitter facebook linkedin copy

    Detect creation of suspicious executable file names. Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.


    Read More
  • Suspicious Execution of InstallUtil Without Log

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Uses the .NET InstallUtil.exe application in order to execute image without log


    Read More
  • Suspicious Execution via macOS Script Editor

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1566 attack.t1566.002 attack.initial-access attack.t1059 attack.t1059.002 attack.t1204 attack.t1204.001 attack.execution attack.persistence attack.t1553  ·
    Share on: twitter facebook linkedin copy

    Detects when the macOS Script Editor utility spawns an unusual child process.


    Read More
  • Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1204.004 attack.t1027.010  ·
    Share on: twitter facebook linkedin copy

    Detects process creation with suspicious whitespace padding followed by a '#' character, which may indicate ClickFix or FileFix techniques used to conceal malicious commands from visual inspection. ClickFix and FileFix are social engineering attack techniques where adversaries distribute phishing documents or malicious links that deceive users into opening the Windows Run dialog box or File Explorer search bar. The victims are then instructed to paste commands from their clipboard, which contain extensive whitespace padding using various Unicode space characters to push the actual malicious command far to the right, effectively hiding it from immediate view.


    Read More
  • Suspicious Extrac32 Alternate Data Stream Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Extract data from cab file and hide it in an alternate data stream


    Read More
  • Suspicious File Created by ArcSOC.exe

    calendar Apr 28, 2026 · attack.command-and-control attack.persistence attack.initial-access attack.execution attack.stealth attack.t1127 attack.t1105 attack.t1133  ·
    Share on: twitter facebook linkedin copy

    Detects instances where the ArcGIS Server process ArcSOC.exe, which hosts REST services running on an ArcGIS server, creates a file with suspicious file type, indicating that it may be an executable, script file, or otherwise unusual.


    Read More
  • Suspicious File Created Via OneNote Application

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious files created via the OneNote application. This could indicate a potential malicious ".one"/".onepkg" file was executed as seen being used in malware activity in the wild


    Read More
  • Suspicious File Creation Activity From Fake Recycle.Bin Folder

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects file write event from/to a fake recycle bin folder that is often used as a staging directory for malware


    Read More
  • Suspicious File Creation In Uncommon AppData Folder

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of suspicious files and folders inside the user's AppData folder but not inside any of the common and well known directories (Local, Romaing, LocalLow). This method could be used as a method to bypass detection who exclude the AppData folder in fear of FPs


    Read More
  • Suspicious File Download From File Sharing Websites - File Stream

    calendar Apr 28, 2026 · attack.stealth attack.s0139 attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects the download of suspicious file type from a well-known file and paste sharing domain


    Read More
  • Suspicious File Downloaded From Direct IP Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of certutil with certain flags that allow the utility to download files from direct IPs.


    Read More
  • Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027 attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of certutil with certain flags that allow the utility to download files from file-sharing websites.


    Read More
  • Suspicious File Encoded To Base64 Via Certutil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of certutil with the "encode" flag to encode a file to base64 where the extensions of the file is suspicious


    Read More
  • Suspicious Filename with Embedded Base64 Commands

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.004 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects files with specially crafted filenames that embed Base64-encoded bash payloads designed to execute when processed by shell scripts. These filenames exploit shell interpretation quirks to trigger hidden commands, a technique observed in VShell malware campaigns.


    Read More
  • Suspicious Files in Default GPO Folder

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder


    Read More
  • Suspicious Get-Variable.exe Creation

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.stealth attack.t1546 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Get-Variable is a valid PowerShell cmdlet WindowsApps is by default in the path where PowerShell is executed. So when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.


    Read More
  • Suspicious GUP Usage

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Notepad++ updater in a suspicious directory, which is often used in DLL side-loading attacks


    Read More
  • Suspicious HH.EXE Execution

    calendar Apr 28, 2026 · attack.execution attack.initial-access attack.stealth attack.t1047 attack.t1059.001 attack.t1059.003 attack.t1059.005 attack.t1059.007 attack.t1218 attack.t1218.001 attack.t1218.010 attack.t1218.011 attack.t1566 attack.t1566.001  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious execution of a Microsoft HTML Help (HH.exe)


    Read More
  • Suspicious High IntegrityLevel Conhost Legacy Option

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    ForceV1 asks for information directly from the kernel space. Conhost connects to the console application. High IntegrityLevel means the process is running with elevated privileges, such as an Administrator context.


    Read More
  • Suspicious Hyper-V Cmdlets

    calendar Apr 28, 2026 · attack.stealth attack.t1564.006  ·
    Share on: twitter facebook linkedin copy

    Adversaries may carry out malicious operations using a virtual instance to avoid detection


    Read More
  • Suspicious IIS URL GlobalRules Rewrite Via AppCmd

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "appcmd" to create new global URL rewrite rules. This behaviour has been observed being used by threat actors to add new rules so they can access their webshells.


    Read More
  • Suspicious Inbox Manipulation Rules

    calendar Apr 28, 2026 · attack.stealth attack.t1140  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious rules that delete or move messages or folders are set on a user's inbox.


    Read More
  • Suspicious Invoke-Item From Mount-DiskImage

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.005  ·
    Share on: twitter facebook linkedin copy

    Adversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.


    Read More
  • Suspicious IO.FileStream

    calendar Apr 28, 2026 · attack.stealth attack.t1070.003  ·
    Share on: twitter facebook linkedin copy

    Open a handle on the drive volume via the \.\ DOS device path specifier and perform direct access read of the first few bytes of the volume.


    Read More
  • Suspicious JavaScript Execution Via Mshta.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.005  ·
    Share on: twitter facebook linkedin copy

    Detects execution of javascript code using "mshta.exe".


    Read More
  • Suspicious LNK Double Extension File Created

    calendar Apr 28, 2026 · attack.stealth attack.t1036.007  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of files with an "LNK" as a second extension. This is sometimes used by malware as a method to abuse the fact that Windows hides the "LNK" extension by default.


    Read More
  • Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location

    calendar Apr 28, 2026 · attack.credential-access attack.defense-impairment attack.t1003 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects loading of dbgcore.dll or dbghelp.dll from uncommon locations such as user directories. These DLLs contain the MiniDumpWriteDump function, which can be abused for credential dumping purposes or in some cases for evading EDR/AV detection by suspending processes.


    Read More
  • Suspicious Login Activity Classified By Google

    calendar Apr 28, 2026 · attack.initial-access attack.privilege-escalation attack.persistence attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects Google Workspace login activity that's classified as suspicious by Google.


    Read More
  • Suspicious Microsoft Office Child Process

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1047 attack.t1204.002 attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)


    Read More
  • Suspicious Mount-DiskImage

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.005  ·
    Share on: twitter facebook linkedin copy

    Adversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.


    Read More
  • Suspicious Msbuild Execution By Uncommon Parent Process

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious execution of 'Msbuild.exe' by a uncommon parent process


    Read More
  • Suspicious MSDT Parent Process

    calendar Apr 28, 2026 · attack.stealth attack.t1036 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation


    Read More
  • Suspicious MSHTA Child Process

    calendar Apr 28, 2026 · attack.stealth attack.t1218.005 car.2013-02-003 car.2013-03-001 car.2014-04-003  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious process spawning from an "mshta.exe" process, which could be indicative of a malicious HTA script execution


    Read More
  • Suspicious MsiExec Embedding Parent

    calendar Apr 28, 2026 · attack.stealth attack.t1218.007  ·
    Share on: twitter facebook linkedin copy

    Adversaries may abuse msiexec.exe to proxy the execution of malicious payloads


    Read More
  • Suspicious Msiexec Execute Arbitrary DLL

    calendar Apr 28, 2026 · attack.stealth attack.t1218.007  ·
    Share on: twitter facebook linkedin copy

    Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is thus commonly associated with executing installation packages (.msi)


    Read More
  • Suspicious Msiexec Quiet Install From Remote Location

    calendar Apr 28, 2026 · attack.stealth attack.t1218.007  ·
    Share on: twitter facebook linkedin copy

    Detects usage of Msiexec.exe to install packages hosted remotely quietly


    Read More
  • Suspicious Network Connection Binary No CommandLine

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious network connections made by a well-known Windows binary run with no command line parameters


    Read More
  • Suspicious Obfuscated PowerShell Code

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious UTF16 and base64 encoded and often obfuscated PowerShell code often used in command lines


    Read More
  • Suspicious Package Installed - Linux

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Detects installation of suspicious packages using system installation utilities


    Read More
  • Suspicious Parent Double Extension File Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1036.007  ·
    Share on: twitter facebook linkedin copy

    Detect execution of suspicious double extension files in ParentCommandLine


    Read More
  • Suspicious Path In Keyboard Layout IME File Registry Value

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message. Before doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named "Ime File" with a DLL path. IMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.


    Read More
  • Suspicious Ping/Del Command Combination

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects a method often used by ransomware. Which combines the "ping" to wait a couple of seconds and then "del" to delete the file in question. Its used to hide the file responsible for the initial infection for example


    Read More
  • Suspicious Powercfg Execution To Change Lock Screen Timeout

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious execution of 'Powercfg.exe' to change lock screen timeout


    Read More
  • Suspicious PowerShell Invocations - Specific - ProcessCreation

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious PowerShell invocation command parameters


    Read More
  • Suspicious PowerShell WindowStyle Option

    calendar Apr 28, 2026 · attack.stealth attack.t1564.003  ·
    Share on: twitter facebook linkedin copy

    Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden


    Read More
  • Suspicious Printer Driver Empty Manufacturer

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574 cve.2021-1675  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious printer driver installation with an empty Manufacturer value


    Read More
  • Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.


    Read More
  • Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs

    calendar Apr 28, 2026 · attack.credential-access attack.defense-impairment attack.t1003.001 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace. These DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll, dbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.


    Read More
  • Suspicious Process Execution From Fake Recycle.Bin Folder

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects process execution from a fake recycle bin folder, often used to avoid security solution.


    Read More
  • Suspicious Process Masquerading As SvcHost.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious process that is masquerading as the legitimate "svchost.exe" by naming its binary "svchost.exe" and executing from an uncommon location. Adversaries often disguise their malicious binaries by naming them after legitimate system processes like "svchost.exe" to evade detection.


    Read More
  • Suspicious Process Parents

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious parent processes that should not have any children or should only have a single possible child program


    Read More
  • Suspicious Process Start Locations

    calendar Apr 28, 2026 · attack.stealth attack.t1036 car.2013-05-002  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious process run from unusual locations


    Read More
  • Suspicious PROCEXP152.sys File Created In TMP

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of the PROCEXP152.sys file in the application-data local temporary folder. This driver is used by Sysinternals Process Explorer but also by KDU (https://github.com/hfiref0x/KDU) or Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU.


    Read More
  • Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects Netsh command execution that whitelists a program located in a suspicious location in the Windows Firewall


    Read More
  • Suspicious Provlaunch.EXE Child Process

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.


    Read More
  • Suspicious RASdial Activity

    calendar Apr 28, 2026 · attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious process related to rasdial.exe


    Read More
  • Suspicious RazerInstaller Explorer Subprocess

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1553 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects a explorer.exe sub process of the RazerInstaller software which can be invoked from the installer to select a different installation folder but can also be exploited to escalate privileges to LOCAL SYSTEM


    Read More
  • Suspicious Recursive Takeown

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1222.001  ·
    Share on: twitter facebook linkedin copy

    Adversaries can interact with the DACLs using built-in Windows commands takeown which can grant adversaries higher permissions on specific files and folders


    Read More
  • Suspicious Registry Modification From ADS Via Regini.EXE

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the import of an alternate data stream with regini.exe, regini.exe can be used to modify registry keys.


    Read More
  • Suspicious Regsvr32 Execution From Remote Share

    calendar Apr 28, 2026 · attack.stealth attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects REGSVR32.exe to execute DLL hosted on remote shares


    Read More
  • Suspicious Remote Child Process From Outlook

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious child process spawning from Outlook where the image is located in a remote location (SMB/WebDav shares).


    Read More
  • Suspicious Remote Logon with Explicit Credentials

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078 attack.lateral-movement  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious processes logging on with explicit credentials


    Read More
  • Suspicious Renamed Comsvcs DLL Loaded By Rundll32

    calendar Apr 28, 2026 · attack.credential-access attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects rundll32 loading a renamed comsvcs.dll to dump process memory


    Read More
  • Suspicious Response File Execution Via Odbcconf.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "odbcconf" with the "-f" flag in order to load a response file with a non-".rsp" extension.


    Read More
  • Suspicious Rundll32 Activity Invoking Sys File

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious process related to rundll32 based on command line that includes a *.sys file as seen being used by UNC2452


    Read More
  • Suspicious Rundll32 Execution With Image Extension

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of Rundll32.exe with DLL files masquerading as image files


    Read More
  • Suspicious Rundll32 Invoking Inline VBScript

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious process related to rundll32 based on command line that invokes inline VBScript as seen being used by UNC2452


    Read More
  • Suspicious Rundll32 Setupapi.dll Activity

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    setupapi.dll library provide InstallHinfSection function for processing INF files. INF file may contain instructions allowing to create values in the registry, modify files and install drivers. This technique could be used to obtain persistence via modifying one of Run or RunOnce registry keys, run process or use other DLLs chain calls (see references) InstallHinfSection function in setupapi.dll calls runonce.exe executable regardless of actual content of INF file.


    Read More
  • Suspicious Runscripthelper.exe

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of powershell scripts via Runscripthelper.exe


    Read More
  • Suspicious Scheduled Task Creation via Masqueraded XML File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.stealth attack.t1036.005 attack.t1053.005  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a scheduled task using the "-XML" flag with a file without the '.xml' extension. This behavior could be indicative of potential defense evasion attempt during persistence


    Read More
  • Suspicious Service Binary Directory

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects a service binary running in a suspicious directory


    Read More
  • Suspicious Service DACL Modification Via Set-Service Cmdlet - PS

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.011  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)


    Read More
  • Suspicious Service Installed

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders. Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)


    Read More
  • Suspicious Set Value of MSDT in Registry (CVE-2022-30190)

    calendar Apr 28, 2026 · attack.stealth attack.t1221 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects set value ms-msdt MSProtocol URI scheme in Registry that could be an attempt to exploit CVE-2022-30190.


    Read More
  • Suspicious Shell Open Command Registry Modification

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1548.002 attack.t1546.001  ·
    Share on: twitter facebook linkedin copy

    Detects modifications to shell open registry keys that point to suspicious locations typically used by malware for persistence. Generally, modifications to the *\shell\open\command registry key can indicate an attempt to change the default action for opening files, and various UAC bypass or persistence techniques involve modifying these keys to execute malicious scripts or binaries.


    Read More
  • Suspicious ShellExec_RunDLL Call Via Ordinal

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious call to the "ShellExec_RunDLL" exported function of SHELL32.DLL through the ordinal number to launch other commands. Adversary might only use the ordinal number in order to bypass existing detection that alert on usage of ShellExec_RunDLL on CommandLine.


    Read More
  • Suspicious SignIns From A Non Registered Device

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects risky authentication from a non AD registered device without MFA being required.


    Read More
  • Suspicious Space Characters in RunMRU Registry Path - ClickFix

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1204.004 attack.t1027.010  ·
    Share on: twitter facebook linkedin copy

    Detects the occurrence of numerous space characters in RunMRU registry paths, which may indicate execution via phishing lures using clickfix techniques to hide malicious commands in the Windows Run dialog box from naked eyes.


    Read More
  • Suspicious Space Characters in TypedPaths Registry Path - FileFix

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1204.004 attack.t1027.010  ·
    Share on: twitter facebook linkedin copy

    Detects the occurrence of numerous space characters in TypedPaths registry paths, which may indicate execution via phishing lures using file-fix techniques to hide malicious commands.


    Read More
  • Suspicious Speech Runtime Binary Child Process

    calendar Apr 28, 2026 · attack.lateral-movement attack.stealth attack.t1021.003 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious Speech Runtime Binary Execution by monitoring its child processes. Child processes spawned by SpeechRuntime.exe could indicate an attempt for lateral movement via COM & DCOM hijacking.


    Read More
  • Suspicious Splwow64 Without Params

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious Splwow64.exe process without any command line parameters


    Read More
  • Suspicious Start-Process PassThru

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003  ·
    Share on: twitter facebook linkedin copy

    Powershell use PassThru option to start in background


    Read More
  • Suspicious Svchost Process Access

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious access to the "svchost" process such as that used by Invoke-Phantom to kill the thread of the Windows event logging service.


    Read More
  • Suspicious SYSTEM User Process Creation

    calendar Apr 28, 2026 · attack.credential-access attack.privilege-escalation attack.stealth attack.t1134 attack.t1003 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious process creation as SYSTEM user (suspicious program or command line parameter)


    Read More
  • Suspicious Unblock-File

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.005  ·
    Share on: twitter facebook linkedin copy

    Remove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.


    Read More
  • Suspicious Uninstall of Windows Defender Feature via PowerShell

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the use of PowerShell with Uninstall-WindowsFeature or Remove-WindowsFeature cmdlets to disable or remove the Windows Defender GUI feature, a common technique used by adversaries to evade defenses.


    Read More
  • Suspicious Unsigned Thor Scanner Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects loading and execution of an unsigned thor scanner binary.


    Read More
  • Suspicious Usage of For Loop with Recursive Directory Search in CMD

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.003 attack.t1027.010  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious usage of the cmd.exe 'for /f' loop combined with the 'tokens=' parameter and a recursive directory listing. This pattern may indicate an attempt to discover and execute system binaries dynamically, for example powershell, a technique sometimes used by attackers to evade detection. This behavior has been observed in various malicious lnk files.


    Read More
  • Suspicious Usage Of ShellExec_RunDLL

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious usage of the ShellExec_RunDLL function to launch other commands as seen in the the raspberry-robin attack


    Read More
  • Suspicious Use of CSharp Interactive Console

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of CSharp interactive console by PowerShell


    Read More
  • Suspicious Userinit Child Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious child process of userinit


    Read More
  • Suspicious VBoxDrvInst.exe Parameters

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detect VBoxDrvInst.exe run with parameters allowing processing INF file. This allows to create values in the registry and install drivers. For example one could use this technique to obtain persistence via modifying one of Run or RunOnce registry keys


    Read More
  • Suspicious Velociraptor Child Process

    calendar Apr 28, 2026 · attack.command-and-control attack.persistence attack.t1219  ·
    Share on: twitter facebook linkedin copy

    Detects the suspicious use of the Velociraptor DFIR tool to execute other tools or download additional payloads, as seen in a campaign where it was abused for remote access and to stage further attacks.


    Read More
  • Suspicious Volume Shadow Copy VSS_PS.dll Load

    calendar Apr 28, 2026 · attack.impact attack.t1490  ·
    Share on: twitter facebook linkedin copy

    Detects the image load of vss_ps.dll by uncommon executables. This DLL is used by the Volume Shadow Copy Service (VSS) to manage shadow copies of files and volumes. It is often abused by attackers to delete or manipulate shadow copies, which can hinder forensic investigations and data recovery efforts. The fact that it is loaded by processes that are not typically associated with VSS operations can indicate suspicious activity.


    Read More
  • Suspicious Volume Shadow Copy Vssapi.dll Load

    calendar Apr 28, 2026 · attack.impact attack.t1490  ·
    Share on: twitter facebook linkedin copy

    Detects the image load of VSS DLL by uncommon executables


    Read More
  • Suspicious Vsls-Agent Command With AgentExtensionPath Load

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects Microsoft Visual Studio vsls-agent.exe lolbin execution with a suspicious library load using the --agentExtensionPath parameter


    Read More
  • Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of "reg.exe" to add Defender folder exclusions. Qbot has been seen using this technique to add exclusions for folders within AppData and ProgramData.


    Read More
  • Suspicious Windows Defender Registry Key Tampering Via Reg.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of "reg.exe" to tamper with different Windows Defender registry keys in order to disable some important features related to protection and detection


    Read More
  • Suspicious Windows Service Tampering

    calendar Apr 28, 2026 · attack.impact attack.defense-impairment attack.t1489 attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of binaries such as 'net', 'sc' or 'powershell' in order to stop, pause, disable or delete critical or important Windows services such as AV, Backup, etc. As seen being used in some ransomware scripts


    Read More
  • Suspicious Windows Trace ETW Session Tamper Via Logman.EXE

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685 attack.t1685.005  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "logman" utility in order to disable or delete Windows trace sessions


    Read More
  • Suspicious Windows Update Agent Empty Cmdline

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious Windows Update Agent activity in which a wuauclt.exe process command line doesn't contain any command line flags


    Read More
  • Suspicious WMIC Execution Via Office Process

    calendar Apr 28, 2026 · attack.stealth attack.t1204.002 attack.t1047 attack.t1218.010 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Office application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).


    Read More
  • Suspicious WmiPrvSE Child Process

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1047 attack.t1204.002 attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious and uncommon child processes of WmiPrvSE


    Read More
  • Suspicious Wordpad Outbound Connections

    calendar Apr 28, 2026 · attack.command-and-control attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects a network connection initiated by "wordpad.exe" over uncommon destination ports. This might indicate potential process injection activity from a beacon or similar mechanisms.


    Read More
  • Suspicious Workstation Locking via Rundll32

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects a suspicious call to the user32.dll function that locks the user workstation


    Read More
  • Suspicious X509Enrollment - Process Creation

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Detect use of X509Enrollment


    Read More
  • Suspicious X509Enrollment - Ps Script

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1553.004  ·
    Share on: twitter facebook linkedin copy

    Detect use of X509Enrollment


    Read More
  • Suspicious XOR Encoded PowerShell Command

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.001 attack.t1140 attack.t1027  ·
    Share on: twitter facebook linkedin copy

    Detects presence of a potentially xor encoded powershell command


    Read More
  • Suspicious ZipExec Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    ZipExec is a Proof-of-Concept (POC) tool to wrap binary-based tools into a password-protected zip file.


    Read More
  • SyncAppvPublishingServer Bypass Powershell Restriction - PS Module

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.


    Read More
  • SyncAppvPublishingServer Execute Arbitrary PowerShell Code

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Executes arbitrary PowerShell code using SyncAppvPublishingServer.exe.


    Read More
  • SyncAppvPublishingServer Execution to Bypass Powershell Restriction

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects SyncAppvPublishingServer process execution which usually utilized by adversaries to bypass PowerShell execution restrictions.


    Read More
  • SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Executes arbitrary PowerShell code using SyncAppvPublishingServer.vbs


    Read More
  • Sysinternals PsSuspend Suspicious Execution

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses


    Read More
  • Sysinternals Tools AppX Versions Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Sysinternals tools via an AppX package. Attackers could install the Sysinternals Suite to get access to tools such as psexec and procdump to avoid detection based on System paths.


    Read More
  • Syslog Clearing or Removal Via System Utilities

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.006  ·
    Share on: twitter facebook linkedin copy

    Detects specific commands commonly used to remove or empty the syslog. Which is a technique often used by attacker as a method to hide their tracks


    Read More
  • Sysmon Application Crashed

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects application popup reporting a failure of the Sysmon service


    Read More
  • Sysmon Blocked Executable

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Triggers on any Sysmon "FileBlockExecutable" event, which indicates a violation of the configured block policy


    Read More
  • Sysmon Blocked File Shredding

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Triggers on any Sysmon "FileBlockShredding" event, which indicates a violation of the configured shredding policy.


    Read More
  • Sysmon Channel Reference Deletion

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Potential threat actor tampering with Sysmon manifest and eventually disabling it


    Read More
  • Sysmon Configuration Change

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects a Sysmon configuration change, which could be the result of a legitimate reconfiguration or someone trying manipulate the configuration


    Read More
  • Sysmon Configuration Error

    calendar Apr 28, 2026 · attack.stealth attack.t1564  ·
    Share on: twitter facebook linkedin copy

    Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages


    Read More
  • Sysmon Configuration Modification

    calendar Apr 28, 2026 · attack.stealth attack.t1564  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker tries to hide from Sysmon by disabling or stopping it


    Read More
  • Sysmon Configuration Update

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects updates to Sysmon's configuration. Attackers might update or replace the Sysmon configuration with a bare bone one to avoid monitoring without shutting down the service completely


    Read More
  • Sysmon Driver Altitude Change

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes in Sysmon driver altitude value. If the Sysmon driver is configured to load at an altitude of another registered service, it will fail to load at boot.


    Read More
  • Sysmon Driver Unloaded Via Fltmc.EXE

    calendar Apr 28, 2026 · attack.stealth attack.defense-impairment attack.t1070 attack.t1685 attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects possible Sysmon filter driver unloaded via fltmc.exe


    Read More
  • Sysmon File Executable Creation Detected

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Triggers on any Sysmon "FileExecutableDetected" event, which triggers every time a PE that is monitored by the config is created.


    Read More
  • System Control Panel Item Loaded From Uncommon Location

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects image load events of system control panel items (.cpl) from uncommon or non-system locations that may indicate DLL sideloading or other abuse techniques.


    Read More
  • System File Execution Location Anomaly

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a Windows system binary that is usually located in the system folder from an uncommon location.


    Read More
  • System Information Discovery Using System_Profiler

    calendar Apr 28, 2026 · attack.discovery attack.stealth attack.t1082 attack.t1497.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "system_profiler" with specific "Data Types" that have been seen being used by threat actors and malware. It provides system hardware and software configuration information. This process is primarily used for system information discovery. However, "system_profiler" can also be used to determine if virtualization software is being run for defense evasion purposes.


    Read More
  • System Information Discovery Via Sysctl - MacOS

    calendar Apr 28, 2026 · attack.stealth attack.t1497.001 attack.discovery attack.t1082  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "sysctl" with specific arguments that have been used by threat actors and malware. It provides system hardware information. This process is primarily used to detect and avoid virtualization and analysis environments.


    Read More
  • TAIDOOR RAT DLL Load

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.stealth attack.t1055.001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects specific process characteristics of Chinese TAIDOOR RAT malware load


    Read More
  • Tamper Windows Defender - PSClassic

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.


    Read More
  • Tamper Windows Defender - ScriptBlockLogging

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell scripts attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.


    Read More
  • Tamper Windows Defender Remove-MpPreference

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to remove Windows Defender configurations using the 'MpPreference' cmdlet


    Read More
  • Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to remove Windows Defender configuration using the 'MpPreference' cmdlet


    Read More
  • Tamper With Sophos AV Registry Keys

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects tamper attempts to sophos av functionality via registry key modification


    Read More
  • Taskkill Symantec Endpoint Protection

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects one of the possible scenarios for disabling Symantec Endpoint Protection. Symantec Endpoint Protection antivirus software services incorrectly implement the protected service mechanism. As a result, the NT AUTHORITY/SYSTEM user can execute the taskkill /im command several times ccSvcHst.exe /f, thereby killing the process belonging to the service, and thus shutting down the service.


    Read More
  • Taskmgr as LOCAL_SYSTEM

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of taskmgr.exe process in context of LOCAL_SYSTEM


    Read More
  • Tasks Folder Evasion

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    The Tasks folder in system32 and syswow64 are globally writable paths. Adversaries can take advantage of this and load or influence any script hosts or ANY .NET Application in Tasks to load and execute a custom assembly into cscript, wscript, regsvr32, mshta, eventvwr


    Read More
  • TeamViewer Log File Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070.004  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of the TeamViewer log files which may indicate an attempt to destroy forensic evidence


    Read More
  • Telegram API Access

    calendar Apr 28, 2026 · attack.command-and-control attack.t1071.001 attack.t1102.002  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious requests to Telegram API without the usual Telegram User-Agent


    Read More
  • Temporary Access Pass Added To An Account

    calendar Apr 28, 2026 · attack.privilege-escalation attack.initial-access attack.persistence attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a temporary access pass (TAP) is added to an account. TAPs added to priv accounts should be investigated


    Read More
  • Terminal Server Client Connection History Cleared - Registry

    calendar Apr 28, 2026 · attack.persistence attack.stealth attack.defense-impairment attack.t1070 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of registry keys containing the MSTSC connection history


    Read More
  • The Windows Defender Firewall Service Failed To Load Group Policy

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects activity when The Windows Defender Firewall service failed to load Group Policy


    Read More
  • Third Party Software DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects DLL sideloading of DLLs that are part of third party software (zoom, discord....etc)


    Read More
  • Time Travel Debugging Utility Usage

    calendar Apr 28, 2026 · attack.credential-access attack.stealth attack.t1218 attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.


    Read More
  • Time Travel Debugging Utility Usage - Image

    calendar Apr 28, 2026 · attack.credential-access attack.stealth attack.t1218 attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects usage of Time Travel Debugging Utility. Adversaries can execute malicious processes and dump processes, such as lsass.exe, via tttracer.exe.


    Read More
  • Tomcat WebServer Logs Deleted

    calendar Apr 28, 2026 · attack.stealth attack.t1070  ·
    Share on: twitter facebook linkedin copy

    Detects the deletion of tomcat WebServer logs which may indicate an attempt to destroy forensic evidence


    Read More
  • Too Many Global Admins

    calendar Apr 28, 2026 · attack.initial-access attack.stealth attack.t1078 attack.persistence attack.privilege-escalation  ·
    Share on: twitter facebook linkedin copy

    Identifies an event where there are there are too many accounts assigned the Global Administrator role.


    Read More
  • Touch Suspicious Service File

    calendar Apr 28, 2026 · attack.stealth attack.t1070.006  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "touch" process in service file.


    Read More
  • Triple Cross eBPF Rootkit Default LockFile

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of the file "rootlog" which is used by the TripleCross rootkit as a way to check if the backdoor is already running.


    Read More
  • Triple Cross eBPF Rootkit Default Persistence

    calendar Apr 28, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.t1053.003  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of "ebpfbackdoor" files in both "cron.d" and "sudoers.d" directories. Which both are related to the TripleCross persistence method


    Read More
  • Triple Cross eBPF Rootkit Execve Hijack

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of a the file "execve_hijack" which is used by the Triple Cross rootkit as a way to elevate privileges


    Read More
  • Triple Cross eBPF Rootkit Install Commands

    calendar Apr 28, 2026 · attack.stealth attack.t1014  ·
    Share on: twitter facebook linkedin copy

    Detects default install commands of the Triple Cross eBPF rootkit based on the "deployer.sh" script


    Read More
  • Troubleshooting Pack Cmdlet Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "TroubleshootingPack" cmdlets to leverage CVE-2022-30190 or action similar to "msdt" lolbin (as described in LOLBAS)


    Read More
  • Trust Access Disable For VBApplications

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects registry changes to Microsoft Office "AccessVBOM" to a value of "1" which disables trust access for VBA on the victim machine and lets attackers execute malicious macros without any Microsoft Office warnings.


    Read More
  • Trusted Path Bypass via Windows Directory Spoofing

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.007 attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects DLLs loading from a spoofed Windows directory path with an extra space (e.g "C:\Windows \System32") which can bypass Windows trusted path verification. This technique tricks Windows into treating the path as trusted, allowing malicious DLLs to load with high integrity privileges bypassing UAC.


    Read More
  • TrustedPath UAC Bypass Pattern

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects indicators of a UAC bypass method by mocking directories


    Read More
  • Turla Group Commands May 2020

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.stealth attack.g0010 attack.execution attack.t1059.001 attack.t1053.005 attack.t1027 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects commands used by Turla group as reported by ESET in May 2020


    Read More
  • UAC Bypass Abusing Winsat Path Parsing - File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)


    Read More
  • UAC Bypass Abusing Winsat Path Parsing - Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)


    Read More
  • UAC Bypass Abusing Winsat Path Parsing - Registry

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using a path parsing issue in winsat.exe (UACMe 52)


    Read More
  • UAC Bypass Tools Using ComputerDefaults

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects tools such as UACMe used to bypass UAC with computerdefaults.exe (UACMe 59)


    Read More
  • UAC Bypass Using .NET Code Profiler on MMC

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using .NET Code Profiler and mmc.exe DLL hijacking (UACMe 39)


    Read More
  • UAC Bypass Using ChangePK and SLUI

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects an UAC bypass that uses changepk.exe and slui.exe (UACMe 61)


    Read More
  • UAC Bypass Using Consent and Comctl32 - File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)


    Read More
  • UAC Bypass Using Consent and Comctl32 - Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using consent.exe and comctl32.dll (UACMe 22)


    Read More
  • UAC Bypass Using Disk Cleanup

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using scheduled tasks and variable expansion of cleanmgr.exe (UACMe 34)


    Read More
  • UAC Bypass Using DismHost

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using DismHost DLL hijacking (UACMe 63)


    Read More
  • UAC Bypass Using Event Viewer RecentViews

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using Event Viewer RecentViews


    Read More
  • UAC Bypass Using EventVwr

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of a UAC bypass using Windows Event Viewer


    Read More
  • UAC Bypass Using IDiagnostic Profile

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the "IDiagnosticProfileUAC" UAC bypass technique


    Read More
  • UAC Bypass Using IDiagnostic Profile - File

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a file by "dllhost.exe" in System32 directory part of "IDiagnosticProfileUAC" UAC bypass technique


    Read More
  • UAC Bypass Using IEInstal - File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)


    Read More
  • UAC Bypass Using IEInstal - Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using IEInstal.exe (UACMe 64)


    Read More
  • UAC Bypass Using Iscsicpl - ImageLoad

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the "iscsicpl.exe" UAC bypass technique that leverages a DLL Search Order hijacking technique to load a custom DLL's from temp or a any user controlled location in the users %PATH%


    Read More
  • UAC Bypass Using MSConfig Token Modification - File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)


    Read More
  • UAC Bypass Using MSConfig Token Modification - Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using a msconfig GUI hack (UACMe 55)


    Read More
  • UAC Bypass Using NTFS Reparse Point - File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)


    Read More
  • UAC Bypass Using NTFS Reparse Point - Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using NTFS reparse point and wusa.exe DLL hijacking (UACMe 36)


    Read More
  • UAC Bypass Using PkgMgr and DISM

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using pkgmgr.exe and dism.exe (UACMe 23)


    Read More
  • UAC Bypass Using Windows Media Player - File

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)


    Read More
  • UAC Bypass Using Windows Media Player - Process

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)


    Read More
  • UAC Bypass Using Windows Media Player - Registry

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using Windows Media Player osksupport.dll (UACMe 32)


    Read More
  • UAC Bypass Using WOW64 Logger DLL Hijack

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using a WoW64 logger DLL hijack (UACMe 30)


    Read More
  • UAC Bypass via Event Viewer

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects UAC bypass method using Windows event viewer


    Read More
  • UAC Bypass via ICMLuaUtil

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using ICMLuaUtil Elevated COM interface


    Read More
  • UAC Bypass via Sdclt

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002 car.2019-04-001  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)


    Read More
  • UAC Bypass via Windows Firewall Snap-In Hijack

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to bypass User Account Control (UAC) by hijacking the Microsoft Management Console (MMC) Windows Firewall snap-in


    Read More
  • UAC Bypass Via Wsreset

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Unfixed method for UAC bypass from Windows 10. WSReset.exe file associated with the Windows Store. It will run a binary file contained in a low-privilege registry.


    Read More
  • UAC Bypass With Fake DLL

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1548.002 attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Attempts to load dismcore.dll after dropping it


    Read More
  • UAC Bypass WSReset

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects the pattern of UAC Bypass via WSReset usable by default sysmon-config


    Read More
  • UAC Disabled

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker tries to disable User Account Control (UAC) by setting the registry value "EnableLUA" to 0.


    Read More
  • UAC Notification Disabled

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value. UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users. When "UACDisableNotify" is set to 1, UAC prompts are suppressed.


    Read More
  • UAC Secure Desktop Prompt Disabled

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548.002  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker tries to change User Account Control (UAC) elevation request destination via the "PromptOnSecureDesktop" value. The "PromptOnSecureDesktop" setting specifically determines whether UAC prompts are displayed on the secure desktop. The secure desktop is a separate desktop environment that's isolated from other processes running on the system. It's designed to prevent malicious software from intercepting or tampering with UAC prompts. When "PromptOnSecureDesktop" is set to 0, UAC prompts are displayed on the user's current desktop instead of the secure desktop. This reduces the level of security because it potentially exposes the prompts to manipulation by malicious software.


    Read More
  • UEFI Persistence Via Wpbbin - FileCreation

    calendar Apr 28, 2026 · attack.persistence attack.stealth attack.t1542.001  ·
    Share on: twitter facebook linkedin copy

    Detects creation of a file named "wpbbin" in the "%systemroot%\system32" directory. Which could be indicative of UEFI based persistence method


    Read More
  • UEFI Persistence Via Wpbbin - ProcessCreation

    calendar Apr 28, 2026 · attack.persistence attack.stealth attack.t1542.001  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the binary "wpbbin" which is used as part of the UEFI based persistence method described in the reference section


    Read More
  • Ufw Force Stop Using Ufw-Init

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to force stop the ufw using ufw-init


    Read More
  • Unauthorized System Time Modification

    calendar Apr 28, 2026 · attack.stealth attack.t1070.006  ·
    Share on: twitter facebook linkedin copy

    Detect scenarios where a potentially unauthorized application or user is modifying the system time.


    Read More
  • UNC4841 - Barracuda ESG Exploitation Indicators

    calendar Apr 28, 2026 · attack.execution attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects file indicators as seen used by UNC4841 during their Barracuda ESG zero day exploitation.


    Read More
  • UNC4841 - Download Compressed Files From Temp.sh Using Wget

    calendar Apr 28, 2026 · attack.stealth attack.t1140 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "wget" to download a ".zip" or ".rar" files from "temp.sh". As seen used by UNC4841 during their Barracuda ESG zero day exploitation.


    Read More
  • UNC4841 - Download Tar File From Untrusted Direct IP Via Wget

    calendar Apr 28, 2026 · attack.stealth attack.t1140 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "wget" to download a "tar" from an IP address that doesn't have a trusted certificate. As seen used by UNC4841 during their Barracuda ESG zero day exploitation.


    Read More
  • UNC4841 - Email Exfiltration File Pattern

    calendar Apr 28, 2026 · attack.execution attack.persistence detection.emerging-threats attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects filename pattern of email related data used by UNC4841 for staging and exfiltration


    Read More
  • UNC4841 - SSL Certificate Exfiltration Via Openssl

    calendar Apr 28, 2026 · attack.stealth attack.t1140 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "openssl" to connect to an IP address. This techniques was used by UNC4841 to exfiltrate SSL certificates and as a C2 channel with named pipes. Investigate commands executed in the temporal vicinity of this command.


    Read More
  • Uncommon Assistive Technology Applications Execution Via AtBroker.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the start of a non built-in assistive technology applications via "Atbroker.EXE".


    Read More
  • Uncommon AddinUtil.EXE CommandLine Execution

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Add-In deployment cache updating utility (AddInutil.exe) with uncommon Addinroot or Pipelineroot paths. An adversary may execute AddinUtil.exe with uncommon Addinroot/Pipelineroot paths that point to the adversaries Addins.Store payload.


    Read More
  • Uncommon Child Process Of AddinUtil.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon child processes of the Add-In deployment cache updating utility (AddInutil.exe) which could be a sign of potential abuse of the binary to proxy execution via a custom Addins.Store payload.


    Read More
  • Uncommon Child Process Of Appvlp.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon child processes of Appvlp.EXE Appvlp or the Application Virtualization Utility is included with Microsoft Office. Attackers are able to abuse "AppVLP" to execute shell commands. Normally, this binary is used for Application Virtualization, but it can also be abused to circumvent the ASR file path rule folder or to mark a file as a system file.


    Read More
  • Uncommon Child Process Of BgInfo.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.005 attack.t1218 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon child processes of "BgInfo.exe" which could be a sign of potential abuse of the binary to proxy execution via external VBScript


    Read More
  • Uncommon Child Process Of Conhost.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon "conhost" child processes. This could be a sign of "conhost" usage as a LOLBIN or potential process injection activity.


    Read More
  • Uncommon Child Process Of Defaultpack.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon child processes of "DefaultPack.EXE" binary as a proxy to launch other programs


    Read More
  • Uncommon Child Process Of Setres.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon child process of Setres.EXE. Setres.EXE is a Windows server only process and tool that can be used to set the screen resolution. It can potentially be abused in order to launch any arbitrary file with a name containing the word "choice" from the current execution path.


    Read More
  • Uncommon Child Process Spawned By Odbcconf.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1218.008  ·
    Share on: twitter facebook linkedin copy

    Detects an uncommon child process of "odbcconf.exe" binary which normally shouldn't have any child processes.


    Read More
  • Uncommon Extension In Keyboard Layout IME File Registry Value

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects usage of Windows Input Method Editor (IME) keyboard layout feature, which allows an attacker to load a DLL into the process after sending the WM_INPUTLANGCHANGEREQUEST message. Before doing this, the client needs to register the DLL in a special registry key that is assumed to implement this keyboard layout. This registry key should store a value named "Ime File" with a DLL path. IMEs are essential for languages that have more characters than can be represented on a standard keyboard, such as Chinese, Japanese, and Korean.


    Read More
  • Uncommon File Creation By Mysql Daemon Process

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of files with scripting or executable extensions by Mysql daemon. Which could be an indicator of "User Defined Functions" abuse to download malware.


    Read More
  • Uncommon FileSystem Load Attempt By Format.com

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of format.com with an uncommon filesystem selection that could indicate a defense evasion activity in which "format.com" is used to load malicious DLL files or other programs.


    Read More
  • Uncommon Link.EXE Parent Process

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects an uncommon parent process of "LINK.EXE". Link.EXE in Microsoft incremental linker. Its a utility usually bundled with Visual Studio installation. Multiple utilities often found in the same folder (editbin.exe, dumpbin.exe, lib.exe, etc) have a hardcode call to the "LINK.EXE" binary without checking its validity. This would allow an attacker to sideload any binary with the name "link.exe" if one of the aforementioned tools get executed from a different location. By filtering the known locations of such utilities we can spot uncommon parent process of LINK.EXE that might be suspicious or malicious.


    Read More
  • Uncommon Microsoft Office Trusted Location Added

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to registry keys related to "Trusted Location" of Microsoft Office where the path is set to something uncommon. Attackers might add additional trusted locations to avoid macro security restrictions.


    Read More
  • Uncommon New Firewall Rule Added In Windows Firewall Exception List

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects when a rule has been added to the Windows Firewall exception list


    Read More
  • Uncommon Outbound Kerberos Connection

    calendar Apr 28, 2026 · attack.credential-access attack.t1558 attack.lateral-movement attack.t1550.003  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon outbound network activity via Kerberos default port indicating possible lateral movement or first stage PrivEsc via delegation.


    Read More
  • Uncommon Process Access Rights For Target Image

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1055.011  ·
    Share on: twitter facebook linkedin copy

    Detects process access request to uncommon target images with a "PROCESS_ALL_ACCESS" access mask.


    Read More
  • Uncommon Sigverif.EXE Child Process

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon child processes spawning from "sigverif.exe", which could indicate potential abuse of the latter as a living of the land binary in order to proxy execution.


    Read More
  • Uncommon Svchost Command Line Parameter

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth attack.t1036.005 attack.t1055 attack.t1055.012  ·
    Share on: twitter facebook linkedin copy

    Detects instances of svchost.exe running with an unusual or uncommon command line parameter by excluding known legitimate or common patterns. This could point at a file masquerading as svchost, a process injection, or hollowing of a legitimate svchost instance.


    Read More
  • Uncommon Svchost Parent Process

    calendar Apr 28, 2026 · attack.stealth attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects an uncommon svchost parent process


    Read More
  • Unfamiliar Sign-In Properties

    calendar Apr 28, 2026 · attack.stealth attack.t1078 attack.persistence attack.privilege-escalation attack.initial-access  ·
    Share on: twitter facebook linkedin copy

    Detects sign-in with properties that are unfamiliar to the user. The detection considers past sign-in history to look for anomalous sign-ins.


    Read More
  • Uninstall Crowdstrike Falcon Sensor

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Adversaries may disable security tools to avoid possible detection of their tools and activities by uninstalling Crowdstrike Falcon


    Read More
  • Uninstall Sysinternals Sysmon

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the removal of Sysmon, which could be a potential attempt at defense evasion


    Read More
  • Unmount Share Via Net.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1070.005  ·
    Share on: twitter facebook linkedin copy

    Detects when when a mounted share is removed. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation


    Read More
  • Unsigned .node File Loaded

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.persistence attack.stealth attack.t1129 attack.t1574.001 attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detects the loading of unsigned .node files. Adversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack. .node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code. This technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.


    Read More
  • Unsigned AppX Installation Attempt Using Add-AppxPackage

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "Add-AppxPackage" or it's alias "Add-AppPackage" to install unsigned AppX packages


    Read More
  • Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript

    calendar Apr 28, 2026 · attack.persistence attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "Add-AppxPackage" or it's alias "Add-AppPackage" to install unsigned AppX packages


    Read More
  • Unsigned Binary Loaded From Suspicious Location

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects Code Integrity (CI) engine blocking processes from loading unsigned DLLs residing in suspicious locations


    Read More
  • Unsigned DLL Loaded by Windows Utility

    calendar Apr 28, 2026 · attack.stealth attack.t1218.011 attack.t1218.010  ·
    Share on: twitter facebook linkedin copy

    Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.


    Read More
  • Unsigned Mfdetours.DLL Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects DLL sideloading of unsigned "mfdetours.dll". Executing "mftrace.exe" can be abused to attach to an arbitrary process and force load any DLL named "mfdetours.dll" from the current directory of execution.


    Read More
  • Unsigned Module Loaded by ClickOnce Application

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects unsigned module load by ClickOnce application.


    Read More
  • Unusual File Download from Direct IP Address

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects the download of suspicious file type from URLs with IP


    Read More
  • Unusual File Download From File Sharing Websites - File Stream

    calendar Apr 28, 2026 · attack.stealth attack.s0139 attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detects the download of suspicious file type from a well-known file and paste sharing domain


    Read More
  • Use Icacls to Hide File to Everyone

    calendar Apr 28, 2026 · attack.stealth attack.t1564.001  ·
    Share on: twitter facebook linkedin copy

    Detect use of icacls to deny access for everyone in Users folder sometimes used to hide malicious files


    Read More
  • Use NTFS Short Name in Command Line

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detect use of the Windows 8.3 short name. Which could be used as a method to avoid command-line detection


    Read More
  • Use NTFS Short Name in Image

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detect use of the Windows 8.3 short name. Which could be used as a method to avoid Image based detection


    Read More
  • Use Of Hidden Paths Or Files

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects calls to hidden files or files located in hidden directories in NIX systems.


    Read More
  • Use of Legacy Authentication Protocols

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.credential-access attack.stealth attack.t1078.004 attack.t1110  ·
    Share on: twitter facebook linkedin copy

    Alert on when legacy authentication has been used on an account


    Read More
  • Use of Remote.exe

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Remote.exe is part of WinDbg in the Windows SDK and can be used for AWL bypass and running remote files.


    Read More
  • Use of Scriptrunner.exe

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    The "ScriptRunner.exe" binary can be abused to proxy execution through it and bypass possible whitelisting


    Read More
  • Use Of The SFTP.EXE Binary As A LOLBIN

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of the "sftp.exe" binary as a LOLBIN by abusing the "-D" flag


    Read More
  • Use of TTDInject.exe

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    Detects the executiob of TTDInject.exe, which is used by Windows 10 v1809 and newer to debug time travel (underlying call of tttracer.exe)


    Read More
  • Use of VisualUiaVerifyNative.exe

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    VisualUiaVerifyNative.exe is a Windows SDK that can be used for AWL bypass and is listed in Microsoft's recommended block rules.


    Read More
  • Use of VSIISExeLauncher.exe

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    The "VSIISExeLauncher.exe" binary part of the Visual Studio/VS Code can be used to execute arbitrary binaries


    Read More
  • Use of Wfc.exe

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1127  ·
    Share on: twitter facebook linkedin copy

    The Workflow Command-line Compiler can be used for AWL bypass and is listed in Microsoft's recommended block rules.


    Read More
  • Use Short Name Path in Image

    calendar Apr 28, 2026 · attack.stealth attack.t1564.004  ·
    Share on: twitter facebook linkedin copy

    Detect use of the Windows 8.3 short name. Which could be used as a method to avoid Image detection


    Read More
  • User Access Blocked by Azure Conditional Access

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.credential-access attack.initial-access attack.stealth attack.t1110 attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detect access has been blocked by Conditional Access policies. The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.


    Read More
  • User Added To Admin Group Via Dscl

    calendar Apr 28, 2026 · attack.persistence attack.initial-access attack.privilege-escalation attack.stealth attack.t1078.003  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to create and add an account to the admin group via "dscl"


    Read More
  • User Added To Admin Group Via DseditGroup

    calendar Apr 28, 2026 · attack.persistence attack.initial-access attack.privilege-escalation attack.stealth attack.t1078.003  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to create and/or add an account to the admin group, thus granting admin privileges.


    Read More
  • User Added To Admin Group Via Sysadminctl

    calendar Apr 28, 2026 · attack.persistence attack.initial-access attack.privilege-escalation attack.stealth attack.t1078.003  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to create and add an account to the admin group via "sysadminctl"


    Read More
  • User Added to an Administrator's Azure AD Role

    calendar Apr 28, 2026 · attack.initial-access attack.persistence attack.privilege-escalation attack.stealth attack.t1098.003 attack.t1078  ·
    Share on: twitter facebook linkedin copy

    User Added to an Administrator's Azure AD Role


    Read More
  • User Added To Group With CA Policy Modification Access

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert on group membership additions of groups that have CA policy modification access


    Read More
  • User Added to Local Administrator Group

    calendar Apr 28, 2026 · attack.initial-access attack.privilege-escalation attack.stealth attack.t1078 attack.persistence attack.t1098  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity


    Read More
  • User Added To Privilege Role

    calendar Apr 28, 2026 · attack.persistence attack.initial-access attack.privilege-escalation attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects when a user is added to a privileged role.


    Read More
  • User Removed From Group With CA Policy Modification Access

    calendar Apr 28, 2026 · attack.privilege-escalation attack.credential-access attack.persistence attack.defense-impairment attack.t1548 attack.t1556  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert on group membership removal of groups that have CA policy modification access


    Read More
  • User Shell Folders Registry Modification via CommandLine

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.defense-impairment attack.t1547.001 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects modifications to User Shell Folders registry values via reg.exe or PowerShell, which could indicate persistence attempts. Attackers may modify User Shell Folders registry values to point to malicious executables or scripts that will be executed during startup. This technique is often used to maintain persistence on a compromised system by ensuring that malicious payloads are executed automatically.


    Read More
  • User State Changed From Guest To Member

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detects the change of user type from "Guest" to "Member" for potential elevation of privilege.


    Read More
  • Users Added to Global or Device Admin Roles

    calendar Apr 28, 2026 · attack.persistence attack.initial-access attack.privilege-escalation attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Monitor and alert for users added to device admin roles.


    Read More
  • Users Authenticating To Other Azure AD Tenants

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.initial-access attack.stealth attack.t1078.004  ·
    Share on: twitter facebook linkedin copy

    Detect when users in your Azure AD tenant are authenticating to other Azure AD Tenants.


    Read More
  • Using SettingSyncHost.exe as LOLBin

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.008  ·
    Share on: twitter facebook linkedin copy

    Detects using SettingSyncHost.exe to run hijacked binary


    Read More
  • UtilityFunctions.ps1 Proxy Dll

    calendar Apr 28, 2026 · attack.stealth attack.t1216  ·
    Share on: twitter facebook linkedin copy

    Detects the use of a Microsoft signed script executing a managed DLL with PowerShell.


    Read More
  • Verclsid.exe Runs COM Object

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects when verclsid.exe is used to run COM object via GUID


    Read More
  • Virtualbox Driver Installation or Starting of VMs

    calendar Apr 28, 2026 · attack.stealth attack.t1564.006 attack.t1564  ·
    Share on: twitter facebook linkedin copy

    Adversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.


    Read More
  • Visual Basic Command Line Compiler Usage

    calendar Apr 28, 2026 · attack.stealth attack.t1027.004  ·
    Share on: twitter facebook linkedin copy

    Detects successful code compilation via Visual Basic Command Line Compiler that utilizes Windows Resource to Object Converter.


    Read More
  • Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects child processes of Microsoft.NodejsTools.PressAnyKey.exe that can be used to execute any other binary


    Read More
  • Visual Studio NodejsTools PressAnyKey Renamed Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects renamed execution of "Microsoft.NodejsTools.PressAnyKey.exe", which can be abused as a LOLBIN to execute arbitrary binaries


    Read More
  • VMGuestLib DLL Sideload

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects DLL sideloading of VMGuestLib.dll by the WmiApSrv service.


    Read More
  • VMMap Signed Dbghelp.DLL Potential Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of a signed dbghelp.dll by the Sysinternals VMMap.


    Read More
  • VMMap Unsigned Dbghelp.DLL Potential Sideloading

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential DLL sideloading of an unsigned dbghelp.dll by the Sysinternals VMMap.


    Read More
  • Vulnerable Driver Blocklist Registry Tampering Via CommandLine

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects tampering of the Vulnerable Driver Blocklist registry via command line tools such as PowerShell or REG.EXE. The Vulnerable Driver Blocklist is a security feature that helps prevent the loading of known vulnerable drivers. Disabling this feature may indicate an attempt to bypass security controls, often targeted by threat actors to facilitate the installation of malicious or vulnerable drivers, particularly in scenarios involving Endpoint Detection and Response


    Read More
  • Vulnerable Netlogon Secure Channel Connection Allowed

    calendar Apr 28, 2026 · attack.privilege-escalation attack.t1548  ·
    Share on: twitter facebook linkedin copy

    Detects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.


    Read More
  • Wab Execution From Non Default Location

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) from non default locations as seen with bumblebee activity


    Read More
  • Wab/Wabmig Unusual Parent Or Child Processes

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects unusual parent or children of the wab.exe (Windows Contacts) and Wabmig.exe (Microsoft Address Book Import Tool) processes as seen being used with bumblebee activity


    Read More
  • WannaCry Ransomware Activity

    calendar Apr 28, 2026 · attack.lateral-movement attack.defense-impairment attack.t1210 attack.discovery attack.t1083 attack.t1222.001 attack.impact attack.t1486 attack.t1490 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects WannaCry ransomware activity


    Read More
  • Wdigest CredGuard Registry Modification

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects potential malicious modification of the property value of IsCredGuardEnabled from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to disable Cred Guard on a system. This is usually used with UseLogonCredential to manipulate the caching credentials.


    Read More
  • Wdigest Enable UseLogonCredential

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects potential malicious modification of the property value of UseLogonCredential from HKLM:\SYSTEM\CurrentControlSet\Control\SecurityProviders\WDigest to enable clear-text credentials


    Read More
  • Weak Encryption Enabled and Kerberoast

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects scenario where weak encryption is enabled for a user profile which could be used for hash/password cracking.


    Read More
  • Weak or Abused Passwords In CLI

    calendar Apr 28, 2026 · attack.execution attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects weak passwords or often abused passwords (seen used by threat actors) via the CLI. An example would be a threat actor creating a new user via the net command and providing the password inline


    Read More
  • WFP Filter Added via Registry

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1685 attack.t1569.002  ·
    Share on: twitter facebook linkedin copy

    Detects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.


    Read More
  • Win Defender Restored Quarantine File

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the restoration of files from the defender quarantine


    Read More
  • Win Susp Computer Name Containing Samtheadmin

    calendar Apr 28, 2026 · attack.initial-access cve.2021-42278 cve.2021-42287 attack.persistence attack.privilege-escalation attack.stealth attack.t1078  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious computer name samtheadmin-{1..100}$ generated by hacktool


    Read More
  • WinDivert Driver Load

    calendar Apr 28, 2026 · attack.credential-access attack.collection attack.defense-impairment attack.t1599.001 attack.t1557.001  ·
    Share on: twitter facebook linkedin copy

    Detects the load of the Windiver driver, a powerful user-mode capture/sniffing/modification/blocking/re-injection package for Windows


    Read More
  • Windows AMSI Related Registry Tampering Via CommandLine

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects tampering of AMSI (Anti-Malware Scan Interface) related registry values via command line tools such as reg.exe or PowerShell. AMSI provides a generic interface for applications and services to integrate with antimalware products. Adversaries may disable AMSI to evade detection of malicious scripts and code execution.


    Read More
  • Windows AppX Deployment Full Trust Package Installation

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1204.002 attack.t1553.005  ·
    Share on: twitter facebook linkedin copy

    Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions


    Read More
  • Windows AppX Deployment Unsigned Package Installation

    calendar Apr 28, 2026 · attack.execution attack.defense-impairment attack.t1204.002 attack.t1553.005  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events


    Read More
  • Windows Binaries Write Suspicious Extensions

    calendar Apr 28, 2026 · attack.stealth attack.t1036  ·
    Share on: twitter facebook linkedin copy

    Detects Windows executables that write files with suspicious extensions


    Read More
  • Windows Binary Executed From WSL

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of Windows binaries from within a WSL instance. This could be used to masquerade parent-child relationships


    Read More
  • Windows Credential Guard Disabled - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to disable Windows Credential Guard by setting registry values to 0. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.


    Read More
  • Windows Credential Guard Registry Tampering Via CommandLine

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to add, modify, or delete Windows Credential Guard related registry keys or values via command line tools such as Reg.exe or PowerShell. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation. The rule matches suspicious command lines that target DeviceGuard or LSA registry paths and manipulate keys like EnableVirtualizationBasedSecurity, RequirePlatformSecurityFeatures, or LsaCfgFlags. Such activity may indicate an attempt to disable or tamper with Credential Guard, potentially exposing sensitive credentials for misuse.


    Read More
  • Windows Credential Guard Related Registry Value Deleted - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to disable Windows Credential Guard by deleting registry values. Credential Guard uses virtualization-based security to isolate secrets so that only privileged system software can access them. Adversaries may disable Credential Guard to gain access to sensitive credentials stored in the system, such as NTLM hashes and Kerberos tickets, which can be used for lateral movement and privilege escalation.


    Read More
  • Windows Default Domain GPO Modification

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1484.001  ·
    Share on: twitter facebook linkedin copy

    Detects modifications to Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may modify these default GPOs to deploy malicious configurations across the domain.


    Read More
  • Windows Default Domain GPO Modification via GPME

    calendar Apr 28, 2026 · attack.privilege-escalation attack.defense-impairment attack.t1484.001  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the Group Policy Management Editor (GPME) to modify Default Domain or Default Domain Controllers Group Policy Objects (GPOs). Adversaries may leverage GPME to make stealthy changes in these default GPOs to deploy malicious GPOs configurations across the domain without raising suspicion.


    Read More
  • Windows Defender Configuration Changes

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious changes to the Windows Defender configuration


    Read More
  • Windows Defender Context Menu Removed

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the use of reg.exe or PowerShell to delete the Windows Defender context menu handler registry keys. This action removes the "Scan with Microsoft Defender" option from the right-click menu for files, directories, and drives. Attackers may use this technique to hinder manual, on-demand scans and reduce the visibility of the security product.


    Read More
  • Windows Defender Definition Files Removed

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Adversaries may disable security tools to avoid possible detection of their tools and activities by removing Windows Defender Definition Files


    Read More
  • Windows Defender Exclusion List Modified

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects modifications to the Windows Defender exclusion registry key. This could indicate a potentially suspicious or even malicious activity by an attacker trying to add a new exclusion in order to bypass security.


    Read More
  • Windows Defender Exclusion Registry Key - Write Access Requested

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects write access requests to the Windows Defender exclusions registry keys. This could be an indication of an attacker trying to request a handle or access the object to write new exclusions in order to bypass security.


    Read More
  • Windows Defender Exclusions Added

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the Setting of Windows Defender Exclusions


    Read More
  • Windows Defender Exclusions Added - PowerShell

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685 attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects modifications to the Windows Defender configuration settings using PowerShell to add exclusions


    Read More
  • Windows Defender Exclusions Added - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the Setting of Windows Defender Exclusions


    Read More
  • Windows Defender Exploit Guard Tamper

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when someone is adding or removing applications or folders from exploit guard "ProtectedFolders" or "AllowedApplications"


    Read More
  • Windows Defender Firewall Has Been Reset To Its Default Configuration

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects activity when Windows Defender Firewall has been reset to its default configuration


    Read More
  • Windows Defender Grace Period Expired

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects the expiration of the grace period of Windows Defender. This means protection against viruses, spyware, and other potentially unwanted software is disabled.


    Read More
  • Windows Defender Malware And PUA Scanning Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling of the Windows Defender feature of scanning for malware and other potentially unwanted software


    Read More
  • Windows Defender Malware Detection History Deletion

    calendar Apr 28, 2026 · attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Windows Defender logs when the history of detected infections is deleted.


    Read More
  • Windows Defender Real-time Protection Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling of Windows Defender Real-time Protection. As this event doesn't contain a lot of information on who initiated this action you might want to reduce it to a "medium" level if this occurs too many times in your environment


    Read More
  • Windows Defender Real-Time Protection Failure/Restart

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects issues with Windows Defender Real-Time Protection features


    Read More
  • Windows Defender Service Disabled - Registry

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when an attacker or tool disables the Windows Defender service (WinDefend) via the registry


    Read More
  • Windows Defender Submit Sample Feature Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling of the "Automatic Sample Submission" feature of Windows Defender.


    Read More
  • Windows Defender Threat Detection Service Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when the "Windows Defender Threat Protection" service is disabled.


    Read More
  • Windows Defender Threat Severity Default Action Modified

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects modifications or creations of Windows Defender's default threat action settings based on severity to 'allow' or take 'no action'. This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level, allowing malicious software to run unimpeded. An attacker might use this technique to bypass defenses before executing payloads.


    Read More
  • Windows Defender Virus Scanning Feature Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects disabling of the Windows Defender virus scanning feature


    Read More
  • Windows Event Auditing Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects scenarios where system auditing (i.e.: Windows event log auditing) is disabled. This may be used in a scenario where an entity would want to bypass local logging to evade detection when Windows event logging is enabled and reviewed. Also, it is recommended to turn off "Local Group Policy Object Processing" via GPO, which will make sure that Active Directory GPOs take precedence over local/edited computer policies via something such as "gpedit.msc". Please note, that disabling "Local Group Policy Object Processing" may cause an issue in scenarios of one off specific GPO modifications - however, it is recommended to perform these modifications in Active Directory anyways.


    Read More
  • Windows Event Log Access Tampering Via Registry

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.defense-impairment attack.t1547.001 attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the Windows EventLog channel permission values. It focuses on changes to the Security Descriptor Definition Language (SDDL) string, as modifications to these values can restrict access to specific users or groups, potentially aiding in defense evasion by controlling who can view or modify a event log channel. Upon execution, the user shouldn't be able to access the event log channel via the event viewer or via utilities such as "Get-EventLog" or "wevtutil".


    Read More
  • Windows EventLog Autologger Session Registry Modification Via CommandLine

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685.001  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to disable Windows EventLog autologger sessions via registry modification. The AutoLogger event tracing session records events that occur early in the operating system boot process. Applications and device drivers can use the AutoLogger session to capture traces before the user logs in. Adversaries may disable these sessions to evade detection and prevent security monitoring of early boot activities and system events.


    Read More
  • Windows Filtering Platform Blocked Connection From EDR Agent Binary

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents. Adversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.


    Read More
  • Windows Firewall Disabled via PowerShell

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to disable the Windows Firewall using PowerShell


    Read More
  • Windows Firewall Profile Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects when a user disables the Windows Firewall via a Profile to help evade defense.


    Read More
  • Windows Firewall Settings Have Been Changed

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1686.003  ·
    Share on: twitter facebook linkedin copy

    Detects activity when the settings of the Windows firewall have been changed


    Read More
  • Windows Hypervisor Enforced Code Integrity Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the HypervisorEnforcedCodeIntegrity registry key and the "Enabled" value being set to 0 in order to disable the Hypervisor Enforced Code Integrity feature. This allows an attacker to load unsigned and untrusted code to be run in the kernel


    Read More
  • Windows Kernel Debugger Execution

    calendar Apr 28, 2026 · attack.privilege-escalation attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Windows Kernel Debugger "kd.exe".


    Read More
  • Windows MSIX Package Support Framework AI_STUBS Execution

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.defense-impairment attack.t1218 attack.t1553.005 attack.t1204.002  ·
    Share on: twitter facebook linkedin copy

    Detects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.


    Read More
  • Windows PowerShell User Agent

    calendar Apr 28, 2026 · attack.command-and-control attack.t1071.001  ·
    Share on: twitter facebook linkedin copy

    Detects Windows PowerShell Web Access


    Read More
  • Windows Processes Suspicious Parent Directory

    calendar Apr 28, 2026 · attack.stealth attack.t1036.003 attack.t1036.005  ·
    Share on: twitter facebook linkedin copy

    Detect suspicious parent processes of well-known Windows processes


    Read More
  • Windows Service Terminated With Error

    calendar Apr 28, 2026 · attack.stealth  ·
    Share on: twitter facebook linkedin copy

    Detects Windows services that got terminated for whatever reason


    Read More
  • Windows Shell/Scripting Processes Spawning Suspicious Programs

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.005 attack.t1059.001 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child processes of a Windows shell and scripting processes such as wscript, rundll32, powershell, mshta...etc.


    Read More
  • Windows Spooler Service Suspicious Binary Load

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.execution attack.stealth attack.t1574 cve.2021-1675 cve.2021-34527 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detect DLL Load from Spooler Service backup folder. This behavior has been observed during the exploitation of the Print Spooler Vulnerability CVE-2021-1675 and CVE-2021-34527 (PrinterNightmare).


    Read More
  • Windows Vulnerable Driver Blocklist Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects when the Windows Vulnerable Driver Blocklist is set to disabled. This setting is crucial for preventing the loading of known vulnerable drivers, and its modification may indicate an attempt to bypass security controls. It is often targeted by threat actors to facilitate the installation of malicious or vulnerable drivers, particularly in scenarios involving Endpoint Detection and Response (EDR) bypass techniques. This rule applies to systems that support the Vulnerable Driver Blocklist feature, including Windows 10 version 1903 and later, and Windows Server 2022 and later. Note that this change will require a reboot to take effect, and this rule only detects the registry modification action.


    Read More
  • Winget Admin Settings Modification

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the AppInstaller (winget) admin settings. Such as enabling local manifest installations or disabling installer hash checks


    Read More
  • Winlogon AllowMultipleTSSessions Enable

    calendar Apr 28, 2026 · attack.persistence attack.defense-impairment attack.t1112  ·
    Share on: twitter facebook linkedin copy

    Detects when the 'AllowMultipleTSSessions' value is enabled. Which allows for multiple Remote Desktop connection sessions to be opened at once. This is often used by attacker as a way to connect to an RDP session without disconnecting the other users


    Read More
  • Winnti Malware HK University Campaign

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 attack.g0044 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects specific process characteristics of Winnti malware noticed in Dec/Jan 2020 in a campaign against Honk Kong universities


    Read More
  • Winnti Pipemon Characteristics

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001 attack.g0044 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects specific process characteristics of Winnti Pipemon malware reported by ESET


    Read More
  • Winrs Local Command Execution

    calendar Apr 28, 2026 · attack.lateral-movement attack.stealth attack.t1021.006 attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of Winrs.exe where it is used to execute commands locally. Commands executed this way are launched under Winrshost.exe and can represent proxy execution used for defense evasion or lateral movement.


    Read More
  • Wlrmdr.EXE Uncommon Argument Or Child Process

    calendar Apr 28, 2026 · attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of "Wlrmdr.exe" with the "-u" command line flag which allows anything passed to it to be an argument of the ShellExecute API, which would allow an attacker to execute arbitrary binaries. This detection also focuses on any uncommon child processes spawned from "Wlrmdr.exe" as a supplement for those that posses "ParentImage" telemetry.


    Read More
  • WMIC Loading Scripting Libraries

    calendar Apr 28, 2026 · attack.stealth attack.t1220  ·
    Share on: twitter facebook linkedin copy

    Detects threat actors proxy executing code and bypassing application controls by leveraging wmic and the /FORMAT argument switch to download and execute an XSL file (i.e js, vbs, etc). It could be an indicator of SquiblyTwo technique, which uses Windows Management Instrumentation (WMI) to execute malicious code.


    Read More
  • Write Protect For Storage Disabled

    calendar Apr 28, 2026 · attack.defense-impairment attack.t1685  ·
    Share on: twitter facebook linkedin copy

    Detects applications trying to modify the registry in order to disable any write-protect property for storage devices. This could be a precursor to a ransomware attack and has been an observed technique used by cypherpunk group.


    Read More
  • Writing Of Malicious Files To The Fonts Folder

    calendar Apr 28, 2026 · attack.stealth attack.t1211 attack.t1059 attack.persistence attack.execution  ·
    Share on: twitter facebook linkedin copy

    Monitors for the hiding possible malicious files in the C:\Windows\Fonts\ location. This folder doesn't require admin privillege to be written and executed from.


    Read More
  • WSL Child Process Anomaly

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218 attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL


    Read More
  • WSL Kali-Linux Usage

    calendar Apr 28, 2026 · attack.stealth attack.t1202  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Kali Linux through Windows Subsystem for Linux


    Read More
  • XBAP Execution From Uncommon Locations Via PresentationHost.EXE

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1218  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of ".xbap" (Browser Applications) files via PresentationHost.EXE from an uncommon location. These files can be abused to run malicious ".xbap" files any bypass AWL


    Read More
  • XSL Script Execution Via WMIC.EXE

    calendar Apr 28, 2026 · attack.stealth attack.t1047 attack.t1220 attack.execution attack.t1059.005 attack.t1059.007  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of WMIC with the "format" flag to potentially load local XSL files. Adversaries abuse this functionality to execute arbitrary files while potentially bypassing application whitelisting defenses. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files.


    Read More
  • Xwizard.EXE Execution From Non-Default Location

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.execution attack.stealth attack.t1574.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of Xwizard tool from a non-default directory. When executed from a non-default directory, this utility can be abused in order to side load a custom version of "xwizards.dll".


    Read More
  • ZxShell Malware

    calendar Apr 28, 2026 · attack.execution attack.stealth attack.t1059.003 attack.t1218.011 attack.s0412 attack.g0001 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects a ZxShell start by the called and well-known function name


    Read More
  • Obfuscated IP Download Activity

    calendar Apr 28, 2026 · attack.discovery  ·
    Share on: twitter facebook linkedin copy

    Detects use of an encoded/obfuscated version of an IP address (hex, octal...) in an URL combined with a download command


    Read More
  • Obfuscated IP Via CLI

    calendar Apr 28, 2026 · attack.discovery  ·
    Share on: twitter facebook linkedin copy

    Detects usage of an encoded/obfuscated version of an IP address (hex, octal, etc.) via command line


    Read More
  • Delete Important Scheduled Task

    calendar Apr 28, 2026 · attack.impact attack.t1489  ·
    Share on: twitter facebook linkedin copy

    Detects when adversaries stop services or processes by deleting their respective scheduled tasks in order to conduct data destructive activities


    Read More
  • Disable Important Scheduled Task

    calendar Apr 28, 2026 · attack.impact attack.t1489  ·
    Share on: twitter facebook linkedin copy

    Detects when adversaries stop services or processes by disabling their respective scheduled tasks in order to conduct data destructive activities


    Read More
  • Important Scheduled Task Deleted or Disabled

    calendar Apr 28, 2026 · attack.impact attack.t1489  ·
    Share on: twitter facebook linkedin copy

    Detects when adversaries try to stop system services or processes by deleting or disabling their respective scheduled tasks in order to conduct data destructive activities


    Read More
  • Important Scheduled Task Deleted/Disabled

    calendar Apr 28, 2026 · attack.execution attack.privilege-escalation attack.persistence attack.t1053.005  ·
    Share on: twitter facebook linkedin copy

    Detects when adversaries stop services or processes by deleting or disabling their respective scheduled tasks in order to conduct data destructive activities


    Read More
  • Registry Disable System Restore

    calendar Apr 28, 2026 · attack.impact attack.t1490  ·
    Share on: twitter facebook linkedin copy

    Detects the modification of the registry to disable a system restore on the computer


    Read More
  • System Restore Registry Modification via CommandLine

    calendar Apr 28, 2026 · attack.impact attack.t1490  ·
    Share on: twitter facebook linkedin copy

    Detects system restore registry modification via command line, which can be used by adversaries to disable system restore on the computer.


    Read More
  • Google Workspace Application Access Level Modified

    calendar Apr 28, 2026 · attack.persistence attack.privilege-escalation attack.t1098.003  ·
    Share on: twitter facebook linkedin copy

    Detects when an access level is changed for a Google workspace application. An access level is part of BeyondCorp Enterprise which is Google Workspace's way of enforcing Zero Trust model. An adversary would be able to remove access levels to gain easier access to Google workspace resources.


    Read More
  • Google Workspace Application Removed

    calendar Apr 28, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an an application is removed from Google Workspace.


    Read More
  • Google Workspace Granted Domain API Access

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1098  ·
    Share on: twitter facebook linkedin copy

    Detects when an API access service account is granted domain authority.


    Read More
  • Google Workspace MFA Disabled

    calendar Apr 28, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when multi-factor authentication (MFA) is disabled.


    Read More
  • Google Workspace Out Of Domain Email Forwarding

    calendar Apr 28, 2026 · attack.t1114.003 attack.collection  ·
    Share on: twitter facebook linkedin copy

    Detects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse.


    Read More
  • Google Workspace Role Modified or Deleted

    calendar Apr 28, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an a role is modified or deleted in Google Workspace.


    Read More
  • Google Workspace Role Privilege Deleted

    calendar Apr 28, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an a role privilege is deleted in Google Workspace.


    Read More
  • Google Workspace User Granted Admin Privileges

    calendar Apr 28, 2026 · attack.privilege-escalation attack.persistence attack.t1098  ·
    Share on: twitter facebook linkedin copy

    Detects when an Google Workspace user is granted admin privileges.


    Read More
  • Potential Dropper Script Execution Via WScript/CScript/MSHTA

    calendar Apr 27, 2026 · attack.execution attack.t1059.005 attack.t1059.007  ·
    Share on: twitter facebook linkedin copy

    Detects wscript/cscript/mshta executions of scripts located in user directories


    Read More
  • Potentially Suspicious Powershell Script Execution From Temp Folder

    calendar Apr 27, 2026 · attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects a potentially suspicious powershell script executions from temporary folder


    Read More
  • Script Interpreter Execution From Suspicious Folder

    calendar Apr 27, 2026 · attack.execution attack.t1059  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious script execution from suspicious directories or folders accessible by environment variables that may indicate malware activity. Script interpreters (cscript, wscript, mshta, powershell) executing from folders like Temp, Public, or user profile directories may suggest attempts to evade detection or execute malicious scripts.


    Read More
  • WScript or CScript Dropper - File

    calendar Apr 27, 2026 · attack.execution attack.t1059.005 attack.t1059.007  ·
    Share on: twitter facebook linkedin copy

    Detects a file ending in jse, vbe, js, vba, vbs, wsf, wsh written by cscript.exe or wscript.exe


    Read More
  • Potential Suspicious Change To Sensitive/Critical Files

    calendar Apr 27, 2026 · attack.impact attack.t1565.001  ·
    Share on: twitter facebook linkedin copy

    Detects changes of sensitive and critical files. Monitors files that you don't expect to change without planning on Linux system. These files include, but are not limited to, system configuration files, authentication files, and critical application files. Attackers often target these files to maintain persistence, escalate privileges, or disrupt system operations.


    Read More
  • Potential CVE-2026-33829 Exploitation - Windows Snipping Tool Remote File Path URI

    calendar Apr 27, 2026 · attack.credential-access attack.t1187 detection.emerging-threats cve.2026-33829  ·
    Share on: twitter facebook linkedin copy

    Detects potential exploitation of CVE-2026-33829, a vulnerability in the Windows Snipping Tool URI handler (ms-screensketch:). An attacker can abuse the 'filePath' parameter to supply a UNC path or HTTP URL, causing SnippingTool.exe to initiate a connection to a remote resource. When a UNC path is used (e.g. \attacker.com\share), this triggers an outbound NTLM authentication attempt, allowing the attacker to capture or relay the victim's Net-NTLMv2 hash. HTTP-based paths may result in remote file loading or server-side request forgery (SSRF)-style access. The URI can be delivered via a malicious hyperlink, phishing email, or web page.


    Read More
  • Github Delete Action Invoked

    calendar Apr 27, 2026 · attack.impact attack.collection attack.t1213.003  ·
    Share on: twitter facebook linkedin copy

    Detects delete action in the Github audit logs for codespaces, environment, project and repo.


    Read More
  • New Cron File Created

    calendar Apr 27, 2026 · attack.privilege-escalation attack.execution attack.persistence attack.t1053.003  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of cron files in Cron directories, which could indicate potential persistence mechanisms being established by an attacker. Note that not all cron file creations are malicious - legitimate system administration activities and software installations may also create cron files. This detection should be investigated in context, considering factors such as the user creating the file, the timing of creation, and the contents of the cron job. Focus investigation on unexpected cron files created by non-administrative users or during suspicious timeframes. Additionally, it is recommended to review the contents of the newly created cron files to assess their intent. Furthermore, it is suggested to baseline normal cron file creation and apply additional filters to reduce false positives based on the specific environment.


    Read More
  • Kubernetes Potential Enumeration Activity

    calendar Apr 27, 2026 · attack.execution attack.discovery attack.t1609 attack.t1613  ·
    Share on: twitter facebook linkedin copy

    Detects potential Kubernetes enumeration or attack activity via the audit log. This includes the execution of common shells, utilities, or specialized tools like 'Rakkess' (access_matrix) and 'TruffleHog' via Kubernetes API requests. Attackers use these methods to perform reconnaissance (enumeration), secret harvesting, or execute code (exec) within a cluster.


    Read More
  • Suspicious Email Delivered In Microsoft 365

    calendar Apr 27, 2026 · attack.initial-access attack.t1566.001 attack.t1566.002  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.


    Read More
  • Shell Invocation via Env Command - Linux

    calendar Apr 27, 2026 · attack.execution attack.t1059.004  ·
    Share on: twitter facebook linkedin copy

    Detects the use of the env command to invoke a shell. This may indicate an attempt to bypass restricted environments, escalate privileges, or execute arbitrary commands.


    Read More
  • PowerShell Download Via Net.WebClient - PowerShell Classic

    calendar Apr 27, 2026 · attack.execution attack.command-and-control attack.t1059.001 attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects PowerShell download activity, via the .DownloadFile() or .DownloadString() methods of the Net.WebClient class. This technique is often abused by attackers to download additional payloads.


    Read More
  • Netcat The Powershell Version

    calendar Apr 27, 2026 · attack.command-and-control attack.execution attack.t1095 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Adversaries may use a non-application layer protocol for communication between host and C2 server or among infected hosts within a network


    Read More
  • Classes Autorun Keys Modification

    calendar Apr 27, 2026 · attack.privilege-escalation attack.persistence attack.t1547.001  ·
    Share on: twitter facebook linkedin copy

    Detects modification of Windows Registry Classes keys used for persistence. Adversaries modify these autostart extensibility points (ASEP) to execute malicious code when file types are opened or actions are performed. Various legitimate software also uses these keys. Currently, this rule only filters out known legitimate software paths, thus it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.


    Read More
  • Office Autorun Keys Modification

    calendar Apr 27, 2026 · attack.privilege-escalation attack.persistence attack.t1547.001  ·
    Share on: twitter facebook linkedin copy

    Detects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened. There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive. Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.


    Read More
  • Office Macro File Creation

    calendar Apr 27, 2026 · attack.initial-access attack.t1566.001  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a new office macro files on the systems


    Read More
  • Outlook Security Settings Updated - Registry

    calendar Apr 27, 2026 · attack.persistence attack.t1137  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the registry values related to outlook security settings


    Read More
  • Potential Persistence Via Visual Studio Tools for Office

    calendar Apr 27, 2026 · attack.t1137.006 attack.persistence  ·
    Share on: twitter facebook linkedin copy

    Detects persistence via Visual Studio Tools for Office (VSTO) add-ins in Office applications.


    Read More
  • Service Reconnaissance Via Wmic.EXE

    calendar Apr 27, 2026 · attack.execution attack.t1047  ·
    Share on: twitter facebook linkedin copy

    An adversary might use WMI to check if a certain remote service is running on a remote device. When the test completes, a service information will be displayed on the screen if it exists. A common feedback message is that "No instance(s) Available" if the service queried is not running. A common error message is "Node - (provided IP or default) ERROR Description =The RPC server is unavailable" if the provided remote host is unreachable


    Read More
  • PUA - Memory Dump Mount Via MemProcFS

    calendar Apr 27, 2026 · attack.credential-access attack.t1003 attack.t1003.001 attack.t1003.004 attack.t1003.002  ·
    Share on: twitter facebook linkedin copy

    Detects execution of MemProcFS a memory forensics tool with the '-device' parameter. MemProcFS mounts physical memory as a virtual file system, allowing direct access to process memory and system structures. Threat actors were seen abusing this utility to mount memory dumps and then extract sensitive information from processes like LSASS or extract registry hives to obtain credentials, LSA secrets, SAM data, and cached domain credentials. MemProcFS usage that is not part of authorized forensic analysis should be treated as suspicious and warrants further investigation.


    Read More
  • New Okta User Created

    calendar Apr 27, 2026 · attack.credential-access  ·
    Share on: twitter facebook linkedin copy

    Detects new user account creation


    Read More
  • Okta 2023 Breach Indicator Of Compromise

    calendar Apr 27, 2026 · attack.credential-access detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects new user account creation or activation with specific names related to the Okta Support System 2023 breach. This rule can be enhanced by filtering out known and legitimate username used in your environnement.


    Read More
  • Okta Admin Role Assigned to an User or Group

    calendar Apr 27, 2026 · attack.privilege-escalation attack.persistence attack.t1098.003  ·
    Share on: twitter facebook linkedin copy

    Detects when an the Administrator role is assigned to an user or group.


    Read More
  • Okta Admin Role Assignment Created

    calendar Apr 27, 2026 · attack.persistence  ·
    Share on: twitter facebook linkedin copy

    Detects when a new admin role assignment is created. Which could be a sign of privilege escalation or persistence


    Read More
  • Okta API Token Created

    calendar Apr 27, 2026 · attack.persistence  ·
    Share on: twitter facebook linkedin copy

    Detects when a API token is created


    Read More
  • Okta API Token Revoked

    calendar Apr 27, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when a API Token is revoked.


    Read More
  • Okta Application Modified or Deleted

    calendar Apr 27, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an application is modified or deleted.


    Read More
  • Okta Application Sign-On Policy Modified or Deleted

    calendar Apr 27, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an application Sign-on Policy is modified or deleted.


    Read More
  • Okta FastPass Phishing Detection

    calendar Apr 27, 2026 · attack.initial-access attack.t1566  ·
    Share on: twitter facebook linkedin copy

    Detects when Okta FastPass prevents a known phishing site.


    Read More
  • Okta Identity Provider Created

    calendar Apr 27, 2026 · attack.privilege-escalation attack.persistence attack.t1098.001  ·
    Share on: twitter facebook linkedin copy

    Detects when a new identity provider is created for Okta.


    Read More
  • Okta Network Zone Deactivated or Deleted

    calendar Apr 27, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an Network Zone is Deactivated or Deleted.


    Read More
  • Okta Policy Modified or Deleted

    calendar Apr 27, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an Okta policy is modified or deleted.


    Read More
  • Okta Policy Rule Modified or Deleted

    calendar Apr 27, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when an Policy Rule is Modified or Deleted.


    Read More
  • Okta Security Threat Detected

    calendar Apr 27, 2026 · attack.command-and-control  ·
    Share on: twitter facebook linkedin copy

    Detects when an security threat is detected in Okta.


    Read More
  • Okta Suspicious Activity Reported by End-user

    calendar Apr 27, 2026 · attack.resource-development attack.t1586.003  ·
    Share on: twitter facebook linkedin copy

    Detects when an Okta end-user reports activity by their account as being potentially suspicious.


    Read More
  • Okta Unauthorized Access to App

    calendar Apr 27, 2026 · attack.impact  ·
    Share on: twitter facebook linkedin copy

    Detects when unauthorized access to app occurs.


    Read More
  • Okta User Account Locked Out

    calendar Apr 27, 2026 · attack.impact attack.t1531  ·
    Share on: twitter facebook linkedin copy

    Detects when an user account is locked out.


    Read More
  • Potential Okta Password in AlternateID Field

    calendar Apr 27, 2026 · attack.credential-access attack.t1552  ·
    Share on: twitter facebook linkedin copy

    Detects when a user has potentially entered their password into the username field, which will cause the password to be retained in log files.


    Read More
  • HackTool - NetExec Execution

    calendar Apr 23, 2026 · attack.discovery attack.t1018 attack.lateral-movement attack.t1021  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the hacktool NetExec. NetExec (formerly CrackMapExec) is a widely used post-exploitation tool designed for Active Directory penetration testing and network enumeration In enterprise environments, the use of NetExec is considered suspicious or potentially malicious because it enables attackers to enumerate hosts, exploit network services, and move laterally across systems. Threat actors and red teams commonly use NetExec to identify vulnerable systems, harvest credentials, and execute commands remotely.


    Read More
  • HackTool - NetExec File Indicators

    calendar Apr 23, 2026 · attack.execution attack.lateral-movement attack.discovery attack.t1021.002 attack.t1059.005  ·
    Share on: twitter facebook linkedin copy

    Detects file creation events indicating NetExec (nxc.exe) execution on the local machine. NetExec is a PyInstaller-bundled binary that extracts its embedded data files to a "_MEI" directory under the Temp folder upon execution. Files dropped under the "\nxc" sub-directory of that extraction path are unique to NetExec and serve as reliable on-disk indicators of execution. NetExec (formerly CrackMapExec) is a widely used post-exploitation and lateral movement tool used for Active Directory enumeration, credential harvesting, and remote code execution.


    Read More
  • Notepad++ Updater DNS Query to Uncommon Domains

    calendar Apr 21, 2026 · attack.collection attack.credential-access attack.t1195.002 attack.initial-access attack.t1557  ·
    Share on: twitter facebook linkedin copy

    Detects when the Notepad++ updater (gup.exe) makes DNS queries to domains that are not part of the known legitimate update infrastructure. This could indicate potential exploitation of the updater mechanism or suspicious network activity that warrants further investigation.


    Read More
  • Uncommon File Created by Notepad++ Updater Gup.EXE

    calendar Apr 21, 2026 · attack.collection attack.credential-access attack.t1195.002 attack.initial-access attack.t1557  ·
    Share on: twitter facebook linkedin copy

    Detects when the Notepad++ updater (gup.exe) creates files in suspicious or uncommon locations. This could indicate potential exploitation of the updater component to deliver unwanted malware or unwarranted files.


    Read More
  • OpenCanary - Host Port Scan (SYN Scan)

    calendar Apr 20, 2026 · attack.discovery attack.t1046  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an OpenCanary node has been targeted by a SYN port scan.


    Read More
  • OpenCanary - NMAP FIN Scan

    calendar Apr 20, 2026 · attack.discovery attack.t1046  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an OpenCanary node has been targeted by a NMAP FIN Scan


    Read More
  • OpenCanary - NMAP NULL Scan

    calendar Apr 20, 2026 · attack.discovery attack.t1046  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an OpenCanary node has been targeted by a NMAP NULL Scan


    Read More
  • OpenCanary - NMAP OS Scan

    calendar Apr 20, 2026 · attack.discovery attack.t1046  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an OpenCanary node has been targeted by a NMAP OS Scan


    Read More
  • OpenCanary - NMAP XMAS Scan

    calendar Apr 20, 2026 · attack.discovery attack.t1046  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an OpenCanary node has been targeted by a NMAP XMAS Scan


    Read More
  • OpenCanary - RDP New Connection Attempt

    calendar Apr 20, 2026 · attack.initial-access attack.lateral-movement attack.persistence attack.t1133 attack.t1021.001  ·
    Share on: twitter facebook linkedin copy

    Detects instances where an RDP service on an OpenCanary node has had a connection attempt.


    Read More
  • Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation

    calendar Apr 1, 2026 · attack.privilege-escalation attack.t1068 cve.2025-32463 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463. This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations. When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment, potentially leading to arbitrary code execution and privilege escalation.


    Read More
  • BPFDoor Abnormal Process ID or Lock File Accessed

    calendar Apr 1, 2026 · attack.execution attack.t1106 attack.t1059  ·
    Share on: twitter facebook linkedin copy

    detects BPFDoor .lock and .pid files access in temporary file storage facility


    Read More
  • LiteLLM / TeamPCP Supply Chain Attack Indicators

    calendar Apr 1, 2026 · attack.initial-access attack.t1195.002 attack.collection attack.t1560.001 attack.persistence attack.privilege-escalation attack.t1543.002 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects process executions related to the backdoored versions of LiteLLM (v1.82.7 or v1.82.8). In March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP. The malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.


    Read More
  • TeamPCP LiteLLM Supply Chain Attack Persistence Indicators

    calendar Apr 1, 2026 · attack.persistence attack.privilege-escalation attack.t1543.002 attack.initial-access attack.t1195.002 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of specific persistence files as observed in the LiteLLM PyPI supply chain attack. In March 2026, a supply chain attack was discovered involving the popular open-source LLM framework LiteLLM by Threat Actor TeamPCP. The malicious package harvests every credential on the system, encrypts and exfiltrates them, and installs a persistent C2 backdoor.


    Read More
  • Security Support Provider (SSP) Added to LSA Configuration

    calendar Apr 1, 2026 · attack.privilege-escalation attack.persistence attack.t1547.005  ·
    Share on: twitter facebook linkedin copy

    Detects the addition of a SSP to the registry. Upon a reboot or API call, SSP DLLs gain access to encrypted and plaintext passwords stored in Windows.


    Read More
  • Axios NPM Compromise File Creation Indicators - Linux

    calendar Apr 1, 2026 · attack.initial-access attack.t1195.002 attack.command-and-control attack.t1105 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.


    Read More
  • Axios NPM Compromise File Creation Indicators - MacOS

    calendar Apr 1, 2026 · attack.initial-access attack.t1195.002 attack.command-and-control attack.t1105 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects file creation events linked to the Axios NPM supply chain compromise on macOS devices. Axios is a popular JavaScript HTTP client. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper.


    Read More
  • Axios NPM Compromise File Creation Indicators - Windows

    calendar Apr 1, 2026 · attack.initial-access attack.t1195.002 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects file creation events linked to the Axios NPM supply chain compromise. Axios is a popular JavaScript HTTP client. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. The dropper contacted a C2 server, delivered platform-specific payloads, deleted itself, and replaced package.json to evade detection. The attack used cscript.exe (VBScript), curl.exe (C2), and PowerShell masquerading as Windows Terminal.


    Read More
  • Axios NPM Compromise Malicious C2 Domain DNS Query

    calendar Apr 1, 2026 · attack.command-and-control attack.t1071.001 attack.t1568 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects DNS queries for the malicious C2 domain associated with the plain-crypto-js/Axios npm package supply chain compromise. On March 30, 2026, malicious versions (1.14.1, 0.30.4) were published to npm, injecting a dependency (plain-crypto-js@4.2.1) that executed a postinstall script as a cross-platform RAT dropper. This detection detects endpoints attempting to resolve the attacker's C2 domain (sfrclak.com) used for command and control communication.


    Read More
  • PUA - TruffleHog Execution

    calendar Mar 29, 2026 · attack.discovery attack.credential-access attack.t1083 attack.t1552.001  ·
    Share on: twitter facebook linkedin copy

    Detects execution of TruffleHog, a tool used to search for secrets in different platforms like Git, Jira, Slack, SharePoint, etc. that could be used maliciously. While it is a legitimate tool, intended for use in CI pipelines and security assessments, It was observed in the Shai-Hulud malware campaign targeting npm packages to steal sensitive information.


    Read More
  • Script Interpreter Spawning Credential Scanner - Linux

    calendar Mar 29, 2026 · attack.credential-access attack.t1552 attack.execution attack.collection attack.t1005 attack.t1059.004  ·
    Share on: twitter facebook linkedin copy

    Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.


    Read More
  • Script Interpreter Spawning Credential Scanner - Windows

    calendar Mar 29, 2026 · attack.credential-access attack.t1552 attack.collection attack.execution attack.t1005 attack.t1059.007  ·
    Share on: twitter facebook linkedin copy

    Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks). This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.


    Read More
  • Shai-Hulud 2.0 Malicious NPM Package Installation

    calendar Mar 29, 2026 · attack.initial-access attack.execution attack.t1195.002 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the command-line installation of specific malicious npm packages and versions associated with the Shai-Hulud 2.0 supply chain attack.


    Read More
  • Shai-Hulud 2.0 Malicious NPM Package Installation - Linux

    calendar Mar 29, 2026 · attack.initial-access attack.execution attack.t1195.002 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the command-line installation of specific malicious npm packages and versions associated with the Shai-Hulud 2.0 supply chain attack.


    Read More
  • Shai-Hulud Malicious Bun Execution

    calendar Mar 29, 2026 · attack.t1195.002 attack.t1203 attack.execution attack.initial-access detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of bun_environment.js via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a setup_bun.js script to install the Bun runtime if not present, and then executes the malicious bun_environment.js payload.


    Read More
  • Shai-Hulud Malicious Bun Execution - Linux

    calendar Mar 29, 2026 · attack.t1195.002 attack.t1203 attack.execution attack.initial-access detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of bun_environment.js via the Bun runtime, a behavior associated with the Shai-Hulud "Second Coming" NPM supply chain attack. The malware uses a setup_bun.js script to install the Bun runtime if not present, and then executes the malicious bun_environment.js payload.


    Read More
  • Shai-Hulud Malicious GitHub Workflow Creation

    calendar Mar 29, 2026 · attack.persistence attack.credential-access attack.t1552.001 attack.collection attack.t1119 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects creation of shai-hulud-workflow.yml file associated with Shai Hulud worm targeting NPM supply chain attack that exfiltrates GitHub secrets


    Read More
  • Shai-Hulud Malware Indicators - Linux

    calendar Mar 29, 2026 · attack.execution attack.t1059 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential Shai-Hulud malware indicators based on specific command line arguments associated with its execution.


    Read More
  • Shai-Hulud Malware Indicators - Windows

    calendar Mar 29, 2026 · attack.execution attack.t1059 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects potential Shai-Hulud malware indicators based on specific command line arguments associated with its execution.


    Read More
  • HackTool - WSASS Execution

    calendar Mar 19, 2026 · attack.credential-access attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects execution of WSASS, a tool used to dump LSASS memory on Windows systems by leveraging WER's (Windows Error Reporting) WerFaultSecure.EXE to bypass PPL (Protected Process Light) protections.


    Read More
  • System Language Discovery via Reg.Exe

    calendar Mar 1, 2026 · attack.discovery attack.t1614.001  ·
    Share on: twitter facebook linkedin copy

    Detects the usage of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.


    Read More
  • CodeIntegrity - Unmet Signing Level Requirements By File Under Validation

    calendar Mar 1, 2026 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects attempted file load events that did not meet the signing level requirements. It often means the file's signature is revoked or a signature with the Lifetime Signing EKU has expired. This event is best correlated with EID 3089 to determine the error of the validation.


    Read More
  • Non Interactive PowerShell Process Spawned

    calendar Mar 1, 2026 · attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects non-interactive PowerShell activity by looking at the "powershell" process with a non-user GUI process such as "explorer.exe" as a parent.


    Read More
  • OpenEDR Spawning Command Shell

    calendar Feb 28, 2026 · attack.execution attack.t1059.003 attack.lateral-movement attack.t1021.004 attack.command-and-control attack.t1219  ·
    Share on: twitter facebook linkedin copy

    Detects the OpenEDR ssh-shellhost.exe spawning a command shell (cmd.exe) or PowerShell with PTY (pseudo-terminal) capabilities. This may indicate remote command execution through OpenEDR's remote management features, which could be legitimate administrative activity or potential abuse of the remote access tool. Threat actors may leverage OpenEDR's remote shell capabilities to execute commands on compromised systems, facilitating lateral movement or other command-and-control operations.


    Read More
  • Potentially Suspicious File Creation by OpenEDR's ITSMService

    calendar Feb 28, 2026 · attack.command-and-control attack.t1105 attack.lateral-movement attack.t1570 attack.t1219  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of potentially suspicious files by OpenEDR's ITSMService process. The ITSMService is responsible for remote management operations and can create files on the system through the Process Explorer or file management features. While legitimate for IT operations, creation of executable or script files could indicate unauthorized file uploads, data staging, or malicious file deployment.


    Read More
  • BloodHound Collection Files

    calendar Feb 28, 2026 · attack.discovery attack.t1087.001 attack.t1087.002 attack.t1482 attack.t1069.001 attack.t1069.002 attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects default file names outputted by the BloodHound collection tool SharpHound


    Read More
  • Suspicious Child Process of SolarWinds WebHelpDesk

    calendar Feb 13, 2026 · attack.initial-access attack.t1190 cve.2025-26399 cve.2025-40536 cve.2025-40551 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child processes spawned by SolarWinds WebHelpDesk (WHD) application, which may indicate exploitation activity leveraging RCE vulnerabilities such as CVE-2025-40551, CVE-2025-40536, or CVE-2025-26399


    Read More
  • Suspicious Child Process of Notepad++ Updater - GUP.Exe

    calendar Feb 4, 2026 · attack.collection attack.credential-access attack.t1195.002 attack.initial-access attack.t1557  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child process creation by the Notepad++ updater process (gup.exe). This could indicate potential exploitation of the updater component to deliver unwanted malware.


    Read More
  • Direct Autorun Keys Modification

    calendar Jan 29, 2026 · attack.privilege-escalation attack.persistence attack.t1547.001  ·
    Share on: twitter facebook linkedin copy

    Detects direct modification of autostart extensibility point (ASEP) in registry using reg.exe.


    Read More
  • Modify User Shell Folders Startup Value

    calendar Jan 29, 2026 · attack.persistence attack.privilege-escalation attack.t1547.001  ·
    Share on: twitter facebook linkedin copy

    Detect modification of the User Shell Folders registry values for Startup or Common Startup which could indicate persistence attempts. Attackers may modify User Shell Folders registry keys to point to malicious executables or scripts that will be executed during startup. This technique is often used to maintain persistence on a compromised system by ensuring that the malicious payload is executed automatically.


    Read More
  • DNS Query to External Service Interaction Domains

    calendar Jan 24, 2026 · attack.initial-access attack.t1190 attack.reconnaissance attack.t1595.002  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious DNS queries to external service interaction domains often used for out-of-band interactions after successful RCE


    Read More
  • PUA - Kernel Driver Utility (KDU) Execution

    calendar Jan 24, 2026 · attack.persistence attack.privilege-escalation attack.t1543.003  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Kernel Driver Utility (KDU) tool. KDU can be used to bypass driver signature enforcement and load unsigned or malicious drivers into the Windows kernel. Potentially allowing for privilege escalation, persistence, or evasion of security controls.


    Read More
  • Capabilities Discovery - Linux

    calendar Jan 24, 2026 · attack.discovery attack.t1083  ·
    Share on: twitter facebook linkedin copy

    Detects usage of "getcap" binary. This is often used during recon activity to determine potential binaries that can be abused as GTFOBins or other.


    Read More
  • Local System Accounts Discovery - Linux

    calendar Jan 5, 2026 · attack.discovery attack.t1087.001  ·
    Share on: twitter facebook linkedin copy

    Detects enumeration of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.


    Read More
  • Curl Web Request With Potential Custom User-Agent

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "curl.exe" with a potential custom "User-Agent". Attackers can leverage this to download or exfiltrate data via "curl" to a domain that only accept specific "User-Agent" strings


    Read More
  • File Download From IP URL Via Curl.EXE

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects file downloads directly from IP address URL using curl.exe


    Read More
  • Insecure Proxy/DOH Transfer Via Curl.EXE

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "curl.exe" with the "insecure" flag over proxy or DOH.


    Read More
  • Insecure Transfer Via Curl.EXE

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "curl.exe" with the "--insecure" flag.


    Read More
  • Local File Read Using Curl.EXE

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "curl.exe" with the "file://" protocol handler in order to read local files.


    Read More
  • Potential Cookies Session Hijacking

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "curl.exe" with the "-c" flag in order to save cookie data.


    Read More
  • Suspicious File Download From File Sharing Domain Via Curl.EXE

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious file download from file sharing domains using curl.exe


    Read More
  • Suspicious File Download From IP Via Curl.EXE

    calendar Dec 25, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious file downloads directly from IP addresses using curl.exe


    Read More
  • AppLocker Prevented Application or Script from Running

    calendar Dec 24, 2025 · attack.execution attack.t1204.002 attack.t1059.001 attack.t1059.003 attack.t1059.005 attack.t1059.006 attack.t1059.007  ·
    Share on: twitter facebook linkedin copy

    Detects when AppLocker prevents the execution of an Application, DLL, Script, MSI, or Packaged-App from running.


    Read More
  • LSASS Process Crashed - Application

    calendar Dec 24, 2025 · attack.credential-access attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects Windows error reporting events where the process that crashed is LSASS (Local Security Authority Subsystem Service). This could be the cause of a provoked crash by techniques such as Lsass-Shtinkering to dump credentials.


    Read More
  • Suspicious ArcSOC.exe Child Process

    calendar Dec 21, 2025 · attack.execution attack.t1059 attack.t1203  ·
    Share on: twitter facebook linkedin copy

    Detects script interpreters, command-line tools, and similar suspicious child processes of ArcSOC.exe. ArcSOC.exe is the process name which hosts ArcGIS Server REST services. If an attacker compromises an ArcGIS Server system and uploads a malicious Server Object Extension (SOE), they can send crafted requests to the corresponding service endpoint and remotely execute code from the ArcSOC.exe process.


    Read More
  • Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder

    calendar Dec 12, 2025 · attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.


    Read More
  • Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location

    calendar Dec 12, 2025 · attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.


    Read More
  • Potentially Suspicious File Download From File Sharing Domain Via PowerShell.EXE

    calendar Dec 12, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious file downloads from file sharing domains using PowerShell.exe


    Read More
  • Suspicious File Download From File Sharing Domain Via Wget.EXE

    calendar Dec 12, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects potentially suspicious file downloads from file sharing domains using wget.exe


    Read More
  • Malicious PowerShell Commandlets - PoshModule

    calendar Dec 10, 2025 · attack.execution attack.discovery attack.t1482 attack.t1087 attack.t1087.001 attack.t1087.002 attack.t1069.001 attack.t1069.002 attack.t1069 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Commandlet names from well-known PowerShell exploitation frameworks


    Read More
  • Malicious PowerShell Commandlets - ProcessCreation

    calendar Dec 10, 2025 · attack.execution attack.discovery attack.t1482 attack.t1087 attack.t1087.001 attack.t1087.002 attack.t1069.001 attack.t1069.002 attack.t1069 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Commandlet names from well-known PowerShell exploitation frameworks


    Read More
  • Malicious PowerShell Commandlets - ScriptBlock

    calendar Dec 10, 2025 · attack.execution attack.discovery attack.t1482 attack.t1087 attack.t1087.001 attack.t1087.002 attack.t1069.001 attack.t1069.002 attack.t1069 attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects Commandlet names from well-known PowerShell exploitation frameworks


    Read More
  • Malicious PowerShell Scripts - FileCreation

    calendar Dec 10, 2025 · attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of known offensive powershell scripts used for exploitation


    Read More
  • Malicious PowerShell Scripts - PoshModule

    calendar Dec 10, 2025 · attack.execution attack.t1059.001  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of known offensive powershell scripts used for exploitation or reconnaissance


    Read More
  • Linux Suspicious Child Process from Node.js - React2Shell

    calendar Dec 10, 2025 · attack.execution attack.t1059 attack.initial-access attack.t1190 detection.emerging-threats cve.2025-55182  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child processes spawned from Node.js server processes on Linux systems, potentially indicating remote code execution exploitation such as CVE-2025-55182 (React2Shell). This rule particularly looks for exploitation of vulnerability on Node.js Servers where attackers abuse Node.js child_process module to execute arbitrary system commands. When execSync() or exec() is used, the command line often includes a shell invocation followed by suspicious commands or scripts (e.g., /bin/sh -c ). For other methods, the Image field will show the spawned process directly.


    Read More
  • Windows Suspicious Child Process from Node.js - React2Shell

    calendar Dec 10, 2025 · attack.execution attack.t1059 attack.initial-access attack.t1190 detection.emerging-threats cve.2025-55182  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious child processes started by Node.js server processes on Windows, which may indicate exploitation of vulnerabilities like CVE-2025-55182 (React2Shell). Attackers can abuse the Node.js 'child_process' module to run system commands or scripts using methods such as spawn(), exec(), execFile(), fork(), or execSync(). If execSync() or exec() is used in the exploit, the command line often shows a shell (e.g., cmd.exe /d /s /c ...) running a suspicious command unless other shells are explicitly invoked. For other methods, the spawned process appears directly in the Image field unless a shell is explicitly used.


    Read More
  • Potential Malicious Usage of CloudTrail System Manager

    calendar Dec 9, 2025 · attack.privilege-escalation attack.initial-access attack.t1566 attack.t1566.002  ·
    Share on: twitter facebook linkedin copy

    Detect when System Manager successfully executes commands against an instance.


    Read More
  • Potentially Suspicious EventLog Recon Activity Using Log Query Utilities

    calendar Dec 9, 2025 · attack.credential-access attack.discovery attack.t1552 attack.t1087  ·
    Share on: twitter facebook linkedin copy

    Detects execution of different log query utilities and commands to search and dump the content of specific event logs or look for specific event IDs. This technique is used by threat actors in order to extract sensitive information from events logs such as usernames, IP addresses, hostnames, etc.


    Read More
  • Startup Folder File Write

    calendar Dec 9, 2025 · attack.privilege-escalation attack.persistence attack.t1547.001  ·
    Share on: twitter facebook linkedin copy

    A General detection for files being created in the Windows startup directory. This could be an indicator of persistence.


    Read More
  • Wow6432Node CurrentVersion Autorun Keys Modification

    calendar Dec 9, 2025 · attack.privilege-escalation attack.persistence attack.t1547.001  ·
    Share on: twitter facebook linkedin copy

    Detects modification of autostart extensibility point (ASEP) in registry.


    Read More
  • CredUI.DLL Loaded By Uncommon Process

    calendar Dec 9, 2025 · attack.credential-access attack.collection attack.t1056.002  ·
    Share on: twitter facebook linkedin copy

    Detects loading of "credui.dll" and related DLLs by an uncommon process. Attackers might leverage this DLL for potential use of "CredUIPromptForCredentials" or "CredUnPackAuthenticationBufferW".


    Read More
  • Desktop.INI Created by Uncommon Process

    calendar Dec 9, 2025 · attack.privilege-escalation attack.persistence attack.t1547.009  ·
    Share on: twitter facebook linkedin copy

    Detects unusual processes accessing desktop.ini, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.


    Read More
  • GUI Input Capture - macOS

    calendar Dec 9, 2025 · attack.collection attack.credential-access attack.t1056.002  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to use system dialog prompts to capture user credentials


    Read More
  • Audio Capture

    calendar Dec 8, 2025 · attack.collection attack.t1123  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to record audio using the arecord and ecasound utilities.


    Read More
  • Clipboard Collection of Image Data with Xclip Tool

    calendar Dec 8, 2025 · attack.collection attack.t1115  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to collect image data stored in the clipboard from users with the usage of xclip tool. Xclip has to be installed. Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.


    Read More
  • Clipboard Collection with Xclip Tool - Auditd

    calendar Dec 8, 2025 · attack.collection attack.t1115  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to collect data stored in the clipboard from users with the usage of xclip tool. Xclip has to be installed. Highly recommended using rule on servers, due to high usage of clipboard utilities on user workstations.


    Read More
  • Creation Of An User Account

    calendar Dec 8, 2025 · attack.t1136.001 attack.persistence  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of a new user account. Such accounts may be used for persistence that do not require persistent remote access tools to be deployed on the system.


    Read More
  • Credentials In Files - Linux

    calendar Dec 8, 2025 · attack.credential-access attack.t1552.001  ·
    Share on: twitter facebook linkedin copy

    Detecting attempts to extract passwords with grep


    Read More
  • Data Compressed

    calendar Dec 8, 2025 · attack.exfiltration attack.collection attack.t1560.001  ·
    Share on: twitter facebook linkedin copy

    An adversary may compress data (e.g., sensitive documents) that is collected prior to exfiltration in order to make it portable and minimize the amount of data sent over the network.


    Read More
  • Data Exfiltration with Wget

    calendar Dec 8, 2025 · attack.exfiltration attack.t1048.003  ·
    Share on: twitter facebook linkedin copy

    Detects attempts to post the file with the usage of wget utility. The adversary can bypass the permission restriction with the misconfigured sudo permission for wget utility which could allow them to read files like /etc/shadow.


    Read More
  • Linux Network Service Scanning - Auditd

    calendar Dec 8, 2025 · attack.discovery attack.t1046  ·
    Share on: twitter facebook linkedin copy

    Detects enumeration of local or remote network services.


    Read More
  • Loading of Kernel Module via Insmod

    calendar Dec 8, 2025 · attack.persistence attack.privilege-escalation attack.t1547.006  ·
    Share on: twitter facebook linkedin copy

    Detects loading of kernel modules with insmod command. Loadable Kernel Modules (LKMs) are pieces of code that can be loaded and unloaded into the kernel upon demand. Adversaries may use LKMs to obtain persistence within the system or elevate the privileges.


    Read More
  • Network Sniffing - Linux

    calendar Dec 8, 2025 · attack.credential-access attack.discovery attack.t1040  ·
    Share on: twitter facebook linkedin copy

    Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.


    Read More
  • Overwriting the File with Dev Zero or Null

    calendar Dec 8, 2025 · attack.impact attack.t1485  ·
    Share on: twitter facebook linkedin copy

    Detects overwriting (effectively wiping/deleting) of a file.


    Read More
  • Possible Coin Miner CPU Priority Param

    calendar Dec 8, 2025 · attack.privilege-escalation attack.t1068  ·
    Share on: twitter facebook linkedin copy

    Detects command line parameter very often used with coin miners


    Read More
  • Potential Abuse of Linux Magic System Request Key

    calendar Dec 8, 2025 · attack.execution attack.t1059.004 attack.impact attack.t1529 attack.t1489 attack.t1499  ·
    Share on: twitter facebook linkedin copy

    Detects the potential abuse of the Linux Magic SysRq (System Request) key by adversaries with root or sufficient privileges to silently manipulate or destabilize a system. By writing to /proc/sysrq-trigger, they can crash the system, kill processes, or disrupt forensic analysis—all while bypassing standard logging. Though intended for recovery and debugging, SysRq can be misused as a stealthy post-exploitation tool. It is controlled via /proc/sys/kernel/sysrq or permanently through /etc/sysctl.conf.


    Read More
  • Program Executions in Suspicious Folders

    calendar Dec 8, 2025 · attack.t1587 attack.t1584 attack.resource-development  ·
    Share on: twitter facebook linkedin copy

    Detects program executions in suspicious non-program folders related to malware or hacking activity


    Read More
  • Screen Capture with Import Tool

    calendar Dec 8, 2025 · attack.collection attack.t1113  ·
    Share on: twitter facebook linkedin copy

    Detects adversary creating screen capture of a desktop with Import Tool. Highly recommended using rule on servers, due to high usage of screenshot utilities on user workstations. ImageMagick must be installed.


    Read More
  • Screen Capture with Xwd

    calendar Dec 8, 2025 · attack.collection attack.t1113  ·
    Share on: twitter facebook linkedin copy

    Detects adversary creating screen capture of a full with xwd. Highly recommended using rule on servers, due high usage of screenshot utilities on user workstations


    Read More
  • Service Reload or Start - Linux

    calendar Dec 8, 2025 · attack.privilege-escalation attack.persistence attack.t1543.002  ·
    Share on: twitter facebook linkedin copy

    Detects the start, reload or restart of a service.


    Read More
  • Special File Creation via Mknod Syscall

    calendar Dec 8, 2025 · attack.privilege-escalation attack.persistence attack.t1543.003  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the mknod syscall to create special files (e.g., character or block devices). Attackers or malware might use mknod to create fake devices, interact with kernel interfaces, or establish covert channels in Linux systems. Monitoring the use of mknod is important because this syscall is rarely used by legitimate applications, and it can be abused to bypass file system restrictions or create backdoors.


    Read More
  • Split A File Into Pieces - Linux

    calendar Dec 8, 2025 · attack.exfiltration attack.t1030  ·
    Share on: twitter facebook linkedin copy

    Detection use of the command "split" to split files into parts and possible transfer.


    Read More
  • Suspicious Commands Linux

    calendar Dec 8, 2025 · attack.execution attack.t1059.004  ·
    Share on: twitter facebook linkedin copy

    Detects relevant commands often related to malware or hacking activity


    Read More
  • Suspicious History File Operations - Linux

    calendar Dec 8, 2025 · attack.credential-access attack.t1552.003  ·
    Share on: twitter facebook linkedin copy

    Detects commandline operations on shell history files


    Read More
  • System and Hardware Information Discovery

    calendar Dec 8, 2025 · attack.discovery attack.t1082  ·
    Share on: twitter facebook linkedin copy

    Detects system information discovery commands


    Read More
  • System Info Discovery via Sysinfo Syscall

    calendar Dec 8, 2025 · attack.discovery attack.t1057 attack.t1082  ·
    Share on: twitter facebook linkedin copy

    Detects use of the sysinfo system call in Linux, which provides a snapshot of key system statistics such as uptime, load averages, memory usage, and the number of running processes. Malware or reconnaissance tools might leverage sysinfo to fingerprint the system - gathering data to determine if it's a viable target.


    Read More
  • System Owner or User Discovery - Linux

    calendar Dec 8, 2025 · attack.discovery attack.t1033  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of host or user discovery utilities such as "whoami", "hostname", "id", etc. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.


    Read More
  • System Shutdown/Reboot - Linux

    calendar Dec 8, 2025 · attack.impact attack.t1529  ·
    Share on: twitter facebook linkedin copy

    Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.


    Read More
  • Systemd Service Creation

    calendar Dec 8, 2025 · attack.privilege-escalation attack.persistence attack.t1543.002  ·
    Share on: twitter facebook linkedin copy

    Detects a creation of systemd services which could be used by adversaries to execute malicious code.


    Read More
  • Unix Shell Configuration Modification

    calendar Dec 8, 2025 · attack.privilege-escalation attack.persistence attack.t1546.004  ·
    Share on: twitter facebook linkedin copy

    Detect unix shell configuration modification. Adversaries may establish persistence through executing malicious commands triggered when a new shell is opened.


    Read More
  • Webshell Remote Command Execution

    calendar Dec 8, 2025 · attack.persistence attack.t1505.003  ·
    Share on: twitter facebook linkedin copy

    Detects possible command execution by web application/web shell


    Read More
  • Github Self-Hosted Runner Execution

    calendar Dec 3, 2025 · attack.command-and-control attack.t1102.002 attack.t1071  ·
    Share on: twitter facebook linkedin copy

    Detects GitHub self-hosted runners executing workflows on local infrastructure that could be abused for persistence and code execution. Shai-Hulud is an npm supply chain worm targeting CI/CD environments. It installs runners on compromised systems to maintain access after credential theft, leveraging their access to secrets and internal networks.


    Read More
  • DNS Query by Finger Utility

    calendar Nov 27, 2025 · attack.command-and-control attack.t1071.004 attack.execution attack.t1059.003  ·
    Share on: twitter facebook linkedin copy

    Detects DNS queries made by the finger utility, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such DNS queries can also help identify potential malicious infrastructure used by threat actors for command and control (C2) communication.


    Read More
  • FileFix - Command Evidence in TypedPaths

    calendar Nov 27, 2025 · attack.execution attack.t1204.004  ·
    Share on: twitter facebook linkedin copy

    Detects commonly-used chained commands and strings in the most recent 'url' value of the 'TypedPaths' key, which could be indicative of a user being targeted by the FileFix technique.


    Read More
  • Finger.EXE Execution

    calendar Nov 27, 2025 · attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the "finger.exe" utility. Finger.EXE or "TCPIP Finger Command" is an old utility that is still present on modern Windows installation. It Displays information about users on a specified remote computer (typically a UNIX computer) that is running the finger service or daemon. Due to the old nature of this utility and the rareness of machines having the finger service. Any execution of "finger.exe" can be considered "suspicious" and worth investigating.


    Read More
  • Network Connection Initiated via Finger.EXE

    calendar Nov 27, 2025 · attack.command-and-control attack.t1071.004 attack.execution attack.t1059.003  ·
    Share on: twitter facebook linkedin copy

    Detects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such network connections can also help identify potential malicious infrastructure used by threat actors


    Read More
  • Potential ClickFix Execution Pattern - Registry

    calendar Nov 27, 2025 · attack.execution attack.t1204.001  ·
    Share on: twitter facebook linkedin copy

    Detects potential ClickFix malware execution patterns by monitoring registry modifications in RunMRU keys containing HTTP/HTTPS links. ClickFix is known to be distributed through phishing campaigns and uses techniques like clipboard hijacking and fake CAPTCHA pages. Through the fakecaptcha pages, the adversary tricks users into opening the Run dialog box and pasting clipboard-hijacked content, such as one-liners that execute remotely hosted malicious files or scripts.


    Read More
  • Suspicious FileFix Execution Pattern

    calendar Nov 27, 2025 · attack.execution attack.t1204.004  ·
    Share on: twitter facebook linkedin copy

    Detects suspicious FileFix execution patterns where users are tricked into running malicious commands through browser file upload dialog manipulation. This attack typically begins when users visit malicious websites impersonating legitimate services or news platforms, which may display fake CAPTCHA challenges or direct instructions to open file explorer and paste clipboard content. The clipboard content usually contains commands that download and execute malware, such as information stealing tools.


    Read More
  • Grixba Malware Reconnaissance Activity

    calendar Nov 27, 2025 · attack.reconnaissance attack.t1595.001 attack.discovery attack.t1046 detection.emerging-threats  ·
    Share on: twitter facebook linkedin copy

    Detects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations. This tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.


    Read More
  • Add Port Monitor Persistence in Registry

    calendar Nov 26, 2025 · attack.privilege-escalation attack.persistence attack.t1547.010  ·
    Share on: twitter facebook linkedin copy

    Adversaries may use port monitors to run an attacker supplied DLL during system boot for persistence or privilege escalation. A port monitor can be set through the AddMonitor API call to set a DLL to be loaded at startup.


    Read More
  • Advanced IP Scanner - File Event

    calendar Nov 26, 2025 · attack.discovery attack.t1046  ·
    Share on: twitter facebook linkedin copy

    Detects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.


    Read More
  • Anydesk Temporary Artefact

    calendar Nov 26, 2025 · attack.command-and-control attack.t1219.002  ·
    Share on: twitter facebook linkedin copy

    An adversary may use legitimate desktop support and remote access software, such as Team Viewer, Go2Assist, LogMein, AmmyyAdmin, etc, to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. Remote access tools like VNC, Ammyy, and Teamviewer are used frequently when compared with other legitimate software commonly used by adversaries. (Citation: Symantec Living off the Land)


    Read More
  • Bypass UAC Using Event Viewer

    calendar Nov 26, 2025 · attack.privilege-escalation attack.persistence attack.t1547.010  ·
    Share on: twitter facebook linkedin copy

    Bypasses User Account Control using Event Viewer and a relevant Windows Registry modification


    Read More
  • Change Default File Association Via Assoc

    calendar Nov 26, 2025 · attack.privilege-escalation attack.persistence attack.t1546.001  ·
    Share on: twitter facebook linkedin copy

    Detects file association changes using the builtin "assoc" command. When a file is opened, the default program used to open the file (also called the file association or handler) is checked. File association selections are stored in the Windows Registry and can be edited by users, administrators, or programs that have Registry access or by administrators using the built-in assoc utility. Applications can modify the file association for a given file extension to call an arbitrary program when a file with the given extension is opened.


    Read More
  • Chromium Browser Headless Execution To Mockbin Like Site

    calendar Nov 26, 2025 · attack.execution  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of a Chromium based browser process with the "headless" flag and a URL pointing to the mockbin.org service (which can be used to exfiltrate data).


    Read More
  • Chromium Browser Instance Executed With Custom Extension

    calendar Nov 26, 2025 · attack.persistence attack.t1176.001  ·
    Share on: twitter facebook linkedin copy

    Detects a Chromium based browser process with the 'load-extension' flag to start a instance with a custom extension


    Read More
  • Console CodePage Lookup Via CHCP

    calendar Nov 26, 2025 · attack.discovery attack.t1614.001  ·
    Share on: twitter facebook linkedin copy

    Detects use of chcp to look up the system locale value as part of host discovery


    Read More
  • Creation of a Local Hidden User Account by Registry

    calendar Nov 26, 2025 · attack.persistence attack.t1136.001  ·
    Share on: twitter facebook linkedin copy

    Sysmon registry detection of a local hidden user account.


    Read More
  • Cred Dump Tools Dropped Files

    calendar Nov 26, 2025 · attack.credential-access attack.t1003.001 attack.t1003.002 attack.t1003.003 attack.t1003.004 attack.t1003.005  ·
    Share on: twitter facebook linkedin copy

    Files with well-known filenames (parts of credential dump software or files produced by them) creation


    Read More
  • Data Copied To Clipboard Via Clip.EXE

    calendar Nov 26, 2025 · attack.collection attack.t1115  ·
    Share on: twitter facebook linkedin copy

    Detects the execution of clip.exe in order to copy data to the clipboard. Adversaries may collect data stored in the clipboard from users copying information within or between applications.


    Read More
  • Default RDP Port Changed to Non Standard Port

    calendar Nov 26, 2025 · attack.privilege-escalation attack.persistence attack.t1547.010  ·
    Share on: twitter facebook linkedin copy

    Detects changes to the default RDP port. Remote desktop is a common feature in operating systems. It allows a user to log into a remote system using an interactive session with a graphical user interface. Microsoft refers to its implementation of the Remote Desktop Protocol (RDP) as Remote Desktop Services (RDS).


    Read More
  • Deleted Data Overwritten Via Cipher.EXE

    calendar Nov 26, 2025 · attack.impact attack.t1485  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "cipher" built-in utility in order to overwrite deleted data from disk. Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and remote drives


    Read More
  • DirLister Execution

    calendar Nov 26, 2025 · attack.discovery attack.t1083  ·
    Share on: twitter facebook linkedin copy

    Detect the usage of "DirLister.exe" a utility for quickly listing folder or drive contents. It was seen used by BlackCat ransomware to create a list of accessible directories and files.


    Read More
  • Domain Trust Discovery Via Dsquery

    calendar Nov 26, 2025 · attack.discovery attack.t1482  ·
    Share on: twitter facebook linkedin copy

    Detects execution of "dsquery.exe" for domain trust discovery


    Read More
  • DriverQuery.EXE Execution

    calendar Nov 26, 2025 · attack.discovery  ·
    Share on: twitter facebook linkedin copy

    Detect usage of the "driverquery" utility. Which can be used to perform reconnaissance on installed drivers


    Read More
  • File And SubFolder Enumeration Via Dir Command

    calendar Nov 26, 2025 · attack.discovery attack.t1217  ·
    Share on: twitter facebook linkedin copy

    Detects usage of the "dir" command part of Windows CMD with the "/S" command line flag in order to enumerate files in a specified directory and all subdirectories.


    Read More
  • File Download From Browser Process Via Inline URL

    calendar Nov 26, 2025 · attack.command-and-control attack.t1105  ·
    Share on: twitter facebook linkedin copy

    Detects execution of a browser process with a URL argument pointing to a file with a potentially interesting extension. This can be abused to download arbitrary files or to hide from the user for example by launching the browser in a minimized state.


    Read More
  • File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell

    calendar Nov 26, 2025 · attack.discovery attack.t1135  ·
    Share on: twitter facebook linkedin copy

    Detects the initial execution of "cmd.exe" which spawns "explorer.exe" with the appropriate command line arguments for opening the "My Computer" folder.


    Read More
  • Findstr GPP Passwords

    calendar Nov 26, 2025 · attack.credential-access attack.t1552.006  ·
    Share on: twitter facebook linkedin copy

    Look for the encrypted cpassword value within Group Policy Preference files on the Domain Controller. This value can be decrypted with gpp-decrypt.


    Read More
  • Gpresult Display Group Policy Information

    calendar Nov 26, 2025 · attack.discovery attack.t1615  ·
    Share on: twitter facebook linkedin copy

    Detects cases in which a user uses the built-in Windows utility gpresult to display the Resultant Set of Policy (RSoP) information


    Read More
  • IE Change Domain Zone

    calendar Nov 26, 2025 · attack.persistence attack.t1137  ·
    Share on: twitter facebook linkedin copy

    Hides the file extension through modification of the registry


    Read More
  • LSASS Process Memory Dump Creation Via Taskmgr.EXE

    calendar Nov 26, 2025 · attack.credential-access attack.t1003.001  ·
    Share on: twitter facebook linkedin copy

    Detects the creation of an "lsass.dmp" file by the taskmgr process. This indicates a manual dumping of the LSASS.exe process memory using Windows Task Manager.


    Read More
  • LSASS Process Reconnaissance Via Findstr.EXE

    calendar Nov 26, 2025 · attack.credential-access attack.t1552.006  ·
    Share on: twitter