EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Shell Open Registry Keys Manipulation

Detects the shell open key manipulation (exefile and ms-settings) used for persistence and the pattern of UAC Bypass using fodhelper.exe, computerdefaults.exe, slui.exe via registry keys (e.g. UACMe 33 or 62)

T1548.002T1546.001
Sigmahigh

Shell Process Spawned by Java.EXE

Detects shell spawned from Java host process, which could be a sign of exploitation (e.g. log4j exploitation)

Sigmamedium

Shell32 DLL Execution in Suspicious Directory

Detects shell32.dll executing a DLL in a suspicious directory

T1218.011
Sigmahigh

Shellshock Expression

Detects shellshock expressions in log files

T1505.003
Sigmahigh

ShimCache Flush

Detects actions that clear the local ShimCache and remove forensic evidence

T1112
Sigmahigh

Sign-in Failure Due to Conditional Access Requirements Not Met

Define a baseline threshold for failed sign-ins due to Conditional Access failures

T1110T1078.004
Sigmahigh

Sign-In From Malware Infected IP

Indicates sign-ins from IP addresses infected with malware that is known to actively communicate with a bot server.

T1090
Sigmahigh

Sign-ins by Unknown Devices

Monitor and alert for Sign-ins by unknown devices from non-Trusted locations.

T1078.004
Sigmalow

Sign-ins from Non-Compliant Devices

Monitor and alert for sign-ins where the device was non-compliant.

T1078.004
Sigmahigh

Signed DLL Loaded With Missing PE Version Metadata

Detects the loading of a digitally signed DLL whose PE version-info resource is entirely missing. Legitimate signed DLLs from reputable vendors often carry populated metadata fields (Description, Company, Product, OriginalFileName, FileVersion). An attacker who signs a purpose-built or hollowed DLL with a stolen, mis-issued, or cheaply purchased code-signing certificate will often omit these fields, producing a valid signature with no accompanying version info. This pattern is observed in DLL side-loading, search-order hijacking, and certificate-abuse campaigns where signing is used purely to satisfy security-product trust checks. Hunting Hypothesis: - Investigate the signing certificate (issuer, subject, validity window, thumbprint) for disposable or recently issued CAs and cross-reference against known threat-actor certificates. - Examine the DLL's on-disk path relative to the loading process — paths outside standard system directories or inside application folders susceptible to search-order hijacking are high-priority leads. - Correlate with the parent process context; DLLs loaded into high-value targets such as lsass.exe, svchost.exe, or browser processes warrant immediate escalation. Note: The "selection_metadata_null" selection matches fields with a null value. Some backends may interpret null field conditions as "field does not exist" rather than "field has a null value", which would change the detection semantics. If your backend does not support or support null-value matching in different ways than expected, you may need to adjust the rule logic accordingly or remove the "selection_metadata_null" condition.

T1574.001
Sigmalow

Silence.EDA Detection

Detects Silence EmpireDNSAgent as described in the Group-IP report

T1059.001T1071.004T1572T1529G0091+1
Sigmacritical

Silenttrinity Stager Msbuild Activity

Detects a possible remote connections to Silenttrinity c2

T1127.001
Sigmahigh

Sliver C2 Default Service Installation

Detects known malicious service installation that appear in cases in which a Sliver implants execute the PsExec commands

T1543.003T1569.002
Sigmahigh

SMB Create Remote File Admin Share

Look for non-system accounts SMB accessing a file with write (0x2) access mask via administrative share (i.e C$).

T1021.002
Sigmahigh

SMB over QUIC Via Net.EXE

Detects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments.

T1570
Sigmamedium

SMB over QUIC Via PowerShell Script

Detects the mounting of Windows SMB shares over QUIC, which can be an unexpected event in some enterprise environments

T1570
Sigmamedium

SMB Spoolss Name Piped Usage

Detects the use of the spoolss named pipe over SMB. This can be used to trigger the authentication via NTLM of any machine that has the spoolservice enabled.

T1021.002
Sigmamedium

smbexec.py Service Installation

Detects the use of smbexec.py tool by detecting a specific service installation

T1021.002T1569.002
Sigmahigh

Source Code Enumeration Detection by Keyword

Detects source code enumeration that use GET requests by keyword searches in URL strings

T1083
Sigmamedium

Space After Filename - macOS

Detects attempts to masquerade as legitimate files by adding a space to the end of the filename.

T1036.006
Sigmalow

Special File Creation via Mknod Syscall

Detects usage of the `mknod` syscall to create special files (e.g., character or block devices). Attackers or malware might use `mknod` to create fake devices, interact with kernel interfaces, or establish covert channels in Linux systems. Monitoring the use of `mknod` is important because this syscall is rarely used by legitimate applications, and it can be abused to bypass file system restrictions or create backdoors.

T1543.003
Sigmalow

Split A File Into Pieces

Detection use of the command "split" to split files into parts and possible transfer.

T1030
Sigmalow

Split A File Into Pieces - Linux

Detection use of the command "split" to split files into parts and possible transfer.

T1030
Sigmalow

Spring Framework Exceptions

Detects suspicious Spring framework exceptions that could indicate exploitation attempts

T1190
Sigmamedium
PreviousPage 103 of 137Next