EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

SQL Client Tools PowerShell Session Detection

This rule detects execution of a PowerShell code through the sqltoolsps.exe utility, which is included in the standard set of utilities supplied with the Microsoft SQL Server Management studio. Script blocks are not logged in this case, so this utility helps to bypass protection mechanisms based on the analysis of these logs.

T1059.001T1127
Sigmamedium

SQL Injection Strings In URI

Detects potential SQL injection attempts via GET requests in access logs.

T1190
Sigmahigh

SQLite Chromium Profile Data DB Access

Detect usage of the "sqlite" binary to query databases in Chromium-based browsers for potential data stealing.

T1539T1555.003T1005
Sigmahigh

SQLite Firefox Profile Data DB Access

Detect usage of the "sqlite" binary to query databases in Firefox and other Gecko-based browsers for potential data stealing.

T1539T1005
Sigmahigh

Stale Accounts In A Privileged Role

Identifies when an account hasn't signed in during the past n number of days.

T1078
Sigmahigh

Standard User In High Privileged Group

Detect standard users login that are part of high privileged groups such as the Administrator group

Sigmamedium

Start of NT Virtual DOS Machine

Ntvdm.exe allows the execution of 16-bit Windows applications on 32-bit Windows operating systems, as well as the execution of both 16-bit and 32-bit DOS applications

Sigmamedium

Start Windows Service Via Net.EXE

Detects the usage of the "net.exe" command to start a service using the "start" flag

T1569.002
Sigmalow

Startup Folder File Write

A General detection for files being created in the Windows startup directory. This could be an indicator of persistence.

T1547.001
Sigmamedium

Startup Item File Created - MacOS

Detects the creation of a startup item plist file, that automatically get executed at boot initialization to establish persistence. Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items.

T1037.005
Sigmalow

Startup/Logon Script Added to Group Policy Object

Detects the modification of Group Policy Objects (GPO) to add a startup/logon script to users or computer objects.

T1484.001T1547
Sigmamedium

Steganography Extract Files with Steghide

Detects extraction of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.

T1027.003
Sigmalow

Steganography Hide Files with Steghide

Detects embedding of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.

T1027.003
Sigmalow

Steganography Hide Zip Information in Picture File

Detects appending of zip file to image

T1027.003
Sigmalow

Steganography Unzip Hidden Information From Picture File

Detects extracting of zip file from image file

T1027.003
Sigmalow

Sticky Key Like Backdoor Execution

Detects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen

T1546.008
Sigmacritical

Sticky Key Like Backdoor Usage - Registry

Detects the usage and installation of a backdoor that uses an option to register a malicious debugger for built-in tools that are accessible in the login screen

T1546.008
Sigmacritical

Stop Windows Service Via Net.EXE

Detects the stopping of a Windows service via the "net" utility.

T1489
Sigmalow

Stop Windows Service Via PowerShell Stop-Service

Detects the stopping of a Windows service via the PowerShell Cmdlet "Stop-Service"

T1489
Sigmalow

Stop Windows Service Via Sc.EXE

Detects the stopping of a Windows service via the "sc.exe" utility

T1489
Sigmalow

Successful Account Login Via WMI

Detects successful logon attempts performed with WMI

T1047
Sigmalow

Successful Authentications From Countries You Do Not Operate Out Of

Detect successful authentications from countries you do not operate out of.

T1078.004T1110
Sigmamedium

Successful IIS Shortname Fuzzing Scan

When IIS uses an old .Net Framework it's possible to enumerate folders with the symbol "~"

T1190
Sigmamedium

Successful MSIX/AppX Package Installation

Detects successful MSIX/AppX package installations on Windows systems by monitoring EventID 854 in the Microsoft-Windows-AppXDeployment-Server/Operational log. While most installations are legitimate, this can help identify unauthorized or suspicious package installations. It is crucial to monitor such events as threat actors may exploit MSIX/AppX packages to deliver and execute malicious payloads.

T1204.002
Sigmalow
PreviousPage 104 of 137Next