EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Suspicious Download from Office Domain

Detects suspicious ways to download files from Microsoft domains that are used to store attachments in Emails or OneNote documents

T1105T1608
Sigmahigh

Suspicious Download Via Certutil.EXE

Detects the execution of certutil with certain flags that allow the utility to download files.

T1027T1105
Sigmamedium

Suspicious Driver Install by pnputil.exe

Detects when a possible suspicious driver is being installed via pnputil.exe lolbin

T1547
Sigmamedium

Suspicious Driver/DLL Installation Via Odbcconf.EXE

Detects execution of "odbcconf" with the "INSTALLDRIVER" action where the driver doesn't contain a ".dll" extension. This is often used as a defense evasion method.

T1218.008
Sigmahigh

Suspicious Dropbox API Usage

Detects an executable that isn't dropbox but communicates with the Dropbox API

T1105T1567.002
Sigmahigh

Suspicious DumpMinitool Execution

Detects suspicious ways to use the "DumpMinitool.exe" binary

T1036T1003.001
Sigmahigh

Suspicious Electron Application Child Processes

Detects suspicious child processes of electron apps (teams, discord, slack, etc.). This could be a potential sign of ".asar" file tampering (See reference section for more information) or binary execution proxy through specific CLI arguments (see related rule)

Sigmamedium

Suspicious Email Delivered In Microsoft 365

Detects instances where an email, identified as malicious or suspicious by the Microsoft Defender for Office 365 (formerly ATP) engine, was delivered to a user's Inbox or Junk folder. It might indicate that a potential threat, such as a spearphishing attachment or links, has bypassed initial blocking mechanisms and reached an end-user, requiring further investigation and potential remediation.

T1566.001T1566.002
Sigmamedium

Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call

Detects suspicious base64 encoded and obfuscated "LOAD" keyword used in .NET "reflection.assembly"

T1059.001T1027
Sigmahigh

Suspicious Encoded PowerShell Command Line

Detects suspicious powershell process starts with base64 encoded commands (e.g. Emotet)

T1059.001
Sigmahigh

Suspicious Encoded Scripts in a WMI Consumer

Detects suspicious encoded payloads in WMI Event Consumers

T1047T1546.003
Sigmahigh

Suspicious Environment Variable Has Been Registered

Detects the creation of user-specific or system-wide environment variables via the registry. Which contains suspicious commands and strings

Sigmahigh

Suspicious Eventlog Clear

Detects usage of known powershell cmdlets such as "Clear-EventLog" to clear the Windows event logs

T1685.005
Sigmamedium

Suspicious Eventlog Clearing or Configuration Change Activity

Detects the clearing or configuration tampering of EventLog using utilities such as "wevtutil", "powershell" and "wmic". This technique were seen used by threat actors and ransomware strains in order to evade defenses.

T1685.005T1685.001
Sigmahigh

Suspicious Executable File Creation

Detect creation of suspicious executable file names. Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.

T1564
Sigmahigh

Suspicious Execution From Outlook Temporary Folder

Detects a suspicious program execution in Outlook temp folder

T1566.001
Sigmahigh

Suspicious Execution Location Of Wermgr.EXE

Detects suspicious Windows Error Reporting manager (wermgr.exe) execution location.

Sigmahigh

Suspicious Execution of Hostname

Use of hostname to get information

T1082
Sigmalow

Suspicious Execution of InstallUtil Without Log

Uses the .NET InstallUtil.exe application in order to execute image without log

Sigmamedium

Suspicious Execution of Powershell with Base64

Commandline to launch powershell with a base64 payload

T1059.001
Sigmamedium

Suspicious Execution Of Renamed Sysinternals Tools - Registry

Detects the creation of the "accepteula" key related to the Sysinternals tools being created from executables with the wrong name (e.g. a renamed Sysinternals tool)

T1588.002
Sigmahigh

Suspicious Execution of Shutdown

Use of the commandline to shutdown or reboot windows

T1529
Sigmamedium

Suspicious Execution of Shutdown to Log Out

Detects the rare use of the command line tool shutdown to logoff a user

T1529
Sigmamedium

Suspicious Execution of Systeminfo

Detects usage of the "systeminfo" command to retrieve information

T1082
Sigmalow
PreviousPage 108 of 137Next