EXPLORE

EXPLORE DETECTIONS

🔍
3,115 detections found

Binary Padding - Linux

Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.

T1027.001
Sigmahigh

Binary Padding - MacOS

Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.

T1027.001
Sigmahigh

Binary Proxy Execution Via Dotnet-Trace.EXE

Detects commandline arguments for executing a child process via dotnet-trace.exe

T1218
Sigmamedium

Bitbucket Audit Log Configuration Updated

Detects changes to the bitbucket audit log configuration.

T1562.001
Sigmamedium

Bitbucket Full Data Export Triggered

Detects when full data export is attempted.

T1213.003
Sigmahigh

Bitbucket Global Permission Changed

Detects global permissions change activity.

T1098
Sigmamedium

Bitbucket Global Secret Scanning Rule Deleted

Detects Bitbucket global secret scanning rule deletion activity.

T1562.001
Sigmamedium

Bitbucket Global SSH Settings Changed

Detects Bitbucket global SSH access configuration changes.

T1562.001T1021.004
Sigmamedium

Bitbucket Project Secret Scanning Allowlist Added

Detects when a secret scanning allowlist rule is added for projects.

T1562.001
Sigmalow

Bitbucket Secret Scanning Exempt Repository Added

Detects when a repository is exempted from secret scanning feature.

T1562.001
Sigmahigh

Bitbucket Secret Scanning Rule Deleted

Detects when secret scanning rule is deleted for the project or repository.

T1562.001
Sigmalow

Bitbucket Unauthorized Access To A Resource

Detects unauthorized access attempts to a resource.

T1586
Sigmacritical

Bitbucket Unauthorized Full Data Export Triggered

Detects when full data export is attempted an unauthorized user.

T1213.003T1586
Sigmacritical

Bitbucket User Details Export Attempt Detected

Detects user data export activity.

T1213T1082T1591.004
Sigmamedium

Bitbucket User Login Failure

Detects user authentication failure events. Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.

T1078.004T1110
Sigmamedium

Bitbucket User Login Failure Via SSH

Detects SSH user login access failures. Please note that this rule can be noisy and is recommended to use with correlation based on "author.name" field.

T1021.004T1110
Sigmamedium

Bitbucket User Permissions Export Attempt

Detects user permission data export attempt.

T1213T1082T1591.004
Sigmamedium

Bitlocker Key Retrieval

Monitor and alert for Bitlocker key retrieval.

T1078.004
Sigmamedium

BitLockerTogo.EXE Execution

Detects the execution of "BitLockerToGo.EXE". BitLocker To Go is BitLocker Drive Encryption on removable data drives. This feature includes the encryption of, USB flash drives, SD cards, External hard disk drives, Other drives that are formatted by using the NTFS, FAT16, FAT32, or exFAT file system. This is a rarely used application and usage of it at all is worth investigating. Malware such as Lumma stealer has been seen using this process as a target for process hollowing.

T1218
Sigmalow

BITS Transfer Job Download From Direct IP

Detects a BITS transfer job downloading file(s) from a direct IP address.

T1197
Sigmahigh

BITS Transfer Job Download From File Sharing Domains

Detects BITS transfer job downloading files from a file sharing domain.

T1197
Sigmahigh

BITS Transfer Job Download To Potential Suspicious Folder

Detects new BITS transfer job where the LocalName/Saved file is stored in a potentially suspicious location

T1197
Sigmahigh

BITS Transfer Job Downloading File Potential Suspicious Extension

Detects new BITS transfer job saving local files with potential suspicious extensions

T1197
Sigmamedium

BITS Transfer Job With Uncommon Or Suspicious Remote TLD

Detects a suspicious download using the BITS client from a FQDN that is unusual. Adversaries may abuse BITS jobs to persistently execute or clean up after malicious payloads.

T1197
Sigmamedium
PreviousPage 11 of 130Next