EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Suspicious Plink Port Forwarding

Detects suspicious Plink tunnel port forwarding to a local port

T1572T1021.001
Sigmahigh

Suspicious Powercfg Execution To Change Lock Screen Timeout

Detects suspicious execution of 'Powercfg.exe' to change lock screen timeout

Sigmamedium

Suspicious PowerShell Download - PoshModule

Detects suspicious PowerShell download command

T1059.001
Sigmamedium

Suspicious PowerShell Download - Powershell Script

Detects suspicious PowerShell download command

T1059.001
Sigmamedium

Suspicious PowerShell Download and Execute Pattern

Detects suspicious PowerShell download patterns that are often used in malicious scripts, stagers or downloaders (make sure that your backend applies the strings case-insensitive)

T1059.001
Sigmahigh

Suspicious PowerShell Encoded Command Patterns

Detects PowerShell command line patterns in combincation with encoded commands that often appear in malware infection chains

T1059.001
Sigmahigh

Suspicious PowerShell Get Current User

Detects the use of PowerShell to identify the current logged user.

T1033
Sigmalow

Suspicious PowerShell IEX Execution Patterns

Detects suspicious ways to run Invoke-Execution using IEX alias

T1059.001
Sigmahigh

Suspicious PowerShell In Registry Run Keys

Detects potential PowerShell commands or code within registry run keys

T1547.001
Sigmamedium

Suspicious PowerShell Invocation From Script Engines

Detects suspicious powershell invocations from interpreters or unusual programs

T1059.001
Sigmamedium

Suspicious PowerShell Invocations - Generic

Detects suspicious PowerShell invocation command parameters

T1059.001
Sigmahigh

Suspicious PowerShell Invocations - Generic - PowerShell Module

Detects suspicious PowerShell invocation command parameters

T1059.001
Sigmahigh

Suspicious PowerShell Invocations - Specific

Detects suspicious PowerShell invocation command parameters

T1059.001
Sigmahigh

Suspicious PowerShell Invocations - Specific - PowerShell Module

Detects suspicious PowerShell invocation command parameters

T1059.001
Sigmahigh

Suspicious PowerShell Invocations - Specific - ProcessCreation

Detects suspicious PowerShell invocation command parameters

Sigmamedium

Suspicious PowerShell Mailbox Export to Share

Detects usage of the powerShell New-MailboxExportRequest Cmdlet to exports a mailbox to a remote or local share, as used in ProxyShell exploitations

Sigmacritical

Suspicious PowerShell Mailbox Export to Share - PS

Detects usage of the powerShell New-MailboxExportRequest Cmdlet to exports a mailbox to a remote or local share, as used in ProxyShell exploitations

Sigmacritical

Suspicious PowerShell Parameter Substring

Detects suspicious PowerShell invocation with a parameter substring

T1059.001
Sigmahigh

Suspicious PowerShell Parent Process

Detects a suspicious or uncommon parent processes of PowerShell

T1059.001
Sigmahigh

Suspicious PowerShell WindowStyle Option

Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden

T1564.003
Sigmamedium

Suspicious Printer Driver Empty Manufacturer

Detects a suspicious printer driver installation with an empty Manufacturer value

T1574
Sigmahigh

Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze

Detects process access events where WerFaultSecure accesses MsMpEng.exe with dbgcore.dll or dbghelp.dll in the call trace, indicating potential EDR freeze techniques. This technique leverages WerFaultSecure.exe running as a Protected Process Light (PPL) with WinTCB protection level to call MiniDumpWriteDump and suspend EDR/AV processes, allowing malicious activity to execute undetected during the suspension period.

T1685
Sigmahigh

Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs

Detects suspicious process access to LSASS.exe from processes located in uncommon locations with dbgcore.dll or dbghelp.dll in the call trace. These DLLs contain functions like MiniDumpWriteDump that can be abused for credential dumping purposes. While modern tools like Mimikatz have moved to using ntdll.dll, dbgcore.dll and dbghelp.dll are still used by basic credential dumping utilities and legacy tools for LSASS memory access and process suspension techniques.

T1003.001T1685
Sigmahigh

Suspicious Process By Web Server Process

Detects potentially suspicious processes being spawned by a web server process which could be the result of a successfully placed web shell or exploitation

T1505.003T1190
Sigmahigh
PreviousPage 114 of 137Next