EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Suspicious Process Created Via Wmic.EXE

Detects WMIC executing "process call create" with suspicious calls to processes such as "rundll32", "regsrv32", etc.

T1047
Sigmahigh

Suspicious Process Discovery With Get-Process

Get the processes that are running on the local computer.

T1057
Sigmalow

Suspicious Process Execution From Fake Recycle.Bin Folder

Detects process execution from a fake recycle bin folder, often used to avoid security solution.

Sigmahigh

Suspicious Process Masquerading As SvcHost.EXE

Detects a suspicious process that is masquerading as the legitimate "svchost.exe" by naming its binary "svchost.exe" and executing from an uncommon location. Adversaries often disguise their malicious binaries by naming them after legitimate system processes like "svchost.exe" to evade detection.

T1036.005
Sigmahigh

Suspicious Process Parents

Detects suspicious parent processes that should not have any children or should only have a single possible child program

T1036
Sigmahigh

Suspicious Process Patterns NTDS.DIT Exfil

Detects suspicious process patterns used in NTDS.DIT exfiltration

T1003.003
Sigmahigh

Suspicious Process Start Locations

Detects suspicious process run from unusual locations

T1036
Sigmamedium

Suspicious Processes Spawned by Java.EXE

Detects suspicious processes spawned from a Java host process which could indicate a sign of exploitation (e.g. log4j)

Sigmahigh

Suspicious Processes Spawned by WinRM

Detects suspicious processes including shells spawnd from WinRM host process

T1190
Sigmahigh

Suspicious PROCEXP152.sys File Created In TMP

Detects the creation of the PROCEXP152.sys file in the application-data local temporary folder. This driver is used by Sysinternals Process Explorer but also by KDU (https://github.com/hfiref0x/KDU) or Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU.

T1685
Sigmamedium

Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE

Detects Netsh command execution that whitelists a program located in a suspicious location in the Windows Firewall

T1686.003
Sigmahigh

Suspicious Program Names

Detects suspicious patterns in program names or folders that are often found in malicious samples or hacktools

T1059
Sigmahigh

Suspicious Provlaunch.EXE Child Process

Detects suspicious child processes of "provlaunch.exe" which might indicate potential abuse to proxy execution.

T1218
Sigmahigh

Suspicious PsExec Execution

detects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if attacker uses a different psexec client other than sysinternal one

T1021.002
Sigmahigh

Suspicious PsExec Execution - Zeek

detects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if attacker uses a different psexec client other than sysinternal one

T1021.002
Sigmahigh

Suspicious Query of MachineGUID

Use of reg to get MachineGuid information

T1082
Sigmalow

Suspicious RASdial Activity

Detects suspicious process related to rasdial.exe

T1059
Sigmamedium

Suspicious RDP Redirect Using TSCON

Detects a suspicious RDP session redirect using tscon.exe

T1563.002T1021.001
Sigmahigh

Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet

Detects suspicious reconnaissance command line activity on Windows systems using the PowerShell Get-LocalGroupMember Cmdlet

T1087.001
Sigmamedium

Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS

Detects execution of the built-in script located in "C:\Windows\System32\gatherNetworkInfo.vbs". Which can be used to gather information about the target machine

T1615T1059.005
Sigmahigh

Suspicious Recursive Takeown

Adversaries can interact with the DACLs using built-in Windows commands takeown which can grant adversaries higher permissions on specific files and folders

T1222.001
Sigmamedium

Suspicious Redirection to Local Admin Share

Detects a suspicious output redirection to the local admins share, this technique is often found in malicious scripts or hacktool stagers

T1048
Sigmahigh

Suspicious Reg Add BitLocker

Detects suspicious addition to BitLocker related registry keys via the reg.exe utility

T1486
Sigmahigh

Suspicious Registry Modification From ADS Via Regini.EXE

Detects the import of an alternate data stream with regini.exe, regini.exe can be used to modify registry keys.

T1112
Sigmahigh
PreviousPage 115 of 137Next