EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Suspicious Regsvr32 Execution From Remote Share

Detects REGSVR32.exe to execute DLL hosted on remote shares

T1218.010
Sigmahigh

Suspicious Rejected SMB Guest Logon From IP

Detect Attempt PrintNightmare (CVE-2021-1675) Remote code execution in Windows Spooler Service

T1110.001
Sigmamedium

Suspicious Remote Child Process From Outlook

Detects a suspicious child process spawning from Outlook where the image is located in a remote location (SMB/WebDav shares).

T1059T1202
Sigmahigh

Suspicious Remote Logon with Explicit Credentials

Detects suspicious processes logging on with explicit credentials

T1078
Sigmamedium

Suspicious Renamed Comsvcs DLL Loaded By Rundll32

Detects rundll32 loading a renamed comsvcs.dll to dump process memory

T1003.001
Sigmahigh

Suspicious Response File Execution Via Odbcconf.EXE

Detects execution of "odbcconf" with the "-f" flag in order to load a response file with a non-".rsp" extension.

T1218.008
Sigmahigh

Suspicious Reverse Shell Command Line

Detects suspicious shell commands or program code that may be executed or used in command line to establish a reverse shell

T1059.004
Sigmahigh

Suspicious Run Key from Download

Detects the suspicious RUN keys created by software located in Download or temporary Outlook/Internet Explorer directories

T1547.001
Sigmahigh

Suspicious RunAs-Like Flag Combination

Detects suspicious command line flags that let the user set a target user and command as e.g. seen in PsExec-like tools

Sigmamedium

Suspicious Rundll32 Activity Invoking Sys File

Detects suspicious process related to rundll32 based on command line that includes a *.sys file as seen being used by UNC2452

T1218.011
Sigmahigh

Suspicious Rundll32 Execution With Image Extension

Detects the execution of Rundll32.exe with DLL files masquerading as image files

T1218.011
Sigmahigh

Suspicious Rundll32 Invoking Inline VBScript

Detects suspicious process related to rundll32 based on command line that invokes inline VBScript as seen being used by UNC2452

T1055
Sigmahigh

Suspicious Rundll32 Setupapi.dll Activity

setupapi.dll library provide InstallHinfSection function for processing INF files. INF file may contain instructions allowing to create values in the registry, modify files and install drivers. This technique could be used to obtain persistence via modifying one of Run or RunOnce registry keys, run process or use other DLLs chain calls (see references) InstallHinfSection function in setupapi.dll calls runonce.exe executable regardless of actual content of INF file.

T1218.011
Sigmamedium

Suspicious Runscripthelper.exe

Detects execution of powershell scripts via Runscripthelper.exe

T1059T1202
Sigmamedium

Suspicious Scan Loop Network

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system

T1059T1018
Sigmamedium

Suspicious Scheduled Task Creation

Detects suspicious scheduled task creation events. Based on attributes such as paths, commands line flags, etc.

T1053.005
Sigmahigh

Suspicious Scheduled Task Creation Involving Temp Folder

Detects the creation of scheduled tasks that involves a temporary folder and runs only once

T1053.005
Sigmahigh

Suspicious Scheduled Task Creation via Masqueraded XML File

Detects the creation of a scheduled task using the "-XML" flag with a file without the '.xml' extension. This behavior could be indicative of potential defense evasion attempt during persistence

T1036.005T1053.005
Sigmamedium

Suspicious Scheduled Task Name As GUID

Detects creation of a scheduled task with a GUID like name

T1053.005
Sigmamedium

Suspicious Scheduled Task Update

Detects update to a scheduled task event that contain suspicious keywords.

T1053.005
Sigmahigh

Suspicious Scheduled Task Write to System32 Tasks

Detects the creation of tasks from processes executed from suspicious locations

T1053
Sigmahigh

Suspicious Schtasks Execution AppData Folder

Detects the creation of a schtask that executes a file from C:\Users\<USER>\AppData\Local

T1053.005T1059.001
Sigmahigh

Suspicious Schtasks Schedule Type With High Privileges

Detects scheduled task creations or modification to be run with high privileges on a suspicious schedule type

T1053.005
Sigmamedium

Suspicious Schtasks Schedule Types

Detects scheduled task creations or modification on a suspicious schedule type

T1053.005
Sigmahigh
PreviousPage 116 of 137Next