EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Suspicious ScreenSave Change by Reg.exe

Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension

T1546.002
Sigmamedium

Suspicious Screensaver Binary File Creation

Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension

T1546.002
Sigmamedium

Suspicious Scripting in a WMI Consumer

Detects suspicious commands that are related to scripting/powershell in WMI Event Consumers

T1059.005
Sigmahigh

Suspicious Serv-U Process Pattern

Detects a suspicious process pattern which could be a sign of an exploited Serv-U service

T1555
Sigmahigh

Suspicious Service Binary Directory

Detects a service binary running in a suspicious directory

T1202
Sigmahigh

Suspicious Service DACL Modification Via Set-Service Cmdlet

Detects suspicious DACL modifications via the "Set-Service" cmdlet using the "SecurityDescriptorSddl" flag (Only available with PowerShell 7) that can be used to hide services or make them unstopable

T1543.003
Sigmahigh

Suspicious Service DACL Modification Via Set-Service Cmdlet - PS

Detects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)

T1574.011
Sigmahigh

Suspicious Service Installation

Detects suspicious service installation commands

T1543.003
Sigmahigh

Suspicious Service Installation Script

Detects suspicious service installation scripts

T1543.003
Sigmahigh

Suspicious Service Installed

Detects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders. Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)

T1685
Sigmamedium

Suspicious Service Path Modification

Detects service path modification via the "sc" binary to a suspicious command or path

T1543.003
Sigmahigh

Suspicious Shell Open Command Registry Modification

Detects modifications to shell open registry keys that point to suspicious locations typically used by malware for persistence. Generally, modifications to the `*\shell\open\command` registry key can indicate an attempt to change the default action for opening files, and various UAC bypass or persistence techniques involve modifying these keys to execute malicious scripts or binaries.

T1548.002T1546.001
Sigmamedium

Suspicious ShellExec_RunDLL Call Via Ordinal

Detects suspicious call to the "ShellExec_RunDLL" exported function of SHELL32.DLL through the ordinal number to launch other commands. Adversary might only use the ordinal number in order to bypass existing detection that alert on usage of ShellExec_RunDLL on CommandLine.

T1218.011
Sigmahigh

Suspicious Shells Spawn by Java Utility Keytool

Detects suspicious shell spawn from Java utility keytool process (e.g. adselfservice plus exploitation)

Sigmahigh

Suspicious Shim Database Patching Activity

Detects installation of new shim databases that try to patch sections of known processes for potential process injection or persistence.

T1546.011
Sigmahigh

Suspicious SignIns From A Non Registered Device

Detects risky authentication from a non AD registered device without MFA being required.

T1078
Sigmahigh

Suspicious Space Characters in RunMRU Registry Path - ClickFix

Detects the occurrence of numerous space characters in RunMRU registry paths, which may indicate execution via phishing lures using clickfix techniques to hide malicious commands in the Windows Run dialog box from naked eyes.

T1204.004T1027.010
Sigmahigh

Suspicious Space Characters in TypedPaths Registry Path - FileFix

Detects the occurrence of numerous space characters in TypedPaths registry paths, which may indicate execution via phishing lures using file-fix techniques to hide malicious commands.

T1204.004T1027.010
Sigmahigh

Suspicious Speech Runtime Binary Child Process

Detects suspicious Speech Runtime Binary Execution by monitoring its child processes. Child processes spawned by SpeechRuntime.exe could indicate an attempt for lateral movement via COM & DCOM hijacking.

T1021.003T1218
Sigmahigh

Suspicious Splwow64 Without Params

Detects suspicious Splwow64.exe process without any command line parameters

T1202
Sigmahigh

Suspicious Spool Service Child Process

Detects suspicious print spool service (spoolsv.exe) child processes.

T1203T1068
Sigmahigh

Suspicious SQL Error Messages

Detects SQL error messages that indicate probing for an injection attack

T1190
Sigmahigh

Suspicious SQL Query

Detects suspicious SQL query keywrods that are often used during recon, exfiltration or destructive activities. Such as dropping tables and selecting wildcard fields

T1190T1505.001
Sigmamedium

Suspicious SSL Connection

Adversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.

T1573
Sigmalow
PreviousPage 117 of 137Next