EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Sysprep on AppData Folder

Detects suspicious sysprep process start with AppData folder as target (as used by Trojan Syndicasec in Thrip report by Symantec)

T1059
Sigmamedium

System and Hardware Information Discovery

Detects system information discovery commands

T1082
Sigmainformational

System Control Panel Item Loaded From Uncommon Location

Detects image load events of system control panel items (.cpl) from uncommon or non-system locations that may indicate DLL sideloading or other abuse techniques.

T1574.001
Sigmahigh

System Disk And Volume Reconnaissance Via Wmic.EXE

An adversary might use WMI to discover information about the system, such as the volume name, size, free space, and other disk information. This can be done using the 'wmic' command-line utility and has been observed being used by threat actors such as Volt Typhoon.

T1047T1082
Sigmamedium

System Drawing DLL Load

Detects processes loading "System.Drawing.ni.dll". This could be an indicator of potential Screen Capture.

T1113
Sigmalow

System File Execution Location Anomaly

Detects the execution of a Windows system binary that is usually located in the system folder from an uncommon location.

T1036
Sigmahigh

System Info Discovery via Sysinfo Syscall

Detects use of the sysinfo system call in Linux, which provides a snapshot of key system statistics such as uptime, load averages, memory usage, and the number of running processes. Malware or reconnaissance tools might leverage sysinfo to fingerprint the system - gathering data to determine if it's a viable target.

T1057T1082
Sigmalow

System Information Discovery

Detects system information discovery commands

T1082
Sigmainformational

System Information Discovery - Auditd

Detects System Information Discovery commands

T1082
Sigmalow

System Information Discovery Using Ioreg

Detects the use of "ioreg" which will show I/O Kit registry information. This process is used for system information discovery. It has been observed in-the-wild by calling this process directly or using bash and grep to look for specific strings.

T1082
Sigmamedium

System Information Discovery Using sw_vers

Detects the use of "sw_vers" for system information discovery

T1082
Sigmamedium

System Information Discovery Using System_Profiler

Detects the execution of "system_profiler" with specific "Data Types" that have been seen being used by threat actors and malware. It provides system hardware and software configuration information. This process is primarily used for system information discovery. However, "system_profiler" can also be used to determine if virtualization software is being run for defense evasion purposes.

T1082T1497.001
Sigmamedium

System Information Discovery via Registry Queries

Detects attempts to query system information directly from the Windows Registry.

T1082
Sigmalow

System Information Discovery Via Sysctl - MacOS

Detects the execution of "sysctl" with specific arguments that have been used by threat actors and malware. It provides system hardware information. This process is primarily used to detect and avoid virtualization and analysis environments.

T1497.001T1082
Sigmamedium

System Information Discovery Via Wmic.EXE

Detects the use of the WMI command-line (WMIC) utility to identify and display various system information, including OS, CPU, GPU, disk drive names, memory capacity, display resolution, baseboard, BIOS, and GPU driver products/versions.

T1082
Sigmalow

System Integrity Protection (SIP) Disabled

Detects the use of csrutil to disable the Configure System Integrity Protection (SIP). This technique is used in post-exploit scenarios.

T1518.001
Sigmamedium

System Integrity Protection (SIP) Enumeration

Detects the use of csrutil to view the Configure System Integrity Protection (SIP) status. This technique is used in post-exploit scenarios.

T1518.001
Sigmalow

System Language Discovery via Reg.Exe

Detects the usage of Reg.Exe to query system language settings. Attackers may discover the system language to determine the geographic location of victims, customize payloads for specific regions, or avoid targeting certain locales to evade detection.

T1614.001
Sigmamedium

System Network Connections Discovery - Linux

Detects usage of system utilities to discover system network connections

T1049
Sigmalow

System Network Connections Discovery - MacOs

Detects usage of system utilities to discover system network connections

T1049
Sigmainformational

System Network Connections Discovery Via Net.EXE

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.

T1049
Sigmalow

System Network Discovery - Linux

Detects enumeration of local network configuration

T1016
Sigmainformational

System Network Discovery - macOS

Detects enumeration of local network configuration

T1016
Sigmainformational

System Owner or User Discovery - Linux

Detects the execution of host or user discovery utilities such as "whoami", "hostname", "id", etc. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

T1033
Sigmalow
PreviousPage 121 of 137Next