EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

System Restore Registry Modification via CommandLine

Detects system restore registry modification via command line, which can be used by adversaries to disable system restore on the computer.

T1490
Sigmahigh

System Scripts Autorun Keys Modification

Detects modification of autostart extensibility point (ASEP) in registry.

T1547.001
Sigmamedium

System Shutdown/Reboot - Linux

Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.

T1529
Sigmainformational

System Shutdown/Reboot - MacOs

Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.

T1529
Sigmainformational

Systemd Service Creation

Detects a creation of systemd services which could be used by adversaries to execute malicious code.

T1543.002
Sigmamedium

T1047 Wmiprvse Wbemcomn DLL Hijack

Detects a threat actor creating a file named `wbemcomn.dll` in the `C:\Windows\System32\wbem\` directory over the network for a WMI DLL Hijack scenario.

T1047T1021.002
Sigmahigh

TacticalRMM Service Installation

Detects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.

T1219.002
Sigmamedium

Tamper Windows Defender - PSClassic

Attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.

T1685
Sigmahigh

Tamper Windows Defender - ScriptBlockLogging

Detects PowerShell scripts attempting to disable scheduled scanning and other parts of Windows Defender ATP or set default actions to allow.

T1685
Sigmahigh

Tamper Windows Defender Remove-MpPreference

Detects attempts to remove Windows Defender configurations using the 'MpPreference' cmdlet

T1685
Sigmahigh

Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging

Detects attempts to remove Windows Defender configuration using the 'MpPreference' cmdlet

T1685
Sigmahigh

Tamper With Sophos AV Registry Keys

Detects tamper attempts to sophos av functionality via registry key modification

T1685
Sigmahigh

Tap Driver Installation

Well-known TAP software installation. Possible preparation for data exfiltration using tunnelling techniques

T1048
Sigmamedium

Tap Driver Installation - Security

Detects the installation of a well-known TAP driver service. This could be a sign of potential preparation for data exfiltration using tunnelling techniques.

T1048
Sigmalow

Tap Installer Execution

Well-known TAP software installation. Possible preparation for data exfiltration using tunneling techniques

T1048
Sigmamedium

Task Scheduler DLL Loaded By Application Located In Potentially Suspicious Location

Detects the loading of the "taskschd.dll" module from a process that located in a potentially suspicious or uncommon directory. The loading of this DLL might indicate that the application have the capability to create a scheduled task via the "Schedule.Service" COM object. Investigation of the loading application and its behavior is required to determining if its malicious.

T1053.005
Sigmalow

Taskkill Symantec Endpoint Protection

Detects one of the possible scenarios for disabling Symantec Endpoint Protection. Symantec Endpoint Protection antivirus software services incorrectly implement the protected service mechanism. As a result, the NT AUTHORITY/SYSTEM user can execute the taskkill /im command several times ccSvcHst.exe /f, thereby killing the process belonging to the service, and thus shutting down the service.

T1685
Sigmahigh

Taskmgr as LOCAL_SYSTEM

Detects the creation of taskmgr.exe process in context of LOCAL_SYSTEM

T1036
Sigmahigh

Tasks Folder Evasion

The Tasks folder in system32 and syswow64 are globally writable paths. Adversaries can take advantage of this and load or influence any script hosts or ANY .NET Application in Tasks to load and execute a custom assembly into cscript, wscript, regsvr32, mshta, eventvwr

T1574.001
Sigmahigh

TeamViewer Domain Query By Non-TeamViewer Application

Detects DNS queries to a TeamViewer domain only resolved by a TeamViewer client by an image that isn't named TeamViewer (sometimes used by threat actors for obfuscation)

T1219.002
Sigmamedium

TeamViewer Log File Deleted

Detects the deletion of the TeamViewer log files which may indicate an attempt to destroy forensic evidence

T1070.004
Sigmalow

TeamViewer Remote Session

Detects the creation of log files during a TeamViewer remote session

T1219.002
Sigmamedium

Telegram API Access

Detects suspicious requests to Telegram API without the usual Telegram User-Agent

T1071.001T1102.002
Sigmamedium

Telegram Bot API Request

Detects suspicious DNS queries to api.telegram.org used by Telegram Bots of any kind

T1102.002
Sigmamedium
PreviousPage 122 of 137Next