EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Windows Defender Service Disabled - Registry

Detects when an attacker or tool disables the Windows Defender service (WinDefend) via the registry

T1685
Sigmahigh

Windows Defender Submit Sample Feature Disabled

Detects disabling of the "Automatic Sample Submission" feature of Windows Defender.

T1685
Sigmalow

Windows Defender Threat Detected

Detects actions taken by Windows Defender malware detection engines

T1059
Sigmahigh

Windows Defender Threat Detection Service Disabled

Detects when the "Windows Defender Threat Protection" service is disabled.

T1685
Sigmamedium

Windows Defender Threat Severity Default Action Modified

Detects modifications or creations of Windows Defender's default threat action settings based on severity to 'allow' or take 'no action'. This is a highly suspicious configuration change that effectively disables Defender's ability to automatically mitigate threats of a certain severity level, allowing malicious software to run unimpeded. An attacker might use this technique to bypass defenses before executing payloads.

T1685
Sigmahigh

Windows Defender Virus Scanning Feature Disabled

Detects disabling of the Windows Defender virus scanning feature

T1685
Sigmahigh

Windows Event Auditing Disabled

Detects scenarios where system auditing (i.e.: Windows event log auditing) is disabled. This may be used in a scenario where an entity would want to bypass local logging to evade detection when Windows event logging is enabled and reviewed. Also, it is recommended to turn off "Local Group Policy Object Processing" via GPO, which will make sure that Active Directory GPOs take precedence over local/edited computer policies via something such as "gpedit.msc". Please note, that disabling "Local Group Policy Object Processing" may cause an issue in scenarios of one off specific GPO modifications - however, it is recommended to perform these modifications in Active Directory anyways.

T1685.001
Sigmalow

Windows Event Log Access Tampering Via Registry

Detects changes to the Windows EventLog channel permission values. It focuses on changes to the Security Descriptor Definition Language (SDDL) string, as modifications to these values can restrict access to specific users or groups, potentially aiding in defense evasion by controlling who can view or modify a event log channel. Upon execution, the user shouldn't be able to access the event log channel via the event viewer or via utilities such as "Get-EventLog" or "wevtutil".

T1547.001T1112
Sigmahigh

Windows EventLog Autologger Session Registry Modification Via CommandLine

Detects attempts to disable Windows EventLog autologger sessions via registry modification. The AutoLogger event tracing session records events that occur early in the operating system boot process. Applications and device drivers can use the AutoLogger session to capture traces before the user logs in. Adversaries may disable these sessions to evade detection and prevent security monitoring of early boot activities and system events.

T1685.001
Sigmahigh

Windows Filtering Platform Blocked Connection From EDR Agent Binary

Detects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents. Adversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.

T1685
Sigmahigh

Windows Firewall Disabled via PowerShell

Detects attempts to disable the Windows Firewall using PowerShell

T1685
Sigmamedium

Windows Firewall Profile Disabled

Detects when a user disables the Windows Firewall via a Profile to help evade defense.

T1686.003
Sigmamedium

Windows Firewall Settings Have Been Changed

Detects activity when the settings of the Windows firewall have been changed

T1686.003
Sigmalow

Windows Hotfix Updates Reconnaissance Via Wmic.EXE

Detects the execution of wmic with the "qfe" flag in order to obtain information about installed hotfix updates on the system. This is often used by pentester and attacker enumeration scripts

T1047
Sigmamedium

Windows Hypervisor Enforced Code Integrity Disabled

Detects changes to the HypervisorEnforcedCodeIntegrity registry key and the "Enabled" value being set to 0 in order to disable the Hypervisor Enforced Code Integrity feature. This allows an attacker to load unsigned and untrusted code to be run in the kernel

T1685
Sigmahigh

Windows Internet Hosted WebDav Share Mount Via Net.EXE

Detects when an internet hosted webdav share is mounted using the "net.exe" utility

T1021.002
Sigmahigh

Windows Kernel Debugger Execution

Detects execution of the Windows Kernel Debugger "kd.exe".

Sigmamedium

Windows LAPS Credential Dump From Entra ID

Detects when an account dumps the LAPS password from Entra ID.

T1098.005
Sigmahigh

Windows Mail App Mailbox Access Via PowerShell Script

Detects PowerShell scripts that try to access the default Windows MailApp MailBox. This indicates manipulation of or access to the stored emails of a user. E.g. this could be used by an attacker to exfiltrate or delete the content of the emails.

T1070.008
Sigmamedium

Windows MSIX Package Support Framework AI_STUBS Execution

Detects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'. This activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.

T1218T1553.005T1204.002
Sigmalow

Windows Network Access Suspicious desktop.ini Action

Detects unusual processes accessing desktop.ini remotely over network share, which can be leveraged to alter how Explorer displays a folder's content (i.e. renaming files) without changing them on disk.

T1547.009
Sigmamedium

Windows Pcap Drivers

Detects Windows Pcap driver installation based on a list of associated .sys files.

T1040
Sigmamedium

Windows PowerShell User Agent

Detects Windows PowerShell Web Access

T1071.001
Sigmamedium

Windows Processes Suspicious Parent Directory

Detect suspicious parent processes of well-known Windows processes

T1036.003T1036.005
Sigmalow
PreviousPage 134 of 137Next