EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

New File Association Using Exefile

Detects the abuse of the exefile handler in new file association. Used for bypass of security products.

Sigmahigh

New File Exclusion Added To Time Machine Via Tmutil - MacOS

Detects the addition of a new file or path exclusion to MacOS Time Machine via the "tmutil" utility. An adversary could exclude a path from Time Machine backups to prevent certain files from being backed up.

T1490
Sigmamedium

New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application

Detects the addition of a new rule to the Windows Firewall exception list for an application located in a potentially suspicious location.

T1686.003
Sigmahigh

New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE

Detects the addition of a new "Allow" firewall rule by the WMI process (WmiPrvSE.EXE). This can occur if an attacker leverages PowerShell cmdlets such as "New-NetFirewallRule", or directly uses WMI CIM classes such as "MSFT_NetFirewallRule".

T1686.003
Sigmamedium

New Firewall Rule Added Via Netsh.EXE

Detects the addition of a new rule to the Windows firewall via netsh

T1686.003S0246
Sigmamedium

New Generic Credentials Added Via Cmdkey.EXE

Detects usage of "cmdkey.exe" to add generic credentials. As an example, this can be used before connecting to an RDP session via command line interface.

T1003.005
Sigmamedium

New Github Organization Member Added

Detects when a new member is added or invited to a github organization.

T1136.003
Sigmainformational

New Kernel Driver Via SC.EXE

Detects creation of a new service (kernel driver) with the type "kernel"

T1543.003
Sigmamedium

New Kind of Network (NKN) Detection

NKN is a networking service using blockchain technology to support a decentralized network of peers. While there are legitimate uses for it, it can also be used as a C2 channel. This rule looks for a DNS request to the ma>

Sigmalow

New Kubernetes Service Account Created

Detects creation of new Kubernetes service account, which could indicate an attacker's attempt to persist within a cluster.

T1136
Sigmalow

New Module Module Added To IIS Server

Detects the addition of a new module to an IIS server.

T1685.001T1505.004
Sigmamedium

New Netsh Helper DLL Registered From A Suspicious Location

Detects changes to the Netsh registry key to add a new DLL value that is located on a suspicious location. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper

T1546.007
Sigmahigh

New Network ACL Entry Added

Detects that network ACL entries have been added to a route table which could indicate that new attack vectors have been opened up in the AWS account.

T1686.001
Sigmalow

New Network Route Added

Detects the addition of a new network route to a route table in AWS.

T1686.001
Sigmamedium

New Network Trace Capture Started Via Netsh.EXE

Detects the execution of netsh with the "trace" flag in order to start a network capture

T1040
Sigmamedium

New ODBC Driver Registered

Detects the registration of a new ODBC driver.

Sigmalow

New Okta User Created

Detects new user account creation

Sigmainformational

New or Renamed User Account with '$' Character

Detects the creation of a user with the "$" character. This can be used by attackers to hide a user or trick detection systems that lack the parsing mechanisms.

T1036
Sigmamedium

New Outlook Macro Created

Detects the creation of a macro file for Outlook.

T1137T1008T1546
Sigmamedium

New PDQDeploy Service - Client Side

Detects PDQDeploy service installation on the target system. When a package is deployed via PDQDeploy it installs a remote service on the target machine with the name "PDQDeployRunner-X" where "X" is an integer starting from 1

T1543.003
Sigmamedium

New PDQDeploy Service - Server Side

Detects a PDQDeploy service installation which indicates that PDQDeploy was installed on the machines. PDQDeploy can be abused by attackers to remotely install packages or execute commands on target machines

T1543.003
Sigmamedium

New Port Forwarding Rule Added Via Netsh.EXE

Detects the execution of netsh commands that configure a new port forwarding (PortProxy) rule

T1090
Sigmamedium

New PortProxy Registry Entry Added

Detects the modification of the PortProxy registry key which is used for port forwarding.

T1090
Sigmamedium

New PowerShell Instance Created

Detects the execution of PowerShell via the creation of a named pipe starting with PSHost

T1059.001
Sigmainformational
PreviousPage 57 of 137Next