EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Outbound RDP Connections Over Non-Standard Tools

Detects Non-Standard tools initiating a connection over port 3389 indicating possible lateral movement. An initial baseline is required before using this utility to exclude third party RDP tooling that you might use.

T1021.001
Sigmahigh

Outdated Dependency Or Vulnerability Alert Disabled

Dependabot performs a scan to detect insecure dependencies, and sends Dependabot alerts. This rule detects when an organization owner disables Dependabot alerts private repositories or Dependabot security updates for all repositories.

T1195.001
Sigmahigh

Outgoing Logon with New Credentials

Detects logon events that specify new credentials

T1550
Sigmalow

Outlook EnableUnsafeClientMailRules Setting Enabled

Detects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros

T1059T1202
Sigmahigh

Outlook EnableUnsafeClientMailRules Setting Enabled - Registry

Detects an attacker trying to enable the outlook security setting "EnableUnsafeClientMailRules" which allows outlook to run applications or execute macros

T1112
Sigmahigh

Outlook Macro Execution Without Warning Setting Enabled

Detects the modification of Outlook security setting to allow unprompted execution of macros.

T1137T1008T1546
Sigmahigh

Outlook Security Settings Updated - Registry

Detects changes to the registry values related to outlook security settings

T1137
Sigmamedium

Overwriting the File with Dev Zero or Null

Detects overwriting (effectively wiping/deleting) of a file.

T1485
Sigmalow

PAExec Service Installation

Detects PAExec service installation

T1569.002
Sigmamedium

Pass the Hash Activity 2

Detects the attack technique pass the hash which is used to move laterally inside the network

T1550.002
Sigmamedium

Password Change on Directory Service Restore Mode (DSRM) Account

Detects potential attempts made to set the Directory Services Restore Mode administrator password. The Directory Service Restore Mode (DSRM) account is a local administrator account on Domain Controllers. Attackers may change the password in order to obtain persistence.

T1098
Sigmahigh

Password Dumper Activity on LSASS

Detects process handle on LSASS process with certain access mask and object type SAM_DOMAIN

T1003.001
Sigmahigh

Password Dumper Remote Thread in LSASS

Detects password dumper activity by monitoring remote thread creation EventID 8 in combination with the lsass.exe process as TargetImage. The process in field Process is the malicious program. A single execution can lead to hundreds of events.

S0005T1003.001
Sigmahigh

Password Policy Discovery - Linux

Detects password policy discovery commands

T1201
Sigmalow

Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy

Detetcts PowerShell activity in which Get-Addefaultdomainpasswordpolicy is used to get the default password policy for an Active Directory domain.

T1201
Sigmalow

Password Policy Enumerated

Detects when the password policy is enumerated.

T1201
Sigmamedium

Password Protected Compressed File Extraction Via 7Zip

Detects usage of 7zip utilities (7z.exe, 7za.exe and 7zr.exe) to extract password protected zip files.

T1560.001
Sigmalow

Password Protected ZIP File Opened

Detects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.

T1027
Sigmamedium

Password Protected ZIP File Opened (Email Attachment)

Detects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.

T1027T1566.001
Sigmahigh

Password Protected ZIP File Opened (Suspicious Filenames)

Detects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.

T1027T1105T1036
Sigmahigh

Password Provided In Command Line Of Net.EXE

Detects a when net.exe is called with a password in the command line

T1021.002T1078
Sigmamedium

Password Reset By User Account

Detect when a user has reset their password in Azure AD

T1078.004
Sigmamedium

Password Set to Never Expire via WMI

Detects the use of wmic.exe to modify user account settings and explicitly disable password expiration.

T1047T1098
Sigmamedium

Password Spray Activity

Indicates that a password spray attack has been successfully performed.

T1110
Sigmahigh
PreviousPage 63 of 137Next