EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Ping Hex IP

Detects a ping command that uses a hex encoded IP address

T1140T1027
Sigmahigh

PktMon.EXE Execution

Detects execution of PktMon, a tool that captures network packets.

T1040
Sigmamedium

Pnscan Binary Data Transmission Activity

Detects command line patterns associated with the use of Pnscan for sending and receiving binary data across the network. This behavior has been identified in a Linux malware campaign targeting Docker, Apache Hadoop, Redis, and Confluence and was previously used by the threat actor known as TeamTNT

T1046
Sigmamedium

Port Forwarding Activity Via SSH.EXE

Detects port forwarding activity via SSH.exe

T1572T1021.001T1021.004
Sigmamedium

Portable Gpg.EXE Execution

Detects the execution of "gpg.exe" from uncommon location. Often used by ransomware and loaders to decrypt/encrypt data.

T1486
Sigmamedium

Possible Coin Miner CPU Priority Param

Detects command line parameter very often used with coin miners

T1068
Sigmacritical

Possible DC Shadow Attack

Detects DCShadow via create new SPN

T1207
Sigmamedium

Possible DCSync Attack

Detects remote RPC calls to MS-DRSR from non DC hosts, which could indicate DCSync / DCShadow attacks.

T1033
Sigmahigh

Possible Impacket SecretDump Remote Activity

Detect AD credential dumping using impacket secretdump HKTL

T1003.002T1003.004T1003.003
Sigmahigh

Possible Impacket SecretDump Remote Activity - Zeek

Detect AD credential dumping using impacket secretdump HKTL. Based on the SIGMA rules/windows/builtin/win_impacket_secretdump.yml

T1003.002T1003.004T1003.003
Sigmahigh

Possible PetitPotam Coerce Authentication Attempt

Detect PetitPotam coerced authentication activity.

T1187
Sigmahigh

Possible Privilege Escalation via Weak Service Permissions

Detection of sc.exe utility spawning by user with Medium integrity level to change service ImagePath or FailureCommand

T1574.011
Sigmahigh

Possible Shadow Credentials Added

Detects possible addition of shadow credentials to an active directory object.

T1556
Sigmahigh

Potential 7za.DLL Sideloading

Detects potential DLL sideloading of "7za.dll"

T1574.001
Sigmalow

Potential Abuse of Linux Magic System Request Key

Detects the potential abuse of the Linux Magic SysRq (System Request) key by adversaries with root or sufficient privileges to silently manipulate or destabilize a system. By writing to /proc/sysrq-trigger, they can crash the system, kill processes, or disrupt forensic analysis—all while bypassing standard logging. Though intended for recovery and debugging, SysRq can be misused as a stealthy post-exploitation tool. It is controlled via /proc/sys/kernel/sysrq or permanently through /etc/sysctl.conf.

T1059.004T1529T1489T1499
Sigmamedium

Potential Access Token Abuse

Detects potential token impersonation and theft. Example, when using "DuplicateToken(Ex)" and "ImpersonateLoggedOnUser" with the "LOGON32_LOGON_NEW_CREDENTIALS flag".

T1134.001
Sigmamedium

Potential Active Directory Enumeration Using AD Module - ProcCreation

Detects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.

Sigmamedium

Potential Active Directory Enumeration Using AD Module - PsModule

Detects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.

Sigmamedium

Potential Active Directory Enumeration Using AD Module - PsScript

Detects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.

Sigmamedium

Potential Active Directory Reconnaissance/Enumeration Via LDAP

Detects potential Active Directory enumeration via LDAP

T1069.002T1087.002T1482
Sigmamedium

Potential AD User Enumeration From Non-Machine Account

Detects read access to a domain user from a non-machine account

T1087.002
Sigmamedium

Potential Adplus.EXE Abuse

Detects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.

T1003.001
Sigmahigh

Potential Amazon SSM Agent Hijacking

Detects potential Amazon SSM agent hijack attempts as outlined in the Mitiga research report.

T1219.002
Sigmamedium

Potential AMSI Bypass Script Using NULL Bits

Detects usage of special strings/null bits in order to potentially bypass AMSI functionalities

T1685
Sigmamedium
PreviousPage 65 of 137Next