EXPLORE

EXPLORE DETECTIONS

🔍
298 detections found

Find hidden scheduled tasks

T1053.005
CrowdStrike

Find OpenClaw on Endpoints

Identifies the installation, configuration, and execution of the OpenClaw (Moltbot/Clawdbot) autonomous AI agent. OpenClaw poses a significant risk for shadow AI and data exfiltration as it requires extensive permissions (Shell, APIs, Local Files) and is often controlled via messaging apps like WhatsApp or Telegram. # Detection Logic: ### Installation: Monitors for web-based install scripts (install.sh/ps1) and package manager activity (npm, npx, brew) related to OpenClaw. ### Configuration: Tracks file-write events to hidden user directories (.openclaw, .clawdbot, .moltbot) where plaintext API keys and skill configs are typically stored. ### Execution: Detects the Node.js-based gateway service starting on the default port 18789 or via specific command-line arguments.

T1059
CrowdStrike

Find OpenClaw on Endpoints

Identifies the installation, configuration, and execution of the OpenClaw (Moltbot/Clawdbot) autonomous AI agent. OpenClaw poses a significant risk for shadow AI and data exfiltration as it requires extensive permissions (Shell, APIs, Local Files) and is often controlled via messaging apps like WhatsApp or Telegram. # Detection Logic: ### Installation: Monitors for web-based install scripts (install.sh/ps1) and package manager activity (npm, npx, brew) related to OpenClaw. ### Configuration: Tracks file-write events to hidden user directories (.openclaw, .clawdbot, .moltbot) where plaintext API keys and skill configs are typically stored. ### Execution: Detects the Node.js-based gateway service starting on the default port 18789 or via specific command-line arguments.

T1059
CrowdStrike

Find processes that only ran a few of times on a specific host

CrowdStrike

Find processes that only ran a few of times on a specific host

CrowdStrike

Find tasks scheduled by logon type

T1053.005
CrowdStrike

Find tasks scheduled by logon type

T1053.005
CrowdStrike

Find tasks scheduled by run level

T1053.005
CrowdStrike

Find tasks scheduled by run level

T1053.005
CrowdStrike

Find tasks scheduled by user ID

T1053.005
CrowdStrike

Find tasks scheduled by user ID

T1053.005
CrowdStrike

Find tasks scheduled with ComHandler

T1053.005
CrowdStrike

Find tasks scheduled with ComHandler

T1053.005
CrowdStrike

Firewall Rule Additions

This query correlates processes with Windows Firewall rule modifications they triggered, identifying which executables are creating or modifying firewall rules.

CrowdStrike

Firewall Rule Additions

This query correlates processes with Windows Firewall rule modifications they triggered, identifying which executables are creating or modifying firewall rules.

CrowdStrike

Frequency Analysis via Program Clustering

This query detects potential reconnaissance or lateral movement activity by identifying Windows endpoints where three or more distinct discovery/enumeration tools were executed within 10-minute windows

CrowdStrike

Frequency Analysis via Program Clustering

This query detects potential reconnaissance or lateral movement activity by identifying Windows endpoints where three or more distinct discovery/enumeration tools were executed within 10-minute windows

CrowdStrike

GenAI Usage

This query identifies DNS requests to GenAI services.

CrowdStrike

GenAI Usage

This query identifies DNS requests to GenAI services.

CrowdStrike

Get Host Zero Trust Assessment Scores

This query outputs a table with hosts including their zero trust scores

CrowdStrike

Get Host Zero Trust Assessment Scores

This query outputs a table with hosts including their zero trust scores

CrowdStrike

Get USB Devices

Retrieving a list of USB Devices plugged to the device

CrowdStrike

Get USB Devices

Retrieving a list of USB Devices plugged to the device

CrowdStrike

High Volume SMB File Copy (Data Exfiltration / Ransomware) – Microsoft Defender for Identity

Detects a large volume of file transfers over SMB within a short timeframe, as identified by Microsoft Defender for Identity. This behavior may indicate bulk data exfiltration or ransomware activity, where files are rapidly copied, staged, or encrypted across systems and should be investigated immediately. Detects a large volume of file transfers over SMB within a short timeframe, as identified by Microsoft Defender for Identity. This behavior may indicate bulk data exfiltration or ransomware activity, where files are rapidly copied, staged, or encrypted across systems and should be investigated immediately.

T1048
CrowdStrike
PreviousPage 7 of 13Next