EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Processes Accessing the Microphone and Webcam

Potential adversaries accessing the microphone and webcam in an endpoint.

T1123
Sigmamedium

ProcessHacker Privilege Elevation

Detects a ProcessHacker tool that elevated privileges to a very high level

T1543.003T1569.002
Sigmahigh

Program Executed Using Proxy/Local Command Via SSH.EXE

Detect usage of the "ssh.exe" binary as a proxy to launch other programs.

T1218
Sigmamedium

Program Executions in Suspicious Folders

Detects program executions in suspicious non-program folders related to malware or hacking activity

T1587T1584
Sigmamedium

Protected Storage Service Access

Detects access to a protected_storage service over the network. Potential abuse of DPAPI to extract domain backup keys from Domain Controllers

T1021.002
Sigmahigh

Proxy Execution via Vshadow

Detects the invocation of vshadow.exe with the -exec parameter that executes a specified script or command after the shadow copies are created but before the VShadow tool exits. VShadow is a command-line tool that you can use to create and manage volume shadow copies. While legitimate backup or administrative scripts may use this flag, attackers can leverage this parameter to proxy the execution of malware.

T1202
Sigmamedium

Proxy Execution Via Wuauclt.EXE

Detects the use of the Windows Update Client binary (wuauclt.exe) for proxy execution.

T1218
Sigmahigh

ProxyLogon MSExchange OabVirtualDirectory

Detects specific patterns found after a successful ProxyLogon exploitation in relation to a Commandlet invocation of Set-OabVirtualDirectory

T1587.001
Sigmacritical

PSAsyncShell - Asynchronous TCP Reverse Shell

Detects the use of PSAsyncShell an Asynchronous TCP Reverse Shell written in powershell

T1059.001
Sigmahigh

PSExec and WMI Process Creations Block

Detects blocking of process creations originating from PSExec and WMI commands

T1047T1569.002
Sigmahigh

PsExec Default Named Pipe

Detects PsExec service default pipe creation

T1569.002S0029
Sigmalow

Psexec Execution

Detects user accept agreement execution in psexec commandline

T1569T1021
Sigmamedium

PSEXEC Remote Execution File Artefact

Detects creation of the PSEXEC key file. Which is created anytime a PsExec command is executed. It gets written to the file system and will be recorded in the USN Journal on the target system

T1136.002T1543.003T1570S0029
Sigmahigh

PsExec Service Child Process Execution as LOCAL SYSTEM

Detects suspicious launch of the PSEXESVC service on this system and a sub process run as LOCAL_SYSTEM (-s), which means that someone remotely started a command on this system running it with highest privileges and not only the privileges of the login user account (e.g. the administrator account)

Sigmahigh

PsExec Service Execution

Detects launch of the PSEXESVC service, which means that this system was the target of a psexec remote execution

Sigmamedium

PsExec Service File Creation

Detects default PsExec service filename which indicates PsExec service installation and execution

T1569.002S0029
Sigmalow

PsExec Service Installation

Detects PsExec service installation and execution events

T1569.002S0029
Sigmamedium

PsExec Tool Execution From Suspicious Locations - PipeName

Detects PsExec default pipe creation where the image executed is located in a suspicious location. Which could indicate that the tool is being used in an attack

T1569.002S0029
Sigmamedium

PsExec/PAExec Escalation to LOCAL SYSTEM

Detects suspicious commandline flags used by PsExec and PAExec to escalate a command line to LOCAL_SYSTEM rights

T1587.001
Sigmahigh

PSScriptPolicyTest Creation By Uncommon Process

Detects the creation of the "PSScriptPolicyTest" PowerShell script by an uncommon process. This file is usually generated by Microsoft Powershell to test against Applocker.

Sigmamedium

PST Export Alert Using eDiscovery Alert

Alert on when a user has performed an eDiscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content

T1114
Sigmamedium

PST Export Alert Using New-ComplianceSearchAction

Alert when a user has performed an export to a search using 'New-ComplianceSearchAction' with the '-Export' flag. This detection will detect PST export even if the 'eDiscovery search or exported' alert is disabled in the O365.This rule will apply to ExchangePowerShell usage and from the cloud.

T1114
Sigmamedium

PUA - 3Proxy Execution

Detects the use of 3proxy, a tiny free proxy server

T1572
Sigmahigh

PUA - AdFind Suspicious Execution

Detects AdFind execution with common flags seen used during attacks

T1018T1087.002T1482T1069.002
Sigmahigh
PreviousPage 86 of 137Next