EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Remote Access Tool Services Have Been Installed - Security

Detects service installation of different remote access tools software. These software are often abused by threat actors to perform

T1543.003T1569.002
Sigmamedium

Remote Access Tool Services Have Been Installed - System

Detects service installation of different remote access tools software. These software are often abused by threat actors to perform

T1543.003T1569.002
Sigmamedium

Remote AppX Package Downloaded from File Sharing or CDN Domain

Detects an appx package that was added to the pipeline of the "to be processed" packages which was downloaded from a file sharing or CDN domain.

Sigmahigh

Remote CHM File Download/Execution Via HH.EXE

Detects the usage of "hh.exe" to execute/download remotely hosted ".chm" files.

T1218.001
Sigmahigh

Remote Code Execute via Winrm.vbs

Detects an attempt to execute code or create service on remote host via winrm.vbs.

T1216
Sigmamedium

Remote DCOM/WMI Lateral Movement

Detects remote RPC calls that performs remote DCOM operations. These could be abused for lateral movement via DCOM or WMI.

T1021.003T1047
Sigmahigh

Remote DLL Load Via Rundll32.EXE

Detects a remote DLL load event via "rundll32.exe".

T1204.002
Sigmamedium

Remote Encrypting File System Abuse

Detects remote RPC calls to possibly abuse remote encryption service via MS-EFSR

Sigmahigh

Remote Event Log Recon

Detects remote RPC calls to get event log information via EVEN or EVEN6

Sigmahigh

Remote File Copy

Detects the use of tools that copy files from or to remote systems

T1105
Sigmalow

Remote File Download Via Desktopimgdownldr Utility

Detects the desktopimgdownldr utility being used to download a remote file. An adversary may use desktopimgdownldr to download arbitrary files as an alternative to certutil.

T1105
Sigmamedium

Remote File Download Via Findstr.EXE

Detects execution of "findstr" with specific flags and a remote share path. This specific set of CLI flags would allow "findstr" to download the content of the file located on the remote share as described in the LOLBAS entry.

T1218T1564.004T1552.001T1105
Sigmamedium

Remote LSASS Process Access Through Windows Remote Management

Detects remote access to the LSASS process via WinRM. This could be a sign of credential dumping from tools like mimikatz.

T1003.001T1059.001T1021.006S0002
Sigmahigh

Remote PowerShell Session (PS Classic)

Detects remote PowerShell sessions

T1059.001T1021.006
Sigmalow

Remote PowerShell Session (PS Module)

Detects remote PowerShell sessions

T1059.001T1021.006
Sigmahigh

Remote PowerShell Session Host Process (WinRM)

Detects remote PowerShell sections by monitoring for wsmprovhost (WinRM host process) as a parent or child process (sign of an active PowerShell remote session).

T1059.001T1021.006
Sigmamedium

Remote PowerShell Sessions Network Connections (WinRM)

Detects basic PowerShell Remoting (WinRM) by monitoring for network inbound connections to ports 5985 OR 5986

T1059.001
Sigmahigh

Remote Printing Abuse for Lateral Movement

Detects remote RPC calls to possibly abuse remote printing service via MS-RPRN / MS-PAR

Sigmahigh

Remote Registry Lateral Movement

Detects remote RPC calls to modify the registry and possible execute code

T1112
Sigmahigh

Remote Registry Recon

Detects remote RPC calls to collect information

Sigmahigh

Remote Schedule Task Lateral Movement via ATSvc

Detects remote RPC calls to create or execute a scheduled task via ATSvc

T1053T1053.002
Sigmahigh

Remote Schedule Task Lateral Movement via ITaskSchedulerService

Detects remote RPC calls to create or execute a scheduled task

T1053T1053.002
Sigmahigh

Remote Schedule Task Lateral Movement via SASec

Detects remote RPC calls to create or execute a scheduled task via SASec

T1053T1053.002
Sigmahigh

Remote Schedule Task Recon via AtScv

Detects remote RPC calls to read information about scheduled tasks via AtScv

Sigmahigh
PreviousPage 94 of 137Next