1200KM / index
Sigma Rule Source Index
2791 original source rules with stable pages, exact TTP links, logsource tags and source attribution.
Complete Sigma rule directory
- Bitbucket Full Data Export Triggered
- Bitbucket Global Permission Changed
- Bitbucket Global Secret Scanning Rule Deleted
- Bitbucket Global SSH Settings Changed
- Bitbucket Audit Log Configuration Updated
- Bitbucket Project Secret Scanning Allowlist Added
- Bitbucket Secret Scanning Exempt Repository Added
- Bitbucket Secret Scanning Rule Deleted
- Bitbucket Unauthorized Access To A Resource
- Bitbucket Unauthorized Full Data Export Triggered
- Bitbucket User Details Export Attempt Detected
- Bitbucket User Login Failure
- Bitbucket User Login Failure Via SSH
- Bitbucket User Permissions Export Attempt
- Django Framework Exceptions
- Github Delete Action Invoked
- Github High Risk Configuration Disabled
- Outdated Dependency Or Vulnerability Alert Disabled
- Github Fork Private Repositories Setting Enabled/Cleared
- New Github Organization Member Added
- Github New Secret Created
- Github Outside Collaborator Detected
- GitHub Repository Pages Site Changed to Public
- Github Push Protection Bypass Detected
- Github Push Protection Disabled
- Github Repository/Organization Transferred
- Github Secret Scanning Feature Disabled
- Github Self Hosted Runner Changes Detected
- Github SSH Certificate Configuration Changed
- Potential JNDI Injection Exploitation In JVM Based Application
- Potential Local File Read Vulnerability In JVM Based Application
- Potential OGNL Injection Exploitation In JVM Based Application
- Process Execution Error In JVM Based Application
- Potential XXE Exploitation Attempt In JVM Based Application
- Kubernetes Admission Controller Modification
- Deployment Deleted From Kubernetes Cluster
- Kubernetes Events Deleted
- Potential Remote Command Execution In Pod Container
- Container With A hostPath Mount Created
- Creation Of Pod In System Namespace
- Kubernetes Potential Enumeration Activity
- Privileged Container Deployed
- RBAC Permission Enumeration Attempt
- Kubernetes Secrets Enumeration
- New Kubernetes Service Account Created
- Potential Sidecar Injection Into Running Deployment
- Potential RCE Exploitation Attempt In NodeJS
- OpenCanary - FTP Login Attempt
- OpenCanary - GIT Clone Request
- OpenCanary - HTTP GET Request
- OpenCanary - HTTP POST Login Attempt
- OpenCanary - HTTPPROXY Login Attempt
- OpenCanary - MSSQL Login Attempt Via SQLAuth
- OpenCanary - MSSQL Login Attempt Via Windows Authentication
- OpenCanary - MySQL Login Attempt
- OpenCanary - NTP Monlist Request
- OpenCanary - NMAP FIN Scan
- OpenCanary - NMAP NULL Scan
- OpenCanary - NMAP OS Scan
- OpenCanary - NMAP XMAS Scan
- OpenCanary - Host Port Scan (SYN Scan)
- OpenCanary - RDP New Connection Attempt
- OpenCanary - REDIS Action Command Attempt
- OpenCanary - SIP Request
- OpenCanary - SMB File Open Request
- OpenCanary - SNMP OID Request
- OpenCanary - SSH Login Attempt
- OpenCanary - SSH New Connection Attempt
- OpenCanary - Telnet Login Attempt
- OpenCanary - TFTP Request
- OpenCanary - VNC Connection Attempt
- Python SQL Exceptions
- Remote Schedule Task Lateral Movement via ATSvc
- Possible DCSync Attack
- Remote Schedule Task Lateral Movement via ITaskSchedulerService
- Remote DCOM/WMI Lateral Movement
- Remote Registry Lateral Movement
- Remote Server Service Abuse for Lateral Movement
- Remote Schedule Task Lateral Movement via SASec
- SharpHound Recon Account Discovery
- SharpHound Recon Sessions
- Ruby on Rails Framework Exceptions
- Spring Framework Exceptions
- Potential SpEL Injection In Spring Framework
- Suspicious SQL Error Messages
- Potential Server Side Template Injection In Velocity
- Antivirus Exploitation Framework Detection
- Antivirus Hacktool Detection
- Antivirus Password Dumper Detection
- Antivirus Ransomware Detection
- Antivirus Relevant File Paths Alerts
- Antivirus Web Shell Detection
- Suspicious SQL Query
- AWS ConsoleLogin Failed Authentication
- AWS Successful Console Login Without MFA
- AWS CloudTrail Important Change
- AWS GuardDuty Detector Deleted Or Updated
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure
- New Network ACL Entry Added
- New Network Route Added
- PUA - AWS TruffleHog Execution
- Ingress/Egress Security Group Modification
- LoadBalancer Security Group Modification
- RDS Database Security Group Modification
- Potential Malicious Usage of CloudTrail System Manager
- AWS Config Disabling Channel/Recorder
- AWS Console GetSigninToken Potential Abuse
- SES Identity Has Been Deleted
- AWS SAML Provider Deletion Activity
- AWS S3 Bucket Versioning Disable
- AWS EC2 Disable EBS Encryption
- AWS Key Pair Import Activity
- AWS EC2 Startup Shell Script Change
- AWS EC2 VM Export Failure
- AWS ECS Task Definition That Queries The Credential Endpoint
- AWS EFS Fileshare Mount Modified or Deleted
- AWS EKS Cluster Created or Deleted
- AWS ElastiCache Security Group Created
- AWS ElastiCache Security Group Modified or Deleted
- Potential Bucket Enumeration on AWS
- AWS GuardDuty Important Change
- AWS IAM Backdoor Users Keys
- AWS IAM S3Browser LoginProfile Creation
- AWS IAM S3Browser Templated S3 Bucket Policy Creation
- AWS IAM S3Browser User or AccessKey Creation
- AWS KMS Imported Key Material Usage
- AWS RDS Master Password Change
- Modification or Deletion of an AWS RDS Cluster
- Restore Public AWS RDS Instance
- AWS Root Credentials
- AWS Route 53 Domain Transfer Lock Disabled
- AWS Route 53 Domain Transferred to Another Account
- AWS S3 Data Management Tampering
- AWS SecurityHub Findings Evasion
- AWS Snapshot Backup Exfiltration
- AWS Identity Center Identity Provider Change
- AWS STS AssumeRole Misuse
- AWS STS GetCallerIdentity Enumeration Via TruffleHog
- AWS STS GetSessionToken Misuse
- AWS Suspicious SAML Activity
- AWS User Login Profile Was Modified
- Azure Active Directory Hybrid Health AD FS New Server
- Azure Active Directory Hybrid Health AD FS Service Delete
- User Added to an Administrator's Azure AD Role
- Azure Application Deleted
- Azure Container Registry Created or Deleted
- Number Of Resource Creation Or Deployment Activities
- Azure Device or Configuration Modified or Deleted
- Azure DNS Zone Modified or Deleted
- Azure Firewall Modified or Deleted
- Azure Firewall Rule Collection Modified or Deleted
- Granting Of Permissions To An Account
- Azure Keyvault Key Modified or Deleted
- Azure Key Vault Modified or Deleted
- Azure Keyvault Secrets Modified or Deleted
- Azure Kubernetes Admission Controller
- Azure Kubernetes Cluster Created or Deleted
- Azure Kubernetes CronJob
- Azure Kubernetes Events Deleted
- Azure Kubernetes Network Policy Change
- Azure Kubernetes Sensitive Role Access
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted
- Azure Kubernetes Secret or Config Object Access
- Azure Kubernetes Service Account Modified or Deleted
- Disabled MFA to Bypass Authentication Mechanisms
- Azure Network Firewall Policy Modified or Deleted
- Azure New CloudShell Created
- Rare Subscription-level Operations In Azure
- Azure Subscription Permission Elevation Via ActivityLogs
- CA Policy Removed by Non Approved Actor
- CA Policy Updated by Non Approved Actor
- New CA Policy by Non-approved Actor
- Account Created And Deleted Within A Close Time Frame
- Bitlocker Key Retrieval
- Certificate-Based Authentication Enabled
- Changes to Device Registration Policy
- Guest Users Invited To Tenant By Non Approved Inviters
- New Root Certificate Authority Added
- Users Added to Global or Device Admin Roles
- Application AppID Uri Configuration Changes
- Added Credentials to Existing Application
- Delegated Permissions Granted For All Users
- End User Consent
- End User Consent Blocked
- Added Owner To Application
- App Granted Microsoft Permissions
- App Granted Privileged Delegated Or App Permissions
- App Assigned To Azure RBAC/Microsoft Entra Role
- Application URI Configuration Changes
- Windows LAPS Credential Dump From Entra ID
- Change to Authentication Method
- Azure Domain Federation Settings Modified
- User Added To Group With CA Policy Modification Access
- User Removed From Group With CA Policy Modification Access
- Guest User Invited By Non Approved Inviters
- User State Changed From Guest To Member
- PIM Approvals And Deny Elevation
- PIM Alert Setting Changes To Disabled
- Changes To PIM Settings
- User Added To Privilege Role
- Bulk Deletion Changes To Privileged Account Permissions
- Privileged Account Creation
- Azure Subscription Permission Elevation Via AuditLogs
- Temporary Access Pass Added To An Account
- Password Reset By User Account
- Anomalous Token
- Anomalous User Activity
- Activity From Anonymous IP Address
- Anonymous IP Address
- Atypical Travel
- Impossible Travel
- Suspicious Inbox Forwarding Identity Protection
- Suspicious Inbox Manipulation Rules
- Azure AD Account Credential Leaked
- Malicious IP Address Sign-In Failure Rate
- Malicious IP Address Sign-In Suspicious
- Sign-In From Malware Infected IP
- New Country
- Password Spray Activity
- Primary Refresh Token Access Attempt
- Suspicious Browser Activity
- Azure AD Threat Intelligence
- SAML Token Issuer Anomaly
- Unfamiliar Sign-In Properties
- Stale Accounts In A Privileged Role
- Invalid PIM License
- Roles Assigned Outside PIM
- Roles Activated Too Frequently
- Roles Activation Doesn't Require MFA
- Roles Are Not Being Used
- Too Many Global Admins
- Account Lockout
- Increased Failed Authentications Of Any Type
- Measurable Increase Of Successful Authentications
- Authentications To Important Apps Using Single Factor Authentication
- Successful Authentications From Countries You Do Not Operate Out Of
- Discovery Using AzureHound
- Device Registration or Join Without MFA
- Failed Authentications From Countries You Do Not Operate Out Of
- Azure AD Only Single Factor Authentication Required
- Suspicious SignIns From A Non Registered Device
- Sign-ins from Non-Compliant Devices
- Sign-ins by Unknown Devices
- Potential MFA Bypass Using Legacy Client Authentication
- Application Using Device Code Authentication Flow
- Applications That Are Using ROPC Authentication Flow
- Account Disabled or Blocked for Sign in Attempts
- Sign-in Failure Due to Conditional Access Requirements Not Met
- Use of Legacy Authentication Protocols
- Login to Disabled Account
- Multifactor Authentication Denied
- Multifactor Authentication Interrupted
- Azure Unusual Authentication Interruption
- User Access Blocked by Azure Conditional Access
- Users Authenticating To Other Azure AD Tenants
- GCP Access Policy Deleted
- GCP Break-glass Container Workload Deployed
- Google Cloud Re-identifies Sensitive Information
- Google Cloud Firewall Modified or Deleted
- Google Full Network Traffic Packet Capture
- Google Cloud Kubernetes Admission Controller
- Google Cloud Service Account Disabled or Deleted
- Google Workspace Application Access Level Modified
- Google Workspace Granted Domain API Access
- Google Workspace User Granted Admin Privileges
- Google Workspace Government Attack Warning
- Google Workspace Out Of Domain Email Forwarding
- Suspicious Login Activity Classified By Google
- Azure Login Bypassing Conditional Access Policies
- Disabling Multi Factor Authentication
- New Federated Domain Added
- Suspicious Email Delivered In Microsoft 365
- New Federated Domain Added - Exchange
- Activity from Suspicious IP Addresses
- Activity from Anonymous IP Addresses
- Activity from Infrequent Country
- Data Exfiltration to Unsanctioned Apps
- Microsoft 365 - Impossible Travel Activity
- Logon from a Risky IP Address
- Microsoft 365 - Potential Ransomware Activity
- PST Export Alert Using eDiscovery Alert
- PST Export Alert Using New-ComplianceSearchAction
- Suspicious Inbox Forwarding
- Microsoft 365 - Unusual Volume of File Deletion
- Microsoft 365 - User Restricted from Sending Email
- Okta Admin Role Assigned to an User or Group
- Okta FastPass Phishing Detection
- Okta Identity Provider Created
- Okta MFA Reset or Deactivated
- Okta New Admin Console Behaviours
- Potential Okta Password in AlternateID Field
- Okta Suspicious Activity Reported by End-user
- Okta User Account Locked Out
- Okta User Session Start Via An Anonymising Proxy Service
- Binary Padding - Linux
- Bpfdoor TCP Ports Redirect
- Linux Capabilities Discovery
- File Time Attribute Change - Linux
- Remove Immutable File Attribute - Auditd
- Clipboard Collection with Xclip Tool - Auditd
- Clipboard Collection of Image Data with Xclip Tool
- Possible Coin Miner CPU Priority Param
- Data Compressed
- Data Exfiltration with Wget
- Overwriting the File with Dev Zero or Null
- File or Folder Permissions Change
- Credentials In Files - Linux
- Hidden Files and Directories
- Steganography Hide Zip Information in Picture File
- Masquerading as Linux Crond Process
- Modify System Firewall
- Network Sniffing - Linux
- Screen Capture with Import Tool
- Screen Capture with Xwd
- Steganography Hide Files with Steghide
- Steganography Extract Files with Steghide
- Suspicious Commands Linux
- Suspicious History File Operations - Linux
- Service Reload or Start - Linux
- System Shutdown/Reboot - Linux
- Steganography Unzip Hidden Information From Picture File
- System Owner or User Discovery - Linux
- Audio Capture
- ASLR Disabled Via Sysctl or Direct Syscall - Linux
- Linux Keylogging with Pam.d
- Password Policy Discovery - Linux
- System Information Discovery - Auditd
- Auditing Configuration Changes on Linux Host
- BPFDoor Abnormal Process ID or Lock File Accessed
- Use Of Hidden Paths Or Files
- Modification of ld.so.preload
- Logging Configuration Changes on Linux Host
- Potential Abuse of Linux Magic System Request Key
- System and Hardware Information Discovery
- Systemd Service Creation
- Unix Shell Configuration Modification
- Disable System Firewall
- Clear or Disable Kernel Ring Buffer Logs via Syslog Syscall
- Creation Of An User Account
- Loading of Kernel Module via Insmod
- Linux Network Service Scanning - Auditd
- Split A File Into Pieces - Linux
- System Info Discovery via Sysinfo Syscall
- Program Executions in Suspicious Folders
- Special File Creation via Mknod Syscall
- Webshell Remote Command Execution
- Relevant ClamAV Message
- Modifying Crontab
- Guacamole Two Users Sharing Session Anomaly
- Equation Group Indicators
- Buffer Overflow Attempts
- Commands to Clear or Remove the Syslog - Builtin
- Remote File Copy
- Code Injection by ld.so Preload
- Privileged User Has Been Created
- Linux Command History Tampering
- Suspicious Activity in Shell Commands
- Suspicious Reverse Shell Command Line
- Shellshock Expression
- JexBoss Command Sequence
- Symlink Etc Passwd
- Suspicious OpenSSH Daemon Error
- Disabling Security Tools - Builtin
- Suspicious Named Error
- Suspicious VSFTPD Error Messages
- Linux Doas Conf File Creation
- Persistence Via Sudoers.d Files
- New Cron File Created
- Suspicious Filename with Embedded Base64 Commands
- Triple Cross eBPF Rootkit Default Persistence
- Wget Creating Files in Tmp Directory
- Linux Reverse Shell Indicator
- Linux Crypto Mining Pool Connections
- Communication To LocaltoNet Tunneling Service Initiated - Linux
- Communication To Ngrok Tunneling Service - Linux
- Potentially Suspicious Malware Callback Communication - Linux
- Shell Invocation via Apt - Linux
- Scheduled Task/Job At
- Audit Rules Deleted Via Auditctl
- Kaspersky Endpoint Security Stopped Via CommandLine - Linux
- Suspicious Invocation of Shell via AWK - Linux
- Decode Base64 Encoded Text
- Linux Base64 Encoded Pipe to Shell
- Linux Base64 Encoded Shebang In CLI
- BPFtrace Unsafe Option Usage
- Linux Setgid Capability Set on a Binary via Setcap Utility
- Linux Setuid Capability Set on a Binary via Setcap Utility
- Capabilities Discovery - Linux
- Capsh Shell Invocation - Linux
- Remove Immutable File Attribute
- Chmod Targeting Sensitive Directories
- Linux Sudo Chroot Execution
- Linux Logs Clearing Attempts
- Syslog Clearing or Removal Via System Utilities
- Clipboard Collection with Xclip Tool
- Copy Passwd Or Shadow From TMP Path
- Crontab Enumeration
- Linux Crypto Mining Indicators
- Curl Usage on Linux
- Suspicious Download and Execute Pattern via Curl/Wget
- DD File Overwrite
- Potential Linux Process Code Injection Via DD Utility
- UFW Disable Attempt
- Linux Doas Tool Execution
- Shell Invocation via Env Command - Linux
- ESXi Network Configuration Discovery Via ESXCLI
- ESXi Admin Permission Assigned To Account Via ESXCLI
- ESXi Storage Information Discovery Via ESXCLI
- ESXi Syslog Configuration Change Via ESXCLI
- ESXi System Information Discovery Via ESXCLI
- ESXi Account Creation Via ESXCLI
- ESXi VM List Discovery Via ESXCLI
- ESXi VM Kill Via ESXCLI
- ESXi VSAN Information Discovery Via ESXCLI
- File and Directory Discovery - Linux
- File Deletion
- Shell Execution via Find - Linux
- Shell Execution via Flock - Linux
- Shell Execution GCC - Linux
- Shell Execution via Git - Linux
- OS Architecture Discovery Via Grep
- Group Has Been Deleted Via Groupdel
- Install Root Certificate
- Suspicious Package Installed - Linux
- Flush Iptables Ufw Chain
- Local System Accounts Discovery - Linux
- Local Groups Discovery - Linux
- Potential GobRAT File Discovery Via Grep
- Mount Execution With Hidepid Parameter
- Potential Netcat Reverse Shell Execution
- Shell Execution via Nice - Linux
- Nohup Execution
- OMIGOD SCX RunAsProvider ExecuteScript
- OMIGOD SCX RunAsProvider ExecuteShellCommand
- Pnscan Binary Data Transmission Activity
- Connection Proxy
- PUA - TruffleHog Execution - Linux
- Python One-Liners with Base64 Decoding - Linux
- Python WebServer Execution - Linux
- Python Spawning Pretty TTY Via PTY Module
- Inline Python Execution - Spawn Shell Via OS System Library
- Remote Access Tool - Team Viewer Session Started On Linux Host
- Linux Remote System Discovery
- Linux Package Uninstall
- Shell Execution via Rsync - Linux
- Suspicious Invocation of Shell via Rsync
- Scheduled Cron Task/Job - Linux
- Security Software Discovery - Linux
- Disabling Security Tools
- Disable Or Stop Services
- Setuid and Setgid
- Shell Invocation Via Ssh - Linux
- Potential Linux Amazon SSM Agent Hijacking
- Container Residence Discovery Via Proc Virtual FS
- Suspicious Curl File Upload - Linux
- Suspicious Curl Change User Agents - Linux
- Docker Container Discovery Via Dockerenv Listing
- Process Execution From Shared Memory Directory
- Potentially Suspicious Execution From Tmp Folder
- Potential Discovery Activity Using Find - Linux
- Suspicious Git Clone - Linux
- History File Deletion
- Print History File Contents
- Linux HackTool Execution
- Potential Container Discovery Via Inodes Listing
- Interactive Bash Suspicious Children
- Suspicious Java Children Processes
- Linux Network Service Scanning Tools Execution
- Linux Shell Pipe to Shell
- Access of Sudoers File Content
- Linux Recon Indicators
- Script Interpreter Spawning Credential Scanner - Linux
- Potential Suspicious Change To Sensitive/Critical Files
- System Information Discovery
- System Network Connections Discovery - Linux
- System Network Discovery - Linux
- Mask System Power Settings Via Systemctl
- Touch Suspicious Service File
- Triple Cross eBPF Rootkit Install Commands
- User Has Been Deleted Via Userdel
- Vim GTFOBin Abuse - Linux
- Linux Webshell Indicators
- Download File To Potentially Suspicious Directory Via Wget
- Potential Xterm Reverse Shell
- MacOS Emond Launch Daemon
- Startup Item File Created - MacOS
- MacOS Scripting Interpreter AppleScript
- Decode Base64 Encoded Text -MacOs
- Binary Padding - MacOS
- File Time Attribute Change
- Hidden Flag Set On File/Directory Via Chflags - MacOS
- Indicator Removal on Host - Clear Mac System Logs
- Clipboard Access Via OSAScript
- Creation Of A Local User Account
- Hidden User Creation
- Credentials from Password Stores - Keychain
- System Integrity Protection (SIP) Disabled
- System Integrity Protection (SIP) Enumeration
- Disable Security Tools
- User Added To Admin Group Via Dscl
- User Added To Admin Group Via DseditGroup
- Root Account Enable Via Dsenableroot
- File and Directory Discovery - MacOS
- Credentials In Files
- GUI Input Capture - macOS
- Disk Image Mounting Via Hdiutil - MacOS
- Suspicious Installer Package Child Process
- System Information Discovery Using Ioreg
- JXA In-memory Execution Via OSAScript
- Launch Agent/Daemon Execution Via Launchctl
- Local System Accounts Discovery - MacOs
- Local Groups Discovery - MacOs
- MacOS Network Service Scanning
- Network Sniffing - MacOs
- File Download Via Nscurl - MacOS
- Suspicious Microsoft Office Child Process - MacOS
- OSACompile Run-Only Execution
- Payload Decoded and Decrypted via Built-in Utilities
- Potential Persistence Via PlistBuddy
- Remote Access Tool - Potential MeshAgent Execution - MacOS
- Remote Access Tool - Renamed MeshAgent Execution - MacOS
- Remote Access Tool - Team Viewer Session Started On MacOS Host
- Macos Remote System Discovery
- Scheduled Cron Task/Job - MacOs
- Screen Capture - macOS
- Security Software Discovery - MacOs
- Space After Filename - macOS
- Split A File Into Pieces
- Suspicious Browser Child Process - MacOS
- Suspicious Execution via macOS Script Editor
- Potential Discovery Activity Using Find - MacOS
- Suspicious History File Operations
- Potential In-Memory Download And Compile Of Payloads
- System Network Discovery - macOS
- Osacompile Execution By Potentially Suspicious Applet/Osascript
- System Information Discovery Using sw_vers
- User Added To Admin Group Via Sysadminctl
- Guest Account Enabled Via Sysadminctl
- System Information Discovery Via Sysctl - MacOS
- System Network Connections Discovery - MacOs
- System Information Discovery Using System_Profiler
- System Shutdown/Reboot - MacOs
- Potential Base64 Decoded From Images
- Time Machine Backup Deletion Attempt Via Tmutil - MacOS
- Time Machine Backup Disabled Via Tmutil - MacOS
- New File Exclusion Added To Time Machine Via Tmutil - MacOS
- Gatekeeper Bypass via Xattr
- Cisco Clear Logs
- Cisco Collect Data
- Cisco Crypto Commands
- Cisco Disabling Logging
- Cisco Discovery
- Cisco Denial of Service
- Cisco Dot1x Disabled
- Cisco File Deletion
- Cisco Show Commands Input
- Cisco Local Accounts
- Cisco Modify Configuration
- Cisco Stage Data
- Cisco Sniffing
- Cisco BGP Authentication Failures
- Cisco LDP Authentication Failures
- DNS Query to External Service Interaction Domains
- Cobalt Strike DNS Beaconing
- Monero Crypto Coin Mining Pool Lookup
- Suspicious DNS Query with B64 Encoded String
- Telegram Bot API Request
- DNS TXT Answer with Possible Execution Strings
- Wannacry Killswitch Domain
- FortiGate - New Administrator Account Created
- FortiGate - Firewall Address Object Added
- FortiGate - New Firewall Policy Added
- FortiGate - New Local User Created
- FortiGate - New VPN SSL Web Portal Added
- FortiGate - VPN SSL Settings Modified
- Huawei BGP Authentication Failures
- Juniper BGP Missing MD5
- MITRE BZAR Indicators for Execution
- MITRE BZAR Indicators for Persistence
- Potential PetitPotam Attack Via EFS RPC Calls
- SMB Spoolss Name Piped Usage
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network
- DNS Events Related To Mining Pools
- Suspicious DNS Z Flag Bit Set
- DNS TOR Proxies
- Executable from Webdav
- WebDav Put Request
- Publicly Accessible RDP Service
- Remote Task Creation via ATSVC Named Pipe - Zeek
- Possible Impacket SecretDump Remote Activity - Zeek
- First Time Seen Remote Named Pipe - Zeek
- Suspicious PsExec Execution - Zeek
- Transferring Files with Credential Data via Network Shares - Zeek
- Kerberos Network Traffic RC4 Ticket Encryption
- Apache Segmentation Fault
- Apache Threading Error
- Nginx Core Dump
- Download from Suspicious Dyndns Hosts
- Download From Suspicious TLD - Blacklist
- Download From Suspicious TLD - Whitelist
- Windows WebDAV User Agent
- F5 BIG-IP iControl Rest API Command Execution - Proxy
- Potential Hello-World Scraper Botnet Activity
- HackTool - BabyShark Agent Default URL Pattern
- HackTool - CobaltStrike Malleable Profile Patterns - Proxy
- HackTool - Empire UserAgent URI Combo
- PUA - Advanced IP/Port Scanner Update Check
- PwnDrp Access
- Raw Paste Service Access
- Flash Player Update from Suspicious Location
- Suspicious Network Communication With IPFS
- Telegram API Access
- APT User Agent
- Suspicious Base64 Encoded User-Agent
- Bitsadmin to Uncommon IP Server Address
- Bitsadmin to Uncommon TLD
- Crypto Miner User Agent
- HTTP Request With Empty User Agent
- Exploit Framework User Agent
- Hack Tool User Agent
- Malware User Agent
- Windows PowerShell User Agent
- Rclone Activity via Proxy
- Suspicious User Agent
- Potential Base64 Encoded User-Agent
- Suspicious External WebDAV Execution
- F5 BIG-IP iControl Rest API Command Execution - Webserver
- Successful IIS Shortname Fuzzing Scan
- Java Payload Strings
- JNDIExploit Pattern
- Path Traversal Exploitation Attempts
- Source Code Enumeration Detection by Keyword
- SQL Injection Strings In URI
- Server Side Template Injection Strings
- Suspicious User-Agents Related To Recon Tools
- Suspicious Windows Strings In URI
- Webshell ReGeorg Detection Via Web Logs
- Windows Webshell Strings
- Cross Site Scripting Strings
- Relevant Anti-Virus Signature Keywords In Application Log
- LSASS Process Crashed - Application
- Microsoft Malware Protection Engine Crash
- Ntdsutil Abuse
- Audit CVE Event
- Backup Catalog Deleted
- Restricted Software Access By SRP
- Application Uninstalled
- MSI Installation From Web
- Atera Agent Installation
- MSSQL Destructive Query
- MSSQL Server Failed Logon
- MSSQL Server Failed Logon From External Network
- Remote Access Tool - ScreenConnect Command Execution
- Remote Access Tool - ScreenConnect File Transfer
- Microsoft Malware Protection Engine Crash - WER
- AppLocker Prevented Application or Script from Running
- Windows AppX Deployment Full Trust Package Installation
- Windows AppX Deployment Unsigned Package Installation
- New BITS Job Created Via Bitsadmin
- New BITS Job Created Via PowerShell
- BITS Transfer Job Downloading File Potential Suspicious Extension
- BITS Transfer Job Download From File Sharing Domains
- BITS Transfer Job Download From Direct IP
- BITS Transfer Job With Uncommon Or Suspicious Remote TLD
- BITS Transfer Job Download To Potential Suspicious Folder
- Certificate Private Key Acquired
- Certificate Exported From Local Certificate Store
- CodeIntegrity - Blocked Image/Driver Load For Policy Violation
- CodeIntegrity - Blocked Driver Load With Revoked Certificate
- DNS Query for Anonfiles.com Domain - DNS Client
- Suspicious Cobalt Strike DNS Beaconing - DNS Client
- DNS Query To MEGA Hosting Website - DNS Client
- Query Tor Onion Address - DNS Client
- DNS Query To Ufile.io - DNS Client
- Failed DNS Zone Transfer
- DNS Server Error Failed Loading the ServerLevelPluginDLL
- USB Device Plugged
- Uncommon New Firewall Rule Added In Windows Firewall Exception List
- New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
- New Firewall Rule Added In Windows Firewall Exception List Via WmiPrvSE.EXE
- All Rules Have Been Deleted From The Windows Firewall Configuration
- A Rule Has Been Deleted From The Windows Firewall Exception List
- The Windows Defender Firewall Service Failed To Load Group Policy
- Windows Defender Firewall Has Been Reset To Its Default Configuration
- Windows Firewall Settings Have Been Changed
- ETW Logging/Processing Option Disabled On IIS Server
- HTTP Logging Disabled On IIS Server
- New Module Module Added To IIS Server
- Previously Installed IIS Module Was Removed
- Potential Active Directory Reconnaissance/Enumeration Via LDAP
- ProxyLogon MSExchange OabVirtualDirectory
- Certificate Request Export to Exchange Webserver
- Mailbox Export to Exchange Webserver
- Remove Exported Mailbox from Exchange Webserver
- Exchange Set OabVirtualDirectory ExternalUrl Property
- MSExchange Transport Agent Installation - Builtin
- Failed MSExchange Transport Agent Installation
- NTLM Logon
- NTLM Brute Force
- Potential Remote Desktop Connection to Non-Domain Host
- OpenSSH Server Listening On Socket
- Potential Access Token Abuse
- Admin User Remote Logon
- A Member Was Added to a Security-Enabled Global Group
- A Member Was Removed From a Security-Enabled Global Group
- Successful Overpass the Hash Attempt
- Pass the Hash Activity 2
- RDP Login from Localhost
- A Security-Enabled Global Group Was Deleted
- External Remote RDP Logon from Public IP
- External Remote SMB Logon from Public IP
- Failed Logon From Public IP
- Outgoing Logon with New Credentials
- Potential Privilege Escalation via Local Kerberos Relay over LDAP
- RottenPotato Like Attack Pattern
- Successful Account Login Via WMI
- Windows Filtering Platform Blocked Connection From EDR Agent Binary
- Azure AD Health Monitoring Agent Registry Keys Access
- Azure AD Health Service Agents Registry Keys Access
- Powerview Add-DomainObjectAcl DCSync AD Extend Right
- AD Privileged Users or Groups Reconnaissance
- AD Object WriteDAC Access
- Active Directory Replication from Non Machine Account
- Potential AD User Enumeration From Non-Machine Account
- Add or Remove Computer from DC
- Access To ADMIN$ Network Share
- Enabled User Right in AD to Control User Objects
- Active Directory User Backdoors
- Weak Encryption Enabled and Kerberoast
- Hacktool Ruler
- Remote Task Creation via ATSVC Named Pipe
- Security Eventlog Cleared
- Processes Accessing the Microphone and Webcam
- CobaltStrike Service Installations - Security
- Failed Code Integrity Checks
- DCERPC SMB Spoolss Named Pipe
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security
- Mimikatz DC Sync
- Windows Default Domain GPO Modification
- Device Installation Blocked
- Windows Event Auditing Disabled
- Important Windows Event Auditing Disabled
- ETW Logging Disabled In .NET Processes - Registry
- DPAPI Domain Backup Key Extraction
- DPAPI Domain Master Key Backup Attempt
- External Disk Drive Or USB Storage Device Was Recognized By The System
- Persistence and Execution at Scale via GPO Scheduled Task
- Hidden Local User Creation
- HackTool - EDRSilencer Execution - Filter Added
- HackTool - NoFilter Execution
- HybridConnectionManager Service Installation
- Impacket PsExec Execution
- Possible Impacket SecretDump Remote Activity
- Invoke-Obfuscation CLIP+ Launcher - Security
- Invoke-Obfuscation Obfuscated IEX Invocation - Security
- Invoke-Obfuscation STDIN+ Launcher - Security
- Invoke-Obfuscation VAR+ Launcher - Security
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security
- Invoke-Obfuscation RUNDLL LAUNCHER - Security
- Invoke-Obfuscation Via Stdin - Security
- Invoke-Obfuscation Via Use Clip - Security
- Invoke-Obfuscation Via Use MSHTA - Security
- Invoke-Obfuscation Via Use Rundll32 - Security
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
- ISO Image Mounted
- Kerberoasting Activity - Initial Query
- Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation
- First Time Seen Remote Named Pipe
- LSASS Access From Non System Account
- Credential Dumping Tools Service Execution - Security
- WCE wceaux.dll Access
- Metasploit SMB Authentication
- Metasploit Or Impacket Service Installation Via SMB PsExec
- Meterpreter or Cobalt Strike Getsystem Service Installation - Security
- NetNTLM Downgrade Attack
- Windows Network Access Suspicious desktop.ini Action
- New or Renamed User Account with '$' Character
- Denied Access To Remote Desktop
- Password Policy Enumerated
- Windows Pcap Drivers
- Possible PetitPotam Coerce Authentication Attempt
- PetitPotam Suspicious Kerberos TGT Request
- Possible DC Shadow Attack
- PowerShell Scripts Installed as Services - Security
- Protected Storage Service Access
- RDP over Reverse SSH Tunnel WFP
- Register new Logon Process by Rubeus
- Service Registry Key Read Access Request
- Remote PowerShell Sessions Network Connections (WinRM)
- Replay Attack Detected
- SAM Registry Hive Handle Request
- SCM Database Handle Failure
- SCM Database Privileged Operation
- Potential Secure Deletion with SDelete
- Remote Access Tool Services Have Been Installed - Security
- Service Installed By Unusual Client - Security
- File Access Of Signal Desktop Sensitive Data
- SMB Create Remote File Admin Share
- A New Trust Was Created To A Domain
- Addition of SID History to Active Directory Object
- Win Susp Computer Name Containing Samtheadmin
- Password Change on Directory Service Restore Mode (DSRM) Account
- Account Tampering - Suspicious Failed Logon Reasons
- Group Policy Abuse for Privilege Addition
- Startup/Logon Script Added to Group Policy Object
- Kerberos Manipulation
- Suspicious LDAP-Attributes Used
- Suspicious Windows ANONYMOUS LOGON Local Account Created
- Suspicious Remote Logon with Explicit Credentials
- Password Dumper Activity on LSASS
- Potentially Suspicious AccessMask Requested From LSASS
- Reconnaissance Activity
- Password Protected ZIP File Opened
- Password Protected ZIP File Opened (Suspicious Filenames)
- Password Protected ZIP File Opened (Email Attachment)
- Uncommon Outbound Kerberos Connection - Security
- Possible Shadow Credentials Added
- Suspicious PsExec Execution
- Suspicious Access to Sensitive File Extensions
- Suspicious Kerberos RC4 Ticket Encryption
- Suspicious Scheduled Task Creation
- Important Scheduled Task Deleted/Disabled
- Suspicious Scheduled Task Update
- Unauthorized System Time Modification
- Remote Service Activity via SVCCTL Named Pipe
- SysKey Registry Keys Access
- Sysmon Channel Reference Deletion
- Tap Driver Installation - Security
- Suspicious Teams Application Related ObjectAcess Event
- Transferring Files with Credential Data via Network Shares
- User Added to Local Administrator Group
- User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'
- Local User Creation
- Potential Privileged System Service Operation - SeLoadDriverPrivilege
- User Logoff Event
- VSSAudit Security Event Source Registration
- Windows Defender Exclusion List Modified
- Windows Defender Exclusion Registry Key - Write Access Requested
- WMI Persistence - Security
- T1047 Wmiprvse Wbemcomn DLL Hijack
- Microsoft Defender Blocked from Loading Unsigned DLL
- Unsigned Binary Loaded From Suspicious Location
- HybridConnectionManager Service Running
- Suspicious Rejected SMB Guest Logon From IP
- Unsigned or Unencrypted SMB Connection to Share Established
- Sysmon Application Crashed
- NTLMv1 Logon Between Client and Server
- ISATAP Router Address Was Set
- Active Directory Certificate Services Denied Certificate Enrollment Request
- DHCP Server Loaded the CallOut DLL
- DHCP Server Error Failed Loading the CallOut DLL
- Local Privilege Escalation Indicator TabTip
- Eventlog Cleared
- Important Windows Eventlog Cleared
- No Suitable Encryption Key Found For Generating Kerberos Ticket
- Critical Hive In Suspicious Location Access Bits Cleared
- Volume Shadow Copy Mount
- Crash Dump Created By Operating System
- Windows Update Error
- Zerologon Exploitation Using Well-known Tools
- Vulnerable Netlogon Secure Channel Connection Allowed
- NTFS Vulnerability Exploitation
- CobaltStrike Service Installations - System
- Windows Defender Threat Detection Service Disabled
- smbexec.py Service Installation
- Invoke-Obfuscation CLIP+ Launcher - System
- Invoke-Obfuscation Obfuscated IEX Invocation - System
- Invoke-Obfuscation STDIN+ Launcher - System
- Invoke-Obfuscation VAR+ Launcher - System
- Invoke-Obfuscation COMPRESS OBFUSCATION - System
- Invoke-Obfuscation RUNDLL LAUNCHER - System
- Invoke-Obfuscation Via Stdin - System
- Invoke-Obfuscation Via Use Clip - System
- Invoke-Obfuscation Via Use MSHTA - System
- Invoke-Obfuscation Via Use Rundll32 - System
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
- KrbRelayUp Service Installation
- Credential Dumping Tools Service Execution - System
- Meterpreter or Cobalt Strike Getsystem Service Installation - System
- Moriya Rootkit - System
- PowerShell Scripts Installed as Services
- CSExec Service Installation
- HackTool Service Registration or Execution
- Mesh Agent Service Installation
- PAExec Service Installation
- New PDQDeploy Service - Server Side
- New PDQDeploy Service - Client Side
- ProcessHacker Privilege Elevation
- RemCom Service Installation
- Remote Access Tool Services Have Been Installed - System
- Sliver C2 Default Service Installation
- Service Installed By Unusual Client - System
- Suspicious Service Installation
- PsExec Service Installation
- TacticalRMM Service Installation
- Tap Driver Installation
- Uncommon Service Installation Image Path
- Service Installation in Suspicious Folder
- Service Installation with Suspicious Folder Pattern
- Suspicious Service Installation Script
- Scheduled Task Executed From A Suspicious Location
- Scheduled Task Executed Uncommon LOLBIN
- Important Scheduled Task Deleted or Disabled
- Ngrok Usage with Remote Desktop Service
- Mimikatz Use
- Windows Defender Grace Period Expired
- LSASS Access Detected via Attack Surface Reduction
- PSExec and WMI Process Creations Block
- Windows Defender Exclusions Added
- Windows Defender Exploit Guard Tamper
- Windows Defender Submit Sample Feature Disabled
- Windows Defender Malware And PUA Scanning Disabled
- Windows Defender AMSI Trigger Detected
- Windows Defender Real-time Protection Disabled
- Windows Defender Real-Time Protection Failure/Restart
- Win Defender Restored Quarantine File
- Windows Defender Configuration Changes
- Microsoft Defender Tamper Protection Trigger
- Windows Defender Threat Detected
- Windows Defender Virus Scanning Feature Disabled
- WMI Persistence
- HackTool - CACTUSTORCH Remote Thread Creation
- HackTool - Potential CobaltStrike Process Injection
- Remote Thread Created In KeePass.EXE
- Potential Credential Dumping Attempt Via PowerShell Remote Thread
- Remote Thread Creation Via PowerShell In Uncommon Target
- Password Dumper Remote Thread in LSASS
- Rare Remote Thread Creation By Uncommon Source Image
- Remote Thread Creation By Uncommon Source Image
- Remote Thread Creation In Uncommon Target Image
- Remote Thread Creation Ttdinject.exe Proxy
- Hidden Executable In NTFS Alternate Data Stream
- Suspicious File Download From File Sharing Websites - File Stream
- Unusual File Download From File Sharing Websites - File Stream
- HackTool Named File Stream Created
- Exports Registry Key To an Alternate Data Stream
- Unusual File Download from Direct IP Address
- DNS Query for Anonfiles.com Domain - Sysmon
- AppX Package Installation Attempts Via AppInstaller.EXE
- Cloudflared Tunnels Related DNS Requests
- DNS Query To Common Malware Hosting and Shortener Services
- DNS Query To Devtunnels Domain
- DNS Server Discovery Via LDAP Query
- DNS Query To AzureWebsites.NET By Non-Browser Process
- DNS Query by Finger Utility
- Notepad++ Updater DNS Query to Uncommon Domains
- DNS HybridConnectionManager Service Bus
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing
- Suspicious Cobalt Strike DNS Beaconing - Sysmon
- DNS Query To MEGA Hosting Website
- DNS Query Request To OneLaunch Update Service
- DNS Query Request By QuickAssist.EXE
- DNS Query Request By Regsvr32.EXE
- DNS Query To Remote Access Software Domain From Non-Browser App
- Suspicious DNS Query for IP Lookup Service APIs
- TeamViewer Domain Query By Non-TeamViewer Application
- DNS Query Tor .Onion Address - Sysmon
- DNS Query To Ufile.io
- DNS Query To Visual Studio Code Tunnels Domain
- Malicious Driver Load
- Malicious Driver Load By Name
- PUA - Process Hacker Driver Load
- PUA - System Informer Driver Load
- Driver Load From A Temporary Directory
- Vulnerable Driver Load
- Vulnerable Driver Load By Name
- Vulnerable HackSys Extreme Vulnerable Driver Load
- Vulnerable WinRing0 Driver Load
- WinDivert Driver Load
- Credential Manager Access By Uncommon Applications
- Access To Windows Credential History File By Uncommon Applications
- Access To Crypto Currency Wallets By Uncommon Applications
- Access To Windows DPAPI Master Keys By Uncommon Applications
- Access To Potentially Sensitive Sysvol Files By Uncommon Applications
- Suspicious File Access to Browser Credential Storage
- Microsoft Teams Sensitive File Access By Uncommon Applications
- Unusual File Modification by dns.exe
- Backup Files Deleted
- EventLog EVTX File Deleted
- Exchange PowerShell Cmdlet History Deleted
- IIS WebServer Access Logs Deleted
- PowerShell Console History Logs Deleted
- Prefetch File Deleted
- TeamViewer Log File Deleted
- Tomcat WebServer Logs Deleted
- File Deleted Via Sysinternals SDelete
- Unusual File Deletion by Dns.exe
- ADS Zone.Identifier Deleted By Uncommon Application
- ADSI-Cache File Creation By Uncommon Tool
- Advanced IP Scanner - File Event
- Anydesk Temporary Artefact
- Suspicious Binary Writes Via AnyDesk
- Suspicious File Created by ArcSOC.exe
- BloodHound Collection Files
- Potentially Suspicious File Creation by OpenEDR's ITSMService
- EVTX Created In Uncommon Location
- Creation Of Non-Existent System DLL
- Suspicious Deno File Written from Remote Source
- New Custom Shim Database Created
- Suspicious Screensaver Binary File Creation
- Files With System DLL Name In Unsuspected Locations
- Files With System Process Name In Unsuspected Locations
- Creation Exe for Service with Unquoted Path
- Cred Dump Tools Dropped Files
- WScript or CScript Dropper - File
- CSExec Service File Creation
- Dynamic CSharp Compile Artefact
- Potential DCOM InternetExplorer.Application DLL Hijack
- Desktop.INI Created by Uncommon Process
- DLL Search Order Hijackig Via Additional Space in Path
- Suspicious ASPX File Drop by Exchange
- Suspicious File Drop by Exchange
- GoToAssist Temporary Installation Artefact
- Uncommon File Created by Notepad++ Updater Gup.EXE
- HackTool - CrackMapExec File Indicators
- HackTool - Dumpert Process Dumper Default File
- HackTool - Typical HiveNightmare SAM File Export
- HackTool - Inveigh Execution Artefacts
- HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators
- HackTool - Mimikatz Kirbi File Creation
- HackTool - NetExec File Indicators
- HackTool - Powerup Write Hijack DLL
- HackTool - QuarksPwDump Dump File
- HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump
- HackTool - SafetyKatz Dump Indicator
- HackTool - Impacket File Indicators
- Potential Initial Access via DLL Search Order Hijacking
- Installation of TeamViewer Desktop
- Malicious DLL File Dropped in the Teams or OneDrive Folder
- ISO File Created Within Temp Folders
- ISO or Image Mount Indicator in Recent Files
- LSASS Process Memory Dump Files
- LSASS Process Dump Artefact In CrashDumps Folder
- WerFault LSASS Process Memory Dump
- Adwind RAT / JRAT File Artifact
- Octopus Scanner Malware
- File Creation In Suspicious Directory By Msdt.EXE
- Suspicious DotNET CLR Usage Log Artifact
- SCR File Write Event
- NTDS.DIT Created
- NTDS.DIT Creation By Uncommon Parent Process
- NTDS.DIT Creation By Uncommon Process
- NTDS Exfiltration Filename Patterns
- Potential Persistence Via Microsoft Office Add-In
- Office Macro File Creation
- Office Macro File Download
- Office Macro File Creation From Suspicious Process
- New Outlook Macro Created
- Potential Persistence Via Outlook Form
- Suspicious File Created in Outlook Temporary Directory
- Suspicious Outlook Macro Created
- Potential Persistence Via Microsoft Office Startup Folder
- File With Uncommon Extension Created By An Office Application
- Uncommon File Created In Office Startup Folder
- PCRE.NET Package Temp Files
- Suspicious File Created In PerfLogs
- Malicious PowerShell Scripts - FileCreation
- Potential Startup Shortcut Persistence Via PowerShell.EXE
- Rclone Config File Creation
- Potential Winnti Dropper Activity
- RemCom Service File Creation
- ScreenConnect Temporary Installation Artefact
- Remote Access Tool - ScreenConnect Temporary File
- Potential RipZip Attack on Startup Folder
- Potential SAM Database Dump
- Self Extraction Directive File Created In Potentially Suspicious Location
- Windows Shell/Scripting Application File Write to Suspicious Folder
- Windows Binaries Write Suspicious Extensions
- Startup Folder File Write
- Suspicious Creation with Colorcpl
- Created Files by Microsoft Sync Center
- Suspicious Files in Default GPO Folder
- Suspicious Desktopimgdownldr Target File
- Suspicious Double Extension Files
- DPAPI Backup Keys And Certificate Export Activity IOC
- Suspicious MSExchangeMailboxReplication ASPX Write
- Suspicious Executable File Creation
- Suspicious File Write to Webapps Root Directory
- Suspicious File Write to SharePoint Layouts Directory
- Suspicious Get-Variable.exe Creation
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream
- Potential Homoglyph Attack Using Lookalike Characters in Filename
- Legitimate Application Dropped Archive
- Legitimate Application Dropped Executable
- Legitimate Application Writing Files In Uncommon Location
- Legitimate Application Dropped Script
- Suspicious LNK Double Extension File Created
- PowerShell Profile Modification
- Suspicious PROCEXP152.sys File Created In TMP
- Suspicious Binaries and Scripts in Public Folder
- Potential File Extension Spoofing Using Right-to-Left Override
- Suspicious Startup Folder Persistence
- Suspicious Interactive PowerShell as SYSTEM
- Suspicious Scheduled Task Write to System32 Tasks
- TeamViewer Remote Session
- VsCode Powershell Profile Modification
- Windows Terminal Profile Settings Modification By Uncommon Process
- ADExplorer Writing Complete AD Snapshot Into .dat File
- Process Explorer Driver Creation By Non-Sysinternals Binary
- Process Monitor Driver Creation By Non-Sysinternals Binary
- PsExec Service File Creation
- PSEXEC Remote Execution File Artefact
- LSASS Process Memory Dump Creation Via Taskmgr.EXE
- Hijack Legit RDP Session to Move Laterally
- UAC Bypass Using Consent and Comctl32 - File
- UAC Bypass Using .NET Code Profiler on MMC
- UAC Bypass Using IDiagnostic Profile - File
- UAC Bypass Using IEInstal - File
- UAC Bypass Using MSConfig Token Modification - File
- UAC Bypass Using NTFS Reparse Point - File
- UAC Bypass Abusing Winsat Path Parsing - File
- UAC Bypass Using Windows Media Player - File
- VHD Image Download Via Browser
- Potential Webshell Creation On Static Website
- Creation of WerFault.exe/Wer.dll in Unusual Folder
- WinRAR Creating Files in Startup Locations
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File
- WMI Persistence - Script Event Consumer File Write
- Wmiexec Default Output File
- Wmiprvse Wbemcomn DLL Hijack - File
- UEFI Persistence Via Wpbbin - FileCreation
- Writing Local Admin Share
- Potentially Suspicious Self Extraction Directive File Created
- Suspicious Appended Extension
- Clfs.SYS Loaded By Process Located In a Potential Suspicious Location
- DLL Loaded From Suspicious Location Via Cmspt.EXE
- Potential Azure Browser SSO Abuse
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32
- CredUI.DLL Loaded By Uncommon Process
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded
- PCRE.NET Package Image Load
- Load Of RstrtMgr.DLL By A Suspicious Process
- Load Of RstrtMgr.DLL By An Uncommon Process
- Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
- PowerShell Core DLL Loaded By Non PowerShell Process
- Time Travel Debugging Utility Usage - Image
- Unsigned .node File Loaded
- Suspicious Volume Shadow Copy VSS_PS.dll Load
- Suspicious Volume Shadow Copy Vssapi.dll Load
- Potentially Suspicious Volume Shadow Copy Vsstrace.dll Load
- HackTool - SharpEvtMute DLL Load
- HackTool - SILENTTRINITY Stager DLL Load
- Potential DCOM InternetExplorer.Application DLL Hijack - Image Load
- Unsigned Image Loaded Into LSASS Process
- DotNET Assembly DLL Loaded Via Office Application
- CLR DLL Loaded Via Office Applications
- GAC DLL Loaded Via Office Applications
- Microsoft Excel Add-In Loaded From Uncommon Location
- Microsoft VBA For Outlook Addin Loaded Via Outlook
- VBA DLL Loaded Via Office Application
- Remote DLL Load Via Rundll32.EXE
- WMI ActiveScriptEventConsumers Activity Via Scrcons.EXE DLL Load
- Potential 7za.DLL Sideloading
- Abusable DLL Potential Sideloading From Suspicious Location
- Potential Antivirus Software DLL Sideloading
- Potential appverifUI.DLL Sideloading
- Aruba Network Service Potential DLL Sideloading
- Potential AVKkid.DLL Sideloading
- Potential CCleanerDU.DLL Sideloading
- Potential CCleanerReactivator.DLL Sideloading
- Potential Chrome Frame Helper DLL Sideloading
- Potential DLL Sideloading Via ClassicExplorer32.dll
- Potential DLL Sideloading Via comctl32.dll
- Potential DLL Sideloading Using Coregen.exe
- System Control Panel Item Loaded From Uncommon Location
- Potential DLL Sideloading Of DBGCORE.DLL
- Potential DLL Sideloading Of DBGHELP.DLL
- Potential DLL Sideloading Of DbgModel.DLL
- Potential EACore.DLL Sideloading
- Potential Edputil.DLL Sideloading
- Potential System DLL Sideloading From Non System Locations
- Potential Goopdate.DLL Sideloading
- Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE
- Potential Iviewers.DLL Sideloading
- Potential JLI.dll Side-Loading
- Potential DLL Sideloading Via JsSchHlp
- Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
- Potential Libvlc.DLL Sideloading
- Potential Mfdetours.DLL Sideloading
- Unsigned Mfdetours.DLL Sideloading
- Potential DLL Sideloading Of MpSvc.DLL
- Potential DLL Sideloading Of MsCorSvc.DLL
- Potential DLL Sideloading Of Non-Existent DLLs From System Folders
- Microsoft Office DLL Sideload
- Potential Python DLL SideLoading
- Potential Rcdll.DLL Sideloading
- Potential RjvPlatform.DLL Sideloading From Default Location
- Potential RjvPlatform.DLL Sideloading From Non-Default Location
- Potential RoboForm.DLL Sideloading
- DLL Sideloading Of ShellChromeAPI.DLL
- Potential ShellDispatch.DLL Sideloading
- Potential SmadHook.DLL Sideloading
- Potential SolidPDFCreator.DLL Sideloading
- Third Party Software DLL Sideloading
- Fax Service DLL Search Order Hijack
- Potential Vcruntime140 DLL Sideloading
- Potential Vivaldi_elf.DLL Sideloading
- VMGuestLib DLL Sideload
- VMMap Signed Dbghelp.DLL Potential Sideloading
- VMMap Unsigned Dbghelp.DLL Potential Sideloading
- Potential DLL Sideloading Via VMware Xfer
- Potential Waveedit.DLL Sideloading
- Potential Wazuh Security Platform DLL Sideloading
- Potential Mpclient.DLL Sideloading
- Potential WWlib.DLL Sideloading
- BaaUpdate.exe Suspicious DLL Load
- Unsigned Module Loaded by ClickOnce Application
- DLL Load By System Process From Suspicious Locations
- Python Image Load By Non-Python Process
- DotNet CLR DLL Loaded By Scripting Applications
- Unsigned DLL Loaded by Windows Utility
- Suspicious Unsigned Thor Scanner Execution
- UAC Bypass Using Iscsicpl - ImageLoad
- UAC Bypass With Fake DLL
- MMC Loading Script Engines DLLs
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location
- Trusted Path Bypass via Windows Directory Spoofing
- WMI Persistence - Command Line Event Consumer
- WMIC Loading Scripting Libraries
- Wmiprvse Wbemcomn DLL Hijack
- Suspicious WSMAN Provider Image Loads
- Network Connection Initiated By AddinUtil.EXE
- Uncommon Connection to Active Directory Web Services
- Uncommon Network Connection Initiated By Certutil.EXE
- Outbound Network Connection Initiated By Cmstp.EXE
- Outbound Network Connection Initiated By Microsoft Dialer
- Network Connection Initiated To AzureWebsites.NET By Non-Browser Process
- Network Connection Initiated To BTunnels Domains
- Network Connection Initiated To Cloudflared Tunnels Domains
- Network Communication With Crypto Mining Pool
- New Connection Initiated To Potential Dead Drop Resolver Domain
- Network Connection Initiated To DevTunnels Domain
- Suspicious Dropbox API Usage
- Suspicious Network Connection to IP Lookup Service APIs
- Suspicious Non-Browser Network Communication With Google API
- Communication To LocaltoNet Tunneling Service Initiated
- Network Connection Initiated To Mega.nz
- Process Initiated Network Connection To Ngrok Domain
- Communication To Ngrok Tunneling Service Initiated
- Potentially Suspicious Network Connection To Notion API
- Network Communication Initiated To Portmap.IO Domain
- Suspicious Non-Browser Network Communication With Telegram API
- Network Connection Initiated To Visual Studio Code Tunnels Domain
- Network Connection Initiated By Eqnedt32.EXE
- Network Connection Initiated via Finger.EXE
- Network Connection Initiated By IMEWDBLD.EXE
- Non-Mail Client IMAP Connection Hunt Starter
- Network Connection Initiated Via Notepad.EXE
- Office Application Initiated Network Connection To Non-Local IP
- Python Initiated Connection
- Outbound RDP Connections Over Non-Standard Tools
- RDP Over Reverse SSH Tunnel
- RDP to HTTP or HTTPS Target Ports
- RegAsm.EXE Initiating Network Connection To Public IP
- Network Connection Initiated By Regsvr32.EXE
- Remote Access Tool - AnyDesk Incoming Connection
- Rundll32 Internet Connection
- Silenttrinity Stager Msbuild Activity
- Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder
- Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location
- Potentially Suspicious Malware Callback Communication
- Communication To Uncommon Destination Ports
- Uncommon Outbound Kerberos Connection
- Microsoft Sync Center Suspicious Network Connections
- Suspicious Outbound SMTP Connections
- Potential Remote PowerShell Session Initiated
- Outbound Network Connection To Public IP Via Winlogon
- Local Network Connection Initiated By Script Interpreter
- Outbound Network Connection Initiated By Script Interpreter
- Potentially Suspicious Wuauclt Network Connection
- ADFS Database Named Pipe Connection By Uncommon Tool
- CobaltStrike Named Pipe
- CobaltStrike Named Pipe Pattern Regex
- CobaltStrike Named Pipe Patterns
- HackTool - CoercedPotato Named Pipe Creation
- HackTool - EfsPotato Named Pipe Creation
- HackTool - Credential Dumping Tools Named Pipe Created
- HackTool - Koh Default Named Pipe
- Alternate PowerShell Hosts Pipe
- New PowerShell Instance Created
- PUA - CSExec Default Named Pipe
- PUA - PAExec Default Named Pipe
- PUA - RemCom Default Named Pipe
- WMI Event Consumer Created Named Pipe
- Malicious Named Pipe Created
- PsExec Tool Execution From Suspicious Locations - PipeName
- Nslookup PowerShell Download Cradle
- Delete Volume Shadow Copies Via WMI With PowerShell
- PowerShell Downgrade Attack - PowerShell
- PowerShell Download Via Net.WebClient - PowerShell Classic
- PowerShell Called from an Executable Version Mismatch
- Netcat The Powershell Version
- Remote PowerShell Session (PS Classic)
- Potential RemoteFXvGPUDisablement.EXE Abuse
- Renamed Powershell Under Powershell Channel
- Use Get-NetTCPConnection
- Zip A Folder With PowerShell For Staging In Temp - PowerShell
- Tamper Windows Defender - PSClassic
- Suspicious Non PowerShell WSMAN COM Provider
- Alternate PowerShell Hosts - PowerShell Module
- Bad Opsec Powershell Code Artifacts
- Clear PowerShell History - PowerShell Module
- PowerShell Decompress Commands
- Malicious PowerShell Scripts - PoshModule
- Suspicious Get-ADDBAccount Usage
- PowerShell Get Clipboard
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
- Invoke-Obfuscation Via Stdin - PowerShell Module
- Invoke-Obfuscation Via Use Clip - PowerShell Module
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
- Malicious PowerShell Commandlets - PoshModule
- Remote PowerShell Session (PS Module)
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module
- AD Groups Or Users Enumeration Using PowerShell - PoshModule
- Suspicious PowerShell Download - PoshModule
- Use Get-NetTCPConnection - PowerShell Module
- Suspicious PowerShell Invocations - Generic - PowerShell Module
- Suspicious PowerShell Invocations - Specific - PowerShell Module
- Suspicious Get Local Groups Information
- Suspicious Computer Machine Password by PowerShell
- Suspicious Get Information for SMB Share - PowerShell Module
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Module
- SyncAppvPublishingServer Bypass Powershell Restriction - PS Module
- Access to Browser Login Data
- Powershell Add Name Resolution Policy Table Rule
- PowerShell ADRecon Execution
- AMSI Bypass Pattern Assembly GetType
- Potential AMSI Bypass Script Using NULL Bits
- Silence.EDA Detection
- Get-ADUser Enumeration Using UserAccountControl Flags
- Automated Collection Command PowerShell
- Windows Screen Capture with CopyFromScreen
- Clear PowerShell History - PowerShell
- Clearing Windows Console History
- Powershell Create Scheduled Task
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell
- Powershell Install a DLL in System Directory
- Registry-Free Process Scope COR_PROFILER
- PowerShell Create Local User
- DMSA Service Account Created in Specific OUs - PowerShell
- Create Volume Shadow Copy with Powershell
- Powershell Detect Virtualization Environment
- DirectorySearcher Powershell Exploitation
- Manipulation of User Computer or Group Security Principals Across AD
- Disable Powershell Command History
- Disable-WindowsOptionalFeature Command PowerShell
- Potential In-Memory Execution Using Reflection.Assembly
- Potential COM Objects Download Cradles Usage - PS Script
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock
- Dump Credentials from Windows Credential Manager With PowerShell
- Enable Windows Remote Management
- Enumerate Credentials from Windows Credential Manager With PowerShell
- Disable of ETW Trace - Powershell
- Certificate Exported Via PowerShell - ScriptBlock
- Suspicious FromBase64String Usage On Gzip Archive - Ps Script
- Service Registry Permissions Weakness Check
- Active Directory Computers Enumeration With Get-AdComputer
- Active Directory Group Enumeration With Get-AdGroup
- Suspicious Get-ADReplAccount
- Automated Collection Bookmarks Using Get-ChildItem PowerShell
- Security Software Discovery Via Powershell Script
- HackTool - Rubeus Execution - ScriptBlock
- HackTool - WinPwn Execution - ScriptBlock
- PowerShell ICMP Exfiltration
- Import PowerShell Modules From Suspicious Directories
- Execute Invoke-command on Remote Host
- Powershell DNSExfiltration
- Invoke-Obfuscation CLIP+ Launcher - PowerShell
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
- Invoke-Obfuscation STDIN+ Launcher - Powershell
- Invoke-Obfuscation VAR+ Launcher - PowerShell
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
- Invoke-Obfuscation Via Stdin - Powershell
- Invoke-Obfuscation Via Use Clip - Powershell
- Invoke-Obfuscation Via Use MSHTA - PowerShell
- Invoke-Obfuscation Via Use Rundll32 - PowerShell
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
- Powershell Keylogging
- Powershell LocalAccount Manipulation
- Malicious PowerShell Commandlets - ScriptBlock
- Malicious PowerShell Keywords
- Live Memory Dump Using Powershell
- DMSA Link Attributes Modified
- Modify Group Policy Settings - ScriptBlockLogging
- Powershell MsXml COM Object
- Malicious Nishang PowerShell Commandlets
- NTFS Alternate Data Stream
- Code Executed Via Office Add-in XLL File
- Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock
- Potential Invoke-Mimikatz PowerShell Script
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
- PowerShell Web Access Installation - PsScript
- PowerView PowerShell Cmdlets - ScriptBlock
- PowerShell Credential Prompt
- PSAsyncShell - Asynchronous TCP Reverse Shell
- PowerShell PSAttack
- PowerShell Remote Session Creation
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
- Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock
- PowerShell Script With File Hostname Resolving Capabilities
- Root Certificate Installed - PowerShell
- Suspicious Invoke-Item From Mount-DiskImage
- PowerShell Script With File Upload Capabilities
- Powershell Sensitive File Discovery
- PowerShell Script Change Permission Via Set-Acl - PsScript
- PowerShell Set-Acl On Windows Folder - PsScript
- Change PowerShell Policies to an Insecure Level - PowerShell
- PowerShell ShellCode
- Malicious ShellIntel PowerShell Commandlets
- Detected Windows Software Discovery - PowerShell
- Powershell Store File In Alternate Data Stream
- AD Groups Or Users Enumeration Using PowerShell - ScriptBlock
- Potential PowerShell Obfuscation Using Character Join
- Suspicious Eventlog Clear
- Powershell Directory Enumeration
- Suspicious PowerShell Download - Powershell Script
- Powershell Execute Batch Script
- Extracting Information with PowerShell
- Troubleshooting Pack Cmdlet Execution
- Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy
- Suspicious PowerShell Get Current User
- Suspicious GPO Discovery With Get-GPO
- Suspicious Process Discovery With Get-Process
- PowerShell Get-Process LSASS in ScriptBlock
- Suspicious GetTypeFromCLSID ShellExecute
- Suspicious Hyper-V Cmdlets
- Suspicious PowerShell Invocations - Generic
- Suspicious PowerShell Invocations - Specific
- Change User Agents with WebRequest
- Suspicious IO.FileStream
- Potential Keylogger Activity
- Potential Suspicious PowerShell Keywords
- Suspicious Get Local Groups Information - PowerShell
- Powershell Local Email Collection
- Suspicious Mount-DiskImage
- PowerShell Deleted Mounted Share
- Suspicious Connection to Remote Account
- Suspicious New-PSDrive to Admin Share
- Suspicious TCP Tunnel Via PowerShell Script
- Recon Information for Export with PowerShell
- Remove Account From Domain Admin Group
- Suspicious Service DACL Modification Via Set-Service Cmdlet - PS
- Potential PowerShell Obfuscation Using Alias Cmdlets
- Suspicious Get Information for SMB Share
- Suspicious SSL Connection
- Suspicious Start-Process PassThru
- Suspicious Unblock-File
- Replace Desktop Wallpaper by Powershell
- Powershell Suspicious Win32_PnPEntity
- Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script
- Suspicious PowerShell WindowStyle Option
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Script
- SyncAppvPublishingServer Execution to Bypass Powershell Restriction
- Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
- Tamper Windows Defender - ScriptBlockLogging
- Testing Usage of Uncommonly Used Port
- Powershell Timestomp
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell
- Potential Persistence Via PowerShell User Profile Using Add-Content
- Abuse of Service Permissions to Hide Services Via Set-Service - PS
- Registry Modification Attempt Via VBScript - PowerShell
- Usage Of Web Request Commands And Cmdlets - ScriptBlock
- PowerShell WMI Win32_Product Install MSI
- Potential WinAPI Calls Via PowerShell Scripts
- Windows Defender Exclusions Added - PowerShell
- Windows Firewall Profile Disabled
- Winlogon Helper DLL
- Powershell WMI Persistence
- WMIC Unquoted Services Path Lookup - PowerShell
- WMImplant Hack Tool
- Suspicious X509Enrollment - Ps Script
- Powershell XML Execute Command
- CMSTP Execution Process Access
- HackTool - CobaltStrike BOF Injection Pattern
- HackTool - Generic Process Access
- HackTool - HandleKatz Duplicating LSASS Handle
- HackTool - LittleCorporal Generated Maldoc Injection
- HackTool - SysmonEnte Execution
- Lsass Memory Dump via Comsvcs DLL
- LSASS Memory Access by Tool With Dump Keyword In Name
- Potential Credential Dumping Activity Via LSASS
- Credential Dumping Activity By Python Based Tool
- Remote LSASS Process Access Through Windows Remote Management
- Suspicious LSASS Access Via MalSecLogon
- Potentially Suspicious GrantedAccess Flags On LSASS
- Credential Dumping Attempt Via WerFault
- LSASS Access From Potentially White-Listed Processes
- Uncommon Process Access Rights For Target Image
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs
- Potential Direct Syscall of NtOpenProcess
- Credential Dumping Attempt Via Svchost
- Suspicious Svchost Process Access
- Function Call From Undocumented COM Interface EditionUpgradeManager
- UAC Bypass Using WOW64 Logger DLL Hijack
- Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze
- 7Zip Compressing Dump Files
- Compress Data and Lock With Password for Exfiltration With 7-ZIP
- Suspicious AddinUtil.EXE CommandLine Execution
- Uncommon Child Process Of AddinUtil.EXE
- Uncommon AddinUtil.EXE CommandLine Execution
- AddinUtil.EXE Execution From Uncommon Directory
- Potential Adplus.EXE Abuse
- AgentExecutor PowerShell Execution
- Suspicious AgentExecutor PowerShell Execution
- Windows AMSI Related Registry Tampering Via CommandLine
- Uncommon Child Process Of Appvlp.EXE
- Suspicious ArcSOC.exe Child Process
- AspNetCompiler Execution
- Suspicious Child Process of AspNetCompiler
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler
- Interactive AT Job
- Uncommon Assistive Technology Applications Execution Via AtBroker.EXE
- Hiding Files with Attrib.exe
- Set Suspicious Files as System Files Using Attrib.EXE
- Audit Policy Tampering Via NT Resource Kit Auditpol
- Audit Policy Tampering Via Auditpol
- Windows EventLog Autologger Session Registry Modification Via CommandLine
- Suspicious Autorun Registry Modified via WMI
- Suspicious BitLocker Access Agent Update Utility Execution
- Indirect Inline Command Execution Via Bash.EXE
- Indirect Command Execution From Script File Via Bash.EXE
- Boot Configuration Tampering Via Bcdedit.EXE
- Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE
- Data Export From MSSQL Table Via BCP.EXE
- Suspicious Child Process Of BgInfo.EXE
- Uncommon Child Process Of BgInfo.EXE
- BitLockerTogo.EXE Execution
- File Download Via Bitsadmin
- Suspicious Download From Direct IP Via Bitsadmin
- Suspicious Download From File-Sharing Website Via Bitsadmin
- File With Suspicious Extension Downloaded Via Bitsadmin
- File Download Via Bitsadmin To A Suspicious Target Folder
- Monitoring For Persistence Via BITS
- Potential Data Stealing Via Chromium Headless Debugging
- Browser Execution In Headless Mode
- File Download with Headless Browser
- Chromium Browser Instance Executed With Custom Extension
- Suspicious Chromium Browser Instance Executed With Custom Extension
- File Download From Browser Process Via Inline URL
- Browser Started with Remote Debugging
- Tor Client/Browser Execution
- Suspicious Calculator Usage
- Potential Binary Proxy Execution Via Cdb.EXE
- New Root Certificate Installed Via CertMgr.EXE
- File Download via CertOC.EXE
- File Download From IP Based URL Via CertOC.EXE
- DLL Loaded via CertOC.EXE
- Suspicious DLL Loaded via CertOC.EXE
- Suspicious CertReq Command to Download
- New Root Certificate Installed Via Certutil.EXE
- File Decoded From Base64/Hex Via Certutil.EXE
- Suspicious Download Via Certutil.EXE
- Suspicious File Downloaded From Direct IP Via Certutil.EXE
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
- File Encoded To Base64 Via Certutil.EXE
- Suspicious File Encoded To Base64 Via Certutil.EXE
- File In Suspicious Location Encoded To Base64 Via Certutil.EXE
- Certificate Exported Via Certutil.EXE
- Potential NTLM Coercion Via Certutil.EXE
- Console CodePage Lookup Via CHCP
- Suspicious CodePage Switch Via CHCP
- Deleted Data Overwritten Via Cipher.EXE
- Process Access via TrolleyExpress Exclusion
- Data Copied To Clipboard Via Clip.EXE
- Cloudflared Portable Execution
- Cloudflared Quick Tunnel Execution
- Cloudflared Tunnel Connections Cleanup
- Cloudflared Tunnel Execution
- Change Default File Association Via Assoc
- Change Default File Association To Executable Via Assoc
- Curl Download And Execute Combination
- File Deletion Via Del
- Greedy File Deletion Using Del
- File And SubFolder Enumeration Via Dir Command
- Potential Dosfuscation Activity
- Command Line Execution with Suspicious URL and AppData Strings
- Cmd Launched with Hidden Start Flags to Suspicious Targets
- Potential Privilege Escalation Using Symlink Between Osk and Cmd
- VolumeShadowCopy Symlink Creation Via Mklink
- Suspicious File Execution From Internet Hosted WebDav Share
- Cmd.EXE Missing Space Characters Execution Anomaly
- Potential CommandLine Path Traversal Via Cmd.EXE
- Potentially Suspicious Ping/Copy Command Combination
- Suspicious Ping/Del Command Combination
- Potentially Suspicious CMD Shell Output Redirect
- Directory Removal Via Rmdir
- Copy From VolumeShadowCopy Via Cmd.EXE
- Read Contents From Stdin Via Cmd.EXE
- Sticky Key Like Backdoor Execution
- Persistence Via Sticky Key Backdoor
- Potential Download/Upload Activity Using Type Command
- Unusual Parent Process For Cmd.EXE
- New Generic Credentials Added Via Cmdkey.EXE
- Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE
- Potential Arbitrary File Download Via Cmdl32.EXE
- CMSTP Execution Process Creation
- OpenEDR Spawning Command Shell
- Arbitrary File Download Via ConfigSecurityPolicy.EXE
- Powershell Executed From Headless ConHost Process
- Suspicious High IntegrityLevel Conhost Legacy Option
- Conhost.exe CommandLine Path Traversal
- Uncommon Child Process Of Conhost.EXE
- Potentially Suspicious Child Processes Spawned by ConHost
- Conhost Spawned By Uncommon Parent Process
- Control Panel Items
- New DMSA Service Account Created in Specific OUs
- CreateDump Process Dump
- Windows Credential Guard Registry Tampering Via CommandLine
- Dynamic .NET Compilation Via Csc.EXE
- Csc.EXE Execution Form Potentially Suspicious Parent
- Suspicious Csi.exe Usage
- Suspicious Use of CSharp Interactive Console
- Active Directory Structure Export Via Csvde.EXE
- NTLM Hash Leak Via Curl NTLM Authentication
- Suspicious Curl.EXE Download
- Curl File Upload To File Sharing Websites
- Suspicious CustomShellHost Execution
- ManageEngine Endpoint Central Dctask64.EXE Potential Abuse
- Uncommon Child Process Of Defaultpack.EXE
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction'
- Windows Defender Context Menu Removed
- Deno Runtime Spawns Shell Or Scripting Interpreter
- Remote File Download Via Desktopimgdownldr Utility
- Suspicious Desktopimgdownldr Command
- Devcon Execution Disabling VMware VMCI Device
- DeviceCredentialDeployment Execution
- Potential DLL Sideloading Via DeviceEnroller.EXE
- Arbitrary MSI Download Via Devinit.EXE
- DirLister Execution
- System Information Discovery via Registry Queries
- Potentially Suspicious Child Process Of DiskShadow.EXE
- Diskshadow Script Mode - Uncommon Script Extension Execution
- Diskshadow Script Mode - Execution From Potential Suspicious Location
- PowerShell Web Access Feature Enabled Via DISM
- Dism Remove Online Package
- DLL Sideloading by VMware Xfer Utility
- Dllhost.EXE Execution Anomaly
- DNS Exfiltration and Tunneling Tools Execution
- Unusual Child Process of dns.exe
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
- Potential Application Whitelisting Bypass via Dnx.EXE
- Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE
- Binary Proxy Execution Via Dotnet-Trace.EXE
- Process Memory Dump Via Dotnet-Dump
- Potentially Over Permissive Permissions Granted Using Dsacls.EXE
- Potential Password Spraying Attempt Using Dsacls.EXE
- Domain Trust Discovery Via Dsquery
- Suspicious Kernel Dump Using Dtrace
- Potential Windows Defender AV Bypass Via Dump64.EXE Rename
- DumpMinitool Execution
- Suspicious DumpMinitool Execution
- New Capture Session Launched Via DXCap.EXE
- Esentutl Gather Credentials
- Copying Sensitive Files with Credential Data
- Esentutl Steals Browser Information
- Security Event Logging Disabled via MiniNt Registry Key - Process
- Potentially Suspicious Event Viewer Child Process
- Potentially Suspicious Cabinet File Expansion
- Explorer Process Tree Break
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell
- Explorer NOUACCHECK Flag
- Remote File Download Via Findstr.EXE
- Findstr GPP Passwords
- Findstr Launching .lnk File
- LSASS Process Reconnaissance Via Findstr.EXE
- Permission Misconfiguration Reconnaissance Via Findstr.EXE
- Recon Command Output Piped To Findstr.EXE
- Security Tools Keyword Lookup Via Findstr.EXE
- Insensitive Subfolder Search Via Findstr.EXE
- Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE
- Finger.EXE Execution
- Filter Driver Unloaded Via Fltmc.EXE
- Sysmon Driver Unloaded Via Fltmc.EXE
- Forfiles.EXE Child Process Masquerading
- Forfiles Command Execution
- Use of FSharp Interpreters
- Fsutil Drive Enumeration
- Potentially Suspicious NTFS Symlink Behavior Modification
- Fsutil Suspicious Invocation
- Potential Arbitrary Command Execution Via FTP.EXE
- Arbitrary File Download Via GfxDownloadWrapper.EXE
- Suspicious Git Clone
- Github Self-Hosted Runner Execution
- Portable Gpg.EXE Execution
- Gpresult Display Group Policy Information
- File Download Using Notepad++ GUP Utility
- Suspicious Child Process of Notepad++ Updater - GUP.Exe
- Suspicious GUP Usage
- HH.EXE Execution
- Remote CHM File Download/Execution Via HH.EXE
- HTML Help HH.EXE Suspicious Child Process
- Suspicious HH.EXE Execution
- HackTool - ADCSPwn Execution
- HackTool - Bloodhound/Sharphound Execution
- HackTool - F-Secure C3 Load by Rundll32
- HackTool - Certify Execution
- HackTool - Certipy Execution
- Operator Bloopers Cobalt Strike Commands
- Operator Bloopers Cobalt Strike Modules
- CobaltStrike Load by Rundll32
- Potential CobaltStrike Process Patterns
- HackTool - CoercedPotato Execution
- HackTool - Covenant PowerShell Launcher
- HackTool - CrackMapExec Execution
- HackTool - CrackMapExec Execution Patterns
- HackTool - CrackMapExec Process Patterns
- HackTool - CrackMapExec PowerShell Obfuscation
- HackTool - CreateMiniDump Execution
- HackTool - DInjector PowerShell Cradle Execution
- HackTool - Doppelanger LSASS Dumper Execution
- HackTool - Dumpert Process Dumper Execution
- Hacktool - EDR-Freeze Execution
- HackTool - EDRSilencer Execution
- HackTool - Empire PowerShell Launch Parameters
- HackTool - Empire PowerShell UAC Bypass
- HackTool - WinRM Access Via Evil-WinRM
- Hacktool Execution - Imphash
- Hacktool Execution - PE Metadata
- HackTool - HandleKatz LSASS Dumper Execution
- HackTool - Hashcat Password Cracker Execution
- HackTool - HollowReaper Execution
- HackTool - Htran/NATBypass Execution
- HackTool - Hydra Password Bruteforce Execution
- HackTool - Potential Impacket Lateral Movement Activity
- HackTool - Impacket Tools Execution
- HackTool - Impersonate Execution
- HackTool - Inveigh Execution
- Invoke-Obfuscation CLIP+ Launcher
- Invoke-Obfuscation Obfuscated IEX Invocation
- Invoke-Obfuscation STDIN+ Launcher
- Invoke-Obfuscation VAR+ Launcher
- Invoke-Obfuscation COMPRESS OBFUSCATION
- Invoke-Obfuscation Via Stdin
- Invoke-Obfuscation Via Use Clip
- Invoke-Obfuscation Via Use MSHTA
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
- HackTool - Jlaive In-Memory Assembly Execution
- HackTool - Koadic Execution
- HackTool - KrbRelay Execution
- HackTool - RemoteKrbRelay Execution
- HackTool - KrbRelayUp Execution
- Potential Meterpreter/CobaltStrike Activity
- HackTool - Mimikatz Execution
- HackTool - NetExec Execution
- HackTool - PCHunter Execution
- HackTool - Default PowerSploit/Empire Scheduled Task Creation
- HackTool - PowerTool Execution
- HackTool - PurpleSharp Execution
- HackTool - Pypykatz Credentials Dumping Activity
- HackTool - Quarks PwDump Execution
- HackTool - RedMimicry Winnti Playbook Execution
- Potential SMB Relay Attack Tool Execution
- HackTool - Rubeus Execution
- HackTool - SafetyKatz Execution
- HackTool - SecurityXploded Execution
- HackTool - PPID Spoofing SelectMyParent Tool Execution
- HackTool - SharpChisel Execution
- HackTool - SharpDPAPI Execution
- HackTool - SharpImpersonation Execution
- HackTool - SharPersist Execution
- HackTool - SharpEvtMute Execution
- HackTool - SharpLdapWhoami Execution
- HackTool - SharpMove Tool Execution
- HKTL - SharpSuccessor Privilege Escalation Tool Execution
- HackTool - SharpUp PrivEsc Tool Execution
- HackTool - SharpView Execution
- HackTool - SharpWSUS/WSUSpendu Execution
- HackTool - SILENTTRINITY Stager Execution
- HackTool - Sliver C2 Implant Activity Pattern
- HackTool - SOAPHound Execution
- HackTool - Stracciatella Execution
- HackTool - SysmonEOP Execution
- HackTool - TruffleSnout Execution
- HackTool - UACMe Akagi Execution
- HackTool - Windows Credential Editor (WCE) Execution
- HackTool - winPEAS Execution
- HackTool - WinPwn Execution
- HackTool - WSASS Execution
- HackTool - XORDump Execution
- Suspicious ZipExec Execution
- Suspicious Execution of Hostname
- Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine
- Suspicious HWP Sub Processes
- Potential Fake Instance Of Hxtsr.EXE Executed
- Use Icacls to Hide File to Everyone
- File Download And Execution Via IEExec.EXE
- Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location
- Disable Windows IIS HTTP Logging
- Microsoft IIS Service Account Password Dumped
- IIS Native-Code Module Command Line Installation
- Microsoft IIS Connection Strings Decryption
- IIS WebServer Log Deletion via CommandLine Utilities
- Suspicious IIS Module Registration
- C# IL Code Compilation Via Ilasm.EXE
- Arbitrary File Download Via IMEWDBLD.EXE
- InfDefaultInstall.exe .inf Execution
- File Download Via InstallUtil.EXE
- Suspicious Child Process Of Manage Engine ServiceDesk
- Java Running with Remote Debugging
- Suspicious SysAidServer Child
- JScript Compiler Execution
- Kavremover Dropped Binary LOLBIN Usage
- Attempts of Kerberos Coercion Via DNS SPN Spoofing
- Potentially Suspicious Child Process of KeyScrambler.exe
- Import LDAP Data Interchange Format File Via Ldifde.EXE
- Uncommon Link.EXE Parent Process
- Suspicious Windows Trace ETW Session Tamper Via Logman.EXE
- LOLBAS Data Exfiltration by DataSvcUtil.exe
- Devtoolslauncher.exe Executes Specified Binary
- Suspicious Diantz Alternate Data Stream Execution
- Suspicious Diantz Download and Compress Into a CAB File
- Suspicious Extrac32 Execution
- Suspicious Extrac32 Alternate Data Stream Execution
- Potential Reconnaissance Activity Via GatherNetworkInfo.VBS
- Gpscript Execution
- Ie4uinit Lolbin Use From Invalid Path
- Launch-VsDevShell.PS1 Proxy Execution
- Potential Manage-bde.wsf Abuse To Proxy Execution
- Mavinject Inject DLL Into Running Process
- MpiExec Lolbin
- Execute Files with Msdeploy.exe
- Use of OpenConsole
- OpenWith.exe Executes Specified Binary
- Use of Pcalua For Execution
- Indirect Command Execution By Program Compatibility Wizard
- Execute Pcwrun.EXE To Leverage Follina
- Code Execution via Pcwutl.dll
- Execute Code with Pester.bat as Parent
- Execute Code with Pester.bat
- PrintBrm ZIP Creation of Extraction
- Pubprn.vbs Proxy Execution
- DLL Execution via Rasautou.exe
- REGISTER_APP.VBS Proxy Execution
- Use of Remote.exe
- Replace.exe Usage
- Lolbin Runexehelper Use As Proxy
- Suspicious Runscripthelper.exe
- Use of Scriptrunner.exe
- Using SettingSyncHost.exe as LOLBin
- Use Of The SFTP.EXE Binary As A LOLBIN
- Suspicious Driver Install by pnputil.exe
- Suspicious GrpConv Execution
- Dumping Process via Sqldumper.exe
- SyncAppvPublishingServer Execute Arbitrary PowerShell Code
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code
- Potential DLL Injection Or Execution Using Tracker.exe
- Use of TTDInject.exe
- Time Travel Debugging Utility Usage
- Lolbin Unregmp2.exe Use As Proxy
- UtilityFunctions.ps1 Proxy Dll
- Visual Basic Command Line Compiler Usage
- Use of VisualUiaVerifyNative.exe
- Use of VSIISExeLauncher.exe
- Use of Wfc.exe
- Potential Register_App.Vbs LOLScript Abuse
- LSA PPL Protection Setting Modification via CommandLine
- Potential Credential Dumping Via LSASS Process Clone
- Potential Mftrace.EXE Abuse
- Windows Default Domain GPO Modification via GPME
- MMC20 Lateral Movement
- MMC Executing Files with Reversed Extensions Using RTLO Abuse
- MMC Spawning Windows Shell
- CodePage Modification Via MODE.COM To Russian Language
- Potential Suspicious Mofcomp Execution
- Potential Mpclient.DLL Sideloading Via Defender Binaries
- File Download Via Windows Defender MpCmpRun.EXE
- Windows Defender Definition Files Removed
- MSDT Execution Via Answer File
- Potential Arbitrary Command Execution Using Msdt.EXE
- Suspicious Cabinet File Execution Via Msdt.EXE
- Suspicious MSDT Parent Process
- Arbitrary File Download Via MSEDGE_PROXY.EXE
- Remotely Hosted HTA File Executed Via Mshta.EXE
- Wscript Shell Run In CommandLine
- Suspicious JavaScript Execution Via Mshta.EXE
- Potential LethalHTA Technique Execution
- Suspicious MSHTA Child Process
- MSHTA Execution with Suspicious File Extensions
- Suspicious Mshta.EXE Execution Patterns
- DllUnregisterServer Function Call Via Msiexec.EXE
- Suspicious MsiExec Embedding Parent
- Suspicious Msiexec Execute Arbitrary DLL
- Msiexec Quiet Installation
- Suspicious Msiexec Quiet Install From Remote Location
- Potential MsiExec Masquerading
- MsiExec Web Install
- Windows MSIX Package Support Framework AI_STUBS Execution
- Arbitrary File Download Via MSOHTMED.EXE
- Arbitrary File Download Via MSPUB.EXE
- Potential Process Injection Via Msra.EXE
- Detection of PowerShell Execution via Sqlps.exe
- SQL Client Tools PowerShell Session Detection
- Suspicious Child Process Of SQL Server
- Potential MSTSC Shadowing Activity
- New Remote Desktop Connection Initiated Via Mstsc.EXE
- Mstsc.EXE Execution With Local RDP File
- Suspicious Mstsc.EXE Execution With Local RDP File
- Msxsl.EXE Execution
- Remote XSL Execution Via Msxsl.EXE
- Suspicious Group And Account Reconnaissance Activity Using Net.EXE
- Unmount Share Via Net.EXE
- Start Windows Service Via Net.EXE
- Stop Windows Service Via Net.EXE
- Windows Admin Share Mount Via Net.EXE
- Windows Internet Hosted WebDav Share Mount Via Net.EXE
- Windows Share Mount Via Net.EXE
- System Network Connections Discovery Via Net.EXE
- Password Provided In Command Line Of Net.EXE
- New User Created Via Net.EXE
- New User Created Via Net.EXE With Never Expire Option
- Suspicious Manipulation Of Default Accounts Via Net.EXE
- Share And Session Enumeration Using Net.EXE
- New Firewall Rule Added Via Netsh.EXE
- Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE
- RDP Connection Allowed Via Netsh.EXE
- Firewall Rule Deleted Via Netsh.EXE
- Firewall Disabled via Netsh.EXE
- Netsh Allow Group Policy on Microsoft Defender Firewall
- Firewall Configuration Discovery Via Netsh.EXE
- Potential Persistence Via Netsh Helper DLL
- New Network Trace Capture Started Via Netsh.EXE
- New Port Forwarding Rule Added Via Netsh.EXE
- RDP Port Forwarding Rule Added Via Netsh.EXE
- Harvesting Of Wifi Credentials Via Netsh.EXE
- Nltest.EXE Execution
- Potential Recon Activity Via Nltest.EXE
- Potential Arbitrary Code Execution Via Node.EXE
- Node Process Executions
- Notepad Password Files Discovery
- Network Reconnaissance Activity
- Suspicious Usage Of Active Directory Diagnostic Tool (ntdsutil.exe)
- Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)
- Driver/DLL Installation Via Odbcconf.EXE
- Suspicious Driver/DLL Installation Via Odbcconf.EXE
- Odbcconf.EXE Suspicious DLL Location
- New DLL Registered Via Odbcconf.EXE
- Potentially Suspicious DLL Registered Via Odbcconf.EXE
- Response File Execution Via Odbcconf.EXE
- Suspicious Response File Execution Via Odbcconf.EXE
- Uncommon Child Process Spawned By Odbcconf.EXE
- Potential Arbitrary File Download Using Office Application
- Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp
- Potentially Suspicious Office Document Executed From Trusted Location
- OneNote.EXE Execution of Malicious Embedded Scripts
- Suspicious Microsoft OneNote Child Process
- Outlook EnableUnsafeClientMailRules Setting Enabled
- Suspicious Execution From Outlook Temporary Folder
- Suspicious Outlook Child Process
- Suspicious Remote Child Process From Outlook
- Suspicious Binary In User Directory Spawned From Office Application
- Suspicious Microsoft Office Child Process
- Potential Arbitrary DLL Load Using Winword
- Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution
- PDQ Deploy Remote Adminstartion Tool Execution
- Perl Inline Command Execution
- Php Inline Command Execution
- Ping Hex IP
- PktMon.EXE Execution
- Suspicious Plink Port Forwarding
- Potential RDP Tunneling Via Plink
- Potential AMSI Bypass Via .NET Reflection
- Potential AMSI Bypass Using NULL Bits
- Audio Capture via PowerShell
- Suspicious Encoded PowerShell Command Line
- Suspicious PowerShell Encoded Command Patterns
- PowerShell Base64 Encoded FromBase64String Cmdlet
- Malicious Base64 Encoded PowerShell Keywords in Command Lines
- PowerShell Base64 Encoded IEX Cmdlet
- PowerShell Base64 Encoded Invoke Keyword
- Powershell Base64 Encoded MpPreference Cmdlet
- PowerShell Base64 Encoded Reflective Assembly Load
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
- PowerShell Base64 Encoded WMI Classes
- Potential Process Execution Proxy Via CL_Invocation.ps1
- Assembly Loading Via CL_LoadAssembly.ps1
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Potential PowerShell Obfuscation Via Reversed Commands
- Potential PowerShell Command Line Obfuscation
- Obfuscated PowerShell MSI Install via WindowsInstaller COM
- PowerShell MSI Install via WindowsInstaller COM From Remote Location
- Computer Discovery And Export Via Get-ADComputer Cmdlet
- Potential PowerShell Console History Access Attempt via History File
- New Service Creation Using PowerShell
- Gzip Archive Decode Via PowerShell
- Powershell Defender Disable Scan Feature
- Powershell Defender Exclusion
- Disable Windows Defender AV Security Monitoring
- Windows Firewall Disabled via PowerShell
- Disabled IE Security Features
- Potential PowerShell Downgrade Attack
- Potential COM Objects Download Cradles Usage - Process Creation
- Obfuscated PowerShell OneLiner Execution
- Potential DLL File Download Via PowerShell Invoke-WebRequest
- PowerShell Download and Execution Cradles
- PowerShell Download Pattern
- DSInternals Suspicious PowerShell Cmdlets
- Suspicious Execution of Powershell with Base64
- Potential Encoded PowerShell Patterns In CommandLine
- Powershell Inline Execution From A File
- Certificate Exported Via PowerShell
- Base64 Encoded PowerShell Command Detected
- Suspicious FromBase64String Usage On Gzip Archive - Process Creation
- PowerShell Get-Clipboard Cmdlet Via CLI
- Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet
- PowerShell Get-Process LSASS
- Abuse of Service Permissions to Hide Services Via Set-Service
- Suspicious PowerShell IEX Execution Patterns
- Root Certificate Installed From Susp Locations
- Import PowerShell Modules From Suspicious Directories - ProcCreation
- Suspicious Invoke-WebRequest Execution With DirectIP
- Suspicious Invoke-WebRequest Execution
- Suspicious Kerberos Ticket Request via CLI
- Malicious PowerShell Commandlets - ProcessCreation
- MSExchange Transport Agent Installation
- Non Interactive PowerShell Process Spawned
- Potential PowerShell Obfuscation Via WCHAR/CHAR
- Execution of Powershell Script in Public Folder
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses
- Tamper Windows Defender Remove-MpPreference
- Potential Powershell ReverseShell Connection
- Run PowerShell Script from ADS
- Run PowerShell Script from Redirected Input Stream
- PowerShell SAM Copy
- Suspicious PowerShell Invocation From Script Engines
- Potentially Suspicious Powershell Script Execution From Temp Folder
- Suspicious Service DACL Modification Via Set-Service Cmdlet
- Change PowerShell Policies to an Insecure Level
- Service StartupType Change Via PowerShell Set-Service
- Deletion of Volume Shadow Copies via WMI with PowerShell
- Exchange PowerShell Snap-Ins Usage
- Stop Windows Service Via PowerShell Stop-Service
- Suspicious PowerShell Download and Execute Pattern
- Suspicious PowerShell Parameter Substring
- Suspicious PowerShell Parent Process
- PowerShell Script Run in AppData
- Powershell Token Obfuscation - Process Creation
- Suspicious Uninstall of Windows Defender Feature via PowerShell
- User Discovery And Export Via Get-ADUser Cmdlet
- Net WebClient Casing Anomalies
- Suspicious X509Enrollment - Process Creation
- Suspicious XOR Encoded PowerShell Command
- Folder Compress To Potentially Suspicious Output Via Compress-Archive Cmdlet
- Arbitrary File Download Via PresentationHost.EXE
- XBAP Execution From Uncommon Locations Via PresentationHost.EXE
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution
- Sensitive File Dump Via Print.EXE
- Abusing Print Executable
- File Download Using ProtocolHandler.exe
- Potential Provlaunch.EXE Binary Proxy Execution Abuse
- Suspicious Provlaunch.EXE Child Process
- Screen Capture Activity Via Psr.EXE
- PUA - 3Proxy Execution
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE
- PUA - AdFind.EXE Execution
- PUA - AdFind Suspicious Execution
- PUA - Advanced IP Scanner Execution
- PUA - Advanced Port Scanner Execution
- PUA - AdvancedRun Execution
- PUA - AdvancedRun Suspicious Execution
- PUA - Chisel Tunneling Tool Execution
- PUA - CleanWipe Execution
- PUA - Crassus Execution
- PUA - CsExec Execution
- PUA - DefenderCheck Execution
- PUA - DIT Snapshot Viewer
- PUA - Fast Reverse Proxy (FRP) Execution
- PUA- IOX Tunneling Tool Execution
- PUA - Kernel Driver Utility (KDU) Execution
- PUA - Memory Dump Mount Via MemProcFS
- PUA - Mouse Lock Execution
- PUA - Netcat Suspicious Execution
- PUA - SoftPerfect Netscan Execution
- PUA - Ngrok Execution
- PUA - Nimgrab Execution
- PUA - NimScan Execution
- PUA - NirCmd Execution
- PUA - NirCmd Execution As LOCAL SYSTEM
- PUA - Nmap/Zenmap Execution
- PUA - NPS Tunneling Tool Execution
- PUA - NSudo Execution
- PUA - PingCastle Execution
- PUA - PingCastle Execution From Potentially Suspicious Parent
- PUA - Process Hacker Execution
- PUA - Radmin Viewer Utility Execution
- PUA - Potential PE Metadata Tamper Using Rcedit
- PUA - Rclone Execution
- PUA - Restic Backup Tool Execution
- PUA - RunXCmd Execution
- PUA - Seatbelt Execution
- PUA - System Informer Execution
- PUA - TruffleHog Execution
- PUA - WebBrowserPassView Execution
- PUA - Wsudo Suspicious Execution
- PUA - Adidnsdump Execution
- Python One-Liners with Base64 Decoding
- Python Inline Command Execution
- Python Spawning Pretty TTY on Windows
- Potentially Suspicious Usage Of Qemu
- QuickAssist Execution
- Files Added To An Archive Using Rar.EXE
- Rar Usage with Password and Compression Level
- Suspicious Greedy Compression Using Rar.EXE
- Suspicious RASdial Activity
- RDP Enable or Disable via Win32_TerminalServiceSetting WMI Class
- Process Memory Dump via RdrLeakDiag.EXE
- Windows Recovery Environment Disabled Via Reagentc
- Potential Persistence Attempt Via Run Keys Using Reg.EXE
- Add SafeBoot Keys Via Reg Utility
- Suspicious Reg Add BitLocker
- Dropping Of Password Filter DLL
- Suspicious Windows Defender Folder Exclusion Added Via Reg.EXE
- RunMRU Registry Key Deletion
- SafeBoot Registry Key Deleted Via Reg.EXE
- Service Registry Key Deleted Via Reg.EXE
- Potentially Suspicious Desktop Background Change Using Reg.EXE
- Direct Autorun Keys Modification
- Disabling Windows Defender WMI Autologger Session via Reg.exe
- Security Service Disabled Via Reg.EXE
- Dumping of Sensitive Hives Via Reg.EXE
- Windows Recall Feature Enabled Via Reg.EXE
- Enumeration for Credentials in Registry
- Potential Suspicious Registry File Imported Via Reg.EXE
- RestrictedAdminMode Registry Value Tampering - ProcCreation
- Suspicious Query of MachineGUID
- Modify Group Policy Settings
- Enable LM Hash Storage - ProcCreation
- Potential Configuration And Service Reconnaissance Via Reg.EXE
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE
- Suspicious ScreenSave Change by Reg.exe
- Changing Existing Service ImagePath Value Via Reg.EXE
- Detected Windows Software Discovery
- Reg Add Suspicious Paths
- System Language Discovery via Reg.Exe
- System Restore Registry Modification via CommandLine
- Disabled Volume Snapshots
- Suspicious Windows Defender Registry Key Tampering Via Reg.EXE
- Write Protect For Storage Disabled
- RegAsm.EXE Execution Without CommandLine Flags or Files
- Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension
- Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location
- Exports Critical Registry Keys To a File
- Exports Registry Key To a File
- Imports Registry Key From a File
- Imports Registry Key From an ADS
- Regedit as Trusted Installer
- Suspicious Registry Modification From ADS Via Regini.EXE
- Registry Modification Via Regini.EXE
- DLL Execution Via Register-cimprovider.exe
- Enumeration for 3rd Party Creds From CLI
- Registry Export of Third-Party Credentials
- Suspicious Debugger Registration Cmdline
- Potential Persistence Via Logon Scripts - CommandLine
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI
- Python Function Execution Security Warning Disabled In Excel
- Potential Privilege Escalation via Service Permissions Weakness
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution
- Hiding User Account Via SpecialAccounts Registry Key - CommandLine
- Potential Regsvr32 Commandline Flag Anomaly
- Potentially Suspicious Regsvr32 HTTP IP Pattern
- Potentially Suspicious Regsvr32 HTTP/FTP Pattern
- Suspicious Regsvr32 Execution From Remote Share
- Potentially Suspicious Child Process Of Regsvr32
- Regsvr32 Execution From Potential Suspicious Location
- Regsvr32 Execution From Highly Suspicious Location
- Regsvr32 DLL Execution With Suspicious File Extension
- Scripting/CommandLine Process Spawned Regsvr32
- Regsvr32 DLL Execution With Uncommon Extension
- Remote Access Tool - AnyDesk Execution
- Remote Access Tool - AnyDesk Piped Password Via CLI
- Remote Access Tool - AnyDesk Silent Installation
- Remote Access Tool - Anydesk Execution From Suspicious Folder
- Remote Access Tool - GoToAssist Execution
- Remote Access Tool - LogMeIn Execution
- Remote Access Tool - Potential MeshAgent Execution - Windows
- Remote Access Tool - MeshAgent Command Execution via MeshCentral
- Remote Access Tool - NetSupport Execution
- Remote Access Tool - Renamed MeshAgent Execution - Windows
- Remote Access Tool - ScreenConnect Execution
- Remote Access Tool - ScreenConnect Installation Execution
- Remote Access Tool - ScreenConnect Remote Command Execution
- Remote Access Tool - ScreenConnect Potential Suspicious Remote Command Execution
- Remote Access Tool - ScreenConnect Server Web Shell Execution
- Remote Access Tool - Simple Help Execution
- Remote Access Tool - TacticalRMM Agent Registration to Potentially Attacker-Controlled Server
- Remote Access Tool - Team Viewer Session Started On Windows Host
- Remote Access Tool - UltraViewer Execution
- Discovery of a System Time
- Renamed AdFind Execution
- Renamed AutoIt Execution
- Potential Defense Evasion Via Binary Rename
- Potential Defense Evasion Via Rename Of Highly Relevant Binaries
- Renamed BOINC Client Execution
- Renamed BrowserCore.EXE Execution
- Renamed Cloudflared.EXE Execution
- Renamed CreateDump Utility Execution
- Renamed CURL.EXE Execution
- Renamed ZOHO Dctask64 Execution
- Renamed FTP.EXE Execution
- Renamed Gpg.EXE Execution
- Renamed Jusched.EXE Execution
- Renamed Mavinject.EXE Execution
- Renamed MegaSync Execution
- Renamed Msdt.EXE Execution
- Renamed NirCmd.EXE Execution
- Renamed Office Binary Execution
- Renamed PAExec Execution
- Renamed PingCastle Binary Execution
- Renamed Plink Execution
- Visual Studio NodejsTools PressAnyKey Renamed Execution
- Renamed Schtasks Execution
- Renamed SysInternals DebugView Execution
- Renamed ProcDump Execution
- Renamed Sysinternals Sdelete Execution
- Renamed Vmnat.exe Execution
- Renamed Whoami Execution
- Capture Credentials with Rpcping.exe
- Ruby Inline Command Execution
- Potential Rundll32 Execution With DLL Stored In ADS
- Suspicious Rundll32 Invoking Inline VBScript
- Rundll32 InstallScreenSaver Execution
- Suspicious Key Manager Access
- Rundll32 Execution Without CommandLine Parameters
- Suspicious NTLM Authentication on the Printer Spooler Service
- Potential Obfuscated Ordinal Call Via Rundll32
- Process Memory Dump Via Comsvcs.DLL
- Rundll32 Registered COM Objects
- Suspicious Process Start Locations
- Suspicious Rundll32 Setupapi.dll Activity
- Shell32 DLL Execution in Suspicious Directory
- RunDLL32 Spawning Explorer
- Potentially Suspicious Rundll32 Activity
- Suspicious Control Panel DLL Load
- Suspicious Rundll32 Execution With Image Extension
- Suspicious ShellExec_RunDLL Call Via Ordinal
- ShimCache Flush
- Suspicious Rundll32 Activity Invoking Sys File
- Potentially Suspicious Rundll32.EXE Execution of UDL File
- Rundll32 UNC Path Execution
- Rundll32 Execution With Uncommon DLL Extension
- WebDav Client Execution Via Rundll32.EXE
- Suspicious WebDav Client Execution Via Rundll32.EXE
- Rundll32 Execution Without Parameters
- Run Once Task Execution as Configured in Registry
- Possible Privilege Escalation via Weak Service Permissions
- New Service Creation Using Sc.EXE
- Service StartupType Change Via Sc.EXE
- New Kernel Driver Via SC.EXE
- Interesting Service Enumeration Via Sc.EXE
- Allow Service Access Using Security Descriptor Tampering Via Sc.EXE
- Deny Service Access Using Security Descriptor Tampering Via Sc.EXE
- Service DACL Abuse To Hide Services Via Sc.EXE
- Service Security Descriptor Tampering Via Sc.EXE
- Suspicious Service Path Modification
- Potential Persistence Attempt Via Existing Service Tampering
- Stop Windows Service Via Sc.EXE
- Suspicious Schtasks Execution AppData Folder
- Suspicious Modification Of Scheduled Tasks
- Scheduled Task Creation Via Schtasks.EXE
- Suspicious Scheduled Task Creation Involving Temp Folder
- Scheduled Task Creation with Curl and PowerShell Execution Combo
- Delete Important Scheduled Task
- Delete All Scheduled Tasks
- Disable Important Scheduled Task
- Schedule Task Creation From Env Variable Or Potentially Suspicious Path Via Schtasks.EXE
- Schtasks From Suspicious Folders
- Suspicious Scheduled Task Name As GUID
- Uncommon One Time Only Scheduled Task At 00:00
- Potential SSH Tunnel Persistence Install Using A Scheduled Task
- Potential Persistence Via Microsoft Compatibility Appraiser
- Potential Persistence Via Powershell Search Order Hijacking - Task
- Scheduled Task Executing Payload from Registry
- Scheduled Task Executing Encoded Payload from Registry
- Suspicious Schtasks Schedule Types
- Suspicious Schtasks Schedule Type With High Privileges
- Suspicious Scheduled Task Creation via Masqueraded XML File
- Suspicious Command Patterns In Scheduled Task Creation
- Schtasks Creation Or Modification With SYSTEM Privileges
- Scheduled Task Creation Masquerading as System Processes
- Script Event Consumer Spawning Process
- Potential Shim Database Persistence via Sdbinst.EXE
- Uncommon Extension Shim Database Installation Via Sdbinst.EXE
- Sdclt Child Processes
- Sdiagnhost Calling Suspicious Child Process
- Potential Suspicious Activity Using SeCEdit
- NodeJS Execution of JavaScript File
- Suspicious Serv-U Process Pattern
- Uncommon Child Process Of Setres.EXE
- Potential SPN Enumeration Via Setspn.EXE
- Setup16.EXE Execution With Custom .Lst File
- Indirect Command Execution via SFTP ProxyCommand
- Suspicious Execution of Shutdown
- Suspicious Execution of Shutdown to Log Out
- Uncommon Sigverif.EXE Child Process
- Audio Capture via SoundRecorder
- Suspicious Speech Runtime Binary Child Process
- Suspicious Splwow64 Without Params
- Suspicious Spool Service Child Process
- Veeam Backup Database Suspicious Query
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE
- SQLite Chromium Profile Data DB Access
- SQLite Firefox Profile Data DB Access
- Arbitrary File Download Via Squirrel.EXE
- Process Proxy Execution Via Squirrel.EXE
- Port Forwarding Activity Via SSH.EXE
- Program Executed Using Proxy/Local Command Via SSH.EXE
- Potential RDP Tunneling Via SSH
- Potential Amazon SSM Agent Hijacking
- Execution via stordiag.exe
- Abused Debug Privilege by Arbitrary Parent Processes
- User Added to Local Administrators Group
- User Added To Highly Privileged Group
- User Added to Remote Desktop Users Group
- Execute From Alternate Data Streams
- Always Install Elevated Windows Installer
- Arbitrary Shell Command Execution Via Settingcontent-Ms
- Phishing Pattern ISO in Archive
- Automated Collection Command Prompt
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments
- Potential Suspicious Browser Launch From Document Reader Process
- Suspicious Child Process Created as System
- Potential Commandline Obfuscation Using Escape Characters
- Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
- Suspicious ClickFix/FileFix Execution Pattern
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
- Suspicious Usage of For Loop with Recursive Directory Search in CMD
- Potential Command Line Path Traversal Evasion Attempt
- Potential Browser Data Stealing
- Copy From Or To Admin Share Or Sysvol Folder
- Suspicious Copy From or To System Directory
- LOL-Binary Copied From System Directory
- Potential Crypto Mining Activity
- Potential Data Exfiltration Activity Via CommandLine Tools
- Raccine Uninstall
- Suspicious Double Extension File Execution
- Suspicious Parent Double Extension File Execution
- Suspicious Download from Office Domain
- Always Install Elevated MSI Spawned Cmd And Powershell
- Elevated System Shell Spawned From Uncommon Parent Location
- Hidden Powershell in Link File Pattern
- ETW Logging Tamper In .NET Processes Via CommandLine
- ETW Trace Evasion Activity
- Suspicious Eventlog Clearing or Configuration Change Activity
- Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
- Potentially Suspicious Execution From Parent Process In Public Folder
- Process Execution From A Potentially Suspicious Folder
- Suspicious File Characteristics Due to Missing Fields
- Suspicious FileFix Execution Pattern
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI
- Writing Of Malicious Files To The Fonts Folder
- Potential Homoglyph Attack Using Lookalike Characters
- Potentially Suspicious Inline JavaScript Execution via NodeJS Binary
- Potential WinAPI Calls Via CommandLine
- Potentially Suspicious JWT Token Search Via CLI
- Suspicious LNK Command-Line Padding with Whitespace Characters
- Local Accounts Discovery
- LSASS Dump Keyword In CommandLine
- Potential File Download Via MS-AppInstaller Protocol Handler
- Suspicious Network Command
- Suspicious Scan Loop Network
- Potential Network Sniffing Activity Using Network Tools
- Non-privileged Usage of Reg or Powershell
- Suspicious Process Patterns NTDS.DIT Exfil
- Use Short Name Path in Image
- Use NTFS Short Name in Command Line
- Use NTFS Short Name in Image
- Suspicious Process Parents
- Potential PowerShell Execution Via DLL
- Privilege Escalation via Named Pipe Impersonation
- Private Keys Reconnaissance Via CommandLine Tools
- Windows Processes Suspicious Parent Directory
- Suspicious Program Names
- Recon Information for Export with Command Prompt
- Suspicious Redirection to Local Admin Share
- Registry Modification of MS-settings Protocol Handler
- Potential Remote Desktop Tunneling
- Potential Defense Evasion Via Right-to-Left Override
- Script Interpreter Execution From Suspicious Folder
- Script Interpreter Spawning Credential Scanner - Windows
- Sensitive File Access Via Volume Shadow Copy Backup
- Suspicious New Service Creation
- Suspicious Service Binary Directory
- Suspicious Windows Service Tampering
- Shadow Copies Creation Using Operating Systems Utilities
- Shadow Copies Deletion Using Operating Systems Utilities
- Windows Shell/Scripting Processes Spawning Suspicious Programs
- Process Creation Using Sysnative Folder
- System File Execution Location Anomaly
- Suspicious SYSTEM User Process Creation
- Suspicious SYSVOL Domain Group Policy Access
- Tasks Folder Evasion
- Malicious Windows Script Components File Execution by TAEF Detection
- Malicious PE Execution by Microsoft Visual Studio Debugger
- Suspicious Userinit Child Process
- Suspicious Velociraptor Child Process
- Usage Of Web Request Commands And Cmdlets
- WhoAmI as Parameter
- Execution via WorkFolders.exe
- Suspect Svchost Activity
- Suspicious Process Masquerading As SvcHost.EXE
- Terminal Service Process Spawn
- Uncommon Svchost Command Line Parameter
- Uncommon Svchost Parent Process
- Permission Check Via Accesschk.EXE
- Active Directory Database Snapshot Via ADExplorer
- Suspicious Active Directory Database Snapshot Via ADExplorer
- Potential Execution of Sysinternals Tools
- Procdump Execution
- Potential SysInternals ProcDump Evasion
- Potential LSASS Process Dump Via Procdump
- Psexec Execution
- PsExec/PAExec Escalation to LOCAL SYSTEM
- Potential PsExec Remote Execution
- Suspicious Use of PsLogList
- Sysinternals PsService Execution
- Sysinternals PsSuspend Execution
- Sysinternals PsSuspend Suspicious Execution
- Potential File Overwrite Via Sysinternals SDelete
- Potential Privilege Escalation To LOCAL SYSTEM
- Sysmon Configuration Update
- Uninstall Sysinternals Sysmon
- Potential Binary Impersonating Sysinternals Tools
- Sysprep on AppData Folder
- Suspicious Execution of Systeminfo
- Suspicious Recursive Takeown
- Tap Installer Execution
- Compressed File Creation Via Tar.EXE
- Compressed File Extraction Via Tar.EXE
- Taskkill Symantec Endpoint Protection
- Loaded Module Enumeration Via Tasklist.EXE
- Taskmgr as LOCAL_SYSTEM
- New Process Created Via Taskmgr.EXE
- Potentially Suspicious Command Targeting Teams Sensitive Files
- Suspicious TSCON Start as SYSTEM
- Suspicious RDP Redirect Using TSCON
- UAC Bypass Using ChangePK and SLUI
- UAC Bypass Using Disk Cleanup
- Bypass UAC via CMSTP
- CMSTP UAC Bypass via COM Object Access
- UAC Bypass Tools Using ComputerDefaults
- UAC Bypass Using Consent and Comctl32 - Process
- UAC Bypass Using DismHost
- Bypass UAC via Fodhelper.exe
- UAC Bypass via Windows Firewall Snap-In Hijack
- UAC Bypass via ICMLuaUtil
- UAC Bypass Using IDiagnostic Profile
- UAC Bypass Using IEInstal - Process
- UAC Bypass Using MSConfig Token Modification - Process
- UAC Bypass Using NTFS Reparse Point - Process
- UAC Bypass Using PkgMgr and DISM
- Potential UAC Bypass Via Sdclt.EXE
- TrustedPath UAC Bypass Pattern
- UAC Bypass Abusing Winsat Path Parsing - Process
- UAC Bypass Using Windows Media Player - Process
- Bypass UAC via WSReset.exe
- UAC Bypass WSReset
- Use of UltraVNC Remote Access Software
- Suspicious UltraVNC Execution
- Uninstall Crowdstrike Falcon Sensor
- User Shell Folders Registry Modification via CommandLine
- Uncommon Userinit Child Process
- Windows Credential Manager Access via VaultCmd
- Registry Modification Attempt Via VBScript
- Verclsid.exe Runs COM Object
- Virtualbox Driver Installation or Starting of VMs
- Suspicious VBoxDrvInst.exe Parameters
- Potential Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
- Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script
- VMToolsd Suspicious Child Process
- Potentially Suspicious Child Process Of VsCode
- Visual Studio Code Tunnel Execution
- Visual Studio Code Tunnel Shell Execution
- Renamed Visual Studio Code Tunnel Execution
- Visual Studio Code Tunnel Service Installation
- Potential Binary Proxy Execution Via VSDiagnostics.EXE
- Proxy Execution via Vshadow
- Suspicious Vsls-Agent Command With AgentExtensionPath Load
- Vulnerable Driver Blocklist Registry Tampering Via CommandLine
- Use of W32tm as Timer
- All Backups Deleted Via Wbadmin.EXE
- Windows Backup Deleted Via Wbadmin.EXE
- Sensitive File Dump Via Wbadmin.EXE
- File Recovery From Backup Via Wbadmin.EXE
- Sensitive File Recovery From Backup Via Wbadmin.EXE
- Potentially Suspicious WebDAV LNK Execution
- Chopper Webshell Process Pattern
- Webshell Hacking Activity Patterns
- Webshell Detection With Command Line Keywords
- Suspicious Process By Web Server Process
- Webshell Tool Reconnaissance Activity
- Potential Credential Dumping Via WER
- Potential ReflectDebugger Content Execution Via WerFault.EXE
- PPL Tampering Via WerFaultSecure
- Suspicious Child Process Of Wermgr.EXE
- Suspicious Where Execution
- Enumerate All Information With Whoami.EXE
- Whoami.EXE Execution From Privileged Process
- Group Membership Reconnaissance Via Whoami.EXE
- Whoami.EXE Execution With Output Option
- Whoami.EXE Execution Anomaly
- Security Privileges Enumeration Via Whoami.EXE
- Add New Download Source To Winget
- Add Insecure Download Source To Winget
- Add Potential Suspicious New Download Source To Winget
- Install New Package Via Winget Local Manifest
- Winrar Compressing Dump Files
- Potentially Suspicious Child Process Of WinRAR.EXE
- WinRAR Execution in Non-Standard Folder
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl
- Remote Code Execute via Winrm.vbs
- Remote PowerShell Session Host Process (WinRM)
- Suspicious Processes Spawned by WinRM
- Winrs Local Command Execution
- Potential Lateral Movement via Windows Remote Shell
- Compress Data and Lock With Password for Exfiltration With WINZIP
- Wlrmdr.EXE Uncommon Argument Or Child Process
- WMI Backdoor Exchange Transport Agent
- Password Set to Never Expire via WMI
- WMI Persistence - Script Event Consumer
- NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE
- Potential Windows Defender Tampering Via Wmic.EXE
- Process Creation Attempt via Wmic.EXE
- Computer System Reconnaissance Via Wmic.EXE
- Hardware Model Reconnaissance Via Wmic.EXE
- Local Groups Reconnaissance Via Wmic.EXE
- Windows Hotfix Updates Reconnaissance Via Wmic.EXE
- Potential Process Reconnaissance via Wmic.EXE
- Potential Product Reconnaissance Via Wmic.EXE
- Potential Product Class Reconnaissance Via Wmic.EXE
- Service Reconnaissance Via Wmic.EXE
- Uncommon System Information Discovery Via Wmic.EXE
- Potential Unquoted Service Path Reconnaissance Via Wmic.EXE
- System Disk And Volume Reconnaissance Via Wmic.EXE
- WMIC Remote Command Execution
- Service Started/Stopped Via Wmic.EXE
- Service Startup Type Change Via Wmic.EXE
- Potential Remote SquiblyTwo Technique Execution
- Registry Enumeration via WMI Stdregprov
- Registry Manipulation via WMI Stdregprov
- Suspicious WMIC Execution Via Office Process
- Suspicious Process Created Via Wmic.EXE
- Application Termination Attempt via Wmic.EXE
- Application Removed Via Wmic.EXE
- Potential Tampering With Security Products Via WMIC
- XSL Script Execution Via WMIC.EXE
- WmiPrvSE Spawned A Process
- Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell
- Suspicious WmiPrvSE Child Process
- UEFI Persistence Via Wpbbin - ProcessCreation
- Potential Dropper Script Execution Via WScript/CScript/MSHTA
- Cscript/Wscript Uncommon Script Extension Execution
- WSL Child Process Anomaly
- Installation of WSL Kali-Linux
- WSL Kali-Linux Usage
- Windows Binary Executed From WSL
- Proxy Execution Via Wuauclt.EXE
- Suspicious Windows Update Agent Empty Cmdline
- Xwizard.EXE Execution From Non-Default Location
- COM Object Execution via Xwizard.EXE
- Potential Process Hollowing Activity
- Potential Defense Evasion Via Raw Disk Access By Uncommon Tools
- Windows Credential Guard Related Registry Value Deleted - Registry
- Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted
- Folder Removed From Exploit Guard ProtectedFolders List - Registry
- Terminal Server Client Connection History Cleared - Registry
- Removal Of AMSI Provider Registry Keys
- Removal of Potential COM Hijacking Registry Keys
- RunMRU Registry Key Deletion - Registry
- Removal Of Index Value to Hide Schedule Task - Registry
- Removal Of SD Value to Hide Schedule Task - Registry
- Creation of a Local Hidden User Account by Registry
- UAC Bypass Via Wsreset
- CMSTP Execution Registry Event
- Windows Defender Threat Severity Default Action Modified
- Disable Security Events Logging Adding Reg Key MiniNt
- Wdigest CredGuard Registry Modification
- Esentutl Volume Shadow Copy Service Keys
- Windows Credential Editor Registry
- HybridConnectionManager Service Installation - Registry
- Registry Entries For Azorult Malware
- Potential Qakbot Registry Activity
- Path To Screensaver Binary Modified
- Narrator's Feedback-Hub Persistence
- NetNTLM Downgrade Attack - Registry
- New DLL Added to AppCertDlls Registry Key
- New DLL Added to AppInit_DLLs Registry Key
- Office Application Startup - Office Test
- Windows Registry Trust Record Modification
- Registry Persistence Mechanisms in Recycle Bin
- New PortProxy Registry Entry Added
- RedMimicry Winnti Playbook Registry Manipulation
- WINEKEY Registry Modification
- Run Once Task Configuration in Registry
- Shell Open Registry Keys Manipulation
- Potential Credential Dumping Via LSASS SilentProcessExit Technique
- Security Support Provider (SSP) Added to LSA Configuration
- Sticky Key Like Backdoor Usage - Registry
- Atbroker Registry Change
- Suspicious Run Key from Download
- DLL Load via LSASS
- Suspicious Camera and Microphone Access
- Registry Tampering by Potentially Suspicious Processes
- Enable Remote Connection Between Anonymous Computer - AllowAnonymousCallback
- Registry Persistence via Service in Safe Mode
- Add Port Monitor Persistence in Registry
- Allow RDP Remote Assistance Feature
- Potential AMSI COM Server Hijacking
- AMSI Disabled via Registry Modification
- Classes Autorun Keys Modification
- Common Autorun Keys Modification
- CurrentControlSet Autorun Keys Modification
- CurrentVersion Autorun Keys Modification
- CurrentVersion NT Autorun Keys Modification
- Internet Explorer Autorun Keys Modification
- Office Autorun Keys Modification
- Session Manager Autorun Keys Modification
- System Scripts Autorun Keys Modification
- WinSock2 Autorun Keys Modification
- Wow6432Node CurrentVersion Autorun Keys Modification
- Wow6432Node Classes Autorun Keys Modification
- Wow6432Node Windows NT CurrentVersion Autorun Keys Modification
- New BgInfo.EXE Custom DB Path Registry Configuration
- New BgInfo.EXE Custom VBScript Registry Configuration
- New BgInfo.EXE Custom WMI Query Registry Configuration
- Bypass UAC Using DelegateExecute
- Bypass UAC Using Event Viewer
- Bypass UAC Using SilentCleanup Task
- Default RDP Port Changed to Non Standard Port
- IE Change Domain Zone
- Sysmon Driver Altitude Change
- Change Winevt Channel Access Permission Via Registry
- Running Chrome VPN Extensions via the Registry 2 VPN Extension
- ClickOnce Trust Prompt Tampering
- Potential CobaltStrike Service Installations - Registry
- COM Hijack via Sdclt
- CrashControl CrashDump Disabled
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set
- Service Binary in Suspicious Folder
- Windows Credential Guard Disabled - Registry
- Custom File Open Handler Executes PowerShell
- Potential Registry Persistence Attempt Via DbgManagedDebugger
- Windows Defender Exclusions Added - Registry
- Potentially Suspicious Desktop Background Change Via Registry
- Antivirus Filter Driver Disallowed On Dev Drive - Registry
- Windows Hypervisor Enforced Code Integrity Disabled
- Hypervisor Enforced Paging Translation Disabled
- DHCP Callout DLL Installation
- Disable Administrative Share Creation at Startup
- Potential AutoLogger Sessions Tampering
- Disable Microsoft Defender Firewall via Registry
- Disable Internal Tools or Feature in Registry
- Disable Privacy Settings Experience in Registry
- Disable Windows Security Center Notifications
- Registry Disable System Restore
- Windows Defender Service Disabled - Registry
- Windows Event Log Access Tampering Via Registry
- Disable Windows Firewall by Registry
- Disable Windows Event Logging Via Registry
- Disable Exploit Guard Network Protection on Windows Defender
- Disabled Windows Defender Eventlog
- Disable PUA Protection on Windows Defender
- Disable Tamper Protection on Windows Defender
- Add DisallowRun Execution to Registry
- DNS-over-HTTPS Enabled by Registry
- New DNS ServerLevelPluginDll Installed
- ETW Logging Disabled In .NET Processes - Sysmon Registry
- Directory Service Restore Mode(DSRM) Registry Value Tampering
- Periodic Backup For System Registry Hives Enabled
- Windows Recall Feature Enabled - Registry
- Enabling COR Profiler Environment Variables
- Scripted Diagnostics Turn Off Check Enabled - Registry
- Potential EventLog File Location Tampering
- Suspicious Application Allowed Through Exploit Guard
- Change User Account Associated with the FAX Service
- Change the Fax Dll
- FileFix - Command Evidence in TypedPaths
- Registry Modification to Hidden File Extension
- Displaying Hidden Files Feature Disabled
- Registry Hide Function from User
- Hide Schedule Task Via Index Value Tamper
- Uncommon Extension In Keyboard Layout IME File Registry Value
- Suspicious Path In Keyboard Layout IME File Registry Value
- New Root or CA or AuthRoot Certificate to Store
- Potential Ransomware Activity Using LegalNotice Message
- Lolbas OneDriveStandaloneUpdater.exe Proxy Download
- RestrictedAdminMode Registry Value Tampering
- Lsass Full Dump Request Via DumpType Registry Settings
- NET NGenAssemblyUsageLog Registry Key Tamper
- New Netsh Helper DLL Registered From A Suspicious Location
- Potential Persistence Via Netsh Helper DLL - Registry
- New Application in AppCompat
- Potential Credential Dumping Attempt Using New NetworkProvider - REG
- Potentially Suspicious ODBC Driver Registered
- Trust Access Disable For VBApplications
- Microsoft Office Protected View Disabled
- Python Function Execution Security Warning Disabled In Excel - Registry
- Enable Microsoft Dynamic Data Exchange
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting
- Outlook Macro Execution Without Warning Setting Enabled
- Outlook EnableUnsafeClientMailRules Setting Enabled - Registry
- Outlook Security Settings Updated - Registry
- Macro Enabled In A Potentially Suspicious Document
- Uncommon Microsoft Office Trusted Location Added
- Office Macros Warning Disabled
- MaxMpxCt Registry Value Changed
- Potential Persistence Via AppCompat RegisterAppRestart Layer
- Potential Persistence Via App Paths Default Property
- Potential Persistence Using DebugPath
- COM Object Hijacking Via Modification Of Default System CLSID Default Value
- Potential COM Object Hijacking Via TreatAs Subkey - Registry
- Potential PSFactoryBuffer COM Hijacking
- Potential Persistence Via Custom Protocol Handler
- Potential Persistence Via Event Viewer Events.asp
- Potential Persistence Via GlobalFlags
- Modification of IE Registry Settings
- Potential Persistence Via Logon Scripts - Registry
- Potential Persistence Via Visual Studio Tools for Office
- Potential Persistence Via Outlook Home Page
- Potential Persistence Via Outlook Today Page
- Potential WerFault ReflectDebugger Registry Value Abuse
- Potential Persistence Via Scrobj.dll COM Hijacking
- Potential Persistence Via Shim Database Modification
- Suspicious Shim Database Patching Activity
- Potential Persistence Via Shim Database In Uncommon Location
- Potential Persistence Via Excel Add-in - Registry
- Potential ClickFix Execution Pattern - Registry
- Registry Modification for OCI DLL Redirection
- PowerShell as a Service in Registry
- Suspicious PowerShell In Registry Run Keys
- PowerShell Logging Disabled Via Registry Key Tampering
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG
- PUA - Sysinternal Tool Execution - Registry
- Suspicious Execution Of Renamed Sysinternals Tools - Registry
- PUA - Sysinternals Tools Execution - Registry
- Usage of Renamed Sysinternals Tools - RegistrySet
- ETW Logging Disabled For rpcrt4.dll
- Potentially Suspicious Command Executed Via Run Dialog Box - Registry
- ScreenSaver Registry Key Set
- ServiceDll Hijack
- ETW Logging Disabled For SCM
- Registry Explorer Policy Modification
- Persistence Via New SIP Provider
- Tamper With Sophos AV Registry Keys
- Hiding User Account Via SpecialAccounts Registry Key
- Activate Suppression of Windows Security Center Notifications
- Suspicious Keyboard Layout Load
- Potential PendingFileRenameOperations Tampering
- Suspicious Printer Driver Empty Manufacturer
- Registry Persistence via Explorer Run Key
- New RUN Key Pointing to Suspicious Folder
- Suspicious Space Characters in RunMRU Registry Path - ClickFix
- Suspicious Service Installed
- Suspicious Shell Open Command Registry Modification
- Suspicious Space Characters in TypedPaths Registry Path - FileFix
- Modify User Shell Folders Startup Value
- WFP Filter Added via Registry
- Enable LM Hash Storage
- Scheduled TaskCache Change by Uncommon Program
- Potential Registry Persistence Attempt Via Windows Telemetry
- RDP Sensitive Settings Changed to Zero
- RDP Sensitive Settings Changed
- New TimeProviders Registered With Uncommon DLL Name
- COM Hijacking via TreatAs
- UAC Bypass via Event Viewer
- UAC Bypass via Sdclt
- UAC Bypass Abusing Winsat Path Parsing - Registry
- UAC Bypass Using Windows Media Player - Registry
- UAC Disabled
- UAC Notification Disabled
- UAC Secure Desktop Prompt Disabled
- VBScript Payload Stored in Registry
- Windows Vulnerable Driver Blocklist Disabled
- Execution DLL of Choice Using WAB.EXE
- Wdigest Enable UseLogonCredential
- Disable Windows Defender Functionalities Via Registry Keys
- Winlogon AllowMultipleTSSessions Enable
- Winlogon Notify Key Logon Persistence
- Sysmon Configuration Error
- Sysmon Configuration Modification
- WMI Event Subscription
- Suspicious Encoded Scripts in a WMI Consumer
- Suspicious Scripting in a WMI Consumer
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.