1200KM / tag
attack.stealth — sigma-tag tag
843 related reference pages for sigma-tag: attack.stealth.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Abuse of Service Permissions to Hide Services Via Set-Service · sigma-rule
- Abuse of Service Permissions to Hide Services Via Set-Service - PS · sigma-rule
- Abusing Print Executable · sigma-rule
- Account Created And Deleted Within A Close Time Frame · sigma-rule
- Account Disabled or Blocked for Sign in Attempts · sigma-rule
- Account Tampering - Suspicious Failed Logon Reasons · sigma-rule
- Activity From Anonymous IP Address · sigma-rule
- AddinUtil.EXE Execution From Uncommon Directory · sigma-rule
- Addition of SID History to Active Directory Object · sigma-rule
- Admin User Remote Logon · sigma-rule
- ADS Zone.Identifier Deleted By Uncommon Application · sigma-rule
- AgentExecutor PowerShell Execution · sigma-rule
- Application AppID Uri Configuration Changes · sigma-rule
- Application URI Configuration Changes · sigma-rule
- Application Using Device Code Authentication Flow · sigma-rule
- Applications That Are Using ROPC Authentication Flow · sigma-rule
- Arbitrary DLL or Csproj Code Execution Via Dotnet.EXE · sigma-rule
- Arbitrary File Download Via IMEWDBLD.EXE · sigma-rule
- Arbitrary File Download Via MSEDGE_PROXY.EXE · sigma-rule
- Arbitrary File Download Via MSOHTMED.EXE · sigma-rule
- Arbitrary File Download Via MSPUB.EXE · sigma-rule
- Arbitrary File Download Via PresentationHost.EXE · sigma-rule
- Arbitrary File Download Via Squirrel.EXE · sigma-rule
- Arbitrary MSI Download Via Devinit.EXE · sigma-rule
- Aruba Network Service Potential DLL Sideloading · sigma-rule
- ASLR Disabled Via Sysctl or Direct Syscall - Linux · sigma-rule
- AspNetCompiler Execution · sigma-rule
- Assembly Loading Via CL_LoadAssembly.ps1 · sigma-rule
- Atbroker Registry Change · sigma-rule
- Atypical Travel · sigma-rule
- Audit CVE Event · sigma-rule
- Authentications To Important Apps Using Single Factor Authentication · sigma-rule
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl · sigma-rule
- AWL Bypass with Winrm.vbs and Malicious WsmPty.xsl/WsmTxt.xsl - File · sigma-rule
- AWS IAM S3Browser LoginProfile Creation · sigma-rule
- AWS IAM S3Browser Templated S3 Bucket Policy Creation · sigma-rule
- AWS IAM S3Browser User or AccessKey Creation · sigma-rule
- AWS Key Pair Import Activity · sigma-rule
- AWS Root Credentials · sigma-rule
- AWS SAML Provider Deletion Activity · sigma-rule
- AWS Successful Console Login Without MFA · sigma-rule
- AWS Suspicious SAML Activity · sigma-rule
- Azure AD Only Single Factor Authentication Required · sigma-rule
- Azure AD Threat Intelligence · sigma-rule
- Azure Domain Federation Settings Modified · sigma-rule
- Azure Kubernetes Admission Controller · sigma-rule
- Azure Login Bypassing Conditional Access Policies · sigma-rule
- Azure Subscription Permission Elevation Via ActivityLogs · sigma-rule
- Azure Subscription Permission Elevation Via AuditLogs · sigma-rule
- Azure Unusual Authentication Interruption · sigma-rule
- BaaUpdate.exe Suspicious DLL Load · sigma-rule
- Backup Catalog Deleted · sigma-rule
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments · sigma-rule
- Base64 Encoded PowerShell Command Detected · sigma-rule
- Binary Padding - Linux · sigma-rule
- Binary Padding - MacOS · sigma-rule
- Binary Proxy Execution Via Dotnet-Trace.EXE · sigma-rule
- Bitbucket User Login Failure · sigma-rule
- Bitlocker Key Retrieval · sigma-rule
- BitLockerTogo.EXE Execution · sigma-rule
- BITS Transfer Job Download From Direct IP · sigma-rule
- BITS Transfer Job Download From File Sharing Domains · sigma-rule
- BITS Transfer Job Download To Potential Suspicious Folder · sigma-rule
- BITS Transfer Job Downloading File Potential Suspicious Extension · sigma-rule
- BITS Transfer Job With Uncommon Or Suspicious Remote TLD · sigma-rule
- Bitsadmin to Uncommon IP Server Address · sigma-rule
- Bitsadmin to Uncommon TLD · sigma-rule
- Browser Execution In Headless Mode · sigma-rule
- Bypass UAC via CMSTP · sigma-rule
- C# IL Code Compilation Via Ilasm.EXE · sigma-rule
- Certificate Exported Via Certutil.EXE · sigma-rule
- Changes To PIM Settings · sigma-rule
- Changing Existing Service ImagePath Value Via Reg.EXE · sigma-rule
- Cisco BGP Authentication Failures · sigma-rule
- Cisco Clear Logs · sigma-rule
- Cisco File Deletion · sigma-rule
- Cisco LDP Authentication Failures · sigma-rule
- Clear PowerShell History - PowerShell · sigma-rule
- Clear PowerShell History - PowerShell Module · sigma-rule
- Clearing Windows Console History · sigma-rule
- Cmd Launched with Hidden Start Flags to Suspicious Targets · sigma-rule
- CMSTP Execution Process Access · sigma-rule
- CMSTP Execution Process Creation · sigma-rule
- CMSTP Execution Registry Event · sigma-rule
- CMSTP UAC Bypass via COM Object Access · sigma-rule
- CobaltStrike Load by Rundll32 · sigma-rule
- CobaltStrike Named Pipe · sigma-rule
- CobaltStrike Named Pipe Pattern Regex · sigma-rule
- CobaltStrike Named Pipe Patterns · sigma-rule
- Code Execution via Pcwutl.dll · sigma-rule
- Code Injection by ld.so Preload · sigma-rule
- CodePage Modification Via MODE.COM To Russian Language · sigma-rule
- COM Object Execution via Xwizard.EXE · sigma-rule
- Control Panel Items · sigma-rule
- ConvertTo-SecureString Cmdlet Usage Via CommandLine · sigma-rule
- CrashControl CrashDump Disabled · sigma-rule
- Created Files by Microsoft Sync Center · sigma-rule
- CreateDump Process Dump · sigma-rule
- Creation Of Non-Existent System DLL · sigma-rule
- Creation Of Pod In System Namespace · sigma-rule
- Creation of WerFault.exe/Wer.dll in Unusual Folder · sigma-rule
- Csc.EXE Execution Form Potentially Suspicious Parent · sigma-rule
- Curl Download And Execute Combination · sigma-rule
- Custom File Open Handler Executes PowerShell · sigma-rule
- Decode Base64 Encoded Text · sigma-rule
- Decode Base64 Encoded Text -MacOs · sigma-rule
- Detection of PowerShell Execution via Sqlps.exe · sigma-rule
- Device Registration or Join Without MFA · sigma-rule
- DeviceCredentialDeployment Execution · sigma-rule
- Devtoolslauncher.exe Executes Specified Binary · sigma-rule
- DHCP Callout DLL Installation · sigma-rule
- DHCP Server Error Failed Loading the CallOut DLL · sigma-rule
- DHCP Server Loaded the CallOut DLL · sigma-rule
- Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE · sigma-rule
- Directory Removal Via Rmdir · sigma-rule
- Disable Administrative Share Creation at Startup · sigma-rule
- Disable of ETW Trace - Powershell · sigma-rule
- Disable Powershell Command History · sigma-rule
- Diskshadow Script Mode - Execution From Potential Suspicious Location · sigma-rule
- Diskshadow Script Mode - Uncommon Script Extension Execution · sigma-rule
- Displaying Hidden Files Feature Disabled · sigma-rule
- DLL Execution via Rasautou.exe · sigma-rule
- DLL Execution Via Register-cimprovider.exe · sigma-rule
- DLL Load By System Process From Suspicious Locations · sigma-rule
- DLL Loaded From Suspicious Location Via Cmspt.EXE · sigma-rule
- DLL Loaded via CertOC.EXE · sigma-rule
- DLL Search Order Hijackig Via Additional Space in Path · sigma-rule
- DLL Sideloading by VMware Xfer Utility · sigma-rule
- DLL Sideloading Of ShellChromeAPI.DLL · sigma-rule
- Dllhost.EXE Execution Anomaly · sigma-rule
- DllUnregisterServer Function Call Via Msiexec.EXE · sigma-rule
- DMSA Link Attributes Modified · sigma-rule
- DMSA Service Account Created in Specific OUs - PowerShell · sigma-rule
- DNS Query Request By Regsvr32.EXE · sigma-rule
- DNS Server Error Failed Loading the ServerLevelPluginDLL · sigma-rule
- DNS-over-HTTPS Enabled by Registry · sigma-rule
- DotNet CLR DLL Loaded By Scripting Applications · sigma-rule
- Driver/DLL Installation Via Odbcconf.EXE · sigma-rule
- DumpMinitool Execution · sigma-rule
- Dynamic .NET Compilation Via Csc.EXE · sigma-rule
- Dynamic CSharp Compile Artefact · sigma-rule
- Enabling COR Profiler Environment Variables · sigma-rule
- ETW Trace Evasion Activity · sigma-rule
- EventLog EVTX File Deleted · sigma-rule
- Exchange PowerShell Cmdlet History Deleted · sigma-rule
- Execute Code with Pester.bat · sigma-rule
- Execute Code with Pester.bat as Parent · sigma-rule
- Execute Files with Msdeploy.exe · sigma-rule
- Execute From Alternate Data Streams · sigma-rule
- Execute Pcwrun.EXE To Leverage Follina · sigma-rule
- Execution DLL of Choice Using WAB.EXE · sigma-rule
- Execution via stordiag.exe · sigma-rule
- Execution via WorkFolders.exe · sigma-rule
- Explorer Process Tree Break · sigma-rule
- Exports Registry Key To an Alternate Data Stream · sigma-rule
- External Remote RDP Logon from Public IP · sigma-rule
- External Remote SMB Logon from Public IP · sigma-rule
- Failed Authentications From Countries You Do Not Operate Out Of · sigma-rule
- Failed Code Integrity Checks · sigma-rule
- Failed Logon From Public IP · sigma-rule
- Fax Service DLL Search Order Hijack · sigma-rule
- File Decoded From Base64/Hex Via Certutil.EXE · sigma-rule
- File Deleted Via Sysinternals SDelete · sigma-rule
- File Deletion · sigma-rule
- File Deletion Via Del · sigma-rule
- File Download Using ProtocolHandler.exe · sigma-rule
- File Download Via Bitsadmin · sigma-rule
- File Download Via Bitsadmin To A Suspicious Target Folder · sigma-rule
- File Download Via InstallUtil.EXE · sigma-rule
- File Download Via Windows Defender MpCmpRun.EXE · sigma-rule
- File Download with Headless Browser · sigma-rule
- File Encoded To Base64 Via Certutil.EXE · sigma-rule
- File In Suspicious Location Encoded To Base64 Via Certutil.EXE · sigma-rule
- File Time Attribute Change · sigma-rule
- File Time Attribute Change - Linux · sigma-rule
- File With Suspicious Extension Downloaded Via Bitsadmin · sigma-rule
- Files With System DLL Name In Unsuspected Locations · sigma-rule
- Files With System Process Name In Unsuspected Locations · sigma-rule
- Filter Driver Unloaded Via Fltmc.EXE · sigma-rule
- Findstr Launching .lnk File · sigma-rule
- Flash Player Update from Suspicious Location · sigma-rule
- Forfiles.EXE Child Process Masquerading · sigma-rule
- Fsutil Suspicious Invocation · sigma-rule
- Github New Secret Created · sigma-rule
- Github Self Hosted Runner Changes Detected · sigma-rule
- Github SSH Certificate Configuration Changed · sigma-rule
- Google Cloud Kubernetes Admission Controller · sigma-rule
- Google Workspace Government Attack Warning · sigma-rule
- Gpscript Execution · sigma-rule
- Greedy File Deletion Using Del · sigma-rule
- Guest Account Enabled Via Sysadminctl · sigma-rule
- Guest User Invited By Non Approved Inviters · sigma-rule
- Guest Users Invited To Tenant By Non Approved Inviters · sigma-rule
- HackTool - CACTUSTORCH Remote Thread Creation · sigma-rule
- HackTool - CoercedPotato Execution · sigma-rule
- HackTool - CoercedPotato Named Pipe Creation · sigma-rule
- HackTool - Covenant PowerShell Launcher · sigma-rule
- HackTool - CrackMapExec PowerShell Obfuscation · sigma-rule
- HackTool - DInjector PowerShell Cradle Execution · sigma-rule
- HackTool - EfsPotato Named Pipe Creation · sigma-rule
- HackTool - F-Secure C3 Load by Rundll32 · sigma-rule
- HackTool - HollowReaper Execution · sigma-rule
- HackTool - Impersonate Execution · sigma-rule
- HackTool - Koh Default Named Pipe · sigma-rule
- HackTool - LittleCorporal Generated Maldoc Injection · sigma-rule
- HackTool - NoFilter Execution · sigma-rule
- HackTool - Potential CobaltStrike Process Injection · sigma-rule
- HackTool - Powerup Write Hijack DLL · sigma-rule
- HackTool - PPID Spoofing SelectMyParent Tool Execution · sigma-rule
- HackTool - RedMimicry Winnti Playbook Execution · sigma-rule
- HackTool - SharpDPAPI Execution · sigma-rule
- HackTool - SharpImpersonation Execution · sigma-rule
- HackTool - SharpUp PrivEsc Tool Execution · sigma-rule
- HackTool - XORDump Execution · sigma-rule
- HackTool Named File Stream Created · sigma-rule
- HH.EXE Execution · sigma-rule
- Hidden Executable In NTFS Alternate Data Stream · sigma-rule
- Hidden Files and Directories · sigma-rule
- Hidden Flag Set On File/Directory Via Chflags - MacOS · sigma-rule
- Hidden User Creation · sigma-rule
- Hiding Files with Attrib.exe · sigma-rule
- Hiding User Account Via SpecialAccounts Registry Key · sigma-rule
- Hiding User Account Via SpecialAccounts Registry Key - CommandLine · sigma-rule
- HTML Help HH.EXE Suspicious Child Process · sigma-rule
- Huawei BGP Authentication Failures · sigma-rule
- Ie4uinit Lolbin Use From Invalid Path · sigma-rule
- IIS WebServer Access Logs Deleted · sigma-rule
- IIS WebServer Log Deletion via CommandLine Utilities · sigma-rule
- Import LDAP Data Interchange Format File Via Ldifde.EXE · sigma-rule
- Impossible Travel · sigma-rule
- Increased Failed Authentications Of Any Type · sigma-rule
- Indirect Command Execution By Program Compatibility Wizard · sigma-rule
- Indirect Command Execution From Script File Via Bash.EXE · sigma-rule
- Indirect Command Execution via SFTP ProxyCommand · sigma-rule
- Indirect Inline Command Execution Via Bash.EXE · sigma-rule
- InfDefaultInstall.exe .inf Execution · sigma-rule
- Insensitive Subfolder Search Via Findstr.EXE · sigma-rule
- Interactive Bash Suspicious Children · sigma-rule
- Invalid PIM License · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - Security · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - System · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security · sigma-rule
- Invoke-Obfuscation COMPRESS OBFUSCATION - System · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - Security · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - System · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - Security · sigma-rule
- Invoke-Obfuscation RUNDLL LAUNCHER - System · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Powershell · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Security · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR+ Launcher · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - Security · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System · sigma-rule
- Invoke-Obfuscation Via Stdin · sigma-rule
- Invoke-Obfuscation Via Stdin - Powershell · sigma-rule
- Invoke-Obfuscation Via Stdin - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Stdin - Security · sigma-rule
- Invoke-Obfuscation Via Stdin - System · sigma-rule
- Invoke-Obfuscation Via Use Clip · sigma-rule
- Invoke-Obfuscation Via Use Clip - Powershell · sigma-rule
- Invoke-Obfuscation Via Use Clip - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Clip - Security · sigma-rule
- Invoke-Obfuscation Via Use Clip - System · sigma-rule
- Invoke-Obfuscation Via Use MSHTA · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - Security · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - System · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - Security · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - System · sigma-rule
- JScript Compiler Execution · sigma-rule
- Juniper BGP Missing MD5 · sigma-rule
- Kavremover Dropped Binary LOLBIN Usage · sigma-rule
- Kubernetes Admission Controller Modification · sigma-rule
- Kubernetes Events Deleted · sigma-rule
- Launch-VsDevShell.PS1 Proxy Execution · sigma-rule
- Legitimate Application Dropped Archive · sigma-rule
- Legitimate Application Dropped Executable · sigma-rule
- Legitimate Application Dropped Script · sigma-rule
- Legitimate Application Writing Files In Uncommon Location · sigma-rule
- Linux Base64 Encoded Pipe to Shell · sigma-rule
- Linux Base64 Encoded Shebang In CLI · sigma-rule
- Linux Command History Tampering · sigma-rule
- Linux Package Uninstall · sigma-rule
- Linux Shell Pipe to Shell · sigma-rule
- Login to Disabled Account · sigma-rule
- Logon from a Risky IP Address · sigma-rule
- LOL-Binary Copied From System Directory · sigma-rule
- Lolbin Runexehelper Use As Proxy · sigma-rule
- Lolbin Unregmp2.exe Use As Proxy · sigma-rule
- Malicious DLL File Dropped in the Teams or OneDrive Folder · sigma-rule
- Malicious Named Pipe Created · sigma-rule
- Malicious PE Execution by Microsoft Visual Studio Debugger · sigma-rule
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure · sigma-rule
- Malicious Windows Script Components File Execution by TAEF Detection · sigma-rule
- ManageEngine Endpoint Central Dctask64.EXE Potential Abuse · sigma-rule
- Masquerading as Linux Crond Process · sigma-rule
- Mavinject Inject DLL Into Running Process · sigma-rule
- MaxMpxCt Registry Value Changed · sigma-rule
- Measurable Increase Of Successful Authentications · sigma-rule
- Meterpreter or Cobalt Strike Getsystem Service Installation - Security · sigma-rule
- Meterpreter or Cobalt Strike Getsystem Service Installation - System · sigma-rule
- Microsoft 365 - Impossible Travel Activity · sigma-rule
- Microsoft Defender Blocked from Loading Unsigned DLL · sigma-rule
- Microsoft Malware Protection Engine Crash · sigma-rule
- Microsoft Malware Protection Engine Crash - WER · sigma-rule
- Microsoft Office DLL Sideload · sigma-rule
- Microsoft Sync Center Suspicious Network Connections · sigma-rule
- MMC Executing Files with Reversed Extensions Using RTLO Abuse · sigma-rule
- MMC Loading Script Engines DLLs · sigma-rule
- Modification of ld.so.preload · sigma-rule
- Monitoring For Persistence Via BITS · sigma-rule
- Mount Execution With Hidepid Parameter · sigma-rule
- MpiExec Lolbin · sigma-rule
- MSDT Execution Via Answer File · sigma-rule
- MSHTA Execution with Suspicious File Extensions · sigma-rule
- MSI Installation From Web · sigma-rule
- Msiexec Quiet Installation · sigma-rule
- MsiExec Web Install · sigma-rule
- Msxsl.EXE Execution · sigma-rule
- Multifactor Authentication Denied · sigma-rule
- Multifactor Authentication Interrupted · sigma-rule
- Network Connection Initiated By AddinUtil.EXE · sigma-rule
- Network Connection Initiated By Regsvr32.EXE · sigma-rule
- Network Connection Initiated Via Notepad.EXE · sigma-rule
- New BITS Job Created Via Bitsadmin · sigma-rule
- New BITS Job Created Via PowerShell · sigma-rule
- New Capture Session Launched Via DXCap.EXE · sigma-rule
- New Country · sigma-rule
- New DLL Registered Via Odbcconf.EXE · sigma-rule
- New DMSA Service Account Created in Specific OUs · sigma-rule
- New DNS ServerLevelPluginDll Installed · sigma-rule
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE · sigma-rule
- New or Renamed User Account with '$' Character · sigma-rule
- New Process Created Via Taskmgr.EXE · sigma-rule
- Node Process Executions · sigma-rule
- NTFS Alternate Data Stream · sigma-rule
- Obfuscated PowerShell MSI Install via WindowsInstaller COM · sigma-rule
- Odbcconf.EXE Suspicious DLL Location · sigma-rule
- Okta New Admin Console Behaviours · sigma-rule
- OneNote.EXE Execution of Malicious Embedded Scripts · sigma-rule
- OpenCanary - SSH Login Attempt · sigma-rule
- OpenCanary - SSH New Connection Attempt · sigma-rule
- OpenCanary - Telnet Login Attempt · sigma-rule
- OpenWith.exe Executes Specified Binary · sigma-rule
- Outbound Network Connection Initiated By Cmstp.EXE · sigma-rule
- Outbound Network Connection To Public IP Via Winlogon · sigma-rule
- Outlook EnableUnsafeClientMailRules Setting Enabled · sigma-rule
- Password Protected ZIP File Opened · sigma-rule
- Password Protected ZIP File Opened (Email Attachment) · sigma-rule
- Password Protected ZIP File Opened (Suspicious Filenames) · sigma-rule
- Password Provided In Command Line Of Net.EXE · sigma-rule
- Password Reset By User Account · sigma-rule
- Payload Decoded and Decrypted via Built-in Utilities · sigma-rule
- PIM Alert Setting Changes To Disabled · sigma-rule
- PIM Approvals And Deny Elevation · sigma-rule
- Ping Hex IP · sigma-rule
- Possible Privilege Escalation via Weak Service Permissions · sigma-rule
- Potential 7za.DLL Sideloading · sigma-rule
- Potential Access Token Abuse · sigma-rule
- Potential Antivirus Software DLL Sideloading · sigma-rule
- Potential Application Whitelisting Bypass via Dnx.EXE · sigma-rule
- Potential appverifUI.DLL Sideloading · sigma-rule
- Potential Arbitrary Code Execution Via Node.EXE · sigma-rule
- Potential Arbitrary Command Execution Using Msdt.EXE · sigma-rule
- Potential Arbitrary Command Execution Via FTP.EXE · sigma-rule
- Potential Arbitrary DLL Load Using Winword · sigma-rule
- Potential Arbitrary File Download Using Office Application · sigma-rule
- Potential Arbitrary File Download Via Cmdl32.EXE · sigma-rule
- Potential AVKkid.DLL Sideloading · sigma-rule
- Potential Azure Browser SSO Abuse · sigma-rule
- Potential Base64 Decoded From Images · sigma-rule
- Potential Binary Impersonating Sysinternals Tools · sigma-rule
- Potential Binary Proxy Execution Via Cdb.EXE · sigma-rule
- Potential Binary Proxy Execution Via VSDiagnostics.EXE · sigma-rule
- Potential CCleanerDU.DLL Sideloading · sigma-rule
- Potential CCleanerReactivator.DLL Sideloading · sigma-rule
- Potential Chrome Frame Helper DLL Sideloading · sigma-rule
- Potential Command Line Path Traversal Evasion Attempt · sigma-rule
- Potential Commandline Obfuscation Using Escape Characters · sigma-rule
- Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image · sigma-rule
- Potential Data Stealing Via Chromium Headless Debugging · sigma-rule
- Potential Defense Evasion Via Binary Rename · sigma-rule
- Potential Defense Evasion Via Raw Disk Access By Uncommon Tools · sigma-rule
- Potential Defense Evasion Via Rename Of Highly Relevant Binaries · sigma-rule
- Potential Defense Evasion Via Right-to-Left Override · sigma-rule
- Potential DLL Injection Or Execution Using Tracker.exe · sigma-rule
- Potential DLL Sideloading Of DBGCORE.DLL · sigma-rule
- Potential DLL Sideloading Of DBGHELP.DLL · sigma-rule
- Potential DLL Sideloading Of DbgModel.DLL · sigma-rule
- Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE · sigma-rule
- Potential DLL Sideloading Of Libcurl.DLL Via GUP.EXE · sigma-rule
- Potential DLL Sideloading Of MpSvc.DLL · sigma-rule
- Potential DLL Sideloading Of MsCorSvc.DLL · sigma-rule
- Potential DLL Sideloading Of Non-Existent DLLs From System Folders · sigma-rule
- Potential DLL Sideloading Using Coregen.exe · sigma-rule
- Potential DLL Sideloading Via ClassicExplorer32.dll · sigma-rule
- Potential DLL Sideloading Via comctl32.dll · sigma-rule
- Potential DLL Sideloading Via DeviceEnroller.EXE · sigma-rule
- Potential DLL Sideloading Via JsSchHlp · sigma-rule
- Potential DLL Sideloading Via VMware Xfer · sigma-rule
- Potential EACore.DLL Sideloading · sigma-rule
- Potential Edputil.DLL Sideloading · sigma-rule
- Potential Encoded PowerShell Patterns In CommandLine · sigma-rule
- Potential Fake Instance Of Hxtsr.EXE Executed · sigma-rule
- Potential File Download Via MS-AppInstaller Protocol Handler · sigma-rule
- Potential File Extension Spoofing Using Right-to-Left Override · sigma-rule
- Potential Goopdate.DLL Sideloading · sigma-rule
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream · sigma-rule
- Potential Hidden Directory Creation Via NTFS INDEX_ALLOCATION Stream - CLI · sigma-rule
- Potential Homoglyph Attack Using Lookalike Characters · sigma-rule
- Potential Homoglyph Attack Using Lookalike Characters in Filename · sigma-rule
- Potential In-Memory Execution Using Reflection.Assembly · sigma-rule
- Potential Initial Access via DLL Search Order Hijacking · sigma-rule
- Potential Iviewers.DLL Sideloading · sigma-rule
- Potential JLI.dll Side-Loading · sigma-rule
- Potential LethalHTA Technique Execution · sigma-rule
- Potential Libvlc.DLL Sideloading · sigma-rule
- Potential Linux Process Code Injection Via DD Utility · sigma-rule
- Potential LSASS Process Dump Via Procdump · sigma-rule
- Potential Manage-bde.wsf Abuse To Proxy Execution · sigma-rule
- Potential Meterpreter/CobaltStrike Activity · sigma-rule
- Potential MFA Bypass Using Legacy Client Authentication · sigma-rule
- Potential Mfdetours.DLL Sideloading · sigma-rule
- Potential Mftrace.EXE Abuse · sigma-rule
- Potential Mpclient.DLL Sideloading · sigma-rule
- Potential Mpclient.DLL Sideloading Via Defender Binaries · sigma-rule
- Potential Mpclient.DLL Sideloading Via OfflineScannerShell.EXE Execution · sigma-rule
- Potential MsiExec Masquerading · sigma-rule
- Potential NTLM Coercion Via Certutil.EXE · sigma-rule
- Potential Obfuscated Ordinal Call Via Rundll32 · sigma-rule
- Potential Password Spraying Attempt Using Dsacls.EXE · sigma-rule
- Potential PendingFileRenameOperations Tampering · sigma-rule
- Potential Persistence Attempt Via Existing Service Tampering · sigma-rule
- Potential PowerShell Command Line Obfuscation · sigma-rule
- Potential PowerShell Execution Via DLL · sigma-rule
- Potential PowerShell Obfuscation Using Alias Cmdlets · sigma-rule
- Potential PowerShell Obfuscation Using Character Join · sigma-rule
- Potential PowerShell Obfuscation Via Reversed Commands · sigma-rule
- Potential PowerShell Obfuscation Via WCHAR/CHAR · sigma-rule
- Potential Privilege Escalation via Service Permissions Weakness · sigma-rule
- Potential Process Execution Proxy Via CL_Invocation.ps1 · sigma-rule
- Potential Process Hollowing Activity · sigma-rule
- Potential Process Injection Via Msra.EXE · sigma-rule
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution · sigma-rule
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG · sigma-rule
- Potential Provlaunch.EXE Binary Proxy Execution Abuse · sigma-rule
- Potential Python DLL SideLoading · sigma-rule
- Potential Ransomware or Unauthorized MBR Tampering Via Bcdedit.EXE · sigma-rule
- Potential Rcdll.DLL Sideloading · sigma-rule
- Potential ReflectDebugger Content Execution Via WerFault.EXE · sigma-rule
- Potential Register_App.Vbs LOLScript Abuse · sigma-rule
- Potential Registry Persistence Attempt Via DbgManagedDebugger · sigma-rule
- Potential Regsvr32 Commandline Flag Anomaly · sigma-rule
- Potential Remote SquiblyTwo Technique Execution · sigma-rule
- Potential RemoteFXvGPUDisablement.EXE Abuse · sigma-rule
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module · sigma-rule
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock · sigma-rule
- Potential RjvPlatform.DLL Sideloading From Default Location · sigma-rule
- Potential RjvPlatform.DLL Sideloading From Non-Default Location · sigma-rule
- Potential RoboForm.DLL Sideloading · sigma-rule
- Potential Rundll32 Execution With DLL Stored In ADS · sigma-rule
- Potential Script Proxy Execution Via CL_Mutexverifiers.ps1 · sigma-rule
- Potential Secure Deletion with SDelete · sigma-rule
- Potential ShellDispatch.DLL Sideloading · sigma-rule
- Potential SmadHook.DLL Sideloading · sigma-rule
- Potential SolidPDFCreator.DLL Sideloading · sigma-rule
- Potential Suspicious Activity Using SeCEdit · sigma-rule
- Potential Suspicious Mofcomp Execution · sigma-rule
- Potential SysInternals ProcDump Evasion · sigma-rule
- Potential System DLL Sideloading From Non System Locations · sigma-rule
- Potential Vcruntime140 DLL Sideloading · sigma-rule
- Potential Vivaldi_elf.DLL Sideloading · sigma-rule
- Potential Waveedit.DLL Sideloading · sigma-rule
- Potential Wazuh Security Platform DLL Sideloading · sigma-rule
- Potential WerFault ReflectDebugger Registry Value Abuse · sigma-rule
- Potential Winnti Dropper Activity · sigma-rule
- Potential WWlib.DLL Sideloading · sigma-rule
- Potentially Over Permissive Permissions Granted Using Dsacls.EXE · sigma-rule
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler · sigma-rule
- Potentially Suspicious Cabinet File Expansion · sigma-rule
- Potentially Suspicious Child Process Of DiskShadow.EXE · sigma-rule
- Potentially Suspicious Child Process of KeyScrambler.exe · sigma-rule
- Potentially Suspicious Child Process Of Regsvr32 · sigma-rule
- Potentially Suspicious Child Process Of VsCode · sigma-rule
- Potentially Suspicious Child Processes Spawned by ConHost · sigma-rule
- Potentially Suspicious CMD Shell Output Redirect · sigma-rule
- Potentially Suspicious DLL Registered Via Odbcconf.EXE · sigma-rule
- Potentially Suspicious Execution From Parent Process In Public Folder · sigma-rule
- Potentially Suspicious Execution From Tmp Folder · sigma-rule
- Potentially Suspicious Execution Of Regasm/Regsvcs From Uncommon Location · sigma-rule
- Potentially Suspicious Execution Of Regasm/Regsvcs With Uncommon Extension · sigma-rule
- Potentially Suspicious Office Document Executed From Trusted Location · sigma-rule
- Potentially Suspicious Ping/Copy Command Combination · sigma-rule
- Potentially Suspicious Regsvr32 HTTP IP Pattern · sigma-rule
- Potentially Suspicious Regsvr32 HTTP/FTP Pattern · sigma-rule
- Potentially Suspicious Rundll32 Activity · sigma-rule
- Potentially Suspicious Rundll32.EXE Execution of UDL File · sigma-rule
- Potentially Suspicious Self Extraction Directive File Created · sigma-rule
- Potentially Suspicious Wuauclt Network Connection · sigma-rule
- PowerShell Base64 Encoded FromBase64String Cmdlet · sigma-rule
- PowerShell Base64 Encoded Invoke Keyword · sigma-rule
- PowerShell Base64 Encoded Reflective Assembly Load · sigma-rule
- PowerShell Base64 Encoded WMI Classes · sigma-rule
- PowerShell Console History Logs Deleted · sigma-rule
- PowerShell Decompress Commands · sigma-rule
- PowerShell Deleted Mounted Share · sigma-rule
- Powershell Detect Virtualization Environment · sigma-rule
- Powershell Executed From Headless ConHost Process · sigma-rule
- PowerShell Logging Disabled Via Registry Key Tampering · sigma-rule
- PowerShell MSI Install via WindowsInstaller COM From Remote Location · sigma-rule
- PowerShell ShellCode · sigma-rule
- Powershell Store File In Alternate Data Stream · sigma-rule
- Powershell Timestomp · sigma-rule
- Powershell Token Obfuscation - Process Creation · sigma-rule
- PowerShell WMI Win32_Product Install MSI · sigma-rule
- Prefetch File Deleted · sigma-rule
- PrintBrm ZIP Creation of Extraction · sigma-rule
- Privileged Account Creation · sigma-rule
- Procdump Execution · sigma-rule
- Process Access via TrolleyExpress Exclusion · sigma-rule
- Process Creation Using Sysnative Folder · sigma-rule
- Process Execution From A Potentially Suspicious Folder · sigma-rule
- Process Execution From Shared Memory Directory · sigma-rule
- Process Memory Dump Via Comsvcs.DLL · sigma-rule
- Process Memory Dump Via Dotnet-Dump · sigma-rule
- Process Proxy Execution Via Squirrel.EXE · sigma-rule
- Program Executed Using Proxy/Local Command Via SSH.EXE · sigma-rule
- Proxy Execution via Vshadow · sigma-rule
- Proxy Execution Via Wuauclt.EXE · sigma-rule
- PUA - AdvancedRun Execution · sigma-rule
- PUA - AdvancedRun Suspicious Execution · sigma-rule
- PUA - DefenderCheck Execution · sigma-rule
- PUA - Potential PE Metadata Tamper Using Rcedit · sigma-rule
- PUA - Process Hacker Execution · sigma-rule
- PUA - System Informer Execution · sigma-rule
- Pubprn.vbs Proxy Execution · sigma-rule
- Python Image Load By Non-Python Process · sigma-rule
- Python One-Liners with Base64 Decoding · sigma-rule
- Python One-Liners with Base64 Decoding - Linux · sigma-rule
- Rare Remote Thread Creation By Uncommon Source Image · sigma-rule
- RegAsm.EXE Execution Without CommandLine Flags or Files · sigma-rule
- RegAsm.EXE Initiating Network Connection To Public IP · sigma-rule
- REGISTER_APP.VBS Proxy Execution · sigma-rule
- Registry Modification for OCI DLL Redirection · sigma-rule
- Registry Persistence via Service in Safe Mode · sigma-rule
- Registry-Free Process Scope COR_PROFILER · sigma-rule
- Regsvr32 DLL Execution With Suspicious File Extension · sigma-rule
- Regsvr32 DLL Execution With Uncommon Extension · sigma-rule
- Regsvr32 Execution From Highly Suspicious Location · sigma-rule
- Regsvr32 Execution From Potential Suspicious Location · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - MacOS · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - Windows · sigma-rule
- Remote CHM File Download/Execution Via HH.EXE · sigma-rule
- Remote Code Execute via Winrm.vbs · sigma-rule
- Remote File Download Via Findstr.EXE · sigma-rule
- Remote Thread Creation By Uncommon Source Image · sigma-rule
- Remote Thread Creation In Uncommon Target Image · sigma-rule
- Remote Thread Creation Ttdinject.exe Proxy · sigma-rule
- Remote Thread Creation Via PowerShell In Uncommon Target · sigma-rule
- Remote XSL Execution Via Msxsl.EXE · sigma-rule
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses · sigma-rule
- Remotely Hosted HTA File Executed Via Mshta.EXE · sigma-rule
- Remove Exported Mailbox from Exchange Webserver · sigma-rule
- Renamed AutoIt Execution · sigma-rule
- Renamed BrowserCore.EXE Execution · sigma-rule
- Renamed CreateDump Utility Execution · sigma-rule
- Renamed CURL.EXE Execution · sigma-rule
- Renamed FTP.EXE Execution · sigma-rule
- Renamed Jusched.EXE Execution · sigma-rule
- Renamed Mavinject.EXE Execution · sigma-rule
- Renamed MegaSync Execution · sigma-rule
- Renamed Msdt.EXE Execution · sigma-rule
- Renamed NirCmd.EXE Execution · sigma-rule
- Renamed Office Binary Execution · sigma-rule
- Renamed PAExec Execution · sigma-rule
- Renamed PingCastle Binary Execution · sigma-rule
- Renamed Plink Execution · sigma-rule
- Renamed Powershell Under Powershell Channel · sigma-rule
- Renamed ProcDump Execution · sigma-rule
- Renamed Schtasks Execution · sigma-rule
- Renamed Vmnat.exe Execution · sigma-rule
- Renamed ZOHO Dctask64 Execution · sigma-rule
- Response File Execution Via Odbcconf.EXE · sigma-rule
- Roles Activated Too Frequently · sigma-rule
- Roles Activation Doesn't Require MFA · sigma-rule
- Roles Are Not Being Used · sigma-rule
- Roles Assigned Outside PIM · sigma-rule
- Root Account Enable Via Dsenableroot · sigma-rule
- Run PowerShell Script from ADS · sigma-rule
- Rundll32 Execution With Uncommon DLL Extension · sigma-rule
- Rundll32 Execution Without CommandLine Parameters · sigma-rule
- Rundll32 InstallScreenSaver Execution · sigma-rule
- Rundll32 Internet Connection · sigma-rule
- RunDLL32 Spawning Explorer · sigma-rule
- Rundll32 UNC Path Execution · sigma-rule
- RunMRU Registry Key Deletion · sigma-rule
- RunMRU Registry Key Deletion - Registry · sigma-rule
- Scheduled Task Creation Masquerading as System Processes · sigma-rule
- Scheduled Task Creation with Curl and PowerShell Execution Combo · sigma-rule
- SCR File Write Event · sigma-rule
- ScreenSaver Registry Key Set · sigma-rule
- Scripting/CommandLine Process Spawned Regsvr32 · sigma-rule
- Sdiagnhost Calling Suspicious Child Process · sigma-rule
- Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location · sigma-rule
- Self Extraction Directive File Created In Potentially Suspicious Location · sigma-rule
- Sensitive File Dump Via Print.EXE · sigma-rule
- Server Side Template Injection Strings · sigma-rule
- Service DACL Abuse To Hide Services Via Sc.EXE · sigma-rule
- Service Registry Key Read Access Request · sigma-rule
- Service Registry Permissions Weakness Check · sigma-rule
- Service Security Descriptor Tampering Via Sc.EXE · sigma-rule
- SES Identity Has Been Deleted · sigma-rule
- Set Suspicious Files as System Files Using Attrib.EXE · sigma-rule
- Setup16.EXE Execution With Custom .Lst File · sigma-rule
- Shadow Copies Deletion Using Operating Systems Utilities · sigma-rule
- Shell32 DLL Execution in Suspicious Directory · sigma-rule
- Sign-in Failure Due to Conditional Access Requirements Not Met · sigma-rule
- Sign-ins by Unknown Devices · sigma-rule
- Sign-ins from Non-Compliant Devices · sigma-rule
- Silenttrinity Stager Msbuild Activity · sigma-rule
- Space After Filename - macOS · sigma-rule
- SQL Client Tools PowerShell Session Detection · sigma-rule
- Stale Accounts In A Privileged Role · sigma-rule
- Steganography Extract Files with Steghide · sigma-rule
- Steganography Hide Files with Steghide · sigma-rule
- Steganography Hide Zip Information in Picture File · sigma-rule
- Steganography Unzip Hidden Information From Picture File · sigma-rule
- Successful Authentications From Countries You Do Not Operate Out Of · sigma-rule
- Suspect Svchost Activity · sigma-rule
- Suspicious AddinUtil.EXE CommandLine Execution · sigma-rule
- Suspicious AgentExecutor PowerShell Execution · sigma-rule
- Suspicious BitLocker Access Agent Update Utility Execution · sigma-rule
- Suspicious Browser Activity · sigma-rule
- Suspicious Cabinet File Execution Via Msdt.EXE · sigma-rule
- Suspicious Calculator Usage · sigma-rule
- Suspicious Child Process Created as System · sigma-rule
- Suspicious Child Process of AspNetCompiler · sigma-rule
- Suspicious Child Process Of BgInfo.EXE · sigma-rule
- Suspicious Child Process Of Wermgr.EXE · sigma-rule
- Suspicious CodePage Switch Via CHCP · sigma-rule
- Suspicious Computer Machine Password by PowerShell · sigma-rule
- Suspicious Control Panel DLL Load · sigma-rule
- Suspicious Copy From or To System Directory · sigma-rule
- Suspicious Creation with Colorcpl · sigma-rule
- Suspicious Csi.exe Usage · sigma-rule
- Suspicious CustomShellHost Execution · sigma-rule
- Suspicious Diantz Alternate Data Stream Execution · sigma-rule
- Suspicious DLL Loaded via CertOC.EXE · sigma-rule
- Suspicious DotNET CLR Usage Log Artifact · sigma-rule
- Suspicious Double Extension Files · sigma-rule
- Suspicious Download From Direct IP Via Bitsadmin · sigma-rule
- Suspicious Download From File-Sharing Website Via Bitsadmin · sigma-rule
- Suspicious Download Via Certutil.EXE · sigma-rule
- Suspicious Driver/DLL Installation Via Odbcconf.EXE · sigma-rule
- Suspicious DumpMinitool Execution · sigma-rule
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call · sigma-rule
- Suspicious Executable File Creation · sigma-rule
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix · sigma-rule
- Suspicious Extrac32 Alternate Data Stream Execution · sigma-rule
- Suspicious File Created by ArcSOC.exe · sigma-rule
- Suspicious File Download From File Sharing Websites - File Stream · sigma-rule
- Suspicious File Downloaded From Direct IP Via Certutil.EXE · sigma-rule
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE · sigma-rule
- Suspicious File Encoded To Base64 Via Certutil.EXE · sigma-rule
- Suspicious Filename with Embedded Base64 Commands · sigma-rule
- Suspicious Files in Default GPO Folder · sigma-rule
- Suspicious Get-Variable.exe Creation · sigma-rule
- Suspicious GUP Usage · sigma-rule
- Suspicious HH.EXE Execution · sigma-rule
- Suspicious High IntegrityLevel Conhost Legacy Option · sigma-rule
- Suspicious Hyper-V Cmdlets · sigma-rule
- Suspicious Inbox Manipulation Rules · sigma-rule
- Suspicious IO.FileStream · sigma-rule
- Suspicious JavaScript Execution Via Mshta.EXE · sigma-rule
- Suspicious LNK Double Extension File Created · sigma-rule
- Suspicious Login Activity Classified By Google · sigma-rule
- Suspicious Microsoft Office Child Process · sigma-rule
- Suspicious MSDT Parent Process · sigma-rule
- Suspicious MSHTA Child Process · sigma-rule
- Suspicious MsiExec Embedding Parent · sigma-rule
- Suspicious Msiexec Execute Arbitrary DLL · sigma-rule
- Suspicious Msiexec Quiet Install From Remote Location · sigma-rule
- Suspicious Parent Double Extension File Execution · sigma-rule
- Suspicious Ping/Del Command Combination · sigma-rule
- Suspicious PowerShell WindowStyle Option · sigma-rule
- Suspicious Printer Driver Empty Manufacturer · sigma-rule
- Suspicious Process Masquerading As SvcHost.EXE · sigma-rule
- Suspicious Process Parents · sigma-rule
- Suspicious Process Start Locations · sigma-rule
- Suspicious Provlaunch.EXE Child Process · sigma-rule
- Suspicious Regsvr32 Execution From Remote Share · sigma-rule
- Suspicious Remote Child Process From Outlook · sigma-rule
- Suspicious Remote Logon with Explicit Credentials · sigma-rule
- Suspicious Response File Execution Via Odbcconf.EXE · sigma-rule
- Suspicious Rundll32 Activity Invoking Sys File · sigma-rule
- Suspicious Rundll32 Execution With Image Extension · sigma-rule
- Suspicious Rundll32 Invoking Inline VBScript · sigma-rule
- Suspicious Rundll32 Setupapi.dll Activity · sigma-rule
- Suspicious Runscripthelper.exe · sigma-rule
- Suspicious Scheduled Task Creation via Masqueraded XML File · sigma-rule
- Suspicious Service Binary Directory · sigma-rule
- Suspicious Service DACL Modification Via Set-Service Cmdlet - PS · sigma-rule
- Suspicious ShellExec_RunDLL Call Via Ordinal · sigma-rule
- Suspicious SignIns From A Non Registered Device · sigma-rule
- Suspicious Space Characters in RunMRU Registry Path - ClickFix · sigma-rule
- Suspicious Space Characters in TypedPaths Registry Path - FileFix · sigma-rule
- Suspicious Speech Runtime Binary Child Process · sigma-rule
- Suspicious Splwow64 Without Params · sigma-rule
- Suspicious Start-Process PassThru · sigma-rule
- Suspicious SYSTEM User Process Creation · sigma-rule
- Suspicious Unsigned Thor Scanner Execution · sigma-rule
- Suspicious Usage of For Loop with Recursive Directory Search in CMD · sigma-rule
- Suspicious Use of CSharp Interactive Console · sigma-rule
- Suspicious Userinit Child Process · sigma-rule
- Suspicious Vsls-Agent Command With AgentExtensionPath Load · sigma-rule
- Suspicious Windows Update Agent Empty Cmdline · sigma-rule
- Suspicious WMIC Execution Via Office Process · sigma-rule
- Suspicious WmiPrvSE Child Process · sigma-rule
- Suspicious XOR Encoded PowerShell Command · sigma-rule
- Suspicious ZipExec Execution · sigma-rule
- SyncAppvPublishingServer Bypass Powershell Restriction - PS Module · sigma-rule
- SyncAppvPublishingServer Execute Arbitrary PowerShell Code · sigma-rule
- SyncAppvPublishingServer Execution to Bypass Powershell Restriction · sigma-rule
- SyncAppvPublishingServer VBS Execute Arbitrary PowerShell Code · sigma-rule
- Sysmon Configuration Error · sigma-rule
- Sysmon Configuration Modification · sigma-rule
- Sysmon Driver Unloaded Via Fltmc.EXE · sigma-rule
- System Control Panel Item Loaded From Uncommon Location · sigma-rule
- System File Execution Location Anomaly · sigma-rule
- System Information Discovery Using System_Profiler · sigma-rule
- System Information Discovery Via Sysctl - MacOS · sigma-rule
- Taskmgr as LOCAL_SYSTEM · sigma-rule
- Tasks Folder Evasion · sigma-rule
- TeamViewer Log File Deleted · sigma-rule
- Temporary Access Pass Added To An Account · sigma-rule
- Terminal Server Client Connection History Cleared - Registry · sigma-rule
- Third Party Software DLL Sideloading · sigma-rule
- Time Travel Debugging Utility Usage · sigma-rule
- Time Travel Debugging Utility Usage - Image · sigma-rule
- Tomcat WebServer Logs Deleted · sigma-rule
- Too Many Global Admins · sigma-rule
- Touch Suspicious Service File · sigma-rule
- Triple Cross eBPF Rootkit Install Commands · sigma-rule
- Troubleshooting Pack Cmdlet Execution · sigma-rule
- Trusted Path Bypass via Windows Directory Spoofing · sigma-rule
- UAC Bypass With Fake DLL · sigma-rule
- UEFI Persistence Via Wpbbin - FileCreation · sigma-rule
- UEFI Persistence Via Wpbbin - ProcessCreation · sigma-rule
- Unauthorized System Time Modification · sigma-rule
- Uncommon Assistive Technology Applications Execution Via AtBroker.EXE · sigma-rule
- Uncommon AddinUtil.EXE CommandLine Execution · sigma-rule
- Uncommon Child Process Of AddinUtil.EXE · sigma-rule
- Uncommon Child Process Of Appvlp.EXE · sigma-rule
- Uncommon Child Process Of BgInfo.EXE · sigma-rule
- Uncommon Child Process Of Conhost.EXE · sigma-rule
- Uncommon Child Process Of Defaultpack.EXE · sigma-rule
- Uncommon Child Process Of Setres.EXE · sigma-rule
- Uncommon Child Process Spawned By Odbcconf.EXE · sigma-rule
- Uncommon Link.EXE Parent Process · sigma-rule
- Uncommon Process Access Rights For Target Image · sigma-rule
- Uncommon Sigverif.EXE Child Process · sigma-rule
- Uncommon Svchost Command Line Parameter · sigma-rule
- Uncommon Svchost Parent Process · sigma-rule
- Unfamiliar Sign-In Properties · sigma-rule
- Unmount Share Via Net.EXE · sigma-rule
- Unsigned .node File Loaded · sigma-rule
- Unsigned Binary Loaded From Suspicious Location · sigma-rule
- Unsigned DLL Loaded by Windows Utility · sigma-rule
- Unsigned Mfdetours.DLL Sideloading · sigma-rule
- Unsigned Module Loaded by ClickOnce Application · sigma-rule
- Unusual File Download from Direct IP Address · sigma-rule
- Unusual File Download From File Sharing Websites - File Stream · sigma-rule
- Use Icacls to Hide File to Everyone · sigma-rule
- Use NTFS Short Name in Command Line · sigma-rule
- Use NTFS Short Name in Image · sigma-rule
- Use Of Hidden Paths Or Files · sigma-rule
- Use of Legacy Authentication Protocols · sigma-rule
- Use of Remote.exe · sigma-rule
- Use of Scriptrunner.exe · sigma-rule
- Use Of The SFTP.EXE Binary As A LOLBIN · sigma-rule
- Use of TTDInject.exe · sigma-rule
- Use of VisualUiaVerifyNative.exe · sigma-rule
- Use of VSIISExeLauncher.exe · sigma-rule
- Use of Wfc.exe · sigma-rule
- Use Short Name Path in Image · sigma-rule
- User Access Blocked by Azure Conditional Access · sigma-rule
- User Added To Admin Group Via Dscl · sigma-rule
- User Added To Admin Group Via DseditGroup · sigma-rule
- User Added To Admin Group Via Sysadminctl · sigma-rule
- User Added to an Administrator's Azure AD Role · sigma-rule
- User Added to Local Administrator Group · sigma-rule
- User Added To Privilege Role · sigma-rule
- User State Changed From Guest To Member · sigma-rule
- Users Added to Global or Device Admin Roles · sigma-rule
- Users Authenticating To Other Azure AD Tenants · sigma-rule
- Using SettingSyncHost.exe as LOLBin · sigma-rule
- UtilityFunctions.ps1 Proxy Dll · sigma-rule
- Verclsid.exe Runs COM Object · sigma-rule
- Virtualbox Driver Installation or Starting of VMs · sigma-rule
- Visual Basic Command Line Compiler Usage · sigma-rule
- Visual Studio NodejsTools PressAnyKey Arbitrary Binary Execution · sigma-rule
- Visual Studio NodejsTools PressAnyKey Renamed Execution · sigma-rule
- VMGuestLib DLL Sideload · sigma-rule
- VMMap Signed Dbghelp.DLL Potential Sideloading · sigma-rule
- VMMap Unsigned Dbghelp.DLL Potential Sideloading · sigma-rule
- Win Susp Computer Name Containing Samtheadmin · sigma-rule
- Windows Binaries Write Suspicious Extensions · sigma-rule
- Windows Binary Executed From WSL · sigma-rule
- Windows MSIX Package Support Framework AI_STUBS Execution · sigma-rule
- Windows Processes Suspicious Parent Directory · sigma-rule
- Windows Shell/Scripting Processes Spawning Suspicious Programs · sigma-rule
- Winrs Local Command Execution · sigma-rule
- Wlrmdr.EXE Uncommon Argument Or Child Process · sigma-rule
- WMIC Loading Scripting Libraries · sigma-rule
- Writing Of Malicious Files To The Fonts Folder · sigma-rule
- WSL Child Process Anomaly · sigma-rule
- WSL Kali-Linux Usage · sigma-rule
- XBAP Execution From Uncommon Locations Via PresentationHost.EXE · sigma-rule
- XSL Script Execution Via WMIC.EXE · sigma-rule
- Xwizard.EXE Execution From Non-Default Location · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.