Files
splunk-security_content/docs/_pages/detections.md
2022-03-09 11:36:28 +01:00

50 KiB

title, layout, author_profile, permalink, classes, sidebar
title layout author_profile permalink classes sidebar
Detections categories false /detections/ wide
nav
detections
Name Technique Type
7zip CommandLine To SMB Share Path None Hunting
AWS Cloud Provisioning From Previously Unseen City None Anomaly
AWS Cloud Provisioning From Previously Unseen Country None Anomaly
AWS Cloud Provisioning From Previously Unseen IP Address None Anomaly
AWS Cloud Provisioning From Previously Unseen Region None Anomaly
AWS Create Policy Version to allow all resources None TTP
AWS CreateAccessKey None Hunting
AWS CreateLoginProfile None TTP
AWS Cross Account Activity From Previously Unseen Account None Anomaly
AWS Detect Users creating keys with encrypt policy without MFA None TTP
AWS Detect Users with KMS keys performing encryption S3 None Anomaly
AWS ECR Container Scanning Findings High None TTP
AWS ECR Container Scanning Findings Low Informational Unknown None Hunting
AWS ECR Container Scanning Findings Medium None Anomaly
AWS ECR Container Upload Outside Business Hours None Anomaly
AWS ECR Container Upload Unknown User None Anomaly
AWS EKS Kubernetes cluster sensitive object access None Hunting
AWS Excessive Security Scanning None TTP
AWS IAM AccessDenied Discovery Events None Anomaly
AWS IAM Assume Role Policy Brute Force None TTP
AWS IAM Delete Policy None Hunting
AWS IAM Failure Group Deletion None Anomaly
AWS IAM Successful Group Deletion None Hunting
AWS Lambda UpdateFunctionCode None Hunting
AWS Network Access Control List Created with All Open Ports None TTP
AWS Network Access Control List Deleted None Anomaly
AWS SAML Access by Provider User and Principal None Anomaly
AWS SAML Update identity provider None TTP
AWS SetDefaultPolicyVersion None TTP
AWS UpdateLoginProfile None TTP
Abnormally High AWS Instances Launched by User None Anomaly
Abnormally High AWS Instances Launched by User - MLTK None Anomaly
Abnormally High AWS Instances Terminated by User None Anomaly
Abnormally High AWS Instances Terminated by User - MLTK None Anomaly
Abnormally High Number Of Cloud Infrastructure API Calls None Anomaly
Abnormally High Number Of Cloud Instances Destroyed None Anomaly
Abnormally High Number Of Cloud Instances Launched None Anomaly
Abnormally High Number Of Cloud Security Group API Calls None Anomaly
Access LSASS Memory for Dump Creation None TTP
Account Discovery With Net App None TTP
Active Setup Registry Autostart None TTP
Add DefaultUser And Password In Registry None Anomaly
Add or Set Windows Defender Exclusion None TTP
AdsiSearcher Account Discovery None TTP
Allow File And Printing Sharing In Firewall None TTP
Allow Inbound Traffic By Firewall Rule Registry None TTP
Allow Inbound Traffic In Firewall Rule None TTP
Allow Network Discovery In Firewall None TTP
Allow Operation with Consent Admin None TTP
Amazon EKS Kubernetes Pod scan detection None Hunting
Amazon EKS Kubernetes cluster scan detection None Hunting
Anomalous usage of 7zip None Anomaly
Any Powershell DownloadFile None TTP
Any Powershell DownloadString None TTP
Attacker Tools On Endpoint None TTP
Attempt To Add Certificate To Untrusted Store None TTP
Attempt To Stop Security Service None TTP
Attempted Credential Dump From Registry via Reg exe None TTP
Auto Admin Logon Registry Entry None TTP
BCDEdit Failure Recovery Modification None TTP
BITS Job Persistence None TTP
BITSAdmin Download File None TTP
Batch File Write to System32 None TTP
Bcdedit Command Back To Normal Mode Boot None TTP
CHCP Command Execution None TTP
CMD Carry Out String Command Parameter None Hunting
CMD Echo Pipe - Escalation None TTP
CMLUA Or CMSTPLUA UAC Bypass None TTP
CSC Net On The Fly Compilation None Hunting
CertUtil Download With URLCache and Split Arguments None TTP
CertUtil Download With VerifyCtl and Split Arguments None TTP
CertUtil With Decode Argument None TTP
Certutil exe certificate extraction None TTP
Change Default File Association None TTP
Change To Safe Mode With Network Config None TTP
Check Elevated CMD using whoami None TTP
Child Processes of Spoolsv exe None TTP
Circle CI Disable Security Job None Anomaly
Circle CI Disable Security Step None Anomaly
Clear Unallocated Sector Using Cipher App None TTP
Clients Connecting to Multiple DNS Servers None TTP
Clop Common Exec Parameter None TTP
Clop Ransomware Known Service Name None TTP
Cloud API Calls From Previously Unseen User Roles None Anomaly
Cloud Compute Instance Created By Previously Unseen User None Anomaly
Cloud Compute Instance Created In Previously Unused Region None Anomaly
Cloud Compute Instance Created With Previously Unseen Image None Anomaly
Cloud Compute Instance Created With Previously Unseen Instance Type None Anomaly
Cloud Instance Modified By Previously Unseen User None Anomaly
Cloud Network Access Control List Deleted None Anomaly
Cloud Provisioning Activity From Previously Unseen City None Anomaly
Cloud Provisioning Activity From Previously Unseen Country None Anomaly
Cloud Provisioning Activity From Previously Unseen IP Address None Anomaly
Cloud Provisioning Activity From Previously Unseen Region None Anomaly
Cmdline Tool Not Executed In CMD Shell None TTP
Cobalt Strike Named Pipes None TTP
Common Ransomware Extensions None Hunting
Common Ransomware Notes None Hunting
Conti Common Exec parameter None TTP
Control Loading from World Writable Directory None TTP
Correlation by Repository and Risk None Correlation
Correlation by User and Risk None Correlation
Create Remote Thread In Shell Application None TTP
Create Remote Thread into LSASS None TTP
Create local admin accounts using net exe None TTP
Create or delete windows shares using net exe None TTP
Creation of Shadow Copy None TTP
Creation of Shadow Copy with wmic and powershell None TTP
Creation of lsass Dump with Taskmgr None TTP
Credential Dumping via Copy Command from Shadow Copy None TTP
Credential Dumping via Symlink to Shadow Copy None TTP
Curl Download and Bash Execution None TTP
DLLHost with no Command Line Arguments with Network None TTP
DNS Exfiltration Using Nslookup App None TTP
DNS Query Length Outliers - MLTK None Anomaly
DNS Query Length With High Standard Deviation None Anomaly
DNS Query Requests Resolved by Unauthorized DNS Servers None TTP
DNS record changed None TTP
DSQuery Domain Discovery None TTP
Delete ShadowCopy With PowerShell None TTP
Deleting Of Net Users None TTP
Deleting Shadow Copies None TTP
Detect API activity from users without MFA None Hunting
Detect ARP Poisoning None TTP
Detect AWS API Activities From Unapproved Accounts None Hunting
Detect AWS Console Login by New User None Hunting
Detect AWS Console Login by User from New City None Hunting
Detect AWS Console Login by User from New Country None Hunting
Detect AWS Console Login by User from New Region None Hunting
Detect Activity Related to Pass the Hash Attacks None TTP
Detect AzureHound Command-Line Arguments None TTP
Detect AzureHound File Modifications None TTP
Detect Baron Samedit CVE-2021-3156 None TTP
Detect Baron Samedit CVE-2021-3156 Segfault None TTP
Detect Baron Samedit CVE-2021-3156 via OSQuery None TTP
Detect Computer Changed with Anonymous Account None Hunting
Detect Copy of ShadowCopy with Script Block Logging None TTP
Detect Credential Dumping through LSASS access None TTP
Detect DNS requests to Phishing Sites leveraging EvilGinx2 None TTP
Detect Empire with PowerShell Script Block Logging None TTP
Detect Excessive Account Lockouts From Endpoint None Anomaly
Detect Excessive User Account Lockouts None Anomaly
Detect Exchange Web Shell None TTP
Detect F5 TMUI RCE CVE-2020-5902 None TTP
Detect GCP Storage access from a new IP None Anomaly
Detect HTML Help Renamed None Hunting
Detect HTML Help Spawn Child Process None TTP
Detect HTML Help URL in Command Line None TTP
Detect HTML Help Using InfoTech Storage Handlers None TTP
Detect IPv6 Network Infrastructure Threats None TTP
Detect Large Outbound ICMP Packets None TTP
Detect Long DNS TXT Record Response None TTP
Detect MSHTA Url in Command Line None TTP
Detect Mimikatz Using Loaded Images None TTP
Detect Mimikatz Via PowerShell And EventCode 4703 None TTP
Detect Mimikatz With PowerShell Script Block Logging None TTP
Detect New Local Admin account None TTP
Detect New Login Attempts to Routers None TTP
Detect New Open GCP Storage Buckets None TTP
Detect New Open S3 Buckets over AWS CLI None TTP
Detect New Open S3 buckets None TTP
Detect Outbound LDAP Traffic None Hunting
Detect Outbound SMB Traffic None TTP
Detect Outlook exe writing a zip file None TTP
Detect Path Interception By Creation Of program exe None TTP
Detect Port Security Violation None TTP
Detect Prohibited Applications Spawning cmd exe None Hunting
Detect PsExec With accepteula Flag None TTP
Detect RClone Command-Line Usage None TTP
Detect Rare Executables None Anomaly
Detect Regasm Spawning a Process None TTP
Detect Regasm with Network Connection None TTP
Detect Regasm with no Command Line Arguments None TTP
Detect Regsvcs Spawning a Process None TTP
Detect Regsvcs with Network Connection None TTP
Detect Regsvcs with No Command Line Arguments None TTP
Detect Regsvr32 Application Control Bypass None TTP
Detect Renamed 7-Zip None Hunting
Detect Renamed PSExec None Hunting
Detect Renamed RClone None Hunting
Detect Renamed WinRAR None Hunting
Detect Rogue DHCP Server None TTP
Detect Rundll32 Application Control Bypass - advpack None TTP
Detect Rundll32 Application Control Bypass - setupapi None TTP
Detect Rundll32 Application Control Bypass - syssetup None TTP
Detect Rundll32 Inline HTA Execution None TTP
Detect S3 access from a new IP None Anomaly
Detect SNICat SNI Exfiltration None TTP
Detect SharpHound Command-Line Arguments None TTP
Detect SharpHound File Modifications None TTP
Detect SharpHound Usage None TTP
Detect Software Download To Network Device None TTP
Detect Spike in AWS API Activity None Anomaly
Detect Spike in AWS Security Hub Alerts for EC2 Instance None Anomaly
Detect Spike in AWS Security Hub Alerts for User None Anomaly
Detect Spike in Network ACL Activity None Anomaly
Detect Spike in S3 Bucket deletion None Anomaly
Detect Spike in Security Group Activity None Anomaly
Detect Spike in blocked Outbound Traffic from your AWS None Anomaly
Detect Traffic Mirroring None TTP
Detect USB device insertion None TTP
Detect Unauthorized Assets by MAC address None TTP
Detect Use of cmd exe to Launch Script Interpreters None TTP
Detect WMI Event Subscription Persistence None TTP
Detect Windows DNS SIGRed via Splunk Stream None TTP
Detect Windows DNS SIGRed via Zeek None TTP
Detect Zerologon via Zeek None TTP
Detect attackers scanning for vulnerable JBoss servers None TTP
Detect hosts connecting to dynamic domain providers None TTP
Detect malicious requests to exploit JBoss servers None TTP
Detect mshta inline hta execution None TTP
Detect mshta renamed None Hunting
Detect new API calls from user roles None Anomaly
Detect new user AWS Console Login None Hunting
Detect processes used for System Network Configuration Discovery None TTP
Detect shared ec2 snapshot None TTP
Detect web traffic to dynamic domain providers None TTP
Detection of DNS Tunnels None TTP
Detection of tools built by NirSoft None TTP
Disable AMSI Through Registry None TTP
Disable Defender AntiVirus Registry None TTP
Disable Defender BlockAtFirstSeen Feature None TTP
Disable Defender Enhanced Notification None TTP
Disable Defender MpEngine Registry None TTP
Disable Defender Spynet Reporting None TTP
Disable Defender Submit Samples Consent Feature None TTP
Disable ETW Through Registry None TTP
Disable Logs Using WevtUtil None TTP
Disable Registry Tool None TTP
Disable Schedule Task None TTP
Disable Security Logs Using MiniNt Registry None TTP
Disable Show Hidden Files None TTP
Disable UAC Remote Restriction None TTP
Disable Windows App Hotkeys None TTP
Disable Windows Behavior Monitoring None TTP
Disable Windows SmartScreen Protection None TTP
Disabled Kerberos Pre-Authentication Discovery With Get-ADUser None TTP
Disabled Kerberos Pre-Authentication Discovery With PowerView None TTP
Disabling CMD Application None TTP
Disabling ControlPanel None TTP
Disabling Defender Services None TTP
Disabling Firewall with Netsh None TTP
Disabling FolderOptions Windows Feature None TTP
Disabling Net User Account None TTP
Disabling NoRun Windows App None TTP
Disabling Remote User Account Control None TTP
Disabling SystemRestore In Registry None TTP
Disabling Task Manager None TTP
Domain Account Discovery With Net App None TTP
Domain Account Discovery with Dsquery None Hunting
Domain Account Discovery with Wmic None TTP
Domain Controller Discovery with Nltest None TTP
Domain Controller Discovery with Wmic None Hunting
Domain Group Discovery With Dsquery None Hunting
Domain Group Discovery With Net None Hunting
Domain Group Discovery With Wmic None Hunting
Domain Group Discovery with Adsisearcher None TTP
Download Files Using Telegram None TTP
Drop IcedID License dat None Hunting
Dump LSASS via comsvcs DLL None TTP
Dump LSASS via procdump None TTP
Dump LSASS via procdump Rename None Hunting
EC2 Instance Modified With Previously Unseen User None Anomaly
EC2 Instance Started In Previously Unseen Region None Anomaly
EC2 Instance Started With Previously Unseen AMI None Anomaly
EC2 Instance Started With Previously Unseen Instance Type None Anomaly
EC2 Instance Started With Previously Unseen User None Anomaly
ETW Registry Disabled None TTP
Elevated Group Discovery With Net None TTP
Elevated Group Discovery With Wmic None TTP
Elevated Group Discovery with PowerView None Hunting
Email Attachments With Lots Of Spaces None Anomaly
Email files written outside of the Outlook directory None TTP
Email servers sending high volume traffic to hosts None Anomaly
Enable RDP In Other Port Number None TTP
Enable WDigest UseLogonCredential Registry None TTP
Enumerate Users Local Group Using Telegram None TTP
Esentutl SAM Copy None Hunting
Eventvwr UAC Bypass None TTP
Excel Spawning PowerShell None TTP
Excel Spawning Windows Script Host None TTP
Excessive Attempt To Disable Services None Anomaly
Excessive DNS Failures None Anomaly
Excessive File Deletion In WinDefender Folder None TTP
Excessive Service Stop Attempt None Anomaly
Excessive Usage Of Cacls App None Anomaly
Excessive Usage Of Net App None Anomaly
Excessive Usage Of SC Service Utility None Anomaly
Excessive Usage Of Taskkill None Anomaly
Excessive Usage of NSLOOKUP App None Anomaly
Excessive number of distinct processes created in Windows Temp folder None Anomaly
Excessive number of service control start as disabled None Anomaly
Excessive number of taskhost processes None Anomaly
Exchange PowerShell Abuse via SSRF None TTP
Exchange PowerShell Module Usage None TTP
Executable File Written in Administrative SMB Share None TTP
Executables Or Script Creation In Suspicious Path None TTP
Execute Javascript With Jscript COM CLSID None TTP
Execution of File With Spaces Before Extension None TTP
Execution of File with Multiple Extensions None TTP
Extended Period Without Successful Netbackup Backups None Hunting
Extraction of Registry Hives None TTP
File with Samsam Extension None TTP
Firewall Allowed Program Enable None Anomaly
First Time Seen Child Process of Zoom None Anomaly
First Time Seen Running Windows Service None Anomaly
First time seen command line argument None Hunting
FodHelper UAC Bypass None TTP
Fsutil Zeroing File None TTP
GCP Detect accounts with high risk roles by project None Hunting
GCP Detect gcploit framework None TTP
GCP Detect high risk permissions by resource and account None Hunting
GCP GCR container uploaded None Hunting
GCP Kubernetes cluster pod scan detection None Hunting
GCP Kubernetes cluster scan detection None TTP
GPUpdate with no Command Line Arguments with Network None TTP
GSuite Email Suspicious Attachment None Anomaly
Gdrive suspicious file sharing None Hunting
Get ADDefaultDomainPasswordPolicy with Powershell None Hunting
Get ADDefaultDomainPasswordPolicy with Powershell Script Block None Hunting
Get ADUser with PowerShell None Hunting
Get ADUser with PowerShell Script Block None Hunting
Get ADUserResultantPasswordPolicy with Powershell None TTP
Get ADUserResultantPasswordPolicy with Powershell Script Block None TTP
Get DomainPolicy with Powershell None TTP
Get DomainPolicy with Powershell Script Block None TTP
Get DomainUser with PowerShell None TTP
Get DomainUser with PowerShell Script Block None TTP
Get WMIObject Group Discovery None Hunting
Get WMIObject Group Discovery with Script Block Logging None Hunting
Get-DomainTrust with PowerShell None TTP
Get-DomainTrust with PowerShell Script Block None TTP
Get-ForestTrust with PowerShell None TTP
Get-ForestTrust with PowerShell Script Block None TTP
GetAdComputer with PowerShell None Hunting
GetAdComputer with PowerShell Script Block None Hunting
GetAdGroup with PowerShell None Hunting
GetAdGroup with PowerShell Script Block None Hunting
GetCurrent User with PowerShell None Hunting
GetCurrent User with PowerShell Script Block None Hunting
GetDomainComputer with PowerShell None TTP
GetDomainComputer with PowerShell Script Block None TTP
GetDomainController with PowerShell None Hunting
GetDomainController with PowerShell Script Block None TTP
GetDomainGroup with PowerShell None TTP
GetDomainGroup with PowerShell Script Block None TTP
GetLocalUser with PowerShell None Hunting
GetLocalUser with PowerShell Script Block None Hunting
GetNetTcpconnection with PowerShell None Hunting
GetNetTcpconnection with PowerShell Script Block None Hunting
GetWmiObject DS User with PowerShell None TTP
GetWmiObject DS User with PowerShell Script Block None TTP
GetWmiObject Ds Computer with PowerShell None TTP
GetWmiObject Ds Computer with PowerShell Script Block None TTP
GetWmiObject Ds Group with PowerShell None TTP
GetWmiObject Ds Group with PowerShell Script Block None TTP
GetWmiObject User Account with PowerShell None Hunting
GetWmiObject User Account with PowerShell Script Block None Hunting
GitHub Dependabot Alert None Anomaly
GitHub Pull Request from Unknown User None Anomaly
Github Commit Changes In Master None Anomaly
Github Commit In Develop None Anomaly
Gsuite Drive Share In External Email None Anomaly
Gsuite Email Suspicious Subject With Attachment None Anomaly
Gsuite Email With Known Abuse Web Service Link None Anomaly
Gsuite Outbound Email With Attachment To External Domain None Anomaly
Gsuite Suspicious Shared File Name None Anomaly
Gsuite suspicious calendar invite None Hunting
Hide User Account From Sign-In Screen None TTP
Hiding Files And Directories With Attrib exe None TTP
High Frequency Copy Of Files In Network Share None Anomaly
High Number of Login Failures from a single source None Anomaly
High Process Termination Frequency None Anomaly
Hosts receiving high volume of network traffic from email server None Anomaly
Hunting for Log4Shell None Hunting
ICACLS Grant Command None TTP
Icacls Deny Command None TTP
IcedID Exfiltrated Archived File Creation None Hunting
Identify New User Accounts None Hunting
Impacket Lateral Movement Commandline Parameters None TTP
Interactive Session on Remote Endpoint with PowerShell None TTP
Java Class File download by Java User Agent None TTP
Jscript Execution Using Cscript App None TTP
Kerberoasting spn request with RC4 encryption None TTP
Kerberos Pre-Authentication Flag Disabled in UserAccountControl None TTP
Kerberos Pre-Authentication Flag Disabled with PowerShell None TTP
Known Services Killed by Ransomware None TTP
Kubernetes AWS detect RBAC authorization by account None Hunting
Kubernetes AWS detect most active service accounts by pod None Hunting
Kubernetes AWS detect sensitive role access None Hunting
Kubernetes AWS detect service accounts forbidden failure access None Hunting
Kubernetes AWS detect suspicious kubectl calls None Hunting
Kubernetes Azure detect RBAC authorization by account None Hunting
Kubernetes Azure detect most active service accounts by pod namespace None Hunting
Kubernetes Azure detect sensitive object access None Hunting
Kubernetes Azure detect sensitive role access None Hunting
Kubernetes Azure detect service accounts forbidden failure access None Hunting
Kubernetes Azure detect suspicious kubectl calls None Hunting
Kubernetes Azure pod scan fingerprint None Hunting
Kubernetes Azure scan fingerprint None Hunting
Kubernetes GCP detect RBAC authorizations by account None Hunting
Kubernetes GCP detect most active service accounts by pod None Hunting
Kubernetes GCP detect sensitive object access None Hunting
Kubernetes GCP detect sensitive role access None Hunting
Kubernetes GCP detect service accounts forbidden failure access None Hunting
Kubernetes GCP detect suspicious kubectl calls None Hunting
Kubernetes Nginx Ingress LFI None TTP
Kubernetes Nginx Ingress RFI None TTP
Kubernetes Scanner Image Pulling None TTP
Large Volume of DNS ANY Queries None Anomaly
Linux Add Files In Known Crontab Directories None Anomaly
Linux Add User Account None Hunting
Linux At Allow Config File Creation None Anomaly
Linux At Application Execution None Anomaly
Linux Change File Owner To Root None Anomaly
Linux Common Process For Elevation Control None Hunting
Linux DD File Overwrite None TTP
Linux Doas Conf File Creation None Anomaly
Linux Doas Tool Execution None Anomaly
Linux Edit Cron Table Parameter None Hunting
Linux File Created In Kernel Driver Directory None Anomaly
Linux File Creation In Init Boot Directory None Anomaly
Linux File Creation In Profile Directory None Anomaly
Linux Insert Kernel Module Using Insmod Utility None Anomaly
Linux Install Kernel Module Using Modprobe Utility None Anomaly
Linux Java Spawning Shell None TTP
Linux NOPASSWD Entry In Sudoers File None Anomaly
Linux Possible Access Or Modification Of sshd Config File None Anomaly
Linux Possible Access To Credential Files None Anomaly
Linux Possible Access To Sudoers File None Anomaly
Linux Possible Append Command To At Allow Config File None Anomaly
Linux Possible Append Command To Profile Config File None Anomaly
Linux Possible Append Cronjob Entry on Existing Cronjob File None Hunting
Linux Possible Cronjob Modification With Editor None Hunting
Linux Possible Ssh Key File Creation None Anomaly
Linux Preload Hijack Library Calls None TTP
Linux Service File Created In Systemd Directory None Anomaly
Linux Service Restarted None Anomaly
Linux Service Started Or Enabled None Anomaly
Linux Setuid Using Chmod Utility None Anomaly
Linux Setuid Using Setcap Utility None Anomaly
Linux Sudo OR Su Execution None Hunting
Linux Sudoers Tmp File Creation None Anomaly
Linux System Network Discovery None Anomaly
Linux Visudo Utility Execution None Anomaly
Linux pkexec Privilege Escalation None TTP
Loading Of Dynwrapx Module None TTP
Local Account Discovery With Wmic None Hunting
Local Account Discovery with Net None Hunting
Log4Shell CVE-2021-44228 Exploitation None Correlation
Log4Shell JNDI Payload Injection Attempt None Anomaly
Log4Shell JNDI Payload Injection with Outbound Connection None Anomaly
Logon Script Event Trigger Execution None TTP
MS Scripting Process Loading Ldap Module None Anomaly
MS Scripting Process Loading WMI Module None Anomaly
MSBuild Suspicious Spawned By Script Process None TTP
MSHTML Module Load in Office Product None TTP
MSI Module Loaded by Non-System Binary None Hunting
MacOS - Re-opened Applications None TTP
Mailsniper Invoke functions None TTP
Malicious InProcServer32 Modification None TTP
Malicious PowerShell Process - Encoded Command None Hunting
Malicious PowerShell Process - Execution Policy Bypass None TTP
Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments None TTP
Malicious PowerShell Process With Obfuscation Techniques None TTP
Malicious Powershell Executed As A Service None TTP
Microsoft Exchange Mailbox Replication service writing Active Server Pages None TTP
Mimikatz PassTheTicket CommandLine Parameters None TTP
Mmc LOLBAS Execution Process Spawn None TTP
Modification Of Wallpaper None TTP
Modify ACL permission To Files Or Folder None TTP
Monitor DNS For Brand Abuse None TTP
Monitor Email For Brand Abuse None TTP
Monitor Registry Keys for Print Monitors None TTP
Monitor Web Traffic For Brand Abuse None TTP
Mshta spawning Rundll32 OR Regsvr32 Process None TTP
Msmpeng Application DLL Side Loading None TTP
Multiple Archive Files Http Post Traffic None TTP
Multiple Disabled Users Failing To Authenticate From Host Using Kerberos None Anomaly
Multiple Invalid Users Failing To Authenticate From Host Using Kerberos None Anomaly
Multiple Invalid Users Failing To Authenticate From Host Using NTLM None Anomaly
Multiple Okta Users With Invalid Credentials From The Same IP None TTP
Multiple Users Attempting To Authenticate Using Explicit Credentials None Anomaly
Multiple Users Failing To Authenticate From Host Using Kerberos None Anomaly
Multiple Users Failing To Authenticate From Host Using NTLM None Anomaly
Multiple Users Failing To Authenticate From Process None Anomaly
Multiple Users Remotely Failing To Authenticate From Host None Anomaly
NET Profiler UAC bypass None TTP
NLTest Domain Trust Discovery None TTP
Net Localgroup Discovery None Hunting
Network Connection Discovery With Arp None Hunting
Network Connection Discovery With Net None Hunting
Network Connection Discovery With Netstat None Hunting
Network Discovery Using Route Windows App None Hunting
New container uploaded to AWS ECR None Hunting
Nishang PowershellTCPOneLine None TTP
No Windows Updates in a time frame None Hunting
Non Chrome Process Accessing Chrome Default Dir None Anomaly
Non Firefox Process Access Firefox Profile Dir None Anomaly
Ntdsutil Export NTDS None TTP
O365 Add App Role Assignment Grant User None TTP
O365 Added Service Principal None TTP
O365 Bypass MFA via Trusted IP None TTP
O365 Disable MFA None TTP
O365 Excessive Authentication Failures Alert None Anomaly
O365 Excessive SSO logon errors None Anomaly
O365 New Federated Domain Added None TTP
O365 PST export alert None TTP
O365 Suspicious Admin Email Forwarding None Anomaly
O365 Suspicious Rights Delegation None TTP
O365 Suspicious User Email Forwarding None Anomaly
Office Application Drop Executable None TTP
Office Application Spawn Regsvr32 process None TTP
Office Application Spawn rundll32 process None TTP
Office Document Creating Schedule Task None TTP
Office Document Executing Macro Code None TTP
Office Document Spawned Child Process To Download None TTP
Office Product Spawn CMD Process None TTP
Office Product Spawning BITSAdmin None TTP
Office Product Spawning CertUtil None TTP
Office Product Spawning MSHTA None TTP
Office Product Spawning Rundll32 with no DLL None TTP
Office Product Spawning Wmic None TTP
Office Product Writing cab or inf None TTP
Office Spawning Control None TTP
Okta Account Lockout Events None Anomaly
Okta Failed SSO Attempts None Anomaly
Okta User Logins From Multiple Cities None Anomaly
Open Redirect in Splunk Web None TTP
Osquery pack - ColdRoot detection None TTP
Outbound Network Connection from Java Using Default Ports None TTP
Overwriting Accessibility Binaries None TTP
Password Policy Discovery with Net None Hunting
Permission Modification using Takeown App None TTP
PetitPotam Network Share Access Request None TTP
PetitPotam Suspicious Kerberos TGT Request None TTP
Ping Sleep Batch Command None Anomaly
Plain HTTP POST Exfiltrated Data None TTP
Possible Browser Pass View Parameter None Hunting
Possible Lateral Movement PowerShell Spawn None TTP
Potentially malicious code on commandline None Anomaly
PowerShell - Connect To Internet With Hidden Window None Hunting
PowerShell 4104 Hunting None Hunting
PowerShell Domain Enumeration None TTP
PowerShell Get LocalGroup Discovery None Hunting
PowerShell Loading DotNET into Memory via System Reflection Assembly None TTP
PowerShell Start-BitsTransfer None TTP
Powershell Creating Thread Mutex None TTP
Powershell Disable Security Monitoring None TTP
Powershell Enable SMB1Protocol Feature None TTP
Powershell Execute COM Object None TTP
Powershell Fileless Process Injection via GetProcAddress None TTP
Powershell Fileless Script Contains Base64 Encoded Content None TTP
Powershell Get LocalGroup Discovery with Script Block Logging None Hunting
Powershell Processing Stream Of Data None TTP
Powershell Remote Thread To Known Windows Process None TTP
Powershell Remove Windows Defender Directory None TTP
Powershell Using memory As Backing Store None TTP
Powershell Windows Defender Exclusion Commands None TTP
Prevent Automatic Repair Mode using Bcdedit None TTP
Print Processor Registry Autostart None TTP
Print Spooler Adding A Printer Driver None TTP
Print Spooler Failed to Load a Plug-in None TTP
Process Creating LNK file in Suspicious Location None TTP
Process Deleting Its Process File Path None TTP
Process Execution via WMI None TTP
Process Kill Base On File Path None TTP
Process Writing DynamicWrapperX None Hunting
Processes Tapping Keyboard Events None TTP
Processes created by netsh None TTP
Processes launching netsh None TTP
Prohibited Network Traffic Allowed None TTP
Prohibited Software On Endpoint None Hunting
Protocol or Port Mismatch None Anomaly
Protocols passing authentication in cleartext None TTP
Randomly Generated Scheduled Task Name None Hunting
Randomly Generated Windows Service Name None Hunting
Ransomware Notes bulk creation None Anomaly
Recon AVProduct Through Pwh or WMI None TTP
Recon Using WMI Class None TTP
Recursive Delete of Directory In Batch CMD None TTP
Reg exe Manipulating Windows Services Registry Keys None TTP
Reg exe used to hide files directories via registry keys None TTP
Registry Keys Used For Persistence None TTP
Registry Keys Used For Privilege Escalation None TTP
Registry Keys for Creating SHIM Databases None TTP
Regsvr32 Silent and Install Param Dll Loading None Anomaly
Regsvr32 with Known Silent Switch Cmdline None Anomaly
Remcos RAT File Creation in Remcos Folder None TTP
Remcos client registry install entry None TTP
Remote Desktop Network Bruteforce None TTP
Remote Desktop Network Traffic None Anomaly
Remote Desktop Process Running On System None Hunting
Remote Process Instantiation via DCOM and PowerShell None TTP
Remote Process Instantiation via DCOM and PowerShell Script Block None TTP
Remote Process Instantiation via WMI None TTP
Remote Process Instantiation via WMI and PowerShell None TTP
Remote Process Instantiation via WMI and PowerShell Script Block None TTP
Remote Process Instantiation via WinRM and PowerShell None TTP
Remote Process Instantiation via WinRM and PowerShell Script Block None TTP
Remote Process Instantiation via WinRM and Winrs None TTP
Remote Registry Key modifications None TTP
Remote System Discovery with Adsisearcher None TTP
Remote System Discovery with Dsquery None Hunting
Remote System Discovery with Net None Hunting
Remote System Discovery with Wmic None TTP
Remote WMI Command Attempt None TTP
Resize ShadowStorage volume None TTP
Revil Common Exec Parameter None TTP
Revil Registry Entry None TTP
Rubeus Command Line Parameters None TTP
Rubeus Kerberos Ticket Exports Through Winlogon Access None TTP
RunDLL Loading DLL By Ordinal None TTP
Runas Execution in CommandLine None Hunting
Rundll32 Control RunDLL Hunt None Hunting
Rundll32 Control RunDLL World Writable Directory None TTP
Rundll32 Create Remote Thread To A Process None TTP
Rundll32 CreateRemoteThread In Browser None TTP
Rundll32 DNSQuery None TTP
Rundll32 Process Creating Exe Dll Files None TTP
Rundll32 Shimcache Flush None TTP
Rundll32 with no Command Line Arguments with Network None TTP
Ryuk Test Files Detected None TTP
Ryuk Wake on LAN Command None TTP
SAM Database File Access Attempt None Hunting
SLUI RunAs Elevated None TTP
SLUI Spawning a Process None TTP
SMB Traffic Spike None Anomaly
SMB Traffic Spike - MLTK None Anomaly
SQL Injection with Long URLs None TTP
Samsam Test File Write None TTP
Sc exe Manipulating Windows Services None TTP
SchCache Change By App Connect And Create ADSI Object None Anomaly
Schedule Task with HTTP Command Arguments None TTP
Schedule Task with Rundll32 Command Trigger None TTP
Scheduled Task Creation on Remote Endpoint using At None TTP
Scheduled Task Deleted Or Created via CMD None TTP
Scheduled Task Initiation on Remote Endpoint None TTP
Scheduled tasks used in BadRabbit ransomware None TTP
Schtasks Run Task On Demand None TTP
Schtasks scheduling job on remote system None TTP
Schtasks used for forcing a reboot None TTP
Screensaver Event Trigger Execution None TTP
Script Execution via WMI None TTP
Sdclt UAC Bypass None TTP
Sdelete Application Execution None TTP
SearchProtocolHost with no Command Line with Network None TTP
SecretDumps Offline NTDS Dumping Tool None TTP
ServicePrincipalNames Discovery with PowerShell None TTP
ServicePrincipalNames Discovery with SetSPN None TTP
Services Escalate Exe None TTP
Services LOLBAS Execution Process Spawn None TTP
Set Default PowerShell Execution Policy To Unrestricted or Bypass None TTP
Shim Database File Creation None TTP
Shim Database Installation With Suspicious Parameters None TTP
Short Lived Scheduled Task None TTP
Short Lived Windows Accounts None TTP
SilentCleanup UAC Bypass None TTP
Single Letter Process On Endpoint None TTP
Spectre and Meltdown Vulnerable Systems None TTP
Spike in File Writes None Anomaly
Splunk Enterprise Information Disclosure None TTP
Spoolsv Spawning Rundll32 None TTP
Spoolsv Suspicious Loaded Modules None TTP
Spoolsv Suspicious Process Access None TTP
Spoolsv Writing a DLL None TTP
Spoolsv Writing a DLL - Sysmon None TTP
Sqlite Module In Temp Folder None TTP
Start Up During Safe Mode Boot None TTP
Sunburst Correlation DLL and Network Event None TTP
Supernova Webshell None TTP
Suspicious Changes to File Associations None TTP
Suspicious Computer Account Name Change None TTP
Suspicious Copy on System32 None TTP
Suspicious Curl Network Connection None TTP
Suspicious DLLHost no Command Line Arguments None TTP
Suspicious Driver Loaded Path None TTP
Suspicious Email - UBA Anomaly None Anomaly
Suspicious Email Attachment Extensions None Anomaly
Suspicious Event Log Service Behavior None TTP
Suspicious File Write None Hunting
Suspicious GPUpdate no Command Line Arguments None TTP
Suspicious IcedID Rundll32 Cmdline None TTP
Suspicious Image Creation In Appdata Folder None TTP
Suspicious Java Classes None Anomaly
Suspicious Kerberos Service Ticket Request None TTP
Suspicious Linux Discovery Commands None TTP
Suspicious MSBuild Rename None TTP
Suspicious MSBuild Spawn None TTP
Suspicious PlistBuddy Usage None TTP
Suspicious PlistBuddy Usage via OSquery None TTP
Suspicious Process DNS Query Known Abuse Web Services None TTP
Suspicious Process File Path None TTP
Suspicious Process With Discord DNS Query None Anomaly
Suspicious Reg exe Process None TTP
Suspicious Regsvr32 Register Suspicious Path None TTP
Suspicious Rundll32 PluginInit None TTP
Suspicious Rundll32 Rename None Hunting
Suspicious Rundll32 StartW None TTP
Suspicious Rundll32 dllregisterserver None TTP
Suspicious Rundll32 no Command Line Arguments None TTP
Suspicious SQLite3 LSQuarantine Behavior None TTP
Suspicious Scheduled Task from Public Directory None Anomaly
Suspicious SearchProtocolHost no Command Line Arguments None TTP
Suspicious Ticket Granting Ticket Request None Hunting
Suspicious WAV file in Appdata Folder None TTP
Suspicious microsoft workflow compiler rename None Hunting
Suspicious microsoft workflow compiler usage None TTP
Suspicious msbuild path None TTP
Suspicious mshta child process None TTP
Suspicious mshta spawn None TTP
Suspicious wevtutil Usage None TTP
Suspicious writes to System Volume Information None Hunting
Suspicious writes to windows Recycle Bin None TTP
Svchost LOLBAS Execution Process Spawn None TTP
System Info Gathering Using Dxdiag Application None Hunting
System Information Discovery Detection None TTP
System Processes Run From Unexpected Locations None TTP
System User Discovery With Query None Hunting
System User Discovery With Whoami None Hunting
TOR Traffic None TTP
Time Provider Persistence Registry None TTP
Trickbot Named Pipe None TTP
UAC Bypass MMC Load Unsigned Dll None TTP
UAC Bypass With Colorui COM Object None TTP
USN Journal Deletion None TTP
Uncommon Processes On Endpoint None Hunting
Unified Messaging Service Spawning a Process None TTP
Uninstall App Using MsiExec None TTP
Unload Sysmon Filter Driver None TTP
Unloading AMSI via Reflection None TTP
Unsigned Image Loaded by LSASS None TTP
Unsuccessful Netbackup backups None Hunting
Unusual Number of Computer Service Tickets Requested None Hunting
Unusual Number of Kerberos Service Tickets Requested None Anomaly
Unusual Number of Remote Endpoint Authentication Events None Hunting
Unusually Long Command Line None Anomaly
Unusually Long Command Line - MLTK None Anomaly
Unusually Long Content-Type Length None Anomaly
User Discovery With Env Vars PowerShell None Hunting
User Discovery With Env Vars PowerShell Script Block None Hunting
Vbscript Execution Using Wscript App None TTP
Verclsid CLSID Execution None Hunting
W3WP Spawning Shell None TTP
WBAdmin Delete System Backups None TTP
WMI Permanent Event Subscription None TTP
WMI Permanent Event Subscription - Sysmon None TTP
WMI Recon Running Process Or Services None TTP
WMI Temporary Event Subscription None TTP
WMIC XSL Execution via URL None TTP
WSReset UAC Bypass None TTP
Wbemprox COM Object Execution None TTP
Web Fraud - Account Harvesting None TTP
Web Fraud - Anomalous User Clickspeed None Anomaly
Web Fraud - Password Sharing Across Accounts None Anomaly
Web Servers Executing Suspicious Processes None TTP
Wermgr Process Connecting To IP Check Web Services None TTP
Wermgr Process Create Executable File None TTP
Wermgr Process Spawned CMD Or Powershell Process None TTP
Wget Download and Bash Execution None TTP
WinEvent Scheduled Task Created Within Public Path None TTP
WinEvent Scheduled Task Created to Spawn Shell None TTP
WinEvent Windows Task Scheduler Event Action Started None Hunting
WinRM Spawning a Process None TTP
Windows AdFind Exe None TTP
Windows Curl Download to Suspicious Path None TTP
Windows Curl Upload to Remote Destination None TTP
Windows DISM Remove Defender None TTP
Windows Defender Exclusion Registry Entry None TTP
Windows Disable Memory Crash Dump None TTP
Windows DisableAntiSpyware Registry None TTP
Windows DiskCryptor Usage None Hunting
Windows Diskshadow Proxy Execution None TTP
Windows DotNet Binary in Non Standard Path None TTP
Windows Event For Service Disabled None Hunting
Windows Event Log Cleared None TTP
Windows Excessive Disabled Services Event None TTP
Windows File Without Extension In Critical Folder None TTP
Windows High File Deletion Frequency None Anomaly
Windows Hunting System Account Targeting Lsass None Hunting
Windows InstallUtil Credential Theft None TTP
Windows InstallUtil Remote Network Connection None TTP
Windows InstallUtil URL in Command Line None TTP
Windows InstallUtil Uninstall Option None TTP
Windows InstallUtil Uninstall Option with Network None TTP
Windows InstallUtil in Non Standard Path None TTP
Windows Java Spawning Shells None TTP
Windows Modify Show Compress Color And Info Tip Registry None TTP
Windows NirSoft AdvancedRun None TTP
Windows NirSoft Utilities None Hunting
Windows Non-System Account Targeting Lsass None TTP
Windows Possible Credential Dumping None TTP
Windows Process With NamedPipe CommandLine None Anomaly
Windows Raccine Scheduled Task Deletion None TTP
Windows Rasautou DLL Execution None TTP
Windows Raw Access To Disk Volume Partition None Anomaly
Windows Raw Access To Master Boot Record Drive None TTP
Windows Remote Assistance Spawning Process None TTP
Windows Schtasks Create Run As System None TTP
Windows Security Account Manager Stopped None TTP
Windows Service Created With Suspicious Service Path None TTP
Windows Service Created Within Public Path None TTP
Windows Service Creation Using Registry Entry None TTP
Windows Service Creation on Remote Endpoint None TTP
Windows Service Initiation on Remote Endpoint None TTP
Windows WMI Process Call Create None Hunting
Windows connhost exe started forcefully None TTP
Windows hosts file modification None TTP
Winhlp32 Spawning a Process None TTP
Winword Spawning Cmd None TTP
Winword Spawning PowerShell None TTP
Winword Spawning Windows Script Host None TTP
Wmic Group Discovery None Hunting
Wmic NonInteractive App Uninstallation None Hunting
Wmiprsve LOLBAS Execution Process Spawn None TTP
Wscript Or Cscript Suspicious Child Process None TTP
Wsmprovhost LOLBAS Execution Process Spawn None TTP
XMRIG Driver Loaded None TTP
XSL Script Execution With WMIC None TTP
aws detect attach to role policy None Hunting
aws detect permanent key creation None Hunting
aws detect role creation None Hunting
aws detect sts assume role abuse None Hunting
aws detect sts get session token abuse None Hunting
gcp detect oauth token abuse None Hunting