| 7zip CommandLine To SMB Share Path |
None |
Hunting |
| AWS Cloud Provisioning From Previously Unseen City |
None |
Anomaly |
| AWS Cloud Provisioning From Previously Unseen Country |
None |
Anomaly |
| AWS Cloud Provisioning From Previously Unseen IP Address |
None |
Anomaly |
| AWS Cloud Provisioning From Previously Unseen Region |
None |
Anomaly |
| AWS Create Policy Version to allow all resources |
None |
TTP |
| AWS CreateAccessKey |
None |
Hunting |
| AWS CreateLoginProfile |
None |
TTP |
| AWS Cross Account Activity From Previously Unseen Account |
None |
Anomaly |
| AWS Detect Users creating keys with encrypt policy without MFA |
None |
TTP |
| AWS Detect Users with KMS keys performing encryption S3 |
None |
Anomaly |
| AWS ECR Container Scanning Findings High |
None |
TTP |
| AWS ECR Container Scanning Findings Low Informational Unknown |
None |
Hunting |
| AWS ECR Container Scanning Findings Medium |
None |
Anomaly |
| AWS ECR Container Upload Outside Business Hours |
None |
Anomaly |
| AWS ECR Container Upload Unknown User |
None |
Anomaly |
| AWS EKS Kubernetes cluster sensitive object access |
None |
Hunting |
| AWS Excessive Security Scanning |
None |
TTP |
| AWS IAM AccessDenied Discovery Events |
None |
Anomaly |
| AWS IAM Assume Role Policy Brute Force |
None |
TTP |
| AWS IAM Delete Policy |
None |
Hunting |
| AWS IAM Failure Group Deletion |
None |
Anomaly |
| AWS IAM Successful Group Deletion |
None |
Hunting |
| AWS Lambda UpdateFunctionCode |
None |
Hunting |
| AWS Network Access Control List Created with All Open Ports |
None |
TTP |
| AWS Network Access Control List Deleted |
None |
Anomaly |
| AWS SAML Access by Provider User and Principal |
None |
Anomaly |
| AWS SAML Update identity provider |
None |
TTP |
| AWS SetDefaultPolicyVersion |
None |
TTP |
| AWS UpdateLoginProfile |
None |
TTP |
| Abnormally High AWS Instances Launched by User |
None |
Anomaly |
| Abnormally High AWS Instances Launched by User - MLTK |
None |
Anomaly |
| Abnormally High AWS Instances Terminated by User |
None |
Anomaly |
| Abnormally High AWS Instances Terminated by User - MLTK |
None |
Anomaly |
| Abnormally High Number Of Cloud Infrastructure API Calls |
None |
Anomaly |
| Abnormally High Number Of Cloud Instances Destroyed |
None |
Anomaly |
| Abnormally High Number Of Cloud Instances Launched |
None |
Anomaly |
| Abnormally High Number Of Cloud Security Group API Calls |
None |
Anomaly |
| Access LSASS Memory for Dump Creation |
None |
TTP |
| Account Discovery With Net App |
None |
TTP |
| Active Setup Registry Autostart |
None |
TTP |
| Add DefaultUser And Password In Registry |
None |
Anomaly |
| Add or Set Windows Defender Exclusion |
None |
TTP |
| AdsiSearcher Account Discovery |
None |
TTP |
| Allow File And Printing Sharing In Firewall |
None |
TTP |
| Allow Inbound Traffic By Firewall Rule Registry |
None |
TTP |
| Allow Inbound Traffic In Firewall Rule |
None |
TTP |
| Allow Network Discovery In Firewall |
None |
TTP |
| Allow Operation with Consent Admin |
None |
TTP |
| Amazon EKS Kubernetes Pod scan detection |
None |
Hunting |
| Amazon EKS Kubernetes cluster scan detection |
None |
Hunting |
| Anomalous usage of 7zip |
None |
Anomaly |
| Any Powershell DownloadFile |
None |
TTP |
| Any Powershell DownloadString |
None |
TTP |
| Attacker Tools On Endpoint |
None |
TTP |
| Attempt To Add Certificate To Untrusted Store |
None |
TTP |
| Attempt To Stop Security Service |
None |
TTP |
| Attempted Credential Dump From Registry via Reg exe |
None |
TTP |
| Auto Admin Logon Registry Entry |
None |
TTP |
| BCDEdit Failure Recovery Modification |
None |
TTP |
| BITS Job Persistence |
None |
TTP |
| BITSAdmin Download File |
None |
TTP |
| Batch File Write to System32 |
None |
TTP |
| Bcdedit Command Back To Normal Mode Boot |
None |
TTP |
| CHCP Command Execution |
None |
TTP |
| CMD Carry Out String Command Parameter |
None |
Hunting |
| CMD Echo Pipe - Escalation |
None |
TTP |
| CMLUA Or CMSTPLUA UAC Bypass |
None |
TTP |
| CSC Net On The Fly Compilation |
None |
Hunting |
| CertUtil Download With URLCache and Split Arguments |
None |
TTP |
| CertUtil Download With VerifyCtl and Split Arguments |
None |
TTP |
| CertUtil With Decode Argument |
None |
TTP |
| Certutil exe certificate extraction |
None |
TTP |
| Change Default File Association |
None |
TTP |
| Change To Safe Mode With Network Config |
None |
TTP |
| Check Elevated CMD using whoami |
None |
TTP |
| Child Processes of Spoolsv exe |
None |
TTP |
| Circle CI Disable Security Job |
None |
Anomaly |
| Circle CI Disable Security Step |
None |
Anomaly |
| Clear Unallocated Sector Using Cipher App |
None |
TTP |
| Clients Connecting to Multiple DNS Servers |
None |
TTP |
| Clop Common Exec Parameter |
None |
TTP |
| Clop Ransomware Known Service Name |
None |
TTP |
| Cloud API Calls From Previously Unseen User Roles |
None |
Anomaly |
| Cloud Compute Instance Created By Previously Unseen User |
None |
Anomaly |
| Cloud Compute Instance Created In Previously Unused Region |
None |
Anomaly |
| Cloud Compute Instance Created With Previously Unseen Image |
None |
Anomaly |
| Cloud Compute Instance Created With Previously Unseen Instance Type |
None |
Anomaly |
| Cloud Instance Modified By Previously Unseen User |
None |
Anomaly |
| Cloud Network Access Control List Deleted |
None |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen City |
None |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen Country |
None |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen IP Address |
None |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen Region |
None |
Anomaly |
| Cmdline Tool Not Executed In CMD Shell |
None |
TTP |
| Cobalt Strike Named Pipes |
None |
TTP |
| Common Ransomware Extensions |
None |
Hunting |
| Common Ransomware Notes |
None |
Hunting |
| Conti Common Exec parameter |
None |
TTP |
| Control Loading from World Writable Directory |
None |
TTP |
| Correlation by Repository and Risk |
None |
Correlation |
| Correlation by User and Risk |
None |
Correlation |
| Create Remote Thread In Shell Application |
None |
TTP |
| Create Remote Thread into LSASS |
None |
TTP |
| Create local admin accounts using net exe |
None |
TTP |
| Create or delete windows shares using net exe |
None |
TTP |
| Creation of Shadow Copy |
None |
TTP |
| Creation of Shadow Copy with wmic and powershell |
None |
TTP |
| Creation of lsass Dump with Taskmgr |
None |
TTP |
| Credential Dumping via Copy Command from Shadow Copy |
None |
TTP |
| Credential Dumping via Symlink to Shadow Copy |
None |
TTP |
| Curl Download and Bash Execution |
None |
TTP |
| DLLHost with no Command Line Arguments with Network |
None |
TTP |
| DNS Exfiltration Using Nslookup App |
None |
TTP |
| DNS Query Length Outliers - MLTK |
None |
Anomaly |
| DNS Query Length With High Standard Deviation |
None |
Anomaly |
| DNS Query Requests Resolved by Unauthorized DNS Servers |
None |
TTP |
| DNS record changed |
None |
TTP |
| DSQuery Domain Discovery |
None |
TTP |
| Delete ShadowCopy With PowerShell |
None |
TTP |
| Deleting Of Net Users |
None |
TTP |
| Deleting Shadow Copies |
None |
TTP |
| Detect API activity from users without MFA |
None |
Hunting |
| Detect ARP Poisoning |
None |
TTP |
| Detect AWS API Activities From Unapproved Accounts |
None |
Hunting |
| Detect AWS Console Login by New User |
None |
Hunting |
| Detect AWS Console Login by User from New City |
None |
Hunting |
| Detect AWS Console Login by User from New Country |
None |
Hunting |
| Detect AWS Console Login by User from New Region |
None |
Hunting |
| Detect Activity Related to Pass the Hash Attacks |
None |
TTP |
| Detect AzureHound Command-Line Arguments |
None |
TTP |
| Detect AzureHound File Modifications |
None |
TTP |
| Detect Baron Samedit CVE-2021-3156 |
None |
TTP |
| Detect Baron Samedit CVE-2021-3156 Segfault |
None |
TTP |
| Detect Baron Samedit CVE-2021-3156 via OSQuery |
None |
TTP |
| Detect Computer Changed with Anonymous Account |
None |
Hunting |
| Detect Copy of ShadowCopy with Script Block Logging |
None |
TTP |
| Detect Credential Dumping through LSASS access |
None |
TTP |
| Detect DNS requests to Phishing Sites leveraging EvilGinx2 |
None |
TTP |
| Detect Empire with PowerShell Script Block Logging |
None |
TTP |
| Detect Excessive Account Lockouts From Endpoint |
None |
Anomaly |
| Detect Excessive User Account Lockouts |
None |
Anomaly |
| Detect Exchange Web Shell |
None |
TTP |
| Detect F5 TMUI RCE CVE-2020-5902 |
None |
TTP |
| Detect GCP Storage access from a new IP |
None |
Anomaly |
| Detect HTML Help Renamed |
None |
Hunting |
| Detect HTML Help Spawn Child Process |
None |
TTP |
| Detect HTML Help URL in Command Line |
None |
TTP |
| Detect HTML Help Using InfoTech Storage Handlers |
None |
TTP |
| Detect IPv6 Network Infrastructure Threats |
None |
TTP |
| Detect Large Outbound ICMP Packets |
None |
TTP |
| Detect Long DNS TXT Record Response |
None |
TTP |
| Detect MSHTA Url in Command Line |
None |
TTP |
| Detect Mimikatz Using Loaded Images |
None |
TTP |
| Detect Mimikatz Via PowerShell And EventCode 4703 |
None |
TTP |
| Detect Mimikatz With PowerShell Script Block Logging |
None |
TTP |
| Detect New Local Admin account |
None |
TTP |
| Detect New Login Attempts to Routers |
None |
TTP |
| Detect New Open GCP Storage Buckets |
None |
TTP |
| Detect New Open S3 Buckets over AWS CLI |
None |
TTP |
| Detect New Open S3 buckets |
None |
TTP |
| Detect Outbound LDAP Traffic |
None |
Hunting |
| Detect Outbound SMB Traffic |
None |
TTP |
| Detect Outlook exe writing a zip file |
None |
TTP |
| Detect Path Interception By Creation Of program exe |
None |
TTP |
| Detect Port Security Violation |
None |
TTP |
| Detect Prohibited Applications Spawning cmd exe |
None |
Hunting |
| Detect PsExec With accepteula Flag |
None |
TTP |
| Detect RClone Command-Line Usage |
None |
TTP |
| Detect Rare Executables |
None |
Anomaly |
| Detect Regasm Spawning a Process |
None |
TTP |
| Detect Regasm with Network Connection |
None |
TTP |
| Detect Regasm with no Command Line Arguments |
None |
TTP |
| Detect Regsvcs Spawning a Process |
None |
TTP |
| Detect Regsvcs with Network Connection |
None |
TTP |
| Detect Regsvcs with No Command Line Arguments |
None |
TTP |
| Detect Regsvr32 Application Control Bypass |
None |
TTP |
| Detect Renamed 7-Zip |
None |
Hunting |
| Detect Renamed PSExec |
None |
Hunting |
| Detect Renamed RClone |
None |
Hunting |
| Detect Renamed WinRAR |
None |
Hunting |
| Detect Rogue DHCP Server |
None |
TTP |
| Detect Rundll32 Application Control Bypass - advpack |
None |
TTP |
| Detect Rundll32 Application Control Bypass - setupapi |
None |
TTP |
| Detect Rundll32 Application Control Bypass - syssetup |
None |
TTP |
| Detect Rundll32 Inline HTA Execution |
None |
TTP |
| Detect S3 access from a new IP |
None |
Anomaly |
| Detect SNICat SNI Exfiltration |
None |
TTP |
| Detect SharpHound Command-Line Arguments |
None |
TTP |
| Detect SharpHound File Modifications |
None |
TTP |
| Detect SharpHound Usage |
None |
TTP |
| Detect Software Download To Network Device |
None |
TTP |
| Detect Spike in AWS API Activity |
None |
Anomaly |
| Detect Spike in AWS Security Hub Alerts for EC2 Instance |
None |
Anomaly |
| Detect Spike in AWS Security Hub Alerts for User |
None |
Anomaly |
| Detect Spike in Network ACL Activity |
None |
Anomaly |
| Detect Spike in S3 Bucket deletion |
None |
Anomaly |
| Detect Spike in Security Group Activity |
None |
Anomaly |
| Detect Spike in blocked Outbound Traffic from your AWS |
None |
Anomaly |
| Detect Traffic Mirroring |
None |
TTP |
| Detect USB device insertion |
None |
TTP |
| Detect Unauthorized Assets by MAC address |
None |
TTP |
| Detect Use of cmd exe to Launch Script Interpreters |
None |
TTP |
| Detect WMI Event Subscription Persistence |
None |
TTP |
| Detect Windows DNS SIGRed via Splunk Stream |
None |
TTP |
| Detect Windows DNS SIGRed via Zeek |
None |
TTP |
| Detect Zerologon via Zeek |
None |
TTP |
| Detect attackers scanning for vulnerable JBoss servers |
None |
TTP |
| Detect hosts connecting to dynamic domain providers |
None |
TTP |
| Detect malicious requests to exploit JBoss servers |
None |
TTP |
| Detect mshta inline hta execution |
None |
TTP |
| Detect mshta renamed |
None |
Hunting |
| Detect new API calls from user roles |
None |
Anomaly |
| Detect new user AWS Console Login |
None |
Hunting |
| Detect processes used for System Network Configuration Discovery |
None |
TTP |
| Detect shared ec2 snapshot |
None |
TTP |
| Detect web traffic to dynamic domain providers |
None |
TTP |
| Detection of DNS Tunnels |
None |
TTP |
| Detection of tools built by NirSoft |
None |
TTP |
| Disable AMSI Through Registry |
None |
TTP |
| Disable Defender AntiVirus Registry |
None |
TTP |
| Disable Defender BlockAtFirstSeen Feature |
None |
TTP |
| Disable Defender Enhanced Notification |
None |
TTP |
| Disable Defender MpEngine Registry |
None |
TTP |
| Disable Defender Spynet Reporting |
None |
TTP |
| Disable Defender Submit Samples Consent Feature |
None |
TTP |
| Disable ETW Through Registry |
None |
TTP |
| Disable Logs Using WevtUtil |
None |
TTP |
| Disable Registry Tool |
None |
TTP |
| Disable Schedule Task |
None |
TTP |
| Disable Security Logs Using MiniNt Registry |
None |
TTP |
| Disable Show Hidden Files |
None |
TTP |
| Disable UAC Remote Restriction |
None |
TTP |
| Disable Windows App Hotkeys |
None |
TTP |
| Disable Windows Behavior Monitoring |
None |
TTP |
| Disable Windows SmartScreen Protection |
None |
TTP |
| Disabled Kerberos Pre-Authentication Discovery With Get-ADUser |
None |
TTP |
| Disabled Kerberos Pre-Authentication Discovery With PowerView |
None |
TTP |
| Disabling CMD Application |
None |
TTP |
| Disabling ControlPanel |
None |
TTP |
| Disabling Defender Services |
None |
TTP |
| Disabling Firewall with Netsh |
None |
TTP |
| Disabling FolderOptions Windows Feature |
None |
TTP |
| Disabling Net User Account |
None |
TTP |
| Disabling NoRun Windows App |
None |
TTP |
| Disabling Remote User Account Control |
None |
TTP |
| Disabling SystemRestore In Registry |
None |
TTP |
| Disabling Task Manager |
None |
TTP |
| Domain Account Discovery With Net App |
None |
TTP |
| Domain Account Discovery with Dsquery |
None |
Hunting |
| Domain Account Discovery with Wmic |
None |
TTP |
| Domain Controller Discovery with Nltest |
None |
TTP |
| Domain Controller Discovery with Wmic |
None |
Hunting |
| Domain Group Discovery With Dsquery |
None |
Hunting |
| Domain Group Discovery With Net |
None |
Hunting |
| Domain Group Discovery With Wmic |
None |
Hunting |
| Domain Group Discovery with Adsisearcher |
None |
TTP |
| Download Files Using Telegram |
None |
TTP |
| Drop IcedID License dat |
None |
Hunting |
| Dump LSASS via comsvcs DLL |
None |
TTP |
| Dump LSASS via procdump |
None |
TTP |
| Dump LSASS via procdump Rename |
None |
Hunting |
| EC2 Instance Modified With Previously Unseen User |
None |
Anomaly |
| EC2 Instance Started In Previously Unseen Region |
None |
Anomaly |
| EC2 Instance Started With Previously Unseen AMI |
None |
Anomaly |
| EC2 Instance Started With Previously Unseen Instance Type |
None |
Anomaly |
| EC2 Instance Started With Previously Unseen User |
None |
Anomaly |
| ETW Registry Disabled |
None |
TTP |
| Elevated Group Discovery With Net |
None |
TTP |
| Elevated Group Discovery With Wmic |
None |
TTP |
| Elevated Group Discovery with PowerView |
None |
Hunting |
| Email Attachments With Lots Of Spaces |
None |
Anomaly |
| Email files written outside of the Outlook directory |
None |
TTP |
| Email servers sending high volume traffic to hosts |
None |
Anomaly |
| Enable RDP In Other Port Number |
None |
TTP |
| Enable WDigest UseLogonCredential Registry |
None |
TTP |
| Enumerate Users Local Group Using Telegram |
None |
TTP |
| Esentutl SAM Copy |
None |
Hunting |
| Eventvwr UAC Bypass |
None |
TTP |
| Excel Spawning PowerShell |
None |
TTP |
| Excel Spawning Windows Script Host |
None |
TTP |
| Excessive Attempt To Disable Services |
None |
Anomaly |
| Excessive DNS Failures |
None |
Anomaly |
| Excessive File Deletion In WinDefender Folder |
None |
TTP |
| Excessive Service Stop Attempt |
None |
Anomaly |
| Excessive Usage Of Cacls App |
None |
Anomaly |
| Excessive Usage Of Net App |
None |
Anomaly |
| Excessive Usage Of SC Service Utility |
None |
Anomaly |
| Excessive Usage Of Taskkill |
None |
Anomaly |
| Excessive Usage of NSLOOKUP App |
None |
Anomaly |
| Excessive number of distinct processes created in Windows Temp folder |
None |
Anomaly |
| Excessive number of service control start as disabled |
None |
Anomaly |
| Excessive number of taskhost processes |
None |
Anomaly |
| Exchange PowerShell Abuse via SSRF |
None |
TTP |
| Exchange PowerShell Module Usage |
None |
TTP |
| Executable File Written in Administrative SMB Share |
None |
TTP |
| Executables Or Script Creation In Suspicious Path |
None |
TTP |
| Execute Javascript With Jscript COM CLSID |
None |
TTP |
| Execution of File With Spaces Before Extension |
None |
TTP |
| Execution of File with Multiple Extensions |
None |
TTP |
| Extended Period Without Successful Netbackup Backups |
None |
Hunting |
| Extraction of Registry Hives |
None |
TTP |
| File with Samsam Extension |
None |
TTP |
| Firewall Allowed Program Enable |
None |
Anomaly |
| First Time Seen Child Process of Zoom |
None |
Anomaly |
| First Time Seen Running Windows Service |
None |
Anomaly |
| First time seen command line argument |
None |
Hunting |
| FodHelper UAC Bypass |
None |
TTP |
| Fsutil Zeroing File |
None |
TTP |
| GCP Detect accounts with high risk roles by project |
None |
Hunting |
| GCP Detect gcploit framework |
None |
TTP |
| GCP Detect high risk permissions by resource and account |
None |
Hunting |
| GCP GCR container uploaded |
None |
Hunting |
| GCP Kubernetes cluster pod scan detection |
None |
Hunting |
| GCP Kubernetes cluster scan detection |
None |
TTP |
| GPUpdate with no Command Line Arguments with Network |
None |
TTP |
| GSuite Email Suspicious Attachment |
None |
Anomaly |
| Gdrive suspicious file sharing |
None |
Hunting |
| Get ADDefaultDomainPasswordPolicy with Powershell |
None |
Hunting |
| Get ADDefaultDomainPasswordPolicy with Powershell Script Block |
None |
Hunting |
| Get ADUser with PowerShell |
None |
Hunting |
| Get ADUser with PowerShell Script Block |
None |
Hunting |
| Get ADUserResultantPasswordPolicy with Powershell |
None |
TTP |
| Get ADUserResultantPasswordPolicy with Powershell Script Block |
None |
TTP |
| Get DomainPolicy with Powershell |
None |
TTP |
| Get DomainPolicy with Powershell Script Block |
None |
TTP |
| Get DomainUser with PowerShell |
None |
TTP |
| Get DomainUser with PowerShell Script Block |
None |
TTP |
| Get WMIObject Group Discovery |
None |
Hunting |
| Get WMIObject Group Discovery with Script Block Logging |
None |
Hunting |
| Get-DomainTrust with PowerShell |
None |
TTP |
| Get-DomainTrust with PowerShell Script Block |
None |
TTP |
| Get-ForestTrust with PowerShell |
None |
TTP |
| Get-ForestTrust with PowerShell Script Block |
None |
TTP |
| GetAdComputer with PowerShell |
None |
Hunting |
| GetAdComputer with PowerShell Script Block |
None |
Hunting |
| GetAdGroup with PowerShell |
None |
Hunting |
| GetAdGroup with PowerShell Script Block |
None |
Hunting |
| GetCurrent User with PowerShell |
None |
Hunting |
| GetCurrent User with PowerShell Script Block |
None |
Hunting |
| GetDomainComputer with PowerShell |
None |
TTP |
| GetDomainComputer with PowerShell Script Block |
None |
TTP |
| GetDomainController with PowerShell |
None |
Hunting |
| GetDomainController with PowerShell Script Block |
None |
TTP |
| GetDomainGroup with PowerShell |
None |
TTP |
| GetDomainGroup with PowerShell Script Block |
None |
TTP |
| GetLocalUser with PowerShell |
None |
Hunting |
| GetLocalUser with PowerShell Script Block |
None |
Hunting |
| GetNetTcpconnection with PowerShell |
None |
Hunting |
| GetNetTcpconnection with PowerShell Script Block |
None |
Hunting |
| GetWmiObject DS User with PowerShell |
None |
TTP |
| GetWmiObject DS User with PowerShell Script Block |
None |
TTP |
| GetWmiObject Ds Computer with PowerShell |
None |
TTP |
| GetWmiObject Ds Computer with PowerShell Script Block |
None |
TTP |
| GetWmiObject Ds Group with PowerShell |
None |
TTP |
| GetWmiObject Ds Group with PowerShell Script Block |
None |
TTP |
| GetWmiObject User Account with PowerShell |
None |
Hunting |
| GetWmiObject User Account with PowerShell Script Block |
None |
Hunting |
| GitHub Dependabot Alert |
None |
Anomaly |
| GitHub Pull Request from Unknown User |
None |
Anomaly |
| Github Commit Changes In Master |
None |
Anomaly |
| Github Commit In Develop |
None |
Anomaly |
| Gsuite Drive Share In External Email |
None |
Anomaly |
| Gsuite Email Suspicious Subject With Attachment |
None |
Anomaly |
| Gsuite Email With Known Abuse Web Service Link |
None |
Anomaly |
| Gsuite Outbound Email With Attachment To External Domain |
None |
Anomaly |
| Gsuite Suspicious Shared File Name |
None |
Anomaly |
| Gsuite suspicious calendar invite |
None |
Hunting |
| Hide User Account From Sign-In Screen |
None |
TTP |
| Hiding Files And Directories With Attrib exe |
None |
TTP |
| High Frequency Copy Of Files In Network Share |
None |
Anomaly |
| High Number of Login Failures from a single source |
None |
Anomaly |
| High Process Termination Frequency |
None |
Anomaly |
| Hosts receiving high volume of network traffic from email server |
None |
Anomaly |
| Hunting for Log4Shell |
None |
Hunting |
| ICACLS Grant Command |
None |
TTP |
| Icacls Deny Command |
None |
TTP |
| IcedID Exfiltrated Archived File Creation |
None |
Hunting |
| Identify New User Accounts |
None |
Hunting |
| Impacket Lateral Movement Commandline Parameters |
None |
TTP |
| Interactive Session on Remote Endpoint with PowerShell |
None |
TTP |
| Java Class File download by Java User Agent |
None |
TTP |
| Jscript Execution Using Cscript App |
None |
TTP |
| Kerberoasting spn request with RC4 encryption |
None |
TTP |
| Kerberos Pre-Authentication Flag Disabled in UserAccountControl |
None |
TTP |
| Kerberos Pre-Authentication Flag Disabled with PowerShell |
None |
TTP |
| Known Services Killed by Ransomware |
None |
TTP |
| Kubernetes AWS detect RBAC authorization by account |
None |
Hunting |
| Kubernetes AWS detect most active service accounts by pod |
None |
Hunting |
| Kubernetes AWS detect sensitive role access |
None |
Hunting |
| Kubernetes AWS detect service accounts forbidden failure access |
None |
Hunting |
| Kubernetes AWS detect suspicious kubectl calls |
None |
Hunting |
| Kubernetes Azure detect RBAC authorization by account |
None |
Hunting |
| Kubernetes Azure detect most active service accounts by pod namespace |
None |
Hunting |
| Kubernetes Azure detect sensitive object access |
None |
Hunting |
| Kubernetes Azure detect sensitive role access |
None |
Hunting |
| Kubernetes Azure detect service accounts forbidden failure access |
None |
Hunting |
| Kubernetes Azure detect suspicious kubectl calls |
None |
Hunting |
| Kubernetes Azure pod scan fingerprint |
None |
Hunting |
| Kubernetes Azure scan fingerprint |
None |
Hunting |
| Kubernetes GCP detect RBAC authorizations by account |
None |
Hunting |
| Kubernetes GCP detect most active service accounts by pod |
None |
Hunting |
| Kubernetes GCP detect sensitive object access |
None |
Hunting |
| Kubernetes GCP detect sensitive role access |
None |
Hunting |
| Kubernetes GCP detect service accounts forbidden failure access |
None |
Hunting |
| Kubernetes GCP detect suspicious kubectl calls |
None |
Hunting |
| Kubernetes Nginx Ingress LFI |
None |
TTP |
| Kubernetes Nginx Ingress RFI |
None |
TTP |
| Kubernetes Scanner Image Pulling |
None |
TTP |
| Large Volume of DNS ANY Queries |
None |
Anomaly |
| Linux Add Files In Known Crontab Directories |
None |
Anomaly |
| Linux Add User Account |
None |
Hunting |
| Linux At Allow Config File Creation |
None |
Anomaly |
| Linux At Application Execution |
None |
Anomaly |
| Linux Change File Owner To Root |
None |
Anomaly |
| Linux Common Process For Elevation Control |
None |
Hunting |
| Linux DD File Overwrite |
None |
TTP |
| Linux Doas Conf File Creation |
None |
Anomaly |
| Linux Doas Tool Execution |
None |
Anomaly |
| Linux Edit Cron Table Parameter |
None |
Hunting |
| Linux File Created In Kernel Driver Directory |
None |
Anomaly |
| Linux File Creation In Init Boot Directory |
None |
Anomaly |
| Linux File Creation In Profile Directory |
None |
Anomaly |
| Linux Insert Kernel Module Using Insmod Utility |
None |
Anomaly |
| Linux Install Kernel Module Using Modprobe Utility |
None |
Anomaly |
| Linux Java Spawning Shell |
None |
TTP |
| Linux NOPASSWD Entry In Sudoers File |
None |
Anomaly |
| Linux Possible Access Or Modification Of sshd Config File |
None |
Anomaly |
| Linux Possible Access To Credential Files |
None |
Anomaly |
| Linux Possible Access To Sudoers File |
None |
Anomaly |
| Linux Possible Append Command To At Allow Config File |
None |
Anomaly |
| Linux Possible Append Command To Profile Config File |
None |
Anomaly |
| Linux Possible Append Cronjob Entry on Existing Cronjob File |
None |
Hunting |
| Linux Possible Cronjob Modification With Editor |
None |
Hunting |
| Linux Possible Ssh Key File Creation |
None |
Anomaly |
| Linux Preload Hijack Library Calls |
None |
TTP |
| Linux Service File Created In Systemd Directory |
None |
Anomaly |
| Linux Service Restarted |
None |
Anomaly |
| Linux Service Started Or Enabled |
None |
Anomaly |
| Linux Setuid Using Chmod Utility |
None |
Anomaly |
| Linux Setuid Using Setcap Utility |
None |
Anomaly |
| Linux Sudo OR Su Execution |
None |
Hunting |
| Linux Sudoers Tmp File Creation |
None |
Anomaly |
| Linux System Network Discovery |
None |
Anomaly |
| Linux Visudo Utility Execution |
None |
Anomaly |
| Linux pkexec Privilege Escalation |
None |
TTP |
| Loading Of Dynwrapx Module |
None |
TTP |
| Local Account Discovery With Wmic |
None |
Hunting |
| Local Account Discovery with Net |
None |
Hunting |
| Log4Shell CVE-2021-44228 Exploitation |
None |
Correlation |
| Log4Shell JNDI Payload Injection Attempt |
None |
Anomaly |
| Log4Shell JNDI Payload Injection with Outbound Connection |
None |
Anomaly |
| Logon Script Event Trigger Execution |
None |
TTP |
| MS Scripting Process Loading Ldap Module |
None |
Anomaly |
| MS Scripting Process Loading WMI Module |
None |
Anomaly |
| MSBuild Suspicious Spawned By Script Process |
None |
TTP |
| MSHTML Module Load in Office Product |
None |
TTP |
| MSI Module Loaded by Non-System Binary |
None |
Hunting |
| MacOS - Re-opened Applications |
None |
TTP |
| Mailsniper Invoke functions |
None |
TTP |
| Malicious InProcServer32 Modification |
None |
TTP |
| Malicious PowerShell Process - Encoded Command |
None |
Hunting |
| Malicious PowerShell Process - Execution Policy Bypass |
None |
TTP |
| Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments |
None |
TTP |
| Malicious PowerShell Process With Obfuscation Techniques |
None |
TTP |
| Malicious Powershell Executed As A Service |
None |
TTP |
| Microsoft Exchange Mailbox Replication service writing Active Server Pages |
None |
TTP |
| Mimikatz PassTheTicket CommandLine Parameters |
None |
TTP |
| Mmc LOLBAS Execution Process Spawn |
None |
TTP |
| Modification Of Wallpaper |
None |
TTP |
| Modify ACL permission To Files Or Folder |
None |
TTP |
| Monitor DNS For Brand Abuse |
None |
TTP |
| Monitor Email For Brand Abuse |
None |
TTP |
| Monitor Registry Keys for Print Monitors |
None |
TTP |
| Monitor Web Traffic For Brand Abuse |
None |
TTP |
| Mshta spawning Rundll32 OR Regsvr32 Process |
None |
TTP |
| Msmpeng Application DLL Side Loading |
None |
TTP |
| Multiple Archive Files Http Post Traffic |
None |
TTP |
| Multiple Disabled Users Failing To Authenticate From Host Using Kerberos |
None |
Anomaly |
| Multiple Invalid Users Failing To Authenticate From Host Using Kerberos |
None |
Anomaly |
| Multiple Invalid Users Failing To Authenticate From Host Using NTLM |
None |
Anomaly |
| Multiple Okta Users With Invalid Credentials From The Same IP |
None |
TTP |
| Multiple Users Attempting To Authenticate Using Explicit Credentials |
None |
Anomaly |
| Multiple Users Failing To Authenticate From Host Using Kerberos |
None |
Anomaly |
| Multiple Users Failing To Authenticate From Host Using NTLM |
None |
Anomaly |
| Multiple Users Failing To Authenticate From Process |
None |
Anomaly |
| Multiple Users Remotely Failing To Authenticate From Host |
None |
Anomaly |
| NET Profiler UAC bypass |
None |
TTP |
| NLTest Domain Trust Discovery |
None |
TTP |
| Net Localgroup Discovery |
None |
Hunting |
| Network Connection Discovery With Arp |
None |
Hunting |
| Network Connection Discovery With Net |
None |
Hunting |
| Network Connection Discovery With Netstat |
None |
Hunting |
| Network Discovery Using Route Windows App |
None |
Hunting |
| New container uploaded to AWS ECR |
None |
Hunting |
| Nishang PowershellTCPOneLine |
None |
TTP |
| No Windows Updates in a time frame |
None |
Hunting |
| Non Chrome Process Accessing Chrome Default Dir |
None |
Anomaly |
| Non Firefox Process Access Firefox Profile Dir |
None |
Anomaly |
| Ntdsutil Export NTDS |
None |
TTP |
| O365 Add App Role Assignment Grant User |
None |
TTP |
| O365 Added Service Principal |
None |
TTP |
| O365 Bypass MFA via Trusted IP |
None |
TTP |
| O365 Disable MFA |
None |
TTP |
| O365 Excessive Authentication Failures Alert |
None |
Anomaly |
| O365 Excessive SSO logon errors |
None |
Anomaly |
| O365 New Federated Domain Added |
None |
TTP |
| O365 PST export alert |
None |
TTP |
| O365 Suspicious Admin Email Forwarding |
None |
Anomaly |
| O365 Suspicious Rights Delegation |
None |
TTP |
| O365 Suspicious User Email Forwarding |
None |
Anomaly |
| Office Application Drop Executable |
None |
TTP |
| Office Application Spawn Regsvr32 process |
None |
TTP |
| Office Application Spawn rundll32 process |
None |
TTP |
| Office Document Creating Schedule Task |
None |
TTP |
| Office Document Executing Macro Code |
None |
TTP |
| Office Document Spawned Child Process To Download |
None |
TTP |
| Office Product Spawn CMD Process |
None |
TTP |
| Office Product Spawning BITSAdmin |
None |
TTP |
| Office Product Spawning CertUtil |
None |
TTP |
| Office Product Spawning MSHTA |
None |
TTP |
| Office Product Spawning Rundll32 with no DLL |
None |
TTP |
| Office Product Spawning Wmic |
None |
TTP |
| Office Product Writing cab or inf |
None |
TTP |
| Office Spawning Control |
None |
TTP |
| Okta Account Lockout Events |
None |
Anomaly |
| Okta Failed SSO Attempts |
None |
Anomaly |
| Okta User Logins From Multiple Cities |
None |
Anomaly |
| Open Redirect in Splunk Web |
None |
TTP |
| Osquery pack - ColdRoot detection |
None |
TTP |
| Outbound Network Connection from Java Using Default Ports |
None |
TTP |
| Overwriting Accessibility Binaries |
None |
TTP |
| Password Policy Discovery with Net |
None |
Hunting |
| Permission Modification using Takeown App |
None |
TTP |
| PetitPotam Network Share Access Request |
None |
TTP |
| PetitPotam Suspicious Kerberos TGT Request |
None |
TTP |
| Ping Sleep Batch Command |
None |
Anomaly |
| Plain HTTP POST Exfiltrated Data |
None |
TTP |
| Possible Browser Pass View Parameter |
None |
Hunting |
| Possible Lateral Movement PowerShell Spawn |
None |
TTP |
| Potentially malicious code on commandline |
None |
Anomaly |
| PowerShell - Connect To Internet With Hidden Window |
None |
Hunting |
| PowerShell 4104 Hunting |
None |
Hunting |
| PowerShell Domain Enumeration |
None |
TTP |
| PowerShell Get LocalGroup Discovery |
None |
Hunting |
| PowerShell Loading DotNET into Memory via System Reflection Assembly |
None |
TTP |
| PowerShell Start-BitsTransfer |
None |
TTP |
| Powershell Creating Thread Mutex |
None |
TTP |
| Powershell Disable Security Monitoring |
None |
TTP |
| Powershell Enable SMB1Protocol Feature |
None |
TTP |
| Powershell Execute COM Object |
None |
TTP |
| Powershell Fileless Process Injection via GetProcAddress |
None |
TTP |
| Powershell Fileless Script Contains Base64 Encoded Content |
None |
TTP |
| Powershell Get LocalGroup Discovery with Script Block Logging |
None |
Hunting |
| Powershell Processing Stream Of Data |
None |
TTP |
| Powershell Remote Thread To Known Windows Process |
None |
TTP |
| Powershell Remove Windows Defender Directory |
None |
TTP |
| Powershell Using memory As Backing Store |
None |
TTP |
| Powershell Windows Defender Exclusion Commands |
None |
TTP |
| Prevent Automatic Repair Mode using Bcdedit |
None |
TTP |
| Print Processor Registry Autostart |
None |
TTP |
| Print Spooler Adding A Printer Driver |
None |
TTP |
| Print Spooler Failed to Load a Plug-in |
None |
TTP |
| Process Creating LNK file in Suspicious Location |
None |
TTP |
| Process Deleting Its Process File Path |
None |
TTP |
| Process Execution via WMI |
None |
TTP |
| Process Kill Base On File Path |
None |
TTP |
| Process Writing DynamicWrapperX |
None |
Hunting |
| Processes Tapping Keyboard Events |
None |
TTP |
| Processes created by netsh |
None |
TTP |
| Processes launching netsh |
None |
TTP |
| Prohibited Network Traffic Allowed |
None |
TTP |
| Prohibited Software On Endpoint |
None |
Hunting |
| Protocol or Port Mismatch |
None |
Anomaly |
| Protocols passing authentication in cleartext |
None |
TTP |
| Randomly Generated Scheduled Task Name |
None |
Hunting |
| Randomly Generated Windows Service Name |
None |
Hunting |
| Ransomware Notes bulk creation |
None |
Anomaly |
| Recon AVProduct Through Pwh or WMI |
None |
TTP |
| Recon Using WMI Class |
None |
TTP |
| Recursive Delete of Directory In Batch CMD |
None |
TTP |
| Reg exe Manipulating Windows Services Registry Keys |
None |
TTP |
| Reg exe used to hide files directories via registry keys |
None |
TTP |
| Registry Keys Used For Persistence |
None |
TTP |
| Registry Keys Used For Privilege Escalation |
None |
TTP |
| Registry Keys for Creating SHIM Databases |
None |
TTP |
| Regsvr32 Silent and Install Param Dll Loading |
None |
Anomaly |
| Regsvr32 with Known Silent Switch Cmdline |
None |
Anomaly |
| Remcos RAT File Creation in Remcos Folder |
None |
TTP |
| Remcos client registry install entry |
None |
TTP |
| Remote Desktop Network Bruteforce |
None |
TTP |
| Remote Desktop Network Traffic |
None |
Anomaly |
| Remote Desktop Process Running On System |
None |
Hunting |
| Remote Process Instantiation via DCOM and PowerShell |
None |
TTP |
| Remote Process Instantiation via DCOM and PowerShell Script Block |
None |
TTP |
| Remote Process Instantiation via WMI |
None |
TTP |
| Remote Process Instantiation via WMI and PowerShell |
None |
TTP |
| Remote Process Instantiation via WMI and PowerShell Script Block |
None |
TTP |
| Remote Process Instantiation via WinRM and PowerShell |
None |
TTP |
| Remote Process Instantiation via WinRM and PowerShell Script Block |
None |
TTP |
| Remote Process Instantiation via WinRM and Winrs |
None |
TTP |
| Remote Registry Key modifications |
None |
TTP |
| Remote System Discovery with Adsisearcher |
None |
TTP |
| Remote System Discovery with Dsquery |
None |
Hunting |
| Remote System Discovery with Net |
None |
Hunting |
| Remote System Discovery with Wmic |
None |
TTP |
| Remote WMI Command Attempt |
None |
TTP |
| Resize ShadowStorage volume |
None |
TTP |
| Revil Common Exec Parameter |
None |
TTP |
| Revil Registry Entry |
None |
TTP |
| Rubeus Command Line Parameters |
None |
TTP |
| Rubeus Kerberos Ticket Exports Through Winlogon Access |
None |
TTP |
| RunDLL Loading DLL By Ordinal |
None |
TTP |
| Runas Execution in CommandLine |
None |
Hunting |
| Rundll32 Control RunDLL Hunt |
None |
Hunting |
| Rundll32 Control RunDLL World Writable Directory |
None |
TTP |
| Rundll32 Create Remote Thread To A Process |
None |
TTP |
| Rundll32 CreateRemoteThread In Browser |
None |
TTP |
| Rundll32 DNSQuery |
None |
TTP |
| Rundll32 Process Creating Exe Dll Files |
None |
TTP |
| Rundll32 Shimcache Flush |
None |
TTP |
| Rundll32 with no Command Line Arguments with Network |
None |
TTP |
| Ryuk Test Files Detected |
None |
TTP |
| Ryuk Wake on LAN Command |
None |
TTP |
| SAM Database File Access Attempt |
None |
Hunting |
| SLUI RunAs Elevated |
None |
TTP |
| SLUI Spawning a Process |
None |
TTP |
| SMB Traffic Spike |
None |
Anomaly |
| SMB Traffic Spike - MLTK |
None |
Anomaly |
| SQL Injection with Long URLs |
None |
TTP |
| Samsam Test File Write |
None |
TTP |
| Sc exe Manipulating Windows Services |
None |
TTP |
| SchCache Change By App Connect And Create ADSI Object |
None |
Anomaly |
| Schedule Task with HTTP Command Arguments |
None |
TTP |
| Schedule Task with Rundll32 Command Trigger |
None |
TTP |
| Scheduled Task Creation on Remote Endpoint using At |
None |
TTP |
| Scheduled Task Deleted Or Created via CMD |
None |
TTP |
| Scheduled Task Initiation on Remote Endpoint |
None |
TTP |
| Scheduled tasks used in BadRabbit ransomware |
None |
TTP |
| Schtasks Run Task On Demand |
None |
TTP |
| Schtasks scheduling job on remote system |
None |
TTP |
| Schtasks used for forcing a reboot |
None |
TTP |
| Screensaver Event Trigger Execution |
None |
TTP |
| Script Execution via WMI |
None |
TTP |
| Sdclt UAC Bypass |
None |
TTP |
| Sdelete Application Execution |
None |
TTP |
| SearchProtocolHost with no Command Line with Network |
None |
TTP |
| SecretDumps Offline NTDS Dumping Tool |
None |
TTP |
| ServicePrincipalNames Discovery with PowerShell |
None |
TTP |
| ServicePrincipalNames Discovery with SetSPN |
None |
TTP |
| Services Escalate Exe |
None |
TTP |
| Services LOLBAS Execution Process Spawn |
None |
TTP |
| Set Default PowerShell Execution Policy To Unrestricted or Bypass |
None |
TTP |
| Shim Database File Creation |
None |
TTP |
| Shim Database Installation With Suspicious Parameters |
None |
TTP |
| Short Lived Scheduled Task |
None |
TTP |
| Short Lived Windows Accounts |
None |
TTP |
| SilentCleanup UAC Bypass |
None |
TTP |
| Single Letter Process On Endpoint |
None |
TTP |
| Spectre and Meltdown Vulnerable Systems |
None |
TTP |
| Spike in File Writes |
None |
Anomaly |
| Splunk Enterprise Information Disclosure |
None |
TTP |
| Spoolsv Spawning Rundll32 |
None |
TTP |
| Spoolsv Suspicious Loaded Modules |
None |
TTP |
| Spoolsv Suspicious Process Access |
None |
TTP |
| Spoolsv Writing a DLL |
None |
TTP |
| Spoolsv Writing a DLL - Sysmon |
None |
TTP |
| Sqlite Module In Temp Folder |
None |
TTP |
| Start Up During Safe Mode Boot |
None |
TTP |
| Sunburst Correlation DLL and Network Event |
None |
TTP |
| Supernova Webshell |
None |
TTP |
| Suspicious Changes to File Associations |
None |
TTP |
| Suspicious Computer Account Name Change |
None |
TTP |
| Suspicious Copy on System32 |
None |
TTP |
| Suspicious Curl Network Connection |
None |
TTP |
| Suspicious DLLHost no Command Line Arguments |
None |
TTP |
| Suspicious Driver Loaded Path |
None |
TTP |
| Suspicious Email - UBA Anomaly |
None |
Anomaly |
| Suspicious Email Attachment Extensions |
None |
Anomaly |
| Suspicious Event Log Service Behavior |
None |
TTP |
| Suspicious File Write |
None |
Hunting |
| Suspicious GPUpdate no Command Line Arguments |
None |
TTP |
| Suspicious IcedID Rundll32 Cmdline |
None |
TTP |
| Suspicious Image Creation In Appdata Folder |
None |
TTP |
| Suspicious Java Classes |
None |
Anomaly |
| Suspicious Kerberos Service Ticket Request |
None |
TTP |
| Suspicious Linux Discovery Commands |
None |
TTP |
| Suspicious MSBuild Rename |
None |
TTP |
| Suspicious MSBuild Spawn |
None |
TTP |
| Suspicious PlistBuddy Usage |
None |
TTP |
| Suspicious PlistBuddy Usage via OSquery |
None |
TTP |
| Suspicious Process DNS Query Known Abuse Web Services |
None |
TTP |
| Suspicious Process File Path |
None |
TTP |
| Suspicious Process With Discord DNS Query |
None |
Anomaly |
| Suspicious Reg exe Process |
None |
TTP |
| Suspicious Regsvr32 Register Suspicious Path |
None |
TTP |
| Suspicious Rundll32 PluginInit |
None |
TTP |
| Suspicious Rundll32 Rename |
None |
Hunting |
| Suspicious Rundll32 StartW |
None |
TTP |
| Suspicious Rundll32 dllregisterserver |
None |
TTP |
| Suspicious Rundll32 no Command Line Arguments |
None |
TTP |
| Suspicious SQLite3 LSQuarantine Behavior |
None |
TTP |
| Suspicious Scheduled Task from Public Directory |
None |
Anomaly |
| Suspicious SearchProtocolHost no Command Line Arguments |
None |
TTP |
| Suspicious Ticket Granting Ticket Request |
None |
Hunting |
| Suspicious WAV file in Appdata Folder |
None |
TTP |
| Suspicious microsoft workflow compiler rename |
None |
Hunting |
| Suspicious microsoft workflow compiler usage |
None |
TTP |
| Suspicious msbuild path |
None |
TTP |
| Suspicious mshta child process |
None |
TTP |
| Suspicious mshta spawn |
None |
TTP |
| Suspicious wevtutil Usage |
None |
TTP |
| Suspicious writes to System Volume Information |
None |
Hunting |
| Suspicious writes to windows Recycle Bin |
None |
TTP |
| Svchost LOLBAS Execution Process Spawn |
None |
TTP |
| System Info Gathering Using Dxdiag Application |
None |
Hunting |
| System Information Discovery Detection |
None |
TTP |
| System Processes Run From Unexpected Locations |
None |
TTP |
| System User Discovery With Query |
None |
Hunting |
| System User Discovery With Whoami |
None |
Hunting |
| TOR Traffic |
None |
TTP |
| Time Provider Persistence Registry |
None |
TTP |
| Trickbot Named Pipe |
None |
TTP |
| UAC Bypass MMC Load Unsigned Dll |
None |
TTP |
| UAC Bypass With Colorui COM Object |
None |
TTP |
| USN Journal Deletion |
None |
TTP |
| Uncommon Processes On Endpoint |
None |
Hunting |
| Unified Messaging Service Spawning a Process |
None |
TTP |
| Uninstall App Using MsiExec |
None |
TTP |
| Unload Sysmon Filter Driver |
None |
TTP |
| Unloading AMSI via Reflection |
None |
TTP |
| Unsigned Image Loaded by LSASS |
None |
TTP |
| Unsuccessful Netbackup backups |
None |
Hunting |
| Unusual Number of Computer Service Tickets Requested |
None |
Hunting |
| Unusual Number of Kerberos Service Tickets Requested |
None |
Anomaly |
| Unusual Number of Remote Endpoint Authentication Events |
None |
Hunting |
| Unusually Long Command Line |
None |
Anomaly |
| Unusually Long Command Line - MLTK |
None |
Anomaly |
| Unusually Long Content-Type Length |
None |
Anomaly |
| User Discovery With Env Vars PowerShell |
None |
Hunting |
| User Discovery With Env Vars PowerShell Script Block |
None |
Hunting |
| Vbscript Execution Using Wscript App |
None |
TTP |
| Verclsid CLSID Execution |
None |
Hunting |
| W3WP Spawning Shell |
None |
TTP |
| WBAdmin Delete System Backups |
None |
TTP |
| WMI Permanent Event Subscription |
None |
TTP |
| WMI Permanent Event Subscription - Sysmon |
None |
TTP |
| WMI Recon Running Process Or Services |
None |
TTP |
| WMI Temporary Event Subscription |
None |
TTP |
| WMIC XSL Execution via URL |
None |
TTP |
| WSReset UAC Bypass |
None |
TTP |
| Wbemprox COM Object Execution |
None |
TTP |
| Web Fraud - Account Harvesting |
None |
TTP |
| Web Fraud - Anomalous User Clickspeed |
None |
Anomaly |
| Web Fraud - Password Sharing Across Accounts |
None |
Anomaly |
| Web Servers Executing Suspicious Processes |
None |
TTP |
| Wermgr Process Connecting To IP Check Web Services |
None |
TTP |
| Wermgr Process Create Executable File |
None |
TTP |
| Wermgr Process Spawned CMD Or Powershell Process |
None |
TTP |
| Wget Download and Bash Execution |
None |
TTP |
| WinEvent Scheduled Task Created Within Public Path |
None |
TTP |
| WinEvent Scheduled Task Created to Spawn Shell |
None |
TTP |
| WinEvent Windows Task Scheduler Event Action Started |
None |
Hunting |
| WinRM Spawning a Process |
None |
TTP |
| Windows AdFind Exe |
None |
TTP |
| Windows Curl Download to Suspicious Path |
None |
TTP |
| Windows Curl Upload to Remote Destination |
None |
TTP |
| Windows DISM Remove Defender |
None |
TTP |
| Windows Defender Exclusion Registry Entry |
None |
TTP |
| Windows Disable Memory Crash Dump |
None |
TTP |
| Windows DisableAntiSpyware Registry |
None |
TTP |
| Windows DiskCryptor Usage |
None |
Hunting |
| Windows Diskshadow Proxy Execution |
None |
TTP |
| Windows DotNet Binary in Non Standard Path |
None |
TTP |
| Windows Event For Service Disabled |
None |
Hunting |
| Windows Event Log Cleared |
None |
TTP |
| Windows Excessive Disabled Services Event |
None |
TTP |
| Windows File Without Extension In Critical Folder |
None |
TTP |
| Windows High File Deletion Frequency |
None |
Anomaly |
| Windows Hunting System Account Targeting Lsass |
None |
Hunting |
| Windows InstallUtil Credential Theft |
None |
TTP |
| Windows InstallUtil Remote Network Connection |
None |
TTP |
| Windows InstallUtil URL in Command Line |
None |
TTP |
| Windows InstallUtil Uninstall Option |
None |
TTP |
| Windows InstallUtil Uninstall Option with Network |
None |
TTP |
| Windows InstallUtil in Non Standard Path |
None |
TTP |
| Windows Java Spawning Shells |
None |
TTP |
| Windows Modify Show Compress Color And Info Tip Registry |
None |
TTP |
| Windows NirSoft AdvancedRun |
None |
TTP |
| Windows NirSoft Utilities |
None |
Hunting |
| Windows Non-System Account Targeting Lsass |
None |
TTP |
| Windows Possible Credential Dumping |
None |
TTP |
| Windows Process With NamedPipe CommandLine |
None |
Anomaly |
| Windows Raccine Scheduled Task Deletion |
None |
TTP |
| Windows Rasautou DLL Execution |
None |
TTP |
| Windows Raw Access To Disk Volume Partition |
None |
Anomaly |
| Windows Raw Access To Master Boot Record Drive |
None |
TTP |
| Windows Remote Assistance Spawning Process |
None |
TTP |
| Windows Schtasks Create Run As System |
None |
TTP |
| Windows Security Account Manager Stopped |
None |
TTP |
| Windows Service Created With Suspicious Service Path |
None |
TTP |
| Windows Service Created Within Public Path |
None |
TTP |
| Windows Service Creation Using Registry Entry |
None |
TTP |
| Windows Service Creation on Remote Endpoint |
None |
TTP |
| Windows Service Initiation on Remote Endpoint |
None |
TTP |
| Windows WMI Process Call Create |
None |
Hunting |
| Windows connhost exe started forcefully |
None |
TTP |
| Windows hosts file modification |
None |
TTP |
| Winhlp32 Spawning a Process |
None |
TTP |
| Winword Spawning Cmd |
None |
TTP |
| Winword Spawning PowerShell |
None |
TTP |
| Winword Spawning Windows Script Host |
None |
TTP |
| Wmic Group Discovery |
None |
Hunting |
| Wmic NonInteractive App Uninstallation |
None |
Hunting |
| Wmiprsve LOLBAS Execution Process Spawn |
None |
TTP |
| Wscript Or Cscript Suspicious Child Process |
None |
TTP |
| Wsmprovhost LOLBAS Execution Process Spawn |
None |
TTP |
| XMRIG Driver Loaded |
None |
TTP |
| XSL Script Execution With WMIC |
None |
TTP |
| aws detect attach to role policy |
None |
Hunting |
| aws detect permanent key creation |
None |
Hunting |
| aws detect role creation |
None |
Hunting |
| aws detect sts assume role abuse |
None |
Hunting |
| aws detect sts get session token abuse |
None |
Hunting |
| gcp detect oauth token abuse |
None |
Hunting |