Browse Rules

Search and filter across all detection sources

10,415 rules

anvilogic high other

1 or 2 Character Executable [snowflake-crowdstrikefdr_process]

Adversaries have been known to occasionally use executable files named with only 1 or 2 word characters. - Threat Actor Association: Lotus Blossom, OilRig, Trigona, Volt Typhoon

anvilogic high other

3CXDesktopApp.exe Execution [snowflake-crowdstrikefdr_process]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic medium other

Abuse EQNEDT32.EXE [snowflake-crowdstrikefdr_process]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic high other

Access Common Package Config file [snowflake-crowdstrikefdr_process]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high other

Account Discovery Commands - Windows [snowflake-crowdstrikefdr_process]

Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Atomics T1087.001 Test #8 Atomics T1087.001 Test #9 Atomics T1087.001 Test #10 Atomics T1087.002 Test #1 Atomics T1087.002 Test #2 Atomics T1087.002 Test #3 Atomics T1087.002 Test #9

anvilogic critical other

Account Password Changed from Command Line - Windows [snowflake-crowdstrikefdr_process]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic high other

Account set to active via Net.exe [snowflake-crowdstrikefdr_process]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2

anvilogic high other

ADExplorer Execution [snowflake-crowdstrikefdr_process]

Active Directory Explorer (AD Explorer) is a tool from the Sysinternals suite that allows users to view, search, and analyze objects within Active Directory to understand its structure, object properties, and security settings. A threat actor might leverage AD Explorer to gain detailed insights into the AD environment, such as identifying privileged user accounts and network resources, which can be exploited to escalate privileges or facilitate lateral movement within a network. This use case de

anvilogic high other

ADExplorer Snapshot Creation [snowflake-crowdstrikefdr_process]

Active Directory Explorer (AD Explorer) is a tool from the Sysinternals suite that allows users to view, search, and analyze objects within Active Directory, and it includes the capability to take snapshots of the AD database for offline analysis. A threat actor might leverage AD Explorer to gain detailed insights into the AD environment and use its snapshot capability to discreetly export and study the structure, user accounts, and security settings, potentially identifying vectors for privileg

anvilogic low other

Adfind Commands [snowflake-crowdstrikefdr_process]

AdFind is a free command-line query tool that can be used for gathering information from Active Directory. In some instances Adversaries have renamed adfind in order to avoid detection. This use case looks for common commands of Adfind. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, BlackMatter, Conti, DarkSide, FIN6, FIN7, FIN12, Karakurt, Mustang Panda (aka. Stately Taurus//Earth Preta/BRONZE PRESIDENT/TA416/RedDelta), Traveling Spider, Wizard Spider, Yanluowang -- Software Association

anvilogic low other

Adfind Execution [snowflake-crowdstrikefdr_process]

AdFind is a free command-line query tool that can be used for gathering information from Active Directory. This use case looks for process executions of Adfind. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, APT31, BlackMatter, Conti, DarkSide, FIN6, FIN7, FIN12, Karakurt, Lazarus, Traveling Spider, Wizard Spider, Yanluowang - Software Association: ALPHV/BlackCat, BazarLoader, Conti, Dridex, Entropy, Lockbit, Nefilim, Quantum, Sodinokibi/REvil - Atomics T1016 Test #6 Atomics T1018 Test#1

anvilogic low other

Advanced IP Scanner Execution [snowflake-crowdstrikefdr_process]

Advanced IP Scanner is a legitimate utility that can perform network scanning. Several threat actors, including UNC2465, Conti, Pysa ransomware and FIN12, have been reported to use Advanced IP Scanner during reconnaissance activities. -- Threat Actor Association: FIN12, UNC2465 - Software Association: Akira, AvosLocker, Conti, Pysa

anvilogic low other

Advanced Port Scanner Execution [snowflake-crowdstrikefdr_process]

Advanced Port Scanner is a free network scanner that allows users to quickly find open ports on network computers and retrieve versions of programs running on the ports it detects. Threat actors using Rhysida ransomware have been reported to use Advanced Port Scanner during reconnaissance activities.

anvilogic high other

AnyDesk Command Line Execution [snowflake-crowdstrikefdr_process]

For most users, normal AnyDesk activity is executed via the GUI. This use case detects anydesk.exe calls from cmd.exe or PowerShell.exe. Install commands have been filtered out by default. - Threat Actor Association: Alloy Taurus/Gallium, Gamaredon (aka. Armageddon, UAC-0010), Muddled Libra, Scattered Spider (aka. 0ktapus, UNC3944), Scatter Swine, UNC2659 - Software Association: Akira, ALPHV/BlackCat, AvosLocker, BianLian, BlackByte, BumbleBee, Clop, Conti, Diavol, Rhysida, Royal

anvilogic high other

AnyDesk Execution from Suspicious Folder [snowflake-crowdstrikefdr_process]

Adversaries may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services are commonly used as legitimate technical support software, and may be allowed by application control within a target environment. This use case detects when remote access software AnyDesk is executed outside of standard install locations. -- Threat Actor Association: Alloy Taurus/Gallium, Gamaredon (aka. Armageddon, U

anvilogic high other

AnyDesk Silent Install [snowflake-crowdstrikefdr_process]

An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. BlackByte ransomware group has been observed performing silent installs of AnyDesk after establishing a foothold. This use case detects silent installation of AnyDesk. - Threat Actor Association: Alloy Taurus/Gallium, Gamaredon (aka. Armageddon, UAC-0010), Muddled Libra, Scattered Spider (aka. 0ktapus, UNC3944), Scatter Swine, UNC26

anvilogic low other

Application Discovery - Windows [snowflake-crowdstrikefdr_process]

Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Adversaries may attempt to enumerate software for a variety of reasons, such as figuring out what security measures are present or if the compromised sy

anvilogic high other

ATBroker.exe Execution [snowflake-crowdstrikefdr_process]

Helper binary for Assistive Technology (AT), Executes code defined in registry for a new AT. Modifications must be made to the system registry to either register or modify an existing Assistive Technology (AT) service entry. Living Off the Land Binary and Scripts (LOLBAS) (LOLBIN)

anvilogic high other

Attempted Veeam Database Credential Dump [snowflake-crowdstrikefdr_process]

Operators from the Diavol ransomware gang were observed using sqlcmd to extract encrypted credentials from Veeam databases that were decrypted using a publicly documented technique on Veeam's R+D forums. This use case detects commands targeting credentials stored in Veeam databases. While sqlcmd.exe was used in documented cases, the logic is not reliant on detecting sqlcmd.exe to account for instances where the binary has been renamed or another utility was used to interact with the database. --

anvilogic high other

Attrib.exe Metasploit File Dropper [snowflake-crowdstrikefdr_process]

Using attrib.exe, an adversary may display or change file attributes in order to bypass UAC restrictions. Metasploits file_dropper.rb, which is include in some payloads uses this to assist in removing artifacts. -- Software Association: TargetCompany

anvilogic medium other

AutoHotkey Execution [snowflake-crowdstrikefdr_process]

Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts. AutoIT and AutoHotkey (AHK) are scripting languages that enable users to automate Windows tasks. These automation scripts can be used to perform a wide variety of actions, such as clicking on buttons, entering text, and opening and closing programs. This use case detects the usage of the AutoHotkey software to execute ahk files.

anvilogic medium other

AutoIt Execution [snowflake-crowdstrikefdr_process]

AutoIt is a freeware scripting utility that can automate Windows GUI tasks such as mouse clicks, keystrokes, and window manipulations. While it is a legitimate tool, threat actors have abused it to automate malicious activity. This use case detects AutoIt, AutoIt2, or AutoIt3 executions, or commands loading .au3 files. -- Software Association: DarkGate

anvilogic low other

AWS Account Discovery [snowflake-awscloudtrail]

Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. -- Threat Actor Association: GUI-vil

anvilogic high other

AWS Add role to instance profile [snowflake-awscloudtrail]

This use case looks for when a role has been added to an instance profile.

anvilogic high other

AWS Add user to group [snowflake-awscloudtrail]

This use case looks for when a user has been added to a group.