Browse Rules

Search and filter across all detection sources

3,683 rules

anvilogic high spl

1 or 2 Character Executable [splunk-winevent]

Adversaries have been known to occasionally use executable files named with only 1 or 2 word characters. - Threat Actor Association: Lotus Blossom, OilRig, Trigona, Volt Typhoon

anvilogic high spl

3CXDesktopApp.exe Execution [splunk-edr]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic high spl

3CXDesktopApp.exe Execution [splunk-sysmon]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic high spl

3CXDesktopApp.exe Execution [splunk-winevent]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic medium spl

Abuse EQNEDT32.EXE [splunk-edr]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic medium spl

Abuse EQNEDT32.EXE [splunk-sysmon]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic medium spl

Abuse EQNEDT32.EXE [splunk-winevent]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic high spl

Access Common Package Config file [splunk-edr]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-powershell]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-sysmon]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-unix]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-winevent]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic critical spl

Account Password Changed from Command Line - Windows [splunk-edr]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic critical spl

Account Password Changed from Command Line - Windows [splunk-powershell]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic critical spl

Account Password Changed from Command Line - Windows [splunk-winevent]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic high spl

Account set to active via Net.exe [splunk-edr]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2

anvilogic high spl

Account set to active via Net.exe [splunk-sysmon]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2

anvilogic high spl

Account set to active via Net.exe [splunk-winevent]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2

anvilogic high spl

Add DLL_EXE Registry Value [splunk-sysmon]

Adding an entry to the "run keys" in the Registry or startup folder will cause the program referenced to be executed when a user logs in. -- Threat Actor Association: CL-STA-0043, FamousSparrow, FIN6, Flax Typhoon, WIRTE -- Software Association: Blackbyte

anvilogic high spl

Add role to a user in Azure AD [splunk-add]

Adding a role to a user in Azure AD is one the techniques used for privilege escalation.

anvilogic high spl

Add secret to Azure service principal [splunk-add]

The attacker ( logged in as a low privileged user) could add a new secret to the service principal, then login to Azure PowerShell as that service principal. - Threat Actor Association: APT29/Nobelium/Cozy Bear, Storm-1283

anvilogic high spl

Additional dll added to Spool Driver [splunk-sysmon]

This use case look for an additional dll to the print drivers as seen with Print Nightmare CVE-2021-1675. -- Threat Actor Association: Earth Lusca, Vice Society - Software Association: Black Basta, Play, Ransom Cartel

anvilogic high spl

Additional dll added to Spool Driver [splunk-winevent]

This use case look for an additional dll to the print drivers as seen with Print Nightmare CVE-2021-1675. -- Threat Actor Association: Earth Lusca, Vice Society - Software Association: Black Basta, Play, Ransom Cartel

anvilogic high spl

ADExplorer Execution [splunk-edr]

Active Directory Explorer (AD Explorer) is a tool from the Sysinternals suite that allows users to view, search, and analyze objects within Active Directory to understand its structure, object properties, and security settings. A threat actor might leverage AD Explorer to gain detailed insights into the AD environment, such as identifying privileged user accounts and network resources, which can be exploited to escalate privileges or facilitate lateral movement within a network. This use case de

anvilogic high spl

ADExplorer Execution [splunk-sysmon]

Active Directory Explorer (AD Explorer) is a tool from the Sysinternals suite that allows users to view, search, and analyze objects within Active Directory to understand its structure, object properties, and security settings. A threat actor might leverage AD Explorer to gain detailed insights into the AD environment, such as identifying privileged user accounts and network resources, which can be exploited to escalate privileges or facilitate lateral movement within a network. This use case de