Browse Rules

Search and filter across all detection sources

922 rules

chronicle medium yara-l

0x103800

Detects process access requests to the LSASS process with specific call trace calls and access masks. This behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature.

chronicle high yara-l

0x1FFFFF

Detects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up

chronicle unknown yara-l

abusing_attribexe_to_change_file_attributes

Detects possible abuse of attrib.exe to hide files and folder or to mark a file as a system file License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

abusing_azure_browser_sso

Detects abusing Azure Browser SSO by requesting OAuth 2.0 refresh tokens for an Azure-AD-authenticated Windows user (i.e. the machine is joined to Azure AD and a user logs in with their Azure AD account) wanting to perform SSO authentication in the browser. An attacker can use this to authenticate to Azure AD in a browser as that user. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

abusing_managebdewsf

Detects abusing of deprecated manage-bde.wsf. Tampering with manage-bde.wsf to run things in unattended ways. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

abusing_security_support_provider_and_authentication_packages

Detects activity that abuses Windows Security Support Provider (SSP) and Authentication Packages (AP) that come in the form of DLLs that get injected into LSASS.exe process on system boot or dynamically via AddSecurityPackage API. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

abusing_settingcontentms_to_launch_arbitrary_shell_command_execution

None License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

abusing_windows_telemetry_compattelrunnerexeaudit_rule

Detects abusing of CompatTelRunner.exe for persistance. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

account_discovery_activity_detector_sysmon_behavior

This detects characteristics of account discovrery activity that adversaries could use License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

account_tampering__suspicious_failed_logon_reasons

This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

acer_quick_access__dll_searchorder_hijacking_and_potential_abuses

Detects (CVE-2019-18670) exploitation attempt License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

active_directory_as_a_c2_command__control

Active Directory is a Central Authentication and Access control. It isimportant to control it. The service name does not appear either. The importantthing is to check the displayname License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

active_directory_replication_from_non_machine_account

Detects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

activity_related_to_ntdsdit_domain_hash_retrieval

Detects suspicious commands that could be related to activity that uses volume shadow copy to steal and retrieve hashes from the NTDS.dit file remotely License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

addition_of_sid_history_to_active_directory_object

An attacker can use the SID history attribute to gain additional privileges. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

add_programs_to_firewall_exclusion_from_temp_directory_sysmon

Add Programs To Firewall Exclusion From Temp Directory. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle high yara-l

ADFS DKM Key Access

Detects access to the AD contact object to read the AD FS DKM (distributed key manager) master key value

chronicle unknown yara-l

Admin$

Detects access to $ADMIN share. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

admin_user_rdp

It shows those who log in remotely with admin account. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

admin_user_remote_logon

Detect remote login by Administrator user depending on internal pattern License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

ad_privileged_users_or_groups_reconnaissance

Detect priv users or groups recon based on 4661 eventid and known privileged users or groups SIDs License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

adwind_detection

Detects AdWind activity (also known as AlienSpy, Frutas, Unrecom, Sockrat, JSocket and jRat) License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

adwind_rat__jrat

Detects javaw.exe in AppData folder as used by Adwind / JRAT License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

adwind_rat__jrat_part_1

Detects javaw.exe in AppData folder as used by Adwind / JRAT License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

chronicle unknown yara-l

adwind_rat__jrat_part_2

Detects javaw.exe in AppData folder as used by Adwind / JRAT License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.