Browse Rules

Search and filter across all detection sources

691 rules

anvilogic high spl

Logon Script Registry Key added [splunk-edr]

Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.

anvilogic high spl

Multiple Host logons [splunk-edr]

Use case looks for users who have logged into multiple hosts. -- Threat Actor Association: CL-STA-0043

anvilogic high spl

Clear Linux System Logs [splunk-edr]

This use case would detect the alteration or removal of log files. Atomics T1070.003 Test #3 Atomics T1070.003 Test #5

anvilogic high other

Logon Script Registry Key added [snowflake-crowdstrikefdr_process]

Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.

anvilogic high spl

Potential SSH Authorized Key Overwrite [splunk-edr]

Potential overwrites of authorized_keys file for ssh. -- Threat Actor Association: TeamTNT

anvilogic high spl

Suspicious reCAPTCHA Command Line [splunk-edr]

This use case detects commonly abused LOLBAS utilities referencing reCAPTCHA in the command line.

anvilogic medium spl

NIX Interactive Shell [splunk-edr]

This use case detects the creation of an interactive shell on a NIX host -- Software Association: Kinsing

anvilogic medium spl

Suspicious process Spawned by Java [splunk-edr]

Detect Java Spawning suspicious processes. This could indicate successful execution of vulnerabilities such as log4j CVE-2021-44228. - Threat Actor Association: Evilnum, Volt Typhoon

anvilogic high spl

Modify File Attributes [splunk-edr]

chattr changes the file attributes on a Linux file system. - Threat Actor Association: TeamTNT - Atomics T1222.002 Test #9

anvilogic high spl

Net.exe Use with URL [splunk-edr]

This use case detects net share commands mapping a drive to a URL as observed by the BumbleBee loader.

anvilogic medium other

Suspicious Use of _dev_tcp [snowflake-crowdstrikefdr_process]

Detects suspicious command with /dev/tcp

anvilogic low spl

CSVDE Export Active Directory [splunk-edr]

Detects the administration tool csvde.exe attempting to export Active Directory data in an APT scenario. -- Threat Actor Association: Volt Typhoon

anvilogic critical spl

Web: Potential file transfer using SCP [splunk-edr]

This use case is searching for specific keywords that are generated when a SCP file transfer - Threat Actor Association: Lazarus

anvilogic high other

Clear Linux System Logs [snowflake-crowdstrikefdr_process]

This use case would detect the alteration or removal of log files. Atomics T1070.003 Test #3 Atomics T1070.003 Test #5

anvilogic medium spl

Potential CVE-2021-44228 - Log4Shell [splunk-edr]

A vulnerability identified in Java logging library "log4j" that could result in remote code execution. This use case identifies exploitation attempts in compressed files in folder /var/log -- Threat Actor Association: Andariel, APT28, Magic Hound (aka APT35, Charming Kitten, Phosphorus, and Mint Sandstorm), APT41, Karakurt, Lazarus, Stonefly, Teal Kurma (aka Sea Turtle, Marbled Dust, Cosmic Wolf) -- Software Association: Conti, WhisperGate - #TrendingThreat #Russia #Ukraine

anvilogic critical spl

Csplit_Split Small Data Staged for Exfil [splunk-edr]

Identify use of csplit or split, in order to chunk web server data into smaller files for later exfiltration. Atomics T1030 Test #1

anvilogic medium spl

File Execution (Unix) [splunk-edr]

Detect when a file has been executed -- Threat Actor Association: TeamTNT, Winnti Group - Software Association: Mélofée, Ransom Cartel -- Atomics T1548.003 Test#1 Atomics T1548.003 Test#2

anvilogic medium spl

Office Spawns Suspicious Child Process [splunk-edr]

This use case attempts to identify suspicious child processes spawned from a Microsoft Office application -- Threat Actor Association: RomCom (Storm-0978) -- Vulnerability Association: CVE-2023-36884

anvilogic high spl

Hidden Executable with Command Line IP Argument - *nix [splunk-edr]

This use case detects when a hidden executable (any process name starting with .) is supplied with a command line argument containing an IP address.

anvilogic low spl

Event Logs Queried for RDP Sessions [splunk-edr]

Threat actors may query Windows Terminal Services logs for RDP session information. - Example 1: During post-compromise reconnaissance activities, Lazarus was observed using wevtutil to query Windows Terminal Services logs for RDP sessions (Event Code 25) in order to gather session reconnection information. - Example 2: Threat actor tracked as Cluster Charlie (STAC1305) searched Windows Event Logs for Windows Remote Connection Manager event ID 1149 -- This use case detects commands querying Term

anvilogic medium spl

Abuse EQNEDT32.EXE [splunk-edr]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic high other

Potential SSH Authorized Key Overwrite [snowflake-crowdstrikefdr_process]

Potential overwrites of authorized_keys file for ssh. -- Threat Actor Association: TeamTNT

anvilogic high spl

File Copied to _var_log - *nix [splunk-edr]

Threat actors may attempt to conceal their activities or manipulate system logs by copying files into the /var/log/ directory within a compromised environment. This technique may be employed to evade detection, establish persistence or obfuscate the threat actor's actions by blending in with legitimate log files. Once placed in the /var/log/ directory, adversaries may manipulate or delete these files to cover their tracks and impede forensic analysis. This use case detects files moved to /var/lo

anvilogic medium spl

Linux CURL or WGET Direct to IPv4 Address [splunk-edr]

This rule looks for endpoint logs that contain a CURL or WGET command inside of the process line that try and connect directly to an IP address. This use case was originally created in response to CVE-2021-44228. -- Software Association: TeamTNT

anvilogic high spl

Certutil Obfuscate_Encode Files [splunk-edr]

Certutil can be used to encode files to evade defensive measures. -- Threat Actor Association: APT29/Nobelium/Cozy Bear, Arid Viper/APT C-23, BlackTech - Software Association: Conti