Browse Rules

Search and filter across all detection sources

166 rules

sekoia unknown yara

tool_tacticalrmm_installer_strings [yara_rules]

Detects TacticalRMM installer

sagan medium other

[WINDOWS-SYSMON] Installation of PyPyKatz Detected - Credential Harvesting Tool

[WINDOWS-SYSMON] Installation of PyPyKatz Detected - Credential Harvesting Tool

signature-base unknown yara

install_get_persistent_filenames [yara]

EQGRP Toolset Firewall - file install_get_persistent_filenames

yara unknown yara

install_get_persistent_filenames [malware]

EQGRP Toolset Firewall - file install_get_persistent_filenames

sentinel high kql

Credential Dumping Tools - Service Installation

'This query detects the installation of a Windows service that contains artifacts from credential dumping tools such as Mimikatz.'

signature-base unknown yara

EquationGroup_Toolset_Apr17_yak_min_install [yara]

Detects EquationGroup Tool - April Leak

yara unknown yara

EquationGroup_Toolset_Apr17_yak_min_install [malware]

Detects EquationGroup Tool - April Leak

hayabusa medium sigma

TacticalRMM Service Installation

Detects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.

sigma medium sigma

TacticalRMM Service Installation

Detects a TacticalRMM service installation. Tactical RMM is a remote monitoring & management tool.

hayabusa high sigma

smbexec.py Service Installation

Detects the use of smbexec.py tool by detecting a specific service installation

sigma high sigma

smbexec.py Service Installation

Detects the use of smbexec.py tool by detecting a specific service installation

hayabusa medium sigma

Remote Access Tool Services Have Been Installed - Security

Detects service installation of different remote access tools software. These software are often abused by threat actors to perform

hayabusa medium sigma

Remote Access Tool Services Have Been Installed - System

Detects service installation of different remote access tools software. These software are often abused by threat actors to perform

sigma medium sigma

Remote Access Tool Services Have Been Installed - Security

Detects service installation of different remote access tools software. These software are often abused by threat actors to perform

sigma medium sigma

Remote Access Tool Services Have Been Installed - System

Detects service installation of different remote access tools software. These software are often abused by threat actors to perform

yara unknown yara

Silicon_Realms_Install_Stub_Silicon_Realms_Toolworks [packers]

hayabusa high sigma

Remote Access Tool - AnyDesk Silent Installation

Detects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.

sigma high sigma

Remote Access Tool - AnyDesk Silent Installation

Detects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.

panther medium python

GitHub Supply Chain - Software Installation Tool User Agents

Detects software installation tool user agents in GitHub audit logs that should never directly access GitHub. Package managers like npm, pip, yarn, and system installers operate at the registry level, not GitHub audit level. Their presence indicates: 1. Supply chain attacks using spoofed user agents to blend in 2. Compromised systems running installation tools with stolen GitHub tokens 3. Malicious automation disguised as legitimate package managers Based on analysis of GitHub audit logs sho

hayabusa high sigma

Remote Access Tool - AnyDesk Silent Installation

Detects AnyDesk Remote Desktop silent installation. Which can be used by attackers to gain remote access.

falco low other

Network Tool Executed During NPM Package Install

Detect network tools being launched when an NPM package is installed. Malicious NPM packages may invoke preinstall or postinstall commands, which can involve network tools to download malicious payloads or exfiltrate sensitive information. Network tools spawned by npm, node, yarn, pnpm, bun, or related processes during package installation should be investigated. This rule complements the more generic "Launch Suspicious Network Tool in Container" rule with a specific focus on the supply chai

elastic-protections high eql

Potential Evasion via dotNET Framework Installation Utility

The Installer tool is a command-line utility that allows you to install and uninstall server resources by executing the installer components in specified assemblies. Adversaries may abuse this utility to run malicious code.

chronicle unknown yara-l

smbexecpy_service_installation

Detects the use of smbexec.py tool by detecting a specific service installation License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

elastic low eql

Tool Installation Detected via Defend for Containers

This rule detects the installation of tools inside a container. An adversary may need to install additional software to enumerate the container, its environment, and move laterally within the environment.

anvilogic high spl

SimpleHelp Remote Access Tool Service Installation [splunk-winevent]

Threat actors may install remote access tools (RATs) as Windows services to maintain persistent access to compromised systems. Tools like SimpleHelp or JWrapper Remote Access are often abused for stealthy remote control, masquerading as legitimate IT support tools. This use case detects the installation of Windows services (event codes 4697 or 7045) where the service binary path matches known patterns associated with SimpleHelp, JWrapper Remote Access, or similarly named executables, indicating