Browse Rules

Search and filter across all detection sources

14 rules

sagan medium other

[CLOUDTRAIL] IAM cloudtrail event detected - (AddUserToGroup)

[CLOUDTRAIL] IAM cloudtrail event detected - (AddUserToGroup)

signature-base unknown yara

CN_Honker_no_net_priv_esc_AddUser [yara]

Sample from CN Honker Pentest Toolset - file AddUser.dll

sagan informational other

[AWS-IAM] Identity and Access Management event detected (AddUserToGroup)

[AWS-IAM] Identity and Access Management event detected (AddUserToGroup)

wazuh medium xml

ASA: User created or modified on the Firewall.

ASA: User created or modified on the Firewall.

falco informational other

System procs network activity

Detect any unexpected network activity performed by system binaries that typically shouldn't perform network activity, including coreutils binaries (like sleep, mkdir, who, date, and others) or user management binaries (such as login, systemd, usermod, deluser, adduser, chpasswd, and others). This serves as a valuable baseline detection for network-related activities.

splunk unknown spl

Linux Add User Account

The following analytic detects the creation of new user accounts on Linux systems using commands like "useradd" or "adduser." It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as adversaries often create new user accounts to establish persistence on compromised hosts. If confirmed malicious, this could allow attackers to maintain access, escalate privileges, and further compromise the system, p

splunk unknown spl

Linux Auditd Add User Account

The following analytic detects the creation of new user accounts on Linux systems using commands like "useradd" or "adduser." It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions. This activity is significant as adversaries often create new user accounts to establish persistence on compromised hosts. If confirmed malicious, this could allow attackers to maintain access, escalate privileges, and further compromise the system, p

wazuh medium xml

Windows: General account database changed.

Windows: General account database changed.

wazuh medium xml

Windows: Security enabled group created.

Windows: Security enabled group created.

wazuh medium xml

Windows: Security enabled group deleted.

Windows: Security enabled group deleted.

falco informational other

User mgmt binaries

Detect activity by any programs that can manage users, passwords, or permissions (such as login, systemd, usermod, deluser, adduser, chpasswd, and others). sudo and su are excluded. Activity in containers is also excluded -- some containers create custom users on top of a base linux distribution at startup. Some innocuous command lines that don't actually change anything are excluded. You might want to consider applying this rule to container actions as well.

wazuh medium xml

Windows: User account enabled or created.

Windows: User account enabled or created.

wazuh medium xml

Windows: User account disabled or deleted.

Windows: User account disabled or deleted.

wazuh medium xml

PIX: User created or modified on the Firewall.

PIX: User created or modified on the Firewall.