Browse Rules

Search and filter across all detection sources

22 rules

hayabusa critical sigma

HackTool - Empire PowerShell UAC Bypass

Detects some Empire PowerShell UAC bypass methods

sigma critical sigma

HackTool - Empire PowerShell UAC Bypass

Detects some Empire PowerShell UAC bypass methods

hayabusa critical sigma

HackTool - Empire PowerShell UAC Bypass

Detects some Empire PowerShell UAC bypass methods

hayabusa high sigma

UAC Bypass via Event Viewer

Detects UAC bypass method using Windows event viewer

sigma high sigma

UAC Bypass via Event Viewer

Detects UAC bypass method using Windows event viewer

hayabusa high sigma

CMSTP Execution Process Creation

Detects various indicators of Microsoft Connection Manager Profile Installer execution

hayabusa high sigma

UAC Bypass via Event Viewer

Detects UAC bypass method using Windows event viewer

sigma high sigma

CMSTP Execution Process Access

Detects various indicators of Microsoft Connection Manager Profile Installer execution

sigma high sigma

CMSTP Execution Process Creation

Detects various indicators of Microsoft Connection Manager Profile Installer execution

hayabusa high sigma

CMSTP Execution Process Access

Detects various indicators of Microsoft Connection Manager Profile Installer execution

hayabusa high sigma

CMSTP Execution Process Creation

Detects various indicators of Microsoft Connection Manager Profile Installer execution

hayabusa high sigma

UAC Bypass via Sdclt

Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)

sigma high sigma

UAC Bypass via Sdclt

Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)

hayabusa high sigma

Potentially Suspicious Event Viewer Child Process

Detects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt

hayabusa high sigma

UAC Bypass via Sdclt

Detects the pattern of UAC Bypass using registry key manipulation of sdclt.exe (e.g. UACMe 53)

sigma high sigma

Potentially Suspicious Event Viewer Child Process

Detects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt

hayabusa high sigma

Potentially Suspicious Event Viewer Child Process

Detects uncommon or suspicious child processes of "eventvwr.exe" which might indicate a UAC bypass attempt

sigma high sigma

CMSTP UAC Bypass via COM Object Access

Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)

hayabusa high sigma

CMSTP UAC Bypass via COM Object Access

Detects UAC Bypass Attempt Using Microsoft Connection Manager Profile Installer Autoelevate-capable COM Objects (e.g. UACMe ID of 41, 43, 58 or 65)

hayabusa high sigma

CMSTP App Paths Registry Key Modification

Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.

sigma high sigma

CMSTP App Paths Registry Key Modification

Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.

hayabusa high sigma

CMSTP App Paths Registry Key Modification

Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.