Browse Rules

Search and filter across all detection sources

591 rules

signature-base unknown yara

Impacket_Lateral_Movement [yara]

Detects Impacket Network Aktivity for Lateral Movement

yara unknown yara

lateral_movement [malware]

methodology sig looking for signs of lateral movement

hayabusa critical sigma

Turla Group Lateral Movement

Detects automated lateral movement by Turla group

sigma critical sigma

Turla Group Lateral Movement

Detects automated lateral movement by Turla group

hayabusa critical sigma

Turla Group Lateral Movement

Detects automated lateral movement by Turla group

sagan critical other

[WINDOWS-SECURITY] Possible lateral movement via wmic

[WINDOWS-SECURITY] Possible lateral movement via wmic

elastic critical eql

Malicious Remote File Creation

Malicious remote file creation, which can be an indicator of lateral movement activity.

elastic high kql

Lateral Movement Alerts from a Newly Observed Source Address

This rule detects source IPs that triggered their first lateral movement alert within the last 10 minutes (i.e., newly observed), while also triggering at least 2 distinct lateral movement detection rules. This surfaces new potentially malicious IPs exhibiting immediate lateral movement behavior.

chronicle unknown yara-l

mmc20_lateral_movement

Detects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of \

bertjanp unknown kql

List Lateral Movements Paths to Compromised Device

bertjanp unknown kql

List Lateral Movements Paths to Compromised Device

sigma high sigma

Remote DCOM/WMI Lateral Movement

Detects remote RPC calls that performs remote DCOM operations. These could be abused for lateral movement via DCOM or WMI.

hayabusa medium sigma

Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell

Detects Powershell as a child of the WmiPrvSE process. Which could be a sign of lateral movement via WMI.

sigma medium sigma

Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell

Detects Powershell as a child of the WmiPrvSE process. Which could be a sign of lateral movement via WMI.

hayabusa medium sigma

Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell

Detects Powershell as a child of the WmiPrvSE process. Which could be a sign of lateral movement via WMI.

sentinel informational kql

Lateral Movement Risk - Role Chain Length

The policy detects chains of more than 3 roles in the account, this is a misconfiguration that can enable lateral movement.

hayabusa high sigma

Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp

Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.

sigma high sigma

Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp

Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.

hayabusa high sigma

Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp

Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.

panther informational python

AWS EC2 Multi Instance Connect

Detect when an attacker pushes an SSH public key to multiple EC2 instances.

panther medium python

Databricks Access to Multiple Workspaces

Detects users accessing 5 or more distinct workspaces within 24 hours, which may indicate lateral movement, reconnaissance, or compromised credentials.

elastic-protections high eql

Potential Lateral Movement via SMBExec

Identifies suspicious service execution via Windows Command Shell which may indicate lateral movement attempt via known offensive testing tool like SMBExec.

hayabusa high sigma

MMC20 Lateral Movement

Detects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of "-Embedding" as a child of svchost.exe

sigma high sigma

MMC20 Lateral Movement

Detects MMC20.Application Lateral Movement; specifically looks for the spawning of the parent MMC.exe with a command line of "-Embedding" as a child of svchost.exe

elastic low eql

Unusual Remote File Extension

An anomaly detection job has detected a remote file transfer with a rare extension, which could indicate potential lateral movement activity on the host.