Search and filter across all detection sources
4,101 rules
[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected
[WINDOWS-SYSMON] Attack on Sysmon - SysmonDrv Registry value set
[WINDOWS-SYSMON] SYSMON Possible CMD detected
[WINDOWS-SYSMON] Attack on Sysmon - Process Injection
HackTool - SysmonEnte Execution
Detects the use of SysmonEnte, a tool to attack the integrity of Sysmon
[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload
Sysmon detected
Windows Sysmon detected
[WINDOWS-SYSMON] Windows Registry - Restricted Admin Mode Enabled (Sysmon RegistryEvent) - Critical
Sysmon Driver Unloaded Via Fltmc.EXE
Detects possible Sysmon filter driver unloaded via fltmc.exe
[WINDOWS-SYSMON] Windows Registry - Restricted Admin Outbound Credentials Enabled (Sysmon RegistryEvent) - Critical
Sysmon Configuration Modification
Detects when an attacker tries to hide from Sysmon by disabling or stopping it
Uninstall Sysinternals Sysmon
Detects the removal of Sysmon, which could be a potential attempt at defense evasion
Sysmon Blocked Executable
Triggers on any Sysmon "FileBlockExecutable" event, which indicates a violation of the configured block policy
Sysmon Blocked File Shredding
Triggers on any Sysmon "FileBlockShredding" event, which indicates a violation of the configured shredding policy.
Sysmon Configuration Update
Detects updates to Sysmon's configuration. Attackers might update or replace the Sysmon configuration with a bare bone one to avoid monitoring without shutting down the service completely
Sysmon Configuration Error
Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages
[WINDOWS-SYSMON] Evilginx2 Certificate Operations
[WINDOWS-SYSMON] KeePass Password Dumping
[WINDOWS-SYSMON] MSHTA executing powershell
[WINDOWS-SYSMON] MSHTA executing wscript