Browse Rules

Search and filter across all detection sources

246 rules

elastic-protections high eql

Potential DANTE Spyware Execution

Identifies potential execution of a commercial spyware.

elastic-protections high eql

Suspicious API Call from a PowerShell Script

Detects PowerShell scripts calling dual-purpose Win32 APIs.

elastic-protections high eql

Privilege Escalation via SeImpersonatePrivilege

Identifies a privilege escalation attempt from an account with the SeImpersonatePrivilege to full System privileges.

elastic-protections high eql

Suspicious XPC Service Child Process

Detects an abnormal child process of a XPC service running from a suspicious location.

elastic-protections high eql

Windows Socket Creation from Stomped Module

Identifies the creation of a Windows network socket from a potentially stomped module.

elastic-protections high eql

PowerShell Empire Script Execution

Identifies the execution of PowerShell scripts with keywords from known open source Empire penetration testing tool.

elastic-protections high eql

Attempt to Disable Windows Defender Services

Identifies attempt to stop or disable the Windows Defender services from an unusual parent process.

elastic-protections high eql

Potential Defense Evasion via Filter Manager Control Program

Identifies attempt to unload a security driver via the Filter Manager Control Program.

elastic-protections high eql

Shellcode Execution from Low Reputation Module

Identifies attempt to allocate or execute Shellcode from a module with low or unknown reputation.

elastic-protections high eql

Suspicious Python Script Interpreter

Identifies the execution of a recently dropped executable that loads python libraries to interact with Windows APIs.

elastic-protections high eql

Potential PowerShell Empire Execution

Identifies the execution of PowerShell with suspicious argument values. This behavior is often observed during malware installation leveraging PowerShell.

elastic-protections high eql

Suspicious Remote Memory Allocation

Identifies attempts to allocate remote memory with RWX permissions, this behavior is often associated with remote process injection preparation.

elastic-protections high eql

Potential Git CVE-2025-48384 Exploitation

Identifies potential attempts to execute malicious commands via a known git remote code execution vulnerability CVE-2025-48384.

elastic-protections high eql

Access to Windows Passwords Vault via Powershell

Identifies access attempt to the Windows Passwords Vault via Powershell commands. Adversaries may acquire credentials from Vault files.

elastic-protections high eql

Microsoft Office AddIn Loaded

Detects attempts to load an unsigned executable from known Microsoft Office add-ins directories. Adversaries may leverage Office Addins for persistence.

elastic-protections high eql

Potential Evasion via Inline Execute Assembly

Identifies attempts to load the Microsoft Common Language Runtime from a suspicious memory followed by an egress network connection.

elastic-protections high eql

Potential Reverse Shell via Powershell

Identifies the execution of a PowerShell script that may allow remote commands execution via TCP, UDP or ICMP reverse shell.

elastic-protections high eql

Common Language Runtime Loaded via an Unsigned Module

Identifies the load of the Microsoft Common Language Runtime DLL CLR.dll from a recently dropped unsigned DLL.

elastic-protections high eql

Execution from a Downloaded ISO File

Identifies the execution of a process from a downloaded ISO file. Attacker may abuse ISO files to deliver malicious programs.

elastic-protections high eql

Potential Lateral Movement via SMBExec

Identifies suspicious service execution via Windows Command Shell which may indicate lateral movement attempt via known offensive testing tool like SMBExec.

elastic-protections high eql

Potential VSingle Malware Infection

Identifies the execution traces of the Vsingle malware. Vsingle is a Linux trojan that attempts to retrieve C2 servers information from GitHub.

elastic-protections high eql

Suspicious NetSupport Execution

Identifies a suspicious execution of NetSupport remote access software from non-default paths, issuing a DNS query to a non-standard NetSupport domain.

elastic-protections high eql

Suspicious Svchost Registry Modification

Identifies modification of the Windows shared services registry key. Adversaries may use this technique to maintain persistence or run with System privileges.

elastic-protections high eql

Unusual LDAP Client Process

Identifies an unusual Windows native process performing LDAP activity. This may indicate an attempt to perform domain discovery using the LDAP protocol.

elastic-protections high eql

Potential CVE-2025-33053 Exploitation

Identifies a suspicious Diagnostics Utility for Internet Explorer child process. This may indicate the successful exploitation of the vulnerability CVE-2025-33053.