Search and filter across all detection sources
246 rules
Potential DANTE Spyware Execution
Identifies potential execution of a commercial spyware.
Suspicious API Call from a PowerShell Script
Detects PowerShell scripts calling dual-purpose Win32 APIs.
Privilege Escalation via SeImpersonatePrivilege
Identifies a privilege escalation attempt from an account with the SeImpersonatePrivilege to full System privileges.
Suspicious XPC Service Child Process
Detects an abnormal child process of a XPC service running from a suspicious location.
Windows Socket Creation from Stomped Module
Identifies the creation of a Windows network socket from a potentially stomped module.
PowerShell Empire Script Execution
Identifies the execution of PowerShell scripts with keywords from known open source Empire penetration testing tool.
Attempt to Disable Windows Defender Services
Identifies attempt to stop or disable the Windows Defender services from an unusual parent process.
Potential Defense Evasion via Filter Manager Control Program
Identifies attempt to unload a security driver via the Filter Manager Control Program.
Shellcode Execution from Low Reputation Module
Identifies attempt to allocate or execute Shellcode from a module with low or unknown reputation.
Suspicious Python Script Interpreter
Identifies the execution of a recently dropped executable that loads python libraries to interact with Windows APIs.
Potential PowerShell Empire Execution
Identifies the execution of PowerShell with suspicious argument values. This behavior is often observed during malware installation leveraging PowerShell.
Suspicious Remote Memory Allocation
Identifies attempts to allocate remote memory with RWX permissions, this behavior is often associated with remote process injection preparation.
Potential Git CVE-2025-48384 Exploitation
Identifies potential attempts to execute malicious commands via a known git remote code execution vulnerability CVE-2025-48384.
Access to Windows Passwords Vault via Powershell
Identifies access attempt to the Windows Passwords Vault via Powershell commands. Adversaries may acquire credentials from Vault files.
Microsoft Office AddIn Loaded
Detects attempts to load an unsigned executable from known Microsoft Office add-ins directories. Adversaries may leverage Office Addins for persistence.
Potential Evasion via Inline Execute Assembly
Identifies attempts to load the Microsoft Common Language Runtime from a suspicious memory followed by an egress network connection.
Potential Reverse Shell via Powershell
Identifies the execution of a PowerShell script that may allow remote commands execution via TCP, UDP or ICMP reverse shell.
Common Language Runtime Loaded via an Unsigned Module
Identifies the load of the Microsoft Common Language Runtime DLL CLR.dll from a recently dropped unsigned DLL.
Execution from a Downloaded ISO File
Identifies the execution of a process from a downloaded ISO file. Attacker may abuse ISO files to deliver malicious programs.
Potential Lateral Movement via SMBExec
Identifies suspicious service execution via Windows Command Shell which may indicate lateral movement attempt via known offensive testing tool like SMBExec.
Potential VSingle Malware Infection
Identifies the execution traces of the Vsingle malware. Vsingle is a Linux trojan that attempts to retrieve C2 servers information from GitHub.
Suspicious NetSupport Execution
Identifies a suspicious execution of NetSupport remote access software from non-default paths, issuing a DNS query to a non-standard NetSupport domain.
Suspicious Svchost Registry Modification
Identifies modification of the Windows shared services registry key. Adversaries may use this technique to maintain persistence or run with System privileges.
Unusual LDAP Client Process
Identifies an unusual Windows native process performing LDAP activity. This may indicate an attempt to perform domain discovery using the LDAP protocol.
Potential CVE-2025-33053 Exploitation
Identifies a suspicious Diagnostics Utility for Internet Explorer child process. This may indicate the successful exploitation of the vulnerability CVE-2025-33053.