Browse Rules

Search and filter across all detection sources

1,897 rules

anvilogic high other

1 or 2 Character Executable [snowflake-crowdstrikefdr_process]

Adversaries have been known to occasionally use executable files named with only 1 or 2 word characters. - Threat Actor Association: Lotus Blossom, OilRig, Trigona, Volt Typhoon

anvilogic high spl

1 or 2 Character Executable [splunk-winevent]

Adversaries have been known to occasionally use executable files named with only 1 or 2 word characters. - Threat Actor Association: Lotus Blossom, OilRig, Trigona, Volt Typhoon

anvilogic high other

3CXDesktopApp.exe Execution [snowflake-crowdstrikefdr_process]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic high spl

3CXDesktopApp.exe Execution [splunk-edr]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic high spl

3CXDesktopApp.exe Execution [splunk-sysmon]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic high spl

3CXDesktopApp.exe Execution [splunk-winevent]

Malicious activity has been detected on March 29, 2023, originating from a legitimate and signed binary called 3CXDesktopApp, which is a softphone application from 3CX. This malicious activity includes beaconing to infrastructure controlled by the attackers, deployment of additional payloads in the second stage, and in a few cases, direct interaction by the attackers with the system. - Campaign: SmoothOperator - Threat Actor Association: Lazarus Group (aka Labyrinth Chollima)

anvilogic medium other

Abuse EQNEDT32.EXE [snowflake-crowdstrikefdr_process]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic medium spl

Abuse EQNEDT32.EXE [splunk-edr]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic medium spl

Abuse EQNEDT32.EXE [splunk-sysmon]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic medium spl

Abuse EQNEDT32.EXE [splunk-winevent]

Detects potential malicious Microsoft Office payload (CVE-2017-11882 or CVE-2018-0798) on host. Equation Editor. -- Threat Actor Association: Bitter APT, Lotus Blossom, SideWinder, TA428, Tonto Team - Software Association: Soul

anvilogic high other

Access Common Package Config file [snowflake-crowdstrikefdr_process]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-edr]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-powershell]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-sysmon]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-unix]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high spl

Access Common Package Config file [splunk-winevent]

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. An Adversary with access could identify or modify configuration of packages in order to execute code and evade defenses.

anvilogic high other

Account Discovery Commands - Windows [snowflake-crowdstrikefdr_process]

Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Atomics T1087.001 Test #8 Atomics T1087.001 Test #9 Atomics T1087.001 Test #10 Atomics T1087.002 Test #1 Atomics T1087.002 Test #2 Atomics T1087.002 Test #3 Atomics T1087.002 Test #9

anvilogic critical other

Account Password Changed from Command Line - Windows [snowflake-crowdstrikefdr_process]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic critical spl

Account Password Changed from Command Line - Windows [splunk-edr]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic critical spl

Account Password Changed from Command Line - Windows [splunk-powershell]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic critical spl

Account Password Changed from Command Line - Windows [splunk-winevent]

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials) to remove access to accounts. This use case detects commands involving the use of net.exe to change account passwords. Atomics T1531 Test #1

anvilogic high other

Account set to active via Net.exe [snowflake-crowdstrikefdr_process]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2

anvilogic high spl

Account set to active via Net.exe [splunk-edr]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2

anvilogic high spl

Account set to active via Net.exe [splunk-sysmon]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2

anvilogic high spl

Account set to active via Net.exe [splunk-winevent]

Adversaries may obtain and abuse credentials of a default or disabled account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Default accounts are those that are built-into an OS, such as the Guest or Administrator accounts on Windows systems. -- Threat Actor Association: Unfading Sea Haze - Software Association: RansomHub -- Atomics T1078.001 Test#1 Atomics T1078.001 Test#2 Atomics T1564 Test#2