| Abnormal Authentication & Access | app-activity ↳microsoft-sysmon-str-driver-load-6 ↳microsoft-sysmon-json-driver-load-6 ↳microsoft-sysmon-json-kv-file-time-modify-timechanged ↳microsoft-sysmon-xml-process-pipe-create-success-18 ↳microsoft-sysmon-xml-process-pipe-create-17
app-login ↳microsoft-sysmon-cef-driver-load-success-driverloaded ↳microsoft-sysmon-kv-endpoint-notification-success-255 ↳microsoft-sysmon-xml-registry-12 ↳microsoft-sysmon-cef-registry-success-sysmonregkey ↳microsoft-sysmon-json-registry-12 ↳microsoft-sysmon-kv-registry-success-12 ↳microsoft-sysmon-xml-registry-12 ↳microsoft-sysmon-cef-registry-success-sysmonregkey ↳microsoft-sysmon-json-registry-12 ↳microsoft-sysmon-kv-registry-success-12
audit-log-clear ↳microsoft-sysmon-xml-file-time-modify-2 ↳microsoft-sysmon-cef-file-time-modify-success-creationtimechanged ↳microsoft-sysmon-xml-file-time-modify-2-1
authentication-successful ↳microsoft-sysmon-xml-process-close-5-1 ↳microsoft-sysmon-kv-process-close-success-processterminated ↳microsoft-sysmon-json-process-close-terminated ↳microsoft-sysmon-cef-process-close-success-processterminated ↳microsoft-sysmon-kv-process-close-terminated-1 ↳microsoft-sysmon-xml-process-close-5 ↳microsoft-sysmon-json-log-4 ↳microsoft-sysmon-cef-log-success-servicestatechanged
remote-logon ↳microsoft-sysmon-json-log-4 ↳microsoft-sysmon-cef-log-success-servicestatechanged ↳microsoft-sysmon-cef-process-thread-create-success-createremotethread
| T1021 - Remote Services T1078 - Valid Accounts T1078.002 - T1078.002 T1078.003 - Valid Accounts: Local Accounts T1133 - External Remote Services
| |
| Account Manipulation | app-activity ↳microsoft-sysmon-str-driver-load-6 ↳microsoft-sysmon-json-driver-load-6 ↳microsoft-sysmon-json-kv-file-time-modify-timechanged ↳microsoft-sysmon-xml-process-pipe-create-success-18 ↳microsoft-sysmon-xml-process-pipe-create-17
process-created ↳microsoft-sysmon-cef-process-create-success-sysmoncreateprocess
| T1003 - OS Credential Dumping T1003.003 - T1003.003 T1021.003 - T1021.003 T1059.001 - Command and Scripting Interperter: PowerShell T1059.003 - T1059.003 T1078 - Valid Accounts T1098 - Account Manipulation T1098.002 - Account Manipulation: Exchange Email Delegate Permissions T1136 - Create Account T1136.001 - Create Account: Create: Local Account T1218.010 - Signed Binary Proxy Execution: Regsvr32 T1531 - Account Access Removal T1559.002 - T1559.002
| |
| Cryptomining | process-created ↳microsoft-sysmon-cef-process-create-success-sysmoncreateprocess
| T1496 - Resource Hijacking
| |
| Data Exfiltration | file-write ↳microsoft-sysmon-json-file-write-success-2
process-created ↳microsoft-sysmon-cef-process-create-success-sysmoncreateprocess
| T1003 - OS Credential Dumping T1040 - Network Sniffing T1041 - Exfiltration Over C2 Channel T1048 - Exfiltration Over Alternative Protocol T1059 - Command and Scripting Interperter T1071.001 - Application Layer Protocol: Web Protocols T1071.002 - Application Layer Protocol: File Transfer Protocols T1071.004 - Application Layer Protocol: DNS T1552.001 - T1552.001 T1560 - Archive Collected Data T1572 - Protocol Tunneling TA0002 - TA0002
| |
| Phishing | process-created ↳microsoft-sysmon-cef-process-create-success-sysmoncreateprocess
| T1566.001 - T1566.001
| |
| Next Page -->> | | | |