Security Content c2402.1 Release Notes
March 26, 2025 · View on GitHub
These Release Notes document security content updates from content package c2304.1_63.6 to c2402.1.
The security content updates listed below include changes to the following areas:
In the lists below, each item represents a specific model, or rule that has been added, updated, or deprecated. To facilitate finding every data source where the changed content items are referenced, a content library query has been created for each changed parser, model, or rule. To view the results of each query, click on the link for the relevant content item.
Note: Rules that are disabled or have a score of 0 are not included in the lists below.
Models
New Models
-
A-EPA-Powershell-Invoke-WebRequest-Domain – Domains called with Powershell executions using invoke-webrequest for the asset in the organization.
-
A-EPA-Powershell-Invoke-WebRequest – Powershell executions using invoke-webrequest for the asset in the organization.
Updated Models
-
EPA-PDir – Process executable directories in the organization
-
EPA-PG-PS – Powershell executions for the peer group
-
EPA-PU-PS – Powershell executions for the user
-
EPA-Powershell-Invoke-WebRequest-Domain – Domains called with Powershell executions using invoke-webrequest for the organization
-
EPA-Powershell-Invoke-WebRequest – Powershell executions using invoke-webrequest for the user in the organization
Deprecated Models
There are no deprecated models in this release.
Rules
New Rules
There are no new rules in this release.
Updated Rules
-
A-AC-DhU-system-A – Abnormal account creation by system account on asset
-
A-AC-DhU-system-F – First account creation by system account on asset
-
A-AD-Diagnostic-Tool – Invocation of Active Directory Diagnostic Tool (ntdsutil.exe) on this asset
-
A-AE-SwSh-F – New server hostname using NTLM authentication in the organization.
-
A-ALERT-Correlation-Rule – Correlation rule alert on asset
-
A-ALERT-Critical – Security Alert on a critical asset
-
A-ALERT-DL – DL Correlation rule alert on asset
-
A-ALERT-Log4j – Alert associated with an exploitation or post exploitation as seen with Log4j Vulnerability was detected.
-
A-ALERT-Other – Alert on asset
-
A-ALERT – Security alert on asset
-
A-APT-Hurricane-Panda – Artifacts used by the APT group 'Hurricane Panda' have been observed on this asset
-
A-ATP-Tool-FGDump – Malicious exe/dll.
-
A-ATP-Tool-PSTGDump – Malicious pstgdump.exe was run from a temp folder on this asset.
-
A-AccountDiscovery – Local accounts were enumerated on this asset
-
A-Applocker-Bypass – Execution of executables that can be used to bypass Applocker on this asset
-
A-Archer – 'Archer' malware executed on this asset
-
A-AutoRun-Modification – AutoRun Keys modified using reg.exe on this asset
-
A-Baby-Shark-Activity – Activity related to Baby Shark malware has been found on this asset.
-
A-Base64-CommandLine – Base64 string in command line execution on this asset
-
A-Base64-Powershell-CmdLine-Keywords – Base64 encoded strings were found in hidden malicious Powershell command lines on this asset.
-
A-Bginfo-App-Whitelisting – VBscript referenced in a .bgi file was executed on this asset.
-
A-Bitsadmin-Download – Bitsadmin was used to download a file on this asset.
-
A-Bypass-UAC-CMSTP – Child process of automatically elevated instance of Microsoft Connection Manager Profile Installer (cmstp.exe) was created via command line on this asset.
-
A-CDB-App-Whitelisting – 64-bit shellcode was launched using cdb.exe on this asset.
-
A-CMD-Spawn-From-Office – A command line executable was spawned from an Office application on this asset
-
A-CP-Sensitive-Files – Copying sensitive files with credential data on this asset
-
A-CSC-Suspicious-Folder – Csc.exe spawned from suspicious folder on this asset
-
A-CSC-Suspicious-Parent-Process – Suspicious parent process for csc.exe, possible payload delivery on this asset
-
A-CSharp-Interactive-Console – Execution of CSharp interactive console by PowerShell on this asset.
-
A-CertUtil-Suspicious-Usage – The 'certutil' Windows utility was used with known suspicious command line flags on this asset
-
A-Certutil-Encode – Certutil commands to encode files were used on this asset.
-
A-Cmdkey-Cred-Recon – Cmdkey Cached Credentials Recon on this asset
-
A-CreateMiniDump-Hacktool – CreateMiniDump Hacktool detected on this asset.
-
A-DCOMActivation-Known – Remote DCOM activation under DcomLaunch service on this asset.
-
A-DCOMFailure-Known – Remote DCOM activation failure on this asset.
-
A-DCSync – Possible DCSync attack detected
-
A-DLL-AppData – DLL loaded from 'AppData(slash)Local' path on this asset
-
A-DLL-ULOAD-EquationGroup – A known 'Equation Group' artifact was observed on this asset
-
A-DNS-ABSum-A – Abnormal amount of data of DNS queries has been sent from this asset
-
A-DNS-AQCount-A – Abnormal number of DNS queries from this asset
-
A-DNS-AQNXCount-A – Abnormal number of DNS queries to NX domains from this asset
-
A-DNS-DGADOM-QUERY – DNS query for DGA domain from this asset
-
A-DNS-DGADOM-RESPONSE – DNS query for DGA domain was successful from this asset
-
A-DNS-Exfiltration-Tools-Exec – Well-known DNS Exfiltration tools were executed on this asset.
-
A-DNS-OBSum-A – Abnormal amount of data of DNS queries in the organization
-
A-DNS-OQNXCount-A – Abnormal number of DNS queries to NX domains for organization
-
A-DNS-SW-MALDOM – DNS query for SUNBURST malware from this asset
-
A-DNS-ZBSum-A – Abnormal amount of data of DNS queries in the zone
-
A-DNX-App-Whitelisting – C# code located in consoleapp folder was executed on this asset.
-
A-Defrag-Deactivation – Scheduled defragmentation task was deactivated on this asset.
-
A-Devtoolslauncher-Binary – Devtoolslauncher.exe has executed a binary on this asset
-
A-DomainTrust-Discovery – Enumeration of Windows Domain Trusts identified on this asset
-
A-DotNET-URL – DotNET command line contains remote file on this asset.
-
A-Dtrack – Known banking malware, Dtrack, observed on this asset
-
A-Dxcap-Possible-Subprocess – Dxcap.exe was executed on this asset.
-
A-EPA-DLL – Dll loaded from a temp folder via PowerShell on this asset
-
A-EPA-HP-CrontabMod-A – Abnormal execution of process on asset and the command of the process is crontab modification
-
A-EPA-HP-CrontabMod-F – First execution of process on asset and the command of the process is crontab modification
-
A-EPA-OH-CENUM-A – Abnormal for this asset to run credential enumeration tool
-
A-EPA-OH-CENUM-F – Asset running credential enumeration tool for the first time
-
A-EPA-Rundll-FTP-A – Abnormal rundll activity for FTP firewall port blocking/unblocking
-
A-EPA-Rundll-FTP-F – First rundll activity for FTP firewall port blocking/unblocking on the asset.
-
A-EPA-UP-CENUM – Abnormal number of unique credential enumeration tools run on this asset
-
A-EPA-USF-F – First process per service name for asset
-
A-EPA-ZP-A – Abnormal execution of process for the asset in this zone
-
A-EPA-ZP-F – First execution of process for the asset in this zone
-
A-ETW-Trace-Disable – Event tracing has been disabled, possible logging evasion on this asset
-
A-Emotet – A process associated with the Emotet malware has been executed on this asset
-
A-Empire-Monkey – EmpireMonkey APT activity was found on this asset.
-
A-EquationEditor-Droppers – Possible 'Eqnetd32.exe' exploit usage on this asset
-
A-EventLog-Tamper – EventLog has been tampered with on this asset
-
A-Exec-Outlook-Temp – A suspicious program was executed in the Outlook temp folder on this asset.
-
A-Executable-Suspicious-Folder – A process has been run from a binary located in a suspicious folder on this asset
-
A-Exfil-Tunnel-Tools-Exec – Tools known for data exfiltration and tunneling were executed on this asset.
-
A-FA-LSASS – Possible Mimikatz attack on this asset by a user process
-
A-FA-StartupFolder-OH-A – Abnormal addition of a program to the startup folder on the asset
-
A-FA-StartupFolder-OH-F – A program was added to the startup folder for the first time on this asset
-
A-FL-MULTI-USERS-SRC – The same host failed to login to multiple users
-
A-FW-UMWorkerProcess-FileName-F – First time file creation for Exchange Unified Messaging service UMWorkerProcess.exe
-
A-File-Folder-Perm-Mod – The permissions of a file or folder were modified on this asset.
-
A-FileType-Association-Change – File Association changed for this file extension on this asset
-
A-Firewall-Disabled-Netsh – Windows firewall was turned off using netsh commands on this asset.
-
A-Formbook – Possible Formbook usage on this asset
-
A-Fsutil-Sus-Invocation – Suspicious parameters of fsutil were detected on this asset.
-
A-GRAB-REG-HIVES – Grabbing Sensitive Hives via Reg Utility on this asset
-
A-HH-EXE-CHM – HH.exe usage, possible code execution on this asset
-
A-Hanword-Subprocess – Suspicious processes spawned by the Hangul word processor on this asset
-
A-IDS-HdPort-A – Abnormal network alert on port for asset
-
A-IDS-HdPort-F – First network alert on port for asset
-
A-IDS-LZAN-A – Abnormal network alert (by name) for zone
-
A-IDS-LZAN-F – First network alert (by name) for zone
-
A-IDS-OAN-A – Abnormal network alert (by name) for organization
-
A-IDS-OAN-F – First network alert (by name) for organization
-
A-IDS-OLA-A – Abnormal network alert for asset for organization
-
A-IDS-OLA-F – First network alert on asset with no previous alerts for organization
-
A-IDS-OLZ-A – Abnormal network alert for zone in the organization
-
A-IDS-OLZ-F – First network alert for zone in the organization
-
A-IDS-OdPort-A – Abnormal network alert on port for organization
-
A-IDS-OdPort-F – First network alert on port for organization
-
A-IDS-SERVER – First or Abnormal network alert in server zone
-
A-IDS-ZLA-A – Abnormal network alert for asset for zone
-
A-IDS-ZLA-F – First network alert on asset with no previous alerts for zone
-
A-IDS-dZdPort-A – Abnormal network alert on port for zone
-
A-IDS-dZdPort-F – First network alert on port for zone
-
A-INTERACTIVE-JOB – Interactive job from the 'at' program seen on this asset
-
A-Impacket-Lateral-Detection – Activity related to Impacket framework using wmiexec, dcomexe, or smbexec processes via command line have been found on this asset.
-
A-Indirect-Cmd-Exec – An indirect command was executed via Program Compatibility Assistant pcalua.exe or forfiles.exe on this asset.
-
A-JPanda-Activity – Judgement Panda Exfil Activity detected on this asset
-
A-JPanda-RUS-G-Activity – Judgement Panda Exfil Activity- Russian group activity detected on this asset
-
A-Java-Remote-Dubugging – Java executed with remote debugging enabled on this asset
-
A-KL-ToEt-Roast – Suspicious or weak encryption type used for obtaining the kerberos TGTs using non kerberos service for this asset
-
A-KnownFirewallDisable-Log4j – FireWall disable arguments via command line were detected on this asset.
-
A-Koadic-Tool-Usage – 'Koadic' attacker tool usage on this asset
-
A-LSASS-Mem-Dump – LSASS Memory Dumping detected on this asset
-
A-MMC-Spawn-Win-Shell – MMC (Microsoft Management Console) started a Windows command line executable on this asset.
-
A-MSHTA-SVCHOST – Mshta.exe spawned by svchost.exe, possible lateral movement on this asset
-
A-MSTSC-RDP-Hijack – MSTSC Shadowing, possible RDP session hijack/shadowing of session on this asset
-
A-Microsoft-Workflow-Compiler – Microsoft Workflow Compiler was invoked on this asset.
-
A-Mod-Boot-Config – Boot configuration data was deleted using the bcdedit command on this asset.
-
A-Mshta-CMD-Spawn – Mshta.exe has executed a command line executable on this asset
-
A-Mshta-Javascript – Mshta.exe has executed a javascript related command on this asset
-
A-Mshta-Script – Mshta.exe .NET code execution on this asset.
-
A-MsiExec-Web-Install – A suspicious msiexec process was started with web addresses as a parameter on this asset.
-
A-Mustang-Panda-Dropper – Possible Mustang Panda droppers execution on this asset.
-
A-NET-EXE-Recon – Enumeration and reconnaissance activities were performed on this asset
-
A-NET-HCountry-Outbound-WEB-A – Abnormal web browsing communication country for asset
-
A-NET-HCountry-Outbound-WEB-F – First web connection to this country from asset
-
A-NET-OCountry-Outbound-WEB-A – Abnormal web browsing connection country for the organization
-
A-NET-OCountry-Outbound-WEB-F – First web browsing connection to this country from organization
-
A-NET-TOR-Inbound – Inbound connection from a known TOR IP
-
A-NET-TOR-Outbound – Outbound connection to a known TOR IP
-
A-NETF-HCountry-Outbound-WEB-A – Web browsing connection to abnormal country for asset has failed
-
A-NETF-HCountry-Outbound-WEB-F – First failed web browsing connection to this country from asset
-
A-NETF-TOR-Outbound – Outbound failed connection to a known TOR IP
-
A-NETFLOW-BitTorrent – Asset accessed BitTorrent application
-
A-NETFLOW-RDP-F – Asset receiving RDP connection for the first time
-
A-NETFLOW-sH25Bytes-Outbound – Abnormal amount of data using SMTP protocol has been sent outbound
-
A-NETFLOW-sH443Bytes-Outbound – Abnormal amount of data using HTTPS protocol has been sent outbound
-
A-NETFLOW-sH53Bytes-Outbound – Abnormal amount of data using DNS protocol has been sent outbound
-
A-NETFLOW-sH80Bytes-Outbound – Abnormal amount of data using HTTP protocol has been sent outbound
-
A-NETFLOW-sHFTPBytes-Outbound – Abnormal amount of data using FTP protocol has been sent outbound
-
A-NSniff-Cred – Potential network sniffing was observed on this asset.
-
A-NTDS-Access-A – The NTDS database was accessed from a non default location on this asset.
-
A-NTDS-Access-F – The NTDS database was accessed from a new location on this asset.
-
A-NTDS-Access – The NTDS database was accessed from a non default location without 'ntds.dit' in the file path on this asset.
-
A-NTDS-Shadow-Copy1 – The NTDS database changed location to a shadowcopy using 'ntds.dit' and 'harddiskvolumeshadowcopy' in the file path on this asset.
-
A-NTDS-Shadow-Copy2 – The NTDS database changed location to a shadowcopy using 'harddiskvolumeshadowcopy' in the file path on this asset.
-
A-NTLM-WsSrv – Hostname contains workstation or server
-
A-NTLM-mismatch – Mismatch between logged and resolved hostnames
-
A-Netsh-Connections-Win-Firewall – Netsh commands were used to allow incoming connections by Port or Application on Windows Firewall on this asset.
-
A-Netsh-Port-Fwd – Netsh commands were used to configure port forwarding on this asset.
-
A-Netsh-RDP-Port-Fwd – Netsh commands used to configure port forwarding for port 3389, used for RDP, were detected on this asset.
-
A-New-ScheduledTask – New scheduled task created using schtasks.exe on this asset
-
A-New-Service – New windows service created using sc.exe on this asset
-
A-Non-Interactive-Powershell – Non-Interactive Powershell activity was found on this asset.
-
A-NotPetya-Activity – NotPetya Ransomware Activity detected on this asset
-
A-Odbcconf-DLL-Load – DLL loaded on this asset via odbcconf.exe execution.
-
A-Office-Payload-Download – Possible malicious payload download via Microsoft Office binaries on this asset
-
A-OpenWith-Exec-Cmd – OpenWith.exe executed via command line on this asset.
-
A-Operation-Wocao-Activity – Possible Operation-Wocao APT activity on this asset, suspicious command line arguments
-
A-Ordinal-Rundll32-Call – Suspicious calls of DLLs in rundll32.dll exports by ordinal on this asset.
-
A-PC-InstallUtil-dll-A – Abnormal dll file usage by InstallUtil.exe on this asset.
-
A-PC-InstallUtil-dll-F – First time dll file usage by InstallUtil.exe on this asset.
-
A-PC-InstallUtil-exe-A – Abnormal for exe file usage by InstallUtil.exe on this asset.
-
A-PC-InstallUtil-exe-F – First time exe file usage by InstallUtil.exe on this asset.
-
A-PC-MSBuild-Csproj-F – First time csproj file usage by MSBuild.exe on this asset.
-
A-PC-MSBuild-xml-F – First time xml file usage by MSBuild.exe on this asset.
-
A-PC-Mshta-Hta-A – Abnormal hta file usage by Mshta.exe on this asset.
-
A-PC-Mshta-Hta-F – First time hta file usage by Mshta.exe on this asset.
-
A-PC-ParentName-ProcessName-DCOM-A – Abnormal child process creation for DCOM associated process on the asset.
-
A-PC-ParentName-ProcessName-DCOM-F – First time child process creation for DCOM associated process on this asset.
-
A-PC-ParentName-W3WP-F – First time child process creation for Exchange web front-end process w3wp.exe
-
A-PC-Procdump-LsassDump – Procdump was executed with lsass dump command line parameters on this asset.
-
A-PC-Regsvr32-sct-A – Abnormal sct file usage by Regsvr32.exe on the asset.
-
A-PC-Regsvr32-sct-F – First time sct file usage by Regsvr32.exe on this asset.
-
A-PC-Rundll-LsassDump – Rundll32 was run with minidump via commandline on this asset.
-
A-POSS-SPN-ENUMERATION – Possible SPN Enumeration on this asset
-
A-PSExec-Rename – PS Exec used on this asset
-
A-PSR-Screenshot – Psr.exe was used to take a screenshot on this asset
-
A-PTH-ALERT-dH – Possible pass the hash attack by this user account
-
A-PTH-ALERT-sH-Failed – Failed pass the hash attack with keylength of 0 in NTLM event and a 'null' sid on this source host.
-
A-PTH-ALERT-sH-Possible – Possible pass the hash attack with keylength of 0 in NTLM event and a 'null' sid on this source host.
-
A-PTH-ALERT-sH – Possible pass the hash attack from this source host
-
A-Ping-Hex-IP – A ping command used a hex decoded IP address on this asset.
-
A-PlugX-DLL-Sideloading – DLL loaded from suspicous location on this asset, typically seen by the PlugX malware family
-
A-Possible-PrivEsc-SvcPerms – Possible privilege escalation using weak service permissions on this asset
-
A-PowerShell-BITS-Job – BITS job via PowerShell was created on this asset.
-
A-Powershell-ADS – Powershell invoked using 'Alternate Data Stream' on this asset
-
A-Powershell-AMSI-Bypass-NET – Request to amsiInitFailed that can be used to disable AMSI Scanning was found on this asset.
-
A-Powershell-AudioCapture – Powershell has recorded external audio on this asset
-
A-Powershell-CMDLETS – Malicious PowerShell script was used via get cmdlets function of PowerShell on the asset
-
A-Powershell-Exec-DLL – PowerShell Strings applied to rundllas.exe seen in PowerShdll.dll on this asset.
-
A-Powershell-Script-AppData – Powershell was invoked in a suspicious command line execution with reference to an AppData folder on this asset.
-
A-PrivEsc-SchedTask-LegacyDACL – Possible privilege escalation using a legacy task file on this asset
-
A-Proc-Dump-Comsvcs – Process Dump via Rundll32 and Comsvcs.dll detected on this asset
-
A-Procdump-Comsvcs-DLL – Process Dump via Comsvcs DLL on this asset
-
A-RA-LogonRunKeys-OH-A – Abnormal addition of a program to the registry run key on this asset
-
A-RA-LogonRunKeys-OH-F – A program was added to the registry run key on this asset at the first time
-
A-RASdial-Activity – Process was executed on this asset with rasdial as a command line argument.
-
A-Regsvr32-Suspicious-Cmd – Suspicious command line arguments related to regsvr32.exe have been observed on this asset.
-
A-Remote-Powershell-Session – Remote Powershell session was detected by monitoring for wsmprovhost as a parent or child process on this asset.
-
A-Rubeus-CMD-Tool – Command line parameters used by Rubeus hack tool detected on this asset
-
A-RunDll32-ControlPanel – RunDll32.exe run from the control panel on this asset
-
A-SA-AsU-A – Abnormal access of admin share on the asset
-
A-SA-AsU-F – First access of admin share on asset
-
A-SA-OH-A – Abnormal admin share on asset in organization
-
A-SA-OH-F – First admin share on asset for organization
-
A-SA-OU-A – Abnormal admin share access to asset for the user in the organization
-
A-SA-OU-F – First admin share access to asset for this user in the organization
-
A-SA-ZH-A – Abnormal admin share on asset for zone
-
A-SA-ZH-F – First admin share on asset in the zone
-
A-SEQ-UH-16-L – Exceeded number of failed logons for the asset (L)
-
A-SEQ-UH-16-M – Exceeded number of failed logons for the asset (M)
-
A-SEQ-UH-16-S – Exceeded number of failed logons for the asset (S)
-
A-SETUPCOMPLETE-PRIV-ESC – Privilege escalation attempt using the SetupComplete.cmd object on this asset
-
A-SecX-Tool-Exec – SecurityXploded Tool execution detected on this asset
-
A-ServiceName-ServiceCmdline-A – Abnormal binary command line for this service
-
A-ServiceName-ServiceCmdline-F – First time binary command line for this service on this asset.
-
A-ServicePath-Modification – Suspicious service path identified on this asset
-
A-ShadowCP-OSUtilities – Shadow Copies Creation Using Operating Systems Utilities on this asset
-
A-ShadowCP-SymLink – Shadow Copies Access via Symlink on this asset
-
A-Shim-Installation – Possible installation of a 'shim' using sdbinst.exe on this asset
-
A-SoundRecorder-AudioCapture – SoundRecorder has recorded external audio on this asset
-
A-Squibly-Two – A WMI SquiblyTwo Attack with possibly renamed WMI by looking for imphash was detected on this asset.
-
A-Sus-Double-Extension – An .exe extension was used after a different non-executable file extension on this asset.
-
A-Sus-Encoded-PS-CmdLine – Suspicious Powershell process was started with base64 encoded commands on this asset.
-
A-Sus-GUP-Usage – Execution of the Notepad++ updater in a suspicious directory on this asset.
-
A-Sus-MsiExec-Directory – Suspicious msiexec process started in an uncommon directory on this asset.
-
A-Sus-Powershell-Invocation-Parent-Proc – Suspicious Powershell invocation from interpreters or unusual programs on this asset.
-
A-Sus-Powershell-Param – Powershell was invoked with a suspicious parameter substring on this asset.
-
A-Sus-Procdump – Suspicious Use of Procdump on this asset.
-
A-Sus-Svchost-Process – A suspicious svchost process was started on this asset.
-
A-Suspicious-ControlPanel – Control Panel commandlets loaded outside the default directory on this asset
-
A-Suspicious-DAT – A suspicious .dat file used, possible APT activity on this asset
-
A-Suspicious-GetSystem-Usage – Possible Meterpeter/Cobalt Strike usage of GetSystem on this asset
-
A-Suspicious-IIS-Modules – Native-Code modules for IIS installed via command line on this asset
-
A-Suspicious-Persistence – Suspicious 'schtask' creation, possible attack tool usage on this asset
-
A-Suspicious-RDP-TSCON – Suspicious usage of RDP using tscon.exe on this asset
-
A-Suspicious-Shell-Child-Process – Windows shell has spawned a suspicious process on this asset
-
A-Svchost-Suspicious-Launch – Svchost.exe has launched without any command line arguments on this asset
-
A-Sys-File-Exec-Anomaly – A Windows program executable was started in a suspicious folder on this asset.
-
A-Sysmon-Driver-Unload – Possible Sysmon driver unloaded on this asset.
-
A-TSCON-LocalSystem – Tscon.exe was executed as Local System on this asset
-
A-Tap-Installer – TAP software was installed on this asset.
-
A-Taskmgr-Local-System – A taskmgr.exe process was executed in the context of LOCAL_SYSTEM
-
A-Taskmgr-as-Parent – A process was created from Windows task manager on this asset.
-
A-TasksFolder-Evasion – The 'tasks' directory was observed in a file creation command on this asset
-
A-Terminal-Svc-Proc-Spawn – Process spawned by the terminal service server on this asset.
-
A-Trickbot-Recon – Trickbot malware domain recon activity on this asset
-
A-TrojanLoader – Possible Trojan Loader activity on this asset
-
A-TropicTrooper-APT – Possible TropicTrooper APT artifacts observed on this asset
-
A-TurlaGroup-LateralMovement – Artifacts from the ATP 'Turla Group' have been observed on this asset
-
A-UAC-Bypass-COM-OBJECT – Windows UAC bypass using COM object access on this asset
-
A-UAC-Bypass-Fodhelper – UAC Bypass using fodhelper.exe on this asset
-
A-UAC-Bypass-Wsreset – UAC Bypass using wsreset.exe on this asset
-
A-UAC-IE-INVOKE – Windows UAC consent dialogue was used to invoke an Internet Explorer process running as Local SYSTEM
-
A-Unauthorized-MBR-Mods – Bcdedit.exe has signs of malicious unauthorized usage on this asset.
-
A-UserProcess-Spawned-FromOffice – An executable running under the 'Users' path has been spawned from an Office application on this asset
-
A-WA-F – Audit log has been cleared on this asset
-
A-WEB-ALERT – Asset attempted access to a domain with malicious reputation
-
A-WEB-Count-A – Abnormal number of failed web requests from this asset
-
A-WEB-DC – Web activity event on a Domain Controller
-
A-WEB-DGA – Asset has accessed a domain that has been identified as DGA
-
A-WEB-DynamicDNS – Asset attempted access to a domain generated using Dynamic DNS service
-
A-WEB-GETBytes-In – Abnormal amount of data had been downloaded from the web by this asset
-
A-WEB-HA-F – First web activity event on asset
-
A-WEB-IOC – Indicator of Compromise (IOC) found in asset's web activity
-
A-WEB-IP-Country-A – Abnormal direct access to an IP address by the asset belonging to an abnormal country for the asset to access
-
A-WEB-IP-Country-F – Asset has directly browsed to an IP address in a country never before accessed
-
A-WEB-Log4j-String-2 – There was an attempt via web activity to exploit the CVE-2021-44228 vulnerability using known keywords on the asset.
-
A-WEB-Log4j-String – There was an attempt via web activity to exploit the CVE-2021-44228 vulnerability on this asset.
-
A-WEB-Phishing – Asset has accessed a domain suspected to be a phishing domain.
-
A-WEB-Reputation-Domain – Asset attempted access to a domain with bad reputation
-
A-WEB-Reputation-IP – Asset attempted to connect to IP address with bad reputation
-
A-WEB-TorProxy – Asset has accessed a known Tor web proxy
-
A-WEB-UU-Tor – Asset has accessed a URL containing '/tor/server'
-
A-WEBF-IP-Country-A – Abnormal direct access to an IP address by the asset belonging to an abnormal country for the asset to access has failed
-
A-WEBF-IP-Country-F – Asset failed to directly connect to an IP address in a country never before accessed
-
A-WHOAMI-SYSTEM – Whoami commanded executed by LOCAL SYSTEM
-
A-WMI-Script-Event-Consumers – Suspicious usage of WMI script event consumers on this asset.
-
A-WMI-Spawn-PowerShell – PowerShell was spawned via WMI on this asset.
-
A-WMI-Suspicious-Process – WMI provider service is used to invoke CMD/PowerShell on this asset.
-
A-WSC-DhA-A – Abnormal account executing service on this asset
-
A-WSC-DhA-F – First account to execute service on this asset
-
A-WSC-DhU-A – Abnormal user installing service on this asset asset
-
A-WSC-DhU-F – First user installing service on this asset
-
A-WSC-F – First service installation activity on asset
-
A-WSC-OS-A – Unusual service name installed on the asset in the organization
-
A-WSC-RANDOM-SERVICE – Random service name for the asset
-
A-WSC-SERVICE-PARAMS – Suspicious parameters in service installation process for this asset
-
A-WSC-SP-A – Unusual process executed by the service on this asset
-
A-WSC-SP-F – First process executed by the service on this asset
-
A-WSC-SP-Temp – Service created from temporary or cached internet files for this asset
-
A-WSC-UZ-F – First service installation in zone on this asset
-
A-WScript-CScript-Dropper – Wscript or Cscript used for script execution from User directories on this asset
-
A-WannaCry – Artifacts seen by WannaCry malware have been observed on this asset
-
A-WebShell-CLI – Possible command line web shell detected on this asset
-
A-WebShell-WebServer – Possible web server web shell detected on this asset
-
A-Win-Proc-Sus-Parent – A suspicious parent process of well-known Windows processes was detected on this asset.
-
A-WinWord-Uncommon-Subprocess – Winword has spawned an uncommon subprocess, csc.exe, on this asset
-
A-Winnti-Malware – Artifacts of 'Winnti' malware have been observed on this asset
-
A-Winword-Uncommon-Process – 'MicroScMgmt' executable run by 'WinWord.exe' on this asset
-
A-Zoho-DCTask – Dctask64.exe executed, possible process injection on this asset
-
A-ZxShell – Known backdoor software, ZxShell, possibly loaded on this asset
-
AC-LocUA-A – Abnormal account creation activity by local user
-
AC-LocUA-F-new – First account creation activity by a new local user
-
AC-LocUA-F – First account creation activity by local user
-
AC-OH-CLI-F – First host on which account was created using CLI command
-
AC-OZ-CLI-F – First zone on which account was created using CLI command
-
AD-Diagnostic-Tool – Invocation of Active Directory Diagnostic Tool (ntdsutil.exe)
-
AE-NTLM-WsSrv – New generic hostname found using ntlm authentication
-
AE-UA-FA – First audit activity type for user
-
AL-F-A-DC-G – Abnormal logon to a Domain Controller for Peer Group
-
AL-F-A-DC – Abnormal logon to a Domain Controller for user
-
AL-F-F-DC-G – First logon to a Domain Controller for peer group
-
AL-F-F-DC – First logon to a Domain Controller for user
-
AL-HLocU-A – Abnormal local user logon to this asset
-
AL-HLocU-F – First local user logon to this asset
-
AL-OHcount – Abnormal number of logged on assets compared to the organization
-
AL-UH-A-DC – Abnormal logon to a Domain Controller that user has not accessed often previously
-
AL-UH-DC-NC – Logon to a Domain Controller for user with no information
-
AL-UH-F-DC – First logon to this Domain Controller for user
-
AL-UHcount-L – Abnormal number of logon assets (L)
-
AL-UHcount-M – Abnormal number of logon assets (M)
-
AL-UHcount-S – Abnormal number of logon assets (S)
-
ALERT-Correlation-Rule – Correlation rule alert on asset accessed by this user
-
ALERT-DL – DL Correlation rule alert on asset accessed by this user
-
AM-UD-A – Abnormal account creation on domain for user
-
AM-UD-F – First account creation on domain for user
-
APP-UAg-3 – More than two new user agents used by the user in the same session
-
APP-UAg-F – First user agent string for user
-
APP-UOs-F – First os/browser combination for user
-
APP-UappA-F – First application activity for user
-
APP-UsH-A – Abnormal source asset for user in application
-
APP-UsH-F – First source asset for user in application
-
APT-Hurricane-Panda – Artifacts used by the APT group 'Hurricane Panda' have been observed
-
AS-PV-GSize-A – Abnormal number of password retrievals in the peer group
-
AS-PV-OG-F – First password retrieval activity for user in peer group
-
AS-PV-OSize-A – Abnormal number of password retrievals in the organization
-
AS-PV-OU-F – First password retrieval activity for user in organization
-
AS-PV-PCWoL – Password retrieval with no login to the asset in the session
-
AS-PV-UHWoPC – Access to Password Vault managed asset with no password checkout for user
-
AS-PV-US-A – Abnormal password retrieval using this safe value for user
-
AS-PV-US-F – First password retrieval using this safe value for user
-
AS-PV-USCOUNT-A – Abnormal number of password safes used by user
-
AS-PV-USize-A – Abnormal number of password retrievals in the user
-
AS-PV-UT-A – Abnormal user Password retrieval activity time
-
AS-PV-UsH-F – First password retrieval from asset for user
-
ATP-FTP-Exfil – Exfiltration Over Alternative Protocol
-
ATP-PSexec – PSExec service was run on the asset by this user.
-
ATP-PWDump – Malicious exe was run which is a part of credential dumping tool
-
ATP-WMIC-Antivirus – Antivirus detection using windows utility msbuild.
-
Applocker-Bypass – Execution of executables that can be used to bypass Applocker
-
Auth-Blacklist-Shost – User authentication or login from a known blacklisted IP
-
Auth-Ransomware-Shost-Failed – User authentication or login failure from a known ransomware IP
-
Auth-Ransomware-Shost – User authentication or login from a known ransomware IP
-
Auth-Tor-Shost-Failed – User authentication or login failure from a known TOR IP
-
Auth-Tor-Shost – User authentication or login from a known TOR IP
-
AutoRun-Modification – AutoRun Keys modified using reg.exe
-
Baby-Shark-Activity – Activity related to Baby Shark malware has been found.
-
Base64-CommandLine – Base64 string in command line
-
Base64-Powershell-CmdLine-Keywords – Base64 encoded strings were found in hidden malicious Powershell command lines
-
Bginfo-App-Whitelisting – VBscript referenced in a .bgi file was executed.
-
Bypass-UAC-CMSTP – Child process of automatically elevated instance of Microsoft Connection Manager Profile Installer (cmstp.exe) was created via command line.
-
CMD-Spawn-From-Office – A command line executable was spawned from an Office application
-
CSC-Suspicious-Folder – Csc.exe spawned from suspicious folder
-
CSC-Suspicious-Parent-Process – Suspicious parent process for csc.exe, possible payload delivery
-
CSharp-Interactive-Console – Execution of CSharp interactive console by PowerShell.
-
ChaferAPT-Activity-ServiceCreated – Chafer APT related activity observed, a suspicious service was created
-
ChaferAPT-Activity-TaskCreated – Chafer APT related activity observed, a suspicious task was created
-
CreateMiniDump-Hacktool – CreateMiniDump Hacktool
-
DCOMActivation-Known – Remote DCOM activation under DcomLaunch service
-
DCOMFailure-Known – Remote DCOM activation failure.
-
DCSync-ExistHost – Possible DCSync attack - existing host has replicated Active Directory.
-
DCSync-FirstDS – Possible DCSync attack - first DS access event from host.
-
DLL-AppData – DLL loaded from 'AppData(slash)Local' path
-
DLL-SideLoading – DLL sideloading malware used, known artifact of APT27
-
DLL-ULOAD-EquationGroup – A known 'Equation Group' artifact was observed
-
DLP-Log4j-String – There was an attempt via email message to exploit the CVE-2021-44228 vulnerability.
-
DNS-Exfiltration-Tools-Exec – Well-known DNS Exfiltration tools were executed.
-
DNX-App-Whitelisting – C# code located in consoleapp folder was executed.
-
DotNET-URL – DotNET command line contains remote file
-
EM-Attachments – Abnormal number of attachments in outbound email for user
-
EM-BSum-5MB-Fail – Failed attempt to email over 5MB of data to a personal email domain.
-
EM-BSum-5MB – Over 5MB of data emailed to personal email domain.
-
EM-BSum-first – Large amount of data in email for user with little or no previous email history
-
EM-BSum-personal – Abnormal size of outgoing emails to personal account
-
EM-BSum – Abnormal size of outgoing emails
-
EM-Bytes – Abnormally large outbound email for user
-
EM-Competition – Email to competition
-
EM-Confidential-File – Confidential file found in outgoing email attachment
-
EM-DED – Email to a disposable email domain
-
EM-DNum – Abnormal number of outgoing email domains
-
EM-EXEC-Personal – Email sent by an Executive user is forwarded to personal email
-
EM-EXEC-Public – Email sent by an Executive user is forwarded to public email
-
EM-FNum – Abnormal number of outgoing emails
-
EM-File – Source code file found in outgoing email attachment
-
EM-G-EXEC-A – Abnormal for this peer group has forwarded/sent an email from an executive user
-
EM-G-EXEC-F – First time this peer group has forwarded/sent an email from an executive user
-
EM-GD-A – Abnormal email domain for group
-
EM-GD-F – First email domain for group
-
EM-GFEXT-A – Abnormal file attachment type in email for peer group
-
EM-Gcountry-A – Abnormal email to country
-
EM-Gcountry-F – First email to country for the peer group
-
EM-InB-Ex – A user has been given mailbox permissions for an executive user
-
EM-InB-Perm-A – Abnormal number of mailbox permission given by user.
-
EM-InB-Perm-N-A – Abnormal for user to give mailbox permissions
-
EM-InB-Perm-N-F – First time a user has given mailbox permissions on another mailbox that is not their own
-
EM-InRule-EX – User has created an inbox forwarding rule to forward email to an external domain email
-
EM-InRule-Fin – User has created an inbox forwarding rule to forward emails containing financial keywords
-
EM-InRule-Public – User has created an inbox forwarding rule to forward email to a public email domain
-
EM-N-SUM-20 – Over 20MB sent by a new user over email
-
EM-OD-A – Abnormal email domain for organization
-
EM-OD-F – First email domain for organization
-
EM-OFEXT-A – Abnormal file attachment type in email for organization
-
EM-OutSpam-L – Email sent to more recipients than usual, at least one external. (L)
-
EM-OutSpam-M – Email sent to more recipients than usual, at least one external. (M)
-
EM-Personal-Job – Email with job seeking keywords in subject is sent to personal email address from company email address
-
EM-Personal-PrivacySize – Email with privacy keywords in subject is sent to personal email address from company email address and the email is larger than 10KB
-
EM-Personal-Privacy – Email with privacy keywords in subject is sent to personal email address from company email address
-
EM-PersonalEmail – Email sent to their personal email from company email
-
EM-PublicDomain – Email has been sent to public email domain from company email
-
EM-UD-A – Abnormal email domain for user
-
EM-UD-F – First email domain for user
-
EM-UFEXT-A – Abnormal file attachment type in email for user
-
EM-Ucountry-A – Abnormal email to country for the user
-
EM-Ucountry-F – First email to country for the user
-
EM-country-A – Abnormal email to country for the organization
-
EM-country-F – First email to country for the organization
-
EPA-CtrlPnl-A – First control panel function usage for peer group
-
EPA-DLL – Dll loaded from a temp folder via PowerShell
-
EPA-GSequenceSize-PS – Abnormal number of powershell executions in the peer group
-
EPA-OH-CENUM-A – Abnormal for this host to run credential enumeration tool
-
EPA-OH-CENUM-F – Host running credential enumeration tool for the first time
-
EPA-OSequenceSize-PS – Abnormal number of powershell executions in the org
-
EPA-OU-CENUM-A – Abnormal for this user to run credential enumeration tool
-
EPA-OU-CENUM-F – First user running credential enumeration tool
-
EPA-PDir-F – First execution of a process in this directory for the organization
-
EPA-PG-PS-A – Abnormal execution of powershell process for this peer group
-
EPA-PG-PS-F – First execution of powershell process for this peer group
-
EPA-PI-TorIp – Process has created a connection to known Tor exit node
-
EPA-PU-PS-A – Abnormal execution of powershell process for user
-
EPA-PU-PS-F – First execution of powershell process for user
-
EPA-RANDOM-SERVICE – Random service name for the user
-
EPA-SERVICE-PARAMS – Suspicious parameters found in process for service creation
-
EPA-UD-DGA-A – Abnormal access to this domain through network which has been identified as DGA
-
EPA-UD-DGA-F – First access to this domain through network which has been identified as DGA
-
EPA-UD-DGA-N – Common access to this domain through network which has been identified as DGA
-
EPA-UP-CENUM – Abnormal number of unique credential enumeration tools run by this user
-
EPA-UP-CrontabMod-A – Abnormal execution of of process which contains commands for crontab modification for user.
-
EPA-UP-CrontabMod-F – First execution of process which contains commands for crontab modification for user.
-
EPA-USequenceSize-PS – Abnormal number of powershell executions for the user
-
ETW-Trace-Disable – Event tracing has been disabled, possible logging evasion
-
EXPERT-PENTEST-DOMAINS – Possible credentials theft attack detected
-
EXPERT-POWERSHELL-ENCRYPTED – Encrypted argument in a Powershell command detected
-
Empire-Monkey – EmpireMonkey APT activity was found
-
EventLog-Tamper – EventLog has been tampered with
-
Exec-Outlook-Temp – A suspicious program was executed in the Outlook temp folder.
-
Exfil-Tunnel-Tools-Exec – Tools known for data exfiltration and tunneling were executed.
-
FA-LSASS – Possible Mimikatz attack by a user process
-
FA-Outlook-pst – A file ends with either pst or ost
-
FA-Outlook – A file has been copied from a path which contains outlook-keyword
-
FA-StartupFolder-OU-A – Abnormal program addition to the startup folder by the user.
-
FA-StartupFolder-OU-F – A program was added to the startup folder for the first time by the user
-
FA-UC-F – Failed activity from a country from which there was no prior successful activity
-
FA-UFCOUNT-DELETE – Abnormal number of deleted files in a day
-
FA-UH-CRIT – File deletion on a critical system
-
FA-UH-DELETE – Abnormal number of hosts where files were deleted from
-
FAIL-PTH-ALERT-dH – Possible unsuccessful pass the hash attack by the user
-
FAIL-PTH-ALERT-sH – Possible unsuccessful pass the hash attack from the source
-
FE-WC – Modified WMIPRVSE by FIREEYE for pentesting
-
FEM-FU – Emailing a previously failed attachment
-
FEM-UD-R – Repeated email failure to domain
-
File-Folder-Perm-Mod – The permissions of a file or folder were modified.
-
FileType-Association-Change – File Association changed for this file extension
-
Firewall-Disabled-Netsh – Windows firewall was turned off using netsh commands.
-
GRAB-REG-HIVES – Grabbing Sensitive Hives via Reg Utility
-
HH-EXE-CHM – HH.exe usage, possible code execution
-
Hanword-Subprocess – Suspicious processes spawned by the Hangul word processor
-
INTERACTIVE-JOB – Interactive job from the 'at' program
-
Impacket-Lateral-Detection – Activity related to Impacket framework using wmiexec, dcomexe, or smbexec processes via command line have been found.
-
JPanda-Activity – Judgement Panda Exfil Activity detected
-
JPanda-RUS-G-Activity – Judgement Panda Exfil Activity- Russian group activity detected
-
KL-GSnCOUNT-A – Abnormal number of services used to obtain TGTs by peer group
-
KL-Tf-fail – Failed logon due to a malformed authentication ticket
-
KL-TfG – Rare Kerberos ticket failure code
-
KL-ToEt-Roast – Suspicious or weak encryption type used for obtaining kerberos TGTs using non kerberos service
-
KL-USnCOUNT-A – Abnormal number of services used to obtain TGTs by user
-
Koadic-Tool-Usage – 'Koadic' attacker tool usage
-
LL-GH-A-new – Abnormal local logon to asset for group by new user
-
LL-GH-A – Abnormal local logon to asset for group
-
LL-GH-F-new – First local logon to asset for group by new user
-
LL-GH-F – First local logon to asset for group
-
LL-HU-F-new – Local logon to private asset for new user
-
LL-UH-A – Abnormal local logon to asset
-
LL-UH-F – First local logon to asset
-
LSASS-Mem-Dump – LSASS Memory Dumping
-
MMC-Spawn-Win-Shell – MMC (Microsoft Management Console) started a Windows command line executable.
-
MSHTA-SVCHOST – Mshta.exe spawned by svchost.exe, possible lateral movement
-
MSTSC-RDP-Hijack – MSTSC Shadowing, possible RDP session hijack/shadowing of session
-
Mshta-CMD-Spawn – Mshta.exe has executed a command line executable
-
Mshta-Javascript – Mshta.exe has executed a javascript related command
-
Mshta-Script – Mshta.exe .NET code execution
-
MsiExec-Web-Install – A suspicious msiexec process was started with web addresses as a parameter.
-
Mustang-Panda-Dropper – Possible Mustang Panda droppers execution.
-
NET-EXE-ADD-ORG-A – Abnormal usage of net.exe to create a user account by this user.
-
NET-EXE-ADD-ORG-F – First time net.exe has been used to create a user account by this user.
-
NKL-GH-A-new – Abnormal kerberos/ntlm logon on asset for peer group by new user
-
NKL-GH-A – Abnormal NTLM/Kerberos logon to asset for peer group
-
NKL-GH-F-new – First kerberos/ntlm logon to server for peer group by new user
-
NKL-GH-F – First NTLM/Kerberos logon to asset for peer group
-
NKL-HU-F-new – Ntlm/Kerberos logon to private asset for new user
-
NKL-UH-A – Abnormal NTLM/Kerberos logon to asset
-
Netsh-Connections-Win-Firewall – Netsh commands were used to allow incoming connections by Port or Application on Windows Firewall.
-
Netsh-RDP-Port-Fwd – Netsh commands used to configure port forwarding for port 3389, used for RDP, were detected.
-
New-ScheduledTask – New scheduled task created using schtasks.exe
-
New-Service – New windows service created
-
Non-Interactive-Powershell – Non-Interactive Powershell activity was found.
-
NotPetya-Activity – NotPetya Ransomware Activity detected
-
OG-SYSVOL-A – Abnormal SYSVOL Domain Group Policy Access for thjis peer group
-
OG-SYSVOL-F – Suspicious SYSVOL Domain Group Policy Access for the first time for this peer group
-
Odbcconf-DLL-Load – DLL loaded via odbcconf.exe execution.
-
Operation-Wocao-Activity – Possible Operation-Wocao APT activity, suspicious command line arguments
-
Ordinal-Rundll32-Call – Suspicious calls of DLLs in rundll32.dll exports by ordinal.
-
PC-InstallUtil-dll-A – Abnormal dll file usage by InstallUtil.exe
-
PC-InstallUtil-dll-F – First time dll file usage by InstallUtil.exe
-
PC-InstallUtil-exe-A – Abnormal exe file usage by InstallUtil.exe
-
PC-InstallUtil-exe-F – First time exe file usage by InstallUtil.exe
-
PC-MSBuild-Csproj-F – First time csproj file usage by MSBuild.exe
-
PC-MSBuild-xml-F – First time xml file usage by MSBuild.exe
-
PC-Mshta-Hta-A – Abnormal hta file usage by Mshta.exe
-
PC-Mshta-Hta-F – First time hta file usage by Mshta.exe
-
PC-ParentName-ProcessName-DCOM-A – Abnormal child process creation for DCOM associated process.
-
PC-ParentName-ProcessName-DCOM-F – First time child process creation for DCOM associated process
-
PC-ParentName-ProcessName-DotNET-A – Abnormal child process creation for .NET associated process
-
PC-PowerShell-ExchangeSnapIns – Exchange Snap-In was imported and run by Powershell.
-
PC-PowerShell-PowerCatDownload – PowerCat tool was downloaded via Powershell.
-
PC-PowerShell-SocketCreate – Powershell TCP Socket Creation through Powershell.
-
PC-Powershell-HafniumActivity – Powershell HAFNIUM Activity
-
PC-Procdump-LsassDump – Procdump was executed with lsass dump command line parameters.
-
PC-Regsvr32-sct-A – Abnormal sct file usage by Regsvr32.exe
-
PC-Regsvr32-sct-F – First time sct file usage by Regsvr32.exe
-
PC-Rundll-LsassDump – Rundll32 was run with minidump via commandline
-
POSS-SPN-ENUMERATION – Possible SPN Enumeration
-
PSExec-Rename – PS Exec used
-
PTH-ALERT-dH – Possible pass the hash attack by the user
-
PTH-ALERT-sH-Failed – Failed pass the hash attack with keylength of 0 in NTLM event and a 'null' sid.
-
PTH-ALERT-sH-Possible – Possible pass the hash attack with keylength of 0 in NTLM event and a 'null' sid.
-
PTH-ALERT-sH – Possible pass the hash attack from the source
-
ParentProcess-P-A – Abnormal parent process for peer group
-
ParentProcess-P-F – First execution of this parent process for peer group.
-
PlugX-DLL-Sideloading – DLL loaded from suspicous location typically seen by the PlugX malware family
-
Possible-PrivEsc-SvcPerms – Possible privilege escalation using weak service permissions
-
PowerShell-BITS-Job – BITS job via PowerShell was created.
-
Powershell-ADS – Powershell invoked using 'Alternate Data Stream'
-
Powershell-AMSI-Bypass-NET – Request to amsiInitFailed that can be used to disable AMSI Scanning was found.
-
Powershell-Advanced-A – Abnormal user using advanced powershell capabilities
-
Powershell-Advanced-F – First use of advanced powershell capabilities by user
-
Powershell-CMDLETS – Malicious PowerShell script was used via get cmdlets function of PowerShell
-
Powershell-Commands-A – Abnormal Powershell Command
-
Powershell-Commands-F – First new Powershell Command
-
Powershell-Empire – The attacker tool, Powershell Empire, has been used
-
Powershell-Exec-DLL – PowerShell Strings applied to rundllas.exe seen in PowerShdll.dll
-
Powershell-Invoke-Count – Abnormal number of Invoke-Command/Expression used by the org
-
Powershell-RunType-A – Abnormal invocation of powershell
-
Powershell-Script-A – Abnormal powershell script
-
Powershell-Script-AppData – Powershell was invoked in a suspicious command line execution with reference to an AppData folder.
-
Powershell-Script-F – First time this powershell script has been run
-
Powershell-WMI-A – Abnormal user using powershell WMI
-
Powershell-WMI-F – First time for user using powershell WMI
-
Powershell-Web-A – Abnormal amount of powershell web activity
-
PrivEsc-SchedTask-LegacyDACL – Possible privilege escalation using a legacy task file
-
Proc-Dump-Comsvcs – Process Dump via Rundll32 and Comsvcs.dll
-
Procdump-Comsvcs-DLL – Process Dump via Comsvcs DLL
-
RA-LogonRunKeys-OU-A – Abnormal addition of a program to the registry run key by the user
-
RA-LogonRunKeys-OU-F – A program was added to the registry run key for the first time by the user
-
RDP-Brute-Force – Abnormal number of RDP failed logons for this user
-
RL-OZ-A-DC – Abnormal logon to a Domain Controller from zone for organization
-
RL-OZ-F-DC – First logon to a Domain Controller from zone for organization
-
RL-UZ-F-DC – First logon to a Domain Controller from zone for user
-
Regsvr32-Suspicious-Cmd – Suspicious commands related to Regsvr32.exe have been observed.
-
Remote-Powershell-Session – Remote Powershell session was detected by monitoring for wsmprovhost as a parent or child process.
-
Rubeus-CMD-Tool – Command line parameters used by Rubeus hack tool detected
-
RunDll32-ControlPanel – RunDll32.exe run from control panel
-
SA-AsU-A – Abnormal access of admin share on this host
-
SA-AsU-F – First access of admin share on this host
-
SA-Bloodhound-2 – ADMIN IPC Share samr folder accessed
-
SA-Bloodhound-3 – ADMIN IPC Share srcsvc accessed
-
SA-Bloodhound – ADMIN IPC Share lsarpc folder accessed
-
SA-OH-A – Abnormal admin share on this host
-
SA-OH-F – First admin share on this host
-
SA-OU-A – Abnormal admin share access for user in the organization
-
SA-OU-F – First admin share access for user in the organization
-
SEQ-UH-09 – Abnormal time of the week for a failed logon for user
-
SETUPCOMPLETE-PRIV-ESC – Privilege escalation attempt using the SetupComplete.cmd object
-
SL-UH-A – Abnormal access from asset for a service account
-
SL-UH-I – Interactive logon using a service account
-
ServicePath-Modification – Suspicious service path identified
-
ShadowCP-OSUtilities – Shadow Copies Creation Using Operating Systems Utilities
-
Shim-Installation – Possible installation of a 'shim' using sdbinst.exe
-
Sus-Encoded-PS-CmdLine – Suspicious Powershell process was started with base64 encoded commands.
-
Sus-GUP-Usage – Execution of the Notepad++ updater in a suspicious directory.
-
Sus-MsiExec-Directory – Suspicious msiexec process started in an uncommon directory.
-
Sus-Powershell-Invocation-Parent-Proc – Suspicious Powershell invocation from interpreters or unusual programs.
-
Sus-Powershell-Param – Powershell was invoked with a suspicious parameter substring
-
Sus-Procdump – Suspicious Use of Procdump
-
Sus-Svchost-Process – A suspicious svchost process was started.
-
Suspicious-ControlPanel – Control Panel commandlets loaded outside the default directory
-
Suspicious-GetSystem-Usage – Possible Meterpeter/Cobalt Strike usage of GetSystem
-
Suspicious-IIS-Modules – Native-Code modules for IIS installed via command line
-
Suspicious-Persistence – Suspicious 'schtask' creation, possible attack tool usage
-
Suspicious-RDP-TSCON – Suspicious usage of RDP using tscon.exe
-
Suspicious-Shell-Child-Process – Windows shell has spawned a suspicious process
-
Sysmon-Driver-Unload – Possible Sysmon driver unloaded.
-
TurlaGroup-LateralMovement – Artifacts from the ATP 'Turla Group' have been observed
-
UAC-Bypass-COM-OBJECT – Windows UAC bypass using COM object access
-
UAC-Bypass-Fodhelper – UAC Bypass using fodhelper.exe
-
UAC-Bypass-Wsreset – UAC Bypass using wsreset.exe
-
UW-BSum – Abnormal amount of data written to USB
-
UW-DH-A – Abnormal asset for USB device
-
UW-DH-F – First asset for device in USB event
-
UW-FNum – Abnormal number of files written to USB
-
UW-PST – A file ending with either pst or ost has been written into USB
-
UW-UD-A – Abnormal USB device for user
-
UW-UD-F – First device for user in USB event
-
UW-UH-A – Abnormal asset for user in USB event
-
UW-UHD-000 – First USB activity event for user, asset and USB device
-
UW-UHD-001 – First USB activity event for user and asset. The USB device (if present) has been used by/with other users/assets in the past.
-
UW-UHD-010 – First USB activity event for user and USB device. The asset has been used with other USB devices in other USB events
-
UW-UHD-011 – First USB activity event for user. The asset and the USB device (if present) have been seen in other USB events
-
UW-UHD-100 – First USB activity event for USB device and asset. The user has been seen performing USB activity in other USB events
-
UW-UHD-101 – First USB activity event for asset. The user and the USB device (if present) have been seen in other USB events
-
UW-UHD-110 – First USB activity event for USB device. The user and the asset have been seen in other USB events
-
UW-UHD-F – First asset and device for user in USB event
-
Unauthorized-MBR-Mods – Bcdedit.exe has signs of malicious unauthorized usage.
-
UserProcess-Spawned-FromOffice – An executable running under the 'Users' path has been spawned from an Office application
-
WA-CS – Audit activity on a critical system for user
-
WA-HA-F-1 – First audit log clearance on host
-
WA-HA-F-2 – First audit policy change on host
-
WCA-DP – Meeting updated to remove password
-
WCA-MTOW-A – Abnormal web conference meeting time
-
WCA-Ransomware-IP – User performs web conference login from an IP associated with Ransomware
-
WCA-TOW-A – Abnormal web conference login time
-
WCA-Threat-IP – User performs web conference login from a known malicious IP
-
WCA-Tor-IP – User performs web conference login from a known Tor exit node
-
WCA-Ucountry-A – Abnormal web conference login country for user
-
WEB-ALERT-EXEC – Security violation by Executive in web activity
-
WEB-FS – User has accessed a file sharing domain
-
WEB-GBytes-A-FS – Abnormal amount of data for peer group has been uploaded to a file sharing site
-
WEB-GBytes-A-JS – Abnormal amount of data had been uploaded to a job search site in the peer group
-
WEB-GBytesSum-EWD – Abnormal amount of data for the peer group uploaded to webmail domains
-
WEB-GSequenceSize-JS – Abnormal number of job search events in the group
-
WEB-GUa-Browser-F – First activity using this web browser for the peer group
-
WEB-GUa-OS-F – First web activity using this operating system for the peer group
-
WEB-GZ-F – First web activity from this zone for the peer group
-
WEB-IOC – Indicator of Compromise (IOC) found in user's web activity
-
WEB-IP-COUNTRY-A – Abnormal direct access to an IP address belonging to an abnormal country for user to access
-
WEB-IP-Country-F – User has directly browsed to an IP address belonging to a country never before accessed
-
WEB-IPF-Country-F – User has failed trying to directly browse to an IP address belonging to a country never before accessed
-
WEB-Log4j-String-2 – There was an attempt via web activity to exploit the CVE-2021-44228 vulnerability using known keywords.
-
WEB-Log4j-String – There was an attempt via web activity to exploit the CVE-2021-44228 vulnerability.
-
WEB-New-File-20-Block – User with no web activity history was blocked from uploading 20MB or more
-
WEB-New-File-20 – User with no web activity history has uploaded 20MB or more
-
WEB-New-File – New user accessing file sharing websites
-
WEB-OBytes-A-FS – Abnormal amount of data for user has been uploaded to a file sharing site
-
WEB-OBytesSum-EWD – Abnormal amount of data for the organization uploaded to webmail domains
-
WEB-OG-FS – One of the top file sharing users in the peer group
-
WEB-OG-JS-A – Abnormal job search activity for user in the peer group
-
WEB-OG-JS-F – First job search activity for user in the peer group
-
WEB-OSequenceSize-JS – Abnormal number of job search events in the org
-
WEB-OU-FS – One of the top file sharing users in the organization
-
WEB-OU-JS-A – Abnormal job search activity for user in the organization
-
WEB-OU-JS-F – First job search activity for user in the organization
-
WEB-OUa-Browser-F – First activity using this web browser for the organization
-
WEB-OUa-OS-F – First web activity using this operating system for the organization
-
WEB-OZ-F – First web activity from this zone for the organization
-
WEB-OsUa-MobileBrowser-F – First activity using this mobile web browser for this mobile operating system
-
WEB-Phishing – Web activity to a phishing domain.
-
WEB-RCCount – Abnormal number of proxy events with 3xx/4xx requests for the user
-
WEB-Shadow-Mining – User has browsed to a known coinmining/shadowmining domain
-
WEB-UBlock – Abnormal number of denied web access domains
-
WEB-UBytes-A-JS – Abnormal amount of data had been uploaded to a job search site for the user
-
WEB-UBytesSum-EWD – Abnormal amount of data for user uploaded to webmail domains
-
WEB-UBytesSum-Out-FS – Abnormal amount of data for user has been uploaded to file sharing websites
-
WEB-UD-ALERT-A – Abnormal security alert accessing this malicious domain for user
-
WEB-UD-ALERT-N – Common security alert on this malicious domain for user
-
WEB-UD-DGA-A – Abnormal access to this domain which has been identified as DGA
-
WEB-UD-DGA-N – Common access to this domain which has been identified as DGA
-
WEB-UD-DynamicDNS – User attempted access to a domain generated using Dynamic DNS service
-
WEB-UD-Phishing – User attempted to access a domain which is associated to Phishing
-
WEB-UD-Reputation-A – Abnormal access to this web domain which has been identified as risky by a reputation feed.
-
WEB-UD-Reputation-F – First access to this web domain which has been identified as risky by a reputation feed.
-
WEB-UD-Reputation-N – Common access to this web domain which has been identified as risky by a reputation feed.
-
WEB-UD-TorProxy – User has accessed a known Tor web proxy
-
WEB-UDLP-A-FS – Abnormal amount of data for organization has been uploaded to a file sharing site
-
WEB-UDLP-A – Possible data exfiltration: Abnormal amount of data had been uploaded to the web
-
WEB-UGETDLP-A – Possible data exfiltration: Abnormal amount of data had been written to the web in http GET requests
-
WEB-UI-Ransomware – User attempted to connect to IP address which is associated to Ransomware
-
WEB-UI-Reputation-A – Abnormal access to this IP address which has been identified as risky by a reputation feed.
-
WEB-UI-Reputation-F – First access to this internet IP address which has been identified as risky by a reputation feed.
-
WEB-UI-Reputation-N – Common access to this IP address which has been identified as risky by a reputation feed.
-
WEB-UI-Tor – User has accessed a known Tor exit node
-
WEB-URank-A – Abnormal web activity to this low ranked web domain
-
WEB-URank-Binary – Executable download from first low ranked web domain
-
WEB-URank-DLP – Possible data exfiltration: Abnormal amount of data had been uploaded to low ranked websites
-
WEB-URank-F – First web activity to this low ranked web domain
-
WEB-URank-Tor – User has accessed a tor-to-web proxy site
-
WEB-USequenceSize-Denied – Abnormal number of denied web activity events for user
-
WEB-USequenceSize-JS – Abnormal number of job search events by user
-
WEB-USequenceSize – Abnormal number of web activity events for user
-
WEB-UT-TOW-A – Abnormal day for this user to access the web via the organization
-
WEB-UU-Tor – User has accessed a URL containing '/tor/server'
-
WEB-UUa-Browser-F – First activity using this web browser for this user to a new domain
-
WEB-UUa-MobileBrowser-F – First activity using this mobile web browser/app for this user to a new domain
-
WEB-UUa-OS-F – First web activity using this operating system for this user
-
WEB-UZ-F – First web activity for this user in this zone
-
WINCMD-WmiObject – Powershell WMI object to enumerate network adapter was used
-
WMI-Script-Event-Consumers – Suspicious usage of WMI script event consumers.
-
WMI-Spawn-PowerShell – PowerShell was spawned via WMI.
-
WMIExec-VBS-Script – Suspicious usage of wscript/cscript
-
WSC-GH-F – First service installation on host in the peer group
-
WSC-GS-A – Unusual service name in the peer group
-
WSC-OH-F – First service installation on host in the organization
-
WSC-OS-A – Unusual service name in the organization
-
WSC-OZ-F – First service installation in zone for organization
-
WSC-PSEXEC-A – Abnormal service installation Psexec for the user
-
WSC-PSEXEC-F – First service installation Psexec for the user
-
WSC-RANDOM-SERVICE – Random service name found for this user
-
WSC-SERVICE-PARAMS – Suspicious parameters in service installation process for this user
-
WSC-SP-A – Unusual process executed by service for this user
-
WSC-SP-F – First process executed by service for this user
-
WSC-SP-POWERSHELL – Service created to execute sensitive process
-
WSC-UH-F – First service installation on host by the user
-
WSC-US-A – Unusual service name in the user
-
WSC-UZ-F – First service installation in zone by this user
-
WScript-CScript-Dropper – Wscript or Cscript used for script execution from User directories
-
WTC-GH-F – First scheduled task on host in the peer group
-
WTC-GT-A – Unusual task name in the peer group
-
WTC-HT-EXEC – Non-Executive user created a scheduled task/service on executive asset
-
WTC-HT-PRIV – Non-Privileged user created a scheduled task/service on privileged asset
-
WTC-OH-F – First scheduled task on host in the organization
-
WTC-OT-A – Unusual task name in the organization
-
WTC-TP-A – Unusual process for scheduled task
-
WTC-TP-POWERSHELL – Scheduled task created to execute sensitive process
-
WTC-UH-F – First scheduled task on host for the user
-
WTC-UT-A – Unusual task name in the user
-
WebShell-CLI – Possible command line web shell detected
-
WebShell-WebServer – Possible web server web shell detected
-
Win-Proc-Sus-Parent – A suspicious parent process of well-known Windows processes was detected.
-
WinWord-Uncommon-Subprocess – Winword has spawned an uncommon subprocess, csc.exe
-
Winnti-Malware – Artifacts of 'Winnti' malware have been observed
-
Zoho-DCTask – Dctask64.exe executed, possible process injection
Deprecated Rules
There are no deprecated rules in this release.