65 detection rules reference this event. View event page.Kusto (65)
- [Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022 severity high T1546
- Access Token Manipulation - Create Process with Token severity medium T1134,T1134.002
- Account Creation severity medium T1136
- Audit policy manipulation using auditpol utility severity medium T1204
- Bitsadmin Activity severity medium T1048,T1105,T1197
- CertUtil Used for File Download (Living off the Land) severity high T1105,T1140,T1218
- Clearing of forensic evidence from event logs using wevtutil severity high T1070
- DCOM Lateral Movement severity medium T1021,T1021.003
- Deletion of data on multiple drives using cipher exe severity medium T1485
- Detect Msiexec executing DLL network connections T1218,T1218.007
- Detect Rare scheduled task created T1053,T1053.005
- Detect Suspicious Commands Initiated by Webserver Processes severity high T1059,T1082,T1087,T1574
- Detect Unknown process launched via WinRM T1021,T1021.006
- Detect Unsigned executable launch from scheduled task T1053,T1053.005
- Detecting UAC bypass - ChangePK and SLUI registry tampering severity medium T1490
- Detecting UAC bypass - elevated COM interface severity medium T1490
- Detecting UAC bypass - modify Windows Store settings severity medium T1490
- Dev-0228 File Path Hashes November 2021 severity high T1003,T1569
- Dev-0270 Malicious Powershell usage severity high T1048,T1685
- DEV-0270 New User Creation severity high T1098
- Dev-0270 Registry IOC - September 2022 severity high T1486
- Dev-0270 WMIC Discovery severity high T1482
- Disable or Modify Windows Defender severity medium T1685
- Disabling Security Services via Registry severity medium T1685
- Doppelpaymer Stop Services severity high T1059,T1685
- DopplePaymer Procdump severity high T1003
- Email access via active sync severity medium T1068,T1078
- Exchange Worker Process Making Remote Call severity medium T1059,T1059.001,T1059.003
- Execution of software vulnerable to webp buffer overflow of CVE-2023-4863 severity informational T1203
- Identify Mango Sandstorm powershell commands severity high T1570
- Ingress Tool Transfer - Certutil severity low T1027,T1105,T1140,T1564,T1564.004
- Java Executing cmd to run Powershell severity high T1059
- LaZagne Credential Theft severity medium T1003
- LSASS Credential Dumping with Procdump severity high T1003
- Match Legitimate Name or Location - 2 severity medium T1036,T1036.005
- Office Apps Launching Wscipt severity medium T1059,T1105,T1203
- Oracle suspicious command execution severity medium T1210,T1611
- Potential Build Process Compromise - MDE severity medium T1554
- Potential Kerberos Relaying Activity - MDE
- Potential Lateral Movement via MSI ODBC Driver Install over DCOM
- PowerShell Encoded Command Execution (Living off the Land) severity medium T1027,T1059,T1059.001
- Probable AdFind Recon Tool Usage severity high T1016,T1018,T1069,T1069.002,T1087,T1087.002
- Process Tree Analysis
- PRT Credential Stealing T1003,T1134,T1134.001,T1555
- Qakbot Campaign Self Deletion severity medium T1070
- Qakbot Discovery Activies severity medium T1010,T1059,T1140
- Rare Process as a Service severity medium T1543,T1543.003
- Regsvr32 Rundll32 with Anomalous Parent Process severity high T1218,T1218.010,T1218.011
- Remote Desktop Protocol - SharpRDP severity medium T1021,T1021.001
- Rename System Utilities severity medium T1036,T1036.003
- Scheduled Task - Suspicious Network Connection
- Security Service Registry ACL Modification severity high T1685
- Shadow Copy Deletions severity medium T1490
- ShieldBreak: Defender AV Privilege Escalation
- SMB/Windows Admin Shares severity medium T1021,T1021.002
- Spearphishing Attachment: ISO Images (Microsoft Defender for Endpoint)
- SQL Server spawning suspicious child process T1505,T1505.001,T1611
- Stopping multiple processes using taskkill severity medium T1685
- SUNBURST suspicious SolarWinds child processes severity medium
- Suspicious parentprocess relationship - Office child processes. severity medium T1566,T1566.002
- Trusted Developer Utilities Proxy Execution severity medium T1127
- Unsigned Windows System Binary T1036,T1036.001,T1036.005
- Unusual identity creation using exchange powershell severity high T1136
- WMI Spawning Suspicious Child Process (Living off the Land) severity high T1021,T1021.006,T1047,T1059,T1059.001,T1059.003
- Zinc Actor IOCs files - October 2022 severity high T1546