Detection rules › By event
Microsoft-Windows-Sysmon event 8
Sigma (11)
- HackTool - CACTUSTORCH Remote Thread Creation
- HackTool - Potential CobaltStrike Process Injection
- Password Dumper Remote Thread in LSASS
- Potential Credential Dumping Attempt Via PowerShell Remote Thread
- Rare Remote Thread Creation By Uncommon Source Image
- Remote Thread Created In KeePass.EXE
- Remote Thread Creation By Uncommon Source Image
- Remote Thread Creation In Mstsc.Exe From Suspicious Location
- Remote Thread Creation In Uncommon Target Image
- Remote Thread Creation Ttdinject.exe Proxy
- Remote Thread Creation Via PowerShell In Uncommon Target
Elastic (1)
Splunk (8)
- Create Remote Thread In Shell Application
- Create Remote Thread into LSASS
- Powershell Remote Thread To Known Windows Process
- Rundll32 Create Remote Thread To A Process
- Rundll32 CreateRemoteThread In Browser
- Windows Process Injection Of Wermgr to Known Browser
- Windows Process Injection Remote Thread
- Windows Process Injection With Public Source Path