Stages and Predicates
Stage 1: selection
or:
ScriptBlockText|contains: ' active_users '
ScriptBlockText|contains: ' basic_info '
ScriptBlockText|contains: ' change_user '
ScriptBlockText|contains: ' command_exec '
ScriptBlockText|contains: ' disable_wdigest '
ScriptBlockText|contains: ' disable_winrm '
ScriptBlockText|contains: ' enable_wdigest '
ScriptBlockText|contains: ' enable_winrm '
ScriptBlockText|contains: ' gen_cli '
ScriptBlockText|contains: ' logon_events '
ScriptBlockText|contains: ' power_off '
ScriptBlockText|contains: ' process_kill '
ScriptBlockText|contains: ' registry_mod '
ScriptBlockText|contains: ' remote_posh '
ScriptBlockText|contains: ' sched_job '
ScriptBlockText|contains: ' service_mod '
ScriptBlockText|contains: ' vacant_system '
ScriptBlockText|contains: WMImplant
Indicators
Each row is a field, operator, and value that the rule matches. The corpus column counts how many other rules in the catalog look for the same combination: high numbers point to widely-used, community-vetted indicators. Blank or 1 shows that the indicator is specific to this rule.
| Field | Kind | Values |
|---|
ScriptBlockText | match | active_users basic_info change_user command_exec disable_wdigest disable_winrm enable_wdigest enable_winrm gen_cli logon_events power_off process_kill registry_mod remote_posh sched_job service_mod vacant_system WMImplant
|
Neighbors
Broader alternatives (more inclusive than this rule)
These rules match a superset of what this rule catches. They cover the same events plus more. Use them if you want wider coverage and can absorb more false positives.