Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Process creation and related events
| Attribute | Value |
|---|---|
| Category | MDE |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes |
| Azure Monitor Tables Reference | View Documentation |
| Defender XDR Advanced Hunting Schema | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AccountDomain | string | Domain of the account. |
| AccountName | string | User name of the account. |
| AccountObjectId | string | Unique identifier for the account in Azure AD. |
| AccountSid | string | Security Identifier (SID) of the account. |
| AccountUpn | string | User principal name (UPN) of the account. |
| ActionType | string | Type of activity that triggered the event. |
| AdditionalFields | dynamic | Additional information about the entity or event. |
| AppGuardContainerId | string | Identifier for the virtualized container used by Application Guard to isolate browser activity. |
| CreatedProcessSessionId | long | Windows session ID of the created process. |
| DeviceId | string | Unique identifier for the device in the service. |
| DeviceName | string | Fully qualified domain name (FQDN) of the device. |
| FileName | string | Name of the file that the recorded action was applied to. |
| FileSize | long | Size of the file in bytes. |
| FolderPath | string | Folder containing the file that the recorded action was applied to. |
| InitiatingProcessAccountDomain | string | Domain of the account that ran the process responsible for the event. |
| InitiatingProcessAccountName | string | User name of the account that ran the process responsible for the event. |
| InitiatingProcessAccountObjectId | string | Azure AD object ID of the user account that ran the process responsible for the event. |
| InitiatingProcessAccountSid | string | Security Identifier (SID) of the account that ran the process responsible for the event. |
| InitiatingProcessAccountUpn | string | User principal name (UPN) of the account that ran the process responsible for the event. |
| InitiatingProcessCommandLine | string | Command line used to run the process that initiated the event. |
| InitiatingProcessCreationTime | datetime | Date and time when the process that initiated the event was started. |
| InitiatingProcessFileName | string | Name of the process that initiated the event. |
| InitiatingProcessFileSize | long | The size of the file (bytes) that ran the process responsible for the event. |
| InitiatingProcessFolderPath | string | Folder containing the process (image file) that initiated the event. |
| InitiatingProcessId | long | Process ID (PID) of the process that initiated the event. |
| InitiatingProcessIntegrityLevel | string | Integrity level of the process that initiated the event. Windows assigns integrity levels to processes based on certain characteristics, such as if they were launched from an internet download. These integrity levels influence permissions to resources.. |
| InitiatingProcessLogonId | long | Identifier for a logon session of the process that initiated the event. This identifier is unique on the same machine only between restarts.. |
| InitiatingProcessMD5 | string | MD5 hash of the process (image file) that initiated the event. |
| InitiatingProcessParentCreationTime | datetime | Date and time when the parent of the process responsible for the event was started. |
| InitiatingProcessParentFileName | string | Name of the parent process that spawned the process responsible for the event. |
| InitiatingProcessParentId | long | Process ID (PID) of the parent process that spawned the process responsible for the event. |
| InitiatingProcessRemoteSessionDeviceName | string | Device name of the remote device from which the initiating process's RDP session was initiated. |
| InitiatingProcessRemoteSessionIP | string | IP address of the remote device from which the initiating process's RDP session was initiated. |
| InitiatingProcessSessionId | long | Windows session ID of the initiating process. |
| InitiatingProcessSHA1 | string | SHA-1 hash of the process (image file) that initiated the event. |
| InitiatingProcessSHA256 | string | SHA-256 hash of the process (image file) that initiated the event. In some cases this column may not be populated - please use the InitiatingProcessSHA1 column instead. |
| InitiatingProcessSignatureStatus | string | Information about the signature status of the process (image file) that initiated the event. |
| InitiatingProcessSignerType | string | Type of file signer of the process (image file) that initiated the event. |
| InitiatingProcessTokenElevation | string | Token type indicating the presence or absence of User Access Control (UAC) privilege elevation applied to the process that initiated the event. |
| InitiatingProcessUniqueId | string | Unique identifier of the initiating process; this is equal to the Process Start Key in Windows devices. |
| InitiatingProcessVersionInfoCompanyName | string | The company name in version information (image file) responsible for the event. |
| InitiatingProcessVersionInfoFileDescription | string | The description in version information (image file) responsible for the event. |
| InitiatingProcessVersionInfoInternalFileName | string | The internal file name in version information (image file) responsible for the event. |
| InitiatingProcessVersionInfoOriginalFileName | string | The original file name in version information (image file) responsible for the event. |
| InitiatingProcessVersionInfoProductName | string | The product name in version information (image file) responsible for the event. |
| InitiatingProcessVersionInfoProductVersion | string | The product version in version information (image file) responsible for the event. |
| IsInitiatingProcessRemoteSession | bool | Indicates whether the initiating process was run under a remote desktop protocol (RDP) session (true) or locally (false). |
| IsProcessRemoteSession | bool | Indicates whether the created process was run under a remote desktop protocol (RDP) session (true) or locally (false). |
| LogonId | long | Identifier for a logon session. This identifier is unique on the same machine only between restarts. |
| MachineGroup | string | Machine group of the machine. This group is used by role-based access control to determine access to the machine. |
| MD5 | string | MD5 hash of the file that the recorded action was applied to. |
| ProcessCommandLine | string | Command line used to create the new process. |
| ProcessCreationTime | datetime | Date and time the process was created. |
| ProcessId | long | Process ID (PID) of the newly created process. |
| ProcessIntegrityLevel | string | Integrity level of the newly created process. Windows assigns integrity levels to processes based on certain characteristics, such as if they were launched from an internet downloaded. These integrity levels influence permissions to resources.. |
| ProcessRemoteSessionDeviceName | string | Device name of the remote device from which the created process's RDP session was initiated. |
| ProcessRemoteSessionIP | string | IP address of the remote device from which the created process's RDP session was initiated. |
| ProcessTokenElevation | string | Token type indicating the presence or absence of User Access Control (UAC) privilege elevation applied to the newly created process. |
| ProcessUniqueId | string | Unique identifier of the process; this is equal to the Process Start Key in Windows devices. |
| ProcessVersionInfoCompanyName | string | Company name from the version information of the newly created process. |
| ProcessVersionInfoFileDescription | string | Description from the version information of the newly created process. |
| ProcessVersionInfoInternalFileName | string | Internal file name from the version information of the newly created process. |
| ProcessVersionInfoOriginalFileName | string | Original file name from the version information of the newly created process. |
| ProcessVersionInfoProductName | string | Product name from the version information of the newly created process. |
| ProcessVersionInfoProductVersion | string | Product version from the version information of the newly created process. |
| ReportId | long | Event identifier based on a repeating counter. To identify unique events, this column must be used in conjunction with the ComputerName and EventTime columns.. |
| SHA1 | string | SHA-1 hash of the file that the recorded action was applied to. |
| SHA256 | string | SHA-256 of the file that the recorded action was applied to. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | Date and time the event was recorded by the MDE agent on the endpoint. |
| Type | string | The name of the table |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
This table is ingested by the following connectors:
| Connector | Selection Criteria |
|---|---|
| Microsoft Defender XDR |
In solution Attacker Tools Threat Protection Essentials:
| Analytic Rule | Selection Criteria |
|---|---|
| PowerShell Encoded Command Execution (Living off the Land) | |
| Probable AdFind Recon Tool Usage |
In solution Dev 0270 Detection and Hunting:
| Analytic Rule | Selection Criteria |
|---|---|
| DEV-0270 New User Creation | |
| Dev-0270 Malicious Powershell usage | |
| Dev-0270 Registry IOC - September 2022 | |
| Dev-0270 WMIC Discovery |
In solution Endpoint Threat Protection Essentials:
| Analytic Rule | Selection Criteria |
|---|---|
| CertUtil Used for File Download (Living off the Land) |
In solution FalconFriday:
| Analytic Rule | Selection Criteria |
|---|---|
| Access Token Manipulation - Create Process with Token | |
| DCOM Lateral Movement | ActionType != "ListeningConnectionCreated"InitiatingProcessParentFileName == "svchost.exe" |
| Detecting UAC bypass - ChangePK and SLUI registry tampering | InitiatingProcessFileName == "changepk.exe"InitiatingProcessParentFileName == "slui.exe"ProcessIntegrityLevel == "High" |
| Detecting UAC bypass - elevated COM interface | InitiatingProcessCommandLine has_any "E9495B87-D950-4AB5-87A5-FF6D70BF3E90"InitiatingProcessFileName == "dllhost.exe"ProcessIntegrityLevel == "High" |
| Detecting UAC bypass - modify Windows Store settings | InitiatingProcessFileName == "wsreset.exe"ProcessIntegrityLevel == "High" |
| Disable or Modify Windows Defender | InitiatingProcessVersionInfoProductName != "Android Studio" |
| Ingress Tool Transfer - Certutil | ProcessCommandLine has "certutil" |
| Match Legitimate Name or Location - 2 | |
| Oracle suspicious command execution | InitiatingProcessFileName == "oracle.exe" |
| Remote Desktop Protocol - SharpRDP | ActionType == "LogonSuccess" |
| Rename System Utilities | |
| SMB/Windows Admin Shares | ActionType == "InboundConnectionAccepted"ProcessCommandLine != "msiexec.exe /V" |
| Suspicious parentprocess relationship - Office child processes. | |
| Trusted Developer Utilities Proxy Execution | FolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"InitiatingProcessFileName in "WDExpress.exe,devenv.exe"InitiatingProcessFolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"ProcessCommandLine has_any "/exe"ProcessCommandLine has_any "out" |
In solution Microsoft Defender XDR:
| Analytic Rule | Selection Criteria |
|---|---|
| Account Creation | InitiatingProcessFileName == "net.exe"ProcessCommandLine !contains "/add"ProcessCommandLine !contains "/domain" |
| Bitsadmin Activity | ProcessCommandLine has "/Upload"ProcessCommandLine has_any "/Transfer" |
| Clearing of forensic evidence from event logs using wevtutil | ProcessCommandLine has "CL"ProcessCommandLine has "WEVTUTIL" |
| Deletion of data on multiple drives using cipher exe | ProcessCommandLine has "/w" |
| Detect Suspicious Commands Initiated by Webserver Processes | InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessFileName startswith "tomcat"InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessParentFileName startswith "tomcat"ProcessCommandLine contains "%temp%"ProcessCommandLine has "certutil"ProcessCommandLine has "ipconfig"ProcessCommandLine has "ping"ProcessCommandLine has "systeminfo"ProcessCommandLine has "timeout"ProcessCommandLine has "wget"ProcessCommandLine has "whoami" |
| Disabling Security Services via Registry | |
| Doppelpaymer Stop Services | InitiatingProcessFileName startswith "psexe"ProcessCommandLine has "msexchange"ProcessCommandLine has "sql"ProcessCommandLine has "stop-service" |
| DopplePaymer Procdump | ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass" |
| Execution of software vulnerable to webp buffer overflow of CVE-2023-4863 | |
| Java Executing cmd to run Powershell | InitiatingProcessFileName == "java.exe" |
| LSASS Credential Dumping with Procdump | ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass"ProcessCommandLine has "lsass.exe" |
| LaZagne Credential Theft | |
| Office Apps Launching Wscipt | InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"ProcessCommandLine has ".jse" |
| Potential Build Process Compromise - MDE | ActionType in "FileCreated,FileModified" |
| Qakbot Campaign Self Deletion | InitiatingProcessCommandLine has "-n 6"InitiatingProcessCommandLine has "127.0.0.1"InitiatingProcessCommandLine has "calc.exe"InitiatingProcessFileName == "cmd.exe" |
| Qakbot Discovery Activies | InitiatingProcessCommandLine endswith "127.0.0.1"InitiatingProcessCommandLine has "-a"InitiatingProcessCommandLine has "-nao"InitiatingProcessCommandLine has "-t"InitiatingProcessCommandLine has "/all"InitiatingProcessFileName in "explorer.exe,mobsync.exe" |
| Rare Process as a Service | |
| Regsvr32 Rundll32 with Anomalous Parent Process | |
| Shadow Copy Deletions | |
| Stopping multiple processes using taskkill |
In solution Windows Security Events:
| Analytic Rule | Selection Criteria |
|---|---|
| WMI Spawning Suspicious Child Process (Living off the Land) |
In solution Zinc Open Source:
| Analytic Rule | Selection Criteria |
|---|---|
| Zinc Actor IOCs files - October 2022 | |
| [Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022 |
Standalone Content:
| Analytic Rule | Selection Criteria |
|---|---|
| Audit policy manipulation using auditpol utility | InitiatingProcessFileName == "auditpol.exe" |
| Dev-0228 File Path Hashes November 2021 | |
| Email access via active sync | |
| Identify Mango Sandstorm powershell commands | |
| SUNBURST suspicious SolarWinds child processes | InitiatingProcessFileName == "solarwinds.businesslayerhost.exe" |
| Security Service Registry ACL Modification | |
| Unusual identity creation using exchange powershell |
In solution Cyware: ProcessCommandLine has "powershell.exe"
| Hunting Query |
|---|
| Detecting Suspicious PowerShell Command Executions |
In solution Endpoint Threat Protection Essentials:
| Hunting Query | Selection Criteria |
|---|---|
| Backup Deletion | |
| Potential Microsoft Security Services Tampering | InitiatingProcessCommandLine has "$true"InitiatingProcessCommandLine has "/IM"InitiatingProcessCommandLine has "Set-MpPreference"InitiatingProcessCommandLine has "Start"InitiatingProcessCommandLine has "config"InitiatingProcessParentFileName != "cscript.exe" |
| Rare Windows Firewall Rule updates using Netsh | InitiatingProcessCommandLine has_all "advfirewall"InitiatingProcessFileName == "netsh.exe" |
| Unicode Obfuscation in Command Line |
In solution Hybrid Attack - Cloud & Identity:
| Hunting Query | Selection Criteria |
|---|---|
| Cloud Run Command followed by kernel persistence indicators on target servers |
In solution Legacy IOC based Threat Protection:
| Hunting Query | Selection Criteria |
|---|---|
| Dev-0056 Command Line Activity November 2021 | |
| Dev-0322 Command Line Activity November 2021 | InitiatingProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV"ProcessCommandLine matchesregex "cmd.exe /c"ProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV" |
| Dev-0322 File Drop Activity November 2021 | |
| Nylon Typhoon Command Line Activity November 2021 | |
| SolarWinds Inventory |
In solution Microsoft Defender XDR:
| Hunting Query | Selection Criteria |
|---|---|
| Account Creation | InitiatingProcessFileName == "net.exe"ProcessCommandLine !contains "/add"ProcessCommandLine !contains "/domain" |
| Anomalous Payload Delivered from ISO files | ActionType == "BrowserLaunchedToOpenUrl" |
| Bitsadmin Activity | ProcessCommandLine has "/Upload"ProcessCommandLine has_any "/Transfer" |
| Check for multiple signs of Ransomware Activity | ProcessCommandLine has "cl"ProcessCommandLine has "config"ProcessCommandLine has "delete"ProcessCommandLine has "deletejournal"ProcessCommandLine has "disabled"ProcessCommandLine has "sc"ProcessCommandLine has "shadowcopy delete"ProcessCommandLine has "usn"ProcessCommandLine has "wbadmin"ProcessCommandLine has "wevtutil"ProcessCommandLine has "wmic" |
| Clear System Logs | ProcessCommandLine has "deletejournal"ProcessCommandLine has "usn" |
| Clearing of forensic evidence from event logs using wevtutil | ProcessCommandLine has "CL"ProcessCommandLine has "WEVTUTIL" |
| Credential Harvesting Using LaZagne | ProcessCommandLine has "hklm"ProcessCommandLine has "sam"ProcessCommandLine has "save" |
| DLLHost.exe WMIC domain discovery | InitiatingProcessCommandLine == "dllhost.exe"InitiatingProcessFileName == "dllhost.exe"ProcessCommandLine has "wmic computersystem get domain" |
| Deletion of data on multiple drives using cipher exe | ProcessCommandLine has "/w" |
| Detect MaiSniper | |
| Detect Malicious use of Msiexec Mimikatz | InitiatingProcessFileName == "msiexec.exe"ProcessCommandLine contains "privilege::"ProcessCommandLine contains "token::"ProcessCommandLine has "sekurlsa" |
| Detect Suspicious Commands Initiated by Webserver Processes | InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessFileName startswith "tomcat"InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessParentFileName startswith "tomcat"ProcessCommandLine contains "%temp%"ProcessCommandLine has "certutil"ProcessCommandLine has "ipconfig"ProcessCommandLine has "ping"ProcessCommandLine has "systeminfo"ProcessCommandLine has "timeout"ProcessCommandLine has "wget"ProcessCommandLine has "whoami" |
| Detect Suspicious Mshta Usage | InitiatingProcessCommandLine contains "<script>"InitiatingProcessFileName == "mshta.exe" |
| Disabling Services via Registry | |
| Doppelpaymer Stop Services | InitiatingProcessFileName startswith "psexe"ProcessCommandLine has "msexchange"ProcessCommandLine has "sql"ProcessCommandLine has "stop-service" |
| DopplePaymer Procdump | ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass" |
| Enumeration of Users & Groups for Lateral Movement | ProcessCommandLine !contains "/add"ProcessCommandLine !contains "\\"ProcessCommandLine contains "/do"ProcessCommandLine contains "/domain"ProcessCommandLine contains "group"ProcessCommandLine contains "user" |
| Imminent Ransomware | |
| Java Executing cmd to run Powershell | InitiatingProcessFileName == "java.exe" |
| Judgement Panda Exfil Activity | |
| LaZagne Credential Theft | |
| MITRE - Suspicious Events | |
| Malicious Use of MSBuild as LOLBin | InitiatingProcessFileName == "wmiprvse.exe"ProcessCommandLine has "programdata" |
| Office Apps Launching Wscipt | InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"ProcessCommandLine has ".jse" |
| Possible Teams phishing activity | |
| PowerShell Downloads | ProcessCommandLine has "DownloadFile"ProcessCommandLine has "IEX"ProcessCommandLine has "Invoke-Shellcode"ProcessCommandLine has "Invoke-WebRequest"ProcessCommandLine has "Net.WebClient"ProcessCommandLine has "Start-BitsTransfer"ProcessCommandLine has "http"ProcessCommandLine has "mpcmdrun.exe" |
| PowerShell adding exclusion path for Microsoft Defender of ProgramData | |
| Qakbot Campaign Self Deletion | InitiatingProcessCommandLine has "-n 6"InitiatingProcessCommandLine has "127.0.0.1"InitiatingProcessCommandLine has "calc.exe"InitiatingProcessFileName == "cmd.exe" |
| Qakbot Discovery Activies | InitiatingProcessCommandLine endswith "127.0.0.1"InitiatingProcessCommandLine has "-a"InitiatingProcessCommandLine has "-nao"InitiatingProcessCommandLine has "-t"InitiatingProcessCommandLine has "/all"InitiatingProcessFileName in "explorer.exe,mobsync.exe" |
| Qakbot Reconnaissance Activities | ProcessCommandLine has_any "whoami /all" |
| Rare Process as a Service | |
| Regsvr32 Rundll32 with Anomalous Parent Process | |
| Shadow Copy Deletions | |
| Spoolsv Spawning Rundll32 | InitiatingProcessCommandLine endswith "rundll32.exe"InitiatingProcessFileName == "rundll32.exe"InitiatingProcessParentFileName has "spoolsv.exe" |
| Stopping multiple processes using taskkill | |
| Suspicious Tomcat Confluence Process Launch | InitiatingProcessCommandLine has "confluence" |
| Turning off services using sc exe | ProcessCommandLine has "config"ProcessCommandLine has "disabled"ProcessCommandLine has "sc" |
| Webserver Executing Suspicious Applications | InitiatingProcessFileName in "httpd.exe,w3wp.exe" |
In solution MicrosoftDefenderForEndpoint:
| Hunting Query | Selection Criteria |
|---|---|
| Probable AdFind Recon Tool Usage |
Standalone Content:
| Hunting Query | Selection Criteria |
|---|---|
| BadUSB HID injection PowerShell via Windows Run dialog | InitiatingProcessFileName == "explorer.exe"ProcessCommandLine has_all "-ExecutionPolicy"ProcessCommandLine has_all "-WindowStyle" |
| List all the VScode Extensions which are installed on a user system | ProcessCommandLine contains "VSIxs"ProcessCommandLine contains "vsce-sign.exe" |
| MDE_FindsPowerShellExecutionEvents | ProcessCommandLine has "DownloadFile"ProcessCommandLine has "Invoke-Shellcode"ProcessCommandLine has "Invoke-WebRequest"ProcessCommandLine has "Net.WebClient"ProcessCommandLine has "http:" |
| SUNBURST suspicious SolarWinds child processes | InitiatingProcessFileName == "solarwinds.businesslayerhost.exe" |
GitHub Only:
| Hunting Query | Selection Criteria |
|---|---|
| 7-zip-prep-for-exfiltration | ProcessCommandLine contains "ProgramData\\pst" |
| APT Baby Shark | ProcessCommandLine == "cmd.exe /c taskkill /im cmd.exe"ProcessCommandLine startswith "powershell.exe mshta.exe http" |
| APT29 thinktanks | ProcessCommandLine has "-noni -ep bypass $" |
| Abuse.ch Recent Threat Feed | |
| Abuse.ch Recent Threat Feed (1) | |
| Accessibility Features | |
| Add malicious user to Admins and RDP users group via PowerShell | InitiatingProcessFileName == "powershell.exe" |
| AppLocker Policy Design Assistant | FolderPath !startswith "/" |
| Backup deletion | ProcessCommandLine has "delete"ProcessCommandLine has "shadowcopy" |
| BadUSB LOLBIN execution via certutil (HID injection via Run dialog) | InitiatingProcessFileName == "explorer.exe"ProcessCommandLine has "certutil" |
| Base64 Detector and Decoder | |
| Base64encodePEFile | ProcessCommandLine contains "TVqQAAMAAAAEAAA" |
| Baseline Comparison | |
| Bear Activity GTR 2019 | |
| Bitsadmin Activity | ProcessCommandLine has "/Upload"ProcessCommandLine has_any "/Transfer" |
| CVE-2021-36934 usage detection | AccountName != "system"ProcessCommandLine contains "HKLM" |
| Check for multiple signs of ransomware activity | ProcessCommandLine has "cl"ProcessCommandLine has "config"ProcessCommandLine has "delete"ProcessCommandLine has "deletejournal"ProcessCommandLine has "disabled"ProcessCommandLine has "sc"ProcessCommandLine has "shadowcopy delete"ProcessCommandLine has "usn"ProcessCommandLine has "wbadmin"ProcessCommandLine has "wevtutil"ProcessCommandLine has "wmic" |
| Clearing of forensic evidence from event logs using wevtutil | ProcessCommandLine has "CL"ProcessCommandLine has "WEVTUTIL" |
| Cloud Hopper | ProcessCommandLine has ".vbs /shell" |
| Crashing Applications | |
| Create account | InitiatingProcessFileName == "net.exe"ProcessCommandLine !contains "/add"ProcessCommandLine !contains "/domain" |
| Create new user with known DEV-0270 username and password | |
| Critical user management operations followed by disabling of System Restore from admin account | InitiatingProcessFileName == "rundll32.exe"ProcessCommandLine has "Change"ProcessCommandLine has "SystemRestore"ProcessCommandLine has "disable" |
| DLLHost.exe WMIC domain discovery | InitiatingProcessCommandLine == "dllhost.exe"InitiatingProcessFileName == "dllhost.exe"ProcessCommandLine has "wmic computersystem get domain" |
| DLLHost.exe file creation via PowerShell | InitiatingProcessFileName == "powershell.exe" |
| DarkSide | |
| Deletion of data on multiple drives using cipher exe | ProcessCommandLine has "/w" |
| Detect Encoded Powershell | |
| Detect Malicious use of MSIExec | ProcessCommandLine has "http"ProcessCommandLine has "return" |
| Disable Controlled Folders | InitiatingProcessFileName == "cmd.exe" |
| Disabling Services via Registry | |
| Discovering potentially tampered devices [Nobelium] | |
| Discovery for highly-privileged accounts | |
| Dopplepaymer In-Memory Malware Implant | ProcessCommandLine contains "}} -p"ProcessCommandLine startswith "-q -s {{" |
| Dragon Fly | |
| Electron-CVE-2018-1000006 | InitiatingProcessFileName in "chrome.exe,iexplore.exe,runtimebroker.exe"ProcessCommandLine has "--gpu-launcher" |
| Elise backdoor | |
| Email data exfiltration via PowerShell | |
| EmojiHunt | |
| Enumeration of users & groups for lateral movement | ProcessCommandLine !contains "/add"ProcessCommandLine !contains "\\"ProcessCommandLine contains "/do"ProcessCommandLine contains "/domain"ProcessCommandLine contains "group"ProcessCommandLine contains "user" |
| Equation Group C2 Communication | ProcessCommandLine endswith ",dll_u"ProcessCommandLine has "-export dll_u" |
| Excel Macro Execution | InitiatingProcessFileName == "excel.exe" |
| Excel launching anomalous processes | InitiatingProcessFileName in "excel.exe,regsvr32.exe"InitiatingProcessParentFileName has "excel.exe" |
| ExecuteBase64DecodedPayload | ProcessCommandLine contains ".b64decode("ProcessCommandLine contains ".decode("ProcessCommandLine contains ".decode64("ProcessCommandLine contains "base64 --decode" |
| HostExportingMailboxAndRemovingExport[Solarigate] | ProcessCommandLine contains "New-MailboxExportRequest"ProcessCommandLine contains "Remove-MailboxExportRequest" |
| Hunt for RMM tool execution following Teams messages | |
| Hunt for RMM tool execution following Teams messages | |
| Hurricane Panda activity | ProcessCommandLine endswith "localgroup administrators admin /add" |
| Identify unusual identity additions related to EUROPIUM | ProcessCommandLine has "HealthMailbox55x2yq"ProcessCommandLine has_any "New-Mailbox" |
| Imminent Ransomware | |
| Inhibit recovery by disabling tools and functionality | ProcessCommandLine has "REG_DWORD /d \"ProcessCommandLine has_all "reg" |
| Judgement Panda exfil activity | |
| LSASS Credential Dumping with Procdump | ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass"ProcessCommandLine has "lsass.exe" |
| LaZagne Credential Theft | |
| LemonDuck-competition-killer | |
| LemonDuck-component-download-structure | InitiatingProcessFileName == "cmd.exe" |
| LemonDuck-component-names | InitiatingProcessFileName == "cmd.exe" |
| LemonDuck-defender-exclusions | InitiatingProcessCommandLine has_all "Set-MpPreference" |
| Linux-DynoRoot-CVE-2018-1111 | InitiatingProcessCommandLine contains "-dhclient"InitiatingProcessCommandLine contains "/etc/NetworkManager/dispatcher.d/" |
| MITRE - Suspicious Events | |
| MacOceanLotusBackdoor | |
| MacOceanLotusDropper | ProcessCommandLine contains "theme0" |
| Make FolderPath Vogon Poetry | |
| Malware_In_recyclebin | ProcessCommandLine contains ":\\recycler" |
| Masquerading system executable | |
| Mass account password change | |
| Modifying the registry to add a ransom message notification | |
| NTDS theft | ProcessCommandLine has_any "temp" |
| PSExec Attrib commands | InitiatingProcessCommandLine has ".bat"InitiatingProcessParentFileName endswith "PSEXESVC.exe" |
| Password Protected Archive Creation | |
| Possible Ransomware Related Destruction Activity | ProcessCommandLine contains "/grant Everyone:F"ProcessCommandLine contains "/w"ProcessCommandLine has "/all"ProcessCommandLine has "/change"ProcessCommandLine has "/d"ProcessCommandLine has "/disable"ProcessCommandLine has "/quiet"ProcessCommandLine has "delete shadows"ProcessCommandLine has "deletejournal"ProcessCommandLine has "shadowcopy delete"ProcessCommandLine has "usn" |
| Possible Teams phishing activity | |
| Possible command injection attempts against Azure Integration Runtimes | |
| PotentialMicrosoftDefenderTampering[Solarigate] | InitiatingProcessCommandLine has "$true"InitiatingProcessCommandLine has "/IM"InitiatingProcessCommandLine has "/d 1"InitiatingProcessCommandLine has "Set-MpPreference"InitiatingProcessCommandLine has "config"InitiatingProcessParentFileName != "cscript.exe" |
| PowerShell adding exclusion path for Microsoft Defender of ProgramData | |
| PowerShell downloads | ProcessCommandLine has "DownloadFile"ProcessCommandLine has "IEX"ProcessCommandLine has "Invoke-Shellcode"ProcessCommandLine has "Invoke-WebRequest"ProcessCommandLine has "Net.WebClient"ProcessCommandLine has "Start-BitsTransfer"ProcessCommandLine has "http"ProcessCommandLine has "mpcmdrun.exe" |
| Qakbot discovery activies | InitiatingProcessCommandLine endswith "127.0.0.1"InitiatingProcessCommandLine has "-a"InitiatingProcessCommandLine has "-nao"InitiatingProcessCommandLine has "-t"InitiatingProcessCommandLine has "/all"InitiatingProcessFileName in "explorer.exe,mobsync.exe" |
| Qakbot reconnaissance activities | ProcessCommandLine has_any "whoami /all" |
| Ransomware hits healthcare - Alternate Data Streams use | ProcessCommandLine has "-p"ProcessCommandLine startswith "-q -s" |
| Ransomware hits healthcare - Cipher.exe tool deleting data | ProcessCommandLine has "/w" |
| Ransomware hits healthcare - Clearing of system logs | ProcessCommandLine has "deletejournal"ProcessCommandLine has "usn" |
| Ransomware hits healthcare - Robbinhood activity | InitiatingProcessFileName == "winlogon.exe" |
| Ransomware hits healthcare - Turning off System Restore | InitiatingProcessFileName == "rundll32.exe"ProcessCommandLine has "Change"ProcessCommandLine has "SystemRestore"ProcessCommandLine has "disable" |
| Rare firewall rule changes using netsh | InitiatingProcessCommandLine has_all "advfirewall"InitiatingProcessFileName == "netsh.exe" |
| Rare-process-as-a-service | |
| RedMenshen-BPFDoor-backdoor | InitiatingProcessCommandLine has "/dev/shm/kdmtmpflush" |
| Remote Management and Monitoring tool - AeroAdmin - Create Process | ProcessVersionInfoCompanyName has_any "AeroAdmin"ProcessVersionInfoProductName has_any "AeroAdmin" |
| Remote Management and Monitoring tool - Ammyy - Create Process | ProcessVersionInfoCompanyName has "Ammyy"ProcessVersionInfoProductName has "Ammyy Admin" |
| Remote Management and Monitoring tool - AnyDesk - Create Process | ProcessVersionInfoCompanyName has_any "anydesk software"ProcessVersionInfoProductName has "anydesk" |
| Remote Management and Monitoring tool - AnyViewer - Create Process | ProcessVersionInfoCompanyName has "AOMEI"ProcessVersionInfoProductName has "AnyViewer" |
| Remote Management and Monitoring tool - Atera - Create Process | ProcessVersionInfoCompanyName has "Atera Networks" |
| Remote Management and Monitoring tool - AweSun - Create Process | ProcessVersionInfoCompanyName has "AweRay"ProcessVersionInfoProductName has "AweSun" |
| Remote Management and Monitoring tool - BarracudaRMM - Create Process | ProcessVersionInfoCompanyName has_any "Barracuda MSP" |
| Remote Management and Monitoring tool - BeyondTrust - Create Process | ProcessVersionInfoCompanyName has_any "BeyondTrust" |
| Remote Management and Monitoring tool - ChromeRDP - Create Process | ProcessVersionInfoCompanyName has "Google"ProcessVersionInfoProductName has "Chrome Remote Desktop" |
| Remote Management and Monitoring tool - ConnectWise - Create Process | ProcessVersionInfoCompanyName has_any "ConnectWise" |
| Remote Management and Monitoring tool - DameWare - Create Process | ProcessVersionInfoCompanyName has_any "DameWare"ProcessVersionInfoFileDescription has "DameWare"ProcessVersionInfoProductName has "DameWare" |
| Remote Management and Monitoring tool - DesktopNow - Create Process | ProcessVersionInfoCompanyName has "NCH Software"ProcessVersionInfoProductName has "DesktopNow" |
| Remote Management and Monitoring tool - DistantDesktop - Create Process | ProcessVersionInfoCompanyName has "Distant Software"ProcessVersionInfoProductName has "Distant Desktop" |
| Remote Management and Monitoring tool - FleetDeck - Create Process | ProcessVersionInfoCompanyName has "FleetDeck"ProcessVersionInfoProductName has "FleetDeck" |
| Remote Management and Monitoring tool - GetScreen - Create Process | ProcessVersionInfoCompanyName has "getscreen.me"ProcessVersionInfoProductName has "getscreen.me" |
| Remote Management and Monitoring tool - ISLOnline - Create Process | ProcessVersionInfoCompanyName has_any "Xlab"ProcessVersionInfoProductName has_any "ISL Light" |
| Remote Management and Monitoring tool - IperiusRemote - Create Process | ProcessVersionInfoCompanyName has "Enter Srl"ProcessVersionInfoProductName has "Iperius Remote" |
| Remote Management and Monitoring tool - Level - Create Process | |
| Remote Management and Monitoring tool - LiteManager - Create Process | ProcessVersionInfoProductName has_any "LiteManager" |
| Remote Management and Monitoring tool - LogMeIn - Create Process | ProcessVersionInfoCompanyName has "LogMeIn"ProcessVersionInfoProductName has_any "LogMeIn" |
| Remote Management and Monitoring tool - MSP360_CloudBerry - Create Process | ProcessVersionInfoCompanyName has_any "CloudBerry"ProcessVersionInfoProductName has_any "RMM" |
| Remote Management and Monitoring tool - MeshCentral - Create Process | ProcessVersionInfoProductName has "meshcentral" |
| Remote Management and Monitoring tool - NAble - Create Process | ProcessVersionInfoCompanyName has_any "N-Able" |
| Remote Management and Monitoring tool - Naverisk - Create Process | ProcessVersionInfoCompanyName has_any "naverisk" |
| Remote Management and Monitoring tool - NetSupport - Create Process | ProcessVersionInfoCompanyName has "netsupport" |
| Remote Management and Monitoring tool - NinjaRMM - Create Process | ProcessVersionInfoCompanyName has_any "NinjaRMM"ProcessVersionInfoProductName has "NinjaRMM" |
| Remote Management and Monitoring tool - OptiTune - Create Process | ProcessVersionInfoCompanyName has "Bravura Software LLC"ProcessVersionInfoProductName has "OptiTune" |
| Remote Management and Monitoring tool - PDQ - Create Process | ProcessVersionInfoProductName has "PDQConnectAgent" |
| Remote Management and Monitoring tool - Panorama9 - Create Process | ProcessVersionInfoCompanyName has "panorama9"ProcessVersionInfoProductName has "panorama9" |
| Remote Management and Monitoring tool - PcVisit - Create Process | ProcessVersionInfoCompanyName has "pcvisit software ag"ProcessVersionInfoProductName has "pcvisit" |
| Remote Management and Monitoring tool - Pulseway - Create Process | ProcessVersionInfoCompanyName has "MMSoft Design"ProcessVersionInfoProductName has "Pulseway" |
| Remote Management and Monitoring tool - RPort - Create Process | ProcessVersionInfoCompanyName has "RealVNC"ProcessVersionInfoProductName has "rport" |
| Remote Management and Monitoring tool - RealVNC - Create Process | ProcessVersionInfoCompanyName has "realvnc" |
| Remote Management and Monitoring tool - RemoteDesktopPlus - Create Process | ProcessVersionInfoCompanyName has "www.donkz.nl"ProcessVersionInfoOriginalFileName has "rdp.exe"ProcessVersionInfoProductName has "Remote Desktop Plus" |
| Remote Management and Monitoring tool - RemotePC - Create Process | ProcessVersionInfoCompanyName has "idrive"ProcessVersionInfoProductName has_any "remotepc" |
| Remote Management and Monitoring tool - RemoteUtilities - Create Process | ProcessVersionInfoCompanyName has "Remote Utilities"ProcessVersionInfoProductName has "Remote Utilities" |
| Remote Management and Monitoring tool - RustDesk - Create Process | ProcessVersionInfoProductName has "rustdesk" |
| Remote Management and Monitoring tool - ScreenMeet - Create Process | ProcessVersionInfoCompanyName has "Projector Inc"ProcessVersionInfoProductName has "ScreenMeet" |
| Remote Management and Monitoring tool - ServerEye - Create Process | ProcessVersionInfoCompanyName has "Krämer IT Solutions GmbH"ProcessVersionInfoProductName has_any "ServerEye" |
| Remote Management and Monitoring tool - ShowMyPC - Create Process | ProcessVersionInfoCompanyName has "ShowMyPC"ProcessVersionInfoProductName has "ShowMyPC" |
| Remote Management and Monitoring tool - SimpleHelp - Create Process | ProcessVersionInfoCompanyName has "SimpleHelp"ProcessVersionInfoProductName has "SimpleHelp" |
| Remote Management and Monitoring tool - Splashtop - Create Process | ProcessVersionInfoCompanyName has "Splashtop"ProcessVersionInfoProductName has "Splashtop" |
| Remote Management and Monitoring tool - SupRemo - Create Process | ProcessVersionInfoCompanyName has "NanoSystems"ProcessVersionInfoProductName has "SupRemo" |
| Remote Management and Monitoring tool - SyncroMSP - Create Process | ProcessVersionInfoCompanyName has "Servably, Inc."ProcessVersionInfoProductName has "Syncro" |
| Remote Management and Monitoring tool - TacticalRMM - Create Process | ProcessVersionInfoCompanyName has_any "AmidaWare"ProcessVersionInfoProductName has "Tactical RMM" |
| Remote Management and Monitoring tool - TeamViewer - Create Process | ProcessVersionInfoCompanyName has "TeamViewer"ProcessVersionInfoProductName has "TeamViewer" |
| Remote Management and Monitoring tool - TigerVNC - Create Process | ProcessVersionInfoCompanyName has "TigerVNC"ProcessVersionInfoProductName has "TigerVNC" |
| Remote Management and Monitoring tool - TightVNC - Create Process | ProcessVersionInfoCompanyName has "GlavSoft"ProcessVersionInfoProductName has "TightVNC" |
| Remote Management and Monitoring tool - UltraViewer - Create Process | ProcessVersionInfoCompanyName has "DucFabulous"ProcessVersionInfoProductName has "UltraViewer" |
| Remote Management and Monitoring tool - XMReality - Create Process | ProcessVersionInfoCompanyName has "XMReality"ProcessVersionInfoProductName has "XMReality" |
| Remote Management and Monitoring tool - ZohoAssist - Create Process | ProcessVersionInfoCompanyName has "Zoho"ProcessVersionInfoProductName has "Zoho Assist" |
| Remote Management and Monitoring tool - mRemoteNG - Create Process | ProcessVersionInfoProductName has "mRemoteNG" |
| Remote Management and Monitoring tool - parsec.app - Create Process | ProcessVersionInfoCompanyName has "Parsec"ProcessVersionInfoProductName has "Parsec" |
| Remote Management and Montioring tool - Action1 - Create Process | ProcessVersionInfoCompanyName has "Action1"ProcessVersionInfoProductName has "Action1" |
| Renamed Rclone Exfil | ProcessVersionInfoProductName has "rclone" |
| Shadow Copy Deletions | |
| Spoolsv Spawning Rundll32 | InitiatingProcessCommandLine endswith "rundll32.exe"InitiatingProcessFileName == "rundll32.exe"InitiatingProcessParentFileName has "spoolsv.exe" |
| Stolen Images Execution | |
| Stopping multiple processes using taskkill | |
| Stopping processes using net stop | ProcessCommandLine has "stop" |
| StrRAT-AV-Discovery | InitiatingProcessCommandLine has "roaming"InitiatingProcessFileName in "java.exe,javaw.exe"ProcessCommandLine has "path antivirusproduct get displayname" |
| StrRAT-Malware-Persistence | InitiatingProcessFileName in "java.exe,javaw.exe" |
| Suspicious Bitlocker Encryption | ProcessCommandLine contains "1"ProcessCommandLine has "EnableBDEWithNoTPM"ProcessCommandLine has "true" |
| Suspicious JScript staging comment | ProcessCommandLine has "VMBlastSG" |
| Suspicious PowerShell curl flags | |
| Suspicious Tomcat Confluence Process Launch | InitiatingProcessCommandLine has "confluence" |
| Suspicious process event creation from VMWare Horizon TomcatService | InitiatingProcessFileName has "ws_TomcatService.exe" |
| SuspiciousEnumerationUsingAdfind[Nobelium] | ProcessCommandLine matchesregex "(.*)>(.*)" |
| Turning off System Restore | InitiatingProcessFileName == "rundll32.exe"ProcessCommandLine has "Change"ProcessCommandLine has "SystemRestore"ProcessCommandLine has "disable" |
| Turning off services using sc exe | ProcessCommandLine has "config"ProcessCommandLine has "disabled"ProcessCommandLine has "sc" |
| Use of MSBuild as LOLBin | InitiatingProcessFileName == "wmiprvse.exe"ProcessCommandLine has "programdata" |
| VMWare-LPE-2022-22960 | InitiatingProcessCommandLine has_any "/opt/vmware/certproxy/bing/certproxyService.sh" |
| WastedLocker Downloader | InitiatingProcessFileName == "wscript.exe" |
| Webserver Executing Suspicious Applications | InitiatingProcessFileName in "httpd.exe,w3wp.exe" |
| Zip-Doc - Word Launching MSHTA | InitiatingProcessFileName == "WINWORD.EXE" |
| alt-data-streams | ProcessCommandLine startswith "-q -s" |
| anomalous-payload-delivered-from-iso-file | ActionType == "BrowserLaunchedToOpenUrl" |
| app-armor-stopped | InitiatingProcessCommandLine has "/bin/bash /tmp/"ProcessCommandLine has "service apparmor stop" |
| apt sofacy | |
| apt sofacy zebrocy | ProcessCommandLine endswith "cmd.exe /c SYSTEMINFO & TASKLIST" |
| apt ta17 293a ps | ProcessCommandLine == "ps.exe -accepteula" |
| apt tropictrooper | ProcessCommandLine contains "abCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCc" |
| apt unidentified nov 18 | ProcessCommandLine endswith "cyzfc.dat, PointFunctionCall" |
| check-for-shadowhammer-activity-implant | |
| clear-system-logs | ProcessCommandLine has "deletejournal"ProcessCommandLine has "usn" |
| cobalt-strike-invoked-w-wmi | InitiatingProcessFileName == "wmiprvse.exe"ProcessCommandLine !has "Windows\\CCM\\"ProcessCommandLine contains "frombase64"ProcessCommandLine matchesregex "[A-Za-z0-9+/]{50,}[=]{0,2}" |
| confluence-weblogic-targeted | InitiatingProcessCommandLine contains "//confluence"InitiatingProcessFileName == "beasvc.exe"InitiatingProcessParentFileName == "beasvc.exe"ProcessCommandLine !contains "ApplicationNo"ProcessCommandLine !contains "Cosmos"ProcessCommandLine !contains "CustomerGroup"ProcessCommandLine !contains "Unrestricted"ProcessCommandLine !startswith "POWERSHELL.EXE -C \"ProcessCommandLine contains "$"ProcessCommandLine contains "-e"ProcessCommandLine contains "-split"ProcessCommandLine contains ">"ProcessCommandLine contains "@echo"ProcessCommandLine contains "encodedcommand"ProcessCommandLine contains "wget" |
| cve-2019-0808-set-scheduled-task | ProcessCommandLine contains "ecosetup"ProcessCommandLine contains "highest"ProcessCommandLine contains "spsextserv.exe" |
| cypherpunk-exclusive-commands | InitiatingProcessParentFileName startswith "psexe"ProcessCommandLine has "Dvr /go" |
| cypherpunk-remote-exec-w-psexesvc | InitiatingProcessCommandLine has ".bat"InitiatingProcessParentFileName startswith "psexe"ProcessCommandLine has "DisableIOAVProtection" |
| deleting-data-w-cipher-tool | ProcessCommandLine has "/w" |
| detect-anomalous-process-trees | |
| detect-cve-2019-0863-AngryPolarBearBug2-exploit | ProcessCommandLine contains "/run"ProcessCommandLine contains "Windows Error Reporting" |
| detect-cve-2019-0973-installerbypass-exploit | ProcessCommandLine contains "/fa"ProcessCommandLine contains ":\\windows\\installer" |
| detect-cve-2019-1129-byebear-exploit | ProcessCommandLine contains "del"ProcessCommandLine contains "rmdir" |
| detect-cyzfc-activity (2) | ProcessCommandLine contains "-noni -ep bypass $zk=" |
| detect-cyzfc-activity (3) | ProcessCommandLine contains "https://www.jmj.com/personal/nauerthn_state_gov" |
| detect-doublepulsar-execution | ProcessCommandLine contains "payload"ProcessCommandLine contains "targetip"ProcessCommandLine contains "targetport"ProcessCommandLine contains "verifybackdoor" |
| detect-exploitation-of-cve-2018-8653 | InitiatingProcessCommandLine contains "WinHttpAutoProxySvc"InitiatingProcessFileName == "svchost.exe" |
| detect-impacket-atexec | ActionType in "NamedPipeEvent,RegistryKeyCreated" |
| detect-impacket-dcomexec | ActionType == "InboundConnectionAccepted" |
| detect-impacket-psexec-module | ActionType == "FileCreated" |
| detect-impacket-wmiexec | |
| detect-impacket-wmiexec | |
| detect-impacket-wmiexec | |
| detect-mailsniper | |
| detect-malicious-rar-extraction | |
| detect-malicious-use-of-msiexec | ProcessCommandLine has "http"ProcessCommandLine has "return" |
| detect-malicious-use-of-msiexec-mimikatz | InitiatingProcessFileName == "msiexec.exe"ProcessCommandLine contains "privilege::"ProcessCommandLine contains "token::"ProcessCommandLine has "sekurlsa" |
| detect-malicious-use-of-msiexec-powershell | ProcessCommandLine contains "%temp%" |
| detect-nbtscan-activity | |
| detect-office-applications-spawning-msdt-CVE-2022-30190 | InitiatingProcessFileName in "excel.exe,outlook.exe,powerpnt.exe,winword.exe" |
| detect-office-products-spawning-wmic | InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe" |
| detect-prifou-pua | ProcessCommandLine has "/mds"ProcessCommandLine has "/mhp"ProcessCommandLine has "/mnl"ProcessCommandLine has "/mnt"ProcessCommandLine has "bundlename=chromium"ProcessCommandLine has "rsf" |
| detect-steganography-exfiltration | |
| detect-suspicious-commands-initiated-by-web-server-processes | InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessFileName startswith "tomcat"InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessParentFileName startswith "tomcat"ProcessCommandLine contains "%temp%"ProcessCommandLine has "certutil"ProcessCommandLine has "ipconfig"ProcessCommandLine has "ping"ProcessCommandLine has "systeminfo"ProcessCommandLine has "timeout"ProcessCommandLine has "wget"ProcessCommandLine has "whoami" |
| detect-suspicious-mshta-usage | InitiatingProcessCommandLine contains "<script>"InitiatingProcessFileName == "mshta.exe" |
| detect-uac-elevation | ProcessTokenElevation == "TokenElevationTypeFull" |
| detect-web-server-exploit-doublepulsar | InitiatingProcessCommandLine contains "//confluence"InitiatingProcessFileName == "beasvc.exe"InitiatingProcessParentFileName == "beasvc.exe"ProcessCommandLine !contains "ApplicationNo"ProcessCommandLine !contains "Cosmos"ProcessCommandLine !contains "CustomerGroup"ProcessCommandLine !contains "Unrestricted"ProcessCommandLine !startswith "POWERSHELL.EXE -C \"ProcessCommandLine contains "$"ProcessCommandLine contains "-e"ProcessCommandLine contains "-split"ProcessCommandLine contains ">"ProcessCommandLine contains "@echo"ProcessCommandLine contains "encodedcommand"ProcessCommandLine contains "wget" |
| doppelpaymer | |
| doppelpaymer-procdump | ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass" |
| doppelpaymer-psexec | InitiatingProcessFileName startswith "psexe" |
| doppelpaymer-stop-services | InitiatingProcessFileName startswith "psexe"ProcessCommandLine has "msexchange"ProcessCommandLine has "sql"ProcessCommandLine has "stop-service" |
| evasive-powershell-executions | ProcessCommandLine has_all "-command" |
| evasive-powershell-strings | |
| exchange-powershell-snapin-loaded | ProcessCommandLine contains "Add-PSSnapin Microsoft.Exchange.Powershell.Snapin" |
| hiding-java-class-file | ProcessCommandLine contains ".class"ProcessCommandLine has "attrib +h +s +r" |
| insider-threat-detection-queries (13) | |
| insider-threat-detection-queries (14) | |
| insider-threat-detection-queries (2) | |
| insider-threat-detection-queries (3) | |
| insider-threat-detection-queries (8) | |
| java-executing-cmd-to-run-powershell | InitiatingProcessFileName == "java.exe" |
| jse-launched-by-word | InitiatingProcessFileName in "explorer.exe,winword.exe"ProcessCommandLine contains ".jse" |
| kinsing-miner-download | |
| launch-questd-w-osascript | ProcessCommandLine contains "questd"ProcessCommandLine has "osascript -e do shell script \" |
| launching-base64-powershell[Nobelium] | InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe" |
| launching-cmd-echo[Nobelium] | InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe"ProcessCommandLine has "echo" |
| lazagne | ProcessCommandLine has "hklm"ProcessCommandLine has "sam"ProcessCommandLine has "save" |
| locate-shlayer-payload-decryption-activity | ProcessCommandLine has "-base64"ProcessCommandLine has "-nosalt"ProcessCommandLine has "-out" |
| locate-shlayer-payload-decrytion-activity | ProcessCommandLine has "-base64"ProcessCommandLine has "-nosalt"ProcessCommandLine has "-out" |
| locate-surfbuyer-downloader-decoding-activity | ProcessCommandLine has "/tmp/e_"ProcessCommandLine has "base64" |
| oceanlotus-apt32-files | |
| office-apps-launching-wscipt | InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"ProcessCommandLine has ".jse" |
| oracle-webLogic-executing-powershell | |
| powercat-download | ProcessCommandLine endswith "powercat.ps1" |
| powershell-activity-after-email-from-malicious-sender | InitiatingProcessParentFileName == "outlook.exe" |
| powershell-version-2.0-execution | ProcessCommandLine has "-v 2"ProcessCommandLine has "-v 2.0"ProcessCommandLine has "-version 2"ProcessCommandLine has "-version 2.0" |
| procdump-lsass-credentials | ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass"ProcessCommandLine has "lsass.exe" |
| python-based-attacks-on-macos | InitiatingProcessParentFileName in "Microsoft Excel,Microsoft Word"ProcessCommandLine matchesregex "[A-Za-z0-9]{50}" |
| python-use-by-ransomware-macos | ProcessCommandLine contains "EIKKEIKK"ProcessCommandLine contains "python" |
| qakbot-campaign-esentutl | ProcessCommandLine has "WebCache"ProcessCommandLine has_any "V01" |
| qakbot-campaign-process-injection | ProcessCommandLine has "WebCache"ProcessCommandLine has_any "V01" |
| qakbot-campaign-self-deletion | InitiatingProcessCommandLine has "-n 6"InitiatingProcessCommandLine has "127.0.0.1"InitiatingProcessCommandLine has "calc.exe"InitiatingProcessFileName == "cmd.exe" |
| qakbot-campaign-suspicious-javascript | InitiatingProcessCommandLine has "start /MIN"InitiatingProcessFileName == "cmd.exe"ProcessCommandLine has "E:javascript" |
| ransom-note-creation-macos | ProcessCommandLine has "say \\\" |
| rare_sch_task_with_activity | |
| rce-on-vulnerable-server | InitiatingProcessCommandLine has "php-cgi.exe"ProcessCommandLine has_all "curl -fsSL" |
| regsvr32-rundll32-with-anomalous-parent-process | |
| reverse-shell-nishang | ProcessCommandLine contains "$client = New-Object System.Net.Sockets.TCPClient" |
| reverse-shell-nishang-base64 | ProcessCommandLine contains "-e" |
| reverse-shell-ransomware-macos | ProcessCommandLine has "bash -i >& /dev/tcp/" |
| robbinhood-evasion | InitiatingProcessFileName == "winlogon.exe" |
| shimcache-flushed | ProcessCommandLine has_any "apphelp.dll" |
| sql-server-abuse | InitiatingProcessFileName in "launchpad.exe,sqlagent.exe,sqlps.exe,sqlservr.exe" |
| tomcat-8-executing-powershell | InitiatingProcessFileName in "cmd.exe,powershell.exe"InitiatingProcessParentFileName startswith "tomcat"ProcessCommandLine has_any "cmd.exe" |
| turn-off-system-restore | InitiatingProcessFileName == "rundll32.exe"ProcessCommandLine has "Change"ProcessCommandLine has "SystemRestore"ProcessCommandLine has "disable" |
| umworkerprocess-unusual-subprocess-activity | InitiatingProcessFileName == "UMWorkerProcess.exe" |
| wadhrama-data-destruction | ProcessCommandLine has "delete"ProcessCommandLine has "shadowcopy" |
| wadhrama-ransomware | |
| wdigest-caching | ProcessCommandLine has "1"ProcessCommandLine has "UseLogonCredential"ProcessCommandLine has "WDigest"ProcessCommandLine has "dword" |
| wifikeys | ProcessCommandLine has "key=clear"ProcessCommandLine startswith "netsh" |
In solution HIPAA Compliance: ProcessCommandLine has "Set-MpPreference"
| Workbook |
|---|
| HIPAACompliance |
In solution Lumen Defender Threat Feed:
| Workbook | Selection Criteria |
|---|---|
| Lumen-Threat-Feed-Overview |
In solution MaturityModelForEventLogManagementM2131: ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"
| Workbook |
|---|
| MaturityModelForEventLogManagement_M2131 |
In solution Microsoft Defender XDR:
| Workbook | Selection Criteria |
|---|---|
| MicrosoftDefenderForEndPoint |
GitHub Only:
| Workbook | Selection Criteria |
|---|---|
| MicrosoftDefenderForEndPoint | |
| MicrosoftSentinelDeploymentandMigrationTracker | |
| SolarWindsPostCompromiseHunting | ActionType == "RemoteInteractiveLogon"ActionType == "LdapSearch" |
| WorkspaceUsage |
| Parser | Schema | Product | Selection Criteria |
|---|---|---|---|
| ASimProcessEventMicrosoft365D | ProcessEvent | Microsoft 365 Defender for endpoint |
References by type: 0 connectors, 256 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
ProcessCommandLine has "/w" |
- | 5 | - | - | 5 |
InitiatingProcessFileName == "rundll32.exe"ProcessCommandLine has "Change"ProcessCommandLine has "SystemRestore"ProcessCommandLine has "disable" |
- | 4 | - | - | 4 |
ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass" |
- | 3 | - | - | 3 |
ProcessCommandLine contains "-ma"ProcessCommandLine has "-accepteula"ProcessCommandLine has "lsass"ProcessCommandLine has "lsass.exe" |
- | 3 | - | - | 3 |
InitiatingProcessFileName startswith "psexe"ProcessCommandLine has "msexchange"ProcessCommandLine has "sql"ProcessCommandLine has "stop-service" |
- | 3 | - | - | 3 |
InitiatingProcessCommandLine has "-n 6"InitiatingProcessCommandLine has "127.0.0.1"InitiatingProcessCommandLine has "calc.exe"InitiatingProcessFileName == "cmd.exe" |
- | 3 | - | - | 3 |
InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessFileName startswith "tomcat"InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"InitiatingProcessParentFileName startswith "tomcat"ProcessCommandLine contains "%temp%"ProcessCommandLine has "certutil"ProcessCommandLine has "ipconfig"ProcessCommandLine has "ping"ProcessCommandLine has "systeminfo"ProcessCommandLine has "timeout"ProcessCommandLine has "wget"ProcessCommandLine has "whoami" |
- | 3 | - | - | 3 |
ProcessCommandLine has "/Upload"ProcessCommandLine has_any "/Transfer" |
- | 3 | - | - | 3 |
InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"ProcessCommandLine has ".jse" |
- | 3 | - | - | 3 |
InitiatingProcessFileName == "net.exe"ProcessCommandLine !contains "/add"ProcessCommandLine !contains "/domain" |
- | 3 | - | - | 3 |
ProcessCommandLine has "CL"ProcessCommandLine has "WEVTUTIL" |
- | 3 | - | - | 3 |
InitiatingProcessCommandLine endswith "127.0.0.1"InitiatingProcessCommandLine has "-a"InitiatingProcessCommandLine has "-nao"InitiatingProcessCommandLine has "-t"InitiatingProcessCommandLine has "/all"InitiatingProcessFileName in "explorer.exe,mobsync.exe" |
- | 3 | - | - | 3 |
InitiatingProcessFileName == "java.exe" |
- | 3 | - | - | 3 |
ProcessCommandLine has "deletejournal"ProcessCommandLine has "usn" |
- | 3 | - | - | 3 |
InitiatingProcessFileName == "cmd.exe" |
- | 3 | - | - | 3 |
InitiatingProcessFileName == "solarwinds.businesslayerhost.exe" |
- | 2 | - | - | 2 |
InitiatingProcessCommandLine has_all "advfirewall"InitiatingProcessFileName == "netsh.exe" |
- | 2 | - | - | 2 |
ProcessCommandLine has "hklm"ProcessCommandLine has "sam"ProcessCommandLine has "save" |
- | 2 | - | - | 2 |
ProcessCommandLine !contains "/add"ProcessCommandLine !contains "\\"ProcessCommandLine contains "/do"ProcessCommandLine contains "/domain"ProcessCommandLine contains "group"ProcessCommandLine contains "user" |
- | 2 | - | - | 2 |
ActionType == "BrowserLaunchedToOpenUrl" |
- | 2 | - | - | 2 |
ProcessCommandLine has "http"ProcessCommandLine has "return" |
- | 2 | - | - | 2 |
InitiatingProcessFileName == "msiexec.exe"ProcessCommandLine contains "privilege::"ProcessCommandLine contains "token::"ProcessCommandLine has "sekurlsa" |
- | 2 | - | - | 2 |
ProcessCommandLine has "DownloadFile"ProcessCommandLine has "IEX"ProcessCommandLine has "Invoke-Shellcode"ProcessCommandLine has "Invoke-WebRequest"ProcessCommandLine has "Net.WebClient"ProcessCommandLine has "Start-BitsTransfer"ProcessCommandLine has "http"ProcessCommandLine has "mpcmdrun.exe" |
- | 2 | - | - | 2 |
InitiatingProcessFileName in "httpd.exe,w3wp.exe" |
- | 2 | - | - | 2 |
InitiatingProcessCommandLine contains "<script>"InitiatingProcessFileName == "mshta.exe" |
- | 2 | - | - | 2 |
InitiatingProcessCommandLine has "confluence" |
- | 2 | - | - | 2 |
ProcessCommandLine has "cl"ProcessCommandLine has "config"ProcessCommandLine has "delete"ProcessCommandLine has "deletejournal"ProcessCommandLine has "disabled"ProcessCommandLine has "sc"ProcessCommandLine has "shadowcopy delete"ProcessCommandLine has "usn"ProcessCommandLine has "wbadmin"ProcessCommandLine has "wevtutil"ProcessCommandLine has "wmic" |
- | 2 | - | - | 2 |
ProcessCommandLine has "config"ProcessCommandLine has "disabled"ProcessCommandLine has "sc" |
- | 2 | - | - | 2 |
InitiatingProcessCommandLine == "dllhost.exe"InitiatingProcessFileName == "dllhost.exe"ProcessCommandLine has "wmic computersystem get domain" |
- | 2 | - | - | 2 |
InitiatingProcessCommandLine endswith "rundll32.exe"InitiatingProcessFileName == "rundll32.exe"InitiatingProcessParentFileName has "spoolsv.exe" |
- | 2 | - | - | 2 |
InitiatingProcessFileName == "wmiprvse.exe"ProcessCommandLine has "programdata" |
- | 2 | - | - | 2 |
ProcessCommandLine has_any "whoami /all" |
- | 2 | - | - | 2 |
InitiatingProcessCommandLine contains "//confluence"InitiatingProcessFileName == "beasvc.exe"InitiatingProcessParentFileName == "beasvc.exe"ProcessCommandLine !contains "ApplicationNo"ProcessCommandLine !contains "Cosmos"ProcessCommandLine !contains "CustomerGroup"ProcessCommandLine !contains "Unrestricted"ProcessCommandLine !startswith "POWERSHELL.EXE -C \"ProcessCommandLine contains "$"ProcessCommandLine contains "-e"ProcessCommandLine contains "-split"ProcessCommandLine contains ">"ProcessCommandLine contains "@echo"ProcessCommandLine contains "encodedcommand"ProcessCommandLine contains "wget" |
- | 2 | - | - | 2 |
InitiatingProcessFileName == "winlogon.exe" |
- | 2 | - | - | 2 |
ProcessCommandLine has "WebCache"ProcessCommandLine has_any "V01" |
- | 2 | - | - | 2 |
ProcessCommandLine has "-base64"ProcessCommandLine has "-nosalt"ProcessCommandLine has "-out" |
- | 2 | - | - | 2 |
ProcessCommandLine has "delete"ProcessCommandLine has "shadowcopy" |
- | 2 | - | - | 2 |
InitiatingProcessFileName == "powershell.exe" |
- | 2 | - | - | 2 |
ProcessCommandLine has "certutil" |
- | 1 | - | - | 1 |
ActionType != "ListeningConnectionCreated"InitiatingProcessParentFileName == "svchost.exe" |
- | 1 | - | - | 1 |
InitiatingProcessVersionInfoProductName != "Android Studio" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "oracle.exe" |
- | 1 | - | - | 1 |
ActionType == "LogonSuccess" |
- | 1 | - | - | 1 |
ActionType == "InboundConnectionAccepted"ProcessCommandLine != "msiexec.exe /V" |
- | 1 | - | - | 1 |
FolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"InitiatingProcessFileName in "WDExpress.exe,devenv.exe"InitiatingProcessFolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"ProcessCommandLine has_any "/exe"ProcessCommandLine has_any "out" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has_any "E9495B87-D950-4AB5-87A5-FF6D70BF3E90"InitiatingProcessFileName == "dllhost.exe"ProcessIntegrityLevel == "High" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "wsreset.exe"ProcessIntegrityLevel == "High" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "changepk.exe"InitiatingProcessParentFileName == "slui.exe"ProcessIntegrityLevel == "High" |
- | 1 | - | - | 1 |
ActionType in "FileCreated,FileModified" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "auditpol.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine has "powershell.exe" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has "$true"InitiatingProcessCommandLine has "/IM"InitiatingProcessCommandLine has "Set-MpPreference"InitiatingProcessCommandLine has "Start"InitiatingProcessCommandLine has "config"InitiatingProcessParentFileName != "cscript.exe" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV"ProcessCommandLine matchesregex "cmd.exe /c"ProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "explorer.exe"ProcessCommandLine has_all "-ExecutionPolicy"ProcessCommandLine has_all "-WindowStyle" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "VSIxs"ProcessCommandLine contains "vsce-sign.exe" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "explorer.exe"ProcessCommandLine has "certutil" |
- | 1 | - | - | 1 |
ProcessCommandLine == "cmd.exe /c taskkill /im cmd.exe"ProcessCommandLine startswith "powershell.exe mshta.exe http" |
- | 1 | - | - | 1 |
ProcessCommandLine endswith "cmd.exe /c SYSTEMINFO & TASKLIST" |
- | 1 | - | - | 1 |
ProcessCommandLine == "ps.exe -accepteula" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "abCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCc" |
- | 1 | - | - | 1 |
ProcessCommandLine endswith "cyzfc.dat, PointFunctionCall" |
- | 1 | - | - | 1 |
ProcessCommandLine has "-noni -ep bypass $" |
- | 1 | - | - | 1 |
ProcessCommandLine has ".vbs /shell" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "wmiprvse.exe"ProcessCommandLine !has "Windows\\CCM\\"ProcessCommandLine contains "frombase64"ProcessCommandLine matchesregex "[A-Za-z0-9+/]{50,}[=]{0,2}" |
- | 1 | - | - | 1 |
InitiatingProcessParentFileName startswith "psexe"ProcessCommandLine has "Dvr /go" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has ".bat"InitiatingProcessParentFileName startswith "psexe"ProcessCommandLine has "DisableIOAVProtection" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "-noni -ep bypass $zk=" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "https://www.jmj.com/personal/nauerthn_state_gov" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "}} -p"ProcessCommandLine startswith "-q -s {{" |
- | 1 | - | - | 1 |
ProcessCommandLine endswith ",dll_u"ProcessCommandLine has "-export dll_u" |
- | 1 | - | - | 1 |
ProcessCommandLine endswith "localgroup administrators admin /add" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe"ProcessCommandLine has "echo" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "theme0" |
- | 1 | - | - | 1 |
ProcessCommandLine has "-p"ProcessCommandLine startswith "-q -s" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has "/dev/shm/kdmtmpflush" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "wscript.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "New-MailboxExportRequest"ProcessCommandLine contains "Remove-MailboxExportRequest" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "EIKKEIKK"ProcessCommandLine contains "python" |
- | 1 | - | - | 1 |
ProcessCommandLine has "bash -i >& /dev/tcp/" |
- | 1 | - | - | 1 |
ProcessCommandLine has "1"ProcessCommandLine has "UseLogonCredential"ProcessCommandLine has "WDigest"ProcessCommandLine has "dword" |
- | 1 | - | - | 1 |
ProcessCommandLine startswith "-q -s" |
- | 1 | - | - | 1 |
ProcessCommandLine contains ".class"ProcessCommandLine has "attrib +h +s +r" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has "$true"InitiatingProcessCommandLine has "/IM"InitiatingProcessCommandLine has "/d 1"InitiatingProcessCommandLine has "Set-MpPreference"InitiatingProcessCommandLine has "config"InitiatingProcessParentFileName != "cscript.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine has_any "apphelp.dll" |
- | 1 | - | - | 1 |
ProcessCommandLine endswith "powercat.ps1" |
- | 1 | - | - | 1 |
ProcessCommandLine has "DownloadFile"ProcessCommandLine has "Invoke-Shellcode"ProcessCommandLine has "Invoke-WebRequest"ProcessCommandLine has "Net.WebClient"ProcessCommandLine has "http:" |
- | 1 | - | - | 1 |
ProcessCommandLine matchesregex "(.*)>(.*)" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "TVqQAAMAAAAEAAA" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "payload"ProcessCommandLine contains "targetip"ProcessCommandLine contains "targetport"ProcessCommandLine contains "verifybackdoor" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine contains "WinHttpAutoProxySvc"InitiatingProcessFileName == "svchost.exe" |
- | 1 | - | - | 1 |
ActionType in "NamedPipeEvent,RegistryKeyCreated" |
- | 1 | - | - | 1 |
ActionType == "InboundConnectionAccepted" |
- | 1 | - | - | 1 |
ActionType == "FileCreated" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "%temp%" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "excel.exe,outlook.exe,powerpnt.exe,winword.exe" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine contains ".b64decode("ProcessCommandLine contains ".decode("ProcessCommandLine contains ".decode64("ProcessCommandLine contains "base64 --decode" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "explorer.exe,winword.exe"ProcessCommandLine contains ".jse" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "questd"ProcessCommandLine has "osascript -e do shell script \" |
- | 1 | - | - | 1 |
ProcessCommandLine has "/tmp/e_"ProcessCommandLine has "base64" |
- | 1 | - | - | 1 |
ProcessCommandLine contains ":\\recycler" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "/grant Everyone:F"ProcessCommandLine contains "/w"ProcessCommandLine has "/all"ProcessCommandLine has "/change"ProcessCommandLine has "/d"ProcessCommandLine has "/disable"ProcessCommandLine has "/quiet"ProcessCommandLine has "delete shadows"ProcessCommandLine has "deletejournal"ProcessCommandLine has "shadowcopy delete"ProcessCommandLine has "usn" |
- | 1 | - | - | 1 |
InitiatingProcessParentFileName == "outlook.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine has "-v 2"ProcessCommandLine has "-v 2.0"ProcessCommandLine has "-version 2"ProcessCommandLine has "-version 2.0" |
- | 1 | - | - | 1 |
InitiatingProcessParentFileName in "Microsoft Excel,Microsoft Word"ProcessCommandLine matchesregex "[A-Za-z0-9]{50}" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has "start /MIN"InitiatingProcessFileName == "cmd.exe"ProcessCommandLine has "E:javascript" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "-e" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "$client = New-Object System.Net.Sockets.TCPClient" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "launchpad.exe,sqlagent.exe,sqlps.exe,sqlservr.exe" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "UMWorkerProcess.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "ProgramData\\pst" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "Add-PSSnapin Microsoft.Exchange.Powershell.Snapin" |
- | 1 | - | - | 1 |
AccountName != "system"ProcessCommandLine contains "HKLM" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "chrome.exe,iexplore.exe,runtimebroker.exe"ProcessCommandLine has "--gpu-launcher" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine contains "-dhclient"InitiatingProcessCommandLine contains "/etc/NetworkManager/dispatcher.d/" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has_any "/opt/vmware/certproxy/bing/certproxyService.sh" |
- | 1 | - | - | 1 |
FolderPath !startswith "/" |
- | 1 | - | - | 1 |
ProcessCommandLine has "key=clear"ProcessCommandLine startswith "netsh" |
- | 1 | - | - | 1 |
ProcessCommandLine has "say \\\" |
- | 1 | - | - | 1 |
InitiatingProcessFileName startswith "psexe" |
- | 1 | - | - | 1 |
ProcessCommandLine has "/mds"ProcessCommandLine has "/mhp"ProcessCommandLine has "/mnl"ProcessCommandLine has "/mnt"ProcessCommandLine has "bundlename=chromium"ProcessCommandLine has "rsf" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "ecosetup"ProcessCommandLine contains "highest"ProcessCommandLine contains "spsextserv.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "/run"ProcessCommandLine contains "Windows Error Reporting" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "/fa"ProcessCommandLine contains ":\\windows\\installer" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "del"ProcessCommandLine contains "rmdir" |
- | 1 | - | - | 1 |
ProcessCommandLine has "stop" |
- | 1 | - | - | 1 |
ProcessCommandLine contains "1"ProcessCommandLine has "EnableBDEWithNoTPM"ProcessCommandLine has "true" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Action1"ProcessVersionInfoProductName has "Action1" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "AeroAdmin"ProcessVersionInfoProductName has_any "AeroAdmin" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Ammyy"ProcessVersionInfoProductName has "Ammyy Admin" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "anydesk software"ProcessVersionInfoProductName has "anydesk" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "AOMEI"ProcessVersionInfoProductName has "AnyViewer" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Atera Networks" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "AweRay"ProcessVersionInfoProductName has "AweSun" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "Barracuda MSP" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "BeyondTrust" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Google"ProcessVersionInfoProductName has "Chrome Remote Desktop" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "ConnectWise" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "DameWare"ProcessVersionInfoFileDescription has "DameWare"ProcessVersionInfoProductName has "DameWare" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "NCH Software"ProcessVersionInfoProductName has "DesktopNow" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Distant Software"ProcessVersionInfoProductName has "Distant Desktop" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "FleetDeck"ProcessVersionInfoProductName has "FleetDeck" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "getscreen.me"ProcessVersionInfoProductName has "getscreen.me" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Enter Srl"ProcessVersionInfoProductName has "Iperius Remote" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "Xlab"ProcessVersionInfoProductName has_any "ISL Light" |
- | 1 | - | - | 1 |
ProcessVersionInfoProductName has_any "LiteManager" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "LogMeIn"ProcessVersionInfoProductName has_any "LogMeIn" |
- | 1 | - | - | 1 |
ProcessVersionInfoProductName has "meshcentral" |
- | 1 | - | - | 1 |
ProcessVersionInfoProductName has "mRemoteNG" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "CloudBerry"ProcessVersionInfoProductName has_any "RMM" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "N-Able" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "naverisk" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "netsupport" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "NinjaRMM"ProcessVersionInfoProductName has "NinjaRMM" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Bravura Software LLC"ProcessVersionInfoProductName has "OptiTune" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "panorama9"ProcessVersionInfoProductName has "panorama9" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Parsec"ProcessVersionInfoProductName has "Parsec" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "pcvisit software ag"ProcessVersionInfoProductName has "pcvisit" |
- | 1 | - | - | 1 |
ProcessVersionInfoProductName has "PDQConnectAgent" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "MMSoft Design"ProcessVersionInfoProductName has "Pulseway" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "realvnc" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "www.donkz.nl"ProcessVersionInfoOriginalFileName has "rdp.exe"ProcessVersionInfoProductName has "Remote Desktop Plus" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "idrive"ProcessVersionInfoProductName has_any "remotepc" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Remote Utilities"ProcessVersionInfoProductName has "Remote Utilities" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "RealVNC"ProcessVersionInfoProductName has "rport" |
- | 1 | - | - | 1 |
ProcessVersionInfoProductName has "rustdesk" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Projector Inc"ProcessVersionInfoProductName has "ScreenMeet" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Krämer IT Solutions GmbH"ProcessVersionInfoProductName has_any "ServerEye" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "ShowMyPC"ProcessVersionInfoProductName has "ShowMyPC" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "SimpleHelp"ProcessVersionInfoProductName has "SimpleHelp" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Splashtop"ProcessVersionInfoProductName has "Splashtop" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "NanoSystems"ProcessVersionInfoProductName has "SupRemo" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Servably, Inc."ProcessVersionInfoProductName has "Syncro" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has_any "AmidaWare"ProcessVersionInfoProductName has "Tactical RMM" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "TeamViewer"ProcessVersionInfoProductName has "TeamViewer" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "TigerVNC"ProcessVersionInfoProductName has "TigerVNC" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "GlavSoft"ProcessVersionInfoProductName has "TightVNC" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "DucFabulous"ProcessVersionInfoProductName has "UltraViewer" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "XMReality"ProcessVersionInfoProductName has "XMReality" |
- | 1 | - | - | 1 |
ProcessVersionInfoCompanyName has "Zoho"ProcessVersionInfoProductName has "Zoho Assist" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "excel.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine has_any "temp" |
- | 1 | - | - | 1 |
ProcessVersionInfoProductName has "rclone" |
- | 1 | - | - | 1 |
InitiatingProcessFileName == "WINWORD.EXE" |
- | 1 | - | - | 1 |
ProcessCommandLine has "HealthMailbox55x2yq"ProcessCommandLine has_any "New-Mailbox" |
- | 1 | - | - | 1 |
ProcessCommandLine has_all "-command" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has_all "Set-MpPreference" |
- | 1 | - | - | 1 |
ProcessCommandLine has "VMBlastSG" |
- | 1 | - | - | 1 |
InitiatingProcessFileName has "ws_TomcatService.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine has "REG_DWORD /d \"ProcessCommandLine has_all "reg" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has ".bat"InitiatingProcessParentFileName endswith "PSEXESVC.exe" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "excel.exe,regsvr32.exe"InitiatingProcessParentFileName has "excel.exe" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has "roaming"InitiatingProcessFileName in "java.exe,javaw.exe"ProcessCommandLine has "path antivirusproduct get displayname" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "java.exe,javaw.exe" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has "/bin/bash /tmp/"ProcessCommandLine has "service apparmor stop" |
- | 1 | - | - | 1 |
InitiatingProcessCommandLine has "php-cgi.exe"ProcessCommandLine has_all "curl -fsSL" |
- | 1 | - | - | 1 |
InitiatingProcessFileName in "cmd.exe,powershell.exe"InitiatingProcessParentFileName startswith "tomcat"ProcessCommandLine has_any "cmd.exe" |
- | 1 | - | - | 1 |
ProcessCommandLine has "Set-MpPreference" |
- | 1 | - | - | 1 |
ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user" |
- | 1 | - | - | 1 |
| Total | 0 | 256 | 0 | 0 | 256 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= system |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
InboundConnectionAccepted |
- | 2 | - | - | 2 |
FileCreated |
- | 2 | - | - | 2 |
BrowserLaunchedToOpenUrl |
- | 2 | - | - | 2 |
!= ListeningConnectionCreated |
- | 1 | - | - | 1 |
LogonSuccess |
- | 1 | - | - | 1 |
FileModified |
- | 1 | - | - | 1 |
NamedPipeEvent |
- | 1 | - | - | 1 |
RegistryKeyCreated |
- | 1 | - | - | 1 |
Add member to role |
- | 1 | - | - | 1 |
Add user |
- | 1 | - | - | 1 |
InteractiveLogon |
- | 1 | - | - | 1 |
RemoteInteractiveLogon |
- | 1 | - | - | 1 |
Reset user password |
- | 1 | - | - | 1 |
ResourceAccess |
- | 1 | - | - | 1 |
Sign-in |
- | 1 | - | - | 1 |
Update user |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
startswith C:\\Program Files (x86)\\Microsoft Visual Studio |
- | 1 | - | - | 1 |
!startswith / |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has -n 6 |
- | 3 | - | - | 3 |
has 127.0.0.1 |
- | 3 | - | - | 3 |
has calc.exe |
- | 3 | - | - | 3 |
endswith 127.0.0.1 |
- | 3 | - | - | 3 |
has -a |
- | 3 | - | - | 3 |
has -nao |
- | 3 | - | - | 3 |
has -t |
- | 3 | - | - | 3 |
has /all |
- | 3 | - | - | 3 |
has $true |
- | 2 | - | - | 2 |
has /IM |
- | 2 | - | - | 2 |
has Set-MpPreference |
- | 2 | - | - | 2 |
has config |
- | 2 | - | - | 2 |
has_all advfirewall |
- | 2 | - | - | 2 |
contains <script> |
- | 2 | - | - | 2 |
has confluence |
- | 2 | - | - | 2 |
dllhost.exe |
- | 2 | - | - | 2 |
endswith rundll32.exe |
- | 2 | - | - | 2 |
contains //confluence |
- | 2 | - | - | 2 |
has .bat |
- | 2 | - | - | 2 |
has_any E9495B87-D950-4AB5-87A5-FF6D70BF3E90 |
- | 1 | - | - | 1 |
has Start |
- | 1 | - | - | 1 |
has /dev/shm/kdmtmpflush |
- | 1 | - | - | 1 |
has /d 1 |
- | 1 | - | - | 1 |
contains WinHttpAutoProxySvc |
- | 1 | - | - | 1 |
has start /MIN |
- | 1 | - | - | 1 |
contains -dhclient |
- | 1 | - | - | 1 |
contains /etc/NetworkManager/dispatcher.d/ |
- | 1 | - | - | 1 |
has_any /opt/vmware/certproxy/bing/certproxyService.sh |
- | 1 | - | - | 1 |
has_all Set-MpPreference |
- | 1 | - | - | 1 |
has roaming |
- | 1 | - | - | 1 |
has /bin/bash /tmp/ |
- | 1 | - | - | 1 |
has php-cgi.exe |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
cmd.exe |
- | 8 | - | - | 8 |
excel.exe |
- | 7 | - | - | 7 |
winword.exe |
- | 6 | - | - | 6 |
explorer.exe |
- | 6 | - | - | 6 |
rundll32.exe |
- | 6 | - | - | 6 |
beasvc.exe |
- | 5 | - | - | 5 |
httpd.exe |
- | 5 | - | - | 5 |
w3wp.exe |
- | 5 | - | - | 5 |
outlook.exe |
- | 5 | - | - | 5 |
java.exe |
- | 5 | - | - | 5 |
startswith psexe |
- | 4 | - | - | 4 |
dllhost.exe |
- | 3 | - | - | 3 |
startswith tomcat |
- | 3 | - | - | 3 |
net.exe |
- | 3 | - | - | 3 |
mobsync.exe |
- | 3 | - | - | 3 |
wmiprvse.exe |
- | 3 | - | - | 3 |
powershell.exe |
- | 3 | - | - | 3 |
solarwinds.businesslayerhost.exe |
- | 2 | - | - | 2 |
netsh.exe |
- | 2 | - | - | 2 |
msiexec.exe |
- | 2 | - | - | 2 |
mshta.exe |
- | 2 | - | - | 2 |
SolarWinds.BusinessLayerHost.exe |
- | 2 | - | - | 2 |
winlogon.exe |
- | 2 | - | - | 2 |
javaw.exe |
- | 2 | - | - | 2 |
oracle.exe |
- | 1 | - | - | 1 |
WDExpress.exe |
- | 1 | - | - | 1 |
devenv.exe |
- | 1 | - | - | 1 |
wsreset.exe |
- | 1 | - | - | 1 |
changepk.exe |
- | 1 | - | - | 1 |
auditpol.exe |
- | 1 | - | - | 1 |
wscript.exe |
- | 1 | - | - | 1 |
svchost.exe |
- | 1 | - | - | 1 |
powerpnt.exe |
- | 1 | - | - | 1 |
launchpad.exe |
- | 1 | - | - | 1 |
sqlagent.exe |
- | 1 | - | - | 1 |
sqlps.exe |
- | 1 | - | - | 1 |
sqlservr.exe |
- | 1 | - | - | 1 |
UMWorkerProcess.exe |
- | 1 | - | - | 1 |
chrome.exe |
- | 1 | - | - | 1 |
iexplore.exe |
- | 1 | - | - | 1 |
runtimebroker.exe |
- | 1 | - | - | 1 |
WINWORD.EXE |
- | 1 | - | - | 1 |
has ws_TomcatService.exe |
- | 1 | - | - | 1 |
regsvr32.exe |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
startswith C:\\Program Files (x86)\\Microsoft Visual Studio |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
beasvc.exe |
- | 5 | - | - | 5 |
startswith tomcat |
- | 4 | - | - | 4 |
httpd.exe |
- | 3 | - | - | 3 |
w3wp.exe |
- | 3 | - | - | 3 |
!= cscript.exe |
- | 2 | - | - | 2 |
has spoolsv.exe |
- | 2 | - | - | 2 |
startswith psexe |
- | 2 | - | - | 2 |
svchost.exe |
- | 1 | - | - | 1 |
slui.exe |
- | 1 | - | - | 1 |
outlook.exe |
- | 1 | - | - | 1 |
Microsoft Excel |
- | 1 | - | - | 1 |
Microsoft Word |
- | 1 | - | - | 1 |
endswith PSEXESVC.exe |
- | 1 | - | - | 1 |
has excel.exe |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
!= Android Studio |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
contains -ma |
- | 6 | - | - | 6 |
has -accepteula |
- | 6 | - | - | 6 |
has lsass |
- | 6 | - | - | 6 |
has deletejournal |
- | 6 | - | - | 6 |
has usn |
- | 6 | - | - | 6 |
has certutil |
- | 5 | - | - | 5 |
!contains /add |
- | 5 | - | - | 5 |
has /w |
- | 5 | - | - | 5 |
contains %temp% |
- | 4 | - | - | 4 |
has http |
- | 4 | - | - | 4 |
has config |
- | 4 | - | - | 4 |
has delete |
- | 4 | - | - | 4 |
has disabled |
- | 4 | - | - | 4 |
has sc |
- | 4 | - | - | 4 |
has Change |
- | 4 | - | - | 4 |
has SystemRestore |
- | 4 | - | - | 4 |
has disable |
- | 4 | - | - | 4 |
has lsass.exe |
- | 3 | - | - | 3 |
has msexchange |
- | 3 | - | - | 3 |
has sql |
- | 3 | - | - | 3 |
has stop-service |
- | 3 | - | - | 3 |
has ipconfig |
- | 3 | - | - | 3 |
has ping |
- | 3 | - | - | 3 |
has systeminfo |
- | 3 | - | - | 3 |
has timeout |
- | 3 | - | - | 3 |
has wget |
- | 3 | - | - | 3 |
has whoami |
- | 3 | - | - | 3 |
has /Upload |
- | 3 | - | - | 3 |
has_any /Transfer |
- | 3 | - | - | 3 |
has .jse |
- | 3 | - | - | 3 |
!contains /domain |
- | 3 | - | - | 3 |
has CL |
- | 3 | - | - | 3 |
has WEVTUTIL |
- | 3 | - | - | 3 |
has DownloadFile |
- | 3 | - | - | 3 |
has Invoke-Shellcode |
- | 3 | - | - | 3 |
has Invoke-WebRequest |
- | 3 | - | - | 3 |
has Net.WebClient |
- | 3 | - | - | 3 |
has shadowcopy delete |
- | 3 | - | - | 3 |
contains -e |
- | 3 | - | - | 3 |
has hklm |
- | 2 | - | - | 2 |
has sam |
- | 2 | - | - | 2 |
has save |
- | 2 | - | - | 2 |
!contains \\ |
- | 2 | - | - | 2 |
contains /do |
- | 2 | - | - | 2 |
contains /domain |
- | 2 | - | - | 2 |
contains group |
- | 2 | - | - | 2 |
contains user |
- | 2 | - | - | 2 |
has return |
- | 2 | - | - | 2 |
contains privilege:: |
- | 2 | - | - | 2 |
contains token:: |
- | 2 | - | - | 2 |
has sekurlsa |
- | 2 | - | - | 2 |
has IEX |
- | 2 | - | - | 2 |
has Start-BitsTransfer |
- | 2 | - | - | 2 |
has mpcmdrun.exe |
- | 2 | - | - | 2 |
has cl |
- | 2 | - | - | 2 |
has wbadmin |
- | 2 | - | - | 2 |
has wevtutil |
- | 2 | - | - | 2 |
has wmic |
- | 2 | - | - | 2 |
has wmic computersystem get domain |
- | 2 | - | - | 2 |
has programdata |
- | 2 | - | - | 2 |
has_any whoami /all |
- | 2 | - | - | 2 |
!contains ApplicationNo |
- | 2 | - | - | 2 |
!contains Cosmos |
- | 2 | - | - | 2 |
!contains CustomerGroup |
- | 2 | - | - | 2 |
!contains Unrestricted |
- | 2 | - | - | 2 |
!startswith POWERSHELL.EXE -C \ |
- | 2 | - | - | 2 |
contains $ |
- | 2 | - | - | 2 |
contains -split |
- | 2 | - | - | 2 |
contains > |
- | 2 | - | - | 2 |
contains @echo |
- | 2 | - | - | 2 |
contains encodedcommand |
- | 2 | - | - | 2 |
contains wget |
- | 2 | - | - | 2 |
startswith -q -s |
- | 2 | - | - | 2 |
has WebCache |
- | 2 | - | - | 2 |
has_any V01 |
- | 2 | - | - | 2 |
has -base64 |
- | 2 | - | - | 2 |
has -nosalt |
- | 2 | - | - | 2 |
has -out |
- | 2 | - | - | 2 |
has shadowcopy |
- | 2 | - | - | 2 |
!= msiexec.exe /V |
- | 1 | - | - | 1 |
has_any /exe |
- | 1 | - | - | 1 |
has_any out |
- | 1 | - | - | 1 |
has powershell.exe |
- | 1 | - | - | 1 |
has_all -ExecutionPolicy |
- | 1 | - | - | 1 |
has_all -WindowStyle |
- | 1 | - | - | 1 |
contains VSIxs |
- | 1 | - | - | 1 |
contains vsce-sign.exe |
- | 1 | - | - | 1 |
cmd.exe /c taskkill /im cmd.exe |
- | 1 | - | - | 1 |
startswith powershell.exe mshta.exe http |
- | 1 | - | - | 1 |
endswith cmd.exe /c SYSTEMINFO & TASKLIST |
- | 1 | - | - | 1 |
ps.exe -accepteula |
- | 1 | - | - | 1 |
contains abCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCc |
- | 1 | - | - | 1 |
endswith cyzfc.dat, PointFunctionCall |
- | 1 | - | - | 1 |
has -noni -ep bypass $ |
- | 1 | - | - | 1 |
has .vbs /shell |
- | 1 | - | - | 1 |
!has Windows\\CCM\\ |
- | 1 | - | - | 1 |
contains frombase64 |
- | 1 | - | - | 1 |
has Dvr /go |
- | 1 | - | - | 1 |
has DisableIOAVProtection |
- | 1 | - | - | 1 |
contains -noni -ep bypass $zk= |
- | 1 | - | - | 1 |
contains https://www.jmj.com/personal/nauerthn_state_gov |
- | 1 | - | - | 1 |
contains }} -p |
- | 1 | - | - | 1 |
startswith -q -s {{ |
- | 1 | - | - | 1 |
endswith ,dll_u |
- | 1 | - | - | 1 |
has -export dll_u |
- | 1 | - | - | 1 |
endswith localgroup administrators admin /add |
- | 1 | - | - | 1 |
has echo |
- | 1 | - | - | 1 |
contains theme0 |
- | 1 | - | - | 1 |
has -p |
- | 1 | - | - | 1 |
contains New-MailboxExportRequest |
- | 1 | - | - | 1 |
contains Remove-MailboxExportRequest |
- | 1 | - | - | 1 |
contains EIKKEIKK |
- | 1 | - | - | 1 |
contains python |
- | 1 | - | - | 1 |
has bash -i >& /dev/tcp/ |
- | 1 | - | - | 1 |
has 1 |
- | 1 | - | - | 1 |
has UseLogonCredential |
- | 1 | - | - | 1 |
has WDigest |
- | 1 | - | - | 1 |
has dword |
- | 1 | - | - | 1 |
contains .class |
- | 1 | - | - | 1 |
has attrib +h +s +r |
- | 1 | - | - | 1 |
has_any apphelp.dll |
- | 1 | - | - | 1 |
endswith powercat.ps1 |
- | 1 | - | - | 1 |
has http: |
- | 1 | - | - | 1 |
contains TVqQAAMAAAAEAAA |
- | 1 | - | - | 1 |
contains payload |
- | 1 | - | - | 1 |
contains targetip |
- | 1 | - | - | 1 |
contains targetport |
- | 1 | - | - | 1 |
contains verifybackdoor |
- | 1 | - | - | 1 |
contains .b64decode( |
- | 1 | - | - | 1 |
contains .decode( |
- | 1 | - | - | 1 |
contains .decode64( |
- | 1 | - | - | 1 |
contains base64 --decode |
- | 1 | - | - | 1 |
contains .jse |
- | 1 | - | - | 1 |
contains questd |
- | 1 | - | - | 1 |
has osascript -e do shell script \ |
- | 1 | - | - | 1 |
has /tmp/e_ |
- | 1 | - | - | 1 |
has base64 |
- | 1 | - | - | 1 |
contains :\\recycler |
- | 1 | - | - | 1 |
contains /grant Everyone:F |
- | 1 | - | - | 1 |
contains /w |
- | 1 | - | - | 1 |
has /all |
- | 1 | - | - | 1 |
has /change |
- | 1 | - | - | 1 |
has /d |
- | 1 | - | - | 1 |
has /disable |
- | 1 | - | - | 1 |
has /quiet |
- | 1 | - | - | 1 |
has delete shadows |
- | 1 | - | - | 1 |
has -v 2 |
- | 1 | - | - | 1 |
has -v 2.0 |
- | 1 | - | - | 1 |
has -version 2 |
- | 1 | - | - | 1 |
has -version 2.0 |
- | 1 | - | - | 1 |
has E:javascript |
- | 1 | - | - | 1 |
contains $client = New-Object System.Net.Sockets.TCPClient |
- | 1 | - | - | 1 |
contains ProgramData\\pst |
- | 1 | - | - | 1 |
contains Add-PSSnapin Microsoft.Exchange.Powershell.Snapin |
- | 1 | - | - | 1 |
contains HKLM |
- | 1 | - | - | 1 |
has --gpu-launcher |
- | 1 | - | - | 1 |
has key=clear |
- | 1 | - | - | 1 |
startswith netsh |
- | 1 | - | - | 1 |
has say \\\ |
- | 1 | - | - | 1 |
has /mds |
- | 1 | - | - | 1 |
has /mhp |
- | 1 | - | - | 1 |
has /mnl |
- | 1 | - | - | 1 |
has /mnt |
- | 1 | - | - | 1 |
has bundlename=chromium |
- | 1 | - | - | 1 |
has rsf |
- | 1 | - | - | 1 |
contains ecosetup |
- | 1 | - | - | 1 |
contains highest |
- | 1 | - | - | 1 |
contains spsextserv.exe |
- | 1 | - | - | 1 |
contains /run |
- | 1 | - | - | 1 |
contains Windows Error Reporting |
- | 1 | - | - | 1 |
contains /fa |
- | 1 | - | - | 1 |
contains :\\windows\\installer |
- | 1 | - | - | 1 |
contains del |
- | 1 | - | - | 1 |
contains rmdir |
- | 1 | - | - | 1 |
has stop |
- | 1 | - | - | 1 |
contains 1 |
- | 1 | - | - | 1 |
has EnableBDEWithNoTPM |
- | 1 | - | - | 1 |
has true |
- | 1 | - | - | 1 |
has_any temp |
- | 1 | - | - | 1 |
has HealthMailbox55x2yq |
- | 1 | - | - | 1 |
has_any New-Mailbox |
- | 1 | - | - | 1 |
has_all -command |
- | 1 | - | - | 1 |
has VMBlastSG |
- | 1 | - | - | 1 |
has REG_DWORD /d \ |
- | 1 | - | - | 1 |
has_all reg |
- | 1 | - | - | 1 |
has path antivirusproduct get displayname |
- | 1 | - | - | 1 |
has service apparmor stop |
- | 1 | - | - | 1 |
has_all curl -fsSL |
- | 1 | - | - | 1 |
has_any cmd.exe |
- | 1 | - | - | 1 |
has Set-MpPreference |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
High |
- | 3 | - | - | 3 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has Action1 |
- | 1 | - | - | 1 |
has_any AeroAdmin |
- | 1 | - | - | 1 |
has Ammyy |
- | 1 | - | - | 1 |
has_any anydesk software |
- | 1 | - | - | 1 |
has AOMEI |
- | 1 | - | - | 1 |
has Atera Networks |
- | 1 | - | - | 1 |
has AweRay |
- | 1 | - | - | 1 |
has_any Barracuda MSP |
- | 1 | - | - | 1 |
has_any BeyondTrust |
- | 1 | - | - | 1 |
has Google |
- | 1 | - | - | 1 |
has_any ConnectWise |
- | 1 | - | - | 1 |
has_any DameWare |
- | 1 | - | - | 1 |
has NCH Software |
- | 1 | - | - | 1 |
has Distant Software |
- | 1 | - | - | 1 |
has FleetDeck |
- | 1 | - | - | 1 |
has getscreen.me |
- | 1 | - | - | 1 |
has Enter Srl |
- | 1 | - | - | 1 |
has_any Xlab |
- | 1 | - | - | 1 |
has LogMeIn |
- | 1 | - | - | 1 |
has_any CloudBerry |
- | 1 | - | - | 1 |
has_any N-Able |
- | 1 | - | - | 1 |
has_any naverisk |
- | 1 | - | - | 1 |
has netsupport |
- | 1 | - | - | 1 |
has_any NinjaRMM |
- | 1 | - | - | 1 |
has Bravura Software LLC |
- | 1 | - | - | 1 |
has panorama9 |
- | 1 | - | - | 1 |
has Parsec |
- | 1 | - | - | 1 |
has pcvisit software ag |
- | 1 | - | - | 1 |
has MMSoft Design |
- | 1 | - | - | 1 |
has realvnc |
- | 1 | - | - | 1 |
has www.donkz.nl |
- | 1 | - | - | 1 |
has idrive |
- | 1 | - | - | 1 |
has Remote Utilities |
- | 1 | - | - | 1 |
has RealVNC |
- | 1 | - | - | 1 |
has Projector Inc |
- | 1 | - | - | 1 |
has Krämer IT Solutions GmbH |
- | 1 | - | - | 1 |
has ShowMyPC |
- | 1 | - | - | 1 |
has SimpleHelp |
- | 1 | - | - | 1 |
has Splashtop |
- | 1 | - | - | 1 |
has NanoSystems |
- | 1 | - | - | 1 |
has Servably, Inc. |
- | 1 | - | - | 1 |
has_any AmidaWare |
- | 1 | - | - | 1 |
has TeamViewer |
- | 1 | - | - | 1 |
has TigerVNC |
- | 1 | - | - | 1 |
has GlavSoft |
- | 1 | - | - | 1 |
has DucFabulous |
- | 1 | - | - | 1 |
has XMReality |
- | 1 | - | - | 1 |
has Zoho |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has DameWare |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has rdp.exe |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
has Action1 |
- | 1 | - | - | 1 |
has_any AeroAdmin |
- | 1 | - | - | 1 |
has Ammyy Admin |
- | 1 | - | - | 1 |
has anydesk |
- | 1 | - | - | 1 |
has AnyViewer |
- | 1 | - | - | 1 |
has AweSun |
- | 1 | - | - | 1 |
has Chrome Remote Desktop |
- | 1 | - | - | 1 |
has DameWare |
- | 1 | - | - | 1 |
has DesktopNow |
- | 1 | - | - | 1 |
has Distant Desktop |
- | 1 | - | - | 1 |
has FleetDeck |
- | 1 | - | - | 1 |
has getscreen.me |
- | 1 | - | - | 1 |
has Iperius Remote |
- | 1 | - | - | 1 |
has_any ISL Light |
- | 1 | - | - | 1 |
has_any LiteManager |
- | 1 | - | - | 1 |
has_any LogMeIn |
- | 1 | - | - | 1 |
has meshcentral |
- | 1 | - | - | 1 |
has mRemoteNG |
- | 1 | - | - | 1 |
has_any RMM |
- | 1 | - | - | 1 |
has NinjaRMM |
- | 1 | - | - | 1 |
has OptiTune |
- | 1 | - | - | 1 |
has panorama9 |
- | 1 | - | - | 1 |
has Parsec |
- | 1 | - | - | 1 |
has pcvisit |
- | 1 | - | - | 1 |
has PDQConnectAgent |
- | 1 | - | - | 1 |
has Pulseway |
- | 1 | - | - | 1 |
has Remote Desktop Plus |
- | 1 | - | - | 1 |
has_any remotepc |
- | 1 | - | - | 1 |
has Remote Utilities |
- | 1 | - | - | 1 |
has rport |
- | 1 | - | - | 1 |
has rustdesk |
- | 1 | - | - | 1 |
has ScreenMeet |
- | 1 | - | - | 1 |
has_any ServerEye |
- | 1 | - | - | 1 |
has ShowMyPC |
- | 1 | - | - | 1 |
has SimpleHelp |
- | 1 | - | - | 1 |
has Splashtop |
- | 1 | - | - | 1 |
has SupRemo |
- | 1 | - | - | 1 |
has Syncro |
- | 1 | - | - | 1 |
has Tactical RMM |
- | 1 | - | - | 1 |
has TeamViewer |
- | 1 | - | - | 1 |
has TigerVNC |
- | 1 | - | - | 1 |
has TightVNC |
- | 1 | - | - | 1 |
has UltraViewer |
- | 1 | - | - | 1 |
has XMReality |
- | 1 | - | - | 1 |
has Zoho Assist |
- | 1 | - | - | 1 |
has rclone |
- | 1 | - | - | 1 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊