| splunk |
Windows Powershell Commands from DNS TXT |
production |
2026-07-30 |
| sigma |
ADCS - Certighost Ghost Machine Account Creation |
experimental |
2026-07-30 |
| sigma |
Active Directory Replication from Non Machine Account - DcSync Indicator |
test |
2026-07-30 |
| sigma |
Suspicious Machine Account Replication - DcSync Indicator |
test |
2026-07-30 |
| snort |
ET INFO Server Hello with Downgrade Request to TLS 1.1 or Lower |
rev 1 |
2026-07-28 |
| snort |
ET TROJAN OWAReaper C2 Beacon |
rev 1 |
2026-07-28 |
| suricata |
ET MALWARE OWAReaper C2 Beacon |
rev 1 |
2026-07-28 |
| suricata |
ET INFO Server Hello with Downgrade Request to TLS 1.1 or Lower |
rev 1 |
2026-07-28 |
| elastic |
Multiple Alerts in Different ATT&CK Tactics on a Single Host |
deprecated |
2026-07-28 |
| sigma |
System File Execution Location Anomaly |
test |
2026-07-28 |
| sigma |
Suspicious WSMAN Provider Image Loads |
test |
2026-07-28 |
| sigma |
Msiexec Quiet Installation |
test |
2026-07-28 |
| sigma |
PSScriptPolicyTest Creation By Uncommon Process |
test |
2026-07-28 |
| sigma |
PowerShell Core DLL Loaded By Non PowerShell Process |
test |
2026-07-28 |
| sigma |
Files With System Process Name In Unsuspected Locations |
test |
2026-07-28 |
| sigma |
Load Of RstrtMgr.DLL By An Uncommon Process |
test |
2026-07-28 |
| sigma |
Credential Manager Access By Uncommon Applications |
test |
2026-07-28 |
| sigma |
Access To Windows DPAPI Master Keys By Uncommon Applications |
test |
2026-07-28 |
| snort |
ET TROJAN Suspected Gamaredon APT Related Activity |
rev 5 |
2026-07-27 |
| suricata |
ET MALWARE Suspected Gamaredon APT Related Activity |
rev 6 |
2026-07-27 |
| splunk |
Windows AppCertDLL Modification Via Command Line |
production |
2026-07-27 |
| splunk |
Windows AppCertDLL Modification Via Registry |
production |
2026-07-27 |
| splunk |
Svchost LOLBAS Execution Process Spawn |
production |
2026-07-27 |
| splunk |
Windows File Without Extension In Critical Folder |
production |
2026-07-27 |
| sigma |
ADCS - Certighost Certificate Issued via CDC Chase (CVE-2026-54121) |
experimental |
2026-07-27 |
| sigma |
ADCS - Certighost CDC Chase Certificate Request (CVE-2026-54121) |
experimental |
2026-07-27 |
| snort |
ET INFO Adobe Coldfusion POST Request for RDS Services |
rev 1 |
2026-07-24 |
| snort |
ET CURRENT_EVENTS CoGUI Landing Page 2026-07-24 |
rev 1 |
2026-07-24 |
| snort |
ET INFO Generic Phish Landing Page 2026-07-24 |
rev 1 |
2026-07-24 |
| suricata |
ET HUNTING Generic Phish Landing Page 2026-07-24 |
rev 1 |
2026-07-24 |
| suricata |
ET INFO Adobe Coldfusion POST Request for RDS Services |
rev 1 |
2026-07-24 |
| suricata |
ET PHISHING CoGUI Landing Page 2026-07-24 |
rev 1 |
2026-07-24 |
| sigma |
Network Communication With Crypto Mining Pool |
stable |
2026-07-24 |
| sigma |
Potentially Suspicious Image Load of Offreg.dll |
experimental |
2026-07-23 |
| sigma |
Registry Hive File Staged Outside Standard User Profile Path |
experimental |
2026-07-23 |
| sigma |
Suspicious Cross-User Process Spawn |
experimental |
2026-07-23 |
| sigma |
Potentially Suspicious Explicit Credential Local Logon |
experimental |
2026-07-23 |
| sigma |
Sysmon Configuration Error |
test |
2026-07-23 |
| splunk |
Windows WinSCP Configuration Security Access |
production |
2026-07-22 |
| snort |
ET TROJAN JS SpyPress C2 Beacon |
rev 1 |
2026-07-21 |