| splunk |
Disable UAC Remote Restriction |
production |
2026-05-13 |
| splunk |
Disable Show Hidden Files |
production |
2026-05-13 |
| splunk |
Disable Security Logs Using MiniNt Registry |
production |
2026-05-13 |
| splunk |
Disable Schedule Task |
production |
2026-05-13 |
| splunk |
Disable Registry Tool |
production |
2026-05-13 |
| splunk |
Disable Logs Using WevtUtil |
production |
2026-05-13 |
| splunk |
Disable ETW Through Registry |
production |
2026-05-13 |
| splunk |
Disable Defender Spynet Reporting |
production |
2026-05-13 |
| splunk |
Disable Defender MpEngine Registry |
production |
2026-05-13 |
| splunk |
Disable Defender Enhanced Notification |
production |
2026-05-13 |
| splunk |
Disable Defender BlockAtFirstSeen Feature |
production |
2026-05-13 |
| splunk |
Disable AMSI Through Registry |
production |
2026-05-13 |
| splunk |
Detection of tools built by NirSoft |
experimental |
2026-05-13 |
| splunk |
Detect Use of cmd exe to Launch Script Interpreters |
production |
2026-05-13 |
| splunk |
Detect SharpHound Usage |
production |
2026-05-13 |
| splunk |
Detect SharpHound File Modifications |
production |
2026-05-13 |
| splunk |
Detect SharpHound Command-Line Arguments |
production |
2026-05-13 |
| splunk |
Detect Rundll32 Inline HTA Execution |
production |
2026-05-13 |
| splunk |
Detect RTLO In Process |
production |
2026-05-13 |
| splunk |
Detect RTLO In File Name |
production |
2026-05-13 |
| splunk |
Detect Regsvr32 Application Control Bypass |
production |
2026-05-13 |
| splunk |
Detect Regsvcs with No Command Line Arguments |
production |
2026-05-13 |
| splunk |
Detect Regsvcs with Network Connection |
production |
2026-05-13 |
| splunk |
Detect Regsvcs Spawning a Process |
production |
2026-05-13 |
| splunk |
Detect Regasm with no Command Line Arguments |
production |
2026-05-13 |
| splunk |
Detect Regasm with Network Connection |
production |
2026-05-13 |
| splunk |
Detect Regasm Spawning a Process |
production |
2026-05-13 |
| splunk |
Detect Rare Executables |
production |
2026-05-13 |
| splunk |
Detect PsExec With accepteula Flag |
production |
2026-05-13 |
| splunk |
Detect Prohibited Applications Spawning cmd exe |
production |
2026-05-13 |
| splunk |
Detect Path Interception By Creation Of program exe |
production |
2026-05-13 |
| splunk |
Detect Password Spray Attack Behavior On User |
production |
2026-05-13 |
| splunk |
Detect Password Spray Attack Behavior From Source |
production |
2026-05-13 |
| splunk |
Detect Outlook exe writing a zip file |
production |
2026-05-13 |
| splunk |
Detect New Local Admin account |
production |
2026-05-13 |
| splunk |
Allow Inbound Traffic By Firewall Rule Registry |
production |
2026-05-13 |
| splunk |
Allow File And Printing Sharing In Firewall |
production |
2026-05-13 |
| splunk |
Advanced IP or Port Scanner Execution |
production |
2026-05-13 |
| splunk |
AdsiSearcher Account Discovery |
production |
2026-05-13 |
| splunk |
Add DefaultUser And Password In Registry |
production |
2026-05-13 |