| splunk |
Creation of Shadow Copy |
production |
2026-05-13 |
| splunk |
Creation of Shadow Copy with wmic and powershell |
production |
2026-05-13 |
| splunk |
Credential Dumping via Copy Command from Shadow Copy |
production |
2026-05-13 |
| splunk |
Credential Dumping via Symlink to Shadow Copy |
production |
2026-05-13 |
| splunk |
Crowdstrike Admin Weak Password Policy |
production |
2026-05-13 |
| splunk |
Crowdstrike Admin With Duplicate Password |
production |
2026-05-13 |
| splunk |
CrowdStrike Falcon Stream Alerts |
production |
2026-05-13 |
| splunk |
Crowdstrike High Identity Risk Severity |
production |
2026-05-13 |
| splunk |
Crowdstrike Medium Severity Alert |
production |
2026-05-13 |
| splunk |
Crowdstrike Multiple LOW Severity Alerts |
production |
2026-05-13 |
| splunk |
Crowdstrike Privilege Escalation For Non-Admin User |
production |
2026-05-13 |
| splunk |
Crowdstrike User Weak Password Policy |
production |
2026-05-13 |
| splunk |
Crowdstrike User with Duplicate Password |
production |
2026-05-13 |
| splunk |
CSC Net On The Fly Compilation |
production |
2026-05-13 |
| splunk |
Detect Baron Samedit CVE-2021-3156 Segfault |
experimental |
2026-05-13 |
| splunk |
Curl Execution with Percent Encoded URL |
production |
2026-05-13 |
| splunk |
Delete ShadowCopy With PowerShell |
production |
2026-05-13 |
| splunk |
Deleting Shadow Copies |
production |
2026-05-13 |
| splunk |
Detect AzureHound Command-Line Arguments |
production |
2026-05-13 |
| splunk |
Detect AzureHound File Modifications |
production |
2026-05-13 |
| splunk |
Detect Baron Samedit CVE-2021-3156 |
experimental |
2026-05-13 |
| splunk |
Detect Baron Samedit CVE-2021-3156 via OSQuery |
experimental |
2026-05-13 |
| splunk |
Detect Certify Command Line Arguments |
production |
2026-05-13 |
| splunk |
Detect Certify With PowerShell Script Block Logging |
production |
2026-05-13 |
| splunk |
Detect Certipy File Modifications |
production |
2026-05-13 |
| splunk |
Detect Computer Changed with Anonymous Account |
production |
2026-05-13 |
| splunk |
Detect Copy of ShadowCopy with Script Block Logging |
production |
2026-05-13 |
| splunk |
Detect Empire with PowerShell Script Block Logging |
production |
2026-05-13 |
| splunk |
Detect Excessive Account Lockouts From Endpoint |
production |
2026-05-13 |
| splunk |
Detect Exchange Web Shell |
production |
2026-05-13 |
| splunk |
Detect HTML Help Using InfoTech Storage Handlers |
production |
2026-05-13 |
| splunk |
Detect Mimikatz With PowerShell Script Block Logging |
production |
2026-05-13 |
| splunk |
Detect mshta inline hta execution |
production |
2026-05-13 |
| splunk |
Detect New Local Admin account |
production |
2026-05-13 |
| splunk |
Detect Outlook exe writing a zip file |
production |
2026-05-13 |
| splunk |
Detect Password Spray Attack Behavior From Source |
production |
2026-05-13 |
| splunk |
Detect Password Spray Attack Behavior On User |
production |
2026-05-13 |
| splunk |
Detect Path Interception By Creation Of program exe |
production |
2026-05-13 |
| splunk |
Detect Prohibited Applications Spawning cmd exe |
production |
2026-05-13 |
| splunk |
Detect PsExec With accepteula Flag |
production |
2026-05-13 |