| splunk |
Rundll32 Control RunDLL Hunt |
production |
2026-05-13 |
| splunk |
Runas Execution in CommandLine |
production |
2026-05-13 |
| splunk |
Rubeus Command Line Parameters |
production |
2026-05-13 |
| splunk |
Revil Registry Entry |
production |
2026-05-13 |
| splunk |
Revil Common Exec Parameter |
production |
2026-05-13 |
| splunk |
Resize ShadowStorage volume |
production |
2026-05-13 |
| splunk |
Remote WMI Command Attempt |
production |
2026-05-13 |
| splunk |
Remote System Discovery with Wmic |
production |
2026-05-13 |
| splunk |
Remote System Discovery with Dsquery |
production |
2026-05-13 |
| splunk |
Remote System Discovery with Adsisearcher |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via WMI and PowerShell Script Block |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via WMI and PowerShell |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via WMI |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via WinRM and Winrs |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via WinRM and PowerShell Script Block |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via WinRM and PowerShell |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via DCOM and PowerShell Script Block |
production |
2026-05-13 |
| splunk |
Remote Process Instantiation via DCOM and PowerShell |
production |
2026-05-13 |
| splunk |
Remote Desktop Process Running On System |
experimental |
2026-05-13 |
| splunk |
Remcos RAT File Creation in Remcos Folder |
production |
2026-05-13 |
| splunk |
Remcos client registry install entry |
production |
2026-05-13 |
| splunk |
Registry Keys Used For Privilege Escalation |
production |
2026-05-13 |
| splunk |
Registry Keys for Creating SHIM Databases |
production |
2026-05-13 |
| splunk |
Reg exe Manipulating Windows Services Registry Keys |
production |
2026-05-13 |
| splunk |
Recursive Delete of Directory In Batch CMD |
production |
2026-05-13 |
| splunk |
Recon Using WMI Class |
production |
2026-05-13 |
| splunk |
Ransomware Notes bulk creation |
production |
2026-05-13 |
| splunk |
Randomly Generated Windows Service Name |
experimental |
2026-05-13 |
| splunk |
Randomly Generated Scheduled Task Name |
experimental |
2026-05-13 |
| splunk |
Processes Tapping Keyboard Events |
experimental |
2026-05-13 |
| splunk |
Process Writing DynamicWrapperX |
production |
2026-05-13 |
| splunk |
Process Kill Base On File Path |
production |
2026-05-13 |
| splunk |
Process Execution via WMI |
production |
2026-05-13 |
| splunk |
Process Deleting Its Process File Path |
production |
2026-05-13 |
| splunk |
Process Creating LNK file in Suspicious Location |
production |
2026-05-13 |
| splunk |
Print Spooler Failed to Load a Plug-in |
production |
2026-05-13 |
| splunk |
Print Spooler Adding A Printer Driver |
production |
2026-05-13 |
| splunk |
Print Processor Registry Autostart |
production |
2026-05-13 |
| splunk |
Prevent Automatic Repair Mode using Bcdedit |
production |
2026-05-13 |
| splunk |
PowerShell WebRequest Using Memory Stream |
production |
2026-05-13 |