This website requires JavaScript.
Explore
Help
Sign In
CSEC_PUBLIC
/
hayabusa
Watch
1
Star
0
Fork
0
You've already forked hayabusa
Code
Issues
Pull Requests
Packages
Projects
Releases
Wiki
Activity
Files
b10b714b36c8490ab6956488826a3391837865ef
hayabusa
/
rules
/
sigma
/
process_creation
T
History
…
..
process_creation_abusing_windows_telemetry_for_persistence.yml
…
process_creation_advanced_ip_scanner.yml
…
process_creation_alternate_data_streams.yml
…
process_creation_apt_gallium_sha1.yml
…
process_creation_apt_gallium.yml
…
process_creation_apt_pandemic.yml
…
process_creation_apt_slingshot.yml
…
process_creation_apt_turla_commands_critical.yml
…
process_creation_apt_wocao.yml
…
process_creation_automated_collection.yml
…
process_creation_c3_load_by_rundll32.yml
…
process_creation_certoc_execution.yml
…
process_creation_clip.yml
…
process_creation_cobaltstrike_load_by_rundll32.yml
…
process_creation_conti_cmd_ransomware.yml
…
process_creation_coti_sqlcmd.yml
…
process_creation_discover_private_keys.yml
…
process_creation_dns_serverlevelplugindll.yml
…
process_creation_dotnet.yml
…
process_creation_hack_dumpert.yml
…
process_creation_infdefaultinstall.yml
…
process_creation_lolbas_data_exfiltration_by_using_datasvcutil.yml
…
process_creation_lolbins_by_office_applications.yml
…
process_creation_lolbins_suspicious_driver_installed_by_pnputil.yml
…
process_creation_lolbins_with_wmiprvse_parent_process.yml
…
process_creation_msdeploy.yml
…
process_creation_office_applications_spawning_wmi_commandline.yml
…
process_creation_office_from_proxy_executing_regsvr32_payload2.yml
…
process_creation_office_from_proxy_executing_regsvr32_payload.yml
…
process_creation_office_spawning_wmi_commandline.yml
…
process_creation_pingback_backdoor.yml
…
process_creation_protocolhandler_suspicious_file.yml
…
process_creation_root_certificate_installed.yml
…
process_creation_sdelete.yml
…
process_creation_software_discovery.yml
…
process_creation_stickykey_like_backdoor.yml
…
process_creation_stordiag_execution.yml
…
process_creation_susp_7z.yml
…
process_creation_susp_athremotefxvgpudisablementcommand.yml
…
process_creation_susp_del.yml
…
process_creation_susp_recon.yml
…
process_creation_susp_web_request_cmd.yml
…
process_creation_susp_winzip.yml
…
process_creation_susp_zip_compress.yml
…
process_creation_syncappvpublishingserver_execute_arbitrary_powershell.yml
…
process_creation_syncappvpublishingserver_vbs_execute_powershell.yml
…
process_creation_sysinternals_eula_accepted.yml
…
process_creation_sysmon_uac_bypass_eventvwr.yml
…
process_creation_tool_psexec.yml
…
process_creation_win_exchange_transportagent.yml
…
process_mailboxexport_share.yml
…
process_susp_esentutl_params.yml
…
sysmon_abusing_debug_privilege.yml
…
sysmon_accesschk_usage_after_priv_escalation.yml
…
sysmon_always_install_elevated_msi_spawned_cmd_and_powershell.yml
…
sysmon_always_install_elevated_windows_installer.yml
…
sysmon_apt_muddywater_dnstunnel.yml
…
sysmon_apt_sourgrum.yml
…
sysmon_atlassian_confluence_cve_2021_26084_exploit.yml
…
sysmon_cmstp_execution_by_creation.yml
…
sysmon_creation_mavinject_dll.yml
…
sysmon_cve_2021_26857_msexchange.yml
…
sysmon_expand_cabinet_files.yml
…
sysmon_hack_wce.yml
…
sysmon_high_integrity_sdclt.yml
…
sysmon_logon_scripts_userinitmprlogonscript_proc.yml
…
sysmon_long_powershell_commandline.yml
…
sysmon_netcat_execution.yml
…
sysmon_proxy_execution_wuauclt.yml
…
sysmon_remove_windows_defender_definition_files.yml
…
sysmon_sdclt_child_process.yml
…
sysmon_susp_plink_remote_forward.yml
…
sysmon_susp_service_modification.yml
…
sysmon_susp_webdav_client_execution.yml
…
sysmon_uninstall_crowdstrike_falcon.yml
…
sysmon_vmtoolsd_susp_child_process.yml
…
wim_pc_apt_chafer_mar18.yml
…
win_ad_find_discovery.yml
…
win_anydesk_silent_install.yml
…
win_apt_apt29_thinktanks.yml
…
win_apt_babyshark.yml
…
win_apt_bear_activity_gtr19.yml
…
win_apt_bluemashroom.yml
…
win_apt_cloudhopper.yml
…
win_apt_dragonfly.yml
…
win_apt_elise.yml
…
win_apt_emissarypanda_sep19.yml
…
win_apt_empiremonkey.yml
…
win_apt_equationgroup_dll_u_load.yml
…
win_apt_evilnum_jul20.yml
…
win_apt_greenbug_may20.yml
…
win_apt_hafnium.yml
…
win_apt_hurricane_panda.yml
…
win_apt_judgement_panda_gtr19.yml
…
win_apt_ke3chang_regadd.yml
…
win_apt_lazarus_activity_apr21.yml
…
win_apt_lazarus_activity_dec20.yml
…
win_apt_lazarus_loader.yml
…
win_apt_lazarus_session_highjack.yml
…
win_apt_mustangpanda.yml
…
win_apt_revil_kaseya.yml
…
win_apt_sofacy.yml
…
win_apt_ta17_293a_ps.yml
…
win_apt_ta505_dropper.yml
…
win_apt_taidoor.yml
…
win_apt_tropictrooper.yml
…
win_apt_turla_comrat_may20.yml
…
win_apt_unc2452_cmds.yml
…
win_apt_unc2452_ps.yml
…
win_apt_unidentified_nov_18.yml
…
win_apt_winnti_mal_hk_jan20.yml
…
win_apt_winnti_pipemon.yml
…
win_apt_zxshell.yml
…
win_attrib_hiding_files.yml
…
win_bad_opsec_sacrificial_processes.yml
…
win_bootconf_mod.yml
…
win_bypass_squiblytwo.yml
…
win_change_default_file_association.yml
…
win_cl_invocation_lolscript.yml
…
win_cl_mutexverifiers_lolscript.yml
…
win_class_exec_xwizard.yml
…
win_cmdkey_recon.yml
…
win_cmstp_com_object_access.yml
…
win_cobaltstrike_process_patterns.yml
…
win_commandline_path_traversal_evasion.yml
…
win_commandline_path_traversal.yml
…
win_control_panel_item.yml
…
win_copying_sensitive_files_with_credential_data.yml
…
win_credential_access_via_password_filter.yml
…
win_crime_fireball.yml
…
win_crime_maze_ransomware.yml
…
win_crime_snatch_ransomware.yml
…
win_crypto_mining_monero.yml
…
win_data_compressed_with_rar.yml
…
win_detecting_fake_instances_of_hxtsr.yml
…
win_dll_sideload_xwizard.yml
…
win_dns_exfiltration_tools_execution.yml
…
win_dnscat2_powershell_implementation.yml
…
win_encoded_frombase64string.yml
…
win_encoded_iex.yml
…
win_etw_modification_cmdline.yml
…
win_etw_trace_evasion.yml
…
win_exfiltration_and_tunneling_tools_execution.yml
…
win_exploit_cve_2015_1641.yml
…
win_exploit_cve_2017_0261.yml
…
win_exploit_cve_2017_8759.yml
…
win_exploit_cve_2017_11882.yml
…
win_exploit_cve_2019_1378.yml
…
win_exploit_cve_2019_1388.yml
…
win_exploit_cve_2020_1048.yml
…
win_exploit_cve_2020_1350.yml
…
win_exploit_cve_2020_10189.yml
…
win_exploit_systemnightmare.yml
…
win_file_permission_modifications.yml
…
win_grabbing_sensitive_hives_via_reg.yml
…
win_hack_adcspwn.yml
…
win_hack_bloodhound.yml
…
win_hack_koadic.yml
…
win_hack_rubeus.yml
…
win_hack_secutyxploded.yml
…
win_hh_chm.yml
…
win_hiding_malware_in_fonts_folder.yml
…
win_hktl_createminidump.yml
…
win_hktl_uacme_uac_bypass.yml
…
win_html_help_spawn.yml
…
win_hwp_exploits.yml
…
win_impacket_compiled_tools.yml
…
win_impacket_lateralization.yml
…
win_indirect_cmd_compatibility_assistant.yml
…
win_indirect_cmd.yml
…
win_install_reg_debugger_backdoor.yml
…
win_interactive_at.yml
…
win_invoke_obfuscation_clip.yml
…
win_invoke_obfuscation_obfuscated_iex_commandline.yml
…
win_invoke_obfuscation_stdin.yml
…
win_invoke_obfuscation_var.yml
…
win_invoke_obfuscation_via_compress.yml
…
win_invoke_obfuscation_via_rundll.yml
…
win_invoke_obfuscation_via_stdin.yml
…
win_invoke_obfuscation_via_use_clip.yml
…
win_invoke_obfuscation_via_use_mhsta.yml
…
win_invoke_obfuscation_via_use_rundll32.yml
…
win_invoke_obfuscation_via_var.yml
…
win_lethalhta.yml
…
win_local_system_owner_account_discovery.yml
…
win_lolbas_execution_of_wuauclt.yml
…
win_lolbin_execution_via_winget.yml
…
win_lsass_dump.yml
…
win_mal_adwind.yml
…
win_malware_conti_7zip.yml
…
win_malware_conti_shadowcopy.yml
…
win_malware_conti.yml
…
win_malware_dridex.yml
…
win_malware_dtrack.yml
…
win_malware_emotet.yml
…
win_malware_formbook.yml
…
win_malware_notpetya.yml
…
win_malware_qbot.yml
…
win_malware_ryuk.yml
…
win_malware_script_dropper.yml
…
win_malware_trickbot_recon_activity.yml
…
win_malware_trickbot_wermgr.yml
…
win_malware_wannacry.yml
…
win_manage_bde_lolbas.yml
…
win_mavinject_proc_inj.yml
…
win_meterpreter_or_cobaltstrike_getsystem_service_start.yml
…
win_mimikatz_command_line.yml
…
win_mmc_spawn_shell.yml
…
win_modif_of_services_for_via_commandline.yml
…
win_monitoring_for_persistence_via_bits.yml
…
win_mouse_lock.yml
…
win_mshta_javascript.yml
…
win_mshta_spawn_shell.yml
…
win_multiple_suspicious_cli.yml
…
win_net_enum.yml
…
win_net_user_add.yml
…
win_netsh_allow_port_rdp.yml
…
win_netsh_fw_add_susp_image.yml
…
win_netsh_fw_add.yml
…
win_netsh_packet_capture.yml
…
win_netsh_port_fwd_3389.yml
…
win_netsh_port_fwd.yml
…
win_netsh_wifi_credential_harvesting.yml
…
win_network_sniffing.yml
…
win_new_service_creation.yml
…
win_nltest_recon.yml
…
win_non_interactive_powershell.yml
…
win_non_priv_reg_or_ps.yml
…
win_office_shell.yml
…
win_office_spawn_exe_from_users_directory.yml
…
win_pc_set_policies_to_unsecure_level.yml
…
win_pc_susp_cmdl32_lolbas.yml
…
win_pc_susp_reg_bitlocker.yml
…
win_pc_susp_schtasks_user_temp.yml
…
win_pc_susp_zipexec.yml
…
win_plugx_susp_exe_locations.yml
…
win_possible_applocker_bypass.yml
…
win_possible_privilege_escalation_via_service_registry_permissions.yml
…
win_powershell_amsi_bypass.yml
…
win_powershell_audio_capture.yml
…
win_powershell_b64_shellcode.yml
…
win_powershell_bitsjob.yml
…
win_powershell_cmdline_reversed_strings.yml
…
win_powershell_cmdline_special_characters.yml
…
win_powershell_cmdline_specific_comb_methods.yml
…
win_powershell_defender_exclusion.yml
…
win_powershell_disable_windef_av.yml
…
win_powershell_dll_execution.yml
…
win_powershell_downgrade_attack.yml
…
win_powershell_download.yml
…
win_powershell_frombase64string.yml
…
win_powershell_reverse_shell_connection.yml
…
win_powershell_suspicious_parameter_variation.yml
…
win_powershell_xor_commandline.yml
…
win_powersploit_empire_schtasks.yml
…
win_proc_wrong_parent.yml
…
win_procdump.yml
…
win_process_creation_bitsadmin_download.yml
…
win_process_dump_rdrleakdiag.yml
…
win_process_dump_rundll32_comsvcs.yml
…
win_psexesvc_start.yml
…
win_purplesharp_indicators.yml
…
win_query_registry.yml
…
win_rasautou_dll_execution.yml
…
win_rdp_hijack_shadowing.yml
…
win_redmimicry_winnti_proc.yml
…
win_reg_add_run_key.yml
…
win_regedit_export_critical_keys.yml
…
win_regedit_export_keys.yml
…
win_regedit_import_keys_ads.yml
…
win_regedit_import_keys.yml
…
win_regini_ads.yml
…
win_regini.yml
…
win_remote_powershell_session_process.yml
…
win_remote_time_discovery.yml
…
win_renamed_binary_highly_relevant.yml
…
win_renamed_binary.yml
…
win_renamed_jusched.yml
…
win_renamed_megasync.yml
…
win_renamed_paexec.yml
…
win_renamed_powershell.yml
…
win_renamed_procdump.yml
…
win_renamed_psexec.yml
…
win_renamed_whoami.yml
…
win_run_powershell_script_from_ads.yml
…
win_run_powershell_script_from_input_stream.yml
…
win_run_virtualbox.yml
…
win_rundll32_without_parameters.yml
…
win_script_event_consumer_spawn.yml
…
win_sdbinst_shim_persistence.yml
…
win_service_execution.yml
…
win_service_stop.yml
…
win_shadow_copies_access_symlink.yml
…
win_shadow_copies_creation.yml
…
win_shadow_copies_deletion.yml
…
win_shell_spawn_mshta.yml
…
win_shell_spawn_susp_program.yml
…
win_silenttrinity_stage_use.yml
…
win_soundrec_audio_capture.yml
…
win_spn_enum.yml
…
win_sticky_keys_unauthenticated_privileged_console_access.yml
…
win_sus_auditpol_usage.yml
…
win_susp_adfind.yml
…
win_susp_atbroker.yml
…
win_susp_bcdedit.yml
…
win_susp_bginfo.yml
…
win_susp_bitstransfer.yml
…
win_susp_calc.yml
…
win_susp_cdb.yml
…
win_susp_certutil_command.yml
…
win_susp_certutil_encode.yml
…
win_susp_child_process_as_system_.yml
…
win_susp_cli_escape.yml
…
win_susp_cmd_http_appdata.yml
…
win_susp_cmd_shadowcopy_access.yml
…
win_susp_codepage_switch.yml
…
win_susp_commands_recon_activity.yml
…
win_susp_compression_params.yml
…
win_susp_comsvcs_procdump.yml
…
win_susp_conhost.yml
…
win_susp_control_cve_2021_40444.yml
…
win_susp_control_dll_load.yml
…
win_susp_copy_lateral_movement.yml
…
win_susp_copy_system32.yml
…
win_susp_covenant.yml
…
win_susp_crackmapexec_execution.yml
…
win_susp_crackmapexec_powershell_obfuscation.yml
…
win_susp_csc_folder.yml
…
win_susp_csc.yml
…
win_susp_csi.yml
…
win_susp_curl_download.yml
…
win_susp_curl_fileupload.yml
…
win_susp_curl_start_combo.yml
…
win_susp_dctask64_proc_inject.yml
…
win_susp_desktopimgdownldr.yml
…
win_susp_devtoolslauncher.yml
…
win_susp_direct_asep_reg_keys_modification.yml
…
win_susp_disable_eventlog.yml
…
win_susp_disable_ie_features.yml
…
win_susp_disable_raccine.yml
…
win_susp_diskshadow.yml
…
win_susp_ditsnap.yml
…
win_susp_dnx.yml
…
win_susp_double_extension.yml
…
win_susp_dxcap.yml
…
win_susp_emotet_rundll32_execution.yml
…
win_susp_eventlog_clear.yml
…
win_susp_execution_path_webserver.yml
…
win_susp_execution_path.yml
…
win_susp_explorer_break_proctree.yml
…
win_susp_explorer.yml
…
win_susp_file_characteristics.yml
…
win_susp_file_download_via_gfxdownloadwrapper.yml
…
win_susp_findstr_lnk.yml
…
win_susp_findstr.yml
…
win_susp_finger_usage.yml
…
win_susp_firewall_disable.yml
…
win_susp_fsutil_usage.yml
…
win_susp_ftp.yml
…
win_susp_gup.yml
…
win_susp_iss_module_install.yml
…
win_susp_mounted_share_deletion.yml
…
win_susp_mpcmdrun_download.yml
…
win_susp_mshta_pattern.yml
…
win_susp_msiexec_cwd.yml
…
win_susp_msiexec_web_install.yml
…
win_susp_msoffice.yml
…
win_susp_net_execution.yml
…
win_susp_netsh_dll_persistence.yml
…
win_susp_ngrok_pua.yml
…
win_susp_ntdsutil.yml
…
win_susp_odbcconf.yml
…
win_susp_openwith.yml
…
win_susp_outlook_temp.yml
…
win_susp_outlook.yml
…
win_susp_pcwutl.yml
…
win_susp_pester.yml
…
win_susp_ping_hex_ip.yml
…
win_susp_powershell_empire_launch.yml
…
win_susp_powershell_empire_uac_bypass.yml
…
win_susp_powershell_enc_cmd.yml
…
win_susp_powershell_encoded_param.yml
…
win_susp_powershell_getprocess_lsass.yml
…
win_susp_powershell_hidden_b64_cmd.yml
…
win_susp_powershell_parent_combo.yml
…
win_susp_powershell_parent_process.yml
…
win_susp_powershell_sam_access.yml
…
win_susp_print.yml
…
win_susp_procdump_lsass.yml
…
win_susp_procdump.yml
…
win_susp_ps_appdata.yml
…
win_susp_ps_downloadfile.yml
…
win_susp_psexec_eula.yml
…
win_susp_psexex_paexec_flags.yml
…
win_susp_psr_capture_screenshots.yml
…
win_susp_rar_flags.yml
…
win_susp_rasdial_activity.yml
…
win_susp_razorinstaller_explorer.yml
…
win_susp_rclone_execution.yml
…
win_susp_recon_activity.yml
…
win_susp_reg_disable_sec_services.yml
…
win_susp_regedit_trustedinstaller.yml
…
win_susp_register_cimprovider.yml
…
win_susp_registration_via_cscript.yml
…
win_susp_regsvr32_anomalies.yml
…
win_susp_regsvr32_flags_anomaly.yml
…
win_susp_regsvr32_no_dll.yml
…
win_susp_renamed_dctask64.yml
…
win_susp_renamed_debugview.yml
…
win_susp_renamed_paexec.yml
…
win_susp_rpcping.yml
…
win_susp_run_locations.yml
…
win_susp_rundll32_activity.yml
…
win_susp_rundll32_by_ordinal.yml
…
win_susp_rundll32_inline_vbs.yml
…
win_susp_rundll32_no_params.yml
…
win_susp_rundll32_setupapi_installhinfsection.yml
…
win_susp_rundll32_sys.yml
…
win_susp_runonce_execution.yml
…
win_susp_runscripthelper.yml
…
win_susp_schtask_creation_temp_folder.yml
…
win_susp_schtask_creation.yml
…
win_susp_screenconnect_access.yml
…
win_susp_screensaver_reg.yml
…
win_susp_script_exec_from_temp.yml
…
win_susp_script_execution.yml
…
win_susp_service_dacl_modification.yml
…
win_susp_service_dir.yml
…
win_susp_service_path_modification.yml
…
win_susp_servu_exploitation_cve_2021_35211.yml
…
win_susp_servu_process_pattern.yml
…
win_susp_shell_spawn_from_mssql.yml
…
win_susp_shimcache_flush.yml
…
win_susp_splwow64.yml
…
win_susp_spoolsv_child_processes.yml
…
win_susp_sqldumper_activity.yml
…
win_susp_squirrel_lolbin.yml
…
win_susp_svchost_no_cli.yml
…
win_susp_svchost.yml
…
win_susp_sysprep_appdata.yml
…
win_susp_sysvol_access.yml
…
win_susp_taskmgr_localsystem.yml
…
win_susp_taskmgr_parent.yml
…
win_susp_tracker_execution.yml
…
win_susp_tscon_localsystem.yml
…
win_susp_tscon_rdp_redirect.yml
…
win_susp_uac_bypass_trustedpath.yml
…
win_susp_use_of_csharp_console.yml
…
win_susp_use_of_sqlps_bin.yml
…
win_susp_use_of_sqltoolsps_bin.yml
…
win_susp_use_of_te_bin.yml
…
win_susp_use_of_vsjitdebugger_bin.yml
…
win_susp_userinit_child.yml
…
win_susp_vboxdrvinst.yml
…
win_susp_vbscript_unc2452.yml
…
win_susp_volsnap_disable.yml
…
win_susp_whoami_anomaly.yml
…
win_susp_whoami.yml
…
win_susp_winrar_execution.yml
…
win_susp_winrm_awl_bypass.yml
…
win_susp_winrm_execution.yml
…
win_susp_wmi_execution.yml
…
win_susp_wmic_eventconsumer_create.yml
…
win_susp_wmic_proc_create_rundll32.yml
…
win_susp_wmic_security_product_uninstall.yml
…
win_susp_workfolders.yml
…
win_susp_wsl_lolbin.yml
…
win_susp_wuauclt.yml
…
win_sysmon_driver_unload.yml
…
win_system_exe_anomaly.yml
…
win_tap_installer_execution.yml
…
win_task_folder_evasion.yml
…
win_termserv_proc_spawn.yml
…
win_tools_relay_attacks.yml
…
win_trust_discovery.yml
…
win_uac_bypass_changepk_slui.yml
…
win_uac_bypass_cleanmgr.yml
…
win_uac_bypass_computerdefaults.yml
…
win_uac_bypass_consent_comctl32.yml
…
win_uac_bypass_dismhost.yml
…
win_uac_bypass_ieinstal.yml
…
win_uac_bypass_msconfig_gui.yml
…
win_uac_bypass_ntfs_reparse_point.yml
…
win_uac_bypass_pkgmgr_dism.yml
…
win_uac_bypass_winsat.yml
…
win_uac_bypass_wmp.yml
…
win_uac_bypass_wsreset.yml
…
win_uac_cmstp.yml
…
win_uac_fodhelper.yml
…
win_uac_wsreset.yml
…
win_using_sc_to_change_sevice_image_path_by_non_admin.yml
…
win_using_settingsynchost_as_lolbin.yml
…
win_verclsid_runs_com.yml
…
win_visual_basic_compiler.yml
…
win_vul_java_remote_debugging.yml
…
win_webshell_detection.yml
…
win_webshell_recon_detection.yml
…
win_webshell_spawn.yml
…
win_whoami_as_system.yml
…
win_whoami_priv.yml
…
win_win10_sched_task_0day.yml
…
win_winword_dll_load.yml
…
win_wmi_backdoor_exchange_transport_agent.yml
…
win_wmi_persistence_script_event_consumer.yml
…
win_wmi_spwns_powershell.yml
…
win_wmiprvse_spawning_process.yml
…
win_workflow_compiler.yml
…
win_write_protect_for_storage_disabled.yml
…
win_wsreset_uac_bypass.yml
…
win_xsl_script_processing.yml
…