Detects the use of RunXCmd tool for command execution
Detects the use of RunXCmd tool for command execution
Detects the use of NSudo tool for command execution
Detects the use of NirCmd tool for command execution as SYSTEM user
Detects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity
Detects remote RPC calls to possibly abuse remote encryption service via MS-EFSR
Identifies clients that may be performing DNS lookups associated with common currency mining pools.
Detects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
Detects blocking of process creations originating from PSExec and WMI commands
Detects manual service execution (start) via system utilities.
Detects a PsExec service start
Detects the use of smbexec.py tool by detecting a specific service installation
Detects PsExec service installation and execution events (service and Sysmon)
Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
Detects a ProcessHacker tool that elevated privileges to a very high level
Detects powershell script installed as a Service
Detects that a powershell code is written to the registry as a service.
Windows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE
Detects well-known credential dumping tools execution via service execution events
Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement. We can also catch this by system log 7045 (https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/win_cobaltstrike_service_installs.yml) In some SIEM you can catch those events also in HKLM\System\ControlSet001\Services or HKLM\System\ControlSet002\Services, however, this rule is based on a regular sysmon’s events.
Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement