Tool
SIEM
Sigma (generic) detection rules
1,715 rules indexed · SIEM-agnostic detection content
Sigma is the open generic signature format for SIEM systems. Expand any rule to see its raw YAML and convert it inline to native query syntax. Pick a platform above to browse every rule already rendered in that language.
Using these Sigma rules
Deploy. Pick your SIEM above and paste the rendered query straight into a saved search or detection rule, or expand any rule to convert its generic YAML inline to the language you run.
Adapt. Map the field names to your log schema - Sigma assumes a normalised taxonomy - and tune thresholds and timeframes to your own baseline before you trust the alert.
Validate. Every rule is mapped to ATT&CK, so run the matching Atomic Red Team test on /atomic to confirm the rule actually fires before you rely on it.
◈
Detection rules
50 shown of 1,715
high
Potential Compromised 3CXDesktopApp ICO C2 File Download
Detects potential malicious .ICO files download from a compromised 3CXDesktopApp via web requests to the the malicious Github repository
view Sigma YAML
title: Potential Compromised 3CXDesktopApp ICO C2 File Download
id: 76bc1601-9546-4b75-9419-06e0e8d10651
related:
- id: 3c4b3bbf-36b4-470c-b6cf-f07e8b1c7e26 # Proxy C2
type: similar
- id: bd03a0dc-5d93-49eb-b2e8-2dfd268600f8 # DNS C2
type: similar
- id: 51eecf75-d069-43c7-9ea2-63f75499edd4 # net_connection C2
type: similar
- id: 93bbde78-dc86-4e73-9ffc-ff8a384ca89c # ProcCreation Exec
type: similar
- id: 63f3605b-979f-48c2-b7cc-7f90523fed88 # ProcCreation ChildProc
type: similar
- id: e7581747-1e44-4d4b-85a6-0db0b4a00f2a # ProcCreation Update
type: similar
- id: d0b65ad3-e945-435e-a7a9-438e62dd48e9 # ImageLoad
type: similar
status: test
description: Detects potential malicious .ICO files download from a compromised 3CXDesktopApp via web requests to the the malicious Github repository
references:
- https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/
- https://www.linkedin.com/feed/update/urn:li:activity:7047435754834198529/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-03-31
tags:
- attack.command-and-control
- detection.emerging-threats
logsource:
category: proxy
detection:
selection:
c-uri|contains|all:
- 'IconStorages/images/main/icon'
- '.ico'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Compromised 3CXDesktopApp Update Activity
Detects the 3CXDesktopApp updater downloading a known compromised version of the 3CXDesktopApp software
view Sigma YAML
title: Potential Compromised 3CXDesktopApp Update Activity
id: e7581747-1e44-4d4b-85a6-0db0b4a00f2a
related:
- id: 3c4b3bbf-36b4-470c-b6cf-f07e8b1c7e26 # Proxy C2
type: similar
- id: 76bc1601-9546-4b75-9419-06e0e8d10651 # Proxy GH
type: similar
- id: bd03a0dc-5d93-49eb-b2e8-2dfd268600f8 # DNS C2
type: similar
- id: 51eecf75-d069-43c7-9ea2-63f75499edd4 # net_connection C2
type: similar
- id: 93bbde78-dc86-4e73-9ffc-ff8a384ca89c # ProcCreation Exec
type: similar
- id: 63f3605b-979f-48c2-b7cc-7f90523fed88 # ProcCreation ChildProc
type: similar
- id: d0b65ad3-e945-435e-a7a9-438e62dd48e9 # ImageLoad
type: similar
status: test
description: Detects the 3CXDesktopApp updater downloading a known compromised version of the 3CXDesktopApp software
references:
- https://www.linkedin.com/feed/update/urn:li:activity:7047435754834198529/
- https://www.huntress.com/blog/3cx-voip-software-compromise-supply-chain-threats
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-03-29
tags:
- attack.stealth
- attack.t1218
- attack.execution
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\3CXDesktopApp\app\update.exe'
CommandLine|contains|all:
- '--update'
- 'http'
- '/electron/update/win32/18.12'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Conti Ransomware Database Dumping Activity Via SQLCmd
Detects a command used by conti to dump database
view Sigma YAML
title: Potential Conti Ransomware Database Dumping Activity Via SQLCmd
id: 2f47f1fd-0901-466e-a770-3b7092834a1b
status: test
description: Detects a command used by conti to dump database
references:
- https://twitter.com/vxunderground/status/1423336151860002816?s=20 # The leak info not the files itself
- https://www.virustotal.com/gui/file/03e9b8c2e86d6db450e5eceec057d7e369ee2389b9daecaf06331a95410aa5f8/detection
- https://docs.microsoft.com/en-us/sql/tools/sqlcmd-utility?view=sql-server-ver15
author: frack113
date: 2021-08-16
modified: 2023-05-04
tags:
- attack.collection
- attack.t1005
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_tools:
- Image|endswith: '\sqlcmd.exe'
- CommandLine|contains:
- 'sqlcmd '
- 'sqlcmd.exe'
selection_svr:
CommandLine|contains: ' -S localhost '
selection_query:
CommandLine|contains:
- 'sys.sysprocesses'
- 'master.dbo.sysdatabases'
- 'BACKUP DATABASE'
condition: all of selection_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Credential Dumping Attempt Using New NetworkProvider - CLI
Detects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
view Sigma YAML
title: Potential Credential Dumping Attempt Using New NetworkProvider - CLI
id: baef1ec6-2ca9-47a3-97cc-4cf2bda10b77
related:
- id: 0442defa-b4a2-41c9-ae2c-ea7042fc4701
type: similar
status: test
description: Detects when an attacker tries to add a new network provider in order to dump clear text credentials, similar to how the NPPSpy tool does it
references:
- https://learn.microsoft.com/en-us/troubleshoot/windows-client/setup-upgrade-and-drivers/network-provider-settings-removed-in-place-upgrade
- https://github.com/gtworek/PSBits/tree/master/PasswordStealing/NPPSpy
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-08-23
modified: 2023-02-02
tags:
- attack.credential-access
- attack.t1003
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains|all:
- '\System\CurrentControlSet\Services\'
- '\NetworkProvider'
# filter:
# CommandLine|contains:
# - '\System\CurrentControlSet\Services\WebClient\NetworkProvider'
# - '\System\CurrentControlSet\Services\LanmanWorkstation\NetworkProvider'
# - '\System\CurrentControlSet\Services\RDPNP\NetworkProvider'
# - '\System\CurrentControlSet\Services\P9NP\NetworkProvider' # Related to WSL remove the comment if you use WSL in your ENV
condition: selection
falsepositives:
- Other legitimate network providers used and not filtred in this rule
level: high
Convert to SIEM query
high
Potential Credential Dumping Attempt Via PowerShell Remote Thread
Detects remote thread creation by PowerShell processes into "lsass.exe"
view Sigma YAML
title: Potential Credential Dumping Attempt Via PowerShell Remote Thread
id: fb656378-f909-47c1-8747-278bf09f4f4f
related:
- id: 3f07b9d1-2082-4c56-9277-613a621983cc
type: obsolete
- id: 0f920ebe-7aea-4c54-b202-9aa0c609cfe5
type: similar
status: test
description: Detects remote thread creation by PowerShell processes into "lsass.exe"
references:
- https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse
author: oscd.community, Natalia Shornikova
date: 2020-10-06
modified: 2022-12-18
tags:
- attack.credential-access
- attack.t1003.001
logsource:
product: windows
category: create_remote_thread
detection:
selection:
SourceImage|endswith:
- '\powershell.exe'
- '\pwsh.exe'
TargetImage|endswith: '\lsass.exe'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Credential Dumping Via WER
Detects potential credential dumping via Windows Error Reporting LSASS Shtinkering technique which uses the Windows Error Reporting to dump lsass
view Sigma YAML
title: Potential Credential Dumping Via WER
id: 9a4ccd1a-3526-4d99-b980-9f9c5d3a6ff3
status: test
description: Detects potential credential dumping via Windows Error Reporting LSASS Shtinkering technique which uses the Windows Error Reporting to dump lsass
references:
- https://github.com/deepinstinct/Lsass-Shtinkering
- https://media.defcon.org/DEF%20CON%2030/DEF%20CON%2030%20presentations/Asaf%20Gilboa%20-%20LSASS%20Shtinkering%20Abusing%20Windows%20Error%20Reporting%20to%20Dump%20LSASS.pdf
author: '@pbssubhash , Nasreddine Bencherchali'
date: 2022-12-08
modified: 2022-12-09
tags:
- attack.credential-access
- attack.t1003.001
logsource:
product: windows
category: process_creation
detection:
selection_img:
- Image|endswith: '\Werfault.exe'
- OriginalFileName: 'WerFault.exe'
selection_cli:
ParentUser|contains: # covers many language settings
- 'AUTHORI'
- 'AUTORI'
User|contains:
- 'AUTHORI'
- 'AUTORI'
CommandLine|contains|all:
# Doc: WerFault.exe -u -p <target process> -ip <source process> -s <file mapping handle>
# Example: C:\Windows\system32\Werfault.exe -u -p 744 -ip 1112 -s 244
# If the source process is not equal to the target process and the target process is LSASS then this is an indication of this technique
# Example: If the "-p" points the PID of "lsass.exe" and "-ip" points to a different process than "lsass.exe" then this is a sign of malicious activity
- ' -u -p '
- ' -ip '
- ' -s '
filter_lsass:
ParentImage: 'C:\Windows\System32\lsass.exe'
condition: all of selection_* and not 1 of filter_*
falsepositives:
- Windows Error Reporting might produce similar behavior. In that case, check the PID associated with the "-p" parameter in the CommandLine.
level: high
Convert to SIEM query
high
Potential Crypto Mining Activity
Detects command line parameters or strings often used by crypto miners
view Sigma YAML
title: Potential Crypto Mining Activity
id: 66c3b204-9f88-4d0a-a7f7-8a57d521ca55
status: stable
description: Detects command line parameters or strings often used by crypto miners
references:
- https://www.poolwatch.io/coin/monero
author: Florian Roth (Nextron Systems)
date: 2021-10-26
modified: 2023-02-13
tags:
- attack.impact
- attack.t1496
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- ' --cpu-priority='
- '--donate-level=0'
- ' -o pool.'
- ' --nicehash'
- ' --algo=rx/0 '
- 'stratum+tcp://'
- 'stratum+udp://'
# base64 encoded: --donate-level=
- 'LS1kb25hdGUtbGV2ZWw9'
- '0tZG9uYXRlLWxldmVsP'
- 'tLWRvbmF0ZS1sZXZlbD'
# base64 encoded: stratum+tcp:// and stratum+udp://
- 'c3RyYXR1bSt0Y3A6Ly'
- 'N0cmF0dW0rdGNwOi8v'
- 'zdHJhdHVtK3RjcDovL'
- 'c3RyYXR1bSt1ZHA6Ly'
- 'N0cmF0dW0rdWRwOi8v'
- 'zdHJhdHVtK3VkcDovL'
filter:
CommandLine|contains:
- ' pool.c '
- ' pool.o '
- 'gcc -'
condition: selection and not filter
falsepositives:
- Legitimate use of crypto miners
- Some build frameworks
level: high
Convert to SIEM query
high
Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
Detects potential DLL side loading of "KeyScramblerIE.dll" by "KeyScrambler.exe".
Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe".
view Sigma YAML
title: Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE
id: d2451be2-b582-4e15-8701-4196ac180260
related:
- id: ca5583e9-8f80-46ac-ab91-7f314d13b984
type: similar
status: test
description: |
Detects potential DLL side loading of "KeyScramblerIE.dll" by "KeyScrambler.exe".
Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe".
references:
- https://thehackernews.com/2024/03/two-chinese-apt-groups-ramp-up-cyber.html
- https://csirt-cti.net/2024/02/01/stately-taurus-continued-new-information-on-cyberespionage-attacks-against-myanmar-military-junta/
- https://bazaar.abuse.ch/sample/5cb9876681f78d3ee8a01a5aaa5d38b05ec81edc48b09e3865b75c49a2187831/
- https://twitter.com/Max_Mal_/status/1775222576639291859
- https://twitter.com/DTCERT/status/1712785426895839339
author: Swachchhanda Shrawan Poudel
date: 2024-04-15
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
Image|endswith:
- '\KeyScrambler.exe'
- '\KeyScramblerLogon.exe'
ImageLoaded|endswith: '\KeyScramblerIE.dll'
filter_main_legitimate_path:
Image|contains:
- 'C:\Program Files (x86)\KeyScrambler\'
- 'C:\Program Files\KeyScrambler\'
ImageLoaded|contains:
- 'C:\Program Files (x86)\KeyScrambler\'
- 'C:\Program Files\KeyScrambler\'
filter_main_signature:
Signature: 'QFX Software Corporation'
SignatureStatus: 'Valid'
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential DLL Sideloading Of Non-Existent DLLs From System Folders
Detects loading of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes, potentially indicating phantom DLL hijacking attempts.
Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs.
view Sigma YAML
title: Potential DLL Sideloading Of Non-Existent DLLs From System Folders
id: 6b98b92b-4f00-4f62-b4fe-4d1920215771
related:
- id: df6ecb8b-7822-4f4b-b412-08f524b4576c # FileEvent rule
type: similar
- id: 602a1f13-c640-4d73-b053-be9a2fa58b77
type: obsolete
status: test
description: |
Detects loading of specific system DLL files that are usually not present on the system (or at least not in system directories) but may be loaded by legitimate processes, potentially indicating phantom DLL hijacking attempts.
Phantom DLL hijacking involves placing malicious DLLs with names of non-existent system binaries in locations where legitimate applications may search for them, leading to execution of the malicious DLLs.
references:
- http://remoteawesomethoughts.blogspot.com/2019/05/windows-10-task-schedulerservice.html
- https://clement.notin.org/blog/2020/09/12/CVE-2020-7315-McAfee-Agent-DLL-injection/
- https://decoded.avast.io/martinchlumecky/png-steganography/
- https://github.com/Wh04m1001/SysmonEoP
- https://itm4n.github.io/cdpsvc-dll-hijacking/
- https://posts.specterops.io/lateral-movement-scm-and-dll-hijacking-primer-d2f61e8ab992
- https://securelist.com/passiveneuron-campaign-with-apt-implants-and-cobalt-strike/117745/
- https://www.crowdstrike.com/en-us/blog/4-ways-adversaries-hijack-dlls/
- https://www.hexacorn.com/blog/2013/12/08/beyond-good-ol-run-key-part-5/
- https://www.hexacorn.com/blog/2025/06/14/wermgr-exe-boot-offdmpsvc-dll-lolbin/
- https://www.hexacorn.com/blog/2025/06/14/wpr-exe-boottrace-phantom-dll-axeonoffhelper-dll-lolbin/
- https://x.com/0gtweet/status/1564131230941122561
author: Nasreddine Bencherchali (Nextron Systems), SBousseaden
date: 2022-12-09
modified: 2026-01-24
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded|endswith:
# Add other DLLs
- ':\Windows\System32\axeonoffhelper.dll'
- ':\Windows\System32\cdpsgshims.dll'
- ':\Windows\System32\oci.dll'
- ':\Windows\System32\offdmpsvc.dll'
- ':\Windows\System32\shellchromeapi.dll'
- ':\Windows\System32\TSMSISrv.dll'
- ':\Windows\System32\TSVIPSrv.dll'
- ':\Windows\System32\wbem\wbemcomn.dll'
- ':\Windows\System32\WLBSCTRL.dll'
- ':\Windows\System32\wow64log.dll'
- ':\Windows\System32\WptsExtensions.dll'
filter_main_ms_signed:
Signed: 'true'
SignatureStatus: 'Valid'
# There could be other signatures (please add when found)
Signature: 'Microsoft Windows'
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential DLL Sideloading Via VMware Xfer
Detects loading of a DLL by the VMware Xfer utility from the non-default directory which may be an attempt to sideload arbitrary DLL
view Sigma YAML
title: Potential DLL Sideloading Via VMware Xfer
id: 9313dc13-d04c-46d8-af4a-a930cc55d93b
status: test
description: Detects loading of a DLL by the VMware Xfer utility from the non-default directory which may be an attempt to sideload arbitrary DLL
references:
- https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-08-02
modified: 2023-02-17
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
product: windows
category: image_load
detection:
selection:
Image|endswith: '\VMwareXferlogs.exe'
ImageLoaded|endswith: '\glib-2.0.dll'
filter: # VMware might be installed in another path so update the rule accordingly
ImageLoaded|startswith: 'C:\Program Files\VMware\'
condition: selection and not filter
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential DLL Sideloading Via comctl32.dll
Detects potential DLL sideloading using comctl32.dll to obtain system privileges
view Sigma YAML
title: Potential DLL Sideloading Via comctl32.dll
id: 6360757a-d460-456c-8b13-74cf0e60cceb
status: test
description: Detects potential DLL sideloading using comctl32.dll to obtain system privileges
references:
- https://github.com/binderlabs/DirCreate2System
- https://github.com/sailay1996/awesome_windows_logical_bugs/blob/60cbb23a801f4c3195deac1cc46df27c225c3d07/dir_create2system.txt
author: Nasreddine Bencherchali (Nextron Systems), Subhash Popuri (@pbssubhash)
date: 2022-12-16
modified: 2022-12-19
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded|startswith:
- 'C:\Windows\System32\logonUI.exe.local\'
- 'C:\Windows\System32\werFault.exe.local\'
- 'C:\Windows\System32\consent.exe.local\'
- 'C:\Windows\System32\narrator.exe.local\'
- 'C:\windows\system32\wermgr.exe.local\'
ImageLoaded|endswith: '\comctl32.dll'
condition: selection
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential Data Exfiltration Activity Via CommandLine Tools
Detects the use of various CLI utilities exfiltrating data via web requests
view Sigma YAML
title: Potential Data Exfiltration Activity Via CommandLine Tools
id: 7d1aaf3d-4304-425c-b7c3-162055e0b3ab
status: test
description: Detects the use of various CLI utilities exfiltrating data via web requests
references:
- https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-08-02
modified: 2025-10-19
tags:
- attack.execution
- attack.t1059.001
logsource:
category: process_creation
product: windows
detection:
selection_iwr:
Image|endswith:
- '\powershell_ise.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\cmd.exe'
CommandLine|contains:
- 'curl '
- 'Invoke-RestMethod'
- 'Invoke-WebRequest'
- 'irm '
- 'iwr '
- 'wget '
CommandLine|contains|all:
- ' -ur' # Shortest possible version of the -uri flag
- ' -me' # Shortest possible version of the -method flag
- ' -b'
- ' POST '
selection_curl:
Image|endswith: '\curl.exe'
CommandLine|contains: '--ur' # Shortest possible version of the --uri flag
selection_curl_data:
CommandLine|contains:
- ' -d ' # Shortest possible version of the --data flag
- ' --data '
selection_wget:
Image|endswith: '\wget.exe'
CommandLine|contains:
- '--post-data'
- '--post-file'
payloads:
- CommandLine|re:
- 'net\s+view'
- 'sc\s+query'
- CommandLine|contains:
- 'Get-Content'
- 'GetBytes'
- 'hostname'
- 'ifconfig'
- 'ipconfig'
- 'netstat'
- 'nltest'
- 'qprocess'
- 'systeminfo'
- 'tasklist'
- 'ToBase64String'
- 'whoami'
- CommandLine|contains|all:
- 'type '
- ' > '
- ' C:\'
condition: (selection_iwr or all of selection_curl* or selection_wget) and payloads
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential Data Stealing Via Chromium Headless Debugging
Detects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control
view Sigma YAML
title: Potential Data Stealing Via Chromium Headless Debugging
id: 3e8207c5-fcd2-4ea6-9418-15d45b4890e4
related:
- id: b3d34dc5-2efd-4ae3-845f-8ec14921f449
type: derived
status: test
description: Detects chromium based browsers starting in headless and debugging mode and pointing to a user profile. This could be a sign of data stealing or remote control
references:
- https://github.com/defaultnamehere/cookie_crimes/
- https://mango.pdf.zone/stealing-chrome-cookies-without-a-password
- https://embracethered.com/blog/posts/2020/cookie-crimes-on-mirosoft-edge/
- https://embracethered.com/blog/posts/2020/chrome-spy-remote-control/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2022-12-23
tags:
- attack.credential-access
- attack.collection
- attack.stealth
- attack.t1185
- attack.t1564.003
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains|all:
- '--remote-debugging-' # Covers: --remote-debugging-address, --remote-debugging-port, --remote-debugging-socket-name, --remote-debugging-pipe....etc
- '--user-data-dir'
- '--headless'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
view Sigma YAML
title: Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
id: 4a30ac0c-b9d6-4e01-b71a-5f851bbf4259
status: test
description: Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
author: '@Kostastsale, TheDFIRReport'
references:
- Internal Research
tags:
- attack.stealth
date: 2022-12-05
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '😀'
- '😃'
- '😄'
- '😁'
- '😆'
- '😅'
- '😂'
- '🤣'
- '🥲'
- '🥹'
- '☺️'
- '😊'
- '😇'
- '🙂'
- '🙃'
- '😉'
- '😌'
- '😍'
- '🥰'
- '😘'
- '😗'
- '😙'
- '😚'
- '😋'
- '😛'
- '😝'
- '😜'
- '🤪'
- '🤨'
- '🧐'
- '🤓'
- '😎'
- '🥸'
- '🤩'
- '🥳'
- '😏'
- '😒'
- '😞'
- '😔'
- '😟'
- '😕'
- '🙁'
- '☹️'
- '😣'
- '😖'
- '😫'
- '😩'
- '🥺'
- '😢'
- '😭'
- '😮💨'
- '😤'
- '😠'
- '😡'
- '🤬'
- '🤯'
- '😳'
- '🥵'
- '🥶'
- '😱'
- '😨'
- '😰'
- '😥'
- '😓'
- '🫣'
- '🤗'
- '🫡'
- '🤔'
- '🫢'
- '🤭'
- '🤫'
- '🤥'
- '😶'
- '😶🌫️'
- '😐'
- '😑'
- '😬'
- '🫠'
- '🙄'
- '😯'
- '😦'
- '😧'
- '😮'
- '😲'
- '🥱'
- '😴'
- '🤤'
- '😪'
- '😵'
- '😵💫'
- '🫥'
- '🤐'
- '🥴'
- '🤢'
- '🤮'
- '🤧'
- '😷'
- '🤒'
- '🤕'
- '🤑'
- '🤠'
- '😈'
- '👿'
- '👹'
- '👺'
- '🤡'
- '💩'
- '👻'
- '💀'
- '☠️'
- '👽'
- '👾'
- '🤖'
- '🎃'
- '😺'
- '😸'
- '😹'
- '😻'
- '😼'
- '😽'
- '🙀'
- '😿'
- '😾'
- '👋'
- '🤚'
- '🖐'
- '✋'
- '🖖'
- '👌'
- '🤌'
- '🤏'
- '✌️'
- '🤞'
- '🫰'
- '🤟'
- '🤘'
- '🤙'
- '🫵'
- '🫱'
- '🫲'
- '🫳'
- '🫴'
- '👈'
- '👉'
- '👆'
- '🖕'
- '👇'
- '☝️'
- '👍'
- '👎'
- '✊'
- '👊'
- '🤛'
- '🤜'
- '👏'
- '🫶'
- '🙌'
- '👐'
- '🤲'
- '🤝'
- '🙏'
- '✍️'
- '💪'
- '🦾'
- '🦵'
- '🦿'
- '🦶'
- '👣'
- '👂'
- '🦻'
- '👃'
- '🫀'
- '🫁'
- '🧠'
- '🦷'
- '🦴'
- '👀'
- '👁'
- '👅'
- '👄'
- '🫦'
- '💋'
- '🩸'
- '👶'
- '👧'
- '🧒'
- '👦'
- '👩'
- '🧑'
- '👨'
- '👩🦱'
- '🧑🦱'
- '👨🦱'
- '👩🦰'
- '🧑🦰'
- '👨🦰'
- '👱♀️'
- '👱'
- '👱♂️'
- '👩🦳'
- '🧑🦳'
- '👨🦳'
- '👩🦲'
- '🧑🦲'
- '👨🦲'
- '🧔♀️'
- '🧔'
- '🧔♂️'
- '👵'
- '🧓'
- '👴'
- '👲'
- '👳♀️'
- '👳'
- '👳♂️'
- '🧕'
- '👮♀️'
- '👮'
- '👮♂️'
- '👷♀️'
- '👷'
- '👷♂️'
- '💂♀️'
- '💂'
- '💂♂️'
- '🕵️♀️'
- '🕵️'
- '🕵️♂️'
- '👩⚕️'
- '🧑⚕️'
- '👨⚕️'
- '👩🌾'
- '🧑🌾'
- '👨🌾'
- '👩🍳'
- '🧑🍳'
- '👨🍳'
- '👩🎓'
- '🧑🎓'
- '👨🎓'
- '👩🎤'
- '🧑🎤'
- '👨🎤'
- '👩🏫'
- '🧑🏫'
- '👨🏫'
- '👩🏭'
- '🧑🏭'
- '👨🏭'
- '👩💻'
- '🧑💻'
- '👨💻'
- '👩💼'
- '🧑💼'
- '👨💼'
- '👩🔧'
- '🧑🔧'
- '👨🔧'
- '👩🔬'
- '🧑🔬'
- '👨🔬'
- '👩🎨'
- '🧑🎨'
- '👨🎨'
- '👩🚒'
- '🧑🚒'
- '👨🚒'
- '👩✈️'
- '🧑✈️'
- '👨✈️'
- '👩🚀'
- '🧑🚀'
- '👨🚀'
- '👩⚖️'
- '🧑⚖️'
- '👨⚖️'
- '👰♀️'
- '👰'
- '👰♂️'
- '🤵♀️'
- '🤵'
- '🤵♂️'
- '👸'
- '🫅'
- '🤴'
- '🥷'
- '🦸♀️'
- '🦸'
- '🦸♂️'
- '🦹♀️'
- '🦹'
- '🦹♂️'
- '🤶'
- '🧑🎄'
- '🎅'
- '🧙♀️'
- '🧙'
- '🧙♂️'
- '🧝♀️'
- '🧝'
- '🧝♂️'
- '🧛♀️'
- '🧛'
- '🧛♂️'
- '🧟♀️'
- '🧟'
- '🧟♂️'
- '🧞♀️'
- '🧞'
- '🧞♂️'
- '🧜♀️'
- '🧜'
- '🧜♂️'
- '🧚♀️'
- '🧚'
- '🧚♂️'
- '🧌'
- '👼'
- '🤰'
- '🫄'
- '🫃'
- '🤱'
- '👩🍼'
- '🧑🍼'
- '👨🍼'
- '🙇♀️'
- '🙇'
- '🙇♂️'
- '💁♀️'
- '💁'
- '💁♂️'
- '🙅♀️'
- '🙅'
- '🙅♂️'
- '🙆♀️'
- '🙆'
- '🙆♂️'
- '🙋♀️'
- '🙋'
- '🙋♂️'
- '🧏♀️'
- '🧏'
- '🧏♂️'
- '🤦♀️'
- '🤦'
- '🤦♂️'
- '🤷♀️'
- '🤷'
- '🤷♂️'
- '🙎♀️'
- '🙎'
- '🙎♂️'
- '🙍♀️'
- '🙍'
- '🙍♂️'
- '💇♀️'
- '💇'
- '💇♂️'
- '💆♀️'
- '💆'
- '💆♂️'
- '🧖♀️'
- '🧖'
- '🧖♂️'
- '💅'
- '💃'
- '🕺'
- '👯♀️'
- '👯'
- '👯♂️'
- '🕴'
- '👩🦽'
- '🧑🦽'
- '👨🦽'
- '👩🦼'
- '🧑🦼'
- '👨🦼'
- '🚶♀️'
- '🚶'
- '🚶♂️'
- '👩🦯'
- '🧑🦯'
- '👨🦯'
- '🧎♀️'
- '🧎'
- '🧎♂️'
- '🏃♀️'
- '🏃'
- '🏃♂️'
- '🧍♀️'
- '🧍'
- '🧍♂️'
- '👭'
- '🧑🤝🧑'
- '👬'
- '👫'
- '👩❤️👩'
- '💑'
- '👨❤️👨'
- '👩❤️👨'
- '👩❤️💋👩'
- '💏'
- '👨❤️💋👨'
- '👩❤️💋👨'
- '👪'
- '👨👩👦'
- '👨👩👧'
- '👨👩👧👦'
- '👨👩👦👦'
- '👨👩👧👧'
- '👨👨👦'
- '👨👨👧'
- '👨👨👧👦'
- '👨👨👦👦'
- '👨👨👧👧'
- '👩👩👦'
- '👩👩👧'
- '👩👩👧👦'
- '👩👩👦👦'
- '👩👩👧👧'
- '👨👦'
- '👨👦👦'
- '👨👧'
- '👨👧👦'
- '👨👧👧'
- '👩👦'
- '👩👦👦'
- '👩👧'
- '👩👧👦'
- '👩👧👧'
- '🗣'
- '👤'
- '👥'
- '🫂'
- '🧳'
- '🌂'
- '☂️'
- '🧵'
- '🪡'
- '🪢'
- '🧶'
- '👓'
- '🕶'
- '🥽'
- '🥼'
- '🦺'
- '👔'
- '👕'
- '👖'
- '🧣'
- '🧤'
- '🧥'
- '🧦'
- '👗'
- '👘'
- '🥻'
- '🩴'
- '🩱'
- '🩲'
- '🩳'
- '👙'
- '👚'
- '👛'
- '👜'
- '👝'
- '🎒'
- '👞'
- '👟'
- '🥾'
- '🥿'
- '👠'
- '👡'
- '🩰'
- '👢'
- '👑'
- '👒'
- '🎩'
- '🎓'
- '🧢'
- '⛑'
- '🪖'
- '💄'
- '💍'
- '💼'
- '👋🏻'
- '🤚🏻'
- '🖐🏻'
- '✋🏻'
- '🖖🏻'
- '👌🏻'
- '🤌🏻'
- '🤏🏻'
- '✌🏻'
- '🤞🏻'
- '🫰🏻'
- '🤟🏻'
- '🤘🏻'
- '🤙🏻'
- '🫵🏻'
- '🫱🏻'
- '🫲🏻'
- '🫳🏻'
- '🫴🏻'
- '👈🏻'
- '👉🏻'
- '👆🏻'
- '🖕🏻'
- '👇🏻'
- '☝🏻'
- '👍🏻'
- '👎🏻'
- '✊🏻'
- '👊🏻'
- '🤛🏻'
- '🤜🏻'
- '👏🏻'
- '🫶🏻'
- '🙌🏻'
- '👐🏻'
- '🤲🏻'
- '🙏🏻'
- '✍🏻'
- '💪🏻'
- '🦵🏻'
- '🦶🏻'
- '👂🏻'
- '🦻🏻'
- '👃🏻'
- '👶🏻'
- '👧🏻'
- '🧒🏻'
- '👦🏻'
- '👩🏻'
- '🧑🏻'
- '👨🏻'
- '👩🏻🦱'
- '🧑🏻🦱'
- '👨🏻🦱'
- '👩🏻🦰'
- '🧑🏻🦰'
- '👨🏻🦰'
- '👱🏻♀️'
- '👱🏻'
- '👱🏻♂️'
- '👩🏻🦳'
- '🧑🏻🦳'
- '👨🏻🦳'
- '👩🏻🦲'
- '🧑🏻🦲'
- '👨🏻🦲'
- '🧔🏻♀️'
- '🧔🏻'
- '🧔🏻♂️'
- '👵🏻'
- '🧓🏻'
- '👴🏻'
- '👲🏻'
- '👳🏻♀️'
- '👳🏻'
- '👳🏻♂️'
- '🧕🏻'
- '👮🏻♀️'
- '👮🏻'
- '👮🏻♂️'
- '👷🏻♀️'
- '👷🏻'
- '👷🏻♂️'
- '💂🏻♀️'
- '💂🏻'
- '💂🏻♂️'
- '🕵🏻♀️'
- '🕵🏻'
- '🕵🏻♂️'
- '👩🏻⚕️'
- '🧑🏻⚕️'
- '👨🏻⚕️'
- '👩🏻🌾'
- '🧑🏻🌾'
- '👨🏻🌾'
- '👩🏻🍳'
- '🧑🏻🍳'
- '👨🏻🍳'
- '👩🏻🎓'
- '🧑🏻🎓'
- '👨🏻🎓'
- '👩🏻🎤'
- '🧑🏻🎤'
- '👨🏻🎤'
- '👩🏻🏫'
- '🧑🏻🏫'
- '👨🏻🏫'
- '👩🏻🏭'
- '🧑🏻🏭'
- '👨🏻🏭'
- '👩🏻💻'
- '🧑🏻💻'
- '👨🏻💻'
- '👩🏻💼'
- '🧑🏻💼'
- '👨🏻💼'
- '👩🏻🔧'
- '🧑🏻🔧'
- '👨🏻🔧'
- '👩🏻🔬'
- '🧑🏻🔬'
- '👨🏻🔬'
- '👩🏻🎨'
- '🧑🏻🎨'
- '👨🏻🎨'
- '👩🏻🚒'
- '🧑🏻🚒'
- '👨🏻🚒'
- '👩🏻✈️'
- '🧑🏻✈️'
- '👨🏻✈️'
- '👩🏻🚀'
- '🧑🏻🚀'
- '👨🏻🚀'
- '👩🏻⚖️'
- '🧑🏻⚖️'
- '👨🏻⚖️'
- '👰🏻♀️'
- '👰🏻'
- '👰🏻♂️'
- '🤵🏻♀️'
- '🤵🏻'
- '🤵🏻♂️'
- '👸🏻'
- '🫅🏻'
- '🤴🏻'
- '🥷🏻'
- '🦸🏻♀️'
- '🦸🏻'
- '🦸🏻♂️'
- '🦹🏻♀️'
- '🦹🏻'
- '🦹🏻♂️'
- '🤶🏻'
- '🧑🏻🎄'
- '🎅🏻'
- '🧙🏻♀️'
- '🧙🏻'
- '🧙🏻♂️'
- '🧝🏻♀️'
- '🧝🏻'
- '🧝🏻♂️'
- '🧛🏻♀️'
- '🧛🏻'
- '🧛🏻♂️'
- '🧜🏻♀️'
- '🧜🏻'
- '🧜🏻♂️'
- '🧚🏻♀️'
- '🧚🏻'
- '🧚🏻♂️'
- '👼🏻'
- '🤰🏻'
- '🫄🏻'
- '🫃🏻'
- '🤱🏻'
- '👩🏻🍼'
- '🧑🏻🍼'
- '👨🏻🍼'
- '🙇🏻♀️'
- '🙇🏻'
- '🙇🏻♂️'
- '💁🏻♀️'
- '💁🏻'
- '💁🏻♂️'
- '🙅🏻♀️'
- '🙅🏻'
- '🙅🏻♂️'
- '🙆🏻♀️'
- '🙆🏻'
- '🙆🏻♂️'
- '🙋🏻♀️'
- '🙋🏻'
- '🙋🏻♂️'
- '🧏🏻♀️'
- '🧏🏻'
- '🧏🏻♂️'
- '🤦🏻♀️'
- '🤦🏻'
- '🤦🏻♂️'
- '🤷🏻♀️'
- '🤷🏻'
- '🤷🏻♂️'
- '🙎🏻♀️'
- '🙎🏻'
- '🙎🏻♂️'
- '🙍🏻♀️'
- '🙍🏻'
- '🙍🏻♂️'
- '💇🏻♀️'
- '💇🏻'
- '💇🏻♂️'
- '💆🏻♀️'
- '💆🏻'
- '💆🏻♂️'
- '🧖🏻♀️'
- '🧖🏻'
- '🧖🏻♂️'
- '💃🏻'
- '🕺🏻'
- '🕴🏻'
- '👩🏻🦽'
- '🧑🏻🦽'
- '👨🏻🦽'
- '👩🏻🦼'
- '🧑🏻🦼'
- '👨🏻🦼'
- '🚶🏻♀️'
- '🚶🏻'
- '🚶🏻♂️'
- '👩🏻🦯'
- '🧑🏻🦯'
- '👨🏻🦯'
- '🧎🏻♀️'
- '🧎🏻'
- '🧎🏻♂️'
- '🏃🏻♀️'
- '🏃🏻'
- '🏃🏻♂️'
- '🧍🏻♀️'
- '🧍🏻'
- '🧍🏻♂️'
- '👭🏻'
- '🧑🏻🤝🧑🏻'
- '👬🏻'
- '👫🏻'
- '🧗🏻♀️'
- '🧗🏻'
- '🧗🏻♂️'
- '🏇🏻'
- '🏂🏻'
- '🏌🏻♀️'
- '🏌🏻'
- '🏌🏻♂️'
- '🏄🏻♀️'
- '🏄🏻'
- '🏄🏻♂️'
- '🚣🏻♀️'
- '🚣🏻'
- '🚣🏻♂️'
- '🏊🏻♀️'
- '🏊🏻'
- '🏊🏻♂️'
- '⛹🏻♀️'
- '⛹🏻'
- '⛹🏻♂️'
- '🏋🏻♀️'
- '🏋🏻'
- '🏋🏻♂️'
- '🚴🏻♀️'
- '🚴🏻'
- '🚴🏻♂️'
- '🚵🏻♀️'
- '🚵🏻'
- '🚵🏻♂️'
- '🤸🏻♀️'
- '🤸🏻'
- '🤸🏻♂️'
- '🤽🏻♀️'
- '🤽🏻'
- '🤽🏻♂️'
- '🤾🏻♀️'
- '🤾🏻'
- '🤾🏻♂️'
- '🤹🏻♀️'
- '🤹🏻'
- '🤹🏻♂️'
- '🧘🏻♀️'
- '🧘🏻'
- '🧘🏻♂️'
- '🛀🏻'
- '🛌🏻'
- '👋🏼'
- '🤚🏼'
- '🖐🏼'
- '✋🏼'
- '🖖🏼'
- '👌🏼'
- '🤌🏼'
- '🤏🏼'
- '✌🏼'
- '🤞🏼'
- '🫰🏼'
- '🤟🏼'
- '🤘🏼'
- '🤙🏼'
- '🫵🏼'
- '🫱🏼'
- '🫲🏼'
- '🫳🏼'
- '🫴🏼'
- '👈🏼'
- '👉🏼'
- '👆🏼'
- '🖕🏼'
- '👇🏼'
- '☝🏼'
- '👍🏼'
- '👎🏼'
- '✊🏼'
- '👊🏼'
- '🤛🏼'
- '🤜🏼'
- '👏🏼'
- '🫶🏼'
- '🙌🏼'
- '👐🏼'
- '🤲🏼'
- '🙏🏼'
- '✍🏼'
- '💪🏼'
- '🦵🏼'
- '🦶🏼'
- '👂🏼'
- '🦻🏼'
- '👃🏼'
- '👶🏼'
- '👧🏼'
- '🧒🏼'
- '👦🏼'
- '👩🏼'
- '🧑🏼'
- '👨🏼'
- '👩🏼🦱'
- '🧑🏼🦱'
- '👨🏼🦱'
- '👩🏼🦰'
- '🧑🏼🦰'
- '👨🏼🦰'
- '👱🏼♀️'
- '👱🏼'
- '👱🏼♂️'
- '👩🏼🦳'
- '🧑🏼🦳'
- '👨🏼🦳'
- '👩🏼🦲'
- '🧑🏼🦲'
- '👨🏼🦲'
- '🧔🏼♀️'
- '🧔🏼'
- '🧔🏼♂️'
- '👵🏼'
- '🧓🏼'
- '👴🏼'
- '👲🏼'
- '👳🏼♀️'
- '👳🏼'
- '👳🏼♂️'
- '🧕🏼'
- '👮🏼♀️'
- '👮🏼'
- '👮🏼♂️'
- '👷🏼♀️'
- '👷🏼'
- '👷🏼♂️'
- '💂🏼♀️'
- '💂🏼'
- '💂🏼♂️'
- '🕵🏼♀️'
- '🕵🏼'
- '🕵🏼♂️'
- '👩🏼⚕️'
- '🧑🏼⚕️'
- '👨🏼⚕️'
- '👩🏼🌾'
- '🧑🏼🌾'
- '👨🏼🌾'
- '👩🏼🍳'
- '🧑🏼🍳'
- '👨🏼🍳'
- '👩🏼🎓'
- '🧑🏼🎓'
- '👨🏼🎓'
- '👩🏼🎤'
- '🧑🏼🎤'
- '👨🏼🎤'
- '👩🏼🏫'
- '🧑🏼🏫'
- '👨🏼🏫'
- '👩🏼🏭'
- '🧑🏼🏭'
- '👨🏼🏭'
- '👩🏼💻'
- '🧑🏼💻'
- '👨🏼💻'
- '👩🏼💼'
- '🧑🏼💼'
- '👨🏼💼'
- '👩🏼🔧'
- '🧑🏼🔧'
- '👨🏼🔧'
- '👩🏼🔬'
- '🧑🏼🔬'
- '👨🏼🔬'
- '👩🏼🎨'
- '🧑🏼🎨'
- '👨🏼🎨'
- '👩🏼🚒'
- '🧑🏼🚒'
- '👨🏼🚒'
- '👩🏼✈️'
- '🧑🏼✈️'
- '👨🏼✈️'
- '👩🏼🚀'
- '🧑🏼🚀'
- '👨🏼🚀'
- '👩🏼⚖️'
- '🧑🏼⚖️'
- '👨🏼⚖️'
- '👰🏼♀️'
- '👰🏼'
- '👰🏼♂️'
- '🤵🏼♀️'
- '🤵🏼'
- '🤵🏼♂️'
- '👸🏼'
- '🫅🏼'
- '🤴🏼'
- '🥷🏼'
- '🦸🏼♀️'
- '🦸🏼'
- '🦸🏼♂️'
- '🦹🏼♀️'
- '🦹🏼'
- '🦹🏼♂️'
- '🤶🏼'
- '🧑🏼🎄'
- '🎅🏼'
- '🧙🏼♀️'
- '🧙🏼'
- '🧙🏼♂️'
- '🧝🏼♀️'
- '🧝🏼'
- '🧝🏼♂️'
- '🧛🏼♀️'
- '🧛🏼'
- '🧛🏼♂️'
- '🧜🏼♀️'
- '🧜🏼'
- '🧜🏼♂️'
- '🧚🏼♀️'
- '🧚🏼'
- '🧚🏼♂️'
- '👼🏼'
- '🤰🏼'
- '🫄🏼'
- '🫃🏼'
- '🤱🏼'
- '👩🏼🍼'
- '🧑🏼🍼'
- '👨🏼🍼'
- '🙇🏼♀️'
- '🙇🏼'
- '🙇🏼♂️'
- '💁🏼♀️'
- '💁🏼'
- '💁🏼♂️'
- '🙅🏼♀️'
- '🙅🏼'
- '🙅🏼♂️'
- '🙆🏼♀️'
- '🙆🏼'
- '🙆🏼♂️'
- '🙋🏼♀️'
- '🙋🏼'
- '🙋🏼♂️'
- '🧏🏼♀️'
- '🧏🏼'
- '🧏🏼♂️'
- '🤦🏼♀️'
- '🤦🏼'
- '🤦🏼♂️'
- '🤷🏼♀️'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
view Sigma YAML
title: Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 2
id: c98f2a0d-e1b8-4f76-90d3-359caf88d6b9
status: test
description: Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
author: '@Kostastsale, TheDFIRReport'
references:
- Internal Research
tags:
- attack.stealth
date: 2022-12-05
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '🤷🏼'
- '🤷🏼♂️'
- '🙎🏼♀️'
- '🙎🏼'
- '🙎🏼♂️'
- '🙍🏼♀️'
- '🙍🏼'
- '🙍🏼♂️'
- '💇🏼♀️'
- '💇🏼'
- '💇🏼♂️'
- '💆🏼♀️'
- '💆🏼'
- '💆🏼♂️'
- '🧖🏼♀️'
- '🧖🏼'
- '🧖🏼♂️'
- '💃🏼'
- '🕺🏼'
- '🕴🏼'
- '👩🏼🦽'
- '🧑🏼🦽'
- '👨🏼🦽'
- '👩🏼🦼'
- '🧑🏼🦼'
- '👨🏼🦼'
- '🚶🏼♀️'
- '🚶🏼'
- '🚶🏼♂️'
- '👩🏼🦯'
- '🧑🏼🦯'
- '👨🏼🦯'
- '🧎🏼♀️'
- '🧎🏼'
- '🧎🏼♂️'
- '🏃🏼♀️'
- '🏃🏼'
- '🏃🏼♂️'
- '🧍🏼♀️'
- '🧍🏼'
- '🧍🏼♂️'
- '👭🏼'
- '🧑🏼🤝🧑🏼'
- '👬🏼'
- '👫🏼'
- '🧗🏼♀️'
- '🧗🏼'
- '🧗🏼♂️'
- '🏇🏼'
- '🏂🏼'
- '🏌🏼♀️'
- '🏌🏼'
- '🏌🏼♂️'
- '🏄🏼♀️'
- '🏄🏼'
- '🏄🏼♂️'
- '🚣🏼♀️'
- '🚣🏼'
- '🚣🏼♂️'
- '🏊🏼♀️'
- '🏊🏼'
- '🏊🏼♂️'
- '⛹🏼♀️'
- '⛹🏼'
- '⛹🏼♂️'
- '🏋🏼♀️'
- '🏋🏼'
- '🏋🏼♂️'
- '🚴🏼♀️'
- '🚴🏼'
- '🚴🏼♂️'
- '🚵🏼♀️'
- '🚵🏼'
- '🚵🏼♂️'
- '🤸🏼♀️'
- '🤸🏼'
- '🤸🏼♂️'
- '🤽🏼♀️'
- '🤽🏼'
- '🤽🏼♂️'
- '🤾🏼♀️'
- '🤾🏼'
- '🤾🏼♂️'
- '🤹🏼♀️'
- '🤹🏼'
- '🤹🏼♂️'
- '🧘🏼♀️'
- '🧘🏼'
- '🧘🏼♂️'
- '🛀🏼'
- '🛌🏼'
- '👋🏽'
- '🤚🏽'
- '🖐🏽'
- '✋🏽'
- '🖖🏽'
- '👌🏽'
- '🤌🏽'
- '🤏🏽'
- '✌🏽'
- '🤞🏽'
- '🫰🏽'
- '🤟🏽'
- '🤘🏽'
- '🤙🏽'
- '🫵🏽'
- '🫱🏽'
- '🫲🏽'
- '🫳🏽'
- '🫴🏽'
- '👈🏽'
- '👉🏽'
- '👆🏽'
- '🖕🏽'
- '👇🏽'
- '☝🏽'
- '👍🏽'
- '👎🏽'
- '✊🏽'
- '👊🏽'
- '🤛🏽'
- '🤜🏽'
- '👏🏽'
- '🫶🏽'
- '🙌🏽'
- '👐🏽'
- '🤲🏽'
- '🙏🏽'
- '✍🏽'
- '💪🏽'
- '🦵🏽'
- '🦶🏽'
- '👂🏽'
- '🦻🏽'
- '👃🏽'
- '👶🏽'
- '👧🏽'
- '🧒🏽'
- '👦🏽'
- '👩🏽'
- '🧑🏽'
- '👨🏽'
- '👩🏽🦱'
- '🧑🏽🦱'
- '👨🏽🦱'
- '👩🏽🦰'
- '🧑🏽🦰'
- '👨🏽🦰'
- '👱🏽♀️'
- '👱🏽'
- '👱🏽♂️'
- '👩🏽🦳'
- '🧑🏽🦳'
- '👨🏽🦳'
- '👩🏽🦲'
- '🧑🏽🦲'
- '👨🏽🦲'
- '🧔🏽♀️'
- '🧔🏽'
- '🧔🏽♂️'
- '👵🏽'
- '🧓🏽'
- '👴🏽'
- '👲🏽'
- '👳🏽♀️'
- '👳🏽'
- '👳🏽♂️'
- '🧕🏽'
- '👮🏽♀️'
- '👮🏽'
- '👮🏽♂️'
- '👷🏽♀️'
- '👷🏽'
- '👷🏽♂️'
- '💂🏽♀️'
- '💂🏽'
- '💂🏽♂️'
- '🕵🏽♀️'
- '🕵🏽'
- '🕵🏽♂️'
- '👩🏽⚕️'
- '🧑🏽⚕️'
- '👨🏽⚕️'
- '👩🏽🌾'
- '🧑🏽🌾'
- '👨🏽🌾'
- '👩🏽🍳'
- '🧑🏽🍳'
- '👨🏽🍳'
- '👩🏽🎓'
- '🧑🏽🎓'
- '👨🏽🎓'
- '👩🏽🎤'
- '🧑🏽🎤'
- '👨🏽🎤'
- '👩🏽🏫'
- '🧑🏽🏫'
- '👨🏽🏫'
- '👩🏽🏭'
- '🧑🏽🏭'
- '👨🏽🏭'
- '👩🏽💻'
- '🧑🏽💻'
- '👨🏽💻'
- '👩🏽💼'
- '🧑🏽💼'
- '👨🏽💼'
- '👩🏽🔧'
- '🧑🏽🔧'
- '👨🏽🔧'
- '👩🏽🔬'
- '🧑🏽🔬'
- '👨🏽🔬'
- '👩🏽🎨'
- '🧑🏽🎨'
- '👨🏽🎨'
- '👩🏽🚒'
- '🧑🏽🚒'
- '👨🏽🚒'
- '👩🏽✈️'
- '🧑🏽✈️'
- '👨🏽✈️'
- '👩🏽🚀'
- '🧑🏽🚀'
- '👨🏽🚀'
- '👩🏽⚖️'
- '🧑🏽⚖️'
- '👨🏽⚖️'
- '👰🏽♀️'
- '👰🏽'
- '👰🏽♂️'
- '🤵🏽♀️'
- '🤵🏽'
- '🤵🏽♂️'
- '👸🏽'
- '🫅🏽'
- '🤴🏽'
- '🥷🏽'
- '🦸🏽♀️'
- '🦸🏽'
- '🦸🏽♂️'
- '🦹🏽♀️'
- '🦹🏽'
- '🦹🏽♂️'
- '🤶🏽'
- '🧑🏽🎄'
- '🎅🏽'
- '🧙🏽♀️'
- '🧙🏽'
- '🧙🏽♂️'
- '🧝🏽♀️'
- '🧝🏽'
- '🧝🏽♂️'
- '🧛🏽♀️'
- '🧛🏽'
- '🧛🏽♂️'
- '🧜🏽♀️'
- '🧜🏽'
- '🧜🏽♂️'
- '🧚🏽♀️'
- '🧚🏽'
- '🧚🏽♂️'
- '👼🏽'
- '🤰🏽'
- '🫄🏽'
- '🫃🏽'
- '🤱🏽'
- '👩🏽🍼'
- '🧑🏽🍼'
- '👨🏽🍼'
- '🙇🏽♀️'
- '🙇🏽'
- '🙇🏽♂️'
- '💁🏽♀️'
- '💁🏽'
- '💁🏽♂️'
- '🙅🏽♀️'
- '🙅🏽'
- '🙅🏽♂️'
- '🙆🏽♀️'
- '🙆🏽'
- '🙆🏽♂️'
- '🙋🏽♀️'
- '🙋🏽'
- '🙋🏽♂️'
- '🧏🏽♀️'
- '🧏🏽'
- '🧏🏽♂️'
- '🤦🏽♀️'
- '🤦🏽'
- '🤦🏽♂️'
- '🤷🏽♀️'
- '🤷🏽'
- '🤷🏽♂️'
- '🙎🏽♀️'
- '🙎🏽'
- '🙎🏽♂️'
- '🙍🏽♀️'
- '🙍🏽'
- '🙍🏽♂️'
- '💇🏽♀️'
- '💇🏽'
- '💇🏽♂️'
- '💆🏽♀️'
- '💆🏽'
- '💆🏽♂️'
- '🧖🏽♀️'
- '🧖🏽'
- '🧖🏽♂️'
- '💃🏽'
- '🕺🏽'
- '🕴🏽'
- '👩🏽🦽'
- '🧑🏽🦽'
- '👨🏽🦽'
- '👩🏽🦼'
- '🧑🏽🦼'
- '👨🏽🦼'
- '🚶🏽♀️'
- '🚶🏽'
- '🚶🏽♂️'
- '👩🏽🦯'
- '🧑🏽🦯'
- '👨🏽🦯'
- '🧎🏽♀️'
- '🧎🏽'
- '🧎🏽♂️'
- '🏃🏽♀️'
- '🏃🏽'
- '🏃🏽♂️'
- '🧍🏽♀️'
- '🧍🏽'
- '🧍🏽♂️'
- '👭🏽'
- '🧑🏽🤝🧑🏽'
- '👬🏽'
- '👫🏽'
- '🧗🏽♀️'
- '🧗🏽'
- '🧗🏽♂️'
- '🏇🏽'
- '🏂🏽'
- '🏌🏽♀️'
- '🏌🏽'
- '🏌🏽♂️'
- '🏄🏽♀️'
- '🏄🏽'
- '🏄🏽♂️'
- '🚣🏽♀️'
- '🚣🏽'
- '🚣🏽♂️'
- '🏊🏽♀️'
- '🏊🏽'
- '🏊🏽♂️'
- '⛹🏽♀️'
- '⛹🏽'
- '⛹🏽♂️'
- '🏋🏽♀️'
- '🏋🏽'
- '🏋🏽♂️'
- '🚴🏽♀️'
- '🚴🏽'
- '🚴🏽♂️'
- '🚵🏽♀️'
- '🚵🏽'
- '🚵🏽♂️'
- '🤸🏽♀️'
- '🤸🏽'
- '🤸🏽♂️'
- '🤽🏽♀️'
- '🤽🏽'
- '🤽🏽♂️'
- '🤾🏽♀️'
- '🤾🏽'
- '🤾🏽♂️'
- '🤹🏽♀️'
- '🤹🏽'
- '🤹🏽♂️'
- '🧘🏽♀️'
- '🧘🏽'
- '🧘🏽♂️'
- '🛀🏽'
- '🛌🏽'
- '👋🏾'
- '🤚🏾'
- '🖐🏾'
- '✋🏾'
- '🖖🏾'
- '👌🏾'
- '🤌🏾'
- '🤏🏾'
- '✌🏾'
- '🤞🏾'
- '🫰🏾'
- '🤟🏾'
- '🤘🏾'
- '🤙🏾'
- '🫵🏾'
- '🫱🏾'
- '🫲🏾'
- '🫳🏾'
- '🫴🏾'
- '👈🏾'
- '👉🏾'
- '👆🏾'
- '🖕🏾'
- '👇🏾'
- '☝🏾'
- '👍🏾'
- '👎🏾'
- '✊🏾'
- '👊🏾'
- '🤛🏾'
- '🤜🏾'
- '👏🏾'
- '🫶🏾'
- '🙌🏾'
- '👐🏾'
- '🤲🏾'
- '🙏🏾'
- '✍🏾'
- '💪🏾'
- '🦵🏾'
- '🦶🏾'
- '👂🏾'
- '🦻🏾'
- '👃🏾'
- '👶🏾'
- '👧🏾'
- '🧒🏾'
- '👦🏾'
- '👩🏾'
- '🧑🏾'
- '👨🏾'
- '👩🏾🦱'
- '🧑🏾🦱'
- '👨🏾🦱'
- '👩🏾🦰'
- '🧑🏾🦰'
- '👨🏾🦰'
- '👱🏾♀️'
- '👱🏾'
- '👱🏾♂️'
- '👩🏾🦳'
- '🧑🏾🦳'
- '👨🏾🦳'
- '👩🏾🦲'
- '🧑🏾🦲'
- '👨🏾🦲'
- '🧔🏾♀️'
- '🧔🏾'
- '🧔🏾♂️'
- '👵🏾'
- '🧓🏾'
- '👴🏾'
- '👲🏾'
- '👳🏾♀️'
- '👳🏾'
- '👳🏾♂️'
- '🧕🏾'
- '👮🏾♀️'
- '👮🏾'
- '👮🏾♂️'
- '👷🏾♀️'
- '👷🏾'
- '👷🏾♂️'
- '💂🏾♀️'
- '💂🏾'
- '💂🏾♂️'
- '🕵🏾♀️'
- '🕵🏾'
- '🕵🏾♂️'
- '👩🏾⚕️'
- '🧑🏾⚕️'
- '👨🏾⚕️'
- '👩🏾🌾'
- '🧑🏾🌾'
- '👨🏾🌾'
- '👩🏾🍳'
- '🧑🏾🍳'
- '👨🏾🍳'
- '👩🏾🎓'
- '🧑🏾🎓'
- '👨🏾🎓'
- '👩🏾🎤'
- '🧑🏾🎤'
- '👨🏾🎤'
- '👩🏾🏫'
- '🧑🏾🏫'
- '👨🏾🏫'
- '👩🏾🏭'
- '🧑🏾🏭'
- '👨🏾🏭'
- '👩🏾💻'
- '🧑🏾💻'
- '👨🏾💻'
- '👩🏾💼'
- '🧑🏾💼'
- '👨🏾💼'
- '👩🏾🔧'
- '🧑🏾🔧'
- '👨🏾🔧'
- '👩🏾🔬'
- '🧑🏾🔬'
- '👨🏾🔬'
- '👩🏾🎨'
- '🧑🏾🎨'
- '👨🏾🎨'
- '👩🏾🚒'
- '🧑🏾🚒'
- '👨🏾🚒'
- '👩🏾✈️'
- '🧑🏾✈️'
- '👨🏾✈️'
- '👩🏾🚀'
- '🧑🏾🚀'
- '👨🏾🚀'
- '👩🏾⚖️'
- '🧑🏾⚖️'
- '👨🏾⚖️'
- '👰🏾♀️'
- '👰🏾'
- '👰🏾♂️'
- '🤵🏾♀️'
- '🤵🏾'
- '🤵🏾♂️'
- '👸🏾'
- '🫅🏾'
- '🤴🏾'
- '🥷🏾'
- '🦸🏾♀️'
- '🦸🏾'
- '🦸🏾♂️'
- '🦹🏾♀️'
- '🦹🏾'
- '🦹🏾♂️'
- '🤶🏾'
- '🧑🏾🎄'
- '🎅🏾'
- '🧙🏾♀️'
- '🧙🏾'
- '🧙🏾♂️'
- '🧝🏾♀️'
- '🧝🏾'
- '🧝🏾♂️'
- '🧛🏾♀️'
- '🧛🏾'
- '🧛🏾♂️'
- '🧜🏾♀️'
- '🧜🏾'
- '🧜🏾♂️'
- '🧚🏾♀️'
- '🧚🏾'
- '🧚🏾♂️'
- '👼🏾'
- '🤰🏾'
- '🫄🏾'
- '🫃🏾'
- '🤱🏾'
- '👩🏾🍼'
- '🧑🏾🍼'
- '👨🏾🍼'
- '🙇🏾♀️'
- '🙇🏾'
- '🙇🏾♂️'
- '💁🏾♀️'
- '💁🏾'
- '💁🏾♂️'
- '🙅🏾♀️'
- '🙅🏾'
- '🙅🏾♂️'
- '🙆🏾♀️'
- '🙆🏾'
- '🙆🏾♂️'
- '🙋🏾♀️'
- '🙋🏾'
- '🙋🏾♂️'
- '🧏🏾♀️'
- '🧏🏾'
- '🧏🏾♂️'
- '🤦🏾♀️'
- '🤦🏾'
- '🤦🏾♂️'
- '🤷🏾♀️'
- '🤷🏾'
- '🤷🏾♂️'
- '🙎🏾♀️'
- '🙎🏾'
- '🙎🏾♂️'
- '🙍🏾♀️'
- '🙍🏾'
- '🙍🏾♂️'
- '💇🏾♀️'
- '💇🏾'
- '💇🏾♂️'
- '💆🏾♀️'
- '💆🏾'
- '💆🏾♂️'
- '🧖🏾♀️'
- '🧖🏾'
- '🧖🏾♂️'
- '💃🏾'
- '🕺🏾'
- '👩🏾🦽'
- '🧑🏾🦽'
- '👨🏾🦽'
- '👩🏾🦼'
- '🧑🏾🦼'
- '👨🏾🦼'
- '🚶🏾♀️'
- '🚶🏾'
- '🚶🏾♂️'
- '👩🏾🦯'
- '🧑🏾🦯'
- '👨🏾🦯'
- '🧎🏾♀️'
- '🧎🏾'
- '🧎🏾♂️'
- '🏃🏾♀️'
- '🏃🏾'
- '🏃🏾♂️'
- '🧍🏾♀️'
- '🧍🏾'
- '🧍🏾♂️'
- '👭🏾'
- '🧑🏾🤝🧑🏾'
- '👬🏾'
- '👫🏾'
- '🧗🏾♀️'
- '🧗🏾'
- '🧗🏾♂️'
- '🏇🏾'
- '🏂🏾'
- '🏌🏾♀️'
- '🏌🏾'
- '🏌🏾♂️'
- '🏄🏾♀️'
- '🏄🏾'
- '🏄🏾♂️'
- '🚣🏾♀️'
- '🚣🏾'
- '🚣🏾♂️'
- '🏊🏾♀️'
- '🏊🏾'
- '🏊🏾♂️'
- '⛹🏾♀️'
- '⛹🏾'
- '⛹🏾♂️'
- '🏋🏾♀️'
- '🏋🏾'
- '🏋🏾♂️'
- '🚴🏾♀️'
- '🚴🏾'
- '🚴🏾♂️'
- '🚵🏾♀️'
- '🚵🏾'
- '🚵🏾♂️'
- '🤸🏾♀️'
- '🤸🏾'
- '🤸🏾♂️'
- '🤽🏾♀️'
- '🤽🏾'
- '🤽🏾♂️'
- '🤾🏾♀️'
- '🤾🏾'
- '🤾🏾♂️'
- '🤹🏾♀️'
- '🤹🏾'
- '🤹🏾♂️'
- '🧘🏾♀️'
- '🧘🏾'
- '🧘🏾♂️'
- '🛀🏾'
- '🛌🏾'
- '👋🏿'
- '🤚🏿'
- '🖐🏿'
- '✋🏿'
- '🖖🏿'
- '👌🏿'
- '🤌🏿'
- '🤏🏿'
- '✌🏿'
- '🤞🏿'
- '🫰🏿'
- '🤟🏿'
- '🤘🏿'
- '🤙🏿'
- '🫵🏿'
- '🫱🏿'
- '🫲🏿'
- '🫳🏿'
- '🫴🏿'
- '👈🏿'
- '👉🏿'
- '👆🏿'
- '🖕🏿'
- '👇🏿'
- '☝🏿'
- '👍🏿'
- '👎🏿'
- '✊🏿'
- '👊🏿'
- '🤛🏿'
- '🤜🏿'
- '👏🏿'
- '🫶🏿'
- '🙌🏿'
- '👐🏿'
- '🤲🏿'
- '🙏🏿'
- '✍🏿'
- '🤳🏿'
- '💪🏿'
- '🦵🏿'
- '🦶🏿'
- '👂🏿'
- '🦻🏿'
- '👃🏿'
- '👶🏿'
- '👧🏿'
- '🧒🏿'
- '👦🏿'
- '👩🏿'
- '🧑🏿'
- '👨🏿'
- '👩🏿🦱'
- '🧑🏿🦱'
- '👨🏿🦱'
- '👩🏿🦰'
- '🧑🏿🦰'
- '👨🏿🦰'
- '👱🏿♀️'
- '👱🏿'
- '👱🏿♂️'
- '👩🏿🦳'
- '🧑🏿🦳'
- '👨🏿🦳'
- '👩🏿🦲'
- '🧑🏿🦲'
- '👨🏿🦲'
- '🧔🏿♀️'
- '🧔🏿'
- '🧔🏿♂️'
- '👵🏿'
- '🧓🏿'
- '👴🏿'
- '👲🏿'
- '👳🏿♀️'
- '👳🏿'
- '👳🏿♂️'
- '🧕🏿'
- '👮🏿♀️'
- '👮🏿'
- '👮🏿♂️'
- '👷🏿♀️'
- '👷🏿'
- '👷🏿♂️'
- '💂🏿♀️'
- '💂🏿'
- '💂🏿♂️'
- '🕵🏿♀️'
- '🕵🏿'
- '🕵🏿♂️'
- '👩🏿⚕️'
- '🧑🏿⚕️'
- '👨🏿⚕️'
- '👩🏿🌾'
- '🧑🏿🌾'
- '👨🏿🌾'
- '👩🏿🍳'
- '🧑🏿🍳'
- '👨🏿🍳'
- '👩🏿🎓'
- '🧑🏿🎓'
- '👨🏿🎓'
- '👩🏿🎤'
- '🧑🏿🎤'
- '👨🏿🎤'
- '👩🏿🏫'
- '🧑🏿🏫'
- '👨🏿🏫'
- '👩🏿🏭'
- '🧑🏿🏭'
- '👨🏿🏭'
- '👩🏿💻'
- '🧑🏿💻'
- '👨🏿💻'
- '👩🏿💼'
- '🧑🏿💼'
- '👨🏿💼'
- '👩🏿🔧'
- '🧑🏿🔧'
- '👨🏿🔧'
- '👩🏿🔬'
- '🧑🏿🔬'
- '👨🏿🔬'
- '👩🏿🎨'
- '🧑🏿🎨'
- '👨🏿🎨'
- '👩🏿🚒'
- '🧑🏿🚒'
- '👨🏿🚒'
- '👩🏿✈️'
- '🧑🏿✈️'
- '👨🏿✈️'
- '👩🏿🚀'
- '🧑🏿🚀'
- '👨🏿🚀'
- '👩🏿⚖️'
- '🧑🏿⚖️'
- '👨🏿⚖️'
- '👰🏿♀️'
- '👰🏿'
- '👰🏿♂️'
- '🤵🏿♀️'
- '🤵🏿'
- '🤵🏿♂️'
- '👸🏿'
- '🫅🏿'
- '🤴🏿'
- '🥷🏿'
- '🦸🏿♀️'
- '🦸🏿'
- '🦸🏿♂️'
- '🦹🏿♀️'
- '🦹🏿'
- '🦹🏿♂️'
- '🤶🏿'
- '🧑🏿🎄'
- '🎅🏿'
- '🧙🏿♀️'
- '🧙🏿'
- '🧙🏿♂️'
- '🧝🏿♀️'
- '🧝🏿'
- '🧝🏿♂️'
- '🧛🏿♀️'
- '🧛🏿'
- '🧛🏿♂️'
- '🧜🏿♀️'
- '🧜🏿'
- '🧜🏿♂️'
- '🧚🏿♀️'
- '🧚🏿'
- '🧚🏿♂️'
- '👼🏿'
- '🤰🏿'
- '🫄🏿'
- '🫃🏿'
- '🤱🏿'
- '👩🏿🍼'
- '🧑🏿🍼'
- '👨🏿🍼'
- '🙇🏿♀️'
- '🙇🏿'
- '🙇🏿♂️'
- '💁🏿♀️'
- '💁🏿'
- '💁🏿♂️'
- '🙅🏿♀️'
- '🙅🏿'
- '🙅🏿♂️'
- '🙆🏿♀️'
- '🙆🏿'
- '🙆🏿♂️'
- '🙋🏿♀️'
- '🙋🏿'
- '🙋🏿♂️'
- '🧏🏿♀️'
- '🧏🏿'
- '🧏🏿♂️'
- '🤦🏿♀️'
- '🤦🏿'
- '🤦🏿♂️'
- '🤷🏿♀️'
- '🤷🏿'
- '🤷🏿♂️'
- '🙎🏿♀️'
- '🙎🏿'
- '🙎🏿♂️'
- '🙍🏿♀️'
- '🙍🏿'
- '🙍🏿♂️'
- '💇🏿♀️'
- '💇🏿'
- '💇🏿♂️'
- '💆🏿♀️'
- '💆🏿'
- '💆🏿♂️'
- '🧖🏿♀️'
- '🧖🏿'
- '🧖🏿♂️'
- '💃🏿'
- '🕺🏿'
- '🕴🏿'
- '👩🏿🦽'
- '🧑🏿🦽'
- '👨🏿🦽'
- '👩🏿🦼'
- '🧑🏿🦼'
- '👨🏿🦼'
- '🚶🏿♀️'
- '🚶🏿'
- '🚶🏿♂️'
- '👩🏿🦯'
- '🧑🏿🦯'
- '👨🏿🦯'
- '🧎🏿♀️'
- '🧎🏿'
- '🧎🏿♂️'
- '🏃🏿♀️'
- '🏃🏿'
- '🏃🏿♂️'
- '🧍🏿♀️'
- '🧍🏿'
- '🧍🏿♂️'
- '👭🏿'
- '🧑🏿🤝🧑🏿'
- '👬🏿'
- '👫🏿'
- '🧗🏿♀️'
- '🧗🏿'
- '🧗🏿♂️'
- '🏇🏿'
- '🏂🏿'
- '🏌🏿♀️'
- '🏌🏿'
- '🏌🏿♂️'
- '🏄🏿♀️'
- '🏄🏿'
- '🏄🏿♂️'
- '🚣🏿♀️'
- '🚣🏿'
- '🚣🏿♂️'
- '🏊🏿♀️'
- '🏊🏿'
- '🏊🏿♂️'
- '⛹🏿♀️'
- '⛹🏿'
- '⛹🏿♂️'
- '🏋🏿♀️'
- '🏋🏿'
- '🏋🏿♂️'
- '🚴🏿♀️'
- '🚴🏿'
- '🚴🏿♂️'
- '🚵🏿♀️'
- '🚵🏿'
- '🚵🏿♂️'
- '🤸🏿♀️'
- '🤸🏿'
- '🤸🏿♂️'
- '🤽🏿♀️'
- '🤽🏿'
- '🤽🏿♂️'
- '🤾🏿♀️'
- '🤾🏿'
- '🤾🏿♂️'
- '🤹🏿♀️'
- '🤹🏿'
- '🤹🏿♂️'
- '🧘🏿♀️'
- '🧘🏿'
- '🧘🏿♂️'
- '🛀🏿'
- '🛌🏿'
- '🐶'
- '🐱'
- '🐭'
- '🐹'
- '🐰'
- '🦊'
- '🐻'
- '🐼'
- '🐻❄️'
- '🐨'
- '🐯'
- '🦁'
- '🐮'
- '🐷'
- '🐽'
- '🐸'
- '🐵'
- '🙈'
- '🙉'
- '🙊'
- '🐒'
- '🐔'
- '🐧'
- '🐦'
- '🐤'
- '🐣'
- '🐥'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
view Sigma YAML
title: Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 3
id: f9578658-9e71-4711-b634-3f9b50cd3c06
status: test
description: Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
author: '@Kostastsale, TheDFIRReport'
references:
- Internal Research
tags:
- attack.stealth
date: 2022-12-05
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '🦆'
- '🦅'
- '🦉'
- '🦇'
- '🐺'
- '🐗'
- '🐴'
- '🦄'
- '🐝'
- '🪱'
- '🐛'
- '🦋'
- '🐌'
- '🐞'
- '🐜'
- '🪰'
- '🪲'
- '🪳'
- '🦟'
- '🦗'
- '🕷'
- '🕸'
- '🦂'
- '🐢'
- '🐍'
- '🦎'
- '🦖'
- '🦕'
- '🐙'
- '🦑'
- '🦐'
- '🦞'
- '🦀'
- '🪸'
- '🐡'
- '🐠'
- '🐟'
- '🐬'
- '🐳'
- '🐋'
- '🦈'
- '🐊'
- '🐅'
- '🐆'
- '🦓'
- '🦍'
- '🦧'
- '🦣'
- '🐘'
- '🦛'
- '🦏'
- '🐪'
- '🐫'
- '🦒'
- '🦘'
- '🦬'
- '🐃'
- '🐂'
- '🐄'
- '🐎'
- '🐖'
- '🐏'
- '🐑'
- '🦙'
- '🐐'
- '🦌'
- '🐕'
- '🐩'
- '🦮'
- '🐕🦺'
- '🐈'
- '🐈⬛'
- '🪶'
- '🐓'
- '🦃'
- '🦤'
- '🦚'
- '🦜'
- '🦢'
- '🦩'
- '🕊'
- '🐇'
- '🦝'
- '🦨'
- '🦡'
- '🦫'
- '🦦'
- '🦥'
- '🐁'
- '🐀'
- '🐿'
- '🦔'
- '🐾'
- '🐉'
- '🐲'
- '🌵'
- '🎄'
- '🌲'
- '🌳'
- '🌴'
- '🪹'
- '🪺'
- '🪵'
- '🌱'
- '🌿'
- '☘️'
- '🍀'
- '🎍'
- '🪴'
- '🎋'
- '🍃'
- '🍂'
- '🍁'
- '🍄'
- '🐚'
- '🪨'
- '🌾'
- '💐'
- '🌷'
- '🪷'
- '🌹'
- '🥀'
- '🌺'
- '🌸'
- '🌼'
- '🌻'
- '🌞'
- '🌝'
- '🌛'
- '🌜'
- '🌚'
- '🌕'
- '🌖'
- '🌗'
- '🌘'
- '🌑'
- '🌒'
- '🌓'
- '🌔'
- '🌙'
- '🌎'
- '🌍'
- '🌏'
- '🪐'
- '💫'
- '⭐️'
- '🌟'
- '✨'
- '⚡️'
- '☄️'
- '💥'
- '🔥'
- '🌪'
- '🌈'
- '☀️'
- '🌤'
- '⛅️'
- '🌥'
- '☁️'
- '🌦'
- '🌧'
- '⛈'
- '🌩'
- '🌨'
- '❄️'
- '☃️'
- '⛄️'
- '🌬'
- '💨'
- '💧'
- '💦'
- '🫧'
- '☔️'
- '☂️'
- '🌊'
- '🌫🍏'
- '🍎'
- '🍐'
- '🍊'
- '🍋'
- '🍌'
- '🍉'
- '🍇'
- '🍓'
- '🫐'
- '🍈'
- '🍒'
- '🍑'
- '🥭'
- '🍍'
- '🥥'
- '🥝'
- '🍅'
- '🍆'
- '🥑'
- '🥦'
- '🥬'
- '🥒'
- '🌶'
- '🫑'
- '🌽'
- '🥕'
- '🫒'
- '🧄'
- '🧅'
- '🥔'
- '🍠'
- '🫘'
- '🥐'
- '🥯'
- '🍞'
- '🥖'
- '🥨'
- '🧀'
- '🥚'
- '🍳'
- '🧈'
- '🥞'
- '🧇'
- '🥓'
- '🥩'
- '🍗'
- '🍖'
- '🦴'
- '🌭'
- '🍔'
- '🍟'
- '🍕'
- '🫓'
- '🥪'
- '🥙'
- '🧆'
- '🌮'
- '🌯'
- '🫔'
- '🥗'
- '🥘'
- '🫕'
- '🥫'
- '🍝'
- '🍜'
- '🍲'
- '🍛'
- '🍣'
- '🍱'
- '🥟'
- '🦪'
- '🍤'
- '🍙'
- '🍚'
- '🍘'
- '🍥'
- '🥠'
- '🥮'
- '🍢'
- '🍡'
- '🍧'
- '🍨'
- '🍦'
- '🥧'
- '🧁'
- '🍰'
- '🎂'
- '🍮'
- '🍭'
- '🍬'
- '🍫'
- '🍿'
- '🍩'
- '🍪'
- '🌰'
- '🥜'
- '🍯'
- '🥛'
- '🍼'
- '🫖'
- '☕️'
- '🍵'
- '🧃'
- '🥤'
- '🧋'
- '🫙'
- '🍶'
- '🍺'
- '🍻'
- '🥂'
- '🍷'
- '🫗'
- '🥃'
- '🍸'
- '🍹'
- '🧉'
- '🍾'
- '🧊'
- '🥄'
- '🍴'
- '🍽'
- '🥣'
- '🥡'
- '🥢'
- '🧂'
- '⚽️'
- '🏀'
- '🏈'
- '⚾️'
- '🥎'
- '🎾'
- '🏐'
- '🏉'
- '🥏'
- '🎱'
- '🪀'
- '🏓'
- '🏸'
- '🏒'
- '🏑'
- '🥍'
- '🏏'
- '🪃'
- '🥅'
- '⛳️'
- '🪁'
- '🏹'
- '🎣'
- '🤿'
- '🥊'
- '🥋'
- '🎽'
- '🛹'
- '🛼'
- '🛷'
- '⛸'
- '🥌'
- '🎿'
- '⛷'
- '🏂'
- '🪂'
- '🏋️♀️'
- '🏋️'
- '🏋️♂️'
- '🤼♀️'
- '🤼'
- '🤼♂️'
- '🤸♀️'
- '🤸'
- '🤸♂️'
- '⛹️♀️'
- '⛹️'
- '⛹️♂️'
- '🤺'
- '🤾♀️'
- '🤾'
- '🤾♂️'
- '🏌️♀️'
- '🏌️'
- '🏌️♂️'
- '🏇'
- '🧘♀️'
- '🧘'
- '🧘♂️'
- '🏄♀️'
- '🏄'
- '🏄♂️'
- '🏊♀️'
- '🏊'
- '🏊♂️'
- '🤽♀️'
- '🤽'
- '🤽♂️'
- '🚣♀️'
- '🚣'
- '🚣♂️'
- '🧗♀️'
- '🧗'
- '🧗♂️'
- '🚵♀️'
- '🚵'
- '🚵♂️'
- '🚴♀️'
- '🚴'
- '🚴♂️'
- '🏆'
- '🥇'
- '🥈'
- '🥉'
- '🏅'
- '🎖'
- '🏵'
- '🎗'
- '🎫'
- '🎟'
- '🎪'
- '🤹'
- '🤹♂️'
- '🤹♀️'
- '🎭'
- '🩰'
- '🎨'
- '🎬'
- '🎤'
- '🎧'
- '🎼'
- '🎹'
- '🥁'
- '🪘'
- '🎷'
- '🎺'
- '🪗'
- '🎸'
- '🪕'
- '🎻'
- '🎲'
- '♟'
- '🎯'
- '🎳'
- '🎮'
- '🎰'
- '🧩'
- '🚗'
- '🚕'
- '🚙'
- '🚌'
- '🚎'
- '🏎'
- '🚓'
- '🚑'
- '🚒'
- '🚐'
- '🛻'
- '🚚'
- '🚛'
- '🚜'
- '🦯'
- '🦽'
- '🦼'
- '🛴'
- '🚲'
- '🛵'
- '🏍'
- '🛺'
- '🚨'
- '🚔'
- '🚍'
- '🚘'
- '🚖'
- '🛞'
- '🚡'
- '🚠'
- '🚟'
- '🚃'
- '🚋'
- '🚞'
- '🚝'
- '🚄'
- '🚅'
- '🚈'
- '🚂'
- '🚆'
- '🚇'
- '🚊'
- '🚉'
- '✈️'
- '🛫'
- '🛬'
- '🛩'
- '💺'
- '🛰'
- '🚀'
- '🛸'
- '🚁'
- '🛶'
- '⛵️'
- '🚤'
- '🛥'
- '🛳'
- '⛴'
- '🚢'
- '⚓️'
- '🛟'
- '🪝'
- '⛽️'
- '🚧'
- '🚦'
- '🚥'
- '🚏'
- '🗺'
- '🗿'
- '🗽'
- '🗼'
- '🏰'
- '🏯'
- '🏟'
- '🎡'
- '🎢'
- '🛝'
- '🎠'
- '⛲️'
- '⛱'
- '🏖'
- '🏝'
- '🏜'
- '🌋'
- '⛰'
- '🏔'
- '🗻'
- '🏕'
- '⛺️'
- '🛖'
- '🏠'
- '🏡'
- '🏘'
- '🏚'
- '🏗'
- '🏭'
- '🏢'
- '🏬'
- '🏣'
- '🏤'
- '🏥'
- '🏦'
- '🏨'
- '🏪'
- '🏫'
- '🏩'
- '💒'
- '🏛'
- '⛪️'
- '🕌'
- '🕍'
- '🛕'
- '🕋'
- '⛩'
- '🛤'
- '🛣'
- '🗾'
- '🎑'
- '🏞'
- '🌅'
- '🌄'
- '🌠'
- '🎇'
- '🎆'
- '🌇'
- '🌆'
- '🏙'
- '🌃'
- '🌌'
- '🌉'
- '🌁'
- '⌚️'
- '📱'
- '📲'
- '💻'
- '⌨️'
- '🖥'
- '🖨'
- '🖱'
- '🖲'
- '🕹'
- '🗜'
- '💽'
- '💾'
- '💿'
- '📀'
- '📼'
- '📷'
- '📸'
- '📹'
- '🎥'
- '📽'
- '🎞'
- '📞'
- '☎️'
- '📟'
- '📠'
- '📺'
- '📻'
- '🎙'
- '🎚'
- '🎛'
- '🧭'
- '⏱'
- '⏲'
- '⏰'
- '🕰'
- '⌛️'
- '⏳'
- '📡'
- '🔋'
- '🪫'
- '🔌'
- '💡'
- '🔦'
- '🕯'
- '🪔'
- '🧯'
- '🛢'
- '💸'
- '💵'
- '💴'
- '💶'
- '💷'
- '🪙'
- '💰'
- '💳'
- '💎'
- '⚖️'
- '🪜'
- '🧰'
- '🪛'
- '🔧'
- '🔨'
- '⚒'
- '🛠'
- '⛏'
- '🪚'
- '🔩'
- '⚙️'
- '🪤'
- '🧱'
- '⛓'
- '🧲'
- '🔫'
- '💣'
- '🧨'
- '🪓'
- '🔪'
- '🗡'
- '⚔️'
- '🛡'
- '🚬'
- '⚰️'
- '🪦'
- '⚱️'
- '🏺'
- '🔮'
- '📿'
- '🧿'
- '🪬'
- '💈'
- '⚗️'
- '🔭'
- '🔬'
- '🕳'
- '🩹'
- '🩺'
- '🩻'
- '🩼'
- '💊'
- '💉'
- '🩸'
- '🧬'
- '🦠'
- '🧫'
- '🧪'
- '🌡'
- '🧹'
- '🪠'
- '🧺'
- '🧻'
- '🚽'
- '🚰'
- '🚿'
- '🛁'
- '🛀'
- '🧼'
- '🪥'
- '🪒'
- '🧽'
- '🪣'
- '🧴'
- '🛎'
- '🔑'
- '🗝'
- '🚪'
- '🪑'
- '🛋'
- '🛏'
- '🛌'
- '🧸'
- '🪆'
- '🖼'
- '🪞'
- '🪟'
- '🛍'
- '🛒'
- '🎁'
- '🎈'
- '🎏'
- '🎀'
- '🪄'
- '🪅'
- '🎊'
- '🎉'
- '🪩'
- '🎎'
- '🏮'
- '🎐'
- '🧧'
- '✉️'
- '📩'
- '📨'
- '📧'
- '💌'
- '📥'
- '📤'
- '📦'
- '🏷'
- '🪧'
- '📪'
- '📫'
- '📬'
- '📭'
- '📮'
- '📯'
- '📜'
- '📃'
- '📄'
- '📑'
- '🧾'
- '📊'
- '📈'
- '📉'
- '🗒'
- '🗓'
- '📆'
- '📅'
- '🗑'
- '🪪'
- '📇'
- '🗃'
- '🗳'
- '🗄'
- '📋'
- '📁'
- '📂'
- '🗂'
- '🗞'
- '📰'
- '📓'
- '📔'
- '📒'
- '📕'
- '📗'
- '📘'
- '📙'
- '📚'
- '📖'
- '🔖'
- '🧷'
- '🔗'
- '📎'
- '🖇'
- '📐'
- '📏'
- '🧮'
- '📌'
- '📍'
- '✂️'
- '🖊'
- '🖋'
- '✒️'
- '🖌'
- '🖍'
- '📝'
- '✏️'
- '🔍'
- '🔎'
- '🔏'
- '🔐'
- '🔒'
- '🔓❤️'
- '🧡'
- '💛'
- '💚'
- '💙'
- '💜'
- '🖤'
- '🤍'
- '🤎'
- '❤️🔥'
- '❤️🩹'
- '💔'
- '❣️'
- '💕'
- '💞'
- '💓'
- '💗'
- '💖'
- '💘'
- '💝'
- '💟'
- '☮️'
- '✝️'
- '☪️'
- '🕉'
- '☸️'
- '✡️'
- '🔯'
- '🕎'
- '☯️'
- '☦️'
- '🛐'
- '⛎'
- '♈️'
- '♉️'
- '♊️'
- '♋️'
- '♌️'
- '♍️'
- '♎️'
- '♏️'
- '♐️'
- '♑️'
- '♒️'
- '♓️'
- '🆔'
- '⚛️'
- '🉑'
- '☢️'
- '☣️'
- '📴'
- '📳'
- '🈶'
- '🈚️'
- '🈸'
- '🈺'
- '🈷️'
- '✴️'
- '🆚'
- '💮'
- '🉐'
- '㊙️'
- '㊗️'
- '🈴'
- '🈵'
- '🈹'
- '🈲'
- '🅰️'
- '🅱️'
- '🆎'
- '🆑'
- '🅾️'
- '🆘'
- '❌'
- '⭕️'
- '🛑'
- '⛔️'
- '📛'
- '🚫'
- '💯'
- '💢'
- '♨️'
- '🚷'
- '🚯'
- '🚳'
- '🚱'
- '🔞'
- '📵'
- '🚭'
- '❗️'
- '❕'
- '❓'
- '❔'
- '‼️'
- '⁉️'
- '🔅'
- '🔆'
- '〽️'
- '⚠️'
- '🚸'
- '🔱'
- '⚜️'
- '🔰'
- '♻️'
- '✅'
- '🈯️'
- '💹'
- '❇️'
- '✳️'
- '❎'
- '🌐'
- '💠'
- 'Ⓜ️'
- '🌀'
- '💤'
- '🏧'
- '🚾'
- '♿️'
- '🅿️'
- '🛗'
- '🈳'
- '🈂️'
- '🛂'
- '🛃'
- '🛄'
- '🛅'
- '🚹'
- '🚺'
- '🚼'
- '⚧'
- '🚻'
- '🚮'
- '🎦'
- '📶'
- '🈁'
- '🔣'
- 'ℹ️'
- '🔤'
- '🔡'
- '🔠'
- '🆖'
- '🆗'
- '🆙'
- '🆒'
- '🆕'
- '🆓'
- '0️⃣'
- '1️⃣'
- '2️⃣'
- '3️⃣'
- '4️⃣'
- '5️⃣'
- '6️⃣'
- '7️⃣'
- '8️⃣'
- '9️⃣'
- '🔟'
- '🔢'
- '#️⃣'
- '*️⃣'
- '⏏️'
- '▶️'
- '⏸'
- '⏯'
- '⏹'
- '⏺'
- '⏭'
- '⏮'
- '⏩'
- '⏪'
- '⏫'
- '⏬'
- '◀️'
- '🔼'
- '🔽'
- '➡️'
- '⬅️'
- '⬆️'
- '⬇️'
- '↗️'
- '↘️'
- '↙️'
- '↖️'
- '↕️'
- '↔️'
- '↪️'
- '↩️'
- '⤴️'
- '⤵️'
- '🔀'
- '🔁'
- '🔂'
- '🔄'
- '🔃'
- '🎵'
- '🎶'
- '➕'
- '➖'
- '➗'
- '✖️'
- '🟰'
- '♾'
- '💲'
- '💱'
- '™️'
- '©️'
- '®️'
- '〰️'
- '➰'
- '➿'
- '🔚'
- '🔙'
- '🔛'
- '🔝'
- '🔜'
- '✔️'
- '☑️'
- '🔘'
- '🔴'
- '🟠'
- '🟡'
- '🟢'
- '🔵'
- '🟣'
- '⚫️'
- '⚪️'
- '🟤'
- '🔺'
- '🔻'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
view Sigma YAML
title: Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
id: 225274c4-8dd1-40db-9e09-71dff4f6fb3c
status: test
description: Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
author: '@Kostastsale, TheDFIRReport'
references:
- Internal Research
tags:
- attack.stealth
date: 2022-12-05
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '🔸'
- '🔹'
- '🔶'
- '🔷'
- '🔳'
- '🔲'
- '▪️'
- '▫️'
- '◾️'
- '◽️'
- '◼️'
- '◻️'
- '🟥'
- '🟧'
- '🟨'
- '🟩'
- '🟦'
- '🟪'
- '⬛️'
- '⬜️'
- '🟫'
- '🔈'
- '🔇'
- '🔉'
- '🔊'
- '🔔'
- '🔕'
- '📣'
- '📢'
- '👁🗨'
- '💬'
- '💭'
- '🗯'
- '♠️'
- '♣️'
- '♥️'
- '♦️'
- '🃏'
- '🎴'
- '🀄️'
- '🕐'
- '🕑'
- '🕒'
- '🕓'
- '🕔'
- '🕕'
- '🕖'
- '🕗'
- '🕘'
- '🕙'
- '🕚'
- '🕛'
- '🕜'
- '🕝'
- '🕞'
- '🕟'
- '🕠'
- '🕡'
- '🕢'
- '🕣'
- '🕤'
- '🕥'
- '🕦'
- '🕧✢'
- '✣'
- '✤'
- '✥'
- '✦'
- '✧'
- '★'
- '☆'
- '✯'
- '✡︎'
- '✩'
- '✪'
- '✫'
- '✬'
- '✭'
- '✮'
- '✶'
- '✷'
- '✵'
- '✸'
- '✹'
- '→'
- '⇒'
- '⟹'
- '⇨'
- '⇾'
- '➾'
- '⇢'
- '☛'
- '☞'
- '➔'
- '➜'
- '➙'
- '➛'
- '➝'
- '➞'
- '♠︎'
- '♣︎'
- '♥︎'
- '♦︎'
- '♤'
- '♧'
- '♡'
- '♢'
- '♚'
- '♛'
- '♜'
- '♝'
- '♞'
- '♟'
- '♔'
- '♕'
- '♖'
- '♗'
- '♘'
- '♙'
- '⚀'
- '⚁'
- '⚂'
- '⚃'
- '⚄'
- '⚅'
- '🂠'
- '⚈'
- '⚉'
- '⚆'
- '⚇'
- '𓀀'
- '𓀁'
- '𓀂'
- '𓀃'
- '𓀄'
- '𓀅'
- '𓀆'
- '𓀇'
- '𓀈'
- '𓀉'
- '𓀊'
- '𓀋'
- '𓀌'
- '𓀍'
- '𓀎'
- '𓀏'
- '𓀐'
- '𓀑'
- '𓀒'
- '𓀓'
- '𓀔'
- '𓀕'
- '𓀖'
- '𓀗'
- '𓀘'
- '𓀙'
- '𓀚'
- '𓀛'
- '𓀜'
- '𓀝🏳️'
- '🏴'
- '🏁'
- '🚩'
- '🏳️🌈'
- '🏳️⚧️'
- '🏴☠️'
- '🇦🇫'
- '🇦🇽'
- '🇦🇱'
- '🇩🇿'
- '🇦🇸'
- '🇦🇩'
- '🇦🇴'
- '🇦🇮'
- '🇦🇶'
- '🇦🇬'
- '🇦🇷'
- '🇦🇲'
- '🇦🇼'
- '🇦🇺'
- '🇦🇹'
- '🇦🇿'
- '🇧🇸'
- '🇧🇭'
- '🇧🇩'
- '🇧🇧'
- '🇧🇾'
- '🇧🇪'
- '🇧🇿'
- '🇧🇯'
- '🇧🇲'
- '🇧🇹'
- '🇧🇴'
- '🇧🇦'
- '🇧🇼'
- '🇧🇷'
- '🇮🇴'
- '🇻🇬'
- '🇧🇳'
- '🇧🇬'
- '🇧🇫'
- '🇧🇮'
- '🇰🇭'
- '🇨🇲'
- '🇨🇦'
- '🇮🇨'
- '🇨🇻'
- '🇧🇶'
- '🇰🇾'
- '🇨🇫'
- '🇹🇩'
- '🇨🇱'
- '🇨🇳'
- '🇨🇽'
- '🇨🇨'
- '🇨🇴'
- '🇰🇲'
- '🇨🇬'
- '🇨🇩'
- '🇨🇰'
- '🇨🇷'
- '🇨🇮'
- '🇭🇷'
- '🇨🇺'
- '🇨🇼'
- '🇨🇾'
- '🇨🇿'
- '🇩🇰'
- '🇩🇯'
- '🇩🇲'
- '🇩🇴'
- '🇪🇨'
- '🇪🇬'
- '🇸🇻'
- '🇬🇶'
- '🇪🇷'
- '🇪🇪'
- '🇪🇹'
- '🇪🇺'
- '🇫🇰'
- '🇫🇴'
- '🇫🇯'
- '🇫🇮'
- '🇫🇷'
- '🇬🇫'
- '🇵🇫'
- '🇹🇫'
- '🇬🇦'
- '🇬🇲'
- '🇬🇪'
- '🇩🇪'
- '🇬🇭'
- '🇬🇮'
- '🇬🇷'
- '🇬🇱'
- '🇬🇩'
- '🇬🇵'
- '🇬🇺'
- '🇬🇹'
- '🇬🇬'
- '🇬🇳'
- '🇬🇼'
- '🇬🇾'
- '🇭🇹'
- '🇭🇳'
- '🇭🇰'
- '🇭🇺'
- '🇮🇸'
- '🇮🇳'
- '🇮🇩'
- '🇮🇷'
- '🇮🇶'
- '🇮🇪'
- '🇮🇲'
- '🇮🇱'
- '🇮🇹'
- '🇯🇲'
- '🇯🇵'
- '🎌'
- '🇯🇪'
- '🇯🇴'
- '🇰🇿'
- '🇰🇪'
- '🇰🇮'
- '🇽🇰'
- '🇰🇼'
- '🇰🇬'
- '🇱🇦'
- '🇱🇻'
- '🇱🇧'
- '🇱🇸'
- '🇱🇷'
- '🇱🇾'
- '🇱🇮'
- '🇱🇹'
- '🇱🇺'
- '🇲🇴'
- '🇲🇰'
- '🇲🇬'
- '🇲🇼'
- '🇲🇾'
- '🇲🇻'
- '🇲🇱'
- '🇲🇹'
- '🇲🇭'
- '🇲🇶'
- '🇲🇷'
- '🇲🇺'
- '🇾🇹'
- '🇲🇽'
- '🇫🇲'
- '🇲🇩'
- '🇲🇨'
- '🇲🇳'
- '🇲🇪'
- '🇲🇸'
- '🇲🇦'
- '🇲🇿'
- '🇲🇲'
- '🇳🇦'
- '🇳🇷'
- '🇳🇵'
- '🇳🇱'
- '🇳🇨'
- '🇳🇿'
- '🇳🇮'
- '🇳🇪'
- '🇳🇬'
- '🇳🇺'
- '🇳🇫'
- '🇰🇵'
- '🇲🇵'
- '🇳🇴'
- '🇴🇲'
- '🇵🇰'
- '🇵🇼'
- '🇵🇸'
- '🇵🇦'
- '🇵🇬'
- '🇵🇾'
- '🇵🇪'
- '🇵🇭'
- '🇵🇳'
- '🇵🇱'
- '🇵🇹'
- '🇵🇷'
- '🇶🇦'
- '🇷🇪'
- '🇷🇴'
- '🇷🇺'
- '🇷🇼'
- '🇼🇸'
- '🇸🇲'
- '🇸🇦'
- '🇸🇳'
- '🇷🇸'
- '🇸🇨'
- '🇸🇱'
- '🇸🇬'
- '🇸🇽'
- '🇸🇰'
- '🇸🇮'
- '🇬🇸'
- '🇸🇧'
- '🇸🇴'
- '🇿🇦'
- '🇰🇷'
- '🇸🇸'
- '🇪🇸'
- '🇱🇰'
- '🇧🇱'
- '🇸🇭'
- '🇰🇳'
- '🇱🇨'
- '🇵🇲'
- '🇻🇨'
- '🇸🇩'
- '🇸🇷'
- '🇸🇿'
- '🇸🇪'
- '🇨🇭'
- '🇸🇾'
- '🇹🇼'
- '🇹🇯'
- '🇹🇿'
- '🇹🇭'
- '🇹🇱'
- '🇹🇬'
- '🇹🇰'
- '🇹🇴'
- '🇹🇹'
- '🇹🇳'
- '🇹🇷'
- '🇹🇲'
- '🇹🇨'
- '🇹🇻'
- '🇻🇮'
- '🇺🇬'
- '🇺🇦'
- '🇦🇪'
- '🇬🇧'
- '🏴'
- '🏴'
- '🏴'
- '🇺🇳'
- '🇺🇸'
- '🇺🇾'
- '🇺🇿'
- '🇻🇺'
- '🇻🇦'
- '🇻🇪'
- '🇻🇳'
- '🇼🇫'
- '🇪🇭'
- '🇾🇪'
- '🇿🇲'
- '🇿🇼🫠'
- '🫢'
- '🫣'
- '🫡'
- '🫥'
- '🫤'
- '🥹'
- '🫱'
- '🫱🏻'
- '🫱🏼'
- '🫱🏽'
- '🫱🏾'
- '🫱🏿'
- '🫲'
- '🫲🏻'
- '🫲🏼'
- '🫲🏽'
- '🫲🏾'
- '🫲🏿'
- '🫳'
- '🫳🏻'
- '🫳🏼'
- '🫳🏽'
- '🫳🏾'
- '🫳🏿'
- '🫴'
- '🫴🏻'
- '🫴🏼'
- '🫴🏽'
- '🫴🏾'
- '🫴🏿'
- '🫰'
- '🫰🏻'
- '🫰🏼'
- '🫰🏽'
- '🫰🏾'
- '🫰🏿'
- '🫵'
- '🫵🏻'
- '🫵🏼'
- '🫵🏽'
- '🫵🏾'
- '🫵🏿'
- '🫶'
- '🫶🏻'
- '🫶🏼'
- '🫶🏽'
- '🫶🏾'
- '🫶🏿'
- '🤝🏻'
- '🤝🏼'
- '🤝🏽'
- '🤝🏾'
- '🤝🏿'
- '🫱🏻🫲🏼'
- '🫱🏻🫲🏽'
- '🫱🏻🫲🏾'
- '🫱🏻🫲🏿'
- '🫱🏼🫲🏻'
- '🫱🏼🫲🏽'
- '🫱🏼🫲🏾'
- '🫱🏼🫲🏿'
- '🫱🏽🫲🏻'
- '🫱🏽🫲🏼'
- '🫱🏽🫲🏾'
- '🫱🏽🫲🏿'
- '🫱🏾🫲🏻'
- '🫱🏾🫲🏼'
- '🫱🏾🫲🏽'
- '🫱🏾🫲🏿'
- '🫱🏿🫲🏻'
- '🫱🏿🫲🏼'
- '🫱🏿🫲🏽'
- '🫱🏿🫲🏾'
- '🫦'
- '🫅'
- '🫅🏻'
- '🫅🏼'
- '🫅🏽'
- '🫅🏾'
- '🫅🏿'
- '🫃'
- '🫃🏻'
- '🫃🏼'
- '🫃🏽'
- '🫃🏾'
- '🫃🏿'
- '🫄'
- '🫄🏻'
- '🫄🏼'
- '🫄🏽'
- '🫄🏾'
- '🫄🏿'
- '🧌'
- '🪸'
- '🪷'
- '🪹'
- '🪺'
- '🫘'
- '🫗'
- '🫙'
- '🛝'
- '🛞'
- '🛟'
- '🪬'
- '🪩'
- '🪫'
- '🩼'
- '🩻'
- '🫧'
- '🪪'
- '🟰'
- '😮💨'
- '😵💫'
- '😶🌫️'
- '❤️🔥'
- '❤️🩹'
- '🧔♀️'
- '🧔🏻♀️'
- '🧔🏼♀️'
- '🧔🏽♀️'
- '🧔🏾♀️'
- '🧔🏿♀️'
- '🧔♂️'
- '🧔🏻♂️'
- '🧔🏼♂️'
- '🧔🏽♂️'
- '🧔🏾♂️'
- '🧔🏿♂️'
- '💑🏻'
- '💑🏼'
- '💑🏽'
- '💑🏾'
- '💑🏿'
- '💏🏻'
- '💏🏼'
- '💏🏽'
- '💏🏾'
- '💏🏿'
- '👨🏻❤️👨🏻'
- '👨🏻❤️👨🏼'
- '👨🏻❤️👨🏽'
- '👨🏻❤️👨🏾'
- '👨🏻❤️👨🏿'
- '👨🏼❤️👨🏻'
- '👨🏼❤️👨🏼'
- '👨🏼❤️👨🏽'
- '👨🏼❤️👨🏾'
- '👨🏼❤️👨🏿'
- '👨🏽❤️👨🏻'
- '👨🏽❤️👨🏼'
- '👨🏽❤️👨🏽'
- '👨🏽❤️👨🏾'
- '👨🏽❤️👨🏿'
- '👨🏾❤️👨🏻'
- '👨🏾❤️👨🏼'
- '👨🏾❤️👨🏽'
- '👨🏾❤️👨🏾'
- '👨🏾❤️👨🏿'
- '👨🏿❤️👨🏻'
- '👨🏿❤️👨🏼'
- '👨🏿❤️👨🏽'
- '👨🏿❤️👨🏾'
- '👨🏿❤️👨🏿'
- '👩🏻❤️👨🏻'
- '👩🏻❤️👨🏼'
- '👩🏻❤️👨🏽'
- '👩🏻❤️👨🏾'
- '👩🏻❤️👨🏿'
- '👩🏻❤️👩🏻'
- '👩🏻❤️👩🏼'
- '👩🏻❤️👩🏽'
- '👩🏻❤️👩🏾'
- '👩🏻❤️👩🏿'
- '👩🏼❤️👨🏻'
- '👩🏼❤️👨🏼'
- '👩🏼❤️👨🏽'
- '👩🏼❤️👨🏾'
- '👩🏼❤️👨🏿'
- '👩🏼❤️👩🏻'
- '👩🏼❤️👩🏼'
- '👩🏼❤️👩🏽'
- '👩🏼❤️👩🏾'
- '👩🏼❤️👩🏿'
- '👩🏽❤️👨🏻'
- '👩🏽❤️👨🏼'
- '👩🏽❤️👨🏽'
- '👩🏽❤️👨🏾'
- '👩🏽❤️👨🏿'
- '👩🏽❤️👩🏻'
- '👩🏽❤️👩🏼'
- '👩🏽❤️👩🏽'
- '👩🏽❤️👩🏾'
- '👩🏽❤️👩🏿'
- '👩🏾❤️👨🏻'
- '👩🏾❤️👨🏼'
- '👩🏾❤️👨🏽'
- '👩🏾❤️👨🏾'
- '👩🏾❤️👨🏿'
- '👩🏾❤️👩🏻'
- '👩🏾❤️👩🏼'
- '👩🏾❤️👩🏽'
- '👩🏾❤️👩🏾'
- '👩🏾❤️👩🏿'
- '👩🏿❤️👨🏻'
- '👩🏿❤️👨🏼'
- '👩🏿❤️👨🏽'
- '👩🏿❤️👨🏾'
- '👩🏿❤️👨🏿'
- '👩🏿❤️👩🏻'
- '👩🏿❤️👩🏼'
- '👩🏿❤️👩🏽'
- '👩🏿❤️👩🏾'
- '👩🏿❤️👩🏿'
- '🧑🏻❤️🧑🏼'
- '🧑🏻❤️🧑🏽'
- '🧑🏻❤️🧑🏾'
- '🧑🏻❤️🧑🏿'
- '🧑🏼❤️🧑🏻'
- '🧑🏼❤️🧑🏽'
- '🧑🏼❤️🧑🏾'
- '🧑🏼❤️🧑🏿'
- '🧑🏽❤️🧑🏻'
- '🧑🏽❤️🧑🏼'
- '🧑🏽❤️🧑🏾'
- '🧑🏽❤️🧑🏿'
- '🧑🏾❤️🧑🏻'
- '🧑🏾❤️🧑🏼'
- '🧑🏾❤️🧑🏽'
- '🧑🏾❤️🧑🏿'
- '🧑🏿❤️🧑🏻'
- '🧑🏿❤️🧑🏼'
- '🧑🏿❤️🧑🏽'
- '🧑🏿❤️🧑🏾'
- '👨🏻❤️💋👨🏻'
- '👨🏻❤️💋👨🏼'
- '👨🏻❤️💋👨🏽'
- '👨🏻❤️💋👨🏾'
- '👨🏻❤️💋👨🏿'
- '👨🏼❤️💋👨🏻'
- '👨🏼❤️💋👨🏼'
- '👨🏼❤️💋👨🏽'
- '👨🏼❤️💋👨🏾'
- '👨🏼❤️💋👨🏿'
- '👨🏽❤️💋👨🏻'
- '👨🏽❤️💋👨🏼'
- '👨🏽❤️💋👨🏽'
- '👨🏽❤️💋👨🏾'
- '👨🏽❤️💋👨🏿'
- '👨🏾❤️💋👨🏻'
- '👨🏾❤️💋👨🏼'
- '👨🏾❤️💋👨🏽'
- '👨🏾❤️💋👨🏾'
- '👨🏾❤️💋👨🏿'
- '👨🏿❤️💋👨🏻'
- '👨🏿❤️💋👨🏼'
- '👨🏿❤️💋👨🏽'
- '👨🏿❤️💋👨🏾'
- '👨🏿❤️💋👨🏿'
- '👩🏻❤️💋👨🏻'
- '👩🏻❤️💋👨🏼'
- '👩🏻❤️💋👨🏽'
- '👩🏻❤️💋👨🏾'
- '👩🏻❤️💋👨🏿'
- '👩🏻❤️💋👩🏻'
- '👩🏻❤️💋👩🏼'
- '👩🏻❤️💋👩🏽'
- '👩🏻❤️💋👩🏾'
- '👩🏻❤️💋👩🏿'
- '👩🏼❤️💋👨🏻'
- '👩🏼❤️💋👨🏼'
- '👩🏼❤️💋👨🏽'
- '👩🏼❤️💋👨🏾'
- '👩🏼❤️💋👨🏿'
- '👩🏼❤️💋👩🏻'
- '👩🏼❤️💋👩🏼'
- '👩🏼❤️💋👩🏽'
- '👩🏼❤️💋👩🏾'
- '👩🏼❤️💋👩🏿'
- '👩🏽❤️💋👨🏻'
- '👩🏽❤️💋👨🏼'
- '👩🏽❤️💋👨🏽'
- '👩🏽❤️💋👨🏾'
- '👩🏽❤️💋👨🏿'
- '👩🏽❤️💋👩🏻'
- '👩🏽❤️💋👩🏼'
- '👩🏽❤️💋👩🏽'
- '👩🏽❤️💋👩🏾'
- '👩🏽❤️💋👩🏿'
- '👩🏾❤️💋👨🏻'
- '👩🏾❤️💋👨🏼'
- '👩🏾❤️💋👨🏽'
- '👩🏾❤️💋👨🏾'
- '👩🏾❤️💋👨🏿'
- '👩🏾❤️💋👩🏻'
- '👩🏾❤️💋👩🏼'
- '👩🏾❤️💋👩🏽'
- '👩🏾❤️💋👩🏾'
- '👩🏾❤️💋👩🏿'
- '👩🏿❤️💋👨🏻'
- '👩🏿❤️💋👨🏼'
- '👩🏿❤️💋👨🏽'
- '👩🏿❤️💋👨🏾'
- '👩🏿❤️💋👨🏿'
- '👩🏿❤️💋👩🏻'
- '👩🏿❤️💋👩🏼'
- '👩🏿❤️💋👩🏽'
- '👩🏿❤️💋👩🏾'
- '👩🏿❤️💋👩🏿'
- '🧑🏻❤️💋🧑🏼'
- '🧑🏻❤️💋🧑🏽'
- '🧑🏻❤️💋🧑🏾'
- '🧑🏻❤️💋🧑🏿'
- '🧑🏼❤️💋🧑🏻'
- '🧑🏼❤️💋🧑🏽'
- '🧑🏼❤️💋🧑🏾'
- '🧑🏼❤️💋🧑🏿'
- '🧑🏽❤️💋🧑🏻'
- '🧑🏽❤️💋🧑🏼'
- '🧑🏽❤️💋🧑🏾'
- '🧑🏽❤️💋🧑🏿'
- '🧑🏾❤️💋🧑🏻'
- '🧑🏾❤️💋🧑🏼'
- '🧑🏾❤️💋🧑🏽'
- '🧑🏾❤️💋🧑🏿'
- '🧑🏿❤️💋🧑🏻'
- '🧑🏿❤️💋🧑🏼'
- '🧑🏿❤️💋🧑🏽'
- '🧑🏿❤️💋🧑🏾'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Defense Evasion Via Rename Of Highly Relevant Binaries
Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
view Sigma YAML
title: Potential Defense Evasion Via Rename Of Highly Relevant Binaries
id: 0ba1da6d-b6ce-4366-828c-18826c9de23e
related:
- id: 36480ae1-a1cb-4eaa-a0d6-29801d7e9142
type: similar
- id: 2569ed8c-1147-498a-9b8c-2ad3656b10ed # Renamed Rundll32 Specific
type: derived
- id: a7a7e0e5-1d57-49df-9c58-9fe5bc0346a2 # Renamed PsExec
type: obsolete
- id: d178a2d7-129a-4ba4-8ee6-d6e1fecd5d20 # Renamed PowerShell
type: obsolete
- id: d4d2574f-ac17-4d9e-b986-aeeae0dc8fe2 # Renamed Rundll32
type: obsolete
status: test
description: Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.
references:
- https://mgreen27.github.io/posts/2019/05/12/BinaryRename.html
- https://mgreen27.github.io/posts/2019/05/29/BinaryRename2.html
- https://www.trendmicro.com/vinfo/hk-en/security/news/cybercrime-and-digital-threats/megacortex-ransomware-spotted-attacking-enterprise-networks
- https://twitter.com/christophetd/status/1164506034720952320
- https://threatresearch.ext.hp.com/svcready-a-new-loader-reveals-itself/
- https://www.huntress.com/blog/malicious-browser-extention-crashfix-kongtuke
author: Matthew Green - @mgreen27, Florian Roth (Nextron Systems), frack113
date: 2019-06-15
modified: 2026-02-12
tags:
- attack.stealth
- attack.t1036.003
- car.2013-05-009
logsource:
category: process_creation
product: windows
detection:
selection:
- Description: 'Execute processes remotely'
- Product: 'Sysinternals PsExec'
- Description|startswith:
- 'Windows PowerShell'
- 'pwsh'
- OriginalFileName:
- 'certutil.exe'
- 'cmstp.exe'
- 'cscript.exe'
- 'IE4UINIT.EXE'
- 'finger.exe'
- 'mshta.exe'
- 'msiexec.exe'
- 'msxsl.exe'
- 'powershell_ise.exe'
- 'powershell.exe'
- 'psexec.c' # old versions of psexec (2016 seen)
- 'psexec.exe'
- 'psexesvc.exe'
- 'pwsh.dll'
- 'reg.exe'
- 'regsvr32.exe'
- 'rundll32.exe'
- 'WerMgr'
- 'wmic.exe'
- 'wscript.exe'
filter:
Image|endswith:
- '\certutil.exe'
- '\cmstp.exe'
- '\cscript.exe'
- '\ie4uinit.exe'
- '\finger.exe'
- '\mshta.exe'
- '\msiexec.exe'
- '\msxsl.exe'
- '\powershell_ise.exe'
- '\powershell.exe'
- '\psexec.exe'
- '\psexec64.exe'
- '\PSEXESVC.exe'
- '\pwsh.exe'
- '\reg.exe'
- '\regsvr32.exe'
- '\rundll32.exe'
- '\wermgr.exe'
- '\wmic.exe'
- '\wscript.exe'
condition: selection and not filter
falsepositives:
- Custom applications use renamed binaries adding slight change to binary name. Typically this is easy to spot and add to whitelist
- PsExec installed via Windows Store doesn't contain original filename field (False negative)
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_renamed_binary_highly_relevant/info.yml
Convert to SIEM query
high
Potential Defense Evasion Via Right-to-Left Override
Detects the presence of the "u202+E" character, which causes a terminal, browser, or operating system to render text in a right-to-left sequence.
This character is used as an obfuscation and masquerading techniques by adversaries to trick users into opening malicious files.
view Sigma YAML
title: Potential Defense Evasion Via Right-to-Left Override
id: ad691d92-15f2-4181-9aa4-723c74f9ddc3
related:
- id: e0552b19-5a83-4222-b141-b36184bb8d79
type: derived
- id: 584bca0f-3608-4402-80fd-4075ff6072e3
type: derived
status: test
description: |
Detects the presence of the "u202+E" character, which causes a terminal, browser, or operating system to render text in a right-to-left sequence.
This character is used as an obfuscation and masquerading techniques by adversaries to trick users into opening malicious files.
references:
- https://redcanary.com/blog/right-to-left-override/
- https://www.malwarebytes.com/blog/news/2014/01/the-rtlo-method
- https://unicode-explorer.com/c/202E
- https://tria.ge/241015-l98snsyeje/behavioral2
- https://unprotect.it/technique/right-to-left-override-rlo-extension-spoofing/
author: Micah Babinski, @micahbabinski, Swachchhanda Shrawan Poudel (Nextron Systems), Luc Génaux
date: 2023-02-15
modified: 2026-03-20
tags:
- attack.stealth
- attack.t1036.002
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- '\u202e' # Unicode RTLO character
- '[U+202E]'
# Real char U+202E copied/pasted below
- ''
condition: selection
falsepositives:
- Commandlines that contains scriptures such as arabic or hebrew might make use of this character
level: high
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_susp_right_to_left_override/info.yml
Convert to SIEM query
high
Potential Devil Bait Malware Reconnaissance
Detects specific process behavior observed with Devil Bait samples
view Sigma YAML
title: Potential Devil Bait Malware Reconnaissance
id: e8954be4-b2b8-4961-be18-da1a5bda709c
related:
- id: 8e0bb260-d4b2-4fff-bb8d-3f82118e6892
type: derived
status: test
description: Detects specific process behavior observed with Devil Bait samples
references:
- https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/devil-bait/NCSC-MAR-Devil-Bait.pdf
- https://www.virustotal.com/gui/file/fa71eee906a7849ba3f4bab74edb577bd1f1f8397ca428591b4a9872ce1f1e9b/behavior
author: Nasreddine Bencherchali (Nextron Systems), NCSC (Idea)
date: 2023-05-15
modified: 2025-10-19
tags:
- attack.stealth
- attack.t1218
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_redirect:
ParentImage|endswith: '\wscript.exe'
Image|endswith: '\cmd.exe'
CommandLine|contains: '>>%APPDATA%\Microsoft\'
CommandLine|endswith:
- '.xml'
- '.txt'
selection_recon_cmd:
- CommandLine|re: 'ipconfig\s+/all'
- CommandLine|contains:
# Taken from a6f9043627f8be2452153b5dbf6278e9b91763c3b5c2aea537a859e0c8c6b504
# If you find samples using other commands please add them
- 'dir'
- 'systeminfo'
- 'tasklist'
condition: all of selection_*
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential Devil Bait Related Indicator
Detects the creation of ".xml" and ".txt" files in folders of the "\AppData\Roaming\Microsoft" directory by uncommon processes. This behavior was seen common across different Devil Bait samples and stages as described by the NCSC
view Sigma YAML
title: Potential Devil Bait Related Indicator
id: 93d5f1b4-36df-45ed-8680-f66f242b8415
status: test
description: Detects the creation of ".xml" and ".txt" files in folders of the "\AppData\Roaming\Microsoft" directory by uncommon processes. This behavior was seen common across different Devil Bait samples and stages as described by the NCSC
references:
- https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/devil-bait/NCSC-MAR-Devil-Bait.pdf
author: Nasreddine Bencherchali (Nextron Systems)
date: 2023-05-15
tags:
- detection.emerging-threats
- attack.stealth
logsource:
product: windows
category: file_event
detection:
selection:
Image|endswith:
- '\schtasks.exe'
- '\wscript.exe'
- '\mshta.exe'
# Example folders used by the samples include:
# - %AppData%\Microsoft\Network\
# - %AppData%\Microsoft\Office\
TargetFilename|contains: '\AppData\Roaming\Microsoft\'
TargetFilename|endswith:
- '.txt'
- '.xml'
condition: selection
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential EACore.DLL Sideloading
Detects potential DLL sideloading of "EACore.dll"
view Sigma YAML
title: Potential EACore.DLL Sideloading
id: edd3ddc3-386f-4ba5-9ada-4376b2cfa7b5
status: test
description: Detects potential DLL sideloading of "EACore.dll"
references:
- https://research.checkpoint.com/2023/beyond-the-horizon-traveling-the-world-on-camaro-dragons-usb-flash-drives/
author: X__Junior (Nextron Systems)
date: 2023-08-03
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded|endswith: '\EACore.dll'
filter_main_legit_path:
Image|contains|all:
- 'C:\Program Files\Electronic Arts\EA Desktop\'
- '\EACoreServer.exe'
ImageLoaded|startswith: 'C:\Program Files\Electronic Arts\EA Desktop\'
condition: selection and not 1 of filter_main_*
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential Edputil.DLL Sideloading
Detects potential DLL sideloading of "edputil.dll"
view Sigma YAML
title: Potential Edputil.DLL Sideloading
id: e4903324-1a10-4ed3-981b-f6fe3be3a2c2
status: test
description: Detects potential DLL sideloading of "edputil.dll"
references:
- https://alternativeto.net/news/2023/5/cybercriminals-use-wordpad-vulnerability-to-spread-qbot-malware/
author: X__Junior (Nextron Systems)
date: 2023-06-09
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded|endswith: '\edputil.dll'
filter_main_generic:
ImageLoaded|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
- 'C\Windows\WinSxS\'
condition: selection and not 1 of filter_main_*
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential Emotet Activity
Detects all Emotet like process executions that are not covered by the more generic rules
view Sigma YAML
title: Potential Emotet Activity
id: d02e8cf5-6099-48cf-9bfc-1eec2d0c7b18
status: stable
description: Detects all Emotet like process executions that are not covered by the more generic rules
references:
- https://app.any.run/tasks/e13ab713-64cf-4b23-ad93-6dceaa5429ac/
- https://app.any.run/tasks/81f3c28c-c686-425d-8a2b-a98198d244e1/
- https://app.any.run/tasks/97f875e8-0e08-4328-815f-055e971ba754/
- https://app.any.run/tasks/84fc9b4a-ea2b-47b1-8aa6-9014402dfb56/
author: Florian Roth (Nextron Systems)
date: 2019-09-30
modified: 2023-02-04
tags:
- attack.execution
- attack.stealth
- attack.t1059.001
- attack.t1027
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains:
- ' -e* PAA'
- 'JABlAG4AdgA6AHUAcwBlAHIAcAByAG8AZgBpAGwAZQ' # $env:userprofile
- 'QAZQBuAHYAOgB1AHMAZQByAHAAcgBvAGYAaQBsAGUA' # $env:userprofile
- 'kAGUAbgB2ADoAdQBzAGUAcgBwAHIAbwBmAGkAbABlA' # $env:userprofile
- 'IgAoACcAKgAnACkAOwAkA' # "('*');$
- 'IAKAAnACoAJwApADsAJA' # "('*');$
- 'iACgAJwAqACcAKQA7ACQA' # "('*');$
- 'JABGAGwAeAByAGgAYwBmAGQ'
- 'PQAkAGUAbgB2ADoAdABlAG0AcAArACgA' # =$env:temp+(
- '0AJABlAG4AdgA6AHQAZQBtAHAAKwAoA' # =$env:temp+(
- '9ACQAZQBuAHYAOgB0AGUAbQBwACsAKA' # =$env:temp+(
filter:
CommandLine|contains:
- 'fAAgAEMAbwBuAHYAZQByAHQAVABvAC0ASgBzAG8AbgAgAC0ARQByAHIAbwByAEEAYwB0AGkAbwBuACAAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQ'
- 'wAIABDAG8AbgB2AGUAcgB0AFQAbwAtAEoAcwBvAG4AIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUA'
- '8ACAAQwBvAG4AdgBlAHIAdABUAG8ALQBKAHMAbwBuACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlA'
condition: selection and not filter
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential EmpireMonkey Activity
Detects potential EmpireMonkey APT activity
view Sigma YAML
title: Potential EmpireMonkey Activity
id: 10152a7b-b566-438f-a33c-390b607d1c8d
status: test
description: Detects potential EmpireMonkey APT activity
references:
- https://securelist.com/fin7-5-the-infamous-cybercrime-rig-fin7-continues-its-activities/90703/
- https://malpedia.caad.fkie.fraunhofer.de/actor/anthropoid_spider
author: Markus Neis, Nasreddine Bencherchali (Nextron Systems)
date: 2019-04-02
modified: 2023-03-09
tags:
- attack.stealth
- attack.t1218.010
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains|all:
- '/e:jscript' # This is a guess since the report doesn't mention the method of execution. This assumes that it is achieved via specifying the execution engine
- '\Local\Temp\Errors.bat'
condition: selection
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential EventLog File Location Tampering
Detects tampering with EventLog service "file" key. In order to change the default location of an Evtx file. This technique is used to tamper with log collection and alerting
view Sigma YAML
title: Potential EventLog File Location Tampering
id: 0cb8d736-995d-4ce7-a31e-1e8d452a1459
status: test
description: Detects tampering with EventLog service "file" key. In order to change the default location of an Evtx file. This technique is used to tamper with log collection and alerting
references:
- https://learn.microsoft.com/en-us/windows/win32/eventlog/eventlog-key
author: D3F7A5105
date: 2023-01-02
modified: 2023-08-17
tags:
- attack.defense-impairment
- attack.t1685.001
logsource:
category: registry_set
product: windows
detection:
selection:
TargetObject|contains: '\SYSTEM\CurrentControlSet\Services\EventLog\'
TargetObject|endswith: '\File'
filter:
Details|contains: '\System32\Winevt\Logs\'
condition: selection and not filter
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp
Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.
view Sigma YAML
title: Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp
id: 551d9c1f-816c-445b-a7a6-7a3864720d60
status: test
description: |
Detects suspicious child processes of Excel which could be an indicator of lateral movement leveraging the "ActivateMicrosoftApp" Excel DCOM object.
references:
- https://posts.specterops.io/lateral-movement-abuse-the-power-of-dcom-excel-application-3c016d0d9922
- https://github.com/grayhatkiller/SharpExShell
- https://learn.microsoft.com/en-us/office/vba/api/excel.xlmsapplication
author: Aaron Stratton
date: 2023-11-13
tags:
- attack.t1021.003
- attack.lateral-movement
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\excel.exe'
selection_child:
- OriginalFileName:
- 'foxprow.exe'
- 'schdplus.exe'
- 'winproj.exe'
- Image|endswith:
- '\foxprow.exe'
- '\schdplus.exe'
- '\winproj.exe'
condition: all of selection_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation Attempt From Office Application
Detects Office applications executing a child process that includes directory traversal patterns. This could be an attempt to exploit CVE-2022-30190 (MSDT RCE) or CVE-2021-40444 (MSHTML RCE)
view Sigma YAML
title: Potential Exploitation Attempt From Office Application
id: 868955d9-697e-45d4-a3da-360cefd7c216
status: test
description: Detects Office applications executing a child process that includes directory traversal patterns. This could be an attempt to exploit CVE-2022-30190 (MSDT RCE) or CVE-2021-40444 (MSHTML RCE)
references:
- https://twitter.com/sbousseaden/status/1531653369546301440
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-40444
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190
author: Christian Burkard (Nextron Systems), @SBousseaden (idea)
date: 2022-06-02
modified: 2023-02-04
tags:
- attack.execution
- cve.2021-40444
- detection.emerging-threats
- attack.stealth
logsource:
product: windows
category: process_creation
detection:
selection:
ParentImage|endswith:
- '\winword.exe'
- '\excel.exe'
- '\powerpnt.exe'
- '\msaccess.exe'
- '\mspub.exe'
- '\eqnedt32.exe'
- '\visio.exe'
CommandLine|contains:
- '../../../..'
- '..\..\..\..'
- '..//..//..//..'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation Attempt Of Undocumented WindowsServer RCE
Detects potential exploitation attempt of undocumented Windows Server Pre Auth Remote Code Execution (RCE)
view Sigma YAML
title: Potential Exploitation Attempt Of Undocumented WindowsServer RCE
id: 6d5b8176-d87d-4402-8af4-53aee9db7b5d
status: test
description: Detects potential exploitation attempt of undocumented Windows Server Pre Auth Remote Code Execution (RCE)
references:
- https://github.com/SigmaHQ/sigma/pull/3946
- https://twitter.com/hackerfantastic/status/1616455335203438592?s=20
author: Florian Roth (Nextron Systems), Nasreddine Bencherchali
date: 2023-01-21
tags:
- attack.initial-access
- attack.t1190
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\svchost.exe'
Image|endswith: '\svchost.exe'
ParentCommandLine|contains: '-k DHCPServer'
CommandLine|contains: '-k DHCPServer'
User|contains: # Covers many language settings for Network Service. Please expand.
- 'NETWORK SERVICE'
- 'NETZWERKDIENST'
- 'SERVIZIO DI RETE'
- 'SERVICIO DE RED'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process
Detects potentially suspicious child process of SSH process (sshd) with a specific execution user. This could be a sign of potential exploitation of CVE-2024-3094.
view Sigma YAML
title: Potential Exploitation of CVE-2024-3094 - Suspicious SSH Child Process
id: 9aa27839-e8ba-4d7a-ac1a-746c22c3d1e5
status: test
description: |
Detects potentially suspicious child process of SSH process (sshd) with a specific execution user. This could be a sign of potential exploitation of CVE-2024-3094.
references:
- https://github.com/amlweems/xzbot?tab=readme-ov-file#backdoor-demo
author: Arnim Rupp, Nasreddine Bencherchali, Thomas Patzke
date: 2024-04-01
modified: 2024-07-03
tags:
- attack.execution
- cve.2024-3094
- detection.emerging-threats
logsource:
category: process_creation
product: linux
detection:
selection:
ParentImage|endswith: '/sshd'
CommandLine|startswith:
- 'bash -c'
- 'sh -c'
User: 'root'
condition: selection
falsepositives:
- Administrative activity directly with root authentication might trigger this rule if it's unnecessarily prefixed with "sh -c" or "bash -c"
level: high
Convert to SIEM query
high
Potential Exploitation of CVE-2024-37085 - Suspicious Creation Of ESX Admins Group
Detects execution of the "net.exe" command in order to add a group named "ESX Admins".
This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
view Sigma YAML
title: Potential Exploitation of CVE-2024-37085 - Suspicious Creation Of ESX Admins Group
id: c408acfe-2870-41df-8d2f-9f4daa4555ed
status: test
description: |
Detects execution of the "net.exe" command in order to add a group named "ESX Admins".
This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
references:
- https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/
author: frack113
date: 2024-07-29
tags:
- attack.execution
- cve.2024-37085
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_net_img:
- Image|endswith:
- '\net.exe'
- '\net1.exe'
- OriginalFileName:
- 'net.exe'
- 'net1.exe'
selection_net_cmd:
CommandLine|contains|all:
- '/add'
- '/domain'
- 'ESX Admins'
- 'group'
selection_powershell_img:
- Image|endswith:
- '\PowerShell.exe'
- '\pwsh.exe'
- OriginalFileName:
- 'PowerShell.exe'
- 'pwsh.dll'
selection_powershell_cli:
CommandLine|contains|all:
- 'New-ADGroup'
- 'ESX Admins'
condition: all of selection_net_* or all of selection_powershell_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity
Detects any creation or modification to a windows domain group with the name "ESX Admins".
This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
view Sigma YAML
title: Potential Exploitation of CVE-2024-37085 - Suspicious ESX Admins Group Activity
id: 47a1658b-67a4-48e2-8ab1-c10437fc0148
status: test
description: |
Detects any creation or modification to a windows domain group with the name "ESX Admins".
This could indicates a potential exploitation attempt of CVE-2024-37085, which allows an attacker to elevate their privileges to full administrative access on an domain-joined ESXi hypervisor.
VMware ESXi hypervisors joined to an Active Directory domain consider any member of a domain group named "ESX Admins" to have full administrative access by default.
references:
- https://www.microsoft.com/en-us/security/blog/2024/07/29/ransomware-operators-exploit-esxi-hypervisor-vulnerability-for-mass-encryption/
author: Nasreddine Bencherchali (Nextron Systems)
date: 2024-07-30
tags:
- attack.execution
- cve.2024-37085
- detection.emerging-threats
logsource:
product: windows
service: security
detection:
selection:
EventID:
- 4727
- 4728
- 4731
- 4737
- 4754
- 4755
- 4756
keyword_group:
- 'ESX Admins'
condition: selection and keyword_group
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
Detects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0.
CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass,
which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through
template injection. This sequence enables unauthenticated remote code execution, significantly increasing
the impact of exploitation.
view Sigma YAML
title: Potential Exploitation of CVE-2025-4427/4428 Ivanti EPMM Pre-Auth RCE
id: 41956f7c-7a6b-46d6-b6bb-da6eb2e83fbe
status: experimental
description: |
Detects potential exploitation of a chained vulnerability attack targeting Ivanti EPMM 12.5.0.0.
CVE-2025-4427 allows unauthenticated access to protected API endpoints via an authentication bypass,
which can then be leveraged to trigger CVE-2025-4428 — a remote code execution vulnerability through
template injection. This sequence enables unauthenticated remote code execution, significantly increasing
the impact of exploitation.
references:
- https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/?123
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-05-20
tags:
- attack.initial-access
- attack.t1190
- attack.execution
- attack.t1203
- cve.2025-4427
- cve.2025-4428
- detection.emerging-threats
logsource:
category: webserver
detection:
selection_uri:
cs-uri-stem|contains: '/mifs/rs/api/v2/featureusage'
cs-uri-query|contains: 'format='
selection_exploit_rce:
- cs-uri-query|contains|all:
- 'java.lang.Runtime'
- '.getMethod'
- 'getRuntime'
- '.exec('
- cs-uri-query|contains|all:
- 'java%2elang%2eRuntime' # java.lang.Runtime
- '%2egetMethod' # .getMethod
- '%2eexec%28' # .exec(
- cs-uri-query|contains:
- '%6a%61%76%61%2e%6c%61%6e%67%2e%52%75%6e%74%69%6d%65%65%28%29' # java.lang.Runtime
- '%67%65%74%52%75%6e%74%69%6d%65' # getRuntime
- '%2e%65%78%65%63%28' # .exec(
selection_exploit_template_injection:
cs-uri-query|contains:
- '{7*7}'
- '%7B7*7%7D'
- '%7b7%2a7%7d'
condition: selection_uri and 1 of selection_exploit_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
view Sigma YAML
title: Potential Exploitation of CrushFTP RCE Vulnerability (CVE-2025-54309)
id: 0fdc7c7f-c690-4217-9ae3-31f5156eed72
status: experimental
description: Detects suspicious child processes created by CrushFTP. It could be an indication of exploitation of a RCE vulnerability such as CVE-2025-54309.
references:
- https://reliaquest.com/blog/threat-spotlight-cve-2025-54309-crushftp-exploit/
- https://pwn.guide/free/web/crushftp
- https://firecompass.com/crushftp-vulnerability-cve-2025-54309-securing-file-transfer-services/
author: Nisarg Suthar
date: 2025-08-01
tags:
- attack.privilege-escalation
- attack.initial-access
- attack.execution
- attack.t1059.001
- attack.t1059.003
- attack.t1068
- attack.t1190
- cve.2025-54309
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith: '\crushftp.exe'
selection_child_powershell:
Image|endswith:
- '\powershell.exe'
- '\powershell_ise.exe'
- '\pwsh.exe'
CommandLine|contains|all:
- 'IEX'
- 'enc'
- 'Hidden'
- 'bypass'
selection_child_cmd:
Image|endswith: '\cmd.exe'
CommandLine|contains:
- '/c powershell'
- 'whoami'
- 'net.exe'
- 'net1.exe'
selection_child_others:
Image|endswith:
- '\bitsadmin.exe'
- '\certutil.exe'
- '\mshta.exe'
- '\cscript.exe'
- '\wscript.exe'
condition: selection_parent and 1 of selection_child_*
falsepositives:
- Legitimate administrative command execution
level: high
Convert to SIEM query
high
Potential Exploitation of GoAnywhere MFT Vulnerability
Detects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035.
This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
view Sigma YAML
title: Potential Exploitation of GoAnywhere MFT Vulnerability
id: 6c76b3d0-afe4-4870-9443-ffe6773c5fef
status: experimental
description: |
Detects suspicious command execution by child processes of the GoAnywhere Managed File Transfer (MFT) application, which may indicate exploitation such as CVE-2025-10035.
This behavior is indicative of post-exploitation activity related to CVE-2025-10035, as observed in campaigns by the threat actor Storm-1175.
references:
- https://www.microsoft.com/en-us/security/blog/2025/10/06/investigating-active-exploitation-of-cve-2025-10035-goanywhere-managed-file-transfer-vulnerability/
author: MSFT (idea), Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-10-07
tags:
- attack.initial-access
- attack.t1190
- attack.execution
- attack.t1059.001
- attack.persistence
- attack.t1133
- detection.emerging-threats
- cve.2025-10035
logsource:
category: process_creation
product: windows
detection:
# Detects the GoAnywhere Tomcat parent process based on path and command line arguments
selection_parent:
ParentImage|contains: '\GoAnywhere\tomcat\'
selection_powershell_img:
Image|endswith:
- '\powershell.exe'
- '\powershell_ise.exe'
- '\pwsh.exe'
selection_powershell_cmd:
- CommandLine|contains|all:
- 'IEX'
- 'enc'
- 'Hidden'
- 'bypass'
- CommandLine|re:
- 'net\s+user'
- 'net\s+group'
- 'query\s+session'
- CommandLine|contains:
- 'whoami'
- 'systeminfo'
- 'dsquery'
- 'localgroup administrators'
- 'nltest'
- 'samaccountname='
- 'adscredentials'
- 'o365accountconfiguration'
- '.DownloadString('
- '.DownloadFile('
- 'FromBase64String('
- 'System.IO.Compression'
- 'System.IO.MemoryStream'
- 'curl'
selection_child_cmd:
Image|endswith: '\cmd.exe'
CommandLine|contains:
- 'powershell'
- 'whoami'
- 'net.exe'
- 'net1.exe'
- 'rundll32'
- 'quser'
- 'nltest'
- 'curl'
selection_child_others:
CommandLine|contains:
- 'bitsadmin'
- 'certutil'
- 'mshta'
- 'cscript'
- 'wscript'
condition: selection_parent and (all of selection_powershell_* or 1 of selection_child_*)
falsepositives:
- Legitimate administrative scripts or built-in GoAnywhere functions could potentially trigger this rule. Tuning may be required based on normal activity in your environment.
level: high
Convert to SIEM query
high
Potential Exploitation of RCE Vulnerability CVE-2025-33053
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053
which involves unauthorized code execution via WebDAV through external control of file names or paths.
The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating
their working directories to point to attacker-controlled WebDAV servers, causing them to execute
malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries
through Process.Start() search order manipulation.
view Sigma YAML
title: Potential Exploitation of RCE Vulnerability CVE-2025-33053
id: abe06362-a5b9-4371-8724-ebd00cd48a04
related:
- id: 9a2d8b3e-f5a1-4c68-9e21-7d9e1cf8a123
type: similar
- id: 04fc4b22-91a6-495a-879d-0144fec5ec03
type: similar
status: experimental
description: |
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053
which involves unauthorized code execution via WebDAV through external control of file names or paths.
The exploit abuses legitimate utilities like iediagcmd.exe or CustomShellHost.exe by manipulating
their working directories to point to attacker-controlled WebDAV servers, causing them to execute
malicious executables (like route.exe) from the WebDAV path instead of legitimate system binaries
through Process.Start() search order manipulation.
references:
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053
- https://research.checkpoint.com/2025/stealth-falcon-zero-day/
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-06-13
tags:
- attack.command-and-control
- attack.execution
- attack.stealth
- attack.t1218
- attack.lateral-movement
- attack.t1105
- detection.emerging-threats
- cve.2025-33053
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage:
- 'C:\Program Files\internet explorer\iediagcmd.exe'
- 'C:\Windows\System32\CustomShellHost.exe'
selection_child_current_dir:
- CurrentDirectory|startswith: '\\\\'
- CurrentDirectory|contains: '\DavWWWRoot\'
- Image|contains: '\DavWWWRoot\'
- Image|startswith: '\\\\'
selection_child_img:
Image|endswith:
- '\route.exe'
- '\netsh.exe'
- '\makecab.exe'
- '\dxdiag.exe'
- '\ipconfig.exe'
- '\explorer.exe'
filter_main_system:
Image|startswith:
- 'C:\Windows\System32\'
- 'C:\Windows\SysWOW64\'
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053
by monitoring suspicious image loads from WebDAV paths. The exploit involves malicious executables from
attacker-controlled WebDAV servers loading the Windows system DLLs like gdi32.dll, netapi32.dll, etc.
view Sigma YAML
title: Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Image Load
id: 04fc4b22-91a6-495a-879d-0144fec5ec03
related:
- id: abe06362-a5b9-4371-8724-ebd00cd48a04
type: similar
- id: 9a2d8b3e-f5a1-4c68-9e21-7d9e1cf8a123
type: similar
status: experimental
description: |
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053
by monitoring suspicious image loads from WebDAV paths. The exploit involves malicious executables from
attacker-controlled WebDAV servers loading the Windows system DLLs like gdi32.dll, netapi32.dll, etc.
references:
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053
- https://research.checkpoint.com/2025/stealth-falcon-zero-day/
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-06-13
tags:
- attack.command-and-control
- attack.execution
- attack.stealth
- attack.t1218
- attack.lateral-movement
- attack.t1105
- detection.emerging-threats
- cve.2025-33053
logsource:
category: image_load
product: windows
detection:
selection_img_path:
Image|startswith: '\\\\'
Image|contains: '\DavWWWRoot\'
selection_img_bin:
Image|endswith:
- '\route.exe'
- '\netsh.exe'
- '\makecab.exe'
- '\dxdiag.exe'
- '\ipconfig.exe'
- '\explorer.exe'
condition: all of selection_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053
by looking for process access that involves legitimate Windows executables (iediagcmd.exe, CustomShellHost.exe)
accessing suspicious executables hosted on WebDAV shares. This indicates an attacker may be exploiting
Process.Start() search order manipulation to execute malicious code from attacker-controlled WebDAV servers
instead of legitimate system binaries. The vulnerability allows unauthorized code execution through
external control of file names or paths via WebDAV.
view Sigma YAML
title: Potential Exploitation of RCE Vulnerability CVE-2025-33053 - Process Access
id: 9a2d8b3e-f5a1-4c68-9e21-7d9e1cf8a123
related:
- id: abe06362-a5b9-4371-8724-ebd00cd48a04
type: similar
- id: 04fc4b22-91a6-495a-879d-0144fec5ec03
type: similar
status: experimental
description: |
Detects potential exploitation of remote code execution vulnerability CVE-2025-33053
by looking for process access that involves legitimate Windows executables (iediagcmd.exe, CustomShellHost.exe)
accessing suspicious executables hosted on WebDAV shares. This indicates an attacker may be exploiting
Process.Start() search order manipulation to execute malicious code from attacker-controlled WebDAV servers
instead of legitimate system binaries. The vulnerability allows unauthorized code execution through
external control of file names or paths via WebDAV.
references:
- https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-33053
- https://research.checkpoint.com/2025/stealth-falcon-zero-day/
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-06-13
tags:
- attack.command-and-control
- attack.execution
- attack.stealth
- attack.t1218
- attack.lateral-movement
- attack.t1105
- detection.emerging-threats
- cve.2025-33053
logsource:
category: process_access
product: windows
detection:
selection_src:
SourceImage:
- 'C:\Program Files\internet explorer\iediagcmd.exe'
- 'C:\Windows\System32\CustomShellHost.exe'
selection_target_dir:
- TargetImage|startswith: '\\\\'
- TargetImage|contains: '\DavWWWRoot\'
selection_target_exe:
TargetImage|endswith:
- '\route.exe'
- '\netsh.exe'
- '\makecab.exe'
- '\dxdiag.exe'
- '\ipconfig.exe'
- '\explorer.exe'
condition: all of selection_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential File Extension Spoofing Using Right-to-Left Override
Detects suspicious filenames that contain a right-to-left override character and a potentially spoofed file extensions.
view Sigma YAML
title: Potential File Extension Spoofing Using Right-to-Left Override
id: 979baf41-ca44-4540-9d0c-4fcef3b5a3a4
related:
- id: ad691d92-15f2-4181-9aa4-723c74f9ddc3
type: derived
status: test
description: |
Detects suspicious filenames that contain a right-to-left override character and a potentially spoofed file extensions.
references:
- https://redcanary.com/blog/right-to-left-override/
- https://www.malwarebytes.com/blog/news/2014/01/the-rtlo-method
- https://tria.ge/241015-l98snsyeje/behavioral2
- https://www.unicode.org/versions/Unicode5.2.0/ch02.pdf
author: Jonathan Peters (Nextron Systems), Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2024-11-17
modified: 2026-03-20
tags:
- attack.execution
- attack.stealth
- attack.t1036.002
logsource:
category: file_event
product: windows
detection:
selection_rtlo_unicode:
TargetFilename|contains:
- '\u202e' # Unicode RTLO character
- '[U+202E]'
# Real char U+202E copied/pasted below
- ''
selection_extensions:
TargetFilename|contains:
- '3pm.' # Reversed `.mp3`
- '4pm.' # Reversed `.mp4`
- 'cod.' # Reversed `.doc`
- 'fdp.' # Reversed `.pdf`
- 'ftr.' # Reversed `.rtf`
- 'gepj.' # Reversed `.jpeg`
- 'gnp.' # Reversed `.png`
- 'gpj.' # Reversed `.jpg`
- 'ism.' # Reversed `.msi`
- 'lmth.' # Reversed `.html`
- 'nls.' # Reversed `.sln`
- 'piz.' # Reversed `.zip`
- 'slx.' # Reversed `.xls`
- 'tdo.' # Reversed `.odt`
- 'vsc.' # Reversed `.csv`
- 'vwm.' # Reversed `.wmv`
- 'xcod.' # Reversed `.docx`
- 'xslx.' # Reversed `.xlsx`
- 'xtpp.' # Reversed `.pptx`
condition: all of selection_*
falsepositives:
- Filenames that contains scriptures such as arabic or hebrew might make use of this character
level: high
regression_tests_path: regression_data/rules/windows/file/file_event/file_event_win_susp_right_to_left_override_extension_spoofing/info.yml
Convert to SIEM query
high
Potential File Overwrite Via Sysinternals SDelete
Detects the use of SDelete to erase a file not the free space
view Sigma YAML
title: Potential File Overwrite Via Sysinternals SDelete
id: a4824fca-976f-4964-b334-0621379e84c4
status: test
description: Detects the use of SDelete to erase a file not the free space
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1485/T1485.md
author: frack113
date: 2021-06-03
modified: 2023-02-28
tags:
- attack.impact
- attack.t1485
logsource:
category: process_creation
product: windows
detection:
selection:
OriginalFileName: sdelete.exe
filter:
CommandLine|contains:
- ' -h'
- ' -c'
- ' -z'
- ' /\?'
condition: selection and not filter
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential GobRAT File Discovery Via Grep
Detects the use of grep to discover specific files created by the GobRAT malware
view Sigma YAML
title: Potential GobRAT File Discovery Via Grep
id: e34cfa0c-0a50-4210-9cb3-5632d08eb041
status: test
description: Detects the use of grep to discover specific files created by the GobRAT malware
references:
- https://blogs.jpcert.or.jp/en/2023/05/gobrat.html
- https://www.virustotal.com/gui/file/60bcd645450e4c846238cf0e7226dc40c84c96eba99f6b2cffcd0ab4a391c8b3/detection
- https://www.virustotal.com/gui/file/3e44c807a25a56f4068b5b8186eee5002eed6f26d665a8b791c472ad154585d1/detection
author: Joseliyo Sanchez, @Joseliyo_Jstnk
date: 2023-06-02
tags:
- attack.discovery
- attack.t1082
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: '/grep'
CommandLine|contains:
- 'apached'
- 'frpc'
- 'sshd.sh'
- 'zone.arm'
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Goofy Guineapig Backdoor Activity
Detects a specific broken command that was used by Goofy-Guineapig as described by the NCSC report.
view Sigma YAML
title: Potential Goofy Guineapig Backdoor Activity
id: 477a5ed3-a374-4282-9f3b-ed94e159a108
status: test
description: Detects a specific broken command that was used by Goofy-Guineapig as described by the NCSC report.
references:
- https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/goofy-guineapig/NCSC-MAR-Goofy-Guineapig.pdf
author: X__Junior (Nextron Systems)
date: 2023-05-14
tags:
- attack.execution
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
CommandLine|contains: 'choice /t %d /d y /n >nul'
condition: selection
falsepositives:
- Unlikely
level: high
Convert to SIEM query
high
Potential Goofy Guineapig GoolgeUpdate Process Anomaly
Detects "GoogleUpdate.exe" spawning a new instance of itself in an uncommon location as seen used by the Goofy Guineapig backdoor
view Sigma YAML
title: Potential Goofy Guineapig GoolgeUpdate Process Anomaly
id: bdbab15a-3826-48fa-a1b7-723cd8f32fcc
status: test
description: Detects "GoogleUpdate.exe" spawning a new instance of itself in an uncommon location as seen used by the Goofy Guineapig backdoor
references:
- https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/goofy-guineapig/NCSC-MAR-Goofy-Guineapig.pdf
author: X__Junior (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
date: 2023-05-15
tags:
- detection.emerging-threats
- attack.stealth
logsource:
category: process_creation
product: windows
detection:
selection:
ParentImage|endswith: '\GoogleUpdate.exe'
Image|endswith: '\GoogleUpdate.exe'
filter_main_legit_paths:
- Image|startswith:
- 'C:\Program Files\Google\'
- 'C:\Program Files (x86)\Google\'
- Image|contains: '\AppData\Local\Google\Update\'
condition: selection and not 1 of filter_main_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Information Disclosure CVE-2023-43261 Exploitation - Proxy
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in proxy logs.
view Sigma YAML
title: Potential Information Disclosure CVE-2023-43261 Exploitation - Proxy
id: f48f5368-355c-4a1b-8bf5-11c13d589eaa
related:
- id: a2bcca38-9f3a-4d5e-b603-0c587e8569d7
type: similar
status: test
description: |
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in proxy logs.
references:
- https://thehackernews.com/2023/10/experts-warn-of-severe-flaws-affecting.html
- https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
- https://github.com/win3zz/CVE-2023-43261
- https://vulncheck.com/blog/real-world-cve-2023-43261
author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo
date: 2023-10-20
modified: 2023-10-30
tags:
- attack.initial-access
- attack.t1190
- cve.2023-43621
- detection.emerging-threats
logsource:
category: proxy
detection:
selection:
cs-method: 'GET'
# Note: In theory the path can also be for other files. But since the logs can contains password and interesting information. Its most likely going to be targeted during a real attack
c-uri|contains: '/lang/log/httpd.log' # Als covered .old
sc-status: 200
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Information Disclosure CVE-2023-43261 Exploitation - Web
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in access logs.
view Sigma YAML
title: Potential Information Disclosure CVE-2023-43261 Exploitation - Web
id: a2bcca38-9f3a-4d5e-b603-0c587e8569d7
related:
- id: f48f5368-355c-4a1b-8bf5-11c13d589eaa
type: similar
status: test
description: |
Detects exploitation attempts of CVE-2023-43261 and information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 that allows attackers to access sensitive router components in access logs.
references:
- https://thehackernews.com/2023/10/experts-warn-of-severe-flaws-affecting.html
- https://medium.com/@win3zz/inside-the-router-how-i-accessed-industrial-routers-and-reported-the-flaws-29c34213dfdf
- https://github.com/win3zz/CVE-2023-43261
- https://vulncheck.com/blog/real-world-cve-2023-43261
author: Nasreddine Bencherchali (Nextron Systems), Thurein Oo
date: 2023-10-20
modified: 2023-10-30
tags:
- attack.initial-access
- attack.t1190
- cve.2023-43621
- detection.emerging-threats
logsource:
category: webserver
definition: 'Requirements: In order for this detection to trigger, access logs of the router must be collected.'
detection:
selection:
cs-method: 'GET'
# Note: In theory the path can also be for other files. But since the logs can contains password and interesting information. Its most likely going to be targeted during a real attack
cs-uri-stem|contains: '/lang/log/httpd.log' # Als covered .old
sc-status: 200
condition: selection
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential Invoke-Mimikatz PowerShell Script
Detects Invoke-Mimikatz PowerShell script and alike. Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords.
view Sigma YAML
title: Potential Invoke-Mimikatz PowerShell Script
id: 189e3b02-82b2-4b90-9662-411eb64486d4
status: test
description: Detects Invoke-Mimikatz PowerShell script and alike. Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords.
references:
- https://www.elastic.co/guide/en/security/current/potential-invoke-mimikatz-powershell-script.html#potential-invoke-mimikatz-powershell-script
author: Tim Rauch, Elastic (idea)
date: 2022-09-28
tags:
- attack.credential-access
- attack.t1003
logsource:
category: ps_script
product: windows
detection:
selection_1:
ScriptBlockText|contains|all:
- 'DumpCreds'
- 'DumpCerts'
selection_2:
ScriptBlockText|contains: 'sekurlsa::logonpasswords'
selection_3:
ScriptBlockText|contains|all:
- 'crypto::certificates'
- 'CERT_SYSTEM_STORE_LOCAL_MACHINE'
condition: 1 of selection*
falsepositives:
- Mimikatz can be useful for testing the security of networks
level: high
Convert to SIEM query
high
Potential Iviewers.DLL Sideloading
Detects potential DLL sideloading of "iviewers.dll" (OLE/COM Object Interface Viewer)
view Sigma YAML
title: Potential Iviewers.DLL Sideloading
id: 4c21b805-4dd7-469f-b47d-7383a8fcb437
status: test
description: Detects potential DLL sideloading of "iviewers.dll" (OLE/COM Object Interface Viewer)
references:
- https://www.secureworks.com/research/shadowpad-malware-analysis
author: X__Junior (Nextron Systems)
date: 2023-03-21
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded|endswith: '\iviewers.dll'
filter:
ImageLoaded|startswith:
- 'C:\Program Files (x86)\Windows Kits\'
- 'C:\Program Files\Windows Kits\'
condition: selection and not filter
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential JLI.dll Side-Loading
Detects potential DLL side-loading of jli.dll.
JLI.dll has been observed being side-loaded by Java processes by various threat actors, including APT41, XWorm,
and others in order to load malicious payloads in context of legitimate Java processes.
view Sigma YAML
title: Potential JLI.dll Side-Loading
id: 7a3b6d1f-4a2b-4f8c-9d7e-e9f8cbf21a35
status: experimental
description: |
Detects potential DLL side-loading of jli.dll.
JLI.dll has been observed being side-loaded by Java processes by various threat actors, including APT41, XWorm,
and others in order to load malicious payloads in context of legitimate Java processes.
references:
- https://securelist.com/apt41-in-africa/116986/
- https://lab52.io/blog/snake-keylogger-in-geopolitical-affairs-abuse-of-trusted-java-utilities-in-cybercrime-operations/
- https://hijacklibs.net/entries/3rd_party/oracle/jli.html
- https://www.proofpoint.com/us/blog/threat-insight/phish-china-aligned-espionage-actors-ramp-up-taiwan-semiconductor-targeting
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-07-25
modified: 2025-10-06
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.001
logsource:
category: image_load
product: windows
detection:
selection:
ImageLoaded|endswith: '\jli.dll'
filter_main_legitimate_install_paths:
ImageLoaded|startswith:
# Keeping the paths generic as jli.dll was found inside various directories of installed software
- 'C:\Program Files\'
- 'C:\Program Files (x86)\'
Description: 'OpenJDK Platform binary'
OriginalFileName: 'jli.dll'
Product|startswith: 'OpenJDK Platform'
Signed: 'true'
filter_optional_eclipse:
ImageLoaded|startswith: 'C:\eclipse\plugins\'
condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
- Unknown
level: high
Convert to SIEM query
high
Potential JNDI Injection Exploitation In JVM Based Application
Detects potential JNDI Injection exploitation. Often coupled with Log4Shell exploitation.
view Sigma YAML
title: Potential JNDI Injection Exploitation In JVM Based Application
id: bb0e9cec-d4da-46f5-997f-22efc59f3dca
status: test
description: Detects potential JNDI Injection exploitation. Often coupled with Log4Shell exploitation.
references:
- https://www.wix.engineering/post/threat-and-vulnerability-hunting-with-application-server-error-logs
- https://secariolabs.com/research/analysing-and-reproducing-poc-for-log4j-2-15-0
author: Moti Harmats
date: 2023-02-11
tags:
- attack.initial-access
- attack.t1190
logsource:
category: application
product: jvm
definition: 'Requirements: application error logs must be collected (with LOG_LEVEL=ERROR and above)'
detection:
keywords:
- 'com.sun.jndi.ldap.'
- 'org.apache.logging.log4j.core.net.JndiManager'
condition: keywords
falsepositives:
- Application bugs
level: high
Convert to SIEM query
high
Potential Java WebShell Upload in SAP NetViewer Server
Detects potential Java webshell uploads via HTTP requests with Content-Type 'application/octet-stream' and Java file extensions.
This behavior might indicate exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution through webshells in SAP NetViewer.
view Sigma YAML
title: Potential Java WebShell Upload in SAP NetViewer Server
id: 639b893f-f93a-4e53-a7c8-f08cf73fe7f7
status: experimental
description: |
Detects potential Java webshell uploads via HTTP requests with Content-Type 'application/octet-stream' and Java file extensions.
This behavior might indicate exploitation of vulnerabilities like CVE-2025-31324, which allows remote code execution through webshells in SAP NetViewer.
references:
- https://blog.eclecticiq.com/china-nexus-nation-state-actors-exploit-sap-netweaver-cve-2025-31324-to-target-critical-infrastructures
author: Swachchhanda Shrawan Poudel (Nextron Systems)
date: 2025-05-14
tags:
- attack.persistence
- attack.t1505.003
- detection.emerging-threats
- cve.2025-31324
logsource:
category: webserver
detection:
selection:
cs-content-type: 'application/octet-stream'
cs-method: 'POST'
cs-uri-stem|contains|all:
- '/irj/'
- '.jsp'
cs-uri-stem|endswith:
- '.class'
- '.java'
- '.jsp'
condition: selection
falsepositives:
- Legitimate uploads of Java files in development environments
level: high
Convert to SIEM query
Showing 851-900 of 1,715