threat
engine
.sh
Back
·
··:··
Sign in
Account
free plan
Dashboard
Stack Monitoring
Notifications
Watchlist
Account & tokens
API docs
Pricing
Sign out
Home
/
Detection rules
/
T1154
Category
SIEM
EDR / XDR
SOAR
Network IDS
Malware / file
Runtime / Cloud
Analytics
Vendor-native
Adversary emulation
Tool
Splunk
Elastic
Microsoft Sentinel
Chronicle (YARA-L)
Vendor-native detections for T1154
0 vendor-native detections · ready to paste into your SIEM · cross-linked to ATT&CK
All tactics
collection
command-and-control
credential-access
defense-impairment
discovery
execution
exfiltration
impact
initial-access
lateral-movement
persistence
privilege-escalation
reconnaissance
resource-development
stealth
All data sources
Active DNS
Active Directory Credential Request
Active Directory Object Access
Active Directory Object Creation
Active Directory Object Deletion
Active Directory Object Modification
Application Log Content
Certificate Registration
Cloud Service Disable
Cloud Service Enumeration
Cloud Service Metadata
Cloud Service Modification
Cloud Storage Access
Cloud Storage Creation
Cloud Storage Deletion
Cloud Storage Enumeration
Cloud Storage Metadata
Cloud Storage Modification
Command Execution
Container Creation
Container Enumeration
Container Start
Domain Registration
Drive Access
Drive Creation
Drive Modification
Driver Load
Driver Metadata
File Access
File Creation
File Deletion
File Metadata
File Modification
Firewall Disable
Firewall Rule Modification
Firmware Modification
Group Enumeration
Group Metadata
Group Modification
Host Status
Image Creation
Image Metadata
Image Modification
Instance Creation
Instance Deletion
Instance Enumeration
Instance Metadata
Instance Modification
Instance Start
Instance Stop
Kernel Module Load
Logon Session Creation
Logon Session Metadata
Malware Content
Malware Metadata
Module Load
Named Pipe Metadata
Network Connection Creation
Network Share Access
Network Traffic Content
Network Traffic Flow
OS API Execution
Passive DNS
Pod Creation
Pod Enumeration
Process Access
Process Creation
Process Metadata
Process Modification
Process Termination
Response Content
Response Metadata
Scheduled Job Creation
Scheduled Job Metadata
Scheduled Job Modification
Script Execution
Service Creation
Service Metadata
Service Modification
Snapshot Creation
Snapshot Deletion
Snapshot Metadata
Snapshot Modification
Social Media
User Account Authentication
User Account Creation
User Account Deletion
User Account Metadata
User Account Modification
Volume Creation
Volume Deletion
Volume Modification
WMI Creation
Web Credential Creation
Web Credential Usage
Windows Registry Key Access
Windows Registry Key Creation
Windows Registry Key Modification
Search
technique T1154 ×
No vendor-native rules match this filter
Try a different search, source, or technique.
SOC and Response
CVE triage
Stack monitoring
Am I affected
IOC triage
KEV catalog
Recently exploited
Daily brief
Change tracking
Detection Engineering
Detection coverage workspace
Saved stacks
SIEM query builder
Detection rules
D3FEND
Threat Hunting
Threat actors
ATT&CK techniques
Attack paths
Indicators
Ransomware groups
Atomic tests
Red Team and Pentest
Exploitability triage
Recon pack
Attack paths
CAPEC patterns
Adversary emulation
Compliance and GRC
Framework mapping
Control assessment
Audit view
Atlas
Search
Threat actors
Techniques
Detection coverage
Tools & malware
CWE
CAPEC
KEV catalog
Package vulns
About
All capabilities
Pricing
API docs
Privacy policy
Terms of service
threatengine.sh
Are you sure?
Cancel
Confirm
We use one first-party cookie to remember how you found us, only if you allow it. Everything the site needs to work uses essential cookies. See our
privacy policy
.
Essential only
Accept all