Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0008 — WMI Creation
DC0008

WMI Creation

1096 analytic(s) · 540 detection strategy(ies)

Description

Initial construction of a WMI object, such as a filter, consumer, subscription, binding, or providers.

Referenced in Analytics

1096
AN0001 Analytic 0001 DET0001

Detects access attempts to cloud instance metadata endpoints (e.g., 169.254.169.254) from virtual machines or containerized workloads. This includes both direct access and SSRF exploitation patterns.

AWS:VPCFlowLogs AWS:CloudTrail ebpf:syscalls
AN0002 Analytic 0002 DET0002

Detects non-standard processes (e.g., PowerShell, python.exe, rundll32.exe) making outbound connections using publish/subscribe protocols (e.g., MQTT, AMQP) over non-browser, encrypted channels, often beaconing to message brokers.

WinEventLog:Sysmon NSM:Flow
AN0003 Analytic 0003 DET0002

Detects CLI tools (e.g., mosquitto_pub, nc, python scripts) interacting with pub/sub brokers using unusual topic names, high-frequency publication rates, or obfuscated payloads to non-standard hosts.

auditd:SYSCALL NSM:Flow
AN0004 Analytic 0004 DET0002

Detects osascript, curl, or custom binaries interacting with XMPP/MQTT brokers in unapproved destinations with encrypted payloads or frequent POST-like requests to broker URIs.

macos:unifiedlog macos:osquery
AN0005 Analytic 0005 DET0002

Detects pub/sub traffic over unusual ports, high-frequency topic publications, and connections to known-bad or dynamic broker endpoints outside allowlisted infrastructure.

NSM:Flow
AN0006 Analytic 0006 DET0003

Adversary uses built-in tools such as 'net user /add /domain' or PowerShell to create a domain user account. The behavior chain includes: (1) suspicious process execution on a domain controller followed by (2) user account creation event (Event ID 4720) on the same host.

WinEventLog:Security WinEventLog:Sysmon
AN0009 Analytic 0009 DET0004

Abnormal modification of the PATH environment variable or registry keys controlling system paths, combined with execution of binaries named after legitimate system tools from user-writable directories. Defender correlates registry modifications, file creation of suspicious binaries, and process execution paths inconsistent with baseline system directories.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0010 Analytic 0010 DET0004

User modification of the $PATH environment variable in shell configuration files or direct runtime PATH changes, followed by execution of binaries from user-controlled directories. Defender observes file edits to ~/.bashrc, ~/.profile, or /etc/paths.d and process execution resolving to unexpected binary locations.

auditd:SYSCALL linux:osquery
AN0011 Analytic 0011 DET0004

Modification of PATH or HOME environment variables through shell config files, launchctl, or /etc/paths.d entries, combined with process execution from attacker-controlled directories. Defender correlates file changes in /etc/paths.d with process execution resolving to malicious binaries.

macos:unifiedlog macos:unifiedlog
AN0012 Analytic 0012 DET0005

Execution of binaries where the on-disk filename does not match PE metadata such as OriginalFilename or InternalName. Often observed with renamed LOLBAS or system binaries like rundll32, powershell, or psexec.

WinEventLog:Sysmon WinEventLog:Sysmon EDR:AMSI
AN0013 Analytic 0013 DET0005

Execution of renamed or relocated native macOS utilities with uncommon names or non-default paths (e.g., renamed `osascript`, `bash`, or `curl`).

macos:unifiedlog macos:endpointsecurity fs:fileevents
AN0014 Analytic 0014 DET0005

Execution of renamed common utilities (e.g., `bash`, `nc`, `python`, `sh`) from atypical directories or with names intended to deceive defenders or EDRs.

auditd:SYSCALL linux:osquery linux:syslog
AN0015 Analytic 0015 DET0006

From a defender’s perspective, suspicious bridging is observed when network devices begin allowing traffic that contradicts existing segmentation or access policies. Observable behaviors include sudden modifications to ACLs or firewall rules, unusual cross-boundary traffic flows (e.g., east-west communications across separated VLANs), or simultaneous ingress/egress anomalies. Multi-event correlation is key: configuration changes on a router/firewall followed by unexpected traffic patterns, especially from unusual sources, is a strong indicator of compromise.

NSM:Flow networkdevice:syslog
AN0016 Analytic 0016 DET0007

Adversary uses nltest, PowerShell, or Win32/.NET API to enumerate domain trust relationships (via DSEnumerateDomainTrusts, GetAllTrustRelationships, or LDAP queries), followed by discovery or authentication staging.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Security
AN0021 Analytic 0021 DET0009

Adversary manipulates dependencies/dev tools used by developers or CI: a package manager (npm/yarn/pnpm, pip/pipenv, nuget/dotnet, chocolatey/winget, maven/gradle) or a compiler/IDE downloads or restores content; files are written under project paths and execution paths (node_modules, packages, .nuget, .gradle, .m2, %AppData%\npm, %UserProfile%\.cargo\bin, temp build dirs). First run of newly written components triggers scripts (preinstall/postinstall), shell/PowerShell spawning, or loader DLLs, followed by network egress to non-approved registries/CDNs.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-CodeIntegrity/Operational NSM:Flow
AN0022 Analytic 0022 DET0009

Developer or CI invokes package managers/compilers (apt/yum + build-essential, npm/yarn/pnpm, pip/pip3, gem, cargo, go, maven/gradle). These write executable or script files into PATH or project dirs and immediately execute embedded lifecycle hooks (preinstall/postinstall, setup.py, npm scripts) that spawn shells or curl/wget, followed by egress to unfamiliar registries or domains.

auditd:SYSCALL auditd:SYSCALL journald:package NSM:Flow
AN0023 Analytic 0023 DET0009

Developer tools (Homebrew, pip, npm/yarn, Xcode builds) install or update dependencies; new Mach-O or scripts appear under /usr/local, /opt/homebrew, ~/Library/Application Support, project dirs (node_modules/.bin, venv/bin). First run spawns sh/zsh/osascript/curl and new outbound flows; Gatekeeper/AMFI may flag unsigned components.

macos:unifiedlog macos:endpointsecurity NSM:Flow
AN0024 Analytic 0024 DET0010

Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes.

WinEventLog:Security WinEventLog:WMI WinEventLog:Security WinEventLog:Sysmon
AN0026 Analytic 0026 DET0010

Correlates launchd plist modifications with subsequent unauthorized script execution or anomalous parent-child process trees involving user agents.

macos:unifiedlog macos:unifiedlog
AN0029 Analytic 0029 DET0010

Detects macros or VBA triggers set to execute on document open or close events, often correlating with embedded payloads or C2 traffic shortly after execution.

m365:office m365:office
AN0030 Analytic 0030 DET0011

Processes generating large outbound connections with disproportionate send/receive ratios, often to uncommon ports or hosts, potentially inserting meaningless data into protocol payloads.

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0031 Analytic 0031 DET0011

Outbound traffic with anomalous payload sizes and patterns from non-networking processes, often observed via packet inspection or connection logs.

auditd:SYSCALL NSM:Flow
AN0032 Analytic 0032 DET0011

Previously unseen applications generating outbound connections with atypical data flow characteristics, such as excessive data with no return response.

macos:unifiedlog macos:osquery NSM:Flow
AN0033 Analytic 0033 DET0011

Anomalous traffic from ESXi host management daemons (like hostd or vpxa) embedding non-standard payloads in management protocols (e.g., HTTPS) or beaconing behavior.

esxi:vmkernel esxi:hostd
AN0034 Analytic 0034 DET0012

Discrepancies between VBA source code and p-code inside Office documents. Defender perspective: anomalies in file metadata streams, execution of Office processes loading macros without source code consistency, and script execution with no corresponding source metadata.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0035 Analytic 0035 DET0012

Execution of Wine or LibreOffice macros with inconsistent VBA metadata. Defender perspective: file analysis showing p-code embedded without matching source streams.

auditd:SYSCALL linux:syslog
AN0036 Analytic 0036 DET0012

Opening of Office files where VBA source code appears benign or missing, but p-code remains active. Defender perspective: process execution of Office apps with macro execution lacking visible source components.

macos:unifiedlog macos:unifiedlog
AN0037 Analytic 0037 DET0013

Access to browser artifact locations (e.g., Chrome, Edge, Firefox) by processes like PowerShell, cmd.exe, or unknown tools, followed by file reads, decoding, or export operations indicating enumeration of bookmarks, autofill, or history databases.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell
AN0039 Analytic 0039 DET0013

Scripting or CLI tool access to ~/Library/Application Support/Google/Chrome or ~/Library/Safari bookmarks, cookies, or history databases. Detection relies on unexpected processes accessing or reading from these locations.

macos:unifiedlog macos:osquery
AN0040 Analytic 0040 DET0014

Detects staging of sensitive files into temporary or public directories, compression with 7zip/WinRAR, or batch copy prior to exfiltration.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0041 Analytic 0041 DET0014

Detects script or user activity copying files to a central temp or /mnt directory followed by archive/compression utilities.

auditd:SYSCALL auditd:SYSCALL
AN0042 Analytic 0042 DET0014

Detects files collected into user temp or shared directories followed by compression with ditto, zip, or custom scripts.

macos:unifiedlog macos:unifiedlog
AN0045 Analytic 0045 DET0015

Detects unusual command executions and service modifications that indicate self-patching or disabling of vulnerable services post-compromise. Defenders should monitor for service stop commands, suspicious process termination, and execution of binaries or scripts aligned with known patching or service management tools outside of expected admin contexts.

WinEventLog:Security WinEventLog:Sysmon
AN0048 Analytic 0048 DET0016

Adversary executes commands to enumerate installed antivirus, EDR, or firewall agents using WMI, registry queries, and built-in tools (e.g., tasklist, netsh, sc query). Correlated with elevated process privileges or scripting engine usage.

WinEventLog:Security WinEventLog:Sysmon
AN0049 Analytic 0049 DET0016

Adversary runs discovery commands such as `ps aux`, `systemctl status`, or `cat /etc/init.d/` to enumerate security software or services. Often occurs alongside privilege escalation or bash script execution.

auditd:SYSCALL
AN0050 Analytic 0050 DET0016

Adversary attempts to detect monitoring agents such as Little Snitch, KnockKnock, or other system daemons via process listing (`ps -e`), application folder checks, and system extension listing.

macos:unifiedlog auditd:SYSCALL
AN0051 Analytic 0051 DET0017

Correlated modification of AppCompat registry keys and execution of sdbinst.exe to install custom shim databases. Followed by DLL injection via shim behavior into target application processes.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0052 Analytic 0052 DET0018

A process (often LOLBin or user-launched program) loads a DLL from a user-writable/UNC/Temp path or unsigned/invalid signer. Within a short window the DLL is (a) newly written to disk, (b) spawned as follow-on execution (rundll32/regsvr32), or (c) establishes outbound C2.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon WinEventLog:Microsoft-Windows-CodeIntegrity/Operational
AN0053 Analytic 0053 DET0018

A process loads a shared object (.so) via dlopen/LD_PRELOAD/open from non-standard or temporary locations (e.g., /tmp, /dev/shm), especially shortly after that .so is written or fetched, or linked via manipulated environment variables (LD_PRELOAD/LD_LIBRARY_PATH).

auditd:SYSCALL auditd:EXECVE linux:syslog NSM:Flow
AN0054 Analytic 0054 DET0018

A process loads a non-system .dylib/.so via dyld (dlopen/dlsym) from user-writable locations (~/Library, /tmp) or after the library was recently created/downloaded, often followed by network egress or persistence.

macos:unifiedlog macos:endpointsecurity macos:endpointsecurity
AN0055 Analytic 0055 DET0019

Executable or script payloads lacking symbol information and readable strings that are created or dropped by unusual or short-lived processes.

WinEventLog:Sysmon WinEventLog:Sysmon EDR:file
AN0056 Analytic 0056 DET0019

Executable or binary files created without symbol tables or with stripped sections, especially by non-user shell processes or compilers invoked outside standard dev paths.

auditd:EXECVE auditd:SYSCALL linux:osquery
AN0057 Analytic 0057 DET0019

Creation of run-only AppleScripts or Mach-O binaries lacking symbol table and string references, especially when dropped by user space scripting engines or staging apps.

macos:unifiedlog macos:endpointsecurity macos:osquery
AN0058 Analytic 0058 DET0019

Inbound binary payloads transferred over HTTP/S with compressed or encoded headers, lacking signature markers or metadata indicative of compiler/toolchain.

NSM:Flow
AN0059 Analytic 0059 DET0020

Detects modification of shell startup/logout scripts such as ~/.bashrc, ~/.bash_profile, or /etc/profile, followed by anomalous process execution or network connections upon interactive or remote shell login.

auditd:SYSCALL auditd:EXECVE NSM:Flow
AN0060 Analytic 0060 DET0020

Correlates zsh shell configuration file changes (e.g., ~/.zshrc, ~/.zlogin, /etc/zprofile) with execution of unauthorized binaries or unexpected network activity triggered on Terminal.app launch.

macos:unifiedlog macos:endpointsecurity
AN0061 Analytic 0061 DET0021

Adversary disables or stops critical services (e.g., Exchange, SQL, AV, endpoint monitoring) using native utilities or API calls, often preceding destructive actions (T1485, T1486). Behavioral chain: Elevated execution context + stop-service or sc.exe or ChangeServiceConfigW + terminated or disabled service + possible follow-up file manipulation.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:System WinEventLog:Sysmon
AN0062 Analytic 0062 DET0021

Adversary executes systemctl or service stop targeting high-value services (e.g., mysql, sshd), possibly followed by rm or shred against data stores. Behavioral chain: sudo/su usage + stop command + /var/log/messages or syslog entries + file access/delete.

auditd:SYSCALL auditd:SYSCALL linux:syslog
AN0063 Analytic 0063 DET0021

Use of launchctl to stop services or kill critical background processes (e.g., securityd, com.apple.*), typically followed by command-line tools like rm or diskutil. Behavioral chain: Terminal or remote shell + launchctl bootout/disable + process termination + follow-on modification.

macos:unifiedlog auditd:SYSCALL
AN0065 Analytic 0065 DET0022

Adversary stages a lure that references a remote resource (e.g., LNK/SCF/Office template). When the user opens/renders the file or a shell enumerates icons, the host automatically attempts SMB or WebDAV authentication to the attacker host. The chain is: (1) lure file is created or modified in a user-exposed location → (2) user or system accesses the lure → (3) host makes outbound NTLM (SMB 139/445 or WebDAV over 80/443) to an untrusted destination → (4) repeated attempts from multiple users/hosts or from privileged workstations.

WinEventLog:Sysmon WinEventLog:Security NSM:Flow NSM:Flow
AN0066 Analytic 0066 DET0023

Detection of unpacking behavior through abnormal memory allocation, followed by executable code injection and execution from non-image sections.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0067 Analytic 0067 DET0023

Correlates ELF file execution with high-entropy writable memory segments and self-modifying code patterns.

auditd:SYSCALL auditd:SYSCALL
AN0068 Analytic 0068 DET0023

Detection of packed Mach-O binaries unpacking into memory and transferring control to dynamically modified code segments.

macos:unifiedlog macos:endpointsecurity
AN0069 Analytic 0069 DET0024

Detects unauthorized access, copying, or modification of Kerberos ccache files (krb5cc_%UID% or krb5.ccache) in /tmp or custom paths defined by KRB5CCNAME. Correlates file access with suspicious processes (e.g., credential dumping tools) and subsequent anomalous Kerberos authentication requests from non-standard processes.

auditd:SYSCALL auditd:SYSCALL
AN0070 Analytic 0070 DET0024

Detects abnormal interaction with memory-based Kerberos ccache (API:{uuid}) or file-based overrides. Focus on processes attempting to enumerate or extract Kerberos tickets outside of built-in utilities. Detects use of open-source tools (e.g., Bifrost, modified Mimikatz ports) that interact with the Kerberos framework APIs.

macos:unifiedlog macos:osquery
AN0071 Analytic 0071 DET0025

Abuse of trusted Electron apps (Teams, Slack, Chrome) to spawn child processes or execute payloads via malicious command-line arguments (e.g., --gpu-launcher) and modified app resources (.asar). Behavior chain: suspicious parent process (Electron app) → unusual command-line args → child process creation → optional DLL/network artifacts.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0072 Analytic 0072 DET0025

Abuse of Linux Electron binaries by modifying app.asar or config JS files and spawning unexpected child processes (bash, curl, python).

auditd:SYSCALL WinEventLog:Sysmon
AN0073 Analytic 0073 DET0025

Abuse of macOS Electron apps by modifying app.asar bundles and spawning child processes (osascript, curl, sh) from Electron executables.

macos:unifiedlog macos:osquery
AN0074 Analytic 0074 DET0026

Correlated registry modifications under Print Processors path, followed by DLL file creation within the system print processor directory, and DLL load by spoolsv.exe. Malicious execution often occurs during service restart or system boot, with SYSTEM-level privileges.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0075 Analytic 0075 DET0027

Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs.

NSM:Flow WinEventLog:Sysmon
AN0076 Analytic 0076 DET0027

Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains.

NSM:Flow auditd:SYSCALL
AN0078 Analytic 0078 DET0027

Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget.

NSM:Flow esxi:shell
AN0079 Analytic 0079 DET0027

Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels.

NSM:Flow
AN0080 Analytic 0080 DET0028

Processes invoking network-intensive child processes or uploading large data volumes, often from non-standard user or system contexts, with evidence of long-duration TCP/UDP sessions to unusual destinations.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0081 Analytic 0081 DET0028

User-initiated processes generating sustained outbound traffic over common or non-standard ports, often outside business hours, potentially linked to scanning or proxyjacking. Includes curl, wget, masscan, or proxy clients.

auditd:SYSCALL NSM:Flow
AN0082 Analytic 0082 DET0028

Suspicious long-lived or high-throughput connections by non-Apple signed apps or processes not commonly associated with network uploads. Detect background processes using open sockets for data egress.

macos:unifiedlog macos:unifiedlog
AN0083 Analytic 0083 DET0028

Containerized apps or sidecar containers generating excessive outbound traffic or being leveraged for proxy networks. Includes sudden increases in network interface stats, especially in dormant or low-util apps.

containers:osquery docker:stats
AN0085 Analytic 0085 DET0029

Adversary uses a tool like Ruler to insert a malicious custom form into the user's Outlook mailbox. The form is designed to auto-execute on Outlook startup or on receipt of a specially crafted email. This results in child processes launched from outlook.exe and possibly network connections or payload loading.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Application WinEventLog:PowerShell
AN0089 Analytic 0089 DET0031

Execution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths.

WinEventLog:Sysmon WinEventLog:Windows Defender WinEventLog:PowerShell
AN0090 Analytic 0090 DET0031

Binaries or applications executed with tampered or unverifiable code signatures. Often tied to Gatekeeper bypasses, App Translocation, or use of unsigned launch daemons by untrusted users.

macos:unifiedlog macos:endpointsecurity fs:fileevents
AN0091 Analytic 0091 DET0032

Suspicious use of attrib.exe or PowerShell commands to set hidden attributes on files/directories. Defender view: processes modifying file attributes to 'hidden' or creating files with ADS (alternate data streams).

WinEventLog:Sysmon WinEventLog:Sysmon
AN0092 Analytic 0092 DET0032

Creation of files or directories with a leading '.' in privileged directories (/etc, /var, /usr/bin). Defender view: monitoring auditd logs for file creations where name begins with '.' and correlated with unusual user/process context.

auditd:FILE auditd:EXECVE
AN0094 Analytic 0094 DET0033

Defenders can observe suspicious replacement or tampering of system accessibility binaries (e.g., utilman.exe, sethc.exe, osk.exe) and anomalous modifications to registry keys used to redirect accessibility programs (such as IFEO keys). Additionally, execution of cmd.exe or other suspicious binaries triggered from the login screen by SYSTEM can be correlated as part of a behavior chain.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0095 Analytic 0095 DET0034

Identifies adversary behavior that launches commands or invokes APIs to enumerate active processes (e.g., tasklist.exe, Get-Process, or CreateToolhelp32Snapshot). Detects execution combined with parent process lineage, network session context, or remote origin.

WinEventLog:Security WinEventLog:Sysmon
AN0096 Analytic 0096 DET0034

Detects execution of common process enumeration utilities (e.g., ps, top, htop) or access to /proc with suspicious ancestry. Correlates command usage with interactive shell context and user role.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0097 Analytic 0097 DET0034

Monitors execution of ps, top, or launchctl with unusual parent processes or from terminal scripts. Also detects AppleScript-based process listing or `system_profiler SPApplicationsDataType` misuse.

macos:unifiedlog macos:osquery
AN0100 Analytic 0100 DET0035

Suspicious processes initiating encrypted HTTPS connections to common web service domains, followed by abnormal data upload behavior or automated posting behavior indicative of C2 bidirectional traffic.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-WinINet
AN0101 Analytic 0101 DET0035

Non-interactive system processes making encrypted HTTPS connections to well-known web services followed by high outbound traffic volume or scripted upload patterns.

auditd:SYSCALL NSM:Flow NSM:Flow
AN0102 Analytic 0102 DET0035

Scripting engines (e.g., osascript, Python) initiating HTTPS requests to social media or content-sharing platforms, paired with automated response handling indicative of two-way communication.

macos:unifiedlog NSM:Connections
AN0105 Analytic 0105 DET0037

Detects unauthorized access to web browser credential stores (e.g., Chrome Login Data, Edge Credential Locker) by processes other than the browser itself. Correlates file reads of credential databases with subsequent API calls to `CryptUnprotectData` or memory inspection attempts.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0107 Analytic 0107 DET0037

Detects abnormal access to Safari credential stores (Keychain-backed) or Chrome/Firefox login databases. Observes processes executing `security dump-keychain` or directly reading credential files in `~/Library/Application Support`. Correlates file access with suspicious process ancestry or unsigned binaries.

macos:unifiedlog macos:unifiedlog
AN0108 Analytic 0108 DET0038

Executables written or modified in installer directories (e.g., %TEMP% subdirectories or Program Files installer paths) followed by execution under elevated context. Defender observes abnormal file replacement activity, process creation by installer processes pointing to attacker-supplied binaries, and unexpected module loads in elevated processes.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0109 Analytic 0109 DET0039

Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs).

WinEventLog:Sysmon WinEventLog:Sysmon
AN0110 Analytic 0110 DET0039

Monitor /var/log/audit/audit.log and DNS resolver logs for repeated failed lookups or connections to high-entropy domain names. Correlate suspicious DNS queries with process lineage (e.g., Python, bash, or unusual system daemons).

auditd:SYSCALL linux:syslog
AN0111 Analytic 0111 DET0039

Inspect unified logs for anomalous DNS resolutions triggered by non-network applications. Flag repeated connections to newly registered or algorithmically generated domains. Correlate with endpoint process telemetry.

macos:unifiedlog macos:unifiedlog
AN0113 Analytic 0113 DET0040

Detects adversary activity that removes persistence artifacts such as services, registry keys, scheduled tasks, user accounts, and binaries through commands like `sc delete`, `schtasks /delete`, or `reg delete`.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:TaskScheduler WinEventLog:Security
AN0114 Analytic 0114 DET0040

Detects removal of persistence artifacts such as crontab entries, systemd service units, and malicious user accounts through commands like `crontab -r`, `rm /etc/systemd/system/*.service`, or `userdel`.

auditd:SYSCALL auditd:SYSCALL
AN0117 Analytic 0117 DET0041

Adversary with write access to storage modifies lifecycle policies (e.g., via PutBucketLifecycle) to schedule rapid object deletion across one or more storage buckets. This is often used to trigger impact (destruction), remove logs (defense evasion), or force extortion (ransomware).

AWS:CloudTrail
AN0118 Analytic 0118 DET0042

Detects abuse of verclsid.exe to execute COM objects by monitoring process creation, CLSID arguments, DLLs or scriptlet engines loaded into memory, and If the CLSID points to remote SCT/HTA content, verclsid.exe makes outbound connections.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0119 Analytic 0119 DET0043

Unusual process or API usage attempting to query system locale, timezone, or keyboard layout (e.g., calls to GetLocaleInfoW, GetTimeZoneInformation). Detection can be enhanced by correlating with processes not typically associated with system configuration queries, such as unknown binaries or scripts.

WinEventLog:Security etw:Microsoft-Windows-Kernel-Base
AN0120 Analytic 0120 DET0043

Detection of commands accessing locale, timezone, or language settings such as 'locale', 'timedatectl', or parsing /etc/timezone. Anomalous execution by unusual users or automation scripts should be flagged.

auditd:SYSCALL linux:Sysmon
AN0121 Analytic 0121 DET0043

Detection of system calls or commands accessing system locale (e.g., 'defaults read -g AppleLocale', 'systemsetup -gettimezone'). Correlate with unusual parent processes or execution contexts.

macos:unifiedlog macos:osquery
AN0122 Analytic 0122 DET0043

Detection of queries to instance metadata services (e.g., AWS IMDS, Azure Metadata Service) for availability zone, region, or network geolocation details. Correlation with non-management accounts or non-standard workloads may indicate adversary reconnaissance.

AWS:CloudTrail azure:vpcflow
AN0123 Analytic 0123 DET0044

Installation of a new browser extension followed by suspicious file writes or outbound network connections to untrusted domains by the browser process.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0124 Analytic 0124 DET0044

Installation of malicious .mobileconfig profiles or browser extension plist entries followed by abnormal browser child process activity.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0125 Analytic 0125 DET0044

Manual or scripted installation of Chrome extensions using user scripts or config files, followed by unexpected network connections from browser processes.

auditd:SYSCALL NSM:Flow auditd:SYSCALL
AN0126 Analytic 0126 DET0045

Inconsistencies between process command-line arguments logged at creation time and subsequent process behavior. Defender perspective: monitoring for processes launched in a suspended state, followed by memory modifications (e.g., WriteProcessMemory targeting the PEB) that overwrite arguments before execution resumes. Detection also includes observing anomalous behaviors from processes whose logged arguments do not align with executed activity (e.g., network connections, file writes, or registry modifications).

WinEventLog:Security WinEventLog:Sysmon
AN0127 Analytic 0127 DET0046

Execution of discovery commands or API calls for virtualization artifacts (e.g., registry keys, device drivers, services), sleep/skipped execution behavior, or sandbox evasion DLLs before payload deployment.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0128 Analytic 0128 DET0046

Execution of commands to enumerate virtualization-related files or processes (e.g., '/sys/class/dmi/id/product_name', dmesg, lscpu, lspci), or querying hypervisor interfaces prior to malware execution.

auditd:SYSCALL auditd:SYSCALL
AN0129 Analytic 0129 DET0046

Execution of scripts or binaries that check for virtualization indicators (e.g., system_profiler, ioreg -l, kextstat), combined with delay functions or anomalous launchd activity.

macos:unifiedlog macos:unifiedlog
AN0130 Analytic 0130 DET0047

Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0133 Analytic 0133 DET0049

Detects attempts to clear RDP/network history and modify network configuration artifacts through command execution, registry key deletion, firewall rule changes, and suspicious file deletions (e.g., Default.rdp, registry edits to Terminal Server Client keys).

WinEventLog:Security WinEventLog:Sysmon EDR:cli WinEventLog:Security
AN0134 Analytic 0134 DET0049

Detects deletion or overwriting of logs/configs that store SSH or proxy activity, such as /var/log/auth.log or custom .bash_history clearing tied to SSH sessions or firewall rule changes.

auditd:SYSCALL auditd:SYSCALL
AN0136 Analytic 0136 DET0049

Detects firewall rule modifications or reset of logs/connection tables (e.g., `clear logging`, `erase startup-config`, `write erase`) following remote access activity on routers, switches, or VPN appliances.

networkdevice:syslog NSM:Flow
AN0137 Analytic 0137 DET0050

An adversary writes or drops a malicious Office Add-in (e.g., WLL, XLL, COM) to a trusted directory or modifies registry keys to load malicious add-ins on Office application launch. Upon user opening Word or Excel, the add-in is automatically loaded, triggering execution of the payload, often spawning scripting engines or anomalous child processes.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0139 Analytic 0139 DET0051

Creation or modification of files in directories known to be excluded from AV scanning (e.g., C:\Windows\Temp, Exchange server directories, or default AV exclusions). Defender perspective: correlate file creation with execution behavior or anomalous parent processes writing to excluded paths.

WinEventLog:Sysmon WinEventLog:Security
AN0140 Analytic 0140 DET0051

Adversaries writing or moving payloads into directories configured as AV/EDR exclusion paths (e.g., /tmp, /var/lib, or custom directories from auditd exclusion rules). Defender perspective: detect file creation in paths matching known exclusions correlated with unusual parent processes.

auditd:SYSCALL auditd:PATH
AN0141 Analytic 0141 DET0051

Suspicious file creation or modification in directories ignored by XProtect or AV exclusions (e.g., ~/Library, temporary cache directories). Defender perspective: monitor file events in ignored paths with correlation to execution or persistence activity.

macos:unifiedlog macos:unifiedlog
AN0144 Analytic 0144 DET0053

Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes.

NSM:Flow
AN0146 Analytic 0146 DET0053

Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.

macos:unifiedlog macos:unifiedlog
AN0147 Analytic 0147 DET0054

Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.

WinEventLog:Security WinEventLog:Security WinEventLog:Security m365:unified WinEventLog:Sysmon
AN0148 Analytic 0148 DET0054

Delivery of suspicious internal communication (e.g., Thunderbird, Evolution) using compromised internal accounts. Sequence of: unexpected user activity + mail transfer logs + download or execution of attachments.

auditd:SYSCALL Application:Mail linux:syslog
AN0149 Analytic 0149 DET0054

Abnormal Apple Mail use, including internal email relays followed by file execution or script events (e.g., attachments launched via Preview, terminal triggered from Mail.app)

macos:unifiedlog macos:unifiedlog
AN0152 Analytic 0152 DET0055

Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell NSM:Flow
AN0153 Analytic 0153 DET0056

Detection of unauthorized modifications to Windows root certificate stores by monitoring registry keys, certificate installation processes, and creation of new certificate entries not in baseline trusted lists.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0156 Analytic 0156 DET0057

Detects suspicious memory access attempts targeting the `securityd` process. Observes tools invoking process memory read operations (e.g., ptrace, task_for_pid) against `securityd`. Correlates with anomalous parent process lineage, root privilege escalation, or repeated unauthorized attempts.

macos:unifiedlog macos:unifiedlog
AN0158 Analytic 0158 DET0058

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

WinEventLog:Sysmon etw:Microsoft-Windows-NDIS-PacketCapture
AN0159 Analytic 0159 DET0058

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

auditd:SYSCALL NSM:Flow
AN0160 Analytic 0160 DET0058

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

macos:unifiedlog macos:osquery
AN0162 Analytic 0162 DET0059

Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0163 Analytic 0163 DET0059

Detect unauthorized manipulation of log files, database entries, or system configuration files through auditd and syslog. Correlate shell commands that alter HISTFILE or data-related processes with abnormal file access patterns.

auditd:SYSCALL linux:syslog
AN0165 Analytic 0165 DET0060

Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded).

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0166 Analytic 0166 DET0060

Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk.

auditd:SYSCALL auditd:SYSCALL iptables:LOG
AN0167 Analytic 0167 DET0060

Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories.

macos:endpointsecurity macos:unifiedlog macos:unifiedlog
AN0168 Analytic 0168 DET0060

Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories.

esxi:hostd esxi:vmkernel
AN0169 Analytic 0169 DET0060

Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks.

NSM:Flow snmp:syslog
AN0170 Analytic 0170 DET0061

Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript).

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0172 Analytic 0172 DET0063

Detects Python execution via python.exe or py.exe with anomalous parent lineage (e.g., Office macros, LOLBAS), execution from unusual directories, or chained network/PowerShell/system-level activity.

WinEventLog:Sysmon EDR:hunting
AN0173 Analytic 0173 DET0063

Detects native Python or framework-based execution from Terminal, embedded apps, or launchd jobs. Flags network calls, persistence writes, or system enumeration after Python launch.

macos:unifiedlog macos:osquery macos:syslog
AN0174 Analytic 0174 DET0063

Detects Python execution from non-standard user contexts or cron jobs that invoke outbound traffic, access sensitive files, or perform process injection (e.g., ptrace or /proc memory maps).

auditd:SYSCALL linux:syslog
AN0175 Analytic 0175 DET0063

Detects Python script or interpreter execution on ESXi hosts via embedded BusyBox shells, nested installations, or dropped files via SSH or datastore mount. Flags unusual scripting or post-compromise enumeration behavior.

esxi:vobd esxi:hostd
AN0176 Analytic 0176 DET0064

Unquoted service or shortcut paths that contain spaces and allow path interception by higher-level executables. Defender observes registry service configurations with unquoted paths, file creation of executables in parent directories of unquoted paths, and subsequent process execution from unexpected locations.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0177 Analytic 0177 DET0065

Defenders may detect abuse of container administration commands by observing anomalous use of management utilities (`docker exec`, `kubectl exec`, or API calls to kubelet) correlated with unexpected process creation inside containers. Behavioral chains include unauthorized API requests followed by command execution within running pods or containers, often originating from unusual user accounts, automation scripts, or IP addresses outside the expected cluster management plane.

docker:daemon kubernetes:apiserver
AN0178 Analytic 0178 DET0066

Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0179 Analytic 0179 DET0066

Behavioral chain: (1) browser/office/GUI mail client opens a URL, (2) outbound connection to untrusted domain, (3) a new file is saved in $HOME/Downloads, /tmp, or cache immediately after.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN0180 Analytic 0180 DET0066

Behavioral chain: (1) Safari/Chrome/Firefox/Office handles a URL; unified logs show open/click or LSQuarantine assignment, (2) outbound connection to untrusted domain, (3) a new file appears in ~/Downloads or /private/var/folders/* with quarantine flag.

macos:unifiedlog NSM:Connections fs:fsevents
AN0181 Analytic 0181 DET0067

Execution of processes using nohup or shell redirection to ignore SIGHUP and continue running after session termination. Defender perspective: correlation between commands including nohup, disowned jobs, or `&` suffix with continued process execution after parent terminal exit.

auditd:SYSCALL auditd:SYSCALL
AN0182 Analytic 0182 DET0067

PowerShell or script execution with parameters that suppress errors or ignore user interrupts, such as `-ErrorAction SilentlyContinue`. Defender perspective: detecting discrepancies between suppressed error arguments and continued execution behavior.

WinEventLog:PowerShell WinEventLog:Sysmon
AN0183 Analytic 0183 DET0067

Use of nohup, disown, or AppleScript constructs to suppress process interrupts. Defender perspective: commands containing nohup or hidden background tasks (`osascript` with persistent execution) correlated with processes surviving user logouts.

macos:unifiedlog macos:unifiedlog
AN0184 Analytic 0184 DET0068

Adversary installs or modifies IIS components (ISAPI filters, extensions, or modules) using DLL files registered via configuration changes or administrative tools like AppCmd.exe. These components intercept or manipulate HTTP requests/responses for persistence or C2.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System WinEventLog:Microsoft-IIS-Configuration
AN0185 Analytic 0185 DET0069

Chain: (1) a new external device is recognized by Windows (USB/Thunderbolt/PCIe) or a new block device appears; (2) within a short window, the same user/session spawns processes or the OS mounts a new volume; (3) optional follow-on activity such as HID keystroke injection, DMA driver load, or new network interface MAC on DHCP. Correlate Security EID 6416 / Kernel-PnP with sysmon and DHCP/network metadata.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System wineventlog:dhcp
AN0186 Analytic 0186 DET0069

Chain: (1) udev / kernel logs show hot-plug (USB/Thunderbolt/PCIe); (2) block device created by udisks/diskarbitration; (3) optional: new network interface or DHCP lease observed. Correlate /var/log/messages|syslog, auditd SYSCALL open/creat on /dev, and DHCP/Zeek.

auditd:SYSCALL linux:syslog NSM:Flow
AN0187 Analytic 0187 DET0069

Chain: (1) unified logs report IOUSBHost/IOThunderbolt device arrival; (2) diskarbitrationd attaches a new volume; (3) optional: config profile manipulation or new network interface MAC obtains a lease. Correlate unifiedlogs (subsystems: IOUSBHost, IOKit, diskarbitrationd), FSEvents, and DHCP/Zeek.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0188 Analytic 0188 DET0070

Unusual inbound email activity where attachments or embedded URLs are delivered to users followed by execution of new processes or suspicious document behavior. Detection involves correlating email metadata, file creation, and network activity after a phishing message is received.

m365:unified WinEventLog:Sysmon WinEventLog:Sysmon
AN0189 Analytic 0189 DET0070

Monitor for malicious payload delivery through phishing where attachments or URLs in email clients (e.g., Thunderbird, mutt) result in unusual file creation or outbound network connections. Focus on correlation between mail logs, file writes, and execution activity.

Application:Mail auditd:SYSCALL
AN0190 Analytic 0190 DET0070

Detection of phishing through anomalous Mail app activity, such as attachments saved to disk and immediately executed, or Safari/Preview launching URLs and files linked from email messages. Correlate UnifiedLogs events with subsequent process execution.

macos:unifiedlog macos:unifiedlog
AN0191 Analytic 0191 DET0070

Phishing via Office documents containing embedded macros or links that spawn processes. Detection relies on correlating Office application logs with suspicious child process execution and outbound network connections.

m365:unified WinEventLog:Sysmon
AN0194 Analytic 0194 DET0071

Detects file transfers or mounting operations from remote hosts followed by write actions into a local staging directory, often using SMB or remote shell activity.

WinEventLog:Sysmon WinEventLog:Microsoft-Windows-SMBClient/Security WinEventLog:PowerShell
AN0195 Analytic 0195 DET0071

Detects inbound SCP, rsync, or NFS mounts from remote systems followed by aggregation of files into known staging paths like /mnt/staging or /var/tmp.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN0196 Analytic 0196 DET0071

Detects rsync or scp inbound from other hosts that then aggregate content into /Users/Shared or /private/tmp, often involving compressed files or scripts.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0197 Analytic 0197 DET0071

Detects remote writes or snapshots mounted from other systems into a central ESXi VMFS path or NFS store used for remote staging of files before exfiltration.

esxi:vmkernel esxi:vob esxi:shell
AN0198 Analytic 0198 DET0071

Detects remote write activity across cloud VMs or object storage buckets within the same region/account that correlate with data aggregation across hosts.

AWS:CloudTrail AWS:VPCFlowLogs esxi:hostd
AN0199 Analytic 0199 DET0072

Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context.

WinEventLog:Security WinEventLog:System WinEventLog:Security WinEventLog:Security
AN0200 Analytic 0200 DET0073

Abuse of systemctl to execute commands or manage systemd services. Defender perspective: correlate suspicious service creation or modification with execution of systemctl subcommands such as start, enable, or status. Detect cases where systemctl is used to load services from unusual locations (e.g., /tmp, /dev/shm) or where new service units are created outside of expected administrative workflows.

auditd:EXECVE auditd:SYSCALL auditd:EXECVE auditd:CONFIG_CHANGE
AN0204 Analytic 0204 DET0075

Anomalous process (e.g., `rundll32`, `svchost`, `cmd`) initiates connections to internal peer hosts not seen in typical communication baselines, used to proxy or forward traffic internally, often using SMB, RPC, or high ports.

WinEventLog:Sysmon WinEventLog:Sysmon Windows Firewall Log
AN0205 Analytic 0205 DET0075

`socat`, `ssh`, `iptables`, or `ncat` invoked from user space or cron jobs to create port forwarding, reverse shells, or inter-host tunnels between compromised Linux systems. Behavior is typically paired with socket activity and high entropy traffic.

auditd:SYSCALL NSM:Connections NSM:Flow
AN0206 Analytic 0206 DET0075

Execution of AppleScript or Automator services launching `ssh -L`, `socat`, or `launchctl` items that dynamically reroute traffic from one Mac endpoint to another. LaunchAgents used to establish permanent internal tunnels.

macos:unifiedlog NSM:Flow macos:osquery
AN0207 Analytic 0207 DET0075

ESXi shell execution of tools/scripts (`nc`, `socat`, `perl`) relaying network traffic to other internal hosts, especially when initiated by unauthorized users or VMs.

esxi:shell esxi:vmkernel NSM:Flow
AN0209 Analytic 0209 DET0076

Detects execution of VB-based scripts or macros (VBS/VBA/VBScript) through cscript.exe/wscript.exe, Office-based process chains, or HTA usage. Focuses on chained behavior: Office or HTML container spawns script host > script host spawns PowerShell, network connections, or process injection.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0210 Analytic 0210 DET0076

Detects embedded or emulated VBScript/VBA execution via Wine-based apps, Office for Mac abusing cross-platform .NET features, or macros dropped and invoked via AppleScript or third-party automation tools.

macos:unifiedlog macos:osquery macos:syslog
AN0211 Analytic 0211 DET0076

Detects abuse of Mono/.NET Core environments to execute VB-like scripts, often in environments with Office emulation or WINE. Focus is on rare invocations of scripting hosts like mono.exe or .NET shells, often seen in spam filtering or forensic labs with Office support.

auditd:SYSCALL linux:syslog
AN0212 Analytic 0212 DET0077

Execution of file transfer or network access activity through non-primary interfaces (e.g., WiFi, Bluetooth, cellular) by processes not typically associated with such behavior (e.g., rundll32, powershell, regsvr32).

WinEventLog:Sysmon WinEventLog:System WinEventLog:Sysmon
AN0214 Analytic 0214 DET0077

AppleScript or system calls to activate WiFi/Bluetooth interfaces (`networksetup`, `blueutil`), followed by exfiltration via AirDrop, cloud sync, or network socket.

macos:unifiedlog macos:osquery macos:osquery
AN0216 Analytic 0216 DET0079

Detection of anomalous RDP or remote service session activity where a logon session is hijacked rather than newly created. Indicators include mismatched user credentials vs. active session tokens, service session takeovers without corresponding successful logon events, or RDP shadowing activity without user consent.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0218 Analytic 0218 DET0079

Detection of hijacked VNC or SSH sessions on macOS where adversaries take over an existing session rather than authenticating directly. Indicators include process execution from active sessions without new logon events, manipulation of TTY sessions, or anomalous network activity tied to dormant sessions.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0219 Analytic 0219 DET0080

Adversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container.

ApplicationLog:IIS WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0220 Analytic 0220 DET0080

Adversary exploits Apache/Nginx/app servers. Chain: (1) suspicious requests in access logs → (2) spike of 5xx or WAF blocks → (3) web server or interpreter (apache2/nginx/php-fpm/node/python) spawns /bin/sh, curl, wget, socat, or writes webshell → (4) outbound callback.

ApplicationLog:WebServer auditd:SYSCALL NSM:Flow
AN0221 Analytic 0221 DET0080

Adversary targets macOS-hosted public services (e.g., nginx, node). Chain: suspicious inbound request → service crash/5xx → service spawns shell or writes file → new outbound connection.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0222 Analytic 0222 DET0080

Adversary exploits containerized app via ingress or service. Chain: (1) suspicious request in ingress/app logs → (2) container process spawns a shell/exec/sidecar (kubectl exec/docker exec) → (3) egress to Internet or metadata service (169.254.169.254).

ApplicationLog:Ingress docker:events NSM:Flow
AN0223 Analytic 0223 DET0080

Adversary targets cloud-hosted public endpoints. Chain: (1) ALB/ELB/Cloud LB logs show exploit-like inputs or error spikes → (2) workload spawns shell or reaches metadata API → (3) egress to new external hosts.

ALB:HTTPLogs AWS:VPCFlowLogs
AN0224 Analytic 0224 DET0080

Adversary exploits exposed OpenSLP on ESXi or vCenter public endpoints. Chain: inbound request pattern to mgmt service → hostd/vpxd error/crash/restart → unexpected process behavior or datastore access → outbound callback.

esxi:hostd NSM:Flow
AN0225 Analytic 0225 DET0080

Adversary exploits public admin services on routers/firewalls/switches. Chain: anomalous HTTP/SNMP/SmartInstall inputs → device syslog errors/restarts → config changes/CLI spawn → egress to attacker C2.

networkdevice:controlplane NSM:Flow
AN0226 Analytic 0226 DET0081

Execution of trusted, Microsoft-signed binaries such as `rundll32.exe`, `msiexec.exe`, or `regsvr32.exe` used to execute externally hosted, unsigned, or suspicious payloads through command-line parameters or network retrieval.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0227 Analytic 0227 DET0081

Execution of trusted system binaries (e.g., `split`, `tee`, `bash`, `env`) used in uncommon sequences or chained behaviors to execute malicious payloads or perform actions inconsistent with normal system or script behavior.

auditd:SYSCALL auditd:SYSCALL
AN0228 Analytic 0228 DET0081

Use of system binaries such as `osascript`, `bash`, or `curl` to download or execute unsigned code or files in conjunction with application proxying.

macos:unifiedlog macos:osquery
AN0229 Analytic 0229 DET0082

Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0230 Analytic 0230 DET0082

Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity.

auditd:SYSCALL auditd:SYSCALL linux:syslog
AN0233 Analytic 0233 DET0083

Execution of container orchestration commands (e.g., `docker exec`, `kubectl exec`) or API-driven interactions with running containers from unauthorized hosts or non-standard user contexts. Defender sees programmatic or interactive command execution within containers outside expected CI/CD tools or automation frameworks, often followed by file writes, privilege escalation, or lateral discovery.

auditd:SYSCALL docker:events kubernetes:apiserver AWS:CloudTrail kubernetes:audit
AN0235 Analytic 0235 DET0085

An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\SAM, HKLM\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0236 Analytic 0236 DET0086

Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of `mofcomp.exe`, usage of `Register-WmiEvent` via PowerShell, and anomalous child processes of `WmiPrvSE.exe` that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels.

WinEventLog:WMI WinEventLog:Sysmon WinEventLog:Sysmon
AN0237 Analytic 0237 DET0087

Detection of processes that load or decode encrypted/encoded files in memory and subsequently execute or inject them, indicating payload unpacking or memory-resident malware.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0238 Analytic 0238 DET0087

Detection of suspicious use of shell utilities or scripts that decode or decrypt a payload and execute it without writing to disk.

auditd:SYSCALL linux:Sysmon
AN0239 Analytic 0239 DET0087

Detection of encoded payloads being decoded and executed in-memory using scripting tools or third-party decoders.

macos:unifiedlog macos:endpointsecurity macos:unifiedlog
AN0240 Analytic 0240 DET0088

Defender observes execution of commands like `tasklist`, `sc query`, `reg query`, or PowerShell WMI/Registry queries targeting known backup products (e.g., Veeam, Acronis, CrashPlan). Behavior often includes parent-child lineage involving PowerShell or cmd.exe with discovery syntax, and enumeration of services, directories, or registry paths tied to backup software.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0241 Analytic 0241 DET0088

Defender observes use of CLI tools (`find`, `grep`, `ls`, `dpkg`, `rpm`, `systemctl`, `ps aux`) to discover backup agents or config files (e.g., rsnapshot, duplicity, veeam). This often includes command lines that recursively search `/etc/`, `/opt/`, or `/var/` directories for keywords like `backup`, and parent-child relationships involving shell or Python scripts.

auditd:SYSCALL auditd:PATH
AN0242 Analytic 0242 DET0088

Defender detects execution of `mdfind`, `launchctl`, or GUI-based enumeration (e.g., `/Applications/Time Machine.app`) along with command-line usage of `find`, `grep`, or `system_profiler` to identify installed backup tools like Time Machine, Carbon Copy Cloner, or Backblaze. Often triggered from Terminal sessions or within post-exploitation scripts.

macos:unifiedlog macos:unifiedlog
AN0245 Analytic 0245 DET0089

Detects unauthorized TCC access or use of Quartz Event Services (CGEventTapCreate) or IOHID for event tap installation within unexpected processes.

macos:unifiedlog macos:osquery
AN0246 Analytic 0246 DET0089

Keylogging on legacy network devices via unauthorized system image modification or remote capture of console keystrokes (telnet, SSH) through altered firmware or man-in-the-middle key sniffing.

networkdevice:syslog NSM:Flow
AN0247 Analytic 0247 DET0090

Behavioral sequence where removable media is mounted, files are written/updated, and subsequently read/executed on a separate host, suggesting removable-media relay communication.

WinEventLog:System WinEventLog:Sysmon WinEventLog:Sysmon
AN0248 Analytic 0248 DET0090

Detection of file write-access to USB-mount directories (e.g., /media/, /run/media/) followed by same-file access or execution on another host.

auditd:SYSCALL auditd:SYSCALL
AN0249 Analytic 0249 DET0090

Correlates removable volume mounts (disk arbitration) with file I/O events on that volume, followed by same file execution shortly after insert.

macos:unifiedlog fs:fsusage
AN0250 Analytic 0250 DET0091

Behavioral chain involving suspicious use of GetProcAddress and LoadLibrary following memory allocation and manual mapping, often paired with low entropy strings, abnormal API use without static import tables, or delayed module load behaviors.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN0251 Analytic 0251 DET0092

Installation or execution of a malicious browser or IDE extension, followed by abnormal registry entries or outbound network connections from the host application

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0252 Analytic 0252 DET0092

Installation of configuration profiles or plist entries associated with malicious or unauthorized browser extensions

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0253 Analytic 0253 DET0092

Manual or script-based installation of extension-like modules into browser config directories or IDE plugin paths, followed by suspicious network activity

auditd:SYSCALL fs:fileevents NSM:Flow
AN0254 Analytic 0254 DET0093

Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell).

WinEventLog:Sysmon WinEventLog:PowerShell
AN0255 Analytic 0255 DET0093

Adversary runs commands like `whoami`, `id`, `w`, or `cat /etc/passwd` from non-interactive or scripting contexts to enumerate system user details.

auditd:SYSCALL
AN0256 Analytic 0256 DET0093

Adversary uses `dscl`, `who`, or environment variables like `$USER` to identify accounts or sessions via Terminal or malicious LaunchAgents.

macos:unifiedlog macos:endpointsecurity
AN0258 Analytic 0258 DET0094

Detects creation or modification of scheduled tasks using schtasks.exe, at.exe, or COM objects followed by execution of outlier processes tied to the scheduled job.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0259 Analytic 0259 DET0094

Detects creation or modification of cron jobs via crontab, /etc/cron.* directories, or systemd timer units with execution by unusual users or non-standard intervals.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0260 Analytic 0260 DET0094

Detects creation or alteration of LaunchAgents or LaunchDaemons with corresponding plist modification followed by execution of associated binaries.

macos:unifiedlog fs:fsusage macos:osquery
AN0261 Analytic 0261 DET0094

Detects unusual use of `cron` or `sleep` loops inside containers executing unfamiliar scripts or binaries repeatedly.

auditd:SYSCALL containerd:runtime
AN0263 Analytic 0263 DET0095

Adversary uses a tool like Ruler or MFCMapi to create a malicious Outlook rule that triggers execution upon receipt of a crafted email. On email delivery, Outlook executes the rule, resulting in code execution (e.g., launching mshta.exe or PowerShell). Outlook spawns a non-standard child process, often unsanctioned, without user interaction.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Application WinEventLog:PowerShell
AN0265 Analytic 0265 DET0096

Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts.

WinEventLog:Security WinEventLog:Sysmon
AN0272 Analytic 0272 DET0097

Scripted or binary usage of X11 utilities (e.g., xdotool, wmctrl) or direct /proc/*/window mappings to discover open GUI windows and active desktops.

auditd:EXECVE linus:syslog
AN0273 Analytic 0273 DET0097

Processes that utilize AppleScript, `CGWindowListCopyWindowInfo`, or `NSRunningApplication` APIs to list active application windows and foreground processes.

macos:unifiedlog macos:osquery
AN0274 Analytic 0274 DET0098

Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:System
AN0275 Analytic 0275 DET0099

Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0277 Analytic 0277 DET0100

Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process WinEventLog:Sysmon
AN0278 Analytic 0278 DET0101

Detects execution of Lua interpreters or scripts (.lua), especially when correlated with suspicious parent processes or file drop events, indicating malicious use of embedded scripting.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0279 Analytic 0279 DET0101

Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts.

auditd:SYSCALL auditd:SYSCALL
AN0284 Analytic 0284 DET0102

Monitors for TCC-bypassing or unauthorized access to input services like IOHIDSystem or Quartz Event Services used in keylogging or screen monitoring.

macos:unifiedlog macos:osquery
AN0285 Analytic 0285 DET0102

Detects web-based credential phishing by analyzing traffic to suspicious URLs that mimic login portals and POST credential content.

NSM:Flow NSM:Firewall
AN0286 Analytic 0286 DET0103

Detects network share disconnection attempts using command-line tools like `net use /delete`, PowerShell `Remove-SmbMapping`, and correlation with process lineage and SMB session teardown activity.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell NSM:Flow
AN0288 Analytic 0288 DET0104

Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries.

auditd:SYSCALL auditd:SYSCALL
AN0292 Analytic 0292 DET0105

Use of hash-cracking tools (e.g., John the Ripper, Hashcat) after credential dumping, combined with high CPU usage or GPU invocation via unsigned binaries accessing password hash files

WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0293 Analytic 0293 DET0105

Execution of hash cracking binaries or scripts (e.g., john, hashcat) following access to shadow file or dumped hashes

auditd:SYSCALL linux:syslog
AN0294 Analytic 0294 DET0105

Unsigned or scripting-based processes invoking password cracking binaries or accessing hashed credential artifacts post-login

macos:unifiedlog
AN0297 Analytic 0297 DET0106

Detects PE injection through a behavioral sequence where one process opens (OpenProcess) a handle to another, allocates remote memory (VirtualAllocEx), writes a PE header (MZ) or shellcode (WriteProcessMemory), then initiates a new thread (CreateRemoteThread or NtCreateThreadEx) in that process—executing injected code in memory without touching disk. Optional: injects a trampoline or shellcode that unpacks/reflectively maps the payload.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0298 Analytic 0298 DET0107

Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity.

m365:unified WinEventLog:Security WinEventLog:Sysmon
AN0299 Analytic 0299 DET0107

Detection of spearphishing links through mail logs and browser activity. Behavior includes email with suspicious URLs → user click recorded in mail/web proxy logs → shell or interpreter launched from browser process.

Application:Mail auditd:SYSCALL NSM:Flow
AN0300 Analytic 0300 DET0107

Correlation of Mail.app logs with Safari/Chrome activity. Suspicious behavior includes email links → Safari/Chrome accessing newly registered or lookalike domains → osascript or Terminal spawned unexpectedly.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0302 Analytic 0302 DET0108

Atypical processes (e.g., powershell.exe, regsvr32.exe) encode large outbound traffic using Base64 or other character encodings; this traffic is sent over uncommon ports or embedded in protocol fields (e.g., HTTP cookies or headers).

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0303 Analytic 0303 DET0108

Custom scripts or processes encode outbound traffic using gzip, Base64, or hex prior to exfiltration via curl, wget, or custom sockets. Encoding typically occurs before or during outbound connections from non-network daemons.

auditd:SYSCALL NSM:Flow linux:syslog
AN0304 Analytic 0304 DET0108

Processes use built-in encoding utilities (e.g., `base64`, `xxd`, or `plutil`) to encode file contents followed by HTTP/HTTPS transfer via curl or custom applications.

macos:unifiedlog macos:unifiedlog
AN0305 Analytic 0305 DET0108

ESXi daemons (e.g., hostd, vpxa) are wrapped or impersonated to send large outbound traffic using gzip/Base64 encoding over SSH or HTTP. These actions follow suspicious logins or shell access.

esxi:shell esxi:vmkernel ESXiLogs:authlog
AN0306 Analytic 0306 DET0109

Monitor for unexpected modifications of plist files in persistence or configuration directories (e.g., ~/Library/LaunchAgents, ~/Library/Preferences, /Library/LaunchDaemons). Detect when modifications are followed by execution of new or unexpected binaries. Track use of utilities such as defaults, plutil, or text editors making changes to Info.plist files. Correlate file modifications with subsequent process launches or service starts that reference the altered plist.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0307 Analytic 0307 DET0110

Correlation of chmod operations setting setuid/setgid bits followed by privileged process execution (EUID != UID), especially from user-writable or abnormal paths.

auditd:SYSCALL auditd:SYSCALL
AN0311 Analytic 0311 DET0112

Monitoring modification and execution of user or system logon scripts such as in registry Run keys or startup folders.

WinEventLog:Security WinEventLog:Security WinEventLog:TaskScheduler
AN0312 Analytic 0312 DET0112

Detection of changes or execution of shell initialization scripts like .bashrc, .profile, or /etc/profile for persistence.

auditd:SYSCALL auditd:PATH linux:osquery
AN0316 Analytic 0316 DET0113

Detects AS-REP roasting attempts by monitoring for Kerberos AS-REQ/AS-REP authentication patterns where preauthentication is disabled (Event ID 4768 with Pre-Auth Type 0). Correlates these requests with subsequent service ticket activity (Event ID 4769) and anomalies such as requests using weak RC4 encryption (etype 0x17). Excessive enumeration of accounts with 'Do not require Kerberos preauthentication' set in Active Directory is another key detection point.

WinEventLog:Security WinEventLog:Sysmon
AN0317 Analytic 0317 DET0114

Detects attempts to enumerate local groups via Net.exe, PowerShell, or native API calls that precede lateral movement or privilege abuse.

WinEventLog:Security
AN0318 Analytic 0318 DET0114

Detects enumeration of local groups using common binaries (groups, getent, cat /etc/group) or scripting with suspicious lineage.

auditd:SYSCALL
AN0319 Analytic 0319 DET0114

Detects use of dscl or id/group commands to enumerate local system groups, often by post-exploitation tools or persistence checks.

macos:unifiedlog
AN0320 Analytic 0320 DET0115

Inbound spearphishing attempts delivered via third-party services (e.g., Gmail, LinkedIn messages) leading to malicious file downloads or browser-initiated script execution. Defender view includes correlation of external service logins, unexpected file write operations, and suspicious descendant processes spawned from productivity or browser applications.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0321 Analytic 0321 DET0115

Use of non-enterprise email or messaging services in Thunderbird, Evolution, or browsers leading to suspicious file downloads and subsequent execution. Defender view includes browser-initiated downloads of unexpected content and shell or interpreter processes launched post-download.

auditd:SYSCALL linux:syslog NSM:Flow
AN0322 Analytic 0322 DET0115

Phishing attempts via iCloud Mail, Gmail, or social media apps accessed on macOS systems. Defender view includes Mail.app or Safari downloads of files followed by osascript, Terminal, or abnormal child process execution.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0323 Analytic 0323 DET0116

Abuse of safe mode via BCD modification, boot configuration utilities (bcdedit.exe, bootcfg.exe), and registry persistence under SafeBoot keys. Defender view: suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0324 Analytic 0324 DET0117

Creation or modification of Windows services or scheduled tasks with names or descriptions mimicking legitimate entries, followed by anomalous execution of untrusted binaries or LOLBAS.

WinEventLog:System WinEventLog:Security WinEventLog:Sysmon
AN0326 Analytic 0326 DET0117

Creation of LaunchAgents or LaunchDaemons with names resembling known system services but executing non-Apple signed code or scripts.

fs:fileevents macos:endpointsecurity macos:unifiedlog
AN0327 Analytic 0327 DET0118

Correlates inbound network access to remote service ports (e.g., SMB/RPC 445/135, RDP 3389, WinRM 5985/5986) with near-time instability in the target service (crash, abnormal restart), suspicious child process creation under the service, and post-access lateral-movement behaviors. The chain indicates likely exploitation rather than normal administration.

WinEventLog:System WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0328 Analytic 0328 DET0118

Links inbound network access to SSHD/SMB/NFS/Databases or custom daemons with subsequent daemon crash/restart, core dump, or spawning of shells/reverse shells from the service context, indicating remote exploitation.

linux:syslog auditd:SYSCALL NSM:Flow
AN0329 Analytic 0329 DET0118

Detects exploitation targeting ESXi/vCenter by correlating attempts to reach known exploitable endpoints (OpenSLP 427, CIM 5989, Hostd/Vpxa HTTPS 443, ESXi SOAP) with vmkernel/hostd crashes, unexpected hostd/vpxa restarts, or new reverse/outbound connections from ESXi host/vCenter to internal assets.

esxi:hostd NSM:Flow
AN0330 Analytic 0330 DET0118

Ties inbound access to exposed services (ARD/VNC 5900, SSH 22, ScreenSharing, web services) with process crashes in unified logs and abnormal child processes spawned under those services (e.g., bash, curl) to indicate exploitation.

macos:unifiedlog macos:osquery NSM:Flow
AN0331 Analytic 0331 DET0119

Detects execution of image viewers or PowerShell scripts accessing or decoding files with mismatched MIME headers or embedded script-like byte patterns; often correlated with suspicious parent-child process lineage and outbound connections.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0332 Analytic 0332 DET0119

Detects access to media files followed by execution of scripts (bash, Python, etc.) referencing those same files, or outbound traffic triggered shortly after file read. Correlates unusual use of tools like `steghide`, `exiftool`, or image libraries.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0333 Analytic 0333 DET0119

Detects manipulation of PNG, JPG, or GIF files by user-initiated scripts followed by script execution or exfiltration behavior, especially from `osascript`, `python`, or `bash`, in combination with LaunchAgent persistence or curl activity.

macos:osquery macos:osquery macos:unifiedlog
AN0334 Analytic 0334 DET0120

Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users.

WinEventLog:Security WinEventLog:Sysmon
AN0335 Analytic 0335 DET0120

Password changes or account deletions via 'passwd', 'userdel', or 'chage' preceded by interactive shell or remote command execution from non-privileged accounts.

auditd:SYSCALL NSM:Connections
AN0340 Analytic 0340 DET0121

Creation or modification of Login Items using AppleScript or Service Management Framework. Detection focuses on file creation/modification of `backgrounditems.btm`, new executables in `Contents/Library/LoginItems/`, use of `SMLoginItemSetEnabled` API, or suspicious processes triggered post-login without user interaction. Behavioral pivot includes anomalous AppleEvents, suspicious parent-child process pairs, and login-triggered execution chains.

macos:unifiedlog macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0341 Analytic 0341 DET0122

Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0342 Analytic 0342 DET0123

Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:System
AN0343 Analytic 0343 DET0123

Detects mounted external devices (via /media or /mnt) followed by large file read or copy operations by shell scripts, unauthorized users, or staging tools (e.g., tar, rsync).

auditd:SYSCALL auditd:SYSCALL
AN0344 Analytic 0344 DET0123

Detects mounting of external volumes followed by high-volume or sensitive file access via Finder, terminal, or third-party apps (e.g., rsync, zip).

macos:unifiedlog macos:osquery fs:fsusage
AN0345 Analytic 0345 DET0124

Process invokes a standard encoder (e.g., PowerShell -enc, certutil -encode, base64 via .NET/Invoke-Expression) or emits long Base64/hex literals → shortly followed by outbound network egress with high bytes_out:bytes_in ratio or HTTP headers/payloads containing Base64/MIME blocks.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell M365Defender:DeviceNetworkEvents
AN0346 Analytic 0346 DET0124

Shell/utility (base64, xxd -p, od, openssl enc -base64, python/perl base64 libraries) encodes data → subsequent outbound connections (curl/wget/bash TCP, socat, python requests) with high asymmetry or Base64/MIME blobs in HTTP/DNS payloads.

auditd:SYSCALL WinEventLog:Sysmon NSM:Flow
AN0347 Analytic 0347 DET0124

Processes use base64/xxd/openssl/python Objective‑C APIs to encode data (seen in EndpointSecurity exec events or Unified Logs) → quick outbound connections with large bytes_out or HTTP POSTs carrying Base64/MIME bodies.

macos:unifiedlog PF:Logs NSM:Flow
AN0348 Analytic 0348 DET0124

ESXi shell (BusyBox) or VMware utilities (openssl, python if present) used to Base64/hex encode data from datastore or config files → followed by abnormal egress from the host (NSX/flow logs) with asymmetric bytes_out or HTTPS posts to non-management endpoints.

esxi:shell esxi:hostd NSX:FlowLogs NSM:Flow
AN0349 Analytic 0349 DET0125

Unusual modification or creation of loginwindow-related plist files in '~/Library/Preferences/ByHost' correlated with unauthorized application paths and execution upon login.

macos:unifiedlog fs:filesystem macos:unifiedlog macos:endpointsecurity
AN0350 Analytic 0350 DET0126

Adversary attempts to gain persistence by modifying ~/.ssh/authorized_keys via shell, text editor, echo or redirected output.

auditd:SYSCALL auditd:SYSCALL
AN0351 Analytic 0351 DET0126

Insertion of public keys into authorized_keys using bash/zsh or editor tools, correlated with suspicious process ancestry.

macos:unifiedlog macos:auth
AN0355 Analytic 0355 DET0127

Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage.

WinEventLog:Sysmon WinEventLog:System
AN0356 Analytic 0356 DET0127

Adversary drops renamed binaries in uncommon directories (e.g., /tmp, /dev/shm) or uses special characters in names (e.g., trailing space, Unicode RLO). Execution or cronjob registration follows shortly after file drop.

auditd:SYSCALL linux:syslog linux:osquery
AN0357 Analytic 0357 DET0127

Adversary creates disguised launch daemons or apps with misleading names and bundle metadata (e.g., Info.plist values inconsistent with binary path or icon). Launch is correlated with user logon or persistence setup.

macos:unifiedlog macos:endpointsecurity fs:fileevents
AN0358 Analytic 0358 DET0127

Adversary uses renamed container images, injects files into containers with misleading names or metadata (e.g., renamed system binaries), and executes them during startup or scheduled jobs.

containerd:runtime docker:events ebpf:syscalls
AN0360 Analytic 0360 DET0128

Suspicious use of scripting parameters or registry edits to hide process windows (e.g., powershell.exe -WindowStyle Hidden, or registry modifications pushing window positions off screen). Defender view: correlation of hidden execution with anomalous process lineage or hVNC-like CreateDesktop API calls.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0362 Analytic 0362 DET0128

Modification of plist files to set apple.awt.UIElement or similar flags hiding app icons and windows, and dscl/command-line activity that suppresses visibility. Defender view: correlation of plist modifications with unexpected hidden user applications.

macos:unifiedlog macos:unifiedlog
AN0363 Analytic 0363 DET0129

Adversary enumeration of domain accounts using net.exe, PowerShell, WMI, or LDAP queries from non-domain controllers or non-admin endpoints.

WinEventLog:Sysmon WinEventLog:PowerShell NSM:Flow
AN0364 Analytic 0364 DET0129

Domain account enumeration using ldapsearch, samba tools (e.g., 'wbinfo -u'), or winbindd lookups.

auditd:SYSCALL linuxsyslog NSM:Flow
AN0365 Analytic 0365 DET0129

Domain group and user enumeration via dscl or dscacheutil, or queries to directory services from non-admin endpoints.

macos:unifiedlog macos:unifiedlog
AN0367 Analytic 0367 DET0131

Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0368 Analytic 0368 DET0131

Detects file exfiltration using tools like curl, scp, or custom binaries over protocols such as FTP, HTTP/S, or DNS tunneling, especially outside baseline user behavior.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN0369 Analytic 0369 DET0131

Detects non-native file transfer via curl, Python scripts, or AppleScript using uncommon protocols like FTP, SMTP, or DNS exfiltration through mDNSResponder abuse.

macos:unifiedlog macos:osquery macos:osquery
AN0372 Analytic 0372 DET0132

Adversary-created named mutex using system APIs (e.g., CreateMutexW) followed by conditional process termination or alternate code path indicating malware avoiding reinfection.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0375 Analytic 0375 DET0133

Detection of the creation of VSCode or JetBrains CLI tunneling profiles followed by persistent remote access via IDE-integrated tunnels, potentially authenticated via GitHub or JetBrains accounts.

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0376 Analytic 0376 DET0133

Creation of VSCode tunnel configuration file combined with interactive remote session via code CLI or ssh with JetBrains gateway.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN0377 Analytic 0377 DET0133

Detection of JetBrains or VSCode tunnel profile creation followed by unusual persistent SSH or IDE-based tunnel communications to devtunnel APIs.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0378 Analytic 0378 DET0134

Detects unauthorized access to Windows Credential Manager through anomalous process execution (vaultcmd.exe, rundll32.exe keymgr.dll), suspicious API calls (CredEnumerateA), or direct file access to Credential Locker files. Correlates process creation with subsequent file reads of .vcrd/.vpol files under user Credential Locker directories.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0379 Analytic 0379 DET0135

Detects unauthorized use of SMTP/IMAP/POP3 by suspicious binaries (e.g., PowerShell, rundll32) to exfiltrate data or beacon via email, often bypassing proxy or content filters.

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0380 Analytic 0380 DET0135

Detects non-interactive or script-driven email transmission using tools like `sendmail`, `mailx`, or custom SMTP scripts by background processes, especially when sending attachments or large payloads.

auditd:SYSCALL NSM:Flow
AN0381 Analytic 0381 DET0135

Detects email-sending behavior via Terminal, AppleScript, or Automator that interfaces with SMTP or IMAP, typically using curl or mail-related APIs in unsanctioned contexts.

macos:unifiedlog macos:osquery
AN0382 Analytic 0382 DET0135

Detects hosts transmitting large volumes of SMTP, IMAP, or POP3 traffic to external IPs or relays that aren't associated with the enterprise mail infrastructure.

NSM:Flow
AN0384 Analytic 0384 DET0137

Unusual direct disk access attempts (e.g., use of \\.\PhysicalDrive notation), abnormal writes to MBR/boot sectors, and installation of kernel drivers that grant raw disk access. Correlate anomalous process creation with disk modification attempts and driver loads.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0385 Analytic 0385 DET0137

Processes invoking destructive commands (dd, shred, wipe) with raw device targets (e.g., /dev/sda, /dev/nvme0n1). Detect direct writes to disk partitions and abnormal superblock or bootloader modifications. Correlate shell execution with subsequent block device I/O.

auditd:SYSCALL auditd:EXECVE
AN0388 Analytic 0388 DET0138

Execution of InstallUtil.exe from .NET framework directories with arguments specifying non-standard or attacker-supplied assemblies, especially when followed by suspicious child process creation or script execution. Detection also includes correlation of newly created binaries prior to InstallUtil invocation and anomalous command-line usage compared to historical baselines.

WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0390 Analytic 0390 DET0139

Detects credential interception via malicious LD_PRELOAD-based shared libraries loaded into ssh, sudo, or scp processes. Correlates environment variable injection, unexpected library loads, and memory patching behavior.

auditd:SYSCALL auditd:SYSCALL
AN0393 Analytic 0393 DET0140

Detects deletion of suspicious files (e.g., payloads, temp exes, scripts) via `rm`, `unlink`, or secure deletion tools like `shred`, especially when performed by unexpected users or shortly after execution.

auditd:SYSCALL auditd:SYSCALL
AN0394 Analytic 0394 DET0140

Detects removal of adversary artifacts via `rm`, `unlink`, or secure tools, with focus on shell sessions, temp files, and modified LaunchAgents or system directories.

fs:fsusage macos:unifiedlog
AN0396 Analytic 0396 DET0141

Process creation involving suspicious delays (e.g., Sleep, ping -n loops, WaitForSingleObject), followed by sensitive system access or lateral movement behaviors.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0397 Analytic 0397 DET0141

Script-based execution of sleep loops or time delay commands (e.g., sleep, ping delay, while-loops) followed by file creation or network connections.

auditd:SYSCALL auditd:SYSCALL
AN0398 Analytic 0398 DET0141

Use of `usleep`, `nanosleep`, or `NSTimer` calls in executables or binaries with no GUI interaction, especially followed by disk/network activity.

macos:unifiedlog WinEventLog:Sysmon
AN0399 Analytic 0399 DET0142

Detects unauthorized or anomalous use of command-line interfaces (CLI) on network devices. Focuses on remote access sessions (e.g., SSH/Telnet), privilege escalation within CLI sessions, execution of high-risk commands (e.g., config replace, terminal monitor, no logging), and configuration changes outside of approved windows.

networkdevice:syslog NSM:Flow networkdevice:syslog
AN0401 Analytic 0401 DET0143

Unexpected processes (e.g., bash, python, custom binaries) dynamically loading libcrypto or performing AES/RC4 encryption operations, then initiating outbound sessions with abnormal byte entropy or asymmetric traffic patterns.

auditd:SYSCALL linux:syslog linux:osquery
AN0402 Analytic 0402 DET0143

Launchd jobs or user processes invoking symmetric crypto APIs from the Security framework and generating outbound connections carrying randomized payloads inconsistent with normal TLS patterns.

macos:unifiedlog macos:unifiedlog
AN0403 Analytic 0403 DET0143

ESXi daemons (hostd, vpxa) unexpectedly using symmetric encryption routines for external connections. Defender identifies logs of service traffic with encrypted payloads inconsistent with VMware management baselines.

esxi:vpxd esxcli:network
AN0404 Analytic 0404 DET0143

Flows showing encrypted payloads with high entropy not matching TLS handshake patterns, particularly when occurring on non-standard ports. Defender observes NetFlow/IPFIX byte distribution anomalies or IDS/IPS detecting symmetric encryption patterns without associated key exchange.

NSM:Flow NSM:Connections
AN0405 Analytic 0405 DET0144

Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN0406 Analytic 0406 DET0145

Detection of firewall tampering by monitoring processes executing netsh, PowerShell Set-NetFirewallProfile, or sc stop mpssvc. Registry modifications under HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy also indicate adversarial actions.

WinEventLog:Security WinEventLog:Sysmon
AN0407 Analytic 0407 DET0145

Detection of iptables, nftables, or firewalld rule modifications. Correlation of sudden drops in active firewall rules with suspicious processes suggests adversarial evasion.

auditd:SYSCALL linux:osquery
AN0411 Analytic 0411 DET0146

Adversary spawns command-line tools (e.g., del, cipher /w, SDelete) or scripts to recursively delete or overwrite user/system files. This may be correlated with abnormal file IO activity, registry writes, or tampering in critical system directories.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0412 Analytic 0412 DET0146

Massive recursive deletions or overwrites via `rm -rf`, `shred`, `dd`, or wiper binaries. May include unlink syscalls, deletion of known config/data paths, or sequential overwrite patterns.

auditd:SYSCALL auditd:SYSCALL
AN0415 Analytic 0415 DET0146

Adversary destroys virtual disks (VMDK), images, or VMs by invoking `vim-cmd`, deleting datastore contents, or purging snapshots.

esxi:vmkernel
AN0418 Analytic 0418 DET0148

Forged SAML tokens can be observed as authentication attempts with valid signatures but missing expected preceding Kerberos or authentication events. Defenders may correlate SAML assertions with absent Event IDs 4769, 1200, or 1202, or tokens issued with abnormal lifetimes, issuers, or claims compared to baseline.

azure:signinlogs WinEventLog:Security
AN0421 Analytic 0421 DET0148

Forged SAML tokens can appear as SaaS logins where authentication succeeded without MFA, or where tokens contain claims inconsistent with the user profile. Look for concurrent sessions across different geographies with the same SAML assertion ID.

saas:access m365:unified
AN0423 Analytic 0423 DET0149

Detects data access or staging events followed by outbound data flows using unencrypted protocols (e.g., FTP, HTTP) initiated by unexpected processes or to rare destinations.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security NSM:Flow
AN0424 Analytic 0424 DET0149

Detects file access or compression utilities followed by outbound connections using curl, wget, ftp, or custom binaries communicating over unencrypted protocols.

auditd:SYSCALL auditd:SYSCALL NSM:Flow NSM:Flow
AN0425 Analytic 0425 DET0149

Detects abnormal outbound HTTP/FTP connections by local scripts or binaries outside of standard browser activity, following access to local documents or user data.

macos:osquery macos:osquery macos:unifiedlog NSM:Flow
AN0426 Analytic 0426 DET0149

Detects shell-based scripts accessing configuration files or snapshots and transmitting them over unencrypted protocols such as FTP or HTTP to non-management IPs.

esxi:hostd NSM:Flow NSM:Flow
AN0427 Analytic 0427 DET0149

Detects use of unencrypted protocols (e.g., TFTP, FTP, HTTP) to transfer configuration files, routing tables, or logs to untrusted IP addresses, especially using administrative commands like `copy run ftp:`.

networkdevice:cli networkdevice:syslog NSM:Flow
AN0428 Analytic 0428 DET0150

Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0430 Analytic 0430 DET0151

Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \\host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values).

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell etw:Microsoft-Windows-Kernel-Process WinEventLog:TaskScheduler WinEventLog:TaskScheduler EDR:Telemetry
AN0431 Analytic 0431 DET0151

A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic.

auditd:SYSCALL auditd:SYSCALL linux:syslog linux:cron
AN0432 Analytic 0432 DET0151

Process/script execution of systemsetup -gettimezone, date, ioreg, or API usage (timeIntervalSinceNow, gettimeofday) followed by time-based scheduling (launchd plist modification) or sleep-based execution.

macos:unifiedlog macos:unifiedlog
AN0435 Analytic 0435 DET0152

Detection focuses on adversaries placing or modifying malicious dylibs in locations searched by legitimate applications. From the defender’s perspective, observable patterns include unexpected creation or modification of dylib files in application bundle paths, unusual module loads by processes compared to historical baselines, and execution of applications loading dylibs from suspicious directories (e.g., /tmp, user-controlled paths). Correlation across file system changes, process execution, and module loads provides high-fidelity detection.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0436 Analytic 0436 DET0153

Unusual processes (e.g., powershell.exe, wscript.exe, mshta.exe) posting data to webhook endpoints (Discord, Slack, webhook.site) using HTTP POST/PUT requests. Defender perspective: suspicious process lineage followed by outbound HTTPS traffic to webhook domains.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0437 Analytic 0437 DET0153

Processes such as curl, wget, or custom scripts initiating POST requests to webhook endpoints with encoded or bulk data. Defender perspective: abnormal chaining of file compression or access followed by outbound data to webhook URLs.

auditd:EXECVE auditd:SYSCALL NSM:Flow
AN0438 Analytic 0438 DET0153

Unexpected apps or scripts (osascript, curl, Automator workflows) exfiltrating data via webhooks. Defender perspective: correlation of clipboard/file read operations followed by HTTPS POST traffic to webhook services.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0439 Analytic 0439 DET0153

VMware services or management daemons generating HTTP POST requests to webhook endpoints, chained with unusual datastore or log access. Defender perspective: exfiltration from VM logs or disk images over webhook URLs.

esxi:hostd esxi:vmkernel
AN0441 Analytic 0441 DET0154

Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\Control Panel\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout.

WinEventLog:Security WinEventLog:Sysmon
AN0444 Analytic 0444 DET0157

Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Security WinEventLog:Security
AN0445 Analytic 0445 DET0158

Detection of msiexec.exe execution where command-line arguments reference remote MSI packages, UNC paths, HTTP/HTTPS URLs, or DLLs, correlated with subsequent module loads and/or network connections to previously unseen destinations. The behavioral chain links process creation of msiexec.exe with suspicious parameters, network activity to retrieve payloads, and module loading indicative of malicious installation or DLL execution.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0446 Analytic 0446 DET0159

Detection of USB-based remote access hardware (e.g., TinyPilot, PiKVM) attached to the host via drive or peripheral enumeration, triggering vendor identifiers or unusual EDID announcements.

WinEventLog:System
AN0447 Analytic 0447 DET0159

Insertion of USB-based hardware proxies (e.g., PiKVM) which register under predictable names (e.g., tinypilot) or mount under known paths (e.g., /opt/tinypilot-privileged).

auditd:SYSCALL
AN0448 Analytic 0448 DET0159

Attachment of hardware-backed USB KVM devices (e.g., TinyPilot) that enumerate new HID or serial communication interfaces with identifiable metadata.

macos:unifiedlog
AN0454 Analytic 0454 DET0160

Detect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login.

macos:unifiedlog
AN0455 Analytic 0455 DET0161

Cause→effect chain: (1) a user or service spawns a shell/PowerShell that queries local/domain password policy via commands/cmdlets (e.g., `net accounts`, `Get-ADDefaultDomainPasswordPolicy`, `secedit /export`); (2) optional directory/LDAP reads from DCs; (3) same principal performs adjacent Discovery or credential-related actions within a short window. Correlate sysmon process creation with PowerShell ScriptBlock and Security logs.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Security
AN0456 Analytic 0456 DET0161

Chain: (1) interactive/non-interactive `chage -l`, `grep`/`cat` of PAM config (e.g., `/etc/pam.d/common-password`, `/etc/security/pwquality.conf`); (2) optional reads of `/etc/login.defs`; (3) same user performs account enumeration or password change attempts shortly after. Use auditd `execve` and file read events plus shell history collection.

auditd:SYSCALL auditd:SYSCALL linux:syslog
AN0457 Analytic 0457 DET0161

Chain: (1) execution of `pwpolicy` or MDM/DirectoryService reads of account policies; (2) optional read of `/Library/Preferences/com.apple.loginwindow` or config profiles; (3) follow-on credential probing or lateral movement by same user/session. Use unified logs and process telemetry.

macos:unifiedlog macos:unifiedlog macos:MDM
AN0462 Analytic 0462 DET0162

Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin.

WinEventLog:System WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0463 Analytic 0463 DET0162

Process creates a raw/packet socket and attaches a (e)BPF filter (setsockopt SO_ATTACH_FILTER/ATTACH_BPF or bpf(BPF_PROG_LOAD)). Immediately after a matching inbound packet, the same process binds/connects outward to a remote host (reverse shell or beacon).

auditd:SYSCALL linux:osquery NSM:Flow
AN0464 Analytic 0464 DET0162

Process opens /dev/bpf* (libpcap) or loads NetworkExtension filter, then after a crafted inbound packet the same process initiates an outbound connection to the trigger origin.

OpenBSM:AuditTrail macos:unifiedlog NSM:Flow
AN0465 Analytic 0465 DET0163

Defenders may observe unauthorized or anomalous changes to NAT configurations, including the addition of new translation rules or modifications to existing ones. Suspicious behaviors include sudden introduction of NAT mappings bridging segmented networks, new port address translation rules that obscure true source IPs, or traffic flows inconsistent with expected network design. Multi-event correlation includes detecting configuration changes on routers/firewalls, followed by traffic traversing unexpected internal/external address pairs.

networkdevice:config NSM:Flow
AN0467 Analytic 0467 DET0165

Detects adversary behavior clearing command history via `history -c`, deletion or modification of ~/.bash_history, or manipulation of the HISTFILE environment variable post-login.

auditd:SYSCALL auditd:SYSCALL
AN0468 Analytic 0468 DET0165

Detects adversary clearing shell history using `history -c` or deleting/altering ~/.zsh_history or ~/.bash_history. Focus on sessions with missing or wiped history.

macos:unifiedlog fs:fsusage
AN0472 Analytic 0472 DET0166

Adversary registers a malicious Microsoft Exchange transport agent DLL (.NET assembly), configures it via PowerShell or Exchange Management Shell, and persists code execution by manipulating email processing logic based on rules or headers.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Application WinEventLog:Sysmon
AN0473 Analytic 0473 DET0166

Adversary installs or modifies email content filters or transport scripts (e.g., Postfix milter, Sendmail milter, Exim filters) using shell access or configuration manipulation.

auditd:SYSCALL linux:syslog auditd:EXECVE auditd:SYSCALL linux:Sysmon
AN0474 Analytic 0474 DET0167

Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Kernel-Boot
AN0475 Analytic 0475 DET0167

Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom).

auditd:SYSCALL auditd:SYSCALL
AN0476 Analytic 0476 DET0167

EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages.

macos:unifiedlog macos:unifiedlog
AN0477 Analytic 0477 DET0167

Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity.

NSM:Flow networkdevice:firmware
AN0478 Analytic 0478 DET0168

Script or binary performs a rapid sequence of system discovery checks (e.g., CPU count, RAM size, registry keys, running processes) indicative of VM detection

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0479 Analytic 0479 DET0168

Shell script or binary uses multiple system commands (e.g., dmidecode, lscpu, lspci) in quick succession to detect virtualization environment

auditd:SYSCALL
AN0480 Analytic 0480 DET0168

Bash, Swift, or Objective-C programs enumerate system profile, I/O registry, or inspect kernel extensions to identify VM artifacts

macos:unifiedlog
AN0484 Analytic 0484 DET0171

Forged web cookies on Windows endpoints can be detected by monitoring unusual modifications of browser cookie stores (e.g., Chrome SQLite DB, Edge cache) by processes outside of browsers, followed by authentication events to SaaS or IaaS services. Defenders may observe processes writing directly to cookie storage paths or injecting tokens into browser sessions.

WinEventLog:Sysmon WinEventLog:Security
AN0488 Analytic 0488 DET0172

A trusted/signed developer utility (parent) is executed in a non-developer context and (a) spawns suspicious children (e.g., powershell.exe, cmd.exe, rundll32.exe, regsvr32.exe, wscript.exe), (b) loads unsigned/user-writable DLLs, (c) writes and then runs a new PE from user-writable paths, and/or (d) immediately makes outbound network connections.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:AppLocker
AN0491 Analytic 0491 DET0173

Flood of incoming TLS or HTTP(S) connections to macOS-hosted services (e.g., MAMP, Apache), causing high CPU usage and system unresponsiveness.

macos:unifiedlog macos:unifiedlog
AN0494 Analytic 0494 DET0174

Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services.

auditd:SYSCALL NSM:Connections
AN0495 Analytic 0495 DET0174

Detects exploitation attempts against macOS authentication frameworks such as OpenDirectory or Keychain. Defender perspective includes abnormal crashes in opendirectoryd, unauthorized Keychain API usage, and unusual sudo or login events. Correlation links unexpected process behavior with credential access anomalies.

macos:unifiedlog macos:osquery
AN0498 Analytic 0498 DET0176

Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Application etw:Microsoft-Windows-Kernel-Process WinEventLog:Sysmon NSM:Flow
AN0499 Analytic 0499 DET0176

Correlated evidence of browser or webview fetches to uncommon domains or mutated JS resources (proxy/NGFW logs + Zeek/HTTP logs) followed by unexpected interpreters or script engines executing (python, ruby, sh) spawned from browser processes or user sessions, rapid on-disk staging in /tmp, and outbound connections that deviate from baseline. Defender sees: uncommon resource fetch → short-lived child process executions from user browser context → file writes in temp directories → anomalous outbound C2-like connections.

auditd:SYSCALL linux:syslog NSM:Flow linux:Sysmon NSM:Connections
AN0500 Analytic 0500 DET0176

Correlated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch.

macos:unifiedlog macos:unifiedlog macos:unifiedlog NSM:Flow macos:unifiedlog
AN0502 Analytic 0502 DET0177

Adversary uses a tool like Ruler to configure a malicious Outlook folder Home Page that loads a remote or embedded HTML payload upon folder interaction. Execution chain begins with Outlook launching, a specific folder being accessed, and a suspicious child process being spawned or COM-based execution invoked.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Application WinEventLog:PowerShell
AN0504 Analytic 0504 DET0178

Detection of VNC service or executable starting unexpectedly, followed by user session creation and interactive desktop activity (mouse/keyboard simulation).

WinEventLog:Sysmon WinEventLog:Security NSM:Flow
AN0505 Analytic 0505 DET0178

Spawning of VNC-related processes (e.g., `x11vnc`, `vncserver`) coupled with authentication logs and port listening behavior on TCP 5900.

auditd:EXECVE linux:syslog NSM:Flow
AN0506 Analytic 0506 DET0178

Detection of VNC-based remote control via `screensharingd` activity in Unified Logs along with concurrent remote login activity or suspicious user interaction.

macos:unifiedlog macos:osquery NSM:firewall
AN0507 Analytic 0507 DET0179

Detection of adversary enumeration of domain or local group memberships via native tools such as net.exe, PowerShell, or WMI. This activity may precede lateral movement or privilege escalation.

WinEventLog:Security WinEventLog:PowerShell
AN0508 Analytic 0508 DET0179

Detection of group enumeration using commands like 'id', 'groups', or 'getent group', often followed by privilege escalation or SSH lateral movement.

auditd:SYSCALL
AN0509 Analytic 0509 DET0179

Group membership checks via 'dscl', 'dscacheutil', or 'id', typically executed via terminal or automation scripts.

macos:unifiedlog
AN0510 Analytic 0510 DET0180

Detection correlates file creation or modification of `.lnk` (shortcut) files in autostart locations with anomalous parent-child process lineage or unsigned binaries. Defenders should watch for LNK creation/modification events outside of known software installations, patch events, or OS updates. Flag shortcut targets pointing to suspicious locations or unknown binaries, particularly those written by script interpreters or spawned from phishing delivery chains.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0511 Analytic 0511 DET0181

Creation or modification of stored procedures invoking xp_cmdshell or CLR assemblies for command execution and persistence.

WinEventLog:Application WinEventLog:Sysmon WinEventLog:Application
AN0512 Analytic 0512 DET0181

SQL stored procedures that invoke OS-level commands via `xp_cmdshell` equivalent or via UDF (User-Defined Functions) mechanisms.

auditd:SYSCALL ApplicationLogs:SQL
AN0513 Analytic 0513 DET0182

Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \\host\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell etw:Microsoft-Windows-RPC
AN0514 Analytic 0514 DET0182

CLI tools (smbclient -L, smbmap, rpcclient, nmblookup) or custom scripts enumerate SMB shares on many internal hosts → corresponding SMB connections (445/139) captured by Zeek/Netflow within a short window.

auditd:SYSCALL NSM:Flow NSM:Flow
AN0515 Analytic 0515 DET0182

Use of native/mac tools (sharing -l, smbutil view, mount_smbfs) or scripts to enumerate SMB shares across many hosts, followed by outbound SMB connections observed in PF/Zeek logs.

macos:endpointsecurity macos:unifiedlog NSM:Firewall NSM:Flow
AN0516 Analytic 0516 DET0183

Correlate suspicious file transfers over SMB or Admin$ shares with process creation events (e.g., cmd.exe, powershell.exe, certutil.exe) that do not align with normal administrative behavior. Detect remote file writes followed by execution of transferred binaries.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0517 Analytic 0517 DET0183

Monitor scp, rsync, curl, sftp, or ftp processes initiating transfers to internal systems combined with file creation events in unusual directories. Correlate transfer activity with subsequent execution of those binaries.

auditd:SYSCALL auditd:FILE
AN0518 Analytic 0518 DET0183

Detect anomalous use of scp, rsync, curl, or third-party sync apps transferring executables into user directories. Correlate new file creation with immediate execution events.

macos:unifiedlog macos:unifiedlog
AN0531 Analytic 0531 DET0186

Automated execution of native utilities and scripts to discover, enumerate, and exfiltrate files and clipboard content. Focus is on detecting repeated file access, scripting engine use, and use of command-line utilities commonly leveraged by collection scripts.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0532 Analytic 0532 DET0186

Repeated or automated access to user document directories or clipboard using shell scripts or utilities like xclip/pbpaste. Detectable via auditd syscall logs or osquery file events.

auditd:SYSCALL auditd:SYSCALL
AN0533 Analytic 0533 DET0186

Use of pbpaste, AppleScript, or third-party automation frameworks (e.g., Automator) to collect clipboard or file content in bursts. Observable via unified logs.

macos:unifiedlog macos:unifiedlog
AN0535 Analytic 0535 DET0187

Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using `auditpol` or `wevtutil` to disable categories or clear audit policies, and detecting suspicious gaps or resets in event logs. Defenders observe registry changes, service state changes, process execution of disabling commands, and anomalies in event record sequences.

WinEventLog:System WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0536 Analytic 0536 DET0188

Drive enumeration using PowerShell (`Get-PSDrive`), `wmic logicaldisk`, or Win32 API indicative of local volume enumeration by non-admin users or executed outside of baseline system inventory scripts.

WinEventLog:Sysmon
AN0537 Analytic 0537 DET0188

Abnormal use of `lsblk`, `fdisk -l`, `lshw -class disk`, or `parted` by non-admin users or within non-interactive shells suggests suspicious disk enumeration activity.

auditd:SYSCALL auditd:EXECVE
AN0538 Analytic 0538 DET0188

Disk enumeration via `diskutil list` or `system_profiler SPStorageDataType` run outside of user login or not associated with system inventory tools

macos:unifiedlog macos:unifiedlog
AN0539 Analytic 0539 DET0188

Use of `esxcli storage` or `vim-cmd vmsvc/getallvms` by unusual sessions or through interactive shells unrelated to administrative maintenance tasks.

esxi:hostd esxi:auth
AN0540 Analytic 0540 DET0189

Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence).

WinEventLog:Application WinEventLog:Sysmon WinEventLog:Sysmon
AN0541 Analytic 0541 DET0189

Detection of anti-malware quarantining or flagging a tool, followed by a new binary written to disk with a similar function or name and a resumed process chain.

auditd:SYSCALL auditd:SYSCALL linux:osquery EDR:detection
AN0550 Analytic 0550 DET0191

Abuse of ClickOnce applications where rundll32.exe invokes dfshim.dll with ShOpenVerbApplication or dfsvc.exe spawns unexpected child processes or loads unsigned modules.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Security-Mitigations/KernelMode
AN0552 Analytic 0552 DET0192

Alterations to plist configuration files (RulesActiveState.plist, SyncedRules.plist, UnsyncedRules.plist, MessageRules.plist) that define email hiding or filtering rules. Defender perspective: unexpected changes in these files associated with Mail.app processes.

macos:unifiedlog macos:unifiedlog
AN0555 Analytic 0555 DET0193

Identify unauthorized creation, deletion, or modification of business-critical stored data such as Office documents, database files, and log archives. Detect anomalous processes modifying stored data outside of expected workflows (e.g., non-database processes modifying database files).

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0556 Analytic 0556 DET0193

Detect suspicious file creation, modification, or deletion in stored data directories (e.g., `/var/lib/mysql/`, `/var/log/`, mail spools). Identify shell commands interacting directly with structured data files instead of legitimate database utilities.

auditd:SYSCALL auditd:SYSCALL
AN0558 Analytic 0558 DET0194

Execution of control.exe or rundll32.exe with parameters pointing to CPL files, especially from non-standard directories or newly created files, followed by suspicious child process execution or registry modifications registering new Control Panel items.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0559 Analytic 0559 DET0195

Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration.

WinEventLog:Sysmon WinEventLog:PowerShell
AN0560 Analytic 0560 DET0195

Execution of `ifconfig`, `ip a`, or access to `/proc/net/` indicating collection of local interface and route configuration.

auditd:EXECVE
AN0561 Analytic 0561 DET0195

Execution of `ifconfig`, `networksetup`, or `system_profiler` to query IP/MAC/interface configuration and status.

macos:unifiedlog
AN0564 Analytic 0564 DET0196

Suspicious outbound HTTPS connections where the TLS Server Name Indication (SNI) does not match the HTTP Host header, indicating potential use of domain fronting to mask C2 traffic via CDNs.

NSM:Connections WinEventLog:Sysmon
AN0565 Analytic 0565 DET0196

Applications such as `curl`, `wget`, or custom binaries initiate HTTPS connections where the TLS SNI is mismatched or absent while HTTP Host targets CDN-available C2 endpoints.

NSM:Flow auditd:SYSCALL
AN0566 Analytic 0566 DET0196

Unsigned or user-space apps initiate TLS connections with one hostname and HTTP headers requesting a different domain, commonly abused in CDN-resident domain fronting techniques.

macos:unifiedlog macos:osquery
AN0567 Analytic 0567 DET0196

Traffic originating from ESXi hosts or management interfaces displays SNI-to-Host mismatch behavior, particularly anomalous given typical infrastructure communication patterns.

NSM:Firewall esxi:shell
AN0568 Analytic 0568 DET0197

A non-standard process (or script-hosted process) loads camera/video-capture libraries (e.g., avicap32.dll, mf.dll, ksproxy.ax), opens the Camera Frame Server/device, writes video/image artifacts (e.g., .mp4/.avi/.yuv) to unusual locations, and optionally initiates outbound transfer shortly after.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Microsoft-Windows-Windows Camera Frame Server/Operational
AN0569 Analytic 0569 DET0197

A process opens/reads /dev/video* (V4L2), performs ioctl/read loops, writes large/continuous video artifacts to disk, and/or quickly establishes outbound connections for exfiltration.

auditd:SYSCALL auditd:SYSCALL linux:osquery linux:syslog NSM:Flow
AN0570 Analytic 0570 DET0197

A non-whitelisted process receives TCC camera entitlement (kTCCServiceCamera), opens AppleCamera/AVFoundation device handles, writes .mov/.mp4 artifacts to unusual locations, and/or beacons/exfiltrates soon after.

macos:unifiedlog macos:endpointsecurity macos:endpointsecurity macos:unifiedlog
AN0571 Analytic 0571 DET0198

Detection correlates anomalous Docker or Kubernetes API requests with access to logs, secrets, or service accounts. Observes unauthorized use of `docker logs`, `kubectl get secrets`, or direct API calls to Kubernetes API server endpoints. Identifies behavioral patterns where adversaries escalate from basic pod/container interaction to privileged API calls exposing sensitive credential material.

docker:api kubernetes:apiserver kubernetes:apiserver kubernetes:orchestrator
AN0574 Analytic 0574 DET0199

Detects enumeration of VMs using PowerShell (`Get-VM`), VMware Workstation (`vmrun.exe`), or Hyper-V (`VBoxManage.exe`). Defender observes suspicious command lines executed by unexpected users or outside normal administrative sessions.

WinEventLog:Security
AN0575 Analytic 0575 DET0199

Detects VM enumeration attempts using virtualization utilities such as VirtualBox (`VBoxManage`) or Parallels CLI. Defender observes abnormal invocation of VM listing commands correlated with non-admin users or unusual parent processes.

macos:unifiedlog
AN0576 Analytic 0576 DET0200

Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand). (2) That utility spawns a secondary program/command (PowerShell, cmd, msiexec, regsvr32, curl, arbitrary EXE) and/or opens outbound network connections. (3) Optional precursor modification of SSH config to persist LocalCommand/ProxyCommand. Correlate process creation, command/script content, file access to %USERPROFILE%\.ssh\config, and network connections from the utility or its child.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0577 Analytic 0577 DET0201

DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN0578 Analytic 0578 DET0202

Detects interactive or scripted abuse of cmd.exe, batch files, or shell invocation chains. Focuses on parent-child relationships (e.g., cmd.exe launched from unusual parents), anomalous command-line parameters, and chaining with discovery, credential access, or lateral movement behaviors.

WinEventLog:Security WinEventLog:Sysmon EDR:scriptblock
AN0579 Analytic 0579 DET0203

Detects ptrace-based process injection by correlating audit logs of ptrace syscalls, memory modifications (e.g., poketext, pokedata), and suspicious register manipulation on a target process not normally debugged by the originator. Alerts on processes attempting to ptrace non-child or privileged processes, especially those followed by abnormal memory or execution behavior.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0580 Analytic 0580 DET0204

Detects suspicious registry modifications under `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\*\Driver`, DLL loads by `spoolsv.exe` of non-standard or unsigned modules, and abnormal usage of the `AddMonitor` API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in `C:\Windows\System32` not tied to known patches or installations.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Application
AN0581 Analytic 0581 DET0205

Execution of XSL scripts via msxsl.exe or wmic.exe using embedded JScript or VBScript for proxy execution. Detection correlates process creation, command-line patterns, and module load behavior of scripting components (e.g., jscript.dll).

WinEventLog:Sysmon WinEventLog:Sysmon
AN0582 Analytic 0582 DET0206

Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster.

kubernetes:apiserver kubernetes:events container:proxy
AN0584 Analytic 0584 DET0208

Excessive resource exhaustion or service crash induced by processes launched by users or scripts that rapidly consume CPU/memory or attempt malformed service interactions.

WinEventLog:Sysmon WinEventLog:Application WinEventLog:System
AN0585 Analytic 0585 DET0208

Malicious script or binary causes repeated kernel panics, OOM kills, or systemd service restarts targeting services like nginx, httpd, sshd.

auditd:SYSCALL linux:syslog journald:systemd
AN0589 Analytic 0589 DET0209

Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell
AN0590 Analytic 0590 DET0210

Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0591 Analytic 0591 DET0210

Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.

auditd:SYSCALL linux:syslog
AN0593 Analytic 0593 DET0210

Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships.

esxi:vpxd esxi:hostd
AN0594 Analytic 0594 DET0211

Direct login to cloud-hosted virtual machines via cloud-native access methods (e.g., EC2 Instance Connect, Azure Serial Console, SSM), followed by command execution or privilege escalation on the VM

AWS:CloudTrail WinEventLog:Sysmon
AN0595 Analytic 0595 DET0212

Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0599 Analytic 0599 DET0214

Detection of executables or scripts containing hidden embedded resources or secondary payloads, often with anomalies in file size vs. functionality or dropped child binaries.

WinEventLog:Sysmon WinEventLog:Sysmon EDR:file
AN0601 Analytic 0601 DET0214

Detection of Mach-O binaries or AppleScripts that contain nested, encoded, or run-only embedded payloads dropped at runtime.

macos:unifiedlog macos:endpointsecurity macos:osquery
AN0602 Analytic 0602 DET0215

High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0603 Analytic 0603 DET0215

Encryption via custom or open-source tools (e.g., openssl, gpg, aescrypt) recursively targeting user or system directories. Also includes overwrite of existing data and ransom note drops.

auditd:SYSCALL auditd:SYSCALL
AN0604 Analytic 0604 DET0215

Userland or kernel-level ransomware encrypting user files (Documents, Desktop) using `srm`, `gpg`, or compiled payloads. Often correlated with ransom note creation in multiple directories.

macos:unifiedlog macos:unifiedlog
AN0606 Analytic 0606 DET0215

Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers.

AWS:CloudTrail
AN0608 Analytic 0608 DET0217

Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage.

WinEventLog:Sysmon etw:Microsoft-Windows-Win32k WinEventLog:Security
AN0609 Analytic 0609 DET0218

Unusual modifications to service binary paths, registry keys, or DLL load paths resulting in alternate execution flow. Defender observes registry key modifications, suspicious file writes into system directories, and processes loading libraries from abnormal paths.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN0610 Analytic 0610 DET0218

Adversary manipulation of shared library paths, environment variables, or replacement of service binaries. Defender observes suspicious modifications in /etc/ld.so.preload, service config changes, or file writes replacing existing executables.

auditd:SYSCALL linux:syslog linux:osquery
AN0611 Analytic 0611 DET0218

Abuse of DYLD_INSERT_LIBRARIES or hijacking framework paths for malicious libraries. Defender observes processes invoking abnormal dylibs, modified plist files, or persistence entries pointing to altered binaries.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0613 Analytic 0613 DET0219

Detection of Linux container escape attempts via syscalls (`unshare`, `keyctl`, `mount`) or process execution outside container namespaces. Defenders may correlate unusual system calls from containerized processes with subsequent process creation on the host or modification of host resources.

auditd:SYSCALL linux:Sysmon
AN0614 Analytic 0614 DET0219

Detection of Windows container escape attempts by observing processes accessing host directories, symbolic link abuse, or privilege escalation attempts. Defenders may detect anomalous process execution with access to system-level directories outside of container boundaries.

WinEventLog:Security WinEventLog:Sysmon
AN0616 Analytic 0616 DET0220

Detects USB device insertion followed by high-volume or sensitive file access and staging activity by suspicious processes or accounts.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:System
AN0617 Analytic 0617 DET0220

Detects USB block device mount followed by file access in sensitive directories or high-volume copy operations by user-controlled processes.

auditd:SYSCALL auditd:SYSCALL
AN0618 Analytic 0618 DET0220

Detects external volume mount with Finder, Terminal, or script-initiated file copy from user profiles, sensitive folders, or cloud storage sync directories to USB.

macos:unifiedlog fs:fsusage macos:osquery
AN0619 Analytic 0619 DET0221

Unusual or unauthorized processes accessing microphone APIs (e.g., winmm.dll, avrt.dll) followed by audio file writes to user-accessible or temp directories.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0620 Analytic 0620 DET0221

Processes accessing ALSA/PulseAudio devices or executing audio capture binaries like 'arecord', followed by file creation or suspicious child process spawning.

auditd:SYSCALL linux:Sysmon auditd:SYSCALL
AN0621 Analytic 0621 DET0221

Processes invoking AVFoundation or CoreAudio frameworks, accessing input devices via TCC logs or Unified Logs, followed by writing AIFF/WAV/MP3 files to disk.

macos:unifiedlog Apple TCC Logs fs:fsusage
AN0622 Analytic 0622 DET0222

Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-COM/Operational WinEventLog:Sysmon WinEventLog:PowerShell
AN0623 Analytic 0623 DET0223

Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe).

WinEventLog:Security WinEventLog:Application
AN0624 Analytic 0624 DET0223

Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes.

auditd:SYSCALL
AN0625 Analytic 0625 DET0223

Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads.

macos:unifiedlog macos:jamf
AN0628 Analytic 0628 DET0224

Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0629 Analytic 0629 DET0225

Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0630 Analytic 0630 DET0226

Detects behavior where files with non-executable or misleading extensions (e.g., .jpg, .txt) are created or modified but subsequently executed as binaries based on internal file headers or abnormal parent process lineage. This includes identifying polyglot files or malformed magic bytes indicative of masquerading attempts.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0631 Analytic 0631 DET0226

Detects when a script or binary is named with misleading or benign-looking extensions (.jpg, .doc) and is then executed via command line or a scheduled task. Includes ELF header mismatches and content-type inconsistencies on disk.

auditd:SYSCALL linux:osquery
AN0632 Analytic 0632 DET0226

Detects binaries disguised as media or document types through extension-only masquerading or by modifying the file signature. Observes execution of files whose extension is not typically executable (.jpg, .txt), yet have valid Mach-O headers or execute via Terminal or launch services.

macos:unifiedlog
AN0633 Analytic 0633 DET0227

Processes initiating outbound connections on uncommon ports or using protocols inconsistent with the assigned port. Correlating process creation with subsequent network connections reveals anomalies such as svchost.exe or Office applications using high, atypical ports.

WinEventLog:Security WinEventLog:Sysmon
AN0634 Analytic 0634 DET0227

Unusual daemons or user processes binding/listening on ports outside of standard ranges, or initiating client connections using mismatched protocol/port pairings.

auditd:SYSCALL linux:syslog linux:osquery
AN0635 Analytic 0635 DET0227

Applications making outbound connections on non-standard ports or launchd services bound to ports inconsistent with system baselines.

macos:unifiedlog macos:unifiedlog
AN0636 Analytic 0636 DET0227

VM services or management daemons communicating on ports not defined by VMware defaults, such as vpxa or hostd processes initiating traffic over high-numbered or unexpected ports.

esxi:vpxd esxcli:network
AN0637 Analytic 0637 DET0228

Initial process initiates outbound connection to first-stage C2, receives payloads or commands, then spawns or injects into a second process that establishes a new outbound connection to an unrelated destination (second-stage C2).

WinEventLog:Sysmon WinEventLog:Sysmon
AN0638 Analytic 0638 DET0228

Shell script or binary initiates curl/wget request to staging domain, writes output to disk or memory, and shortly afterward launches another process that establishes new outbound connection to a different IP or hostname.

auditd:SYSCALL iptables:LOG
AN0639 Analytic 0639 DET0228

Initial process using NSURLSession or similar APIs reaches out to known staging domains, followed by creation of a reverse shell or RAT connecting to a second unrelated server.

macos:endpointsecurity macos:unifiedlog
AN0640 Analytic 0640 DET0228

CLI-based or API-based network call from the hypervisor to external staging host, shortly followed by a connection to a second external IP by a spawned process or scheduled task.

esxi:hostd esxi:cron
AN0641 Analytic 0641 DET0229

Enumeration of global address lists or email account metadata via PowerShell cmdlets (e.g., Get-GlobalAddressList) or MAPI/RPC from non-admin, non-mailserver systems.

WinEventLog:PowerShell WinEventLog:Sysmon
AN0643 Analytic 0643 DET0230

Detects execution of binaries signed with unusual or recently issued certificates, correlation of process execution with abnormal publisher metadata, and mismatched certificate chains. Monitors for revoked or unknown code signing certificates used in high-privilege contexts.

WinEventLog:Security WinEventLog:Sysmon
AN0644 Analytic 0644 DET0230

Monitors Gatekeeper, spctl, and unified log entries for binaries executed with unexpected or untrusted signatures. Correlates file metadata changes with process launches where signature validation is skipped, altered, or fails but the process still executes.

macos:unifiedlog macos:unifiedlog
AN0645 Analytic 0645 DET0231

Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0647 Analytic 0647 DET0233

Defenders may observe adversary attempts to collect or export full device configurations by detecting unusual SNMP queries, Smart Install (SMI) activity, or CLI/API commands that request running or startup configuration dumps. Correlated behaviors include high-volume read requests for sensitive OIDs, repeated use of 'show running-config' or equivalent commands from untrusted IPs, or unexpected TFTP/SCP/FTP transfers containing configuration files. These behaviors often appear in sequence: anomalous authentication or privilege escalation, followed by bulk configuration retrieval and outbound transfer.

networkdevice:syslog networkdevice:cli NSM:Flow snmp:access
AN0648 Analytic 0648 DET0234

Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Security
AN0649 Analytic 0649 DET0234

Processes opening /proc/*/mem or /proc/*/maps targeting credential-storing services like sshd or login. Behavior often includes high privilege escalation and memory inspection tools such as gcore or gdb.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0650 Analytic 0650 DET0234

Unsigned processes accessing system memory or launching known credential scraping tools (e.g., osascript, dylib injections) to access the Keychain or sensitive memory regions.

macos:unifiedlog macos:keychain macos:osquery
AN0651 Analytic 0651 DET0235

Detect the creation or modification of common media file formats (e.g., .jpg, .png, .wav) following suspicious process activity like compression or encryption, especially when paired with lateral movement or exfiltration behavior.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0652 Analytic 0652 DET0235

Unusual use of steganographic or media processing binaries (e.g., `steghide`, `ffmpeg`, `imagemagick`) followed by outbound communication to external IPs with high data output and media MIME types.

auditd:SYSCALL NSM:Flow NSM:Flow
AN0653 Analytic 0653 DET0235

Abnormal usage of Preview, ImageMagick, or binary editors to alter images/documents, followed by exfiltration or outbound connections with mismatched file MIME types or payload structure.

macos:unifiedlog macos:osquery NSM:Flow
AN0654 Analytic 0654 DET0235

Suspicious modification of file artifacts (e.g., logs, ISO templates) on ESXi datastores, followed by beaconing or POST operations to external IPs potentially hiding payloads in file-like traffic.

esxi:vmkernel esxi:hostd NSM:Flow
AN0655 Analytic 0655 DET0236

Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity.

m365:unified WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0656 Analytic 0656 DET0236

Phishing attachments executed on Linux systems are detected by linking email logs to file creation in mail directories and subsequent suspicious process execution. Look for unexpected binaries or scripts spawned from user mail directories and anomalous outbound network activity.

Application:Mail auditd:SYSCALL NSM:Flow
AN0657 Analytic 0657 DET0236

Phishing attachment detection on macOS through correlation of Mail app logs, file creation in user directories, and abnormal process execution (e.g., Preview.app or Mail.app spawning Terminal or scripting binaries). Network traffic after attachment interaction is also monitored.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0658 Analytic 0658 DET0237

Detection of modified or newly created /etc/rc.local or /etc/init.d scripts followed by suspicious execution during system startup.

auditd:SYSCALL linux:syslog
AN0659 Analytic 0659 DET0237

Detection of edits or additions to /etc/rc.common, /Library/StartupItems, or /System/Library/StartupItems and associated script execution during login or reboot.

macos:unifiedlog fs:fsusage
AN0662 Analytic 0662 DET0238

Adversary modifies website or application-hosted content via unauthorized file changes or script injections, often by exploiting web servers or CMS access.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Application
AN0663 Analytic 0663 DET0238

Adversary gains shell access or uploads a malicious script to deface hosted web content in Nginx, Apache, or other services.

auditd:SYSCALL apache:access_log linux:syslog
AN0664 Analytic 0664 DET0238

Adversary modifies internal or external site content through manipulated application bundles, hosted content, or web server configs.

macos:unifiedlog macos:unifiedlog
AN0666 Analytic 0666 DET0238

Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets.

CloudTrail:PutObject AWS:CloudTrail
AN0675 Analytic 0675 DET0241

Detects forged Kerberos Silver Tickets by identifying anomalous Kerberos service ticket activity such as malformed fields in logon events, TGS requests without interaction with the KDC, and access attempts using service accounts outside expected hosts/resources. Also monitors suspicious processes accessing LSASS memory for credential dumping.

WinEventLog:Security WinEventLog:Kerberos WinEventLog:Sysmon
AN0676 Analytic 0676 DET0242

Unusual database command-line access (e.g., `psql`, `mysql`, `mongo`) from non-admin users, occurring outside typical automation windows or without known service context. Often followed by data dumps to .sql/.csv files or outbound data transfers. Defender sees CLI tools launched interactively or by unusual parent processes, file writes to dump-like filenames, and external connections shortly after.

auditd:SYSCALL auditd:PATH NSM:Flow
AN0677 Analytic 0677 DET0242

Database client execution (e.g., sqlcmd.exe, isql.exe) by users or from locations not tied to enterprise automation or backups. Often followed by creation of .sql/.bak/.csv files, registry artifacts for ODBC/JDBC drivers, or encrypted ZIPs. Defender sees SQL tools launched by explorer.exe, Powershell, or odd parent processes, plus file writes in user temp locations.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0678 Analytic 0678 DET0242

Execution of Java-based or CLI database tools (e.g., DBeaver, Beekeeper, mysql, psql) from user profiles not tied to dev/admin roles, especially when followed by file writes and cloud sync activity. Defender correlates GUI tool launches, file write events in ~/Downloads or ~/Documents, and outbound API calls to known cloud services.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0681 Analytic 0681 DET0243

Defenders may observe attempts to alter cryptographic settings on network devices that reduce key strength or allowable cipher suites. Suspicious indicators include configuration changes that downgrade encryption algorithms, key length parameters, or the disabling of strong encryption in favor of legacy ciphers. These activities often appear as CLI commands modifying crypto policies, firmware changes affecting crypto libraries, or unexpected updates to key management files. Correlation across device config logs and traffic analysis showing weaker ciphers provides higher confidence of malicious key space reduction.

networkdevice:config networkdevice:cli NSM:Flow
AN0682 Analytic 0682 DET0244

Detection of persistent login hooks configured via defaults or plist modifications that result in execution of scripts or binaries at user login, breaking expected parent-child process lineage.

macos:unifiedlog fs:plist
AN0688 Analytic 0688 DET0246

Detection of unauthorized keylogger behavior through access to `/dev/input`, loading kernel modules (e.g., via insmod), or polling user input devices from non-user shells

linux:syslog linux:syslog
AN0689 Analytic 0689 DET0246

Processes accessing TCC-protected input APIs or polling HID services without user interaction, or dynamically loaded keylogging frameworks using accessibility privileges

macos:unifiedlog macos:osquery
AN0691 Analytic 0691 DET0248

CONTAINERS (Docker/K8s/containerd): A user pulls an untrusted image from a public/unknown registry and then creates/starts a container from that image. Shortly after start, the container spawns unexpected utilities (e.g., curl/wget/bash/python), or makes outbound network connections atypical for the namespace/workload. The analytic correlates Image Creation/Download → Container Creation → Container Start → Command Execution/Network activity within a short window and with a consistent image digest.

containerd:events kubernetes:audit kubernetes:events auditd:SYSCALL NSM:Flow
AN0692 Analytic 0692 DET0248

IAAS (Cloud images/VMs): A new VM/instance is launched from a non-approved or newly-seen image (AMI/GCP Image/Azure Image). On first boot, cloud-init/user-data or embedded agents download code, spawn system utilities, or open outbound C2/mining traffic. The analytic correlates Instance/Image Creation → Instance Start → in-guest Process/Command Execution and/or anomalous network traffic.

AWS:CloudTrail azure:activity WinEventLog:Sysmon NSM:Flow
AN0693 Analytic 0693 DET0249

Remote/API driven creation **and** start of a container whose image is not on an allow‑list (or is tagged `latest`), executed by a non-admin principal, and/or started with risky runtime attributes (e.g., `--privileged`, host PID/NET namespaces, sensitive host path mounts, capability adds). Correlates *create* ➜ *start* ➜ first network/process actions from that container within a short time window.

docker:daemon containerd:runtime ebpf:syscalls docker:events
AN0694 Analytic 0694 DET0250

Defenders observe command-line executions or API-based registry reads targeting sensitive paths like HKLM or HKCU with keyword filters such as 'password', 'cred', or 'logon'. Typically performed by Reg.exe, PowerShell, custom binaries, or offensive tools such as Cobalt Strike. Correlation with process ancestry and command-line arguments indicates suspicious credential discovery activity.

WinEventLog:Sysmon WinEventLog:Sysmon EDR:hunting
AN0698 Analytic 0698 DET0252

User-initiated installation of Python (pip), NodeJS (npm), or other language libraries, followed by unexpected network connections, credential access, or startup file modifications. Defender sees `pip install` or `npm install` commands run by a non-root user, followed shortly by new `.py`, `.sh`, or `.js` files in hidden directories, or interpreter-based execution during boot/login.

auditd:SYSCALL auditd:PATH NSM:Flow
AN0699 Analytic 0699 DET0252

Execution of `pip.exe`, `npm.cmd`, or MSI installers within user context, followed by script interpreter startup (e.g., python.exe) or PowerShell with unusual child processes or file writes in `%APPDATA%`, `%TEMP%`, or `%LOCALAPPDATA%`. Defender correlates command-line install tools with Sysmon and Event Logs to trace downstream behavior.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0700 Analytic 0700 DET0252

Execution of Homebrew, pip3, npm, or manually downloaded PKGs from Terminal or shell, followed by the creation of startup agents, interpreter spawns, or outbound connections to unfamiliar domains. Defender links Terminal commands to plist creation, unsigned binary launches, and `python3` or `node` processes connecting to remote endpoints.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0701 Analytic 0701 DET0253

Detects the creation or modification of `.service` unit files in system/user-level directories, combined with execution of `systemctl`, `service`, or dynamically created drop-ins via systemd generators. Detects persistence by analyzing the `ExecStart` path, file entropy, and symlink usage, especially when paired with execution from `/tmp`, `/dev/shm`, or unmounted volumes.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0703 Analytic 0703 DET0254

Detect alterations of transmitted data via monitoring syscalls (`send`, `recv`, `write`) or middleware interception. Identify mismatched file hashes when compared at origin vs. destination. Watch for anomalous activity from processes interacting with secure transmission services (e.g., OpenSSL, scp).

auditd:SYSCALL linux:syslog
AN0705 Analytic 0705 DET0255

Monitor for use of native utilities such as wevtutil.exe or PowerShell cmdlets (Get-WinEvent, Get-EventLog) to enumerate or export logs. Unusual access to security or system event channels, especially by non-administrative users or processes, should be correlated with subsequent file export or network transfer activity.

WinEventLog:Security WinEventLog:Security
AN0710 Analytic 0710 DET0256

Suspicious reuse of SSH agent sockets across multiple users or processes, anomalous access to ~/.ssh/ or /tmp/ssh-* sockets, and abnormal patterns of lateral movement via SSH without new authentication events. Defender view: detect when one process accesses another user's SSH agent or when an existing SSH connection is used to pivot unexpectedly.

auditd:SYSCALL auditd:EXECVE NSM:Connections
AN0711 Analytic 0711 DET0256

Unusual access to SSH agent sockets in /tmp/ or /private/tmp, process access to another user’s $SSH_AUTH_SOCK, and lateral SSH activity without corresponding login events. Defender view: correlation of socket access with anomalous network flows to internal systems.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0712 Analytic 0712 DET0257

Detects extraction or mounting of container/archive files (e.g., .iso, .vhd, .zip) that originated from the Internet but whose contained files lack Zone.Identifier MOTW tagging. Correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside SmartScreen or Protected View.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0713 Analytic 0713 DET0258

Defender observes unauthorized modification or creation of Python hook files such as `.pth`, `sitecustomize.py`, or `usercustomize.py` in Python `site-packages`, `dist-packages`, or user paths. This is often correlated with subsequent unexpected interpreter execution (e.g., python3 running without user interaction), changes in interpreter behavior (e.g., malicious imports), and outbound connections initiated from Python. Defender links write/modify actions on hook files with execve of python process and/or anomalous child process or network activity.

auditd:SYSCALL auditd:PATH auditd:CONFIG_CHANGE NSM:Flow
AN0714 Analytic 0714 DET0259

Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
AN0715 Analytic 0715 DET0259

Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch

auditd:SYSCALL NSM:Flow
AN0716 Analytic 0716 DET0259

Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications

macos:unifiedlog macos:unifiedlog
AN0720 Analytic 0720 DET0260

On Linux systems, forged credentials may be injected into browser session files, curl/wget headers, or token caches in memory. Detection can leverage auditd to track processes accessing sensitive files (~/.mozilla, ~/.config/chromium, ~/.aws/credentials) and correlate with suspicious outbound connections.

auditd:SYSCALL WinEventLog:Sysmon
AN0724 Analytic 0724 DET0261

Detects file reads across locations followed by writes to temp or staging directories, often compressed or encrypted, indicating local staging behavior.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0725 Analytic 0725 DET0261

Detects aggregation of files from different directories into /tmp, /mnt, or user-specified directories with archiving tools like tar or gzip.

auditd:SYSCALL auditd:SYSCALL
AN0726 Analytic 0726 DET0261

Detects staged data aggregated in /Users/Shared, /private/tmp with compression tools like ditto or zip, initiated via Terminal or AppleScript.

macos:unifiedlog macos:unifiedlog
AN0727 Analytic 0727 DET0261

Detects local staging behavior via snapshot creation or files written into VMFS partitions by scripts or unauthorized shell access.

esxi:vmkernel esxi:shell
AN0728 Analytic 0728 DET0262

Monitor DNS query results where subsequent connections use derived or unusual port numbers not explicitly resolved, especially when tied to suspicious processes. Correlate Sysmon DNS logs (Event ID 22) with process creation and socket activity.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0729 Analytic 0729 DET0262

Inspect resolver and audit logs for processes initiating outbound connections to ports calculated from DNS response IPs. Abnormal ephemeral port usage shortly after DNS queries can indicate DNS calculation behavior.

auditd:SYSCALL linux:syslog
AN0730 Analytic 0730 DET0262

Use unified logs to detect unusual DNS responses correlated with subsequent connections to calculated or non-standard ports. Monitor non-browser apps making repeated outbound connections that deviate from expected patterns.

macos:unifiedlog macos:unifiedlog
AN0733 Analytic 0733 DET0264

Detects JavaScript execution through WSH (wscript.exe, cscript.exe) or HTA (mshta.exe), particularly when spawned from Office macros, web browsers, or abnormal user paths. Correlates script execution with outbound network activity or system modification.

WinEventLog:Sysmon m365:defender WinEventLog:Sysmon
AN0734 Analytic 0734 DET0264

Detects JavaScript for Automation (JXA) via osascript or compiled scripts using OSAKit APIs. Flags execution involving system modification, inter-process scripting, or browser abuse.

macos:unifiedlog macos:osquery macos:syslog
AN0735 Analytic 0735 DET0264

Detects Node.js or JavaScript interpreter execution from web shells, cron jobs, or local users. Correlates execution with reverse shell behavior, file modifications, or abnormal outbound connections.

auditd:SYSCALL linux:syslog
AN0736 Analytic 0736 DET0265

Abuse of launchctl to execute or manage Launch Agents and Daemons. Defender perspective: correlation of suspicious plist file creation or modification in LaunchAgents/LaunchDaemons directories with subsequent execution of the launchctl command. Abnormal executable paths (e.g., /tmp, /Shared) or launchctl activity followed by network connections are highly suspicious.

macos:unifiedlog macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0738 Analytic 0738 DET0266

Detects the use of mail utilities like `mail` or `mailx` to delete mailbox content, or file-level deletion of inbox files from `/var/spool/mail/` or `/var/mail/` following suspicious sessions.

auditd:SYSCALL auditd:SYSCALL
AN0741 Analytic 0741 DET0267

Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks.

WinEventLog:Sysmon Windows:perfmon WinEventLog:Sysmon
AN0742 Analytic 0742 DET0267

Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence.

auditd:SYSCALL linux:procfs NSM:Flow
AN0743 Analytic 0743 DET0267

Background launch agents/daemons with high CPU use and network access to external mining services.

macos:unifiedlog macos:unifiedlog
AN0745 Analytic 0745 DET0267

High CPU usage by unauthorized containers running mining binaries or public proxy tools.

containerd:events prometheus:metrics container:cni
AN0747 Analytic 0747 DET0268

Detects adversarial archiving using libraries (zlib, zip APIs) invoked by scripts or binaries. Correlates process executions of Python, PowerShell, or custom .NET binaries with DLL/module loads linked to compression libraries, followed by archive file creation.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0748 Analytic 0748 DET0268

Detects adversarial archiving by scripts or binaries calling compression libraries (libzip, zlib, bzip2). Correlates execution of Python, Perl, or compiled binaries with dynamic linking to archiving libraries and creation of compressed files in /tmp or user directories.

auditd:SYSCALL auditd:MMAP auditd:FILE
AN0749 Analytic 0749 DET0268

Detects malicious archiving via system or third-party libraries (libz, libarchive) invoked by Python, Swift, or Objective-C binaries. Correlates unified logs of library loads with creation of compressed or encrypted archives (.zip, .gz, .bz2, .dmg).

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0750 Analytic 0750 DET0269

Logon via RDP or WMI by a user account followed by uncommon command execution, file manipulation, or lateral network connections.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0752 Analytic 0752 DET0269

Remote login via ARD or SSH followed by screensharingd process activity or modification of TCC-protected files.

macos:unifiedlog macos:osquery
AN0755 Analytic 0755 DET0270

Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN0760 Analytic 0760 DET0273

Processes like curl, wget, python, socat, or custom binaries initiating TLS/SSL sessions to non-standard destinations. Defender sees abnormal syscalls for connect(), loading of libssl libraries, and persistent outbound encrypted traffic from daemons not normally communicating externally.

auditd:SYSCALL linux:syslog linux:osquery
AN0761 Analytic 0761 DET0273

Applications or launchd jobs initiating encrypted TLS traffic to rare external hosts. Defender observes unified logs showing ssl/TLS API calls by processes not baseline-approved, and payload entropy suggesting encrypted C2 sessions.

macos:unifiedlog macos:unifiedlog
AN0762 Analytic 0762 DET0273

VMware management daemons or guest processes initiating encrypted connections outside expected vCenter, update servers, or internal comms. Defender identifies hostd or vpxa initiating outbound TLS flows with uncommon destinations.

esxi:vpxd esxi:vmkernel
AN0763 Analytic 0763 DET0273

Unusual TLS tunnels through ports not normally encrypted (e.g., TLS on port 8080, 53). Defender sees NetFlow/IPFIX or packet inspection indicating high-entropy traffic volumes and asymmetric client/server exchange ratios.

NSM:Flow NSM:Connections
AN0764 Analytic 0764 DET0274

Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup

WinEventLog:Security WinEventLog:Sysmon
AN0765 Analytic 0765 DET0274

Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0766 Analytic 0766 DET0274

Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0767 Analytic 0767 DET0275

An adversary leverages built-in tools such as certutil.exe, powershell.exe, or copy.exe to decode, reassemble, or extract hidden malicious content from obfuscated containers or encoded formats. The decoding utility often spawns shortly after file staging or download and may be chained with script interpreters or further payload execution.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0770 Analytic 0770 DET0276

Detection of rogue Domain Controller registration and Active Directory replication abuse by correlating: (1) creation/modification of nTDSDSA and server objects in the Configuration partition, (2) unexpected usage of Directory Replication Service SPNs (GC/ or E3514235-4B06-11D1-AB04-00C04FC2DCD2), (3) replication RPC calls (DrsAddEntry, DrsReplicaAdd, GetNCChanges) originating from non-DC hosts, and (4) Kerberos authentication by non-DC machines using DRS-related SPNs. These events in combination, especially from hosts outside the Domain Controllers OU, may indicate DCShadow or rogue DC activity.

WinEventLog:Security WinEventLog:Security WinEventLog:Security m365:dirsync NSM:Flow
AN0774 Analytic 0774 DET0278

Unusual modification of boot records (MBR, VBR) or EFI partitions not associated with legitimate patch cycles or OS upgrades. Registry or WMI events associated with firmware update tools executed from unexpected parent processes. API calls (e.g., DeviceIoControl) writing directly to raw disk sectors. Subsequent abnormal boot configuration changes followed by unsigned driver loads.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0776 Analytic 0776 DET0278

Abnormal modification of EFI firmware binaries in /System/Library/CoreServices/ or NVRAM parameters not associated with OS updates. Unified logs capturing calls to bless or nvram commands executed from untrusted parent processes. Sudden unsigned kext loads after EFI variable tampering.

macos:unifiedlog macos:unifiedlog
AN0778 Analytic 0778 DET0279

Monitor for abnormal creation or modification of Windows services (e.g., via sc.exe, PowerShell, or API calls) that load non-standard executables. Correlate registry changes in service keys with service creation events and process execution to detect service abuse for persistence or execution.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0779 Analytic 0779 DET0279

Detect unusual invocations of systemctl, service, or init scripts creating or modifying daemons. Monitor audit logs for execution of binaries from unexpected paths linked to service start/stop activity.

auditd:SYSCALL linux:syslog auditd:SYSCALL
AN0780 Analytic 0780 DET0279

Monitor launchd service definitions and property list (.plist) modifications for non-standard executables. Detect unauthorized processes registered as launch daemons or agents.

macos:unifiedlog macos:unifiedlog
AN0781 Analytic 0781 DET0280

Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0782 Analytic 0782 DET0281

Monitors for compression tool usage (e.g., 7zip, WinRAR, MakeCab) that follows or precedes file modification, suspicious file types (e.g., .exe, .dll) being compressed, or dropped from self-extracting archives followed by immediate execution.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0783 Analytic 0783 DET0281

Detects sequential command-line compression utilities (e.g., gzip, tar, zip, 7z) followed by execution of unpacked files, especially in temp directories or under non-standard locations like /dev/shm or /tmp with ELF binaries.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0784 Analytic 0784 DET0281

Identifies archive utilities (e.g., ditto, unzip, xar, pkgutil) used to extract payloads to non-standard paths, then correlates with execution or file permission changes (e.g., `chmod +x`) and process spawns from decompressed location.

macos:unifiedlog macos:unifiedlog fs:fsusage
AN0785 Analytic 0785 DET0282

Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0786 Analytic 0786 DET0283

Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon ETW:Token WinEventLog:Security
AN0787 Analytic 0787 DET0284

Unexpected processes (e.g., powershell.exe, wscript.exe, office apps) initiating HTTP POST/PUT requests to text storage domains like pastebin.com or hastebin.com, particularly when preceded by file access in sensitive directories. Defender perspective: correlation of process lineage, large clipboard/file read operations, and outbound uploads to text storage services.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0788 Analytic 0788 DET0284

Use of curl, wget, or custom scripts to POST data to pastebin-like services. Defender perspective: identify chained behavior where files are compressed/read followed by HTTPS POST requests to text-sharing endpoints.

auditd:EXECVE auditd:SYSCALL NSM:Flow
AN0789 Analytic 0789 DET0284

Processes such as osascript, curl, or office applications sending data to text storage APIs/domains. Defender perspective: anomalous clipboard or file reads by unexpected applications immediately followed by outbound HTTPS requests to pastebin-like services.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0790 Analytic 0790 DET0284

ESXi services (vmx, hostd) generating outbound HTTPS POST requests to text storage sites. Defender perspective: anomalous datastore or log reads chained with traffic to pastebin-like destinations.

esxi:hostd esxi:vmkernel
AN0791 Analytic 0791 DET0285

A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0797 Analytic 0797 DET0287

Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window.

WinEventLog:Application WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0798 Analytic 0798 DET0287

Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after.

linux:syslog auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL NetFlow:Flow
AN0799 Analytic 0799 DET0287

Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections.

macos:unifiedlog fs:fsevents macos:osquery NSM:Connections
AN0800 Analytic 0800 DET0288

Correlates suspicious removal or modification of the com.apple.quarantine extended attribute, manipulation of LSFileQuarantineEnabled values in Info.plist, and unexpected process execution of unsigned or non-notarized binaries. Also monitors abnormal trust validation failures in unified logs and unusual activity in QuarantineEvents database entries.

macos:unifiedlog macos:unifiedlog macos:osquery
AN0805 Analytic 0805 DET0290

Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals.

auditd:SYSCALL auditd:SYSCALL
AN0807 Analytic 0807 DET0290

Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence.

esxi:hostd esxi:cron esxi:vmkernel
AN0812 Analytic 0812 DET0292

Detection of file execution where the file name contains a trailing space to masquerade as a known executable. Adversaries may exploit the way command line interpreters handle file names with trailing whitespace.

auditd:SYSCALL linux:syslog
AN0813 Analytic 0813 DET0292

Execution of renamed or dropped files with a trailing space to deceive users or analysts, especially in LaunchAgents or LaunchDaemons.

macos:unifiedlog fs:fsusage
AN0819 Analytic 0819 DET0294

User opens a file delivered by email, web, chat, or share. The handler application (Word/PDF reader/archiver) creates a file in user-controlled paths (Downloads, Temp, Desktop) and then spawns a new or unusual child process (e.g., powershell.exe, wscript.exe, cmd.exe, regsvr32.exe, rundll32.exe, msiexec.exe). Optional precursors include FileStreamCreated (URL/UNC) and Office → system32 batch writes.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0820 Analytic 0820 DET0294

User opens a downloaded document/installer leading to EndpointSecurity file create in ~/Downloads or ~/Library paths then an exec of a suspicious utility (osascript, bash/zsh, curl, chmod, open with -a Terminal). Correlates File Creation with subsequent process exec and, optionally, quarantine/LSQuarantine events.

macos:unifiedlog macos:endpointsecurity
AN0821 Analytic 0821 DET0294

User or desktop application writes a new file to ~/Downloads, /tmp, or mounted removable media followed by execve of a risky interpreter/loader (bash, sh, python, perl, php, node, curl|wget piping to sh, ld.so, rdesktop, xdg-open - with unusual args). Uses auditd PATH+SYSCALL (open/creat/write/rename) with execve event linking.

auditd:SYSCALL auditd:SYSCALL
AN0822 Analytic 0822 DET0295

Detects hijacking of an existing thread (OpenThread) through a behavioral chain involving thread suspension (SuspendThread), memory modification (VirtualAllocEx + WriteProcessMemory), context manipulation (SetThreadContext), and thread resumption—all within another live process's address space (ResumeThread).

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process WinEventLog:Sysmon
AN0824 Analytic 0824 DET0296

Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation.

auditd:SYSCALL NSM:Flow
AN0825 Analytic 0825 DET0296

Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception.

macos:unifiedlog NSM:Flow
AN0827 Analytic 0827 DET0297

Processes attempting raw disk access to overwrite sensitive structures such as the MBR or partition table using \\.\PhysicalDrive notation. Detection relies on correlating process creation, privilege escalation, and raw sector writes in Sysmon and Security logs.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0828 Analytic 0828 DET0297

Execution of utilities (dd, hdparm, sgdisk) or custom binaries attempting to overwrite disk boot structures (/dev/sda MBR sector or partition tables). Detection correlates shell execution with syscalls writing to sector 0 or disk metadata blocks.

auditd:SYSCALL auditd:EXECVE
AN0831 Analytic 0831 DET0298

Detects adversarial archiving using built-in or third-party utilities (makecab, diantz, xcopy, certutil, 7z, WinRAR, WinZip). Correlates suspicious process creation events with command-line arguments for compression/encoding, followed by creation of archive files (.cab, .zip, .7z, .rar). Identifies anomalous loading of crypt32.dll for encryption operations or execution of diantz.exe to compress remotely staged files.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0832 Analytic 0832 DET0298

Detects execution of archiving utilities (tar, gzip, bzip2, xz, zip, openssl) followed by suspicious archive file creation. Correlates archive creation in temporary or staging directories with execution of commands involving compression or encryption options.

auditd:SYSCALL auditd:FILE
AN0833 Analytic 0833 DET0298

Detects invocation of macOS-native archiving utilities (zip, ditto, hdiutil) or openssl used for encryption. Correlates execution with archive or encrypted file creation (.zip, .dmg, .tar.gz) in user or temporary directories. Identifies anomalous use of archiving commands by Office applications or daemons.

macos:unifiedlog macos:unifiedlog
AN0834 Analytic 0834 DET0299

Sequential behavioral chain of privilege escalation through permission modification: (1) Process creation of permission-modifying utilities (icacls, takeown, attrib, cacls), (2) Correlation with unusual user context or timing, (3) DACL modification events targeting sensitive files/directories, (4) Subsequent file access or modification attempts indicating successful privilege bypass

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell
AN0836 Analytic 0836 DET0299

macOS-specific permission modification behavioral chain: (1) chmod/chown/chflags process execution, (2) System Integrity Protection (SIP) bypass attempts, (3) Extended attribute (xattr) modifications, (4) Unified log correlation with file system events, (5) Subsequent access to previously restricted resources

macos:unifiedlog fs:fsevents
AN0838 Analytic 0838 DET0300

Detect anomalous chains of memory allocation and execution inside the same process (e.g., VirtualAlloc → memcpy → VirtualProtect → CreateThread). Unlike process injection, reflective code loading does not perform cross-process memory writes — the suspicious activity occurs entirely within the process’s own PID context.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-DotNETRuntime etw:Microsoft-Antimalware-Scan-Interface WinEventLog:Sysmon
AN0839 Analytic 0839 DET0300

Monitor for in-process mmap + mprotect + execve/execveat activity where memory permissions are changed from writable to executable inside the same process without a corresponding ELF on disk.

auditd:SYSCALL auditd:MMAP
AN0840 Analytic 0840 DET0300

Suspicious calls to dlopen(), dlsym(), or mmap with RWX flags in processes that do not typically perform dynamic module loading. Monitor anonymous memory regions executed by user processes.

macos:unifiedlog macos:unifiedlog
AN0841 Analytic 0841 DET0301

Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools.

WinEventLog:System WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Windows Defender/Operational
AN0842 Analytic 0842 DET0302

A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
AN0843 Analytic 0843 DET0302

A source performs a short closed-port sequence; the host then modifies iptables/nftables/ufw rules or starts a daemon binding a new socket, followed by a successful connection from the same source.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN0844 Analytic 0844 DET0302

A source performs a closed-port sequence; the endpoint enables a PF/socketfilterfw rule or a background process binds a port; then a successful connection completes from the same source.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0846 Analytic 0846 DET0303

Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.

WinEventLog:Sysmon
AN0847 Analytic 0847 DET0303

Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.

auditd:PATH linux:Sysmon
AN0848 Analytic 0848 DET0303

Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.

macos:unifiedlog
AN0849 Analytic 0849 DET0303

Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.

vpxd.log esxi:shell
AN0850 Analytic 0850 DET0304

Exploitation of system or application vulnerability (e.g., CVE-based exploit) followed by service crash, restart, or repeated failure within a short time frame, impacting application/system availability.

WinEventLog:Application WinEventLog:Sysmon WinEventLog:System
AN0851 Analytic 0851 DET0304

User or remote input triggers application crash or segmentation fault (e.g., SIGSEGV) with service recovery attempts, observed via audit logs and systemd journaling.

auditd:SYSCALL journald:Application NSM:Flow
AN0852 Analytic 0852 DET0304

Application crash or repeated restart cycle triggered by malformed input or exploit file, observed via unified logs and process crash monitoring.

macos:unifiedlog macos:unifiedlog
AN0853 Analytic 0853 DET0304

Cloud workload exploitation leads to repeated container, service, or VM termination/restart, typically associated with CVE-based crash triggers or fuzzed payloads.

AWS:CloudTrail AWS:CloudWatch AWS:VPCFlowLogs
AN0854 Analytic 0854 DET0305

Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf).

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0856 Analytic 0856 DET0307

Correlated file access to insecure credential files (e.g., *.env, *.xml, *.ps1) followed by suspicious process execution or authentication using retrieved credentials. Detected through Sysmon logs and Windows Security Event logs.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0861 Analytic 0861 DET0308

Detection focuses on identifying unauthorized or anomalous changes to compute infrastructure components. Defender perspective: monitor for creation, deletion, or modification of instances, volumes, and snapshots outside of approved change management windows; correlate abnormal activity such as rapid snapshot creation followed by new instance mounts, or repeated infrastructure changes by rarely used accounts. Flagging activity linked to unusual geolocation, API client, or automation script is suspicious.

AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudWatch
AN0862 Analytic 0862 DET0309

Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-CodeIntegrity/Operational NSM:Flow
AN0863 Analytic 0863 DET0309

A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress.

auditd:SYSCALL journald:package NSM:Flow
AN0864 Analytic 0864 DET0309

A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems.

macos:unifiedlog macos:endpointsecurity NSM:Flow
AN0868 Analytic 0868 DET0311

Detection of inconsistencies between reported sensor health and actual process/service state. For example, Windows Defender tray icon/UI showing healthy status while corresponding Defender services (WinDefend, MsMpEng) are stopped or disabled. Correlates process creation events with missing or terminated security processes and spoofed health events.

WinEventLog:System WinEventLog:Sysmon
AN0869 Analytic 0869 DET0311

Monitoring for discrepancies between system daemon/service state and reported health messages (e.g., syslog shows AV/IDS daemon stopped, but spoofed messages claim it is still running). Detects userland processes impersonating AV/IDS command-line outputs or modifying log forwarding configurations.

auditd:SYSCALL linux:syslog
AN0870 Analytic 0870 DET0311

Detection of fake or spoofed macOS Security & Privacy GUIs showing healthy status after XProtect, Gatekeeper, or AV processes are disabled. Correlates user-space UI process creation with terminated or missing security daemons.

macos:unifiedlog macos:unifiedlog
AN0871 Analytic 0871 DET0312

Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0872 Analytic 0872 DET0313

Detection of browser-based or email client-driven file creation (often from temp directories) following navigation to or execution of HTML files containing JavaScript Blob APIs or base64 Data URLs, with follow-on execution of the dropped payload. Leveraging Sysmon EventID 15 to inspect Zone.Identifier ADS for HostUrl/ReferrerUrl indicators (e.g., HostUrl=about:internet). Optional: absence of a large HTTP download record for the same URL/client in proxy logs (suggests local assembly)

WinEventLog:Sysmon WinEventLog:Sysmon EDR:detection WinEventLog:Sysmon Network Traffic
AN0873 Analytic 0873 DET0313

Detection of browser-based downloads from HTML sources that trigger file creation in temp or user directories followed by execution of new files within short timeframes and suspicious parent-child lineage.

auditd:SYSCALL linux:osquery
AN0874 Analytic 0874 DET0313

Detection of HTML-based downloads via Safari/Chrome that create obfuscated files (e.g., .zip, .app, .js) in user directories and are followed by suspicious executions from preview or launch services.

macos:unifiedlog macos:osquery gatekeeper/quarantine database
AN0875 Analytic 0875 DET0314

Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture.

WinEventLog:Security WinEventLog:System
AN0876 Analytic 0876 DET0314

Correlates interface mode changes to promiscuous with execution of sniffing tools like tcpdump, tshark, or custom pcap libraries. Detects abnormal NIC configurations and unauthorized sniffing from non-root sessions.

auditd:SYSCALL auditd:SYSCALL networkconfig
AN0877 Analytic 0877 DET0314

Detects enabling of interface sniffing via packet capture tools or AppleScript triggering `tcpdump`. Leverages Unified Logs and process lineage to identify suspicious use of `pfctl`, `tcpdump`, or `libpcap` libraries.

macos:unifiedlog macos:osquery fs:fsusage
AN0879 Analytic 0879 DET0314

Detects execution of capture commands via CLI (`monitor capture`, `debug packet`, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear.

networkdevice:syslog networkdevice:syslog networkdevice:syslog
AN0880 Analytic 0880 DET0315

Adversaries create the 'Office Test\Special\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Office-Alerts
AN0882 Analytic 0882 DET0316

Processes attempting raw disk access via \\.\PhysicalDrive paths, abnormal file I/O to MBR/boot sectors, or loading of third-party drivers (e.g., RawDisk) that enable disk overwrite. Correlate process creation, privilege usage, and disk modification events within a short time window.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0883 Analytic 0883 DET0316

Execution of destructive utilities (dd, shred, wipe) targeting block devices, or processes invoking syscalls to directly overwrite /dev/sd* or /dev/nvme* partitions. Correlate abnormal file write attempts with shell process execution and block device access.

auditd:SYSCALL auditd:EXECVE
AN0895 Analytic 0895 DET0318

Processes such as PowerShell, Git, or curl initiating outbound HTTPS POST requests to known code repository APIs (e.g., github.com, gitlab.com) immediately following large file reads. Defender view: correlation between file access of sensitive directories (e.g., Documents, Finance) and abnormal data uploads to repository domains.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0897 Analytic 0897 DET0318

Office or scripting applications initiating unusual HTTPS traffic to code repository APIs with high outbound-to-inbound ratios. Defender perspective: monitor for sensitive file access in combination with network connections to github.com, gitlab.com, or bitbucket.org.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0903 Analytic 0903 DET0320

Detects usage of commands or binaries (e.g., netstat, PowerShell Get-NetTCPConnection) and WMI or API calls to enumerate local or remote network connections.

WinEventLog:Sysmon WinEventLog:PowerShell
AN0904 Analytic 0904 DET0320

Detects use of netstat, ss, lsof, or custom shell scripts to list current network connections. Often paired with privilege escalation or staging.

auditd:SYSCALL linux:cli
AN0905 Analytic 0905 DET0320

Detects shell-based enumeration of active connections using `netstat`, `lsof -i`, or AppleScript-based system discovery.

macos:osquery
AN0908 Analytic 0908 DET0320

Detects enumeration of cloud network interfaces, VPCs, subnets, or peer connections using CLI or SDKs (e.g., AWS CLI, Azure CLI, GCloud CLI).

AWS:CloudTrail azure:activity
AN0909 Analytic 0909 DET0321

Unusual execution of virtualization binaries (VBoxManage.exe, vmware-vmx.exe, vmwp.exe) with headless or suppressed notification arguments. Registry and service modifications linked to virtualization installs. Defender view: anomalies in process creation, service metadata, and registry writes tied to enabling hidden VMs.

WinEventLog:Sysmon WinEventLog:System WinEventLog:Security
AN0910 Analytic 0910 DET0321

Execution of QEMU, KVM, or VirtualBox processes with unusual flags (e.g., '-nographic', '-snapshot'). File creation of VM images in atypical directories. Defender view: monitoring audit logs for process executions and file modifications linked to hidden virtualization.

auditd:SYSCALL auditd:SYSCALL
AN0911 Analytic 0911 DET0321

Execution of virtualization binaries (Parallels, VMware Fusion, VirtualBox) with arguments to hide UI. File monitoring for plist modifications indicating hidden virtualization behavior. Defender perspective: tracking process lineage and file modifications in system configs.

macos:unifiedlog macos:unifiedlog
AN0913 Analytic 0913 DET0322

Detects the presence of executables with high NOP padding, unusually large binary size for their function, and follow-on execution or memory injection from such files, especially when originating from temp or user-space paths.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0914 Analytic 0914 DET0322

Detects ELF binaries written to disk that demonstrate anomalous file size or entropy, quickly followed by execution or memory region writes into remote processes (e.g., using ptrace).

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0915 Analytic 0915 DET0322

Identifies Mach-O binaries dropped into temporary directories with abnormally high binary size or padding patterns, followed by privilege escalation, `exec`, or memory mapping of other processes.

macos:endpointsecurity macos:endpointsecurity macos:endpointsecurity
AN0916 Analytic 0916 DET0323

Detection of anomalous driver and firmware interactions, including unsigned or unexpected firmware updates, driver loads linked to hardware components, and suspicious use of privileged APIs to read/write firmware or controller memory.

WinEventLog:Sysmon firmware:integrity
AN0917 Analytic 0917 DET0323

Detection of suspicious use of ioctl/sysfs calls to access device firmware, unexpected flashing tools execution, and anomalous firmware checksums logged by SMART or kernel audit mechanisms.

auditd:SYSCALL linux:syslog
AN0919 Analytic 0919 DET0324

Identifies self-modifying executables that exhibit changes in binary hash, entropy, or memory sections during or between executions—often tied to dynamic unpacking or decryption behaviors.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0920 Analytic 0920 DET0324

Detects files or processes where execution results in frequent re-creation or modification of ELF binaries or interpreter scripts, often using chmod + execve with abnormal entropy.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN0921 Analytic 0921 DET0324

Tracks modification of executables or interpreter payloads (e.g., Mach-O, dylib) that mutate across runs—using scripting engines, JIT compilers, or side-loaded plugins.

macos:unifiedlog fs:fsusage macos:endpointsecurity macos:endpointsecurity
AN0922 Analytic 0922 DET0325

Unusual process (e.g., `rundll32`, `mshta`, `wscript`, or custom payloads) initiates network connection to external IPs/domains that proxy C2 traffic, often over uncommon ports or high entropy HTTP/S connections.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Windows Defender/Operational
AN0923 Analytic 0923 DET0325

`curl`, `wget`, `ncat`, `socat`, or custom binaries initiate outbound traffic to Internet-based proxies (e.g., via VPS or CDN). Behavior may include reverse shell constructs or persistent outbound beacons.

auditd:SYSCALL NSM:Flow NSM:Flow
AN0924 Analytic 0924 DET0325

AppleScript or terminal sessions launch tools (`curl`, `nc`, `ssh`) to external IPs not commonly accessed. Outbound connections are made by LaunchAgents/LaunchDaemons, often masquerading as system services.

macos:unifiedlog NSM:Flow macos:osquery
AN0925 Analytic 0925 DET0325

ESXi shell or guest VM tools initiate external connections via scripted traffic forwarding to Internet-based proxies. Detected by firewall or shell audit logs showing outbound connection spikes from hypervisor or guest VM to remote proxy nodes.

esxi:shell esxi:vmkernel NSM:Flow
AN0927 Analytic 0927 DET0326

A process/script constructs or references a custom/alphabet translation table (e.g., 64/85/32+ arbitrary chars, XOR/base-N loops) or emits long high-entropy strings that do NOT validate as standard Base64/Hex → shortly after, the same process (or its child) generates outbound traffic with asymmetric bytes_out:bytes_in, fixed-size beacons, or protocol/header mismatches (e.g., Content-Type says JSON but body fails JSON parse / contains non-standard alphabet).

WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell m365:defender
AN0928 Analytic 0928 DET0326

Shell scripts or binaries implement custom mapping tables (tr/sed/awk/golang/rust/python encode loops), or emit long high-entropy tokens that fail Base64/Hex validation → correlated with egress showing asymmetric flow, protocol-mismatch payloads, or DNS/HTTP bodies containing low-diversity-but-long custom alphabets.

auditd:SYSCALL WinEventLog:Sysmon NSM:Flow
AN0929 Analytic 0929 DET0326

EndpointSecurity/Unified Logs show processes generating custom alphabets or long high-entropy, non-standard tokens → network logs (PF/Zeek/EDR) show asymmetric beacons, protocol mismatches, or periodic fixed-size posts.

macos:endpointsecurity PF:Logs NSM:Flow
AN0930 Analytic 0930 DET0326

ESXi shell or scripts produce long, high-entropy tokens (non-standard alphabets) in shell.log/hostd, followed by outbound flows (NSX/Zeek) with asymmetric ratios or protocol mismatches to non-management endpoints.

esxi:shell esxi:hostd NSM:Flow NSM:Flow
AN0931 Analytic 0931 DET0327

Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN0932 Analytic 0932 DET0328

Execution of CMSTP.exe with arguments pointing to suspicious or remote INF/SCT/DLL payloads, optionally followed by outbound network connections to untrusted IPs, process injection via COM interfaces (CMSTPLUA, CMLUAUTIL), registry modifications registering malicious profiles, or creation of suspicious INF/DLL/SCT files prior to execution.

WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0933 Analytic 0933 DET0329

Process chains that use native utilities (vssadmin, wbadmin, diskshadow, bcdedit, REAgentC, wmic) with arguments to delete shadow copies, disable recovery, or remove backup catalogs

WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Backup WinEventLog:System WinEventLog:Sysmon
AN0938 Analytic 0938 DET0330

Correlation of package install event with execution of postinstall scripts containing unknown binaries or abnormal CLI usage. Look for `/usr/sbin/installer` execution followed by child processes originating from postinstall script.

macos:unifiedlog macos:unifiedlog
AN0939 Analytic 0939 DET0330

Detection of maintainer scripts (e.g., postinst, preinst) being modified or executed during dpkg or rpm operations. Watch for script content that spawns additional processes or writes outside package scope.

auditd:SYSCALL auditd:SYSCALL
AN0940 Analytic 0940 DET0330

Detection of msiexec.exe running installer packages that result in anomalous process creation. Look for unexpected binaries executed by msiexec or custom action DLLs in the temp directory.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0941 Analytic 0941 DET0331

Detects the use of message-based injection by monitoring for sequences involving FindWindow (EnumWindows or EnumChildWindows), VirtualAllocEx or related API calls, combined with suspicious PostMessage/SendMessage (e.g., LVM_SETITEMPOSITION) use to SysListView32 controls, followed by LVM_SORTITEMS invocation instead of WriteProcessMemory.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Win32k
AN0942 Analytic 0942 DET0332

Detects execution of AutoHotKey or AutoIT interpreters or compiled scripts used for unauthorized automation, command execution, or payload delivery, correlated with anomalous process lineage, command-line arguments, or script creation events.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0943 Analytic 0943 DET0333

Detects creation of scheduled tasks via `at.exe` or WMI `Win32_ScheduledJob` class, followed by execution of anomalous processes by svchost.exe or taskeng.exe.

WinEventLog:Security WinEventLog:Sysmon
AN0944 Analytic 0944 DET0333

Detects usage of `at` command to schedule jobs, followed by job execution and modification of job files under /var/spool/cron/atjobs.

auditd:SYSCALL auditd:SYSCALL
AN0945 Analytic 0945 DET0333

Detects user or root invocation of `at` command to schedule a job, followed by job execution using LaunchServices and activity in /usr/lib/cron/at.

macos:unifiedlog fs:fsusage macos:osquery
AN0948 Analytic 0948 DET0335

Detects anomalous use of macOS XPC services for code execution. Monitors for processes invoking privileged XPC daemons with abnormal parameters, unexpected binaries communicating over NSXPCConnection, or helper tools executing code outside of their expected parent process lineage. Correlates process access attempts to system-level daemons, privilege escalations via XPC misconfigurations, and injection of malicious payloads through inter-process communication.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN0949 Analytic 0949 DET0336

Monitors for unexpected modifications of system or application binaries, particularly signed executables. Correlates file write events with subsequent unsigned or anomalously signed process execution, and checks for tampered binaries outside normal patch cycles.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN0950 Analytic 0950 DET0336

Detects modification of system or application binaries by monitoring /usr/bin, /bin, and other privileged directories. Correlates file integrity monitoring (FIM) events with unexpected process executions or service restarts.

auditd:SYSCALL auditd:EXECVE
AN0951 Analytic 0951 DET0336

Monitors binary modification in /Applications and system library paths. Detects unsigned or improperly signed binaries executed after modification. Tracks Gatekeeper or notarization bypass attempts tied to modified binaries.

macos:unifiedlog macos:unifiedlog
AN0954 Analytic 0954 DET0338

Use of stolen Kerberos tickets or token impersonation resulting in logon sessions from accounts without expected interactive logon events.

WinEventLog:Security WinEventLog:Sysmon
AN0961 Analytic 0961 DET0339

Defenders may observe unauthorized modifications to encryption-related configuration files, firmware, or crypto modules on network devices. Suspicious patterns include changes to cipher suite configurations, unexpected firmware updates affecting crypto libraries, disabling of hardware cryptographic accelerators, or reductions in key length policies. Correlating configuration changes with anomalies in encrypted traffic characteristics (e.g., weaker ciphers or sudden plaintext transmission) strengthens detection.

networkdevice:config NSM:Flow snmp:status
AN0962 Analytic 0962 DET0340

A user is socially engineered (web page, email, document) to open Run/PowerShell/CMD and paste an obfuscated one-liner. The chain is: (1) user context active in a browser/email/office app → (2) process creation of a command interpreter with suspicious arguments (base64/Invoke-Expression/web download/pipeline to shell) → (3) optional file drop in %TEMP% or %APPDATA% → (4) outbound network connection to an external domain. Events are correlated within a short window and with consistent user/session.

WinEventLog:Security WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN0963 Analytic 0963 DET0340

User pastes a multi-line or one-liner into a terminal (bash/zsh) that downloads/decodes and executes content. Chain: terminal exec of curl/wget/bash/sh with pipe to interpreter or base64-decode → transient file under /tmp|~/.cache → immediate outbound egress.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN0964 Analytic 0964 DET0340

User pastes an obfuscated command into Terminal.app/iTerm2 that decodes or downloads code and executes. Detects Terminal/iTerm2 spawning bash/zsh/python with suspicious pipeline/base64 patterns followed by file writes in ~/Library or /tmp and outbound network connections.

macos:unifiedlog macos:osquery macos:unifiedlog NSM:Flow
AN0965 Analytic 0965 DET0341

Detection of clipboard access via OS utilities (e.g., clip.exe, Get-Clipboard) by non-interactive or abnormal parent processes, potentially chained with staging or exfiltration commands.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0966 Analytic 0966 DET0341

Detection of pbpaste/pbcopy clipboard access by processes without terminal sessions or linked to launch agents, potentially staged for collection.

macos:unifiedlog
AN0967 Analytic 0967 DET0341

Detection of xclip or xsel access to clipboard buffers outside of user terminal context, especially when chained to staging (gzip, base64) or network exfiltration (curl, scp).

auditd:SYSCALL
AN0968 Analytic 0968 DET0342

Execution of hh.exe to open a .chm file followed by suspicious child processes or script engine invocation (VBScript, JScript, mshta, powershell). Behavior includes loading a CHM file from untrusted locations, or immediately spawning commands indicative of payload execution.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN0969 Analytic 0969 DET0343

High-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness.

WinEventLog:Sysmon WinEventLog:Security
AN0970 Analytic 0970 DET0343

Kernel or userland processes generating high-rate network traffic (ICMP, UDP, TCP SYN) beyond expected interface throughput or user behavior norms.

auditd:SYSCALL auditd:SYSCALL
AN0971 Analytic 0971 DET0343

Excessive outbound traffic via `ping`, `curl`, or custom scripts indicating flooding behavior, especially with no UI context or user interaction.

macos:unifiedlog macos:unifiedlog
AN0973 Analytic 0973 DET0344

Detects abuse of fileless storage mechanisms such as Registry keys, WMI classes, and Event Logs used to stage payloads, scripts, or encoded content outside traditional files.

WinEventLog:Security WinEventLog:Application
AN0974 Analytic 0974 DET0344

Detects usage of shared memory directories (/dev/shm, /run/shm) for temporary storage of obfuscated, encoded, or executable data without persistence to disk.

auditd:SYSCALL linux:osquery
AN0975 Analytic 0975 DET0345

Correlate registry modifications (e.g., UAC bypass registry keys), unusual parent-child process relationships (e.g., control.exe spawning cmd.exe), and unsigned elevated process executions with non-standard tokens or elevation flags.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN0977 Analytic 0977 DET0345

Detect execution of `/usr/libexec/security_authtrampoline` or use of AuthorizationExecuteWithPrivileges API, and monitor process lineage for unusual launches of GUI apps with escalated privileges.

macos:unifiedlog auditd:SYSCALL fs:fsusage
AN0980 Analytic 0980 DET0346

Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk.

WinEventLog:Sysmon WinEventLog:Sysmon
AN0981 Analytic 0981 DET0346

Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes.

macos:unifiedlog
AN0982 Analytic 0982 DET0346

Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes.

auditd:SYSCALL
AN0983 Analytic 0983 DET0347

Detects processes or binaries executed from trusted directories (e.g., System32) or using trusted names (e.g., svchost.exe) where the metadata, hash, or parent process does not align with legitimate activity patterns.

WinEventLog:Security WinEventLog:Sysmon
AN0984 Analytic 0984 DET0347

Detects renamed binaries or scripts placed into trusted paths like /usr/bin or /lib with mismatched metadata or unexpected creation/modification times.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL linux:osquery
AN0987 Analytic 0987 DET0347

Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services.

esxi:vmkernel esxi:vmkernel esxi:hostd esxi:hostd
AN0988 Analytic 0988 DET0348

Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access.

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow WinEventLog:Security
AN0989 Analytic 0989 DET0348

Monitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads.

auditd:SYSCALL auditd:SYSCALL NSM:Flow NSM:Flow
AN0990 Analytic 0990 DET0348

Detects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios.

macos:unifiedlog macos:osquery macos:osquery
AN0991 Analytic 0991 DET0348

Detects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa.

esxi:vpxa esxi:vmkernel esxi:syslog
AN0992 Analytic 0992 DET0349

Detect suspicious file creations and process executions triggered by browser activity (e.g., injected payloads written to %AppData% or Temp directories, then executed). Correlate network anomalies with subsequent local process creation or script execution.

WinEventLog:Security WinEventLog:Sysmon NSM:Flow
AN0993 Analytic 0993 DET0349

Detect curl/wget commands saving executable/script payloads to /tmp or /var/tmp followed by execution. Monitor packet captures or IDS/IPS alerts for injected responses or mismatched content types.

auditd:SYSCALL WinEventLog:Sysmon NSM:Flow
AN0994 Analytic 0994 DET0349

Monitor unified logs for processes spawned from Safari or other browsers that immediately load scripts or executables. Detect file drops in ~/Library/Caches or ~/Downloads that execute shortly after being written.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN0995 Analytic 0995 DET0350

Detection of processes launching downgraded PowerShell versions (e.g., v2) or other legacy binaries that lack logging or security features. Correlates command-line arguments, process metadata, and version fields. Monitors registry changes to Defender or HVCI keys that could indicate intentional downgrades.

WinEventLog:Sysmon WinEventLog:Security
AN0997 Analytic 0997 DET0350

Detection of execution of legacy scripting runtimes (e.g., older versions of Python, Bash, or PowerShell Core) lacking auditing. Monitoring for changes to EFI or system boot files indicative of downgrade-based persistence or bypass of integrity features.

macos:unifiedlog macos:unifiedlog
AN0998 Analytic 0998 DET0351

Linux permission escalation behavioral chain: (1) Process creation of permission modification utilities (chmod, chown, chgrp, setfacl) with suspicious parameters indicating privilege escalation intent, (2) System call analysis revealing direct file metadata manipulation (chmod, fchmod, chown, fchown syscalls), (3) Extended attribute and ACL modifications targeting critical system paths, (4) Temporal correlation with subsequent file access or process execution from modified locations, (5) Anomalous permission patterns deviating from system baselines

auditd:SYSCALL auditd:PROCTITLE linux:osquery
AN0999 Analytic 0999 DET0351

macOS permission and attribute manipulation behavioral chain: (1) Process execution of permission utilities (chmod, chown, chgrp) or macOS-specific tools (chflags) with suspicious parameters, (2) System Integrity Protection (SIP) bypass attempts through permission modifications, (3) File flags manipulation (uchg, schg, hidden) for evasion or persistence, (4) Extended attribute (xattr) modifications affecting security metadata, (5) Unified log correlation with file system events and subsequent access patterns, (6) Gatekeeper and code signing bypass through permission/attribute manipulation

macos:unifiedlog fs:fsevents OpenBSM:AuditTrail
AN1005 Analytic 1005 DET0354

Repeated SSH, VPN, or RDP gateway authentication attempts from external IPs → subsequent successful logon → remote shell or lateral movement activity (e.g., scp/sftp).

auditd:SYSCALL NSM:Connections NSM:Flow
AN1006 Analytic 1006 DET0354

Unexpected inbound or outbound VNC/SSH/Screen Sharing connections from external sources → repeated failed logins followed by success → remote interactive sessions or abnormal file transfers.

macos:unifiedlog macos:unifiedlog PF:Logs
AN1007 Analytic 1007 DET0354

Connections to exposed container services (e.g., Docker API, Kubernetes API server) from unauthorized external IPs → abnormal container creation/start → lateral activity within cluster nodes.

ApplicationLog:API kubernetes:audit NSM:Flow
AN1008 Analytic 1008 DET0355

Detect abnormally high volume of inbound email messages or repetitive attachments being delivered to a single mailbox within a short time window. Defenders should look for anomalous spikes in message counts and repetitive attachment file creation events correlated with targeted users.

m365:unified WinEventLog:Sysmon
AN1009 Analytic 1009 DET0355

Monitor mail server logs (e.g., Postfix, Sendmail) for excessive connections or inbound message counts targeting a single recipient. Correlate with repetitive attachment storage in /var/mail or /var/spool/mail directories.

auditd:SYSCALL Application:Mail
AN1011 Analytic 1011 DET0355

Monitor unified logs and Mail.app activity for repetitive incoming messages with attachments. Defenders should look for large volumes of incoming mail stored under ~/Library/Mail with unusual timing or repetitive subjects.

macos:unifiedlog fs:fsusage
AN1012 Analytic 1012 DET0356

Burst of incomplete TCP handshakes (e.g., SYN floods) or uncorrelated ACK packets targeting the state table resulting in OS resource exhaustion.

WinEventLog:Sysmon WinEventLog:Microsoft-Windows-TCPIP NSM:Firewall
AN1013 Analytic 1013 DET0356

Flood of spoofed SYN or ACK packets causing exhaustion of OS TCP state table, potentially via user-space utilities or kernel-level DoS agents.

auditd:SYSCALL NSM:Flow NSM:Flow
AN1014 Analytic 1014 DET0356

Adversary tool/script issuing mass SYN/ACK floods that degrade OS responsiveness and interrupt service response on macOS endpoints.

macos:unifiedlog macos:osquery NSM:Firewall
AN1015 Analytic 1015 DET0357

Execution of utilities (e.g., ping, tracert, Test-NetConnection) or scripted methods to test Internet connectivity by interacting with external IPs/domains.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Security
AN1016 Analytic 1016 DET0357

Execution of ping, traceroute, or curl/wget against public IPs/domains to verify Internet reachability.

auditd:EXECVE linux:syslog
AN1017 Analytic 1017 DET0357

Execution of ping, traceroute, or network utility tools to external destinations; may include `scutil` or system_profiler.

macos:unifiedlog
AN1018 Analytic 1018 DET0357

Execution of `ping`, `vmkping`, or `curl` from shell or through automation jobs/scripts to verify Internet egress.

esxi:shell esxi:hostd
AN1019 Analytic 1019 DET0358

Detection of excessive or programmatic access to Confluence spaces or pages, particularly by privileged users, through a combination of access logs, API usage, and identity context. Correlates logon sessions, user roles, and abnormal document viewing or export behavior. Identifies burst access patterns and tools/scripts abusing the Confluence API for mass enumeration or data scraping.

saas:confluence saas:confluence saas:confluence
AN1020 Analytic 1020 DET0359

Suspicious processes (e.g., Tor clients, relays, unknown binaries) launch with sustained encrypted outbound traffic to known anonymity infrastructure (e.g., Tor, I2P), and may relay to additional internal systems via reverse proxying, ICMP tunneling, or socket forwarding.

WinEventLog:Sysmon WinEventLog:Sysmon dns:query
AN1021 Analytic 1021 DET0359

Tools such as `tor`, `nglite`, `proxychains`, `chisel`, or custom daemons repeatedly initiate outbound sessions to multiple nodes before final destination. This behavior is abnormal for Linux services outside of VPN, monitoring, or CDN relay contexts.

auditd:SYSCALL NSM:Flow Netfilter/iptables
AN1022 Analytic 1022 DET0359

LaunchAgents or LaunchDaemons initiate persistent Tor or relay processes that make encrypted outbound connections. May be paired with sandbox bypasses or unsigned executables communicating over SOCKS proxies.

macos:unifiedlog macos:osquery macos:unifiedlog
AN1023 Analytic 1023 DET0359

Outbound encrypted traffic initiated from hypervisor shell or via VM backdoor mechanisms to relays in VPS infrastructure, especially if traversing multiple nodes before reaching Internet destination. Packet captures or firewall logs show non-VM communication paths.

esxi:esxupdate esxi:vmkernel NSM:Flow
AN1024 Analytic 1024 DET0359

Encrypted traffic or ICMP tunneling from border routers to internal routers or unknown external IPs. Forwarded traffic shows consistent hop-to-hop relaying without matching configured VPN or expected network topology.

NSM:Flow NSM:Firewall networkdevice:syslog
AN1025 Analytic 1025 DET0360

Detection of domain group enumeration through command-line utilities such as 'net group /domain' or PowerShell cmdlets, followed by suspicious access to API calls or LSASS memory.

WinEventLog:Security WinEventLog:PowerShell
AN1026 Analytic 1026 DET0360

Behavioral detection of domain group enumeration via ldapsearch or custom scripts leveraging LDAP over the network.

auditd:SYSCALL linux:syslog NSM:Flow
AN1027 Analytic 1027 DET0360

Enumeration of domain groups using dscacheutil or dscl commands, often following initial login or domain trust queries.

macos:unifiedlog
AN1028 Analytic 1028 DET0361

Abuse of Regsvcs.exe or Regasm.exe to execute arbitrary code embedded in .NET assemblies via [ComRegisterFunction]/[ComUnregisterFunction]. Behavioral chain: (1) Process creation of regsvcs/regasm with suspicious assembly paths/flags → (2) Assembly/DLL load inside regsvcs/regasm → (3) Registry writes to HKCR\CLSID/ProgID during COM registration → (4) Optional child process or network activity spawned by installer/registration code.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Sysmon
AN1029 Analytic 1029 DET0362

Detection of AppCert DLL abuse involves correlating registry modifications to the AppCertDLLs key with subsequent unexpected DLL load behavior during process creation events. Specifically, defenders can observe abnormal DLLs being loaded into standard Windows processes after changes to the 'AppCertDLLs' registry value. Monitoring CreateProcess-family API executions with injected DLLs and linking those DLLs back to recent registry edits is key to identifying misuse. This is often accompanied by elevated privileges and potential lateral movement or discovery behavior.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1030 Analytic 1030 DET0363

A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN1031 Analytic 1031 DET0364

Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:WMI
AN1032 Analytic 1032 DET0365

Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Shell-Core
AN1033 Analytic 1033 DET0366

Detects adversary behavior where a file with a benign-looking first extension (e.g., .txt, .jpg) ends with a dangerous second extension (e.g., .exe, .scr), and is subsequently executed. The behavior chain includes file creation with misleading naming and user or system-initiated process execution from the disguised file.

WinEventLog:Sysmon WinEventLog:Sysmon
AN1034 Analytic 1034 DET0367

Correlates Group Policy updates that configure network logon scripts with subsequent remote file execution behaviors triggered by user logons to identify potential persistence or execution chains tied to adversarial manipulation of logon scripts.

WinEventLog:Security WinEventLog:Security WinEventLog:System
AN1035 Analytic 1035 DET0368

Detects tampered hardware or firmware via anomalous host status telemetry. Behavioral chain: (1) Pre-OS or firmware components exhibit unexpected version changes, signature failures, or modified boot paths; (2) System management/firmware tools log hardware inventory drift; (3) Sensor health telemetry or boot attestation events fail baseline checks; (4) Follow-on process execution from altered firmware or unknown drivers after boot.

WinEventLog:Security WinEventLog:Microsoft-Windows-CodeIntegrity/Operational WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1038 Analytic 1038 DET0369

Correlate file modifications in shell startup scripts (e.g., .bashrc, .profile) with embedded `trap` commands and observe if those changes are followed by the unexpected execution of child processes when terminal signals (e.g., SIGINT) are triggered. Use contextual linking with user session activity to detect privilege misuse.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN1039 Analytic 1039 DET0369

Detect unauthorized `trap` command registrations in shell startup files (e.g., .zprofile, .bash_profile, .zshrc) followed by execution chains during user terminal interaction. Use Unified Logs and EDR telemetry to correlate shell command parsing and process tree anomalies.

macos:unifiedlog macos:unifiedlog
AN1040 Analytic 1040 DET0370

Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations.

WinEventLog:Security WinEventLog:Sysmon
AN1041 Analytic 1041 DET0370

Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories.

auditd:SYSCALL auditd:PATH
AN1042 Analytic 1042 DET0370

Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows.

macos:unifiedlog fs:fsusage
AN1045 Analytic 1045 DET0371

Monitor for suspicious use of Windows API calls such as IsDebuggerPresent() and NtQueryInformationProcess(), or processes manually checking the BeingDebugged flag in the Process Environment Block (PEB). Detect sequences of OutputDebugStringW() calls in short intervals that may indicate debugger flooding attempts.

WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1048 Analytic 1048 DET0372

Correlated use of sleep/delay mechanisms (e.g., kernel32!Sleep, NTDLL APIs) in short-lived processes, combined with parent processes invoking suspicious scripts (e.g., wscript, powershell) with minimal user interaction.

WinEventLog:Sysmon WinEventLog:Sysmon
AN1049 Analytic 1049 DET0372

Shell scripts or binaries invoking repeated 'sleep', 'ping', or low-level syscalls (e.g., nanosleep) in short-lived execution chains with no user or system interaction. Frequently seen in malicious cron jobs or payload stagers.

auditd:SYSCALL auditd:PROCTITLE
AN1050 Analytic 1050 DET0372

Execution of AppleScript, bash, or launchd jobs that invoke delay functions (e.g., sleep, delay in AppleScript) with limited parent interaction and staged follow-on commands.

macos:unifiedlog macos:unifiedlog
AN1052 Analytic 1052 DET0373

Execution of PowerShell commands that modify mailbox permissions using Exchange cmdlets (e.g., Add-MailboxPermission), often tied to BEC or post-compromise persistence.

WinEventLog:Security m365:unified
AN1056 Analytic 1056 DET0375

Monitor for creation or modification of udev rules files in key directories (/etc/udev/rules.d/, /lib/udev/rules.d/, /usr/lib/udev/rules.d/). Look for RUN+= or IMPORT keys invoking suspicious binaries or scripts. Correlate this with process execution from systemd-udevd context, and file writes near udev reload/restart events. Combine this with unexpected background process spawning from udevd-related forks.

auditd:SYSCALL auditd:SYSCALL auditd:CONFIG_CHANGE
AN1057 Analytic 1057 DET0376

Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window.

WinEventLog:Sysmon WinEventLog:Sysmon
AN1058 Analytic 1058 DET0376

Detects use of network scanning utilities or scripts performing rapid connections to multiple services or hosts using auditd and netflow/pcap telemetry.

auditd:SYSCALL NSM:Flow
AN1059 Analytic 1059 DET0376

Detects Bonjour-based mDNS enumeration or use of system tools (e.g., dns-sd, nmap) to find active services via multicast probing or targeted scans.

macos:unifiedlog macos:osquery
AN1060 Analytic 1060 DET0376

Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet.

ebpf:syscalls ebpf:syscalls containerd:runtime
AN1061 Analytic 1061 DET0377

Unauthorized or anomalous loading of kernel-mode drivers or DLLs, concealed services, or abnormal modification of boot components indicative of rootkit activity.

WinEventLog:Sysmon WinEventLog:System WinEventLog:Sysmon
AN1062 Analytic 1062 DET0377

Abnormal loading of kernel modules, direct tampering with /dev, /proc, or LD_PRELOAD behaviors hiding processes or files.

auditd:EXECVE linux:osquery linux:syslog
AN1064 Analytic 1064 DET0378

Correlates script execution or suspicious parent processes with creation or modification of encoded, compressed, or encrypted file formats (e.g., .zip, .7z, .enc) and abnormal command-line syntax or PowerShell obfuscation.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1065 Analytic 1065 DET0378

Detects use of gzip, base64, tar, or openssl in scripts or commands that encode/encrypt files after file staging or system enumeration.

auditd:SYSCALL auditd:SYSCALL linux:cli
AN1066 Analytic 1066 DET0378

Monitors use of archive or encryption tools (zip, openssl) tied to user-scripted activity or binaries writing encoded payloads under /Users or /Volumes.

macos:unifiedlog macos:osquery
AN1067 Analytic 1067 DET0378

Identifies transfer of base64, uuencoded, or high-entropy files over HTTP, FTP, or custom protocols in lateral movement or exfiltration streams.

networkdevice:IDS
AN1069 Analytic 1069 DET0379

Detects rogue Wi-Fi access points broadcasting the same SSID as legitimate APs with stronger signal strength, unexpected MAC/BSSID values, or inconsistent encryption settings. Correlates authentication attempts, captive portal redirections, and anomalous traffic flows through unauthorized APs.

WLANLogs:Association NSM:Flow networkdevice:syslog
AN1070 Analytic 1070 DET0380

Adversaries collecting local files via PowerShell, WMI, or direct file API calls often include recursive file listings, targeted file reads, and temporary file staging.

WinEventLog:Security WinEventLog:Sysmon
AN1071 Analytic 1071 DET0380

Adversaries using bash scripts or tools to recursively enumerate user home directories, config files, or SSH keys.

auditd:SYSCALL auditd:SYSCALL
AN1072 Analytic 1072 DET0380

Adversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents.

macos:unifiedlog fs:fsusage
AN1075 Analytic 1075 DET0381

Correlates file enumeration of XML files in the SYSVOL share with suspicious process execution that decodes or reads encrypted credentials embedded in Group Policy Preference files (e.g., Get-GPPPassword.ps1, gpprefdecrypt.py, Metasploit). Detects abnormal access to \DOMAIN\SYSVOL combined with XML file parsing or decryption logic.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:PowerShell
AN1076 Analytic 1076 DET0382

Detects adversary use of suspended process creation, using the CREATE_SUSPENDED flag via CreateProcess, followed by unmapping the memory of the child process (NtUnmapViewOfSection) and replacing it with malicious code via VirtualAllocEx/WriteProcessMemory, then SetThreadContext and ResumeThread to begin execution within the hollowed process.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1081 Analytic 1081 DET0384

Detects bash, sh, zsh, or BusyBox shell execution initiated via remote sessions, unauthorized users, or embedded within secondary script interpreters. Focus is on chained behavior: shell > suspicious commands > network discovery or persistence indicators.

auditd:SYSCALL linux:osquery linux:syslog
AN1082 Analytic 1082 DET0384

Identifies use of sh/bash/zsh in suspicious context, such as user scripts launched from non-standard apps (e.g., Preview.app), embedded in LaunchDaemons, or executed outside Terminal.app. Looks for misuse in Automator, LaunchAgents, or NSAppleScript-executed shell.

macos:unifiedlog macos:osquery macos:syslog
AN1085 Analytic 1085 DET0385

A process outside of interactive shell context reads ~/.bash_history directly (e.g., using cat, less, grep), often shortly after privilege escalation or user switch (su/sudo). This may be followed by credential scanning in memory or file writes to new locations.

auditd:SYSCALL auditd:EXECVE auditd:SYSCALL
AN1092 Analytic 1092 DET0387

Detects suspicious gratuitous ARP responses or inconsistent IP-to-MAC mappings using auditd and packet capture. Behavioral focus is on unsolicited replies overriding legitimate ARP ownership.

auditd:SYSCALL NSM:Flow
AN1093 Analytic 1093 DET0387

Detects anomalous ARP cache changes and unsolicited ARP broadcasts using unified logs and packet capture. Behavioral detection includes multiple IP addresses mapped to the same MAC address and repeated gratuitous ARP traffic.

macos:unifiedlog NSM:Flow
AN1094 Analytic 1094 DET0388

Detects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1095 Analytic 1095 DET0389

Detects DLL injection through correlation of memory allocation and writing to remote process memory (e.g., VirtualAllocEx, WriteProcessMemory), followed by remote thread creation (e.g., CreateRemoteThread) that loads a suspicious or unsigned DLL using LoadLibrary or reflective loading.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1096 Analytic 1096 DET0390

Correlation of file creation/modification of `.desktop` files within XDG autostart directories, followed by execution of processes at user login initiated by the desktop environment. Malicious entries typically include suspicious Exec paths or anomalous names and are not associated with installed packages.

auditd:SYSCALL auditd:SYSCALL auditd:EXECVE linux:osquery linux:auth
AN1097 Analytic 1097 DET0391

Monitor for runtime data manipulations by detecting suspicious modification of application binaries, API hooking, or unexpected behavior from processes responsible for rendering or displaying data. Correlate registry edits, process creation, and unexpected binary hash mismatches.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1100 Analytic 1100 DET0392

Adversary spawns a process or script to enumerate installed software using WMI, registry, or PowerShell, potentially followed by additional discovery or evasion behavior.

WinEventLog:Security WinEventLog:PowerShell
AN1101 Analytic 1101 DET0392

Adversary invokes 'dpkg -l', 'rpm -qa', or other package managers via shell or script to enumerate installed software.

auditd:SYSCALL linux:shell
AN1102 Analytic 1102 DET0392

Adversary runs 'system_profiler SPApplicationsDataType' or queries plist files to enumerate software via Terminal or scripts.

macos:unifiedlog auditd:SYSCALL
AN1108 Analytic 1108 DET0394

Unexpected file creation in web directories followed by web server processes (e.g., w3wp.exe) spawning command shells or script interpreters (e.g., cmd.exe, powershell.exe)

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security NSM:Flow
AN1109 Analytic 1109 DET0394

File creation of unauthorized script (e.g., .php, .sh) in /var/www/html followed by execution of unexpected system utilities (e.g., curl, bash, nc) by apache/nginx

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN1110 Analytic 1110 DET0394

Web servers (e.g., httpd) spawning abnormal processes post file upload into /Library/WebServer/Documents or /usr/local/var/www

macos:unifiedlog auditd:SYSCALL
AN1111 Analytic 1111 DET0395

Detects abuse of AuthorizationExecuteWithPrivileges API to gain elevated privileges via user credential prompts, typically through invocation of /usr/libexec/security_authtrampoline. Detection involves correlation of API usage, binary reputation, and prompt context.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1112 Analytic 1112 DET0396

Detects suspicious access to macOS Keychain files and APIs. Observes processes invoking the 'security' utility or accessing Keychain databases directly, correlates these with abnormal parent process lineage or unexpected user context. Monitors attempts to dump, unlock, or read credential storage beyond normal application workflows.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1113 Analytic 1113 DET0397

Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes.

WinEventLog:Security WinEventLog:Sysmon
AN1114 Analytic 1114 DET0397

Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs.

auditd:SYSCALL NSM:Flow
AN1115 Analytic 1115 DET0397

Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer.

macos:unifiedlog macos:unifiedlog macos:cron
AN1116 Analytic 1116 DET0398

Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Application
AN1118 Analytic 1118 DET0399

Recurring network exfiltration initiated by scheduled or script-based processes exhibiting time-based regularity and consistent external destinations.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System
AN1119 Analytic 1119 DET0399

Detection of cron-based or script-based recurring transfers where the same script, user, or destination reappears at predictable intervals.

auditd:SYSCALL linux:cron NSM:Flow
AN1120 Analytic 1120 DET0399

LaunchAgent or launchd recurring jobs initiating data transfer to consistent external IPs or domains with repeat timing signatures.

macos:endpointsecurity macos:launchd macos:unifiedlog
AN1121 Analytic 1121 DET0400

Detects high-frequency or anomalous DNS queries initiated by non-browser, non-system processes (e.g., PowerShell, rundll32, python.exe) used to establish command and control via DNS tunneling.

WinEventLog:Sysmon NSM:Flow
AN1122 Analytic 1122 DET0400

Detects local daemons or scripts generating outbound DNS queries with long or frequent subdomains, indicative of DNS tunneling via tools like `iodine`, `dnscat2`, or `dig` from cronjobs or reverse shells.

auditd:SYSCALL NSM:Flow
AN1124 Analytic 1124 DET0400

Detects clients issuing DNS queries with high volume, long subdomain lengths, encoded payload patterns, or to known malicious infrastructure; indicative of DNS-based C2 channels.

NSM:Flow
AN1125 Analytic 1125 DET0400

Detects unusual outbound DNS traffic from ESXi hosts, often from shell scripts, custom daemons, or malicious VIBs interacting with external DNS infrastructure outside the management plane.

esxi:syslog NSM:FLow
AN1126 Analytic 1126 DET0401

Creation or modification of `.plist` files in /Library/LaunchDaemons/, especially those with suspicious Program or ProgramArguments paths, combined with execution activity under launchd with elevated privileges. Detectable through correlated Unified Logs, file monitoring, and process telemetry.

macos:unifiedlog fs:launchdaemons fs:launchdaemons macos:unifiedlog
AN1133 Analytic 1133 DET0404

Monitor Windows Registry modifications to Winlogon keys (Shell, Userinit, Notify) that introduce new executable or DLL paths. Correlate these changes with subsequent DLL loading, image loads, or process creation originating from winlogon.exe or userinit.exe. Abnormal child process lineage or unauthorized binaries in C:\Windows\System32 may indicate abuse.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security Autoruns:RegistryScan
AN1134 Analytic 1134 DET0405

Correlates LNK file execution with embedded resource extraction or suspicious network activity following initial launch, often leading to payload delivery via disguised icons.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1137 Analytic 1137 DET0407

Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.

WinEventLog:Security WinEventLog:Security
AN1138 Analytic 1138 DET0407

Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.

auditd:USER_LOGIN linux:auth
AN1139 Analytic 1139 DET0407

Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.

macos:unifiedlog
AN1142 Analytic 1142 DET0408

Command-line initiated UDP traffic bursts to external reflection amplification ports using built-in scripting or binaries with network anomalies

macos:unifiedlog macos:unifiedlog
AN1144 Analytic 1144 DET0409

Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1145 Analytic 1145 DET0410

Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil).

WinEventLog:Security WinEventLog:Sysmon
AN1149 Analytic 1149 DET0411

Detect adversaries filtering traffic or modifying server responses to evade scanning. Monitor iptables, nftables, or proxy configurations that deny or redirect requests from known scanning agents or defensive tools.

auditd:SYSCALL NSM:Flow
AN1150 Analytic 1150 DET0411

Monitor unified logs for manipulation of proxy configurations, DNS resolution, or filtering rules. Adversaries may redirect responses or use trusted domains that later resolve to malicious C2 infrastructure.

macos:unifiedlog NSM:Flow
AN1151 Analytic 1151 DET0411

Inspect network telemetry for adversary attempts to blend malicious traffic with legitimate flows using VPNs, proxies, or geolocation spoofing. Defensive teams may observe anomalous tunnels, encrypted sessions to suspicious domains, or geo-mismatched IP activity.

NSM:Flow
AN1152 Analytic 1152 DET0411

Monitor VM-level DNS and network traffic logs for adversary-controlled domains or selective response behavior (e.g., dropped requests from security scanners).

esxi:vmkernel esxi:vmkernel
AN1153 Analytic 1153 DET0412

Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN1158 Analytic 1158 DET0412

Access to container image layers or mounted secrets (e.g., Docker secrets) by processes not tied to entrypoint or orchestration context.

auditd:SYSCALL containerd:Events
AN1159 Analytic 1159 DET0412

Use of configuration backup utilities or CLI access to dump plaintext passwords, local user hashes, or SNMP strings.

linux:syslog NSM:Flow
AN1163 Analytic 1163 DET0413

Access of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download.

macos:unifiedlog macos:osquery
AN1164 Analytic 1164 DET0414

Detects AppleScript execution via 'osascript', NSAppleScript/OSAScript APIs, and abnormal application control events across user sessions. Focuses on causal chains such as osascript spawning child processes, script-induced keystrokes, or API-backed dialog spoofing.

macos:unifiedlog
AN1165 Analytic 1165 DET0415

Repeated invocation of high-resource application endpoints or GUI components causing CPU and memory spikes, logged as elevated request volumes, prolonged handle locks, or frequent crash recoveries.

WinEventLog:Application WinEventLog:Sysmon Windows:perfmon
AN1166 Analytic 1166 DET0415

Automated scripts or repeated CLI/API requests that trigger application backends to consume high CPU or memory (e.g., Apache/PHP, MySQL, mail servers), resulting in syslog errors and excessive process spawning.

auditd:SYSCALL linux:syslog NSM:Flow
AN1167 Analytic 1167 DET0415

Repetitive triggering of GUI or backend application workflows that cause increased CPU/memory usage, logged in unified logs as spin reports or crash dumps.

macos:unifiedlog macos:osquery
AN1169 Analytic 1169 DET0416

Detects FTP, SMB, or TFTP traffic initiated by suspicious processes like PowerShell, cmd.exe, or rundll32.exe—especially with large outbound file transfers or unbalanced traffic volume.

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Flow
AN1170 Analytic 1170 DET0416

Detects usage of FTP, SCP, or TFTP by non-interactive shells or automation scripts transferring large data volumes to untrusted IPs.

auditd:SYSCALL NSM:Flow
AN1172 Analytic 1172 DET0416

Detects file movement or outbound TFTP/FTP transfers from ESXi host initiated via shell commands or injected scripts, particularly from scratch partitions or /tmp.

esxi:shell NSM:Flow
AN1173 Analytic 1173 DET0416

Detects internal hosts generating large outbound FTP/TFTP/SMB sessions to external IPs, or file transfers using non-standard ports and application mismatches (e.g., FTP over port 80).

NSM:Flow
AN1174 Analytic 1174 DET0417

Monitor command execution of powercfg.exe with arguments modifying sleep, hibernate, or display timeouts. Abnormal or repeated modifications to power settings outside administrative baselines may indicate persistence attempts. Correlate process creation with registry and system configuration changes to build behavioral chains.

WinEventLog:Security
AN1176 Analytic 1176 DET0417

Monitor pmset command executions altering sleep/hibernate/standby parameters. Unexpected modifications to /Library/Preferences/SystemConfiguration/com.apple.PowerManagement.plist or similar files should be correlated with process activity.

macos:unifiedlog macos:unifiedlog
AN1177 Analytic 1177 DET0418

Multi-stage Windows DACL manipulation behavioral chain: (1) Process creation of permission-modifying utilities (icacls.exe, takeown.exe, attrib.exe, cacls.exe) or PowerShell ACL cmdlets, (2) Command-line analysis revealing privilege escalation intent through suspicious parameters (/grant, /takeown, /T, Set-Acl), (3) DACL modification events (4670) correlating with process execution, (4) Subsequent file access attempts (4663) indicating successful permission bypass, (5) Potential follow-on persistence or lateral movement activities

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:WMI
AN1178 Analytic 1178 DET0419

Correlate DNS queries that generate domains with high entropy or gibberish patterns, combined with short-lived connections from unusual processes. Monitor Sysmon DNS events and Windows Security logs for abnormal query rates and failed lookups.

WinEventLog:Sysmon WinEventLog:Security
AN1179 Analytic 1179 DET0419

Identify processes issuing repeated DNS queries to random-looking domains with abnormal entropy or word concatenations. Correlate resolver logs with high NXDOMAIN rates and auditd socket connections.

auditd:SYSCALL linux:syslog
AN1180 Analytic 1180 DET0419

Monitor unified DNS logs for abnormal domain queries with low lexical similarity to known domains, repeated failed lookups, and random string structures. Cross-check with process logs to confirm unusual origins (non-browser apps).

macos:unifiedlog macos:unifiedlog
AN1182 Analytic 1182 DET0420

Process execution that probes user activity artifacts (e.g., desktop files, registry history) following recent user login/unlock events.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1185 Analytic 1185 DET0421

Detection focuses on abnormal service executions initiated via service control manager APIs, sc.exe, net.exe, or PsExec creating temporary services. Defenders observe process creation of services.exe spawning non-standard binaries, registry changes in service keys followed by rapid execution, and network connections originating from processes tied to transient services. Correlation across process lineage, registry activity, and service logs provides strong signals of malicious service execution.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1186 Analytic 1186 DET0422

Registry key modifications under IFEO paths (e.g., Debugger value set under Image File Execution Options), especially for security-related or accessibility binaries, followed by anomalous process execution with debugger flags or SYSTEM-level access at login. Detectable by correlating registry modifications, process creation, and parent-child anomalies with unusual command-line usage or access tokens.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1187 Analytic 1187 DET0423

Detection focuses on correlating snapshot creation events with subsequent instance creation and mounting activities. From a defender perspective, suspicious sequences include snapshot creation by unexpected or newly created IAM users, snapshots created from sensitive volumes without preceding change-control activity, or snapshots immediately followed by mounting to unauthorized instances. Cross-referencing with user behavior, IP geolocation, and automation context helps distinguish benign backup operations from adversary-driven snapshot exploitation.

AWS:CloudTrail AWS:CloudTrail
AN1189 Analytic 1189 DET0425

Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence.

WinEventLog:Sysmon NSM:Flow
AN1190 Analytic 1190 DET0425

Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context.

auditd:SYSCALL NSM:Flow
AN1191 Analytic 1191 DET0425

Detects user agents or background services making unauthorized or unscheduled web API calls to cloud/web services over HTTPS.

macos:unifiedlog macos:osquery
AN1193 Analytic 1193 DET0426

Processes accessing raw logical drives (e.g., \.\C:) to bypass file system protections or directly manipulate data structures.

WinEventLog:Sysmon WinEventLog:Security
AN1195 Analytic 1195 DET0427

Unauthorized modification of service-related registry keys such as ImagePath, FailureCommand, ServiceDll, or Performance/Parameters keys. Defender correlates registry modifications, anomalous service metadata changes, and subsequent service process executions that deviate from baseline configurations.

WinEventLog:Security WinEventLog:System WinEventLog:Sysmon
AN1196 Analytic 1196 DET0428

Abuse of bind mounts to obscure process directories. Defender perspective: detecting anomalous mount operations where a process’s /proc entry is remapped to another directory, often hiding malicious activity from native utilities (ps, top). Behavior chain includes: (1) execution of `mount` with `-o bind` or `-B` flags, (2) modification of /proc entries inconsistent with expected process lineage, and (3) subsequent anomalous activity from processes whose metadata no longer matches execution context.

auditd:SYSCALL auditd:PATH linux:osquery
AN1197 Analytic 1197 DET0429

Detects the modification or addition of Launch Agents or Startup Items to establish persistence. Adversaries may write plist or executable files to ~/Library/LaunchAgents/, /Library/StartupItems/, or similar directories and configure them to run at user or system boot. Detection requires correlating file creation or modification events with subsequent user logon or boot-time process execution.

macos:unifiedlog macos:fsevents
AN1198 Analytic 1198 DET0430

Monitors suspicious access to password stores such as LSASS, DPAPI, Windows Credential Manager, or browser credential databases. Detects anomalous process-to-process access (e.g., Mimikatz accessing LSASS) and correlation of credential store file reads with execution of non-standard processes.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN1199 Analytic 1199 DET0430

Detects access to known password store files (e.g., /etc/shadow, GNOME Keyring, KWallet, browser credential databases). Monitors anomalous process read attempts and suspicious API calls that attempt to extract stored credentials.

auditd:SYSCALL auditd:EXECVE
AN1200 Analytic 1200 DET0430

Monitors Keychain database access and suspicious invocations of security and osascript utilities. Correlates process execution with attempts to dump or unlock Keychain data.

macos:unifiedlog macos:unifiedlog
AN1206 Analytic 1206 DET0432

Suspicious use of NTFS file attributes such as Alternate Data Streams (ADS) or Extended Attributes (EA) to hide data. Defender perspective: anomalous file creations or modifications containing colon syntax (file.ext:ads), API calls like ZwSetEaFile/ZwQueryEaFile, or PowerShell/Windows utilities interacting with -stream parameters. Correlation across file metadata anomalies, process lineage, and command execution provides context.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-File
AN1207 Analytic 1207 DET0433

Abuse of mavinject.exe to inject DLLs or import descriptors into another running process. Chain: (1) mavinject.exe starts with /INJECTRUNNING or /HMODULE → (2) mavinject obtains high-access handles to a target process (VM_WRITE/CREATE_THREAD) → (3) target process loads attacker DLL (module load) → (4) optional follow-on child activity or network egress from the target process.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Sysmon
AN1208 Analytic 1208 DET0434

Detects creation or modification of user-level Launch Agents in monitored directories using `.plist` files with suspicious `ProgramArguments` or `RunAtLoad` keys. Correlates file write activity with execution of `launchctl` or unsigned binaries invoked at login.

macos:unifiedlog fs:fsusage fs:fsusage macos:osquery
AN1209 Analytic 1209 DET0435

Detection focuses on identifying abuse of LD_PRELOAD and related linker variables. Defender perspective: monitor unexpected setting or modification of LD_PRELOAD in shell initialization scripts or environment exports, file creation of suspicious shared libraries, and correlation of these modifications with anomalous process execution. Key signals include execve events with LD_PRELOAD defined, newly created .so files in user directories, and processes hooking libc functions exhibiting abnormal behavior.

auditd:SYSCALL auditd:PATH linux:osquery
AN1210 Analytic 1210 DET0435

Detection centers on DYLD_INSERT_LIBRARIES and DYLD_LIBRARY_PATH abuse. Defender perspective: monitor for modification of these environment variables in shell or plist files, file creation of dylibs in user-controlled paths, and correlation of environment variable usage with unexpected module loads by user applications. Suspicious indicators include processes with DYLD_INSERT_LIBRARIES set, execution of applications loading untrusted dylibs, and anomalies in module load history.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1211 Analytic 1211 DET0436

Modification or replacement of service executables due to weak file or directory permissions. Defender observes file writes to service binary paths, unexpected modifications of executables associated with registered services, and subsequent service execution of attacker-supplied binaries under elevated permissions.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System WinEventLog:Sysmon
AN1212 Analytic 1212 DET0437

Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEY_LOCAL_MACHINE\SECURITY\Policy\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1213 Analytic 1213 DET0438

Detects suspicious custom compression/encryption routines through anomalous script or binary execution that produces high-entropy files without standard archiving utilities. Correlates script execution, memory API usage (bitwise ops, CryptoAPI calls), and creation of archive-like files with uncommon headers.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1214 Analytic 1214 DET0438

Detects custom archive routines by correlating script execution (Python, Perl, Bash) with creation of high-entropy files in temporary or user directories. Flags processes performing unusual bitwise operations or writing files without standard compression headers.

auditd:SYSCALL auditd:FILE linux:osquery
AN1215 Analytic 1215 DET0438

Detects custom archiving by monitoring execution of Swift/Objective-C apps or scripts producing high-entropy files with non-standard headers. Correlates unified logs of abnormal NSFileHandle/NSData operations, memory use of XOR/bitwise operations, and file creation events.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1216 Analytic 1216 DET0439

Detects the relocation of malicious executables via copy/move actions across suspicious folders (e.g., from Downloads to System32), followed by deletion of the original source or renaming to blend into legitimate binaries.

WinEventLog:Sysmon WinEventLog:Sysmon
AN1220 Analytic 1220 DET0440

Execution of SyncAppvPublishingServer.vbs through wscript.exe with a command-line containing embedded PowerShell, proxying malicious PowerShell execution through a Microsoft-signed VBScript interpreter to evade detection and restrictions.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon
AN1221 Analytic 1221 DET0441

Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1223 Analytic 1223 DET0443

Detects anomalous process execution patterns where a process's parent terminates quickly after process creation or is re-parented to 'init' (PID 1), often indicating double-fork or daemon-style detachment. These behaviors sever the parent-child relationship and obscure the execution origin in process tree analysis.

auditd:SYSCALL auditd:SYSCALL
AN1224 Analytic 1224 DET0443

Detects execution patterns where a child process is detached from its original parent, often showing up under 'launchd' (PID 1) with no parent lineage. These breakages in the process tree are indicative of evasive techniques using `daemon()`, `fork()` or background execution flags.

macos:unifiedlog fs:fsusage
AN1225 Analytic 1225 DET0444

Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration.

NSM:Flow WinEventLog:Sysmon
AN1226 Analytic 1226 DET0444

Detects suspicious curl, wget, or custom socket traffic that leverages DNS, HTTPS, or IRC-style protocols with unbalanced traffic or beacon-like intervals.

NSM:Flow auditd:SYSCALL
AN1228 Analytic 1228 DET0444

Detects application-layer tunneling or unauthorized app protocols like DNS-over-HTTPS, embedded C2 in TLS/HTTP headers, or misused SMB traffic crossing VLANs.

NSM:Flow
AN1229 Analytic 1229 DET0445

Suspicious process spawning (e.g., `rundll32`, `svchost`, `powershell`, or `netsh`) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports.

WinEventLog:Sysmon WinEventLog:Sysmon NSM:Connections
AN1230 Analytic 1230 DET0445

User-space tools (e.g., `socat`, `ncat`, `iptables`, `ssh`) used in non-standard ways to establish reverse shells, port-forwarding, or inter-host connections. Often chained with uncommon outbound destinations or SSH tunnels.

auditd:SYSCALL NSM:Flow
AN1231 Analytic 1231 DET0445

AppleScript, LaunchAgents, or remote login services (`ssh`, `networksetup`) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts.

macos:unifiedlog NSM:Firewall NSM:Flow
AN1234 Analytic 1234 DET0446

Adversaries attempt to read sensitive files such as /etc/passwd and /etc/shadow for credential dumping. This may involve access to the files directly via command-line utilities (e.g., cat, less), creation of backup copies, or parsing through post-exploitation frameworks. Multi-event correlation includes elevated process execution, file access/read on sensitive paths, and anomalous read behaviors tied to non-root or unusual users.

auditd:SYSCALL auditd:SYSCALL
AN1235 Analytic 1235 DET0447

Adversary uses built-in tools like 'net user /add', PowerShell, or WMI to create a local user. Sequence: Account creation event (4720) follows process creation of a suspicious executable (e.g., powershell.exe or net.exe).

WinEventLog:Security WinEventLog:Sysmon
AN1241 Analytic 1241 DET0448

Detects the redirection of syscall execution flow via modification of VDSO code stubs or GOT entries to load and execute a malicious shared object through mmap and ptrace.

auditd:SYSCALL auditd:memprotect auditd:file-events linux:osquery
AN1243 Analytic 1243 DET0450

Monitor kernel module load/unload activity via modprobe, insmod, rmmod, or direct manipulation of /lib/modules. Correlate with installation of kernel headers, compilation commands, or downloads of .ko files. Detect anomalies in unsigned module loading or repeated module load attempts under non-root users.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN1244 Analytic 1244 DET0450

Detect user-initiated kextload commands or modifications to /Library/Extensions. Correlate with changes to KextPolicy database or unauthorized developer signing identities. Alert on attempts to disable SIP or load legacy extensions from unsigned sources.

macos:unifiedlog macos:osquery macos:osquery macos:osquery
AN1245 Analytic 1245 DET0451

Defenders can identify PowerShell profile-based persistence by correlating file creation or modification in known profile locations with subsequent PowerShell process launches that do not use the `-NoProfile` flag. Profile scripts loading unusual modules or launching external programs, particularly under elevated contexts, are suspicious and may represent adversary persistence or privilege escalation.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:PowerShell
AN1246 Analytic 1246 DET0452

Detection correlates abnormal installation or modification of root or code-signing certificates, creation/modification of suspicious registry keys for trust providers, and unusual module loads from non-standard locations. Identifies unsigned or improperly signed executables bypassing trust prompts, combined with persistence artifacts.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1248 Analytic 1248 DET0452

Detection monitors modification of code signing attributes, Gatekeeper/quarantine flags, and insertion of new trust certificates via security add-trusted-cert. Identifies adversary use of xattr to strip quarantine flags from downloaded binaries. Correlates with abnormal module loads bypassing SIP protections.

macos:unifiedlog macos:unifiedlog macos:osquery
AN1249 Analytic 1249 DET0453

Defenders may observe suspicious SNMP MIB enumeration through abnormal queries for large sets of OIDs, repeated SNMP GETBULK/GETNEXT requests, or queries originating from non-administrative IP addresses. Anomalous use of community strings, authentication failures, or enumeration activity outside maintenance windows may also indicate attempts to dump MIB contents. Correlation across syslog, NetFlow, and SNMP audit data can reveal chains of behavior such as repeated authentication failures followed by successful large-scale OID retrieval.

networkdevice:syslog NSM:Flow networkdevice:audit
AN1250 Analytic 1250 DET0454

Detects unauthorized modifications to PAM configuration files or shared object modules. Correlates file modification events under /etc/pam.d/ or /lib/security/ with unusual authentication activity such as multiple simultaneous logins, off-hours logins, or logons without corresponding physical/VPN access.

auditd:SYSCALL auditd:SYSCALL NSM:Connections
AN1252 Analytic 1252 DET0455

Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:PowerShell WinEventLog:Sysmon
AN1253 Analytic 1253 DET0456

A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a **new** process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions.

WinEventLog:Security WinEventLog:Sysmon ETW:ProcThread WinEventLog:Security WinEventLog:Security
AN1254 Analytic 1254 DET0457

Anomalous use of ICMP or UDP by non-network service processes for data exfiltration or remote control, especially if traffic bypasses proxy infrastructure or shows unusual flow patterns.

WinEventLog:Sysmon NSM:Flow
AN1255 Analytic 1255 DET0457

ICMP or raw socket traffic generated by user-mode processes like bash, Python, or nc, typically using `ping`, `hping3`, or crafted packets via libpcap or scapy.

auditd:SYSCALL NSM:Flow
AN1256 Analytic 1256 DET0457

Unsigned binaries or interpreted scripts initiating non-standard protocols (ICMP, UDP, SOCKS) outside of baseline network behavior.

macos:unifiedlog NSM:Flow
AN1257 Analytic 1257 DET0457

VMCI (Virtual Machine Communication Interface) traffic between guest and host, or between VMs, originating from non-management tools or unauthorized binaries.

esxi:vmkernel
AN1258 Analytic 1258 DET0457

Non-standard port/protocol pairings or low-entropy ICMP traffic resembling tunneling patterns (e.g., fixed-size pings with delays).

NSM:Firewall NSM:Flow
AN1259 Analytic 1259 DET0458

Adversary modifies Active Directory domain trust settings via `netdom`, `nltest`, or PowerShell to add new domain trust or alter federation. Modifications occur in AD object attributes like trustDirection, trustType, trustAttributes, often paired with SeEnableDelegationPrivilege or certificate injection.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN1273 Analytic 1273 DET0461

Hidden file system use through APFS containers or custom plist configuration. Defender view: anomalous use of hdiutil or diskutil to attach hidden partitions, modification of plist entries tied to system volumes, or suspicious raw disk access.

macos:unifiedlog macos:unifiedlog
AN1274 Analytic 1274 DET0462

Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception.

WinEventLog:Security WinEventLog:Security NSM:Flow NSM:Flow
AN1280 Analytic 1280 DET0464

Enumeration of saved Wi-Fi profiles and cleartext password retrieval using `netsh wlan` or API-level access to `wlanAPI.dll`.

WinEventLog:Sysmon WinEventLog:PowerShell
AN1281 Analytic 1281 DET0464

File access to NetworkManager connection configs and attempts to read PSK credentials from `/etc/NetworkManager/system-connections/*`.

auditd:PATH auditd:EXECVE
AN1282 Analytic 1282 DET0464

Use of the `security` command or Keychain API to extract known Wi-Fi passwords for target SSIDs.

macos:unifiedlog
AN1284 Analytic 1284 DET0465

Monitoring for SSH logins from default accounts such as 'root', especially when login is via password and not key-based authentication.

auditd:USER_LOGIN
AN1288 Analytic 1288 DET0466

Execution of Microsoft-signed scripts (e.g., pubprn.vbs, installutil.exe, wscript.exe, cscript.exe) used to proxy execution of untrusted or external binaries. Behavior is detected through command-line process lineage, child process spawning, and unsigned payload execution from signed parent.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1290 Analytic 1290 DET0468

Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints.

WinEventLog:System NSM:Flow
AN1292 Analytic 1292 DET0468

Detects DHCP spoofing by monitoring unified logs for unexpected DHCP ACK/OFFER parameters and correlating with packet captures for multiple DHCP servers. Behavioral emphasis is on inconsistent DNS and gateway assignments that redirect traffic.

macos:unifiedlog NSM:Flow
AN1294 Analytic 1294 DET0470

Untrusted processes creating outbound TLS/HTTPS connections with malformed certificates or header fields, often mismatched with target service behavior. Detects protocol impersonation attempts via traffic metadata analysis and host process lineage.

WinEventLog:Sysmon NSM:Flow
AN1295 Analytic 1295 DET0470

Detection of binaries spawning encrypted sessions using OpenSSL or curl to external services with mismatched ports/protocols. Identifies behavior where internal services simulate trusted cloud service traffic patterns.

auditd:SYSCALL NSM:Flow
AN1296 Analytic 1296 DET0470

Unsigned or suspicious applications initiating network traffic claiming to be browser, mail, or cloud clients. Detects impersonation via TLS fingerprint and User-Agent string deviation.

macos:unifiedlog macos:osquery NSM:Content
AN1297 Analytic 1297 DET0470

ESXi hosts initiating connections from non-standard daemons mimicking HTTP/HTTPS or SNMP traffic, but with irregular payload formats or expired/unsigned TLS certificates.

esxi:hostd NSM:Content
AN1298 Analytic 1298 DET0471

Detects adversary tampering of shared directories via file drops (e.g., malicious LNK, EXE, VBS) followed by user execution or suspicious network activity.

WinEventLog:Sysmon WinEventLog:Security
AN1300 Analytic 1300 DET0471

Detects modification of shared network folders via .app bundles or scripting files with hidden extensions (e.g., double extensions like docx.app).

fs:fsevents macos:unifiedlog
AN1301 Analytic 1301 DET0471

Detects upload of malicious or unusual file types into cloud-shared folders, followed by user downloads or interactions.

gcp:workspaceaudit m365:unified
AN1303 Analytic 1303 DET0472

Detects suspicious registration of new password filter DLLs into the authentication process. Correlates registry modifications to LSASS Notification Packages with subsequent DLL creation and loading events. Observes anomalous file placement of DLLs in system directories followed by LSASS loading the new filter during logon/password change activity.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1304 Analytic 1304 DET0473

Correlate the creation or modification of containers using restart policies (e.g., 'always') or DaemonSets with elevated host access, service account misuse, or privileged container contexts. Watch for manipulation of systemd units involving containers or pod scheduling targeting specific nodes or namespaces.

auditd:SYSCALL systemd:unit kubernetes:audit kubernetes:audit
AN1305 Analytic 1305 DET0474

Windows-specific environmental keying behavioral chain: (1) Rapid system information discovery through multiple techniques (WMI queries, registry enumeration, network share discovery, hostname/domain checks), (2) Target validation through specific environmental artifact collection (AD domain membership, network topology, installed software versions), (3) Cryptographic operation correlation indicating payload decryption based on collected environmental values, (4) Subsequent malicious code execution following successful environmental validation, (5) Temporal clustering of discovery activities suggesting automated environmental assessment

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:WMI WinEventLog:PowerShell
AN1306 Analytic 1306 DET0474

Linux environmental keying behavioral chain: (1) System information gathering through native commands (uname, hostname, id, whoami, ifconfig/ip) and file system enumeration, (2) Network configuration discovery (route tables, DNS settings, network interfaces), (3) Filesystem and mount point analysis for target-specific directories or devices, (4) Process and service enumeration to identify target-specific software, (5) Cryptographic library usage correlation with collected environmental data, (6) Payload execution following successful environmental validation

auditd:SYSCALL linux:syslog linux:osquery
AN1307 Analytic 1307 DET0474

macOS environmental keying behavioral chain: (1) System information discovery through native utilities (system_profiler, sw_vers, hostname, dscl) and Security framework queries, (2) Hardware and software enumeration including serial numbers, installed applications, and system versions, (3) Network configuration assessment (networksetup, scutil) and wireless network discovery, (4) Keychain and security context validation, (5) Unified Logs correlation with cryptographic framework usage (CommonCrypto, Security.framework), (6) Application bundle execution following environmental validation

macos:unifiedlog macos:unifiedlog fs:fsevents
AN1308 Analytic 1308 DET0475

Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta).

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1310 Analytic 1310 DET0476

Detects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories.

auditd:SYSCALL linux:syslog linux:osquery
AN1313 Analytic 1313 DET0477

Adversaries using WinRM to remotely execute commands, launch child processes, or access WMI. The detection chain includes service use, network activity, remote session logon, and process creation within a short temporal window.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:WinRM NSM:Connections
AN1314 Analytic 1314 DET0478

Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage.

WinEventLog:Application WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN1315 Analytic 1315 DET0478

Cause→effect chain: (1) User app/browser/archiver logs an open/click or abnormal exit, (2) new executable/script/archive extracted into $HOME/Downloads, /tmp, or ~/.cache, (3) parent app spawns shell/interpreter (bash/sh/python/node/curl/wget) or desktop file, and (4) new outbound connection(s) from the child lineage.

linux:syslog auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN1316 Analytic 1316 DET0478

Cause→effect chain: (1) unified logs show application open/click or crash for Safari/Chrome/Office/Preview/archiver, (2) file write/extraction into ~/Downloads, /private/var/folders/* or ~/Library, (3) parent app spawns osascript/bash/zsh/curl/python or opens a quarantined app with Gatekeeper prompts, (4) network egress from child.

macos:unifiedlog fs:fileevents macos:osquery NSM:Flow
AN1317 Analytic 1317 DET0478

Cause→effect chain in CI/dev desktops: (1) user triggers container run/pull after opening a doc/link/script, (2) newly created image/container uses unexpected external registry or entrypoint, (3) container starts and immediately egresses to suspicious destinations.

docker:events docker:events NSM:Flow
AN1318 Analytic 1318 DET0478

Cause→effect chain in cloud consoles: (1) user clicks link then invokes instance/image creation via API, (2) instance/image originates from external AMI or unknown image, (3) instance immediately egresses or retrieves payloads.

AWS:CloudTrail AWS:CloudTrail gcp:vpcflow
AN1319 Analytic 1319 DET0479

Modification of COR_PROFILER-related environment variables or Registry keys (COR_ENABLE_PROFILING, COR_PROFILER, COR_PROFILER_PATH), combined with anomalous .NET process creation or unmanaged DLL loads. Defender observes registry modifications, suspicious process creation with altered environment variables, and profiler DLLs loaded unexpectedly into .NET CLR processes.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1320 Analytic 1320 DET0480

Detects unauthorized modifications to login-facing web server files (e.g., index.php, login.js) typically tied to VPN, SSO, or intranet portals. Correlates suspicious file changes with remote access artifacts or web shell behavior.

auditd:SYSCALL NSM:Flow
AN1321 Analytic 1321 DET0480

Detects tampering of IIS-based login pages (e.g., default.aspx, login.aspx) tied to VPN, OWA, or SharePoint via script injection or unexpected editor processes modifying web roots.

WinEventLog:Sysmon WinEventLog:iis
AN1322 Analytic 1322 DET0480

Detects unauthorized changes to locally hosted login pages on macOS (common in developer VPN environments) and links file edits to cron jobs, background scripts, or SUID binaries.

fs:fsusage macos:unifiedlog
AN1323 Analytic 1323 DET0481

Correlate suspicious registry modifications to known COM object CLSIDs with subsequent DLL loads or unexpected binary execution paths. Detect placement of COM CLSID entries under HKEY_CURRENT_USER\Software\Classes\CLSID\ overriding default HKLM paths. Flag anomalous DLL loads traced back to hijacked COM registry changes.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1324 Analytic 1324 DET0482

Detection of token duplication and impersonation attempts by correlating suspicious command-line executions (e.g., runas) with API calls to DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken. The chain includes the initial command execution or in-memory API invocation → token handle duplication or thread token assignment → a new or existing process assuming the impersonated user's context.

WinEventLog:Security WinEventLog:Sysmon ETW:Token
AN1325 Analytic 1325 DET0483

Enumeration of services via native CLI tools (e.g., `sc query`, `tasklist /svc`, `net start`) or API calls via PowerShell and WMI.

WinEventLog:Security WinEventLog:PowerShell
AN1326 Analytic 1326 DET0483

Execution of service management commands like `systemctl list-units`, `service --status-all`, or direct reading of `/etc/init.d`.

auditd:EXECVE
AN1327 Analytic 1327 DET0483

Discovery via launchctl commands, or process enumeration using `ps aux | grep com.apple.` to identify daemons and services.

macos:unifiedlog macos:osquery
AN1328 Analytic 1328 DET0484

Spike in object access from new IAM user or role followed by data exfiltration to external IPs

AWS:CloudTrail AWS:CloudTrail AWS:VPCFlowLogs
AN1331 Analytic 1331 DET0485

Identify repeated DNS resolutions where the same domain name returns multiple IPs in short succession, combined with low TTL values and high query volume from unusual processes. Correlate with process lineage (e.g., Office apps spawning abnormal DNS lookups).

WinEventLog:Sysmon WinEventLog:Security
AN1333 Analytic 1333 DET0485

Use unified logs to identify processes issuing repeated DNS queries where the resolved IP addresses change frequently within very short TTL values. Correlate with outbound network traffic to validate C2-like patterns.

macos:unifiedlog macos:unifiedlog
AN1335 Analytic 1335 DET0486

Identifies abuse of odbcconf.exe to execute malicious DLLs using the REGSVR command flag. Behavior chain: (1) Process creation of odbcconf.exe with /REGSVR or /A {REGSVR ...} arguments → (2) DLL load by odbcconf.exe of non-standard or unsigned modules → (3) Optional follow-on process creation or network activity from loaded DLL.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1344 Analytic 1344 DET0488

Behavioral chain: (1) a login from a third-party account or untrusted source network establishes an interactive/remote session; (2) the session acquires elevated privileges or accesses sensitive resources atypical for that account; (3) subsequent lateral movement or data access occurs from the same session/device. Correlate Windows logon events, token elevation/privileged use, and resource access with third-party context.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Security
AN1345 Analytic 1345 DET0488

Behavioral chain: (1) sshd or federated SSO logins from third-party networks or identities; (2) rapid sudo/su privilege elevation; (3) access to sensitive paths or east-west SSH. Correlate auth logs, process execution, and network flows.

auditd:SYSCALL linux:syslog NSM:Flow
AN1346 Analytic 1346 DET0488

Behavioral chain: (1) third-party interactive login or mobileconfig-based device enrollment; (2) privilege use or admin group change; (3) lateral movement mounts/ssh. Correlate unified logs and network telemetry.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN1347 Analytic 1347 DET0488

Behavioral chain: (1) delegated admin or external identity establishes session (e.g., partner/reseller DAP, B2B guest, SAML/OAuth trust); (2) role elevation or app consent/permission grant; (3) downstream privileged actions in the tenant. Correlate IdP sign-in, admin/role assignment, and consent/admin-on-behalf events.

azure:signinlogs azure:audit m365:unified
AN1348 Analytic 1348 DET0488

Behavioral chain: (1) cross-account or third-party principal assumes a role into the tenant/subscription/project; (2) privileged API calls are made in short succession; (3) access originates from unfamiliar networks or geos. Correlate assume-role/federation events with sensitive API usage.

AWS:CloudTrail AWS:CloudTrail gcp:audit
AN1349 Analytic 1349 DET0488

Behavioral chain: (1) third-party app or admin connects via OAuth/marketplace install; (2) high-privilege scopes granted; (3) anomalous actions (mass read/exports, admin changes).

saas:googleworkspace saas:salesforce
AN1351 Analytic 1351 DET0489

A process explicitly forges its parent using EXTENDED_STARTUPINFO + PROC_THREAD_ATTRIBUTE_PARENT_PROCESS (UpdateProcThreadAttribute → CreateProcess[A/W]/CreateProcessAsUserW) or other Native API paths, resulting in **mismatched/implausible lineage** across ETW EventHeader ProcessId, Security 4688 Creator Process ID/Name, and sysmon ParentProcessGuid. Often paired with privilege escalation when the chosen parent runs as SYSTEM.

WinEventLog:Security etw:Microsoft-Windows-Kernel-Process etw:Microsoft-Windows-Kernel-Process
AN1353 Analytic 1353 DET0491

Suspicious enumeration of attached peripherals via WMI, PowerShell, or low-level API calls potentially chained with removable device interactions.

WinEventLog:Security WinEventLog:Sysmon
AN1354 Analytic 1354 DET0491

Enumeration of USB and other peripheral hardware via udevadm, lshw, or /sys or /proc interfaces in proximity to collection or mounting behavior.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN1355 Analytic 1355 DET0491

Execution of system utilities like 'system_profiler' and 'ioreg' to enumerate hardware components or USB devices, particularly if followed by clipboard, file, or network activity.

macos:unifiedlog macos:osquery
AN1358 Analytic 1358 DET0493

Detects abuse of UNIX domain sockets, pipes, or message queues for unauthorized code execution. Correlates unexpected socket creation with suspicious binaries, abnormal shell pipelines, or injected processes establishing IPC channels.

auditd:SYSCALL auditd:SYSCALL
AN1360 Analytic 1360 DET0494

Defenders may observe attempts to disable dedicated crypto hardware on network devices, often visible through anomalous CLI commands, unexpected firmware or configuration updates, and degraded encryption performance. Suspicious indicators include commands that alter hardware acceleration settings (e.g., disabling AES-NI or crypto engines), modification of system image files, or logs showing fallback from hardware to software encryption. Network traffic analysis may also reveal a sudden downgrade in throughput or cipher negotiation behavior consistent with the absence of hardware acceleration.

networkdevice:cli networkdevice:config NSM:Flow
AN1361 Analytic 1361 DET0495

Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses.

WinEventLog:Security WinEventLog:Sysmon
AN1363 Analytic 1363 DET0495

Monitor unified logs for access to payment applications, browser plug-ins, or Apple Pay services from non-standard processes. Detect anomalous use of Automator scripts or keychain extraction targeting financial account credentials.

macos:unifiedlog macos:unifiedlog
AN1366 Analytic 1366 DET0496

Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent.

WinEventLog:Sysmon WinEventLog:System WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1367 Analytic 1367 DET0496

Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent.

auditd:SYSCALL auditd:PATH WinEventLog:Sysmon
AN1368 Analytic 1368 DET0496

Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent.

macos:unifiedlog macos:osquery macos:osquery
AN1370 Analytic 1370 DET0497

Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution.

auditd:SYSCALL auditd:CONFIG_CHANGE
AN1371 Analytic 1371 DET0497

Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss.

macos:unifiedlog macos:unifiedlog
AN1375 Analytic 1375 DET0498

A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement.

WinEventLog:Security WinEventLog:Security etw:Microsoft-Windows-Security-Auditing
AN1381 Analytic 1381 DET0501

Detects compilation activity using csc.exe, ilasm.exe, or msbuild.exe initiated by user-space processes outside typical development environments, followed by execution or network activity from newly written binaries.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1382 Analytic 1382 DET0501

Detects GCC or Clang invoked on suspicious file paths (e.g., /tmp/, ~/Downloads) with output to executable binaries, followed by execution or outbound traffic from these binaries.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN1383 Analytic 1383 DET0501

Detects non-standard compilation activity via Xcode CLI tools or bundled GCC/MONO packages writing new executable files and executing them outside dev environments (e.g., user Downloads folder).

macos:unifiedlog macos:osquery macos:unifiedlog
AN1384 Analytic 1384 DET0502

Abuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1385 Analytic 1385 DET0502

Hidden file creation using leading '.' or file attribute changes with chattr (immutable/hidden flags). Defender view: detect execution of chattr, lsattr anomalies, and unusual hidden files appearing in system directories.

auditd:EXECVE auditd:FILE
AN1386 Analytic 1386 DET0502

Hidden files via 'chflags hidden' or Apple-specific attributes, LaunchAgents/LaunchDaemons placed in non-standard hidden directories. Defender view: detect command execution modifying file flags and unusual plist creation in hidden paths.

macos:unifiedlog macos:unifiedlog
AN1389 Analytic 1389 DET0503

Detects the execution of non-browser processes establishing outbound encrypted network connections using uncommon symmetric encryption protocols (e.g., AES via PowerShell or custom scripts) to alternate external destinations.

WinEventLog:Sysmon WinEventLog:Sysmon
AN1390 Analytic 1390 DET0503

Detects command-line utilities or scripts using encryption libraries or symmetric algorithms (e.g., OpenSSL AES, GPG, Python + PyCrypto) in conjunction with outbound file transfers or traffic to external destinations.

auditd:SYSCALL auditd:SYSCALL NSM:Flow NSM:Flow
AN1391 Analytic 1391 DET0503

Detects symmetric key-based encryption operations (e.g., AES via Python, AppleScript, or OpenSSL) followed by unusual outbound connections from non-browser applications or scripted tools.

macos:unifiedlog macos:osquery macos:unifiedlog
AN1392 Analytic 1392 DET0503

Detects unexpected encrypted egress traffic from management services (e.g., hostd) or guest VMs utilizing symmetric encryption without traditional protocols (e.g., FTP with embedded AES ciphertext).

esxi:vmkernel esxi:hostd NSM:Flow
AN1393 Analytic 1393 DET0504

Detects anomalous use of Dynamic Data Exchange (DDE) for code execution, such as Office applications (WINWORD.EXE, EXCEL.EXE) spawning command interpreters, or loading unusual modules through DDEAUTO/DDE formulas. Correlates suspicious parent-child process relationships, registry keys enabling DDE, and module loads inconsistent with normal Office usage.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1394 Analytic 1394 DET0505

Detection of command-line activity exhibiting syntactic obfuscation patterns, such as excessive escape characters, base64 encoding, command concatenation, or outlier command length and entropy.

WinEventLog:Security
AN1395 Analytic 1395 DET0505

Detection of shell commands that leverage encoded execution, command chaining, excessive piping, or unusual token patterns indicative of obfuscation.

auditd:SYSCALL linux:osquery
AN1396 Analytic 1396 DET0505

Detection of obfuscated commands via shell, osascript, or AppleScript interpreters using unusual tokens, encoding, variable substitution, or runtime string reconstruction.

macos:unifiedlog macos:endpointsecurity
AN1397 Analytic 1397 DET0506

Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1398 Analytic 1398 DET0507

Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources.

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1399 Analytic 1399 DET0508

Detects process injection by correlating memory manipulation API calls (e.g., VirtualAllocEx, WriteProcessMemory), suspicious thread creation (e.g., CreateRemoteThread), and unusual DLL loads within another process's context.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1402 Analytic 1402 DET0509

Detects suspicious access to browser session cookie storage (e.g., Chrome’s `Cookies` SQLite DB) or memory reads of browser processes. Anomalous injection or memory dump utilities targeting browser processes such as `chrome.exe`, `firefox.exe`, or `msedge.exe`.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1407 Analytic 1407 DET0510

Detects suspicious SVG file creation or download events followed by script engine execution (e.g., wscript.exe, mshta.exe, rundll32.exe), network callbacks, or browser-based credential collection.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1408 Analytic 1408 DET0510

Detects downloaded SVG files followed by execution of browser processes or tools like xdg-open, and rapid follow-on network connections or process spawns to interpreters like python or bash.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN1409 Analytic 1409 DET0510

Detects SVGs downloaded via browser that invoke AppleScript, osascript, or JavaScriptCore processes, followed by network egress or file drop to LaunchAgents or ~/Library.

macos:endpointsecurity macos:unifiedlog
AN1410 Analytic 1410 DET0511

Adversary mounts a USB device and begins enumerating, copying, or compressing files using scripting engines, cmd, or remote access tools.

WinEventLog:Security WinEventLog:System WinEventLog:Sysmon
AN1411 Analytic 1411 DET0511

Adversary mounts external drive to /media or /mnt then accesses or copies targeted data via shell, cp, or tar.

auditd:SYSCALL journald:systemd auditd:SYSCALL
AN1412 Analytic 1412 DET0511

Adversary attaches USB drive and accesses sensitive files using Finder, cp, or bash scripts.

macos:unifiedlog fs:fsusage macos:osquery
AN1413 Analytic 1413 DET0512

Detects non-browser processes that establish encrypted outbound connections (e.g., TLS/SSL) to unfamiliar or atypical destinations for the host/user, following a data staging or compression event.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security NSM:Flow
AN1414 Analytic 1414 DET0512

Detects staged file access (e.g., archive or obfuscation), followed by an encrypted outbound connection (TLS/HTTPS) from unusual processes such as curl/wget, Python scripts, or custom binaries.

auditd:SYSCALL auditd:SYSCALL NSM:Flow auditd:SYSCALL
AN1415 Analytic 1415 DET0512

Detects abnormal encrypted network connections (via TLS/HTTPS) initiated by non-browser binaries, particularly after sensitive file access or compression events.

macos:osquery macos:osquery macos:unifiedlog NSM:Flow
AN1417 Analytic 1417 DET0513

Detects adversary behavior accessing Windows cached domain credential files using tools like Mimikatz, reg.exe, or PowerShell, often combined with registry exports or LSASS memory scraping.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1418 Analytic 1418 DET0513

Detects access to SSSD or Quest VAS cached credential databases using tdbdump or other file access patterns, requiring sudo/root access.

auditd:SYSCALL auditd:EXECVE linux:osquery
AN1419 Analytic 1419 DET0514

Detects exploitation attempts targeting vulnerable kernel drivers or OS components, often followed by unusual process or token behavior.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1420 Analytic 1420 DET0514

Detects escalation via vulnerable setuid binaries or kernel modules, often chained with unusual access to /proc/kallsyms or /dev/kmem.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL
AN1421 Analytic 1421 DET0514

Detects use of vulnerable kernel extensions or entitlements abused via setuid or AppleScript injection chains.

macos:unifiedlog macos:endpointsecurity
AN1428 Analytic 1428 DET0516

Detects the execution of scripting or command interpreters (e.g., powershell.exe, cmd.exe, wscript.exe) outside expected administrative time windows or from abnormal user contexts, often followed by encoded/obfuscated arguments or secondary execution events.

WinEventLog:Sysmon
AN1429 Analytic 1429 DET0516

Detects use of shell interpreters (e.g., bash, sh, python, perl) initiated by users or processes not normally executing them, especially when chaining suspicious utilities like netcat, curl, or ssh.

auditd:SYSCALL
AN1430 Analytic 1430 DET0516

Detects launch of command-line interpreters via Terminal, Automator, or hidden `osascript`, especially when parent process lineage deviates from user-initiated applications.

macos:unifiedlog
AN1433 Analytic 1433 DET0517

Detection focuses on unauthorized manipulation of .NET AppDomainManager behavior. Defenders may observe suspicious creation of new AppDomains within trusted processes, anomalous loading of assemblies via non-standard configuration files, or registry/environment variable changes redirecting AppDomainManager to malicious assemblies. Correlated events include config file tampering, new process creation of .NET host processes (e.g., w3wp.exe, powershell.exe) with modified runtime parameters, and module loads of unusual or unsigned .NET DLLs.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1434 Analytic 1434 DET0518

Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports

WinEventLog:Sysmon WinEventLog:Sysmon
AN1435 Analytic 1435 DET0518

Flooding tools like hping3 or nping sending large volumes of packets across multiple ports or IPs

auditd:SYSCALL NSM:Flow
AN1436 Analytic 1436 DET0519

Adversaries inject VBA macros into Office templates such as Normal.dotm or Personal.xlsb or redirect Office template load path via registry key (GlobalDotName) to gain persistence. Template macros trigger execution of malicious code on application startup.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Office-Alerts
AN1438 Analytic 1438 DET0520

Detects log-clearing behavior by correlating suspicious command execution targeting log files under /var/log/, anomalous deletions or truncations of system logs, and unusual child processes (e.g., shell pipelines or redirections).

auditd:SYSCALL auditd:SYSCALL
AN1439 Analytic 1439 DET0520

Detects adversary clearing log files on macOS by correlating calls to shell utilities (e.g., echo >, rm, truncate) targeting files in /var/log/ with unusual context (non-administrative users or abnormal process lineage).

macos:unifiedlog fs:fsusage
AN1440 Analytic 1440 DET0521

Detects suspicious use of PowerShell, .NET, or script interpreters to spawn processes that mimic UAC prompts, often with credential capture dialogue boxes invoked from non-standard parent processes.

WinEventLog:Sysmon WinEventLog:PowerShell
AN1441 Analytic 1441 DET0521

Detects GUI-based credential prompts invoked via zenity/kdialog/dialog or X11 APIs from non-user-facing scripts or background shell sessions, often with authentication-related text.

auditd:SYSCALL linux:cli
AN1442 Analytic 1442 DET0521

Detects AppleScript or Objective-C usage to generate fake authentication windows (e.g., using display dialog or NSAlert) from user-launched or persistence-related processes.

macos:unifiedlog macos:osquery
AN1443 Analytic 1443 DET0522

Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction.

WinEventLog:Security WinEventLog:Sysmon
AN1445 Analytic 1445 DET0522

Detects attempts to forge or replay Kerberos tickets by monitoring Unified Logs for anomalous kinit/klist activity and correlating unusual authentication sequences.

macos:unifiedlog
AN1446 Analytic 1446 DET0523

Monitors execution of administrative utilities (e.g., bcdedit.exe) or registry modifications that disable Driver Signature Enforcement (DSE) or enable Test Signing. Correlates command-line activity, registry changes, and subsequent process executions that bypass signing enforcement.

WinEventLog:Security WinEventLog:Security
AN1447 Analytic 1447 DET0523

Detects modification of System Integrity Protection (SIP) or code signing enforcement policies through csrutil or kernel variable tampering. Correlates execution of csrutil disable commands with subsequent policy state changes and anomalous unsigned process executions.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1448 Analytic 1448 DET0524

A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall WinEventLog:PowerShell
AN1449 Analytic 1449 DET0524

Closed-port knock sequence from a remote IP followed by on-host firewall change (iptables/nftables) or daemon starts listening (socket open) and a successful TCP/UDP connect. Optional detection of libpcap/raw-socket sniffers spawning to watch for secret values.

auditd:SYSCALL auditd:SYSCALL NSM:Flow NSM:Flow
AN1450 Analytic 1450 DET0524

Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN1452 Analytic 1452 DET0525

Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup.

WinEventLog:Security WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon
AN1453 Analytic 1453 DET0525

Execution of system enumeration commands such as `uname`, `df`, `uptime`, `hostname`, `lscpu`, and `cat /etc/os-release` through local terminal or scripts.

auditd:SYSCALL
AN1458 Analytic 1458 DET0526

Detects adversarial archiving of files prior to exfiltration by correlating execution of compression/encryption utilities (e.g., makecab.exe, rar.exe, 7z.exe, powershell Compress-Archive) with subsequent creation of large compressed or encrypted files. Identifies abnormal process lineage involving crypt32.dll usage, command-line arguments invoking compression switches, and file write operations to temporary or staging directories.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1459 Analytic 1459 DET0526

Detects adversarial archiving activity through invocation of utilities like tar, gzip, bzip2, or openssl used in non-administrative or unusual contexts. Correlates command execution patterns with file creation of compressed/encrypted outputs in staging directories (e.g., /tmp, /var/tmp).

auditd:SYSCALL auditd:FILE
AN1460 Analytic 1460 DET0526

Detects use of macOS-native archiving or encryption tools (zip, ditto, hdiutil) for staging collected data. Identifies unexpected invocation of archive utilities by Office apps, browsers, or background daemons. Correlates file creation of .zip/.dmg containers with process lineage anomalies.

macos:unifiedlog macos:unifiedlog
AN1461 Analytic 1461 DET0527

Execution of files containing right-to-left override characters (U+202E) to masquerade true file extensions. Often found in phishing payloads or file downloads.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Windows Defender
AN1462 Analytic 1462 DET0527

Execution of files with reversed filename extensions using Unicode RTLO character. Frequently used to deceive Gatekeeper and users in Safari or Mail-based phishing.

macos:unifiedlog macos:endpointsecurity fs:quarantine
AN1463 Analytic 1463 DET0527

Execution of user-downloaded or created scripts with hidden extensions due to RTLO character insertion in filename, often present in desktop environments or phishing campaigns.

auditd:SYSCALL linux:osquery desktop:file_manager
AN1464 Analytic 1464 DET0528

Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host.

WinEventLog:Sysmon WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon
AN1465 Analytic 1465 DET0529

Unusual or suspicious processes loading critical native API DLLs (e.g., ntdll.dll, kernel32.dll) followed by direct syscall behavior, memory manipulation, or hollowing.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1467 Analytic 1467 DET0529

Execution of processes that link to CoreServices or Foundation APIs followed by creation of memory regions, code execution, or abnormal library injection.

macos:unifiedlog macos:endpointsecurity
AN1468 Analytic 1468 DET0530

An SMB-based remote file share access followed by lateral movement actions such as remote service creation, task scheduling, or suspicious process execution on the target host using ADMIN$ or C$ shares.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1472 Analytic 1472 DET0532

Detects behavioral sequence where an adversary gains elevated privileges and clears event logs using native binaries (e.g., wevtutil), PowerShell, or direct file deletion of .evtx files.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1474 Analytic 1474 DET0534

Unauthorized modification of TCC.db followed by elevated process execution under a trusted parent (e.g., Finder, SystemUIServer) or via launchctl environment override. Also includes identification of SIP being disabled, which is highly uncommon and a prerequisite for this abuse path.

macos:unifiedlog macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1479 Analytic 1479 DET0536

Detects rogue or suspicious wireless access attempts by monitoring firewall, WIDS/WIPS, and controller logs. Focus is on firewall rule changes, rogue AP detection, and anomalous MAC addresses connecting to access points.

NSM:Firewall WIDS:AssociationLogs
AN1480 Analytic 1480 DET0537

1) New or updated software is delivered/installed from atypical sources or with signature/hash mismatches; 2) installer/updater writes binaries to unexpected paths or replaces existing signed files; 3) first run causes unsigned/abnormally signed modules to load or child processes to execute, optionally followed by network egress to new destinations.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-CodeIntegrity/Operational NSM:Flow
AN1481 Analytic 1481 DET0537

1) Package manager or curl/wget installs/upgrades from non-approved repos or unsigned packages; 2) new ELF written into PATH directories or replacement of existing binaries/libraries; 3) first run leads to unexpected child processes or outbound connections.

auditd:SYSCALL auditd:SYSCALL journald:package NSM:Flow
AN1482 Analytic 1482 DET0537

1) pkg/notarization installs from atypical sources or with Gatekeeper/AMFI warnings; 2) new Mach-O written into /Applications or ~/Library paths or substitution of signed components; 3) first run from installer spawns unsigned children or exfil.

macos:unifiedlog macos:osquery macos:endpointsecurity NSM:Flow
AN1483 Analytic 1483 DET0538

Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches.

WinEventLog:Sysmon WinEventLog:Sysmon
AN1484 Analytic 1484 DET0538

sshd, socat, or custom binaries initiating port forwarding or encapsulating traffic (e.g., RDP, SMB) through SSH or HTTP. Defender sees abnormal connect/bind syscalls, encrypted traffic on ports typically used for non-encrypted services, and outlier traffic volume patterns.

auditd:SYSCALL linux:syslog linux:osquery
AN1485 Analytic 1485 DET0538

launchd or user-invoked processes (ssh, socat) encapsulating traffic via SSH tunnels, VPN-style tooling, or DNS-over-HTTPS clients. Defender sees outbound TLS traffic with embedded DNS or RDP payloads.

macos:unifiedlog macos:unifiedlog
AN1486 Analytic 1486 DET0538

VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces.

esxi:vpxd esxcli:network
AN1489 Analytic 1489 DET0540

Sustained execution of resource-intensive processes (e.g., cryptocurrency miners), often launched via scheduled tasks, WMI, or PowerShell. These processes frequently establish persistent external connections and attempt to evade detection using masqueraded or renamed binaries.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN1490 Analytic 1490 DET0540

Unusual long-running processes consuming high CPU cycles (e.g., via 'top' or 'ps') initiated via cron, shell scripts, or Docker. Connections to known mining pools or DNS over HTTPS usage as evasion.

auditd:SYSCALL NSM:Flow linux:cron
AN1491 Analytic 1491 DET0540

Persistent or background daemons (e.g., plist or launchd jobs) spawning high-CPU processes like xmrig or cpuminer. Outbound encrypted traffic to IPs/domains commonly used by mining proxies.

macos:unifiedlog macos:unifiedlog
AN1492 Analytic 1492 DET0540

Ephemeral or unauthorized container instantiation using public images (e.g., from DockerHub) that initiate high CPU usage shortly after startup. Often scheduled via Kubernetes or Docker socket abuse.

containerd:events auditd:SYSCALL NSM:Flow
AN1495 Analytic 1495 DET0542

Monitor registry modifications to `HKLM\SYSTEM\CurrentControlSet\Control\Lsa\Security Packages` or `...\OSConfig\Security Packages`, especially insertions of new DLL entries. Correlate this with subsequent DLL module loads into `lsass.exe`. Track unsigned or anomalous DLLs loading into LSASS using image load auditing. LSASS loads unsigned DLL due to AuditLevel=8 registry configuration or System reboot followed by DLL load into lsass.exe

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1497 Analytic 1497 DET0543

Processes (e.g., bash, python, custom binaries) dynamically linking libcrypto/libssl for RSA key exchange, then creating external connections with abnormal certificate validation or handshake anomalies. Defender observes syscall traces and outbound asymmetric key exchanges from non-SSL-native processes.

auditd:SYSCALL linux:syslog linux:osquery
AN1498 Analytic 1498 DET0543

Applications or launchd services invoking RSA or public-key routines from the Security framework, followed by outbound SSL/TLS sessions with unrecognized certs or anomalous handshakes. Defender observes unified logs of API calls and suspicious network entropy.

macos:unifiedlog macos:unifiedlog
AN1499 Analytic 1499 DET0543

VMware services (hostd, vpxa) unexpectedly negotiating asymmetric crypto sessions to external endpoints outside vCenter or update servers. Defender sees encrypted handshakes in logs inconsistent with baseline ESXi communication patterns.

esxi:vpxd esxcli:network
AN1500 Analytic 1500 DET0543

Encrypted sessions detected with asymmetric key exchange anomalies on non-standard ports or with invalid/malformed certs. Defender correlates NetFlow/IPFIX with IDS/IPS detecting RSA exchanges outside expected TLS flows.

NSM:Flow IDS:TLSInspection
AN1501 Analytic 1501 DET0544

Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1502 Analytic 1502 DET0545

Monitor for suspicious use of cloud-native administrative command services (e.g., AWS Systems Manager Run Command, Azure RunCommand, GCP OS Config) to execute code inside VMs. Detect anomalies such as commands/scripts executed by unexpected users, execution outside of maintenance windows, or commands initiated by service accounts not normally tied to administration. Correlate cloud control-plane activity logs with host-level execution (process creation, script execution) to validate if commands materialized inside the guest OS.

AWS:CloudTrail azure:activity azure:vmguest
AN1503 Analytic 1503 DET0546

Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts.

azure:signinlogs saas:okta
AN1505 Analytic 1505 DET0546

Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users.

m365:unified gcp:audit
AN1506 Analytic 1506 DET0546

Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles.

m365:signinlogs gcp:audit
AN1507 Analytic 1507 DET0547

Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Application
AN1508 Analytic 1508 DET0547

Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.

auditd:SYSCALL linux:syslog NSM:Flow
AN1509 Analytic 1509 DET0547

Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.

macos:unifiedlog macos:unifiedlog
AN1511 Analytic 1511 DET0548

Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive).

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1513 Analytic 1513 DET0548

Office apps or scripts writing files followed by xattr manipulation (to evade quarantine) and subsequent HTTPS uploads. Defender perspective: anomalous file modification + outbound TLS traffic originating from non-networking apps (Word, Excel, Preview).

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1514 Analytic 1514 DET0548

Abnormal API calls from user accounts invoking file upload endpoints outside normal baselines (M365, Google Drive, Box). Defender perspective: monitor unified audit logs for elevated frequency of Upload, Create, or Copy operations from compromised accounts.

m365:unified saas:box
AN1516 Analytic 1516 DET0549

A process (non-system or user-initiated) accesses private key files in user profile paths or system certificate stores followed by potential network connections or compression activity.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN1517 Analytic 1517 DET0549

User or script-based access to ~/.ssh or other directories containing private keys followed by unusual shell activity or network connections.

auditd:SYSCALL auditd:EXECVE
AN1518 Analytic 1518 DET0549

Access to user private key directories (e.g., /Users/*/.ssh) via Terminal, scripting engines, or non-default processes.

macos:unifiedlog macos:unifiedlog
AN1527 Analytic 1527 DET0552

Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\System\CurrentControlSet\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1528 Analytic 1528 DET0553

Detects the creation or execution of padded binary files (e.g., large size but minimal legitimate content) followed by process execution or lateral movement from the host.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN1529 Analytic 1529 DET0553

Detects abnormal creation of binary files with significant size that are subsequently executed or accessed by non-standard users.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN1530 Analytic 1530 DET0553

Monitors for anomalous binary files written to disk with padded size and subsequent execution by user or service context.

macos:unifiedlog fs:fsusage
AN1531 Analytic 1531 DET0554

Detection of non-interactive or suspicious processes accessing Bluetooth interfaces and transmitting outbound traffic following file access or staging activity.

WinEventLog:System WinEventLog:Sysmon WinEventLog:Sysmon
AN1534 Analytic 1534 DET0555

Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond.

macos:unifiedlog macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1535 Analytic 1535 DET0556

MSBuild.exe is invoked outside expected developer/build contexts or with anomalous arguments (e.g., non-canonical paths, remote shares, Base64/obfuscated property values). Within a short window, it (a) spawns high-risk LOLBins/script interpreters, (b) writes new PE/DLL/script artifacts into user-writable paths and executes them, (c) loads unsigned/user-writable modules, (d) performs memory injection/thread creation into other processes, and/or (e) initiates outbound network connections.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-CodeIntegrity/Operational EDR:AMSI
AN1536 Analytic 1536 DET0557

Registry key modification to AppInit_DLLs value followed by anomalous DLL loading by processes importing user32.dll, especially unsigned or uncommon DLLs, suggesting unauthorized AppInit persistence or privilege escalation.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1538 Analytic 1538 DET0559

Correlate process execution of shutdown/reboot commands (e.g., shutdown.exe, restart-computer) with host status change logs (Event IDs 1074, 6006) and absence of related administrative context (e.g., user not in Helpdesk group).

WinEventLog:Security WinEventLog:Sysmon
AN1540 Analytic 1540 DET0559

Identify use of 'shutdown', 'reboot', or 'osascript' system shutdown invocations within unified logs and track unexpected shutdown sequences initiated by GUI or script. Cross-reference with user activity or absence thereof.

macos:unifiedlog macos:unifiedlog
AN1543 Analytic 1543 DET0560

Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints.

WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon
AN1544 Analytic 1544 DET0560

Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns.

auditd:SYSCALL NSM:Connections
AN1545 Analytic 1545 DET0560

Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity.

macos:unifiedlog macos:unifiedlog
AN1548 Analytic 1548 DET0561

Adversary installs or side-loads an IDE extension (VS Code, IntelliJ/JetBrains, Eclipse) or enables IDE tunneling. Chain: (1) IDE binary starts on a non-developer endpoint or server, often with install/force/tunnel flags → (2) extension files/registrations appear under user profile → (3) browser/IDE initiates outbound connections to extension marketplaces, update endpoints, or IDE remote/tunnel services → (4) optional child tools (ssh, node, powershell) execute under the IDE context.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1549 Analytic 1549 DET0561

Adversary installs or abuses IDE extensions via CLI or direct write to profile directories and then communicates with marketplaces or remote tunnel services. Chain: auditd execve (code/idea/eclipse) with install/update flags or writes under ~/.vscode/extensions, ~/.config/JetBrains → outbound flows to *.visualstudio.com, marketplace.visualstudio.com, *.jetbrains.com, githubusercontent.com, or SSH/WebSocket tunnel endpoints → optional ssh/node processes spawned by IDE.

auditd:SYSCALL auditd:SYSCALL NSM:Flow
AN1550 Analytic 1550 DET0561

Adversary adds IDE extensions or plugins (VS Code, JetBrains Toolbox/EAP, Eclipse) via GUI or CLI, possibly via managed profiles. Chain: process start with install/update flags → plist/extension folder changes under ~/Library/Application Support/Code or ~/Library/Application Support/JetBrains → outbound connections to marketplaces/tunnel services → optional helper (ssh/node) spawned.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1551 Analytic 1551 DET0562

Windows environmental validation behavioral chain: (1) Rapid system discovery reconnaissance through WMI queries, registry enumeration, and network share discovery, (2) Environment-specific artifact collection (hostname, domain, IP addresses, installed software, hardware identifiers), (3) Cryptographic operations or conditional logic based on collected environmental values, (4) Selective payload execution contingent on environmental validation results, (5) Temporal correlation between discovery activities and subsequent execution or network communication

WinEventLog:Security WinEventLog:Security WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:WMI WinEventLog:PowerShell
AN1552 Analytic 1552 DET0562

Linux environmental validation behavioral chain: (1) Intensive system enumeration through command execution (uname, hostname, ifconfig, lsblk, mount), (2) File system reconnaissance targeting specific paths, network configurations, and installed packages, (3) Process and user enumeration to validate target environment characteristics, (4) Conditional script execution or binary activation based on environmental criteria, (5) Network connectivity validation and external IP address resolution for geolocation verification

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL auditd:PROCTITLE linux:syslog
AN1553 Analytic 1553 DET0562

macOS environmental validation behavioral chain: (1) System profiling through system_profiler, sysctl, and hardware discovery commands, (2) Network interface and configuration enumeration for geolocation and network environment validation, (3) Application installation and version discovery for software environment fingerprinting, (4) Security feature detection (SIP, Gatekeeper, XProtect status), (5) Conditional payload execution based on macOS-specific environmental criteria and System Integrity Protection bypass validation

macos:unifiedlog fs:fileevents
AN1554 Analytic 1554 DET0562

ESXi hypervisor environmental validation behavioral chain: (1) Virtual machine inventory and configuration enumeration through vim-cmd and esxcli commands, (2) Host hardware and network configuration discovery for hypervisor environment validation, (3) Datastore and storage configuration reconnaissance, (4) vCenter connectivity and cluster membership validation, (5) Selective malware deployment based on virtualization infrastructure characteristics and target VM validation

esxi:shell esxi:hostd
AN1555 Analytic 1555 DET0563

Detection of environment variable tampering (HISTFILE, HISTCONTROL, HISTFILESIZE) and absence of expected bash history writes. Correlation of unset or zeroed history variables with active shell sessions is indicative of adversarial evasion.

auditd:SYSCALL linux:osquery
AN1557 Analytic 1557 DET0563

Detection of PowerShell history suppression using Set-PSReadLineOption with SaveNothing or altered HistorySavePath. Correlating these options with PowerShell usage highlights adversarial evasion attempts.

WinEventLog:PowerShell WinEventLog:Sysmon
AN1560 Analytic 1560 DET0564

Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1561 Analytic 1561 DET0565

Registry access to system language keys (e.g., HKLM\SYSTEM\CurrentControlSet\Control\Nls\Language) or suspicious processes invoking locale-related APIs (e.g., GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList). Defender visibility focuses on anomalous or non-standard processes issuing these queries, especially when run by unknown binaries or scripts.

WinEventLog:Security WinEventLog:Sysmon ETW
AN1562 Analytic 1562 DET0565

Processes executing commands to query system locale and language settings, such as 'locale', 'echo $LANG', or parsing environment variables. Suspicious activity is indicated by these commands being run by unusual users, automation scripts, or non-administrative processes.

auditd:SYSCALL linux:Sysmon
AN1563 Analytic 1563 DET0565

Execution of commands to query system locale and language settings, such as 'defaults read -g AppleLocale' or 'systemsetup -gettimezone'. Unusual parent processes or execution contexts of these commands may indicate adversarial discovery.

macos:unifiedlog macos:osquery
AN1564 Analytic 1564 DET0566

Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell).

WinEventLog:Sysmon WinEventLog:Sysmon
AN1567 Analytic 1567 DET0568

Detects suspicious USB HID device enumeration and keystroke injection patterns, such as rapid sequences of input with no user context, scripts executed through simulated keystrokes, or rogue devices presenting themselves as keyboards.

WinEventLog:System WinEventLog:Security WinEventLog:PowerShell
AN1568 Analytic 1568 DET0568

Detects USB HID device enumeration under `/sys/bus/usb/devices/` and rapid keystroke injection resulting in command execution such as bash or Python scripts launched without interactive user activity.

auditd:SYSCALL linux:syslog
AN1569 Analytic 1569 DET0568

Detects abnormal HID device enumeration via I/O Registry (ioreg -p IOUSB) and keystroke injection targeting AppleScript, osascript, or PowerShell equivalents. Defender correlates new USB device connections with rapid script execution.

macos:unifiedlog macos:unifiedlog
AN1571 Analytic 1571 DET0570

Unusual processes (e.g., powershell.exe, excel.exe) accessing large local files and subsequently initiating HTTPS POST requests to domains associated with cloud storage services (e.g., dropbox.com, drive.google.com, box.com). Defender perspective: correlation between file reads in sensitive directories and high outbound traffic volume to known storage APIs.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1573 Analytic 1573 DET0570

Applications or scripts invoking cloud storage APIs (Dropbox sync, iCloud, Google Drive client) in unexpected contexts. Defender perspective: detect sensitive file reads by non-standard applications followed by unusual encrypted uploads to external cloud storage domains.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1575 Analytic 1575 DET0571

Detects command-line or API-based creation/modification of Windows Services via `sc.exe`, `powershell.exe`, `services.exe`, or `ChangeServiceConfig`. Looks for creation/modification of autostart services via registry changes, file drops to `System32\services`, and anomalous parent-child process trees.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1580 Analytic 1580 DET0573

Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation.

AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail AWS:VPCFlowLogs
AN1581 Analytic 1581 DET0573

Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants.

m365:unified m365:unified m365:unified
AN1582 Analytic 1582 DET0573

Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features.

saas:googledrive saas:box
AN1583 Analytic 1583 DET0574

Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands.

WinEventLog:Sysmon WinEventLog:Sysmon
AN1584 Analytic 1584 DET0574

Use of bash scripts or interactive shells to issue sequential ping, arp, or traceroute commands to map remote hosts.

auditd:EXECVE linux:syslog
AN1585 Analytic 1585 DET0574

Execution of built-in or AppleScript-based system enumeration via `arp`, `netstat`, `ping`, and discovery of `/etc/hosts` contents.

macos:unifiedlog macos:osquery
AN1588 Analytic 1588 DET0575

Detection focuses on monitoring registry modifications under HKLM\SOFTWARE\Microsoft\Netsh that indicate the addition of helper DLLs, followed by anomalous child process activity or module load behavior initiated by netsh.exe. These behaviors are rarely legitimate and may represent an adversary establishing persistence.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1589 Analytic 1589 DET0576

Creation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties.

WinEventLog:PowerShell WinEventLog:Security m365:exchange
AN1593 Analytic 1593 DET0577

Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection.

WinEventLog:Sysmon WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN1595 Analytic 1595 DET0579

Monitor for suspicious usage of driver enumeration utilities (driverquery.exe) or API calls such as EnumDeviceDrivers(). Registry queries against HKLM\SYSTEM\CurrentControlSet\Services and HardwareProfiles that are abnormal may also indicate attempts to discover installed drivers and services. Correlate command execution, process creation, and registry access to build a behavioral chain of driver discovery.

WinEventLog:Security WinEventLog:Sysmon
AN1597 Analytic 1597 DET0579

Detect loading or inspection of kernel extensions (kextstat, kextfind) and file access to /System/Library/Extensions/. Monitor unexpected usage of these utilities by non-administrative users or scripts.

macos:unifiedlog macos:unifiedlog
AN1598 Analytic 1598 DET0580

Detects registration of new or modified network provider DLLs via registry changes, anomalous file creation of DLLs in system directories, and suspicious process activity (mpnotify.exe interacting with non-standard DLLs). Multi-event correlation ties registry modification events to subsequent DLL loads during user logon activity.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Sysmon
AN1599 Analytic 1599 DET0581

Suspicious process initiating outbound connections to web services without corresponding response or return traffic, indicative of one-way command channels.

WinEventLog:Sysmon etw:Microsoft-Windows-WinINet
AN1600 Analytic 1600 DET0581

Curl, wget, or custom HTTP clients initiated by uncommon user accounts or cron jobs to popular web services, with no observed response parsing logic.

auditd:SYSCALL iptables:LOG
AN1601 Analytic 1601 DET0581

Process using URLSession or similar API to fetch from web services without any response handling, indicative of one-way C2 channels.

macos:unifiedlog macos:endpointsecurity
AN1604 Analytic 1604 DET0583

Adversary uses built-in OS tools or API calls to create local or domain accounts for persistence or lateral movement. Tools such as 'net user', PowerShell, or MMC snap-ins may be used. Detection focuses on Event ID 4720 paired with process lineage and user context.

WinEventLog:Security WinEventLog:Sysmon
AN1609 Analytic 1609 DET0584

Unexpected creation or modification of files with `com.apple.ResourceFork` extended attributes containing unusually large or non-standard data. Defender perspective: detection of resource forks in contexts where they are uncommon, especially when paired with process execution or network activity.

macos:unifiedlog macos:unifiedlog macos:unifiedlog
AN1610 Analytic 1610 DET0585

Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-CodeIntegrity/Operational
AN1611 Analytic 1611 DET0586

Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\NTDS\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Microsoft-Windows-VSS
AN1612 Analytic 1612 DET0587

Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:Security
AN1613 Analytic 1613 DET0587

Enumeration of users and groups through suspicious shell commands or unauthorized access to /etc/passwd or /etc/shadow.

auditd:SYSCALL linux:Sysmon
AN1614 Analytic 1614 DET0587

Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.

macos:unifiedlog macos:unifiedlog
AN1620 Analytic 1620 DET0588

Detection of suspicious use of `tscon.exe` or equivalent methods to hijack legitimate RDP sessions. Defenders can observe anomalies such as session reassignments without corresponding authentication, processes spawned in the context of hijacked sessions, or unusual RDP network traffic flows that deviate from expected baselines.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System
AN1621 Analytic 1621 DET0589

Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings.

WinEventLog:Security WinEventLog:Sysmon WinEventLog:PowerShell
AN1622 Analytic 1622 DET0590

Adversary modifies externally-facing web content by accessing and overwriting hosted HTML/JS/CSS files, typically following web shell deployment, credential abuse, or exploitation of web application vulnerabilities.

WinEventLog:Security NSM:Connections WinEventLog:Sysmon
AN1623 Analytic 1623 DET0590

Adversary compromises a Linux-based web server and modifies hosted web files by exploiting upload vulnerabilities, remote code execution, or replacing index.html via SSH/webshell.

auditd:SYSCALL NSM:Connections NSM:Flow
AN1624 Analytic 1624 DET0590

Adversary modifies web-facing content on macOS via web development environments like MAMP or misconfigured Apache instances, typically with access to the hosting user account or via persistence tools.

macos:unifiedlog macos:unifiedlog
AN1625 Analytic 1625 DET0590

Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files.

AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail
AN1627 Analytic 1627 DET0591

Detects use of timestamp-altering commands like `touch -a -m -t` or `touch -r`, particularly when executed by unusual users or in suspicious directories.

auditd:SYSCALL linux:osquery
AN1630 Analytic 1630 DET0592

Defenders may observe adversary attempts to extract configuration data from management repositories by monitoring for anomalous SNMP queries, API calls, or protocol requests (e.g., NETCONF, RESTCONF) that enumerate system configuration. Suspicious sequences include repeated queries from untrusted IPs, abnormal query types requesting sensitive configuration data, or repository access occurring outside of normal administrative maintenance windows. Abnormal authentication attempts, sudden enumeration of device inventory, or bulk data transfer of configuration files may also be observed.

NSM:Flow networkdevice:syslog
AN1631 Analytic 1631 DET0593

Monitoring adversary access to sensitive process memory via the /proc filesystem to extract credential material, often involving multi-step access to /proc/[pid]/mem or /proc/[pid]/maps combined with privilege escalation or credential scraping binaries.

auditd:SYSCALL auditd:SYSCALL auditd:SYSCALL linux:Sysmon
AN1632 Analytic 1632 DET0594

Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints.

WinEventLog:Security WinEventLog:Security NSM:Content
AN1633 Analytic 1633 DET0595

Detects exploitation attempts targeting defensive security software or OS services. Defender observation includes abnormal process behavior (e.g., AV or EDR crashing unexpectedly), unsigned/untrusted modules loaded into defensive processes, or privilege escalation from security agent services. Multi-event correlation ties exploitation attempts to subsequent evasive behavior like service termination or missing logs.

WinEventLog:Security WinEventLog:Sysmon
AN1634 Analytic 1634 DET0595

Detects kernel- or user-space exploitation attempts targeting auditd, AV daemons, or security monitoring agents. Defender observation includes unexpected segfaults, privilege escalation attempts from low-privileged processes, or modifications to security binaries. Correlates exploitation attempts with subsequent gaps in logging or terminated processes.

auditd:SYSCALL linux:syslog
AN1635 Analytic 1635 DET0595

Detects exploitation of macOS security and integrity services, such as Gatekeeper, XProtect, or EDR agents. Defender observations include unsigned processes attempting privileged operations, abnormal termination of security daemons, or modification of system integrity logs.

macos:unifiedlog macos:osquery
AN1638 Analytic 1638 DET0596

SSH login from a remote system (via sshd), followed by user context execution of suspicious binaries or privilege escalation behavior.

auditd:EXECVE linux:syslog NSM:Flow
AN1639 Analytic 1639 DET0596

SSH login detected via Unified Logs, followed by unusual process execution, especially outside normal user behavior patterns.

macos:unifiedlog macos:unifiedlog macos:osquery
AN1640 Analytic 1640 DET0596

SSH login via hostd or `/var/log/auth.log`, followed by CLI access to host shell or file manipulation in restricted areas.

esxi:auth esxi:shell esxi:vmkernel
AN1641 Analytic 1641 DET0597

Detection of suspicious access to password manager processes (KeePass, 1Password, LastPass, Bitwarden) through abnormal process injection, memory reads, or command-line usage of vault-related DLLs. Correlates process creation with OS API calls and file access to vault databases (.kdbx, .opvault, .ldb).

WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon
AN1643 Analytic 1643 DET0597

Detection of password manager database access (1Password .opvault, LastPass caches, KeePass .kdbx) outside expected parent processes. Identifies memory scraping attempts via suspicious API calls or tools attaching to password manager processes.

macos:unifiedlog macos:unifiedlog macos:osquery
AN1946 Analytic 1946 DET0814

Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.

Network Traffic
AN1949 Analytic 1949 DET0817

Monitoring the content of network traffic can help detect patterns associated with active scanning activities. This can include identifying repeated connection attempts, unusual scanning behaviors, or probing activity targeting multiple IP addresses across a network. Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.

Network Traffic Network Traffic
AN1953 Analytic 1953 DET0821

Monitor social media traffic for suspicious activity, including messages requesting information as well as abnormal file or data transfers (especially those involving unknown, or otherwise suspicious accounts). Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access. Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).

Application Log Network Traffic Network Traffic
AN1955 Analytic 1955 DET0823

Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Depending on the specific method of phishing, the detections can vary. Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing) When it comes to following links, monitor for references to uncategorized or known-bad sites. URL inspection within email (including expanding shortened links) can also help detect links leading to known malicious sites. Monitor social media traffic for suspicious activity, including messages requesting information as well as abnormal file or data transfers (especially those involving unknown, or otherwise suspicious accounts). Monitor call logs from corporate devices to identify patterns of potential voice phishing, such as calls to/from known malicious phone numbers. Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.

Network Traffic Application Log Network Traffic
AN1962 Analytic 1962 DET0830

Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).

Network Traffic Network Traffic
AN1973 Analytic 1973 DET0841

Monitor for suspicious network traffic that could be indicative of probing for user information, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.

Network Traffic
AN1983 Analytic 1983 DET0851

Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently created/modified accounts making numerous connection requests to accounts affiliated with your organization. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: Spearphishing via Service).

Network Traffic Persona
AN1995 Analytic 1995 DET0863

Monitor for logged domain name system (DNS) registry data that may hijack domains and/or subdomains that can be used during targeting. In some cases, abnormal subdomain IP addresses (such as those originating in a different country from the root domain) may indicate a malicious subdomain.(Citation: Palo Alto Unit 42 Domain Shadowing 2022) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Consider monitoring for anomalous changes to domain registrant information and/or domain resolution information that may indicate the compromise of a domain. Efforts may need to be tailored to specific domains of interest as benign registration and resolution changes are a common occurrence on the internet. Monitor for queried domain name system (DNS) registry data that may hijack domains and/or subdomains that can be used during targeting. In some cases, abnormal subdomain IP addresses (such as those originating in a different country from the root domain) may indicate a malicious subdomain.(Citation: Palo Alto Unit 42 Domain Shadowing 2022) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.

Domain Name Domain Name Domain Name
AN1997 Analytic 1997 DET0865

Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing) Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).

Network Traffic Application Log Network Traffic
AN1999 Analytic 1999 DET0867

Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.

Network Traffic Network Traffic
AN2000 Analytic 2000 DET0868

Monitor for suspicious network traffic that could be indicative of scanning, such as large quantities originating from a single source (especially if the source is known to be associated with an adversary/botnet).

Network Traffic
AN2002 Analytic 2002 DET0870

Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: Spearphishing via Service). Monitor and analyze traffic patterns and packet inspection associated to protocol(s), leveraging SSL/TLS inspection for encrypted traffic, that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).

Persona Network Traffic
AN2005 Analytic 2005 DET0873

Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently created/modified accounts making numerous connection requests to accounts affiliated with your organization. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: Phishing).

Network Traffic Persona
AN2008 Analytic 2008 DET0876

Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: Phishing). Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).

Persona Network Traffic
AN2010 Analytic 2010 DET0878

Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing) Monitor for references to uncategorized or known-bad sites. URL inspection within email (including expanding shortened links and identifying obfuscated URLs) can also help detect links leading to known malicious sites.(Citation: Mandiant URL Obfuscation 2023) Furthermore, monitor browser logs for homographs in ASCII and in internationalized domain names abusing different character sets (e.g. Cyrillic vs Latin versions of trusted sites). Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. Monitor and analyze traffic patterns and packet inspection associated to protocol(s), leveraging SSL/TLS inspection for encrypted traffic, that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)). Furthermore, monitor network traffic for homographs via the use of internationalized domain names abusing different character sets (e.g. Cyrillic vs Latin versions of trusted sites). Also monitor and analyze traffic patterns and packet inspection for indicators of cloned websites. For example, if adversaries use HTTrack to clone websites, <code> Mirrored from (victim URL)</code> may be visible in the HTML section of packets.

Application Log Network Traffic Network Traffic
AN2017 Analytic 2017 DET0885

Once adversaries have provisioned compromised infrastructure (ex: a server for use in command and control), internet scans may help proactively discover compromised infrastructure. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021) Consider monitoring for anomalous changes to domain registrant information and/or domain resolution information that may indicate the compromise of a domain. Efforts may need to be tailored to specific domains of interest as benign registration and resolution changes are a common occurrence on the internet. Monitor for queried domain name system (DNS) registry data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for logged domain name system (DNS) data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for contextual data about an Internet-facing resource gathered from a scan, such as running services or ports that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.

Internet Scan Domain Name Domain Name Domain Name Internet Scan
AN2023 Analytic 2023 DET0891

Monitor for queried domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for logged domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.

Domain Name Domain Name
AN2024 Analytic 2024 DET0892

Monitor logged domain name system (DNS) data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. Domain registration information is, by design, captured in public registration logs. Consider use of services that may aid in tracking of newly acquired domains, such as WHOIS databases and/or passive DNS. In some cases it may be possible to pivot on known pieces of domain registration information to uncover other infrastructure purchased by the adversary. Consider monitoring for domains created with a similar structure to your own, including under a different TLD. Though various tools and services exist to track, query, and monitor domain name registration information, tracking across multiple DNS infrastructures can require multiple tools/services or more advanced analytics.(Citation: ThreatConnect Infrastructure Dec 2020) Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. Monitor queried domain name system (DNS) registry data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control.

Domain Name Domain Name Domain Name
AN2027 Analytic 2027 DET0895

Monitor for contextual data about an Internet-facing resource gathered from a scan, such as running services or ports that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Once adversaries have provisioned infrastructure (ex: a server for use in command and control), internet scans may help proactively discover adversary acquired infrastructure. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021) Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for queried domain name system (DNS) registry data that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Monitor for logged domain name system (DNS) data that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control. Consider use of services that may aid in tracking of newly acquired infrastructure, such as WHOIS databases for domain registration information. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.

Internet Scan Internet Scan Domain Name Domain Name Domain Name
AN2029 Analytic 2029 DET0898

Process execution without GUI context (e.g., powershell.exe, wscript.exe) generates HTTP traffic with a spoofed User-Agent mimicking a legitimate browser. No corresponding UI application (e.g., msedge.exe) is active or in parent lineage. The User-Agent deviates from known enterprise baselines or contains spoofed platform indicators. User-Agent strings can be gathered with API calls such as `ShellExecuteW` to open the default browser on a socket to receive an HTTP reply, or by hard coding the User-Agent string for a specific browser.

NSM:Flow WinEventLog:Sysmon etw:Microsoft-Windows-Kernel-Process
AN2030 Analytic 2030 DET0897

A process with no prior history or outside of known whitelisted tools initiates file or registry modifications to configure exclusion rules for antivirus, backup, or file-handling systems. Or a file system enumeration for specific file names andcritical extensions like .dll, .exe, .sys, or specific directories such as 'Program Files' or security tool paths or system component discovery for the exclusion of the files or components.

WinEventLog:PowerShell WinEventLog:Security WinEventLog:Security
AN2031 Analytic 2031 DET0898

Detection of HTTP outbound requests with inconsistent or spoofed User-Agent headers from command-line tools (e.g., curl, wget, python requests) following interactive user shells or scheduled jobs outside of normal user session behavior.

NSM:Flow auditd:SYSCALL auditd:SYSCALL
AN2032 Analytic 2032 DET0898

Observation of scripted network requests (e.g., using osascript, curl, or python) that include mismatched or spoofed browser User-Agent strings compared to the typical macOS Safari or Chrome baseline, especially when triggered by non-interactive launch agents, login hooks, or background daemons.

macos:unifiedlog NSM:Flow macos:unifiedlog
AN2035 Analytic 2035 DET0899

Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon
AN2038 Analytic 2038 DET0900

Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution.

WinEventLog:System WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security
AN2040 Analytic 2040 DET0900

Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption.

macos:unifiedlog macos:unifiedlog NSM:Flow
AN2043 Analytic 2043 DET0901

Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration.

WinEventLog:Sysmon WinEventLog:Security WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:System WinEventLog:Sysmon WinEventLog:Security
AN2063 Analytic 2063 DET0920

Detection identifies execution of scripts or files that appear visually benign (low printable character ratio) but result in runtime decoding, dynamic evaluation, and subsequent process or network activity. Correlation links script execution with abnormal Unicode density and follow-on behavior such as child process creation or outbound connections.

WinEventLog:Sysmon WinEventLog:Sysmon WinEventLog:Security WinEventLog:PowerShell WinEventLog:Sysmon WinEventLog:Sysmon

Detection Strategies

540
DET0001 Detect Access to Cloud Instance Metadata API (IaaS) DET0002 Behavioral Detection of Publish/Subscribe Protocol Misuse for C2 DET0003 T1136.002 Detection Strategy - Domain Account Creation Across Platforms DET0004 Detection Strategy for Hijack Execution Flow using Path Interception by PATH Environment Variable. DET0005 Renamed Legitimate Utility Execution with Metadata Mismatch and Suspicious Path DET0006 Detection Strategy for Network Boundary Bridging DET0007 Detection of Domain Trust Discovery via API, Script, and CLI Enumeration DET0009 Supply-chain tamper in dependencies/dev-tools (manager→write/install→first-run→egress) DET0010 Behavioral Detection of Event Triggered Execution Across Platforms DET0011 Detecting Junk Data in C2 Channels via Behavioral Analysis DET0012 Detection Strategy for VBA Stomping DET0013 Detection of Local Browser Artifact Access for Reconnaissance DET0014 Detection of Data Staging Prior to Exfiltration DET0015 Detection Strategy for Exclusive Control DET0016 Security Software Discovery Across Platforms DET0017 Detection Strategy for Application Shimming via sdbinst.exe and Registry Artifacts (Windows) DET0018 Behavior-chain, platform-aware detection strategy for T1129 Shared Modules DET0019 Detection Strategy for Stripped Payloads Across Platforms DET0020 Detect Shell Configuration Modification for Persistence via Event-Triggered Execution DET0021 Behavioral Detection for Service Stop across Platforms DET0022 Detect Forced SMB/WebDAV Authentication via lure files and outbound NTLM DET0023 Obfuscated Binary Unpacking Detection via Behavioral Patterns DET0024 Detect Kerberos Ccache File Theft or Abuse (T1558.005) DET0025 Detecting Electron Application Abuse for Proxy Execution DET0026 Windows Detection Strategy for T1547.012 - Print Processor DLL Persistence DET0027 Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets DET0028 Detect Excessive or Unauthorized Bandwidth Usage for Botnet, Proxyjacking, or Scanning Purposes DET0029 Detect Persistence via Outlook Custom Forms Triggered by Malicious Email DET0031 Invalid Code Signature Execution Detection via Metadata and Behavioral Context DET0032 Detection Strategy for Hidden Files and Directories DET0033 Detection Strategy for Accessibility Feature Hijacking via Binary Replacement or Registry Modification DET0034 Detection of Adversarial Process Discovery Behavior DET0035 Detect Bidirectional Web Service C2 Channels via Process & Network Correlation DET0037 Detect Suspicious Access to Browser Credential Stores DET0038 Detection Strategy for Hijack Execution Flow using Executable Installer File Permissions Weakness DET0039 Detection Strategy for Dynamic Resolution across OS Platforms DET0040 Detection of Persistence Artifact Removal Across Host Platforms DET0041 Detection of Lifecycle Policy Modifications for Triggered Deletion in IaaS Cloud Storage DET0042 Detection Strategy for T1218.012 Verclsid Abuse DET0043 Detection Strategy for System Location Discovery DET0044 Detecting Malicious Browser Extensions Across Platforms DET0045 Detection Strategy for Process Argument Spoofing on Windows DET0046 Detection Strategy for T1497 Virtualization/Sandbox Evasion DET0047 Detect Local Email Collection via Outlook Data File Access and Command Line Tooling DET0049 Behavioral Detection of Network History and Configuration Tampering DET0050 Detect Persistence via Malicious Office Add-ins DET0051 Detection Strategy for File/Path Exclusions DET0053 Detect Obfuscated C2 via Network Traffic Analysis DET0054 Internal Spearphishing via Trusted Accounts DET0055 Detection strategy for Group Policy Discovery on Windows DET0056 Detection Strategy for Subvert Trust Controls via Install Root Certificate. DET0057 Detect Suspicious Access to securityd Memory for Credential Extraction DET0058 Detection Strategy for Web Service: Dead Drop Resolver DET0059 Detection Strategy for Data Manipulation DET0060 Detect Ingress Tool Transfers via Behavioral Chain DET0061 Detect Default File Association Hijack via Registry & Execution Correlation on Windows DET0063 Cross-Platform Behavioral Detection of Python Execution DET0064 Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path DET0065 Detection Strategy for Container Administration Command Abuse DET0066 User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity) DET0067 Detection Strategy for Ignore Process Interrupts DET0068 Detection Strategy for T1505.004 - Malicious IIS Components DET0069 Detect unauthorized or suspicious Hardware Additions (USB/Thunderbolt/Network) DET0070 Detection Strategy for Phishing across platforms. DET0071 Detection of Remote Data Staging Prior to Exfiltration DET0072 Detect Logon Script Modifications and Execution DET0073 Detection Strategy for System Services: Systemctl DET0075 Internal Proxy Behavior via Lateral Host-to-Host C2 Relay DET0076 Behavioral Detection of Visual Basic Execution (VBS/VBA/VBScript) DET0077 Detection of Exfiltration Over Alternate Network Interfaces DET0079 Detection of Remote Service Session Hijacking DET0080 Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress) DET0081 Detection of Proxy Execution via Trusted Signed Binaries Across Platforms DET0082 Internal Website and System Content Defacement via UI or Messaging Modifications DET0083 Container CLI and API Abuse via Docker/Kubernetes (T1059.013) DET0085 Credential Dumping from SAM via Registry Dump and Local File Access DET0086 Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation DET0087 Encrypted or Encoded File Payload Detection Strategy DET0088 Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002) DET0089 Behavioral Detection of Keylogging Activity Across Platforms DET0090 Cross-host C2 via Removable Media Relay DET0091 Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups DET0092 Detection of Malicious or Unauthorized Software Extensions DET0093 Behavioral Detection of User Discovery via Local and Remote Enumeration DET0094 Cross-Platform Behavioral Detection of Scheduled Task/Job Abuse DET0095 Detect Persistence via Malicious Outlook Rules DET0096 Account Manipulation Behavior Chain Detection DET0097 Detection of Application Window Enumeration via API or Scripting DET0098 Detect abuse of Windows BITS Jobs for download, execution and persistence DET0099 Detection Strategy for T1542.001 Pre-OS Boot: System Firmware DET0100 Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing DET0101 Detection Strategy for Lua Scripting Abuse DET0102 Behavioral Detection of Input Capture Across Platforms DET0103 Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects DET0104 Detect Modification of Authentication Processes Across Platforms DET0105 Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools DET0106 Behavioral Detection of PE Injection via Remote Memory Mapping DET0107 Detection Strategy for Spearphishing Links DET0108 Detection Strategy for Data Encoding in C2 Channels DET0109 Detection Strategy for Plist File Modification (T1647) DET0110 Setuid/Setgid Privilege Abuse Detection (Linux/macOS) DET0112 Boot or Logon Initialization Scripts Detection Strategy DET0113 Detect AS-REP Roasting Attempts (T1558.004) DET0114 Behavioral Detection of Local Group Enumeration Across OS Platforms DET0115 Detection Strategy for Spearphishing via a Service across OS Platforms DET0116 Detection Strategy for Safe Mode Boot Abuse DET0117 Detection of Masqueraded Tasks or Services with Suspicious Naming and Execution DET0118 Exploitation of Remote Services – multi-platform lateral movement detection DET0119 Detection Strategy for Steganographic Abuse in File & Script Execution DET0120 Account Access Removal via Multi-Platform Audit Correlation DET0121 Detection Strategy for T1547.015 – Login Items on macOS DET0122 Detect Abuse of Windows Time Providers for Persistence DET0123 Detection of Data Exfiltration via Removable Media DET0124 Behavior-chain detection for T1132.001 Data Encoding: Standard Encoding (Base64/Hex/MIME) across Windows, Linux, macOS, ESXi DET0125 Detect persistence via reopened application plist modification (macOS) DET0126 Detection Strategy for SSH Key Injection in Authorized Keys DET0127 Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy DET0128 Detection Strategy for Hidden Windows DET0129 Domain Account Enumeration Across Platforms DET0131 Behavioral Detection Strategy for Exfiltration Over Alternative Protocol DET0132 Detection of Mutex-Based Execution Guardrails Across Platforms DET0133 IDE Tunneling Detection via Process, File, and Network Behaviors DET0134 Detect Suspicious Access to Windows Credential Manager DET0135 Detection of Mail Protocol-Based C2 Activity (SMTP, IMAP, POP3) DET0137 Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands DET0138 Detection of Malicious Code Execution via InstallUtil.exe DET0139 Detection of Credential Harvesting via API Hooking DET0140 Behavioral Detection of Malicious File Deletion DET0141 Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution DET0142 Behavioral Detection of CLI Abuse on Network Devices DET0143 Detection Strategy for Encrypted Channel via Symmetric Cryptography across OS Platforms DET0144 Detect Forged Kerberos Golden Tickets (T1558.001) DET0145 Detection of Disabled or Modified System Firewalls across OS Platforms. DET0146 Detection of Data Destruction Across Platforms via Mass Overwrite and Deletion Patterns DET0148 Detection Strategy for Forged SAML Tokens DET0149 Detection of Exfiltration Over Unencrypted Non-C2 Protocol DET0150 Detection Strategy for File Creation or Modification of Boot Files DET0151 Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery DET0152 Detection Strategy for Hijack Execution Flow: Dylib Hijacking DET0153 Detection Strategy for Exfiltration Over Webhook DET0154 Detect Screensaver-Based Persistence via Registry and Execution Chains DET0157 Detect Kerberoasting Attempts (T1558.003) DET0158 Detection of Msiexec Abuse for Local, Network, and DLL Execution DET0159 Detect Remote Access via USB Hardware (TinyPilot, PiKVM) DET0160 Detection Strategy for Multi-Factor Authentication Request Generation (T1621) DET0161 Password Policy Discovery – cross-platform behavior-chain analytics DET0162 Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002) DET0163 Detection Strategy for Network Address Translation Traversal DET0165 Behavioral Detection of Command History Clearing DET0166 Detection Strategy for T1505.002 - Transport Agent Abuse (Windows/Linux) DET0167 Firmware Modification via Flash Tool or Corrupted Firmware Upload DET0168 Virtualization/Sandbox Evasion via System Checks across Windows, Linux, macOS DET0171 Detection Strategy for Forged Web Cookies DET0172 Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows) DET0173 Detection Strategy for Endpoint DoS via Service Exhaustion Flood DET0174 Detection Strategy for Exploitation for Credential Access DET0176 Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189) DET0177 Detect Persistence via Outlook Home Page Exploitation DET0178 Behavioral Detection of Unauthorized VNC Remote Control Sessions DET0179 Behavioral Detection of Permission Groups Discovery DET0180 Detection Strategy for T1547.009 – Shortcut Modification (Windows) DET0181 Detection Strategy for SQL Stored Procedures Abuse via T1505.001 DET0182 Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS DET0183 Detection Strategy for Lateral Tool Transfer across OS platforms DET0186 Automated File and API Collection Detection Across Platforms DET0187 Detect Disabled Windows Event Log DET0188 Local Storage Discovery via Drive Enumeration and Filesystem Probing DET0189 Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification DET0191 Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows) DET0192 Detection Strategy for Email Hiding Rules DET0193 Detection Strategy for Stored Data Manipulation across OS Platforms. DET0194 Detection of Malicious Control Panel Item Execution via control.exe or Rundll32 DET0195 Behavioral Detection of System Network Configuration Discovery DET0196 Domain Fronting Behavior via Mismatched TLS SNI and HTTP Host Headers DET0197 Behavior-chain, platform-aware detection strategy for T1125 Video Capture DET0198 Detect Abuse of Container APIs for Credential Access DET0199 Detection Strategy for Virtual Machine Discovery DET0200 Indirect Command Execution – Windows utility abuse behavior chain DET0201 Detection Strategy for Hijack Execution Flow for DLLs DET0202 Behavioral Detection of Windows Command Shell Execution DET0203 Detection Strategy for Ptrace-Based Process Injection on Linux DET0204 Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows) DET0205 Detect XSL Script Abuse via msxsl and wmic DET0206 Detection of Malicious Kubernetes CronJob Scheduling DET0208 Endpoint Resource Saturation and Crash Pattern Detection Across Platforms DET0209 Detection of Registry Query for Environmental Discovery DET0210 Abuse of Domain Accounts DET0211 Detection of Direct VM Console Access via Cloud-Native Methods DET0212 Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows) DET0214 Detection Strategy for Embedded Payloads DET0215 Detection of Multi-Platform File Encryption for Impact DET0217 Detection Strategy for Extra Window Memory (EWM) Injection on Windows DET0218 Detection Strategy for Hijack Execution Flow across OS platforms. DET0219 Detection Strategy for Escape to Host DET0220 Detection of USB-Based Data Exfiltration DET0221 Behavioral Detection Strategy for T1123 Audio Capture Across Windows, Linux, macOS DET0222 Detecting MMC (.msc) Proxy Execution and Malicious COM Activation DET0223 Detection of Adversary Abuse of Software Deployment Tools DET0224 Detect Abuse of Component Object Model (T1559.001) DET0225 Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows) DET0226 Detection Strategy for Masquerading via File Type Modification DET0227 Detection Strategy for Non-Standard Ports DET0228 Detect Multi-Stage Command and Control Channels DET0229 Enumeration of Global Address Lists via Email Account Discovery DET0230 Detect Suspicious or Malicious Code Signing Abuse DET0231 Behavioral Detection of Systemd Timer Abuse for Scheduled Execution DET0233 Detection Strategy for Network Device Configuration Dump via Config Repositories DET0234 Credential Dumping via Sensitive Memory and Registry Access Correlation DET0235 Detecting Steganographic Command and Control via File + Network Correlation DET0236 Detection Strategy for Spearphishing Attachment across OS Platforms DET0237 Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts DET0238 Defacement via File and Web Content Modification Across Platforms DET0241 Detect Forged Kerberos Silver Tickets (T1558.002) DET0242 Suspicious Database Access and Dump Activity Across Environments (T1213.006) DET0243 Detection Strategy for Weaken Encryption: Reduce Key Space on Network Devices DET0244 Detection Strategy for Login Hook Persistence on macOS DET0246 Detection Strategy for MFA Interception via Input Capture and Smart Card Proxying DET0248 User Execution – Malicious Image (containers & IaaS) – pull/run → start → anomalous behavior (T1204.003) DET0249 Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes DET0250 Detect Credential Discovery via Windows Registry Enumeration DET0252 User-Initiated Malicious Library Installation via Package Manager (T1204.005) DET0253 Detection of Systemd Service Creation or Modification on Linux DET0254 Detection Strategy of Transmitted Data Manipulation DET0255 Detection Strategy for Log Enumeration DET0256 Detection Strategy for SSH Session Hijacking DET0257 Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files DET0258 Linux Python Startup Hook Persistence via .pth and Customize Files (T1546.018) DET0259 Remote Desktop Software Execution and Beaconing Detection DET0260 Detection Strategy for Forged Web Credentials DET0261 Detection of Local Data Staging Prior to Exfiltration DET0262 Detection Strategy for Dynamic Resolution through DNS Calculation DET0264 Cross-Platform Detection of JavaScript Execution Abuse DET0265 Detection Strategy for System Services: Launchctl DET0266 Behavioral Detection of Mailbox Data and Log Deletion for Anti-Forensics DET0267 Resource Hijacking Detection Strategy DET0268 Detect Archiving via Library (T1560.002) DET0269 Behavioral Detection Strategy for Remote Service Logins and Post-Access Activity DET0270 Detection of Domain or Tenant Policy Modifications via AD and Identity Provider DET0273 Detection Strategy for Encrypted Channel across OS Platforms DET0274 Boot or Logon Autostart Execution Detection Strategy DET0275 Detect Adversary Deobfuscation or Decoding of Files and Payloads DET0276 Detection Strategy for Rogue Domain Controller (DCShadow) Registration and Replication Abuse DET0278 Detection Strategy for T1542 Pre-OS Boot DET0279 Detection Strategy for System Services across OS platforms. DET0280 Behavior-Based Registry Modification Detection on Windows DET0281 Detection Strategy for Compressed Payload Creation and Execution DET0282 Detection Strategy for System Binary Proxy Execution: Regsvr32 DET0283 Behavior-chain detection for T1134 Access Token Manipulation on Windows DET0284 Detection Strategy for Exfiltration to Text Storage Sites DET0285 Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution DET0287 Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps) DET0288 Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation DET0290 Cross-Platform Detection of Cron Job Abuse for Persistence and Execution DET0292 Masquerading via Space After Filename - Behavioral Detection Strategy DET0294 User Execution – Malicious File via download/open → spawn chain (T1204.002) DET0295 Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching DET0296 Detect Adversary-in-the-Middle via Network and Configuration Anomalies DET0297 Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite DET0298 Detect Archiving via Utility (T1560.001) DET0299 Multi-Platform File and Directory Permissions Modification Detection Strategy DET0300 Detection Strategy for Reflective Code Loading DET0301 Removable Media Execution Chain Detection via File and Process Activity DET0302 Port-knock → rule/daemon change → first successful connect (T1205.001) DET0303 Local Account Enumeration Across Host Platforms DET0304 Detection Strategy for Endpoint DoS via Application or System Exploitation DET0305 Detection of Group Policy Modifications via AD Object Changes and File Activity DET0307 Detect Access to Unsecured Credential Files Across Platforms DET0308 Detection Strategy for Modify Cloud Compute Infrastructure DET0309 Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly) DET0311 Detection for Spoofing Tool UI across OS Platforms DET0312 Detect Active Setup Persistence via StubPath Execution DET0313 Detection Strategy for HTML Smuggling via JavaScript Blob + Dynamic File Drop DET0314 Detection Strategy for Network Sniffing Across Platforms DET0315 Detect Persistence via Office Test Registry DLL Injection DET0316 Detection Strategy for Disk Content Wipe via Direct Access and Overwrite DET0318 Detection Strategy for Exfiltration to Code Repository DET0320 Detection of System Network Connections Discovery Across Platforms DET0321 Detection Strategy for Hidden Virtual Instance Execution DET0322 Detection Strategy for Junk Code Obfuscation with Suspicious Execution Patterns DET0323 Detection Strategy for T1542.002 Pre-OS Boot: Component Firmware DET0324 Detection Strategy for Polymorphic Code Mutation and Execution DET0325 External Proxy Behavior via Outbound Relay to Intermediate Infrastructure DET0326 Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi DET0327 Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity DET0328 Detection of Malicious Profile Installation via CMSTP.exe DET0329 Behavioral Detection for T1490 - Inhibit System Recovery DET0330 Detection Strategy for T1546.016 - Event Triggered Execution via Installer Packages DET0331 Detection Strategy for ListPlanting Injection on Windows DET0332 Detection Strategy for AutoHotKey & AutoIT Abuse DET0333 Cross-Platform Detection of Scheduled Task/Job Abuse via `at` Utility DET0335 Detect Abuse of XPC Services (T1559.003) DET0336 Detect Compromise of Host Software Binaries DET0338 Behavioral Detection Strategy for Use Alternate Authentication Material (T1550) DET0339 Detection Strategy for Weaken Encryption on Network Devices DET0340 User Execution – Malicious Copy & Paste (browser/email → shell with obfuscated one-liner) – T1204.004 DET0341 Clipboard Data Access with Anomalous Context DET0342 Detection of Suspicious Compiled HTML File Execution via hh.exe DET0343 Direct Network Flood Detection across IaaS, Linux, Windows, and macOS DET0344 Detection Strategy for Fileless Storage via Registry, WMI, and Shared Memory DET0345 Detection Strategy for Abuse Elevation Control Mechanism (T1548) DET0346 Detect Screen Capture via Commands and API Calls DET0347 Detection Strategy for Masquerading via Legitimate Resource Name or Location DET0348 Detection Strategy for Exfiltration Over C2 Channel DET0349 Detection Strategy for Content Injection DET0350 Detecting Downgrade Attacks DET0351 Unix-like File Permission Manipulation Behavioral Chain Detection Strategy DET0354 Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers DET0355 Detection Strategy for Email Bombing DET0356 Endpoint DoS via OS Exhaustion Flood Detection Strategy DET0357 Behavioral Detection of Internet Connection Discovery DET0358 Programmatic and Excessive Access to Confluence Documentation DET0359 Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling DET0360 Behavioral Detection of Domain Group Discovery DET0361 Detecting .NET COM Registration Abuse via Regsvcs/Regasm DET0362 Detection Strategy for AppCert DLLs Persistence via Registry Injection DET0363 Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence DET0364 Behavioral Detection Strategy for WMI Execution Abuse on Windows DET0365 Detect Registry and Startup Folder Persistence (Windows) DET0366 Detection Strategy for Double File Extension Masquerading DET0367 Detect Network Logon Script Abuse via Multi-Event Correlation on Windows DET0368 Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks DET0369 Detection Strategy for Event Triggered Execution via Trap (T1546.005) DET0370 Recursive Enumeration of Files and Directories Across Privilege Contexts DET0371 Detection Strategy for Debugger Evasion (T1622) DET0372 Multi-Platform Detection Strategy for T1678 - Delay Execution DET0373 Detection Strategy for Addition of Email Delegate Permissions DET0375 Detection Strategy for T1546.017 - Udev Rules (Linux) DET0376 Behavioral Detection Strategy for Network Service Discovery Across Platforms DET0377 Detection of Kernel/User-Level Rootkit Behavior Across Platforms DET0378 Behavioral Detection of Obfuscated Files or Information DET0379 Detect Evil Twin Wi-Fi Access Points on Network Devices DET0380 Detection of Local Data Collection Prior to Exfiltration DET0381 Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL DET0382 Detection Strategy for Process Hollowing on Windows DET0384 Behavioral Detection of Unix Shell Execution DET0385 Detect Access and Parsing of .bash_history Files for Credential Harvesting DET0387 Detect ARP Cache Poisoning Across Linux, Windows, and macOS DET0388 Detection Strategy for T1548.002 – Bypass User Account Control (UAC) DET0389 Behavioral Detection of DLL Injection via Windows API DET0390 Linux Detection Strategy for T1547.013 - XDG Autostart Entries DET0391 Detection Strategy for Runtime Data Manipulation. DET0392 Multi-Platform Software Discovery Behavior Chain DET0394 Web Shell Detection via Server Behavior and File Execution Chains DET0395 macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection DET0396 Detect Access to macOS Keychain for Credential Theft DET0397 Automated Exfiltration Detection Strategy DET0398 Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks DET0399 Detection Strategy for Scheduled Transfer and Recurrent Exfiltration Patterns DET0400 Behavioral Detection of DNS Tunneling and Application Layer Abuse DET0401 Detection Strategy for Launch Daemon Creation or Modification (macOS) DET0404 Detect Winlogon Helper DLL Abuse via Registry and Process Artifacts on Windows DET0405 Detection Strategy for LNK Icon Smuggling DET0407 Detection of Local Account Abuse for Initial Access and Persistence DET0408 Detection Strategy for Reflection Amplification DoS (T1498.002) DET0409 Detection Strategy for T1550.002 - Pass the Hash (Windows) DET0410 Detection Strategy for Data from Network Shared Drive DET0411 Detection Strategy for Hide Infrastructure DET0412 Detect Access or Search for Unsecured Credentials Across Platforms DET0413 Abuse of Information Repositories for Data Collection DET0414 Detection of AppleScript-Based Execution on macOS DET0415 Application Exhaustion Flood Detection Across Platforms DET0416 Detection of File Transfer Protocol-Based C2 (FTP, FTPS, SMB, TFTP) DET0417 Detection Strategy for Power Settings Abuse DET0418 Windows DACL Manipulation Behavioral Chain Detection Strategy DET0419 Detection Strategy for Dynamic Resolution using Domain Generation Algorithms. DET0420 Detect User Activity Based Sandbox Evasion via Input & Artifact Probing DET0421 Detection Strategy for System Services Service Execution DET0422 Detection Strategy for IFEO Injection on Windows DET0423 Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot DET0425 Suspicious Use of Web Services for C2 DET0426 Detection of Direct Volume Access for File System Evasion DET0427 Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness. DET0428 Detection Strategy for Bind Mounts on Linux DET0429 Detect Modification of macOS Startup Items DET0430 Detect Credentials Access from Password Stores DET0432 Detection Strategy for NTFS File Attribute Abuse (ADS/EAs) DET0433 Detecting Code Injection via mavinject.exe (App-V Injector) DET0434 Detection of Launch Agent Creation or Modification on macOS DET0435 Detection Strategy for Hijack Execution Flow: Dynamic Linker Hijacking DET0436 Detection Strategy for Hijack Execution Flow through Services File Permissions Weakness. DET0437 Detection of LSA Secrets Dumping via Registry and Memory Extraction DET0438 Detect Archiving via Custom Method (T1560.003) DET0439 Detection of Malware Relocation via Suspicious File Movement DET0440 Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse DET0441 Detection of Suspicious Scheduled Task Creation and Execution on Windows DET0443 Detection Strategy for Masquerading via Breaking Process Trees DET0444 Detection of Command and Control Over Application Layer Protocols DET0445 Detection of Proxy Infrastructure Setup and Traffic Bridging DET0446 Credential Access via /etc/passwd and /etc/shadow Parsing DET0447 T1136.001 Detection Strategy - Local Account Creation Across Platforms DET0448 Detection Strategy for VDSO Hijacking on Linux DET0450 Detection Strategy for Kernel Modules and Extensions Autostart Execution DET0451 Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification DET0452 Detect Subversion of Trust Controls via Certificate, Registry, and Attribute Manipulation DET0453 Detection Strategy for SNMP (MIB Dump) on Network Devices DET0454 Detect Malicious Modification of Pluggable Authentication Modules (PAM) DET0455 Abuse of PowerShell for Arbitrary Execution DET0456 Behavior-chain detection for T1134.002 Create Process with Token (Windows) DET0457 Detection of Non-Application Layer Protocols for C2 DET0458 Detection of Trust Relationship Modifications in Domain or Tenant Policies DET0461 Detection Strategy for Hidden File System Abuse DET0462 Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows DET0464 Behavioral Detection of Wi-Fi Discovery Activity DET0465 Detection of Default Account Abuse Across Platforms DET0466 Detection of Script-Based Proxy Execution via Signed Microsoft Utilities DET0468 Detect DHCP Spoofing Across Linux, Windows, and macOS DET0470 Detecting Protocol or Service Impersonation via Anomalous TLS, HTTP Header, and Port Mismatch Correlation DET0471 Detection of Tainted Content Written to Shared Storage DET0472 Detect Malicious Password Filter DLL Registration DET0473 Detect persistent or elevated container services via container runtime or cluster manipulation DET0474 Environmental Keying Discovery-to-Decryption Behavioral Chain Detection Strategy DET0475 Detection Strategy for T1218.011 Rundll32 Abuse DET0476 Email Collection via Local Email Access and Auto-Forwarding Behavior DET0477 Behavioral Detection of WinRM-Based Remote Access DET0478 User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress) DET0479 Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER. DET0480 Detection of Credential Harvesting via Web Portal Modification DET0481 Windows COM Hijacking Detection via Registry and DLL Load Correlation DET0482 Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows DET0483 Detection of System Service Discovery Commands Across OS Platforms DET0484 Multi-Platform Cloud Storage Exfiltration Behavior Chain DET0485 Detection Strategy for Dynamic Resolution using Fast Flux DNS DET0486 Detecting Odbcconf Proxy Execution of Malicious DLLs DET0488 Detect abuse of Trusted Relationships (third-party and delegated admin access) DET0489 Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows) DET0491 Peripheral Device Enumeration via System Utilities and API Calls DET0493 Detect Abuse of Inter-Process Communication (T1559) DET0494 Detection Strategy for Weaken Encryption: Disable Crypto Hardware on Network Devices DET0495 Detection Strategy for Financial Theft DET0496 Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic) DET0497 Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms. DET0498 Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows) DET0501 Detection Strategy for Compile After Delivery - Source Code to Executable Transformation DET0502 Detection Strategy for Hidden Artifacts Across Platforms DET0503 Behavioral Detection Strategy for Exfiltration Over Symmetric Encrypted Non-C2 Protocol DET0504 Detect Abuse of Dynamic Data Exchange (T1559.002) DET0505 Detection Strategy for Command Obfuscation DET0506 Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation DET0507 Detect browser session hijacking via privilege, handle access, and remote thread into browsers DET0508 Behavioral Detection of Process Injection Across Platforms DET0509 Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts DET0510 Detection Strategy for SVG Smuggling with Script Execution and Delivery Behavior DET0511 Detection of Data Access and Collection from Removable Media DET0512 Detection of Exfiltration Over Asymmetric Encrypted Non-C2 Protocol DET0513 Detection of Cached Domain Credential Dumping via Local Hash Cache Access DET0514 Detection Strategy for Exploitation for Privilege Escalation DET0516 Behavioral Detection of Command and Scripting Interpreter Abuse DET0517 Detection Strategy for Hijack Execution Flow through the AppDomainManager on Windows. DET0518 Behavioral Detection of T1498 – Network Denial of Service Across Platforms DET0519 Detect Persistence via Office Template Macro Injection or Registry Hijack DET0520 Behavioral Detection of Log File Clearing on Linux and macOS DET0521 Behavioral Detection of Spoofed GUI Credential Prompts DET0522 Detect Kerberos Ticket Theft or Forgery (T1558) DET0523 Detect Code Signing Policy Modification (Windows & macOS) DET0524 Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205 DET0525 System Discovery via Native and Remote Utilities DET0526 Detect Archiving and Encryption of Collected Data (T1560) DET0527 Right-to-Left Override Masquerading Detection via Filename and Execution Context DET0528 Detecting Remote Script Proxy Execution via PubPrn.vbs DET0529 Behavioral Detection of Native API Invocation via Unusual DLL Loads and Direct Syscalls DET0530 Multi-Event Detection for SMB Admin Share Lateral Movement DET0532 Detection of Event Log Clearing on Windows via Behavioral Chain DET0534 TCC Database Manipulation via Launchctl and Unprotected SIP DET0536 Detection Strategy for Wi-Fi Networks DET0537 Behavioral detection for Supply Chain Compromise (package/update tamper → install → first-run) DET0538 Detection Strategy for Protocol Tunneling accross OS platforms. DET0540 Multi-Platform Behavioral Detection for Compute Hijacking DET0542 Registry and LSASS Monitoring for Security Support Provider Abuse DET0543 Detection Strategy for Encrypted Channel via Asymmetric Cryptography across OS Platforms DET0544 Detection Strategy for Process Doppelgänging on Windows DET0545 Detection Strategy for Cloud Administration Command DET0546 Detection of Abused or Compromised Cloud Accounts for Access and Persistence DET0547 Detection Strategy for T1505 - Server Software Component DET0548 Detection Strategy for Exfiltration Over Web Service DET0549 Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms DET0552 Detection of Windows Service Creation or Modification DET0553 Detection Strategy for Obfuscated Files or Information: Binary Padding DET0554 Detection of Bluetooth-Based Data Exfiltration DET0555 Detection Strategy for Event Triggered Execution via emond on macOS DET0556 Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows) DET0557 Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows) DET0559 Multi-Platform Shutdown or Reboot Detection via Execution and Host Status Events DET0560 Detection of Valid Account Abuse Across Platforms DET0561 Detect malicious IDE extension install/usage and IDE tunneling DET0562 Multi-Platform Execution Guardrails Environmental Validation Detection Strategy DET0563 Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms. DET0564 Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking DET0565 Detection Strategy for System Language Discovery DET0566 Template Injection Detection - Windows DET0568 Detection Strategy for Input Injection DET0570 Detection Strategy for Exfiltration to Cloud Storage DET0571 Detection of System Process Creation or Modification Across Platforms DET0573 Cross-Platform Detection of Data Transfer to Cloud Account DET0574 Detection Strategy for Remote System Enumeration Behavior DET0575 Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows) DET0576 Email Forwarding Rule Abuse Detection Across Platforms DET0577 Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows. DET0579 Detection Strategy for Device Driver Discovery DET0580 Detect Network Provider DLL Registration and Credential Capture DET0581 Detect One-Way Web Service Command Channels DET0583 Detection Strategy for T1136 - Create Account across platforms DET0584 Detection Strategy for Resource Forking on macOS DET0585 Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows) DET0586 Detection of NTDS.dit Credential Dumping from Domain Controllers DET0587 Enumeration of User or Account Information Across Platforms DET0588 Detection of Remote Service Session Hijacking for RDP. DET0589 Detect Modification of Authentication Process via Reversible Encryption DET0590 Behavioral Detection of External Website Defacement across Platforms DET0591 Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering DET0592 Detection Strategy for Data from Configuration Repository on Network Devices DET0593 Detecting OS Credential Dumping via /proc Filesystem Access on Linux DET0594 Detection of Unauthorized DCSync Operations via Replication API Abuse DET0595 Detection Strategy for Exploitation for Stealth DET0596 Behavioral Detection of Remote SSH Logins Followed by Post-Login Execution DET0597 Detect Unauthorized Access to Password Managers DET0814 Detection of Email Addresses DET0817 Detection of Scanning IP Blocks DET0821 Detection of Spearphishing Service DET0823 Detection of Phishing for Information DET0830 Detection of Active Scanning DET0841 Detection of Gather Victim Identity Information DET0851 Detection of Social Media Accounts DET0863 Detection of Domains DET0865 Detection of Spearphishing Attachment DET0867 Detection of Vulnerability Scanning DET0868 Detection of Wordlist Scanning DET0870 Detection of Social Media Accounts DET0873 Detection of Establish Accounts DET0876 Detection of Compromise Accounts DET0878 Detection of Spearphishing Link DET0885 Detection of Compromise Infrastructure DET0891 Detection of DNS Server DET0892 Detection of Domains DET0895 Detection of Acquire Infrastructure DET0898 Detection of Spoofed User-Agent DET0897 Detection of Selective Exclusion DET0899 Detect Social Engineering DET0900 Detection of Defense Impairment DET0901 Detect Windows Firewall DET0920 Detection Strategy for Invisible Unicode

Details

MITRE ID
DC0008
STIX ID
x-mitre-data-component--05645013-2fed-4066-8bdc-626b2e201dd4
Analytics
1096
Detection Strategies
540
Leaving Threaticon

This link opens an external site that isn't part of the platform.