-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathsigma_rule.csv
We can make this file beautiful and searchable if this error is corrected: No commas found in this CSV file in line 0.
3308 lines (3308 loc) · 167 KB
/
sigma_rule.csv
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
appframework_django_exceptions.yml;False
java_jndi_injection_exploitation_attempt.yml;False
java_local_file_read.yml;False
java_ognl_injection_exploitation_attempt.yml;False
java_rce_exploitation_attempt.yml;False
java_xxe_exploitation_attempt.yml;False
kubernetes_audit_deployment_deleted.yml;False
kubernetes_audit_events_deleted.yml;False
kubernetes_audit_exec_into_container.yml;False
kubernetes_audit_hostpath_mount.yml;False
kubernetes_audit_pod_in_system_namespace.yml;False
kubernetes_audit_privileged_pod_creation.yml;False
kubernetes_audit_rbac_permisions_listing.yml;False
kubernetes_audit_secrets_enumeration.yml;False
kubernetes_audit_serviceaccount_creation.yml;False
kubernetes_audit_sidecar_injection.yml;False
nodejs_rce_exploitation_attempt.yml;False
opencanary_ftp_login_attempt.yml;False
opencanary_git_clone_request.yml;False
opencanary_httpproxy_login_attempt.yml;False
opencanary_http_get.yml;False
opencanary_http_post_login_attempt.yml;False
opencanary_mssql_login_sqlauth.yml;False
opencanary_mssql_login_winauth.yml;False
opencanary_mysql_login_attempt.yml;False
opencanary_ntp_monlist.yml;False
opencanary_redis_command.yml;False
opencanary_sip_request.yml;False
opencanary_smb_file_open.yml;False
opencanary_snmp_cmd.yml;False
opencanary_ssh_login_attempt.yml;False
opencanary_ssh_new_connection.yml;False
opencanary_telnet_login_attempt.yml;False
opencanary_tftp_request.yml;False
opencanary_vnc_connection_attempt.yml;False
app_python_sql_exceptions.yml;False
rpc_firewall_atsvc_lateral_movement.yml;False
rpc_firewall_atsvc_recon.yml;False
rpc_firewall_dcsync_attack.yml;False
rpc_firewall_efs_abuse.yml;False
rpc_firewall_eventlog_recon.yml;False
rpc_firewall_itaskschedulerservice_lateral_movement.yml;False
rpc_firewall_itaskschedulerservice_recon.yml;False
rpc_firewall_printing_lateral_movement.yml;False
rpc_firewall_remote_dcom_or_wmi.yml;False
rpc_firewall_remote_registry_lateral_movement.yml;False
rpc_firewall_remote_registry_recon.yml;False
rpc_firewall_remote_server_service_abuse.yml;False
rpc_firewall_remote_service_lateral_movement.yml;False
rpc_firewall_sasec_lateral_movement.yml;False
rpc_firewall_sasec_recon.yml;False
rpc_firewall_sharphound_recon_account.yml;False
rpc_firewall_sharphound_recon_sessions.yml;False
appframework_ruby_on_rails_exceptions.yml;False
spring_application_exceptions.yml;False
spring_spel_injection.yml;False
app_sqlinjection_errors.yml;False
velocity_ssti_injection.yml;False
av_exploiting.yml;False
av_hacktool.yml;False
av_password_dumper.yml;False
av_ransomware.yml;False
av_relevant_files.yml;False
av_webshell.yml;False
db_anomalous_query.yml;False
aws_attached_malicious_lambda_layer.yml;False
aws_cloudtrail_disable_logging.yml;False
aws_config_disable_recording.yml;False
aws_console_getsignintoken.yml;False
aws_delete_identity.yml;False
aws_disable_bucket_versioning.yml;False
aws_ec2_disable_encryption.yml;False
aws_ec2_startup_script_change.yml;False
aws_ec2_vm_export_failure.yml;False
aws_ecs_task_definition_cred_endpoint_query.yml;False
aws_efs_fileshare_modified_or_deleted.yml;False
aws_efs_fileshare_mount_modified_or_deleted.yml;False
aws_eks_cluster_created_or_deleted.yml;False
aws_elasticache_security_group_created.yml;False
aws_elasticache_security_group_modified_or_deleted.yml;False
aws_enum_buckets.yml;False
aws_guardduty_disruption.yml;False
aws_iam_backdoor_users_keys.yml;False
aws_iam_s3browser_loginprofile_creation.yml;False
aws_iam_s3browser_templated_s3_bucket_policy_creation.yml;False
aws_iam_s3browser_user_or_accesskey_creation.yml;False
aws_passed_role_to_glue_development_endpoint.yml;False
aws_rds_change_master_password.yml;False
aws_rds_public_db_restore.yml;False
aws_root_account_usage.yml;False
aws_route_53_domain_transferred_lock_disabled.yml;False
aws_route_53_domain_transferred_to_another_account.yml;False
aws_s3_data_management_tampering.yml;False
aws_securityhub_finding_evasion.yml;False
aws_snapshot_backup_exfiltration.yml;False
aws_sso_idp_change.yml;False
aws_sts_assumerole_misuse.yml;False
aws_sts_getsessiontoken_misuse.yml;False
aws_susp_saml_activity.yml;False
aws_update_login_profile.yml;False
azure_aadhybridhealth_adfs_new_server.yml;False
azure_aadhybridhealth_adfs_service_delete.yml;False
azure_ad_user_added_to_admin_role.yml;False
azure_application_deleted.yml;False
azure_application_gateway_modified_or_deleted.yml;False
azure_application_security_group_modified_or_deleted.yml;False
azure_app_credential_modification.yml;False
azure_container_registry_created_or_deleted.yml;False
azure_creating_number_of_resources_detection.yml;False
azure_device_no_longer_managed_or_compliant.yml;False
azure_device_or_configuration_modified_or_deleted.yml;False
azure_dns_zone_modified_or_deleted.yml;False
azure_firewall_modified_or_deleted.yml;False
azure_firewall_rule_collection_modified_or_deleted.yml;False
azure_granting_permission_detection.yml;False
azure_keyvault_key_modified_or_deleted.yml;False
azure_keyvault_modified_or_deleted.yml;False
azure_keyvault_secrets_modified_or_deleted.yml;False
azure_kubernetes_admission_controller.yml;False
azure_kubernetes_cluster_created_or_deleted.yml;False
azure_kubernetes_cronjob.yml;False
azure_kubernetes_events_deleted.yml;False
azure_kubernetes_network_policy_change.yml;False
azure_kubernetes_pods_deleted.yml;False
azure_kubernetes_rolebinding_modified_or_deleted.yml;False
azure_kubernetes_role_access.yml;False
azure_kubernetes_secret_or_config_object_access.yml;False
azure_kubernetes_service_account_modified_or_deleted.yml;False
azure_mfa_disabled.yml;False
azure_network_firewall_policy_modified_or_deleted.yml;False
azure_network_firewall_rule_modified_or_deleted.yml;False
azure_network_p2s_vpn_modified_or_deleted.yml;False
azure_network_security_modified_or_deleted.yml;False
azure_network_virtual_device_modified_or_deleted.yml;False
azure_new_cloudshell_created.yml;False
azure_owner_removed_from_application_or_service_principal.yml;False
azure_rare_operations.yml;False
azure_service_principal_created.yml;False
azure_service_principal_removed.yml;False
azure_subscription_permissions_elevation_via_activitylogs.yml;False
azure_suppression_rule_created.yml;False
azure_virtual_network_modified_or_deleted.yml;False
azure_vpn_connection_modified_or_deleted.yml;False
azure_aad_secops_ca_policy_removedby_bad_actor.yml;False
azure_aad_secops_ca_policy_updatedby_bad_actor.yml;False
azure_aad_secops_new_ca_policy_addedby_bad_actor.yml;False
azure_ad_account_created_deleted.yml;False
azure_ad_bitlocker_key_retrieval.yml;False
azure_ad_certificate_based_authencation_enabled.yml;False
azure_ad_device_registration_policy_changes.yml;False
azure_ad_guest_users_invited_to_tenant_by_non_approved_inviters.yml;False
azure_ad_new_root_ca_added.yml;False
azure_ad_users_added_to_device_admin_roles.yml;False
azure_app_appid_uri_changes.yml;False
azure_app_credential_added.yml;False
azure_app_delegated_permissions_all_users.yml;False
azure_app_end_user_consent.yml;False
azure_app_end_user_consent_blocked.yml;False
azure_app_owner_added.yml;False
azure_app_permissions_msft.yml;False
azure_app_privileged_permissions.yml;False
azure_app_role_added.yml;False
azure_app_uri_modifications.yml;False
azure_change_to_authentication_method.yml;False
azure_federation_modified.yml;False
azure_group_user_addition_ca_modification.yml;False
azure_group_user_removal_ca_modification.yml;False
azure_guest_invite_failure.yml;False
azure_guest_to_member.yml;False
azure_pim_activation_approve_deny.yml;False
azure_pim_alerts_disabled.yml;False
azure_pim_change_settings.yml;False
azure_priviledged_role_assignment_add.yml;False
azure_priviledged_role_assignment_bulk_change.yml;False
azure_privileged_account_creation.yml;False
azure_subscription_permissions_elevation_via_auditlogs.yml;False
azure_tap_added.yml;False
azure_user_password_change.yml;False
azure_identity_protection_anomalous_token.yml;False
azure_identity_protection_anomalous_user.yml;False
azure_identity_protection_anonymous_ip_activity.yml;False
azure_identity_protection_anonymous_ip_address.yml;False
azure_identity_protection_atypical_travel.yml;False
azure_identity_protection_impossible_travel.yml;False
azure_identity_protection_inbox_forwarding_rule.yml;False
azure_identity_protection_inbox_manipulation.yml;False
azure_identity_protection_leaked_credentials.yml;False
azure_identity_protection_malicious_ip_address.yml;False
azure_identity_protection_malicious_ip_address_suspicious.yml;False
azure_identity_protection_malware_linked_ip.yml;False
azure_identity_protection_new_coutry_region.yml;False
azure_identity_protection_password_spray.yml;False
azure_identity_protection_prt_access.yml;False
azure_identity_protection_suspicious_browser.yml;False
azure_identity_protection_threat_intel.yml;False
azure_identity_protection_token_issuer_anomaly.yml;False
azure_identity_protection_unfamilar_sign_in.yml;False
azure_pim_account_stale.yml;False
azure_pim_invalid_license.yml;False
azure_pim_role_assigned_outside_of_pim.yml;False
azure_pim_role_frequent_activation.yml;False
azure_pim_role_not_used.yml;False
azure_pim_role_no_mfa_required.yml;False
azure_pim_too_many_global_admins.yml;False
azure_account_lockout.yml;False
azure_ad_authentications_from_countries_you_do_not_operate_out_of.yml;False
azure_ad_auth_failure_increase.yml;False
azure_ad_auth_sucess_increase.yml;False
azure_ad_auth_to_important_apps_using_single_factor_auth.yml;False
azure_ad_azurehound_discovery.yml;False
azure_ad_device_registration_or_join_without_mfa.yml;False
azure_ad_failed_auth_from_countries_you_do_not_operate_out_of.yml;False
azure_ad_only_single_factor_auth_required.yml;False
azure_ad_risky_sign_ins_with_singlefactorauth_from_unknown_devices.yml;False
azure_ad_sign_ins_from_noncompliant_devices.yml;False
azure_ad_sign_ins_from_unknown_devices.yml;False
azure_ad_suspicious_signin_bypassing_mfa.yml;False
azure_app_device_code_authentication.yml;False
azure_app_ropc_authentication.yml;False
azure_blocked_account_attempt.yml;False
azure_conditional_access_failure.yml;False
azure_legacy_authentication_protocols.yml;False
azure_login_to_disabled_account.yml;False
azure_mfa_denies.yml;False
azure_mfa_interrupted.yml;False
azure_unusual_authentication_interruption.yml;False
azure_users_authenticating_to_other_azure_ad_tenants.yml;False
azure_user_login_blocked_by_conditional_access.yml;False
bitbucket_audit_full_data_export_triggered.yml;False
bitbucket_audit_global_permissions_change_detected.yml;False
bitbucket_audit_global_secret_scanning_rule_deleted.yml;False
bitbucket_audit_global_ssh_settings_change_detected.yml;False
bitbucket_audit_log_configuration_update_detected.yml;False
bitbucket_audit_project_secret_scanning_allowlist_added.yml;False
bitbucket_audit_secret_scanning_exempt_repository_detected.yml;False
bitbucket_audit_secret_scanning_rule_deleted.yml;False
bitbucket_audit_unauthorized_access_detected.yml;False
bitbucket_audit_unauthorized_full_data_export_triggered.yml;False
bitbucket_audit_user_details_export_attempt_detected.yml;False
bitbucket_audit_user_login_failure_detected.yml;False
bitbucket_audit_user_login_failure_via_ssh_detected.yml;False
bitbucket_audit_user_permissions_export_attempt_detected.yml;False
cisco_duo_mfa_bypass_via_bypass_code.yml;False
gcp_access_policy_deleted.yml;False
gcp_breakglass_container_workload_deployed.yml;False
gcp_bucket_enumeration.yml;False
gcp_bucket_modified_or_deleted.yml;False
gcp_dlp_re_identifies_sensitive_information.yml;False
gcp_dns_zone_modified_or_deleted.yml;False
gcp_firewall_rule_modified_or_deleted.yml;False
gcp_full_network_traffic_packet_capture.yml;False
gcp_kubernetes_admission_controller.yml;False
gcp_kubernetes_cronjob.yml;False
gcp_kubernetes_rolebinding.yml;False
gcp_kubernetes_secrets_modified_or_deleted.yml;False
gcp_service_account_disabled_or_deleted.yml;False
gcp_service_account_modified.yml;False
gcp_sql_database_modified_or_deleted.yml;False
gcp_vpn_tunnel_modified_or_deleted.yml;False
gcp_gworkspace_application_access_levels_modified.yml;False
gcp_gworkspace_application_removed.yml;False
gcp_gworkspace_granted_domain_api_access.yml;False
gcp_gworkspace_mfa_disabled.yml;False
gcp_gworkspace_role_modified_or_deleted.yml;False
gcp_gworkspace_role_privilege_deleted.yml;False
gcp_gworkspace_user_granted_admin_privileges.yml;False
github_delete_action_invoked.yml;False
github_disabled_outdated_dependency_or_vulnerability.yml;False
github_disable_high_risk_configuration.yml;False
github_new_org_member.yml;False
github_new_secret_created.yml;False
github_outside_collaborator_detected.yml;False
github_push_protection_bypass_detected.yml;False
github_push_protection_disabled.yml;False
github_secret_scanning_feature_disabled.yml;False
github_self_hosted_runner_changes_detected.yml;False
microsoft365_disabling_mfa.yml;False
microsoft365_new_federated_domain_added_audit.yml;False
microsoft365_new_federated_domain_added_exchange.yml;False
microsoft365_from_susp_ip_addresses.yml;False
microsoft365_activity_by_terminated_user.yml;False
microsoft365_activity_from_anonymous_ip_addresses.yml;False
microsoft365_activity_from_infrequent_country.yml;False
microsoft365_data_exfiltration_to_unsanctioned_app.yml;False
microsoft365_impossible_travel_activity.yml;False
microsoft365_logon_from_risky_ip_address.yml;False
microsoft365_potential_ransomware_activity.yml;False
microsoft365_pst_export_alert.yml;False
microsoft365_pst_export_alert_using_new_compliancesearchaction.yml;False
microsoft365_susp_inbox_forwarding.yml;False
microsoft365_susp_oauth_app_file_download_activities.yml;False
microsoft365_unusual_volume_of_file_deletion.yml;False
microsoft365_user_restricted_from_sending_email.yml;False
okta_admin_activity_from_proxy_query.yml;False
okta_admin_role_assigned_to_user_or_group.yml;False
okta_admin_role_assignment_created.yml;False
okta_api_token_created.yml;False
okta_api_token_revoked.yml;False
okta_application_modified_or_deleted.yml;False
okta_application_sign_on_policy_modified_or_deleted.yml;False
okta_fastpass_phishing_detection.yml;False
okta_identity_provider_created.yml;False
okta_mfa_reset_or_deactivated.yml;False
okta_network_zone_deactivated_or_deleted.yml;False
okta_new_behaviours_admin_console.yml;False
okta_password_in_alternateid_field.yml;False
okta_policy_modified_or_deleted.yml;False
okta_policy_rule_modified_or_deleted.yml;False
okta_security_threat_detected.yml;False
okta_suspicious_activity_enduser_report.yml;False
okta_unauthorized_access_to_app.yml;False
okta_user_account_locked_out.yml;False
okta_user_created.yml;False
okta_user_session_start_via_anonymised_proxy.yml;False
onelogin_assumed_another_user.yml;False
onelogin_user_account_locked.yml;False
default_credentials_usage.yml;False
host_without_firewall.yml;False
netflow_cleartext_protocols.yml;False
lnx_auditd_audio_capture.yml;False
lnx_auditd_auditing_config_change.yml;False
lnx_auditd_binary_padding.yml;False
lnx_auditd_bpfdoor_file_accessed.yml;False
lnx_auditd_bpfdoor_port_redirect.yml;False
lnx_auditd_capabilities_discovery.yml;False
lnx_auditd_change_file_time_attr.yml;False
lnx_auditd_chattr_immutable_removal.yml;False
lnx_auditd_clipboard_collection.yml;False
lnx_auditd_clipboard_image_collection.yml;False
lnx_auditd_coinminer.yml;False
lnx_auditd_create_account.yml;False
lnx_auditd_data_compressed.yml;False
lnx_auditd_data_exfil_wget.yml;False
lnx_auditd_dd_delete_file.yml;False
lnx_auditd_disable_system_firewall.yml;False
lnx_auditd_file_or_folder_permissions.yml;False
lnx_auditd_find_cred_in_files.yml;False
lnx_auditd_hidden_binary_execution.yml;False
lnx_auditd_hidden_files_directories.yml;False
lnx_auditd_hidden_zip_files_steganography.yml;False
lnx_auditd_keylogging_with_pam_d.yml;False
lnx_auditd_ld_so_preload_mod.yml;False
lnx_auditd_load_module_insmod.yml;False
lnx_auditd_logging_config_change.yml;False
lnx_auditd_masquerading_crond.yml;False
lnx_auditd_modify_system_firewall.yml;False
lnx_auditd_network_service_scanning.yml;False
lnx_auditd_network_sniffing.yml;False
lnx_auditd_omigod_scx_runasprovider_executeshellcommand.yml;False
lnx_auditd_password_policy_discovery.yml;False
lnx_auditd_pers_systemd_reload.yml;False
lnx_auditd_screencapture_import.yml;False
lnx_auditd_screencaputre_xwd.yml;False
lnx_auditd_split_file_into_pieces.yml;False
lnx_auditd_steghide_embed_steganography.yml;False
lnx_auditd_steghide_extract_steganography.yml;False
lnx_auditd_susp_c2_commands.yml;False
lnx_auditd_susp_cmds.yml;False
lnx_auditd_susp_exe_folders.yml;False
lnx_auditd_susp_histfile_operations.yml;False
lnx_auditd_systemd_service_creation.yml;False
lnx_auditd_system_info_discovery.yml;False
lnx_auditd_system_info_discovery2.yml;False
lnx_auditd_system_shutdown_reboot.yml;False
lnx_auditd_unix_shell_configuration_modification.yml;False
lnx_auditd_unzip_hidden_zip_files_steganography.yml;False
lnx_auditd_user_discovery.yml;False
lnx_auditd_web_rce.yml;False
lnx_apt_equationgroup_lnx.yml;False
lnx_buffer_overflows.yml;False
lnx_clear_syslog.yml;False
lnx_file_copy.yml;False
lnx_ldso_preload_injection.yml;False
lnx_nimbuspwn_privilege_escalation_exploit.yml;False
lnx_potential_susp_ebpf_activity.yml;False
lnx_privileged_user_creation.yml;False
lnx_shellshock.yml;False
lnx_shell_clear_cmd_history.yml;False
lnx_shell_susp_commands.yml;False
lnx_shell_susp_log_entries.yml;False
lnx_shell_susp_rev_shells.yml;False
lnx_space_after_filename_.yml;False
lnx_susp_dev_tcp.yml;False
lnx_susp_jexboss.yml;False
lnx_symlink_etc_passwd.yml;False
lnx_auth_pwnkit_local_privilege_escalation.yml;False
lnx_clamav_relevant_message.yml;False
lnx_cron_crontab_file_modification.yml;False
lnx_guacamole_susp_guacamole.yml;False
lnx_sshd_ssh_cve_2018_15473.yml;False
lnx_sshd_susp_ssh.yml;False
lnx_sudo_cve_2019_14287_user.yml;False
lnx_syslog_security_tools_disabling_syslog.yml;False
lnx_syslog_susp_named.yml;False
lnx_vsftpd_susp_error_messages.yml;False
file_event_lnx_doas_conf_creation.yml;False
file_event_lnx_persistence_cron_files.yml;False
file_event_lnx_persistence_sudoers_files.yml;False
file_event_lnx_susp_shell_script_under_profile_directory.yml;False
file_event_lnx_triple_cross_rootkit_lock_file.yml;False
file_event_lnx_triple_cross_rootkit_persistence.yml;False
file_event_lnx_wget_download_file_in_tmp_dir.yml;False
net_connection_lnx_back_connect_shell_dev.yml;False
net_connection_lnx_crypto_mining_indicators.yml;False
net_connection_lnx_ngrok_tunnel.yml;False
net_connection_lnx_susp_malware_callback_port.yml;False
proc_creation_lnx_at_command.yml;False
proc_creation_lnx_base64_decode.yml;False
proc_creation_lnx_base64_execution.yml;False
proc_creation_lnx_base64_shebang_cli.yml;False
proc_creation_lnx_bash_interactive_shell.yml;False
proc_creation_lnx_bpftrace_unsafe_option_usage.yml;False
proc_creation_lnx_bpf_kprob_tracing_enabled.yml;False
proc_creation_lnx_capa_discovery.yml;False
proc_creation_lnx_cat_sudoers.yml;False
proc_creation_lnx_chattr_immutable_removal.yml;False
proc_creation_lnx_clear_logs.yml;False
proc_creation_lnx_clear_syslog.yml;False
proc_creation_lnx_clipboard_collection.yml;False
proc_creation_lnx_cp_passwd_or_shadow_tmp.yml;False
proc_creation_lnx_crontab_enumeration.yml;False
proc_creation_lnx_crontab_removal.yml;False
proc_creation_lnx_crypto_mining.yml;False
proc_creation_lnx_curl_usage.yml;False
proc_creation_lnx_cve_2022_26134_atlassian_confluence.yml;False
proc_creation_lnx_cve_2022_33891_spark_shell_command_injection.yml;False
proc_creation_lnx_dd_file_overwrite.yml;False
proc_creation_lnx_dd_process_injection.yml;False
proc_creation_lnx_disable_ufw.yml;False
proc_creation_lnx_doas_execution.yml;False
proc_creation_lnx_esxcli_network_discovery.yml;False
proc_creation_lnx_esxcli_permission_change_admin.yml;False
proc_creation_lnx_esxcli_storage_discovery.yml;False
proc_creation_lnx_esxcli_syslog_config_change.yml;False
proc_creation_lnx_esxcli_system_discovery.yml;False
proc_creation_lnx_esxcli_user_account_creation.yml;False
proc_creation_lnx_esxcli_vm_discovery.yml;False
proc_creation_lnx_esxcli_vm_kill.yml;False
proc_creation_lnx_esxcli_vsan_discovery.yml;False
proc_creation_lnx_file_and_directory_discovery.yml;False
proc_creation_lnx_file_deletion.yml;False
proc_creation_lnx_grep_os_arch_discovery.yml;False
proc_creation_lnx_groupdel.yml;False
proc_creation_lnx_gtfobin_apt.yml;False
proc_creation_lnx_gtfobin_vim.yml;False
proc_creation_lnx_install_root_certificate.yml;False
proc_creation_lnx_install_suspicioua_packages.yml;False
proc_creation_lnx_iptables_flush_ufw.yml;False
proc_creation_lnx_kill_process.yml;False
proc_creation_lnx_local_account.yml;False
proc_creation_lnx_local_groups.yml;False
proc_creation_lnx_malware_gobrat_grep_payload_discovery.yml;False
proc_creation_lnx_mkfifo_named_pipe_creation.yml;False
proc_creation_lnx_mkfifo_named_pipe_creation_susp_location.yml;False
proc_creation_lnx_mount_hidepid.yml;False
proc_creation_lnx_netcat_reverse_shell.yml;False
proc_creation_lnx_nohup.yml;False
proc_creation_lnx_nohup_susp_execution.yml;False
proc_creation_lnx_omigod_scx_runasprovider_executescript.yml;False
proc_creation_lnx_omigod_scx_runasprovider_executeshellcommand.yml;False
proc_creation_lnx_perl_reverse_shell.yml;False
proc_creation_lnx_php_reverse_shell.yml;False
proc_creation_lnx_pnscan_binary_cli_pattern.yml;False
proc_creation_lnx_process_discovery.yml;False
proc_creation_lnx_proxy_connection.yml;False
proc_creation_lnx_python_pty_spawn.yml;False
proc_creation_lnx_python_reverse_shell.yml;False
proc_creation_lnx_remote_access_tools_teamviewer_incoming_connection.yml;False
proc_creation_lnx_remote_system_discovery.yml;False
proc_creation_lnx_remove_package.yml;False
proc_creation_lnx_ruby_reverse_shell.yml;False
proc_creation_lnx_schedule_task_job_cron.yml;False
proc_creation_lnx_security_software_discovery.yml;False
proc_creation_lnx_security_tools_disabling.yml;False
proc_creation_lnx_services_stop_and_disable.yml;False
proc_creation_lnx_setgid_setuid.yml;False
proc_creation_lnx_ssm_agent_abuse.yml;False
proc_creation_lnx_sudo_cve_2019_14287.yml;False
proc_creation_lnx_susp_chmod_directories.yml;False
proc_creation_lnx_susp_container_residence_discovery.yml;False
proc_creation_lnx_susp_curl_fileupload.yml;False
proc_creation_lnx_susp_curl_useragent.yml;False
proc_creation_lnx_susp_dockerenv_recon.yml;False
proc_creation_lnx_susp_execution_tmp_folder.yml;False
proc_creation_lnx_susp_find_execution.yml;False
proc_creation_lnx_susp_git_clone.yml;False
proc_creation_lnx_susp_history_delete.yml;False
proc_creation_lnx_susp_history_recon.yml;False
proc_creation_lnx_susp_hktl_execution.yml;False
proc_creation_lnx_susp_inod_listing.yml;False
proc_creation_lnx_susp_interactive_bash.yml;False
proc_creation_lnx_susp_java_children.yml;False
proc_creation_lnx_susp_network_utilities_execution.yml;False
proc_creation_lnx_susp_pipe_shell.yml;False
proc_creation_lnx_susp_recon_indicators.yml;False
proc_creation_lnx_susp_sensitive_file_access.yml;False
proc_creation_lnx_susp_shell_child_process_from_parent_tmp_folder.yml;False
proc_creation_lnx_susp_shell_script_exec_from_susp_location.yml;False
proc_creation_lnx_system_info_discovery.yml;False
proc_creation_lnx_system_network_connections_discovery.yml;False
proc_creation_lnx_system_network_discovery.yml;False
proc_creation_lnx_touch_susp.yml;False
proc_creation_lnx_triple_cross_rootkit_execve_hijack.yml;False
proc_creation_lnx_triple_cross_rootkit_install.yml;False
proc_creation_lnx_userdel.yml;False
proc_creation_lnx_usermod_susp_group.yml;False
proc_creation_lnx_webshell_detection.yml;False
proc_creation_lnx_wget_download_suspicious_directory.yml;False
proc_creation_lnx_xterm_reverse_shell.yml;False
file_event_macos_emond_launch_daemon.yml;False
file_event_macos_startup_items.yml;False
proc_creation_macos_applescript.yml;False
proc_creation_macos_base64_decode.yml;False
proc_creation_macos_binary_padding.yml;False
proc_creation_macos_change_file_time_attr.yml;False
proc_creation_macos_clear_system_logs.yml;False
proc_creation_macos_clipboard_data_via_osascript.yml;False
proc_creation_macos_create_account.yml;False
proc_creation_macos_create_hidden_account.yml;False
proc_creation_macos_creds_from_keychain.yml;False
proc_creation_macos_csrutil_disable.yml;False
proc_creation_macos_csrutil_status.yml;False
proc_creation_macos_disable_security_tools.yml;False
proc_creation_macos_dscl_add_user_to_admin_group.yml;False
proc_creation_macos_dseditgroup_add_to_admin_group.yml;False
proc_creation_macos_dsenableroot_enable_root_account.yml;False
proc_creation_macos_file_and_directory_discovery.yml;False
proc_creation_macos_find_cred_in_files.yml;False
proc_creation_macos_gui_input_capture.yml;False
proc_creation_macos_installer_susp_child_process.yml;False
proc_creation_macos_ioreg_discovery.yml;False
proc_creation_macos_jamf_susp_child.yml;False
proc_creation_macos_jamf_usage.yml;False
proc_creation_macos_jxa_in_memory_execution.yml;False
proc_creation_macos_launchctl_execution.yml;False
proc_creation_macos_local_account.yml;False
proc_creation_macos_local_groups.yml;False
proc_creation_macos_network_service_scanning.yml;False
proc_creation_macos_network_sniffing.yml;False
proc_creation_macos_office_susp_child_processes.yml;False
proc_creation_macos_osacompile_runonly_execution.yml;False
proc_creation_macos_payload_decoded_and_decrypted.yml;False
proc_creation_macos_persistence_via_plistbuddy.yml;False
proc_creation_macos_remote_access_tools_teamviewer_incoming_connection.yml;False
proc_creation_macos_remote_system_discovery.yml;False
proc_creation_macos_schedule_task_job_cron.yml;False
proc_creation_macos_screencapture.yml;False
proc_creation_macos_security_software_discovery.yml;False
proc_creation_macos_space_after_filename.yml;False
proc_creation_macos_split_file_into_pieces.yml;False
proc_creation_macos_suspicious_applet_behaviour.yml;False
proc_creation_macos_susp_browser_child_process.yml;False
proc_creation_macos_susp_execution_macos_script_editor.yml;False
proc_creation_macos_susp_find_execution.yml;False
proc_creation_macos_susp_histfile_operations.yml;False
proc_creation_macos_susp_in_memory_download_and_compile.yml;False
proc_creation_macos_susp_macos_firmware_activity.yml;False
proc_creation_macos_swvers_discovery.yml;False
proc_creation_macos_sysadminctl_add_user_to_admin_group.yml;False
proc_creation_macos_sysadminctl_enable_guest_account.yml;False
proc_creation_macos_system_network_connections_discovery.yml;False
proc_creation_macos_system_network_discovery.yml;False
proc_creation_macos_system_profiler_discovery.yml;False
proc_creation_macos_system_shutdown_reboot.yml;False
proc_creation_macos_tail_base64_decode_from_image.yml;False
proc_creation_macos_wizardupdate_malware_infection.yml;False
proc_creation_macos_xattr_gatekeeper_bypass.yml;False
proc_creation_macos_xcsset_malware_infection.yml;False
cisco_cli_clear_logs.yml;False
cisco_cli_collect_data.yml;False
cisco_cli_crypto_actions.yml;False
cisco_cli_disable_logging.yml;False
cisco_cli_discovery.yml;False
cisco_cli_dos.yml;False
cisco_cli_file_deletion.yml;False
cisco_cli_input_capture.yml;False
cisco_cli_local_accounts.yml;False
cisco_cli_modify_config.yml;False
cisco_cli_moving_data.yml;False
cisco_cli_net_sniff.yml;False
cisco_bgp_md5_auth_failed.yml;False
cisco_ldp_md5_auth_failed.yml;False
net_dns_external_service_interaction_domains.yml;False
net_dns_mal_cobaltstrike.yml;False
net_dns_pua_cryptocoin_mining_xmr.yml;False
net_dns_susp_b64_queries.yml;False
net_dns_susp_telegram_api.yml;False
net_dns_susp_txt_exec_strings.yml;False
net_dns_wannacry_killswitch_domain.yml;False
net_firewall_cleartext_protocols.yml;False
huawei_bgp_auth_failed.yml;False
juniper_bgp_missing_md5.yml;False
zeek_dce_rpc_mitre_bzar_execution.yml;False
zeek_dce_rpc_mitre_bzar_persistence.yml;False
zeek_dce_rpc_potential_petit_potam_efs_rpc_call.yml;False
zeek_dce_rpc_printnightmare_print_driver_install.yml;False
zeek_dce_rpc_smb_spoolss_named_pipe.yml;False
zeek_default_cobalt_strike_certificate.yml;False
zeek_dns_mining_pools.yml;False
zeek_dns_nkn.yml;False
zeek_dns_susp_zbit_flag.yml;False
zeek_dns_torproxy.yml;False
zeek_http_executable_download_from_webdav.yml;False
zeek_http_omigod_no_auth_rce.yml;False
zeek_http_webdav_put_request.yml;False
zeek_rdp_public_listener.yml;False
zeek_smb_converted_win_atsvc_task.yml;False
zeek_smb_converted_win_impacket_secretdump.yml;False
zeek_smb_converted_win_lm_namedpipe.yml;False
zeek_smb_converted_win_susp_psexec.yml;False
zeek_smb_converted_win_susp_raccess_sensitive_fext.yml;False
zeek_smb_converted_win_transferring_files_with_credential_data.yml;False
zeek_susp_kerberos_rc4.yml;False
web_apache_segfault.yml;False
web_apache_threading_error.yml;False
web_nginx_core_dump.yml;False
proxy_downloadcradle_webdav.yml;False
proxy_download_susp_dyndns.yml;False
proxy_download_susp_tlds_blacklist.yml;False
proxy_download_susp_tlds_whitelist.yml;False
proxy_f5_tm_utility_bash_api_request.yml;False
proxy_hktl_baby_shark_default_agent_url.yml;False
proxy_hktl_cobalt_strike_malleable_c2_requests.yml;False
proxy_hktl_empire_ua_uri_patterns.yml;False
proxy_pua_advanced_ip_scanner_update_check.yml;False
proxy_pwndrop.yml;False
proxy_raw_paste_service_access.yml;False
proxy_susp_flash_download_loc.yml;False
proxy_susp_ipfs_cred_harvest.yml;False
proxy_telegram_api.yml;False
proxy_ua_apt.yml;False
proxy_ua_base64_encoded.yml;False
proxy_ua_bitsadmin_susp_ip.yml;False
proxy_ua_bitsadmin_susp_tld.yml;False
proxy_ua_cryptominer.yml;False
proxy_ua_empty.yml;False
proxy_ua_frameworks.yml;False
proxy_ua_hacktool.yml;False
proxy_ua_malware.yml;False
proxy_ua_powershell.yml;False
proxy_ua_rclone.yml;False
proxy_ua_susp.yml;False
proxy_ua_susp_base64.yml;False
proxy_webdav_external_execution.yml;False
web_f5_tm_utility_bash_api_request.yml;False
web_iis_tilt_shortname_scan.yml;False
web_java_payload_in_access_logs.yml;False
web_jndi_exploit.yml;False
web_path_traversal_exploitation_attempt.yml;False
web_source_code_enumeration.yml;False
web_sql_injection_in_access_logs.yml;False
web_ssti_in_access_logs.yml;False
web_susp_useragents.yml;False
web_susp_windows_path_uri.yml;False
web_webshell_regeorg.yml;False
web_win_webshells_in_access_logs.yml;False
web_xss_in_access_logs.yml;False
win_alert_mimikatz_keywords.yml;True
win_application_msmpeng_crash_error.yml;False
win_werfault_susp_lsass_credential_dump.yml;False
win_esent_ntdsutil_abuse.yml;False
win_esent_ntdsutil_abuse_susp_location.yml;False
win_audit_cve.yml;False
win_susp_backup_delete.yml;False
win_software_restriction_policies_block.yml;False
win_builtin_remove_application.yml;True
win_msi_install_from_susp_locations.yml;False
win_msi_install_from_web.yml;False
win_software_atera_rmm_agent_install.yml;False
win_mssql_add_sysadmin_account.yml;False
win_mssql_disable_audit_settings.yml;False
win_mssql_failed_logon.yml;False
win_mssql_failed_logon_from_external_network.yml;False
win_mssql_sp_procoption_set.yml;False
win_mssql_xp_cmdshell_audit_log.yml;False
win_mssql_xp_cmdshell_change.yml;False
win_av_relevant_match.yml;True
win_app_remote_access_tools_screenconnect_command_exec.yml;False
win_app_remote_access_tools_screenconnect_file_transfer.yml;False
win_application_msmpeng_crash_wer.yml;False
win_applocker_file_was_not_allowed_to_run.yml;False
win_appmodel_runtime_sysinternals_tools_appx_execution.yml;False
win_appxdeployment_server_applocker_block.yml;False
win_appxdeployment_server_mal_appx_names.yml;False
win_appxdeployment_server_policy_block.yml;False
win_appxdeployment_server_susp_appx_package_installation.yml;False
win_appxdeployment_server_susp_domains.yml;False
win_appxdeployment_server_susp_package_locations.yml;False
win_appxdeployment_server_uncommon_package_locations.yml;False
win_appxpackaging_om_sups_appx_signature.yml;False
win_bits_client_new_job_via_bitsadmin.yml;False
win_bits_client_new_job_via_powershell.yml;False
win_bits_client_new_transfer_saving_susp_extensions.yml;False
win_bits_client_new_transfer_via_file_sharing_domains.yml;False
win_bits_client_new_transfer_via_ip_address.yml;False
win_bits_client_new_transfer_via_uncommon_tld.yml;False
win_bits_client_new_trasnfer_susp_local_folder.yml;False
win_capi2_acquire_certificate_private_key.yml;False
win_certificateservicesclient_lifecycle_system_cert_exported.yml;False
win_codeintegrity_attempted_dll_load.yml;False
win_codeintegrity_blocked_protected_process_file.yml;False
win_codeintegrity_enforced_policy_block.yml;False
win_codeintegrity_revoked_driver_blocked.yml;False
win_codeintegrity_revoked_driver_loaded.yml;False
win_codeintegrity_revoked_image_blocked.yml;False
win_codeintegrity_revoked_image_loaded.yml;False
win_codeintegrity_unsigned_driver_loaded.yml;False
win_codeintegrity_unsigned_image_loaded.yml;False
win_codeintegrity_whql_failure.yml;False
win_diagnosis_scripted_load_remote_diagcab.yml;False
win_dns_client_anonymfiles_com.yml;False
win_dns_client_mega_nz.yml;False
win_dns_client_tor_onion.yml;False
win_dns_client_ufile_io.yml;False
win_dns_client__mal_cobaltstrike.yml;False
win_dns_server_failed_dns_zone_transfer.yml;False
win_dns_server_susp_server_level_plugin_dll.yml;False
win_usb_device_plugged.yml;False
win_firewall_as_add_rule.yml;True
win_firewall_as_add_rule_susp_folder.yml;False
win_firewall_as_add_rule_wmiprvse.yml;True
win_firewall_as_delete_all_rules.yml;False
win_firewall_as_delete_rule.yml;False
win_firewall_as_failed_load_gpo.yml;False
win_firewall_as_reset_config.yml;False
win_firewall_as_setting_change.yml;False
win_ldap_recon.yml;True
win_lsa_server_normal_user_admin.yml;False
win_exchange_proxylogon_oabvirtualdir.yml;False
win_exchange_proxyshell_certificate_generation.yml;False
win_exchange_proxyshell_mailbox_export.yml;False
win_exchange_proxyshell_remove_mailbox_export.yml;False
win_exchange_set_oabvirtualdirectory_externalurl.yml;False
win_exchange_transportagent.yml;False
win_exchange_transportagent_failed.yml;False
win_susp_ntlm_auth.yml;False
win_susp_ntlm_brute_force.yml;False
win_susp_ntlm_rdp.yml;False
win_sshd_openssh_server_listening_on_socket.yml;False
win_security_aadhealth_mon_agent_regkey_access.yml;False
win_security_aadhealth_svc_agent_regkey_access.yml;False
win_security_account_backdoor_dcsync_rights.yml;False
win_security_account_discovery.yml;False
win_security_adcs_certificate_template_configuration_vulnerability.yml;False
win_security_adcs_certificate_template_configuration_vulnerability_eku.yml;False
win_security_add_remove_computer.yml;False
win_security_admin_share_access.yml;False
win_security_ad_object_writedac_access.yml;False
win_security_ad_replication_non_machine_account.yml;False
win_security_ad_user_enumeration.yml;False
win_security_alert_active_directory_user_control.yml;False
win_security_alert_ad_user_backdoors.yml;False
win_security_alert_enable_weak_encryption.yml;False
win_security_alert_ruler.yml;False
win_security_atsvc_task.yml;False
win_security_audit_log_cleared.yml;True
win_security_camera_microphone_access.yml;False
win_security_cobaltstrike_service_installs.yml;False
win_security_codeintegrity_check_failure.yml;False
win_security_dce_rpc_smb_spoolss_named_pipe.yml;False
win_security_dcom_iertutil_dll_hijack.yml;False
win_security_dcsync.yml;False
win_security_device_installation_blocked.yml;False
win_security_disable_event_auditing.yml;True
win_security_disable_event_auditing_critical.yml;False
win_security_dot_net_etw_tamper.yml;False
win_security_dpapi_domain_backupkey_extraction.yml;False
win_security_dpapi_domain_masterkey_backup_attempt.yml;False
win_security_external_device.yml;False
win_security_gpo_scheduledtasks.yml;False
win_security_hidden_user_creation.yml;False
win_security_hktl_edr_silencer.yml;False
win_security_hktl_nofilter.yml;False
win_security_hybridconnectionmgr_svc_installation.yml;False
win_security_impacket_psexec.yml;False
win_security_impacket_secretdump.yml;False
win_security_invoke_obfuscation_clip_services_security.yml;False
win_security_invoke_obfuscation_obfuscated_iex_services_security.yml;False
win_security_invoke_obfuscation_stdin_services_security.yml;False
win_security_invoke_obfuscation_var_services_security.yml;False
win_security_invoke_obfuscation_via_compress_services_security.yml;False
win_security_invoke_obfuscation_via_rundll_services_security.yml;False
win_security_invoke_obfuscation_via_stdin_services_security.yml;False
win_security_invoke_obfuscation_via_use_clip_services_security.yml;False
win_security_invoke_obfuscation_via_use_mshta_services_security.yml;False
win_security_invoke_obfuscation_via_use_rundll32_services_security.yml;False
win_security_invoke_obfuscation_via_var_services_security.yml;False
win_security_iso_mount.yml;True
win_security_lm_namedpipe.yml;False
win_security_lsass_access_non_system_account.yml;False
win_security_mal_creddumper.yml;False
win_security_mal_wceaux_dll.yml;False
win_security_metasploit_authentication.yml;False
win_security_metasploit_or_impacket_smb_psexec_service_install.yml;False
win_security_meterpreter_or_cobaltstrike_getsystem_service_install.yml;False
win_security_net_ntlm_downgrade.yml;False
win_security_net_share_obj_susp_desktop_ini.yml;False
win_security_new_or_renamed_user_account_with_dollar_sign.yml;False
win_security_not_allowed_rdp_access.yml;False
win_security_password_policy_enumerated.yml;False
win_security_pcap_drivers.yml;False
win_security_petitpotam_network_share.yml;False
win_security_petitpotam_susp_tgt_request.yml;False
win_security_possible_dc_shadow.yml;False
win_security_powershell_script_installed_as_service.yml;False
win_security_protected_storage_service_access.yml;False
win_security_rdp_reverse_tunnel.yml;False
win_security_register_new_logon_process_by_rubeus.yml;False
win_security_registry_permissions_weakness_check.yml;False
win_security_remote_powershell_session.yml;False
win_security_replay_attack_detected.yml;False
win_security_sam_registry_hive_handle_request.yml;False
win_security_scm_database_handle_failure.yml;False
win_security_scm_database_privileged_operation.yml;False
win_security_service_installation_by_unusal_client.yml;False
win_security_service_install_remote_access_software.yml;False
win_security_smb_file_creation_admin_shares.yml;False
win_security_susp_add_domain_trust.yml;False
win_security_susp_add_sid_history.yml;False
win_security_susp_computer_name.yml;False
win_security_susp_dsrm_password_change.yml;False
win_security_susp_failed_logon_reasons.yml;False
win_security_susp_kerberos_manipulation.yml;False
win_security_susp_ldap_dataexchange.yml;False
win_security_susp_local_anon_logon_created.yml;False
win_security_susp_logon_explicit_credentials.yml;True
win_security_susp_lsass_dump.yml;False
win_security_susp_lsass_dump_generic.yml;False
win_security_susp_net_recon_activity.yml;False
win_security_susp_opened_encrypted_zip.yml;False
win_security_susp_opened_encrypted_zip_filename.yml;False
win_security_susp_opened_encrypted_zip_outlook.yml;False
win_security_susp_outbound_kerberos_connection.yml;True
win_security_susp_possible_shadow_credentials_added.yml;False
win_security_susp_psexec.yml;False
win_security_susp_raccess_sensitive_fext.yml;False
win_security_susp_rc4_kerberos.yml;False
win_security_susp_scheduled_task_creation.yml;False
win_security_susp_scheduled_task_delete_or_disable.yml;False
win_security_susp_scheduled_task_update.yml;False
win_security_susp_sdelete.yml;False
win_security_susp_time_modification.yml;False
win_security_svcctl_remote_service.yml;False
win_security_syskey_registry_access.yml;False
win_security_sysmon_channel_reference_deletion.yml;False
win_security_tap_driver_installation.yml;False
win_security_teams_suspicious_objectaccess.yml;False
win_security_transf_files_with_cred_data_via_network_shares.yml;False
win_security_user_added_to_local_administrators.yml;False
win_security_user_couldnt_call_priv_service_lsaregisterlogonprocess.yml;False
win_security_user_creation.yml;False
win_security_user_driver_loaded.yml;False
win_security_user_logoff.yml;False
win_security_vssaudit_secevent_source_registration.yml;False
win_security_windows_defender_exclusions_registry_modified.yml;False
win_security_windows_defender_exclusions_write_access.yml;False
win_security_windows_defender_exclusions_write_deleted.yml;False
win_security_wmiprvse_wbemcomn_dll_hijack.yml;False
win_security_wmi_persistence.yml;False
win_security_workstation_was_locked.yml;False
win_security_access_token_abuse.yml;False
win_security_admin_rdp_login.yml;False
win_security_diagtrack_eop_default_login_username.yml;False
win_security_member_added_security_enabled_global_group.yml;False
win_security_member_removed_security_enabled_global_group.yml;False
win_security_overpass_the_hash.yml;True
win_security_pass_the_hash_2.yml;True
win_security_rdp_bluekeep_poc_scanner.yml;False
win_security_rdp_localhost_login.yml;False
win_security_scrcons_remote_wmi_scripteventconsumer.yml;False
win_security_security_enabled_global_group_deleted.yml;False
win_security_successful_external_remote_rdp_login.yml;False
win_security_successful_external_remote_smb_login.yml;False
win_security_susp_failed_logon_source.yml;False
win_security_susp_krbrelayup.yml;False
win_security_susp_logon_newcredentials.yml;False
win_security_susp_rottenpotato.yml;False
win_security_susp_wmi_login.yml;False
win_security_wfp_endpoint_agent_blocked.yml;False
win_security_mitigations_defender_load_unsigned_dll.yml;False
win_security_mitigations_unsigned_dll_from_susp_location.yml;False
win_hybridconnectionmgr_svc_running.yml;False
win_shell_core_susp_packages_installed.yml;False
win_smbclient_security_susp_failed_guest_logon.yml;False
win_system_application_sysmon_crash.yml;False
win_system_lsasrv_ntlmv1.yml;False
win_system_adcs_enrollment_request_denied.yml;False
win_system_susp_dhcp_config.yml;False
win_system_susp_dhcp_config_failed.yml;False
win_system_exploit_cve_2021_42287.yml;False
win_system_lpe_indicators_tabtip.yml;False
win_system_eventlog_cleared.yml;True
win_system_susp_eventlog_cleared.yml;False
win_system_kdcsvc_cert_use_no_strong_mapping.yml;False
win_system_kdcsvc_rc4_downgrade.yml;False
win_system_kdcsvc_tgs_no_suitable_encryption_key_found.yml;False
win_system_susp_critical_hive_location_access_bits_cleared.yml;False
win_system_volume_shadow_copy_mount.yml;False
win_system_susp_vuln_cve_2022_21919_or_cve_2021_34484.yml;False
win_system_susp_system_update_error.yml;False
win_system_possible_zerologon_exploitation_using_wellknown_tools.yml;False
win_system_vul_cve_2020_1472.yml;False
win_system_ntfs_vuln_exploit.yml;False
win_system_cobaltstrike_service_installs.yml;False
win_system_defender_disabled.yml;False
win_system_hack_smbexec.yml;False
win_system_invoke_obfuscation_clip_services.yml;False
win_system_invoke_obfuscation_obfuscated_iex_services.yml;False
win_system_invoke_obfuscation_stdin_services.yml;False
win_system_invoke_obfuscation_var_services.yml;False
win_system_invoke_obfuscation_via_compress_services.yml;False
win_system_invoke_obfuscation_via_rundll_services.yml;False
win_system_invoke_obfuscation_via_stdin_services.yml;False
win_system_invoke_obfuscation_via_use_clip_services.yml;False
win_system_invoke_obfuscation_via_use_mshta_services.yml;False
win_system_invoke_obfuscation_via_use_rundll32_services.yml;False
win_system_invoke_obfuscation_via_var_services.yml;False
win_system_krbrelayup_service_installation.yml;False
win_system_mal_creddumper.yml;False
win_system_meterpreter_or_cobaltstrike_getsystem_service_installation.yml;True
win_system_moriya_rootkit.yml;False
win_system_powershell_script_installed_as_service.yml;False
win_system_service_install_anydesk.yml;False
win_system_service_install_csexecsvc.yml;False
win_system_service_install_hacktools.yml;False
win_system_service_install_mesh_agent.yml;False
win_system_service_install_netsupport_manager.yml;False
win_system_service_install_paexec.yml;False
win_system_service_install_pdqdeploy.yml;False
win_system_service_install_pdqdeploy_runner.yml;False
win_system_service_install_pua_proceshacker.yml;False
win_system_service_install_remcom.yml;False
win_system_service_install_remote_access_software.yml;False
win_system_service_install_remote_utilities.yml;False
win_system_service_install_sliver.yml;False
win_system_service_install_sups_unusal_client.yml;False
win_system_service_install_susp.yml;True
win_system_service_install_sysinternals_psexec.yml;True
win_system_service_install_tacticalrmm.yml;False
win_system_service_install_tap_driver.yml;False
win_system_service_install_uncommon.yml;False
win_system_service_terminated_error_generic.yml;False
win_system_service_terminated_error_important.yml;False
win_system_service_terminated_unexpectedly.yml;False
win_system_susp_rtcore64_service_install.yml;False
win_system_susp_service_installation_folder.yml;True
win_system_susp_service_installation_folder_pattern.yml;False
win_system_susp_service_installation_script.yml;False
win_system_rdp_potential_cve_2019_0708.yml;False
win_taskscheduler_execution_from_susp_locations.yml;False
win_taskscheduler_lolbin_execution_via_task_scheduler.yml;False
win_taskscheduler_susp_schtasks_delete.yml;True
win_terminalservices_rdp_ngrok.yml;False
win_defender_antimalware_platform_expired.yml;False
win_defender_asr_lsass_access.yml;False
win_defender_asr_psexec_wmi.yml;False
win_defender_config_change_exclusion_added.yml;False
win_defender_config_change_exploit_guard_tamper.yml;False
win_defender_config_change_sample_submission_consent.yml;False
win_defender_history_delete.yml;False
win_defender_malware_and_pua_scan_disabled.yml;False
win_defender_malware_detected_amsi_source.yml;False
win_defender_real_time_protection_disabled.yml;False
win_defender_real_time_protection_errors.yml;False
win_defender_restored_quarantine_file.yml;False
win_defender_suspicious_features_tampering.yml;False
win_defender_tamper_protection_trigger.yml;False
win_defender_threat.yml;False
win_defender_virus_scan_disabled.yml;False
win_wmi_persistence.yml;True
create_remote_thread_win_hktl_cactustorch.yml;False
create_remote_thread_win_hktl_cobaltstrike.yml;False
create_remote_thread_win_keepass.yml;False
create_remote_thread_win_mstsc_susp_location.yml;False
create_remote_thread_win_powershell_lsass.yml;False
create_remote_thread_win_powershell_susp_targets.yml;False
create_remote_thread_win_susp_password_dumper_lsass.yml;False
create_remote_thread_win_susp_relevant_source_image.yml;False
create_remote_thread_win_susp_uncommon_source_image.yml;True
create_remote_thread_win_susp_uncommon_target_image.yml;True
create_remote_thread_win_ttdinjec.yml;False
create_stream_hash_ads_executable.yml;True
create_stream_hash_creation_internet_file.yml;True
create_stream_hash_file_sharing_domains_download_susp_extension.yml;False
create_stream_hash_file_sharing_domains_download_unusual_extension.yml;False
create_stream_hash_hktl_generic_download.yml;False
create_stream_hash_regedit_export_to_ads.yml;False
create_stream_hash_susp_ip_domains.yml;False
create_stream_hash_winget_susp_package_source.yml;False
create_stream_hash_zip_tld_download.yml;False
dns_query_win_anonymfiles_com.yml;False
dns_query_win_appinstaller.yml;False
dns_query_win_cloudflared_communication.yml;False
dns_query_win_devtunnels_communication.yml;False
dns_query_win_dns_server_discovery_via_ldap_query.yml;False
dns_query_win_hybridconnectionmgr_servicebus.yml;False
dns_query_win_mal_cobaltstrike.yml;False
dns_query_win_mega_nz.yml;False
dns_query_win_onelaunch_update_service.yml;False
dns_query_win_regsvr32_dns_query.yml;True