Data Source: CrowdStrike ProcessRollup2

Description

Logs process-related activities captured by CrowdStrike, including process creation, termination, and metadata such as hashes, parent processes, and command-line arguments.

Details

Property Value
Source crowdstrike
Sourcetype crowdstrike:events:sensor
Separator event_simpleName
Name ▲▼ Technique ▲▼ Type ▲▼
Windows Group Discovery Via Net Local Groups, Domain Groups Hunting
Windows Potato Privilege Escalation Tool Execution Exploitation for Privilege Escalation TTP
Windows InstallUtil URL in Command Line InstallUtil TTP
Windows New Service Security Descriptor Set Via Sc.EXE Hide Artifacts Anomaly
Windows Excel Spawning Microsoft Project Application Distributed Component Object Model Anomaly
Deleting Shadow Copies Inhibit System Recovery TTP
Windows Rasautou DLL Execution Dynamic-link Library Injection, System Binary Proxy Execution TTP
Windows Credentials from Password Stores Deletion Credentials from Password Stores TTP
USN Journal Deletion Indicator Removal TTP
Mshta spawning Rundll32 OR Regsvr32 Process Mshta TTP
Execution of File with Multiple Extensions Rename Legitimate Utilities TTP
MSBuild Suspicious Spawned By Script Process MSBuild TTP
Windows Password Policy Discovery with Net Password Policy Discovery Hunting
Windows WMI Process And Service List Windows Management Instrumentation Anomaly
Reg exe Manipulating Windows Services Registry Keys Services Registry Permissions Weakness TTP
Suspicious Copy on System32 Rename Legitimate Utilities Anomaly
Detect RTLO In Process Right-to-Left Override TTP
Windows MSIExec DLLRegisterServer Msiexec TTP
Windows TeamCity Payload Execution from Temp Directory Command and Scripting Interpreter, Exploit Public-Facing Application, Web Shell TTP
Windows Rundll32 with Non-Standard File Extension Rundll32 Anomaly
Windows Defender ASR or Threat Configuration Tamper Disable or Modify Tools TTP
ICACLS Grant Command File and Directory Permissions Modification Anomaly
Windows Crowdstrike RTR Script Execution PowerShell Anomaly
Windows Chromium Process Launched with Logging Disabled Virtualization/Sandbox Evasion Anomaly
Suspicious Rundll32 StartW Rundll32 TTP
Windows Binary Execution from an Archive Malicious File Anomaly
System User Discovery With Whoami System Owner/User Discovery Hunting
Windows Odbcconf Load Response File Odbcconf TTP
Windows Audit Policy Auditing Option Disabled via Auditpol Disable or Modify Windows Event Log TTP
Execute Javascript With Jscript COM CLSID Visual Basic TTP
Windows IOBit Unlocker Extension DLL Registration via Regsvr32 Regsvr32 TTP
Windows Proxy Execution of .NET Utilities via Scripts System Binary Proxy Execution Anomaly
Suspicious msbuild path Rename Legitimate Utilities, MSBuild TTP
Remote Process Instantiation via WMI and PowerShell Windows Management Instrumentation TTP
Detect Regsvr32 Application Control Bypass Regsvr32 TTP
Windows Entra User Management Via Azure CLI Cloud Accounts, Account Manipulation, Create Account Anomaly
Wscript Or Cscript Suspicious Child Process Process Injection, Parent PID Spoofing, Create or Modify System Process Anomaly
Windows Cisco Secure Endpoint Stop Immunet Service Via Sfc Disable or Modify Tools Anomaly
Rundll32 Control RunDLL Hunt Rundll32 Hunting
Domain Controller Discovery with Wmic Remote System Discovery Hunting
Windows Remote Assistance Spawning Process Process Injection TTP
Wmic Group Discovery Local Groups Anomaly
Windows Steal or Forge Kerberos Tickets Klist Steal or Forge Kerberos Tickets Hunting
Windows Chromium process Launched with Disable Popup Blocking Virtualization/Sandbox Evasion Anomaly
Windows WSUS Spawning Shell Exploit Public-Facing Application, Web Shell TTP
Windows Process With NamedPipe CommandLine Process Injection Anomaly
CMD Echo Pipe - Escalation Windows Command Shell, Windows Service TTP
User Discovery With Env Vars PowerShell System Owner/User Discovery Hunting
Windows Proxy Via Netsh Internal Proxy Anomaly
Suspicious Scheduled Task from Public Directory Scheduled Task Anomaly
Unload Sysmon Filter Driver Disable or Modify Tools TTP
DSQuery Domain Discovery Domain Trust Discovery TTP
Windows Service Stop Attempt Service Stop Hunting
System User Discovery With Query System Owner/User Discovery Hunting
Curl Execution with Percent Encoded URL Obfuscated Files or Information, Ingress Tool Transfer Anomaly
Windows Command and Scripting Interpreter Path Traversal Exec Command and Scripting Interpreter TTP
Detect Rundll32 Inline HTA Execution Mshta TTP
Windows Net System Service Discovery System Service Discovery Hunting
SecretDumps Offline NTDS Dumping Tool NTDS TTP
Impacket Lateral Movement Commandline Parameters SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service TTP
Windows Excessive Service Stop Attempt Service Stop TTP
Windows Sensitive Group Discovery With Net Domain Groups Anomaly
Windows Office Product Spawned Child Process For Download Spearphishing Attachment TTP
GetLocalUser with PowerShell Local Account Hunting
Suspicious microsoft workflow compiler usage Trusted Developer Utilities Proxy Execution TTP
Child Processes of Spoolsv exe Exploitation for Privilege Escalation TTP
Windows System Script Proxy Execution Syncappvpublishingserver System Script Proxy Execution, System Binary Proxy Execution TTP
Remote Process Instantiation via WinRM and Winrs Windows Remote Management TTP
Windows System Network Config Discovery Display DNS System Network Configuration Discovery Anomaly
Windows Process Execution From ProgramData Match Legitimate Resource Name or Location Hunting
Windows Odbcconf Load DLL Odbcconf TTP
Advanced IP or Port Scanner Execution Network Service Discovery, Network Share Discovery Anomaly
Windows Security Account Manager Stopped Service Stop TTP
Windows Scheduled Task with Highest Privileges Scheduled Task TTP
Detect Regasm Spawning a Process Regsvcs/Regasm TTP
Disabling Firewall with Netsh Disable or Modify Tools Anomaly
Windows TOR Client Execution Multi-hop Proxy Anomaly
GetNetTcpconnection with PowerShell System Network Connections Discovery Hunting
Windows Audit Policy Cleared via Auditpol Disable or Modify Windows Event Log TTP
Windows Compatibility Telemetry Suspicious Child Process Scheduled Task, Event Triggered Execution TTP
Windows AutoIt3 Execution Command and Scripting Interpreter TTP
Windows Diskshadow Proxy Execution System Binary Proxy Execution TTP
Windows PowerShell FakeCAPTCHA Clipboard Execution PowerShell, Windows Command Shell, Malicious Link TTP
Windows Office Product Spawned Rundll32 With No DLL Spearphishing Attachment TTP
Domain Group Discovery With Wmic Domain Groups Hunting
Schtasks scheduling job on remote system Scheduled Task TTP
Windows MSIExec Spawn WinDBG Msiexec TTP
Windows Suspicious VMWare Tools Child Process Command and Scripting Interpreter TTP
Windows Powershell RemoteSigned File PowerShell Anomaly
Detect Rare Executables User Execution Anomaly
SLUI Spawning a Process Bypass User Account Control TTP
Services Escalate Exe Abuse Elevation Control Mechanism TTP
Creation of Shadow Copy NTDS TTP
Windows Office Product Spawned Control Spearphishing Attachment TTP
Windows Wmic CPU Discovery System Information Discovery Anomaly
Windows OneDrive Share Mounted via Net Exfiltration to Cloud Storage Anomaly
Windows Registry Entries Exported Via Reg Query Registry Hunting
Windows AppCertDLL Modification Via Command Line AppCert DLLs Anomaly
GetWmiObject User Account with PowerShell Local Account Hunting
PowerShell Get LocalGroup Discovery Local Groups Hunting
Modify ACL permission To Files Or Folder File and Directory Permissions Modification Anomaly
Windows Global Object Access Audit List Cleared Via Auditpol Disable or Modify Windows Event Log TTP
Dump LSASS via procdump LSASS Memory TTP
BITSAdmin Download File Ingress Tool Transfer, BITS Jobs TTP
Windows SSH Proxy Command PowerShell, Ingress Tool Transfer, Protocol Tunneling Anomaly
Windows Rundll32 Apply User Settings Changes Rundll32 Anomaly
Possible Browser Pass View Parameter Credentials from Web Browsers Hunting
Windows System Time Discovery W32tm Delay System Time Discovery Anomaly
Domain Controller Discovery with Nltest Remote System Discovery TTP
Windows PsTools Recon Usage Remote System Discovery, Network Service Discovery, System Information Discovery Anomaly
Windows Service Creation on Remote Endpoint Windows Service TTP
Windows Devtunnels Execution Proxy Anomaly
GetCurrent User with PowerShell System Owner/User Discovery Hunting
Svchost LOLBAS Execution Process Spawn Scheduled Task TTP
Windows COM Hijacking InprocServer32 Modification Component Object Model Hijacking TTP
Windows Chrome Enable Extension Loading via Command-Line Browser Session Hijacking Anomaly
Hiding Files And Directories With Attrib exe Windows Permissions TTP
Windows Command and Scripting Interpreter Hunting Path Traversal Command and Scripting Interpreter Hunting
Windows Audit Policy Restored via Auditpol Disable or Modify Windows Event Log Anomaly
Windows Information Discovery Fsutil System Information Discovery Anomaly
Windows User Disabled Via Net Account Access Removal Anomaly
Detect mshta inline hta execution Mshta TTP
Windows Suspicious React or Next.js Child Process PowerShell, Windows Command Shell, Exploit Public-Facing Application TTP
Excessive number of service control start as disabled Disable or Modify Tools Anomaly
Windows Mimikatz Binary Execution OS Credential Dumping TTP
Windows Audit Policy Excluded Category via Auditpol Disable or Modify Windows Event Log Anomaly
Suspicious Process Executed From Container File Masquerade File Type, Malicious File TTP
Clop Common Exec Parameter User Execution TTP
PowerShell Start-BitsTransfer BITS Jobs TTP
Excessive Usage of NSLOOKUP App Exfiltration Over Alternative Protocol Anomaly
Windows Scheduled Task Created Via XML Scheduled Task Anomaly
Windows Cabinet File Extraction Via Expand Ingress Tool Transfer TTP
Windows Suspicious Child Process Spawned From WebServer Web Shell Anomaly
Windows Potential Cloudflared Tunnel Execution Protocol Tunneling Anomaly
Notepad with no Command Line Arguments Process Injection TTP
Single Letter Process On Endpoint Malicious File TTP
Windows Steal Authentication Certificates Export Certificate Steal or Forge Authentication Certificates Anomaly
Sdelete Application Execution File Deletion, Data Destruction TTP
Powershell Disable Security Monitoring Disable or Modify Tools TTP
Add or Set Windows Defender Exclusion Disable or Modify Tools TTP
NLTest Domain Trust Discovery Domain Trust Discovery TTP
Windows Excessive Usage Of Net App Account Access Removal Anomaly
Windows Odbcconf Hunting Odbcconf Hunting
Network Connection Discovery With Arp System Network Connections Discovery Hunting
Firewall Allowed Program Enable Disable or Modify System Firewall Anomaly
Elevated Group Discovery With Wmic Domain Groups TTP
Windows System User Discovery Via Quser System Owner/User Discovery Hunting
Windows Command Shell DCRat ForkBomb Payload Windows Command Shell TTP
Excessive Attempt To Disable Services Service Stop Anomaly
Windows Shell Process from CrushFTP PowerShell, Windows Command Shell, Exploit Public-Facing Application, Server Software Component TTP
Windows Default Group Policy Object Modified with GPME Group Policy Modification TTP
Detect Renamed WinRAR Archive via Utility Hunting
Get ADUserResultantPasswordPolicy with Powershell Password Policy Discovery TTP
WMIC XSL Execution via URL XSL Script Processing TTP
Windows Disable Windows Event Logging Disable HTTP Logging IIS Components, Disable or Modify Windows Event Log Anomaly
Windows Modify Registry Regedit Silent Reg Import Modify Registry Anomaly
7zip CommandLine To SMB Share Path Archive via Utility Hunting
Windows Process Execution From RDP Share Remote Desktop Protocol, Command and Scripting Interpreter, Ingress Tool Transfer Anomaly
Ping Sleep Batch Command Time Based Checks Anomaly
Malicious PowerShell Process - Encoded Command Obfuscated Files or Information Hunting
Recursive Delete of Directory In Batch CMD File Deletion TTP
Excessive Usage Of Taskkill Disable or Modify Tools Anomaly
Windows Credentials in Registry Reg Query Credentials in Registry Anomaly
Windows Cisco Secure Endpoint Unblock File Via Sfc Disable or Modify Tools Anomaly
Windows Cisco Secure Endpoint Uninstall Immunet Service Via Sfc Disable or Modify Tools Anomaly
Windows Advanced Installer MSIX with AI_STUBS Execution Malicious File, System Binary Proxy Execution, Mark-of-the-Web Bypass TTP
System Info Gathering Using Dxdiag Application Gather Victim Host Information Hunting
Wermgr Process Spawned CMD Or Powershell Process Command and Scripting Interpreter TTP
Windows Suspicious Process File Path Match Legitimate Resource Name or Location, Create or Modify System Process TTP
Windows Curl Upload to Remote Destination Ingress Tool Transfer TTP
Windows Shell or Script Execution From IIS Directory Exploit Public-Facing Application, IIS Components Anomaly
Windows Disable Internet Explorer Addons Browser Extensions Anomaly
Network Connection Discovery With Netstat System Network Connections Discovery Hunting
Detect Regsvcs Spawning a Process Regsvcs/Regasm TTP
Winhlp32 Spawning a Process Process Injection TTP
Windows Local LLM Framework Execution Create or Modify System Process Hunting
Windows Set Custom DNS ServerLevelPlugin Via Dnscmd Hijack Execution Flow Anomaly
Suspicious Regsvr32 Register Suspicious Path Regsvr32 TTP
Windows Credentials from Password Stores Query Credentials from Password Stores Anomaly
Windows UAC Bypass Suspicious Child Process Bypass User Account Control TTP
Detect Path Interception By Creation Of program exe Path Interception by Unquoted Path TTP
Get ADDefaultDomainPasswordPolicy with Powershell Password Policy Discovery Hunting
Windows Execute Arbitrary Commands with MSDT System Binary Proxy Execution TTP
Windows Process Execution in Temp Dir Match Legitimate Resource Name or Location, Create or Modify System Process Anomaly
Windows Remote Create Service Windows Service Anomaly
Windows Guest Account Enabled Via Net.EXE Default Accounts Anomaly
File Download or Read to Pipe Execution Ingress Tool Transfer TTP
Impacket Lateral Movement smbexec CommandLine Parameters SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service TTP
Windows Findstr GPP Discovery Group Policy Preferences TTP
Process Execution via WMI Windows Management Instrumentation TTP
Windows System User Privilege Discovery System Owner/User Discovery Hunting
Windows SubInAcl Execution Windows Permissions Anomaly
Windows Change File Association Command To Notepad Change Default File Association TTP
Rubeus Command Line Parameters Pass the Ticket, Kerberoasting, AS-REP Roasting TTP
Windows Time Based Evasion Time Based Checks TTP
Windows System Binary Proxy Execution Compiled HTML File Decompile Compiled HTML File TTP
Windows Wmic Systeminfo Discovery System Information Discovery Anomaly
Windows Chromium Process with Disabled Extensions Virtualization/Sandbox Evasion Anomaly
Windows System Discovery Using ldap Nslookup System Owner/User Discovery Anomaly
Windows IIS Components Add New Module IIS Components Anomaly
Unusually Long Command Line None Anomaly
Create or delete windows shares using net exe Network Share Connection Removal TTP
Excessive number of taskhost processes Command and Scripting Interpreter Anomaly
Conti Common Exec parameter User Execution TTP
Get-DomainTrust with PowerShell Domain Trust Discovery TTP
Impacket Lateral Movement WMIExec Commandline Parameters SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service TTP
Schtasks used for forcing a reboot Scheduled Task TTP
Windows Steal Authentication Certificates Export PfxCertificate Steal or Forge Authentication Certificates Anomaly
Windows Remote Services Allow Rdp In Firewall Remote Desktop Protocol Anomaly
Windows Cached Domain Credentials Reg Query Cached Domain Credentials Anomaly
Detect Prohibited Applications Spawning cmd exe Windows Command Shell Hunting
Windows Ldifde Directory Object Behavior Domain Groups, Ingress Tool Transfer TTP
Remote Process Instantiation via DCOM and PowerShell Distributed Component Object Model TTP
Detect mshta renamed Mshta Hunting
Windows Service Create Kernel Mode Driver Exploitation for Privilege Escalation, Windows Service TTP
Remote System Discovery with Wmic Remote System Discovery TTP
Remote System Discovery with Dsquery Remote System Discovery Anomaly
Mmc LOLBAS Execution Process Spawn Distributed Component Object Model, MMC TTP
Potential Telegram API Request Via CommandLine Exfiltration Over C2 Channel, Bidirectional Communication Anomaly
Regsvr32 with Known Silent Switch Cmdline Regsvr32 Anomaly
Windows Indirect Command Execution Via pcalua Indirect Command Execution TTP
Disable Schedule Task Disable or Modify Tools Anomaly
GetWmiObject Ds Group with PowerShell Domain Groups Anomaly
RunDLL Loading DLL By Ordinal Rundll32 TTP
Windows Credential Dumping LSASS Memory Createdump LSASS Memory TTP
WinRAR Spawning Shell Application Ingress Tool Transfer TTP
Windows Get-Variable.EXE Execution from WindowsApps Folder Path Interception by Search Order Hijacking Anomaly
Windows Apache Benchmark Binary Command and Scripting Interpreter Anomaly
Windows Registry Entries Restored Via Reg Query Registry Hunting
Windows WinRAR Launched Outside Default Installation Directory Windows Management Instrumentation Anomaly
Windows AdFind Exe Remote System Discovery TTP
Ntdsutil Export NTDS NTDS TTP
Windows Network Connection Discovery Via Net System Network Connections Discovery Hunting
Windows Files and Dirs Access Rights Modification Via Icacls Windows Permissions Anomaly
Schtasks Run Task On Demand Scheduled Task/Job Anomaly
Domain Group Discovery With Dsquery Domain Groups Anomaly
GetDomainController with PowerShell Remote System Discovery Hunting
Windows Service Initiation on Remote Endpoint Windows Service TTP
Domain Account Discovery with Wmic Domain Account TTP
Suspicious Rundll32 no Command Line Arguments Rundll32 TTP
Windows DLL Side-Loading Process Child Of Calc DLL Anomaly
Windows Regsvr32 Renamed Binary Regsvr32 TTP
Detect Renamed 7-Zip Archive via Utility Hunting
Jscript Execution Using Cscript App JavaScript TTP
Windows Gdrive Binary Activity Exfiltration Over Web Service TTP
GetDomainComputer with PowerShell Remote System Discovery TTP
Windows System Reboot CommandLine System Shutdown/Reboot Hunting
Suspicious Rundll32 PluginInit Rundll32 TTP
Windows Sensitive Registry Hive Dump Via CommandLine Security Account Manager TTP
Windows List ENV Variables Via SET Command From Uncommon Parent Process Injection Anomaly
Windows File Download Via CertUtil Ingress Tool Transfer TTP
Windows SQLCMD Execution Windows Command Shell Hunting
Windows Time Based Evasion via Choice Exec Time Based Checks Anomaly
WBAdmin Delete System Backups Inhibit System Recovery TTP
CertUtil With Decode Argument Deobfuscate/Decode Files or Information TTP
Detect HTML Help URL in Command Line Compiled HTML File TTP
Suspicious GPUpdate no Command Line Arguments Process Injection TTP
Windows SpeechRuntime Suspicious Child Process Distributed Component Object Model TTP
Uninstall App Using MsiExec Msiexec TTP
Windows Curl Download to Suspicious Path Ingress Tool Transfer TTP
ServicePrincipalNames Discovery with SetSPN Kerberoasting TTP
Windows Wmic DiskDrive Discovery System Information Discovery Anomaly
Windows Privilege Escalation Attempt Via MSI Rollback Exploitation for Privilege Escalation TTP
Windows Cmdline Tool Execution From Non-Shell Process JavaScript Anomaly
Windows Office Product Spawned Uncommon Process Spearphishing Attachment TTP
System Information Discovery Detection System Information Discovery TTP
Mimikatz PassTheTicket CommandLine Parameters Pass the Ticket TTP
Windows Chromium Browser Launched with Small Window Size Virtualization/Sandbox Evasion TTP
Rundll32 Shimcache Flush Modify Registry TTP
Windows LOLBAS Executed As Renamed File Rename Legitimate Utilities, Rundll32 TTP
DNS Exfiltration Using Nslookup App Exfiltration Over Alternative Protocol TTP
Windows System Shutdown CommandLine System Shutdown/Reboot Anomaly
Windows Attempt To Stop Security Service Disable or Modify Tools TTP
Detect HTML Help Using InfoTech Storage Handlers Compiled HTML File TTP
Excessive distinct processes from Windows Temp Command and Scripting Interpreter Anomaly
Services LOLBAS Execution Process Spawn Windows Service TTP
Windows Binary Proxy Execution Mavinject DLL Injection Mavinject TTP
Windows System LogOff Commandline System Shutdown/Reboot Anomaly
Windows InstallUtil Uninstall Option InstallUtil TTP
Windows EFI Volume Mount Attempt Via Mountvol Malicious File, Pre-OS Boot, Safe Mode Boot Anomaly
Detect PsExec With accepteula Flag SMB/Windows Admin Shares TTP
Windows Indirect Command Execution Via forfiles Indirect Command Execution TTP
Windows MSIExec Unregister DLLRegisterServer Msiexec TTP
Suspicious DLLHost no Command Line Arguments Process Injection TTP
GetAdGroup with PowerShell Domain Groups Hunting
Windows Eventlog Cleared Via Wevtutil Clear Windows Event Logs Anomaly
Windows Mustang Panda USB Tool Execution Automated Exfiltration, Malicious File, DLL TTP
Suspicious microsoft workflow compiler rename Rename Legitimate Utilities, Trusted Developer Utilities Proxy Execution Hunting
Windows Credentials from Password Stores Creation Credentials from Password Stores TTP
Allow Network Discovery In Firewall Cloud Firewall TTP
Windows NorthStar C2 Agent Execution Malicious File, Registry Run Keys / Startup Folder, Stage Capabilities TTP
Potential System Network Configuration Discovery Activity System Network Configuration Discovery Anomaly
Windows DLL Search Order Hijacking with iscsicpl DLL TTP
Windows MSIExec Remote Download Msiexec Anomaly
Check Elevated CMD using whoami System Owner/User Discovery TTP
Windows Security Support Provider Reg Query Security Support Provider Anomaly
System Processes Run From Unexpected Locations Rename Legitimate Utilities Anomaly
Vbscript Execution Using Wscript App Visual Basic TTP
Get DomainUser with PowerShell Domain Account TTP
Windows Indicator Removal Via Rmdir Indicator Removal Anomaly
Disable Logs Using WevtUtil Clear Windows Event Logs TTP
Windows Rundll32 Execution With Log.DLL Hijack Execution Flow Anomaly
Windows Delete or Modify System Firewall Disable or Modify System Firewall Hunting
Detect Remote Access Software Usage Process Remote Access Tools Anomaly
Windows Ngrok Reverse Proxy Usage Proxy, Web Service, Protocol Tunneling Anomaly
Windows Process Injection Wermgr Child Process Process Injection Anomaly
Possible Lateral Movement PowerShell Spawn Distributed Component Object Model, Windows Remote Management, Windows Management Instrumentation, Scheduled Task, PowerShell, MMC, Windows Service Anomaly
Suspicious SearchProtocolHost no Command Line Arguments Process Injection TTP
BCDEdit Failure Recovery Modification Inhibit System Recovery TTP
Runas Execution in CommandLine Token Impersonation/Theft Hunting
Allow File And Printing Sharing In Firewall Cloud Firewall TTP
Suspicious MSBuild Rename Rename Legitimate Utilities, MSBuild Hunting
Windows PowerShell Process Implementing Manual Base64 Decoder Command Obfuscation, PowerShell Anomaly
Suspicious mshta child process Mshta TTP
BITS Job Persistence BITS Jobs TTP
Detect HTML Help Renamed Compiled HTML File Hunting
Certutil exe certificate extraction Steal or Forge Authentication Certificates TTP
Malicious PowerShell Process - Execution Policy Bypass PowerShell Anomaly
Control Loading from World Writable Directory Control Panel TTP
Windows Rundll32 WebDAV Request Exfiltration Over Unencrypted Non-C2 Protocol Hunting
Suspicious Rundll32 dllregisterserver Rundll32 TTP
Detect Renamed RClone Automated Exfiltration Hunting
Windows Schtasks Create Run As System Scheduled Task TTP
Suspicious Reg exe Process Modify Registry Anomaly
Windows Wmic Memory Chip Discovery System Information Discovery Anomaly
Windows Process With NetExec Command Line Parameters Pass the Ticket, Kerberoasting, AS-REP Roasting TTP
Remote WMI Command Attempt Windows Management Instrumentation TTP
Detection of tools built by NirSoft Software Deployment Tools Anomaly
Excessive Usage Of Cacls App File and Directory Permissions Modification Anomaly
Credential Dumping via Copy Command from Shadow Copy NTDS TTP
Rundll32 Control RunDLL World Writable Directory Rundll32 TTP
Windows EventLog Recon Activity Using Log Query Utilities Log Enumeration Anomaly
Detect Renamed PSExec Service Execution Hunting
WinRM Spawning a Process Exploit Public-Facing Application TTP
Windows Archive Collected Data via Rar Archive via Utility Anomaly
Windows Process Injection In Non-Service SearchIndexer Process Injection TTP
GetAdComputer with PowerShell Remote System Discovery Hunting
Windows MSIExec Spawn Discovery Command Msiexec Anomaly
Resize ShadowStorage volume Inhibit System Recovery TTP
Windows Wmic Network Discovery System Information Discovery Anomaly
Windows DNS Gather Network Info DNS Anomaly
Permission Modification using Takeown App File and Directory Permissions Modification Anomaly
Windows Office Product Spawned MSDT Spearphishing Attachment TTP
Suspicious wevtutil Usage Clear Windows Event Logs TTP
Suspicious PlistBuddy Usage Launch Agent TTP
Suspicious mshta spawn Mshta TTP
Windows Identify Protocol Handlers Command and Scripting Interpreter Hunting
Windows New Deny Permission Set On Service SD Via Sc.EXE Hide Artifacts Anomaly
Windows MSC EvilTwin Directory Path Manipulation Match Legitimate Resource Name or Location, Exploitation for Client Execution, System Binary Proxy Execution TTP
Windows Azure Storage Utility Execution Via CLI Exfiltration to Cloud Storage Anomaly
Windows InstallUtil in Non Standard Path Rename Legitimate Utilities, InstallUtil TTP
Windows Execution of Microsoft MSC File In Suspicious Path MMC Anomaly
Revil Common Exec Parameter User Execution TTP
Windows Network Share Interaction Via Net Data from Network Shared Drive, Network Share Discovery Hunting
Detect Regsvcs with No Command Line Arguments Regsvcs/Regasm TTP
XSL Script Execution With WMIC XSL Script Processing TTP
Windows Symlink Evaluation Change via Fsutil Windows Permissions Anomaly
Windows Audit Policy Disabled via Legacy Auditpol Disable or Modify Windows Event Log Anomaly
Windows Ingress Tool Transfer Using Explorer Ingress Tool Transfer Anomaly
Windows BitLocker Suspicious Command Usage Data Encrypted for Impact, Inhibit System Recovery TTP
Windows SymbolicLink-Testing-Tools Utility Execution File and Directory Permissions Modification, NTFS File Attributes TTP
PowerShell - Connect To Internet With Hidden Window PowerShell Hunting
Windows Indirect Command Execution Via Series Of Forfiles Indirect Command Execution Anomaly
Windows Command Obfuscation with Environment Variable Substrings Command Obfuscation Anomaly
Windows WBAdmin File Recovery From Backup Inhibit System Recovery, Stored Data Manipulation Anomaly
FodHelper UAC Bypass Modify Registry, Bypass User Account Control TTP
Windows Spearphishing Attachment Onenote Spawn Mshta Spearphishing Attachment TTP
Remote Desktop Process Running On System Remote Desktop Protocol Hunting
Windows MpCmdRun RemoveDefinitions Execution Disable or Modify Tools Anomaly
Windows Scheduled Task Service Spawned Shell Scheduled Task, Command and Scripting Interpreter TTP
Rundll32 LockWorkStation Rundll32 Anomaly
Anomalous usage of 7zip Archive via Utility Anomaly
Get-ForestTrust with PowerShell Domain Trust Discovery TTP
Hunting 3CXDesktopApp Software Compromise Software Supply Chain Hunting
Windows Certutil Root Certificate Addition Digital Certificates TTP
Scheduled Task Initiation on Remote Endpoint Scheduled Task TTP
Windows NirSoft AdvancedRun Tool TTP
Windows PaperCut NG Spawn Shell Command and Scripting Interpreter, External Remote Services, Exploit Public-Facing Application TTP
Windows Private Keys Discovery Private Keys Anomaly
Windows Phishing PDF File Executes URL Link Spearphishing Attachment Anomaly
Windows WMI Process Call Create Windows Management Instrumentation Hunting
Windows ConHost with Headless Argument Hidden Window, Run Virtual Instance TTP
Shim Database Installation With Suspicious Parameters Application Shimming TTP
Windows Create Local Administrator Account Via Net Local Account Anomaly
Ryuk Wake on LAN Command Windows Command Shell TTP
Windows Masquerading Msdtc Process Masquerading TTP
Windows MOF Event Triggered Execution via WMI Windows Management Instrumentation Event Subscription TTP
Windows Process Commandline Discovery Process Discovery Hunting
Bcdedit Command Back To Normal Mode Boot Inhibit System Recovery TTP
Windows System Network Connections Discovery Netsh System Network Connections Discovery Anomaly
Detect RClone Command-Line Usage Automated Exfiltration TTP
Get DomainPolicy with Powershell Password Policy Discovery TTP
Detect Use of cmd exe to Launch Script Interpreters Windows Command Shell Anomaly
CSC Net On The Fly Compilation Compile After Delivery Hunting
Process Kill Base On File Path Disable or Modify Tools TTP
Get WMIObject Group Discovery Local Groups Hunting
Windows DotNet Binary in Non Standard Path Rename Legitimate Utilities, InstallUtil TTP
Detect Certify Command Line Arguments Ingress Tool Transfer, Steal or Forge Authentication Certificates TTP
Suspicious Curl Network Connection Ingress Tool Transfer TTP
Windows Metasploit Confluence Plugin Execution Exploit Public-Facing Application, Web Shell, Stage Capabilities TTP
Windows File Download Via PowerShell PowerShell, Ingress Tool Transfer Anomaly
Windows PuTTY Suite Utility Execution SSH Anomaly
Windows User Deletion Via Net Account Access Removal Anomaly
Windows Service Execution RemCom Service Execution TTP
Windows Application Whitelisting Bypass Attempt via Rundll32 Rundll32 TTP
CMD Carry Out String Command Parameter Windows Command Shell Hunting
Attacker Tools On Endpoint OS Credential Dumping, Match Legitimate Resource Name or Location, Active Scanning TTP
Domain Account Discovery with Dsquery Domain Account Anomaly
Icacls Deny Command File and Directory Permissions Modification Anomaly
Windows MsiExec HideWindow Rundll32 Execution Msiexec TTP
Windows WMI Reconnaissance Class Query Windows Management Instrumentation Anomaly
Windows PowGoop Beacon Decoding Data Obfuscation, PowerShell TTP
Windows Audit Policy Security Descriptor Tampering via Auditpol Disable or Modify Windows Event Log Anomaly
Suspicious IcedID Rundll32 Cmdline Rundll32 TTP
Windows Parent PID Spoofing with Explorer Parent PID Spoofing TTP
Windows Debugger Tool Execution Masquerading Hunting
First Time Seen Child Process of Zoom Exploitation for Privilege Escalation Anomaly
Scheduled Task Deleted Or Created via CMD Scheduled Task Anomaly
Windows Raccine Scheduled Task Deletion Disable or Modify Tools TTP
Windows File Collection Via Copy Utilities Automated Collection Anomaly
Prevent Automatic Repair Mode using Bcdedit Inhibit System Recovery TTP
Windows SQL Spawning CertUtil Ingress Tool Transfer TTP
Windows Server Software Component GACUtil Install to GAC IIS Components TTP
Script Execution via WMI Windows Management Instrumentation TTP
Windows Set Account Password Policy To Unlimited Via Net Service Stop Anomaly
Windows Masquerading Explorer As Child Process DLL TTP
Windows System Discovery Using Qwinsta System Owner/User Discovery Hunting
Wmic NonInteractive App Uninstallation Disable or Modify Tools Hunting
Windows WinDBG Spawning AutoIt3 Command and Scripting Interpreter TTP
Get ADUser with PowerShell Domain Account Hunting
Headless Browser Usage Virtualization/Sandbox Evasion, Hidden Window Anomaly
Detect Regasm with no Command Line Arguments Regsvcs/Regasm TTP
Windows Protocol Tunneling with Plink SSH, Protocol Tunneling TTP
Network Discovery Using Route Windows App Internet Connection Discovery Hunting
Windows PowerShell Process With Malicious String PowerShell TTP
Detect SharpHound Command-Line Arguments Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Windows PowerShell Script From WindowsApps Directory PowerShell, Malicious File TTP
Windows Netspy Network Scanner Execution Remote System Discovery, Active Scanning Anomaly
Windows Steal Authentication Certificates CertUtil Backup Steal or Forge Authentication Certificates Anomaly
Windows Password Managers Discovery Password Managers Anomaly
Windows Chromium Process Loaded Extension via Command-Line Browser Session Hijacking Anomaly
Clear Unallocated Sector Using Cipher App File Deletion TTP
Windows Chromium Browser No Security Sandbox Process Virtualization/Sandbox Evasion TTP
Windows System Remote Discovery With Query System Owner/User Discovery Hunting
Creation of Shadow Copy with wmic and powershell NTDS TTP
Headless Browser Mockbin or Mocky Request Hidden Window TTP
SLUI RunAs Elevated Bypass User Account Control TTP
Windows Disable or Modify Tools Via Taskkill Disable or Modify Tools Anomaly
Windows MSTSC RDP Commandline Remote Desktop Protocol Anomaly
Suspicious MSBuild Spawn MSBuild TTP
Regsvr32 Silent and Install Param Dll Loading Regsvr32 Anomaly
Windows File Association Modification via Ftype Windows Command Shell Anomaly
Scheduled Task Creation on Remote Endpoint using At At TTP
Windows Bypass UAC via Pkgmgr Tool Bypass User Account Control Anomaly
GetWmiObject Ds Computer with PowerShell Remote System Discovery Anomaly
Esentutl SAM Copy Security Account Manager Hunting
Windows Remote Service Rdpwinst Tool Execution Remote Desktop Protocol TTP
Remote Process Instantiation via WMI Windows Management Instrumentation TTP
Dump LSASS via comsvcs DLL LSASS Memory TTP
Change To Safe Mode With Network Config Inhibit System Recovery TTP
Detect MSHTA Url in Command Line Mshta TTP
Windows DiskCryptor Usage Data Encrypted for Impact Hunting
GetWmiObject DS User with PowerShell Domain Account Anomaly
Windows Service Create with Tscon Windows Service, RDP Hijacking TTP
GetDomainGroup with PowerShell Domain Groups TTP
Remote Process Instantiation via WinRM and PowerShell Windows Remote Management TTP
Windows ESX Admins Group Creation via Net Local Account, Domain Account TTP
Windows DISM Remove Defender Disable or Modify Tools TTP
Fsutil Zeroing File Indicator Removal TTP
Windows Impair Defense Add Xml Applocker Rules Disable or Modify Tools Hunting
Windows User Discovery Via Net Local Account Hunting
Spoolsv Spawning Rundll32 Print Processors TTP
Windows Service Stop By Deletion Service Stop Hunting
Detect AzureHound Command-Line Arguments Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Windows Chromium Browser with Custom User Data Directory Virtualization/Sandbox Evasion Anomaly
Windows NirSoft Utilities Tool Hunting
Detect SharpHound Usage Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Wmiprvse LOLBAS Execution Process Spawn Windows Management Instrumentation TTP
Credential Dumping via Symlink to Shadow Copy NTDS TTP
Windows Modify System Firewall with Notable Process Path Disable or Modify System Firewall TTP
Local Account Discovery With Wmic Local Account Hunting
Windows ScManager Security Descriptor Tampering Via Sc.EXE Service Execution TTP
Verclsid CLSID Execution Verclsid Hunting
Windows SOAPHound Binary Execution Local Groups, Domain Groups, Local Account, Domain Account, Domain Trust Discovery TTP
Windows EDRSilencer Execution Disable or Modify Tools Anomaly
Wsmprovhost LOLBAS Execution Process Spawn Windows Remote Management TTP
Windows Audit Policy Disabled via Auditpol Disable or Modify Windows Event Log Anomaly
Suspicious SQLite3 LSQuarantine Behavior Data Staged TTP
Nishang PowershellTCPOneLine PowerShell TTP
Windows RDP File Execution Remote Desktop Protocol, Spearphishing Attachment TTP
CHCP Command Execution Command and Scripting Interpreter Anomaly
Sc exe Manipulating Windows Services Windows Service TTP
Processes launching netsh Disable or Modify System Firewall Anomaly
Attempt To Add Certificate To Untrusted Store Install Root Certificate Anomaly
Detect HTML Help Spawn Child Process Compiled HTML File TTP

Supported Apps

Event Fields

+ Fields
  <span class="pill kill-chain">AuthenticationId</span>
  
  <span class="pill kill-chain">AuthenticationId_meaning</span>
  
  <span class="pill kill-chain">AuthenticodeHashData</span>
  
  <span class="pill kill-chain">CommandLine</span>
  
  <span class="pill kill-chain">ConfigBuild</span>
  
  <span class="pill kill-chain">ConfigStateHash</span>
  
  <span class="pill kill-chain">EffectiveTransmissionClass</span>
  
  <span class="pill kill-chain">Entitlements</span>
  
  <span class="pill kill-chain">EventOrigin</span>
  
  <span class="pill kill-chain">ImageFileName</span>
  
  <span class="pill kill-chain">ImageSubsystem</span>
  
  <span class="pill kill-chain">ImageSubsystem_meaning</span>
  
  <span class="pill kill-chain">IntegrityLevel</span>
  
  <span class="pill kill-chain">IntegrityLevel_meaning</span>
  
  <span class="pill kill-chain">MD5HashData</span>
  
  <span class="pill kill-chain">ParentAuthenticationId</span>
  
  <span class="pill kill-chain">ParentBaseFileName</span>
  
  <span class="pill kill-chain">ParentProcessId</span>
  
  <span class="pill kill-chain">ProcessCreateFlags</span>
  
  <span class="pill kill-chain">ProcessEndTime</span>
  
  <span class="pill kill-chain">ProcessParameterFlags</span>
  
  <span class="pill kill-chain">ProcessParameterFlags_meaning</span>
  
  <span class="pill kill-chain">ProcessStartTime</span>
  
  <span class="pill kill-chain">ProcessSxsFlags</span>
  
  <span class="pill kill-chain">ProcessSxsFlags_meaning</span>
  
  <span class="pill kill-chain">RawProcessId</span>
  
  <span class="pill kill-chain">SHA1HashData</span>
  
  <span class="pill kill-chain">SHA256HashData</span>
  
  <span class="pill kill-chain">SessionId</span>
  
  <span class="pill kill-chain">SignInfoFlags</span>
  
  <span class="pill kill-chain">SignInfoFlags_meaning</span>
  
  <span class="pill kill-chain">SourceProcessId</span>
  
  <span class="pill kill-chain">SourceThreadId</span>
  
  <span class="pill kill-chain">Tags</span>
  
  <span class="pill kill-chain">TargetProcessId</span>
  
  <span class="pill kill-chain">TokenType</span>
  
  <span class="pill kill-chain">TokenType_meaning</span>
  
  <span class="pill kill-chain">UserSid</span>
  
  <span class="pill kill-chain">WindowFlags</span>
  
  <span class="pill kill-chain">WindowFlags_meaning</span>
  
  <span class="pill kill-chain">action</span>
  
  <span class="pill kill-chain">aid</span>
  
  <span class="pill kill-chain">aid_city</span>
  
  <span class="pill kill-chain">aid_computer_name</span>
  
  <span class="pill kill-chain">aid_continent</span>
  
  <span class="pill kill-chain">aid_country</span>
  
  <span class="pill kill-chain">aid_machine_domain</span>
  
  <span class="pill kill-chain">aid_os_version</span>
  
  <span class="pill kill-chain">aid_ou</span>
  
  <span class="pill kill-chain">aid_site_name</span>
  
  <span class="pill kill-chain">aid_system_product_name</span>
  
  <span class="pill kill-chain">aip</span>
  
  <span class="pill kill-chain">cid</span>
  
  <span class="pill kill-chain">dest</span>
  
  <span class="pill kill-chain">event_ingest_time</span>
  
  <span class="pill kill-chain">event_platform</span>
  
  <span class="pill kill-chain">event_simpleName</span>
  
  <span class="pill kill-chain">eventtype</span>
  
  <span class="pill kill-chain">host_res_aid</span>
  
  <span class="pill kill-chain">id</span>
  
  <span class="pill kill-chain">os</span>
  
  <span class="pill kill-chain">parent_process_exec</span>
  
  <span class="pill kill-chain">parent_process_id</span>
  
  <span class="pill kill-chain">parent_process_name</span>
  
  <span class="pill kill-chain">process</span>
  
  <span class="pill kill-chain">process_exec</span>
  
  <span class="pill kill-chain">process_hash</span>
  
  <span class="pill kill-chain">process_id</span>
  
  <span class="pill kill-chain">process_integrity_level</span>
  
  <span class="pill kill-chain">process_name</span>
  
  <span class="pill kill-chain">process_path</span>
  
  <span class="pill kill-chain">resolve_dest</span>
  
  <span class="pill kill-chain">resolve_process_integrity_level</span>
  
  <span class="pill kill-chain">tag</span>
  
  <span class="pill kill-chain">timestamp</span>
  
  <span class="pill kill-chain">user</span>
  
  <span class="pill kill-chain">user_id</span>
  
  <span class="pill kill-chain">vendor_product</span>
  
</div>

Example Log

1{"LinkName":"C:\\Users\\Administrator\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Windows PowerShell\\Windows PowerShell.lnk","ProcessCreateFlags":"67634196","IntegrityLevel":"12288","ParentProcessId":"5459598860","SourceProcessId":"5459598860","aip":"3.126.231.40","SHA1HashData":"0000000000000000000000000000000000000000","UserSid":"S-1-5-21-586445407-708991241-1829972403-500","event_platform":"Win","TokenType":"1","ProcessEndTime":"","AuthenticodeHashData":"3b98faafc17b47beb9027c437fceeafdf0624a1c","ParentBaseFileName":"explorer.exe","EventOrigin":"1","ImageSubsystem":"3","id":"e2210781-0e8f-47d2-bf6a-56d2c59f38ee","EffectiveTransmissionClass":"3","SessionId":"2","ShowWindowFlags":"1","Tags":"27, 40, 151, 874, 924, 12094627905582, 12094627906234, 211106232533012, 212205744161605, 263882790666253","timestamp":"1713805173418","event_simpleName":"ProcessRollup2","RawProcessId":"5012","ConfigStateHash":"840884426","MD5HashData":"097ce5761c89434367598b34fe32893b","SHA256HashData":"ba4038fd20e474c047be8aad5bfacdb1bfc1ddbe12f803f473b7918d8d819436","ProcessSxsFlags":"64","AuthenticationId":"2669499","ConfigBuild":"1007.3.0018207.1","WindowFlags":"3073","CommandLine":"\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" ","ParentAuthenticationId":"2669499","TargetProcessId":"5642133882","ImageFileName":"\\Device\\HarddiskVolume1\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe","SourceThreadId":"30426051160","Entitlements":"15","name":"ProcessRollup2V19","ProcessStartTime":"1713805173.321","ProcessParameterFlags":"24577","aid":"168a90e125d443beb2a4e2914985084d","SignInfoFlags":"8683538","cid":"124cb22314bf4f519be84bce582e7a6b"}

Required Output Fields

  • action

  • dest

  • original_file_name

  • parent_process

  • parent_process_exec

  • parent_process_guid

  • parent_process_id

  • parent_process_name

  • parent_process_path

  • process

  • process_exec

  • process_guid

  • process_hash

  • process_id

  • process_integrity_level

  • process_name

  • process_path

  • user

  • user_id

  • vendor_product


Source: GitHub | Version: 3