This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
ab60fdcef471fc0360b7c561d7df4ce27d3f2dc6
blue-team-tools
/
rules
/
windows
/
process_creation
T
History
Thomas Patzke
026be7f753
Merge pull request
#1039
from Vasilisa-L/oscd
...
[OSCD] Pcwutl.dll LOLbin
2020-10-14 00:24:41 +02:00
..
sysmon_apt_muddywater_dnstunnel.yml
…
sysmon_hack_wce.yml
…
sysmon_logon_scripts_userinitmprlogonscript_proc.yml
…
sysmon_long_powershell_commandline.yml
…
win_advanced_ip_scanner.yml
…
win_apt_apt29_thinktanks.yml
…
win_apt_babyshark.yml
…
win_apt_bear_activity_gtr19.yml
…
win_apt_bluemashroom.yml
…
win_apt_chafer_mar18.yml
…
win_apt_cloudhopper.yml
…
win_apt_dragonfly.yml
…
win_apt_elise.yml
…
win_apt_emissarypanda_sep19.yml
…
win_apt_empiremonkey.yml
…
win_apt_equationgroup_dll_u_load.yml
…
win_apt_evilnum_jul20.yml
…
win_apt_gallium.yml
…
win_apt_greenbug_may20.yml
…
win_apt_hurricane_panda.yml
…
win_apt_judgement_panda_gtr19.yml
…
win_apt_ke3chang_regadd.yml
…
win_apt_lazarus_session_highjack.yml
…
win_apt_mustangpanda.yml
…
win_apt_slingshot.yml
…
win_apt_sofacy.yml
…
win_apt_ta17_293a_ps.yml
…
win_apt_taidoor.yml
…
win_apt_tropictrooper.yml
…
win_apt_turla_commands.yml
…
win_apt_turla_comrat_may20.yml
…
win_apt_unidentified_nov_18.yml
…
win_apt_winnti_mal_hk_jan20.yml
…
win_apt_winnti_pipemon.yml
…
win_apt_wocao.yml
…
win_apt_zxshell.yml
…
win_attrib_hiding_files.yml
…
win_bootconf_mod.yml
…
win_bypass_squiblytwo.yml
…
win_change_default_file_association.yml
…
win_class_exec_xwizard.yml
…
win_cmdkey_recon.yml
…
win_cmstp_com_object_access.yml
…
win_commandline_path_traversal.yml
…
win_control_panel_item.yml
…
win_copying_sensitive_files_with_credential_data.yml
…
win_crime_fireball.yml
…
win_crime_maze_ransomware.yml
…
win_crime_snatch_ransomware.yml
…
win_data_compressed_with_rar.yml
…
win_dns_exfiltration_tools_execution.yml
…
win_dnscat2_powershell_implementation.yml
…
win_dsquery_domain_trust_discovery.yml
…
win_encoded_frombase64string.yml
…
win_encoded_iex.yml
…
win_etw_modification_cmdline.yml
…
win_etw_trace_evasion.yml
…
win_exfiltration_and_tunneling_tools_execution.yml
…
win_exploit_cve_2015_1641.yml
…
win_exploit_cve_2017_0261.yml
…
win_exploit_cve_2017_8759.yml
…
win_exploit_cve_2017_11882.yml
…
win_exploit_cve_2019_1378.yml
…
win_exploit_cve_2019_1388.yml
…
win_exploit_cve_2020_1048.yml
…
win_exploit_cve_2020_1350.yml
…
win_exploit_cve_2020_10189.yml
…
win_file_permission_modifications.yml
…
win_grabbing_sensitive_hives_via_reg.yml
…
win_hack_bloodhound.yml
…
win_hack_koadic.yml
…
win_hack_rubeus.yml
…
win_hack_secutyxploded.yml
…
win_hh_chm.yml
…
win_hktl_createminidump.yml
…
win_html_help_spawn.yml
…
win_hwp_exploits.yml
…
win_impacket_lateralization.yml
…
win_indirect_cmd_compatibility_assistant.yml
…
win_indirect_cmd.yml
…
win_install_reg_debugger_backdoor.yml
…
win_interactive_at.yml
…
win_invoke_obfuscation_obfuscated_iex_commandline.yml
…
win_invoke_obfuscation_via_stdin.yml
…
win_invoke_obfuscation_via_use_clip.yml
…
win_invoke_obfuscation_via_use_rundll32.yml
…
win_invoke_obfuscation_via_var++.yml
…
win_kernel_and_3rd_party_drivers_exploits_token_stealing.yml
…
win_lethalhta.yml
…
win_local_system_owner_account_discovery.yml
…
win_lsass_dump.yml
…
win_mal_adwind.yml
…
win_malware_dridex.yml
…
win_malware_dtrack.yml
…
win_malware_emotet.yml
…
win_malware_formbook.yml
…
win_malware_notpetya.yml
…
win_malware_qbot.yml
…
win_malware_ryuk.yml
…
win_malware_script_dropper.yml
…
win_malware_trickbot_recon_activity.yml
…
win_malware_wannacry.yml
…
win_mavinject_proc_inj.yml
…
win_meterpreter_or_cobaltstrike_getsystem_service_start.yml
…
win_mimikatz_command_line.yml
…
win_mmc_spawn_shell.yml
…
win_mouse_lock.yml
…
win_mshta_javascript.yml
…
win_mshta_spawn_shell.yml
…
win_multiple_suspicious_cli.yml
…
win_net_enum.yml
…
win_net_user_add.yml
…
win_netsh_allow_port_rdp.yml
…
win_netsh_fw_add_susp_image.yml
…
win_netsh_fw_add.yml
…
win_netsh_packet_capture.yml
…
win_netsh_port_fwd_3389.yml
…
win_netsh_port_fwd.yml
…
win_netsh_wifi_credential_harvesting.yml
…
win_network_sniffing.yml
…
win_new_service_creation.yml
…
win_non_interactive_powershell.yml
…
win_non_priv_reg_or_ps.yml
…
win_office_shell.yml
…
win_office_spawn_exe_from_users_directory.yml
…
win_plugx_susp_exe_locations.yml
…
win_possible_applocker_bypass.yml
…
win_possible_privilege_escalation_using_rotten_potato.yml
…
win_powershell_amsi_bypass.yml
…
win_powershell_audio_capture.yml
…
win_powershell_b64_shellcode.yml
…
win_powershell_bitsjob.yml
…
win_powershell_disable_windef_av.yml
…
win_powershell_dll_execution.yml
…
win_powershell_downgrade_attack.yml
…
win_powershell_download.yml
…
win_powershell_frombase64string.yml
…
win_powershell_suspicious_parameter_variation.yml
…
win_powershell_xor_commandline.yml
…
win_powersploit_empire_schtasks.yml
…
win_proc_wrong_parent.yml
…
win_process_creation_bitsadmin_download.yml
…
win_process_dump_rundll32_comsvcs.yml
…
win_psexesvc_start.yml
…
win_query_registry.yml
…
win_rdp_hijack_shadowing.yml
…
win_redmimicry_winnti_proc.yml
…
win_regini_ads.yml
…
win_regini.yml
…
win_remote_powershell_session_process.yml
…
win_remote_time_discovery.yml
…
win_renamed_binary_highly_relevant.yml
…
win_renamed_binary.yml
…
win_renamed_jusched.yml
…
win_renamed_paexec.yml
…
win_renamed_powershell.yml
…
win_renamed_procdump.yml
…
win_renamed_psexec.yml
…
win_run_powershell_script_from_ads.yml
…
win_sdbinst_shim_persistence.yml
…
win_service_execution.yml
…
win_service_stop.yml
…
win_shadow_copies_access_symlink.yml
…
win_shadow_copies_creation.yml
…
win_shadow_copies_deletion.yml
…
win_shell_spawn_susp_program.yml
…
win_silenttrinity_stage_use.yml
…
win_soundrec_audio_capture.yml
…
win_spn_enum.yml
…
win_susp_adfind.yml
…
win_susp_atbroker.yml
…
win_susp_bcdedit.yml
…
win_susp_bginfo.yml
…
win_susp_calc.yml
…
win_susp_cdb.yml
…
win_susp_certutil_command.yml
…
win_susp_certutil_encode.yml
…
win_susp_cli_escape.yml
…
win_susp_cmd_http_appdata.yml
…
win_susp_codepage_switch.yml
…
win_susp_commands_recon_activity.yml
…
win_susp_compression_params.yml
…
win_susp_comsvcs_procdump.yml
…
win_susp_control_dll_load.yml
…
win_susp_copy_lateral_movement.yml
…
win_susp_copy_system32.yml
…
win_susp_covenant.yml
…
win_susp_crackmapexec_execution.yml
…
win_susp_crackmapexec_powershell_obfuscation.yml
…
win_susp_csc_folder.yml
…
win_susp_csc.yml
…
win_susp_curl_download.yml
…
win_susp_curl_fileupload.yml
…
win_susp_curl_start_combo.yml
…
win_susp_dctask64_proc_inject.yml
…
win_susp_desktopimgdownldr.yml
…
win_susp_devtoolslauncher.yml
…
win_susp_direct_asep_reg_keys_modification.yml
…
win_susp_disable_ie_features.yml
…
win_susp_ditsnap.yml
…
win_susp_dnx.yml
…
win_susp_double_extension.yml
…
win_susp_dxcap.yml
…
win_susp_eventlog_clear.yml
…
win_susp_exec_folder.yml
…
win_susp_execution_path_webserver.yml
…
win_susp_execution_path.yml
…
win_susp_explorer_break_proctree.yml
…
win_susp_explorer.yml
…
win_susp_file_characteristics.yml
…
win_susp_findstr_lnk.yml
…
win_susp_findstr.yml
…
win_susp_finger.yml
…
win_susp_firewall_disable.yml
…
win_susp_fsutil_usage.yml
…
win_susp_gup.yml
…
win_susp_iss_module_install.yml
…
win_susp_mounted_share_deletion.yml
…
win_susp_mpcmdrun_download.yml
…
win_susp_msiexec_cwd.yml
…
win_susp_msiexec_web_install.yml
…
win_susp_msoffice.yml
…
win_susp_net_execution.yml
…
win_susp_netsh_dll_persistence.yml
…
win_susp_ntdsutil.yml
…
win_susp_odbcconf.yml
…
win_susp_openwith.yml
…
win_susp_outlook_temp.yml
…
win_susp_outlook.yml
…
win_susp_pcwutl.yml
…
win_susp_ping_hex_ip.yml
…
win_susp_powershell_empire_launch.yml
…
win_susp_powershell_empire_uac_bypass.yml
…
win_susp_powershell_enc_cmd.yml
…
win_susp_powershell_encoded_param.yml
…
win_susp_powershell_hidden_b64_cmd.yml
…
win_susp_powershell_parent_combo.yml
…
win_susp_powershell_parent_process.yml
…
win_susp_print.yml
…
win_susp_procdump.yml
…
win_susp_prog_location_process_starts.yml
…
win_susp_ps_appdata.yml
…
win_susp_ps_downloadfile.yml
…
win_susp_psr_capture_screenshots.yml
…
win_susp_rar_flags.yml
…
win_susp_rasdial_activity.yml
…
win_susp_recon_activity.yml
…
win_susp_regsvr32_anomalies.yml
…
win_susp_regsvr32_flags_anomaly.yml
…
win_susp_renamed_dctask64.yml
…
win_susp_renamed_debugview.yml
…
win_susp_run_locations.yml
…
win_susp_rundll32_activity.yml
…
win_susp_rundll32_by_ordinal.yml
…
win_susp_rundll32_setupapi_installhinfsection.yml
…
win_susp_schtask_creation.yml
…
win_susp_script_execution.yml
…
win_susp_service_path_modification.yml
…
win_susp_sqldumper_activity.yml
…
win_susp_squirrel_lolbin.yml
…
win_susp_svchost_no_cli.yml
…
win_susp_svchost.yml
…
win_susp_sysprep_appdata.yml
…
win_susp_sysvol_access.yml
…
win_susp_taskmgr_localsystem.yml
…
win_susp_taskmgr_parent.yml
…
win_susp_tscon_localsystem.yml
…
win_susp_tscon_rdp_redirect.yml
…
win_susp_use_of_csharp_console.yml
…
win_susp_userinit_child.yml
…
win_susp_whoami.yml
…
win_susp_winrm_AWL_bypass.yml
…
win_susp_winrm_execution.yml
…
win_susp_wmi_execution.yml
…
win_susp_wsl_lolbin.yml
…
win_syncappvpublishingserver_exe.yml
…
win_sysmon_driver_unload.yml
…
win_system_exe_anomaly.yml
…
win_tap_installer_execution.yml
…
win_task_folder_evasion.yml
…
win_termserv_proc_spawn.yml
…
win_trust_discovery.yml
…
win_uac_cmstp.yml
…
win_uac_fodhelper.yml
…
win_uac_wsreset.yml
…
win_using_sc_to_change_sevice_image_path_by_non_admin.yml
…
win_using_settingsynchost_as_lolbin.yml
…
win_visual_basic_compiler.yml
…
win_vul_java_remote_debugging.yml
…
win_webshell_detection.yml
…
win_webshell_recon_detection.yml
…
win_webshell_spawn.yml
…
win_whoami_as_system.yml
…
win_win10_sched_task_0day.yml
…
win_wmi_backdoor_exchange_transport_agent.yml
…
win_wmi_persistence_script_event_consumer.yml
…
win_wmi_spwns_powershell.yml
…
win_wmiprvse_spawning_process.yml
…
win_workflow_compiler.yml
…
win_wsreset_uac_bypass.yml
…
win_xsl_script_processing.yml
…