Discovery Detections

Name Data Source Technique Type Analytic Story Date
Windows Group Discovery Via Net Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 T1069.002 Hunting Windows Discovery Techniques, Prestige Ransomware, Graceful Wipe Out Attack, Medusa Ransomware, IcedID, Rhysida Ransomware, Volt Typhoon, Active Directory Discovery, Azorult, Cleo File Transfer Software, Microsoft WSUS CVE-2025-59287, Windows Post-Exploitation, SolarWinds WHD RCE Post Exploitation 2026-05-13
Linux Root Execution of id Sysmon for Linux EventID 1 T1033 Anomaly Linux Post-Exploitation, Linux Persistence Techniques, Linux Privilege Escalation 2026-07-08
Windows Password Policy Discovery with Net Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1201 Hunting Active Directory Discovery 2026-05-13
Windows Administrative Shares Accessed On Multiple Hosts Windows Event Log Security 5140, Windows Event Log Security 5145 T1135 TTP Active Directory Lateral Movement, Active Directory Privilege Escalation 2026-05-13
Windows AD Privileged Object Access Activity Windows Event Log Security 4662 T1087.002 TTP Active Directory Discovery, BlackSuit Ransomware 2026-05-13
Windows Chromium Process Launched with Logging Disabled Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497 Anomaly Browser Hijacking 2026-05-13
GetWmiObject Ds Group with PowerShell Script Block Powershell Script Block Logging 4104 T1069.002 TTP Active Directory Discovery 2026-05-13
System User Discovery With Whoami Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting Winter Vivern, PHP-CGI RCE Attack on Japanese Organizations, Lotus Blossom Chrysalis Backdoor, Rhysida Ransomware, CISA AA23-347A, Active Directory Discovery, Qakbot, LAMEHUG 2026-05-13
Windows Large Number of Computer Service Tickets Requested Windows Event Log Security 4769 T1078 T1135 Anomaly Active Directory Lateral Movement, Active Directory Privilege Escalation 2026-07-05
Windows Hosts File Access Windows Event Log Security 4663 T1012 Anomaly BlankGrabber Stealer, Gh0st RAT 2026-05-13
Domain Controller Discovery with Wmic Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 Hunting Active Directory Discovery 2026-05-13
Windows Domain Account Discovery Via Get-NetComputer Powershell Script Block Logging 4104 T1087.002 Anomaly CISA AA23-347A 2026-05-13
Wmic Group Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 Anomaly Active Directory Discovery, LAMEHUG 2026-05-13
Windows Chromium process Launched with Disable Popup Blocking Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497 Anomaly Browser Hijacking 2026-05-13
User Discovery With Env Vars PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting Active Directory Discovery 2026-05-13
Elevated Group Discovery with PowerView Powershell Script Block Logging 4104 T1069.002 Hunting Active Directory Discovery 2026-05-13
DSQuery Domain Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1482 TTP Domain Trust Discovery, Active Directory Discovery, Compromised Windows Host 2026-05-13
System User Discovery With Query Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting Active Directory Discovery, Medusa Ransomware 2026-05-13
Windows Net System Service Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1007 Hunting LAMEHUG, Gh0st RAT 2026-05-13
Windows Azure PowerShell Module Installation Via PowerShell Script Powershell Script Block Logging 4104 T1021.007 T1069.003 T1078 T1098 T1136.003 Anomaly Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Azure Active Directory Account Takeover 2026-05-13
GetWmiObject DS User with PowerShell Script Block Powershell Script Block Logging 4104 T1087.002 TTP Active Directory Discovery 2026-05-13
Windows Sensitive Group Discovery With Net Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 Anomaly BlackSuit Ransomware, IcedID, Rhysida Ransomware, Volt Typhoon, Active Directory Discovery, Microsoft WSUS CVE-2025-59287 2026-05-13
GetLocalUser with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.001 Hunting Active Directory Discovery 2026-05-13
MacOS Network Share Discovery Osquery Results T1135 Anomaly MacOS Post-Exploitation 2026-05-13
Windows System Network Config Discovery Display DNS Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1016 Anomaly Prestige Ransomware, Windows Post-Exploitation, Water Gamayun, Medusa Ransomware 2026-05-13
Get ADDefaultDomainPasswordPolicy with Powershell Script Block Powershell Script Block Logging 4104 T1201 Hunting Active Directory Discovery 2026-05-13
Advanced IP or Port Scanner Execution Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1046 T1135 Anomaly Windows Defense Evasion Tactics 2026-05-13
GetNetTcpconnection with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1049 Hunting Active Directory Discovery 2026-05-13
Domain Group Discovery With Wmic Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 Hunting Active Directory Discovery 2026-05-13
Windows Wmic CPU Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1082 Anomaly LAMEHUG 2026-05-13
Windows Registry Entries Exported Via Reg Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1012 Hunting CISA AA23-347A, Windows Post-Exploitation, Prestige Ransomware 2026-05-13
Windows Non Discord App Access Discord LevelDB Windows Event Log Security 4663 T1012 Anomaly Phantom Stealer, Snake Keylogger, BlankGrabber Stealer, StealC Stealer, PXA Stealer 2026-06-25
GetWmiObject User Account with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.001 Hunting Active Directory Discovery, Water Gamayun, Winter Vivern 2026-05-13
PowerShell Get LocalGroup Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 Hunting Active Directory Discovery 2026-05-13
GetCurrent User with PowerShell Script Block Powershell Script Block Logging 4104 T1033 Hunting Active Directory Discovery 2026-05-13
Windows Account Discovery With NetUser PreauthNotRequire Powershell Script Block Logging 4104 T1087 Hunting CISA AA23-347A 2026-05-13
Detect SharpHound File Modifications Sysmon EventID 11 T1069.001 T1069.002 T1087.001 T1087.002 T1482 TTP Windows Discovery Techniques, Ransomware, BlackSuit Ransomware 2026-05-13
Network Traffic to Active Directory Web Services Protocol Sysmon EventID 3 T1069.001 T1069.002 T1087.001 T1087.002 T1482 Hunting Windows Discovery Techniques 2026-05-13
Windows System Time Discovery W32tm Delay Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1124 Anomaly DarkCrystal RAT 2026-05-13
Domain Controller Discovery with Nltest Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 TTP Medusa Ransomware, BlackSuit Ransomware, Rhysida Ransomware, CISA AA23-347A, Active Directory Discovery, NetSupport RMM Tool Abuse, Starland RAT Campaign 2026-07-20
Cisco NVM - Suspicious Network Connection to IP Lookup Service API Cisco Network Visibility Module Flow Data T1016 T1590.005 Anomaly Castle RAT, Cisco Network Visibility Module Analytics, BlankGrabber Stealer 2026-07-14
Windows PsTools Recon Usage Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 T1046 T1082 Anomaly Compromised Windows Host 2026-05-13
GetCurrent User with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting Active Directory Discovery 2026-05-13
Powershell Get LocalGroup Discovery with Script Block Logging Powershell Script Block Logging 4104 T1069.001 Hunting Active Directory Discovery 2026-05-13
Windows Account Discovery for Sam Account Name Powershell Script Block Logging 4104 T1087 Anomaly CISA AA23-347A 2026-05-13
Windows Information Discovery Fsutil Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1082 Anomaly Prestige Ransomware, Windows Post-Exploitation 2026-05-13
Windows Query Registry Browser List Application Windows Event Log Security 4663 T1012 Anomaly RedLine Stealer, SnappyBee, China-Nexus Threat Activity, Salt Typhoon 2026-05-13
Linux Auditd Whoami User Discovery Linux Auditd Syscall T1033 Anomaly Linux Living Off The Land, Linux Persistence Techniques, Linux Privilege Escalation, QuietVault, Compromised Linux Host 2026-05-13
Enumerate Users Local Group Using Telegram Windows Event Log Security 4798 T1087 TTP Water Gamayun, Compromised Windows Host, XMRig 2026-05-13
AdsiSearcher Account Discovery Powershell Script Block Logging 4104 T1087.002 TTP Scattered Lapsus$ Hunters, Industroyer2, CISA AA23-347A, Active Directory Discovery, Data Destruction 2026-05-13
Network Share Discovery Via Dir Command Windows Event Log Security 5140 T1135 Hunting IcedID 2026-08-05
NLTest Domain Trust Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1482 TTP Storm-0501 Ransomware, Domain Trust Discovery, Medusa Ransomware, IcedID, Rhysida Ransomware, Active Directory Discovery, Qakbot, Ryuk Ransomware, Cleo File Transfer Software 2026-05-13
Linux Auditd Kernel Module Enumeration Linux Auditd Syscall T1014 T1082 Anomaly Linux Rootkit, Compromised Linux Host, XorDDos 2026-05-13
Network Connection Discovery With Arp Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1049 Hunting Prestige Ransomware, IcedID, Volt Typhoon, Active Directory Discovery, Qakbot, Interlock Ransomware, Windows Post-Exploitation 2026-05-13
Elevated Group Discovery With Wmic Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 TTP Active Directory Discovery 2026-05-13
Windows System User Discovery Via Quser Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting Prestige Ransomware, Crypto Stealer, Windows Post-Exploitation 2026-05-13
Get ADUserResultantPasswordPolicy with Powershell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1201 TTP CISA AA23-347A, Active Directory Discovery 2026-05-13
Windows Credentials from Password Stores Chrome Extension Access Windows Event Log Security 4663 T1012 Anomaly Amadey, Meduza Stealer, Malicious Inno Setup Loader, RedLine Stealer, Phantom Stealer, MoonPeak, BlankGrabber Stealer, Braodo Stealer, CISA AA23-347A, DarkGate Malware, StealC Stealer, Phemedrone Stealer, 0bj3ctivity Stealer 2026-06-25
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script Powershell Script Block Logging 4104 T1071.001 T1078 T1212 T1482 TTP Azure Active Directory Privilege Escalation, Azure Active Directory Persistence, Azure Active Directory Account Takeover 2026-05-13
Ping Sleep Batch Command Sysmon EventID 1, CrowdStrike ProcessRollup2 T1497.003 Anomaly Meduza Stealer, Warzone RAT, Quasar RAT, BlackByte Ransomware, WhisperGate, Data Destruction, Void Manticore, Gh0st RAT 2026-05-13
Web Servers Executing Suspicious Processes Sysmon EventID 1 T1082 TTP Apache Struts Vulnerability 2026-05-13
Network Connection Discovery With Netstat Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1049 Hunting Prestige Ransomware, PlugX, Medusa Ransomware, CISA AA23-347A, Volt Typhoon, Active Directory Discovery, Qakbot, CISA AA22-277A, Windows Post-Exploitation 2026-05-13
Get DomainPolicy with Powershell Script Block Powershell Script Block Logging 4104 T1201 TTP Active Directory Discovery 2026-05-13
Get-DomainTrust with PowerShell Script Block Powershell Script Block Logging 4104 T1482 TTP Active Directory Discovery 2026-05-13
Windows Get-AdComputer Unconstrained Delegation Discovery Powershell Script Block Logging 4104 T1018 TTP Active Directory Kerberos Attacks, Medusa Ransomware 2026-05-13
Get ADUser with PowerShell Script Block Powershell Script Block Logging 4104 T1087.002 Hunting CISA AA23-347A, Active Directory Discovery 2026-05-13
Get ADDefaultDomainPasswordPolicy with Powershell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1201 Hunting Active Directory Discovery 2026-05-13
Linux Auditd Database File And Directory Discovery Linux Auditd Execve T1083 Anomaly Compromised Linux Host, Linux Living Off The Land, Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Windows PowerView AD Access Control List Enumeration Powershell Script Block Logging 4104 T1069 T1078.002 TTP Rhysida Ransomware, Active Directory Discovery, Active Directory Privilege Escalation 2026-05-13
Windows System User Privilege Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting CISA AA23-347A 2026-05-13
Windows File Share Discovery With Powerview Powershell Script Block Logging 4104 T1135 TTP Active Directory Discovery, Active Directory Privilege Escalation 2026-05-13
Windows Linked Policies In ADSI Discovery Powershell Script Block Logging 4104 T1087.002 Anomaly Active Directory Discovery, Data Destruction, Industroyer2 2026-05-13
Windows Time Based Evasion Sysmon EventID 1, CrowdStrike ProcessRollup2 T1497.003 TTP NjRAT, BlankGrabber Stealer 2026-05-13
Get-ForestTrust with PowerShell Script Block Powershell Script Block Logging 4104 T1059.001 T1482 TTP Active Directory Discovery 2026-05-13
Windows Wmic Systeminfo Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1082 Anomaly LAMEHUG, Lotus Blossom Chrysalis Backdoor, BlankGrabber Stealer 2026-05-13
Windows Chromium Process with Disabled Extensions Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497 Anomaly Browser Hijacking 2026-05-13
Windows System Discovery Using ldap Nslookup Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Anomaly Qakbot 2026-05-13
Get-DomainTrust with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1482 TTP Active Directory Discovery 2026-05-13
Windows Find Domain Organizational Units with GetDomainOU Powershell Script Block Logging 4104 T1087.002 TTP Active Directory Discovery 2026-05-13
Windows Find Interesting ACL with FindInterestingDomainAcl Powershell Script Block Logging 4104 T1087.002 TTP Active Directory Discovery 2026-05-13
Windows Ldifde Directory Object Behavior Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 T1105 TTP Volt Typhoon 2026-05-13
Remote System Discovery with Adsisearcher Powershell Script Block Logging 4104 T1018 TTP Active Directory Discovery 2026-05-13
Remote System Discovery with Wmic Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 TTP Active Directory Discovery 2026-05-13
Remote System Discovery with Dsquery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 Anomaly Active Directory Discovery, LAMEHUG 2026-05-13
GetWmiObject Ds Group with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 Anomaly Active Directory Discovery 2026-05-13
Windows Query Registry UnInstall Program List Windows Event Log Security 4663 T1012 Anomaly Meduza Stealer, RedLine Stealer, StealC Stealer 2026-05-13
Windows Registry Entries Restored Via Reg Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1012 Hunting Prestige Ransomware, Windows Post-Exploitation 2026-05-13
Windows AdFind Exe Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 TTP NOBELIUM Group, Graceful Wipe Out Attack, BlackSuit Ransomware, IcedID, Domain Trust Discovery 2026-05-13
Windows Get Local Admin with FindLocalAdminAccess Powershell Script Block Logging 4104 T1087.002 TTP Active Directory Discovery 2026-05-13
Windows Network Connection Discovery Via Net Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1049 Hunting Prestige Ransomware, Active Directory Discovery, Windows Post-Exploitation, Azorult 2026-05-13
Domain Group Discovery With Dsquery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 Anomaly Active Directory Discovery, LAMEHUG 2026-05-13
GetDomainController with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 Hunting Active Directory Discovery 2026-05-13
Domain Account Discovery with Wmic Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.002 TTP Active Directory Discovery, Interlock Ransomware 2026-05-13
Domain Group Discovery with Adsisearcher Powershell Script Block Logging 4104 T1069.002 TTP Scattered Lapsus$ Hunters, Active Directory Discovery 2026-05-13
User Discovery With Env Vars PowerShell Script Block Powershell Script Block Logging 4104 T1033 Hunting Active Directory Discovery 2026-05-13
GetDomainComputer with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 TTP Active Directory Discovery 2026-05-13
Windows Special Privileged Logon On Multiple Hosts Windows Event Log Security 4672 T1021.002 T1087 T1135 TTP Active Directory Lateral Movement, Compromised Windows Host, Active Directory Privilege Escalation 2026-05-13
Windows Time Based Evasion via Choice Exec Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497.003 Anomaly 0bj3ctivity Stealer, Snake Keylogger, VIP Keylogger 2026-05-13
Linux System Network Discovery Sysmon for Linux EventID 1, Osquery Results T1016 Anomaly VoidLink Cloud-Native Linux Malware, Network Discovery, Data Destruction, Industroyer2 2026-05-13
Windows Wmic DiskDrive Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1082 Anomaly LAMEHUG 2026-05-13
Windows PowerView Constrained Delegation Discovery Powershell Script Block Logging 4104 T1018 TTP Rhysida Ransomware, CISA AA23-347A, Active Directory Kerberos Attacks 2026-05-13
System Information Discovery Detection Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1082 TTP Windows Discovery Techniques, Medusa Ransomware, BlackSuit Ransomware, Gozi Malware, Lotus Blossom Chrysalis Backdoor, BlankGrabber Stealer, NetSupport RMM Tool Abuse, Interlock Ransomware, Cleo File Transfer Software, LAMEHUG, SolarWinds WHD RCE Post Exploitation 2026-05-13
GetDomainGroup with PowerShell Script Block Powershell Script Block Logging 4104 T1069.002 TTP Active Directory Discovery 2026-05-13
Windows PowerShell Invoke-RestMethod IP Information Collection Powershell Script Block Logging 4104 T1016 T1059.001 T1082 Anomaly Water Gamayun 2026-05-13
Windows Chromium Browser Launched with Small Window Size Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497 TTP Browser Hijacking 2026-05-13
Get DomainUser with PowerShell Script Block Powershell Script Block Logging 4104 T1087.002 TTP CISA AA23-347A, Active Directory Discovery 2026-05-13
Linux Auditd System Network Configuration Discovery Linux Auditd Syscall T1016 Anomaly Compromised Linux Host, Linux Living Off The Land, Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
GetAdGroup with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 Hunting Active Directory Discovery 2026-05-13
GetNetTcpconnection with PowerShell Script Block Powershell Script Block Logging 4104 T1049 Hunting Active Directory Discovery 2026-05-13
Linux Auditd Virtual Disk File And Directory Discovery Linux Auditd Execve T1083 Anomaly Compromised Linux Host, Linux Living Off The Land, Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Potential System Network Configuration Discovery Activity Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1016 Anomaly Unusual Processes 2026-05-13
Check Elevated CMD using whoami Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 TTP FIN7 2026-05-13
Get DomainUser with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.002 TTP CISA AA23-347A, Active Directory Discovery 2026-05-13
Get ADUserResultantPasswordPolicy with Powershell Script Block Powershell Script Block Logging 4104 T1201 TTP CISA AA23-347A, Active Directory Discovery 2026-05-13
Windows Network Sniffing Tool Executed Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1040 Anomaly Windows Discovery Techniques, Network Discovery, Data Exfiltration, Credential Dumping, Suspicious Command-Line Executions 2026-07-30
Linux Auditd File And Directory Discovery Linux Auditd Execve T1083 Anomaly Compromised Linux Host, Linux Living Off The Land, Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
GetAdGroup with PowerShell Script Block Powershell Script Block Logging 4104 T1069.002 Hunting Scattered Lapsus$ Hunters, Active Directory Discovery 2026-05-13
GetDomainController with PowerShell Script Block Powershell Script Block Logging 4104 T1018 TTP Active Directory Discovery 2026-05-13
Windows Wmic Memory Chip Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1082 Anomaly LAMEHUG 2026-05-13
Windows EventLog Recon Activity Using Log Query Utilities Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1654 Anomaly Windows Discovery Techniques, BlankGrabber Stealer 2026-05-13
GetAdComputer with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 Hunting Active Directory Discovery, Medusa Ransomware 2026-05-13
Windows Wmic Network Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1082 Anomaly LAMEHUG 2026-05-13
Get WMIObject Group Discovery with Script Block Logging Powershell Script Block Logging 4104 T1069.001 Hunting Active Directory Discovery 2026-05-13
Windows Admin Permission Discovery Sysmon EventID 11 T1069.001 Anomaly NjRAT 2026-05-13
Windows Post Exploitation Risk Behavior T1003 T1012 T1016 T1049 T1069 T1082 T1115 T1552 Correlation Windows Post-Exploitation 2026-05-13
Windows Network Share Interaction Via Net Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1039 T1135 Hunting Active Directory Discovery, Network Discovery, Active Directory Privilege Escalation 2026-05-13
GetLocalUser with PowerShell Script Block Powershell Script Block Logging 4104 T1059.001 T1087.001 Hunting Active Directory Discovery, Malicious PowerShell 2026-05-13
Windows Root Domain linked policies Discovery Powershell Script Block Logging 4104 T1087.002 Anomaly Active Directory Discovery, Data Destruction, Industroyer2 2026-05-13
Get-ForestTrust with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1482 TTP Active Directory Discovery 2026-05-13
GetAdComputer with PowerShell Script Block Powershell Script Block Logging 4104 T1018 Hunting Gozi Malware, CISA AA22-320A, Active Directory Discovery, Medusa Ransomware 2026-05-13
MacOS List Firewall Rules Osquery Results T1016 Anomaly Network Discovery 2026-05-13
Detect AzureHound File Modifications Sysmon EventID 11 T1069.001 T1069.002 T1087.001 T1087.002 T1482 TTP Windows Discovery Techniques 2026-05-13
Windows Process Commandline Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1057 Hunting CISA AA23-347A 2026-05-13
GetWmiObject Ds Computer with PowerShell Script Block Powershell Script Block Logging 4104 T1018 TTP Active Directory Discovery 2026-05-13
Windows AD Abnormal Object Access Activity Windows Event Log Security 4662 T1087.002 Anomaly Active Directory Discovery, BlackSuit Ransomware 2026-05-13
Windows System Network Connections Discovery Netsh Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1049 Anomaly Prestige Ransomware, Phantom Stealer, Snake Keylogger, BlankGrabber Stealer, VIP Keylogger, Windows Post-Exploitation 2026-06-25
Get DomainPolicy with Powershell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1201 TTP Active Directory Discovery 2026-05-13
Get WMIObject Group Discovery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 Hunting Active Directory Discovery 2026-05-13
Windows Credentials from Password Stores Chrome LocalState Access Windows Event Log Security 4663 T1012 Anomaly Amadey, Phantom Stealer, Salt Typhoon, Quasar RAT, Salat Stealer, VIP Keylogger, Meduza Stealer, Malicious Inno Setup Loader, Warzone RAT, MoonPeak, BlankGrabber Stealer, DarkGate Malware, StealC Stealer, SnappyBee, Earth Alux, Phemedrone Stealer, PXA Stealer, Lokibot, Scattered Lapsus$ Hunters, Braodo Stealer, 0bj3ctivity Stealer, RedLine Stealer, Snake Keylogger, China-Nexus Threat Activity, NjRAT 2026-06-25
Windows Credentials from Password Stores Chrome Login Data Access Windows Event Log Security 4663 T1012 Anomaly Amadey, Phantom Stealer, Salt Typhoon, Quasar RAT, Salat Stealer, VIP Keylogger, Meduza Stealer, Malicious Inno Setup Loader, Warzone RAT, MoonPeak, BlankGrabber Stealer, DarkGate Malware, StealC Stealer, SnappyBee, Earth Alux, Phemedrone Stealer, PXA Stealer, Lokibot, Scattered Lapsus$ Hunters, Braodo Stealer, 0bj3ctivity Stealer, RedLine Stealer, Snake Keylogger, China-Nexus Threat Activity, NjRAT 2026-07-08
Domain Account Discovery with Dsquery Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.002 Anomaly Active Directory Discovery, LAMEHUG 2026-05-13
Windows Software Discovery Via PowerShell Powershell Script Block Logging 4104 T1012 T1059.001 T1518 Anomaly Windows Discovery Techniques 2026-05-13
Windows Account Discovery for None Disable User Account Powershell Script Block Logging 4104 T1087.001 Hunting CISA AA23-347A 2026-05-13
GetDomainComputer with PowerShell Script Block Powershell Script Block Logging 4104 T1018 TTP Active Directory Discovery 2026-05-13
Windows Suspect Process With Authentication Traffic Sysmon EventID 3 T1087.002 T1204.002 Anomaly Active Directory Discovery 2026-05-13
Windows System Discovery Using Qwinsta Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting Qakbot 2026-05-13
Get ADUser with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.002 Hunting CISA AA23-347A, Active Directory Discovery 2026-05-13
Headless Browser Usage Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497 T1564.003 Anomaly Browser Hijacking, Phantom Stealer, Forest Blizzard 2026-06-25
Network Discovery Using Route Windows App Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1016.001 Hunting Prestige Ransomware, Active Directory Discovery, Qakbot, CISA AA22-277A, Windows Post-Exploitation 2026-05-13
Detect SharpHound Command-Line Arguments Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 T1069.002 T1087.001 T1087.002 T1482 TTP Windows Discovery Techniques, Ransomware, BlackSuit Ransomware 2026-05-13
Windows Netspy Network Scanner Execution Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 T1595 Anomaly Windows Discovery Techniques, Network Discovery 2026-05-13
Windows Forest Discovery with GetForestDomain Powershell Script Block Logging 4104 T1087.002 TTP Active Directory Discovery 2026-05-13
Windows Chromium Browser No Security Sandbox Process Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497 TTP Malicious Inno Setup Loader, Phantom Stealer 2026-06-25
Windows System Remote Discovery With Query Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1033 Hunting Active Directory Discovery, Medusa Ransomware 2026-05-13
Windows Common Abused Cmd Shell Risk Behavior T1016 T1033 T1049 T1059 T1222 T1529 Correlation Windows Defense Evasion Tactics, Disabling Security Tools, DarkCrystal RAT, Netsh Abuse, Volt Typhoon, CISA AA23-347A, Qakbot, Azorult, FIN7, Microsoft WSUS CVE-2025-59287, Windows Post-Exploitation, Sandworm Tools 2026-05-13
Windows PowerView Unconstrained Delegation Discovery Powershell Script Block Logging 4104 T1018 TTP Rhysida Ransomware, CISA AA23-347A, Active Directory Kerberos Attacks 2026-05-13
GetWmiObject Ds Computer with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1018 Anomaly Active Directory Discovery 2026-05-13
Windows Product Key Registry Query Windows Event Log Security 4663 T1012 Anomaly BlankGrabber Stealer 2026-05-13
GetWmiObject DS User with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.002 Anomaly Active Directory Discovery 2026-05-13
GetDomainGroup with PowerShell Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.002 TTP Active Directory Discovery 2026-05-13
GetWmiObject User Account with PowerShell Script Block Powershell Script Block Logging 4104 T1059.001 T1087.001 Hunting Active Directory Discovery, Malicious PowerShell, Winter Vivern 2026-05-13
Windows User Discovery Via Net Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.001 T1087.002 Hunting Active Directory Discovery, Medusa Ransomware, Sandworm Tools 2026-08-05
Linux Kernel Module Enumeration Sysmon for Linux EventID 1 T1014 T1082 Anomaly Linux Rootkit, XorDDos 2026-05-13
Detect AzureHound Command-Line Arguments Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 T1069.002 T1087.001 T1087.002 T1482 TTP Windows Discovery Techniques, Compromised Windows Host 2026-05-13
Windows Chromium Browser with Custom User Data Directory Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1497 Anomaly Malicious Inno Setup Loader, StealC Stealer, Phantom Stealer, Lokibot 2026-06-25
Linux Auditd Hidden Files And Directories Creation Linux Auditd Execve T1083 Anomaly Compromised Linux Host, Linux Living Off The Land, Linux Persistence Techniques, Linux Privilege Escalation 2026-05-13
Detect SharpHound Usage Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 T1069.002 T1087.001 T1087.002 T1482 TTP Windows Discovery Techniques, Ransomware 2026-05-13
SchCache Change By App Connect And Create ADSI Object Sysmon EventID 11 T1087.002 Anomaly BlackMatter Ransomware 2026-05-13
Windows WinPEAS PowerShell Script Execution Powershell Script Block Logging 4104 T1007 T1016 T1033 T1082 T1590 T1592.002 T1592.004 T1615 TTP Windows Post-Exploitation 2026-05-13
Local Account Discovery With Wmic Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1087.001 Hunting Active Directory Discovery, Scattered Lapsus$ Hunters 2026-05-13
Windows Credential Access From Browser Password Store Windows Event Log Security 4663 T1012 Anomaly Phantom Stealer, Salt Typhoon, Quasar RAT, Salat Stealer, VIP Keylogger, Meduza Stealer, Malicious Inno Setup Loader, MoonPeak, BlankGrabber Stealer, StealC Stealer, SnappyBee, Earth Alux, PXA Stealer, Scattered Lapsus$ Hunters, Braodo Stealer, 0bj3ctivity Stealer, Scattered Spider, Snake Keylogger, China-Nexus Threat Activity 2026-06-25
Windows SOAPHound Binary Execution Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 T1069.001 T1069.002 T1087.001 T1087.002 T1482 TTP Windows Discovery Techniques, Compromised Windows Host 2026-05-13
Detect attackers scanning for vulnerable JBoss servers T1082 T1133 TTP JBoss Vulnerability, SamSam Ransomware 2026-05-13
ESXi Bulk VM Termination VMWare ESXi Syslog T1499 T1529 T1673 TTP Black Basta Ransomware, ESXi Post Compromise 2026-05-13
Cisco IOS XE Remote Access Probe Burst Cisco IOS Logs T1018 T1021.004 T1046 Anomaly Salt Typhoon 2026-05-20
Cisco ASA - Reconnaissance Command Activity Cisco ASA Logs T1082 T1590.001 T1590.005 Anomaly Suspicious Cisco Adaptive Security Appliance Activity 2026-05-13
Okta IDP Lifecycle Modifications Okta T1087.004 Anomaly Suspicious Okta Activity 2026-05-13
Cisco IOS XE Reconnaissance Command Activity Cisco IOS Logs T1016 T1082 T1590 Anomaly Salt Typhoon 2026-05-20
Cisco ASA - Packet Capture Activity Cisco ASA Logs T1040 T1557 Anomaly ArcaneDoor, Suspicious Cisco Adaptive Security Appliance Activity 2026-05-13
ESXi VM Discovery VMWare ESXi Syslog T1673 TTP China-Nexus Threat Activity, Black Basta Ransomware, ESXi Post Compromise 2026-05-13
Okta Unauthorized Access to Application Okta T1087.004 Anomaly Okta Account Takeover 2026-05-13
Splunk Authentication Token Exposure in Debug Log T1654 TTP Splunk Vulnerabilities 2026-06-24
Okta Multiple Failed Requests to Access Applications Okta T1538 T1550.004 Hunting Okta Account Takeover 2026-05-13
ESXi System Information Discovery VMWare ESXi Syslog T1082 TTP Black Basta Ransomware, ESXi Post Compromise 2026-05-13
Kubernetes Scanner Image Pulling T1526 TTP Dev Sec Ops 2026-05-13
ASL AWS IAM Successful Group Deletion ASL AWS CloudTrail T1069.003 T1098 Hunting AWS IAM Privilege Escalation 2026-05-13
ASL AWS IAM AccessDenied Discovery Events ASL AWS CloudTrail T1580 Anomaly Suspicious Cloud User Activities 2026-05-13
AWS Excessive Security Scanning AWS CloudTrail T1526 TTP AWS User Monitoring 2026-05-13
Azure AD AzureHound UserAgent Detected Azure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogs T1087.004 T1526 TTP Azure Active Directory Privilege Escalation, Compromised User Account 2026-05-13
Kubernetes Scanning by Unauthenticated IP Address Kubernetes Audit T1046 Anomaly Kubernetes Security 2026-05-13
AWS IAM AccessDenied Discovery Events AWS CloudTrail T1580 Anomaly Suspicious Cloud User Activities 2026-05-13
Amazon EKS Kubernetes cluster scan detection T1526 Hunting Kubernetes Scanning Activity 2026-05-13
AWS IAM Assume Role Policy Brute Force AWS CloudTrail T1110 T1580 TTP AWS IAM Privilege Escalation 2026-05-13
AWS High Number Of Failed Authentications For User AWS CloudTrail ConsoleLogin T1201 Anomaly AWS Identity and Access Management Account Takeover, Compromised User Account 2026-05-13
Kubernetes Suspicious Image Pulling Kubernetes Audit T1526 Anomaly Kubernetes Security 2026-05-13
Azure AD Service Principal Enumeration Azure Active Directory MicrosoftGraphActivityLogs T1087.004 T1526 TTP Azure Active Directory Privilege Escalation, Compromised User Account 2026-05-13
Kubernetes Access Scanning Kubernetes Audit T1046 Anomaly Kubernetes Security 2026-05-13
AWS Password Policy Changes AWS CloudTrail UpdateAccountPasswordPolicy, AWS CloudTrail GetAccountPasswordPolicy, AWS CloudTrail DeleteAccountPasswordPolicy T1201 Hunting Compromised User Account, AWS IAM Privilege Escalation 2026-05-13
AWS IAM Successful Group Deletion AWS CloudTrail DeleteGroup T1069.003 T1098 Hunting AWS IAM Privilege Escalation 2026-05-13
Amazon EKS Kubernetes Pod scan detection T1526 Hunting Kubernetes Scanning Activity 2026-05-13
ASL AWS IAM Assume Role Policy Brute Force ASL AWS CloudTrail T1110 T1580 TTP Scattered Lapsus$ Hunters, AWS IAM Privilege Escalation 2026-05-13
GCP Kubernetes cluster pod scan detection T1526 Hunting Scattered Lapsus$ Hunters, Kubernetes Scanning Activity 2026-05-13
AWS Bedrock High Number List Foundation Model Failures AWS CloudTrail T1580 TTP AWS Bedrock Security 2026-05-13
Internal Horizontal Port Scan NMAP Top 20 Cisco Secure Firewall Threat Defense Connection Event, AWS CloudWatchLogs VPCflow T1046 TTP Scattered Lapsus$ Hunters, Cisco Secure Firewall Threat Defense Analytics, China-Nexus Threat Activity, Network Discovery 2026-05-13
Cisco Secure Firewall - Blocked Connection Cisco Secure Firewall Threat Defense Connection Event T1018 T1046 T1110 T1203 T1595.002 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Internal Horizontal Port Scan Cisco Secure Firewall Threat Defense Connection Event, AWS CloudWatchLogs VPCflow T1046 TTP Scattered Lapsus$ Hunters, Cisco Secure Firewall Threat Defense Analytics, China-Nexus Threat Activity, Network Discovery 2026-05-13
Cisco Secure Firewall - Repeated Blocked Connections Cisco Secure Firewall Threat Defense Connection Event T1018 T1046 T1110 T1203 T1595.002 Anomaly Cisco Secure Firewall Threat Defense Analytics 2026-05-13
Internal Vulnerability Scan T1046 T1595.002 TTP Scattered Lapsus$ Hunters, Network Discovery 2026-05-13
Internal Vertical Port Scan Cisco Secure Firewall Threat Defense Connection Event, AWS CloudWatchLogs VPCflow T1046 TTP Scattered Lapsus$ Hunters, Cisco Secure Firewall Threat Defense Analytics, China-Nexus Threat Activity, Network Discovery 2026-05-13
Cisco SNMP Community String Configuration Changes Cisco IOS Logs T1040 T1552 T1685 Anomaly Cisco Smart Install Remote Code Execution CVE-2018-0171 2026-05-13