Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
241–264 of 400 compositions
- T1499.001
Packet generator invoked with SYN, ACK or flood arguments on Linux
3 of 4 backends · unverified000 - T1556.006
PAM configuration or MFA module file touched under /etc/pam.d
3 of 4 backends · unverified000 - T1556.003
PAM configuration or module directory written on Linux
3 of 4 backends · unverified000 - T1561.002
Partition-table wipe utility invoked on Linux
3 of 4 backends · unverified000 - T1140
Payload reassembly or password-protected archive extraction
4 of 4 backends · unverified000 - T1546.015
Per-user CLSID registered with a payload under InprocServer32 or LocalServer32
4 of 4 backends · unverified000 - T1070.009
Persistence artefact removed via service, task or account deletion
4 of 4 backends · unverified000 - T1572
Port forwarding flags on ssh, plink or netsh portproxy
3 of 4 backends · unverified000 - T1090
Port-relay tool invoked with a listener or SOCKS address
4 of 4 backends · unverified000 - T1653
Power configuration changed to stop a host sleeping
4 of 4 backends · unverified000 - T1070.003
PowerShell console history cleared
4 of 4 backends · unverified000 - T1556.005
PowerShell enables reversible encryption for an AD account
4 of 4 backends · unverified000 - T1059.001
PowerShell engine loaded by a process that is not a PowerShell host
4 of 4 backends · unverified000 - T1690
PowerShell history saving disabled via Set-PSReadLineOption
4 of 4 backends · unverified202 - T1564.008
PowerShell inbox rule created or modified to delete, move or hide mail
4 of 4 backends · unverified000 - T1689
PowerShell launched pinned to the version 2 engine
4 of 4 backends · unverified102 - T1564.003
PowerShell launched with a hidden window style
4 of 4 backends · unverified000 - T1546.013
PowerShell profile script written to a known profile path
4 of 4 backends · unverified000 - T1564.004
PowerShell reading or writing an alternate data stream by name
4 of 4 backends · unverified000 - T1074.002
PowerShell script block copies a file from a UNC path
4 of 4 backends · unverified000 - T1564.011
PowerShell script block suppresses errors around a download or exec cmdlet
4 of 4 backends · unverified000 - T1137.004
PowerShell script touching the Outlook Home Page WebView setting
4 of 4 backends · unverified000 - T1056.002
PowerShell spawns a credential prompt from a script-launched parent
4 of 4 backends · unverified000 - T1027.003
PowerShell walking image pixels on the command line
4 of 4 backends · unverified000