Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
289–312 of 400 compositions
- T1083
Recursive directory listing issued from a Windows shell
3 of 4 backends · unverified000 - T1485
Recursive file deletion or secure-overwrite command line
4 of 4 backends · unverified000 - T1005
Recursive search for sensitive files under a shared root
4 of 4 backends · unverified000 - T1559.002
Registry access to the Office DDE enablement keys
4 of 4 backends · unverified000 - T1552.002
Registry queried for credential-related value names
4 of 4 backends · unverified000 - T1012
Registry queried for host, software or security configuration
4 of 4 backends · unverified000 - T1548T1548.002
Registry write to a known UAC bypass hijack key
0% noise measured in lab
4 of 4 backends · verified000 - T1553.003
Registry write to a Subject Interface Package signing function entry
4 of 4 backends · unverified000 - T1547.014
Registry write to an Active Setup StubPath value
4 of 4 backends · unverified000 - T1547.005T1547.008T1556.002
Registry write to an LSA package list or LSA extension key
0% noise measured in lab
4 of 4 backends · verified000 - T1553
Registry write under the trust-provider FinalPolicy key
4 of 4 backends · unverified000 - T1497
Registry, WMIC or service queries for known VM/sandbox artifacts
4 of 4 backends · unverified000 - T1218.010
Regsvr32 loading a scriptlet or a module from a remote path
0% noise measured in lab
4 of 4 backends · verified000 - T1021.002
Remote connection to an administrative share by a user account
4 of 4 backends · unverified000 - T1571
Remote Desktop listener moved to a non-standard port
4 of 4 backends · unverified000 - T1021
Remote interactive NTLM logon or explicit-credential remote access
4 of 4 backends · unverified000 - T1055.003
Remote memory write handle without remote-thread rights
3 of 4 backends · unverified000 - T1216.001
Remote scriptlet proxied through PubPrn.vbs
4 of 4 backends · unverified000 - T1219
Remote support agent spawning a shell or script host
0% noise measured in lab
4 of 4 backends · verified000 - T1055T1056.004
Remote thread created inside a credential-handling process
3 of 4 backends · unverified000 - T1055.002
Remote-write process handle opened from an unbacked call stack
0% noise measured in lab
3 of 4 backends · verified000 - T1547.001
Run key value pointing at a script host or user-writable path
0% noise measured in lab
4 of 4 backends · verified000 - T1218.011
Rundll32 proxies JavaScript through mshtml's HTML application runner
0% noise measured in lab
4 of 4 backends · verified302 - T1688
Safe mode boot armed from a command line
4 of 4 backends · unverified000