Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
337–360 of 400 compositions
- T1055.014
Shared object opened from /tmp, or ptrace called by a network service
3 of 4 backends · unverified000 - T1574.006
Shared object written into a non-standard directory Linux dynamic linker would trust
2 of 4 backends · unverified000 - T1552.003
Shell history file access recorded by auditd on Linux
3 of 4 backends · unverified000 - T1678
Shell one-liner delays before piping a download into an interpreter
4 of 4 backends · unverified000 - T1132
Shell one-liner encodes data and pipes it to a network transfer tool
4 of 4 backends · unverified000 - T1021.003
Shell or script host spawned by a remotely activatable COM server
4 of 4 backends · unverified000 - T1546.004
Shell startup or logout script modified on Linux
3 of 4 backends · unverified000 - T1614
Shell tools query the host timezone and locale settings
4 of 4 backends · unverified000 - T1547.009
Shortcut file written into a Startup folder
4 of 4 backends · unverified000 - T1187
Shortcut or search-connector file dropped in a user-facing folder
4 of 4 backends · unverified000 - T1134.005
sIDHistory attribute populated on a domain user account
4 of 4 backends · unverified000 - T1216
Signed diagnostic script sourced to proxy code execution
4 of 4 backends · unverified000 - T1072
Software deployment agent spawning a script interpreter
4 of 4 backends · unverified000 - T1505.001
SQL Server engine spawning an operating system process
4 of 4 backends · unverified000 - T1558
SSSD Kerberos secrets database opened on Linux
3 of 4 backends · unverified000 - T1037.004
Startup RC or init script edited by a file-writing tool
4 of 4 backends · unverified000 - T1001.002T1027.003
Steganography tool embedding data into a carrier file on Linux
4 of 4 backends · unverified000 - T1489
Stop or disable command targeting a data-store service
4 of 4 backends · unverified000 - T1565.001
Stored business data file deleted by a process that does not own it
4 of 4 backends · unverified000 - T1548.003
Sudoers file or sudo credential cache altered from a command line
4 of 4 backends · unverified000 - T1021.004
Suspicious one-line command executed as a direct child of sshd
4 of 4 backends · unverified000 - T1027.008
Symbol stripping run against a compiled binary on Linux
4 of 4 backends · unverified000 - T1574.001
System DLL loaded from outside the Windows system directories
4 of 4 backends · unverified002 - T1574.007
System tool name executed from outside its expected system directory
4 of 4 backends · unverified000