Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
49–72 of 400 compositions
- T1574.014
Command line sets a custom .NET AppDomainManager assembly
4 of 4 backends · unverified000 - T1213
Command-line HTTP client querying a collaboration platform API
4 of 4 backends · unverified000 - T1574.008
Common system utility name executed from a non-standard directory
4 of 4 backends · unverified000 - T1560.002
Compression library loaded by a script host or LOLBin
4 of 4 backends · unverified000 - T1090.003
Connection to an onion-routing relay or local SOCKS proxy port
3 of 4 backends · unverified000 - T1059.013
Container CLI used to run a shell inside a running container
4 of 4 backends · unverified000 - T1611
Container process entering the host namespaces
3 of 4 backends · unverified000 - T1543.005
Container started with a persistent restart policy
4 of 4 backends · unverified000 - T1218.002
Control panel item executed from a user-writable directory
0% noise measured in lab
4 of 4 backends · verified000 - T1025
Copy or archive tool targets documents on a non-system drive letter
4 of 4 backends · unverified000 - T1055.012
Core system binary started by an unexpected parent
4 of 4 backends · unverified000 - T1036.005
Core Windows system binary name running from outside System32
4 of 4 backends · unverified000 - T1555.004
Credential Manager vault accessed via vaultcmd or keymgr
4 of 4 backends · unverified000 - T1053.003
Crontab file or cron drop-in directory written on Linux
3 of 4 backends · unverified000 - T1055.001
Cross-process write and thread rights on a system process
0% noise measured in lab
3 of 4 backends · verified000 - T1001.003
curl or wget overrides the Host header to impersonate a cloud service
4 of 4 backends · unverified000 - T1560.003
Custom byte-level encoding routine run inline against file data
4 of 4 backends · unverified000 - T1546.011
Custom shim database registered under AppCompatFlags
4 of 4 backends · unverified000 - T1213.006
Database client launched by a script host or Office parent
4 of 4 backends · unverified000 - T1565
Database or ledger file created by a script host or LOLBin
4 of 4 backends · unverified000 - T1546.012
Debugger value written under an Image File Execution Options key
4 of 4 backends · unverified000 - T1123
Dedicated audio-capture binary executed on Linux
3 of 4 backends · unverified000 - T1567.002
Dedicated cloud-storage transfer utility invoked with an upload verb
4 of 4 backends · unverified000 - T1685.006
Deletion of a Linux system log file recorded by auditd
3 of 4 backends · unverified000