Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
73–96 of 400 compositions
- T1687
Detect a defensive service terminating unexpectedly
4 of 4 backends · unverified000 - T1204
Detect a document or archive application spawning a system utility
4 of 4 backends · unverified000 - T1203
Detect a document or browser process spawning a scripting host
4 of 4 backends · unverified000 - T1020
Detect a file-transfer utility launched by the task scheduler
4 of 4 backends · unverified000 - T1132.002
Detect a hand-rolled character-table encoder in a script block
4 of 4 backends · unverified000 - T1185
Detect a process opening a browser with injection access rights
3 of 4 backends · unverified000 - T1204.004
Detect an interpreter launched from the shell with a pasted one-liner
4 of 4 backends · unverified000 - T1560.001
Detect archiving utilities run with an archive-creating verb
0% noise measured in lab
4 of 4 backends · verified000 - T1176.001
Detect browser launched with a sideloaded extension flag
4 of 4 backends · unverified000 - T1218.009
Detect COM registration utility running a user-writable assembly
0% noise measured in lab
4 of 4 backends · verified000 - T1496
Detect DNS lookups for bandwidth-monetization proxyware services
3 of 4 backends · unverified000 - T1027
Detect encoding or encryption of files under sensitive paths
4 of 4 backends · unverified000 - T1016
Detect execution of built-in network configuration utilities
4 of 4 backends · unverified000 - T1110.001
Detect failed remote logons against commonly guessed accounts
4 of 4 backends · unverified000 - T1071.002
Detect FTP or TFTP connection from a script host or proxy binary
3 of 4 backends · unverified000 - T1053.002
Detect job scheduling through the legacy at utility
0% noise measured in lab
4 of 4 backends · verified000 - T1496.001
Detect mining pool and miner arguments in process command lines
4 of 4 backends · unverified000 - T1127.001
Detect MSBuild spawning a script interpreter or signed-binary proxy
4 of 4 backends · unverified000 - T1018
Detect net view used to enumerate hosts and shares on the network
0% noise measured in lab
4 of 4 backends · verified000 - T1135
Detect network share enumeration from the command line
4 of 4 backends · unverified000 - T1040T1205.002
Detect packet capture libraries loaded outside a capture install
4 of 4 backends · unverified000 - T1110.002
Detect password hash cracking tool execution on a host
4 of 4 backends · unverified000 - T1053.005
Detect scheduled task registered with a suspicious action
3 of 4 backends · unverified000 - T1124
Detect system time and time zone discovery on the command line
4 of 4 backends · unverified000