Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
97–120 of 400 compositions
- T1048
Detect unexpected processes connecting out on FTP or SMTP ports
4 of 4 backends · unverified000 - T1021.005
Detect VNC server or viewer process starting on a host
4 of 4 backends · unverified000 - T1047
Detect WMI method invocation and WMI-spawned child processes
0% noise measured in lab
4 of 4 backends · verified000 - T1003.006
Directory replication rights exercised by a non-machine account
4 of 4 backends · unverified000 - T1129
DLL loaded from a temp, roaming or UNC path without a valid signature
4 of 4 backends · unverified000 - T1546.009
DLL registered under the AppCertDLLs registry key
4 of 4 backends · unverified000 - T1547.003
DllName value written under a W32Time time provider subkey
4 of 4 backends · unverified000 - T1001.001
DNS query with an abnormally long leftmost label
2 of 4 backends · unverified000 - T1039
Document or archive accessed inside a hidden administrative share
4 of 4 backends · unverified000 - T1087.002
Domain account and group enumeration from a command line
0% noise measured in lab
4 of 4 backends · verified000 - T1136.002
Domain account created from a command line
4 of 4 backends · unverified000 - T1069.002
Domain group enumeration via net group or the AD cmdlets
0% noise measured in lab
4 of 4 backends · verified000 - T1484
Domain-wide policy attribute or delegation ACL changed on the domain object
4 of 4 backends · unverified000 - T1652
Driver enumeration by command line or services-key query
4 of 4 backends · unverified000 - T1068
Driver loaded from a user-writable path or a known-abused driver
3 of 4 backends · unverified000 - T1547.010
Driver value written under a Print Monitors registry key
4 of 4 backends · unverified000 - T1218.015
Electron launcher switch used to run an arbitrary child process
4 of 4 backends · unverified000 - T1574.005
Elevated process started from a writable installer staging directory
4 of 4 backends · unverified000 - T1027.013
Encoded payload file decoded by certutil or PowerShell
4 of 4 backends · unverified000 - T1049
Enumeration of local network connections from the command line
4 of 4 backends · unverified000 - T1480
Environment-keyed conditional execution on the command line
4 of 4 backends · unverified000 - T1654
Event log export or query via wevtutil or PowerShell cmdlets
4 of 4 backends · unverified000 - T1098.002
Exchange mailbox delegate permission granted from a command line
4 of 4 backends · unverified000 - T1070.004
Executable artefact deleted from a staging directory
4 of 4 backends · unverified000