T
TheDFIRReport
First rule: Sat Feb 12 2022 01:00:00 GMT+0100 (Central European Standard Time)
0rules authored
0sole author
13co-authored
Rule Types
By Severity
critical
0
high
10
medium
2
low
1
informational
0
By Status
stable
0
test
13
experimental
0
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Potential Tampering With RDP Related Registry Keys Via Reg.EXE
Sat Feb 12 2022 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Obfuscated PowerShell OneLiner Execution
Mon May 09 2022 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Hiding User Account Via SpecialAccounts Registry Key - CommandLine
Sat May 14 2022 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Console CodePage Lookup Via CHCP
Mon Feb 21 2022 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
DNS Query To Ufile.io
Thu Jun 23 2022 02:00:00 GMT+0200 (Central European Summer Time)
lowDetection
Scheduled Task Executing Encoded Payload from Registry
Sat Feb 12 2022 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Browse all 13 rules by TheDFIRReport
Filter the full rule library to see only their contributions