Rule Library
Sigma Rules
51 rules found for "attack.T1047"
3,731Total
3,132Detection
457Emerging
139Hunting
Emerging Threatcriticaltest
Potential Maze Ransomware Activity
Detects specific process characteristics of Maze ransomware word document droppers
WindowsProcess Creation
Florian Roth (Nextron Systems)Fri May 082020
Emerging Threatcriticaltest
UNC2452 PowerShell Pattern
Detects a specific PowerShell command line pattern used by the UNC2452 actors as mentioned in Microsoft and Symantec reports
WindowsProcess Creation
Florian Roth (Nextron Systems)Wed Jan 202020
Threat Huntlowtest
WMI Module Loaded By Uncommon Process
Detects WMI modules being loaded by an uncommon process
WindowsImage Load (DLL)
Roberto Rodriguez (Cyb3rWard0g)Sat Aug 10windows