Rule Library
Sigma Rules
4 rules found for "@harr0ey"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
New Capture Session Launched Via DXCap.EXE
Detects the execution of "DXCap.EXE" with the "-c" flag, which allows a user to launch any arbitrary binary or windows package through DXCap itself. This can be abused to potentially bypass application whitelisting.
WindowsProcess Creation
Beyu Denis+2Sat Oct 26windows
Detectionhightest
OpenWith.exe Executes Specified Binary
The OpenWith.exe executes other binary
WindowsProcess Creation
Beyu Denis+2Sat Oct 12windows
Detectionmediumtest
Code Execution via Pcwutl.dll
Detects launch of executable by calling the LaunchApplication function from pcwutl.dll library.
WindowsProcess Creation
Julia Fomina+1Mon Oct 05windows
Detectionhightest
UAC Bypass Using ChangePK and SLUI
Detects an UAC bypass that uses changepk.exe and slui.exe (UACMe 61)
WindowsProcess Creation
Christian Burkard (Nextron Systems)Mon Aug 23windows