Rule Library
Sigma Rules
3 rules found for "@roxpinteddy"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Advanced IP Scanner - File Event
Detects the use of Advanced IP Scanner. Seems to be a popular tool for ransomware groups.
WindowsFile Event
@roxpinteddyTue May 12windows
Detectionmediumtest
PowerShell Create Local User
Detects creation of a local user via PowerShell
WindowsPowerShell Script
@roxpinteddySat Apr 11windows
Detectionhightest
Rar Usage with Password and Compression Level
Detects the use of rar.exe, on the command line, to create an archive with password protection or with a specific compression level. This is pretty indicative of malicious actions.
WindowsProcess Creation
@roxpinteddyTue May 12windows