Rule Library
Sigma Rules
2 rules found for "Ahmed Farouk"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Suspicious External WebDAV Execution
Detects executables launched from external WebDAV shares using the WebDAV Explorer integration, commonly seen in initial access campaigns.
Proxy Log
Ahmed FaroukFri May 10web
Detectionhightest
Potentially Suspicious Command Executed Via Run Dialog Box - Registry
Detects execution of commands via the run dialog box on Windows by checking values of the "RunMRU" registry key. This technique was seen being abused by threat actors to deceive users into pasting and executing malicious commands, often disguised as CAPTCHA verification steps.
WindowsRegistry Set
Ahmed Farouk+1Fri Nov 01windows