Rule Library
Sigma Rules
5 rules found for "Aleksey Potapov"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Potentially Suspicious AccessMask Requested From LSASS
Detects process handle on LSASS process with certain access mask
Windowssecurity
Roberto Rodriguez (Cyb3rWard0g)+5Fri Nov 01windows
Detectionhightest
HackTool - Potential CobaltStrike Process Injection
Detects a potential remote threat creation with certain characteristics which are typical for Cobalt Strike beacons
WindowsRemote Thread Creation
Olaf Hartong+3Fri Nov 30windows
Detectionhightest
HackTool - SILENTTRINITY Stager DLL Load
Detects SILENTTRINITY stager dll loading activity
WindowsImage Load (DLL)
Aleksey Potapov+1Tue Oct 22windows
Detectionmediumtest
Potentially Suspicious GrantedAccess Flags On LSASS
Detects process access requests to LSASS process with potentially suspicious access flags
WindowsProcess Access
Florian Roth (Nextron Systems)+9Mon Nov 22windows
Detectionhightest
HackTool - SILENTTRINITY Stager Execution
Detects SILENTTRINITY stager use via PE metadata
WindowsProcess Creation
Aleksey Potapov+1Tue Oct 22windows