Rule Library
Sigma Rules
5 rules found for "Anton Kutepov"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Using SettingSyncHost.exe as LOLBin
Detects using SettingSyncHost.exe to run hijacked binary
WindowsProcess Creation
Anton Kutepov+1Wed Feb 05windows
Detectionhightest
Suspicious Encoded PowerShell Command Line
Detects suspicious powershell process starts with base64 encoded commands (e.g. Emotet)
WindowsProcess Creation
Florian Roth (Nextron Systems)+5Mon Sep 03windows
Detectionhightest
Run PowerShell Script from Redirected Input Stream
Detects PowerShell script execution via input stream redirect
WindowsProcess Creation
Moriarty Meng+2Sat Oct 17windows
Detectionhightest
System File Execution Location Anomaly
Detects the execution of a Windows system binary that is usually located in the system folder from an uncommon location.
WindowsProcess Creation
Florian Roth (Nextron Systems)+4Mon Nov 27windows
Detectionhightest
Webshell Detection With Command Line Keywords
Detects certain command line parameters often used during reconnaissance activity via web shells
WindowsProcess Creation
Florian Roth (Nextron Systems)+5Sun Jan 01windows