Rule Library
Sigma Rules
5 rules found for "Bartlomiej Czyz"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Metasploit Or Impacket Service Installation Via SMB PsExec
Detects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation
Windowssecurity
Bartlomiej Czyz+1Thu Jan 21windows
Detectionmediumtest
PowerShell ICMP Exfiltration
Detects Exfiltration Over Alternative Protocol - ICMP. Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
WindowsPowerShell Script
Bartlomiej Czyz+1Sat Oct 10windows
Detectionhightest
Malicious PowerShell Commandlets - ScriptBlock
Detects Commandlet names from well-known PowerShell exploitation frameworks
WindowsPowerShell Script
Sean Metcalf+10Sun Mar 05windows
Detectionhightest
Rundll32 Execution Without Parameters
Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
WindowsProcess Creation
Bartlomiej Czyz+1Sun Jan 31windows
Detectionmediumtest
Path To Screensaver Binary Modified
Detects value modification of registry key containing path to binary used as screensaver.
WindowsRegistry Event
Bartlomiej Czyz+1Sun Oct 11windows