Rule Library
Sigma Rules
3 rules found for "Center for Threat Informed Defense (CTID) Summiting the Pyramid Team"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionlowtest
Service Registry Key Read Access Request
Detects "read access" requests on the services registry key. Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for Registry keys related to services to redirect from the originally specified executable to one that they control, in order to launch their own code when a service starts.
Windowssecurity
Center for Threat Informed Defense (CTID) Summiting the Pyramid TeamThu Sep 28windows
Threat Huntlowtest
Scheduled Task Created - FileCreation
Detects the creation of a scheduled task via file creation.
WindowsFile Event
Center for Threat Informed Defense (CTID) Summiting the Pyramid TeamWed Sep 27windows
Threat Huntlowtest
Scheduled Task Created - Registry
Detects the creation of a scheduled task via Registry keys.
WindowsRegistry Event
Center for Threat Informed Defense (CTID) Summiting the Pyramid TeamWed Sep 27windows