Rule Library
Sigma Rules
4 rules found for "Cyb3rEng"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
File With Uncommon Extension Created By An Office Application
Detects the creation of files with an executable or script extension by an Office application.
WindowsFile Event
Vadim Khrykov (ThreatIntel)+2Mon Aug 23windows
Detectionhightest
Suspicious Microsoft Office Child Process
Detects a suspicious process spawning from one of the Microsoft Office suite products (Word, Excel, PowerPoint, Publisher, Visio, etc.)
WindowsProcess Creation
Florian Roth (Nextron Systems)+7Fri Apr 06windows
Detectionhightest
Suspicious WMIC Execution Via Office Process
Office application called wmic to proxye execution through a LOLBIN process. This is often used to break suspicious parent-child chain (Office app spawns LOLBin).
WindowsProcess Creation
Vadim Khrykov+1Mon Aug 23windows
Detectionhightest
Suspicious WmiPrvSE Child Process
Detects suspicious and uncommon child processes of WmiPrvSE
WindowsProcess Creation
Vadim Khrykov (ThreatIntel)+2Mon Aug 23windows