Rule Library
Sigma Rules
3 rules found for "FPT.EagleEye"
3,731Total
3,132Detection
457Emerging
139Hunting
Emerging Threatcriticaltest
Potential Emotet Rundll32 Execution
Detecting Emotet DLL loading by looking for rundll32.exe processes with command lines ending in ,RunDLL or ,Control_RunDLL
WindowsProcess Creation
FPT.EagleEyeFri Dec 252020
Emerging Threatinformationaltest
Windows Spooler Service Suspicious Binary Load
Detect DLL Load from Spooler Service backup folder. This behavior has been observed during the exploitation of the Print Spooler Vulnerability CVE-2021-1675 and CVE-2021-34527 (PrinterNightmare).
WindowsImage Load (DLL)
FPT.EagleEye+1Tue Jun 292021
Emerging Threathightest
SOURGUM Actor Behaviours
Suspicious behaviours related to an actor tracked by Microsoft as SOURGUM
WindowsProcess Creation
MSTIC+1Tue Jun 152021