Rule Library
Sigma Rules
4 rules found for "Hieu Tran"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Gzip Archive Decode Via PowerShell
Detects attempts of decoding encoded Gzip archives via PowerShell.
WindowsProcess Creation
Hieu TranMon Mar 13windows
Detectionmediumtest
Potential DLL File Download Via PowerShell Invoke-WebRequest
Detects potential DLL files being downloaded using the PowerShell Invoke-WebRequest or Invoke-RestMethod cmdlets.
WindowsProcess Creation
Florian Roth (Nextron Systems)+1Mon Mar 13windows
Detectionhightest
Suspicious Rundll32 Execution With Image Extension
Detects the execution of Rundll32.exe with DLL files masquerading as image files
WindowsProcess Creation
Hieu TranMon Mar 13windows
Detectionhightest
Potential Qakbot Registry Activity
Detects a registry key used by IceID in a campaign that distributes malicious OneNote files
WindowsRegistry Event
Hieu TranMon Mar 13windows