Rule Library
Sigma Rules
2 rules found for "Ivan Dyachkov"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
DLL Execution Via Register-cimprovider.exe
Detects using register-cimprovider.exe to execute arbitrary dll file.
WindowsProcess Creation
Ivan Dyachkov+2Wed Oct 07windows
Threat Huntmediumtest
Diskshadow Script Mode Execution
Detects execution of "Diskshadow.exe" in script mode using the "/s" flag. Attackers often abuse "diskshadow" to execute scripts that deleted the shadow copies on the systems. Investigate the content of the scripts and its location.
WindowsProcess Creation
Ivan Dyachkov+1Wed Oct 07windows