Rule Library
Sigma Rules
4 rules found for "JHasenbusch"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
New User Created Via Net.EXE
Identifies the creation of local users via the net.exe command.
WindowsProcess Creation
Endgame+1Tue Oct 30windows
Detectionlowstable
Share And Session Enumeration Using Net.EXE
Detects attempts to enumerate file shares, printer shares and sessions using "net.exe" with the "view" flag.
WindowsProcess Creation
Endgame+1Tue Oct 30windows
Detectionhightest
Dumping of Sensitive Hives Via Reg.EXE
Detects the usage of "reg.exe" in order to dump sensitive registry hives. This includes SAM, SYSTEM and SECURITY hives.
WindowsProcess Creation
Teymur Kheirkhabarov+5Tue Oct 22windows
Detectionmediumtest
Usage Of Web Request Commands And Cmdlets
Detects the use of various web request commands with commandline tools and Windows PowerShell cmdlets (including aliases) via CommandLine
WindowsProcess Creation
James Pemberton+4Thu Oct 24windows