Rule Library
Sigma Rules
2 rules found for "Jason Lynch"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Suspicious Binary In User Directory Spawned From Office Application
Detects an executable in the users directory started from one of the Microsoft Office suite applications (Word, Excel, PowerPoint, Publisher, Visio)
WindowsProcess Creation
Jason LynchTue Apr 02windows
Detectionhightest
Renamed PAExec Execution
Detects execution of renamed version of PAExec. Often used by attackers
WindowsProcess Creation
Florian Roth (Nextron Systems)+1Sat May 22windows