Rule Library
Sigma Rules
4 rules found for "John Lambert"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
PowerShell Credential Prompt
Detects PowerShell calling a credential prompt
WindowsPowerShell Script
John Lambert+1Sun Apr 09windows
Detectionhightest
Malicious Base64 Encoded PowerShell Keywords in Command Lines
Detects base64 encoded strings used in hidden malicious PowerShell command lines
WindowsProcess Creation
John LambertWed Jan 16windows
Detectionhightest
Security Service Disabled Via Reg.EXE
Detects execution of "reg.exe" to disable security services such as Windows Defender.
WindowsProcess Creation
Florian Roth (Nextron Systems)+2Wed Jul 14windows
Emerging Threathightest
Malware Shellcode in Verclsid Target Process
Detects a process access to verclsid.exe that injects shellcode from a Microsoft Office application / VBA macro
WindowsProcess Access
John Lambert (tech)+1Sat Mar 042017