Rule Library
Sigma Rules
3 rules found for "John Lambert"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
PowerShell Credential Prompt
Detects PowerShell calling a credential prompt
WindowsPowerShell Script
John Lambert+1Sun Apr 09windows
Detectionhightest
Malicious Base64 Encoded PowerShell Keywords in Command Lines
Detects base64 encoded strings used in hidden malicious PowerShell command lines
WindowsProcess Creation
John LambertWed Jan 16windows
Detectionhightest
Security Service Disabled Via Reg.EXE
Detects execution of "reg.exe" to disable security services such as Windows Defender.
WindowsProcess Creation
Florian Roth (Nextron Systems)+2Wed Jul 14windows