Rule Library
Sigma Rules
2 rules found for "Kaspersky Lab"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Kavremover Dropped Binary LOLBIN Usage
Detects the execution of a signed binary dropped by Kaspersky Lab Products Remover (kavremover) which can be abused as a LOLBIN to execute arbitrary commands and binaries.
WindowsProcess Creation
Nasreddine Bencherchali (Nextron Systems)Tue Nov 01windows
Detectionhightest
Run PowerShell Script from ADS
Detects PowerShell script execution from Alternate Data Stream (ADS)
WindowsProcess Creation
Sergey Soldatov+2Wed Oct 30windows