Rule Library
Sigma Rules
4 rules found for "Kirill Kiryanov"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Sysmon Driver Unloaded Via Fltmc.EXE
Detects possible Sysmon filter driver unloaded via fltmc.exe
WindowsProcess Creation
Kirill Kiryanov+1Wed Oct 23windows
Detectionmediumtest
Dumping Process via Sqldumper.exe
Detects process dump via legitimate sqldumper.exe binary
WindowsProcess Creation
Kirill Kiryanov+1Thu Oct 08windows
Detectionmediumtest
New DLL Registered Via Odbcconf.EXE
Detects execution of "odbcconf" with "REGSVR" in order to register a new DLL (equivalent to running regsvr32). Attackers abuse this to install and run malicious DLLs.
WindowsProcess Creation
Kirill Kiryanov+4Mon May 22windows
Detectionmediumtest
Response File Execution Via Odbcconf.EXE
Detects execution of "odbcconf" with the "-f" flag in order to load a response file which might contain a malicious action.
WindowsProcess Creation
Kirill Kiryanov+4Mon May 22windows