Rule Library
Sigma Rules
2 rules found for "Kutepov Anton"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
New Network Trace Capture Started Via Netsh.EXE
Detects the execution of netsh with the "trace" flag in order to start a network capture
WindowsProcess Creation
Kutepov Anton+1Thu Oct 24windows
Detectionmediumtest
Potential COM Object Hijacking Via TreatAs Subkey - Registry
Detects COM object hijacking via TreatAs subkey
WindowsRegistry Set
Kutepov Anton+1Wed Oct 23windows