Rule Library
Sigma Rules
3 rules found for "Michael Haag"
3,731Total
3,132Detection
457Emerging
139Hunting
Threat Huntlowexperimental
Successful MSIX/AppX Package Installation
Detects successful MSIX/AppX package installations on Windows systems by monitoring EventID 854 in the Microsoft-Windows-AppXDeployment-Server/Operational log. While most installations are legitimate, this can help identify unauthorized or suspicious package installations. It is crucial to monitor such events as threat actors may exploit MSIX/AppX packages to deliver and execute malicious payloads.
Windowsappxdeployment-server
Michael Haag+1Mon Nov 03windows
Threat Huntlowtest
Net.EXE Execution
Detects execution of "Net.EXE".
WindowsProcess Creation
Michael Haag+2Wed Jan 16windows
Threat Huntmediumtest
WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Detects script file execution (.js, .jse, .vba, .vbe, .vbs, .wsf, .wsh) by Wscript/Cscript.
WindowsProcess Creation
Michael HaagWed Jan 16windows