Rule Library
Sigma Rules
5 rules found for "Olaf Hartong"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
HackTool - Potential CobaltStrike Process Injection
Detects a potential remote threat creation with certain characteristics which are typical for Cobalt Strike beacons
WindowsRemote Thread Creation
Olaf Hartong+3Fri Nov 30windows
Detectionhightest
Suspicious DotNET CLR Usage Log Artifact
Detects the creation of Usage Log files by the CLR (clr.dll). These files are named after the executing process once the assembly is finished executing for the first time in the (user) session context.
WindowsFile Event
François Hubaut+3Fri Nov 18windows
Detectionhightest
Sysmon Blocked Executable
Triggers on any Sysmon "FileBlockExecutable" event, which indicates a violation of the configured block policy
Windowssysmon
Nasreddine Bencherchali (Nextron Systems)Tue Aug 16windows
Detectionmediumtest
Sysmon File Executable Creation Detected
Triggers on any Sysmon "FileExecutableDetected" event, which triggers every time a PE that is monitored by the config is created.
Windowssysmon
François HubautThu Jul 20windows
Emerging Threathightest
Potential BearLPE Exploitation
Detects potential exploitation of the BearLPE exploit using Task Scheduler ".job" import arbitrary DACL write\par
WindowsProcess Creation
Olaf HartongWed May 222019