Rule Library
Sigma Rules
3 rules found for "Subhash Popuri"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Path Traversal Exploitation Attempts
Detects path traversal exploitation attempts
Web Server Log
Subhash Popuri+3Sat Sep 25web
Detectionhightest
HackTool - Powerup Write Hijack DLL
Powerup tool's Write Hijack DLL exploits DLL hijacking for privilege escalation. In it's default mode, it builds a self deleting .bat file which executes malicious command. The detection rule relies on creation of the malicious bat file (debug.bat by default).
WindowsFile Event
Subhash PopuriSat Aug 21windows
Detectionhightest
Potential DLL Sideloading Via comctl32.dll
Detects potential DLL sideloading using comctl32.dll to obtain system privileges
WindowsImage Load (DLL)
Nasreddine Bencherchali (Nextron Systems)+1Fri Dec 16windows