Rule Library
Sigma Rules
3 rules found for "Tim Burrell"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Suspicious Svchost Process Access
Detects suspicious access to the "svchost" process such as that used by Invoke-Phantom to kill the thread of the Windows event logging service.
WindowsProcess Access
Tim BurrellThu Jan 02windows
Emerging Threathightest
GALLIUM IOCs
Detects artifacts associated with GALLIUM cyber espionage group as reported by Microsoft Threat Intelligence Center in the December 2019 report.
WindowsProcess Creation
Tim BurrellFri Feb 072020
Emerging Threathightest
GALLIUM Artefacts - Builtin
Detects artefacts associated with activity group GALLIUM - Microsoft Threat Intelligence Center indicators released in December 2019.
Windowsdns-server-analytic
Tim BurrellFri Feb 072020