Rule Library
Sigma Rules
5 rules found for "Tim Shelton"
3,731Total
3,132Detection
457Emerging
139Hunting
Emerging Threatmediumtest
Potential APT-C-12 BlueMushroom DLL Load Activity Via Regsvr32
Detects potential BlueMushroom DLL loading activity via regsvr32 from AppData Local
WindowsProcess Creation
Florian Roth (Nextron Systems)+2Wed Oct 022019
Emerging Threatcriticaltest
CVE-2020-10148 SolarWinds Orion API Auth Bypass
Detects CVE-2020-10148 SolarWinds Orion API authentication bypass attempts
Web Server Log
Bhabesh Raj+1Sun Dec 272020
Emerging Threatcriticalstable
Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection
Detects the suspicious file that is created from PoC code against Windows Print Spooler Remote Code Execution Vulnerability CVE-2021-34527 (PrinterNightmare), CVE-2021-1675 .
Antivirus Alert
Sittikorn S+2Thu Jul 012021
Emerging Threathightest
Possible CVE-2021-1675 Print Spooler Exploitation
Detects events of driver load errors in print service logs that could be a sign of successful exploitation attempts of print spooler vulnerability CVE-2021-1675
Windowsprintservice-admin
Florian Roth (Nextron Systems)+3Wed Jun 302021
Emerging Threathightest
Suspicious Sysmon as Execution Parent
Detects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)
WindowsProcess Creation
Florian Roth (Nextron Systems)+1Thu Nov 102022