Rule Library
Sigma Rules
2 rules found for "Tim Shelton"
3,731Total
3,132Detection
457Emerging
139Hunting
Threat Huntlowtest
Scheduled Task Deletion
Detects scheduled task deletion events. Scheduled tasks are likely to be deleted if not used for persistence. Malicious Software often creates tasks directly under the root node e.g. \TASKNAME
Windowssecurity
David Strassegger+1Fri Jan 22windows
Threat Huntmediumtest
Potentially Suspicious PowerShell Child Processes
Detects potentially suspicious child processes spawned by PowerShell. Use this rule to hunt for potential anomalies initiating from PowerShell scripts and commands.
WindowsProcess Creation
Florian Roth (Nextron Systems)+1Tue Apr 26windows