Rule Library
Sigma Rules
6 rules found for "Tom Ueltschi"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Adwind RAT / JRAT File Artifact
Detects javaw.exe in AppData folder as used by Adwind / JRAT
WindowsFile Event
Florian Roth (Nextron Systems)+3Fri Nov 10windows
Detectionmediumtest
Potentially Suspicious GrantedAccess Flags On LSASS
Detects process access requests to LSASS process with potentially suspicious access flags
WindowsProcess Access
Florian Roth (Nextron Systems)+9Mon Nov 22windows
Detectionhightest
Potential Persistence Via Logon Scripts - CommandLine
Detects the addition of a new LogonScript to the registry value "UserInitMprLogonScript" for potential persistence
WindowsProcess Creation
Tom UeltschiSat Jan 12windows
Detectionhightest
Uncommon Userinit Child Process
Detects uncommon "userinit.exe" child processes, which could be a sign of uncommon shells or login scripts used for persistence.
WindowsProcess Creation
Tom Ueltschi+1Sat Jan 12windows
Detectionmediumtest
Potential Persistence Via Logon Scripts - Registry
Detects creation of "UserInitMprLogonScript" registry value which can be used as a persistence method by malicious actors
WindowsRegistry Set
Tom UeltschiSat Jan 12windows
Detectionmediumtest
WMI Event Subscription
Detects creation of WMI event subscription persistence method
WindowsWMI Event
Tom UeltschiSat Jan 12windows