Rule Library
Sigma Rules
5 rules found for "Tony Lambert)"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
Modification of ld.so.preload
Identifies modification of ld.so.preload for shared object injection. This technique is used by attackers to load arbitrary code into processes.
Linuxauditd
E.M. Anhaus (originally from Atomic Blue Detections+2Thu Oct 24linux
Detectionmediumtest
Domain Trust Discovery Via Dsquery
Detects execution of "dsquery.exe" for domain trust discovery
WindowsProcess Creation
E.M. Anhaus+3Thu Oct 24windows
Detectionhightest
LSASS Dump Keyword In CommandLine
Detects the presence of the keywords "lsass" and ".dmp" in the commandline, which could indicate a potential attempt to dump or create a dump of the lsass process.
WindowsProcess Creation
E.M. Anhaus+3Thu Oct 24windows
Detectionhightest
Bypass UAC via Fodhelper.exe
Identifies use of Fodhelper.exe to bypass User Account Control. Adversaries use this technique to execute privileged processes.
WindowsProcess Creation
E.M. Anhaus (originally from Atomic Blue Detections+2Thu Oct 24windows
Detectionhightest
Bypass UAC via WSReset.exe
Detects use of WSReset.exe to bypass User Account Control (UAC). Adversaries use this technique to execute privileged processes.
WindowsProcess Creation
E.M. Anhaus (originally from Atomic Blue Detections+3Thu Oct 24windows