Rule Library
Sigma Rules
6 rules found for "Vasiliy Burov"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhightest
HackTool - Hydra Password Bruteforce Execution
Detects command line parameters used by Hydra password guessing hack tool
WindowsProcess Creation
Vasiliy BurovMon Oct 05windows
Detectionmediumtest
ConvertTo-SecureString Cmdlet Usage Via CommandLine
Detects usage of the "ConvertTo-SecureString" cmdlet via the commandline. Which is fairly uncommon and could indicate potential suspicious activity
WindowsProcess Creation
Teymur Kheirkhabarov+3Sun Oct 11windows
Detectionhightest
Potential PowerShell Obfuscation Via Reversed Commands
Detects the presence of reversed PowerShell commands in the CommandLine. This is often used as a method of obfuscation by attackers
WindowsProcess Creation
Teymur Kheirkhabarov+3Sun Oct 11windows
Detectionhightest
Potential PowerShell Command Line Obfuscation
Detects the PowerShell command lines with special characters
WindowsProcess Creation
Teymur Kheirkhabarov+3Thu Oct 15windows
Detectionlowtest
Potential Encoded PowerShell Patterns In CommandLine
Detects specific combinations of encoding methods in PowerShell via the commandline
WindowsProcess Creation
Teymur Kheirkhabarov+3Sun Oct 11windows
Detectionmediumtest
Suspicious XOR Encoded PowerShell Command
Detects presence of a potentially xor encoded powershell command
WindowsProcess Creation
Sami Ruohonen+6Wed Sep 05windows