Rule Library
Sigma Rules
2 rules found for "yxinmiracle"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionhighexperimental
Suspicious Uninstall of Windows Defender Feature via PowerShell
Detects the use of PowerShell with Uninstall-WindowsFeature or Remove-WindowsFeature cmdlets to disable or remove the Windows Defender GUI feature, a common technique used by adversaries to evade defenses.
WindowsProcess Creation
yxinmiracleFri Aug 22windows
Emerging Threathighexperimental
Grixba Malware Reconnaissance Activity
Detects execution of the Grixba reconnaissance tool based on suspicious command-line parameter combinations. This tool is used by the Play ransomware group for network enumeration, data gathering, and event log clearing.
WindowsProcess Creation
yxinmiracle+1Wed Nov 262025