Windows Detection Rules | Fibratus
Fibratus detection rules for Windows. Runtime behavior-driven detection mapped to MITRE ATT&CK.
Rules in this category
- File access to SAM database
- Credential Manager access via known tools
- LSASS access from unsigned executable
- LSASS handle leak via Seclogon
- LSASS memory dump preparation via SilentProcessExit
- LSASS memory dump via MiniDumpWriteDump
- LSASS memory dump via Windows Error Reporting
- LSASS process clone creation via reflection
- Potential LSASS memory dump
- Potential NTLM hash leak via MS Photos
- Potential NTLM hash leak via shortcut file
- Registry access to SAM database
- Remote thread creation into LSASS
- Sensitive registry hive dump
- Suspicious access to Active Directory domain database
- Suspicious access to Unattended Panther files
- Suspicious access to Windows DPAPI Master Keys
- Suspicious access to Windows Credential Manager files
- Suspicious access to Windows Vault files
- Suspicious LSA secrets registry access
- Suspicious LSASS process access
- Suspicious security package DLL loaded
- Suspicious Vault client DLL load
- Unusual access to SSH keys
- Unusual access to Web Browser Credential stores
- Unusual access to Windows Credential history files
- Activation Context memory section hijacking
- Activity from unhooked NTDLL module
- AppDomain Manager injection via CLR search order hijacking
- BindFlt DLL loaded by an unusual process
- CldApi DLL loaded by an unusual process
- Clear Eventlog
- Direct disk device access
- DLL loaded via APC queue
- DLL loaded via a callback function
- DLL loaded via LdrpKernel32 overwrite
- DLL Side-Loading via a copied binary
- DLL Side-Loading via Microsoft Office dropped file
- .NET assembly loaded by unmanaged process
- Hidden registry key creation
- Image load via NTFS transaction
- Potential injection via .NET debugging
- Potential NTDLL unhooking via file mapping
- Potential operation evasion via direct syscall
- Potential process creation via shellcode
- Potential process injection via tainted memory section
- Potential shellcode execution via ETW logger thread
- Potential shellcode injection via Windows Debugging API
- Potential thread execution hijacking
- Process creation from a stomped module
- Process creation via direct syscall
- Process creation via NTFS transaction
- Process execution from hollowed memory section
- Process execution from remote memory section
- Process execution from a self-deleting binary
- Process spawned from unusual directory
- Process spawned via remote thread
- Regsvr32 scriptlet execution
- Suspicious access to the hosts file
- Suspicious activity from a reflected process
- Suspicious child spawned via reflected process
- Suspicious DLL loaded via memory section mapping
- Suspicious HTML Application script execution
- Suspicious object symbolic link creation
- Suspicious protected process execution
- Suspicious virtual path redirection via bind filter
- Suspicious Windows Defender exclusions registry modification
- Suspicious XSL script execution
- System Binary Proxy Execution via Rundll32
- Thread context manipulation from exception handler
- Thread context set from unbacked memory
- Unsigned DLL injection via remote thread
- Untrusted DLL loaded from unusual directory
- Windows Defender driver unloading
- Windows Defender protection tampering via registry
- Embedded executable file run via shortcut
- Embedded script execution via shortcut file
- Process execution from compressed file via Explorer
- Suspicious MSHTA execution via HTML smuggling
- Suspicious process execution from archive via shortcut file
- Clickfix phishing via browser dialog box
- Executable file creation from a macro-enabled Microsoft Office document
- Execution via Microsoft Office process
- Macro execution via script interpreter
- Microsoft Office file execution via script interpreter
- Microsoft Office file execution via WMI
- Potential ClickFix infection chain
- Process spawned from macro-enabled Microsoft Office document
- Suspicious DLL loaded by Microsoft Office process
- Suspicious execution via WMI from a Microsoft Office process
- Suspicious file delivery via HTML smuggling
- Suspicious Microsoft Office embedded object
- DLL loading of a file transferred over SMB
- Execution of a file transferred over SMB
- Executable file dropped by an unsigned service DLL
- Hidden local account creation
- Network connection via startup folder executable or script
- Potential mandatory profile registry persistence
- Potential port monitor or print processor persistence via registry modification
- RID Hijacking
- Script interpreter host or untrusted process persistence
- Suspicious Microsoft Office add-in loaded
- Suspicious Microsoft Office template
- Suspicious Netsh Helper DLL execution
- Suspicious persistence via registry modification
- Suspicious port monitor loaded
- Suspicious print processor loaded
- Suspicious Startup shell folder modification
- Unusual file written in Startup folder
- Unusual process modified registry run key
- Exploitation via Common Log File System
- Fake system root directory creation
- Fake system root environment variable manipulation
- Potential privilege elevation via arbitrary section creation
- Potential privilege escalation via DeadPotato exploit
- Potential privilege escalation via elevated IFileOperation COM interface
- Potential privilege escalation via phantom DLL hijacking
- Suspicious child process integrity level
- Suspicious registry symbolic link creation
- UAC bypass via assembly Native Image Cache hijack
- UAC bypass via CDSSync scheduled task hijack
- UAC bypass via command handler hijacking
- UAC bypass via Control Panel applet execution hijack
- UAC bypass via DiskCleanup scheduled task hijack
- UAC bypass via DLL hijack from Windows Media player directory
- UAC bypass via .NET Code Profiler DLL Hijack
- UAC bypass via elevated Internet Explorer add-on installer COM interface
- UAC bypass via ICMLuaUtil COM interface
- UAC bypass via NTFS junction DLL hijacking
- UAC bypass via Program Compatibility Assistant scheduled task hijack
- UAC bypass via RequestTrace scheduled task hijack
- UAC bypass via rouge MMC snap-in
- UAC bypass via trusted Windows directory masquerading
- Untrusted DLL loaded from masqueraded Windows directory