Uncommon Child Process Spawned From XBootMgrSleep.EXE:
windowsprocess_creationmedium2026-09-27
Detects a process other than XBootMgr.exe spawned by XBootMgrSleep.exe.
XBootMgrSleep.exe is a Microsoft-signed Windows Performance Toolkit binary that can execute an arbitrary executable after a delay.
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy:
windowsprocess_creationlow2026-08-19
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
New User Account Creation Attempt Via ADSI:
windowsps_scriptmedium2026-08-13
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces)
using either the WinNT or LDAP provider. This is an uncommon method to create user accounts
and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
New User Account Creation Attempt Via ADSI in CommandLine:
windowsprocess_creationmedium2026-08-13
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
Potentially Suspicious Image Load of Offreg.dll:
windowsimage_loadmedium2026-07-23
Detects potentially suspicious loading of the Offline Registry Library (offreg.dll).
Offreg.dll enables direct read/write access to offline registry hives without invoking the Windows Registry API,
bypassing its associated audit logging and telemetry. Attackers may abuse this to stealthily modify registry hives
while evading detection mechanisms that rely on standard registry event logs.
linux latest updates
Process Execution From Shared Memory Directory:
linuxprocess_creationhigh2026-06-20
Detects the execution of a binary from the Linux shared memory directory /dev/shm.
This directory is a tmpfs mount backed entirely by RAM and is abused by attackers for fileless malware staging because files written there never touch physical disk and may evade disk-based detection.
Python One-Liners with Base64 Decoding - Linux:
linuxprocess_creationhigh2026-03-09
Detects the use of Python's base64 decoding functions in command line executions on Linux systems.
Malicious scripts often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.
Linux Setuid Capability Set on a Binary via Setcap Utility:
linuxprocess_creationlow2026-01-24
Detects the use of the 'setcap' utility to set the 'setuid' capability (cap_setuid) on a binary file.
This capability allows a non privileged process to make arbitrary manipulations of user IDs (UIDs), including setting its current UID to a value that would otherwise be restricted (i.e. UID 0, the root user).
This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
Linux Setgid Capability Set on a Binary via Setcap Utility:
linuxprocess_creationlow2026-01-24
Detects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file.
This capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group).
This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
Script Interpreter Spawning Credential Scanner - Linux:
linuxprocess_creationhigh2025-11-25
Detects a script interpreter process (like node.js or bun) spawning a known credential scanning tool (e.g., trufflehog, gitleaks).
This behavior is indicative of an attempt to find and steal secrets, as seen in the "Shai-Hulud: The Second Coming" campaign.
Other latest updates
AWS Bedrock Guardrail Deleted:
awsNULLmedium2026-07-10
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove
model safety controls and allow unsafe or unauthorized model responses.
AWS Bedrock Guardrail Updated:
awsNULLmedium2026-07-10
Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken
model safety controls and allow unsafe or unauthorized model responses.
Antivirus - APT Malware Signature:
NULLantiviruscritical2026-06-15
Detects a highly relevant Antivirus alert that reports APT malware.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Antivirus - Remote Access Tools Signature:
NULLantiviruscritical2026-06-15
Detects a highly relevant Antivirus alert that reports a remote access tool.
This event must not be ignored just because the AV has blocked the malware but investigate, how it came there in the first place.
Google Workspace Out Of Domain Email Forwarding:
gcpNULLmedium2026-04-28
Detects automatic email forwarding to external domains in Google Workspace, which may indicate data leakage or misuse.
Splunk Detection rules latest updates
Windows Multiple Invalid Users Fail To Authenticate Using Kerberos:
endpointEndpointNone
The following analytic identifies a source endpoint failing to authenticate with 30 unique invalid domain users using the Kerberos protocol. This detection leverages EventCode 4768, specifically looking for failure code 0x6, indicating the user is not found in the Kerberos database. This activity is significant as it may indicate a Password Spraying attack, where an adversary attempts to gain initial access or elevate privileges. If confirmed malicious, this could lead to unauthorized access or privilege escalation within the Active Directory environment, posing a significant security risk.
Jscript Execution Using Cscript App:
endpointEndpointNone
The following analytic detects the execution of JScript using the cscript.exe process.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry.
This behavior is significant because JScript files are typically executed by wscript.exe, making cscript.exe execution unusual and potentially indicative of malicious activity, such as the FIN7 group's tactics.
If confirmed malicious, this activity could allow attackers to execute arbitrary scripts, leading to code execution, data exfiltration, or further system compromise.
XSL Script Execution With WMIC:
endpointEndpointNone
The following analytic detects the execution of an XSL script using the WMIC process, which is often indicative of malicious activity. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions involving WMIC and XSL files. This behavior is significant as it has been associated with the FIN7 group, known for using this technique to execute malicious scripts. If confirmed malicious, this activity could allow attackers to execute arbitrary code, potentially leading to system compromise and further malicious actions within the environment.
Windows Screen Capture in TEMP folder:
endpointEndpointNone
The following analytic detects the creation of screen capture files by the Braodo stealer malware. This stealer is known to capture screenshots of the victim's desktop as part of its data theft activities. The detection focuses on identifying unusual screen capture activity, especially when images are saved in directories often used by malware, such as temporary or hidden folders. Monitoring for these files helps to quickly identify malicious screen capture attempts, allowing security teams to respond and mitigate potential information exposure before sensitive data is compromised.
Linux Binary Launched Process with Null Argv:
endpointEndpointNone
The following analytic detects kernel-level events where a setuid binary launches a shell or interpreter with a NULL argument vector, which occurs when a privilege escalation exploit gains root and executes a process via execve() without constructing a legitimate argument array.
O365 Threat Intelligence Suspicious File Detected:
threatO365 TenantNone
The following analytic identifies when a malicious file is detected within the Microsoft Office 365 ecosystem through the Advanced Threat Protection engine. Attackers may stage and execute malicious files from within the Microsoft Office 365 ecosystem. Any detections from built-in Office 365 capabilities should be monitored and responded to appropriately. Certain premium Office 365 capabilities such as Safe Attachment and Safe Links further enhance these detection and response functions.
Windows Registry Delete Task SD:
endpointEndpointNone
The following analytic detects a process attempting to delete a scheduled task's Security Descriptor (SD) from the registry path of that task.
It leverages the Endpoint.Registry data model to identify registry actions performed by the SYSTEM user, specifically targeting deletions of the SD value.
This activity is significant as it may indicate an attempt to remove evidence of a scheduled task for defense evasion.
If confirmed malicious, it suggests an attacker with privileged access trying to hide their tracks, potentially compromising system integrity and security.
ASL AWS EC2 Snapshot Shared Externally:
threatEC2 SnapshotNone
The following analytic detects when an EC2 snapshot is shared publicly by analyzing AWS CloudTrail events. This detection method leverages CloudTrail logs to identify modifications in snapshot permissions, specifically when the snapshot is shared outside the originating AWS account. This activity is significant as it may indicate an attempt to exfiltrate sensitive data stored in the snapshot. If confirmed malicious, an attacker could gain unauthorized access to the snapshot's data, potentially leading to data breaches or further exploitation of the compromised information.
Windows RDP Login Session Was Established:
endpointEndpointNone
The following analytic detects instances where a successful Remote Desktop Protocol (RDP) login session was established, as indicated by Windows Security Event ID 4624 with Logon Type 10. This event confirms that a user has not only provided valid credentials but has also initiated a full interactive RDP session. It is a key indicator of successful remote access to a Windows system. When correlated with Event ID 1149, which logs RDP authentication success, this analytic helps distinguish between mere credential acceptance and actual session establishment—critical for effective monitoring and threat detection.
Windows UAC Bypass Suspicious Escalation Behavior:
endpointEndpointNone
The following analytic detects when a process spawns an executable known for User Account Control (UAC) bypass exploitation and subsequently monitors for any child processes with a higher integrity level than the original process.
This detection leverages Sysmon EventID 1 data, focusing on process integrity levels and known UAC bypass executables.
This activity is significant as it may indicate an attacker has successfully used a UAC bypass exploit to escalate privileges.
If confirmed malicious, the attacker could gain elevated privileges, potentially leading to further system compromise and persistent access.
Windows AD AdminSDHolder ACL Modified:
endpointEndpointNone
The following analytic detects modifications to the Access Control List (ACL) of the AdminSDHolder object in a Windows domain, specifically the addition of new rules. It leverages EventCode 5136 from the Security Event Log, focusing on changes to the nTSecurityDescriptor attribute. This activity is significant because the AdminSDHolder object secures privileged group members, and unauthorized changes can allow attackers to establish persistence and escalate privileges. If confirmed malicious, this could enable an attacker to control domain-level permissions, compromising the entire Active Directory environment.
Python PYTHONPATH Modification During Package Installation:
endpointEndpointNone
The following analytic detects modification of the PYTHONPATH environment variable in conjunction with a package installation process.
Python looks up the `sys.path` variable, which is generated by combining user and site folders with `.pth` files and the value of the PYTHONPATH environment variable, to determine which directories to use for importing modules.
If an adversary is able to control the value of PYTHONPATH, they can point it to an attacker-controlled directory and hijack imported packages, achieving user-level persistence across future Python invocations and new shell sessions.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked by the affected user.
Linux Gem Privilege Escalation:
endpointEndpointNone
The following analytic detects the execution of the RubyGems utility with elevated privileges, specifically when it is used to run system commands as root. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions that include "gem open -e" and "sudo". This activity is significant because it indicates a potential privilege escalation attempt, allowing a user to execute commands as the root user. If confirmed malicious, this could lead to full system compromise, enabling the attacker to gain root access and execute arbitrary commands with elevated privileges.
MacOS Osascript Executing Interactive Shell:
endpointEndpointNone
This analytic detects the macOS osascript utility being used with an interactive Bash invocation, identified by the presence
of "bash -i" in the command line.
Adversaries may abuse osascript and AppleScript's shell execution capabilities to launch
interactive shells, establish remote access, or execute post-exploitation commands.
Windows PowerSploit GPP Discovery:
endpointEndpointNone
The following analytic detects the execution of the Get-GPPPassword PowerShell cmdlet, which is used to search for unsecured credentials in Group Policy Preferences (GPP). This detection leverages PowerShell Script Block Logging to identify specific script block text associated with this cmdlet. Monitoring this activity is crucial as it can indicate an attempt to retrieve and decrypt stored credentials from SYSVOL, potentially leading to unauthorized access. If confirmed malicious, this activity could allow an attacker to escalate privileges or move laterally within the network by exploiting exposed credentials.