| Impacket Lateral Movement Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.002 T1021.003 |
| Impacket Lateral Movement smbexec CommandLine Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.002 T1021.003 |
| Impacket Lateral Movement WMIExec Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.002 T1021.003 |
| Interactive Session on Remote Endpoint with PowerShell | TTP | NULL | Powershell Script Block Logging 4104 | T1021.006 |
| Linux SSH Remote Services Script Execute | TTP | NULL | Sysmon for Linux EventID 1 | T1021.004 |
| Microsoft Intune Device Health Scripts | Hunting | NULL | Azure Monitor Activity | T1021.007 |
| Microsoft Intune DeviceManagementConfigurationPolicies | Hunting | NULL | Azure Monitor Activity | T1021.007 |
| Microsoft Intune Manual Device Management | Hunting | NULL | Azure Monitor Activity | T1021.007 |
| Microsoft Intune Mobile Apps | Hunting | NULL | Azure Monitor Activity | T1021.007 |
| Mmc LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.003 |
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1021.003 T1021.006 |
| Powershell Remote Services Add TrustedHost | TTP | NULL | Powershell Script Block Logging 4104 | T1021.006 |
| Remote Desktop Network Traffic | Anomaly | NULL | Zeek Conn | T1021.001 |
| Remote Desktop Process Running On System | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.001 |
| Remote Process Instantiation via DCOM and PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.003 |
| Remote Process Instantiation via DCOM and PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 | T1021.003 |
| Remote Process Instantiation via WinRM and PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.006 |
| Remote Process Instantiation via WinRM and PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 | T1021.006 |
| Remote Process Instantiation via WinRM and Winrs | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.006 |
| SMB Traffic Spike | Anomaly | NULL | | T1021.002 |
| SMB Traffic Spike - MLTK | Anomaly | NULL | | T1021.002 |
| Windows Alternate Data Stream Created Over Local Share | Anomaly | NULL | Windows Event Log Security 5145 | T1021.002 |
| Windows Azure PowerShell Module Installation Via PowerShell Script | Anomaly | NULL | Powershell Script Block Logging 4104 | T1021.007 |
| Windows Default RDP File Creation | Anomaly | NULL | Sysmon EventID 11 | T1021.001 |
| Windows Default RDP File Creation By Non MSTSC Process | Anomaly | NULL | Sysmon EventID 1 AND Sysmon EventID 11 | T1021.001 |
| Windows Default Rdp File Unhidden | Anomaly | NULL | Sysmon EventID 1 | T1021.001 |
| Windows Excel ActiveMicrosoftApp Child Process | Anomaly | NULL | Sysmon EventID 1 | T1021.003 |
| Windows Excel Spawning Microsoft Project Application | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.003 |
| Windows MSTSC RDP Commandline | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.001 |
| Windows Process Execution From RDP Share | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.001 |
| Windows Protocol Tunneling with Plink | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.004 |
| Windows PUA Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1021.002 |
| Windows PuTTY Suite Utility Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.004 |
| Windows RDP Bitmap Cache File Creation | Anomaly | NULL | Sysmon EventID 11 | T1021.001 |
| Windows RDP Client Launched with Admin Session | Anomaly | NULL | Sysmon EventID 1 | T1021.001 |
| Windows RDP File Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.001 |
| Windows RDP Login Session Was Established | Anomaly | NULL | Windows Event Log Security 4624 | T1021.001 |
| Windows RDP Server Registry Entry Created | Anomaly | NULL | Sysmon EventID 13 | T1021.001 |
| Windows Remote Host Computer Management Access | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1021.006 |
| Windows Remote Management Execute Shell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1021.006 |
| Windows Remote Service Rdpwinst Tool Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.001 |
| Windows Remote Services Allow Rdp In Firewall | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.001 |
| Windows Remote Services Allow Remote Assistance | Anomaly | NULL | Sysmon EventID 13 | T1021.001 |
| Windows Remote Services Rdp Enable | TTP | NULL | Sysmon EventID 13 | T1021.001 |
| Windows RMM Named Pipe | Anomaly | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1021.002 |
| Windows Special Privileged Logon On Multiple Hosts | TTP | NULL | Windows Event Log Security 4672 | T1021.002 |
| Windows SpeechRuntime COM Hijacking DLL Load | TTP | NULL | Sysmon EventID 7 | T1021.003 |
| Windows SpeechRuntime Suspicious Child Process | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.003 |
| Windows Suspicious C2 Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1021.002 |
| Windows Suspicious Named Pipe | TTP | NULL | Sysmon EventID 17, Sysmon EventID 18 | T1021.002 |
| Windows Theme File Creation in Unusual Location | Anomaly | NULL | Sysmon EventID 11 | T1021.002 |
| Wsmprovhost LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1021.006 |