Detection Rule List

Rule Name Rule Type Technique Count Creation Date
CAPA_device_pipe CAPA 0 2 years, 4 months
CAPA_detect_vm_process CAPA 2 2 years, 4 months
CAPA_stackstring_obf CAPA 0 2 years, 4 months
CAPA_mouse_cursor CAPA 1 2 years, 4 months
CAPA_ntglobalflag CAPA 1 2 years, 4 months
CAPA_debugged_flag CAPA 1 2 years, 4 months
CAPA_gettickcount CAPA 1 2 years, 4 months
CAPA_vm_instruction CAPA 0 2 years, 4 months
CAPA_vm_artefact2 CAPA 1 2 years, 4 months
CAPA_vm_registry CAPA 1 2 years, 4 months
CAPA_localsize CAPA 1 2 years, 4 months
CAPA_vm_artefact CAPA 1 2 years, 4 months
CAPA_SetHandleInformation CAPA 1 2 years, 4 months
CAPA_kill_process CAPA 1 2 years, 4 months
CAPA_SANBOX_AV_CHECK CAPA 1 2 years, 4 months
CAPA_Delete_Volume_Shadow_Copy CAPA 1 2 years, 4 months
CAPA_sandbox_name CAPA 1 2 years, 4 months
CAPA_resize_volume_shadow_copy_storage CAPA 0 2 years, 4 months
SIGMA_check_external_ip SIGMA 0 2 years, 4 months
SIGMA_ANTI_VM SIGMA 0 2 years, 4 months
SIGMA_stop_service SIGMA 0 2 years, 4 months
SIGMA_uac_bypass SIGMA 1 2 years, 4 months
SIGMA_lolbins SIGMA 0 2 years, 4 months
SIGMA_delete_shadow_copy SIGMA 1 2 years, 4 months
SIGMA_posh_pc_delete_volume_shadow_copies SIGMA 1 2 years, 4 months
SIGMA_kill_process SIGMA 1 2 years, 4 months
SIGMA_proc_creation_win_shadow_copies_deletion SIGMA 1 2 years, 4 months
SIGMA_process_reimaging SIGMA 0 2 years, 4 months
SIGMA_decode_string_findstr SIGMA 0 2 years, 4 months
SIGMA_onset_delay SIGMA 0 2 years, 4 months

Filter