Detection Rule List

Rule Name Rule Type Technique Count Creation Date
Detect FreeLibrary Unhooking CAPA 1 3 years
Detect Hook Injection 2 CAPA 0 3 years, 3 months
Detect Hook Injection CAPA 0 3 years, 3 months
Detect Confuser CAPA 1 3 years, 9 months
Detect VMProtect CAPA 1 3 years, 9 months
Detect Petite Packer CAPA 1 3 years, 9 months
Detect Themida Packer CAPA 1 3 years, 9 months
Detect PECompact Packer CAPA 1 3 years, 9 months
Detect NSpack Packer CAPA 1 3 years, 9 months
ASPack Packer Detection CAPA 1 3 years, 9 months
UPX Packer Detection CAPA 1 3 years, 9 months
Detect QEMU CAPA 0 3 years, 9 months
Check Sandbox Process CAPA 1 3 years, 9 months
Detect File Melt CAPA 1 3 years, 9 months
Detect Timestomp CAPA 1 3 years, 9 months
Detect FileVersion Impersonation CAPA 1 3 years, 9 months
Detect PPID Spoofing CAPA 1 3 years, 9 months
Check ICEBP CAPA 1 3 years, 9 months
Detect NtQueryInformation Usage CAPA 1 3 years, 9 months
Detect Trap Flag Exception CAPA 1 3 years, 9 months
Detect Software Breakpoint CAPA 1 3 years, 9 months
Detect Debuggers via API's CAPA 1 3 years, 9 months
Detect Hardware Breakpoints CAPA 1 3 years, 9 months
Detect Windows Event Logging Crashing Attempt CAPA 2 3 years, 9 months
Detect Windows Log Clearing CAPA 1 3 years, 9 months
Detect Timestomp 2 CAPA 0 3 years, 9 months
Detect OutputDebugString Error CAPA 1 3 years, 9 months
Detect QueryPerformanceCounter Usage CAPA 1 3 years, 9 months
Detect Sandbox via Device Name (Pipe) CAPA 0 3 years, 9 months
Detect Container Execution Agent via Process Name CAPA 2 3 years, 9 months
Filter