Detection Rule List

Rule Name Rule Type Technique Count Creation Date
Detect OutputDebugString Error CAPA 1 4 years, 1 month
Detect QueryPerformanceCounter Usage CAPA 1 4 years, 1 month
Detect Sandbox via Device Name (Pipe) CAPA 0 4 years, 1 month
Detect Container Execution Agent via Process Name CAPA 2 4 years, 1 month
Detect Obfuscated Stack Strings CAPA 0 4 years, 1 month
Detect GetCursorPos Usage CAPA 1 4 years, 1 month
Detect PEB NtGlobalFlag Check CAPA 1 4 years, 1 month
Detect PEB BeingDebugged Flag CAPA 1 4 years, 1 month
Detect GetTickCount Usage CAPA 1 4 years, 1 month
Detect VM Instructions CAPA 0 4 years, 1 month
Detect VM Artifacts 2 CAPA 1 4 years, 1 month
Detect Windows Sandbox via Registry CAPA 1 4 years, 1 month
Detect LocalSize Usage CAPA 1 4 years, 1 month
Detect VM Artifacts CAPA 1 4 years, 1 month
Detect SetHandleInformation Usage CAPA 1 4 years, 1 month
Detect Process Enumeration CAPA 1 4 years, 1 month
Detect Sandbox And Antivirus Software CAPA 1 4 years, 1 month
Delete Volume Shadow Copy CAPA 1 4 years, 1 month
Detect Sandbox Check via User Account CAPA 1 4 years, 1 month
Detect Resize Volume Shadow Copy Usage CAPA 0 4 years, 1 month
Detect WAN Discovery via IPIFY.ORG SIGMA 0 4 years, 1 month
Detect VBox, VMWare, KVM and HVM SIGMA 0 4 years, 1 month
Detect Stop Multiple Services (via net.exe) SIGMA 0 4 years, 1 month
Detect Certain UAC Bypass Techniques SIGMA 1 4 years, 1 month
Detect Certain Lolbins Techniques SIGMA 0 4 years, 1 month
Detect Shadow Copy Delete via PowerShell SIGMA 1 4 years, 1 month
Detect Shadow Copy Delete via System Utilities Through PowerShell SIGMA 1 4 years, 1 month
Detect Taskkill Usage SIGMA 1 4 years, 1 month
Detect Shadow Copy Deletion via System Utilities SIGMA 1 4 years, 1 month
Detect Process Re-Imaging SIGMA 0 4 years, 1 month
Filter