Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Jscript Execution Using Cscript App
id: 002f1e24-146e-11ec-a470-acde48001122
version: 14
version: 15
creation_date: '2021-09-14'
modification_date: '2026-08-31'
author: Teoderick Contreras, Splunk
Expand All @@ -13,7 +13,6 @@ description: |-
If confirmed malicious, this activity could allow attackers to execute arbitrary scripts, leading to code execution, data exfiltration, or further system compromise.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
3 changes: 1 addition & 2 deletions detections/endpoint/ping_sleep_batch_command.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Ping Sleep Batch Command
id: ce058d6c-79f2-11ec-b476-acde48001122
version: 17
version: 18
creation_date: '2022-01-20'
modification_date: '2026-08-11'
author: Teoderick Contreras, Splunk
Expand All @@ -14,7 +14,6 @@ description: |-
Because ping is commonly used for legitimate network troubleshooting, findings should be reviewed in the context of the complete command line, parent process, user, and commands executed before or after the delay.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Possible Lateral Movement PowerShell Spawn
id: cb909b3e-512b-11ec-aa31-3e22fbd008af
version: 17
version: 18
creation_date: '2021-11-29'
modification_date: '2026-05-13'
author: Mauricio Velazco, Michael Haag, Splunk
Expand All @@ -13,7 +13,6 @@ description: |
If confirmed malicious, this behavior could allow attackers to execute code remotely, escalate privileges, or persist within the environment.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Svchost LOLBAS Execution Process Spawn
id: 09e5c72a-4c0d-11ec-aa29-3e22fbd008af
version: 15
version: 16
creation_date: '2021-11-23'
modification_date: '2026-07-27'
author: Mauricio Velazco, Splunk
Expand All @@ -11,7 +11,6 @@ description: |-
If confirmed malicious, this behavior could allow attackers to execute arbitrary commands, escalate privileges, or maintain persistence within the environment, posing a significant security risk.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Vbscript Execution Using Wscript App
id: 35159940-228f-11ec-8a49-acde48001122
version: 13
version: 14
creation_date: '2021-09-14'
modification_date: '2026-05-13'
author: Teoderick Contreras, Splunk
Expand All @@ -9,7 +9,6 @@ type: TTP
description: The following analytic detects the execution of VBScript using the wscript.exe application. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and command-line telemetry. This activity is significant because wscript.exe is typically not used to execute VBScript, which is usually associated with cscript.exe. This deviation can indicate an attempt to evade traditional process monitoring and antivirus defenses. If confirmed malicious, this technique could allow attackers to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes
WHERE (
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows Command Shell DCRat ForkBomb Payload
id: 2bb1a362-7aa8-444a-92ed-1987e8da83e1
version: 14
version: 15
creation_date: '2022-07-28'
modification_date: '2026-05-13'
author: Teoderick Contreras, Splunk
Expand All @@ -9,7 +9,6 @@ type: TTP
description: The following analytic detects the execution of a DCRat "forkbomb" payload, which spawns multiple cmd.exe processes that launch notepad.exe instances in quick succession. This detection leverages Endpoint Detection and Response (EDR) data, focusing on the rapid creation of cmd.exe and notepad.exe processes within a 30-second window. This activity is significant as it indicates a potential DCRat infection, a known Remote Access Trojan (RAT) with destructive capabilities. If confirmed malicious, this behavior could lead to system instability, resource exhaustion, and potential disruption of services.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly` values(Processes.user) as user values(Processes.action) as action values(Processes.parent_process_exec) as parent_process_exec values(Processes.parent_process_guid) as parent_process_guid values(Processes.parent_process_id) as parent_process_id values(Processes.parent_process_path) as parent_process_path values(Processes.process) as process values(Processes.process_exec) as process_exec values(Processes.process_guid) as process_guid values(Processes.process_hash) as process_hash values(Processes.process_id) as process_id values(Processes.process_integrity_level) as process_integrity_level values(Processes.process_path) as process_path values(Processes.user_id) as user_id values(Processes.vendor_product) as vendor_product dc(Processes.parent_process_id) as parent_process_id_count dc(Processes.process_id) as process_id_count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes
WHERE Processes.parent_process_name= "cmd.exe" (Processes.process_name = "notepad.exe"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows For Loop Usage Within Cmd.exe To Execute Commands
id: a4ce9079-fc8f-4749-982a-13197c8cf977
version: 1
version: 2
creation_date: '2026-09-16'
modification_date: '2026-09-16'
author: Onur Mustafa Erdogan, Splunk
Expand All @@ -11,7 +11,6 @@ description: |-
Adversaries and malicious scripts leverage this pattern to programmatically process command output for discovery, data extraction, or execution purposes while evading simpler detection logic.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows Indirect Command Execution Via forfiles
id: 1fdf31c9-ff4d-4c48-b799-0e8666e08787
version: 11
version: 12
creation_date: '2022-03-04'
modification_date: '2026-05-13'
author: Eric McGinnis, Splunk
Expand All @@ -9,7 +9,6 @@ type: TTP
description: The following analytic detects the execution of programs initiated by forfiles.exe. This command is typically used to run commands on multiple files, often within batch scripts. The detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process creation events where forfiles.exe is the parent process. This activity is significant because forfiles.exe can be exploited to bypass command line execution protections, making it a potential vector for malicious activity. If confirmed malicious, this could allow attackers to execute arbitrary commands, potentially leading to unauthorized access or further system compromise.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes
WHERE Processes.parent_process="*forfiles* /c *"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows Indirect Command Execution Via pcalua
id: 3428ac18-a410-4823-816c-ce697d26f7a8
version: 11
version: 12
creation_date: '2022-03-04'
modification_date: '2026-05-13'
author: Eric McGinnis, Splunk
Expand All @@ -9,7 +9,6 @@ type: TTP
description: The following analytic detects programs initiated by pcalua.exe, the Microsoft Windows Program Compatibility Assistant. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process and parent process information. While pcalua.exe can start legitimate programs, it is significant because attackers may use it to bypass command line execution protections. If confirmed malicious, this activity could allow attackers to execute arbitrary commands, potentially leading to unauthorized actions, privilege escalation, or persistence within the environment.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes
WHERE Processes.parent_process="*pcalua* -a*"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows Proxy Execution of .NET Utilities via Scripts
id: eb59cf01-1874-4d16-b7e4-54a6eb9b3118
version: 2
version: 3
creation_date: '2026-04-29'
modification_date: '2026-05-13'
author: Teoderick Contreras, Splunk
Expand All @@ -11,8 +11,6 @@ description: |-
That pattern is consistent with adversaries using trusted .NET binaries as a proxy to run code while hiding execution behind script parents in low-trust folders, behavior associated with techniques such as signed binary proxy execution.
data_source:
- Sysmon EventID 1
- Windows Event Log Security 4688
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows Scheduled Task Service Spawned Shell
id: d8120352-3b62-4e3c-8cb6-7b47584dd5e8
version: 12
version: 13
creation_date: '2023-07-11'
modification_date: '2026-05-13'
author: Steven Dick
Expand All @@ -13,7 +13,6 @@ description: |
If confirmed malicious, this could allow attackers to execute arbitrary code, maintain persistence, or escalate privileges within the environment.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
3 changes: 1 addition & 2 deletions detections/endpoint/windows_ssh_proxy_command.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows SSH Proxy Command
id: ac520039-21f1-4567-b528-5b7133dba76f
version: 6
version: 7
creation_date: '2025-03-24'
modification_date: '2026-05-13'
author: Michael Haag, AJ King, Nasreddine Bencherchali, Splunk, Jesse Hunter, Splunk Community Contributor
Expand All @@ -12,7 +12,6 @@ description: |
This technique can be used by attackers to execute arbitrary commands through SSH proxy configurations, potentially enabling command & control activities or remote code execution. The detection focuses on commonly abused Windows scripting engines and web requests that may indicate malicious activity when spawned through SSH proxy commands.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows Suspicious React or Next.js Child Process
id: baa80bc8-7c9c-4395-b458-b69feb92830a
version: 5
version: 6
creation_date: '2025-12-08'
modification_date: '2026-05-13'
author: Nasreddine Bencherchali, Splunk
Expand All @@ -13,7 +13,6 @@ description: |
Such activity might be a strong indicator of exploitation of the aforementioned vulnerability.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |
| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime
from datamodel=Endpoint.Processes
Expand Down
3 changes: 1 addition & 2 deletions detections/endpoint/windows_time_based_evasion.yml
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
name: Windows Time Based Evasion
id: 34502357-deb1-499a-8261-ffe144abf561
version: 14
version: 15
creation_date: '2023-09-19'
modification_date: '2026-05-13'
author: Teoderick Contreras, Splunk
Expand All @@ -13,7 +13,6 @@ description: |-
If confirmed malicious, this activity could indicate an active infection attempting to evade detection, potentially leading to further compromise and persistence within the environment.
data_source:
- Sysmon EventID 1
- CrowdStrike ProcessRollup2
search: |-
| tstats `security_content_summariesonly`
count min(_time) as firstTime
Expand Down
Loading