| Service Control Spawned via Script Interpreter | Low | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Execution of Persistent Suspicious Program | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Explorer Child Process | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Windows Server Update Service Spawning Suspicious Processes | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious MS Office Child Process | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Execution from VS Code Extension | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious SolarWinds Web Help Desk Java Module Load or Child Process | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious JetBrains TeamCity Child Process | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Execution from Unusual Directory - Command Line | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Delayed Execution via Ping | Low | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Command Shell Activity Started via RunDLL32 | Low | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Unusual Network Connection via RunDLL32 | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Execution from a Mounted Device | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Script Execution via Microsoft HTML Application | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Unusual Child Processes of RunDLL32 | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Microsoft HTML Application Child Process | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious .NET Code Compilation | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Credential Access via Renamed COM+ Services DLL | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Local NTLM Relay via HTTP | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Rare Connection to WebDAV Target | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Credential Access via Windows Utilities | High | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious Shell Execution via Velociraptor | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Protocol Tunneling via Yuze | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Suspicious ScreenConnect Client Child Process | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |
| Potential Command and Control via Internet Explorer | Medium | Elastic detection rules | Aug 27, 2026 | Elastic License 2.0 |