Unknown detection rules
Every published rule under Unknown, with the source it came from, the licence it carries and the ATT&CK techniques it covers.
- matching detections
Loading detections…
Loading detections
Every published rule under Unknown, with the source it came from, the licence it carries and the ATT&CK techniques it covers.
Loading detections…
Meant to detect process creations containing names consistent with the schema used by Metasploit or Impacket's PsExec tool. Metasploit and Impacket's PsExec tooling is used by malicious actors for lateral movement & performing actions on remote systems.
Outside the enterprise matrix
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.