Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
Featured
Ordered by hand. Each carries a note about why it is here.
All compositions
1–24 of 400 compositions
- T1098.007
Account added to a privileged local or domain group
4 of 4 backends · unverified000 - T1036.010
Account created with a name mimicking a trusted or default account
4 of 4 backends · unverified000 - T1531
Account disabled, deleted or reset from a command line
4 of 4 backends · unverified000 - T1003.003
Active Directory database file copied, exported or dumped
0% noise measured in lab
4 of 4 backends · verified000 - T1484.002
Active Directory domain trust object attribute modified
4 of 4 backends · unverified000 - T1137.006
Add-in dropped into a Word or Excel automatic startup folder
4 of 4 backends · unverified000 - T1003.007
Another process's /proc memory named on a Linux command line
2 of 4 backends · unverified000 - T1518.001
Antivirus and EDR agents enumerated from the command line
4 of 4 backends · unverified000 - T1546.010
AppInit DLL registry values set for system-wide DLL injection
4 of 4 backends · unverified000 - T1565.003
Application binary rewritten outside a package installer
4 of 4 backends · unverified000 - T1560
Archive file created in an uncommon staging directory
4 of 4 backends · unverified000 - T1027.015
Archive utility run against a Linux staging directory
4 of 4 backends · unverified000 - T1074
Archive written to a shared or world-writable staging directory
4 of 4 backends · unverified000 - T1074.001
Archiving utility writing an archive into a local staging directory
4 of 4 backends · unverified000 - T1564.001
attrib.exe or PowerShell sets the Hidden attribute on a file
4 of 4 backends · unverified000 - T1685.001
Audit policy or Windows Event Log channel disabled via CLI tooling
4 of 4 backends · unverified000 - T1059.010
AutoIt or AutoHotkey binary executing under a different file name
4 of 4 backends · unverified000 - T1499.004
Availability-critical Windows service terminating unexpectedly
3 of 4 backends · unverified000 - T1518.002
Backup product named in a service or process discovery command
4 of 4 backends · unverified000 - T1496.002
Bandwidth monetisation client executed on a Linux host
4 of 4 backends · unverified000 - T1059.003
Batch file run by the command shell from a user-writable path
4 of 4 backends · unverified000 - T1553.006
bcdedit invoked to disable driver signature enforcement or test signing
4 of 4 backends · unverified000 2 more, above
The featured compositions at the top of this page are counted in the 400 but not repeated here.
Jump to featured