Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
265–288 of 400 compositions
- T1480.002
Predictable lock file created under tmp or run as an execution guardrail
2 of 4 backends · unverified000 - T1547.012
Print processor DLL registered under the spooler Environments key
4 of 4 backends · unverified000 - T1649
Private key export from a Linux certificate or key store
4 of 4 backends · unverified000 - T1006
Process command line references a raw volume or device path
4 of 4 backends · unverified000 - T1057
Process enumeration via tasklist, WMI process class or PowerShell cmdlets
4 of 4 backends · unverified000 - T1036.006
Process executed from a filename with a trailing space
4 of 4 backends · unverified000 - T1620
Process executed from an anonymous in-memory file on Linux
4 of 4 backends · unverified202 - T1036.002
Process image or command line contains a right-to-left override character
4 of 4 backends · unverified000 - T1566
Process invoked with a path inside the local mail spool
4 of 4 backends · unverified000 - T1555.005
Process opens a password manager process with memory-read access
3 of 4 backends · unverified002 - T1056
Process opens a raw Linux input device under /dev/input
3 of 4 backends · unverified000 - T1622
Process opens its own /proc/self/status, a common debugger-presence check
3 of 4 backends · unverified000 - T1542.003
Process opens the whole-disk raw device object bypassing partitions
3 of 4 backends · unverified000 - T1614.001
Process queries the system locale via registry lookup or PowerShell
4 of 4 backends · unverified000 - T1552.004
Process reads a private key file under a user's SSH or GPG directory
4 of 4 backends · unverified000 - T1021.008
Process spawned inside an AWS SSM interactive session
4 of 4 backends · unverified000 - T1036.008
Process started from an image with a document or image extension
4 of 4 backends · unverified000 - T1055.008
Ptrace attach or cross-process memory write on Linux
3 of 4 backends · unverified000 - T1059.006
Python interpreter spawned by a document or script host
4 of 4 backends · unverified000 - T1546.018
Python startup hook file written on Linux
3 of 4 backends · unverified000 - T1071
Raw socket tool invoked against a classic IRC port
4 of 4 backends · unverified000 - T1095
Raw-socket or ICMP tunnelling utility executed on Linux
3 of 4 backends · unverified000 - T1070.007
RDP connection history or firewall state cleared via command line
4 of 4 backends · unverified000 - T1563T1563.002
RDP session takeover with tscon or session shadowing
4 of 4 backends · unverified000