Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
385–400 of 400 compositions
- T1010
Window enumeration entry points in a PowerShell script block
4 of 4 backends · unverified000 - T1222.001
Windows DACL or ownership seized with a built-in permissions tool
0% noise measured in lab
4 of 4 backends · verified000 - T1679
Windows Defender exclusion configured via PowerShell preference cmdlet
4 of 4 backends · unverified000 - T1498
Windows denial-of-service stress tool launched
4 of 4 backends · unverified000 - T1685.005
Windows event log cleared via wevtutil or a PowerShell log cmdlet
4 of 4 backends · unverified002 - T1686.003
Windows host firewall profile disabled from the command line
4 of 4 backends · unverified000 - T1202
Windows indirection utility spawning a scripting or download tool
4 of 4 backends · unverified000 - T1059.007
Windows Script Host launching a JScript or JSE file
4 of 4 backends · unverified000 - T1685.003
Windows Security tray process executing from an unexpected path
4 of 4 backends · unverified000 - T1112
Winlogon launch values or SafeDllSearchMode rewritten
4 of 4 backends · unverified000 - T1669
Wireless network association event recorded on a Windows host
4 of 4 backends · unverified000 - T1546.003
WMI event subscription objects named on a command line
4 of 4 backends · unverified000 - T1547.013
XDG autostart desktop entry created or modified on Linux
3 of 4 backends · unverified000 - T1220
XSL stylesheet transform executed via msxsl or wmic format switch
0% noise measured in lab
4 of 4 backends · verified000 - T1027.006
Zone identifier stream naming a locally assembled download source
3 of 4 backends · unverified000 - T1553.005
Zone.Identifier stream stamped onto a container or disk image file
3 of 4 backends · unverified000