Siemphony
@siemphony
Reference detections derived from the MITRE ATT&CK detection layer. Machine-authored and unverified — a starting point to fork and test, not a deployable ruleset.
Repertoire
- published compositions
- 400
- ATT&CK techniques covered
- 402
- tactics represented
- 13
All compositions
121–144 of 400 compositions
- T1570
Executable content written over SMB by the System process
4 of 4 backends · unverified000 - T1574.009
Executable created at an unquoted service path interception point
4 of 4 backends · unverified302 - T1566.003
Executable or script written by a consumer messaging client
4 of 4 backends · unverified000 - T1080
Executable or script written to a user-facing network share
4 of 4 backends · unverified000 - T1036
Executable path uses RLO or trailing-space filename trick
3 of 4 backends · unverified000 - T1036.007
Executable run from a file name carrying a benign extension before it
4 of 4 backends · unverified000 - T1554
Executable written into a protected program directory
4 of 4 backends · unverified000 - T1046
Execution of a port or network service scanning utility
4 of 4 backends · unverified000 - T1098
Existing account altered to weaken or extend its credentials
4 of 4 backends · unverified000 - T1091
Explorer launches a process from a non-system drive letter
4 of 4 backends · unverified000 - T1564.014
Extended attribute syscall or setfattr/getfattr execution on Linux
3 of 4 backends · unverified000 - T1200
External device of a code-execution or network class attached
4 of 4 backends · unverified000 - T1133
Failed remote logon from a source outside the private ranges
4 of 4 backends · unverified000 - T1546.001
File association handler rewritten to a script host or LOLBin
4 of 4 backends · unverified000 - T1048.001
File encrypted with a symmetric cipher on the command line
4 of 4 backends · unverified000 - T1070.006
File timestamps rewritten via touch time flags or debugfs
4 of 4 backends · unverified000 - T1105
File transfer utility opening an outbound connection
2 of 4 backends · unverified102 - T1564.012
File written into a default OS antivirus exclusion path
4 of 4 backends · unverified201 - T1027.011
File written to a Linux shared-memory directory
3 of 4 backends · unverified000 - T1491.001
File written to a wallpaper, logon background or intranet web root
4 of 4 backends · unverified000 - T1552.001
Filesystem searched for credential strings in files
4 of 4 backends · unverified000 - T1495
Firmware flashing utility executed on an endpoint
4 of 4 backends · unverified000 - T1529
Forced shutdown or restart requested with no delay
4 of 4 backends · unverified000 - T1087.003
Global address list enumeration in a PowerShell script block
4 of 4 backends · unverified000