Skip to main content

Responses are generated using AI and may contain mistakes.

New-Scale Security Operations PlatformNew-Scale Security Operations Platform Release Notes

September 2026

The New-Scale Security Operations Platform includes the following addressed features and new features for September 2026.

Attack Surface Insights

Feature

Description

Scheduled Updates for Overview Entity by Tags Chart

To improve performance, the Entity by Tags chart in the Overview tab is now scheduled to refresh once every 24 hours.

Automation Management

Feature

Description

Send Case Templated Email Pre-Built Playbook

You can now automatically send a custom email notification to specific email recipients with the new Send Case Templated Email pre-built playbook.

The logic of the Send Case Templated Email pre-built playbook.

The playbook is partially configured and disabled by default. It is partially configured so you can use it as a template and customize it with your own details. To use the playbook as a template, clone the playbook, then customize the steps to define your own email recipients and, optionally, the notification HTML structure.

Custom Send Email Action

You can now send a custom email notification to specific email recipients with the new Custom Send Email action under the threatcenter pre-built service.

The Custom Send Email action takes a list of email recipients, an email subject, and the notification HTML structure, and sends an email notification using the Exabeam notification service.

Cloud Collectors

Feature

Description

Support for Cribl Metadata

Two types of metadata are supported for inclusion in Cribl raw logs. Adding metadata fields to your logs allows additional information from the Cribl source to be parsed and mapped for use in Exabeam applications. Supported metadata types include:

  • Default metadata fields – These fields are available natively in Exabeam but require configuration on the Cribl side. This metadata includes fields like siteid and hostname. When these fields are mapped in Exabeam, they appear with the m_ prefix. Examples: m_siteid, m_hostname.

  • Custom metadata fields – These fields can be configured based on any field you want to include as metadata in a Crible message log. This metadata requires configuration on both the Cribl side and the Exabeam side. In Exabeam, a custom metadata field must be configured in the Advanced Settings section of a Cribl Cloud Collector. In the Cribl source, a field with the same name must be configured in the expected format for ingestion by the cloud collector. When these fields are mapped in Exabeam, they appear with the m_logtags_ prefix. Examples: m_logtags_department, m_logtags_servertype.

For information about what metadata fields are supported, the expected raw log format, and the procedure for configuring custom metadata, see Adding Metadata Fields in the Cloud Collector Guide.

Google Alert Center Cloud Collector

The Google Alert Center Cloud Collector is now available as part of Cloud Collectors to facilitate ingestion of logs from Google Alert Center that include security alerts about suspicious activity in your company's Google accounts—such as unusual login attempts, potential phishing emails, and risky file sharing.

Correlation Rules

Feature

Description

Langflow Spawning Suspicious Process Correlation Rule Template

You can now better detect Jade Puffer (CVE-2025-3248) Langflow post‑exploitation activity with the new Langflow Spawning Suspicious Process correlation rule template.

The correlation rule template is configured to detect suspicious child processes spawned by the Langflow parent process. It focuses on detecting post‑exploit behavior rather than the initial exploit of the /api/v1/validate/code endpoint because network and firewall logs typically do not contain sufficient signal of the initial exploit.

The detals of the Langflow Spawning Suspicious Process correlaton rule template.

Log Stream

Feature

Description

Support for Cribl Metadata

Log Stream now supports the inclusion of both default and custom metadata as part of Cribl raw logs. Adding metadata fields to your logs allows additional information from the Cribl source to be parsed and mapped for use in Exabeam applications. In order to leverage the Cribl information as metadata fields, the following requirements must be met:

  • Both the default and the custom metadata fields must be structured in the Cribl raw log according to the expected JSON format.

  • In the case of custom metadata fields, these fields require configuration on both the Cribl side and the Exabeam side. In Exabeam, a custom metadata field must be configured in the Advanced Settings section of a Cribl Cloud Collector. In the Cribl source, a field with the same name must be configured in the expected format for ingestion by the cloud collector.

When the default metadata fields are ingested and mapped to Exabeam fields, they appear in downstream applications with a prefix of m_. Examples: m_siteid, m_hostname. When the custom metadata fields are ingested and mapped, they appear with a prefix of m_logtags_. Examples: m_logtags_department, m_logtags_servertype.

For information about what metadata fields are supported, the expected raw log format, and the procedure for configuring custom metadata, see Adding Metadata Fields in the Cloud Collector Guide.

New-Scale Platform

Feature

Description

Configurable Session Timeout

To provide organizations with greater flexibility and control over their security posture, administrators can now configure a custom session timeout duration for their specific tenant.

Previously, session timeouts were standardized across all tenants in a given region. Now, you can tailor your session lengths to meet your exact operational needs, whether that means shortening the timeout to meet heightened security and compliance controls, or extending it to support continuous visibility for Security Operations Center displays.

session-timeout.png

For more information, refer to Configuring Tenant Session Timeout in the New-Scale Security Operations Platform Administration Guide.

Exabeam Nova Updates

Nova has expanded from a set of page-specific chat assistants into a single, persistent AI sidebar available everywhere in the New-Scale UI. With this release, analysts no longer need to navigate to a specific page to access AI assistance as Nova is always one click away, regardless of where you are in the product.

exabeam-nova-sidebar.png

This is an Early Access feature and won't be available in the SA or EUW6 regions. To enable this for your environment before general release, contact your account team.

For more information, refer to Exabeam Nova in the New-Scale Security Operations Platform Administration Guide.

Exabeam MCP Server Enhancements

The Exabeam MCP Server now supports additional functionality, including the ability to:

  • Update an analytics/detection management rule

  • Create a new analytics/detection management rule

  • Get analytics/detection management rule details by template ID

  • Get a list of parsers filtered by state and type

  • Get parser details by parser ID

For more information, and to learn how to connect to the server, see Connect to Exabeam MCP Server in the New-Scale Security Operations Platform Administration Guide.

Outcomes Navigator

Feature

Description

Time Range Menu Enhancement

To make clear that the time range menu could affect multiple charts, the time range menu is now located next to the Peer Comparison menu in the Use Case Coverage and MITRE ATT&CK® Coverage overviews.

The time range menu for Peer Comparison in the Use Case Coverage tab.
outcomesnavigator-mitreatt_ckcoverage-timerangemenu.png

Exabeam Nova Coverage Summaries Enhancement

To get more information from a single view, you can now scroll to see the entire Exabeam Nova Use Case Summary and Exabeam Nova MITRE Summary directly in the Use Case Coverage and MITRE ATT&CK® Coverage overviews.

To open the summary in Exabeam Nova, click View Summary in Nova.

The ​Exabeam Nova Use Case Coverage Summary, an AI-generated summary of your overall use case coverage.
The Exabeam Nova MITRE ATT&CK Coverage Summary.

Use Case Coverage Overview Enhancement

To learn more about use cases at a glance, you can now see the a preview of the Exabeam features and applications coverage scores directly on a use case.

On a use case in the Use Case Coverage overview, you can see the coverage scores for:

  • Analytics rules

    The tooltip for the analytics rule coverage score for the Cloud Data Protection use case in the Use Case Coverage tab.
  • Correlation rules

    The tooltip for the correlation rules coverage score for the Cloud Data Protection use case in the Use Case Coverage tab.
  • Dashboards

    The tooltip for the Dashboards rule coverage score for the Cloud Data Protection use case in the Use Case Coverage tab.

When selecting use cases to view further details, you can see the same coverage score information for analytics rules, correlation rules, and Dashboards:

outcomesnavigator-viewusecasedetails-selectusecasecategory.png

Coverage Overview Filters

To focus on specific threats of interest, you can now filter the use cases and ATT&CK techniques in the Use Case Coverage and MITRE ATT&CK® Coverage overviews.

You can filter by:

  • Coverage Score Factors – The Exabeam features and applications that cover the use case or ATT&CK technique. This is currently available for use cases only.

    The Coverage Score Factors filter in the Use Case Coverage tab.
  • Coverage Score Factors Scores – The coverage scores for the Exabeam features and applications.

    The Coverage Score Factors Scores filter in the Use Case Coverage tab.

Site Collectors 2.23

Feature

Description

Automatic Certificate Rotation

Certificates are now automatically rotated one week before they expire. Secure connections are maintained without any manual steps in the user interface. Auto-rotation can be turned off at any time by admins, or it can be scheduled within preferred maintenance windows. Automatic Certificate Rotation provides transparent, predictable, and automated certificate management experience.

Custom Notification Settings for Agent Collectors

You can now customize notification settings for inactive collectors to reduce excessive alerts. Use the Site Collector Management user interface (UI) to view the current policy and change the default notification intervals for inactive collectors. This feature allows you to customize alerts to match the specific needs of each collector type.

Log Collection from MS SQL Server using Windows/Kerberos Authentication

The MS SQL Collector is now updated to facilitate log collection via MS SQL server using Windows/Kerberos authentication. Enhanced user experience is provided via quick and actionable error messages instead of generic 60-second timeout screens for you to troubleshoot without delay.

Refer to the following table for collector versions for Site Collectors 2.23.

Collector / Component

Product Version

Direct Access Agent (DAA) Collector

1.7.0

Service Health and Consumption

Feature

Description

New CISO Digest tab in Service Health and Consumption

The new CISO Digest tab provides security leaders direct access to essential executive insights.

By navigating to Service Health and Consumption Dashboard > CISO Digest on the New-Scale Security Operations Platform, you can access the highlights of your overall security posture through clear coverage scores, operational metrics, and complete case breakdowns across all available frameworks.

You can easily track security trends over time to identify and fix specific organizational weaknesses. Built-in tracking logs team activity. Default settings and automated monthly email summaries provide essential information without needing you to navigate to complex menus. The dashboard covers operational metrics, coverage scores, and case breakdown and includes all available frameworks such as MITRE ATT&CK, Use Case Coverage, Health Insurance Portability, and so on.

All the essential details are shared via monthly email digest to keep you informed and help you take informed decisions.

Threat Center

Feature

Description

Exabeam Nova Related Cases

To reconstruct the full scope of a security threat and track anomalous activity across objects, you can now view other related cases directly within a case.

For cases that have an Exabeam Nova Investigation Summary, Exabeam Nova finds up to 10 other cases from the past two weeks and the following two weeks that share the exact same objects: usernames, hostnames, IP addresses, or domains. It may take up to one hour after Exabeam Nova generates the summary before you can view any related cases.

Under Related Cases in Exabeam Nova, you can:

  • View a summary of the related cases and why Exabeam Nova linked them.

    The Summary and Shared Objects in All Cases section of Exabeam Nova Related Cases.
  • View a list of the related cases; filter the list by case stage and severity; and search the list.

    The List tab of Exabeam Nova Related Cases.
  • View a timeline of the related cases relative to the current case.

    The Timeline tab of Exabeam Nova Related Cases.

Threat Timeline Alignment

To consistently investigate the historical context of a case or alert, you can now use a similar timeline experience in Threat Center that is in Search.

With a streamlined timeline experience, you can now:

  • See a two-column view, with events in the left column and associated detections in the right column

    The Threat Timeline.
  • View event and entity details directly in Threat Center

    Event information in the threat timeline.
    Entities information in the threat timeline.
    Data Insights in the threat timeline.
  • Sort the timeline by oldest or most recent event

    The sorting options in the threat timeline highlighted in a red rectangle.
  • Filter the timeline by activity type, user entities and accounts, device entities, rule name, rule reason, rule severity, MITRE ATT&CK® tactics and techniques, and use cases[a]

    The filter options in the threat timeline highlighted in a red rectangle.

Overview Rules Triggered Enhancements

You can now see more detailed information about triggered rules associated with a case in the Overview tab. In the Rules Triggered section, you can now see:

  • All triggered rules associated with the case or alert. If the rule has triggered once, you can see its correlation rule rule_reason or analytics rule detectionReason. If the rule has triggered multiple times, you can see its rule name, then expand it to view every instance of when the rule was triggered and its rule_reason or detectionReason.

    The Rules Triggered section in the Overview tab.
  • Every instance of when the rule was triggered and its rule_reason or detectionReason.

    The Rules Triggered section with instances of when a rule was triggered highlighted in a red rectangle.
  • Rules organized by detection. The detections are sorted in chronological order, from earliest to most recent. The number at the top of each detection group is the detection rarity score.

    The Rules Triggered section with Group by detection toggled on.
  • Specific icons for each rule type.

    The Rules Triggered section showing the tooltip for a correlation rule.
    The Rules Triggered section showing the tooltip for an analytics rule.
    The Rules Triggered section showing the tooltip for a phishing rule.
    The Rules Triggered section showing the tooltip for an Advanced Analytics rule.
  • The rule severity.

    The Rules Triggered section with the rule severities highlighted in a red rectangle.
  • The rule definition.

    The Rules Triggered section showing the tooltip for the Rule Definition.

You can now also sort the list by severity or trigger frequency.

The Rules Triggered section with the Sort by menu highlighted in a red rectangle.

[a] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.

Threat Detection Management

Feature

Description

triggerDependencyExpression Field for factFeature and profiledFeature Analytics Rules

You can now restrict a factFeature or profiledFeature analytics rule from triggering when another rule has not triggered on the same event using the new triggerDependencyExpression analytics rule field.

You may want to restrict an analytics rule from triggering to prioritize specific analytics rules over generic analytics rules or prevent double counting when multiple analytics rules are eligible to trigger on an event.

To configure a trigger dependency, add the triggerDependencyExpression field to the analytics rule JSON configuration or use the Manual Rule Creator to configure Trigger Dependency Expression. It is an optional field.

Trigger Dependency Expression in the Manual Rule Creator.

A valid field value is a combination of the new HasRuleTriggeredOnSameEvent() function and logical operators. The analytics rule triggers if the expression evaluates to true.

The HasRuleTriggeredOnSameEvent() function takes an analytics rule ID as an argument. If the analytics rule has triggered on the same event, it returns true; if the analytics rule hasn't triggered on the same event, it returns false.

Analytics Rule Notifications

To stay updated on important analytics rule activity, you can now receive four new platform and global notifications about analytics rules.

You can now receive notifications whenever:

  • The analytics engine has finished restarting and has resumed detecting threats in incoming events.

  • An analytics rule has failed to complete its training period.

  • An analytics rule has completed its training period.

Notification settings for analytics rules.

Updated Pre-Built Analytics Rules

You can now better detect defensive evasion, credential theft, compromised communications, and system tampering with updated pre-built analytics rules.

As part of an architectural change to consolidate where compliance framework information is stored, compliance was removed from the following pre-built analytics rules:

  • Fact-PCwmic-SCD – The WMIC (WMI Command Line) process has been used to delete a shadow copy. This sigma rule is authored by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml

  • NumCP-VPNlnF-EC-U-30Days – An abnormal number of vpn login failures have been observed for this user in 30 days.

  • Fact-PCrundll32-PwrshellDll-PCL – rundll32.exe to execute PowerShell related code through DLL loading techniques. This sigma rule is authored by Markus Neis, Nasreddine Bencherchali (Nextron Systems). The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_powershell_execution_via_dll.yml

  • Cntx-Web-UCrit-Exec – User is an executive: True\False

  • Fact-GA-TITOR – An IP address associated with TOR has been observed.

  • NumDCP-Login-DZC-UD-DZ – An abnormal number of unique destination network zones have been observed in login events for users in this department. These events may include both failed and successful logins.

  • Prof-Web-TI-U-WebDom-Malicious – This is the first time an HTTP communication attempt to this malicious web domain has been observed for this user. These events may include both failed and successful traffic.

  • Fact-SEPwrshell-EnumNetworkAdapter – A PowerShell script that enumerate network adapters using wmi object has been executed.

  • Fact-PC-OpenClawInstall – OpenClaw has been installed using the command line tool 'curl'. There is nothing inherently malicious about OpenClaw, however, by default it uses insecure practices and may expose significant security flaws.

  • Prof-RegW-COM-O-CLSID – This is the first time the registry path to a COM class with this CLSID has been modified.

  • Prof-CPM-DestUT-U-DestUT – This is the first time a member with this user type was successfully granted IAM permissions in a GCP policy. IAM policies determine the roles and permissions granted to users on a resource.

  • Fact-PCSplashtop-InstalledService – The Splashtop remote desktop access service has been installed.

  • Cntx-PC-ECrit-CS-DE – Destination endpoint is critical or a Domain Controller: True\False

  • Prof-CA-IC-O-U – This is the first time this user has created an image. An abnormal image upload could mean the image was created with a malicious intent. A malicious image could be used to trick users to create a VM that will contains a shellcode or a malware implanted in advance by an attacker.

  • Prof-PC-CmdArgs-Msbuild-O-XMLParam – This is the first time the 'msbuild.exe' process has been used to build a project with this xml file.

  • Prof-EL-AP-U-AP – This is the first time this user has attempted to perform a remote Windows login or access using this authentication package. These events may include both failed and successful logins.

  • Prof-SA-PN-U-PN – This is the first time an alert triggered on this process for this user.

  • Cntx-GA-TIRansomware-DIP – Destination IP is marked as a ransomware by threat intelligence: True\False

  • Fact-PCpcalua-IC – The PCALUA (Program Compatibility Assistant Service) process has been used to execute an indirect command. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/deprecated/windows/proc_creation_win_indirect_cmd.yml

  • Prof-UCreate-Z-O-SZ – This is the first time a user account has been created in this network zone.

  • Cntx-FUSB-Outlook – File has a .pst/.ost extension: True\False

  • Prof-AI-AS-Plt-U – This is the first time this user has shared an AI agent on this platform.

  • Prof-SA-AS-SE-AS – This is the first time a security alert with this subject triggered from this endpoint.

  • Cntx-PC-Critical-Parent-SystemEnum – Parent process is a system enumeration tool: True\False

  • Prof-GMA-U-O-UD – This is the first time a user has been added to a group by a user in this department.

  • NumDCP-SA-ANC-UD-AN – An abnormal number of unique alerts have triggered for users in this department.

  • Cntx-PCapplocker-UAC – Process is a known Applocker bypass process: True\False

  • Prof-GA-RGN-O-RGN – This is the first time this cloud region has been observed for the organization.

  • Fact-Web-TIRansomware – An HTTP communication attempt has been made to a ransomware associated domain. These events may include both failed and successful traffic.

  • Fact-PCcsc-AP – The CSC (C# Compiler) process has been spawned by a command line executable or a Microsoft Office process. This sigma rule is authored by Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_csc_susp_parent.yml

  • NumSP-Web-Bytes-U-BytesStorageOut – An abnormal amount of bytes have been uploaded to file sharing websites for this user.

  • Prof-RA-R-U-RA – This is the first time this user assumed this role.

  • Fact-PCwsreset-UAC – The WSReset (Windows Store Reset) process has spawned a child process that it shouldn't normally spawn. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Florian Roth and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_wsreset.yml

  • NumCP-RegD-EC-U – An abnormal number of registry deletion events have been observed for this user.

  • Fact-RegW-RunService – Run Services registry keys have been modified.

  • Prof-MFA-FailureReason-U-FailureReason – This is the first time this user failed to authenticate with MFA authentication with this failure reason.

  • NumDCP-SA-ANC-U-AN – An abnormal number of unique alerts have triggered for this user.

  • NumDCP-PLA-LocC-U-LocCity – An abnormal number of unique cities have been observed in physical access events for this user.

  • Prof-DS-E-O-SE – This is the first time a user in the organization performed an activity on a directory service object from this endpoint.

  • Prof-CPM-DestD-U-DestD – This is the first time a user from this domain was successfully granted IAM permissions in a GCP policy. IAM policies determine the roles and permissions granted to users on a resource.

  • NumDCP-FRead-EC-UP-FP – An abnormal number of unique files have been read in this platform for this user.

  • Prof-SEPwrshell-U-O-U – This is the first time this user executed a PowerShell script.

  • Cntx-SA-AC-ProdSev – Alert product and severity

  • Fact-FRead-Passwd – The passwd file is a plain text file in Unix-based operating systems, including Linux and macOS, that stores essential user account information. An attacker can try to read it to get information about the users include the passwords

  • NumSP-Web-Bytes-O-BytesStorageOut – An abnormal amount of bytes have been uploaded to file sharing websites for the organization.

  • Prof-SA-PN-O-PN – This is the first time a security alert triggered on this process for the organization.

  • NumDCP-Login-DZC-U-DZ – An abnormal number of unique destination network zones have been observed in login events for this user. These events may include both failed and successful logins.

  • Prof-DllLoad-Ext-PN-FileExt – This is the first time a DLL image file with this extension was loaded for this process.

  • Fact-PCsc-SvcMod-PCL – The SC (Service Controller) process has been used to configure a PowerShell service. This sigma rule is authored by Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml

  • NumDCP-EL-UC-O-U-SE – An abnormal number of unique user names have been observed in endpoint logins for the organization per source endpoint. These events may include both failed and successful communications.

  • Fact-Fwrite-RCScripts – Adversaries can establish persistence by adding a malicious binary path or shell commands to rc.local, rc.common, and other RC scripts specific to the Unix-like distribution.

  • Fact-PCGoToMyPC-InstalledAgent – The GoToMyPC remote desktop access agent has been installed.

  • Cntx-GA-TI-SIP – Source IP is marked by threat intelligence: True\False

  • Fact-PCnwp-NWP – A Windows system process has been executed from a folder it shouldn't normally execute from. This sigma rule is authored by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_system_exe_anomaly.yml

  • Fact-PCcsws-SExec – The 'wscript.exe' or 'cscript.exe' processes (Windows Script Host) have been used to execute a VBScript shell. These programs can be used to aid in fileless malware execution, a technique that can help evade detection. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_apt_cloudhopper.yml

  • NumDCP-CA-DAC-U-Disks – An abnormal number of volumes were attached to instances by this user. These events may include both failed and successful attachments.

  • Prof-GMA-E-O-DE – This is the first time a user has been added to a group on this endpoint.

  • Fact-PCGoToMyPC-InstalledService – The GoToMyPC remote desktop access service has been installed.

  • Cntx-PC-Critical-Parent-Crit – Parent process is a known critical command: True\False

  • NumCP-DSOW-EC-U – An abnormal number of directory service events have been observed for this user. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • NumSP-FRead-FS-UP-Bytes – An abnormal amount of file bytes have been read in this platform for this user.

  • Fact-PCGoToMyPC-StartedService – The GoToMyPC remote desktop access service has been started.

  • Fact-PCpwrshell-HidExec – The PowerShell process has been executed with a hidden or non-interactive console window. This sigma rule is authored by Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix). The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_susp_parameter_variation.yml

  • Prof-PCnet-U-O-U-netlocalgroup – This is the first time a user account has been added to a group using 'net.exe' for this user.

  • Prof-ELF-E-U-DE – This is the first time this user has failed to log into this endpoint. The user might have logged in successfully before, but this is the first time a failed login event was observed on the endpoint.

  • Prof-BPM-U-PBPolicy-O-U – This is the first time this user has successful edited the IAM policy of a bucket in AWS. IAM bucket policies determine the access users and other identities have to the files and objects inside the storage bucket.

  • Fact-PCcsws-SExec-PP – The 'wscript.exe' or 'cscript.exe' processes (Windows Script Host) were used to execute a script from the user directory or the program data directory. This sigma rule is authored by Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_malware_script_dropper.yml

  • Prof-RegW-EnvVarPath-O-U – This is the first time this user has modified the PATH environment variable by writing to the registry value 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\Path'.

  • Fact-Web-TITOR-Dom – An HTTP communication attempt has been made to a known TOR web proxy domain. These events may include both failed and successful traffic.

  • Prof-Login-EmD-Plt-EmD – This is the first time this email domain has been used to successfully log into this platform.

  • NumCP-AI-CDC-UPLT – An abnormal number of AI conversations have been successfully deleted by this user on this platform.

  • Prof-AI-PI-O-U-Exec – This is the first time an AI request that attempts to cause the agent to execute a command or a script has been sent by this user.

  • Fact-PC-SuspFind – Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. This command searches for files with the setuid (SUID) permission set for the owner.

  • Prof-EMR-FileExt-UD-FileExt – This is the first time a user in this department has received an email attachment with this extension.

  • Fact-PCsetspn-SPNDisc – The 'setspn.exe' process has been used to query service principal names. This sigma rule is authored by Markus Neis, keepwatch and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_setspn_spn_enumeration.yml

  • Fact-PC-DisableHistoryCol – History collection can be disabled in unix shells by modifying the history environment variables. This can help the attacker ot evade detection.

  • Prof-AL-E-O-SE – This is the first time a user in the organization attempted to log into an application from this endpoint. These events may include both failed and successful logins.

  • Prof-VPNIn-Rlm-U-Rlm – This is the first time this user attempted to log into a VPN with this realm. These events may include both failed and successful logins.

  • Prof-GMA-OU-GN-UOU – This is the first time a user in this OU has been added to this group.

  • Cntx-SA-Ecrit-SE – Source endpoint is critical: True\False

  • Fact-PCTeamViewer-InstalledAgent – The TeamViewer remote desktop access agent has been installed.

  • Cntx-Login-LType – Login type

  • Cntx-GMA-GCrit-Admin – Security group is privileged: True\False

  • NumCP-FDnld-EC-O – An abnormal amount of file download events have been observed for the organization.

  • NumDCP-RegW-RPC-ServicesStop-U-RP – An abnormal number of unique services have been stopped by modifying the registry for this user.

  • Fact-PCvssadmin-SCD – The VSSAdmin (Volume Shadow Copy Service Admin) process has been used to delete a shadow copy. This sigma rule is authored by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shadow_copies_deletion.yml

  • Prof-PCwmic-IR-O-U-usr – This is the first time a user account has been renamed using 'wmic.exe' for this user.

  • NumCP-PC-SudoCount-U – An abnormal number of 'sudo' (Superuser Do) process executions have been observed for this user.

  • Fact-PCnetsniff-SniffT – A network sniffing tool has been executed.

  • Prof-PC-PPN-PN-PPN – This is the first time this parent process has been observed for this matured child process.

  • Fact-UModify-UACPreAuthDisable – UAC pre-authentication has been disabled for a user account.

  • Fact-PCrundll32-Meterpreter – The 'rundll32.exe' process has been used to execute a known Meterpreter/Cobalt Strike module. This sigma rule is authored by Teymur Kheirkhabarov, Ecco, Florian Roth and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_meterpreter_or_cobaltstrike_getsystem_service_install.yml

  • Prof-RegW-SilentExitMon-O-U – This is the first time this user has modified or created the silent exit configuration of a process by writing a registry key\value under the key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit'.

  • Fact-PCIOC-ZxShell – The 'rundll32.exe' process has been used to execute a known 'ZxShell' backdooring software module. This sigma rule is authored by Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2014/TA/Axiom/proc_creation_win_apt_zxshell.yml

  • Prof-PCnetsh-U-O-U – This is the first time firewall policies have been enumerated using 'netsh.exe' for this user.

  • Prof-RA-R-UPlt-RN – This is the first time this user has assigned this role on this platform.

  • Fact-PCmwc-PExec – The Microsoft Workflow Compiler process has been executed. Microsoft Workflow Compiler may permit the execution of arbitrary unsigned code. This sigma rule is authored by Nik Seetharaman, frack113 and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lolbin_workflow_compiler.yml

  • Prof-DSF-AT-U-AT – This is the first time this directory service activity type failed for this user. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-PwdChkout-E-U-SE – This is the first time this user retrieved a password from this endpoint.

  • Prof-PCwmic-IR-O-U-grp – This is the first time a group has been renamed using 'wmic.exe' for this user.

  • Prof-SADLP-Tld-Proto-Tld – This is the first time a DLP alert triggered on this domain for this protocol.

  • Prof-PC-E-O-SE-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed on this endpoint.

  • Cntx-PC-Critical-Pentest – Process is a known pentesting tool

  • Prof-VPNIn-SC-O-SC – This is the first time a user attempted to log into a VPN from this country. These events may include both failed and successful logins.

  • Prof-PC-PN-Plt-PN – This is the first time this process has been executed in this platform. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • Fact-PCpwrshell-AMSI – The PowerShell process has been used to disable AMSI (Anti Malware Scan Interface) Scanning using AmsiInitFailed. This sigma rule is authored by Markus Neis, @Kostastsale and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_amsi_init_failed_bypass.yml

  • NumSP-Web-Bytes-U-BytesStorageIn – An abnormal amount of bytes have been downloaded from file sharing websites for this user.

  • Prof-Login-E-DE-SZ – This is the first time a successful login has been observed from this network zone to this endpoint.

  • Fact-PCcertutil-SuspCmd – The CertUtil (Certification Utility) process has been executed with suspicious command line parameters. This sigma rule is authored by Florian Roth (Nextron Systems), juju4, keepwatch and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_decode.yml, https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_download.yml, https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_certutil_encode.yml.

  • NumDCP-VPNln-UC-O-U-SE – An abnormal number of unique user names have been observed in VPN login for the organization per source endpoint. These events may include both failed and successful communications.

  • Fact-PCbitsadmin-FDnld – The BITSAdmin (Background Intelligent Transfer Service Admin) process has been used to download a file. This sigma rule is authored by Michael Haag, FPT.EagleEye and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bitsadmin_download.yml

  • Fact-PCpwrshell-SCC – The PowerShell process has been used to create a shadow copy. This sigma rule is authored by Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_shadow_copies_creation.yml

  • Cntx-GA-TI-DIP – Destination IP is marked by threat intelligence: True\False

  • Fact-PCicacls-FPermMod-Everyone – The ICACLs (Integrity Control Access Control Lists) process has been used to grant global permissions on a file.

  • Cntx-PC-Critical-Sniffer – Process is a sniffing tool: True\False

  • Fact-Web-TI-MalDom – An HTTP communication attempt has been made to a malicious site category. These events may include both failed and successful traffic.

  • Fact-PCsc-SuspSP – The SC (Service Controller) process has been executed with suspicious command line parameters.

  • Fact-PC-ClearComHistory – This can help the attacker ot evade detection.

  • Prof-GA-Country-U-SCountry – This is the first time an activity has been observed from this country for this user, determined by geolocation lookup.

  • Cntx-PC-FC-SusDir – Process executed from a known suspicious folder: True\False

  • Fact-PCcertutil-AP – The CertUtil (Certification Utility) process has been spawned by a command line executable. This sigma rule is authored by Florian Roth (Nextron Systems), Tim Shelton and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shell_spawn_susp_program.yml

  • Fact-PCsr-AC – The Sound Recorder process was used to record external audio. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_soundrecorder_audio_capture.yml

  • Fact-PCtshark-NetSniff – The TShark process (a network sniffing tool) has been executed. This sigma rule is authored by Timur Zinniatullin, oscd.community, Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_network_sniffing.yml

  • Prof-SA-AN-SE-RN – This is the first time this correlation rule triggered from this endpoint.

  • Cntx-SA-Ecrit-DE – Destination endpoint is critical: True\False

  • Fact-PCtakeown-FO – The 'takeown.exe' process has been used to take ownership of a file or a folder.

  • NumCP-FUpld-EC-U – An abnormal amount of file upload events have been observed for this user.

  • Prof-DB-DBOp-UDBN-DBOp – This is the first time a database operation has been observed for this user. A database operation consists of any action in a database query (i.e. SELECT, DROP, UPDATE, etc...).

  • Fact-RegW-AppShim – A registry key/value has been created under the Shim database registry key 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom' or 'HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\InstalledSDB

  • Prof-RA-R-Plt-RN – This is the first time this role was assigned on this platform.

  • Prof-CA-SC-O-U – This is the first time this user has successfully created a snapshot of a compute instance.

  • Prof-Fwrite-U-O-U-Plist – This is the first time a plist file was created by this user.

  • Fact-PCscrcons-WMI – The 'scrcons.exe' process (WMI script event consumer) has been executed. This sigma rule is authored by Thomas Patzke and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wmi_persistence_script_event_consumer.yml

  • Prof-WinSC-U-DE-DU – This is the first time a service permitted to run under this user's credentials was created on this endpoint.

  • Fact-PCIOC-Archer – The 'rundll32.exe' process has executed a command associated with the Archer malware service. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_malware_fireball.yml

  • Cntx-GA-SA – User is a service account: True\False

  • Cntx-EL-ET-Wrkstn – Destination endpoint is a workstation: True\False

  • Prof-DB-U-DBN-UD – This is the first time a database event in this database has been observed for a user in this department. A database event consists of any event or operation performed on a database. These events may include both failed and successful operations.

  • Prof-AI-AC-PLT-UD – This is the first time a user in this department has created an AI agent with this platform.

  • Fact-PCnetsh-FD – The NetSh (Network Shell) process has been used to disable the Windows firewall. This sigma rule is authored by Fatih Sirin and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_netsh_fw_disable.yml

  • NumDCP-ELF-SEC-DE-SE – An abnormal number of unique endpoints have been observed failing to log into this endpoint.

  • Fact-CA-Startup-StartupScriptAWS – A startup script was added or modified in an instance in AWS.

  • Prof-UCreate-DC-U-DC – This is the first time this domain controller has processed a user creation request for this user.

  • NumDCP-PCCEnum-TC-U-CEnum – An abnormal number of unique credential enumeration tools have been executed for this user.

  • Fact-PCcreateminidump-ProcMemDump – The CreateMiniDump process (a memory dumping tool) has been executed. This tool is used to dump the LSASS process memory for credential extraction on the attacker's machine. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_createminidump.yml

  • Prof-ShA-SE-SN – This is the first time this network share has been accessed from this endpoint.

  • Prof-VPNIn-SC-U-SC – This is the first time this user attempted to log into a VPN from this country. These events may include both failed and successful logins.

  • Fact-CPM-PCrit-GCPPublic – A policy has been successfully modified to allow public access to a GCP resource. This activity should be noted since public resources can be read or downloaded by everyone.

  • Fact-PC-Setfile-HiddenFile – The "setfile" unix process can be used to make files hidden by modifying their attributes, making sure they remain undetected by users. An attacker can create hidden file to evade detection.

  • NumCP-WebF-EC-U-Id – An abnormal number of HTTP 4xx/5xx error responses has been observed for this user.

  • Fact-PCcontrol-CPLFExec – The Windows control panel process has loaded control panel items outside of the folders they are loaded from by default. This sigma rule is authored by Kyaw Min Thein, Furkan Caliskan (@caliskanfurkan_) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_control_panel_item.yml

  • Prof-RA-U-O-U – This is the first time this user assumed a role.

  • NumCP-PCpwrshell-EC-UD – An abnormal number of PowerShell process executions have been observed for users in this department.

  • Cntx-GA-AF – Activity failed: True\False

  • Fact-PC-Chmod-Setuid – The setuid bit was set using chmod, which can cause a file to execute with the privileges of its owner.

  • Prof-PCnet-U-O-U-netuserdel – This is the first time a user account has been deleted using 'net.exe' for this user.

  • NumCP-PwdChkout-EC-U-SC – An abnormal number of password retrievals have been observed for this user.

  • Prof-PCpwrshell-En-O-U – This is the first time a process execution of a PowerShell process with an encrypted command has been observed for this user.

  • Fact-PC-MshtaScriptExecution – The MsHTA (Microsoft HTML Application) process has been used to execute a script code.

  • Prof-SA-U-O-UD – This is the first time a security alert triggered for users in this department.

  • Fact-PCecho-EchoP – The 'echo.exe' process has been used to execute a command associated with Meterpreter and Cobalt Strike's GetSystem system privilege escalation function.

  • Prof-Web-WebDom-O-U-WebDomIP – This is the first time an HTTP communication attempt directly to an IP address has been observed for this user. These events may include both failed and successful traffic.

  • Prof-USB-DevId-O-DevId – This is the first time this peripheral device ID has been observed for the organization.

  • Prof-CA-IE-O-U – This is the first time this user has exported a compute instance. Instance export could be used by an attacker to collect sensitive data that resides inside the organization's virtual machines.

  • Prof-SA-DP-LE-DP – This is the first time a network alert on this port has been triggered for this destination endpoint.

  • Fact-PCrundll32-ProcMemDump-1 – The 'rundll32.exe' process has been used to dump process memory using the 'minidump' exported function in 'comsvcs.dll'. This sigma rule is authored by Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_process_dump_via_comsvcs.yml

  • Prof-EMR-ED-O-ED – This is the first time a user from the organization has received an email from this email domain.

  • Prof-RC-Perm-Plt-Perm – This is the first time a role has been created with these permissions on this platform.

  • Prof-Web-BinURL-O-U – This is the first time an executable file was downloaded during an HTTP session for this user. These events may include both failed and successful traffic.

  • Fact-PCmwc-mstsc – The MSTSC (Microsoft Terminal Services Client) process has been used to shadow an existing remote desktop session. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_mstsc_rdp_hijack_shadowing.yml

  • Prof-DS-AT-DSOC-AT – This is the first time this activity has been observed for this directory service object class. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Fact-PC-TempF-Outlook – A process have been executed from an Outlook temporary folder. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_office_outlook_execution_from_temp.yml

  • Prof-DS-DSOC-O-DSOC – This is the first time a user in the organization performed an activity on a directory service object with this object class.

  • Prof-STC-E-O-DE – This is the first time a scheduled task has been created on this endpoint.

  • NumCP-PC-ModprobeCmdC-U – An abnormal number of 'modprobe' (Module Probe, a kernel module management tool) process executions have been observed for this user.

  • Prof-ShA-SZ-SN – This is the first time this network share has been successfully accessed from this network zone.

  • Fact-PCdns-SIGRed – The DNS process has spawned a child process that it shouldn't normally spawn.

  • Prof-DL-U-O-Uplt – This is the first time a kernel module\driver was loaded for this user.

  • Prof-Login-E-SE-DZ – This is the first time a user on this endpoint successfully logged into this network zone.

  • Fact-PCSplashtop-StartedService – The Splashtop remote desktop access service has been started.

  • Prof-UCreate-E-U-DE – This is the first time this user has created a user account on this endpoint.

  • Prof-DllLoad-Dir-O-FD – This is the first time a DLL image file was loaded from this folder for the organization.

  • Fact-SA-ET-RN – A correlation rule has been triggered

  • Fact-FWrite-DExt – A file with an '.exe' extension following a non-executable extension was written to. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_double_extension.yml

  • Fact-PCrundll32-ADllLoad-Trojan –The 'rundll32.exe' process has loaded a module from the AppData folder. This sigma rule is authored by Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_apt_sofacy.yml

  • Prof-FPM-PublicCloud-B-U – This is the first time a cloud storage object was modified to become public in this bucket. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-VPNOut-SDM-U-SD – An abnormal VPN session length has been observed for this user.

  • NumCP-AI-QC-U – An abnormal number of successful AI requests have been performed by this user. AI requests consist of one or more prompts.

  • Prof-RegW-AppPaths-O-U – This is the first time this user has modified a registry key\value under the App Paths key '[HKLM/HKCU]\Software\Microsoft\Windows\CurrentVersion\App Paths'.

  • Prof-PwdChkout-SV-U-SV – This is the first time this user retrieved a password from this safe.

  • Cntx-EL-UCrit-Exec – User is an executive: True\False

  • NumCP-PC-KextloadCmdC-U – An abnormal number of 'kextload' (Kernel Extension Load) process executions have been observed for this user.

  • NumCP-PwdChkout-EC-O-SC – An abnormal number of password retrievals have been observed for the organization.

  • Fact-PC-DExt – A process with an '.exe' extension following a non-executable extension has been executed. This sigma rule is authored by Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_double_extension.yml

  • Prof-DB-DBOp-SZDBN-DBOp – This is the first time a database operation has been observed from this network zone. A database operation consists of any action in a database query (i.e. SELECT, DROP, UPDATE, etc...).

  • Prof-Auth-U-Okta-AnonVPN – This is the first time an Okta user has used an anonymous VPN to authenticate.

  • NumCP-PrivUse-EC-U-APC – An abnormal number of administrative privilege access events have been observed for this user.

  • NumSP-DNSReq-Bytes-SE-Bytes – An abnormal amount of bytes were sent in DNS queries from this endpoint.

  • Prof-GA-CSVC-UD-SVC – This is the first time this cloud service was observed in events in this platform for users in this department.

  • Fact-PCrundll32-Cpl – The Windows control panel process has spawned the 'rundll32.exe' process. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_rundll32_susp_control_dll_load.yml

  • Prof-PCnet-U-O-U-groups – This is the first time local groups have been enumerated using 'net.exe' for this user.

  • Fact-ELF-SA – A service account failed to log into an endpoint using an interactive Windows logon type. A service account is a user account that belongs to an application rather than an end user.

  • Prof-UCreate-U-DE-U-SystemAcct – This is the first time this system account has created a user account on this endpoint.

  • Prof-GA-CSVC-U-SVC – This is the first time this cloud service was observed in events in this platform for this user.

  • Prof-AI-O-Guardrail-Block – This is the first time a user in the organization has triggered an AI guardrail violation.

  • Prof-ELNAC-Loc-U-Loc – This is the first time this user has been observed logging into an endpoint using a network access control platform from this network location.

  • Prof-CA-IC-Publisher-O-Publisher – This is the first time this image publisher has been observed in a successful virtual machine image creation for the organization.

  • Prof-Login-E-U-SZ – This is the first time a successful login has been observed from this network zone for the this user.

  • Fact-PCwmic-WebExec – The WMIC (WMI Command Line) process has been used to invoke a remote XSL script. This sigma rule is authored by Markus Neis, Florian Roth. The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_wmic_squiblytwo_bypass.yml

  • Fact-PCSplashtop-InstalledAgent – The Splashtop remote desktop access agent has been installed.

  • Fact-PCpwrshell-AD – The PowerShell process has executed a 'ps1' script from the AppData folder. This sigma rule is authored by Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_susp_ps_appdata.yml

  • NumDCP-FWrite-EC-U-FP – An abnormal number of unique files have been written for this user.

  • Fact-PCiodine-PExec – The 'iodine.exe' (a DNS tunneling tool) process has been executed. This sigma rule is authored by Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dns_exfiltration_tools_execution.yml

  • Prof-AI-AC-PLT-U – This is the first time this user has created an AI agent with this platform.

  • NumDCP-PwdChkout-SVC-U-SV – An abnormal number of unique safes have been observed in passwords retrieval events for this user.

  • Fact-RegW-CodeSigningPolicy – A code signing policy has been modified by writing to the registry key HKCU\Software\Policies\Microsoft\Windows NT\Driver Signing.

  • Prof-PLA-Loc-U-LocBldg – This is the first time this user has physically accessed this building.

  • Prof-DBQ-RS-U-RS – An abnormal successful database query response size has been observed in this database for this user.

  • Fact-PCpsr-Screenshot – The PSR (Problem Steps Recorder) process has been used to take a screenshot. This is a benign event that is still useful to keep track of. This sigma rule is authored by Beyu Denis, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_psr_capture_screenshots.yml

  • Fact-PCwevtutil-EventTracingDisable – The WEvtUtil (Windows Event Utility) process has been used to disable an ETW (Event Tracing for Windows). This sigma rule is authored by @neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_etw_trace_evasion.yml

  • NumSP-EMR-Bytes-DU-Bytes – An abnormal amount of bytes have been received in incoming emails for this user.

  • Fact-PCsdbinst-SI – The SDBInst (Application Compatibility Database Installer) process has been used to register a shim database. This event is notable as shims can be used to intercept API calls and load malicious DLLs enabling an attacker to run malicious software. This sigma rule is authored by Markus Neis and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sdbinst_shim_persistence.yml

  • Prof-RegR-SAM-O-U – This is the first time this user has read a registry value under the SAM registry key.

  • NumDCP-EL-DEC-O-DE – An abnormal number of unique destination endpoints have been observed in endpoint login events for the organization. These events may include interactive Window logins and other (interactive or not) OS logins, both failed as successful.

  • Fact-PCpwrshell-Empire – The PowerShell process has been used to execute a command associated with an Empire module.

  • Cntx-EMS-Outcome – Email sent outcome

  • Fact-FRead-Shadow – The shadow file is a file in Unix-based operating systems, including Linux and macOS, that stores password-related information for user accounts. It is a crucial component of the system's security as it helps protect user passwords from unauthorized access. An attacker can try to read it to get the passwords of the users.

  • Fact-EMRC-FwR-ExtDom – An inbox rule has been configured to forward emails to an email address that's in a different domain than the rule's creator.

  • NumCP-PCpwrshell-EC-O – An abnormal number of PowerShell process executions have been observed for the organization.

  • Fact-CA-SPM-PublicAWS – A compute snapshot resource in AWS has been made public, granting access to all users.

  • Prof-GA-E-Plt-SZ – This is the first time an activity from this network zone has been observed for this platform.

  • Cntx-VPNln-UCrit-Contractor – User is a contractor : True\False

  • NumSP-DNSReq-Bytes-SZ-Bytes – An abnormal amount of bytes were sent in DNS queries from this network zone.

  • Prof-RegW-FileAssoc-O-U – This is the first time this user has modified a command of a file assocation handler by modifing its registry configuration.

  • NumDCP-EL-UC-SE-U – An abnormal number of unique user names have been observed in endpoint logins from this endpoint. These events may include both failed and successful communications.

  • Cntx-SA-AC-RSev – Correlation rule severity

  • Prof-EL-EDC-O-SZ – This is the first time an endpoint login event to a domain controller has been observed originating from this network zone for the organization. These events may include both failed and successful logins.

  • NumCP-PC-InsmodCmdC-DE – An abnormal number of 'insmod' (Install Module) process executions have been observed on this endpoint.

  • Fact-PCnltest-DomDisc – Windows command line tools to identify domain trust relationships, which may be used during reconnaissance. This sigma rule is authored by E.M. Anhaus, Tony Lambert, oscd.community, omkar72. The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery.yml

  • Prof-UPwdMod-U-O-U – This is the first time this user has modified the password of another user account.

  • Cntx-PC-ECrit-Server-SE – Source endpoint is a server: True\False

  • Prof-AI-UD-Guardrail-Block – This is the first time a user in this department has triggered an AI guardrail violation.

  • Cntx-PC-Critical-Parent-CredEnum – Parent process is a credential enumeration tool: True\False

  • Prof-UCreate-U-Plt-U – This is the first time this user has created a user account on this platform.

  • Prof-SA-AN-SZ-AN – This is the first time this security alert triggered in this network zone.

  • Prof-UDel-U-O-U – This is the first time this user has deleted a user account.

  • Fact-PCstunnel-Exfil – The 'stunnel.exe' (a data exfiltration tool) process has been executed. This sigma rule is authored by Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_exfiltration_and_tunneling_tools_execution.yml

  • Prof-PC-FPermMod-Cacl-O-U – This is the first time a file or folder permissions have been modified using 'icacls.exe' or 'cacls.exe' for this user.

  • Fact-PCLogMeIn-InstalledService – The LogMeIn remote desktop access service has been installed.

  • Prof-VPNIn-E-UD-SE – This is the first time a user in this department attempted to log into a VPN from this endpoint. These events may include both failed and successful logins.

  • Fact-PCcdb-DSE – The CDB (Console Debugger) process has been used to execute a script. This sigma rule is authored by Beyu Denis, oscd.community, Nasreddine Bencherchali and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lolbin_cdb.yml

  • Cntx-EL-UCrit-ADomain – User is a domain account: True\False

  • Prof-RPM-PR-R-Public – This is the first time this role's permissions were modified to make it public.

  • Fact-PCpwrshell-AC – PowerShell commands that attempt to access or record audio from the system microphone. This sigma rule is authored by E.M. Anhaus (Atomic Blue Detections, Endgame), oscd.community, Nasreddine Bencherchali (Nextron Systems). The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_audio_capture.yml

  • Fact-Fwrite-LoginHookFile – Adversaries may use a Login Hook to establish persistence executed upon user logon. They can add or insert a path to a malicious script in the com.apple.loginwindow.plist file, using the LoginHook or LogoutHook key-value pair.

  • NumDCP-SADLP-ProtoC-U-Proto – An abnormal number of unique protocols have been observed in DLP alerts for this user.

  • Fact-RegE-SAM – The registry key 'HKLM\SAM' or 'HKLM\SYSTEM' has been exported from the registry.

  • Cntx-FRead-Repo – File is located in a repository: True\False

  • Fact-PCgup-AF – The Notepad++ updater has been executed from a folder it shouldn't normally execute from. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_gup.yml

  • NumDCP-EL-UC-DESE-U – An abnormal number of unique user names have been observed in endpoint logins for destination endpoint and source endpoint. These events may include both failed and successful communications.

  • Fact-EMS-Competition – An email has been sent to an email domain belonging to a competitor.

  • Fact-PCwindump-NetSniff – The WinDump process (a process dumping tool) has been executed. This sigma rule is authored by Timur Zinniatullin, oscd.community, Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_network_sniffing.yml

  • Cntx-UCreate-UCrit – User is local: True\False

  • NumCP-FUpld-EC-O – An abnormal amount of file upload events have been observed for the organization.

  • Prof-PCroute-NetDisc-U-PN – This is the first time a process execution of 'route.exe' has been observed for this user.

  • Prof-GCreate-U-P-UD – This is the first time users in this department have created a group on this platform.

  • Cntx-SA-VPN – User is logged into a VPN: True\False

  • Prof-SA-AN-O-RN – This is the first time this correlation rule triggered in the organization.

  • NumCP-PC-DirSearchCount-U – An abnormal number of unix file search process executions have been observed for this user.

  • Prof-Fwrite-SystemdService-O-U – This is the first time a systemd service file has been modified by this user.

  • Cntx-GMA-SelfAdd – User added themselves to a security group: True\False

  • Prof-STC-U-PN – This is the first time a scheduled task has been created and configured to execute this process for this user.

  • Fact-PCfsutil-JDel – The FSUtil (File System Utility) process has been used to create or delete a journal. This sigma rule is authored by Ecco, E.M. Anhaus, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_fsutil_usage.yml

  • Prof-DB-U-DBN-U – This is the first time a database event in this database has been observed for this user. A database event consists of any event or operation performed on a database. These events may include both failed and successful operations.

  • Prof-DllLoad-Dll-O-FN – This is the first time this DLL image file was loaded in the organization.

  • Prof-STC-O-UD – This is the first time a scheduled task has been created for users in this department.

  • Fact-PCesentutl-CDbC – The Esentutl (Extensible Storage Engine Utility) process has been used to copy files with credentials data. This sigma rule is authored by Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_copying_sensitive_files_with_credential_data.yml

  • Prof-SA-DP-O-DP – This is the first time a network alert on this port has been triggered in the organization.

  • Fact-PCbcdedit-ESP – The BCDEdit (Boot Configuration Data Edit) process has been used to enable test signing.

  • Cntx-PCquser-ADisc – Local accounts enumerated using quser.exe: True\False

  • Fact-PCpassworddump-SecurityXploded – The 'passworddump.exe' process (a password dumping tool from the 'SecurityXploded' toolkit) has been executed. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_secutyxploded.yml

  • Cntx-GA-UDisabled – User owns a disabled account: True\False

  • Fact-UI-UOO – A user outside the organization was invited to this platform.

  • Prof-PC-CmdArgs-InstallUtil-O-EXEParam – This is the first time the 'installutil.exe' process has been executed with this EXE file as a parameter.

  • Prof-RegW-Services-O-U – This is the first time this user has modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • NumCP-EMS-EC-U-Id – An abnormal number of outgoing emails have been observed for this user.

  • Prof-RegW-CORPROFILER-O-U – This is the first time this user has modified or created a registry value for an environment variable associated with the COR_PROFILER.

  • Prof-Network-ERDP-DE-SE – This is the first time a successful RDP connection has been observed from this source endpoint to this destination endpoint.

  • Prof-GCreate-U-O-UD – This is the first time for users in this department to create a group for the organization.

  • Fact-PCsharphound-BloodHound – The 'sharphound.exe' (a network domain enumeration tool) process has been executed.

  • Prof-EMS-Country-UD-DCountry – This is the first time a user in this department has sent an email to this country, as determined by geolocation lookup.

  • Prof-GA-Country-O-DCountry – This is the first time an activity has been observed to this country, determined by geolocation lookup.

  • NumCP-FUpld-EC-UD – An abnormal amount of file upload events have been observed for users in this department.

  • Prof-PC-PN-PltU-PN – This is the first time this process has been executed in this platform for this user. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • Fact-PCnwp-NWP-PPP – A Windows system process has been spawned by a parent process that's in a folder it shouldn't normally execute from. This sigma rule is authored by vburov and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_proc_wrong_parent.yml

  • Cntx-PC-Critical-Parent-Shell – Parent process is a shell process

  • Prof-PrivUse-U-O-U – This is the first time a Windows privileged has been used and invoked from this directory for this process.

  • Prof-DB-E-UDBN-SIP – This is the first time a successful database event in this database has been observed for this user from this IP address.

  • Prof-AI-AC-O-U – This is the first time this user has created an AI agent.

  • Fact-AI-Guardrail-Block – An AI guardrail violation has been observed.

  • Fact-PC-TsconRDPRedirection – The 'tscon.exe' has been used to redirect RDP traffic.

  • NumCP-ELF-EC-U-DZ – An abnormal number of failed logins to endpoints in this network zone have been observed for this user.

  • Prof-DS-E-UD-SE – This is the first time a user in this department performed an activity on a directory service object from this endpoint.

  • Fact-PCassoc-FAssocCh – The Assoc (File Association) process has been used to change the association of an extension to execution. This sigma rule is authored by Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_change_default_file_association.yml

  • Fact-PChttptunnel-ExfilTExec – The 'httptunnel.exe' (a data exfiltration tool) process has been executed. This sigma rule is authored by Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_exfiltration_and_tunneling_tools_execution.yml

  • Fact-PCping-HexEn – The 'ping.exe' process has been used to ping a hex encoded IP address. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_ping_hex_ip.yml

  • Fact-PCspctl-DisableGatekeeper – The 'spctl' command has been used to disable the Gatekeeper.

  • Prof-RegD-Services-O-UD – This is the first time users in this department have deleted a service by deleting a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-BPM-Public-O-U – This is the first time this user has attempte to modify the IAM policy or the ACL of an AWS bucket to make it public to all users. These events may include both failed and successful modifications.

  • NumCP-AI-MC-U – An abnormal amount of AI agent modifications have been observed for a user.

  • Prof-RA-R-UDPlt-RN – This is the first time this role was assigned by users in this department on this platform.

  • Prof-SEPwrshell-SN-U-SN – This is the first time this user executed a PowerShell script with this name.

  • Prof-RCM-U-O-UPlt – This is the first time this user modified or created a role on this platform.

  • Prof-SA-AN-SE-AN – This is the first time this security alert triggered from this endpoint.

  • Fact-PCTeamViewer-StartedService – The TeamViewer remote desktop access service has been started.

  • Prof-DS-E-U-SZ – This is the first time this user performed an activity on a directory service object from this network zone.

  • Prof-EL-HT-U-HT – This is the first time this user has attempted to log into an endpoint of this type (server, workstation...). These events may include both failed and successful logins.

  • NumSP-Web-Bytes-U-BytesInPost – An abnormal amount of bytes have been uploaded to the web with POST requests for this user.

  • NumDCP-FC-EC-U-FP – An abnormal number of unique files have been copied in this platform for this user.

  • Prof-VPNIn-U-O-UC – This is the first time a user in this country attempted to log into a VPN. These events may include both failed and successful logins.

  • Cntx-PC-Critical-Parent-Webserver – Parent process is a web server process: True\False

  • NumCP-DSOW-EC-O – An abnormal number of directory service write events have been observed for the organization. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-EW-DCShadow-SE-O-SE – This is the first time the GC (global catalog) and DRS (directory replication service) service principal names have been added to this matured endpoint. These SPNs are required for the active directory replication process, and can be added to a rogue domain controller to execute a DCShadow attack.

  • Prof-WinSC-E-U-DE – This is the first time a service creation has been observed on this endpoint for this user.

  • Cntx-PC-Critical-Shell – Process is a shell process

  • Prof-CA-IKM-KeyCreateGCP-O-U – This is the first time this user added or modified an SSH key of an instance in GCP. These events may include both failed and successful modifications.

  • Fact-WinSC-SuspSC-Temp – A service has been created from a temporary internet files directory.

  • Cntx-SA-PA – Alert is from a third party: True\False

  • Fact-PCLogMeIn-StartedService – The LogMeIn remote desktop access service has been started.

  • Fact-RegE-Certs – Registry values related to certificates and private keys have been exported.

  • Prof-VPNIn-E-UD-DE – This is the first time a user in this department attempted to log into a VPN with this server. These events may include both failed and successful logins.

  • Fact-PCsvchost-DCOMLaunch – Remote DCOM activation under DcomLaunch service.

  • Cntx-GA-TIRansomware-SIP – Source IP is marked as a ransomware by threat intelligence: True\False

  • NumCP-ELF-EC-U-RDP – An abnormal number of failed RDP (remote desktop protocol) logins to this endpoint have been observed for this user.

  • NumCP-RegD-Services-EC-U – An abnormal number of unique service configurations have been deleted from the registry for this user.

  • Prof-GA-Plt-U-Plt – This is the first activity observed on this platform for this user.

  • Prof-MFA-MFADevice-U-MFADevice – This is the first time this user authenticates with MFA authentication using this device. These events may include both failed and successful logins.

  • Prof-USB-E-U-SE – This is the first time a peripheral device activity has been observed from this endpoint for this user.

  • Cntx-EL-UCrit-UPriv – User is privileged: True\False

  • Fact-Web-TIPhish-PhishDom – An HTTP communication attempt has been made to a phishing associated domain. These events may include both failed and successful traffic.

  • Prof-RegR-LSA-O-U – This is the first time this user has read a LSA secret from the registry.

  • Prof-GA-Op-Plt-Op – This is the first time this operation has been observed for this platform. Operations can include function types, APIs, application activities and more.

  • Fact-PCreg-SRH – Attempt to export sensitive Windows registry hives using reg.exe, which may be used to collect credentials or system secrets. This sigma rule is authored by Teymur Kheirkhabarov, Endgame, JHasenbusch, Daniil Yugoslavskiy, oscd.community, frack113. The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_reg_dumping_sensitive_hives.yml

  • Fact-PCreg-WDigest – The 'reg.exe' has been used to enable WDigest authentication through the registry.

  • NumDCP-AL-UC-PltSE-U – An abnormal number of unique user names have been observed in application logins to this platform from this endpoint. These events may include both failed and successful communications.

  • Prof-EL-EDC-U-SZ – This is the first time an endpoint login event to a domain controller has been observed originating from this network zone for this user. These events may include both failed and successful logins.

  • Prof-VPNIn-Rlm-UD-Rlm – This is the first time a user in this department attempted to log into a VPN with this realm. These events may include both failed and successful logins.

  • Fact-PCpwrshell-ELT – The PowerShell process has been used to clear or delete an event log. This sigma rule is authored by Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105 and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_eventlog_clear.yml

  • Fact-PCAnyDesk-InstalledAgent – The AnyDesk remote desktop access service has been installed.

  • Fact-BPM-Public-Policy – The IAM policy or the ACL of an AWS bucket has been successfully modified to make it public to all users.

  • Fact-EA-KerberosNotPreAuth – A user has successfully authenticated against an endpoint via Kerberos authentication with preauthentication 0.

  • Prof-USwtch-U-U-DU – This is the first time this user has performed an account switch to this account.

  • Prof-ShA-U-SN – This is the first time this network share has been accessed by this user.

  • Cntx-PC-ECrit-Server-DE – Destination endpoint is a server: True\False

  • NumDCP-FUSB-FPC-U-FP – An abnormal number of unique files has been written to peripheral storage devices for this user.

  • Fact-PCpwrshell-En-SuspEnc – The PowerShell process has been used to execute a command associated with the ChromeLoader malware. This sigma rule is authored by Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, Anton Kutepov, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_base64_encoded_cmd.yml

  • NumCP-AppLF-EC-U – An abnormal number of application login failures have been observed for this user.

  • Prof-VPNIn-E-U-DE – This is the first time this user attempted to log into a VPN with this server. These events may include both failed and successful logins.

  • Cntx-EL-ECrit-CS – Destination endpoint is critical: True\False

  • NumSP-EMS-Bytes-U-Bytes – An abnormal amount of bytes have been sent in outgoing emails for this user.

  • Prof-RegW-IFEO-O-U – This is the first time this user has modified or created the Image File Execution Options of a process by writing to the registry value 'Debugger' under the key 'HKLM\SOFTWARE{\Wow6432Node}\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<executable>'.

  • Prof-RegR-SAM-O-UD – This is the first time users in this department have read a registry value under the SAM registry key.

  • Prof-PC-PN-DE-PN – This is the first time this process has been executed on this endpoint. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • Fact-PC-RemoteExecAdminShare – A remote process has been executed and redirected to an admin share. This activity can be related to the execution of Impacket.

  • Prof-MPermMod-U-O-U – This is the first time this user has modified permissions in a mailbox.

  • Fact-FCopy-Outlook-FExt – A file ending in a '.pst'/'.ost' extension has been copied.

  • Prof-SA-E-U-SE – This is the first time a security alert triggered from this endpoint for this user.

  • NumCP-EScrn-EC-U – An abnormal number of screenshot events have been observed for this user.

  • Cntx-ShA-PrivU – User is privileged: True\False

  • Fact-PC-Shell-Base64 – Identifies base64 being decoded and passed to a Linux shell

  • Fact-PCwmic-ELT – The WMIC (WMI Command Line) process has been used to clear or delete an event log. This sigma rule is authored by Ecco, Daniil Yugoslavskiy, oscd.community, D3F7A5105 and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_eventlog_clear.yml

  • Prof-DS-AT-U-AT – This is the first time this directory service activity has been observed for this user. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-USB-U-O-U – This is the first time a peripheral device activity has been observed for this user.

  • Prof-DB-E-UDBN-SZ – This is the first time a successful database event in this database has been observed for this user from this network zone.

  • Fact-PCcsi-AP – PowerShell starting the C# Interactive Console (csi.exe), which may be used to execute code in an unusual or hidden way. This sigma rule is authored by Michael R. (@nahamike01). The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_use_of_csharp_console.yml

  • NumSP-VPNOut-Bytes-U-Bytes – An abnormal amount of bytes have been uploaded in VPN session for this user.

  • Prof-GMA-U-DE-U – This is the first time this system account has added a user to a group on this endpoint.

  • Cntx-PCplink-Exfil – Process is 'plink.exe': True\False

  • Prof-PCnet-U-O-U-netlocalgroupadmin – This is the first time a user account has been added to the administrators group using 'net.exe' for this user.

  • Fact-EMS-SrcCode – An email containing a source code file attachment has been sent.

  • Fact-PCcrackmapexec-CrackMapExecWin – The 'crackmapexec.exe' (a penetration testing tool) process has been executed. This sigma rule is authored by Markus Neis and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_apt_dragonfly.yml

  • Fact-Web-TI-RepDom – An HTTP communication attempt has been made to a bad reputation domain. These events may include both failed and successful traffic.

  • Fact-PCbcdedit-DisRec – The BCDEdit (Boot Configuration Data Edit) process has been used to disable Windows recovery mode. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcdedit_boot_conf_tamper.yml

  • Prof-DBQ-RS-SZ-RS – An abnormal successful database query response size has been observed for this source network zone.

  • NumCP-RegD-Services-EC-DE – An abnormal number of unique service configurations have been deleted from the registry on this device.

  • NumDC-Git-RepoC-U-Object – An abnormal number of unique repository endpoints where secrets are generally stored, which may indicate unauthorized enumeration or insider reconnaissance activity. Repository name is parsed into the object field which is being counted here.

  • Prof-GA-Brwsr-UD-Brwsr – This is the first time this web browser has been observed for users in this department.

  • Fact-PCbitsadmin-AbP – The 'bitsadmin.exe' process has been spawned by a command line executable. This sigma rule is authored by Florian Roth (Nextron Systems), Tim Shelton and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_shell_spawn_susp_program.yml

  • Prof-CA-IRC-O-U – This is the first time this user executed a remote command on an instance. These events may include both failed and successful executions.

  • Fact-RegD-RDPCon – The RDP connection history has been cleared via the registry.

  • Prof-VPNIn-U-O-UD – This is the first time a user in this department attempted to log into a VPN. These events may include both failed and successful logins.

  • Prof-PrivUse-U-O-UD – This is the first time a Windows privileged has been used and invoked for users in this department.

  • Cntx-FA-FCrit-SrcExecutable – Source file is an executable: True\False

  • Fact-PCjava-JavaRD – The Java process has been executed with remote debugging allowed for more than just the localhost. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_vul_java_remote_debugging.yml

  • Prof-RegD-Services-O-U – This is the first time this user has deleted a service by deleting a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • NumDCP-AL-UC-Plt-U-SE – An abnormal number of unique user names have been observed in application logins to this platform per source endpoint. These events may include both failed and successful communications.

  • Fact-PCntdsutil-NTDS – The 'ntdsutil.exe' (NT Directory Service Utility) process has been executed. This sigma rule is authored by Thomas Patzke and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_ntdsutil_usage.yml

  • Fact-CA-IPM-PublicAWS – A compute image resource in AWS has been made public, granting access to all users.

  • Prof-BC-U-O-U – This is the first time this user has successfully created a cloud storage bucket.

  • Fact-FWrite-SystemCADirs – A file was written in a System CA (Certificate Authority) directory.

  • Cntx-PC-Critical-CredEnum – Process is a credential enumeration tool: True\False

  • Fact-PCwbadmin-CD – The WBAdmin (Windows Backup Admin) process has been used to delete a backup catalog.

  • Prof-PC-O-Pdir – This is the first time a process execution has been observed from this directory.

  • Prof-USB-DevId-U-DevId – This is the first time this peripheral device ID has been observed for this user.

  • Prof-DllLoad-Ext-O-FileExt – This is the first time a DLL image file with this extension was loaded for the organization.

  • Fact-RA-WDigest – The WDigest authentication protocol, which uses clear-text credential caching, has been enabled via the registry.

  • Prof-Login-E-U-DZ – This is the first time this user successfully logged into this network zone.

  • NumDCP-PCHEnum-TC-U-HEnum – An abnormal number of unique host enumeration tools have been executed for this user.

  • Fact-FWrite-SSHConfigFile – The sshd_config file was written to.

  • Cntx-Web-UCrit-Priv – User is privileged: True\False

  • Fact-RegW-OfficeTest – An Office test file has been modified by writing to the registry key HKCU\Software\Microsoft\Office test\Special\Perf.

  • Fact-RegE-LSA – The registry key 'HKLM\SECURITY\Policy\Secrets' has been exported from the registry.

  • Fact-RegW-AppInit – An AppInit DLL registry configuration has been modified or created under the registry key 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows' or 'HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Windows'

  • Fact-PCbcdedit-BootEM – bcdedit.exe usage (e.g., delete, deletevalue, import, safeboot, network) tied to boot configuration tampering which may indicate attempts to damage the system or maintain persistence. This sigma rule is authored by @neu5ron. The content of this repository is released under the [Detection Rule License (DRL) 1.1](https://github.com/SigmaHQ/Detection-Rule-License). Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcdedit_susp_execution.yml

  • Prof-CA-IPM-AddMember-O-U – This is the first time a user has successfully modified the attributes of a compute image in AWS and shared it with a user/group.

  • Fact-PCreg-AutorunMod – The 'reg.exe' process has been used to modify an AutoRun registry key. This sigma rule is authored by Victor Sergeev, Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_reg_direct_asep_registry_keys_modification.yml

  • NumCP-ELF-EC-U-SE – An abnormal number of failed endpoint logins from this endpoint have been observed for this user.

  • Cntx-VPNln-UCrit-Vendor – User is a vendor: True\False

  • Prof-SA-Elbl-DZ-Dlbl – This is the first time a security alert triggered on a server for this destination network zone.

  • Fact-PCpwrshell-BitsJob – The PowerShell process has been used to execute a BITS (Background Intelligent Transfer Service) transfer. This sigma rule is authored by Endgame, JHasenbusch (ported to sigma for oscd.community) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules-deprecated/windows/proc_creation_win_powershell_bitsjob.yml

  • Prof-EMR-ED-UD-ED – This is the first time a user in this department has received an email from this email domain.

  • Fact-PCwhoami-SysPerm – The 'whoami.exe' process has been executed by the system user.

  • Fact-PCDotNet-CommandLine – This .NET supporting process was created with an URL in the commandline.

  • NumDCP-FRead-EC-SA-FP – An abnormal number of unique files have been read in this storage account for this user.

  • Cntx-PC-Critical-SystemEnum – Process is a system enumeration tool: True\False

  • Prof-FWrite-UMWorkerProcess-PN-FN – This is the first time this file was created by the 'umworkerprocess.exe' process.

  • Prof-SA-AN-UD-RN – This is the first time this correlation rule triggered for users in this department.

  • NumCP-PwdChkout-EC-UD-SC – An abnormal number of password retrievals have been observed for users in this department.

  • Fact-PCwevtutil-EventTracingClear – The WEvtUtil (Windows Event Utility) process has been used to clear an ETW (Event Tracing for Windows). This sigma rule is authored by @neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_etw_trace_evasion.yml

  • Prof-DS-E-U-SE – This is the first time this user performed an activity on a directory service object from this endpoint.

  • Fact-RegW-EventLogDisabled – The Event Log service has been disabled via the registry.

  • Prof-STC-O-U – This is the first time a scheduled task has been created for this user.

  • Fact-PC-SysP – The 'rundll32.exe' process has been used to execute a command associated with CVE-2023-23397.

  • Fact-PCappcmd-ModIns – The 'appcmd.exe' (IIS Application Command Line) process has been used to install an IIS native-code module.

  • Prof-PC-PPN-PPN-PN – This is the first time this child process has been observed for this matured parent process.

  • Cntx-PC-FC-PDir – Process executed from a temporary directory: True\False

  • Prof-PC-PN-PltSZ-PN – This is the first time this process has been executed in this platform from this network zone. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • Prof-PC-PN-PltUD-PN – This is the first time this process has been executed in this platform for users in this department. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • NumSP-DNSReq-Bytes-O-Bytes – An abnormal amount of bytes were sent in DNS queries from endpoints in the organization.

  • Prof-EMR-ED-U-ED – This is the first time this user has received an email from this email domain.

  • Fact-FCopy-Outlook-FDir – A file from the Outlook folder has been copied to a non-Outlook folder.

  • Prof-PwdChkout-U-O-U – This is the first time this user retrieved a password.

  • Prof-DSF-AT-UD-AT – This is the first time this directory service activity type failed for users in this department. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-VPNIn-U-O-U – This is the first time this user attempted to log into a VPN. These events may include both failed and successful logins.

  • Prof-SADLP-Proto-U-Proto – This is the first time a DLP alert triggered on this protocol for this user.

  • Prof-PC-U-O-U-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed for this user.

  • Fact-PCschtasks-TM – The SchTasks (Scheduled Tasks) process has been used to modify the user account configuration of a scheduled task.

  • Fact-BPM-Public-AccessBlock – The public access block of a bucket or an account in AWS has been successfully modified to remove public access prevention. This activity enables the bucket or the entire account to become public to all users.

  • Prof-FPM-PublicCloud-P-U – This is the first time this user modified a cloud storage object to become public. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-AL-E-U-SE – This is the first time this user attempted to log into an application from this endpoint. These events may include both failed and successful logins.

  • Fact-STC-SP – A scheduled task has been configured to execute the PowerShell process.

  • Prof-WinSC-E-O-DZ – This is the first time a service creation has been observed in this network zone.

  • Fact-PCmsiexec-WebExec – The MsiExec process (Windows Installer) has been used to execute a remote script using a web addresses parameter. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_msiexec_web_install.yml

  • NumDCP-EL-DEC-SE-DE – An abnormal number of unique destination endpoints have been observed in successful endpoint login events from this endpoint. These events may include interactive Window logins and other (interactive or not) OS logins.

  • Prof-PLA-Loc-U-LocCity – This is the first time this user has physically accessed a building in this city.

  • NumCP-RuleDel-EC-U – An abnormal number of security rules deletion events have been observed for this user.

  • Fact-RegW-TrustProvider – A trust provider component has been modified via the registry.

  • Cntx-ShA-NamedPipe – Share is a known named pipe: True\False

  • Fact-PCat-IJob – The 'at.exe' process has been used to execute an interactive scheduled task. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a29d0e/rules/windows/process_creation/proc_creation_win_at_interactive_execution.yml

  • Prof-CPM-Resource-O-R – This is the first time an IAM policy of a resource in this directory has been successfully modified in GCP. IAM policies determine the roles and permissions granted to users on a resource.

  • Fact-PCpwrshell-ADS – The PowerShell process has been used to execute a PowerShell script from an ADS (Alternate Data Stream). This sigma rule is authored by Sergey Soldatov, Kaspersky Lab, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_run_script_from_ads.yml

  • Prof-GA-RGN-U-RGN – This is the first time this cloud region has been observed for this user.

  • Fact-PCpwrshell-Base64En – The PowerShell process has been used to decode a Base64 string using 'frombase64string'. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_frombase64string.yml

  • Fact-PCeqnedt32-EE – The 'eqnedt32.exe' (EquationEditor) process has been executed. This is a known built in tool used by attackers due to its ability for exploitation. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_exploit_cve_2017_11882.yml

  • NumDCP-EL-UC-DE-U-SE – An abnormal number of unique user names have been observed in endpoint logins to this endpoint per source endpoint. These events may include both failed and successful communications.

  • Fact-PCfltmc-SysmonDU – The FltMC (Filter Manager Control) process has been used to unload the Sysmon driver. This sigma rule is authored by Kirill Kiryanov, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysmon_driver_unload.yml

  • NumDC-RA-U-RAC – An abnormal number of role-assume requests have been observed for this user. These events can include both successful and failed assumed roles.

  • Prof-DllLoad-Ext-SE-FileExt – This is the first time a DLL image file with this extension was loaded on this endpoint.

  • Prof-PCca-U-O-U – This is the first time root certificate has been installed on a Linux machine using 'update-ca-certificates' or 'update-ca-trust' for this user.

  • NumDCP-RegR-RPC-Cert-U-RP – An abnormal number of unique certificates and private keys related registry values have been read by this user.

  • Fact-PCLogMeIn-InstalledAgent – The LogMeIn remote desktop access agent has been installed.

  • Fact-PCpwrshell-Base64En-Hidden – The PowerShell has been used to execute a known malicious encoded command. This sigma rule is authored by John Lambert (rule) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_hidden_b64_cmd.yml

  • Prof-CPM-UCreate-O-U – This is the first time this user created or modified an IAM policy on this cloud platform. IAM policies determine the roles and permissions granted to users on a resource. These events may include both failed and successful creations\modifications.

  • Prof-STC-O-PN – This is the first time a scheduled task has been created and configured to execute this process for the organization.

  • Prof-UCreate-U-O-UD – This is the first time a user in this department has created a user account.

  • Fact-PCcsws-AP – A Windows Script Host process ('cscript.exe' or 'wscript.exe') has been spawned by the RegSvr (Register Server) process. This sigma rule is authored by Florian Roth (Nextron Systems), oscd.community, Tim Shelton and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_regsvr32_anomalies.yml

  • Prof-USB-E-O-SE - This is the first time a peripheral device activity has been observed from this endpoint.

  • Prof-RegW-SafeBoot-O-U – This is the first time this user has modifed the safe mode boot configuration by writing to a registry value/key under the registry key HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal.

  • Fact-PCrundll32-ADllLoad-Susp – The 'rundll32.exe' process has executed an exported module function using an ordinal number. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_rundll32_by_ordinal.yml

  • Prof-USB-E-UD-SE – This is the first time a peripheral device activity has been observed from this endpoint for users in this department.

  • NumCP-VPNlnF-EC-O-U-30Days – An abnormal number of failed VPN logins have been observed for the organization by this user in 30 days.

  • Prof-EMS-FileExt-O-FileExt – This is the first time a user in the organization has sent an email attachment with this extension.

  • Prof-USB-DevId-SE-DevId – This is the first time this peripheral device ID has been observed from this endpoint.

  • Fact-FWrite-SELinuxConfigFile – The SELinux (Security-Enhanced Linux) configuration file was written to.

  • Prof-Login-E-O-SZ – This is the first time a successful login has been observed from this network zone for the organization.

  • Fact-PCoffice-Regsvr32 – A Microsoft Office process has spawned the RegSvr (Registration Service) process. This sigma rule is authored by Florian Roth (Nextron Systems), oscd.community, Tim Shelton and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_regsvr32_anomalies.yml

  • Fact-Web-TITOR-Url – An HTTP communication attempt has been made to a URL containing '/tor/server'. These events may include both failed and successful traffic.

  • Fact-EL-UnauthorizedWindowsRDP – An unauthorized user has attempted and failed a Remote Desktop Protocol (RDP) login to a Windows endpoint.

  • NumCP-Auth-MfaEC-U – An abnormal number of Multi-Factor Authentication (MFA) authentication events for this user have been observed. These events may include both failed and successful authentications to an MFA service.

  • Prof-DS-AT-SE-AT – This is the first time this directory service activity has been observed from this endpoint. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-MFA-AuthMethod-U-AuthMethod – This is the first time this user authenticates with MFA authentication using this authentication method. These events may include both failed and successful logins.

  • Cntx-ShA-AdminShare – Share is an admin share: True\False

  • NumSP-FRead-FS-B-Bytes – An abnormal amount of file bytes have been read in this bucket for this user.

  • Cntx-ELF-LF-BadCred – Login failed due to bad credentials: True\False

  • Prof-Login-E-UD-DZ – This is the first time a user in this department successfully logged into this network zone.

  • Prof-ULck-U-O-U – This is the first time this user has locked a user account.

  • Prof-CPM-URevertAWS-O-U – This is the first time this user has successfully changed the default policy version of a policy in AWS. Policies in AWS are the documents that dictate what permissions are granted to identities and resources.

  • Prof-Network-Country-DP-SCountry – This is the first time a successful network connection has been observed from this country, determined by geolocation lookup, to the organization with this port.

  • Fact-PCLsass-ProcDumpLsass – The 'procdump.exe' process has been used to dump the LSASS process. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sysinternals_procdump_lsass.yml

  • Prof-DS-A-UDSOT-A – This is the first time this activity has been observed on this directory service object class for this user. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-AL-MFA-U-MFA – This is the first time this user has logged into an application without using multi factor authentication (MFA).

  • Prof-GMA-U-O-U – This is the first time a user has been added to a group by this user.

  • Prof-SA-E-SZ-SE – This is the first time a security alert triggered from this endpoint in this network zone.

  • NumCP-AI-U-Guardrail-Block – An abnormal amount of AI guardrail violations have been observed for a user.

  • NumCP-PC-CritCmdC-O – An abnormal number of critical command executions have been observed for the organization.

  • Prof-GA-OS-U-OS – This is the first time this operating system has been observed for this user.

  • NumDCP-EL-DEC-U-DE – An abnormal number of unique destination endpoints have been observed in endpoint login events for this user. These events may include interactive Window logins and other (interactive or not) OS logins, both failed as successful.

  • Fact-PCrundll32-PwrshellDll-PPN – The PowerShell process has been used to spawn 'rundll32.exe' and execute a DLL from a temporary folder.

  • Prof-GA-Country-DZ-SCountry – This is the first time an activity has been observed from this country to this network zone, determined by geolocation lookup.

  • NumDCP-FRead-FS-U-DE – An abnormal number of unique destination endpoints have been observed in file read events for this user.

  • Fact-CPM-PCrit-AWSAdmin – A policy with critical administrative permissions has been successfully created or attached to an identity in AWS. Policies in AWS are the documents that dictates what permissions are granted to identities and resources.

  • Cntx-Network-Protocol – Network protocol

  • Prof-Web-WebDom-O-Tld – This is the first time a successful HTTP communication to this top level domain has been observed for the organization.

  • Fact-Web-ShellUserAgent – An HTTP communication attempt has been made with a user-agent associated with a command shell. These events may include both failed and successful traffic.

  • Prof-FA-SCFA-O-UD – This is the first time source code file activity (by file extension) has been observed for users in this department. File activity could include read, delete, write or any other type of file related operations.

  • Prof-WinSC-E-DE-DZ – This is the first time a service creation has been observed on this endpoint for this destination network zone.

  • NumDCP-FRead-EC-B-FP – An abnormal number of unique files have been read in this bucket for this user.

  • Fact-RegW-AppCert – An AppCert DLL registry configuration has been modified or created under the registry key 'HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager'

  • Fact-RegW-RootCert – A root certificate has been installed via the registry.

  • Fact-PCmshta-JsExec – The MsHTA (Microsoft HTML Application) process has been used to execute javascript. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_mshta_javascript.yml

  • Prof-FWrite-AuthorizedKeys-O-U – This is the first time an 'authorized_keys' file has been modified by this user.

  • NumCP-DL-EC-UPlt – An abnormal number of kernel module or drivers have been loaded for this user.

  • NumCP-DL-EC-SE – An abnormal number of kernel module or drivers have been loaded on this endpoint.

  • NumDCP-GA-OpC-UPlt-FOp – An abnormal number of unique failed operations have been observed in this platform for this user.

  • NumCP-DB-DBOpC-U – An abnormal number of database operation events were observed for this user - this can include both unique and non-unique operations. A database operation consists of any action in a database query (i.e. SELECT, DROP, UPDATE, etc...). These events may include both failed and successful operations.

  • Prof-Fwrite-AuditRule-O-U – This is the first time an audit rule file has been modified by this user.

  • Cntx-SA-UCrit – User is an executive: True\False

  • Fact-WinSC-SuspSC-Param – A service has been created with suspicious execution command parameters.

  • Prof-PCIOC-IOCPenT-U-PenT – This is the first time a process execution of a known pentesting tool has been observed for this user.

  • NumCP-FDel-EC-U – An abnormal number of file deletion events have been observed for this user.

  • Prof-FDel-U-O-U-LogFile – This is the first time a log file has been deleted by this user.

  • NumCP-AI-QC-UO – An abnormal number of successful AI requests for the organization have been performed by this user. AI requests may consist of one or more prompts.

  • Cntx-EL-UCrit-SA – User is a service account: True\False

  • Prof-RPM-U-O-UPlt – This is the first time this user modified the permissions of a role on this platform.

  • Fact-PCdir-UDisc – The 'dir.exe' process has been used to list users by enumerating the users folder.

  • Cntx-Web-WDCrit-FS – Web domain is a file sharing domain: True\False

  • NumCP-RegD-EC-DE – An abnormal number of registry deletion events have been observed on this device.

  • NumCP-PC-ChownCount-U – An abnormal number of 'chown' (Change Owner) process executions have been observed for this user.

  • NumCP-ELF-EC-U-DE – An abnormal number of failed endpoint logins to this endpoint have been observed for this user.

  • Prof-BPM-U-PBACL-O-U – This is the first time this user has successful edited the ACL policy of a bucket in AWS.

  • Fact-LogCl-LogClear-AT – An audit log has been cleared.

  • Prof-Login-Plt-U-Plt – This is the first time this user has attempted to log into this platform. These events do not include endpoint events and may include both failed and successful logins.

  • Prof-SA-PN-UD-PN – This is the first time an alert triggered on this process for users in this department.

  • Fact-PCdctask64-Zoho – The ZOHO 'dctask64.exe' process has been used to perform process injection. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_dctask64_proc_inject.yml

  • Prof-SA-E-UD-SE – This is the first time a security alert triggered from this endpoint for users in this department.

  • Prof-VPNIn-E-U-SE – This is the first time this user attempted to log into a VPN from this endpoint. These events may include both failed and successful logins.

  • Prof-PCMsbuild-E-O-DE – This is the first time the 'msbuild.exe' process has been used to build and execute a project on this endpoint.

  • NumCP-AI-QC-WID – An abnormal number of successful AI requests has been observed for this workspace. AI requests may consist of one or more prompts.

  • Cntx-USwtch-UCrit – User is privileged: True\False

  • Prof-PC-CmdArgs-Msbuild-O-CsprojParam – This is the first time the 'msbuild.exe' process has been used to build this C# project.

  • NumCP-PC-InsmodCmdC-U – An abnormal number of 'insmod' (Install Module) process executions have been observed for this user.

  • NumCP-PC-ChmodCount-U – An abnormal number of 'chmod' (Change Mode) process executions have been observed for this user.

  • Prof-PC-E-NetUserAdd-O-DZ – This is the first time a user account has been created using 'net.exe' on this network zone.

  • NumCP-EMR-EC-DU – An abnormal number of incoming emails have been observed for this user.

  • Fact-PCcmdkey-UDisc – The CMDKey (Credential Manager Command Line) process has been used to enumerate cached credentials. This sigma rule is authored by jmallette, Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmdkey_recon.yml

  • NumCP-SEPwrshell-CmdInvC-O-InvC – An abnormal number of PowerShell command invocations have been observed for the organization.

  • Prof-RegW-U-DetailsLen – An abnormal registry details length has been observed for this user.

  • NumDCP-VPNln-UC-O-U-SIP – An abnormal number of unique user names have been observed in VPN login for the organization per source IP. These events may include both failed and successful communications.

  • Fact-PCdsq-DomDisc – The DSQuery (Directory Service Query) process has been used to discover domain trusts. This sigma rule is authored by E.M. Anhaus, Tony Lambert, oscd.community, omkar72 and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dsquery_domain_trust_discovery.yml

  • Prof-RegW-COM-U-CLSID – This is the first time this user has modified the registry path to a COM class with this CLSID.

  • Cntx-PC-Critical-Parent-MSOffice – Parent process is a Microsoft Office process: True\False

  • Prof-EMS-FileExt-UD-FileExt – This is the first time a user in this department has sent an email attachment with this extension.

  • Cntx-PCwmic-ADisc – Local accounts enumerated using wmic.exe in on endpoint: True\False

  • Prof-DS-DSOC-UD-DSOC – This is the first time a user in this department performed an activity on a directory service object with this object class.

  • Prof-GA-Plt-UD-Plt – This is the first activity observed on this platform for users in this department.

  • Prof-USwtch-U-O-U – This is the first time this user has switched accounts.

  • Prof-PC-U-O-U-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed for this user.

  • Fact-Fwrite-HiddenFile – Creating a file that starts with ".". File that starts with "." is a hidden file. An attacker can create hidden file to evade detection.

  • Prof-CA-SPM-AddMember-O-U – This is the first time this user has successfully modified the attributes of a compute snapshot in AWS and shared it with a user/group.

  • Cntx-EL-ECrit-DC – Destination endpoint is a Domain Controller: True\False

  • NumCP-FDnld-EC-UD – An abnormal amount of file download events have been observed for users in this department.

  • Fact-DNS-DomQ-Sunburst – A DNS query has been observed requesting a domain associated with the SUNBURST malware.

  • Prof-UCreate-U-O-U – This is the first time this user has created a user account.

  • NumCP-VPNlnF-EC-U – An abnormal number of vpn login failures have been observed for this user.

  • NumSP-DBQ-RS-U-RS – An abnormal database query response size has been observed for this user. These events may include both failed and successful queries.

  • Prof-Fwrite-E-O-DE-Xdg – This is the first time a XDG autostart file was created on this endpoint.

  • Prof-SA-AN-O-AN – This is the first time this security alert triggered in the organization.

  • Cntx-Web-ECrit-DC – Endpoint is a Domain Controller: True\False

  • Prof-FA-FDir-DE-NTDSDir – This is the first time a NTDS access has been observed in this folder on this endpoint. NTDS activities could include database attach or detach.

  • Prof-LogCl-U-O-U – This is the first time an audit log has been cleared by this user.

  • Prof-EL-E-UD-DE – This is the first time a user from this department attempted to log into this endpoint. These events may include both failed and successful logins.

  • Fact-MPermMod-UCrit – A user has modified the mailbox permissions of an executive user.

  • Fact-AI-PI-ShowSystemPrompt – An AI request attempting to display the AI system prompt has been sent.

  • Prof-STC-PP-TN-PP – This is the first time a scheduled task has been created and configured to execute this process for this task name.

  • Prof-FUpld-E-U-SE – This is the first time this user has uploaded a file from this endpoint.

  • Prof-RegA-PP-O-PP – This is the first time this process has performed a registry activity.

  • Fact-PCschtasks-DA – The SchTasks (Scheduled Tasks) process has been used to deactivate a scheduled defragmentation task. This sigma rule is authored by Florian Roth (Nextron Systems), Bartlomiej Czyz (@bczyz1) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_apt_slingshot.yml

  • NumCP-AI-CSC-UPLT – An abnormal number of AI conversations have been successfully shared by this user on this platform.

  • Cntx-PLA-Outcome – Physical access failed: True\False

  • Prof-AI-U-Guardrail-Block – This is the first time this user has triggered an AI guardrail violation.

  • Prof-UCreate-U-Plt-UD – This is the first time users in this department have created a user account on this platform.

  • Prof-UCreate-E-O-SE – This is the first time a user account was created from this endpoint.

  • Prof-Login-E-DZ-SZ – This is the first time a successful login has been observed from this source network zone to this destination network zone.

  • Prof-PCnet-U-O-U-user – This is the first time local user accounts have been enumerated using 'net.exe' for this user.

  • Prof-AuditPolicyMod-U-O-U – This is the first time this user has performed an audit policy modification. These events may include both failed and successful modifications.

  • Prof-EMR-FileExt-O-FileExt – This is the first time a user in the organization has received an email attachment with this extension.

  • Fact-PCforfiles-IC – The 'forfiles.exe' process has spawned a child process. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lolbin_forfiles.yml

  • Fact-FWrite-EtcLldSo – The /etc/ld.so.preload file, if present, allows users to add additional shared libraries that will be loaded before the standard libraries. This can be useful for various purposes, such as implementing custom libraries, applying system-wide modifications, or debugging and profiling applications. Attackers could use this file to force the loading of their own malicious libraries, enabling them to modify system behavior, escalate privileges, or intercept sensitive data.

  • Prof-CA-DA-O-U – This is the first time this user has successfully attached a volume to an instance.

  • Fact-FA-Sudoers – The /etc/sudoers file is a critical configuration file in Unix-based operating systems. It controls the access and privileges granted to users and groups to execute commands with elevated privileges (root or superuser privileges) using the sudo command. An attacker can try to read this file to know what user he should get access to, or he can try to write to this file and give a user he have access to these privileges.

  • Prof-GMA-GN-O-GN – This is the first time a user has been added to this group.

  • Prof-UCreate-E-O-DE – This is the first time a user account was created on this endpoint.

  • Fact-PCIOC-Mimikatz-PN –The Mimikatz process has been executed.

  • Fact-PCtaskmgr-SysPerm – The task manager process has been executed by the system user. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_taskmgr_localsystem.yml

  • Prof-AI-TI-O-TN – This is the first time this AI agent tool has been invoked.

  • Prof-PC-U-O-USudo – This is the first time a process execution of a 'sudo' (Superuser Do) command has been observed for this user.

  • Prof-Fwrite-U-O-U-KernelExtExt –This is the first time a kernel extension file was created on MacOS system by this user.

  • Fact-PCwmiprvse-FireEye –The WMIPrvSe (WMI Provider Host) process has been used to execute a command associated with FireEye Pentesting.

  • NumCP-Git-EC-U – An abnormal amount of GitHub API access events have been observed for this user.

  • Fact-PCsetenforce-DisableSELinux – The 'setenforce' command has been used to disable the SELinux (Security-Enhanced Linux).

  • Prof-STC-TN-O-TN – This is the first time a scheduled task with this name has been created.

  • Cntx-Web-WDCrit-IP – Web domain is an IP address: True\False

  • NumSP-FRead-FS-SA-Bytes – An abnormal amount of file bytes have been read in this storage account for this user.

  • Cntx-PCwhoami-ADisc – Local accounts enumerated using whoami.exe on endpoint: True\False

  • NumDCP-WebF-WebDomC-U-WebDom – An abnormal number of unique domains have been observed in failed HTTP events for this user.

  • Prof-PCvssadmin-SCC-O-SE – This is the first time a shadow copy was created using 'vssadmin.exe' from this endpoint.

  • NumDCP-FDel-U-DE – An abnormal number of unique remote destination endpoints have been observed in file deletion events on this endpoint for this user.

  • Cntx-VPNln-UCrit-SA – User is a service account: True\False

  • Fact-PCdnscat-DNSExfil – The DNScat (a DNS tunneling tool) process has been executed. This sigma rule is authored by Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_dns_exfiltration_tools_execution.yml

  • Prof-PCipconfig-NetDisc-U-PN – This is the first time a process execution of 'ipconfig.exe' has been observed for this user.

  • NumDC-ShA-ShareC-U-DS – An abnormal number of unique network shares have been accessed for this user.

  • NumCP-PC-ModprobeCmdC-DE – An abnormal number of 'modprobe' (Module Probe, a kernel module management tool) process executions have been observed on this endpoint.

  • Prof-SA-AN-UD-AN – This is the first time this security alert triggered for users in this department.

  • Fact-RegW-ChromeExt – A Chrome extension has been installed via the registry.

  • NumCP-MPermMod-EC-U – An abnormal number of mailbox permission modifications have been observed for this user.

  • Prof-FDnld-E-O-SE – This is the first time a file has been downloaded to this endpoint.

  • Fact-PCsc-SvcMod-Ingt – The SC (Service Controller) process has been used to change a service binary path or failure command configuration with medium integrity level executed. This sigma rule is authored by Teymur Kheirkhabarov and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml

  • NumDCP-Auth-TgsEC-U-Sn – An abnormal number of Ticket Granting Services (TGS) were observed for this user. In Kerberos authentication, a Ticket Granting Ticket (TGT) is a user authentication token issued by the Key Distribution Center (KDC) to be used to request from the Ticket Granting Service (TGS) access tokens for specific resources/systems joined to the domain. This event is notable since it may indicate use of stolen credentials.

  • Prof-PC-O-COD – This is the first time a process execution of an Office application has opened a remote document from this web domain.

  • Cntx-PCqwinsta-ADisc – Local accounts enumerated using qwinsta.exe on endpoint: True\False

  • Fact-PC-LoginHookFile – Adversaries may use a Login Hook to establish persistence executed upon user logon. The plist can be modified using the defaults command-line utility. This behavior is the same for logout hooks where a script can be executed upon user logout.

  • Cntx-FA-ECrit-CS – Destination endpoint is critical: True\False

  • Fact-PCregsvr32-SuspExec – The RegSvr (Registration Service) process has been used to download/install/register a new DLL that is hosted on web, on this endpoint. This sigma rule is authored by Florian Roth (Nextron Systems), oscd.community, Tim Shelton and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_regsvr32_anomalies.yml

  • NumDCP-EL-UC-DE-UUnknown – An abnormal number of unique unknown user names have been observed in failed logins to this endpoint.

  • Prof-PC-CmdArgs-InstallUtil-O-DLLParam – This is the first time the 'installutil.exe' process has been executed with this DLL file as a parameter.

  • Prof-SA-AN-U-AN – This is the first time this security alert triggered for this user.

  • Cntx-PC-Critical-Crit – Process is a known critical command: True\False

  • Prof-CPM-Resource-U-R – This is the first time an IAM policy of a resource in this directory has been successfully modified by this user in GCP. IAM policies determine the roles and permissions granted to users on a resource.

  • Prof-STC-TN-UD-TN – This is the first time a scheduled task with this name has been created for users in this department.

  • Prof-DS-DSOC-U-DSOC – This is the first time this user performed an activity on a directory service object with this object class.

  • Prof-DB-E-UDBN-SE – This is the first time a successful database event in this database has been observed for this user from this endpoint.

  • Prof-SA-E-O-SZ – This is the first time a security alert triggered in this network zone.

  • NumDCP-EL-UC-DE-U – An abnormal number of unique user names have been observed in logins to this endpoint. These events may include both failed and successful logins.

  • Fact-PCschtasks-TC – The SchTasks (Scheduled Tasks) process has been spawned by a command associated with the 'PowerSploit' or 'Empire' attack tools. This sigma rule is authored by Markus Neis, @Karneades and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hktl_powersploit_empire_default_schtasks.yml

  • Prof-GA-Brwsr-O-Brwsr – This is the first time this web browser has been observed for the organization.

  • Prof-WinSC-E-O-DE – This is the first time a service creation has been observed on this endpoint.

  • Fact-PCcmstp-UAC – The CMSTP (Connection Manager Profile Installer) has been used to silently install a service profile for all users on an endpoint. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_cmstp.yml

  • Prof-PC-PN-Pdir – This is the first time a process execution has been observed from this directory for this process.

  • Cntx-VPNln-UCrit-Exec – User is an executive: True\False

  • Prof-PLA-Loc-U-LocDoor – This is the first time this user has physically accessed this door.

  • Prof-PC-CmdArgs-Regsvr32-O-SCTParam – This is the first time the 'regsvr32.exe' process has been executed with this SCT file as a parameter.

  • Prof-UCreate-E-U-SE – This is the first time this user has created a user account from this endpoint.

  • NumDCP-FWrite-AuditRule-U-DE – An abnormal number of unique endpoints where this user modified the audit.rules file in Unix system.

  • Fact-PC-Visudo – The /etc/sudoers file is typically edited using the visudo command, which provides a safe way to make changes to the file and prevents multiple simultaneous edits, reducing the risk of syntax errors that could lock users out of administrative access. An attacker can try to read this file to know what user he should get access to, or he can try to write to this file and give a user he have access to these privileges.

  • Cntx-PC-ECrit-CS-SE – Source endpoint is critical or a Domain Controller: True\False

  • Prof-FUpld-E-O-SE – This is the first time a file has been uploaded from this endpoint.

  • Prof-ELNAC-E-U-SMac – This is the first a network access control login event has been observed coming from this MAC address for this user. These events may include both failed and successful logins.

  • Prof-EL-NTLM-O-SE – This is the first time a successful NTLM login has been observed from this endpoint.

  • Prof-GA-Mime-O-Mime – This is the first time this MIME type has been observed for the organization. These events do not include network or endpoint platforms.

  • Prof-RA-U-Plt-U – This is the first time a role has been assigned by this user on this platform.

  • Fact-PCsocat-Exfil – The 'socat.exe' (a data exfiltration tool) process has been executed. This sigma rule is authored by Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_exfiltration_and_tunneling_tools_execution.yml

  • NumSP-FUSB-Bytes-U-Bytes – An abnormal amount of file bytes have been written to peripheral storage devices for this user.

  • NumCP-FDnld-EC-U – An abnormal amount of file download events have been observed for this user.

  • NumCP-UPwdMod-O – An abnormal amount of password reset events were observed for this user.

  • Prof-FDnld-E-U-SE – This is the first time a file has been downloaded to this endpoint for this user.

  • NumCP-SEPwrshell-WebReq-O-WebReq – An abnormal number of PowerShell web requests have been observed for the organization.

  • Fact-PCdevtool-BinExec – The DevToolsLauncher process has deployed a process. This sigma rule is authored by Beyu Denis, oscd.community (rule), @_felamos (idea) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_devtoolslauncher.yml

  • Prof-DB-DBOp-UDDBN-DBOp – This is the first time a database operation has been observed for a user in this department (i.e. "HR", "Finance", etc...). A database operation consists of any action in a database query (i.e. SELECT, DROP, UPDATE, etc...)

  • Prof-PC-U-O-U-Kextload –This is the first time a process execution of a 'kextload' (Kernel Extension Load) command has been observed for this user.

  • Prof-AI-AC-O-AT –This is the first time a user in the organization has created an AI agent.

  • Fact-PCTeamViewer-InstalledService – The TeamViewer remote desktop access service has been installed.

  • NumDCP-SA-ANC-SE-AN – An abnormal number of unique alerts have triggered from this endpoint.

  • Prof-AI-TI-UTN-FN – This is the first time this AI agent tool function has been invoked by this user.

  • Prof-GA-PrivU-PltOp-PrivU – This is the first time this successful operation has been performed on this platform by a non-privileged user. Operations can include function types, APIs, application activities and more.

  • Prof-DL-E-O-SE – This is the first time a kernel module\driver was loaded on this endpoint.

  • Prof-AuditPolicyMod-E-O-SE – This is the first time an audit policy modification has been observed from this endpoint. These events may include both failed and successful modifications.

  • Prof-WinSC-E-UD-DE – This is the first time a service creation has been observed on this endpoint for users in this department.

  • Prof-FS-T-U-IT – This is the first time an item shared of this type (file, folder, etc) has been observed for this user.

  • NumDCP-AL-UC-Plt-U-SIP – An abnormal number of unique user names have been observed in application logins to this platform per source IP. These events may include both failed and successful communications.

  • Fact-PCauditctl-DeleteRules – The 'auditctl' command has been used to delete the audit rules.

  • Fact-RegW-Netshell – A NetShell helper DLL has been registered or modified by writing the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh'.

  • Prof-SEPwrshell-CmdInv-U-CmdInv – This is the first time this user executed a PowerShell script with this command.

  • Cntx-AuditPolicyMod-ECrit – Endpoint is critical: True\False

  • NumCP-DNSResp-NXC-O-NX – An abnormal number of DNS queries to NX domains have been observed for the organization.

  • Fact-PC-Chflags-HiddenFile – The "setfile" unix process can be used to make files hidden by modifying their attributes, making sure they remain undetected by users. An attacker can create hidden file to evade detection.

  • Prof-EL-E-U-SE – This is the first time this user attempted to login from this endpoint. These events may include both failed and successful logins.

  • Prof-EMS-FileExt-U-FileExt – This is the first time this user has sent an email attachment with this extension.

  • Fact-PCfodhelper-UAC – The 'fodhelper.exe' has spawned a child process. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_uac_bypass_fodhelper.yml

  • Prof-USB-DevId-UD-DevId – This is the first time this peripheral device ID has been observed for users in this department.

  • Fact-U-PrivMM – A non-privileged user has been observed accessing an attribute of a privileged directory service user account.

  • Prof-PC-E-O-SE-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed on this endpoint.

  • Prof-GCreate-U-P-U – This is the first time this user has created a group on this platform.

  • Fact-FWrite-2018APT – The 'ds7002.lnk', which is related to a known attack, was written to.

  • Cntx-PCwsmprovhost-RP-PN – Process is 'wsmprovhost.exe': True\False

  • Prof-AI-AC-O-UD – This is the first time a user in this department has created an AI agent.

  • Prof-GCreate-U-O-U – This is the first time for this user to create a group for the organization.

  • Fact-PCdllhost-UACCOM – The 'dllhost.exe' process has been used to bypass UAC using COM objects. This sigma rule is authored by Nik Seetharaman, Christian Burkard (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmstp_com_object_access.yml

  • NumCP-DSOW-EC-UD –An abnormal number of directory service write events have been observed for users in this department. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Fact-DllLoadWmiprvse-Exe – The 'wmiprvse.exe' (WMI Provider Service) process has been observed loading a 'cmd.exe' or a 'powershell.exe' image.

  • Prof-FWrite-AuthorizedKeys-O-UD – This is the first time an 'authorized_keys' file has been modified by users in this department.

  • Prof-VPNIn-E-O-SE – This is the first time a user attempted to log into a VPN from this endpoint. These events may include both failed and successful logins.

  • Fact-RegW-GlobalDotName – The registry value GlobalDotName has been created.

  • Prof-DS-E-O-SZ – This is the first time a user in the organization performed an activity on a directory service object from this network zone.

  • Prof-PC-Sysvol-O-UD – This is the first time a SYSVOL domain group policy has been accessed by a process for users in this department.

  • Prof-SA-AN-U-RN – This is the first time this correlation rule triggered for this user.

  • Prof-PCpwrshell-En-O-PP – This is the first time a process execution of PowerShell with an encrypted command has been observed for this parent process.

  • Prof-EMS-Country-U-DCountry –This is the first time this user has sent an email to this country, as determined by geolocation lookup.

  • Prof-PCnet-U-O-U-netuser – This is the first time a user account has been enabled or disabled using 'net.exe' for this user.

  • Prof-CPM-UAttachAWS-O-U – This is the first time this user attached a policy to an identity (user, group and role) in AWS. Policies in AWS are the documents that dictate what permissions are granted to identities and resources. These events may include both failed and successful attachments.

  • Cntx-LogCl-ECrit-CS – Endpoint is critical: True\False

  • Fact-CPM-PCrit-GCPAdmin –A cloud resource policy in GCP has been successfully modified and included critical administrative permissions. IAM policies determine the roles and permissions granted to users on a resource.

  • Prof-SEPwrshell-wmi-O-U – This is the first time this user executed a PowerShell script with WMI commands.

  • Fact-PChh-HtmlExec – The HH (HTML Help) process has loaded a '.chm' (Compiled HTML) file. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Dan Beavin), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_hh_chm_execution.yml

  • Fact-PCAnyDesk-StartedAgent – The AnyDesk remote desktop access service has been started.

  • NumCP-AppAuthF-EC-U – An abnormal number of application authentication failures have been observed for this user.

  • Prof-AI-AC-O-PLT – This is the first time a user in the organization has created an AI agent with this platform.

  • Prof-WinSC-PP-SN-PP – This is the first time this service was created with this command process path.

  • Fact-PCsvchost-NoArg – The SvcHost (Service Host) process has been executed without any command line arguments. This sigma rule is authored by David Burkett, @signalblur and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_svchost_execution_with_no_cli_flags.yml

  • Fact-PCiexplorer-IHttp – The 'consent.exe' (Windows UAC consent dialogue) process has spawned the 'iexplorer.exe' (Internet Explorer) process with system permissions. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_exploit_cve_2019_1388.yml

  • Fact-AI-PI-Base64 – An AI request with a base64 string has been sent. While not inherently malicious, Base64 encoding in an AI request may indicate prompt obfuscation.

  • Prof-PwdChkout-U-O-UD – This is the first time a user in this department retrieved a password.

  • Prof-PrivUse-E-U-SE – This is the first time a Windows privileged has been used and invoked from this endpoint for this user.

  • Prof-DS-Attr-U-Attr – This is the first time this privileged user accessed this directory service attribute.

  • Prof-LogCl-E-O-DE –This is the first time an audit log has been cleared on this endpoint.

  • Prof-SA-DP-DZ-DP – This is the first time a network alert on this port has been triggered for this destination network zone.

  • Prof-GA-Country-SZ-DCountry – This is the first time an activity has been observed to this country for this network zone, determined by geolocation lookup.

  • Cntx-PCwsmprovhost-RP-PPN – Parent process is 'wsmprovhost.exe': True\False

  • Fact-PCbcdedit-DisRec-BootSP – The BCDEdit (Boot Configuration Data Edit) process has been used to Windows error recovery. This sigma rule is authored by E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_bcdedit_boot_conf_tamper.yml

  • Fact-PC-Chmod-Setgid – The setgid bit was set using chmod, which can cause a file to execute with the privileges of its group.

  • NumDCP-VPNln-UC-SE-U – An abnormal number of unique user names have been observed in VPN login from this endpoint. These events may include both failed and successful communications.

  • Prof-FA-SCFA-O-U – This is the first time source code file activity (by file extension) has been observed for this user. File activity could include read, delete, write or any other type of file related operations.

  • Fact-PCLsass-Lsass – The WERFault (Windows Error Reporting Fault) process has been used to dump the LSASS process. This sigma rule is authored by sigma and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_lsass_dump.yml

  • Cntx-PC-Critical-Parent-Pentest – Parent process is a known pentesting tool

  • Prof-GA-Country-O-SCountry – This is the first time an activity has been observed from this country, determined by geolocation lookup.

  • Fact-PCIOC-Mimikatz – The PowerShell process has been used to execute a Mimikatz command.

  • Prof-PC-U-COD – This is the first time a process execution of an Office application has opened a remote document from this web domain for this user.

  • Prof-UKeyCreate-U-O-U – This is the first time this user has generated an access key for a user account.

  • Prof-AI-TI-U-TN – This is the first time this AI agent tool has been invoked by this user.

  • Fact-RegW-ControlPanel – A control panel item has been registered by writing to a registry key/value under HKCU\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls.

  • Fact-PCmklink-SCA – The 'mklink.exe' process has been used to create a symbolic link to a shadow copy. This sigma rule is authored by Teymur Kheirkhabarov, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_shadow_copies_access_symlink.yml

  • Prof-EMS-AC-U-A – An abnormal number of email attachments have been observed in an outgoing email for this user.

  • Fact-PCappcmd-IIS – The 'appcmd.exe' (IIS Application Command Line) process has been used to disable IIS HTTP logging .

  • Prof-GMA-E-O-SZ – This is the first time a user has been added to a group from this network zone.

  • NumSP-Web-Bytes-UD-BytesStorageOut – This is the first time a user has been added to a group from this network zone.

  • Prof-RegR-LSA-O-UD – This is the first time users in this department read have read a LSA secret from the registry.

  • Prof-EL-E-U-DE – This is the first time this user attempted to log into this endpoint. These events may include both failed and successful logins.

  • Fact-PCopenwith-Exec – The OpenWith process has been used to execute a program. This sigma rule is authored by Beyu Denis, oscd.community (rule), @harr0ey (idea) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_openwith.yml

  • Fact-AI-PI-IgnoreInsruct – An AI request attempting to cause the agent to ignore instructions has been sent.

  • NumCP-DNSResp-NXC-SE-NX – An abnormal number of DNS queries to NX domains from this endpoint have been observed.

  • NumCP-PCpwrshell-EC-U – An abnormal number of PowerShell process executions have been observed for this user.

  • Prof-SA-E-O-SE – This is the first time a security alert triggered from this endpoint.

  • NumCP-VPNlnF-EC-O-U-1Day – An abnormal number of failed VPN logins have been observed for the organization by this user in a day.

  • Prof-PC-E-NetUserAdd-O-DE – This is the first time a user account has been created using 'net.exe' on this endpoint.

  • Fact-PCwmic-SCC – The WMIC (WMI Command Line) process has been used to create a shadow copy. This sigma rule is authored by Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_shadow_copies_creation.yml

  • NumDCP-RegW-RPC-ServicesStop-DE-RP – An abnormal number of unique services have been stopped by modifying the registry on this endpoint.

  • Fact-WebMtgM-RmPwd – A meeting has been modified to remove the meeting password.

  • Fact-CA-Startup-StartupScriptGCP –A startup or shutdown script have been added or modified in a instance in GCP.

  • NumSP-SADLP-Bytes-U-Bytes – An abnormal amount of outgoing bytes have been recorded in DLP alerts for this user.

  • Fact-RegW-SIP – A SIP component has been modified via the registry.

  • NumDCP-PLA-LocC-U-LocDoor – An abnormal number of unique doors have been observed in physical access events for this user.

  • Prof-RegW-Services-O-UD – This is the first time users in this department have modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-DS-E-UD-SZ – This is the first time a user in this department performed an activity on a directory service object from this network zone.

  • Cntx-GMA-ULocal – User is local: True\False

  • Fact-Web-TI-IOC – An HTTP communication attempt has been made to a known malicious URL. These events may include both failed and successful traffic.

  • Prof-UCreate-Dom-U-DDom – This is the first time this user has created a user account on this domain.

  • Fact-FRead-Lssas – A process has directly read from the memory space of 'lsass.exe'.

  • Prof-EMS-Country-O-DCountry – This is the first time a user in the organization has sent an email to this country, as determined by geolocation lookup.

  • Prof-RegR-Certs-U-RP – This is the first time this user has read this certificate\private key related registry value.

  • Prof-PrivUse-E-SE-SZ – This is the first time a Windows privileged has been used and invoked from this endpoint and from this network zone.

  • Fact-PCbginfo-VBExec – The BgInfo (Background Information) process has used a .bgi file to bypass application whitelisting. This is notable as this method allows blindly trusted signed binaries to write code which can be leveraged to run malicious actions. This sigma rule is authored by Beyu Denis, oscd.community and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_bginfo.yml

  • Cntx-USwtch-DUCrit – Dest user is privileged: True\False

  • Prof-RegW-UAC-O-U – This is the first time this user has modified or created a registry key\value under the UAC configuration key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System'.

  • Fact-PC-DisableAuditd –Auditd service was disabled.

To prevent over-triggering on first-time observations and to establish a good baseline, minimumTrainingPeriodInDays was updated to 14 for the following pre-built analytics rules:

Note

Changes to minimumTrainingPeriodInDays only affect analytics rules that are being enabled and analytics rules enabled less than 14 days ago.

If an analytics rule has already been enabled for more than 14 days, changes to minimumTrainingPeriodInDays has no impact. The analytics rule remains enabled and won't enter a new training period.

  • NumCP-VPNlnF-EC-U-30Days – An abnormal number of vpn login failures have been observed for this user in 30 days.

  • NumDCP-Login-DZC-UD-DZ – An abnormal number of unique destination network zones have been observed in login events for users in this department. These events may include both failed and successful logins.

  • NumDCP-SA-ANC-UD-AN – An abnormal number of unique alerts have triggered for users in this department.

  • NumSP-Web-Bytes-U-BytesStorageOut – An abnormal amount of bytes have been uploaded to file sharing websites for this user.

  • NumDCP-SA-ANC-U-AN – An abnormal number of unique alerts have triggered for this user.

  • NumDCP-PLA-LocC-U-LocCity – An abnormal number of unique cities have been observed in physical access events for this user.

  • Prof-DS-E-O-SE – This is the first time a user in the organization performed an activity on a directory service object from this endpoint.

  • NumDCP-FRead-EC-UP-FP – An abnormal number of unique files have been read in this platform for this user.

  • NumSP-Web-Bytes-O-BytesStorageOut – An abnormal amount of bytes have been uploaded to file sharing websites for the organization.

  • NumDCP-Login-DZC-U-DZ – An abnormal number of unique destination network zones have been observed in login events for this user. These events may include both failed and successful logins.

  • NumDCP-EL-UC-O-U-SE – An abnormal number of unique user names have been observed in endpoint logins for the organization per source endpoint. These events may include both failed and successful communications.

  • NumDCP-CA-DAC-U-Disks – An abnormal number of volumes were attached to instances by this user. These events may include both failed and successful attachments.

  • NumCP-DSOW-EC-U – An abnormal number of directory service events have been observed for this user. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • NumSP-FRead-FS-UP-Bytes – An abnormal amount of file bytes have been read in this platform for this user.

  • NumCP-SA-TP-AC-UO – An abnormal number of of AI third-party alerts for the organization have been performed by this user.

  • NumCP-AI-CDC-UPLT – An abnormal number of AI conversations have been successfully deleted by this user on this platform.

  • NumCP-FDnld-EC-O – An abnormal amount of file download events have been observed for the organization.

  • NumDCP-RegW-RPC-ServicesStop-U-RP – An abnormal number of unique services have been stopped by modifying the registry for this user.

  • NumCP-PC-SudoCount-U – An abnormal number of 'sudo' (Superuser Do) process executions have been observed for this user.

  • NumSP-Web-Bytes-U-BytesStorageIn – An abnormal amount of bytes have been downloaded from file sharing websites for this user.

  • NumDCP-VPNln-UC-O-U-SE – An abnormal number of unique user names have been observed in VPN login for the organization per source endpoint. These events may include both failed and successful communications.

  • NumCP-FUpld-EC-U – An abnormal amount of file upload events have been observed for this user.

  • NumDCP-ELF-SEC-DE-SE – An abnormal number of unique endpoints have been observed failing to log into this endpoint.

  • NumDCP-PCCEnum-TC-U-CEnum – An abnormal number of unique credential enumeration tools have been executed for this user.

  • NumCP-PCpwrshell-EC-UD – An abnormal number of PowerShell process executions have been observed for users in this department.

  • NumCP-PwdChkout-EC-U-SC – An abnormal number of password retrievals have been observed for this user.

  • NumCP-PC-ModprobeCmdC-U – An abnormal number of 'modprobe' (Module Probe, a kernel module management tool) process executions have been observed for this user.

  • NumCP-AI-QC-U – An abnormal number of successful AI requests have been performed by this user. AI requests consist of one or more prompts.

  • NumCP-PC-KextloadCmdC-U – An abnormal number of 'kextload' (Kernel Extension Load) process executions have been observed for this user.

  • NumCP-PwdChkout-EC-O-SC – An abnormal number of password retrievals have been observed for the organization.

  • NumCP-PrivUse-EC-U-APC – An abnormal number of administrative privilege access events have been observed for this user.

  • NumSP-DNSReq-Bytes-SE-Bytes – An abnormal amount of bytes were sent in DNS queries from this endpoint.

  • NumSP-AI-TS-U-Tokens – An abnormal sum of tokens in successful AI requests and responses has been observed for this user. If the number of tokens is not available, tokens are estimated at one token per four letters.

  • NumDCP-FWrite-EC-U-FP – An abnormal number of unique files have been written for this user.

  • NumDCP-PwdChkout-SVC-U-SV – An abnormal number of unique safes have been observed in passwords retrieval events for this user.

  • NumSP-EMR-Bytes-DU-Bytes – An abnormal amount of bytes have been received in incoming emails for this user.

  • NumDCP-EL-DEC-O-DE – An abnormal number of unique destination endpoints have been observed in endpoint login events for the organization. These events may include interactive Window logins and other (interactive or not) OS logins, both failed as successful.

  • NumCP-PCpwrshell-EC-O – An abnormal number of PowerShell process executions have been observed for the organization.

  • NumSP-DNSReq-Bytes-SZ-Bytes – An abnormal amount of bytes were sent in DNS queries from this network zone.

  • NumDCP-EL-UC-SE-U – An abnormal number of unique user names have been observed in endpoint logins from this endpoint. These events may include both failed and successful communications.

  • NumCP-PC-InsmodCmdC-DE – An abnormal number of 'insmod' (Install Module) process executions have been observed on this endpoint.

  • NumDCP-SADLP-ProtoC-U-Proto – An abnormal number of unique protocols have been observed in DLP alerts for this user.

  • NumDCP-EL-UC-DESE-U – An abnormal number of unique user names have been observed in endpoint logins for destination endpoint and source endpoint. These events may include both failed and successful communications.

  • NumCP-FUpld-EC-O – An abnormal amount of file upload events have been observed for the organization.

  • NumCP-PC-DirSearchCount-U – An abnormal number of unix file search process executions have been observed for this user.

  • NumCP-EMS-EC-U-Id – An abnormal number of outgoing emails have been observed for this user.

  • NumCP-FUpld-EC-UD – An abnormal amount of file upload events have been observed for users in this department.

  • NumCP-ELF-EC-U-DZ – An abnormal number of failed logins to endpoints in this network zone have been observed for this user.

  • NumCP-SA-TP-AC-DLP-UO – An abnormal number of of DLP violations via AI for the organization have been performed by this user.

  • NumCP-AI-MC-U – An abnormal amount of AI agent modifications have been observed for a user.

  • NumSP-Web-Bytes-U-BytesInPost – An abnormal amount of bytes have been uploaded to the web with POST requests for this user.

  • NumDCP-FC-EC-U-FP – An abnormal number of unique files have been copied in this platform for this user.

  • NumCP-DSOW-EC-O – An abnormal number of directory service write events have been observed for the organization. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • NumCP-ELF-EC-U-RDP – An abnormal number of failed RDP (remote desktop protocol) logins to this endpoint have been observed for this user.

  • NumCP-RegD-Services-EC-U – An abnormal number of unique service configurations have been deleted from the registry for this user.

  • NumSP-Network-BytesToExtIP-SZ-Bytes – An abnormal amount of bytes have been sent in communication that initiated in this network zone to an external IP. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator. These events may include both failed and successful communications.

  • NumDCP-AL-UC-PltSE-U – An abnormal number of unique user names have been observed in application logins to this platform from this endpoint. These events may include both failed and successful communications.

  • NumSP-Network-BytesToExtIP-SE-Bytes – An abnormal amount of bytes have been sent in communication that initiated from this endpoint to an external IP. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator. These events may include both failed and successful communications.

  • NumDCP-FUSB-FPC-U-FP – An abnormal number of unique files has been written to peripheral storage devices for this user.

  • NumCP-AppLF-EC-U – An abnormal number of application login failures have been observed for this user.

  • NumSP-EMS-Bytes-U-Bytes – An abnormal amount of bytes have been sent in outgoing emails for this user.

  • NumCP-EScrn-EC-U – An abnormal number of screenshot events have been observed for this user.

  • NumSP-VPNOut-Bytes-U-Bytes – An abnormal amount of bytes have been uploaded in VPN session for this user.

  • NumSP-Network-BytesToExtIP-Failed-SE-Bytes – An abnormal amount of bytes have failed to be sent in communication that initiated from this endpoint to an external IP. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • NumCP-RegD-Services-EC-DE – An abnormal number of unique service configurations have been deleted from the registry on this device.

  • NumDC-Git-RepoC-U-Object – An abnormal number of unique repository endpoints where secrets are generally stored, which may indicate unauthorized enumeration or insider reconnaissance activity. Repository name is parsed into the object field which is being counted here.

  • NumDCP-AL-UC-Plt-U-SE – An abnormal number of unique user names have been observed in application logins to this platform per source endpoint. These events may include both failed and successful communications.

  • NumDCP-PCHEnum-TC-U-HEnum – An abnormal number of unique host enumeration tools have been executed for this user.

  • NumCP-ELF-EC-U-SE – An abnormal number of failed endpoint logins from this endpoint have been observed for this user.

  • NumDCP-FRead-EC-SA-FP – An abnormal number of unique files have been read in this storage account for this user.

  • NumCP-PwdChkout-EC-UD-SC – An abnormal number of password retrievals have been observed for users in this department.

  • NumCP-SA-TP-AC-DLP-UO – An abnormal number of of DLP violations via AI for the organization have been performed by this user.

  • NumSP-DNSReq-Bytes-O-Bytes – An abnormal amount of bytes were sent in DNS queries from endpoints in the organization.

  • NumDCP-EL-DEC-SE-DE – An abnormal number of unique destination endpoints have been observed in successful endpoint login events from this endpoint. These events may include interactive Window logins and other (interactive or not) OS logins.

  • NumCP-RuleDel-EC-U – An abnormal number of security rules deletion events have been observed for this user.

  • NumDCP-EL-UC-DE-U-SE – An abnormal number of unique user names have been observed in endpoint logins to this endpoint per source endpoint. These events may include both failed and successful communications.

  • NumDC-RA-U-RAC – An abnormal number of role-assume requests have been observed for this user. These events can include both successful and failed assumed roles.

  • NumDCP-RegR-RPC-Cert-U-RP – An abnormal number of unique certificates and private keys related registry values have been read by this user.

  • NumCP-VPNlnF-EC-O-U-30Days – An abnormal number of failed VPN logins have been observed for the organization by this user in 30 days.

  • NumCP-Auth-MfaEC-U – An abnormal number of Multi-Factor Authentication (MFA) authentication events for this user have been observed. These events may include both failed and successful authentications to an MFA service.

  • NumSP-FRead-FS-B-Bytes – An abnormal amount of file bytes have been read in this bucket for this user.

  • NumSP-MItemRead-NMS-U-NA – An abnormal number of emails have been read by this user.

  • Prof-AL-MFA-U-MFA – This is the first time this user has logged into an application without using multi factor authentication (MFA).

  • Prof-GMA-U-O-U – This is the first time a user has been added to a group by this user.

  • NumCP-AI-U-Guardrail-Block – An abnormal amount of AI guardrail violations have been observed for a user.

  • NumCP-Web-MethodDelC-SIP – An abnormal number of HTTP requests to an internal resource with the method DELETE by this IP have been observed. Probably detects resources deletion.

  • NumCP-PC-CritCmdC-O – An abnormal number of critical command executions have been observed for the organization.

  • NumDCP-EL-DEC-U-DE – An abnormal number of unique destination endpoints have been observed in endpoint login events for this user. These events may include interactive Window logins and other (interactive or not) OS logins, both failed as successful.

  • NumDCP-FRead-FS-U-DE – An abnormal number of unique destination endpoints have been observed in file read events for this user.

  • NumCP-SA-TP-AC-U – An abnormal number of AI third-party alerts have been observed for this user.

  • Prof-FA-SCFA-O-UD – This is the first time source code file activity (by file extension) has been observed for users in this department. File activity could include read, delete, write or any other type of file related operations.

  • NumDCP-FRead-EC-B-FP – An abnormal number of unique files have been read in this bucket for this user.

  • Prof-FWrite-AuthorizedKeys-O-U – This is the first time an 'authorized_keys' file has been modified by this user.

  • NumCP-DL-EC-UPlt – An abnormal number of kernel module or drivers have been loaded for this user.

  • NumCP-DL-EC-SE – An abnormal number of kernel module or drivers have been loaded on this endpoint.

  • NumDCP-GA-OpC-UPlt-FOp – An abnormal number of unique failed operations have been observed in this platform for this user.

  • NumCP-DB-DBOpC-U – An abnormal number of database operation events were observed for this user - this can include both unique and non-unique operations. A database operation consists of any action in a database query (i.e. SELECT, DROP, UPDATE, etc...). These events may include both failed and successful operations.

  • Prof-Fwrite-AuditRule-O-U – This is the first time an audit rule file has been modified by this user.

  • Prof-Network-FromExtIP-O-DP – This is the first time a successful connection to this port has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • NumCP-FDel-EC-U – An abnormal number of file deletion events have been observed for this user.

  • Prof-FDel-U-O-U-LogFile – This is the first time a log file has been deleted by this user.

  • NumCP-AI-QC-UO – An abnormal number of successful AI requests for the organization have been performed by this user. AI requests may consist of one or more prompts.

  • NumCP-RegD-EC-DE – An abnormal number of registry deletion events have been observed on this device.

  • NumCP-PC-ChownCount-U – An abnormal number of 'chown' (Change Owner) process executions have been observed for this user.

  • NumCP-ELF-EC-U-DE – An abnormal number of failed endpoint logins to this endpoint have been observed for this user.

  • Prof-FDel-UnixLogFiles-O-U – This is the first time a log file deletion has been observed for this user in Unix systems.

  • Prof-PCMsbuild-E-O-DE – This is the first time the 'msbuild.exe' process has been used to build and execute a project on this endpoint.

  • NumCP-AI-QC-WID – An abnormal number of successful AI requests has been observed for this workspace. AI requests may consist of one or more prompts.

  • NumCP-PC-InsmodCmdC-U – An abnormal number of 'insmod' (Install Module) process executions have been observed for this user.

  • NumCP-PC-ChmodCount-U – An abnormal number of 'chmod' (Change Mode) process executions have been observed for this user.

  • Prof-PC-E-NetUserAdd-O-DZ – This is the first time a user account has been created using 'net.exe' on this network zone.

  • NumCP-EMR-EC-DU – An abnormal number of incoming emails have been observed for this user.

  • NumCP-SEPwrshell-CmdInvC-O-InvC – An abnormal number of PowerShell command invocations have been observed for the organization.

  • NumDCP-VPNln-UC-O-U-SIP – An abnormal number of unique user names have been observed in VPN login for the organization per source IP. These events may include both failed and successful communications.

  • NumCP-FDnld-EC-UD – An abnormal amount of file download events have been observed for users in this department.

  • NumCP-VPNlnF-EC-U – An abnormal number of vpn login failures have been observed for this user.

  • NumSP-DBQ-RS-U-RS – An abnormal database query response size has been observed for this user. These events may include both failed and successful queries.

  • NumCP-AI-CSC-UPLT – An abnormal number of AI conversations have been successfully shared by this user on this platform.

  • NumCP-Git-EC-U – An abnormal amount of GitHub API access events have been observed for this user.

  • NumDCP-Network-DPC-SEDE-DP – An abnormal number of unique target ports have been observed in internal communication that initiated by this endpoint to this destination endpoint. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator. These events may include both failed and successful communications.

  • NumSP-FRead-FS-SA-Bytes – An abnormal amount of file bytes have been read in this storage account for this user.

  • NumDCP-WebF-WebDomC-U-WebDom – An abnormal number of unique domains have been observed in failed HTTP events for this user.

  • NumDCP-FDel-U-DE – An abnormal number of unique remote destination endpoints have been observed in file deletion events on this endpoint for this user.

  • NumDC-ShA-ShareC-U-DS – An abnormal number of unique network shares have been accessed for this user.

  • NumCP-PC-ModprobeCmdC-DE – An abnormal number of 'modprobe' (Module Probe, a kernel module management tool) process executions have been observed on this endpoint.

  • NumCP-MPermMod-EC-U – An abnormal number of mailbox permission modifications have been observed for this user.

  • NumCP-FDel-UnixLogFilesC-U – An abnormal number of log files have been deleted by this user in Unix systems.

  • NumDCP-Auth-TgsEC-U-Sn – An abnormal number of Ticket Granting Services (TGS) were observed for this user. In Kerberos authentication, a Ticket Granting Ticket (TGT) is a user authentication token issued by the Key Distribution Center (KDC) to be used to request from the Ticket Granting Service (TGS) access tokens for specific resources/systems joined to the domain. This event is notable since it may indicate use of stolen credentials.

  • NumDCP-EL-UC-DE-UUnknown – An abnormal number of unique unknown user names have been observed in failed logins to this endpoint.

  • NumCP-Web-MethodDelC-WebDom – An abnormal number of HTTP requests to an internal resource with the method DELETE have been observed for this domain. Probably detects resources deletion.

  • NumDCP-EL-UC-DE-U – An abnormal number of unique user names have been observed in logins to this endpoint. These events may include both failed and successful logins.

  • NumDCP-FWrite-AuditRule-U-DE – An abnormal number of unique endpoints where this user modified the audit.rules file in Unix system.

  • NumSP-FUSB-Bytes-U-Bytes – An abnormal amount of file bytes have been written to peripheral storage devices for this user.

  • NumCP-FDnld-EC-U – An abnormal amount of file download events have been observed for this user.

  • NumCP-UPwdMod-O – An abnormal amount of password reset events were observed for this user.

  • NumCP-SEPwrshell-WebReq-O-WebReq – An abnormal number of PowerShell web requests have been observed for the organization.

  • NumDCP-EA-TgsEC-UD-Sn – An abnormal number of Ticket Granting Services (TGS) were observed for users in this department. In Kerberos authentication, a Ticket Granting Ticket (TGT) is a user authentication token issued by the Key Distribution Center (KDC) to be used to request from the Ticket Granting Service (TGS) access tokens for specific resources/systems joined to the domain. This event is notable since it may indicate use of stolen credentials.

  • NumDCP-SA-ANC-SE-AN – An abnormal number of unique alerts have triggered from this endpoint.

  • NumDCP-AL-UC-Plt-U-SIP – An abnormal number of unique user names have been observed in application logins to this platform per source IP. These events may include both failed and successful communications.

  • NumCP-DNSResp-NXC-O-NX – An abnormal number of DNS queries to NX domains have been observed for the organization.

  • NumCP-DSOW-EC-UD –An abnormal number of directory service write events have been observed for users in this department. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • NumCP-AppAuthF-EC-U – An abnormal number of application authentication failures have been observed for this user.

  • NumSP-Web-AIA-U-AILLMBytesOut – An abnormal volume of outbound data to AI/LLM web applications has been observed for this user.

  • NumSP-AI-TS-UO-Tokens – An abnormal sum of tokens in successful AI requests and responses has been observed for the organization and has been attributed to this user. If the number of tokens is not available, tokens are estimated at one token per four letters.

  • NumDCP-VPNln-UC-SE-U – An abnormal number of unique user names have been observed in VPN login from this endpoint. These events may include both failed and successful communications.

  • NumSP-Web-Bytes-UD-BytesStorageOut – This is the first time a user has been added to a group from this network zone.

  • NumCP-DNSResp-NXC-SE-NX – An abnormal number of DNS queries to NX domains from this endpoint have been observed.

  • NumCP-PCpwrshell-EC-U – An abnormal number of PowerShell process executions have been observed for this user.

  • NumCP-VPNlnF-EC-O-U-1Day – An abnormal number of failed VPN logins have been observed for the organization by this user in a day.

  • NumDCP-RegW-RPC-ServicesStop-DE-RP – An abnormal number of unique services have been stopped by modifying the registry on this endpoint.

  • NumSP-SADLP-Bytes-U-Bytes – An abnormal amount of outgoing bytes have been recorded in DLP alerts for this user.

  • NumDCP-PLA-LocC-U-LocDoor – An abnormal number of unique doors have been observed in physical access events for this user.

  • NumCP-Web-AIA-U-AILLMSessionCount – An abnormal number of AI/LLM web sessions has been observed for this user.

  • NumCP-WebF-EC-WebDomain – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed for this web domain.

  • NumCP-WebF-EC-U-Id – An abnormal number of HTTP 4xx/5xx error responses has been observed for this user.

To normalize letter cases and improve reliability, featureValue was updated for the following pre-built analytics rules:

  • Prof-Web-TI-U-WebDom-Malicious – This is the first time an HTTP communication attempt to this malicious web domain has been observed for this user. These events may include both failed and successful traffic.

  • Prof-Web-WebDom-O-Tld – This is the first time a successful HTTP communication to this top level domain has been observed for the organization.

  • NumDCP-WebF-WebDomC-U-WebDom – An abnormal number of unique domains have been observed in failed HTTP events for this user.

To normalize letter cases and improve reliability, query was updated for the following pre-built analytics rules:

  • Prof-MFA-FailureReason-U-FailureReason – This is the first time this user failed to authenticate with MFA authentication with this failure reason.

To normalize letter cases and improve reliability, actOnCondition was updated for the following pre-built analytics rules:

  • Fact-CPM-PCrit-GCPPublic – A policy has been successfully modified to allow public access to a GCP resource. This activity should be noted since public resources can be read or downloaded by everyone.

  • Fact-ELF-SA – A service account failed to log into an endpoint using an interactive Windows logon type. A service account is a user account that belongs to an application rather than an end user.

  • Fact-UI-UOO – A user outside the organization was invited to this platform.

  • Fact-AI-Guardrail-Block – An AI guardrail violation has been observed.

  • Fact-PCspctl-DisableGatekeeper – The 'spctl' command has been used to disable the Gatekeeper.

  • Fact-BPM-Public-Policy – The IAM policy or the ACL of an AWS bucket has been successfully modified to make it public to all users.

  • Fact-FPM-PublicCloud – A cloud storage object was modified to become public. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Fact-CPM-PCrit-GCPAdmin –A cloud resource policy in GCP has been successfully modified and included critical administrative permissions. IAM policies determine the roles and permissions granted to users on a resource.

To normalize letter cases and improve reliability, trainOnCondition was updated for the following pre-built analytics rules:

  • Prof-SA-DP-LE-DP – This is the first time a network alert on this port has been triggered for this destination endpoint.

  • Prof-UCreate-E-U-DE – This is the first time this user has created a user account on this endpoint.

  • Prof-FPM-PublicCloud-B-U – This is the first time a cloud storage object was modified to become public in this bucket. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-UCreate-U-DE-U-SystemAcct – This is the first time this system account has created a user account on this endpoint.

  • Prof-AI-O-Guardrail-Block – This is the first time a user in the organization has triggered an AI guardrail violation.

  • Prof-AI-UD-Guardrail-Block – This is the first time a user in this department has triggered an AI guardrail violation.

  • Prof-RPM-PR-R-Public – This is the first time this role's permissions were modified to make it public.

  • Prof-SA-DP-O-DP – This is the first time a network alert on this port has been triggered in the organization.

  • Prof-BPM-Public-O-U – This is the first time this user has attempte to modify the IAM policy or the ACL of an AWS bucket to make it public to all users. These events may include both failed and successful modifications.

  • NumCP-ELF-EC-U-RDP – An abnormal number of failed RDP (remote desktop protocol) logins to this endpoint have been observed for this user.

  • Prof-Network-FromExtIP-DZ-DP – This is the first time a successful connection to this port has been initiated by an external IP for this target zone. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Prof-MFA-MFADevice-U-MFADevice – This is the first time this user authenticates with MFA authentication using this device. These events may include both failed and successful logins.

  • NumSP-Network-BytesToExtIP-SZ-Bytes – An abnormal amount of bytes have been sent in communication that initiated in this network zone to an external IP. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator. These events may include both failed and successful communications.

  • NumSP-Network-BytesToExtIP-SE-Bytes – An abnormal amount of bytes have been sent in communication that initiated from this endpoint to an external IP. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator. These events may include both failed and successful communications.

  • Prof-Network-FromExtIP-DE-DP – This is the first time a successful connection to this port has been initiated by an external IP for this target endpoint. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • NumSP-Network-BytesToExtIP-Failed-SE-Bytes – An abnormal amount of bytes have failed to be sent in communication that initiated from this endpoint to an external IP. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Fact-FPM-PublicCloud – A cloud storage object was modified to become public. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-Network-FromExtIP-O-DZ – This is the first time a successful connection to an endpoint in this network zone has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Prof-FPM-PublicCloud-P-U – This is the first time this user modified a cloud storage object to become public. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-Network-FromExtIP-O-DE – This is the first time a successful connection to this endpoint has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • NumCP-Auth-MfaEC-U – An abnormal number of Multi-Factor Authentication (MFA) authentication events for this user have been observed. These events may include both failed and successful authentications to an MFA service.

  • Prof-MFA-AuthMethod-U-AuthMethod – This is the first time this user authenticates with MFA authentication using this authentication method. These events may include both failed and successful logins.

  • NumCP-AI-U-Guardrail-Block – An abnormal amount of AI guardrail violations have been observed for a user.

  • NumCP-Web-MethodDelC-SIP – An abnormal number of HTTP requests to an internal resource with the method DELETE by this IP have been observed. Probably detects resources deletion.

  • Prof-Network-FromExtIP-O-DP – This is the first time a successful connection to this port has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Prof-Web-AIA-O-WebDomain – This is the first outbound HTTP session to this AI, ML, Generative AI, or LLM application web domain in the organization.

  • Prof-AI-U-Guardrail-Block – This is the first time this user has triggered an AI guardrail violation.

  • Prof-Network-Country-DEDP-SCountry – This is the first time a successful network connection has been observed from this country, determined by geolocation lookup, to this endpoint with this port.

  • NumDCP-EL-UC-DE-UUnknown – An abnormal number of unique unknown user names have been observed in failed logins to this endpoint.

  • Prof-UCreate-E-U-SE – This is the first time this user has created a user account from this endpoint.

  • Prof-SA-DP-DZ-DP – This is the first time a network alert on this port has been triggered for this destination network zone.

  • NumCP-PCpwrshell-EC-U – An abnormal number of PowerShell process executions have been observed for this user.

To normalize letter cases and improve reliability, featureValue and trainOnCondition was updated for the following pre-built analytics rules:

  • Prof-EA-Kerberos-O-ET – This is the first time a Kerberos authentication has been observed with this encryption type for the organization. These events may include both failed and successful authentication.

  • NumDCP-Auth-TgsEC-U-Sn – An abnormal number of Ticket Granting Services (TGS) were observed for this user. In Kerberos authentication, a Ticket Granting Ticket (TGT) is a user authentication token issued by the Key Distribution Center (KDC) to be used to request from the Ticket Granting Service (TGS) access tokens for specific resources/systems joined to the domain. This event is notable since it may indicate use of stolen credentials.

  • NumDCP-EA-TgsEC-UD-Sn – An abnormal number of Ticket Granting Services (TGS) were observed for users in this department. In Kerberos authentication, a Ticket Granting Ticket (TGT) is a user authentication token issued by the Key Distribution Center (KDC) to be used to request from the Ticket Granting Service (TGS) access tokens for specific resources/systems joined to the domain. This event is notable since it may indicate use of stolen credentials.

To normalize letter cases and improve reliability, scopeValue and trainOnCondition was updated for the following pre-built analytics rules:

  • NumCP-Web-MethodDelC-WebDom – An abnormal number of HTTP requests to an internal resource with the method DELETE have been observed for this domain. Probably detects resources deletion.

To filter the events an analytics rule assesses and improve efficiency, applicable_events and actOnCondition were updated for the following pre-built analytics rules:

  • Fact-SEPwrshell-EnumNetworkAdapter – A PowerShell script that enumerate network adapters using wmi object has been executed.

  • Fact-FRead-Passwd – The passwd file is a plain text file in Unix-based operating systems, including Linux and macOS, that stores essential user account information. An attacker can try to read it to get information about the users include the passwords

  • Fact-PC-SuspFind – Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. This command searches for files with the setuid (SUID) permission set for the owner.

  • Fact-PC-ClearComHistory – This can help the attacker ot evade detection.

  • Fact-FRead-Shadow – The shadow file is a file in Unix-based operating systems, including Linux and macOS, that stores password-related information for user accounts. It is a crucial component of the system's security as it helps protect user passwords from unauthorized access. An attacker can try to read it to get the passwords of the users.

  • Fact-EA-KerberosNotPreAuth – A user has successfully authenticated against an endpoint via Kerberos authentication with preauthentication 0.

  • Fact-RA-WDigest – The WDigest authentication protocol, which uses clear-text credential caching, has been enabled via the registry.

  • Fact-FWrite-SSHConfigFile – The sshd_config file was written to.

  • Fact-FWrite-SELinuxConfigFile – The SELinux (Security-Enhanced Linux) configuration file was written to.

  • Fact-EL-UnauthorizedWindowsRDP – An unauthorized user has attempted and failed a Remote Desktop Protocol (RDP) login to a Windows endpoint.

  • Fact-FWrite-EtcLldSo – The /etc/ld.so.preload file, if present, allows users to add additional shared libraries that will be loaded before the standard libraries. This can be useful for various purposes, such as implementing custom libraries, applying system-wide modifications, or debugging and profiling applications. Attackers could use this file to force the loading of their own malicious libraries, enabling them to modify system behavior, escalate privileges, or intercept sensitive data.

  • Fact-FA-Sudoers – The /etc/sudoers file is a critical configuration file in Unix-based operating systems. It controls the access and privileges granted to users and groups to execute commands with elevated privileges (root or superuser privileges) using the sudo command. An attacker can try to read this file to know what user he should get access to, or he can try to write to this file and give a user he have access to these privileges.

  • Fact-PC-Visudo – The /etc/sudoers file is typically edited using the visudo command, which provides a safe way to make changes to the file and prevents multiple simultaneous edits, reducing the risk of syntax errors that could lock users out of administrative access. An attacker can try to read this file to know what user he should get access to, or he can try to write to this file and give a user he have access to these privileges.

  • Fact-PC-Chmod-Setuid – The setuid bit was set using chmod, which can cause a file to execute with the privileges of its owner.

  • Fact-PC-Chmod-Setgid – The setgid bit was set using chmod, which can cause a file to execute with the privileges of its group.

To filter the events an analytics rule assesses and improve efficiency, applicable_events, trainOnCondition, and querywere updated for the following pre-built analytics rules:

  • NumSP-Web-Bytes-U-BytesStorageOut – An abnormal amount of bytes have been uploaded to file sharing websites for this user.

  • NumSP-Web-Bytes-O-BytesStorageOut – An abnormal amount of bytes have been uploaded to file sharing websites for the organization.

  • NumSP-Web-Bytes-U-BytesStorageIn – An abnormal amount of bytes have been downloaded from file sharing websites for this user.

  • NumDCP-FUSB-FPC-U-FP – An abnormal number of unique files has been written to peripheral storage devices for this user.

  • Prof-Fwrite-AuditRule-O-U – This is the first time an audit rule file has been modified by this user.

  • NumCP-SEPwrshell-CmdInvC-O-InvC – An abnormal number of PowerShell command invocations have been observed for the organization.

  • Prof-PC-U-O-U-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed for this user.

  • Prof-Fwrite-E-O-DE-Xdg – This is the first time a XDG autostart file was created on this endpoint.

  • NumDCP-FWrite-AuditRule-U-DE – An abnormal number of unique endpoints where this user modified the audit.rules file in Unix system.

  • NumSP-FUSB-Bytes-U-Bytes – An abnormal amount of file bytes have been written to peripheral storage devices for this user.

  • NumCP-SEPwrshell-WebReq-O-WebReq – An abnormal number of PowerShell web requests have been observed for the organization.

  • NumSP-Web-Bytes-UD-BytesStorageOut – This is the first time a user has been added to a group from this network zone.

  • NumCP-WebF-EC-WebDomain – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed for this web domain.

  • NumCP-WebF-EC-U-Id – An abnormal number of HTTP 4xx/5xx error responses has been observed for this user.

  • NumCP-WebF-EC-SIP – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed from this IP.

To filter the events an analytics rule assesses and improve efficiency, applicable_events and trainOnCondition were updated for the following pre-built analytics rules:

  • Prof-SEPwrshell-U-O-U – This is the first time this user executed a PowerShell script.

  • Prof-PC-E-O-SE-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed on this endpoint.

  • Prof-Fwrite-U-O-U-Plist – This is the first time a plist file was created by this user.

  • Prof-ShA-SE-SN – This is the first time this network share has been accessed from this endpoint.

  • Prof-Fwrite-SystemdService-O-U – This is the first time a systemd service file has been modified by this user.

  • Prof-SEPwrshell-SN-U-SN – This is the first time this user executed a PowerShell script with this name.

  • Prof-Network-OpenClawWebSocket-DE-SE – This is the first time a successful connection to port 18789 has been observed from this source endpoint to this destination endpoint. The port 18789 is the default port of OpenClaw WebSocket Gateway.

  • Prof-PC-U-O-U-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed for this user.

  • Prof-PC-U-O-USudo – This is the first time a process execution of a 'sudo' (Superuser Do) command has been observed for this user.

  • Prof-Fwrite-U-O-U-KernelExtExt –This is the first time a kernel extension file was created on MacOS system by this user.

  • Prof-PC-U-O-U-Kextload –This is the first time a process execution of a 'kextload' (Kernel Extension Load) command has been observed for this user.

  • Prof-AuditPolicyMod-E-O-SE – This is the first time an audit policy modification has been observed from this endpoint. These events may include both failed and successful modifications.

  • Prof-SEPwrshell-CmdInv-U-CmdInv – This is the first time this user executed a PowerShell script with this command.

  • Prof-PC-E-O-SE-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed on this endpoint.

  • Fact-CPM-PCrit-GCPAdmin –A cloud resource policy in GCP has been successfully modified and included critical administrative permissions. IAM policies determine the roles and permissions granted to users on a resource.

  • Prof-SEPwrshell-Web-O-U – This is the first time this user has executed a PowerShell script that performs a web request.

To filter the events an analytics rule assesses and improve efficiency, applicable_events was updated for the following pre-built analytics rules:

  • Cntx-FUSB-Outlook – File has a .pst/.ost extension: True\False

  • Fact-UModify-UACPreAuthDisable – UAC pre-authentication has been disabled for a user account.

  • Prof-GA-Country-U-SCountry – This is the first time an activity has been observed from this country for this user, determined by geolocation lookup.

  • Prof-USB-DevId-O-DevId – This is the first time this peripheral device ID has been observed for the organization.

  • Prof-CA-IE-O-U – This is the first time this user has exported a compute instance. Instance export could be used by an attacker to collect sensitive data that resides inside the organization's virtual machines.

  • Prof-FPM-PublicCloud-B-U – This is the first time a cloud storage object was modified to become public in this bucket. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-GA-Country-O-DCountry – This is the first time an activity has been observed to this country, determined by geolocation lookup.

  • Prof-USB-E-U-SE – This is the first time a peripheral device activity has been observed from this endpoint for this user.

  • Prof-ShA-U-SN – This is the first time this network share has been accessed by this user.

  • Prof-USB-U-O-U – This is the first time a peripheral device activity has been observed for this user.

  • Fact-FPM-PublicCloud – A cloud storage object was modified to become public. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-GA-Brwsr-UD-Brwsr – This is the first time this web browser has been observed for users in this department.

  • Prof-FPM-CloudACL-O-U – This is the first time this user has modified the ACL of a cloud storage object.

  • Prof-USB-DevId-U-DevId – This is the first time this peripheral device ID has been observed for this user.

  • Prof-FPM-PublicCloud-P-U – This is the first time this user modified a cloud storage object to become public. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-USB-E-O-SE - This is the first time a peripheral device activity has been observed from this endpoint.

  • Prof-USB-E-UD-SE – This is the first time a peripheral device activity has been observed from this endpoint for users in this department.

  • Prof-USB-DevId-SE-DevId – This is the first time this peripheral device ID has been observed from this endpoint.

  • Prof-GA-OS-U-OS – This is the first time this operating system has been observed for this user.

  • Prof-GA-Country-DZ-SCountry – This is the first time an activity has been observed from this country to this network zone, determined by geolocation lookup.

  • Prof-CA-FromSnapshot-O-U – This is the first time this user has created a compute resource from an existing snapshot.

  • Prof-GA-Brwsr-O-Brwsr – This is the first time this web browser has been observed for the organization.

  • Prof-GA-Mime-O-Mime – This is the first time this MIME type has been observed for the organization. These events do not include network or endpoint platforms.

  • Prof-USB-DevId-UD-DevId – This is the first time this peripheral device ID has been observed for users in this department.

  • Prof-GA-Country-SZ-DCountry – This is the first time an activity has been observed to this country for this network zone, determined by geolocation lookup.

  • Prof-GA-Country-O-SCountry – This is the first time an activity has been observed from this country, determined by geolocation lookup.

  • Prof-FPM-CloudACL-B-U – This is the first time this user has modified the ACL of a cloud storage object in this bucket.

To ensure profiledFeature analytics rules trigger on the first-time actions, checkFeatureMaturity was removed for the following pre-built analytics rules:

Note

profiledFeature analytics rules without checkFeatureMaturity may trigger more often. This is expected behavior as profiledFeature analytics rules correctly trigger on first-time actions.

  • Prof-RegW-COM-O-CLSID – This is the first time the registry path to a COM class with this CLSID has been modified.

  • Prof-AI-AS-Plt-U – This is the first time this user has shared an AI agent on this platform.

  • Prof-GMA-U-O-UD – This is the first time a user has been added to a group by a user in this department.

  • Prof-PC-E-NetUserAdd-O-U – This is the first time a user account has been created by this user using 'net.exe'.

  • Prof-ELF-E-U-DE – This is the first time this user has failed to log into this endpoint. The user might have logged in successfully before, but this is the first time a failed login event was observed on the endpoint.

  • Prof-RegW-EnvVarPath-O-U – This is the first time this user has modified the PATH environment variable by writing to the registry value 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\Path'.

  • Prof-AI-PI-O-U-Exec – This is the first time an AI request that attempts to cause the agent to execute a command or a script has been sent by this user.

  • Prof-AL-E-O-SE – This is the first time a user in the organization attempted to log into an application from this endpoint. These events may include both failed and successful logins.

  • Prof-VPNIn-Rlm-U-Rlm – This is the first time this user attempted to log into a VPN with this realm. These events may include both failed and successful logins.

  • Prof-GMA-OU-GN-UOU – This is the first time a user in this OU has been added to this group.

  • Prof-RegW-SilentExitMon-O-U – This is the first time this user has modified or created the silent exit configuration of a process by writing a registry key\value under the key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit'.

  • Prof-PC-E-O-SE-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed on this endpoint.

  • Prof-Login-E-DE-SZ – This is the first time a successful login has been observed from this network zone to this endpoint.

  • Prof-Fwrite-U-O-U-Plist – This is the first time a plist file was created by this user.

  • Prof-AI-AC-PLT-UD – This is the first time a user in this department has created an AI agent with this platform.

  • Prof-UCreate-DC-U-DC – This is the first time this domain controller has processed a user creation request for this user.

  • Prof-ShA-SE-SN – This is the first time this network share has been accessed from this endpoint.

  • Prof-Web-WebDom-O-U-WebDomIP – This is the first time an HTTP communication attempt directly to an IP address has been observed for this user. These events may include both failed and successful traffic.

  • Prof-STC-E-O-DE – This is the first time a scheduled task has been created on this endpoint.

  • Prof-ShA-SZ-SN – This is the first time this network share has been successfully accessed from this network zone.

  • Prof-DL-U-O-Uplt – This is the first time a kernel module\driver was loaded for this user.

  • Prof-DL-U-O-Uplt – This is the first time a kernel module\driver was loaded for this user.

  • Prof-UCreate-E-U-DE – This is the first time this user has created a user account on this endpoint.

  • Prof-GA-CSVC-UD-SVC – This is the first time this cloud service was observed in events in this platform for users in this department.

  • Prof-GA-CSVC-U-SVC – This is the first time this cloud service was observed in events in this platform for this user.

  • Prof-AI-O-Guardrail-Block – This is the first time a user in the organization has triggered an AI guardrail violation.

  • Prof-Login-E-U-SZ – This is the first time a successful login has been observed from this network zone for the this user.

  • Prof-AI-AC-PLT-U – This is the first time this user has created an AI agent with this platform.

  • Prof-RegR-SAM-O-U – This is the first time this user has read a registry value under the SAM registry key.

  • Prof-GA-E-Plt-SZ – This is the first time an activity from this network zone has been observed for this platform.

  • Prof-RegW-FileAssoc-O-U – This is the first time this user has modified a command of a file assocation handler by modifing its registry configuration.

  • Prof-EL-EDC-O-SZ – This is the first time an endpoint login event to a domain controller has been observed originating from this network zone for the organization. These events may include both failed and successful logins.

  • Prof-AI-UD-Guardrail-Block – This is the first time a user in this department has triggered an AI guardrail violation.

  • Prof-GCreate-U-P-UD – This is the first time users in this department have created a group on this platform.

  • Prof-Fwrite-SystemdService-O-U – This is the first time a systemd service file has been modified by this user.

  • Prof-STC-O-UD – This is the first time a scheduled task has been created for users in this department.

  • Prof-RegW-Services-O-U – This is the first time this user has modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-RegW-CORPROFILER-O-U – This is the first time this user has modified or created a registry value for an environment variable associated with the COR_PROFILER.

  • Prof-RegW-CORPROFILER-O-U – This is the first time this user has modified or created a registry value for an environment variable associated with the COR_PROFILER.

  • Prof-GCreate-U-O-UD – This is the first time for users in this department to create a group for the organization.

  • Prof-PrivUse-U-O-U – This is the first time a Windows privileged has been used and invoked from this directory for this process.

  • Prof-AI-AC-O-U – This is the first time this user has created an AI agent.

  • Prof-RegD-Services-O-UD – This is the first time users in this department have deleted a service by deleting a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-EW-DCShadow-SE-O-SE – This is the first time the GC (global catalog) and DRS (directory replication service) service principal names have been added to this matured endpoint. These SPNs are required for the active directory replication process, and can be added to a rogue domain controller to execute a DCShadow attack.

  • Prof-RegR-LSA-O-U – This is the first time this user has read a LSA secret from the registry.

  • Prof-EL-EDC-U-SZ – This is the first time an endpoint login event to a domain controller has been observed originating from this network zone for this user. These events may include both failed and successful logins.

  • Prof-VPNIn-Rlm-UD-Rlm – This is the first time a user in this department attempted to log into a VPN with this realm. These events may include both failed and successful logins.

  • Prof-Network-OpenClawWebSocket-DE-SE – This is the first time a successful connection to port 18789 has been observed from this source endpoint to this destination endpoint. The port 18789 is the default port of OpenClaw WebSocket Gateway.

  • Prof-ShA-U-SN – This is the first time this network share has been accessed by this user.

  • Prof-RegW-IFEO-O-U – This is the first time this user has modified or created the Image File Execution Options of a process by writing to the registry value 'Debugger' under the key 'HKLM\SOFTWARE{\Wow6432Node}\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<executable>'.

  • Prof-PrivUse-U-O-UD – This is the first time a Windows privileged has been used and invoked for users in this department.

  • Prof-RegR-SAM-O-UD – This is the first time users in this department have read a registry value under the SAM registry key.

  • Prof-Network-FromExtIP-O-DZ – This is the first time a successful connection to an endpoint in this network zone has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Prof-Login-E-U-DZ – This is the first time this user successfully logged into this network zone.

  • Prof-STC-O-UD – This is the first time a scheduled task has been created for users in this department.

  • Prof-Git-MCP-O-U – This is the first time this user has accessed an MCP-related GitHub repository using a token.

  • Prof-VPNIn-U-O-UC – This is the first time a user in this country attempted to log into a VPN. These events may include both failed and successful logins.

  • Prof-PC-U-O-U-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed for this user.

  • Prof-AL-E-U-SE – This is the first time this user attempted to log into an application from this endpoint. These events may include both failed and successful logins.

  • Prof-Network-FromExtIP-O-DE – This is the first time a successful connection to this endpoint has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Prof-PCca-U-O-U – This is the first time root certificate has been installed on a Linux machine using 'update-ca-certificates' or 'update-ca-trust' for this user.

  • Prof-MFPermMod-U-O-U – This is the first time a mailbox folder permission was modified by this user for the organization.

  • Prof-RegW-SafeBoot-O-U – This is the first time this user has modifed the safe mode boot configuration by writing to a registry value/key under the registry key HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal.

  • Prof-Login-E-O-SZ – This is the first time a successful login has been observed from this network zone for the organization.

  • Prof-Login-E-UD-DZ – This is the first time a user in this department successfully logged into this network zone.

  • Prof-AL-MFA-U-MFA – This is the first time this user has logged into an application without using multi factor authentication (MFA).

  • Prof-GMA-U-O-U – This is the first time a user has been added to a group by this user.

  • Prof-FA-SCFA-O-UD – This is the first time source code file activity (by file extension) has been observed for users in this department. File activity could include read, delete, write or any other type of file related operations.

  • Prof-FWrite-AuthorizedKeys-O-U – This is the first time an 'authorized_keys' file has been modified by this user.

  • Prof-Fwrite-AuditRule-O-U – This is the first time an audit rule file has been modified by this user.

  • Prof-FDel-U-O-U-LogFile – This is the first time a log file has been deleted by this user.

  • Prof-FDel-UnixLogFiles-O-U – This is the first time a log file deletion has been observed for this user in Unix systems.

  • Prof-PCMsbuild-E-O-DE – This is the first time the 'msbuild.exe' process has been used to build and execute a project on this endpoint.

  • Prof-PC-E-NetUserAdd-O-DZ – This is the first time a user account has been created using 'net.exe' on this network zone.

  • Prof-RegW-COM-U-CLSID – This is the first time this user has modified the registry path to a COM class with this CLSID.

  • Prof-GA-Plt-UD-Plt – This is the first activity observed on this platform for users in this department.

  • Prof-GMA-GN-O-GN – This is the first time a user has been added to this group.

  • Prof-PC-U-O-U-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed for this user.

  • Prof-Fwrite-E-O-DE-Xdg – This is the first time a XDG autostart file was created on this endpoint.

  • Prof-EL-E-UD-DE – This is the first time a user from this department attempted to log into this endpoint. These events may include both failed and successful logins.

  • Prof-FUpld-E-U-SE – This is the first time this user has uploaded a file from this endpoint.

  • Prof-AI-U-Guardrail-Block – This is the first time this user has triggered an AI guardrail violation.

  • Prof-Login-E-DZ-SZ – This is the first time a successful login has been observed from this source network zone to this destination network zone.

  • Prof-PC-U-O-USudo – This is the first time a process execution of a 'sudo' (Superuser Do) command has been observed for this user.

  • Prof-Fwrite-U-O-U-KernelExtExt –This is the first time a kernel extension file was created on MacOS system by this user.

  • Prof-FDnld-E-O-SE – This is the first time a file has been downloaded to this endpoint.

  • Prof-UCreate-E-U-SE – This is the first time this user has created a user account from this endpoint.

  • Prof-FUpld-E-O-SE – This is the first time a file has been uploaded from this endpoint.

  • Prof-EL-NTLM-O-SE – This is the first time a successful NTLM login has been observed from this endpoint.

  • Prof-RA-U-Plt-U – This is the first time a role has been assigned by this user on this platform.

  • Prof-FDnld-E-U-SE – This is the first time a file has been downloaded to this endpoint for this user.

  • Prof-PC-U-O-U-Kextload –This is the first time a process execution of a 'kextload' (Kernel Extension Load) command has been observed for this user.

  • Prof-DL-E-O-SE – This is the first time a kernel module\driver was loaded on this endpoint.

  • Prof-EL-E-U-SE – This is the first time this user attempted to login from this endpoint. These events may include both failed and successful logins.

  • Prof-PC-E-O-SE-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed on this endpoint.

  • Prof-GCreate-U-P-U – This is the first time this user has created a group on this platform.

  • Prof-AI-AC-O-UD – This is the first time a user in this department has created an AI agent.

  • Prof-GCreate-U-O-U – This is the first time for this user to create a group for the organization.

  • Prof-FWrite-AuthorizedKeys-O-UD – This is the first time an 'authorized_keys' file has been modified by users in this department.

  • Prof-DS-E-O-SZ – This is the first time a user in the organization performed an activity on a directory service object from this network zone.

  • Prof-AI-AC-O-PLT – This is the first time a user in the organization has created an AI agent with this platform.

  • Prof-PrivUse-E-U-SE – This is the first time a Windows privileged has been used and invoked from this endpoint for this user.

  • Prof-FA-SCFA-O-U – This is the first time source code file activity (by file extension) has been observed for this user. File activity could include read, delete, write or any other type of file related operations.

  • Prof-RegR-LSA-O-UD – This is the first time users in this department read have read a LSA secret from the registry.

  • Prof-EL-E-U-DE – This is the first time this user attempted to log into this endpoint. These events may include both failed and successful logins.

  • Prof-SEPwrshell-Web-O-U – This is the first time this user has executed a PowerShell script that performs a web request.

  • NumCP-VPNlnF-EC-O-U-1Day – An abnormal number of failed VPN logins have been observed for the organization by this user in a day.

  • Prof-RegW-Services-O-UD – This is the first time users in this department have modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-RegR-Certs-U-RP – This is the first time this user has read this certificate\private key related registry value.

  • Prof-RegW-UAC-O-U – This is the first time this user has modified or created a registry key\value under the UAC configuration key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System'.

To exclude noisy administrative and system network shares from behavioral baselines and reduce false positive alerts, trainOnCondition was updated for the following pre-built analytics rules:

  • Prof-ShA-SZ-SN – This is the first time this network share has been successfully accessed from this network zone.

  • Prof-ShA-U-SN – This is the first time this network share has been accessed by this user.

For faster and more efficient processing, actOnCondition was updated for the following pre-built analytics rules:

  • Fact-EMRC-FwR-ExtDom – An inbox rule has been configured to forward emails to an email address that's in a different domain than the rule's creator.

  • Fact-PCassoc-FAssocCh – The Assoc (File Association) process has been used to change the association of an extension to execution. This sigma rule is authored by Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_change_default_file_association.yml

  • Fact-PCping-HexEn – The 'ping.exe' process has been used to ping a hex encoded IP address. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_ping_hex_ip.yml

To ensure pre-built analytics rules reference valid MITRE techniques, mitre was updated for the following pre-built analytics rules:

  • Prof-DS-E-O-SE – This is the first time a user in the organization performed an activity on a directory service object from this endpoint.

  • Fact-PCsc-SvcMod-PCL – The SC (Service Controller) process has been used to configure a PowerShell service. This sigma rule is authored by Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml

  • NumCP-DSOW-EC-U – An abnormal number of directory service events have been observed for this user. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-RegW-EnvVarPath-O-U – This is the first time this user has modified the PATH environment variable by writing to the registry value 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\Path'.

  • Prof-DSF-AT-U-AT – This is the first time this directory service activity type failed for this user. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Fact-PCsc-SuspSP – The SC (Service Controller) process has been executed with suspicious command line parameters.

  • Prof-WinSC-U-DE-DU – This is the first time a service permitted to run under this user's credentials was created on this endpoint.

  • Prof-DS-DSOC-O-DSOC – This is the first time a user in the organization performed an activity on a directory service object with this object class.

  • Fact-PCgup-AF – The Notepad++ updater has been executed from a folder it shouldn't normally execute from. This sigma rule is authored by Florian Roth (Nextron Systems) and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_gup.yml

  • Prof-RegW-Services-O-U – This is the first time this user has modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-RegW-CORPROFILER-O-U – This is the first time this user has modified or created a registry value for an environment variable associated with the COR_PROFILER.

  • Prof-DS-E-UD-SE – This is the first time a user in this department performed an activity on a directory service object from this endpoint.

  • Prof-BPM-Public-O-U – This is the first time this user has attempte to modify the IAM policy or the ACL of an AWS bucket to make it public to all users. These events may include both failed and successful modifications.

  • Prof-DS-E-U-SZ – This is the first time this user performed an activity on a directory service object from this network zone.

  • NumCP-DSOW-EC-O – An abnormal number of directory service write events have been observed for the organization. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-WinSC-E-U-DE – This is the first time a service creation has been observed on this endpoint for this user.

  • Fact-WinSC-SuspSC-Temp – A service has been created from a temporary internet files directory.

  • Prof-DS-E-U-SE – This is the first time this user performed an activity on a directory service object from this endpoint.

  • Prof-DSF-AT-UD-AT – This is the first time this directory service activity type failed for users in this department. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-WinSC-E-O-DZ – This is the first time a service creation has been observed in this network zone.

  • Prof-Login-E-UD-DZ – This is the first time a user in this department successfully logged into this network zone.

  • Fact-CPM-PCrit-AWSAdmin – A policy with critical administrative permissions has been successfully created or attached to an identity in AWS. Policies in AWS are the documents that dictates what permissions are granted to identities and resources.

  • Prof-WinSC-E-DE-DZ – This is the first time a service creation has been observed on this endpoint for this destination network zone.

  • Fact-WinSC-SuspSC-Param – A service has been created with suspicious execution command parameters.

  • Prof-DS-DSOC-UD-DSOC – This is the first time a user in this department performed an activity on a directory service object with this object class.

  • Fact-RegW-ChromeExt – A Chrome extension has been installed via the registry.

  • Fact-PCsc-SvcMod-Ingt – The SC (Service Controller) process has been used to change a service binary path or failure command configuration with medium integrity level executed. This sigma rule is authored by Teymur Kheirkhabarov and is licensed under Detection Rule License (DRL), https://github.com/SigmaHQ/sigma/blob/master/LICENSE.Detection.Rules.md. Reference: https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_sc_change_sevice_image_path_by_non_admin.yml

  • Prof-DS-DSOC-U-DSOC – This is the first time this user performed an activity on a directory service object with this object class.

  • Prof-GA-Brwsr-O-Brwsr – This is the first time this web browser has been observed for the organization.

  • Prof-WinSC-E-UD-DE – This is the first time a service creation has been observed on this endpoint for users in this department.

  • Fact-U-PrivMM – A non-privileged user has been observed accessing an attribute of a privileged directory service user account.

  • NumCP-DSOW-EC-UD –An abnormal number of directory service write events have been observed for users in this department. Directory services typically manage various types of objects to organize and administer resources within a network environment.

  • Prof-DS-E-O-SZ – This is the first time a user in the organization performed an activity on a directory service object from this network zone.

  • Prof-PC-Sysvol-O-UD – This is the first time a SYSVOL domain group policy has been accessed by a process for users in this department.

  • Prof-WinSC-PP-SN-PP – This is the first time this service was created with this command process path.

  • Prof-RegW-Services-O-UD – This is the first time users in this department have modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-DS-E-UD-SZ – This is the first time a user in this department performed an activity on a directory service object from this network zone.

  • NumCP-WebF-EC-WebDomain – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed for this web domain.

  • NumCP-WebF-EC-SIP – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed from this IP.

  • NumCP-WebF-EC-SIP – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed from this IP.

To ensure pre-built analytics rules reference an Exabeam use case, useCase was updated for the following pre-built analytics rules:

  • NumCP-WebF-EC-WebDomain – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed for this web domain.

  • NumCP-WebF-EC-SIP – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed from this IP.

Because either checkScopeMaturity or checkFeatureMaturity was not configured or set to false, maturityThreshold was removed for the following pre-built analytics rules:

  • Prof-RegW-COM-O-CLSID – This is the first time the registry path to a COM class with this CLSID has been modified.

  • Prof-GMA-U-O-UD – This is the first time a user has been added to a group by a user in this department.

  • Prof-PC-E-NetUserAdd-O-U – This is the first time a user account has been created by this user using 'net.exe'.

  • Prof-DS-E-O-SE – This is the first time a user in the organization performed an activity on a directory service object from this endpoint.

  • Prof-RegW-EnvVarPath-O-U – This is the first time this user has modified the PATH environment variable by writing to the registry value 'HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment\Path'.

  • Prof-AI-PI-O-U-Exec – This is the first time an AI request that attempts to cause the agent to execute a command or a script has been sent by this user.

  • Prof-AL-E-O-SE – This is the first time a user in the organization attempted to log into an application from this endpoint. These events may include both failed and successful logins.

  • Prof-RegW-SilentExitMon-O-U – This is the first time this user has modified or created the silent exit configuration of a process by writing a registry key\value under the key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit'.

  • Prof-PC-E-O-SE-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed on this endpoint.

  • Prof-Fwrite-U-O-U-Plist – This is the first time a plist file was created by this user.

  • Prof-UCreate-DC-U-DC – This is the first time this domain controller has processed a user creation request for this user.

  • Prof-Web-WebDom-O-U-WebDomIP – This is the first time an HTTP communication attempt directly to an IP address has been observed for this user. These events may include both failed and successful traffic.

  • Prof-STC-E-O-DE – This is the first time a scheduled task has been created on this endpoint.

  • Prof-DL-U-O-Uplt – This is the first time a kernel module\driver was loaded for this user.

  • Prof-UCreate-E-U-DE – This is the first time this user has created a user account on this endpoint.

  • Prof-RegW-AppPaths-O-U – This is the first time this user has modified a registry key\value under the App Paths key '[HKLM/HKCU]\Software\Microsoft\Windows\CurrentVersion\App Paths'.

  • Prof-AI-O-Guardrail-Block – This is the first time a user in the organization has triggered an AI guardrail violation.

  • Prof-RegR-SAM-O-U – This is the first time this user has read a registry value under the SAM registry key.

  • Prof-RegW-FileAssoc-O-U – This is the first time this user has modified a command of a file assocation handler by modifing its registry configuration.

  • Prof-EL-EDC-O-SZ – This is the first time an endpoint login event to a domain controller has been observed originating from this network zone for the organization. These events may include both failed and successful logins.

  • Prof-AI-UD-Guardrail-Block – This is the first time a user in this department has triggered an AI guardrail violation.

  • Prof-Fwrite-SystemdService-O-U – This is the first time a systemd service file has been modified by this user.

  • Prof-STC-O-UD – This is the first time a scheduled task has been created for users in this department.

  • Prof-RegW-Services-O-U – This is the first time this user has modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-RegW-CORPROFILER-O-U – This is the first time this user has modified or created a registry value for an environment variable associated with the COR_PROFILER.

  • Prof-GCreate-U-O-UD – This is the first time for users in this department to create a group for the organization.

  • Prof-PrivUse-U-O-U – This is the first time a Windows privileged has been used and invoked from this directory for this process.

  • Prof-AI-AC-O-U – This is the first time this user has created an AI agent.

  • Prof-RegD-Services-O-UD – This is the first time users in this department have deleted a service by deleting a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-EW-DCShadow-SE-O-SE – This is the first time the GC (global catalog) and DRS (directory replication service) service principal names have been added to this matured endpoint. These SPNs are required for the active directory replication process, and can be added to a rogue domain controller to execute a DCShadow attack.

  • Prof-RegR-LSA-O-U – This is the first time this user has read a LSA secret from the registry.

  • Prof-EL-EDC-U-SZ – This is the first time an endpoint login event to a domain controller has been observed originating from this network zone for this user. These events may include both failed and successful logins.

  • Prof-RegW-IFEO-O-U – This is the first time this user has modified or created the Image File Execution Options of a process by writing to the registry value 'Debugger' under the key 'HKLM\SOFTWARE{\Wow6432Node}\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<executable>'.

  • Prof-RegR-SAM-O-UD – This is the first time users in this department have read a registry value under the SAM registry key.

  • Prof-PrivUse-U-O-UD – This is the first time a Windows privileged has been used and invoked for users in this department.

  • Prof-RegD-Services-O-UD – This is the first time users in this department have deleted a service by deleting a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-PC-U-O-U-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed for this user.

  • Prof-CPM-Resource-O-R – This is the first time an IAM policy of a resource in this directory has been successfully modified in GCP. IAM policies determine the roles and permissions granted to users on a resource.

  • Prof-Network-FromExtIP-O-DE – This is the first time a successful connection to this endpoint has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Prof-MFPermMod-U-O-U – This is the first time a mailbox folder permission was modified by this user for the organization.

  • Prof-RegW-SafeBoot-O-U – This is the first time this user has modifed the safe mode boot configuration by writing to a registry value/key under the registry key HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal.

  • Prof-Login-E-O-SZ – This is the first time a successful login has been observed from this network zone for the organization.

  • Prof-PC-U-O-U-Modprobe – This is the first time a process execution of a 'modprobe' (Module Probe, a kernel module management tool) command has been observed for this user.

  • Prof-Fwrite-E-O-DE-Xdg – This is the first time a XDG autostart file was created on this endpoint.

  • Prof-RegA-PP-O-PP – This is the first time this process has performed a registry activity.

  • Prof-AI-U-Guardrail-Block – This is the first time this user has triggered an AI guardrail violation.

  • Prof-GMA-GN-O-GN – This is the first time a user has been added to this group.

  • Prof-PC-U-O-USudo – This is the first time a process execution of a 'sudo' (Superuser Do) command has been observed for this user.

  • Prof-Fwrite-U-O-U-KernelExtExt –This is the first time a kernel extension file was created on MacOS system by this user.

  • Prof-FDnld-E-O-SE – This is the first time a file has been downloaded to this endpoint.

  • Prof-CPM-Resource-U-R – This is the first time an IAM policy of a resource in this directory has been successfully modified by this user in GCP. IAM policies determine the roles and permissions granted to users on a resource.

  • Prof-UCreate-E-U-SE – This is the first time this user has created a user account from this endpoint.

  • Prof-FUpld-E-O-SE – This is the first time a file has been uploaded from this endpoint.

  • Prof-EL-NTLM-O-SE – This is the first time a successful NTLM login has been observed from this endpoint.

  • Prof-PC-U-O-U-Kextload –This is the first time a process execution of a 'kextload' (Kernel Extension Load) command has been observed for this user.

  • Prof-DL-E-O-SE – This is the first time a kernel module\driver was loaded on this endpoint.

  • Prof-Network-FromExtIP-O-DZ – This is the first time a successful connection to an endpoint in this network zone has been initiated by an external IP for the organization. If the initiator cannot be determined from the event, it is inferred based on port values: the IP\endpoint communicating with the lower port is considered the initiator.

  • Prof-STC-O-UD – This is the first time a scheduled task has been created for users in this department.

  • Prof-Git-MCP-O-U – This is the first time this user has accessed an MCP-related GitHub repository using a token.

  • Prof-VPNIn-U-O-UC – This is the first time a user in this country attempted to log into a VPN. These events may include both failed and successful logins.

  • Prof-PCca-U-O-U – This is the first time root certificate has been installed on a Linux machine using 'update-ca-certificates' or 'update-ca-trust' for this user.

  • Prof-PC-E-O-SE-Insmod – This is the first time a process execution of a 'insmod' (Install Module) command has been observed on this endpoint.

  • Prof-AI-AC-O-UD – This is the first time a user in this department has created an AI agent.

  • Prof-GCreate-U-O-U – This is the first time for this user to create a group for the organization.

  • Prof-FWrite-AuthorizedKeys-O-UD – This is the first time an 'authorized_keys' file has been modified by users in this department.

  • Prof-DS-E-O-SZ – This is the first time a user in the organization performed an activity on a directory service object from this network zone.

  • Prof-AI-AC-O-PLT – This is the first time a user in the organization has created an AI agent with this platform.

  • Prof-FA-SCFA-O-U – This is the first time source code file activity (by file extension) has been observed for this user. File activity could include read, delete, write or any other type of file related operations.

  • Prof-RegR-LSA-O-UD – This is the first time users in this department read have read a LSA secret from the registry.

  • Prof-SEPwrshell-Web-O-U – This is the first time this user has executed a PowerShell script that performs a web request.

  • NumCP-VPNlnF-EC-O-U-1Day – An abnormal number of failed VPN logins have been observed for the organization by this user in a day.

  • Prof-RegW-Services-O-UD – This is the first time users in this department have modified or created a service by writing a registry key\value under the key 'HKLM\SYSTEM\CurrentControlSet\Services'.

  • Prof-RegW-UAC-O-U – This is the first time this user has modified or created a registry key\value under the UAC configuration key 'HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System'.

For clarity, title, description, and detectionReason were updated for the following pre-built analytics rules:

  • NumCP-WebF-EC-WebDomain – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed for this web domain.

  • NumCP-WebF-EC-U-Id – An abnormal number of HTTP 4xx/5xx error responses has been observed for this user.

  • Fact-PC-Chmod-Setuid – The setuid bit was set using chmod, which can cause a file to execute with the privileges of its owner.

  • Fact-PC-Chmod-Setgid – The setgid bit was set using chmod, which can cause a file to execute with the privileges of its group.

  • NumCP-WebF-EC-SIP – An abnormal number of HTTP 4xx/5xx error responses to internal resources has been observed from this IP.

To clearly communicate that the pre-built analytics rule is a mandatory rule the analytics engine requires to process correlation rule triggers, title was updated to Mandatory New-Scale Analytics Link: A correlation rule is triggered (Do Not Disable) for the following pre-built analytics rule:

  • Fact-SA-ET-RN – A correlation rule has been triggered

To accurately display the evaluated external domain that triggered the pre-built analytics rule, detectionReason was updated to use the ${event.external_domain} variable for the following pre-built analytics rule:

  • Fact-EMRC-FwR-ExtDom – An inbox rule has been configured to forward emails to an email address that's in a different domain than the rule's creator.

To correct a typo, featureValue was updated for the following pre-built analytics rules:

  • Prof-PC-CmdArgs-Msbuild-O-XMLParam – This is the first time the 'msbuild.exe' process has been used to build a project with this xml file.

  • Prof-SA-PN-U-PN – This is the first time an alert triggered on this process for this user.

  • Prof-SA-PN-O-PN – This is the first time a security alert triggered on this process for the organization.

  • Prof-PC-PN-Plt-PN – This is the first time this process has been executed in this platform. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • NumDCP-PCCEnum-TC-U-CEnum – An abnormal number of unique credential enumeration tools have been executed for this user.

  • Prof-FPM-PublicCloud-B-U – This is the first time a cloud storage object was modified to become public in this bucket. By manipulating file permissions to make the object public, attackers can expose the data of important or sensitive files, making them available to read, download or even modify by everyone.

  • Prof-PCroute-NetDisc-U-PN – This is the first time a process execution of 'route.exe' has been observed for this user.

  • Prof-STC-U-PN – This is the first time a scheduled task has been created and configured to execute this process for this user.

  • Prof-DllLoad-Dll-O-FN – This is the first time this DLL image file was loaded in the organization.

  • Prof-PC-PN-PltU-PN – This is the first time this process has been executed in this platform for this user. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • Prof-PC-PN-DE-PN – This is the first time this process has been executed on this endpoint. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • NumDCP-PCHEnum-TC-U-HEnum – An abnormal number of unique host enumeration tools have been executed for this user.

  • Prof-PC-PN-PltSZ-PN – This is the first time this process has been executed in this platform from this network zone. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • Prof-PC-PN-PltUD-PN – This is the first time this process has been executed in this platform for users in this department. This feature only models processes from - Windows and Unix commands, pentest tools, system enumeration, account enumeration and network sniffers.

  • Prof-STC-O-PN – This is the first time a scheduled task has been created and configured to execute this process for the organization.

  • Prof-PCIOC-IOCPenT-U-PenT – This is the first time a process execution of a known pentesting tool has been observed for this user.

  • Prof-SA-PN-UD-PN – This is the first time an alert triggered on this process for users in this department.

  • Prof-RegA-PP-O-PP – This is the first time this process has performed a registry activity.

  • Prof-STC-TN-O-TN – This is the first time a scheduled task with this name has been created.

  • Prof-PCipconfig-NetDisc-U-PN – This is the first time a process execution of 'ipconfig.exe' has been observed for this user.

  • Prof-STC-TN-UD-TN – This is the first time a scheduled task with this name has been created for users in this department.

  • Prof-PCpwrshell-En-O-PP – This is the first time a process execution of PowerShell with an encrypted command has been observed for this parent process.

To correct a typo, scopeValue was updated for the following pre-built analytics rules:

  • Prof-DllLoad-Ext-PN-FileExt – This is the first time a DLL image file with this extension was loaded for this process.

  • NumSP-FRead-FS-B-Bytes – An abnormal amount of file bytes have been read in this bucket for this user.

  • NumDCP-FRead-EC-B-FP – An abnormal number of unique files have been read in this bucket for this user.

  • Prof-STC-PP-TN-PP – This is the first time a scheduled task has been created and configured to execute this process for this task name.

  • Prof-PC-PN-Pdir – This is the first time a process execution has been observed from this directory for this process.

To correct a typo, value was updated for the following pre-built analytics rules:

  • Cntx-GMA-GCrit-Admin – Security group is privileged: True\False

To correct a typo, query was updated for the following pre-built analytics rules:

  • NumCP-AI-U-Guardrail-Block – An abnormal amount of AI guardrail violations have been observed for a user.

To correct a typo, featureValue and scopeValue were updated for the following pre-built analytics rules:

  • Prof-PC-PPN-PN-PPN – This is the first time this parent process has been observed for this matured child process.

  • Prof-FWrite-UMWorkerProcess-PN-FN – This is the first time this file was created by the 'umworkerprocess.exe' process.

  • Prof-PC-PPN-PPN-PN – This is the first time this child process has been observed for this matured parent process.

Because of low performance, and because other pre-built analytics rules provide more precise Mimikatz and pentesting detection value, the following obsolete pre-built analyyics rule was removed:

  • Fact-Login-PenTT – A domain associated with known hacking tools has been observed in a login event.

Resolved Issues

Site Collector 2.23: Security Vulnerabilities Remediations

The Site Collectors 2.23 (September 2026) release includes remediated security vulnerabilities. For more information about Exabeam’s commitment to remediating vulnerabilities for Site Collector, see the Vulnerability Remediation Policy.

There are no open known CVEs in any container image (Nifi). Toolkit has been deprecated and is no longer in use hence no security vulnerabilities update is available for that.

The following table lists the CVEs remediated for the Nifi container and their severity.

Critical

High

Medium

Low

Total: 2

Total: 17

Total:15

Total: 6

CVE-2026-11856 CVE-2026-4739

CVE-2018-6952

CVE-2025-66862

CVE-2025-66863

CVE-2025-66864

CVE-2025-66865

CVE-2025-66866

CVE-2026-18220

CVE-2026-3441

CVE-2026-3442

CVE-2026-54371

CVE-2026-54876

CVE-2026-66032

CVE-2026-66033

CVE-2026-66034

CVE-2026-66035

CVE-2026-67422

CVE-2026-6846

CVE-2017-13716

CVE-2019-20633

CVE-2021-45261

CVE-2024-2236

CVE-2026-13595

CVE-2026-15003

CVE-2026-27171

CVE-2026-27456

CVE-2026-3184

CVE-2026-42250

CVE-2026-4647

CVE-2026-56288

CVE-2026-56289

CVE-2026-6844

CVE-2026-6845

CVE-2025-1150

CVE-2025-1151

CVE-2025-66861

CVE-2026-53910

CVE-2026-56392

CVE-2026-57062

Threat Detection Management Resolved Issues

Issue ID

Description

ENG-102035

When you navigated to rule trigger events for an analytics rule using the Quick Search column link CRMitreMoreInfoIcon.png, the Search query returned inaccurate results if the analytics rule name was not unique. This issue occurred because the query used the analytics rule name. The query returned rule trigger events for all analytics rules with the same name, not just the one selected from Quick Search.

To ensure the Search query returns rule trigger events for a specific analytics rule, the link to Search now queries using the analytics rule ID.