Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detect or threat hunt for a burst of Windows built-in discovery/reconnaissance utilities (Seven or more distinct tools within a single day) executed under one causality chain on one host, consistent with post-exploitation situational awareness by an interactive operator, script, or C2 implant.
avatar
Collin Lairamore@Bollinmore
avatar
Detections.ai Community
2 months ago
004