Filter Usecases
×Level
Threat Category
MITRE ATT&CK
Primary data source
Filter applied :
Platform: Windows × Clear all
1-20 of
1247
Rule Name
Level
MITRE ATT&CK
Category
Last Updated
Scheduled task manipulation
L2 - Investigation
TA0003
Endpoint
Last updated: April 10, 2026
View details
S3 bucket access anomalies
L2 - Investigation
TA0010
Cloud and SaaS
Last updated: April 10, 2026
View details
Suspicious AWS IAM activity
L2 - Investigation
TA0004
Cloud and SaaS
Last updated: April 10, 2026
View details
Web shell installation
L3 - Incident
TA0003
Application and Data
Last updated: April 10, 2026
View details
Windows Registry Evasion
L2 - Investigation
TA0005
Endpoint
Last updated: April 10, 2026
View details
Shadow IT monitoring
L2 - Investigation
TA0007
Cloud and SaaS
Last updated: April 10, 2026
View details
Malicious process hunting lineage
L2 - Investigation
TA0002
Endpoint
Last updated: April 10, 2026
View details
Column integrity monitoring
L2 - Investigation
TA0040
Application and Data
Last updated: April 10, 2026
View details
Dark web - Corporate IDs in SaaS apps
L1 - Triage
TA0006
Identity and Access
Last updated: April 10, 2026
View details
Short lived admin accounts
L2 - Investigation
TA0004
Identity and Access
Last updated: April 10, 2026
View details
Credential dumping tools
L2 - Investigation
TA0002
Endpoint
Last updated: April 10, 2026
View details
Privilege escalation through service account misuse
L3 - Incident
TA0004
Identity and Access
Last updated: April 10, 2026
View details
Unauthorized PowerShell remote session
L2 - Investigation
TA0002
Endpoint
Last updated: April 10, 2026
View details
Cross-site scripting (XSS) leading to session theft
L3 - Incident
TA0006
Application and Data
Last updated: April 10, 2026
View details
Unauthorized four-eyes authorization disabling in Veeam
L3 - Incident
TA0040
Application and Data
Last updated: April 10, 2026
View details
Failover plan tampering in Veeam solutions
L3 - Incident
TA0005
Application and Data
Last updated: April 10, 2026
View details
Command line obfuscation
L2 - Investigation
TA0005
TA0002
Endpoint
Last updated: April 10, 2026
View details
Network share tampering
L2 - Investigation
TA0005
TA0040
Network
Last updated: April 10, 2026
View details
Unattended system login detection
L2 - Investigation
TA0003
TA0006
TA0005
Identity and Access
Last updated: April 10, 2026
View details
AD backup extraction
L2 - Investigation
TA0006
Identity and Access
Last updated: April 10, 2026
View details
AD database tampering
L2 - Investigation
TA0006
TA0003
TA0005
Identity and Access
Last updated: April 10, 2026
View details
Boot configuration tampering
L2 - Investigation
TA0005
TA0040
Endpoint
Last updated: April 10, 2026
View details
Cloud brute force login attempts
L1 - Triage
TA0006
TA0001
Cloud and SaaS
Last updated: April 10, 2026
View details
DLL injection via registry
L2 - Investigation
TA0004
Endpoint
Last updated: April 10, 2026
View details
Registry security controls disabled
L2 - Investigation
TA0005
Endpoint
Last updated: April 10, 2026
View details
Security logging and monitoring disabled
L2 - Investigation
TA0005
Endpoint
Last updated: April 10, 2026
View details
System level account management activity
L2 - Investigation
TA0004
TA0003
TA0005
Identity and Access
Last updated: April 10, 2026
View details
System time discovery activity
L1 - Triage
TA0007
Endpoint
Last updated: April 10, 2026
View details
Automated file system enumeration
L2 - Investigation
TA0009
Endpoint
Last updated: April 10, 2026
View details
BITS service abuse detection
L2 - Investigation
TA0005
TA0003
TA0011
Endpoint
Last updated: April 10, 2026
View details
Critical service disruption
L2 - Investigation
TA0040
TA0005
TA0003
Endpoint
Last updated: April 10, 2026
View details
Darkgate malware account creation
L2 - Investigation
TA0003
TA0004
Endpoint
Last updated: April 10, 2026
View details
Data staging for exfiltration
L2 - Investigation
TA0010
Application and Data
Last updated: April 10, 2026
View details
DB master credentials changed
L2 - Investigation
TA0003
Cloud and SaaS
Last updated: April 10, 2026
View details
Failed privilege elevation attempts
L2 - Investigation
TA0004
Endpoint
Last updated: April 10, 2026
View details
Kerberos authentication attacks
L2 - Investigation
TA0006
Identity and Access
Last updated: April 10, 2026
View details
Network firewall weakening
L2 - Investigation
TA0005
Network
Last updated: April 10, 2026
View details
Vmware esxi privilege escalation attack
L2 - Investigation
TA0004
Endpoint
Last updated: April 10, 2026
View details


