Product
high
advisory
Detection of Attacker Tools on Endpoints
1 rule 3 TTPsThis analytic detects the execution of tools commonly used by attackers for activities such as unauthorized access, network scanning, privilege escalation, password dumping, or data exfiltration, leveraging process activity data from Endpoint Detection and Response (EDR) agents to identify known attacker tool names.
Sysmon +6
attacker-tools
endpoint-detection
post-exploitation
EDR
windows
1r
3t
high
advisory
Windows Event Logging Service Shutdown Detection
2 rules 1 TTPDetection of the Windows Event Log service shutdown, indicated by Event ID 1100, which can signify attempts to evade detection by disabling logging.
Splunk Enterprise +3
defense-evasion
windows
event-logging
2r
1t