Skip to content

Detection Catalog

Detection ID Name Severity Platforms Capabilities ATT&CK
det.defense.vss.delete.001 Volume Shadow Copy Deletion via vssadmin or wmic 🔴 critical windows windows.vss.delete T1490
det.injection.hollow.001 Process Hollowing via NtUnmapViewOfSection 🔴 critical windows process.injection.hollow T1055.012
det.credential.lsass.access.001 LSASS Memory Access from Non-SYSTEM Account 🟠 high windows process.lsass.access T1003.001
det.defense.amsi.bypass.001 AMSI Bypass via Memory Patching or Provider Removal 🟠 high windows windows.amsi.bypass T1562.001
det.defense.defender.disable.001 Windows Defender Real-Time Protection Disabled 🟠 high windows windows.defender.disable T1562.001
det.execution.certutil.lolbin.001 certutil LOLBin Abuse for Download or Decode 🟠 high windows windows.lolbin.certutil T1105, T1140
det.injection.dll.001 Suspicious DLL Loaded into Remote Process 🟠 high windows process.injection.dll T1055.001
det.persistence.service.create.001 Suspicious Windows Service Created 🟠 high windows windows.service.create T1543.003
det.persistence.wmi.subscription.001 WMI Permanent Event Subscription Created 🟠 high windows wmi.subscription.create T1546.003
det.command_and_control.proxy.tunnel.001 Suspicious Proxy or Tunnel Configuration for C2 🟡 medium windows, linux, macos network.proxy.tunnel T1090
det.discovery.cloud.iam.enumerate.001 Cloud IAM Role and Policy Enumeration 🟡 medium cloud cloud.iam.enumerate T1069.003
det.persistence.registry.run.001 Registry Run Key Persistence 🟡 medium windows registry.run.persist T1547.001

Total: 12 detections — 🔴 critical: 2, 🟠 high: 7, 🟡 medium: 3.