Admin Share Write Followed by Execution
A file lands on ADMIN$ or C$ over SMB and something runs from that path minutes later. Either half is noisy; the sequence is the classic PsExec shape.
Open library
Every rule carries its log-source requirements, its documented false positives and the atomic test that proves it fires. If a rule here has no false-positive section, it is not finished and we have not shipped it.
26 of 26 rules
A file lands on ADMIN$ or C$ over SMB and something runs from that path minutes later. Either half is noisy; the sequence is the classic PsExec shape.
Someone blinding the audit trail. One of the highest-signal cloud detections you can deploy - near-zero noise outside planned change windows.
Directory replication rights exercised by a principal that is not a domain controller. If this fires for real, the domain is gone.
The classic phishing payload chain. The parent–child relationship is what makes this precise - encoded PowerShell on its own is noise.
Volume and breadth together. Backup agents touch many files but few extensions; encryption touches many files across many directories and rewrites the extension.
Correlates a risky sign-in with an authentication-method registration minutes later - the fingerprint of account takeover establishing persistence.
EDR, backup or logging services being stopped. Requires two or more in the same window, which separates pre-encryption housekeeping from ordinary service churn.
A non-allowlisted process opening LSASS with memory-read rights - the core primitive behind Mimikatz, comsvcs.dll dumping and most credential theft tooling.
Creation of the HKCU ms-settings shell open command key, the hijack that makes auto-elevating fodhelper.exe run an attacker binary with no consent prompt.
The last quiet moment before ransomware encrypts. vssadmin, wmic or wbadmin destroying recovery points should page a human, not fill a queue.
The post-exploitation tell. A web server should never parent a shell; when it does, the exploit already worked and you are looking at what came next.
The Security, System, PowerShell or Sysmon log being cleared. Rarely legitimate outside a change window, and one of the few cases where the missing log is the evidence.
Reads are normal. Reads at volume by one principal across many objects in an hour, excluding principals whose baseline already moves data in bulk, are not.
A success is only interesting in context. This pairs it with recent failures for the same account and a country that account has never signed in from in 30 days.
Tunnels are chatty and their labels are long and random. Neither signal alone survives contact with a CDN, so this requires both within a ten minute bin.
One source opening interactive sessions to many hosts in an hour. Counts distinct destinations, because admins revisit a few machines and lateral movement touches many once.
TGS requests downgraded to RC4-HMAC - the encryption type attackers force so service-ticket hashes can be cracked offline.
WmiPrvSE.exe spawning a child is the server side of wmic process call create. The parent relationship is the detection; the command line is context.
Bash redirecting a shell to a network socket. No binary dropped, no file on disk - a common next step after web application compromise.
rundll32.exe invoked with no export name and then opening an outbound socket. Normal usage always names an export; this shape is proxied execution.
Public-ACL or wildcard-principal changes on a bucket. Usually a misconfiguration, occasionally staged exfiltration.
A task registered with an action pointing at a user-writable directory. Legitimate installers schedule from Program Files; attackers schedule from temp.
A new Windows service whose binary lives in Temp, AppData or a public folder. Persistence and privilege escalation in a single event.
The FilterToConsumerBinding that turns WMI into fileless, reboot-surviving execution. Rare in most estates, which is exactly what makes it high-fidelity.
Low-and-slow failures across many accounts from few source IPs - tuned on distinct-user count rather than raw failure volume.
wsmprovhost.exe spawning a child means a remote PowerShell session ran something here. Expected from jump hosts, suspicious from anywhere else.
Nothing matches those filters.