| DET0186 |
Automated File and API Collection Detection Across Platforms |
T1119 |
| DET0124 |
Behavior-chain detection for T1132.001 Data Encoding: Standard Encoding (Base64/Hex/MIME) across Windows, Linux, macOS, ESXi |
T1132.001 |
| DET0326 |
Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi |
T1132.002 |
| DET0556 |
Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows) |
T1127.001 |
| DET0010 |
Behavioral Detection of Event Triggered Execution Across Platforms |
T1546 |
| DET0357 |
Behavioral Detection of Internet Connection Discovery |
T1016.001 |
| DET0521 |
Behavioral Detection of Spoofed GUI Credential Prompts |
T1056.002 |
| DET0384 |
Behavioral Detection of Unix Shell Execution |
T1059.004 |
| DET0076 |
Behavioral Detection of Visual Basic Execution (VBS/VBA/VBScript) |
T1059.005 |
| DET0202 |
Behavioral Detection of Windows Command Shell Execution |
T1059.003 |
| DET0112 |
Boot or Logon Initialization Scripts Detection Strategy |
T1037 |
| DET0063 |
Cross-Platform Behavioral Detection of Python Execution |
T1059.006 |
| DET0264 |
Cross-Platform Detection of JavaScript Execution Abuse |
T1059.007 |
| DET0493 |
Detect Abuse of Inter-Process Communication (T1559) |
T1559 |
| DET0381 |
Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL |
T1552.006 |
| DET0072 |
Detect Logon Script Modifications and Execution |
T1037.001 |
| DET0190 |
Detect MFA Modification or Disabling Across Platforms |
T1556.006 |
| DET0367 |
Detect Network Logon Script Abuse via Multi-Event Correlation on Windows |
T1037.003 |
| DET0734 |
Detection of Automated Collection |
T0802 |
| DET0749 |
Detection of Data from Local System |
T0893 |
| DET0770 |
Detection of Network Connection Enumeration |
T0840 |
| DET0735 |
Detection of Scripting |
T0853 |
| DET0793 |
Detection of System Binary Proxy Execution |
T0894 |
| DET0237 |
Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts |
T1037.004 |
| DET0545 |
Detection Strategy for Cloud Administration Command |
T1651 |
| DET0568 |
Detection Strategy for Input Injection |
T1674 |
| DET0101 |
Detection Strategy for Lua Scripting Abuse |
T1059.011 |
| DET0300 |
Detection Strategy for Reflective Code Loading |
T1620 |
| DET0181 |
Detection Strategy for SQL Stored Procedures Abuse via T1505.001 |
T1505.001 |
| DET0121 |
Detection Strategy for T1547.015 – Login Items on macOS |
T1547.015 |
| DET0587 |
Enumeration of User or Account Information Across Platforms |
T1087 |
| DET0082 |
Internal Website and System Content Defacement via UI or Messaging Modifications |
T1491.001 |
| DET0372 |
Multi-Platform Detection Strategy for T1678 - Delay Execution |
T1678 |