| splunk |
Windows Service Creation on Remote Endpoint |
production |
2026-05-13 |
| splunk |
Windows Service Created with Suspicious Service Path |
production |
2026-05-13 |
| splunk |
Windows Service Create with Tscon |
production |
2026-05-13 |
| splunk |
Windows Service Create SliverC2 |
production |
2026-05-13 |
| splunk |
Windows Service Create RemComSvc |
production |
2026-05-13 |
| splunk |
Windows Service Create Kernel Mode Driver |
production |
2026-05-13 |
| splunk |
Windows Server Software Component GACUtil Install to GAC |
production |
2026-05-13 |
| splunk |
Windows Sensitive Registry Hive Dump Via CommandLine |
production |
2026-05-13 |
| splunk |
Windows Sensitive Group Discovery With Net |
production |
2026-05-13 |
| splunk |
Windows Security Support Provider Reg Query |
production |
2026-05-13 |
| splunk |
Windows Security And Backup Services Stop |
production |
2026-05-13 |
| splunk |
Windows Security Account Manager Stopped |
production |
2026-05-13 |
| splunk |
Windows Screen Capture Via Powershell |
production |
2026-05-13 |
| splunk |
Windows ScManager Security Descriptor Tampering Via Sc.EXE |
production |
2026-05-13 |
| splunk |
Windows Schtasks Create Run As System |
production |
2026-05-13 |
| splunk |
Windows Scheduled Tasks for CompMgmtLauncher or Eventvwr |
production |
2026-05-13 |
| splunk |
Windows RDP Bitmap Cache File Creation |
production |
2026-05-13 |
| splunk |
Windows Raw Access To Master Boot Record Drive |
production |
2026-05-13 |
| splunk |
Windows Raw Access To Disk Volume Partition |
production |
2026-05-13 |
| splunk |
Windows Rasautou DLL Execution |
production |
2026-05-13 |
| splunk |
Windows Rapid Authentication On Multiple Hosts |
production |
2026-05-13 |
| splunk |
Windows Raccine Scheduled Task Deletion |
production |
2026-05-13 |
| splunk |
Windows Query Registry Browser List Application |
production |
2026-05-13 |
| splunk |
Windows PuTTY Suite Utility Execution |
production |
2026-05-13 |
| splunk |
Windows PsTools Recon Usage |
production |
2026-05-13 |
| splunk |
Windows Proxy Via Registry |
production |
2026-05-13 |
| splunk |
Windows Proxy Via Netsh |
production |
2026-05-13 |
| splunk |
Windows Protocol Tunneling with Plink |
production |
2026-05-13 |
| splunk |
Windows Processes Killed By Industroyer2 Malware |
production |
2026-05-13 |
| splunk |
Windows Process Writing File to World Writable Path |
production |
2026-05-13 |
| splunk |
Windows Process With NetExec Command Line Parameters |
production |
2026-05-13 |
| splunk |
Windows Process Injection In Non-Service SearchIndexer |
production |
2026-05-13 |
| splunk |
Windows Process Execution From RDP Share |
production |
2026-05-13 |
| splunk |
Windows Process Commandline Discovery |
production |
2026-05-13 |
| splunk |
Windows Process Accessing Windows Recall Directory |
production |
2026-05-13 |
| splunk |
Windows Privileged Group Modification |
production |
2026-05-13 |
| splunk |
Windows Privilege Escalation User Process Spawn System Process |
production |
2026-05-13 |
| splunk |
Windows Privilege Escalation System Process Without System Parent |
production |
2026-05-13 |
| splunk |
Windows Privilege Escalation Suspicious Process Elevation |
production |
2026-05-13 |
| splunk |
Windows Privilege Escalation Attempt Via MSI Rollback |
production |
2026-05-13 |