Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- - name: Scheduled Tasks
- query_dsl: '""'
- query_string: 'event_identifier:(4698 OR 4702)'
- supported_os: []
- - name: Service Installed
- query_dsl: '""'
- query_string: 'event_identifier:7045'
- supported_os: []
- - name: RDP
- query_dsl: '""'
- query_string: '((event_identifier:(4624)) AND ("LogonType\>10")) OR event_identifier:
- 22'
- supported_os: []
- - name: Account Creation
- query_dsl: '""'
- query_string: 'event_identifier:(4720 OR 4721)'
- supported_os: []
- - name: Event Log Cleared
- query_dsl: '""'
- query_string: 'event_identifier:(1102 OR 517)'
- supported_os: []
- - name: NTUSER.DAT Creation
- query_dsl: '""'
- query_string: 'filename:"NTUSER.DAT" AND timestamp_desc:creation'
- supported_os: []
- - name: Windows Defender
- query_dsl: '""'
- query_string: '"Microsoft-Windows-Windows Defender Strings" AND event_identifier:
- 1006'
- supported_os: []
- - name: Registry Scheduled Tasks
- query_dsl: '""'
- query_string: 'data_type:"task_scheduler:task_cache:entry"'
- supported_os: []
- - name: Network Shares/Shared Object Accessed
- query_dsl: '""'
- query_string: 'event_identifier:(5140 OR 5145)'
- supported_os: []
- - name: AutoRuns
- query_dsl: '""'
- query_string: "parser:\u201Dwindows_run\u201D"
- supported_os: []
- - name: FIle Downloads
- query_dsl: '""'
- query_string: "(file_extension:*) OR parser:\u201Dfirefox_downloads\u201D"
- supported_os: []
- - name: Autostart Services
- query_dsl: '""'
- query_string: "parser:\u201Dwindows_services\u201D"
- supported_os: []
- - name: Execution
- query_dsl: '""'
- query_string: 'parser:(prefetch OR userassist OR amcache OR appcompatcache OR srum)'
- supported_os: []
- - name: Domain
- query_dsl: '""'
- query_string: '"System\\ControlSet001\\Services\\TCPIP\\Parameters" AND domain'
- supported_os: []
Advertisement
Add Comment
Please, Sign In to add comment