Velociraptor Hunt VQL's

Sigma.Windows.Hayabusa.Rules
SELECT * , count()
FROM source(artifact="Sigma.Windows.Hayabusa.Rules")
GROUP BY TitleCustom.Windows.EventLogs.SysmonProcessCreationID
Custom.Windows.Sysinternals.Autoruns
Windows.System.Netstat
Windows.System.Pslist
Windows.Sys.AllUsers
Windows.Forensics.SAM
Windows.EventLogs.RDPAuth
Windows.EventLogs.ServiceCreationComspec
#search for created services - update the service regex to .
Exchange.Windows.EventLogs.LogonSessions
Windows.Forensics.Usn
Windows.System.Services
Windows.System.TaskScheduler/Analysis
Windows.Events.Trackaccount
Last updated
Was this helpful?