Velociraptor Hunt VQL's

Sigma.Windows.Hayabusa.Rules

SELECT * , count()
FROM source(artifact="Sigma.Windows.Hayabusa.Rules")
GROUP BY Title

Custom.Windows.EventLogs.SysmonProcessCreationID

Custom.Windows.Sysinternals.Autoruns

Windows.System.Netstat

Windows.System.Pslist

Windows.Sys.AllUsers

Windows.Forensics.SAM

Windows.EventLogs.RDPAuth

Windows.EventLogs.ServiceCreationComspec

#search for created services - update the service regex to .

Exchange.Windows.EventLogs.LogonSessions

Windows.Forensics.Usn

Windows.System.Services

Windows.System.TaskScheduler/Analysis

Windows.Events.Trackaccount

Last updated

Was this helpful?