Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Detect HTML Help Renamed
id: 62fed254-513b-460e-953d-79771493a9f3
version: 14
version: 15
creation_date: '2021-02-11'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic detects instances where hh.exe (HTML Help) has been renamed and is executing a Compiled HTML Help (CHM) file. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names. This activity is significant because attackers can use renamed hh.exe to execute malicious scripts embedded in CHM files, potentially leading to code execution. If confirmed malicious, this technique could allow attackers to run arbitrary scripts, escalate privileges, or persist within the environment, posing a significant security risk.
data_source:
Expand Down Expand Up @@ -46,10 +46,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.001/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed LOLBAS Binary was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Detect mshta renamed
id: 8f45fcf0-5b68-11eb-ae93-0242ac130002
version: 13
version: 14
creation_date: '2021-01-15'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic identifies instances where mshta.exe has been renamed and executed. It leverages Endpoint Detection and Response (EDR) data, specifically focusing on the original file name field to detect discrepancies. This activity is significant because renaming mshta.exe is a common tactic used by attackers to evade detection and execute malicious scripts. If confirmed malicious, this could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network.
data_source:
Expand Down Expand Up @@ -45,10 +45,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed LOLBAS Binary was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Detect Renamed 7-Zip
id: 4057291a-b8cf-11eb-95fe-acde48001122
version: 12
version: 13
creation_date: '2021-06-03'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic detects the usage of a renamed 7-Zip executable using Sysmon data. It leverages the OriginalFileName field to identify instances where the 7-Zip process has been renamed. This activity is significant as attackers often rename legitimate tools to evade detection while staging or exfiltrating data. If confirmed malicious, this behavior could indicate data exfiltration attempts or other unauthorized data manipulation, potentially leading to significant data breaches or loss of sensitive information. Analysts should validate the legitimacy of the 7-Zip executable and investigate parallel processes for further suspicious activities.
data_source:
Expand Down Expand Up @@ -45,10 +45,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed Popular 3rd Party Software was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Detect Renamed PSExec
id: 683e6196-b8e8-11eb-9a79-acde48001122
version: 17
version: 18
creation_date: '2021-06-03'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk, Alex Oberkircher, Github Community
status: production
status: deprecated
type: Hunting
description: The following analytic identifies instances where `PsExec.exe` has been renamed and executed on an endpoint. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names. This activity is significant because renaming `PsExec.exe` is a common tactic to evade detection. If confirmed malicious, this could allow an attacker to execute commands remotely, potentially leading to unauthorized access, lateral movement, or further compromise of the network.
data_source:
Expand Down Expand Up @@ -60,10 +60,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569.002/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed Command Interpreter was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Detect Renamed RClone
id: 6dca1124-b3ec-11eb-9328-acde48001122
version: 12
version: 13
creation_date: '2021-05-13'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic detects the execution of a renamed `rclone.exe` process, which is commonly used for data exfiltration to remote destinations. This detection leverages Endpoint Detection and Response (EDR) telemetry, focusing on process names and original file names that do not match. This activity is significant because ransomware groups often use RClone to exfiltrate sensitive data. If confirmed malicious, this behavior could indicate an ongoing data exfiltration attempt, potentially leading to significant data loss and further compromise of the affected systems.
data_source:
Expand Down Expand Up @@ -49,10 +49,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1020/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed Popular 3rd Party Software was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Detect Renamed WinRAR
id: 1b7bfb2c-b8e6-11eb-99ac-acde48001122
version: 16
version: 17
creation_date: '2021-06-03'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic identifies instances where `WinRAR.exe` has been renamed and executed. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names within the Endpoint data model. This activity is significant because renaming executables is a common tactic used by attackers to evade detection. If confirmed malicious, this could indicate an attempt to bypass security controls, potentially leading to unauthorized data extraction or further system compromise.
data_source:
Expand Down Expand Up @@ -45,10 +45,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1560.001/archive_utility/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all popular 3rd party software binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed Popular 3rd Party Software was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Suspicious microsoft workflow compiler rename
id: f0db4464-55d9-11eb-ae93-0242ac130002
version: 14
version: 15
creation_date: '2021-01-19'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic detects the renaming of microsoft.workflow.compiler.exe, a rarely used executable typically located in C:\Windows\Microsoft.NET\Framework64\v4.0.30319. This detection leverages Endpoint Detection and Response (EDR) data, focusing on process names and original file names. This activity is significant because renaming this executable can indicate an attempt to evade security controls. If confirmed malicious, an attacker could use this renamed executable to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment.
data_source:
Expand Down Expand Up @@ -49,10 +49,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127/atomic_red_team/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed LOLBAS Binary was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Suspicious MSBuild Rename
id: 4006adac-5937-11eb-ae93-0242ac130002
version: 14
version: 15
creation_date: '2021-01-15'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Michael Haag, Splunk
status: production
status: deprecated
type: Hunting
description: The following analytic detects the execution of renamed instances of msbuild.exe. It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and original file names within the Endpoint data model. This activity is significant because msbuild.exe is a legitimate tool often abused by attackers to execute malicious code while evading detection. If confirmed malicious, this behavior could allow an attacker to execute arbitrary code, potentially leading to system compromise, data exfiltration, or further lateral movement within the network.
data_source:
Expand Down Expand Up @@ -51,10 +51,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed LOLBAS Binary was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Windows LOLBAS Executed As Renamed File
id: fd496996-7d9e-4894-8d40-bb85b6192dc6
version: 10
version: 11
creation_date: '2024-05-03'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Steven Dick
status: production
status: deprecated
type: TTP
description: The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
data_source:
Expand Down Expand Up @@ -56,10 +56,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036/cmd_lolbas_usage/cmd_lolbas_usage.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to renaming of its newer version.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed LOLBAS Binary was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Windows Regsvr32 Renamed Binary
id: 7349a9e9-3cf6-4171-bb0c-75607a8dcd1a
version: 13
version: 14
creation_date: '2022-10-27'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Teoderick Contreras, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic identifies instances where the regsvr32.exe binary has been renamed and executed. This detection leverages Endpoint Detection and Response (EDR) data, specifically focusing on the original filename metadata. Renaming regsvr32.exe is significant as it can be an evasion technique used by attackers to bypass security controls. If confirmed malicious, this activity could allow an attacker to execute arbitrary DLLs, potentially leading to code execution, privilege escalation, or persistence within the environment.
data_source:
Expand Down Expand Up @@ -58,10 +58,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/qakbot/qbot_3/sysmon.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all LOLBAS binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed LOLBAS Binary was Executed
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
name: Windows Renamed Powershell Execution
id: c08014de-cc5a-42de-9775-76ecd5b37bbd
version: 8
version: 9
creation_date: '2022-10-27'
modification_date: '2026-05-13'
modification_date: '2026-09-23'
author: Teoderick Contreras, Nasreddine Bencherchali, Splunk
status: production
status: deprecated
type: TTP
description: The following analytic identifies instances where the PowerShell executable has been renamed and executed under an alternate filename. This behavior is commonly associated with attempts to evade security controls or bypass logging mechanisms that monitor standard PowerShell usage. While rare in legitimate environments, renamed PowerShell binaries are frequently observed in malicious campaigns leveraging Living-off-the-Land Binaries (LOLBins) and fileless malware techniques. This detection flags executions of PowerShell where the process name does not match the default powershell.exe or pwsh.exe, especially when invoked from unusual paths or accompanied by suspicious command-line arguments.
data_source:
Expand Down Expand Up @@ -42,10 +42,8 @@ product:
- Splunk Cloud
category: endpoint
security_domain: endpoint
tests:
- name: True Positive Test
attack_data:
- data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1036.003/renamed_powershell/renamed_powershell.log
source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
sourcetype: XmlWinEventLog
test_type: unit
deprecation_info:
reason: Detection deprecated due to having a duplicated content with another detection. Renaming of all command interpreter binaries are covered in a single detection instead of having their separate searches, for performance related reasons.
removed_in_version: 6.8.0
replacement_content:
- Windows Renamed Command Interpreter was Executed
Loading
Loading