| ASL AWS ECR Container Upload Outside Business Hours | Anomaly | NULL | ASL AWS CloudTrail | T1204.003 |
| ASL AWS ECR Container Upload Unknown User | Anomaly | NULL | ASL AWS CloudTrail | T1204.003 |
| AWS ECR Container Scanning Findings High | TTP | NULL | AWS CloudTrail DescribeImageScanFindings | T1204.003 |
| AWS ECR Container Scanning Findings Low Informational Unknown | Anomaly | NULL | AWS CloudTrail DescribeImageScanFindings | T1204.003 |
| AWS ECR Container Scanning Findings Medium | Anomaly | NULL | AWS CloudTrail DescribeImageScanFindings | T1204.003 |
| AWS ECR Container Upload Outside Business Hours | Anomaly | NULL | AWS CloudTrail PutImage | T1204.003 |
| AWS ECR Container Upload Unknown User | Anomaly | NULL | AWS CloudTrail PutImage | T1204.003 |
| AWS Lambda UpdateFunctionCode | Hunting | NULL | AWS CloudTrail | T1204 |
| Batch File Write to System32 | Anomaly | NULL | Sysmon EventID 11 | T1204.002 |
| Cisco Isovalent - Non Allowlisted Image Use | Anomaly | NULL | Cisco Isovalent Process Exec | T1204.003 |
| Cisco Isovalent - Pods Running Offensive Tools | Anomaly | NULL | Cisco Isovalent Process Exec | T1204.003 |
| Cisco NVM - Susp Script From Archive Triggering Network Activity | Anomaly | NULL | Cisco Network Visibility Module Flow Data | T1204.002 |
| Cisco Secure Firewall - Lumma Stealer Activity | TTP | NULL | Cisco Secure Firewall Threat Defense Intrusion Event | T1204 |
| Clop Common Exec Parameter | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204 |
| Conti Common Exec parameter | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204 |
| Correlation by Repository and Risk | Correlation | NULL | | T1204.003 |
| Correlation by User and Risk | Correlation | NULL | | T1204.003 |
| Detect Rare Executables | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204 |
| Drop IcedID License dat | Hunting | NULL | Sysmon EventID 11 | T1204.002 |
| Kubernetes Anomalous Inbound Network Activity from Process | Anomaly | NULL | | T1204 |
| Kubernetes Anomalous Inbound Outbound Network IO | Anomaly | NULL | | T1204 |
| Kubernetes Anomalous Inbound to Outbound Network IO Ratio | Anomaly | NULL | | T1204 |
| Kubernetes Anomalous Outbound Network Activity from Process | Anomaly | NULL | | T1204 |
| Kubernetes Anomalous Traffic on Network Edge | Anomaly | NULL | | T1204 |
| Kubernetes Create or Update Privileged Pod | Anomaly | NULL | Kubernetes Audit | T1204 |
| Kubernetes DaemonSet Deployed | Anomaly | NULL | Kubernetes Audit | T1204 |
| Kubernetes Falco Shell Spawned | Anomaly | NULL | Kubernetes Falco | T1204 |
| Kubernetes newly seen TCP edge | Anomaly | NULL | | T1204 |
| Kubernetes newly seen UDP edge | Anomaly | NULL | | T1204 |
| Kubernetes Node Port Creation | Anomaly | NULL | Kubernetes Audit | T1204 |
| Kubernetes Pod Created in Default Namespace | Anomaly | NULL | Kubernetes Audit | T1204 |
| Kubernetes Pod With Host Network Attachment | Anomaly | NULL | Kubernetes Audit | T1204 |
| Kubernetes Previously Unseen Container Image Name | Anomaly | NULL | | T1204 |
| Kubernetes Previously Unseen Process | Anomaly | NULL | | T1204 |
| Kubernetes Process Running From New Path | Anomaly | NULL | | T1204 |
| Kubernetes Process with Anomalous Resource Utilisation | Anomaly | NULL | | T1204 |
| Kubernetes Process with Resource Ratio Anomalies | Anomaly | NULL | | T1204 |
| Kubernetes Shell Running on Worker Node | Anomaly | NULL | | T1204 |
| Kubernetes Shell Running on Worker Node with CPU Activity | Anomaly | NULL | | T1204 |
| Kubernetes Unauthorized Access | Anomaly | NULL | Kubernetes Audit | T1204 |
| Linux Ghostscript Exploitation | TTP | NULL | Sysmon for Linux EventID 1 | T1204.002 |
| O365 SharePoint Malware Detection | TTP | NULL | Office 365 Universal Audit Log | T1204.002 |
| O365 Threat Intelligence Suspicious File Detected | TTP | NULL | Office 365 Universal Audit Log | T1204.002 |
| Revil Common Exec Parameter | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204 |
| Risk Rule for Dev Sec Ops by Repository | Correlation | NULL | | T1204.003 |
| Single Letter Process On Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204.002 |
| Suspicious Process Executed From Container File | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204.002 |
| Uncommon Processes On Endpoint | Hunting | NULL | Sysmon EventID 1 | T1204.002 |
| Windows Advanced Installer MSIX with AI_STUBS Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204.002 |
| Windows AppX Deployment Full Trust Package Installation | Hunting | NULL | Windows Event Log AppXDeployment-Server 400 | T1204.002 |
| Windows AppX Deployment Package Installation Success | Anomaly | NULL | Windows Event Log AppXDeployment-Server 854 | T1204.002 |
| Windows AppX Deployment Unsigned Package Installation | TTP | NULL | Windows Event Log AppXDeployment-Server 855 | T1204.002 |
| Windows Binary Execution from an Archive | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 | T1204.002 |
| Windows Default Cobalt Strike PowerShell Beacon | TTP | NULL | Powershell Script Block Logging 4104 | T1204.002 |
| Windows Developer-Signed MSIX Package Installation | Anomaly | NULL | Windows Event Log AppXDeployment-Server 855 | T1204.002 |
| Windows EFI Volume Mount Attempt Via Mountvol | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204.002 |
| Windows Explorer LNK Exploit Process Launch With Padding | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1204.002 |
| Windows Explorer.exe Spawning PowerShell or Cmd | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1204.002 |
| Windows ISO LNK File Creation | Hunting | NULL | Sysmon EventID 11 | T1204.001 |
| Windows MSIX Package Interaction | Hunting | NULL | Windows Event Log AppXPackaging 171 | T1204.002 |
| Windows Mustang Panda USB Tool Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204.002 |
| Windows NorthStar C2 Agent Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204.002 |
| Windows PowerShell FakeCAPTCHA Clipboard Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2, Cisco Network Visibility Module Flow Data | T1204.001 |
| Windows PowerShell Script From WindowsApps Directory | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1204.002 |
| Windows Suspect Process With Authentication Traffic | Anomaly | NULL | Sysmon EventID 3 | T1204.002 |
| Windows Suspicious QEMU Execution | TTP | NULL | Sysmon EventID 1 | T1204.002 |
| Windows Universal Data Link File Creation | Anomaly | NULL | Sysmon EventID 11 | T1204.002 |
| Windows User Execution Malicious URL Shortcut File | Anomaly | NULL | Sysmon EventID 11 | T1204.002 |