Execution
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 suspicious_batch: Suspicious batch
T1059.003 url_cmdline: Cmdline of process contains URL
Defense Evasion
T1218 suspicious_cmdline: Executes a suspicious command
Discovery
T1518 locates_browser: Attempts to identify where browsers are installed
Command and Control
T1102.003 cloud_github: Connects to cloud services of Github (potentially for malicious payload delivery)
Other
static_pe_anomaly: The PE file structure contains anomalies
creates_exe: Creates executable files in the file system
no_graphical_activity: No graphic activity
has_pdb: This executable file has a PDB path
dotnet_import_unmanaged_code: Dotnet program statically imports unmanaged functions/modules
pe_overlay: PE file contains overlay
suricata_alert: Malicious traffic detected
many_files_in_archive: The archive contains more than 5 files