Other
suricata_alert: Malicious traffic detected
yara_rules: Static rules
network_bind: Starts servers listening at None
creates_exe: Creates executable files in the file system
suspicious_process_network: Unusual process network activity detected
create_rpc_bindings: Creates RPC connection
creates_suspended_process: Creates suspended process
msi_has_custom_action: MSI file contains custom action
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
valid_authenticode: The digital signature has been verified