Initial Access
T1192 html_urls: HTML-document downloads a file
Execution
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1047 has_wmi: Executes one or several WMI requests
T1059.001 suspicious_process: Spawns a suspicious process
Discovery
T1016.001 system_network_configuration_discovery: System network configuration discovery detected
Command and Control
T1095 network_icmp: Creates ICMP traffic
Other
yara_rules: Static rules
suricata_alert: Malicious traffic detected