Analyst ·
Use Cases
Current SIEM detection scenarios mapped from logs, alerts, threats, endpoints and network activity.
30 SIEM scenarios continuously evaluated against live logs, alerts and threats.
#1File Download Monitoring
Endpoint & Server · MITRE T1105
Tracks files downloaded via browsers, curl, wget, BITS or PowerShell.
#2Privilege Escalation Attempt
Endpoint & Server · MITRE T1068
Unexpected sudo, UAC bypass, token theft, or elevated process creation.
Pre-req: Enable Windows Audit Policy
#3Brute Force Detection
Endpoint & Server · MITRE T1110
Repeated failed logons against SSH, RDP, or Windows accounts.
#4Suspicious Process Execution
Server · MITRE T1059
Processes flagged by EDR/Defender or known LOLBin abuse.
Pre-req: EDR/Defender integration required.
#5Failed Login Threshold
Endpoint & Server · MITRE T1110.001
Account exceeded permitted number of failed login attempts.
#6Malware Detection
Endpoint & Server · MITRE T1204
Known malware families, ransomware, or trojans detected on host.
Pre-req: EDR/Defender required for additional malware logs
#7File Integrity Monitoring (FIM)
Server · MITRE T1565.001
Changes to monitored system or application files.
Pre-req: Client to provide FIM target servers
#8Suspicious USB Activity
Endpoint & Server · MITRE T1052.001
Removable media insertion or data copy events.
Pre-req: Enable Windows Audit Policy on endpoints
#9Suspicious Archive Extraction
Endpoint & Server · MITRE T1140
Extraction of zip/rar/7z from temp or download folders.
Pre-req: Enable Sysmon
#10Anomalous File Deletion Patterns
Server · MITRE T1485
Large volume or rapid file deletion suggestive of wiper/ransomware.
#11Security Configuration Assessment (SCA)
Server
Host fails CIS / vendor hardening checks.
#12Suspicious Command Execution
Endpoint & Server · MITRE T1059
Commands typical of attacker tradecraft (whoami, net user, etc).
#13Excessive Admin Privilege
Server · MITRE T1078.003
User added to Administrators / Domain Admins or sudo group.
#14Suspicious VPN Connection
Endpoint
VPN client install or connection to non-corporate VPN.
Pre-req: Enable Wazuh agent configuration changes
#15User Account Create/Delete
Endpoint & Server · MITRE T1136
Local or domain account created, modified, or removed.
Pre-req: Enable Sysmon
#16Active Directory Enumeration
Server · MITRE T1087.002
BloodHound, SharpHound, LDAP queries enumerating AD objects.
#17Firewall Policy Change Detection
Endpoint & Server · MITRE T1562.004
Local or network firewall rules added, modified, or disabled.
#18Unusual Binary Execution (Temp)
Endpoint & Server · MITRE T1036
Executable launched from %TEMP%, /tmp, or download folders.
Pre-req: Integrate EDR/Defender
#19Remote Management Tool Usage
Endpoint & Server · MITRE T1219
AnyDesk, TeamViewer, ScreenConnect, RustDesk or similar installed/used.
#20Credential Harvesting Attempt
Endpoint & Server · MITRE T1003
Access to LSASS, browser cred stores, or Mimikatz indicators.
Pre-req: Enable Sysmon and integrate EDR/Defender
#21Application Installation
Endpoint & Server
Software installed via MSI, EXE, package manager.
#22New Service Installation
Endpoint & Server · MITRE T1543.003
New Windows service or Linux systemd unit created.
#23Suspicious PowerShell Execution
Endpoint & Server · MITRE T1059.001
Encoded, hidden, or download-cradle PowerShell commands.
#24Port Scanning Activity
Server · MITRE T1046
Host attempting to scan ports across the network.
Pre-req: Enable Wazuh agent configuration changes
#25Credential Dumping Detection
Endpoint & Server · MITRE T1003.002
ntds.dit, SAM, or shadow file access indicative of dumping.
#26Unauthorized Network Share Access
Endpoint & Server · MITRE T1021.002
Access to administrative or unexpected SMB shares.
Pre-req: Enable Sysmon and Audit Policy
#27System Crash Dump Access
Endpoint & Server
Read or copy of memory.dmp / crash dump files.
#28Unusual Process Parent-Child Relationship
Server · MITRE T1055
e.g. winword.exe spawning powershell, sqlservr spawning cmd.
Pre-req: Integrate EDR/Defender
#29Opened Ports Monitoring
Endpoint & Server
New listening port appeared on host.
#30DNS Timeout Detection
Server
Repeated DNS resolution failures or timeouts.