Skip to main content

Monitor

IDDescriptionSignificance / Prevalence
BH12101Accesses a list of logged on users.uncommon
BH12119Accesses the Event Log.uncommon
BH12120Accesses webcam/microphone peripherals.uncommon
BH12148Captures video streams from the web camera.uncommon
BH12191Contains one or more tracking pixels. uncommon
BH12213Creates Windows Update log files.uncommon anomalous
BH12252Disables monitoring of system-wide notifications for application related events.uncommon anomalous
BH12355Extracts the content of a Personal Information Exchange (PFX) file into a structure without importing it to certificate store.uncommon
BH12394Issues system-wide notifications for events performed by the application.uncommon
BH12428Monitors browser processes.uncommon anomalous
BH12431Monitors installation, enabling or disabling of an app or extension.uncommon
BH12432Monitors keyboard strokes.uncommon
BH12433Monitors mouse movement.uncommon anomalous
BH12436Monitors performance counters.uncommon
BH12437Monitors system I/O devices.uncommon
BH12438Monitors system-wide notifications for application related events.uncommon
BH12439Monitors user input.uncommon anomalous
BH12445Might enumerate HID devices.uncommon anomalous
BH12450Might monitor USB devices.anomalous
BH12451Might monitor media devices.uncommon
BH12473Receives messages from a host environment.anomalous
BH12474Records audio streams in WAV format from the microphone or other input devices.uncommon
BH12475Records audio.anomalous
BH12529Returns a list of all software packages that were installed with PackageManagement.uncommon
BH12534Returns all registered certificate notification tasks.uncommon
BH12558Sends messages to a host environment.anomalous
BH12590Takes screenshots.uncommon
BH12638Tampers with Event Trace Sessions and Performance logs.anomalous uncommon
BH12670Tampers with keyboard/mouse status.uncommon
BH12707Tampers with PowerShell logging and diagnostics.uncommon
BH12728Tampers with Software Inventory Logging.uncommon
BH12748Tampers with the Event Tracing for Windows.uncommon
BH12789Tampers with, generate or subscribe to events.uncommon
BH12849Possibly does API hooking.uncommon
BH12921Monitors messages exchanged via sd-bus.anomalous
BH12922Captures messages exchanged via sd-bus.anomalous
BH12956Captures an X11 display.uncommon anomalous
BH13035Records the system audio or microphone.uncommon anomalous
BH13110Accesses a /dev/video pseudo-file.uncommon anomalous
BH13355Monitors mouse activity.
BH13377Emits keyboard strokes.
BH13403Logs timestamped data to file.
BH13471Queries if a specified process exists.
BH13487Reads information about one or more running processes.
BH13542Monitors battery status.
BH13557Checks if the browser is Java-enabled.
BH13558Checks if the browser is working online.
BH13560Might check the value of the user's Do-Not-Track preference.
BH13562Checks whether the browser is running in standalone mode.
BH13563Gets the vendor name of the current browser.
BH13568Gets the dimensions of the browser window.
BH16356Might check if the cookies are enabled.
BH19101Detects/enumerates running processes on local or remote computer.uncommon
BH19102Detects/enumerates running processes. uncommon
BH19103Enumerates access control lists for the local queue manager.uncommon anomalous
BH19104Enumerates active and past malware threats that Windows Defender detected.uncommon
BH19108Enumerates all currently loaded DLLs and APIs that are available to macros.anomalous
BH19118Enumerates background task information.uncommon
BH19124Enumerates browser processes.anomalous
BH19142Enumerates current light level.uncommon anomalous
BH19165Enumerates event subscribers in the current session.uncommon
BH19169Enumerates events in the event queue.uncommon
BH19195Enumerates known threats from the definitions catalog.uncommon
BH19205Enumerates message queues.uncommon anomalous
BH19208Enumerates name or version of the current browser.
BH19225Enumerates open pages.uncommon
BH19228Enumerates or changes current locale.uncommon
BH19230Enumerates outgoing message queues.uncommon anomalous
BH19232Enumerates peripherals. uncommon
BH19243Enumerates processes on a Remote Desktop Session Host server.uncommon important
BH19255Enumerates results of BPA scans.uncommon
BH19309Enumerates Updating Run reports for all known Updating Runs, or all Updating Runs that match the specified dates or other specified parameters.uncommon anomalous
BH19311Enumerates User Access Logging (UAL) records for a DNS server.uncommon anomalous
BH19312Enumerates User Access Logging (UAL) records for client requests per user for each day.uncommon anomalous
BH19313Enumerates User Access Logging (UAL) records of client request per device.uncommon
BH19314Enumerates User Access Logging (UAL) records of client requests for each day.uncommon
BH19315Enumerates User Access Logging (UAL) records of client requests per device for each day.uncommon anomalous
BH19342Gets a queue manager.uncommon anomalous
BH19351Gets connection pooling Performance Monitor counters.uncommon
BH19368Gets notified when removable storage device is attached or detached.uncommon anomalous
BH19374Gets port information for a network switch.uncommon
BH19376Gets queue access control lists.uncommon anomalous
BH19380Gets System Event Log entries from a PCSV device.uncommon
BH19391Gets the details of events generated in a Server Manager event log.uncommon anomalous
BH19394Gets the history of threats detected on the computer.uncommon
BH19399Gets the job triggers of scheduled jobs.uncommon
BH19400Gets the key bindings for the PSReadLine module.uncommon
BH19408Gets the provider address for a server.uncommon anomalous
BH19414Gets the state of the performance data collector set.uncommon anomalous
BH19416Gets the status of Win32 services on a managed node.uncommon anomalous
BH19440Retrieves per-volume performance metrics on a volume that is monitored by Storage QoS.uncommon anomalous
BH19441Retrieves performance metrics on an I/O flow that is monitored by Storage QoS.uncommon anomalous
BH19454Retrieves the properties of a Windows event log.uncommon
BH19509Enumerates the total amount of system memory. uncommon
BH19514Enumerates file descriptors belonging to the current process.uncommon
BH19515Enumerates file descriptors of a process.uncommon
BH19516Enumerates the computer's active TCP sockets.uncommon
BH19517Enumerates the computer's active UDP sockets.uncommon
BH19545Detects/enumerates process modules.
BH19558Enumerates the number of logical processor cores.
BH19560Enumerates MIME types supported by the browser.
BH19561Enumerates the current platform of the browser.
BH19562Enumerates plugins installed in the browser.
BH19563Enumerates product information.
BH19564Might enumerate user agent of the current browser.
BH19568Enumerates display information.
BH19569Might enumerate information about screen.
BH20196Uses PowerSploit/Empire command to enumerate running processes on local or remote computer.anomalous malicious uncommon
BH20224Uses PowerSploit/Empire command to find logon events on the current or a remote domain for the specified users.anomalous malicious uncommon
BH20229Uses PowerSploit/Empire command to get useful information from a computer, like a credential logons, AppLocker events, PowerShell logs, etc.anomalous important uncommon
BH20233Uses PowerSploit/Empire command to list available logon tokens.anomalous malicious uncommon
BH20237Uses PowerSploit/Empire command to log keystrokes from USB keyboards using Event Tracing for Windows.anomalous malicious
BH20238Uses PowerSploit/Empire command to log pressed key, the time and the active window when it was pressed.anomalous malicious uncommon
BH20251Uses PowerSploit/Empire command to record audio from system microphone and save it to disk.anomalous malicious uncommon
BH20267Uses PowerSploit/Empire command to return a list of processes and their owners on the local or a remote machine.anomalous important uncommon
BH20310Uses PowerSploit/Empire command to search for processes on the domain using WMI.anomalous malicious uncommon
BH20314Uses PowerSploit/Empire command to take a single screenshot.anomalous malicious uncommon
BH20315Uses PowerSploit/Empire command to take screenshots at a regular interval and save them to a folder.anomalous malicious uncommon