Browse Rules

Search and filter across all detection sources

788 rules

sagan informational other

[ONELOGIN] NO_ACTIVE_ACTIVE_DIRECTORY_CONNECTORS

[ONELOGIN] NO_ACTIVE_ACTIVE_DIRECTORY_CONNECTORS

sagan low other

Azure Eventhub Active Directory detected

Azure Eventhub Active Directory detected

sagan critical other

[NETWRIX] Active Directory User Added

[NETWRIX] Active Directory User Added

sagan informational other

[NETWRIX] Active Directory User Added

[NETWRIX] Active Directory User Added

sagan critical other

[NETWRIX] Active Directory Security Group Added

[NETWRIX] Active Directory Security Group Added

sagan informational other

[NETWRIX] Active Directory Security Group Added

[NETWRIX] Active Directory Security Group Added

sigma medium sigma

Potential Active Directory Reconnaissance/Enumeration Via LDAP

Detects potential Active Directory enumeration via LDAP

sagan critical other

[WINDOWS-SECURITY] Possible Active Directory User Enumeration (READ)

[WINDOWS-SECURITY] Possible Active Directory User Enumeration (READ)

sagan medium other

[EXTRAHOP] Web Directory Scan

[EXTRAHOP] Web Directory Scan

sagan unknown other

[WINDOWS-SECURITY] Possible Active Directory Computer Enumeration (READ)

[WINDOWS-SECURITY] Possible Active Directory Computer Enumeration (READ)

sagan unknown other

[WINDOWS-SECURITY] Possible Active Directory Groups Enumeration (READ)

[WINDOWS-SECURITY] Possible Active Directory Groups Enumeration (READ)

sagan unknown other

[WINDOWS-SECURITY] Possible Active Directory OU Enumeration (READ)

[WINDOWS-SECURITY] Possible Active Directory OU Enumeration (READ)

sentinel low kql

Alsid Active Directory attacks pathways

'Searches for triggered Indicators of Exposures related to Active Directory attacks pathways'

sentinel low kql

TIE Active Directory attacks pathways

'Searches for triggered Indicators of Exposures related to Active Directory attacks pathways.'

sagan medium other

[EXTRAHOP] CVE-2022-26923 Active Directory Domain Services Exploit Attempt

[EXTRAHOP] CVE-2022-26923 Active Directory Domain Services Exploit Attempt

sagan informational other

[NETWRIX] Active Directory Computer Modified Encryption Type: 0x17

[NETWRIX] Active Directory Computer Modified Encryption Type: 0x17

sagan informational other

[NETWRIX] Active Directory Computer Modified Encryption Type: 0x17

[NETWRIX] Active Directory Computer Modified Encryption Type: 0x17

sagan critical other

[NETWRIX] Active Directory Member Added to Security Group

[NETWRIX] Active Directory Member Added to Security Group

sentinel low kql

Tenable.ad Active Directory attacks pathways

'Searches for triggered Indicators of Exposures related to Active Directory attacks pathways.'

hayabusa low sigma

Active Directory Group Enumeration With Get-AdGroup

Detects usage of the "Get-AdGroup" cmdlet to enumerate Groups within Active Directory

sigma low sigma

Active Directory Group Enumeration With Get-AdGroup

Detects usage of the "Get-AdGroup" cmdlet to enumerate Groups within Active Directory

hayabusa low sigma

Active Directory Computers Enumeration With Get-AdComputer

Detects usage of the "Get-AdComputer" to enumerate Computers or properties within Active Directory.

hayabusa medium sigma

Active Directory Structure Export Via Csvde.EXE

Detects the execution of "csvde.exe" in order to export organizational Active Directory structure.

hayabusa medium sigma

Active Directory Structure Export Via Ldifde.EXE

Detects the execution of "ldifde.exe" in order to export organizational Active Directory structure.

sigma low sigma

Active Directory Computers Enumeration With Get-AdComputer

Detects usage of the "Get-AdComputer" to enumerate Computers or properties within Active Directory.