Browse Rules

Search and filter across all detection sources

137 rules

wazuh low xml

Application cannot be installed

Application cannot be installed

wazuh informational xml

Application Installed $(win.eventdata.data)

Application Installed $(win.eventdata.data)

wazuh low xml

Windows: Application Installed.

Windows: Application Installed.

yara unknown yara

Installer [Android]

Applications with Installer as an application name

sagan high other

[WINDOWS-APPLOCKER] Package application installation allowed

[WINDOWS-APPLOCKER] Package application installation allowed

sagan high other

[WINDOWS-APPLOCKER] Package application installation allowed

[WINDOWS-APPLOCKER] Package application installation allowed

sagan high other

[WINDOWS-APPLOCKER] Package application installation audited

[WINDOWS-APPLOCKER] Package application installation audited

sagan high other

[WINDOWS-APPLOCKER] Package application installation audited

[WINDOWS-APPLOCKER] Package application installation audited

sagan high other

[WINDOWS-APPLOCKER] Package application installation disabled

[WINDOWS-APPLOCKER] Package application installation disabled

sagan high other

[WINDOWS-APPLOCKER] Package application installation disabled

[WINDOWS-APPLOCKER] Package application installation disabled

chronicle low yara-l

GitHub Application Installed

Detects when a GitHub application is installed within an organization. An untrusted application can be installed and granted permissions to access data within a GitHub organization.

panther low python

Github Organization App Integration Installed

An application integration was installed to your organization's Github account by someone in your organization.

hayabusa medium sigma

Suspicious Application Installed

Detects suspicious application installed by looking at the added shortcut to the app resolver cache

sigma medium sigma

Suspicious Application Installed

Detects suspicious application installed by looking at the added shortcut to the app resolver cache

sagan unknown other

[WINDOWS-APPLICATION] MsiInstaller Installer Exited for SentinelInstaller (3/5)

[WINDOWS-APPLICATION] MsiInstaller Installer Exited for SentinelInstaller (3/5)

wazuh low xml

The application tried to install a more recent version of the protected Windows file

The application tried to install a more recent version of the protected Windows file

hayabusa medium sigma

Rundll32 InstallScreenSaver Execution

An attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver

hayabusa medium sigma

Suspicious Execution of InstallUtil Without Log

Uses the .NET InstallUtil.exe application in order to execute image without log

sigma medium sigma

Rundll32 InstallScreenSaver Execution

An attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver

sigma medium sigma

Suspicious Execution of InstallUtil Without Log

Uses the .NET InstallUtil.exe application in order to execute image without log

hayabusa medium sigma

Rundll32 InstallScreenSaver Execution

An attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver

hayabusa medium sigma

Suspicious Execution of InstallUtil Without Log

Uses the .NET InstallUtil.exe application in order to execute image without log

mdecrevoisier medium sigma

PSexec application execution

Detects scenarios where an attacker installs and executes PSexec.

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): OS X Application $(osquery.columns.name) version $(osquery.columns.bundle_version) is installed

osquery: $(osquery.pack) $(osquery.subquery): OS X Application $(osquery.columns.name) version $(osquery.columns.bundle_version) is installed

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): OS X Application $(osquery.columns.name) version $(osquery.columns.bundle_version) is installed

osquery: $(osquery.pack) $(osquery.subquery): OS X Application $(osquery.columns.name) version $(osquery.columns.bundle_version) is installed