Search and filter across all detection sources
137 rules
Application cannot be installed
Application Installed $(win.eventdata.data)
Windows: Application Installed.
Installer [Android]
Applications with Installer as an application name
[WINDOWS-APPLOCKER] Package application installation allowed
[WINDOWS-APPLOCKER] Package application installation audited
[WINDOWS-APPLOCKER] Package application installation disabled
GitHub Application Installed
Detects when a GitHub application is installed within an organization. An untrusted application can be installed and granted permissions to access data within a GitHub organization.
Github Organization App Integration Installed
An application integration was installed to your organization's Github account by someone in your organization.
Suspicious Application Installed
Detects suspicious application installed by looking at the added shortcut to the app resolver cache
[WINDOWS-APPLICATION] MsiInstaller Installer Exited for SentinelInstaller (3/5)
The application tried to install a more recent version of the protected Windows file
Rundll32 InstallScreenSaver Execution
An attacker may execute an application as a SCR File using rundll32.exe desk.cpl,InstallScreenSaver
Suspicious Execution of InstallUtil Without Log
Uses the .NET InstallUtil.exe application in order to execute image without log
PSexec application execution
Detects scenarios where an attacker installs and executes PSexec.
osquery: $(osquery.pack) $(osquery.subquery): OS X Application $(osquery.columns.name) version $(osquery.columns.bundle_version) is installed