Browse Rules

Search and filter across all detection sources

491 rules

sagan medium other

[TRENDMICRO] Application Control Logs Detected

[TRENDMICRO] Application Control Logs Detected

wazuh informational xml

Event created in the application log

Event created in the application log

sagan medium other

[DYNAMIC] AWS Application Insights logs detected via program.

[DYNAMIC] AWS Application Insights logs detected via program.

sagan critical other

[WINDOWS-SYSTEM] The Application log file was cleared

[WINDOWS-SYSTEM] The Application log file was cleared

sentinel high kql

Web Application attack detected

Identifies Web application attack in Azure Firewall IDPS logs.

anvilogic unknown other

Okta: Application Modified or Deleted [snowflake-okta]

This use case looks for updates or removals of OKTA applications

anvilogic high other

Okta: API Token Created_Deleted [snowflake-okta]

This use-case will detect when API tokens are created or deleted in Okta

anvilogic high spl

Okta: API Token Created_Deleted [splunk-okta]

This use-case will detect when API tokens are created or deleted in Okta

hayabusa high sigma

Relevant Anti-Virus Signature Keywords In Application Log

Detects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.

sigma high sigma

Relevant Anti-Virus Signature Keywords In Application Log

Detects potentially highly relevant antivirus events in the application log based on known virus signature names and malware keywords.

sagan medium other

[JUNIPER] Application-level distributed denial-of-service (AppDDoS) attack in a logical system

[JUNIPER] Application-level distributed denial-of-service (AppDDoS) attack in a logical system

sentinel medium kql

SenservaPro AD Applications Not Using Client Credentials

'Searches for logs of AD Applications without Client Credentials (Key or Secret)'

sagan medium other

[JUNIPER] application-level distributed denial-of-service (AppDDoS) state transition occurred in logical system

[JUNIPER] application-level distributed denial-of-service (AppDDoS) state transition occurred in logical system

sagan high other

[APACHE] Log4j exploit attempt - CVE-2021-44228

[APACHE] Log4j exploit attempt - CVE-2021-44228

anvilogic high other

Okta: Profile Updated [snowflake-okta]

Okta user profile updated

anvilogic high spl

Okta: Profile Updated [splunk-okta]

Okta user profile updated

anvilogic high other

Okta: User Created [snowflake-okta]

Okta user account creation

anvilogic high spl

Okta: User Created [splunk-okta]

Okta user account creation

hayabusa medium sigma

Suspicious Execution of InstallUtil Without Log

Uses the .NET InstallUtil.exe application in order to execute image without log

sagan high other

[WEB-ATTACKS] Log4j exploit attempt - CVE-2021-44228

[WEB-ATTACKS] Log4j exploit attempt - CVE-2021-44228

sigma medium sigma

Suspicious Execution of InstallUtil Without Log

Uses the .NET InstallUtil.exe application in order to execute image without log

hayabusa medium sigma

Suspicious Execution of InstallUtil Without Log

Uses the .NET InstallUtil.exe application in order to execute image without log

panther informational python

Push Security Authorized IdP Login

Login to application with unauthorized identity provider which could indicate a SAMLjacking attack.

panther high python

Push Security Unauthorized IdP Login

Login to application with unauthorized identity provider which could indicate a SAMLjacking attack.

sagan high other

[WEB-ATTACKS] Attempt to Access Default Cacti Login Page

[WEB-ATTACKS] Attempt to Access Default Cacti Login Page