Browse Rules

Search and filter across all detection sources

184 rules

hayabusa high sigma

LSASS Access Detected via Attack Surface Reduction

Detects Access to LSASS Process

sigma high sigma

LSASS Access Detected via Attack Surface Reduction

Detects Access to LSASS Process

sublime medium mql

Service abuse: Dropbox share from new domain

This Attack Surface Reduction (ASR) rule matches on Dropbox notifications with recently registered reply-to domains.

sublime medium mql

Service abuse: QuickBooks notification from new domain

This Attack Surface Reduction (ASR) rule matches on QuickBooks notifications with recently registered reply-to domains.

sublime high mql

Service abuse: SurveyMonkey survey from newly registered domain

This Attack Surface Reduction (ASR) rule matches on SurveyMonkey Surveys with recently registered reply-to domains.

sublime high mql

Service abuse: DocSend share from newly registered domain

This Attack Surface Reduction (ASR) rule matches on DocSend notifications with recently registered reply-to domains.

sublime medium mql

Attachment: PDF with embedded Javascript

PDF contains embedded Javascript.

sublime medium mql

Link: Adobe share from unsolicited sender

This attack surface reduction rule matches on messages from Adobe which were sent by an email address (as determined by the sender display name) which doesn't appear to have a relationship with the recipient organization.

chronicle unknown yara-l

lsass_access_detected_via_attack_surface_reduction

Detects Access to LSASS Process License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

sublime medium mql

Attachment: EML file with HTML attachment (unsolicited)

Detects HTML files in EML attachments from unsolicited senders. Reduces attack surface against HTML smuggling.

sublime high mql

Malformed URL prefix

Malformed URL prefix is a technique used to evade email security scanners.

sublime medium mql

Link: Flagged bit.ly link

Shortened link is blocked or gated by bit.ly. Indicator of malicious email.

sublime medium mql

Open redirect: Snapchat

Message contains use of the click.snapchat.com open redirect.

sublime medium mql

Attachment: RTF with embedded content

RTF files can contain embedded content similar to OLE files (Microsoft Office documents.)

sublime medium mql

Attachment with encrypted zip (unsolicited)

Recursively scans files and archives to detect encrypted zip files.

sublime low mql

Disposable sender email (unsolicited)

Sender is using a disposable email service and no one in our organization has ever sent them an email.

sublime medium mql

Link: Free subdomain host with undisclosed recipients

Detects messages with undisclosed recipients, containing links to free subdomain hosts

sublime medium mql

New sender domain (<=10d) from untrusted sender

Detects inbound emails where the sender domain is less than 10 days old from untrusted senders.

sublime medium mql

Attachment: Office document loads remote document template

Recursively scans archives and Office documents to detect remote document template injection.

sublime medium mql

Open redirect: Dell

Message contains use of the Dell open redirect, but the sender is not Dell.

sublime medium mql

Open redirect: Samsung

Message contains use of the Samsung open redirect, but the sender is not Samsung.

sublime low mql

Open redirect: Slack

Message contains use of Slack's open redirect but the sender is not Slack.

sublime medium mql

Open redirect: YouTube

Looks for use of the YouTube open redirect coming from someone other than YouTube.

sublime medium mql

Attachment: File execution via Javascript

Javascript contains identifiers or strings that may attempt to execute files.

sublime low mql

Russia return-path TLD (untrusted sender)

The return-path header is a .ru TLD from an untrusted sender.