Browse Rules

Search and filter across all detection sources

457 rules

sagan critical other

[CROWDSTRIKE] Collection Tactic Catchall

[CROWDSTRIKE] Collection Tactic Catchall

sagan medium other

[MICROSOFT-ATP] Collection alert

[MICROSOFT-ATP] Collection alert

sigma low sigma

Cisco Collect Data

Collect pertinent data from the configuration files

signature-base unknown yara

Sofacy_CollectorStealer_Gen2 [yara]

File collectors / USB stealers - Generic

signature-base unknown yara

Sofacy_CollectorStealer_Gen3 [yara]

File collectors / USB stealers - Generic

sentinel medium kql

CiscoISE - Log collector was suspended

'Detects when log collector was suspended.'

sekoia unknown yara

apt_apt41_powershell_collection_script [yara_rules]

Detects PowerShell collection script

signature-base unknown yara

Sofacy_CollectorStealer_Gen1 [yara]

Generic rule to detect Sofacy Malware Collector Stealer

sigma high sigma

BloodHound Collection Files

Detects default file names outputted by the BloodHound collection tool SharpHound

hayabusa high sigma

BloodHound Collection Files

Detects default file names outputted by the BloodHound collection tool SharpHound

sagan medium other

[MICROSOFT_DEFENDER_ENDPOINT] Collection High Alert Detected

[MICROSOFT_DEFENDER_ENDPOINT] Collection High Alert Detected

sagan medium other

[MICROSOFT_DEFENDER_ENDPOINT] Collection Informational Alert Detected

[MICROSOFT_DEFENDER_ENDPOINT] Collection Informational Alert Detected

sagan medium other

[MICROSOFT_DEFENDER_ENDPOINT] Collection Low Alert Detected

[MICROSOFT_DEFENDER_ENDPOINT] Collection Low Alert Detected

sagan medium other

[MICROSOFT_DEFENDER_ENDPOINT] Collection Medium Alert Detected

[MICROSOFT_DEFENDER_ENDPOINT] Collection Medium Alert Detected

sagan medium other

[CROWDSTRIKE] Suspicious Execution Detected - SharpHound/BloodHound collector executed

[CROWDSTRIKE] Suspicious Execution Detected - SharpHound/BloodHound collector executed

panther medium python

Gsuite Mail forwarded to external domain

A user has configured mail forwarding to an external domain

sigma medium sigma

Azure Firewall Rule Collection Modified or Deleted

Identifies when Rule Collections (Application, NAT, and Network) is being modified or deleted.

hayabusa medium sigma

Automated Collection Command PowerShell

Once established within a system or network, an adversary may use automated techniques for collecting internal data.

hayabusa medium sigma

Automated Collection Command Prompt

Once established within a system or network, an adversary may use automated techniques for collecting internal data.

sigma medium sigma

Automated Collection Command PowerShell

Once established within a system or network, an adversary may use automated techniques for collecting internal data.

sigma medium sigma

Automated Collection Command Prompt

Once established within a system or network, an adversary may use automated techniques for collecting internal data.

hayabusa medium sigma

Automated Collection Command Prompt

Once established within a system or network, an adversary may use automated techniques for collecting internal data.

bertjanp unknown kql

'File From Host Collected via Portal or Live Response

This query lists all the file downloads from an onboarded EDR device. The query lists the two file collection methods: 1. LiveResponseGetFile: Files collected through the getfile command in Live Response 2: DownloadFile: Files collected though the XDR portal by using the download file feature.

elastic-protections high eql

Environment Variable Secret Collection

Identifies the execution of the env or printenv commands followed by a grep command to collect environment variable secrets. This is a common technique used by attackers to collect sensitive information from the environment.

sentinel low kql

SAP BTP - User added to sensitive privileged role collection

Identifies identity management actions whereby a user is added to a set of monitored privileged role collections.