Browse Rules

Search and filter across all detection sources

141 rules

sagan high other

[CITRIX] Netscaler - AppFw XML DDoS Connect to Server Failed

[CITRIX] Netscaler - AppFw XML DDoS Connect to Server Failed

panther medium python

Salesforce Third-Party Integration Monitoring

Monitors third-party integrations and OAuth connected apps accessing Salesforce. Connected apps use OAuth for authorization and can access data on behalf of users, making them a potential vector for: - Unauthorized data access - Shadow IT applications - Compromised OAuth tokens - Over-privileged integrations This detection triggers on connected app usage events and adjusts severity based on: - Connection type (refresh tokens are higher risk) - App authorization events - Suspicious app naming pa

sagan high other

[HONEYD] Connection to honeypot Apache server [0/10]

[HONEYD] Connection to honeypot Apache server [0/10]

sagan high other

[HONEYD] Connection to honeypot IIS server [0/10]

[HONEYD] Connection to honeypot IIS server [0/10]

sagan high other

[HONEYD] Connection to honeypot SMTP server [0/10]

[HONEYD] Connection to honeypot SMTP server [0/10]

hayabusa medium sigma

Office Application Initiated Network Connection Over Uncommon Ports

Detects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.

sigma medium sigma

Office Application Initiated Network Connection Over Uncommon Ports

Detects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.

hayabusa medium sigma

Dfsvc.EXE Network Connection To Non-Local IPs

Detects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs

sigma medium sigma

Dfsvc.EXE Network Connection To Non-Local IPs

Detects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs

hayabusa medium sigma

Office Application Initiated Network Connection Over Uncommon Ports

Detects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.

hayabusa medium sigma

Dfsvc.EXE Network Connection To Non-Local IPs

Detects network connections from "dfsvc.exe" used to handled ClickOnce applications to non-local IPs

hayabusa high sigma

Dfsvc.EXE Initiated Network Connection Over Uncommon Port

Detects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.

sigma high sigma

Dfsvc.EXE Initiated Network Connection Over Uncommon Port

Detects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.

hayabusa high sigma

Dfsvc.EXE Initiated Network Connection Over Uncommon Port

Detects an initiated network connection over uncommon ports from "dfsvc.exe". A utility used to handled ClickOnce applications.

sentinel medium kql

SAP BTP - Cloud Identity Service application configuration monitor

Identifies CRUD operations on Application (SSO Domain/Service Provider) configurations within SAP Cloud Identity Service. This includes both SAML 2.0 and OpenID Connect applications. Unauthorized application creation could indicate an attacker establishing persistent access through a rogue federated application.

panther low python

Suspicious Snowflake Sessions - Unusual Application

Detects unusual (non-common) applications and client characteristics that have been used to connect to a Snowflake account

sentinel medium kql

Pathlock TDnR - HANA Standalone DB Connection Events

Detects security events from HANA standalone database connections via DBCON in SAP, forwarded by Pathlock Threat Detection and Response. Unauthorized DBCON connections allow direct database access and may be used for lateral movement or to bypass SAP application-layer controls.

hayabusa medium sigma

Office Application Initiated Network Connection To Non-Local IP

Detects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.

sigma medium sigma

Office Application Initiated Network Connection To Non-Local IP

Detects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.

elastic-protections high eql

Possible JAVA Reverse Shell

Identifies the execution of a shell process from a Java JAR application post an incoming network connection. This behavior may indicate a reverse shell activity via malicious Java application.

hayabusa high sigma

CMSTP App Paths Registry Key Modification

Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.

sigma high sigma

CMSTP App Paths Registry Key Modification

Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.

hayabusa medium sigma

Office Application Initiated Network Connection To Non-Local IP

Detects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.

elastic-protections high eql

Potential Reverse Shell via Java

Identifies the execution of a shell process from a Java JAR application post an incoming network connection. This behavior may indicate a reverse shell activity via malicious Java application.

hayabusa high sigma

CMSTP App Paths Registry Key Modification

Detects modifications to the CMSTP App Paths registry key. This may indicate abuse of Microsoft Connection Manager Profile Installer (CMSTP) for arbitrary code execution or UAC bypass.