Browse Rules

Search and filter across all detection sources

5 rules

elastic high eql

Suspicious Microsoft Diagnostics Wizard Execution

Identifies potential abuse of the Microsoft Diagnostics Troubleshooting Wizard (MSDT) to proxy malicious command or binary execution via malicious process arguments.

elastic low eql

Suspicious Troubleshooting Pack Cabinet Execution

Identifies the execution of the Microsoft Diagnostic Wizard to open a diagcab file from a suspicious path and with an unusual parent process. This may indicate an attempt to execute malicious Troubleshooting Pack Cabinet files.

elastic critical kql

Multiple Vulnerabilities by Asset via Wiz

This alert identifies assets with an elevated number of vulnerabilities reported by Wiz, potentially indicating weak security posture, missed patching, or active exposure. The rule highlights assets with a high volume of distinct vulnerabilities, the presence of exploitable vulnerabilities, or a combination of multiple severities, helping prioritize assets that pose increased risk.

anvilogic critical other

WinSCP Execution [snowflake-crowdstrikefdr_process]

WinSCP is an open source free SFTP client, FTP client, WebDAV client, S3 client and SCP client for Windows. Its main function is file transfer between a local and a remote computer. Adversaries have been known to use winscp in order to exfiltrate data. - Threat Actor Association: BlueNoroff, Lazarus, Stonefly, Wizard Spider -- Software Association: Akira, Bazar, Conti, LockBit, Play, Rhysida

anvilogic critical spl

WinSCP Execution [splunk-winevent]

WinSCP is an open source free SFTP client, FTP client, WebDAV client, S3 client and SCP client for Windows. Its main function is file transfer between a local and a remote computer. Adversaries have been known to use winscp in order to exfiltrate data. - Threat Actor Association: BlueNoroff, Lazarus, Stonefly, Wizard Spider -- Software Association: Akira, Bazar, Conti, LockBit, Play, Rhysida