Browse Rules

Search and filter across all detection sources

107 rules

yara unknown yara

davivienda [deprecated]

wazuh informational xml

Puppet Master: Deprecated

Puppet Master: Deprecated

panther informational python

DEPRECATED - GitHub Web Hook Modified

Deprecated. See GitHub.Webhook.Modified instead.

sagan informational other

[CyberArk] Process has stopped (deprecated).

[CyberArk] Process has stopped (deprecated).

sagan medium other

[EXTRAHOP] Deprecated SSL/TLS Versions

[EXTRAHOP] Deprecated SSL/TLS Versions

panther medium python

Notion Many Pages Deleted [Deprecated]

(Deprecated due to false-positive rate) A Notion User deleted multiple pages.

mdecrevoisier high sigma

Interactive privileged shell triggered by schedule task (deprecated)

Detects scenarios where an attacker abuse the at command to elevate privilages. Note that at command is deprecated since Windows 8 and replaced by schtask.

panther medium python

GCP K8s New Daemonset Deployed

Detects Daemonset creation in GCP Kubernetes clusters.

sentinel medium kql

TI Map URL Entity to OfficeActivity Data [Deprecated]

'This query is Deprecated as its filter conditions will never yield results. This query identifies any URL indicators of compromise (IOCs) from threat intelligence (TI) by searching for matches in OfficeActivity data.'

mdecrevoisier high sigma

Firewall deactivation (deprecated command)

Detects scenarios where an attacker disabled the Windows Firewall to evade defense.

sekoia unknown yara

rat_win_remcos [yara_rules]

DEPRECATED : Find Remcos RAT samples based on specific strings

elastic low kql

Deprecated - Azure Virtual Network Device Modified or Deleted

Identifies when a virtual network device is modified or deleted. This can be a network virtual appliance, virtual hub, or virtual router. **Deprecated Notice** - This rule has been deprecated in favor of other rules that provide more contextual threat behavior for Azure Virtual Network.

sentinel high kql

[Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022

'Use Microsoft's up-to-date Threat Intelligence solution from the Content Hub to replace the deprecated query with outdated IoCs. Install it from: https://learn.microsoft.com/azure/sentinel/sentinel-solutions-deploy'

elastic critical kql

Deprecated - Threat Intel Indicator Match

This rule is triggered when indicators from the Threat Intel integrations have a match against local file or network observations. This rule was deprecated. See the Setup section for more information and alternative rules.

elastic low kql

AWS EC2 Deprecated AMI Discovery

Identifies when a user has queried for deprecated Amazon Machine Images (AMIs) in AWS. This may indicate an adversary looking for outdated AMIs that may be vulnerable to exploitation. While deprecated AMIs are not inherently malicious or indicative of a breach, they may be more susceptible to vulnerabilities and should be investigated for potential security risks.

elastic critical kql

Deprecated - Threat Intel Filebeat Module (v8.x) Indicator Match

This rule is triggered when indicators from the Threat Intel Filebeat module (v8.x) has a match against local file or network observations. This rule was deprecated. See the Setup section for more information and alternative rules.

panther medium python

AWS ELB SSL Policies

Ensures that deprecated TLS versions are not supported in internet-facing load balancers

sentinel medium kql

[Deprecated] Explicit MFA Deny

'User explicitly denies MFA push, indicating that login was not expected and the account's password may be compromised. This rule is deprecated as of July-2024. Alternative rule with similar logic and contex from more data source is available at https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Entra%20ID/Analytic%20Rules/MFARejectedbyUser.yaml'

panther medium python

GCP K8s IOCActivity

This detection monitors for any kubernetes API Request originating from an Indicator of Compromise.

car unknown other

Shadow Copy Deletion

This analytic has been deprecated in favor of [CAR-2021-01-009](/analytics/CAR-2021-01-009), which covers the same technique with some additional detections.

panther high python

DEPRECATED - AWS User Login Profile Modified

An attacker with iam:UpdateLoginProfile permission on other users can change the password used to login to the AWS console. May be legitimate account administration.

chronicle unknown yara-l

abusing_managebdewsf

Detects abusing of deprecated manage-bde.wsf. Tampering with manage-bde.wsf to run things in unattended ways. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

panther medium python

Google Drive High Download Count

Scheduled rule for the High Google Drive Download Count query which looks for incidents of more than 10 (tunable) downloads by a user in the past day.

splunk unknown spl

Windows Bypass UAC via Pkgmgr Tool

The following analytic detects the execution of the deprecated 'pkgmgr.exe' process with an XML input file, which is unusual and potentially suspicious. This detection leverages Endpoint Detection and Response (EDR) telemetry, focusing on process execution details and command-line arguments. The significance lies in the deprecated status of 'pkgmgr.exe' and the use of XML files, which could indicate an attempt to bypass User Account Control (UAC). If confirmed malicious, this activity could allo

panther medium python

Databricks Install Library on All Clusters

Detects use of the deprecated installLibraryOnAllClusters action. This anti-pattern can introduce security risks by installing potentially malicious libraries across the entire environment without proper review or controls.