Browse Rules

Search and filter across all detection sources

423 rules

chronicle critical yara-l

Network HTTP Low Prevalence Domain Access

Detects network web access to a low prevalence domain

hayabusa high sigma

Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder

Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.

sigma high sigma

Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder

Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.

hayabusa high sigma

Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder

Detects executables located in potentially suspicious directories initiating network connections towards file sharing domains.

elastic medium kql

Unusual Network Connection to Suspicious Top Level Domain

This rule monitors for the unusual occurrence of outbound network connections to suspicious top level domains.

sigma medium sigma

Network Connection Initiated To BTunnels Domains

Detects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

sigma medium sigma

Network Connection Initiated To DevTunnels Domain

Detects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

wazuh low xml

The browser was unable to retrieve a list of domains from the browser master on the network

The browser was unable to retrieve a list of domains from the browser master on the network

elastic medium eql

Suricata and Elastic Defend Network Correlation

This detection correlates Suricata alerts with Elastic Defend network events to identify the source process performing the network activity.

hayabusa medium sigma

Network Connection Initiated To BTunnels Domains

Detects network connections to BTunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

hayabusa medium sigma

Network Connection Initiated To DevTunnels Domain

Detects network connections to Devtunnels domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

sigma medium sigma

Network Connection Initiated To Cloudflared Tunnels Domains

Detects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

wazuh low xml

The browser has forced an election on network because the Domain Controller (or Server) has changed its role

The browser has forced an election on network because the Domain Controller (or Server) has changed its role

hayabusa medium sigma

Network Connection Initiated To Cloudflared Tunnels Domains

Detects network connections to Cloudflared tunnels domains initiated by a process on the system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

sublime medium mql

Brand impersonation: Barracuda Networks

Impersonation of Barracuda Networks, an IT security company.

sentinel medium kql

GSA - TI Domain Entity

This query identifies Domain indicators of compromise (IOCs) from threat intelligence (TI) by searching for matches in GSA NetworkAccessTraffic.

chronicle unknown yara-l

detecting_phishing_domains_proxy

This rule detects network connections to Phishing domains. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

signature-base unknown yara

Netview_Hacktool [yara]

Network domain enumeration tool - often used by attackers - file Nv.exe

sigma medium sigma

Network Connection Initiated To Visual Studio Code Tunnels Domain

Detects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

elastic medium kql

Unusual Network Connection to Suspicious Web Service

This rule monitors for the unusual occurrence of outbound network connections to suspicious webservice domains.

hayabusa medium sigma

Network Connection Initiated To Visual Studio Code Tunnels Domain

Detects network connections to Visual Studio Code tunnel domains initiated by a process on a system. Attackers can abuse that feature to establish a reverse shell or persistence on a machine.

hayabusa high sigma

Protected Storage Service Access

Detects access to a protected_storage service over the network. Potential abuse of DPAPI to extract domain backup keys from Domain Controllers

sigma high sigma

Protected Storage Service Access

Detects access to a protected_storage service over the network. Potential abuse of DPAPI to extract domain backup keys from Domain Controllers

signature-base unknown yara

Netview_Hacktool_Output [yara]

Network domain enumeration tool output - often used by attackers - file filename.txt

elastic low kql

Machine Learning Detected a DNS Request Predicted to be a DGA Domain

A supervised machine learning model has identified a DNS question name that is predicted to be the result of a Domain Generation Algorithm (DGA), which could indicate command and control network activity.