Browse Rules

Search and filter across all detection sources

305 rules

chronicle critical yara-l

Network HTTP Low Prevalence Domain Access

Detects network web access to a low prevalence domain

chronicle low yara-l

WHOIS Expired Domain Executable Downloaded

Detect web traffic to a recently expired domain followed by an exe file creation event

splunk unknown spl

Monitor Web Traffic For Brand Abuse

The following analytic identifies web requests to domains that closely resemble your monitored brand's domain, indicating potential brand abuse. It leverages data from web traffic sources, such as web proxies or network traffic analysis tools, and cross-references these with known domain permutations generated by the "ESCU - DNSTwist Domain Names" search. This activity is significant as it can indicate phishing attempts or other malicious activities targeting your brand. If confirmed malicious,

elastic medium kql

Unusual Network Connection to Suspicious Web Service

This rule monitors for the unusual occurrence of outbound network connections to suspicious webservice domains.

hayabusa high sigma

Suspicious Download From File-Sharing Website Via Bitsadmin

Detects usage of bitsadmin downloading a file from a suspicious domain

sigma high sigma

Suspicious Download From File-Sharing Website Via Bitsadmin

Detects usage of bitsadmin downloading a file from a suspicious domain

sentinel medium kql

CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule

"Detects phishing campaigns targeting enterprise domains, as identified through CYFIRMA's Data Breach and Dark Web Monitoring. These alerts may include malicious URLs used for credential harvesting, domain impersonation, or social engineering. Immediate triage and takedown actions are recommended."

sentinel high kql

CYFIRMA - Data Breach and Web Monitoring - Phishing Campaign Detection Rule

"Detects phishing campaigns targeting enterprise domains, as identified through CYFIRMA's Data Breach and Dark Web Monitoring. These alerts may include malicious URLs used for credential harvesting, domain impersonation, or social engineering. Immediate triage and takedown actions are recommended."

hayabusa high sigma

Suspicious Download From File-Sharing Website Via Bitsadmin

Detects usage of bitsadmin downloading a file from a suspicious domain

elastic medium kql

GKE Admission Webhook Created or Modified

Detects creation or modification of GKE mutating or validating admission webhook configurations by non-system identities. Malicious webhooks can inject workloads, block security tooling, or intercept API traffic for persistence and defense evasion.

sentinel medium kql

TI Map Domain entity to Web Session Events (ASIM Web Session schema)

'This rule identifies Web Sessions for which the target URL hostname is a known IoC. This rule uses the [Advanced Security Information Model (ASIM)](https:/aka.ms/AboutASIM) and supports any web session source that complies with ASIM.'

sentinel medium kql

TI map Domain entity to Web Session Events (ASIM Web Session schema)

'This rule identifies Web Sessions for which the target URL hostname is a known IoC. This rule uses the [Advanced Security Information Model (ASIM)](https:/aka.ms/AboutASIM) and supports any web session source that complies with ASIM.'

elastic medium kql

Unusual Command Execution via Web Server

This rule leverages the "new_terms" rule type to detect unusual command executions originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical command executions. As command execution from web server parent processes is common, the "new_terms" rule type approach helps to identify deviations from normal behavior.

elastic medium eql

Web Server Cloud Metadata SSRF Request

Detects HTTP requests to web servers whose URL or query string references cloud instance metadata endpoints or equivalent encoded variants. Attackers exploit server-side request forgery (SSRF) vulnerabilities in web applications to reach link-local metadata services on AWS, GCP, Azure, and similar cloud providers and harvest temporary credentials, tokens, or instance details.

elastic medium kql

Unusual Child Execution via Web Server

This rule leverages the "new_terms" rule type to detect unusual child process executions originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical child process executions. As child process spawns from web server parent processes are common, the "new_terms" rule type approach helps identify deviations from normal behavior.

elastic high eql

Potential Webshell Deployed via Apache Struts CVE-2023-50164 Exploitation

Identifies successful exploitation of CVE-2023-50164, a critical path traversal vulnerability in Apache Struts 2 file upload functionality. This high-fidelity rule detects a specific attack sequence where a malicious multipart/form-data POST request with WebKitFormBoundary is made to a Struts .action upload endpoint, immediately followed by the creation of a JSP web shell file by a Java process in Tomcat's webapps directories. This correlated activity indicates active exploitation resulting in r

sublime low mql

Impersonation: Chrome Web Store policy

Detects messages impersonating Chrome Web Store policy communications, including fake extension security alerts and policy acceptance requests. Messages using observed domains and specific HTML formatting patterns typical of this impersonation.

elastic low kql

Unusual File Creation via Web Server

This rule leverages the "new_terms" rule type to detect unusual file creations originating from web server processes on Linux systems. Attackers may exploit web servers to maintain persistence on a compromised system, often resulting in atypical file creations. As file creations from web server processes are common, the "new_terms" rule type approach helps to identify deviations from normal behavior.

anvilogic medium spl

Crowdstrike Typosquatting Phishing Site - Proxy [splunk-proxy]

Several domains were registered following the CrowdStrike outage in July 2024. This use case identifies traffic to known typosquatting/phishing domains registered in the aftermath of the outage.

hayabusa high sigma

Curl File Upload To File Sharing Websites

Detects usage of curl to upload files to known file sharing domains, which may indicate data exfiltration.

sigma high sigma

Curl File Upload To File Sharing Websites

Detects usage of curl to upload files to known file sharing domains, which may indicate data exfiltration.

sentinel low kql

Request for single resource on domain

'This will look for connections to a domain where only a single file is requested, this is unusual as most modern web applications require additional recources. This type of activity is often assocaited with malware beaconing or tracking URL's delivered in emails. Developed for Zscaler but applicable to any outbound web logging.'

hayabusa high sigma

Curl File Upload To File Sharing Websites

Detects usage of curl to upload files to known file sharing domains, which may indicate data exfiltration.

sigma high sigma

Suspicious File Download From File Sharing Websites - File Stream

Detects the download of suspicious file type from a well-known file and paste sharing domain

sigma medium sigma

Unusual File Download From File Sharing Websites - File Stream

Detects the download of suspicious file type from a well-known file and paste sharing domain