Browse Rules

Search and filter across all detection sources

108 rules

sigma low sigma

AWS EKS Cluster Created or Deleted

Identifies when an EKS cluster is created or deleted.

sekoia unknown yara

ransomware_win_eking_rich_header [yara_rules]

Detect Eking ransomware using its rich header

panther high python

Slack EKM Slackbot Unenrolled

Detects when a workspace is longer enrolled in EKM

hayabusa high sigma

ADCS Certificate Template Configuration Vulnerability with Risky EKU

Detects certificate creation with template allowing risk permission subject and risky EKU

sigma high sigma

ADCS Certificate Template Configuration Vulnerability with Risky EKU

Detects certificate creation with template allowing risk permission subject and risky EKU

yara unknown yara

blackhole_basic [exploit_kits]

yara unknown yara

unk_packer [malware]

Spora & Cerber ek

chronicle unknown yara-l

rig_ek_delivers_predator_the_thiefbot_ransomware

Rig EK Delivers Predator the thief&Bot Ransomware License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

panther informational python

EKS Audit Log based single sourceIP is generating multiple 403s

This detection identifies if a public sourceIP is generating multiple 403s with the Kubernetes API server.

panther high python

Slack EKM Config Changed

Detects when the logging settings for a workspace's EKM configuration has changed

yara unknown yara

AnglerEKredirector [exploit_kits]

Angler Exploit Kit Redirector

chronicle unknown yara-l

ekanssnake_ransomware_sysmon_detection

EKANS/SNAKE is a Malware that attempts to attack ICS (Industrial Control Systems) environments License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.

elastic medium eql

AWS EKS Access Entry Created Then Deleted by Same Identity

Detects the creation of an Amazon EKS access entry followed by its deletion by the same identity within a short time window. EKS access entries define Kubernetes RBAC-level permissions for IAM principals in an EKS cluster. An adversary with EKS administrative access may temporarily grant themselves cluster access, use those permissions to create Kubernetes RBAC resources (ClusterRoleBindings, ServiceAccounts with privileged roles), and then delete the access entry to hide the evidence of the ini

yara unknown yara

angler_flash [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

angler_flash2 [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

angler_flash4 [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

angler_flash5 [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

angler_html [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

angler_html2 [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

angler_jar [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

angler_js [exploit_kits]

Angler Exploit Kit Detection

yara unknown yara

blackhole2_css [exploit_kits]

BlackHole2 Exploit Kit Detection

yara unknown yara

blackhole2_htm [exploit_kits]

BlackHole2 Exploit Kit Detection

yara unknown yara

blackhole2_htm10 [exploit_kits]

BlackHole2 Exploit Kit Detection

yara unknown yara

blackhole2_htm11 [exploit_kits]

BlackHole2 Exploit Kit Detection