Search and filter across all detection sources
556 rules
Encrypt: Connection Encrypted
LockBox_EncryptRsaEx [crypto]
LockBox EncryptRsaEx
AWS EC2 EBS Encryption Disabled
Identifies disabling of default EBS encryption. Disabling default encryption does not change the encryption status of existing volumes.
[Barracuda] WAF URL Encryption
[EXTRAHOP] Weak Kerberos Encryption
[PASSWORDSTATE] Encryption Keys Exported
[VEEAM] Encryption Password Added
[VEEAM] Encryption Password Deleted
[VEEAM] Encryption Password Updated
DCP_BLOWFISH_EncryptCBC [crypto]
Look for DCP Blowfish EncryptCBC
DCP_DES_EncryptECB [crypto]
Look for DCP Des EncryptECB
DCP_RIJNDAEL_EncryptECB [crypto]
Look for DCP RijnDael EncryptECB
File Encryption Using Gpg4win
Detects usage of Gpg4win to encrypt files
AWS EC2 Disable EBS Encryption
Identifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.
Key Install: Encryption keys were created.
FlyUtilsCnDES_ECB_Encrypt [crypto]
Look for FlyUtils.CnDES Encrypt ECB function
osquery: $(osquery.pack) $(osquery.subquery): Device $(osquery.columns.name) encryption status is $(osquery.columns.encryption_status)
Suspicious Kerberos RC4 Ticket Encryption
Detects service ticket requests using RC4 encryption type
apt_micdown_encrypted_configuration [yara_rules]
Encrypted C2 configuration of micDown
apt_ProjectSauron_encrypted_LSA [malware]
Rule to detect ProjectSauron encrypted LSA samples
apt_ProjectSauron_encrypted_SSPI [malware]
Rule to detect encrypted ProjectSauron SSPI samples