Browse Rules

Search and filter across all detection sources

22 rules

wazuh low xml

Drop: Prohibit a packet from passing. Send no response.

Drop: Prohibit a packet from passing. Send no response.

yara unknown yara

Visual_Cpp_50_no_debug [packers]

yara unknown yara

Themida_10xx_18xx_no_compression_Oreans_Technologies [packers]

yara unknown yara

mpress_2_xx_x64 [packers]

MPRESS v2.XX x64 - no .NET

yara unknown yara

mpress_2_xx_x86 [packers]

MPRESS v2.XX x86 - no .NET

yara unknown yara

SkD_Undetectabler_3_No_FSG_2_Method_SkD [packers]

yara unknown yara

SkD_Undetectabler_Pro_20_No_UPX_Method_SkD [packers]

yara unknown yara

Themida_10xx_18xx_no_compression_Oreans_Technologies_additional [packers]

yara unknown yara

Themida_10xx_18xx_no_compression_Oreans_Technologies_h [packers]

yara unknown yara

SkD_Undetectabler_3_No_FSG_2_Method_SkD_additional [packers]

yara unknown yara

SkD_Undetectabler_Pro_20_No_UPX_Method_SkD_additional [packers]

yara unknown yara

Themida_10xx_18xx_no_compression_Oreans_Technologies_h_additional [packers]

panther medium python

A More Friendly Name

An optional Description

sagan informational other

[SOPHOS] The computer is running an operating system and service pack combination which is no longer supported. Upgrade to continue receiving protection.

[SOPHOS] The computer is running an operating system and service pack combination which is no longer supported. Upgrade to continue receiving protection.

elastic-protections high eql

Silent NPM Package Install Command

Detects when Node or NPM is used to install a package or packages using options to hide the installation using the following options: "--no-warnings", "--no-progress", and "--loglevel silent". Malicious packages will install required dependencies in order to function and will use these options in order to hide it from the user.

panther high python

CVE-2023-7028 - GitLab Audit Password Reset Multiple Emails

Attackers are exploiting a Critical (CVSS 10.0) GitLab vulnerability in which user account password reset emails could be delivered to an unverified email address.

panther high python

CVE-2023-7028 - GitLab Production Password Reset Multiple Emails

Attackers are exploiting a Critical (CVSS 10.0) GitLab vulnerability in which user account password reset emails could be delivered to an unverified email address.

elastic-protections high eql

Lone Binary Execution from Volume Mount

Detects when a single binary gets executed from a volume mount where no application or package structure exists and the only thing there is the binary. This is highly unusual and suspicious.

mdecrevoisier high sigma

Security package (SSP) loaded into LSA (native)

Detects scenarios where an attacker loads a malicious SSP (Security Support Provider) into the LSA process. Note that this rule will not work with "in memory" SSP injection (Mimikatz) as no event will be triggered.

elastic medium kql

First Time Seen Memcached Writer

Identifies the first successful or no-reply Memcached store command from a client to a server. Memcached commonly has no authentication, so an unauthorized writer can overwrite session tokens, poison cached application content, or alter security-sensitive state. This behavior can enable session hijacking such as the exposure described by CVE-2026-29093.

loldrivers low sigma

Driver Load - dtr_ec.sys

Detects loading of driver dtr_ec.sys via name. dtr_ec.sys is a Dell kernel driver that ships as part of the Dell Feature Enhancement Pack (DFEP) on Dell laptops and desktops. The driver provides unrestricted read/write access to Embedded Controller (EC) registers across 5 ACPI address spaces from usermode with no validation on the register addresses or values. The Embedded Controller manages critical hardware functions including thermal management, battery charging, fan control, power states, an

loldrivers high sigma

Driver Load - dtr_ec.sys

Detects loading of driver dtr_ec.sys via hash. dtr_ec.sys is a Dell kernel driver that ships as part of the Dell Feature Enhancement Pack (DFEP) on Dell laptops and desktops. The driver provides unrestricted read/write access to Embedded Controller (EC) registers across 5 ACPI address spaces from usermode with no validation on the register addresses or values. The Embedded Controller manages critical hardware functions including thermal management, battery charging, fan control, power states, an