Browse Rules

Search and filter across all detection sources

694 rules

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

[WINDOWS-MALWARE] KeRanger OS X ransomware extension detected (.kernel_time)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_complete)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

sagan critical other

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

[WINDOWS-MALWARE] KeRanger OS X ransomware file extension detected (.kernel_pid)

sagan critical other

[WINDOWS-POWERSHELL] PowerShell Script to find all Computers with Specific OS

[WINDOWS-POWERSHELL] PowerShell Script to find all Computers with Specific OS

elastic medium eql

Suspicious File Downloaded from Google Drive

Identifies suspicious file download activity from a Google Drive URL. This could indicate an attempt to deliver phishing payloads via a trusted webservice.

elastic medium kql

External Alerts

Generates a detection alert for each external alert written to the configured indices. Enabling this rule allows you to immediately begin investigating external alerts in the app.

elastic medium eql

PANW and Elastic Defend - Command and Control Correlation

This detection correlates Palo Alto Networks (PANW) command and control events with Elastic Defend network events to identify the source process performing the network activity.

elastic high kql

Multi-Cloud CLI Token and Credential Access Commands

Correlates process telemetry for shells and major cloud/Kubernetes CLIs when command lines match token or credential material access patterns (GCP, Azure, AWS, GitHub, kubectl, DigitalOcean, OCI). Flags hosts where multiple cloud targets appear within a five-minute window.

elastic medium eql

WebServer Access Logs Deleted

Identifies the deletion of WebServer access logs. This may indicate an attempt to evade detection or destroy forensic evidence on a system.

elastic medium eql

Suricata and Elastic Defend Network Correlation

This detection correlates Suricata alerts with Elastic Defend network events to identify the source process performing the network activity.

elastic high kql

Long Base64 Encoded Command via Scripting Interpreter

Identifies oversized command lines used by Python, PowerShell, Node.js, or Deno that contain base64 decoding or encoded-command patterns. Adversaries may embed long inline encoded payloads in scripting interpreters to evade inspection and execute malicious content across Windows, macOS, and Linux systems.

elastic low eql

Unusual Process Extension

Identifies processes running with unusual extensions that are not typically valid for Windows executables.

elastic medium eql

Persistence via a Windows Installer

Identifies when the Windows installer process msiexec.exe creates a new persistence entry via scheduled tasks or startup.

chronicle unknown yara-l

group_modification_logging

Configure systems to issue a log entry and alert when an account is added to or removed from any group assigned administrative privileges. Sigma detects Event ID 4728 indicates a ‘Member is added to a Security Group’. Event ID 4729 indicates a ‘Member is removed from a Security enabled-group’. Event ID 4730 indicates a‘Security Group is deleted’. The case is not applicable for Unix OS. Supported OS - Windows 2008 R2 and 7, Windows 2012 R2 and 8.1, Windows 2016 and 10 Windows Server 2019, Windows

elastic medium kql

Enumeration of Privileged Local Groups Membership

Identifies instances of an unusual process enumerating built-in Windows privileged local groups membership like Administrators or Remote Desktop users.

elastic medium eql

Windows Network Enumeration

Identifies attempts to enumerate hosts in a network using the built-in Windows net.exe tool.