Search and filter across all detection sources
1,175 rules
Azure: Storage: $(OperationName)
Azure: Log analytics: $(OperationName)
[CyberArk] External Object Operation
[EXTRAHOP] LDAP Operational Error
[ONELOGIN] USER_BULK_OPERATION
Zscaler - Unexpected update operation
'Detects unexpected version of update operation.'
Suspicious History File Operations
Detects commandline operations on shell history files
[WINDOWS-SYSMON] Evilginx2 Certificate Operations
ApexOne - Possible exploit or execute operation
'Detects possible exploit or execute operation.'
Zscaler - ZPA connections outside operational hours
'Detects ZAP connections outside operational hours.'
Suspicious History File Operations - Linux
Operation Wocao Activity
Detects activity mentioned in Operation Wocao report
downloader_mac_smooth_operator [yara_rules]
Detect the Smooth_Operator malware
Operation Wocao Activity - Security
Shadow Copies Deletion Using Operating Systems Utilities
Shadow Copies deletion using operating systems utilities
[AS400] AUTFAIL - Operation SVRPGM wihtout authority
[AZURE-EVENTHUB-AD] Security Operator Created
[MICROSOFT_INTUNE] Enrollment Operation Log Detected
[MICROSOFT_INTUNE] ESPEnrollment Operation Log Detected
SCM Database Privileged Operation
Detects non-system users performing privileged operation os the SCM database