Search and filter across all detection sources
213 rules
[NETSCREEN] Bad IP option
osquery: $(osquery.pack) $(osquery.subquery): Shared NFS $(osquery.columns.share) options $(osquery.columns.options)
[HUAWEI] ATCKDF - Ip options attack
BPFtrace Unsafe Option Usage
Detects the usage of the unsafe bpftrace option
Asana Workspace SAML Optional
An Asana user made SAML optional for your organization.
[CISCO-MERAKI] IDS Mode - Option Updated
[CISCO-MERAKI] IDS Ruleset - Option Updated
[CISCO-MERAKI] Malware Scanning - Option Updated
[CyberArk] Update user safe options failed
[WINDOWS-POWERSHELL] Powershell Options StrReverse Obfuscation
[HUAWEI] ATCKDF - Ip option source route attack
[HUAWEI] ATCKDF - Ip options route record attack
[TELNET] Attempt to login with an option
[WINDOWS-MISC] Command line options used by ExploitRemotingService
New User Created Via Net.EXE With Never Expire Option
Detects creation of local users via the net.exe command with the option "never expire"
A More Friendly Name
An optional Description
eXPressor_v1501_Options_Protection_CGSoftLabs [packers]
Zoom All Meetings Secured With One Option Disabled
A Zoom User turned off your organization's requirement that all meetings are secured with one security option.
ETW Logging/Processing Option Disabled On IIS Server
Detects changes to of the IIS server configuration in order to disable/remove the ETW logging/processing option.
eXPressor_v1501_Options_Protection_CGSoftLabs_additional [packers]