Browse Rules

Search and filter across all detection sources

1,073 rules

signature-base unknown yara

update_PcInit [yara]

Chinese Hacktool Set - file PcInit.exe

yara unknown yara

update_PcInit [malware]

Chinese Hacktool Set - file PcInit.exe

sentinel high kql

PCI App with Open Findings Before Audit Window

Detects PCI-scoped applications with open Critical/High findings when an upcoming PCI-DSS audit is within 30 days. Correlates PCIApplications and AuditCalendar watchlists to surface compliance risk before audit deadlines.

yara unknown yara

PCIENC_Cryptor [packers]

loldrivers medium sigma

Driver Load - PcieCubed.sys

Detects loading of driver PcieCubed.sys via name. Driver categorized as POORTRY by Mandiant.

loldrivers high sigma

Driver Load - PcieCubed.sys

Detects loading of driver PcieCubed.sys via hash. Driver categorized as POORTRY by Mandiant.

yara unknown yara

PCIENC_Cryptor_additional [packers]

signature-base unknown yara

MAL_Driver_Legalcorp_Pciexpressvideocapture_FD22 [yara]

Detects malicious driver mentioned in LOLDrivers project using VersionInfo values from the PE header - PcieCubed.sys

yara unknown yara

PCIENC_Cryptor_Hint_FILE_START [packers]

sublime high mql

beta.DLP: PCI US Credit Card Number (Any Network)

Detects messages containing credit card numbers.

wazuh informational xml

Rootcheck event.

Rootcheck event.

wazuh informational xml

CMS (WordPress or Joomla) login attempt.

CMS (WordPress or Joomla) login attempt.

wazuh low xml

Microsoft Security Essentials - Virus detected

Microsoft Security Essentials - Virus detected

wazuh low xml

Microsoft Security Essentials - Virus detected.

Microsoft Security Essentials - Virus detected.

wazuh medium xml

CMS (WordPress or Joomla) brute force attempt.

CMS (WordPress or Joomla) brute force attempt.

wazuh low xml

Microsoft Security Essentials - Suspicious activity detected

Microsoft Security Essentials - Suspicious activity detected

wazuh low xml

Microsoft Security Essentials - Suspicious activity detected.

Microsoft Security Essentials - Suspicious activity detected.

wazuh low xml

Windows: Application Uninstalled.

Windows: Application Uninstalled.

wazuh low xml

Windows: Application Installed.

Windows: Application Installed.

wazuh medium xml

ClamAV: Virus detected

ClamAV: Virus detected

wazuh medium xml

ASA: Multiple AAA (VPN) authentication failures.

ASA: Multiple AAA (VPN) authentication failures.

wazuh medium xml

Symantec-AV: Virus detected.

Symantec-AV: Virus detected.

wazuh high xml

McAfee Windows AV - Virus detected and not removed

McAfee Windows AV - Virus detected and not removed

wazuh low xml

McAfee Windows AV - Virus detected and properly removed

McAfee Windows AV - Virus detected and properly removed

wazuh low xml

Microsoft Security Essentials - Virus detected and properly removed

Microsoft Security Essentials - Virus detected and properly removed