Search and filter across all detection sources
1,073 rules
update_PcInit [yara]
Chinese Hacktool Set - file PcInit.exe
update_PcInit [malware]
PCI App with Open Findings Before Audit Window
Detects PCI-scoped applications with open Critical/High findings when an upcoming PCI-DSS audit is within 30 days. Correlates PCIApplications and AuditCalendar watchlists to surface compliance risk before audit deadlines.
PCIENC_Cryptor [packers]
Driver Load - PcieCubed.sys
Detects loading of driver PcieCubed.sys via name. Driver categorized as POORTRY by Mandiant.
Detects loading of driver PcieCubed.sys via hash. Driver categorized as POORTRY by Mandiant.
PCIENC_Cryptor_additional [packers]
MAL_Driver_Legalcorp_Pciexpressvideocapture_FD22 [yara]
Detects malicious driver mentioned in LOLDrivers project using VersionInfo values from the PE header - PcieCubed.sys
PCIENC_Cryptor_Hint_FILE_START [packers]
beta.DLP: PCI US Credit Card Number (Any Network)
Detects messages containing credit card numbers.
Rootcheck event.
CMS (WordPress or Joomla) login attempt.
Microsoft Security Essentials - Virus detected
Microsoft Security Essentials - Virus detected.
CMS (WordPress or Joomla) brute force attempt.
Microsoft Security Essentials - Suspicious activity detected
Microsoft Security Essentials - Suspicious activity detected.
Windows: Application Uninstalled.
Windows: Application Installed.
ClamAV: Virus detected
ASA: Multiple AAA (VPN) authentication failures.
Symantec-AV: Virus detected.
McAfee Windows AV - Virus detected and not removed
McAfee Windows AV - Virus detected and properly removed
Microsoft Security Essentials - Virus detected and properly removed