Browse Rules

Search and filter across all detection sources

2,126 rules

sagan high other

[WINDOWS-POWERSHELL] Powershell DisableIntrusionPreventionSystem detected

[WINDOWS-POWERSHELL] Powershell DisableIntrusionPreventionSystem detected

sagan high other

[WINDOWS-POWERSHELL] Powershell DisableIntrusionPreventionSystem detected

[WINDOWS-POWERSHELL] Powershell DisableIntrusionPreventionSystem detected

sagan high other

[WINDOWS-POWERSHELL] Powershell DisableRealtimeMonitoring detected

[WINDOWS-POWERSHELL] Powershell DisableRealtimeMonitoring detected

sagan high other

[WINDOWS-POWERSHELL] Powershell DisableScriptScanning detected

[WINDOWS-POWERSHELL] Powershell DisableScriptScanning detected

sagan critical other

[WINDOWS-POWERSHELL] PowerShell Retrieve Users

[WINDOWS-POWERSHELL] PowerShell Retrieve Users

sagan high other

[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation

[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation

sagan high other

[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation

[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation

sagan critical other

[WINDOWS-POWERSHELL] Hoaxshell Uniq Identifier (PowerShell)

[WINDOWS-POWERSHELL] Hoaxshell Uniq Identifier (PowerShell)

sagan high other

[WINDOWS-POWERSHELL] Powershell MAPSReporting Disabled detected

[WINDOWS-POWERSHELL] Powershell MAPSReporting Disabled detected

sagan high other

[WINDOWS-POWERSHELL] Powershell MAPSReporting Disabled detected

[WINDOWS-POWERSHELL] Powershell MAPSReporting Disabled detected

sagan high other

[WINDOWS-POWERSHELL] Powershell Options StrReverse Obfuscation

[WINDOWS-POWERSHELL] Powershell Options StrReverse Obfuscation

sagan high other

[WINDOWS-POWERSHELL] Powershell Options StrReverse Obfuscation

[WINDOWS-POWERSHELL] Powershell Options StrReverse Obfuscation

sagan high other

[WINDOWS-POWERSHELL] Powershell Possible Downgrade Attempt

[WINDOWS-POWERSHELL] Powershell Possible Downgrade Attempt

sagan high other

[WINDOWS-POWERSHELL] Powershell Possible Downgrade Attempt

[WINDOWS-POWERSHELL] Powershell Possible Downgrade Attempt

hayabusa medium sigma

Alternate PowerShell Hosts - PowerShell Module

Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe

sagan critical other

[WINDOWS-POWERSHELL] Possible Hoaxshell attempt (PowerShell Script)

[WINDOWS-POWERSHELL] Possible Hoaxshell attempt (PowerShell Script)

sagan critical other

[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell

[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell

sagan critical other

[WINDOWS-POWERSHELL] Windows Defender Uninstalled via PowerShell

[WINDOWS-POWERSHELL] Windows Defender Uninstalled via PowerShell

sagan critical other

[WINDOWS-POWERSHELL] Windows Firewall Restarted via PowerShell

[WINDOWS-POWERSHELL] Windows Firewall Restarted via PowerShell

sigma medium sigma

Alternate PowerShell Hosts - PowerShell Module

Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe

hayabusa medium sigma

Suspicious PowerShell Download - Powershell Script

Detects suspicious PowerShell download command

sigma medium sigma

Suspicious PowerShell Download - Powershell Script

Detects suspicious PowerShell download command

sagan high other

[WINDOWS-POWERSHELL] Powershell created local user [1/3]

[WINDOWS-POWERSHELL] Powershell created local user [1/3]

sagan high other

[WINDOWS-POWERSHELL] Powershell created local user [1/3]

[WINDOWS-POWERSHELL] Powershell created local user [1/3]

sagan high other

[WINDOWS-POWERSHELL] Powershell created local user [2/3]

[WINDOWS-POWERSHELL] Powershell created local user [2/3]