Browse Rules

Search and filter across all detection sources

129 rules

sagan low other

[WINDOWS-MISC] Trusted Platform Module [TPM] Error. User name not found

[WINDOWS-MISC] Trusted Platform Module [TPM] Error. User name not found

sagan low other

[WINDOWS-MISC] Trusted Platform Module [TPM] Error. User name not found

[WINDOWS-MISC] Trusted Platform Module [TPM] Error. User name not found

hayabusa high sigma

Windows Filtering Platform Blocked Connection From EDR Agent Binary

Detects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents. Adversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.

sigma high sigma

Windows Filtering Platform Blocked Connection From EDR Agent Binary

Detects a Windows Filtering Platform (WFP) blocked connection event involving common Endpoint Detection and Response (EDR) agents. Adversaries may use WFP filters to prevent Endpoint Detection and Response (EDR) agents from reporting security events.

elastic medium eql

Potential Evasion via Windows Filtering Platform

Identifies multiple Windows Filtering Platform block events and where the process name is related to an endpoint security software. Adversaries may add malicious WFP rules to prevent Endpoint security from sending telemetry.

splunk unknown spl

Windows Filtering Platform Policy Added to Block EDR Process

Detects the modification of a Windows Filtering Platform Policy to block the communication of known EDR processes. This can be used by attackers to impair the functionality of these tools and to hide their activities on the machine.

wazuh informational xml

Windows Defender: Antimalware platform is running and in a healthy state

Windows Defender: Antimalware platform is running and in a healthy state

wazuh high xml

Windows Defender: ERROR: PLATFORM OUTDATED

Windows Defender: ERROR: PLATFORM OUTDATED

hayabusa high sigma

HackTool - NoFilter Execution

Detects execution of NoFilter, a tool for abusing the Windows Filtering Platform for privilege escalation via hardcoded policy name indicators

sigma high sigma

HackTool - NoFilter Execution

Detects execution of NoFilter, a tool for abusing the Windows Filtering Platform for privilege escalation via hardcoded policy name indicators

splunk unknown spl

Windows AI Platform DNS Query

The following analytic detects DNS queries initiated by the Windows AI Platform to domains associated with Hugging Face, OpenAI, and other popular providers of machine learning models and services. Monitoring these DNS requests is important because it can reveal when systems are accessing external AI platforms, which may indicate the use of third-party AI resources or the transfer of sensitive data outside the organization’s environment. Detecting such activity enables organizations to enforce d

hayabusa medium sigma

WFP Filter Added via Registry

Detects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.

sigma medium sigma

WFP Filter Added via Registry

Detects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.

wazuh informational xml

Windows Defender: Antimalware platform will soon be updated

Windows Defender: Antimalware platform will soon be updated

hayabusa medium sigma

WFP Filter Added via Registry

Detects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.

hayabusa medium sigma

Windows Backup Deleted Via Wbadmin.EXE

Detects the deletion of backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.

sigma medium sigma

Windows Backup Deleted Via Wbadmin.EXE

Detects the deletion of backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.

wazuh medium xml

Windows Defender: Error while attempting to update antimalware platform

Windows Defender: Error while attempting to update antimalware platform

hayabusa medium sigma

Windows Backup Deleted Via Wbadmin.EXE

Detects the deletion of backups or system state backups via "wbadmin.exe". This technique is used by numerous ransomware families and actors. This may only be successful on server platforms that have Windows Backup enabled.

wazuh informational xml

Windows Defender: Antimalware platform restored an item from quarantine at $(win.eventdata.path)

Windows Defender: Antimalware platform restored an item from quarantine at $(win.eventdata.path)

wazuh informational xml

Windows Defender: Antimalware platform deleted an item from quarantine at $(win.eventdata.path)

Windows Defender: Antimalware platform deleted an item from quarantine at $(win.eventdata.path)

wazuh informational xml

Windows Defender: Antimalware platform deleted history of malware and other potentially unwanted software

Windows Defender: Antimalware platform deleted history of malware and other potentially unwanted software

wazuh low xml

Windows Defender: Antimalware platform will expire soon

Windows Defender: Antimalware platform will expire soon

hayabusa high sigma

HackTool - EDRSilencer Execution - Filter Added

Detects execution of EDRSilencer, a tool that abuses the Windows Filtering Platform (WFP) to block the outbound traffic of running EDR agents based on specific hardcoded filter names.

sigma high sigma

HackTool - EDRSilencer Execution - Filter Added

Detects execution of EDRSilencer, a tool that abuses the Windows Filtering Platform (WFP) to block the outbound traffic of running EDR agents based on specific hardcoded filter names.