Browse Rules

Search and filter across all detection sources

516 rules

sagan high other

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [1/2]

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [1/2]

sagan high other

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [1/2]

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [1/2]

sagan high other

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [2/2]

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [2/2]

sagan high other

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [2/2]

[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [2/2]

sagan medium other

[DYNAMIC] PowerShell logs detect via program

[DYNAMIC] PowerShell logs detect via program

sagan critical other

[WINDOWS-POWERSHELL] Chrome Login Data Retrieval

[WINDOWS-POWERSHELL] Chrome Login Data Retrieval

anvilogic high spl

Logon Script Registry Key added [splunk-powershell]

Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.

sagan medium other

[DYNAMIC] Azure Eventhub Windows Powershell Logs Detected

[DYNAMIC] Azure Eventhub Windows Powershell Logs Detected

sagan high other

[WINDOWS-POWERSHELL] Access to Brave Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Brave Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Brave Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Brave Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Chrome Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Chrome Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Chrome Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Chrome Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Firefox Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Firefox Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Firefox Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Firefox Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Opera Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Opera Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Opera Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Opera Login/Cookie Data

sagan critical other

[WINDOWS-POWERSHELL] Mimikatz Command Line Parameters (sekurlsa::logonpasswords)

[WINDOWS-POWERSHELL] Mimikatz Command Line Parameters (sekurlsa::logonpasswords)

sagan high other

[WINDOWS-POWERSHELL] Access to Microsoft Edge Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Microsoft Edge Login/Cookie Data

sagan high other

[WINDOWS-POWERSHELL] Access to Microsoft Edge Login/Cookie Data

[WINDOWS-POWERSHELL] Access to Microsoft Edge Login/Cookie Data

hayabusa high sigma

PowerShell Logging Disabled Via Registry Key Tampering

Detects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging

sigma high sigma

PowerShell Logging Disabled Via Registry Key Tampering

Detects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging

hayabusa high sigma

PowerShell Logging Disabled Via Registry Key Tampering

Detects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging

sigma medium sigma

PowerShell Console History Logs Deleted

Detects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence

chronicle informational yara-l

MITRE ATT&CK T1033 Recon Successful Logon Enumeration Powershell CISA Report

Detects the use of powershell to enumerate successful logins on a specific host

hayabusa medium sigma

PowerShell Console History Logs Deleted

Detects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence