Search and filter across all detection sources
1,918 rules
[WEB-ATTACKS] Nmap Scripting Engine User-Agent Detected - Nmap Scripting Engine
[ONELOGIN] SCRIPTLET_ERROR
Powershell_Attack_Scripts [yara]
Powershell Attack Scripts
MAL_KHRAT_script [yara]
Rule derived from KHRAT script but can match on other malicious scripts as well
[CHECKPOINT] Action Run Script
AutoIT_compiled_script [utils]
Is an AutoIT compiled script
[FORTINET] Script Entity Removed
Turla_Mal_Script_Jan18_1 [yara]
Detects Turla malicious script
Diskshadow Script Mode - Uncommon Script Extension Execution
Detects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.
PowerShell Scripts Installed as Services
Detects powershell script installed as a Service
PowerShell Script Execution Policy Enabled
Detects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.
PowerShell Scripts Installed as Services - Security
Suspicious Service Installation Script
Detects suspicious service installation scripts
[FORTINET] ActiveX script was removed
apt_apt41_powershell_collection_script [yara_rules]
Detects PowerShell collection script
apt_apt41_powershell_exfiltration_script [yara_rules]
Detects PowerShell exfiltration script