Browse Rules

Search and filter across all detection sources

1,918 rules

sagan high other

[WEB-ATTACKS] Nmap Scripting Engine User-Agent Detected - Nmap Scripting Engine

[WEB-ATTACKS] Nmap Scripting Engine User-Agent Detected - Nmap Scripting Engine

sagan informational other

[ONELOGIN] SCRIPTLET_ERROR

[ONELOGIN] SCRIPTLET_ERROR

signature-base unknown yara

Powershell_Attack_Scripts [yara]

Powershell Attack Scripts

signature-base unknown yara

MAL_KHRAT_script [yara]

Rule derived from KHRAT script but can match on other malicious scripts as well

sagan medium other

[CHECKPOINT] Action Run Script

[CHECKPOINT] Action Run Script

yara unknown yara

AutoIT_compiled_script [utils]

Is an AutoIT compiled script

sagan unknown other

[FORTINET] Script Entity Removed

[FORTINET] Script Entity Removed

sagan unknown other

[FORTINET] Script Entity Removed

[FORTINET] Script Entity Removed

signature-base unknown yara

Turla_Mal_Script_Jan18_1 [yara]

Detects Turla malicious script

hayabusa medium sigma

Diskshadow Script Mode - Uncommon Script Extension Execution

Detects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.

sigma medium sigma

Diskshadow Script Mode - Uncommon Script Extension Execution

Detects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.

hayabusa high sigma

PowerShell Scripts Installed as Services

Detects powershell script installed as a Service

sigma high sigma

PowerShell Scripts Installed as Services

Detects powershell script installed as a Service

hayabusa low sigma

PowerShell Script Execution Policy Enabled

Detects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.

sigma low sigma

PowerShell Script Execution Policy Enabled

Detects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.

hayabusa medium sigma

Diskshadow Script Mode - Uncommon Script Extension Execution

Detects execution of "Diskshadow.exe" in script mode to execute an script with a potentially uncommon extension. Initial baselining of the allowed extension list is required.

hayabusa low sigma

PowerShell Script Execution Policy Enabled

Detects the enabling of the PowerShell script execution policy. Once enabled, this policy allows scripts to be executed.

hayabusa high sigma

PowerShell Scripts Installed as Services - Security

Detects powershell script installed as a Service

hayabusa high sigma

Suspicious Service Installation Script

Detects suspicious service installation scripts

sagan unknown other

[FORTINET] ActiveX script was removed

[FORTINET] ActiveX script was removed

sagan unknown other

[FORTINET] ActiveX script was removed

[FORTINET] ActiveX script was removed

sagan unknown other

[FORTINET] ActiveX script was removed

[FORTINET] ActiveX script was removed

sagan unknown other

[FORTINET] ActiveX script was removed

[FORTINET] ActiveX script was removed

sekoia unknown yara

apt_apt41_powershell_collection_script [yara_rules]

Detects PowerShell collection script

sekoia unknown yara

apt_apt41_powershell_exfiltration_script [yara_rules]

Detects PowerShell exfiltration script