Search and filter across all detection sources
357 rules
Suspicious_JS_script_content [yara]
Detects suspicious statements in JavaScript files
[Barracuda] Email Gateway Attachment_Content Event Detected
[Barracuda] Email Gateway Body_Content Event Detected
[Barracuda] Email Gateway Content_Protected Event Detected
[Barracuda] Email Gateway Content_Url Event Detected
[Barracuda] Email Gateway Header_Content Event Detected
[Barracuda] Email Gateway Subject_Content Event Detected
[Barracuda] Email Gateway Predefined_Attachment_Content Event Detected
[Barracuda] Email Gateway Predefined_Body_Content Event Detected
[Barracuda] Email Gateway Predefined_Header_Content Event Detected
[Barracuda] Email Gateway Predefined_Subject_Content Event Detected
[SOPHOS_FIREWALL] Web Content Filter - Malicious File Detected
Service abuse: Demio notifications with suspicious content patterns
Detects messages from Demio notifications service containing suspicious patterns including phone numbers, monetary amounts, suspicious domain references, explicit content lures, or lengthy action-oriented subjects designed to manipulate recipients.
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Add-ContentFilterPhrase Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-ContentFilterConfig Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-ContentFilterPhrase Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Remove-ContentFilterPhrase Successfully Executed
[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Set-ContentFilterConfig Successfully Executed
SUSP_LNK_SuspiciousCommands [yara]
Detects LNK file with suspicious content
Potential Persistence Via PowerShell User Profile Using Add-Content
Detects calls to "Add-Content" cmdlet in order to modify the content of the user profile and potentially adding suspicious commands for persistence
SUSP_APT_3CX_Regtrans_Anomaly_Apr23 [yara]
Detects suspicious .regtrans-ms files with suspicious size or contents
[BOX] Shield detected an anomalous download, session, location, or malicious content
[MSEXCHANGE-MANAGEMENT] defender-for-office-365 Cmdlet Get-ContentMalwareMdoAggregateReport Successfully Executed
[MSEXCHANGE-MANAGEMENT] defender-for-office-365 Cmdlet Get-ContentMalwareMdoDetailReport Successfully Executed