Browse Rules

Search and filter across all detection sources

357 rules

signature-base unknown yara

Suspicious_JS_script_content [yara]

Detects suspicious statements in JavaScript files

sagan medium other

[Barracuda] Email Gateway Attachment_Content Event Detected

[Barracuda] Email Gateway Attachment_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Body_Content Event Detected

[Barracuda] Email Gateway Body_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Content_Protected Event Detected

[Barracuda] Email Gateway Content_Protected Event Detected

sagan medium other

[Barracuda] Email Gateway Content_Url Event Detected

[Barracuda] Email Gateway Content_Url Event Detected

sagan medium other

[Barracuda] Email Gateway Header_Content Event Detected

[Barracuda] Email Gateway Header_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Subject_Content Event Detected

[Barracuda] Email Gateway Subject_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Predefined_Attachment_Content Event Detected

[Barracuda] Email Gateway Predefined_Attachment_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Predefined_Body_Content Event Detected

[Barracuda] Email Gateway Predefined_Body_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Predefined_Header_Content Event Detected

[Barracuda] Email Gateway Predefined_Header_Content Event Detected

sagan medium other

[Barracuda] Email Gateway Predefined_Subject_Content Event Detected

[Barracuda] Email Gateway Predefined_Subject_Content Event Detected

sagan medium other

[SOPHOS_FIREWALL] Web Content Filter - Malicious File Detected

[SOPHOS_FIREWALL] Web Content Filter - Malicious File Detected

sublime medium mql

Service abuse: Demio notifications with suspicious content patterns

Detects messages from Demio notifications service containing suspicious patterns including phone numbers, monetary amounts, suspicious domain references, explicit content lures, or lengthy action-oriented subjects designed to manipulate recipients.

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Add-ContentFilterPhrase Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Add-ContentFilterPhrase Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-ContentFilterConfig Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-ContentFilterConfig Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-ContentFilterPhrase Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Get-ContentFilterPhrase Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Remove-ContentFilterPhrase Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Remove-ContentFilterPhrase Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Set-ContentFilterConfig Successfully Executed

[MSEXCHANGE-MANAGEMENT] antispam-antimalware Cmdlet Set-ContentFilterConfig Successfully Executed

signature-base unknown yara

SUSP_LNK_SuspiciousCommands [yara]

Detects LNK file with suspicious content

hayabusa medium sigma

Potential Persistence Via PowerShell User Profile Using Add-Content

Detects calls to "Add-Content" cmdlet in order to modify the content of the user profile and potentially adding suspicious commands for persistence

sigma medium sigma

Potential Persistence Via PowerShell User Profile Using Add-Content

Detects calls to "Add-Content" cmdlet in order to modify the content of the user profile and potentially adding suspicious commands for persistence

signature-base unknown yara

SUSP_APT_3CX_Regtrans_Anomaly_Apr23 [yara]

Detects suspicious .regtrans-ms files with suspicious size or contents

sagan medium other

[BOX] Shield detected an anomalous download, session, location, or malicious content

[BOX] Shield detected an anomalous download, session, location, or malicious content

sagan high other

[MSEXCHANGE-MANAGEMENT] defender-for-office-365 Cmdlet Get-ContentMalwareMdoAggregateReport Successfully Executed

[MSEXCHANGE-MANAGEMENT] defender-for-office-365 Cmdlet Get-ContentMalwareMdoAggregateReport Successfully Executed

sagan high other

[MSEXCHANGE-MANAGEMENT] defender-for-office-365 Cmdlet Get-ContentMalwareMdoDetailReport Successfully Executed

[MSEXCHANGE-MANAGEMENT] defender-for-office-365 Cmdlet Get-ContentMalwareMdoDetailReport Successfully Executed