Browse Rules

Search and filter across all detection sources

2,003 rules

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

sagan low other

Windows Sysmon detected

Windows Sysmon detected

sagan high other

[WINDOWS-SYSMON] SYSMON Possible CMD detected

[WINDOWS-SYSMON] SYSMON Possible CMD detected

sagan high other

[WINDOWS-SYSMON] SYSMON Possible CMD detected

[WINDOWS-SYSMON] SYSMON Possible CMD detected

sagan unknown other

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Mode Enabled (Sysmon RegistryEvent) - Critical

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Mode Enabled (Sysmon RegistryEvent) - Critical

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - SysmonDrv Registry value set

[WINDOWS-SYSMON] Attack on Sysmon - SysmonDrv Registry value set

sagan unknown other

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Outbound Credentials Enabled (Sysmon RegistryEvent) - Critical

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Outbound Credentials Enabled (Sysmon RegistryEvent) - Critical

sagan unknown other

[WINDOWS-SYSMON] Windows Event Log Cleared

[WINDOWS-SYSMON] Windows Event Log Cleared

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - Process Injection

[WINDOWS-SYSMON] Attack on Sysmon - Process Injection

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

sagan unknown other

[WINDOWS-SYSMON] Windows Defender has detected malware (High)

[WINDOWS-SYSMON] Windows Defender has detected malware (High)

sagan critical other

[WINDOWS-SYSMON] Windows Defender has detected malware (Severe)

[WINDOWS-SYSMON] Windows Defender has detected malware (Severe)

sagan high other

[WINDOWS-SYSMON] Evilginx2 Certificate Operations

[WINDOWS-SYSMON] Evilginx2 Certificate Operations

sagan critical other

[WINDOWS-SYSMON] KeePass Password Dumping

[WINDOWS-SYSMON] KeePass Password Dumping

sagan critical other

[WINDOWS-SYSMON] MSHTA executing powershell

[WINDOWS-SYSMON] MSHTA executing powershell

sagan critical other

[WINDOWS-SYSMON] MSHTA executing wscript

[WINDOWS-SYSMON] MSHTA executing wscript

sagan critical other

[WINDOWS-SYSMON] Nltest Discovery Commands

[WINDOWS-SYSMON] Nltest Discovery Commands

sagan unknown other

[WINDOWS-SYSMON] Possible hidden service installed

[WINDOWS-SYSMON] Possible hidden service installed

sagan critical other

[WINDOWS-SYSMON] PowerShell BitsTransfer Detected

[WINDOWS-SYSMON] PowerShell BitsTransfer Detected

sagan high other

[WINDOWS-SYSMON] PSExec execution detected

[WINDOWS-SYSMON] PSExec execution detected

sagan high other

[WINDOWS-SYSMON] PSExec execution detected

[WINDOWS-SYSMON] PSExec execution detected

sagan critical other

[WINDOWS-SYSMON] Registry Hive Dump

[WINDOWS-SYSMON] Registry Hive Dump

sagan critical other

[WINDOWS-SYSMON] Reverse rundll command

[WINDOWS-SYSMON] Reverse rundll command