Browse Rules

Search and filter across all detection sources

448 rules

sagan medium other

[EXTRAHOP] Command-and-Control Beaconing

[EXTRAHOP] Command-and-Control Beaconing

sagan critical other

[CISCO-SCA] Empire Command and Control

[CISCO-SCA] Empire Command and Control

sagan critical other

[CROWDSTRIKE] Command and Control Tactic Catchall

[CROWDSTRIKE] Command and Control Tactic Catchall

sagan critical other

[CISCO-SCA] Meterpreter Command and Control Success

[CISCO-SCA] Meterpreter Command and Control Success

sagan medium other

[CROWDSTRIKE] Possible Command And Control Blocked - Process Attempted To Establish Unusual Connection Over Commonly Used Port Possibly To Command And Control Server

[CROWDSTRIKE] Possible Command And Control Blocked - Process Attempted To Establish Unusual Connection Over Commonly Used Port Possibly To Command And Control Server

sagan medium other

[CROWDSTRIKE] Possible Command And Control Detected - Process Attempted To Establish Unusual Connection Over Commonly Used Port Possibly To Command And Control Server

[CROWDSTRIKE] Possible Command And Control Detected - Process Attempted To Establish Unusual Connection Over Commonly Used Port Possibly To Command And Control Server

sagan medium other

[CROWDSTRIKE] Possible Command And Control Killed - Process Attempted To Establish Unusual Connection Over Commonly Used Port Possibly To Command And Control Server

[CROWDSTRIKE] Possible Command And Control Killed - Process Attempted To Establish Unusual Connection Over Commonly Used Port Possibly To Command And Control Server

yara unknown yara

SLServer_command_and_control [malware]

elastic high eql

Deprecated - SUNBURST Command and Control Activity

The malware known as SUNBURST targets the SolarWind's Orion business software for command and control. This rule detects post-exploitation command and control activity of the SUNBURST backdoor.

chronicle high yara-l

AWS GuardDuty Command And Control Activity Detected

Amazon GuardDuty detects Command and control activity in Amazon EC2, AWS Lambda or Amazon EKS Runtimes.

elastic high kql

Possible FIN7 DGA Command and Control Behavior

This rule detects a known command and control pattern in network events. The FIN7 threat group is known to use this command and control technique, while maintaining persistence in their target's network.

sagan medium other

[CROWDSTRIKE] Possible Command And Control Blocked - Certutil Observed Downloading Files From Remote Location

[CROWDSTRIKE] Possible Command And Control Blocked - Certutil Observed Downloading Files From Remote Location

sagan medium other

[CROWDSTRIKE] Possible Command And Control Blocked - Executable Written In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Blocked - Executable Written In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Blocked -Network Access In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Blocked -Network Access In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Detected - Certutil Observed Downloading Files From Remote Location

[CROWDSTRIKE] Possible Command And Control Detected - Certutil Observed Downloading Files From Remote Location

sagan medium other

[CROWDSTRIKE] Possible Command And Control Detected - Executable Written In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Detected - Executable Written In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Killed - Certutil Observed Downloading Files From Remote Location

[CROWDSTRIKE] Possible Command And Control Killed - Certutil Observed Downloading Files From Remote Location

sagan medium other

[CROWDSTRIKE] Possible Command And Control Killed - Executable Written In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Killed - Executable Written In A Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In A Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In A Detection Summary Event

elastic high kql

Halfbaked Command and Control Beacon

Halfbaked is a malware family used to establish persistence in a contested network. This rule detects a network activity algorithm leveraged by Halfbaked implant beacons for command and control.

sagan medium other

[CROWDSTRIKE] Possible Command And Control Blocked - Network Access In An Epp Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Blocked - Network Access In An Epp Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In An Epp Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Detected - Network Access In An Epp Detection Summary Event

sagan medium other

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In An Epp Detection Summary Event

[CROWDSTRIKE] Possible Command And Control Killed - Network Access In An Epp Detection Summary Event

signature-base unknown yara

SLServer_command_and_control [yara]

Searches for the C2 server.