Browse Rules

Search and filter across all detection sources

331 rules

hayabusa low sigma

Net.EXE Execution

Detects execution of "Net.EXE".

sigma low sigma

Net.EXE Execution

Detects execution of "Net.EXE".

hayabusa low sigma

Net.EXE Execution

Detects execution of "Net.EXE".

sigma low sigma

PsExec Default Named Pipe

Detects PsExec service default pipe creation

hayabusa medium sigma

File Download Via Curl.EXE

Detects file download using curl.exe

hayabusa low sigma

PsExec Default Named Pipe

Detects PsExec service default pipe creation

sigma medium sigma

File Download Via Curl.EXE

Detects file download using curl.exe

hayabusa medium sigma

File Download Via Curl.EXE

Detects file download using curl.exe

hayabusa medium sigma

Uncommon PowerShell Hosts

Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe

sigma low sigma

Amsi.DLL Load By Uncommon Process

Detects loading of Amsi.dll by uncommon processes

sigma low sigma

Microsoft Excel Add-In Loaded

Detects Microsoft Excel loading an Add-In (.xll) file

sigma medium sigma

Uncommon PowerShell Hosts

Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe

hayabusa low sigma

Amsi.DLL Load By Uncommon Process

Detects loading of Amsi.dll by uncommon processes

hayabusa medium sigma

Curl.EXE Execution With Custom UserAgent

Detects execution of curl.exe with custom useragent options

hayabusa low sigma

Microsoft Excel Add-In Loaded

Detects Microsoft Excel loading an Add-In (.xll) file

sigma medium sigma

Curl.EXE Execution With Custom UserAgent

Detects execution of curl.exe with custom useragent options

sigma low sigma

WMI Module Loaded By Uncommon Process

Detects WMI modules being loaded by an uncommon process

hayabusa medium sigma

Curl.EXE Execution With Custom UserAgent

Detects execution of curl.exe with custom useragent options

hayabusa medium sigma

Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet

Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet

hayabusa low sigma

WMI Module Loaded By Uncommon Process

Detects WMI modules being loaded by an uncommon process

sigma low sigma

Creation of an Executable by an Executable

Detects the creation of an executable by another executable.

sigma medium sigma

Mail Forwarding/Redirecting Activity In O365

Detects email forwarding or redirecting activity in O365 Audit logs.

sigma medium sigma

Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet

Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet

sigma medium sigma

Potentially Suspicious Compression Tool Parameters

Detects potentially suspicious command line arguments of common data compression tools

sigma medium sigma

WebDAV Temporary Local File Creation

Detects the creation of WebDAV temporary files with potentially suspicious extensions