Search and filter across all detection sources
331 rules
Net.EXE Execution
Detects execution of "Net.EXE".
PsExec Default Named Pipe
Detects PsExec service default pipe creation
File Download Via Curl.EXE
Detects file download using curl.exe
Uncommon PowerShell Hosts
Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
Amsi.DLL Load By Uncommon Process
Detects loading of Amsi.dll by uncommon processes
Microsoft Excel Add-In Loaded
Detects Microsoft Excel loading an Add-In (.xll) file
Curl.EXE Execution With Custom UserAgent
Detects execution of curl.exe with custom useragent options
WMI Module Loaded By Uncommon Process
Detects WMI modules being loaded by an uncommon process
Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet
Detects email forwarding or redirecting activity via ExchangePowerShell Cmdlet
Creation of an Executable by an Executable
Detects the creation of an executable by another executable.
Mail Forwarding/Redirecting Activity In O365
Detects email forwarding or redirecting activity in O365 Audit logs.
Potentially Suspicious Compression Tool Parameters
Detects potentially suspicious command line arguments of common data compression tools
WebDAV Temporary Local File Creation
Detects the creation of WebDAV temporary files with potentially suspicious extensions