Search and filter across all detection sources
39 rules
Serv-U: File downloaded
Serv-U: File uploaded
Serv-U: File deleted
Serv-U: Directory created
Serv-U: Directory deleted
Serv-U: File/Directory renamed
Syscheck Audit: $(extra_data)
A Windows log file was cleared
The audit log was cleared
Audit: Created: $(audit.file.name)
Audit: Deleted: $(audit.file.name)
Microsoft Event log cleared.
File deleted.
Integrity checksum changed.
Log file rotated.
Registry Key Entry Deleted.
Registry Value Entry Deleted.
File added to the system.
Registry Key Integrity Checksum Changed
Registry Value Integrity Checksum Changed
Registry Key Entry Added to the System
Registry Value Entry Added to the System
Windows Defender: Antimalware platform restored an item from quarantine at $(win.eventdata.path)