Browse Rules

Search and filter across all detection sources

39 rules

wazuh informational xml

Serv-U: File downloaded

Serv-U: File downloaded

wazuh informational xml

Serv-U: File uploaded

Serv-U: File uploaded

wazuh informational xml

Serv-U: File deleted

Serv-U: File deleted

wazuh informational xml

Serv-U: Directory created

Serv-U: Directory created

wazuh informational xml

Serv-U: Directory deleted

Serv-U: Directory deleted

wazuh informational xml

Serv-U: File/Directory renamed

Serv-U: File/Directory renamed

wazuh low xml

Syscheck Audit: $(extra_data)

Syscheck Audit: $(extra_data)

wazuh low xml

A Windows log file was cleared

A Windows log file was cleared

wazuh low xml

A Windows log file was cleared

A Windows log file was cleared

wazuh low xml

The audit log was cleared

The audit log was cleared

wazuh informational xml

Audit: Created: $(audit.file.name)

Audit: Created: $(audit.file.name)

wazuh informational xml

Audit: Deleted: $(audit.file.name)

Audit: Deleted: $(audit.file.name)

wazuh low xml

The audit log was cleared

The audit log was cleared

wazuh medium xml

Microsoft Event log cleared.

Microsoft Event log cleared.

wazuh low xml

File deleted.

File deleted.

wazuh low xml

Integrity checksum changed.

Integrity checksum changed.

wazuh informational xml

Log file rotated.

Log file rotated.

wazuh low xml

Registry Key Entry Deleted.

Registry Key Entry Deleted.

wazuh low xml

Registry Value Entry Deleted.

Registry Value Entry Deleted.

wazuh low xml

File added to the system.

File added to the system.

wazuh low xml

Registry Key Integrity Checksum Changed

Registry Key Integrity Checksum Changed

wazuh low xml

Registry Value Integrity Checksum Changed

Registry Value Integrity Checksum Changed

wazuh low xml

Registry Key Entry Added to the System

Registry Key Entry Added to the System

wazuh low xml

Registry Value Entry Added to the System

Registry Value Entry Added to the System

wazuh informational xml

Windows Defender: Antimalware platform restored an item from quarantine at $(win.eventdata.path)

Windows Defender: Antimalware platform restored an item from quarantine at $(win.eventdata.path)