Search and filter across all detection sources
28 rules
Virtual machine being turned ON.
Virtual machine state changed to ON.
Host information added.
Fortigate: Firewall configuration changes
Host information changed.
Windows: System time changed.
Virtual machine being reconfigured.
Virtual machine state changed to OFF.
ASA: Firewall configuration deleted.
ASA: Firewall configuration changed.
Fortigate: Multiple Firewall edit events from same source.
Host Blocked by $(script) Active Response
Host Unblocked by $(script) Active Response
Host Blocked by firewall-drop.sh Active Response
Host Unblocked by firewall-drop.sh Active Response
Host Blocked by host-deny.sh Active Response
Host Unblocked by host-deny.sh Active Response
ASA: User created or modified on the Firewall.
Registry Key Entry Deleted.
Registry Value Entry Deleted.
Registry Key Integrity Checksum Changed
Registry Value Integrity Checksum Changed
Registry Key Entry Added to the System
Registry Value Entry Added to the System
PIX: Firewall configuration deleted.