Browse Rules

Search and filter across all detection sources

1,573 rules

sagan medium other

[PROFTPD] Host name or host address mismatch

[PROFTPD] Host name or host address mismatch

sagan low other

Hostapd detected

Hostapd detected

sagan informational other

[VEEAM] Host Deleted

[VEEAM] Host Deleted

wazuh informational xml

sshd: Host ungracefully disconnected.

sshd: Host ungracefully disconnected.

wazuh informational xml

sshd: No hostkey alg.

sshd: No hostkey alg.

loldrivers low sigma

Driver Load - HOSTNT.sys

Detects loading of driver HOSTNT.sys via name. Hostnt 64-bit driver

loldrivers high sigma

Driver Load - HOSTNT.sys

Detects loading of driver HOSTNT.sys via hash. Hostnt 64-bit driver

sagan unknown other

[FORTINET] Compromised Host Detected

[FORTINET] Compromised Host Detected

sagan unknown other

[FORTINET] Compromised Host Detected

[FORTINET] Compromised Host Detected

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): Address $(osquery.columns.address) Hostnames $(osquery.columns.hostnames)

osquery: $(osquery.pack) $(osquery.subquery): Address $(osquery.columns.address) Hostnames $(osquery.columns.hostnames)

wazuh low xml

osquery: $(osquery.pack) $(osquery.subquery): User $(osquery.columns.username) host $(osquery.columns.host)

osquery: $(osquery.pack) $(osquery.subquery): User $(osquery.columns.username) host $(osquery.columns.host)

hayabusa low sigma

Suspicious Execution of Hostname

Use of hostname to get information

sagan critical other

[FORTINET] Compromised Host Detected

[FORTINET] Compromised Host Detected

sagan critical other

[FORTINET] Compromised Host Detected

[FORTINET] Compromised Host Detected

sagan medium other

[HOSTAPD] Possible downgrade attack

[HOSTAPD] Possible downgrade attack

sagan low other

[HOSTAPD] Possible downgrade attack

[HOSTAPD] Possible downgrade attack

sagan informational other

[VEEAM] Hypervisor Host Deleted

[VEEAM] Hypervisor Host Deleted

sagan unknown other

[WEBLABYRINTH] New host logged!

[WEBLABYRINTH] New host logged!

sigma low sigma

Suspicious Execution of Hostname

Use of hostname to get information

wazuh low xml

sshd: no route to host

sshd: no route to host

hayabusa low sigma

Suspicious Execution of Hostname

Use of hostname to get information

sentinel low kql

API - Invalid host access

'42Crunch API protection against invalid host access'

sentinel high kql

Cisco SE - Malware execusion on host

'Detects malware execution on host.'

signature-base unknown yara

CobaltStrike_C2_Host_Indicator [yara]

Detects CobaltStrike C2 host artifacts

chronicle unknown yara-l

suspicious_change_in_hosts_file

Write event to the Windows host file