Browse Rules

Search and filter across all detection sources

343 rules

wazuh low xml

Replace Malicious code: Malicious code in the connection was replaced.

Replace Malicious code: Malicious code in the connection was replaced.

sagan critical other

[FORTINET] Malicious Code Detected

[FORTINET] Malicious Code Detected

sagan unknown other

[CHECKPOINT] Action Replace Malicious Code

[CHECKPOINT] Action Replace Malicious Code

sagan critical other

[FORTINET] Malicious Code Detected - Direction Outgoing

[FORTINET] Malicious Code Detected - Direction Outgoing

sigma high sigma

Potential Persistence Via Outlook Form

Detects the creation of a new Outlook form which can contain malicious code

hayabusa high sigma

Potential Persistence Via Outlook Form

Detects the creation of a new Outlook form which can contain malicious code

sekoia-rules medium sigma

Suspicious PowerShell Keywords

Detects keywords that could indicate the use of some PowerShell exploitation framework.

sigma medium sigma

Systemd Service Creation

Detects a creation of systemd services which could be used by adversaries to execute malicious code.

hayabusa medium sigma

Powershell Create Scheduled Task

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code

sekoia-rules medium sigma

Microsoft Defender Antivirus Threat Detected

Detection of a Microsoft Defender Antivirus (MDAV) alert indicating the presence of potential malware

sigma medium sigma

Powershell Create Scheduled Task

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code

signature-base unknown yara

Wordpress_Config_Webshell_Preprend [yara]

Webshell that uses standard Wordpress wp-config.php file and appends the malicious code in front of it

elastic-protections high eql

Potential DLL Hollowing from a Writable Image

Identifies attempts to stealthily execute malicious code using DLL hollowing technique from a writable image.

sigma medium sigma

Unsigned DLL Loaded by Windows Utility

Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.

elastic-protections high eql

Command Shell Activity Started via RunDLL32

Identifies command shell activity started via RunDLL32, which is commonly abused by attackers to host malicious code.

hayabusa medium sigma

Unsigned DLL Loaded by Windows Utility

Detects windows utilities loading an unsigned or untrusted DLL. Adversaries often abuse those programs to proxy execution of malicious code.

splunk unknown spl

Windows LOLBAS Executed Outside Expected Path

The following analytic identifies a LOLBAS process being executed outside of it's expected location. Processes being executed outside of expected locations may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.

elastic-protections high eql

Scriptlet Execution via Rundll32

Identifies when scrobj.dll is loaded into rundll32.exe. An adversary may abuse rundll32.exe to proxy execution of malicious code.

sublime medium mql

Attachment: Embedded VBScript in MHT file

MHT files can be used to run VBScript, which can run malicious code.

sigma high sigma

Raw Paste Service Access

Detects direct access to raw pastes in different paste services often used by malware in their second stages to download malicious code in encrypted or encoded form

splunk unknown spl

Windows LOLBAS Executed As Renamed File

The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.

elastic-protections high eql

Suspicious Windows Script Interpreter Child Process

Identifies unusual windows script interpreter child process which could indicate code injection or other form of malicious code execution via Windows scripts.

sekoia-rules high other

ISO LNK Infection Chain

Detection of an ISO download followed by a child-process of explorer, which is characteristic of an infection using an ISO containing an LNK file.

car unknown spl

Registry Edit from Screensaver

Adversaries may use screensaver files to run malicious code. This analytic triggers on suspicious edits to the screensaver registry keys, which dictate which .scr file the screensaver runs.

elastic-protections high eql

Java Drop followed by network activity

Identifies attempts to execute a JAVA application that was recently dropped followed by network connection. Adversaries may abuse this utility to execute malicious code.