Browse Rules

Search and filter across all detection sources

14 rules

sagan informational other

[SOPHOS] Malicious traffic detected

[SOPHOS] Malicious traffic detected

sagan informational other

[SOPHOS] Malicious traffic detected

[SOPHOS] Malicious traffic detected

sagan medium other

[DARKTRACE] Potential Malicious traffic detection

[DARKTRACE] Potential Malicious traffic detection

sagan informational other

[SOPHOS] Malicious traffic detection locally cleared

[SOPHOS] Malicious traffic detection locally cleared

sagan informational other

[SOPHOS] Sophos Firewall detected malicious traffic

[SOPHOS] Sophos Firewall detected malicious traffic

sentinel high kql

VMware SD-WAN Edge - IDS/IPS Alert triggered (Syslog)

The VMware SD-WAN Edge appliance captured a potentially malicious traffic flow. Please investigate the IOC information available. This analytics rule analyzes Syslog streams.

sekoia-rules low sigma

Dynamic DNS Contacted

Detect communication with dynamic dns domain. This kind of domain is often used by attackers. This rule can trigger false positive in non-controlled environment because dynamic dns is not always malicious.

sentinel high kql

VMware SD-WAN Edge - IDS/IPS Alert triggered (Search API)

The VMware SD-WAN Edge appliance captured a potentially malicious traffic flow. Please investigate the IOC information available. This analytics rule analyses Search API streams. Search API queries report only IDS/IPS Alerts. In case you would also need Network Flood Protection, please enable Syslog collection using AMA.

panther high python

Azure Firewall Policy Deleted

Detects when an Azure Firewall policy is deleted. Firewall policies define critical network security rules that control traffic flow and protect resources. Adversaries may delete firewall policies to disable network security controls, allow malicious traffic, or enable data exfiltration. This activity is a strong indicator of defense evasion or preparation for follow-on attacks.

splunk unknown spl

Windows Firewall Rule Modification

This detection identifies instances where a Windows Firewall rule has been modified, which may indicate an attempt to alter security policies. Unauthorized modifications can weaken firewall protections, allowing malicious traffic or preventing legitimate communications. The event logs details such as the modified rule name, protocol, ports, application path, and the user responsible for the change. Security teams should monitor unexpected modifications, correlate them with related events, and in

splunk unknown spl

LOLBAS Network Connection On Uncommon Port

The following analytic identifies Living Off the Land Binaries and Scripts (LOLBAS) that can legitimately initiate public network connections but are communicating over uncommon destination ports. It leverages the Network Traffic data model and applies per-binary common-port exclusions to reduce false positives while preserving suspicious non-standard communication. This behavior may indicate payload download, command-and-control, proxy execution, or attempts to blend malicious traffic into trus

splunk unknown spl

Windows Multi hop Proxy TOR Website Query

The following analytic identifies DNS queries to known TOR proxy websites, such as "*.torproject.org" and "www.theonionrouter.com". It leverages Sysmon EventCode 22 to detect these queries by monitoring DNS query events from endpoints. This activity is significant because adversaries often use TOR proxies to disguise the source of their malicious traffic, making it harder to trace their actions. If confirmed malicious, this behavior could indicate an attempt to obfuscate network traffic, potenti

elastic low eql

Connection to Commonly Abused Web Services

Adversaries may implement command and control (C2) communications that use common web services to hide their activity. This attack technique is typically targeted at an organization and uses web services common to the victim network, which allows the adversary to blend into legitimate traffic activity. These popular services are typically targeted since they have most likely been used before compromise, which helps malicious traffic blend in.

elastic low eql

DNS to Commonly Abused Web Services

Adversaries may implement command and control (C2) communications that use common web services to hide their activity. This attack technique is typically targeted at an organization and uses web services common to the victim network, which allows the adversary to blend into legitimate traffic activity. These popular services are typically targeted since they have most likely been used before compromise, which helps malicious traffic blend in.