Browse Rules

Search and filter across all detection sources

520 rules

sagan critical other

[WINDOWS-SYSMON] Process started from ProgramData with Network Connection Port 389

[WINDOWS-SYSMON] Process started from ProgramData with Network Connection Port 389

sagan informational other

[DELL EMC UNITY] STORAGE PROCESSOR RESTARTING

[DELL EMC UNITY] STORAGE PROCESSOR RESTARTING

hayabusa high sigma

Network Connection Initiated By Eqnedt32.EXE

Detects network connections from the Equation Editor process "eqnedt32.exe".

sigma high sigma

Network Connection Initiated By Eqnedt32.EXE

Detects network connections from the Equation Editor process "eqnedt32.exe".

anvilogic high spl

Unexpected Network Connection from System Process [splunk-winevent]

Threat actors may abuse legitimate system processes that typically lack network functionality to perform malicious network activity, helping evade detection and blend in with normal system behavior. This technique is often associated with process injection or masquerading, where code is executed within trusted processes to establish command-and-control (C2) channels or exfiltrate data. This use case detects instances where non-networking system processes (e.g., conhost.exe, lsass.exe, wininit.ex

hayabusa high sigma

Network Connection Initiated Via Notepad.EXE

Detects a network connection that is initiated by the "notepad.exe" process. This might be a sign of process injection from a beacon process or something similar. Notepad rarely initiates a network communication except when printing documents for example.

sigma high sigma

Network Connection Initiated Via Notepad.EXE

Detects a network connection that is initiated by the "notepad.exe" process. This might be a sign of process injection from a beacon process or something similar. Notepad rarely initiates a network communication except when printing documents for example.

hayabusa high sigma

Network Connection Initiated By Eqnedt32.EXE

Detects network connections from the Equation Editor process "eqnedt32.exe".

elastic-protections high eql

Network Activity from a Reflected Process

Identifies the creation of process clone via the Windows API RtlCreateProcessReflection followed by network activity. This may indicate an attempt to create a process as a target for process injection.

hayabusa high sigma

Network Connection Initiated Via Notepad.EXE

Detects a network connection that is initiated by the "notepad.exe" process. This might be a sign of process injection from a beacon process or something similar. Notepad rarely initiates a network communication except when printing documents for example.

elastic-protections high eql

Network Connection Following Ptrace Manipulation

This rule detects a process attempting a network connection shortly after its memory or register state was modified by another process through ptrace. This behavior may indicate successful process injection followed by network activity from the injected payload.

splunk unknown spl

Cisco NVM - Non-Network Binary Making Network Connection

This analytic detects network connections initiated by binaries that are not typically associated with network communication, such as 'notepad.exe', 'calc.exe' or 'write.exe'. It leverages Cisco Network Visibility Module logs to correlate network flow activity with process context, including command-line arguments, process path, and parent process information. These applications are normally used for locally and do not require outbound network access. When they do initiate such connections, it m

hayabusa high sigma

Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location

Detects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.

sigma high sigma

Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location

Detects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.

hayabusa high sigma

Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location

Detects a network connection initiated by programs or processes running from suspicious or uncommon files system locations.

anvilogic high spl

Unexpected Network Connection from System Process [splunk-sysmon]

Threat actors may abuse legitimate system processes that typically lack network functionality to perform malicious network activity, helping evade detection and blend in with normal system behavior. This technique is often associated with process injection or masquerading, where code is executed within trusted processes to establish command-and-control (C2) channels or exfiltrate data. This use case detects instances where non-networking system processes (e.g., conhost.exe, lsass.exe, wininit.ex

hayabusa medium sigma

Outbound Network Connection To Public IP Via Winlogon

Detects a "winlogon.exe" process that initiate network communications with public IP addresses

sigma medium sigma

Outbound Network Connection To Public IP Via Winlogon

Detects a "winlogon.exe" process that initiate network communications with public IP addresses

hayabusa medium sigma

Outbound Network Connection To Public IP Via Winlogon

Detects a "winlogon.exe" process that initiate network communications with public IP addresses

elastic low eql

Unusual Linux Network Activity

Identifies Linux processes that do not usually use the network but have unexpected network activity, which can indicate command-and-control, lateral movement, persistence, or data exfiltration activity. A process with unusual network activity can denote process exploitation or injection, where the process is used to run persistence mechanisms that allow a malicious actor remote access or control of the host, data exfiltration, and execution of unauthorized network applications.

wazuh medium xml

IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces

IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces

elastic-protections high eql

Network Connection via Process with Unusual Arguments

Identifies suspicious network connections from Windows processes that typically have more than one command line argument. This may be indicative of a masquerading attempt to evade detections that monitor for suspicious parent-child process relationships.

anvilogic high other

Possible Credential Dumping via Windows Network Providers [snowflake-crowdstrikefdr_process]

A Network Provider is a Windows component that facilitates the connection, communication, and resource sharing between a system and a network. Threat actors can create a rogue Network Provider to capture or "dump" credentials by intercepting and logging network authentication requests, such as NPPSpy. This use case detects modifications to registry values for Network Providers. Atomics T1003 Test #2

sigma high sigma

Suspicious Child Process Created as System

Detection of child processes spawned with SYSTEM privileges by parents with LOCAL SERVICE or NETWORK SERVICE accounts

sigma high sigma

Aruba Network Service Potential DLL Sideloading

Detects potential DLL sideloading activity via the Aruba Networks Virtual Intranet Access "arubanetsvc.exe" process using DLL Search Order Hijacking