Browse Rules

Search and filter across all detection sources

5,203 rules

wazuh informational xml

OSSEC process monitoring rules.

OSSEC process monitoring rules.

wazuh informational xml

SQL Server process ID.

SQL Server process ID.

falconforce unknown kql

Process Injection From Untrusted Process

This query searches for processes performing remote process injection via multiple API calls related to process injection. It filters out programs that inject into their own process or into a process from the same directory. It then finds suspicious processes based on the global prevalence.

hayabusa high sigma

Suspicious Outlook Child Process

Detects a suspicious process spawning from an Outlook process.

sigma high sigma

Suspicious Outlook Child Process

Detects a suspicious process spawning from an Outlook process.

hayabusa high sigma

Suspicious Outlook Child Process

Detects a suspicious process spawning from an Outlook process.

hayabusa low sigma

Windows Processes Suspicious Parent Directory

Detect suspicious parent processes of well-known Windows processes

sigma low sigma

Windows Processes Suspicious Parent Directory

Detect suspicious parent processes of well-known Windows processes

sigma medium sigma

Process Monitor Driver Creation By Non-Sysinternals Binary

Detects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.

hayabusa high sigma

Suspicious Processes Spawned by WinRM

Detects suspicious processes including shells spawnd from WinRM host process

hayabusa low sigma

Windows Processes Suspicious Parent Directory

Detect suspicious parent processes of well-known Windows processes

sigma high sigma

Suspicious Processes Spawned by WinRM

Detects suspicious processes including shells spawnd from WinRM host process

hayabusa medium sigma

Process Monitor Driver Creation By Non-Sysinternals Binary

Detects creation of the Process Monitor driver by processes other than Process Monitor (procmon) itself.

sagan critical other

[WINDOWS-SECURITY] Parent process in the Downloads directory started a process

[WINDOWS-SECURITY] Parent process in the Downloads directory started a process

hayabusa high sigma

Abused Debug Privilege by Arbitrary Parent Processes

Detection of unusual child processes by different system processes

hayabusa low sigma

Suspicious Process Discovery With Get-Process

Get the processes that are running on the local computer.

hayabusa high sigma

Suspicious Processes Spawned by WinRM

Detects suspicious processes including shells spawnd from WinRM host process

sigma high sigma

Abused Debug Privilege by Arbitrary Parent Processes

Detection of unusual child processes by different system processes

sigma low sigma

Suspicious Process Discovery With Get-Process

Get the processes that are running on the local computer.

yara unknown yara

create_process [capabilities]

Create a new process

chronicle high yara-l

HackTool - Generic Process Access

Detects process access requests from hacktool processes based on their default image name

hayabusa high sigma

Abused Debug Privilege by Arbitrary Parent Processes

Detection of unusual child processes by different system processes

hayabusa high sigma

Suspicious HWP Sub Processes

Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation

sigma high sigma

HackTool - Generic Process Access

Detects process access requests from hacktool processes based on their default image name

sigma high sigma

Suspicious HWP Sub Processes

Detects suspicious Hangul Word Processor (Hanword) sub processes that could indicate an exploitation