Browse Rules

Search and filter across all detection sources

4,101 rules

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

[WINDOWS-SYSMON] Attack on Sysmon - SysmonEnte Detected

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - SysmonDrv Registry value set

[WINDOWS-SYSMON] Attack on Sysmon - SysmonDrv Registry value set

sagan high other

[WINDOWS-SYSMON] SYSMON Possible CMD detected

[WINDOWS-SYSMON] SYSMON Possible CMD detected

sagan high other

[WINDOWS-SYSMON] SYSMON Possible CMD detected

[WINDOWS-SYSMON] SYSMON Possible CMD detected

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - Process Injection

[WINDOWS-SYSMON] Attack on Sysmon - Process Injection

hayabusa high sigma

HackTool - SysmonEnte Execution

Detects the use of SysmonEnte, a tool to attack the integrity of Sysmon

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

sagan high other

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

[WINDOWS-SYSMON] Attack on Sysmon - Possible Driver Unload

sagan low other

Sysmon detected

Sysmon detected

sagan low other

Windows Sysmon detected

Windows Sysmon detected

sagan unknown other

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Mode Enabled (Sysmon RegistryEvent) - Critical

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Mode Enabled (Sysmon RegistryEvent) - Critical

hayabusa high sigma

Sysmon Driver Unloaded Via Fltmc.EXE

Detects possible Sysmon filter driver unloaded via fltmc.exe

sigma high sigma

HackTool - SysmonEnte Execution

Detects the use of SysmonEnte, a tool to attack the integrity of Sysmon

sagan unknown other

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Outbound Credentials Enabled (Sysmon RegistryEvent) - Critical

[WINDOWS-SYSMON] Windows Registry - Restricted Admin Outbound Credentials Enabled (Sysmon RegistryEvent) - Critical

hayabusa high sigma

Sysmon Configuration Modification

Detects when an attacker tries to hide from Sysmon by disabling or stopping it

hayabusa high sigma

Uninstall Sysinternals Sysmon

Detects the removal of Sysmon, which could be a potential attempt at defense evasion

hayabusa high sigma

Sysmon Blocked Executable

Triggers on any Sysmon "FileBlockExecutable" event, which indicates a violation of the configured block policy

hayabusa high sigma

Sysmon Blocked File Shredding

Triggers on any Sysmon "FileBlockShredding" event, which indicates a violation of the configured shredding policy.

hayabusa medium sigma

Sysmon Configuration Update

Detects updates to Sysmon's configuration. Attackers might update or replace the Sysmon configuration with a bare bone one to avoid monitoring without shutting down the service completely

hayabusa high sigma

Sysmon Configuration Error

Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages

sagan high other

[WINDOWS-SYSMON] Evilginx2 Certificate Operations

[WINDOWS-SYSMON] Evilginx2 Certificate Operations

sagan critical other

[WINDOWS-SYSMON] KeePass Password Dumping

[WINDOWS-SYSMON] KeePass Password Dumping

sagan critical other

[WINDOWS-SYSMON] MSHTA executing powershell

[WINDOWS-SYSMON] MSHTA executing powershell

sagan critical other

[WINDOWS-SYSMON] MSHTA executing wscript

[WINDOWS-SYSMON] MSHTA executing wscript