Browse Rules

Search and filter across all detection sources

7,976 rules

sagan high other

[WINDOWS-SECURITY] Disable Windows Security

[WINDOWS-SECURITY] Disable Windows Security

sagan high other

[WINDOWS-CLIPBOARD] Disable Windows Defender Command

[WINDOWS-CLIPBOARD] Disable Windows Defender Command

sagan high other

[WINDOWS-CLIPBOARD] Disable Windows Defender Command

[WINDOWS-CLIPBOARD] Disable Windows Defender Command

sagan high other

[WINDOWS-CLIPBOARD] Uninstall Windows Defender Command

[WINDOWS-CLIPBOARD] Uninstall Windows Defender Command

sagan high other

[WINDOWS-CLIPBOARD] Uninstall Windows Defender Command

[WINDOWS-CLIPBOARD] Uninstall Windows Defender Command

sagan critical other

[WINDOWS-GEOIP] Attempted explicit windows logon

[WINDOWS-GEOIP] Attempted explicit windows logon

sagan unknown other

[WINDOWS-POWERSHELL] Possible Windows Policy Enumeration

[WINDOWS-POWERSHELL] Possible Windows Policy Enumeration

sagan critical other

[WINDOWS-SECURITY] Disable Windows Defender Logging

[WINDOWS-SECURITY] Disable Windows Defender Logging

sagan unknown other

[WINDOWS-SYSMON] Windows Event Log Cleared

[WINDOWS-SYSMON] Windows Event Log Cleared

sagan unknown other

[WINDOWS-SECURITY] Windows Registry - Restricted Admin Mode Enabled (Windows Security Audit) - Critical

[WINDOWS-SECURITY] Windows Registry - Restricted Admin Mode Enabled (Windows Security Audit) - Critical

sagan unknown other

[WINDOWS-SECURITY] Windows Registry - Restricted Admin Outbound Credentials Enabled (Windows Security Audit) - Critical

[WINDOWS-SECURITY] Windows Registry - Restricted Admin Outbound Credentials Enabled (Windows Security Audit) - Critical

sagan critical other

[WINDOWS-AETAS] Windows Logon at suspicious time

[WINDOWS-AETAS] Windows Logon at suspicious time

sagan critical other

[WINDOWS-AETAS] Windows Logon at suspicious time

[WINDOWS-AETAS] Windows Logon at suspicious time

sagan informational other

[WINDOWS-MISC] Windows audit log was cleared

[WINDOWS-MISC] Windows audit log was cleared

sagan critical other

[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell

[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell

sagan critical other

[WINDOWS-POWERSHELL] Windows Defender Uninstalled via PowerShell

[WINDOWS-POWERSHELL] Windows Defender Uninstalled via PowerShell

sagan critical other

[WINDOWS-POWERSHELL] Windows Firewall Restarted via PowerShell

[WINDOWS-POWERSHELL] Windows Firewall Restarted via PowerShell

sagan critical other

[WINDOWS-SECURITY] Disable Windows Defender Scheduled Tasks

[WINDOWS-SECURITY] Disable Windows Defender Scheduled Tasks

sagan critical other

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

sagan critical other

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

sagan critical other

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

sagan critical other

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)

sagan unknown other

[WINDOWS-SYSMON] Windows Defender has detected malware (High)

[WINDOWS-SYSMON] Windows Defender has detected malware (High)

sagan critical other

[WINDOWS-GEOIP] Windows Logon outside of HOME_COUNTRY

[WINDOWS-GEOIP] Windows Logon outside of HOME_COUNTRY

sagan critical other

[WINDOWS-GEOIP] Windows Logon outside of HOME_COUNTRY

[WINDOWS-GEOIP] Windows Logon outside of HOME_COUNTRY