Search and filter across all detection sources
7,976 rules
[WINDOWS-SECURITY] Disable Windows Security
[WINDOWS-CLIPBOARD] Disable Windows Defender Command
[WINDOWS-CLIPBOARD] Uninstall Windows Defender Command
[WINDOWS-GEOIP] Attempted explicit windows logon
[WINDOWS-POWERSHELL] Possible Windows Policy Enumeration
[WINDOWS-SECURITY] Disable Windows Defender Logging
[WINDOWS-SYSMON] Windows Event Log Cleared
[WINDOWS-SECURITY] Windows Registry - Restricted Admin Mode Enabled (Windows Security Audit) - Critical
[WINDOWS-SECURITY] Windows Registry - Restricted Admin Outbound Credentials Enabled (Windows Security Audit) - Critical
[WINDOWS-AETAS] Windows Logon at suspicious time
[WINDOWS-MISC] Windows audit log was cleared
[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell
[WINDOWS-POWERSHELL] Windows Defender Uninstalled via PowerShell
[WINDOWS-POWERSHELL] Windows Firewall Restarted via PowerShell
[WINDOWS-SECURITY] Disable Windows Defender Scheduled Tasks
[WINDOWS-MALWARE] Shade ransomware file extension detected (.windows10)
[WINDOWS-SYSMON] Windows Defender has detected malware (High)
[WINDOWS-GEOIP] Windows Logon outside of HOME_COUNTRY