EXPLORE

EXPLORE DETECTIONS

🔍
3,281 detections found

Octopus Scanner Malware

Detects Octopus Scanner Malware.

T1195T1195.001
Sigmahigh

Odbcconf.EXE Suspicious DLL Location

Detects execution of "odbcconf" where the path of the DLL being registered is located in a potentially suspicious location.

T1218.008
Sigmahigh

Office Application Initiated Network Connection Over Uncommon Ports

Detects an office suit application (Word, Excel, PowerPoint, Outlook) communicating to target systems over uncommon ports.

Sigmamedium

Office Application Initiated Network Connection To Non-Local IP

Detects an office application (Word, Excel, PowerPoint) that initiate a network connection to a non-private IP addresses. This rule aims to detect traffic similar to one seen exploited in CVE-2021-42292. This rule will require an initial baseline and tuning that is specific to your organization.

T1203
Sigmamedium

Office Application Startup - Office Test

Detects the addition of office test registry that allows a user to specify an arbitrary DLL that will be executed every time an Office application is started

T1137.002
Sigmamedium

Office Autorun Keys Modification

Detects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened. There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive. Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.

T1547.001
Sigmamedium

Office Macro File Creation

Detects the creation of a new office macro files on the systems

T1566.001
Sigmalow

Office Macro File Creation From Suspicious Process

Detects the creation of a office macro file from a a suspicious process

T1566.001
Sigmahigh

Office Macro File Download

Detects the creation of a new office macro files on the system via an application (browser, mail client). This can help identify potential malicious activity, such as the download of macro-enabled documents that could be used for exploitation.

T1566.001
Sigmalow

Office Macros Warning Disabled

Detects registry changes to Microsoft Office "VBAWarning" to a value of "1" which enables the execution of all macros, whether signed or unsigned.

T1112
Sigmahigh

Okta Admin Functions Access Through Proxy

Detects access to Okta admin functions through proxy.

Sigmamedium

Okta Admin Role Assigned to an User or Group

Detects when an the Administrator role is assigned to an user or group.

T1098.003
Sigmamedium

Okta Admin Role Assignment Created

Detects when a new admin role assignment is created. Which could be a sign of privilege escalation or persistence

Sigmamedium

Okta API Token Created

Detects when a API token is created

Sigmamedium

Okta API Token Revoked

Detects when a API Token is revoked.

Sigmamedium

Okta Application Modified or Deleted

Detects when an application is modified or deleted.

Sigmamedium

Okta Application Sign-On Policy Modified or Deleted

Detects when an application Sign-on Policy is modified or deleted.

Sigmamedium

Okta Identity Provider Created

Detects when a new identity provider is created for Okta.

T1098.001
Sigmamedium

Okta MFA Reset or Deactivated

Detects when an attempt at deactivating or resetting MFA.

T1556.006
Sigmamedium

Okta Network Zone Deactivated or Deleted

Detects when an Network Zone is Deactivated or Deleted.

Sigmamedium

Okta New Admin Console Behaviours

Detects when Okta identifies new activity in the Admin Console.

T1078.004
Sigmahigh

Okta Password Health Report Query

Detects all activities against the endpoint "/reports/password-health/*" which should only be accessed via OKTA Admin Console UI. Use this rule to hunt for potential suspicious requests. Correlate this event with "admin console" login and alert on requests without any corresponding admin console login

Sigmalow

Okta Policy Modified or Deleted

Detects when an Okta policy is modified or deleted.

Sigmalow

Okta Policy Rule Modified or Deleted

Detects when an Policy Rule is Modified or Deleted.

Sigmamedium
PreviousPage 60 of 137Next