Regex ID | Rule Name | Rule Type | Common Event | Classification |
---|
1009183 | HX Messages | Base Rule | General Firewall Log | Network Traffic |
Host Acquisition Successfully Completed | Sub Rule | Object Operation | Other Audit Success |
Host Acquisition Successfully Queued | Sub Rule | Object Operation | Other Audit Success |
Host Acquisition Successfully Started | Sub Rule | Object Operation | Other Audit Success |
IOC Hit Found | Sub Rule | Host Compromised | Compromise |
IOC Hit Found : Not Malicious | Sub Rule | Suspicious Activity | Suspicious |
IOC Hit Found : TOR Exit Node | Sub Rule | Network Compromised | Compromise |
IOC Hit Found : TOR Exit Node | Sub Rule | Network Compromised | Compromise |
IOC Hit Found : Ransomware | Sub Rule | Host Compromised | Compromise |
IOC Hit Found : Suspicious WScript Usage | Sub Rule | Host Compromised | Compromise |
IOC Hit Found : CCLEANER Trojan | Sub Rule | Host Compromised | Compromise |
IOC Hit Found : Trojan.JS.Nemucod | Sub Rule | Detected Trojan Activity | Malware |
IOC Hit Found : Trojan.Nakoctb | Sub Rule | Detected Trojan Activity | Malware |
IOC Hit Found : Trojan.Downloader.Hancitor | Sub Rule | Detected Trojan Activity | Malware |
IOC Hit Found : Trojan.Adwind | Sub Rule | Detected Trojan Activity | Malware |
IOC Hit Found : Suspicious VBScript | Sub Rule | Host Compromised | Compromise |
ExD Hit Found | Sub Rule | Host Compromised | Compromise |
IOC Hit Found : TaskMgr Process Dump LSASS.EXE | Sub Rule | Host Compromised | Compromise |
IOC Hit Found : Suspicious Powershell Usage | Sub Rule | Host Compromised | Compromise |
IOC Hit Found : Phishing Activity | Sub Rule | Phishing Activity | Attack |
IOC Hit Found : Mimikatz Malware | Sub Rule | Network Compromised | Compromise |
IOC Hit Found : Malware.Binary | Sub Rule | Detected Malware Activity | Malware |
IOC Hit Found : MalwrSpam | Sub Rule | Detected Malware Activity | Malware |
Malware Protection Found A Compromise Indication | Sub Rule | Detected Malware Activity | Malware |
Quarantine Task Successfully Completed, File Delet | Sub Rule | Quarantine | Activity |