IO
Ilyas Ochkov
First rule: Sat Oct 12 2019 02:00:00 GMT+0200 (Central European Summer Time)
0rules authored
0sole author
12co-authored
Rule Types
By Severity
critical
1
high
3
medium
8
low
0
informational
0
By Status
stable
0
test
12
experimental
0
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Webshell Remote Command Execution
Sat Oct 12 2019 02:00:00 GMT+0200 (Central European Summer Time)
criticalDetection
Uncommon Outbound Kerberos Connection - Security
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Uncommon Outbound Kerberos Connection
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
New or Renamed User Account with '$' Character
Fri Oct 25 2019 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess'
Thu Oct 24 2019 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
New DLL Added to AppInit_DLLs Registry Key
Fri Oct 25 2019 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Browse all 12 rules by Ilyas Ochkov
Filter the full rule library to see only their contributions