W
wagga
First rule: Tue Mar 20 2018 01:00:00 GMT+0100 (Central European Standard Time)
0rules authored
0sole author
12co-authored
Rule Types
By Severity
critical
3
high
7
medium
2
low
0
informational
0
By Status
stable
1
test
11
experimental
0
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Common Autorun Keys Modification
Fri Oct 25 2019 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
NetNTLM Downgrade Attack - Registry
Tue Mar 20 2018 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Suspicious Child Process Of SQL Server
Fri Dec 11 2020 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Potential Powershell ReverseShell Connection
Wed Mar 03 2021 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Lazarus Group Activity
Wed Dec 23 2020 01:00:00 GMT+0100 (Central European Standard Time)
criticalEmerging Threat
Windows Admin Share Mount Via Net.EXE
Mon Oct 05 2020 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Browse all 12 rules by wagga
Filter the full rule library to see only their contributions