Rule Library
Sigma Rules
6 rules found for "NVISO"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
Failed Logon From Public IP
Detects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
Windowssecurity
NVISOWed May 06windows
Detectionhightest
Vulnerable Netlogon Secure Channel Connection Allowed
Detects that a vulnerable Netlogon secure channel connection was allowed, which could be an indicator of CVE-2020-1472.
Windowssystem
NVISOTue Sep 15windows
Detectionhightest
Octopus Scanner Malware
Detects Octopus Scanner Malware.
WindowsFile Event
NVISOTue Jun 09windows
Detectionhightest
Potential Persistence Via Microsoft Office Add-In
Detects potential persistence activity via startup add-ins that load when Microsoft Office starts (.wll/.xll are simply .dll fit for Word or Excel).
WindowsFile Event
NVISOMon May 11windows
Detectionhightest
Fax Service DLL Search Order Hijack
The Fax service attempts to load ualapi.dll, which is non-existent. An attacker can then (side)load their own malicious DLL using this service.
WindowsImage Load (DLL)
NVISOMon May 04windows
Detectionhightest
WMImplant Hack Tool
Detects parameters used by WMImplant
WindowsPowerShell Script
NVISOThu Mar 26windows