Rule Library
Sigma Rules
3 rules found for "NVISO"
3,731Total
3,132Detection
457Emerging
139Hunting
Emerging Threathightest
CVE-2020-0688 Exploitation Attempt
Detects CVE-2020-0688 Exploitation attempts
Web Server Log
NVISOThu Feb 272020
Emerging Threathightest
CVE-2020-1048 Exploitation Attempt - Suspicious New Printer Ports - Registry
Detects changes to the "Ports" registry key with data that includes a Windows path or a file with a suspicious extension. This could be an attempt to exploit CVE-2020-1048 - a Windows Print Spooler elevation of privilege vulnerability.
WindowsRegistry Set
EagleEye Team+2Wed May 132020
Emerging Threatcriticaltest
FlowCloud Registry Markers
Detects FlowCloud malware registry markers from threat group TA410. The malware stores its configuration in the registry alongside drivers utilized by the malware's keylogger components.
WindowsRegistry Event
NVISOTue Jun 092020