Custom Detection Example - Newly created SSL certificate
|
|
0
|
96
|
May 2, 2022
|
Help in identifying data obfuscation(protocol impersonation using cookie)
|
|
9
|
438
|
February 9, 2022
|
CVE-2021-44228 detection
|
|
2
|
594
|
December 14, 2021
|
Handing DETECTION_UPDATE during for ExtraHop-Demisto timeout
|
|
1
|
430
|
October 12, 2021
|
Detecting Unauthorized Remote Access Trigger
|
|
0
|
455
|
October 7, 2021
|
Mapping HTTP.payload information with Src/Dst IP/Port
|
|
5
|
563
|
September 20, 2021
|
Testing a trigger - forcing a detection?
|
|
2
|
692
|
June 22, 2021
|
Detection: CVE-2021-22991
|
|
3
|
1012
|
March 12, 2021
|
External javascript libraries, decompression, ebcdic
|
|
7
|
2742
|
January 21, 2021
|
Detection SIEM Connector Description Issue
|
|
8
|
997
|
January 4, 2021
|
Cisco AnyConnect Secure Mobility Client Arbitrary Code Execution Vulnerability
|
|
0
|
952
|
November 6, 2020
|
Throttle Triggered Precision PCAP
|
|
2
|
949
|
October 15, 2020
|
DNS Answers in ODS feed to Splunk
|
|
2
|
927
|
October 9, 2020
|
Got Bots? We got an App for that!
|
|
1
|
2065
|
September 16, 2020
|
TIMER_30SEC event
|
|
2
|
954
|
August 6, 2020
|
Honey Token Detection across multiple protocols
|
|
0
|
1228
|
June 4, 2020
|
lookupByIP in L2 discovery
|
|
3
|
1000
|
May 18, 2020
|
NDR POW (2/27): POSH Watcher
|
|
6
|
1615
|
May 14, 2020
|
MSRPC Records
|
|
1
|
969
|
March 26, 2020
|
Critical Devices - EXA Connector Trigger
|
|
1
|
1277
|
March 18, 2020
|
IP address, Port, throughput
|
|
0
|
965
|
March 15, 2020
|
Detection: Cloud Snooper
|
|
0
|
1564
|
February 27, 2020
|
NDR POW (12/16) Trickbot/RYUK Variant throw-down
|
|
0
|
1306
|
December 16, 2019
|
Debug log shows unexpected entries
|
|
8
|
1220
|
December 14, 2019
|
NDR POW (Punkbust Of the Week): Catching Homograph Attacks (PHISH PHINDER!)
|
|
0
|
1323
|
December 9, 2019
|
How to Optimize Trigger Code?
|
|
7
|
1390
|
December 5, 2019
|
Hadoop DemonBot detection
|
|
2
|
2061
|
November 13, 2019
|
NDR: Checking for 'Baby Certs" with Reveal(x)
|
|
1
|
1172
|
November 1, 2019
|
Citrix Middle Tier Trigger
|
|
2
|
1086
|
October 21, 2019
|
Trigger for TCP:9100 Destinations
|
|
2
|
1956
|
June 26, 2019
|