Sponsor of the Day:
Jerkmate
https://detection.fyi/sigmahq/sigma/windows/builtin/security/win_security_replay_attack_detected/
Replay Attack Detected | Detection.FYI
Detects possible Kerberos Replay Attack on the domain controllers when
detected detection fyireplay attack
https://detection.fyi/sigmahq/sigma/windows/builtin/windefend/win_defender_threat/
Windows Defender Threat Detected | Detection.FYI
Detects actions taken by Windows Defender malware detection engines
detected detection fyiwindows defenderthreat
https://detection.fyi/sigmahq/sigma/windows/sysmon/sysmon_file_executable_detected/
Sysmon File Executable Creation Detected | Detection.FYI
Triggers on any Sysmon
detected detection fyifile executablesysmoncreation
https://detection.fyi/sigmahq/sigma/application/github/audit/github_outside_collaborator_detected/
Github Outside Collaborator Detected | Detection.FYI
Detects when an organization member or an outside collaborator is added to or removed from a project board or has their permission level changed or when an …
detected detection fyigithuboutsidecollaborator