Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- 8,422
- detections
Showing 30 of 8,422
Identifies when a D3 Smart SOAR incident with High or Critical severity is ingested. This helps security teams prioritize response to the most impactful incidents reported by D3 Smart SOAR.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 48ef0be4-8240-4a03-bbb9-320b562d6ce4
Spot connections to rarely accessed external domains that are present in your watchlist, which could signify data exfiltration attempts or C2 communication.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- deb99c6f-1903-455b-bb2c-0036614110bc
Query to match common security log identifiers with IOCs held by the Cyware Intel watchlist that is created automatically by Cyware
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 61c99147-b749-4164-80b1-c4bfa4efa704
Query identifies users denied registration for multiple webinars or recordings but successfully registered for at least one event. Threshold variable adjusts number of events user needs to be rejected from.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 47559078-dc4c-4de3-96fe-270d4ca95446
Detects high-risk URL indicators (risk score >= 80) from Cyren malware URL threat intelligence feeds in the last 24 hours. These URLs are associated with malware distribution, phishing campaigns, or other malicious content hosting.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 6e8f9c4b-2a3b-5c6d-0e1f-d2e3f4a5b6c7
Detects high-risk IP indicators (risk score >= 80) from Cyren threat intelligence feeds in the last 24 hours. These IPs are associated with malicious activity such as malware distribution, phishing, or botnet command and control.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 5d7e8b3a-1f2c-4e5d-9a0b-c1d2e3f4a5b6
Detects when the Cyren threat intelligence feed has not ingested any data for 6 or more hours. This may indicate a connectivity issue with the data connector, API authentication problems, or upstream service disruption.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 7f9a0d5c-3b4c-6d7e-1f2a-e3f4a5b6c7d8
Suspicious Connection to External Address
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- c0756978-baa6-4239-9174-bac1b1ca1a6a
Medical device is scanned with vulnerability scanner
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 211e9f49-3fca-4598-bc6e-e2c28d86e72c
User signed in using weak credentials
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 65db1346-6435-4079-bbf4-9a7113c98054
Exploitation Attempt of IoT device - Attack detection
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 3d853a88-92d2-4aec-a680-2bf7bb560c56
User signed in using default credentials
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 84e0ea1f-766d-4775-836a-c0c9cca05085
This rule detects medium severity attack surface-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 50 or higher, excluding those categorized as 'ASSET_VULNERABILITY', and generates alerts for assets that may be at risk.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 4c1b282b-62f1-4783-bf40-94c44f0ae630
This rule detects high severity attack surface-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 80 or higher, excluding those categorized as 'ASSET_VULNERABILITY', and generates alerts for assets that may be at risk.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 6cc62c46-dd44-46d7-8681-8422f780eabd
This rule detects medium severity asset-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 50 or higher, excluding those categorized as 'ATTACK_SURFACE_VULNERABILITY', and generates alerts for assets that may be at risk.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 6306f2d9-34a3-409a-850d-175b7bdd1ab1
This rule detects high severity asset-based vulnerabilities from CYFIRMA's vulnerability intelligence data. It identifies vulnerabilities with a confidence score of 80 or higher, excluding those categorized as 'ATTACK_SURFACE_VULNERABILITY', and generates alerts for assets that may be at risk.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 123fad02-6d9e-439e-8241-7a2fffa7e0a5
This rule triggers when CYFIRMA detects source code related to internal or enterprise domains exposed on public platforms like GitHub. Such exposure may lead to intellectual property leakage or help adversaries understand internal systems, increasing the risk of targeted attacks.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 28e315a3-725d-4261-a6c2-e597d51541f4
This rule triggers when CYFIRMA detects source code related to internal or enterprise domains exposed on public platforms like GitHub. Such exposure may lead to intellectual property leakage or help adversaries understand internal systems, increasing the risk of targeted attacks.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 42e6f16a-7773-44cc-8668-8f648bd1aa4f
This rule detects medium-severity social threat alerts from CYFIRMA related to impersonation, fake profiles, or malicious activities on social platforms that may target executives, brands, or employees. These threats can result in reputational damage, phishing, or social engineering attacks. Immediate investigation and takedown are recommended to minimize risk.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- b8149f2f-54da-4f7b-98e1-c01ca47e1e55
This rule detects high-severity social threat alerts from CYFIRMA related to impersonation, fake profiles, or malicious activities on social platforms that may target executives, brands, or employees. These threats can result in reputational damage, phishing, or social engineering attacks. Immediate investigation and takedown are recommended to minimize risk.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 4fe04459-13f1-4ff7-9b7c-f9be0c2aad6d
This analytics rule detects high severity alerts from CYFIRMA indicating exposure of Personally Identifiable Information (PII) or Confidential Information (CII) in public or unsecured sources. Such leaks may include email addresses, credentials, phone numbers, or other sensitive personal or organizational data. These exposures can lead to identity theft, phishing, credential compromise, or regulatory non-compliance.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- b484f224-687f-4406-af8a-ff019f9f2c24
This analytics rule detects high severity alerts from CYFIRMA indicating exposure of Personally Identifiable Information (PII) or Confidential Information (CII) in public or unsecured sources. Such leaks may include email addresses, credentials, phone numbers, or other sensitive personal or organizational data. These exposures can lead to identity theft, phishing, credential compromise, or regulatory non-compliance.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 52d71822-41e4-4c21-b36f-400294f2b43a
This rule detects Medium-severity alerts from CYFIRMA regarding exposure of confidential files or forms linked to internal or client-related information, publicly accessible on platforms. These exposures could lead to data leakage, compliance violations, or targeted attacks.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- a2984be5-8d69-4139-b98f-e89c9c421c27
This rule detects high-severity alerts from CYFIRMA regarding exposure of confidential files or forms linked to internal or client-related information, publicly accessible on platforms. These exposures could lead to data leakage, compliance violations, or targeted attacks.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 67e9c4aa-a2fa-4e4e-9272-1a8da41475c6
This analytics rule detects high-severity ransomware threats targeting the organization, as reported by CYFIRMA's Dark Web and Data Breach Intelligence feeds. The alert is generated when threat actors post, claim, or associate ransomware activity with corporate domains, brands, or subsidiaries, indicating a potential data breach, extortion attempt, or unauthorized access.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- d5f9a6fe-7fd2-488c-8690-0ca24fba43dc
This analytics rule detects high-severity ransomware threats targeting the organization, as reported by CYFIRMA's Dark Web and Data Breach Intelligence feeds. The alert is generated when threat actors post, claim, or associate ransomware activity with corporate domains, brands, or subsidiaries, indicating a potential data breach, extortion attempt, or unauthorized access.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- ed1aabc1-e1c1-42f4-abac-fd5637730f13
Detects phishing campaigns targeting enterprise domains, as identified through CYFIRMA's Data Breach and Dark Web Monitoring. These alerts may include malicious URLs used for credential harvesting, domain impersonation, or social engineering. Immediate triage and takedown actions are recommended.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 00c7b41c-ddeb-4c49-acd7-2f7897e27fb4
Detects phishing campaigns targeting enterprise domains, as identified through CYFIRMA's Data Breach and Dark Web Monitoring. These alerts may include malicious URLs used for credential harvesting, domain impersonation, or social engineering. Immediate triage and takedown actions are recommended.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- 17cce4fc-9b4c-4eef-a4c7-083b44545e6e
Detects critical alerts from CYFIRMA related to sensitive data or credentials leaked on dark web forums. These events often indicate unauthorized access or compromise of enterprise systems, cloud environments, or identity platforms. Immediate investigation is required to assess breach scope and initiate mitigation, including credential resets, access reviews, and threat actor tracking.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- c0afeda7-4832-49a6-8d03-a5d137d513b5
Detects critical alerts from CYFIRMA related to sensitive data or credentials leaked on dark web forums. These events often indicate unauthorized access or compromise of enterprise systems, cloud environments, or identity platforms. Immediate investigation is required to assess breach scope and initiate mitigation, including credential resets, access reviews, and threat actor tracking.
- Licence
- MIT
- Published
- Aug 29, 2026
- Upstream
- c3f1f55b-7e54-4416-8afc-7d7876b29b0f