Log source category
application log source Sigma rules
64 Sigma detection rules in the library use the application log source, mostly on opencanary, rpc_firewall, kubernetes. The application category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
OpenCanary - FTP Login Attempt
highDetects instances where an FTP service on an OpenCanary node has had a login attempt.
opencanary
OpenCanary - GIT Clone Request
highDetects instances where a GIT service on an OpenCanary node has had Git Clone request.
opencanary
OpenCanary - Host Port Scan (SYN Scan)
highDetects instances where an OpenCanary node has been targeted by a SYN port scan.
opencanary
OpenCanary - HTTP GET Request
highDetects instances where an HTTP service on an OpenCanary node has received a GET request.
opencanary
OpenCanary - HTTP POST Login Attempt
highDetects instances where an HTTP service on an OpenCanary node has had login attempt via Form POST.
opencanary
OpenCanary - HTTPPROXY Login Attempt
highDetects instances where an HTTPPROXY service on an OpenCanary node has had an attempt to proxy another page.
opencanary
OpenCanary - MSSQL Login Attempt Via SQLAuth
highDetects instances where an MSSQL service on an OpenCanary node has had a login attempt using SQLAuth.
opencanary
OpenCanary - MSSQL Login Attempt Via Windows Authentication
highDetects instances where an MSSQL service on an OpenCanary node has had a login attempt using Windows Authentication.
opencanary
OpenCanary - MySQL Login Attempt
highDetects instances where a MySQL service on an OpenCanary node has had a login attempt.
opencanary
OpenCanary - NMAP FIN Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP FIN Scan
opencanary
OpenCanary - NMAP NULL Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP NULL Scan
opencanary
OpenCanary - NMAP OS Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP OS Scan
opencanary
OpenCanary - NMAP XMAS Scan
highDetects instances where an OpenCanary node has been targeted by a NMAP XMAS Scan
opencanary
OpenCanary - NTP Monlist Request
highDetects instances where an NTP service on an OpenCanary node has had a NTP monlist request.
opencanary
OpenCanary - RDP New Connection Attempt
highDetects instances where an RDP service on an OpenCanary node has had a connection attempt.
opencanary
OpenCanary - REDIS Action Command Attempt
highDetects instances where a REDIS service on an OpenCanary node has had an action command attempted.
opencanary
OpenCanary - SIP Request
highDetects instances where an SIP service on an OpenCanary node has had a SIP request.
opencanary
OpenCanary - SMB File Open Request
highDetects instances where an SMB service on an OpenCanary node has had a file open request.
opencanary
OpenCanary - SNMP OID Request
highDetects instances where an SNMP service on an OpenCanary node has had an OID request.
opencanary
OpenCanary - SSH Login Attempt
highDetects instances where an SSH service on an OpenCanary node has had a login attempt.
opencanary
OpenCanary - SSH New Connection Attempt
highDetects instances where an SSH service on an OpenCanary node has had a connection attempt.
opencanary
OpenCanary - Telnet Login Attempt
highDetects instances where a Telnet service on an OpenCanary node has had a login attempt.
opencanary
OpenCanary - TFTP Request
highDetects instances where a TFTP service on an OpenCanary node has had a request.
opencanary
OpenCanary - VNC Connection Attempt
highDetects instances where a VNC service on an OpenCanary node has had a connection attempt.
opencanary
Possible DCSync Attack
highDetects remote RPC calls to MS-DRSR from non DC hosts, which could indicate DCSync / DCShadow attacks.
rpc_firewall
Potential JNDI Injection Exploitation In JVM Based Application
highDetects potential JNDI Injection exploitation. Often coupled with Log4Shell exploitation.
jvm
Potential Local File Read Vulnerability In JVM Based Application
highDetects potential local file read vulnerability in JVM based apps. If the exceptions are caused due to user input and contain path traversal payloads then it's a red flag.
jvm
Potential OGNL Injection Exploitation In JVM Based Application
highDetects potential OGNL Injection exploitation, which may lead to RCE. OGNL is an expression language that is supported in many JVM based systems. OGNL Injection is the reason for some high profile RCE's such as Apache Struts (CVE-2017-5638) and Confluence (CVE-2022-26134)
jvm
Potential RCE Exploitation Attempt In NodeJS
highDetects process execution related errors in NodeJS. If the exceptions are caused due to user input then they may suggest an RCE vulnerability.
nodejs
Potential Server Side Template Injection In Velocity
highDetects exceptions in velocity template renderer, this most likely happens due to dynamic rendering of user input and may lead to RCE.
velocity
Potential SpEL Injection In Spring Framework
highDetects potential SpEL Injection exploitation, which may lead to RCE.
spring
Potential XXE Exploitation Attempt In JVM Based Application
highDetects XML parsing issues, if the application expects to work with XML make sure that the parser is initialized safely.
jvm
Process Execution Error In JVM Based Application
highDetects process execution related exceptions in JVM based apps, often relates to RCE
jvm
Recon Activity via SASec
highDetects remote RPC calls to read information about scheduled tasks via SASec
rpc_firewall
Remote DCOM/WMI Lateral Movement
highDetects remote RPC calls that performs remote DCOM operations. These could be abused for lateral movement via DCOM or WMI.
rpc_firewall
Remote Encrypting File System Abuse
highDetects remote RPC calls to possibly abuse remote encryption service via MS-EFSR
rpc_firewall
Remote Event Log Recon
highDetects remote RPC calls to get event log information via EVEN or EVEN6
rpc_firewall
Remote Printing Abuse for Lateral Movement
highDetects remote RPC calls to possibly abuse remote printing service via MS-RPRN / MS-PAR
rpc_firewall
Remote Registry Lateral Movement
highDetects remote RPC calls to modify the registry and possible execute code
rpc_firewall
Remote Registry Recon
highDetects remote RPC calls to collect information
rpc_firewall
Remote Schedule Task Lateral Movement via ATSvc
highDetects remote RPC calls to create or execute a scheduled task via ATSvc
rpc_firewall
Remote Schedule Task Lateral Movement via ITaskSchedulerService
highDetects remote RPC calls to create or execute a scheduled task
rpc_firewall
Remote Schedule Task Lateral Movement via SASec
highDetects remote RPC calls to create or execute a scheduled task via SASec
rpc_firewall
Remote Schedule Task Recon via AtScv
highDetects remote RPC calls to read information about scheduled tasks via AtScv
rpc_firewall
Remote Schedule Task Recon via ITaskSchedulerService
highDetects remote RPC calls to read information about scheduled tasks
rpc_firewall
Remote Server Service Abuse
highDetects remote RPC calls to possibly abuse remote encryption service via MS-SRVS
rpc_firewall
Remote Server Service Abuse for Lateral Movement
highDetects remote RPC calls to possibly abuse remote encryption service via MS-EFSR
rpc_firewall
SharpHound Recon Account Discovery
highDetects remote RPC calls useb by SharpHound to map remote connections and local group membership.
rpc_firewall
SharpHound Recon Sessions
highDetects remote RPC calls useb by SharpHound to map remote connections and local group membership.
rpc_firewall
Suspicious SQL Error Messages
highDetects SQL error messages that indicate probing for an injection attack
sql
Creation Of Pod In System Namespace
mediumDetects deployments of pods within the kube-system namespace, which could be intended to imitate system pods. System pods, created by controllers such as Deployments or DaemonSets have random suffixes in their names. Attackers can use this fact and name their backdoor pods as if they were created by these controllers to avoid detection. Deployment of such a backdoor container e.g. named kube-proxy-bv61v, could be attempted in the kube-system namespace alongside the other administrative containers.
kubernetes · audit
Django Framework Exceptions
mediumDetects suspicious Django web application framework exceptions that could indicate exploitation attempts
django
Kubernetes Events Deleted
mediumDetects when events are deleted in Kubernetes. An adversary may delete Kubernetes events in an attempt to evade detection.
kubernetes · audit
Potential Remote Command Execution In Pod Container
mediumDetects attempts to execute remote commands, within a Pod's container using e.g. the "kubectl exec" command.
kubernetes · audit
Potential Sidecar Injection Into Running Deployment
mediumDetects attempts to inject a sidecar container into a running deployment. A sidecar container is an additional container within a pod, that resides alongside the main container. One way to add containers to running resources like Deployments/DeamonSets/StatefulSets, is via a "kubectl patch" operation. By injecting a new container within a legitimate pod, an attacker can run their code and hide their activity, instead of running their own separated pod in the cluster.
kubernetes · audit
Python SQL Exceptions
mediumGeneric rule for SQL exceptions in Python according to PEP 249
python
Ruby on Rails Framework Exceptions
mediumDetects suspicious Ruby on Rails exceptions that could indicate exploitation attempts
ruby_on_rails
Spring Framework Exceptions
mediumDetects suspicious Spring framework exceptions that could indicate exploitation attempts
spring
Container With A hostPath Mount Created
lowDetects creation of a container with a hostPath mount. A hostPath volume mounts a directory or a file from the node to the container. Attackers who have permissions to create a new pod in the cluster may create one with a writable hostPath volume and chroot to escape to the underlying node.
kubernetes · audit
Deployment Deleted From Kubernetes Cluster
lowDetects the removal of a deployment from a Kubernetes cluster. This could indicate disruptive activity aiming to impact business operations.
kubernetes · audit
Kubernetes Secrets Enumeration
lowDetects enumeration of Kubernetes secrets.
kubernetes · audit
New Kubernetes Service Account Created
lowDetects creation of new Kubernetes service account, which could indicate an attacker's attempt to persist within a cluster.
kubernetes · audit
Privileged Container Deployed
lowDetects the creation of a "privileged" container, an action which could be indicative of a threat actor mounting a container breakout attacks. A privileged container is a container that can access the host with all of the root capabilities of the host machine. This allows it to view, interact and modify processes, network operations, IPC calls, the file system, mount points, SELinux configurations etc. as the root user on the host. Various versions of "privileged" containers can be specified, e.g. by setting the securityContext.privileged flag in the resource specification, setting non-standard Linux capabilities, or configuring the hostNetwork/hostPID fields
kubernetes · audit
RBAC Permission Enumeration Attempt
lowDetects identities attempting to enumerate their Kubernetes RBAC permissions. In the early stages of a breach, attackers will aim to list the permissions they have within the compromised environment. In a Kubernetes cluster, this can be achieved by interacting with the API server, and querying the SelfSubjectAccessReview API via e.g. a "kubectl auth can-i --list" command. This will enumerate the Role-Based Access Controls (RBAC) rules defining the compromised user's authorization.
kubernetes · audit