Log source category
firewall log source Sigma rules
2 Sigma detection rules in the library use the firewall log source. The firewall category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.
2 rules
Equation Group C2 Communication
highDetects communication to C2 servers mentioned in the operational notes of the ShadowBroker leak of EquationGroup C2 tools
Cleartext Protocol Usage
lowEnsure that all account usernames and authentication credentials are transmitted across networks using encrypted channels. Ensure that an encryption is used for all sensitive information in transit. Ensure that an encrypted channels is used for all administrative account access.