Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Alert Rules

Alert Rules consist of alert packages, a dashboard package, and Knowledge Base (KB) lists for analytics integrated into SIEM. It provides a compliance and triage dashboard, enabling you to analyze trends and behaviors of entities and users within the organization and perform a defensive gap assessment with MITRE ATT&CK. 

Release Details

Version: 7.0.0
Release date: August 04, 2026
Supported On: Guardsix SIEM v7.6.0 or later
SHA 256: 3e8a62ac9796e66ba30cbd5c2a440fb0ca095669015f5974f6b2202e593aacb6
Alert Rules Guide
Download

Enhancement

SR-1144
New alert rules are added to enhance threat detection, security events, and incident response.
  1. Browser Credential File Access on Linux

  2. Disk Image or Container File Downloaded via Outlook

  3. Malicious Email Attachment Detected by Microsoft Defender for Office 365

  4. Malicious Email Detected by Microsoft Defender for Office

  5. Office 365 Safe Links Warning Bypassed

  6. Office365 OAuth Consent or Device Code Phishing URL Clicked

  7. Office365 Suspicious OAuth Application Permission Granted

  8. Office365 User-Reported Phishing or Malware Email

  9. Rclone File Upload Activity on Windows and Linux

  10. Registry key Deleted by Suspicious Process

  11. Registry Symbolic Link Value Modified

  12. Suspicious Access to GNOME Keyring Files

  13. Suspicious File Creation in Removable Drive Root

  14. Suspicious File Downloaded from Teams

  15. Suspicious Find Execution on Unix

  16. Suspicious Process Spawned with System Privilege

  17. System Named Pipe Creation by Non-System Process

  18. USB Device Connection Detected

  19. USB Device Insertion Detected via Registry Modification

  20. Windows Directory Environment Variable Modified

Updated query and description of the following alert rules:
  1. Potential Data Exfiltration via Curl

  2. MEGA Client File Upload Activity on Windows

  3. Suspicious Child Process Creation via OneNote

  4. Suspicious Double Extension Detected

  5. Entra ID Device Code Authentication Detected

  6. RClone Utility Execution

  7. Suspicious Outbound RDP Connections Detected

  8. Virtual Machine Environment Discovery via Process or Service Checks

  9. Browser Credential Files Accessed

  10. Chromeloader Cross-Process Injection to Load Extention

  11. Cmdkey Cached Credentials Recon Detected

  12. Regsvr32 Network Activity Detected

  13. Suspicious Script Execution From Temp Folder

  14. Virtualization Environment Discovery via WMI

  15. CEO Fraud - Possible Fraudulent Email Behavior

  16. Execution in Outlook Temp Folder Detected

  17. Guardsix License Expiry Status

  18. Default CPU Usage Status

  19. Default Harddisk Usage Status

  20. Default License Invalid

  21. Default Memory Usage Status

  22. Possible Insider Threat

Removed the following generic and redundant alert rules:
  1. Adobe ColdFusion Remote Code Execution CVE-2018-15961 Attempt

  2. Application Whitelisting Bypass via Dnx Detected

  3. Application Whitelisting Bypass with DLL load via ODBC

  4. BlueKeep Vulnerability CVE-2019-0708 Exploitation

  5. CVE-2022-40684 Exploitation Detected

  6. CVE-2024-38112 Exploitation Detected

  7. Chrome Extension Installed with DevTools Permission

  8. Citrix ADC VPN Directory Traversal Detected

  9. Copyright Violation Email

  10. Default Connection Attempts on Closed Port

  11. Default IRC connection

  12. Default License Grace State

  13. Default Malware not Cleaned

  14. Default Possible Cross Site Scripting Attack Detected

  15. Default Possible Non-PCI Compliant Inbound Network Traffic Detected

  16. Default Possible System Instability State Detected

  17. Default TCP Probable SynFlood Attack

  18. Default Unapproved Port Activity Detected

  19. DenyAllWAF SQL Injection Attack

  20. Drupal Arbitrary Code Execution Detected

  21. EMC Possible Ransomware Detection

  22. Endpoint Protect File Copied To USB Device

  23. Endpoint Protect File Delete

  24. Endpoint Protect Threat Content Detected

  25. Exchange Remote Code Execution CVE-2020-0688 Attempt

  26. Execution of Trojanized 3CX Application

  27. Exfiltration over Cloud Application Detected

  28. Exim Remote Command Execution Detected

  29. Exploitation of CVE-2019-1388 Detected

  30. Fail2ban IP Banned

  31. Formbook Process Creation Detected

  32. FortiGate Admin Login Disable

  33. High Severity EPP Alert

  34. Koadic Execution Detected

  35. Malware Threat Connection from Malicious Source

  36. Malware Threat Connection to Malicious Destination

  37. Malware Threat Connection to Malicious URLs

  38. Malware Threat Emails Sent to Attacker

  39. Oracle WebLogic CVE-2021-2109 Exploitation

  40. Petitpotam - Anonymous RPC and File Share

  41. Possible Applocker Bypass Detected

  42. Possible Malware Detected

  43. Possible Outbound Spamming Detected

  44. Possible User Account Control Bypass Detected

  45. Potential Phishing Attack Detected

  46. Process Pattern Match For CVE-2021-40444 Exploitation

  47. Proxy Execution of Payloads via Microsoft Signed Script

  48. Proxy Execution via Desktop Setting Control Panel

  49. Proxy Execution via Xwizard

  50. Pulse Secure Arbitrary File Reading Detected

  51. RDP Extension File Dropped in Outlook Folder

  52. RDP Over Reverse SSH Tunnel Detected

  53. RSA SecurID Account Lockout

  54. RSA SecurID Passcode Reuse

  55. SSHD Connection Denied

  56. SolarisLDAP Group Remove from LDAP Detected

  57. SolarisLDAP Possible Bruteforce Attack Detected

  58. Suspicious CLR Logs File Creation

  59. Suspicious Certutil Command Detected

  60. Suspicious Program Location with Network Connections

  61. Suspicious Usage of Squirrel Binary

  62. TerraMaster TOS CVE-2020-28188 Exploitation

  63. Threat Intel Connections with Suspicious Domains

  64. UAC Bypass via CMLUA or CMSTPLUA

  65. Usage of Sysinternals Tools Detected

  66. VBA DLL Loaded by Office

  67. VM - High Risk Vulnerability on Low Impact Assets

  68. VMware Link Down

  69. VMware VSphere CVE-2021-21972 Exploitation

  70. VMware View Planner CVE-2021-21978 Exploitation

  71. WannaCry MS17-010 Vulnerable Sources

  72. WannaCry Sources in Connections to Sinkhole Domain

  73. ZoHo ManageEngine Desktop Central CVE-2020-10189 Exploitation Attempt

  74. ZoHo ManageEngine Pre-Auth File Upload CVE-2019-8394 Exploitation Attempt

  75. Zoho ManageEngine ADSelfService Plus CVE-2021-40539 Exploitation

      Past Releases

      Alert Rules v6.2.0 ▾
      Version: 6.2.0
      Release date: April 30, 2026
      Supported On: Logpoint 7.4.0 or later
      SHA 256: 33127f1212cd5073e5d868460c19ecb53d2f1c79760052ef57488d5fd6a7ba8f
      Alert Rules Guide
      Download

      Enhancement

      SR-1090
      New Alert Rules are added to enhance threat detection, security events, and incident response.
      1. Microsoft 365 SharePoint or OneDrive Bulk Access via PowerShell Client
      2. Microsoft 365 SharePoint or OneDrive Mass File Download by User
      3. Microsoft 365 SharePoint Sensitive Keyword Search Discovery
      4. Office365 User Account Creation Followed by Admin Role Assignment
      5. Linux Firewall Policy or Rule Modification
      6. Linux Firewall Service Disabled or Stopped
      7. Python Spawning Shell with Suspicious Arguments
      8. System Check for Virtualization Environment
      9. Unix User Account Creation Detected via File Modification
      10. Unix User Account Creation via System Command
      11. Firewall Rule Modification via Netsh Detected
      12. MEGA Client File Upload Activity on Windows
      13. Network Connection to MEGA via MEGA Client on Windows
      14. Python Execution from Suspicious Location
      15. Python Inline Command Execution
      16. Remote File Upload via Restic on Windows
      17. RMM Tool Activity Detected on Windows
      18. Sensitive File and Directory Discovery on Windows
      19. Suspicious Eventlog Clear or Configuration Change Activity
      20. User Added to Privileged or Remote Access Group
      21. Virtual Machine Environment Discovery via Process or Service Checks
      22. Virtualization Environment Discovery via WMI
      23. Windows Credential Manager Access via VaultCmd
      24. Python Pth File Creation Detected
      25. EnableLinkedConnections Registry Modification
      26. Windows Firewall Disabled via Registry Modification
      27. User Account Creation with Suspicious Naming Pattern
      28. Windows Firewall Configuration Change
      29. Windows Firewall Tampering via PowerShell
      30. Windows Vault Enumeration Followed by Vault Credential Read
      Updated query and description of the following Alert Rules:
      1. Always Install Elevated Windows Installer
      2. Child Process Spawned via Diskshadow
      3. Clipboard Data Access Detected
      4. Creation of Anonymous Sharing Link in SharePoint
      5. Curl Silent Mode Execution Detected
      6. Execution of Temporary Files via Office Application
      7. File Shared to Guest in SharePoint
      8. Firewall Disabled via Netsh Detected
      9. HackTool - PPID Spoofing SelectMyParent Tool Execution
      10. Large ICMP Traffic
      11. Microsoft Defender Disabling Attempt via PowerShell
      12. RDP Registry Modification
      13. Reconnaissance Activity with Nltest
      14. Startup Folder File Write
      15. Suspicious Child Process Spawned by Microsoft Office Product
      16. Suspicious LoadAssembly PowerShell Diagnostic Script Execution
      17. Suspicious Rundll32 Activity Detected
      18. Suspicious Script Execution From Temp Folder
      19. Suspicious Usage of Where Binary
      20. Use of Pcalua for Execution
      21. VM - High Risk Vulnerability on High Impact Assets
      22. VM - High Risk Vulnerability on Low Impact Assets
      23. VM - High Risk Vulnerability on Medium Impact Assets
      24. VM - Medium Risk Vulnerability on High Impact Assets
      25. VM - Medium Risk Vulnerability on Low Impact Assets
      26. VM - Medium Risk Vulnerability on Medium Impact Assets
      27. WinPwn PowerShell Script Block Detected
      28. Windows Service Stop or Delete
      29. Windows User Account Created via Command Line
      Removed the following generic and redundant Alert Rules:
      1. Suspicious Eventlog Clear or Configuration Using Wevtutil Detected
      2. Firewall Rule Addition via Netsh Detected
      3. Script Interpreter Execution From Suspicious Folder
      4. Most Exploitable Vulnerabilities Detected
      5. Suspicious Invocation PowerShell Diagnostic Script Execution


      Alert Rules v6.1.1 ▾
      Version: 6.1.1
      Release date: March 17, 2026
      Supported On: Logpoint 7.4.0 or later
      SHA 256: e4191210a1fa38d0aee7783804070730be1d4b1ef25f981003efb9ddd30b9d34
      Download

      Enhancement

      SR-618

      New Alert Rules are added to enhance threat detection, security events, and incident response.

      • Registry Disable System Restore

      • Registry Persistence Mechanisms in Recycle Bin

      • Sticky Keys Backdoor via Registry Modification

      • Security Product Reconnaissance through WMI

      • Use of Pcalua for Execution

      • WinPwn PowerShell Script Block Detected

      • Audit Policy Tampering via Auditpol

      • Suspicious Active Directory Enumeration via LDAP Command Line

      • Potential Data Exfiltration via Curl

      • Potential Browser Data Stealing

      • Rubeus PowerShell ScriptBlock Detected

      • RestrictedAdminMode Registry Value Tampering

      • WSUS Suspicious Child Process Execution

      • Suspicious PowerShell Embedded Payload Carving

      • Unsigned DLL Loaded by Windows Utility

      • Suspicious Velociraptor Execution

      • PowerShell Cryptography Namespace Invocation

      • Suspicious Child Process Spawned by Browsers

      • Suspicious Kerberos-Related DLL Loading

      Updated query and description of the following Alert Rules:

      • LSASS Memory Dump Detected

      • Network Share Discovery

      • Reconnaissance using Windows Binaries Detected

      • Scheduled Task Creation Detected

      • System Network Connections Discovery

      • File Dropped in Suspicious Location

      • Suspicious Use of Findstr Detected

      • Suspicious Named Pipes Detected

      • Suspicious PowerShell Parameter Substring Detected

      • Execution of Base64 Encoded Command Using IEX

      • Suspicious Base64 Encoded PowerShell Command

      • Startup Folder File Write

      • Mimikatz Command Line Detected

      • Suspicious MSHTA Process Pattern

      • Suspicious PsExec Execution Detected

      • Reconnaissance Activity with Nltest

      • Bypass User Account Control using Registry

      • Registry Persistence Mechanisms Detected

      Removed the following generic and redundant Alert Rules:

      • Encoded PowerShell Command Detected

      • Suspicious File Execution via MSHTA

      • Unsigned DLLs loaded by RunDLL32 or RegSvr32

      • Possible Command Prompt Process Hollowing

      Alert Rules v6.1.0 ▾
      Version: 6.1.0
      Release date: November 14, 2025
      Supported On: Logpoint 7.4.0 or later
      SHA 256: a5f61bc51e16483c773d51988ab88a5b7e01f038baa02410eacf163f6deae368
      Download

      Enhancement

      SR-483
      New Alert Rules are added to enhance threat detection, security events, and speed up incident response.

      Go to Alert Rules to learn more. 
      Alert Rules v6.0.0 ▾
      Version: 6.0.0
      Release date: April 30, 2025
      Supported On: Logpoint 7.4.0 or later
      SHA 256: 5f69fb7f22189a88c4757053346b9dcf3f131b7471a8c3d9984898538a213c9c
      Download

      Enhancement

      SR-338
      New Alert Rules are added to enhance threat detection, security events, and speed up incident response.

      Go to Alert Rhttps://docs.logpoint.com/docs/alert-rules/en/latest/ules to learn more. 

      Comments

      Please sign in to leave a comment.

      Follow

      Related articles

      • JSON Parser
      • Evaluation Process Plugin
      • Cisco
      • ChatGPT Integration
      • Universal Normalizer
      Consent Required To Proceed
      By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

      This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
      Cancel I Agree & Download
      Privacy policy    EULA    Terms of service   
      Copyright © , Guardsix. All rights reserved.

      Note: We use cookies that are essential for the smooth functioning of our website.