Scripting T0853

ICS Tactic: Execution

Authoring guide

These 7 rules share fields, values, and exclusions.

Fields filtered most (14 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
ThreatLevel4eq 4dangerous, suspicious
Category2eq 2ApplicationGatewayFirewallLog, frontdoorwebapplicationfirewalllog
LinksClicked2gt 20
Total_TransactionId2ge 21, 3
action_s2eq 2Blocked, Matched, anomalyscoring, block
name2regex_match 2(?i)^.*\.(doc|docx|docm|pdf|xls|xlsx|xlsm|html|zip)$(?-i)
Action1eq 1Blocked, Matched
Blocked_Reason1contains 1xss
Message1contains 1xss
SQLI_Score1le 15
TotalInboundScore1ge 115
Total_TrackingReference1ge 11
XSS_Score1ge 110
details_msg_s1contains 1xss

Top indicator values (21 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
ThreatLeveleq
dangerous
44
ThreatLeveleq
suspicious
44
LinksClickedgt
0
22
nameregex_match
(?i)^.*\.(doc|docx|docm|pdf|xls|xlsx|xlsm|html|zip)$(?-i)
22
Actioneq
Blocked
15
Actioneq
Matched
15
Blocked_Reasoncontains
xss
1
Categoryeq
ApplicationGatewayFirewallLog
12
Categoryeq
frontdoorwebapplicationfirewalllog
14
Messagecontains
xss
1
SQLI_Scorele
5
1
TotalInboundScorege
15
12
Total_TrackingReferencege
1
12
Total_TransactionIdge
1
1
Total_TransactionIdge
3
16
XSS_Scorege
10
1
action_seq
Blocked
12
action_seq
Matched
12
action_seq
anomalyscoring
14
action_seq
block
14
details_msg_scontains
xss
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Kusto 7 rules