Rule-Based Alert Types
                                            For certain Stellar Cyber alert types based on specific rules, the following topics list the rules that may trigger the indicated Alert Type. For details on rule-based alerts, see Rule-Based Alert Details.
| 
                                                             Link to Rule  | 
                                                        
                                                             Source(s)  | 
                                                        
                                                             Link to XDR Event Name  | 
                                                    
|---|---|---|
| 
                                                             Rules Contributing to Suspicious PowerShell Script Alert Type  | 
                                                        
                                                             SigmaHQ, Developed internally by Stellar Cyber  | 
                                                        |
| 
                                                             Rules Contributing to Suspicious Process Creation Commandline Alert Type
  | 
                                                        
                                                             SigmaHQ, Developed internally by Stellar Cyber  | 
                                                        |
| 
                                                             Rules Contributing to Parent/Child Suspicious Process Creation Alert Type  | 
                                                        
                                                             SigmaHQ, Developed internally by Stellar Cyber  | 
                                                        
Rule-Based AWS Alert Types
Rule-Based Microsoft Entra Alert Types
Rule-Based DNS Alert Types
| 
                                                             Link to Rule  | 
                                                        
                                                             Source(s)  | 
                                                        
                                                             Link to XDR Event Name  | 
                                                    
|---|---|---|
| 
                                                             Rules Contributing to DNS Query to TOR Proxy Domain Alert Type
                                                                  | 
                                                        
                                                             Developed internally by Stellar Cyber  | 
                                                        dns_tor_proxy_domain | 
| 
                                                             Rules Contributing to Phishing Domain with File Extension TLD Alert Type
                                                                  | 
                                                        
                                                             Developed internally by Stellar Cyber  | 
                                                        dns_phishing_file_extension_tld | 
| 
                                                             Rules Contributing to DNS Query to External Service Interaction Domains Alert Type
                                                                  | 
                                                        
                                                             SigmaHQ  | 
                                                        |
| 
                                                             Rules Contributing to DNS Query to Monero Crypto Coin Mining Pool Domains Alert Type
                                                                  | 
                                                        
                                                             SigmaHQ  | 
                                                        |
| 
                                                             Rules Contributing to DNS Query to Anonymous File Upload Domains Alert Type
                                                                  | 
                                                        
                                                             Developed internally by Stellar Cyber  | 
                                                        
Rule-Based OCI Alert Types
Rule-Based Traffic Alert Types
Rule-Based Windows Alert Types
Windows-related rules require the updated Windows Detection Profile (Low Volume) in the sensor profile settings.
