Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
53 detections
Filters
Last updated
All Time
Detection languages
47
3
3
Contributors
53
Categories
20,020
11,432
5,769
4,979
4,820
Platforms
42
6
5
3
Products / Services
22
12
6
3
2
MITRE Techniques
8
8
7
6
4
CVEs
3
2
2
2
1
IDS Classtypes
1
1
1
IDS Protocols
1
1
1
Detects screen-recording or AI voice-transcription applications (iTop Screen Recorder, Krisp, Caption.Ed) running within 60 minutes of an active videoconferencing session, consistent with PurpleDelta operators recording or transcribing interviews or meetings to generate scripted answers.
Detects an AutoIt3.exe/OptiDrive.exe process performing WMI sandbox-fingerprinting queries (Win32_DiskDrive, Win32_VideoController) followed within 15 minutes by access to browser credential files, consistent with ACRStealer's anti-analysis check preceding data collection.
Detects DCRCVDrv.sys driver used in ACRStealer BYOVD campaign via attacker-specific hashes, certificate serial, or atypical staging path; vendor metadata and PDB are supportive only
Detects installation or execution of AnyDesk, Google Remote Desktop, or MobaXterm from user-writable directories (Downloads, Temp, AppData) outside the approved software baseline, excluding code-signed installs pushed via Intune/SCCM.
Detects the unsigned/untrusted AutoIt interpreter binary OptiDrive.exe staged under the masquerade path %LOCALAPPDATA%\DriveOptimize Technologies\, mimicking legitimate 'DriveOptimize Technologies' software.
Detects execution of RClone from non-standard directories or outbound transfer to cloud endpoints outside an approved destination list, consistent with Gunra's pre-encryption data-exfiltration tooling.
Detects Impacket-style (wmiexec, secretsdump, atexec, psexec.py, smbclient.py) and PsExec SMB admin-share lateral movement, excluding approved IT admin accounts and management servers.
Detects RDP-based lateral movement, including pivots into VDI, AD, and authentication infrastructure, excluding known bastion/jump hosts and flagging sessions from atypical source workstations or off-hours timing.
Detects remote process creation via wmic.exe/WmiPrvSE.exe and suspicious WMI event subscriptions, excluding known configuration-management platform service accounts (SCCM, Ansible, Puppet) and requiring the WMI connection to be the first-ever observed connection between the source/destination host pair.
Detects deletion of Volume Shadow Copies and backup catalogs (vssadmin, wbadmin, wmic shadowcopy, bcdedit) consistent with Gunra ransomware's pre-encryption recovery-inhibition behavior, requiring correlated multi-command deletion sequences to reduce noise from routine backup retention.
Detects OS credential dumping of the Active Directory NTDS.dit database via ntdsutil, VSS-based extraction, or Impacket's secretsdump.py, excluding approved AD backup jobs and accounts.
Detects unusually large 7-Zip/WinRAR archive creation from non-standard staging directories followed by outbound network activity, consistent with Gunra's data-staging step before double-extortion exfiltration.
Detects bulk file copy to staging directories, mass file read access, mailbox-export-rule creation, and bulk PST/mailbox access, excluding DLP/eDiscovery/legal-hold exports tagged with a case ID and scheduled data-migration windows.
Detects OpenSSH installation on Windows hosts, unexpected internal SSH sessions, and SSH tunnels terminating at an external (non-RFC1918) destination — particularly from SSL-VPN admin hosts — excluding documented DevOps CI/CD runners and known bastion hosts.
Detects pass-the-hash and pass-the-ticket lateral authentication using NTLM/Kerberos-ticket reuse across multiple hosts without a corresponding interactive logon, excluding known NTLM-by-design service accounts.
Detects anomalous OneDrive/SharePoint bulk download activity specifically correlated with execution of the named main.exe process, excluding Microsoft-signed sync clients and known enterprise migration tools (SharePoint Migration Tool, ShareGate).
Detects LSASS memory access with credential-dumping-consistent access rights from unsigned or non-allowlisted processes, indicative of Mimikatz-driven credential theft used by Gunra ransomware affiliates.
Detects mass file rename/write events producing the distinctive .ENCRT extension used by Gunra's ChaCha20+RSA-4096 encryptor, scoped narrowly to avoid matching legitimate bulk file operations.
Detects creation of the malicious persistent 'forticloud-sync' super-user account on FortiOS following an anomalous admin WebSocket session, consistent with post-exploitation of CVE-2024-55591/CVE-2025-24472.
Network signature for the specific WebSocket/admin-API request sequence used to exploit the FortiOS/FortiProxy authentication-bypass vulnerabilities CVE-2024-55591 and CVE-2025-24472, as leveraged by Gunra ransomware affiliates for initial access.
Detects certutil.exe -urlcache usage or PowerShell Invoke-WebRequest retrieving main.exe/cryptor.exe or similarly named payloads, followed by execution of the downloaded file, excluding downloads from an allowlist of approved internal software-distribution domains.
Page 2 of 3
