Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
5 detections
Filters
Last updated
All Time
Detection languages
2
2
1
Contributors
2
2
1
Categories
3
3
1
1
1
Platforms
4
1
Products / Services
2
1
1
1
1
MITRE Techniques
17,957
15,455
12,307
8,184
6,031
Detects the creation of files named 'strEncodedData.txt' on the local file system. This naming convention is associated with the DarkTortilla RAT, which uses this specific file to stage encoded data prior to exfiltration or further processing.
Detects the java.exe (ActiveMQ) process spawning cmd.exe to run certutil for payload delivery. This is highly indicative of CVE-2023-46604 post-exploitation activity, leading to Metasploit and LockBit ransomware deployment.
Detects a command-line pattern using a ping loopback command to create a delay, a technique used by malware like DarkTortilla/CHAMELEON#NET to evade automated sandbox analysis.
This analytic detects intrusion events from known threat activity using Cisco Secure Firewall Intrusion Events. It leverages Cisco Secure Firewall Threat Defense IntrusionEvent logs to identify cases where one or multiple Snort signatures associated with a known threat or threat actor activity have been triggered within a one-hour time window. The detection uses a lookup table (cisco_snort_ids_to_threat_mapping) to map Snort signature IDs to known threat actors and their techniques. When multiple signatures associated with the same threat actor are triggered within the time window, and the count of unique signatures matches or exceeds the expected number of signatures for that threat technique, an alert is generated. This helps identify potential coordinated threat activity in your network environment by correlating related intrusion events that occur in close temporal proximity. Currently, this detection will alert on the following threat actors or malware families as defined in the cisco_snort_ids_to_threat_mapping lookup: ArcaneDoor, Static Tundra, AgentTesla, Amadey, AsyncRAT, Chafer, DCRAT, Lumma Stealer, Nobelium, Quasar, Remcos, Snake, Xworm. To add or update threat actors, update the cisco_snort_ids_to_threat_mapping.csv lookup file with new or modified threat names and associated Snort signature IDs.
The analytic detects the execution of the Apache Benchmark binary (ab.exe), which is commonly used by MetaSploit payloads. It focuses on process creation events where the original file name is 'ab.exe'. This activity may indicate a MetaSploit attack, potentially leading to unauthorized network connections, system compromise, and data exfiltration. Immediate investigation is required.

