Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects browser extension updates that request a combination of high-risk permissions capable of account takeover (e.g., cookies, webRequest, identity) for extensions previously classified as low-risk. This pattern often indicates a supply chain compromise where a benign extension is acquired and subsequently updated with malicious capabilities.
Detects PowerShell command execution that combines typical Active Directory or system reconnaissance commands with potential persistence mechanisms, which is a common indicator of post-exploitation activity.
Detects DLLs potentially associated with the 'Lorem Ipsum Loader' malware family. These DLLs are designed to sideload into legitimate applications and contain embedded shellcode that is encoded as a sequence of English words to bypass entropy-based detection. The rule looks for the presence of the word-encoded blob alongside specific filenames commonly used in this sideloading technique.
Detects the establishment of persistence on a Windows host by monitoring both Registry Run/RunOnce key modifications and Scheduled Task creation. The rule specifically looks for command lines or registry values that reference common Windows binary names (e.g., Microsoft Edge/Teams update helpers, LockScreenContentServer) which are frequently used by adversaries for masquerading.
Detects instances where the IIS worker process (w3wp.exe) spawns the Windows command shell (cmd.exe) to execute common reconnaissance commands such as whoami, hostname, systeminfo, and net user. This behavior is strongly indicative of post-exploitation activity following a successful web shell deployment on a web server.
Detects ClickFix-style attacks where a user is tricked into copying and pasting malicious, often obfuscated, commands into the Windows Run dialog or a command prompt. The detection identifies suspicious parent processes (like explorer.exe) spawning shell interpreters (powershell.exe, cmd.exe, mshta.exe) with inline encoded payloads or remote content retrieval patterns. It correlates these process executions with recent entries in the Windows RunMRU registry key to identify commands triggered via the Run dialog.
Detects the execution of MSP360 or generic RMM-labeled binaries originating from common user download directories (Downloads or Temp folders) when the filename mimics common phishing lures such as invoice, e-card, RSVP, or document-related naming conventions. This activity indicates a potential social engineering attempt to execute remote monitoring and management tools.
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
This rule monitors endpoint telemetry (DNS queries, network connections, file creation, and process execution) to identify matches against a predefined list of known malicious indicators, including IP addresses, domains, and file hashes (SHA256). The rule differentiates between confirmed malicious activity and low-confidence indicators, providing a prioritized view of potential threats.
Detects file system activity indicative of Royal and BlackSuit ransomware, specifically monitoring for the creation of ransom notes like 'README.TXT' or 'README.BlackSuit.txt' and mass renaming/encryption of files using extensions associated with these families (.royal, .royal_u, .blacksuit).
Detects suspicious behavior by the IIS worker process (w3wp.exe) indicative of web shell deployment, specifically the spawning of command interpreters (cmd.exe, powershell.exe) or the writing of .aspx files. This activity is consistent with exploitation campaigns targeting MOVEit Transfer, such as those conducted by the Lace Tempest (Cl0p) group.
Detects the Akira ransomware binary staged as C:\storage\win.exe and identified by its known SHA256 hash
Detects the Akira ransomware binary staged as C:\storage\win.exe and identified by its known SHA256 hash
Detects the GOST tunnel binary deployed as svchost.exe from a staging directory, identified by its known hash, or by an unsigned PE importing config.dll with a matching MZ header and embedded config.dll reference (reduces FPs from legitimately signed software that imports a DLL of the same name)
Detects the GOST tunnel binary deployed as svchost.exe from a staging directory, identified by its known hash, or by an unsigned PE importing config.dll with a matching MZ header and embedded config.dll reference (reduces FPs from legitimately signed software that imports a DLL of the same name)
Detects the execution of PowerShell with a bypass execution policy that performs a download or web request to save content to a file in the user's temp directory, followed by the immediate execution of that file. This pattern is characteristic of multi-stage malware droppers or fileless attack techniques attempting to stage and execute malicious scripts from temporary locations.
This rule monitors DeviceProcessEvents for the execution of known malicious binaries associated with the SilverFox malware. It specifically looks for occurrences of three distinct SHA256 file hashes within the last 30 days.
Detects SQL injection exploitation attempts against MOVEit Transfer targeting the CVE-2023-34362 vulnerability, followed by the deployment and subsequent interaction with the 'human2.aspx' webshell associated with Cl0p ransomware mass-exploitation campaigns.
Detects modifications to registry keys associated with the 'ms-settings' protocol handler. Adversaries often abuse these keys to perform UAC bypass by injecting a command into the 'shell/open/command' registry path for auto-elevating Windows binaries like fodhelper.exe, eventvwr.exe, sdclt.exe, or ComputerDefaults.exe.
This rule detects instances where wscript.exe spawns iexplore.exe. This behavior is highly suspicious because Microsoft Windows Script Host (wscript.exe) is typically used for running VBScript or JScript files, and it rarely requires launching Internet Explorer (iexplore.exe). Such execution chains are often used by malware or malicious scripts to bypass security controls or to execute code within the context of a browser process.
This rule detects network communication attempts to a specific set of domains associated with the AgtaBackup Remote Access Trojan (RAT). It monitors DeviceNetworkEvents for outbound connections directed toward known command-and-control (C2) infrastructure used by this threat actor.
Page 10 of 1866




