Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a process obtaining handle access to the LSASS process (Sysmon Event ID 10) followed by the creation of a file (Sysmon Event ID 11) using an extension other than '.dmp'. This behavior is characteristic of adversaries attempting to obfuscate credential dumping activities by bypassing simple extension-based detection rules.
Detects web application server processes (such as IIS, Apache, Tomcat, Java, Nginx, or Node.js) spawning command-line interpreters or system utilities. This behavior is frequently associated with webshell execution or post-exploitation activities following the exploitation of a public-facing application, often seen in VPN or enterprise software compromises.
Detects the creation of files commonly associated with ransomware notes (e.g., README.txt, HOW_TO_DECRYPT.txt) across multiple directories, which is a strong indicator of the impact phase where files have been encrypted and the adversary is providing recovery instructions.
Detects the use of the bcdedit.exe utility to configure the Windows boot configuration to enter Safe Mode (minimal or with networking), immediately followed by the execution of a shutdown command with the reboot flag. This sequence is a known technique utilized by Akira ransomware affiliates to force a system reboot into a restricted environment where security agents and endpoint detection and response (EDR) tools may fail to load, allowing for undetected encryption.
Detects a burst of lateral movement activity characterized by the use of administrative tools like PsExec or NetExec/CrackMapExec to execute commands or services on multiple distinct target hosts from a single source host within a short window. This pattern is commonly associated with ransomware affiliates or threat actors performing reconnaissance and mass deployment of malicious payloads prior to encryption.
Detects remote command execution patterns associated with the Impacket suite (e.g., wmiexec.py, atexec.py, smbexec.py). The detection identifies cmd.exe processes spawned by WmiPrvSE.exe or svchost.exe that contain specific command-line arguments indicative of Impacket's remote execution behavior, such as output redirection to hidden administrative shares or temporary files.
Detects the execution of rclone.exe or renamed binaries with command-line flags indicative of data exfiltration to cloud storage providers such as S3, Mega, OneDrive, or Google Drive. This behavior is frequently associated with ransomware actors, including Akira, Qilin, and Storm-2570, who use Rclone to perform mass exfiltration of sensitive file share data prior to encryption (double extortion).
Detects unauthorized attempts to dump credentials from the Local Security Authority Subsystem Service (LSASS) process. This includes the execution of known credential-harvesting tools (e.g., Mimikatz, LaZagne, pypykatz), the use of system utilities like procdump and comsvcs.dll to dump process memory, and anomalous direct handle access to lsass.exe by non-system processes. This activity is associated with Storm-2570 post-compromise tradecraft.
Detects Active Directory Directory Replication Service (DRSUAPI) GetNCChanges requests originating from a principal or host that is not recognized as a Domain Controller. This behavior is indicative of unauthorized DCSync operations used to dump NTDS.dit hashes, a common technique for credential harvesting associated with ransomware actors like Qilin.
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
Detects the execution of reconnaissance commands designed to enumerate Active Directory domain trust relationships. Attackers, including those associated with ransomware operations like INC Ransom, use these tools to map organizational structures and identify pathways for lateral movement and cross-domain propagation.
Detects the creation of scheduled tasks using schtasks.exe that exhibit behaviors associated with common remote execution tools (e.g., Impacket's atexec.py) or staging from insecure directories like Temp, ProgramData, or network shares. These patterns are frequently used by threat actors, including INC Ransom, for lateral movement and remote execution of malicious payloads.
Detects a multi-stage extortion tactic where a host is targeted by a mass creation of initial decryption-style ransom notes across multiple directories, followed by a subsequent drop of distinct follow-up 'press release' or 'threat' notes within a 30-minute window, indicative of INC Ransom behavior.
Detects unauthorized modification or creation of registry keys under HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\ to maintain persistence for remote access/RMM tools during Safe Mode with Networking. This technique is used by Akira ransomware affiliates to evade EDR and security software.
Detects behavioral patterns associated with the Everest ransomware loader, specifically the execution of a .NET host process from a non-standard parent, potentially indicating process injection, combined with network activity indicative of lateral movement or discovery, such as Wake-on-LAN packets or SMB scanning.
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
This rule detects the loading of the 'vsstrace.dll' module by processes that are not standard system processes or authorized software. The 'vsstrace.dll' is a library used by the Volume Shadow Copy Service (VSS). Unauthorized or unexpected processes loading this DLL may indicate an attempt to interact with or manipulate volume shadow copies, which is a common behavior for ransomware attempting to inhibit system recovery.
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
Remote Scheduled Task Creation via RPC
Cortex XDR
This rule detects the creation of scheduled tasks on a remote host via the Task Scheduler RPC interface (opnum 1, RegisterTask). This interface is commonly abused by lateral movement tools such as Impacket's atexec, SharpTask, and SynkLoader to execute code or establish persistence on a remote system.
Detects a multi-stage loader execution chain, potentially named GHAPPIER, by identifying sequential stages of execution. These stages include initial marker file checks, shell-based command dispatching via curl/wget, renaming and execution of secondary payloads, Node.js-based runtime staging, and the eventual creation of implant artifacts in common paths such as VSCode extensions or hidden directories.
Detects suspicious PowerShell process execution initiated by Windows Explorer, specifically involving WebDAV-related commands or network share mounting indicators. This pattern is commonly associated with attackers attempting to download and execute remote payloads from WebDAV shares to bypass security controls.
Page 107 of 1870




