Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
This rule detects known malicious activity including network connections to a specific C2 IP address (69.48.229.140), downloading files from specific C2 URLs, the presence of known malicious file hashes (SHA256), and communications involving specific actor-associated email addresses.
Detects attempts to disable Windows Defender by either executing known Defender Control utilities or by modifying registry keys associated with the disabling of anti-spyware features or the WinDefend service startup.
Detects the insertion of a PowerShell download cradle command into the Windows Explorer RunMRU registry key. This activity is indicative of the 'ClickFix' technique, where a user is socially engineered to copy and paste a malicious command into the Windows Run dialog box.
Detects the loading of WPF/XAML-related assemblies (PresentationFramework.dll, System.Xaml.dll, or PresentationCore.dll) by the SharePoint web server process (w3wp.exe). This behavior is highly irregular for typical SharePoint web worker processes and may indicate an exploitation attempt targeting deserialization vulnerabilities leading to remote code execution.
Detects Impacket-style lateral movement patterns where system processes such as services.exe or wmiprvse.exe spawn command shells to copy files from a network share (UNC path) and execute them. This rule specifically looks for evidence of staging binaries or DLLs from remote shares, which is a common behavior of post-compromise frameworks like Impacket when performing 'hands-on-keyboard' actions.
Detects the execution of known tunneling and reverse proxy tools (ngrok, cloudflared, localtunnel) commonly abused by adversaries to create outbound tunnels for C2, bypass firewalls, or exfiltrate data.
Detects indicators associated with the ChatGPT Custom GPT ClickFix campaign across process, network connection, DNS, and HTTP telemetry: known malicious file hashes, C2 IP addresses, the chattypetty.com domain, and known payload-hosting URLs.
Detects process/file hashes associated with the ChatGPT Custom GPT ClickFix
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
Detects process/file hashes associated with the ChatGPT Custom GPT ClickFix
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
campaign via Windows process_creation telemetry. Split from the combined IOC
hunt: Sigma supports only one logsource per rule, so IP/domain/URL matching live
in separate network_connection and dns_query rules.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects the execution of batch or command scripts initiated by SQL Server (sqlservr.exe) or in contexts involving command-line utility misuse often associated with SQL Server exploitation, such as xp_cmdshell or certutil, particularly when involving paths like AppData or ServiceProfiles.
Detects a potential WMI-based persistence mechanism by identifying the sequential execution of mofcomp.exe to compile a MOF file located in a temporary directory, followed by the execution of a VBScript payload using cscript.exe with the /e:VBScript.Encode flag. This pattern is indicative of an attacker attempting to establish persistence via WMI event subscriptions.
Detects the specific behavior of the NeedyMantis malware where a file named 'encryptbase64.ps1' is written to disk but is not subsequently invoked by any PowerShell process. This is indicative of shellcode masquerading as a script file, where the file is loaded directly into a process's memory to perform ROR-based API hashing and unpacking of a minimized PE loader.
This analytic detects suspicious use of 'mshta.exe' or 'rundll32.exe' invoking 'mshtml.dll'
or the 'RunHTMLApplication' export without including a direct HTTP/HTTPS URL in the command line.
This pattern could be associated with obfuscated script execution used by threat actors during
initial access or payload staging. The absence of a visible URL may indicate attempts to evade static
detections by embedding the URL via string concatenation, encoding (e.g., hex), or indirect script loaders
like 'GetObject()'.
or the 'RunHTMLApplication' export without including a direct HTTP/HTTPS URL in the command line.
This pattern could be associated with obfuscated script execution used by threat actors during
initial access or payload staging. The absence of a visible URL may indicate attempts to evade static
detections by embedding the URL via string concatenation, encoding (e.g., hex), or indirect script loaders
like 'GetObject()'.
This analytic detects network connections initiated by binaries that are not typically associated with network communication,
such as 'notepad.exe', 'calc.exe' or 'write.exe'.
It leverages Cisco Network Visibility Module logs to correlate network flow activity with process context, including command-line arguments, process path, and parent process information.
These applications are normally used for locally and do not require outbound network access. When they do initiate such connections, it may indicate process hollowing, code injection, or proxy execution, where adversaries abuse a trusted process to mask malicious activity.
such as 'notepad.exe', 'calc.exe' or 'write.exe'.
It leverages Cisco Network Visibility Module logs to correlate network flow activity with process context, including command-line arguments, process path, and parent process information.
These applications are normally used for locally and do not require outbound network access. When they do initiate such connections, it may indicate process hollowing, code injection, or proxy execution, where adversaries abuse a trusted process to mask malicious activity.
This detection identifies execution of the file synchronization utility "rclone".
It leverages Cisco Network Visibility Module logs, specifically flow data in order to capture process executions
initiating network connections.
While rclone is a legitimate command-line tool for syncing data to cloud storage providers, it has been widely abused by threat actors for data exfiltration.
This analytic inspects process name and arguments for rclone and flags usage of suspicious flags.
If matched, this could indicate malicious usage for stealthy data exfiltration or cloud abuse.
It leverages Cisco Network Visibility Module logs, specifically flow data in order to capture process executions
initiating network connections.
While rclone is a legitimate command-line tool for syncing data to cloud storage providers, it has been widely abused by threat actors for data exfiltration.
This analytic inspects process name and arguments for rclone and flags usage of suspicious flags.
If matched, this could indicate malicious usage for stealthy data exfiltration or cloud abuse.
This analytic detects suspicious use of `rundll32.exe` in combination with `mshtml.dll` and the export `RunHTMLApplication`.
This behavior is often observed in malware to execute JavaScript or VBScript in memory, enabling payload staging or
bypassing script execution policies and bypassing the usage of the "mshta.exe" binary.
The detection leverages Cisco Network Visibility Module telemetry which offers network flow activity
along with process information such as command-line arguments
If confirmed malicious, this activity may indicate initial access or payload download.
This behavior is often observed in malware to execute JavaScript or VBScript in memory, enabling payload staging or
bypassing script execution policies and bypassing the usage of the "mshta.exe" binary.
The detection leverages Cisco Network Visibility Module telemetry which offers network flow activity
along with process information such as command-line arguments
If confirmed malicious, this activity may indicate initial access or payload download.
This analytic detects script execution (`wscript.exe` or `cscript.exe`) triggered from compressed files opened directly using
`explorer.exe`, `winrar.exe`, or `7zFM.exe`.
When a user double clicks on a ".js" file from within one of these compressed files. Its extracted temporally in the temp directory in folder with certain markers.
It leverages Cisco Network Visibility Module (NVM) flow data, in order to look for a specific parent/child relationship and an initiated network connection.
This behavior is exploited by threat actors such as Scarlet Goldfinch to deliver and run malicious scripts as an initial access technique.
`explorer.exe`, `winrar.exe`, or `7zFM.exe`.
When a user double clicks on a ".js" file from within one of these compressed files. Its extracted temporally in the temp directory in folder with certain markers.
It leverages Cisco Network Visibility Module (NVM) flow data, in order to look for a specific parent/child relationship and an initiated network connection.
This behavior is exploited by threat actors such as Scarlet Goldfinch to deliver and run malicious scripts as an initial access technique.
This analytic detects suspicious downloads from common file sharing and content delivery platforms using known living-off-the-land binaries (LOLBins)
such as 'curl.exe', 'certutil.exe', 'msiexec.exe', 'powershell.exe', 'wmic.exe', and others.
It leverages Cisco Network Visibility Module logs to correlate network flow activity with process context, including command-line arguments, process path,
and parent process information. These tools are often abused by adversaries and malware to retrieve payloads from public hosting platforms
such as GitHub, Discord CDN, Transfer.sh, or Pastebin.
This detection helps identify potential initial access, payload staging, or command and control activity using legitimate services.
such as 'curl.exe', 'certutil.exe', 'msiexec.exe', 'powershell.exe', 'wmic.exe', and others.
It leverages Cisco Network Visibility Module logs to correlate network flow activity with process context, including command-line arguments, process path,
and parent process information. These tools are often abused by adversaries and malware to retrieve payloads from public hosting platforms
such as GitHub, Discord CDN, Transfer.sh, or Pastebin.
This detection helps identify potential initial access, payload staging, or command and control activity using legitimate services.
Page 11 of 1866



