Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where a Terraform process or its associated provider plugins spawn a Go toolchain process (go.exe) to execute a local package. This pattern is associated with malicious Terraform providers that use this technique to bootstrap second-stage payloads such as the Graphalgo RAT.
Detects the execution of rundll32.exe with the '/sta' command-line flag and a GUID-formatted CLSID. This technique is often used by malware (e.g., DarkME RAT) to proxy execution through COM components, which hides the actual path of the loaded DLL or payload, aiding in evasion.
This rule detects the execution of 'clspack.exe' from within the AppData\Microsoft directory. 'clspack.exe' is a legitimate Windows utility normally residing in System32 or SysWOW64. Execution from user-writable directories like AppData is a common indicator of masquerading or binary hijacking.
Detects potential staging and execution chains involving remote MSI file fetching via msiexec.exe, or the execution of .wsf scripts or registry imports originating from or residing in AppData directories. This behavior is indicative of multistage malware delivery or persistence mechanisms where components are downloaded and executed using LOLBins.
Detects the execution of a file named 'setup.exe' from suspicious user-writable directories (Temp, Downloads, AppData) when the command line arguments contain keywords associated with archive utilities like 7-Zip or Foobar2000. This pattern is indicative of a 'nested installer' technique where legitimate software utilities are leveraged to extract or execute malicious payloads.
This rule detects DLL files being loaded by common archive extraction and setup utilities (7-zip, setup.exe). Adversaries often use self-extracting (SFX) archives or installer wrappers to execute malicious code by placing a malicious DLL in the same directory as the executable to facilitate DLL side-loading or masquerading.
This rule detects network connections on standard web ports (80, 443) initiated by Windows executable files (.exe) to specific, known malicious or suspicious domains (codeonicinc.com, setupsoftwarecenter.com). This pattern is consistent with malware installers attempting to download secondary payloads or communicate with C2 infrastructure.
This rule detects the execution of processes associated with known malicious SHA256 file hashes linked to OpenSUpdater. It monitors DeviceProcessEvents from the past 30 days to identify instances where these specific file hashes are executed on endpoints.
This rule detects network connections originating from hosts to specific remote domains ('codeonicinc.com', 'setupsoftwarecenter.com') which are associated with OpenSUpdater command and control (C2) activity. It leverages Microsoft Defender DeviceNetworkEvents to identify endpoints communicating with these known malicious infrastructure components.
This rule detects the execution of a file named 'setup.exe' that is spawned by common interpreters (explorer.exe, msiexec.exe, powershell.exe, cmd.exe) where the command line arguments reference archiving or compression utilities like 'foobar2000', '7z', or '7zip'. This is a common pattern for self-extracting (SFX) installers or malicious droppers attempting to execute payload components.
Detects potential arbitrary file download using a Microsoft Office application
This rule detects executable files (ending in .exe) executing from a specific subdirectory within the user's AppData path (\AppData\Microsoft\Update\). This path is often used by adversaries to masquerade malicious activity or persistence mechanisms as legitimate update processes. The rule excludes common system service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise, focusing on processes initiated by user-level accounts.
This rule detects the presence of command line artifacts, filenames, and strings associated with the SilverFox malware. These strings indicate the execution of a malicious desktop monitoring component ('active_desktop_launcher.exe') or the use of specific IPC/configuration markers ('@@RAPID_CFG_START@@') characteristic of this threat's tradecraft.
This rule detects the loading of a suspicious DLL file named 'active_desktop_render_x64.dll' or the initiation of activity by a process named 'PDF_C2089_20260911100446.exe', which may indicate the execution of malicious code or potential process injection activity.
This rule detects the modification of Windows Registry Run keys, specifically targeting a value named 'MicrosoftUpdate' within the 'Run' registry path. This is a common persistence technique used by adversaries to ensure malicious programs or scripts automatically execute upon user logon by mimicking a legitimate system update process.
This rule detects the creation or presence of specific file artifacts ('PDF_C2089_20260911100446.exe' and 'active_desktop_render_x64.dll') within the '\AppData\Microsoft\Update\' directory. These file names and paths are characteristic of potential malware staging or persistence mechanisms, specifically associated with the SilverFox threat activity.
This rule detects network connections from internal devices to a specific remote IP address (134.122.155.135) over port 443. This is characteristic of communication with a known or suspicious Command and Control (C2) server.
This rule monitors DeviceProcessEvents for the execution of known malicious binaries associated with the SilverFox malware. It specifically looks for occurrences of three distinct SHA256 file hashes within the last 30 days.
Detects instances where the Adobe ColdFusion service (jrun.exe or java.exe) spawns common command-line shells, administrative tools, or utility processes. This behavior is indicative of potential exploitation of ColdFusion vulnerabilities, such as CVE-2023-26360 or CVE-2023-29298, where an adversary gains initial access and executes commands on the underlying system.
Detects credential dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. The rule identifies processes attempting to access LSASS memory using specific access masks often associated with credential extraction, or the presence of the Mimikatz 'sekurlsa::logonpasswords' command in the process command line.
Detects the creation of a DLL file within the 'ProgramData\CrossDevice\' directory. This path is associated with a dangling COM InprocServer32 registration and does not exist by default. The creation of files in this location by non-privileged processes is indicative of staging malicious DLLs for exploitation of COM-based privilege escalation chains, specifically CVE-2026-66804 and CVE-2026-50343.
Page 110 of 1870


