Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
Detects HTTP GET requests originating from internal hosts to external destinations where the User-Agent string contains 'AutoIt'. This behavior is indicative of the DarkGate malware downloading additional payloads or components using AutoIt scripting capabilities.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
Detects the installation of a specific known malicious npm package named 'tw-pkgprobe-7731' via the command line, which may indicate a supply chain compromise or an attempt to execute malicious code within a development environment.
Detects Node.js processes establishing network connections to common webhook relay and collection services, which may indicate data exfiltration or credential theft.
Detects DNS queries for the domain 'pdf.gusercontent.com', which is known to be used as a lookalike domain for Google-related services to deceive users. This pattern is often indicative of malicious infrastructure used for credential harvesting, phishing, or malware delivery.
Detects unauthorized outbound network traffic from browser processes to the lookalike domain 'pdf.gusercontent.com'. This domain is associated with a malicious Firefox browser extension, 'PDF Identity Verifier', which is designed to exfiltrate session telemetry and data from Google account sessions.
Detects the execution of PowerShell scripts located in Windows temporary directories (AppData/Local/Temp or Temp) that utilize common evasion flags such as hidden window style, bypass execution policy, or non-interactive mode. This behavior is frequently associated with initial stagers, droppers, or malicious script execution.
This rule detects PowerShell commands that attempt to reassemble a Base64-encoded payload from multiple concatenated variable fragments. It specifically looks for patterns where filler characters ('*' or '?') are stripped from the payload before it is passed to the [Convert]::FromBase64String method. This technique is commonly used to evade static string analysis and signature-based detection.
Detects the Windows Character Map utility (charmap.exe) loading suspicious modules such as amsi.dll or clr.dll followed by a process execution involving PowerShell or an unidentified command string, which is indicative of DLL side-loading or process hollowing techniques for malicious code execution.
Detects the execution of PowerShell with encoded commands that explicitly perform base64 string decoding using 'FromBase64String'. This pattern is frequently used to obfuscate scripts or payloads, often seen in downloader stagers or malicious scripts to bypass security controls.
Detects modifications to Windows Registry Run and RunOnce keys by processes other than standard system binaries and known management tools. Such modifications are a common method for achieving persistence by ensuring malicious code executes upon user logon.
Detects execution of rundll32.exe from non-standard locations or utilizing specific exported DLL functions often associated with bypassing application whitelisting, executing scripts, or proxying malicious code execution.
Detects the use of PowerShell to modify Windows Defender configuration settings, specifically targeting the disabling of real-time monitoring, behavioral monitoring, or other security protections via the Set-MpPreference cmdlet.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell where the task binary path resides in suspicious directories frequently used by adversaries for staging, such as AppData, Temp, Downloads, or Public folders.
Detects the installation of a potential remote monitoring and management (RMM) agent via common tools like msiexec, nssm, or sc.exe, followed by consistent HTTPS beaconing to domains hosted on Azurewebsites.net. This pattern is indicative of unauthorized remote access tools used for command and control.
This rule detects a malicious execution chain starting with an MSI file being launched by explorer.exe from user-downloaded folders. The installer spawns chrome.exe, drops a specific loader file (e.g., PavokwiLoader.exe or Loader.exe) into the %LOCALAPPDATA%\Temp\modules\ directory, and establishes persistence via the HKCU 'Load' registry value pointing to that location.
Detects a sequence of multiple process injection-related API calls (VirtualAlloc, WriteProcessMemory, CreateRemoteThread) initiated by a process. This rule monitors for patterns indicating cross-process memory manipulation which is commonly used to inject malicious code into other processes. It specifically looks for API calls interacting with kernel32.dll and filters out known Microsoft security products.
Detects a dual persistence mechanism where an adversary establishes both an identically-named Registry Run key and a Scheduled Task, both masquerading as legitimate Canon or Stardock configuration software. These artifacts are configured to launch side-loaded host binaries (COTFileReadApp.exe or DeElevate64.exe) to maintain persistence on a Windows host.
Detects a loader module and a corresponding RIFF/WAVE file that utilizes steganography to conceal a secondary malicious payload. The loader extracts the payload from the WAV file using specific offsets and XOR decoding, then executes it in memory. This pattern is characteristic of a DLL sideloading chain involving WMPCL.dll and WPFLocalizeExtension.dll.
Detects the execution of PowerShell scripts that utilize large arrays of negative integers to reconstruct and dynamically execute code via the [scriptblock]::Create method. This technique is commonly used to obfuscate malicious payloads such as downloaders or API calls from static analysis.
Page 118 of 1870


