Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a sequence of multiple process injection-related API calls (VirtualAlloc, WriteProcessMemory, CreateRemoteThread) initiated by a process. This rule monitors for patterns indicating cross-process memory manipulation which is commonly used to inject malicious code into other processes. It specifically looks for API calls interacting with kernel32.dll and filters out known Microsoft security products.
Detects a dual persistence mechanism where an adversary establishes both an identically-named Registry Run key and a Scheduled Task, both masquerading as legitimate Canon or Stardock configuration software. These artifacts are configured to launch side-loaded host binaries (COTFileReadApp.exe or DeElevate64.exe) to maintain persistence on a Windows host.
Detects a loader module and a corresponding RIFF/WAVE file that utilizes steganography to conceal a secondary malicious payload. The loader extracts the payload from the WAV file using specific offsets and XOR decoding, then executes it in memory. This pattern is characteristic of a DLL sideloading chain involving WMPCL.dll and WPFLocalizeExtension.dll.
Detects the execution of PowerShell scripts that utilize large arrays of negative integers to reconstruct and dynamically execute code via the [scriptblock]::Create method. This technique is commonly used to obfuscate malicious payloads such as downloaders or API calls from static analysis.
Detects a sequence of distinct system and network reconnaissance commands typically performed by malware or RATs for environment fingerprinting. The rule triggers when three or more unique reconnaissance activities—such as querying antivirus status, enumerating network adapters, checking domain information, or listing installed software—occur from the same host within a 5-minute window.
Detects malicious DLLs identified by specific exports and imports (e.g., rdCore.dll, I++u.dll) that are intended to be sideloaded by signed binaries such as Canon's COTFileReadApp.exe or Stardock software. The detection relies on identifying the combination of sideloaded component names and the presence of suspicious import structures characteristic of these specific staging loaders.
Detects instances where the GOMCam2024 executable launches or spawns a Chrome process with specific command-line arguments involving the user-data-directory being set to the system Temp folder. This behavior is often indicative of process injection, proxy-based credential theft, or attempts to execute browser sessions in a non-standard, potentially malicious context.
Detects the creation of a Windows scheduled task using 'schtasks.exe' or the system's scheduled task creation event where the command line or task details contain the string 'psychedelicloveUtils'. This pattern is often indicative of specific malicious persistence mechanisms or automated task-based payloads.
This rule detects the creation or modification of browser native messaging host configuration files (e.g., com.lunex.explorer.json) combined with the simultaneous or subsequent termination of common web browsers. This pattern is indicative of potential browser hijacking, where an adversary sets up a malicious native messaging host to facilitate persistence or intercept browser communications and subsequently restarts or terminates the browser process to reload the configuration.
Detects the execution of msiexec.exe to install an MSI package from a remote URL. This pattern involves the Windows Installer utility being invoked by explorer.exe with the /i (install) and /passive (unattended installation) flags, indicating a potentially malicious download and execution chain often used to deliver payloads via social engineering.
Detects the exploitation of the CMSTPLUA COM-object (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7) to bypass User Account Control (UAC). The rule monitors for PowerShell processes instantiating this object, followed by the execution of a hidden-window PowerShell process, bypassing the consent.exe UAC prompt.
This rule detects a multi-tool attack chain involving the Cairn autonomous exploitation engine and the Hermes Agent. It flags the co-occurrence of outbound network traffic to both the DeepSeek API (Cairn engine) and the Anthropic Claude API (Hermes Agent) from the same host within a one-hour window. This behavior is indicative of an automated, AI-driven post-exploitation orchestration campaign.
Detects an endpoint initiating outbound network connections to three or more distinct LLM provider APIs (DeepSeek, Qwen, Mistral, Gemini) within a short timeframe (15-minute windows). This behavior aligns with the multi-provider voting mechanism used by the CLOSEDQUORUM post-compromise framework to autonomously determine subsequent actions using diverse generative AI models.
Detects a suspected automated exploitation sequence where a web storefront file (e.g., .phtml, .js, .php) is modified to inject malicious script code (skimmer), followed by an unauthorized SQL DELETE operation on sensitive database tables containing payment, customer, or order information, originating from the same host within a 6-hour window.
Detects evidence of the CARBONATO post-exploitation pattern, specifically identifying the installation of a Hermes Agent by monitoring the creation of a 'SOUL.md' persona file within a '.hermes' folder, followed by correlated outbound network traffic to a specific LLM gateway or known Vercel proxy infrastructure used for command relay.
Detects a specific command and control (C2) communication pattern characteristic of RatHat malware, involving the retrieval of HTML overlay templates followed by the submission of captured form or credential data from the same device within a one-hour window.
Detects instances where a Node.js process (node.exe) initiates command-line interpreters (cmd.exe, powershell.exe) with specific arguments or command lines associated with administrative or potentially obfuscated/automated script execution. This is a common pattern for post-exploitation activities or legitimate administrative automation.
Detects the presence of Node.js runtime files (node.exe, index.js) or script-based agents (vbs, ps1) located within user-profile paths (AppData) that mimic legitimate Windows system folders. This pattern is characteristic of masquerading techniques used to stage or run malicious agents under the guise of system components.
Detects the compilation of a Managed Object Format (MOF) file using mofcomp.exe from the temporary directory of the MSSQL service account. This behavior is indicative of an attacker leveraging the xp_cmdshell procedure in MSSQL to deploy a malicious MOF file, which registers a WMI permanent event subscription to establish persistence or facilitate secondary payload execution.
Detects a successful authentication to Microsoft SQL Server using the 'sa' account from a non-local address. This rule is designed to alert on potentially unauthorized access following a brute-force attack, as identified by the correlation of high-volume authentication failures (Event ID 18456) followed by a successful login (Event ID 18453/18454).
Detects the modification of the Image File Execution Options (IFEO) registry key for 'smss.exe' to set a Debugger value. This technique is often used for persistence, whereby an adversary redirects the execution of a legitimate system process to a malicious executable (e.g., a renamed binary like svchost.exe located outside of System32).
Page 119 of 1870
