Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the ChainScript RAT, executing via a masqueraded Node.js process, enumerating Local Extension Settings for browser wallet plugins. This reconnaissance activity is a precursor to exfiltrating crypto wallet data.
Detects the spawning of script interpreters or loaders by Visual Studio Code (Code.exe) shortly after a workspace is initialized, specifically looking for command-line arguments referencing .vscode or tasks.json. This behavior is consistent with exploitation techniques where a user accepts a 'Trust Workspace' prompt, allowing malicious tasks defined in a repository's .vscode folder to execute.
Detects specific malicious archive payloads associated with NeedyMantis that contain a second-stage loader and spoofed system DLLs (e.g., dnsapi.dll, ws2_32.dll, msvcrt140.dll). These archives utilize XOR encoding or RtlDecompressBuffer packing and are designed for DLL sideloading.
Detects the NeedyMantis first-stage loader (e.g., WinSparkle.dll variants) which employs anti-debug techniques such as NtQueryInformationProcess and ThreadHideFromDebugger, alongside stack-based string deobfuscation, to prepare for the extraction and execution of a secondary payload (e.g., encryptbase64.ps1).
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
Detects the execution of PowerShell commands using '[scriptblock]::Create' in conjunction with character array decoding or large negative integer-array patterns. This technique is commonly used to deobfuscate and execute obfuscated PowerShell scripts at runtime.
Detects the execution of known Canon or Stardock software binaries (COTFileReadApp.exe, DeElevate64.exe) when spawned by msiexec.exe from non-standard locations such as Temp or AppData directories. This pattern is indicative of potential defense evasion, where adversaries leverage legitimate software to proxy execution or potentially perform side-loading activities.
Detects the creation of Windows Registry Run keys with names mimicking known applications (e.g., 'Canon Configuration Reader' or 'Stardock DeElevation Tool'). These naming patterns are highly suspicious and indicative of attempts to achieve persistence or perform defense evasion via registry-based autostart execution.
Detects execution of msiexec.exe via the Windows Run dialog (launched by explorer.exe) that utilizes a remote URL for an MSI installer alongside suspicious property flags ('ORG_NOTE', 'passive'). This pattern is associated with 'ClickFix' social engineering campaigns where users are instructed to copy-paste commands to 'fix' a display issue, leading to the execution of malicious installers.
Detects instances where identified RAT-associated or potentially malicious parent processes spawn command-line interpreters (e.g., cmd, powershell) or execute archive management commands, which is indicative of secondary stage payload deployment or automated execution following initial compromise.
Detects network connection attempts to known public DNS-over-HTTPS (DoH) resolvers from specific binaries identified as host processes for SectopRAT, a malware often associated with ClickFix social engineering campaigns.
Detects the creation of files associated with Psychedelic Stealer's persistence mechanism. The malware establishes persistence by installing a malicious native messaging host configuration file (com.lunex.explorer.json) and associated malicious scripts (host.ps1 or host.bat), which allows it to intercept and manipulate web browser native messaging.
Detects the creation of files associated with Psychedelic Stealer's persistence mechanism. The malware establishes persistence by installing a malicious native messaging host configuration file (com.lunex.explorer.json) and associated malicious scripts (host.ps1 or host.bat), which allows it to intercept and manipulate web browser native messaging.
Detects the use of PowerShell with a hidden window ('-w hidden') to execute the 'Add-MpPreference' cmdlet to configure Windows Defender exclusions. This combination is often indicative of malicious activity, such as attempting to bypass security controls stealthily following a UAC bypass or initial access.
This rule detects the creation of a scheduled task named 'psychedelicloveUtils' on Windows systems. This specific task name is associated with the persistence mechanism of the Psychedelic Stealer malware. The detection leverages command-line monitoring for the task creation request and identifies related file-system modifications in the Windows task registry structure.
Detects suspicious execution patterns involving msiexec where a PowerShell process launches or is the parent of an MSI installation occurring from the %TEMP% directory with a GUID-based filename, or when msiexec executes an application from within %AppData%\Local\Programs. This pattern is often associated with fileless malware, ClickFix-style social engineering attacks, or suspicious persistence/installation behavior.
Detects instances where an unexpected process loads both 'amsi.dll' and .NET runtime modules ('clr.dll' or 'mscoree.dll'). This behavior is frequently associated with malicious, position-independent shellcode that attempts to disable AMSI scanning and host the CLR in-memory to execute malicious .NET assemblies or payloads, avoiding standard .NET execution environments like PowerShell or msbuild.exe.
Detects the execution of known remote-access or screen-sharing software (e.g., TeamViewer, AnyDesk, RDP) within 30 minutes of launching common video conferencing applications (e.g., Zoom, Teams, Google Meet). This pattern is consistent with an adversary remotely assisting an unauthorized user during a live coding interview or similar assessment process.
Detects a specific behavioral chain associated with the CHOSEN BRICK implant. This rule identifies when a suspected malicious process writes image/screenshot files (.png, .jpg, .bmp) to disk, followed by a network connection to the Telegram Bot API within a 15-minute window, suggesting potential data exfiltration.
This rule detects the creation, modification, or renaming of files within specific sensitive directories under Local AppData (such as ComponentTask33, INetCache/FilterManager, or Shell/RemoteTempPrimary) that are closely timed with the execution of a PowerShell script named '*_scatter.ps1'. This behavior is indicative of potential malicious staging, data dropping, or modular deployment associated with a specific script-based attack chain.
This rule detects suspicious process lineage where Python (python.exe or pip.exe) is initiating the execution of Windows command shell (cmd.exe) or Windows calculator (calc.exe). This pattern is often associated with exploitation of malicious Python site-hook files or similar techniques where a Python environment is leveraged to spawn secondary processes, potentially leading to unauthorized command execution.
Page 121 of 1870

