Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects modifications to Group Policy Objects (GPOs) performed by accounts identified as domain administrator-equivalent (based on naming conventions) within 60 minutes of a successful logon from a device, potentially indicating GPO weaponization by an adversary using a compromised account.
This rule detects PowerShell script blocks containing a suspicious combination of Base64-like character sets and Cyrillic characters. This technique is often used in obfuscated payloads to evade static analysis signatures or to hinder human readability by inserting non-Latin characters within encoded content, which may trigger different parsing behaviors in various environments.
Detects unauthorized attempts to disable or modify Windows Firewall settings across multiple devices. The rule identifies suspicious registry modifications, firewall service termination events, or security policy changes that suggest an adversary is attempting to impair defensive mechanisms.
Detects the use of legitimate Windows binaries (Rundll32, Wscript, Cscript, and Regsvr32) to execute scripts, HTML applications, or remote scriptlets. This pattern is commonly associated with adversary techniques to proxy execution of malicious code, bypass application controls, or retrieve payloads from remote servers.
Detects the execution of Windows Terminal, PowerShell, or pwsh processes spawned directly by explorer.exe that do not originate from standard Start Menu search or navigation host processes. This pattern is indicative of the user triggering the 'Power User' (Win+X) menu, often associated with adversary attempts to leverage ClickFix-style social engineering lures that rely on the user interacting with specific UI elements.
FileFix lures append a real-looking file path after a '#' comment character so the Explorer address bar visually shows a benign path while the PowerShell prefix executes silently.
Some FileFix/ClickFix chains pivot execution through the mshta.exe living-off-the-land binary immediately after the Explorer address-bar entry, before dropping the final payload.
FileFix's core mechanism abuses the HTML input type=file element; clicking a lure button launches explorer.exe from the browser while JavaScript copies a disguised PowerShell command to the clipboard.
FileFix loader chains abuse trusted code-hosting platforms like Bitbucket/GitHub to host staged payload components, exploiting domain trust to evade network detection.
FileFix lures append a real-looking file path after a '#' comment character so the Explorer address bar visually shows a benign path while the PowerShell prefix executes silently.
Some FileFix/ClickFix chains pivot execution through the mshta.exe living-off-the-land binary immediately after the Explorer address-bar entry, before dropping the final payload.
FileFix's core mechanism abuses the HTML input type=file element; clicking a lure button launches explorer.exe from the browser while JavaScript copies a disguised PowerShell command to the clipboard.
StealC v2, the payload consistently delivered via FileFix campaigns, is capable of stealing cryptocurrency wallet data alongside credentials and VPN configs.
Acronis TRU (Sept 2025) documented a FileFix campaign where a PowerShell loader downloads images from Bitbucket that conceal embedded malicious components, ultimately deploying a Go-based loader and StealC.
The FileFix StealC campaign's final-stage loader is written in Go and performs VM/sandbox checks plus string encryption before executing the infostealer.
Because FileFix commands are typed/pasted directly into the Explorer address bar rather than downloaded, executed content never receives a Mark-of-the-Web tag, sidestepping SmartScreen-style controls.
A FileFix sibling technique dubbed DownloadFix uses a broken/incomplete download to prompt the victim to manually execute a .cmd file via the browser's Downloads shortcut instead of the Explorer address bar.
Detects evidence of potential adversarial interference with Windows Defender updates and MRT.exe (Malicious Software Removal Tool). The rule correlates high volumes of temporary file creation in user directories with unauthorized access to MRT.exe by third-party processes and repeated Windows Defender update failures, indicating a potential attempt to disrupt endpoint security operations.
After the initial FileFix paste-and-execute step, observed campaigns chain into a secondary download of the real payload using LOLBins or PowerShell web clients.
Acronis reported a multilingual FileFix phishing site using anti-analysis techniques and advanced obfuscation, chaining into a Go-based loader with string encryption before deploying StealC.
This rule detects a behavioral chain characteristic of the KongTuke/LandUpdate808 threat actor group. It identifies the correlation between a browser initiating a network connection to a domain with a low-reputation top-level domain (TLD) and that same browser process launching 'explorer.exe' within a 60-second window. This behavior is associated with social engineering lures (fake CAPTCHA) that encourage users to execute clipboard commands, which trigger file-picker dialogs via explorer.exe to facilitate follow-on malicious activity.
Page 125 of 1870

