Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects NeedyMantis-style DLL sideloading: a DLL is dropped at an anomalous ProgramData/ProgramFiles path mirroring known first-stage loader naming/path conventions (masquerading as Poedit, curl, Vim, TightVNC, Office, Broadcom, Intel, or NVIDIA components), AND that exact same DLL is subsequently loaded by a process within 10 minutes. Requiring the corroborating load event (rather than file presence alone) filters out benign drops such as installer staging, AV quarantine copies, or backup/sync tools that never execute the file.
Detects the execution of PowerShell or PowerShell ISE where the parent process is the console host (conhost.exe) and the command-line arguments are either missing, empty, or represent an bare execution of the binary. This pattern is commonly associated with fileless execution techniques where attackers attempt to hide command-line arguments or evade logging.
Detects execution patterns indicative of 'ClickFix' social engineering, where a user is tricked into copying a command to their clipboard and executing it directly in a terminal. The rule monitors for processes that read clipboard contents (via PowerShell or clip.exe) and simultaneously invoke shell interpreters to execute the retrieved data.
Detects unauthorized processes attempting to access sensitive browser profile files, such as login credentials, cookies, and session state files. This behavior is indicative of credential harvesting or session theft by malicious software.
Detects execution of rundll32.exe or regsvr32.exe when spawned by powershell.exe or mshta.exe, specifically targeting DLLs located in common user-writable or temporary directories (AppData, ProgramData, Downloads). This pattern is consistent with the delivery of CastleLoader shellcode loaders following ClickFix-style social engineering lures.
Detects the deployment of NetSupport Manager (client32.exe) or related components when initiated by common scripting interpreters such as PowerShell, MSHTA, or CMD. This behavior is indicative of a ClickFix-style social engineering attack where a user is coerced into executing malicious commands to deploy remote access tools.
Detects the use of legitimate Windows system binaries (LOLBins) such as curl.exe, certutil.exe, or bitsadmin.exe to download files. These binaries are monitored when spawned directly from common entry-point processes like explorer.exe, cmd.exe, or powershell.exe, which is characteristic of second-stage payload retrieval in ClickFix social engineering campaigns.
Page 132 of 1870

