Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects a behavioral fingerprint associated with the NeedyMantis group, characterized by the creation of a DLL and a identically-named, extensionless, encrypted archive file in the same directory within a short time window. This approach identifies the underlying packaging strategy rather than relying on static file names or known paths.
Detects .ps1-named files dropped to disk that are never actually executed by a PowerShell interpreter (powershell.exe / pwsh.exe) within a short window afterward. NeedyMantis's second-stage loader (e.g. encryptbase64.ps1) is raw x64 shellcode, not a real script -- it's read and executed directly by the dropping process, so no genuine PowerShell host process ever references the file by name. Replaces an earlier version of this rule that watched DeviceImageLoadEvents for a .ps1 extension: Windows can only emit an image-load event for a file with a valid PE header loaded via the OS loader, and raw shellcode has no PE header and is never mapped that way, so that approach would not have fired on this malware. Caveat: legitimate deployment tooling that stages a script for delayed or remote execution can also produce this create/execute mismatch; tune the window and add known-good deployment-tool exclusions for your environment.
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects unauthorized processes reading Chromium or Firefox cookie and login stores that specifically reference Claude.ai or Anthropic domains. This rule is designed to identify infostealer malware attempting to hijack active Claude sessions by analyzing process file access and command-line arguments, filtered against known-legitimate security, sync, and development tools. The detection logic mandates corroborating evidence of suspicious execution paths or subsequent outbound network activity.
Detects a fake ClaudeDesktop.exe installer / tampered libcef.dll sideload chain deploying the SectopRAT .NET RAT, requiring multiple corroborating indicators and a PE anomaly consistent with DLL sideloading rather than a single generic string
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
Detects instances where a Claude process accesses a 'SKILL.md' file, followed closely by a suspicious command execution on the same device. The rule specifically targets command-line activity that involves encoding, download-and-execute patterns, staging in sensitive directories, or communication with suspicious domains/IPs, which is indicative of a supply-chain or poisoned agent-skill file attack.
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
Detects unauthorized processes attempting to read or copy sensitive browser data files (e.g., Cookies, Login Data, Local Storage) often targeted by info-stealing malware such as Vidar, LummaC2, or RedLine. The rule filters out legitimate browser-related processes and adds security context by requiring evidence of unsigned code, execution from suspicious locations (Temp/Downloads), or associated outbound network activity to reduce false positives.
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
Detects SectopRAT (Arechclient2) .NET RAT binaries deployed via tampered libcef.dll / JetBrains helper DLL sideloading that harvest browser credentials, cookies, credit card data, and files. Tightened to require combined sideload+family+target indicators plus .NET CLR import evidence, avoiding standalone generic strings.
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
Detects the GitHub Actions runner executing the Bun runtime to run a hidden index.js payload, specifically associated with the compromised 'actions-cool/issues-helper' or 'actions-cool/maintain-one-comment' actions. The rule filters for process execution context tied to GitHub runner internals and validates that the Bun execution follows the pattern observed in these supply chain attacks.
Detects the GitHub Actions runner executing the Bun runtime to run a hidden index.js payload, specifically associated with the compromised 'actions-cool/issues-helper' or 'actions-cool/maintain-one-comment' actions. The rule filters for process execution context tied to GitHub runner internals and validates that the Bun execution follows the pattern observed in these supply chain attacks.
Detects the GitHub Actions runner executing the Bun runtime to run a hidden index.js payload, specifically associated with the compromised 'actions-cool/issues-helper' or 'actions-cool/maintain-one-comment' actions. The rule filters for process execution context tied to GitHub runner internals and validates that the Bun execution follows the pattern observed in these supply chain attacks.
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
Detects the spawning of common administrative or script-execution tools as child processes from SharePoint-related processes (w3wp.exe or OWSTIMER.EXE). This behavior is often indicative of exploitation attempts targeting SharePoint application pools to execute arbitrary code.
Page 134 of 1870

