Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where FortiClient EMS management daemon processes (FCMDaemon.exe, FortiClient_Server.exe, or FCMWebServer.exe) spawn suspicious child processes often associated with living-off-the-land techniques, such as command shells, scripting interpreters, or system administrative utilities.
Detects the loading of Python DLLs (python36.dll or python37.dll) from suspicious, non-standard user-writable directories such as Downloads, Temp, or AppData, which may indicate a DLL sideloading attempt.
Detects the use of PowerShell to modify Windows Defender exclusions by adding a path or process located in user-controlled directories (Downloads, Temp, AppData). This behavior is characteristic of adversaries attempting to suppress security alerts for malicious binaries masquerading as legitimate software.
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
Detects unauthorized creation, modification, or deletion of Group Policy Objects (GPOs) at the Active Directory domain root. This activity is a high-confidence indicator of potential persistence or domain-wide configuration tampering, often observed during ransomware attacks or privilege escalation attempts where attackers weaponize Group Policy.
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
Detects the use of native Windows utilities such as vssadmin.exe, wmic.exe, and diskshadow.exe to delete volume shadow copies. This is a common technique used by ransomware and other malware to prevent system recovery.
This rule detects modification of the Windows Registry to disable the Windows Firewall. Specifically, it monitors for EventID 4657 (A registry value was modified) where the 'EnableFirewall' value is set to '0' within the FirewallPolicy service registry path, indicating an attempt to disable the host-based firewall.
Detects the creation or execution of a scheduled task named 'CreateObjectTask' via schtasks or PowerShell, which is associated with spawning 'dllhost.exe' as a child process under high-privileged parent processes (svchost, taskeng, or schtasks). This behavior is indicative of potential COM hijacking or privilege escalation techniques leveraging system tasks.
Detects the use of PowerShell to perform COM database enumeration, often associated with OleViewDotNet or NtObjectManager tools, specifically looking for indicators of COM object querying such as InProcServer32 path identification.
This rule detects the use of PowerShell cmdlets often associated with enumerating COM object registrations, specifically targeting 'InProcServer32' registry keys. Such enumeration is a common reconnaissance step for identifying 'dangling' COM objects—registrations that point to missing or non-existent files—which can be exploited to achieve DLL Hijacking or persistence via COM hijacking.
Detects the dllhost.exe process, running with SYSTEM privileges, loading a dynamic link library (DLL) from a user-writable path within the ProgramData directory. This behavior is consistent with the abuse of COM marshaling, specifically exploiting dangling CLSID entries to force a privileged COM host process to unmarshal and load an attacker-controlled DLL.
This rule detects the presence of Vidar Stealer version 2.0+ by identifying the specific ARX-based (Addition-Rotation-XOR) stream cipher implementation. The detection logic searches for stable cryptographic constants (FNV-1a prime and golden-ratio constants), unique per-build ARX transformation constants, and specific post-decryption artifacts in the file's binary content.
Detects the accumulator-based virtual machine (VM) skeleton used by Vidar Stealer (v2.0+) to obfuscate its internal configuration and strings. The rule specifically identifies a combination of bit-manipulation and arithmetic primitives (ROR, ROL, NOT, IMUL, ADD, SUB, XOR) acting as a dispatcher pattern within highly entropic executable sections, which is a characteristic behavioral artifact of the Vidar Stealer obfuscation engine.
Detects the presence of specific .NET deserialization gadget chain components (ExpandedWrapper, XamlServices, ObjectDataProvider, LosFormatter) within application traffic or logs, which are indicative of exploitation attempts targeting SharePoint pre-authentication remote code execution vulnerabilities like CVE-2026-65660.
Detects malicious HTTP POST requests targeting SharePoint servers that attempt to inject 'Register' directives into pages or manipulate WebPartPage ToolPane markup, indicative of attempts to bypass SafeControls or exploit vulnerable SharePoint features for code execution.
Detects JavaScript code within HTML pages designed to block browser developer tools (F12, Inspect, View Source) using keydown event listeners. This technique is commonly associated with ClickFix-style phishing campaigns to prevent users or security analysts from inspecting malicious page content or fake CAPTCHA overlays.
Detects malicious exploitation attempts against the SharePoint WebPartPages.asmx SOAP endpoint. Attackers use this endpoint to bypass security patches by invoking template-parsing functions like GetWebPartPageConnectionInfo, which facilitates Register-directive injection and XamlServices deserialization chains for remote code execution.
Page 135 of 1870


