Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of a malicious Electron-based installer masquerading as Anthropic's Claude AI (ClaudeOpus5-desktop.exe). The rule monitors for the specific filename or known malicious hashes, as well as the spawning of an embedded malicious loader process associated with the RevStealer infection chain.
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
Detects a suspicious behavior chain characteristic of information stealers like Vidar. The process first modifies the Windows Registry to disable the Windows Error Reporting (WER) UI (an anti-analysis technique to suppress crash dialogs) and shortly thereafter initiates an outbound network connection to a public IP, likely for C2 communication or data exfiltration.
This rule detects potential execution of Vidar Stealer by identifying specific diagnostic loader strings (e.g., 'Loader: write failed') within file modification and process execution events. The presence of these strings in file metadata or command-line arguments indicates stage-specific activity related to the malware's loading process.
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
This rule detects network connections from internal devices to a list of known malicious domains and IP addresses. These indicators are commonly associated with command and control (C2) infrastructure or malicious activity, and alerting on these connections can help identify compromised systems within the environment.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
This rule identifies suspicious command and control (C2) activity by monitoring network connections to specific known malicious domains, detection of specific authentication tokens in process command lines, and the use of spoofed User-Agent strings associated with predefined C2 URI paths.
Detects instances where wscript.exe spawns cscript.exe with a VBScript file in the command line. This sequence often indicates an attempt to run obfuscated or malicious scripts using built-in Windows scripting engines, which is a common technique for initial access or execution by adversaries.
This rule detects access (creation, modification, renaming, or reading) to browser-specific sensitive credential files ('Login Data' or 'Local State') located in the user data directories of Chrome, Edge, or Brave. It filters out legitimate activity by ensuring the initiating process is not the browser's own application executable, which is indicative of credential theft or dumping by unauthorized tools.
Detects the execution of Windows Package Manager and configuration-related server binaries (WindowsPackageManagerServer.exe, ConfigurationRemotingServer.exe, DSCourier.exe) when not initiated by the authorized 'winget.exe' process. The rule further correlates these processes with the absence or delayed loading of the 'Microsoft.Management.Configuration' library, which may indicate unauthorized usage or tampering with package/configuration management components.
This rule monitors for the creation or renaming of executable files (.exe) within the 'Users\Public' directory. This directory is commonly used by adversaries for staging malicious payloads, as it is writable by standard users and often overlooked by security controls.
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
Detects the execution of PowerShell or Command Prompt with common adversarial flags (e.g., encoded commands, bypass, hidden windows) initiated by the Windows Explorer process. This pattern correlates the execution event with recent user interaction with the Windows Run MRU registry key, suggesting a possible manual execution of malicious commands via the 'Run' dialog box.
Detects usage of msiexec.exe to execute an MSI package from a remote URL. This technique is often used to download and execute malicious installers directly from the internet, bypassing local file storage.
Detects the execution of PowerShell with obfuscation-related flags (-NoProfile, -WindowStyle Hidden, -EncodedCommand) initiated by common scripting interpreters (wscript.exe, mshta.exe, cscript.exe). This pattern is often indicative of malicious scripts, such as HTA or VBScript files, attempting to execute encoded PowerShell commands in a high-privilege context.
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, encoded command) initiated by wscript.exe or mshta.exe. This pattern is commonly used by adversaries to execute obfuscated malicious payloads while proxying the execution through legitimate Windows utilities.
This rule detects potential command-and-control (C2) activity by monitoring network connections to a specific malicious IP address (91.196.32.232) over port 8089 and correlating this with suspicious PowerShell commands. The rule looks for PowerShell scripts executing 'Invoke-RestMethod' to reach out to the C2, as well as obfuscated or beaconing-like behavior involving 'Start-Sleep' intervals paired with C2-related keywords.
Detects the creation or modification of a Windows Registry 'Run' key that triggers a PowerShell script named 'Update.ps1' with hidden execution policies. The rule also captures direct execution of the same PowerShell script via process creation events.
Page 136 of 1870


