Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the presence or execution of artifacts associated with the TrustSink proof-of-concept (deploy.py, cleanup_eam.py, deploy_state.json), which is used to register or remove rogue Entra authentication providers.
Detects anomalous process spawning behavior initiated by Python interpreters (pip/conda) on machine learning developer or training hosts, which may indicate a supply chain compromise where a malicious package executes code during or shortly after installation.
This rule detects three distinct suspicious behaviors related to potential file manipulation and persistence mechanisms: 1. Use of 'copy /b' command to reconstruct files from fragments (e.g., header.doc, body.doc), commonly associated with file joining or data reconstruction. 2. File access within '_rels' directories targeting document fragments, often used in malicious document analysis or extraction. 3. Execution of 'Windowsupdate.exe' from the 'AppData\Local' directory, a technique often used for masquerading as a legitimate Windows service to establish persistence.
Detects the execution of the Windows FTP client (ftp.exe) using command-line arguments that include scripts (-s:), initiated by unconventional parent processes such as explorer.exe or cmd.exe. This behavior is often associated with the execution of automated FTP scripts for data exfiltration or malware delivery.
This rule detects potential AI/ML supply chain compromise by monitoring for package installations (via pip, conda, poetry, etc.) from non-standard repositories, direct URLs, or version control systems within data science and CI/CD pipelines (e.g., Jupyter, Airflow, Jenkins). It further correlates this activity with subsequent suspicious outbound network connections from the host, which is indicative of slopsquatting or malicious dependency execution.
Detects suspicious processes frequently polling Hugging Face repository endpoints (discussions, raw files, commits). This behavior is characteristic of adversaries using public code/dataset hosting services as a covert command-and-control (C2) channel to fetch instructions or exfiltrate data, bypassing traditional network filters by blending in with legitimate developer traffic.
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
This rule detects a suspicious sequence of events where a process related to Electron (a framework often used for cross-platform desktop applications) executes a hidden, obfuscated PowerShell command, followed by a subsequent PowerShell command to modify Microsoft Defender settings by adding an exclusion path for the 'AppData' directory within 10 minutes of the first process.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
This rule detects the loading of a driver named 'eb.sys' (or matching a specific SHA256 hash) paired with the creation of a Windows service for that driver via the 'sc' command. This behavior is indicative of potential rootkit installation or driver-based persistence mechanisms.
Detects instances of node.exe being spawned by potentially suspicious parent processes like msiexec.exe, wscript.exe, cscript.exe, or explorer.exe, or being executed from unusual locations often associated with malicious staging or masquerading, such as Windows Libraries or Themes directories.
This rule detects Terraform CLI execution of the 'init' command correlated with network access to HashiCorp AWS registry domains, or the presence of Terraform lock files in specific sensitive or project-related directory paths. This combination often indicates infrastructure-as-code management activities or potential misuse of Terraform in a production environment.
Detects execution of Windows Installer packages (MSI) masquerading as common software installers (Spotify, Zoom, Microsoft Teams) using known ChainScript-style naming patterns and suspicious command-line parameters (e.g., ALLUSERS=2, MSIINSTALLPERUSER=1) or invocation from common user-mode applications like cmd.exe, powershell.exe, or explorer.exe.
Detects the execution of regsvcs.exe when initiated by PowerShell, or when invoked with specific command line arguments indicating .NET reflection (GetType, GetMethod, method.Invoke) typically associated with fileless execution or proxying malicious code. The rule specifically targets instances involving .NET Framework directories.
Detects unauthorized access to web browser credential stores (e.g., Login Data, Cookies) by non-browser processes, such as scripting engines (PowerShell, WScript) or common LOLBins (MSBuild, InstallUtil). This behavior is indicative of credential theft or data exfiltration attempts by malicious software, including stealers like PureLog.
Detects access to sensitive cryptocurrency wallet files (e.g., wallet.dat, keystore) by processes typically associated with LOLBins (Living-off-the-land Binaries) like PowerShell, MSBuild, or non-executable utilities. This activity is indicative of credential theft or data staging for exfiltration of cryptocurrency assets.
Page 137 of 1870


