Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
Detects unauthorized code injection attempts into web browser processes (chrome.exe, msedge.exe) by non-browser related processes. This behavior involves using APIs like CreateRemoteThread, NtAllocateVirtualMemory, or NtWriteVirtualMemory to modify memory and execute remote threads, which is a common technique used by information stealers such as LummaC2 to bypass browser security controls.
This rule detects potential data staging activity associated with the REMUS malware. It correlates Windows Management Instrumentation (WMI) queries for antivirus information (e.g., 'AntiVirusProduct', 'WbemLocator') with subsequent file creation events in non-standard directories. This behavior is indicative of an adversary preparing or staging system profile data for exfiltration.
Detects a suspicious execution chain where a browser process makes a network connection, followed shortly by a direct execution of command-line tools (powershell.exe, mshta.exe, or cmd.exe) from the Windows explorer.exe process (e.g., via the Run dialog). This behavior is characteristic of 'ClickFix' social engineering attacks where users are tricked into copying and pasting malicious commands from a web page directly into their local environment.
Detects the use of the 'finger.exe' utility in a suspicious manner, indicative of payload staging in a 'ClickFix' phishing attack scenario. The rule monitors for instances where 'finger.exe' is executed with suspicious command-line arguments (containing '@' or '-l') by common parent processes associated with malicious copy-paste activities (cmd.exe, powershell.exe, or explorer.exe).
Detects the execution of Python interpreters from user-writable directories (Temp, Downloads, AppData) when launched by common LOLBins or shell-like parents, which is indicative of the CastleLoader 'ClickFix' phishing chain where attackers deploy a portable Python runtime to execute malicious payloads.
Detects the execution of NetSupport Remote Access Tool (RAT) components (client32.exe, Nskbfltr.sys, or TCCTL32.dll) from locations outside of the standard program installation directories. This behavior is often indicative of unauthorized persistence or masquerading by malware utilizing remote support software for C2.
Detects ClickFix-style browser or explorer spawned command execution using clipboard-paste patterns, or subsequent ransomware-related discovery and inhibit-system-recovery commands such as net.exe, nltest.exe, and vssadmin.exe used after initial access.
Detects the creation of files on disk by a browser process where the Zone.Identifier metadata indicates the origin was a blob:, data:, or about:blank URI. This behavior is indicative of HTML smuggling, where malicious payloads are reconstructed client-side from within an HTML document, bypassing network-based security controls.
Detects a multi-stage Telephone-Oriented Attack Delivery (TOAD) campaign. The first stage identifies phishing emails containing billing or security-themed subjects and phone numbers without links or attachments to evade automated analysis. The second stage monitors for the subsequent installation or execution of common remote-support tools (e.g., AnyDesk, TeamViewer, ScreenConnect). A final correlative rule detects these events occurring sequentially on the same host, indicating a high-confidence indicator of a successful callback phishing social-engineering attempt.
Detects the execution of programs directly from the root of a removable or virtual drive (e.g., ISO, IMG, VHD) via explorer.exe. This activity is a hallmark of phishing attacks that leverage container mounting to bypass Mark-of-the-Web (MOTW) security protections, as files extracted from or executed within mounted containers often fail to inherit MOTW metadata.
Detects command-line execution patterns that exhibit hallmark traits of LLM-generated code, such as overly verbose and explanatory comments, appearing alongside common obfuscation or decoding primitives (e.g., base64, iex, eval). This combination suggests the use of AI to assist in creating decoy logic or burying malicious payloads within legitimate-appearing scripts to evade detection.
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
Detects command-line execution patterns that exhibit hallmark traits of LLM-generated code, such as overly verbose and explanatory comments, appearing alongside common obfuscation or decoding primitives (e.g., base64, iex, eval). This combination suggests the use of AI to assist in creating decoy logic or burying malicious payloads within legitimate-appearing scripts to evade detection.
Detects a two-stage activity: first, the potential unauthorized reading or access of LLM provider API keys from files, environment variables, or command-line arguments; and second, the subsequent use of those same credentials to authenticate to LLM provider APIs (OpenAI, Anthropic, Azure, Bedrock) from a different, unrecognized source IP address, indicating potential credential theft and session hijacking.
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.
Detects anomalous, chained execution patterns initiated by AI agents integrated with Model Context Protocol (MCP) servers. The rule identifies a multi-stage sequence involving the invocation of browser automation tools followed by shell execution and subsequent outbound network activity, potentially indicating an AI-driven attack chaining filesystem, shell, or cloud-API access in an unauthorized manner.
Detects anomalous, rapid execution of a high volume of diverse offensive security tools (scanners, exploitation frameworks, and C2 agents) from a single parent process within a short window, which is characteristic of automated LLM-driven orchestration or scripted attack tool chaining.
Detects outbound HTTPS connections to major generative AI inference endpoints originating from non-browser, non-development tool processes at regular intervals. This activity is indicative of beaconing behavior, where malware (specifically families like LAMEHUG) leverages LLM APIs for dynamic command generation, payload obfuscation, or C2 instruction retrieval, bypassing traditional security controls.
Detects endpoint behavior consistent with AI-assisted exploit development, characterized by the execution of reverse engineering and vulnerability research tools (e.g., IDA Pro, Ghidra, AFL) interleaved with frequent outbound network connections to LLM APIs, followed by the local compilation of a new executable or DLL.
Detects coordinated activity patterns across multiple distinct tenant environments within a one-hour window. The rule looks for shared infrastructure (C2 domains), malicious tool hashes, or specific agentic-CLI command line signatures (e.g., related to orchestration, reconnaissance, or exfiltration) that suggest an AI-orchestrated actor or automated attack campaign affecting multiple organizations simultaneously.
Page 138 of 1870

