Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
Detects instances where AI-assisted development tools (such as Claude, Codex, Copilot, or Gemini) initiate command-line processes (e.g., shells, interpreters, or network utilities) with arguments indicative of credential access, reconnaissance, or sensitive file interactions.
Detects an exploitation chain originating from a Chrome browser process, characterized by the execution of an anomalous child process followed by the creation of an executable file named 'chrome_cleanup.exe' within a short time window. This sequence is indicative of multi-stage exploitation, involving remote code execution via browser vulnerability and subsequent privilege escalation.
Detects the use of PowerShell's Start-Sleep cmdlet with a duration of 3 minutes or longer within process command lines. This technique is commonly used by malware, such as ClickFix-style droppers, to bypass sandbox time-based analysis by delaying execution until the sandbox timeout period has elapsed.
Sweeps Defender Advanced Hunting telemetry for known Sauron Loader indicators: 5 malicious SHA256 hashes (MSI installer, rnp.dll loader, tdwp.dll decrypter, embedded RSA private/public key blobs) across file/process/image-load events, plus 4 C2 domains and their full URLs across network and DNS telemetry. No IP indicators were published in the source reporting (C2 is domain-based over HTTPS) — the IP bucket is intentionally omitted rather than filled with placeholder data.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
This rule detects suspicious PowerShell execution initiated by a Node.js process (node.exe). It monitors for command lines containing common bypass flags (-NoProfile, -NonInteractive, -ExecutionPolicy Bypass) and a specific string pattern 'wra-ps-', which is often associated with malicious scripts or remote access trojans (RATs) being executed via a Node.js application.
This rule detects suspicious activity where a node.exe process, often associated with a node-pty terminal emulation, launches common Windows command-line shells (cmd.exe, powershell.exe) from specific file paths or directories. This behavior is indicative of a Node.js-based Remote Access Trojan (RAT) or shell spawning mechanism being used to establish command and control or persistence on a Windows host.
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
Detects known file hashes associated with SideCopy/ReverseRAT.
Detects known file hashes associated with SideCopy/ReverseRAT.
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.
Detects a behavioral chain where a process establishes persistence using a 'WindowsUpdate' Registry Run key or a scheduled task, followed within five minutes by an outbound network connection from the same process. The rule specifically excludes cases where a ZIP file was written to disk, identifying potential in-memory staging for exfiltration.
Page 140 of 1870


