Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects Sauron Loader stage-2 payload execution: a randomly-named file dropped in %TEMP% and executed within 5 minutes by a native launcher (rundll32/regsvr32/msiexec/cmd/powershell/wscript). Scoped to devices that already show the confirmed rnpkeys.exe side-load from ProgramData\keyroll, turning a very noisy fleet-wide 'temp file executed by native binary' heuristic (matches countless legitimate installers/updaters) into a targeted next-stage check on hosts with corroborated Sauron Loader activity. Also fixes an unused/dead variable and an ambiguous post-join column reference.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
Detects the Sauron Loader vishing chain: a mailbox hit by a high-volume, high-distinct-sender email bombing burst (raised from 20 to 50 emails/hour and now requiring 15+ distinct senders, to exclude single-sender retry loops or broken automation), followed within 2 hours by the same user launching Quick Assist or AnyDesk — consistent with an attacker posing as IT support after the flood. Also fixes a schema bug where EmailEvents was queried with TimeGenerated instead of Timestamp, and a post-join column reference bug.
This rule detects suspicious PowerShell execution initiated by a Node.js process (node.exe). It monitors for command lines containing common bypass flags (-NoProfile, -NonInteractive, -ExecutionPolicy Bypass) and a specific string pattern 'wra-ps-', which is often associated with malicious scripts or remote access trojans (RATs) being executed via a Node.js application.
This rule detects suspicious activity where a node.exe process, often associated with a node-pty terminal emulation, launches common Windows command-line shells (cmd.exe, powershell.exe) from specific file paths or directories. This behavior is indicative of a Node.js-based Remote Access Trojan (RAT) or shell spawning mechanism being used to establish command and control or persistence on a Windows host.
Detects Node.js or ProfileQuickHost processes performing file operations (read, write, rename) on sensitive browser directories, such as 'Local Extension Settings' or wallet-related folders. This pattern is commonly observed in credential-stealing malware attempting to extract browser-stored secrets or cryptocurrency wallet data.
This rule detects network connections from internal devices to a list of known malicious IP addresses associated with command-and-control (C2) infrastructure. It monitors for outbound traffic across all monitored network events on endpoints.
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
Detects known file hashes associated with SideCopy/ReverseRAT.
Detects known file hashes associated with SideCopy/ReverseRAT.
This rule detects malicious activity by monitoring for specific known indicators, including hashes of malicious files (ProcessRollup2), network connections to known C2 infrastructure (NetworkConnectIP4), and URL clicks (UrlClick) associated with malicious domains or paths. It acts as a multi-stage indicator correlation rule to identify execution or communication with known threats.
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
Detects the creation of a Windows scheduled task via schtasks.exe where the initiating process is located in common user-writable temporary or non-standard directories (e.g., AppData, Temp, or Public folders). This behavior is often indicative of malicious persistence mechanisms being established by a dropper or stage-one malware payload.
Detects a behavioral chain where a process establishes persistence using a 'WindowsUpdate' Registry Run key or a scheduled task, followed within five minutes by an outbound network connection from the same process. The rule specifically excludes cases where a ZIP file was written to disk, identifying potential in-memory staging for exfiltration.
TokenGrabber Builder: Webhook XOR/Base64 Obfuscation Artifacts - detects webhook.txt persistence, XOR 0x5A + Base64 webhook obfuscation, WEBHOOK_PLACEHOLDER injection, and the _x() decode routine used to recover the exfiltration endpoint
Detects unauthorized processes (excluding firefox.exe and explorer.exe) accessing or modifying sensitive Firefox browser profile files, specifically places.sqlite (history/bookmarks) and cookies.sqlite (session cookies). This activity is often indicative of credential or session hijacking attempts by malware or malicious scripts.
Detects a sequence of activity where a process queries Windows Registry keys related to installed Python versions, followed shortly by the invocation of Python-to-executable compilation tools like Nuitka or PyInstaller. This pattern is indicative of an adversary or developer performing interpreter discovery before compiling a payload into a standalone executable.
Detects a suspicious sequence of events where a process creates a scheduled task named 'WindowsUpdate' followed by execution of 'netsh' commands to dump wireless profiles or clear keys within a 15-minute window. This behavioral pattern is often associated with credential-stealing malware attempting to establish persistence and harvest sensitive information.
Detects unauthorized processes attempting to access Discord's local storage (LevelDB) where authentication tokens are stored, followed by a network request to the Discord API user validation endpoint, which is a pattern indicative of token extraction and liveness testing by malware.
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
Page 141 of 1871


