Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
Detects the execution of PowerShell with suspicious command-line arguments (headless mode, hidden window, encoded commands) spawned by WScript.exe. This pattern is commonly associated with obfuscated script execution or fileless malware staging.
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
Detects the reflectively-loaded SectopRAT .NET payload by its combination of heavy calli (indirect call) opcode usage for control-flow flattening and its characteristic runtime string-decryption helper method used to resolve the C2 IP/port and other obfuscated strings
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
Page 142 of 1870


