Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where msiexec.exe is used in conjunction with specific application names (Spotify, Zoom, Teams) in the command line, and subsequently launches suspicious child processes such as wscript.exe, cscript.exe, or powershell.exe with specific script or executable arguments. This pattern is often associated with malicious installers or trojanized software attempting to execute embedded payloads.
Detects endpoint behavior consistent with AI-assisted exploit development, characterized by the execution of reverse engineering and vulnerability research tools (e.g., IDA Pro, Ghidra, AFL) interleaved with frequent outbound network connections to LLM APIs, followed by the local compilation of a new executable or DLL.
Detects anomalous, high-volume file access by a single process, followed by local file compression or archiving, and subsequent outbound data transfer to a non-internal IP address. This pattern is characteristic of automated agents (like those used in the GTG-1002/Anthropic AI-orchestrated campaigns) performing rapid data triage and staging for exfiltration.
Detects Node.js processes exhibiting network activity patterns consistent with 'EtherHiding' style C2 infrastructure, characterized by multiple distinct connections to external WebSocket hosts on non-standard TCP ports within a short timeframe, potentially following interaction with a blockchain/JSON-RPC endpoint.
Detects anomalous activity from IDEs or AI coding assistant extension host processes (e.g., VS Code, Cursor, JetBrains). The rule alerts when these processes spawn children that access sensitive local credential files, perform network connections to non-standard/unexpected domains, or modify critical CI/CD build script configuration files, which is indicative of a supply chain compromise within the developer environment.
Detects the removal of persistence mechanisms related to the 'ComponentTask33Agent' task, specifically the deletion of a scheduled task or registry Run key, followed by the deletion of associated files within specific Microsoft-themed AppData subdirectories within a 30-minute window.
Detects anomalous child process spawning from common web browsers or productivity applications (e.g., Office, Acrobat) on hosts that have recently communicated with known LLM or code-generation APIs. This behavioral correlation is intended to identify the potential execution of AI-generated exploit code.
Detects the persistence sequence associated with 'ChainScript', which involves creating a hidden scheduled task using PowerShell or specific scripts, and a fallback mechanism that creates a registry run key entry if the task creation fails. The rule monitors for PowerShell commands, bridge script execution, and registry modifications involving the 'ComponentTask33Agent' or wscript.exe executing an '_agent.vbs' file.
Detects potential runtime polymorphic malware that modifies its own executable or script content while simultaneously communicating with generative AI or LLM API endpoints. This behavior indicates an adversary using LLMs to regenerate obfuscated code or mutate malware signatures dynamically at runtime.
Detects the creation of specific forensic log files (browser_decryption.log, sends.log) within the %TEMP% directory. These files are indicators of the data collection stage performed by the Rapuncel infostealer prior to archiving and exfiltration.
Detects ZIP archives exceeding 100MB that contain specific DLL filenames often used for junk-padding to evade sandbox analysis. This technique is observed in brand-impersonation campaigns targeting users with fake security or authentication software lures.
Detects the staging of ChainScript files into specific, masquerading subdirectories within user AppData folders that mimic legitimate Windows system paths. This activity is indicative of the _scatter.ps1 script redistributing components such as the Node.js runtime, agent configuration, and helper utilities before execution.
Detects instances where common script interpreters (powershell.exe, cmd.exe, mshta.exe, etc.) are launched by developer-centric processes (node.exe, npm.exe, Code.exe) with suspicious command-line arguments often used for reconnaissance, payload downloading, or obfuscated command execution.
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
Detects instances where Microsoft Visual Studio Code (Code.exe) spawns common interpreters or command-line tools (such as node, python, cmd, or powershell) that are not associated with known internal VS Code process behaviors like renderer tasks or tunnel operations. This activity may indicate malicious use of the integrated terminal or extension execution contexts to execute unauthorized code.
Detects the execution of known remote access or remote monitoring software (such as TeamViewer, AnyDesk, or ScreenConnect) on corporate-issued Windows endpoints. The rule triggers on process execution patterns associated with unauthorized remote control, specifically looking for indicators of unattended access or silent installation commonly used by overseas actors to remotely operate company-issued laptops assigned to fraudulently hired identities.
Detects Node.js or Python processes exhibiting behavior characteristic of information-stealing malware (such as the WaterPlum suite: BeaverTail, InvisibleFerret, OtterCookie, StoatWaffle). The rule monitors for these processes accessing sensitive files related to browser credentials, cryptocurrency wallets, scanned identification documents, or performing collection activities like keylogging and screen capturing.
Detects the use of PowerShell cmdlets (Add-MpPreference or Set-MpPreference) to modify Microsoft Defender exclusions (paths, processes, or extensions). This behavior is often associated with adversaries attempting to evade security detection by excluding malicious files or processes from being scanned by Microsoft Defender.
Detects suspicious command-line patterns typically used for downloading or executing malicious payloads, such as curl, base64 encoding, and PowerShell web requests, when spawned directly from Node.js or Visual Studio Code processes. This behavior is associated with supply chain compromises and loader activity (e.g., WaterPlum/Contagious Interview) targeting development environments.
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
Detects instances where node.exe or npm processes spawn a Python interpreter. This behavior is indicative of malicious activity, specifically the execution of second-stage payloads such as the InvisibleFerret backdoor often associated with the BeaverTail JavaScript loader, observed in software supply chain compromise campaigns.
Page 145 of 1871
