Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a specific attack chain attributed to ClosedQuorum, involving LSASS memory dumping, subsequent access to browser-based credential stores or cryptocurrency wallet files, and finally staging the stolen data in C:\Windows\Temp\ within a short time window.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects instances where a non-browser process initiates connections to commercial LLM provider APIs (DeepSeek, OpenRouter, Mistral) followed by a connection to Discord CDN/Webhook endpoints within a 15-minute window. This behavior is indicative of a process acting as an autonomous C2 agent that exfiltrates data after receiving instructions or processing information via an LLM.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects a non-browser process initiating network connections to four distinct commercial LLM API providers (DeepSeek, OpenRouter, Mistral, and Google Gemini) within a 5-minute interval. This behavior is indicative of a C2 pattern where an adversary uses multiple LLM backends to perform plurality-vote or redundant queries, bypassing typical browser-based AI aggregation services.
Detects the creation of files named 'parser.js' or 'loader.js' within hidden or suspicious VSCode directories (e.g., .npm/.vscode/ or AppData/VSCode/). The detection also flags potential signs of malicious intent, such as the existence of a 'package.json' file nearby or the presence of 'tokenapp' in the file path, which are often indicative of the GHAPPIER implant behavior.
Detects the execution of rundll32.exe with a command line containing 'DavWWWRoot', indicating the loading of a DLL from a remote WebDAV share. This is a common technique used by attackers to execute remote malicious code while bypassing local execution policies or attempting to evade local file-based detection.
Detects anomalous, high-frequency access to clipboard APIs (GetClipboardData/SetClipboardData) by non-standard, unrecognized processes. The rule specifically monitors for patterns consistent with clipper malware, which polls the clipboard for cryptocurrency address formats and replaces them with attacker-controlled addresses.
This rule identifies processes that delete themselves shortly after execution. It joins process creation events with file deletion events on the same device, filtering for cases where the initiating process file name, ID, and hash match the deleted file, and where the deletion occurs within 120 seconds of the process creation. This behavior is commonly associated with malware or adversary tools attempting to remove traces of their activity.
Detects the execution of PowerShell via explorer.exe (typically initiated through the Windows Run dialog) where the command line references a WebDAV UNC path (containing DavWWWRoot). This behavior is characteristic of 'ClickFix' social engineering attacks, where users are coerced into copying and pasting commands into the Run dialog that trigger remote script execution.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects the execution of the 'sckit' Go implant, a malicious binary associated with trojanized '@memtensor/memos-cloud-openclaw-plugin' or 'MemoryOS' packages. The rule identifies instances where this binary is spawned as a child process of a language runtime (Node.js or Python) when the execution originates from specific directory paths associated with these packages, or when the parent process command line indicates these packages are being initialized.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Detects malicious activities associated with the SCKit worm, specifically targeting package publishing via npm/twine, GitHub Actions workflow injection (runtime-update.yml), and the dropping of postinstall propagation stubs (bootstrap.cjs) when initiated by SCKit processes.
Page 147 of 1871

