Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
Detects the Sckit Go implant accessing sensitive local configuration and credential files, including SSH keys, cloud CLI tokens, and package manager credentials. The rule monitors for file read events initiated by processes identified as 'sckit' or processes with specific command line arguments.
Detects the creation of a file named 'DCRCVDrv.sys'. This filename is historically associated with malicious kernel-mode drivers used in cyberattacks, such as the DCRDRV exploit or related persistence/evasion mechanisms involving driver installation.
Detects network connection events initiated by known beaconing-related process names. These processes are associated with command and control infrastructure or pivot nodes often used by adversaries for post-compromise activity.
Detects Node.js processes executing suspicious command lines that involve fetching and executing remote JavaScript code. This behavior is indicative of a loader or downloader script commonly used to pull and evaluate malicious payloads at runtime, specifically referencing indicators associated with 'GHAPPIER'.
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
Detects the installation and execution of Cloudflare Tunnel (cloudflared.exe) as a Windows service. Adversaries may abuse this utility to create unauthorized persistent network tunnels, enabling covert remote access to the internal network. This rule correlates process creation events involving 'service install' or 'tunnel run' commands with Windows service installation events referencing the cloudflared binary.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
Detects the execution of Node.js or Python interpreters from user-writable directories (AppData/Local) that are executing specific script files. This pattern is indicative of potential malicious activity where legitimate scripting languages are leveraged to run unauthorized payloads dropped into the user profile.
Detects a suspicious sequence where Microsoft Outlook launches Microsoft Edge to open a URL, and that browser process subsequently makes network connections to infrastructure associated with the ClickFix phishing campaign (e.g., rsvpopenh.one or specific malicious IP).
This rule detects potentially malicious activity involving the execution of Node.js scripts initiated by system script proxies (wscript, cscript, msiexec) within specific paths, often associated with subsequent installation of VBScript agents or direct network communication with a known command-and-control IP address.
Detects suspicious behavior where an identical executable (same path and SHA256) is launched twice within a short window (60 minutes) following a system reboot, utilizing two distinct persistence methods: one triggered via the Task Scheduler (under svchost.exe -k netsvcs) and one via a user logon autostart mechanism (spawned by explorer.exe).
This rule detects a multi-stage attack chain involving the execution of a script (likely config.cmd) via curl, followed by the modification of the Active Setup StubPath registry key for persistence, and subsequent execution of a Python script (config.py) from a non-standard location in AppData\Local\Microsoft\.
Detects suspicious execution of command-line utilities (cmd.exe, powershell.exe, conhost.exe) directly from Windows Explorer (explorer.exe), which is often indicative of fileless malware execution, downloader activity, or 'ClickFix' style social engineering attacks.
Detects instances where the system DNS process (dns.exe) on a domain controller performs recursive DNS resolution towards a set of external IP addresses associated with suspicious infrastructure (AS202412). The rule correlates this activity with recent network connections from common web browsers or system utilities (msedge.exe, svchost.exe) on the same host to identify potential proxying of malicious DNS queries.
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
Page 148 of 1871


