Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects instances where the IIS worker process (w3wp.exe) writes a new .aspx file into the 'MemberFiles' directory. This behavior is highly characteristic of webshell deployment following a successful file upload exploitation.
Detects web server requests for .aspx files where the User-Agent string identifies as Windows PowerShell and includes the zh-CN locale setting. This behavior is often characteristic of automated exploitation tools or web shells (like China Chopper) interacting with compromised web servers.
Detects a multi-stage activity where PowerShell is used to download a ZIP file, followed by the execution of a batch script (1.bat) that subsequently launches LockScreenContentServer.exe. This behavior is indicative of a DLL side-loading chain designed to execute malicious code via legitimate processes.
Detects a multi-stage activity where PowerShell is used to download a ZIP file, followed by the execution of a batch script (1.bat) that subsequently launches LockScreenContentServer.exe. This behavior is indicative of a DLL side-loading chain designed to execute malicious code via legitimate processes.
This rule detects instances where a process matching a known sideload-vulnerable binary (such as werfaultsecure or wuauclt) spawns a PowerShell process that executes commands commonly used for Active Directory reconnaissance and system information discovery. This behavior is indicative of post-compromise activity, specifically reconnaissance phases performed by malware loaders like Lorem Ipsum.
Detects instances where the IIS worker process (w3wp.exe) spawns the Windows command shell (cmd.exe) to execute common reconnaissance commands such as whoami, hostname, systeminfo, and net user. This behavior is strongly indicative of post-exploitation activity following a successful web shell deployment on a web server.
This rule performs an indicator of compromise (IOC) sweep for activities associated with the TOPHIT / VHX Harvester / @prime0 NPM typosquatting campaign. It detects known malicious C2 network connections (IPs and URLs), file artifacts (hashes) on endpoints, and suspicious email activity involving specific operator email addresses.
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects outbound network connections to common TOR entry, guard, or client service ports, or the execution of TOR-related processes. This behavior may indicate an adversary establishing C2 communication channels or attempting to perform anonymized data exfiltration.
Detects instances where a process contacts multiple distinct AI-provider domains within a short time frame while simultaneously performing suspicious operations, such as accessing the LSASS memory, executing process injection, or establishing WMI persistence. This pattern is indicative of a potential 'ClosedQuorum' adversary behavior involving data exfiltration or AI-assisted malicious activity.
Detects anomalous process execution by PeopleSoft application server processes (e.g., psappsrv, jsvc) immediately following an inbound network request. This behavior is indicative of exploitation of a Java deserialization gadget chain, such as those used by the threat actor UNC6240 to achieve Remote Code Execution (RCE) and spawn command interpreters.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
This rule detects instances of 'javaw.exe' executing from unusual directories (e.g., AppData, Temp, Users\Public) while loading a 'jli.dll' file from a related non-standard path, or simultaneously being associated with a scheduled task execution involving 'GlobalTellurSync'. This behavior is indicative of potential DLL side-loading or a persistence mechanism where a legitimate Java executable is repurposed to run malicious code.
Detects a specific persistence chain attributed to DragonForce where the 'javaw.exe' process side-loads a malicious 'jli.dll' from a non-standard, user-writable directory. The rule correlates this DLL image load with the subsequent reading of an encrypted, host-bound payload file ('rvsdiqw.txt') by the same process, which is then decrypted and injected into memory.
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
Page 15 of 1866


