Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects rapid deletion of Windows Defender or WdFilter service registry keys by non-standard processes (not System or ntoskrnl.exe). This pattern is consistent with kernel-mode tamper protection bypass attempts, such as the use of the BTR.sys driver to force the removal of defensive configuration entries, effectively disabling Windows Defender.
Detects potential abuse of SeLoadDriverPrivilege to load unsigned or malicious drivers, often associated with Bring Your Own Vulnerable Driver (BYOVD) attacks. The rule identifies the creation of randomized service keys used to facilitate driver loading, followed by the actual loading of a driver, or explicit command-line references to the privilege being utilized.
Detects the presence or execution of the 'Boot Time Removal Tool' (BTR.sys) driver when it originates from locations outside of the legitimate Windows Defender platform or is initiated by processes not associated with the Defender ecosystem. This behavior is indicative of potential BYOVD (Bring Your Own Vulnerable Driver) attacks where attackers deploy known vulnerable drivers to gain kernel-mode privileges or interfere with security software.
Detects PowerShell command lines that perform suspicious string manipulation using the .Replace() method on specific obfuscated characters, followed by a Base64 decoding operation. This pattern is commonly used by attackers to reassemble and decode fragmented or obfuscated payloads on the fly to evade static analysis.
Detects execution of JavaScript files using the Windows Script Host (wscript.exe or cscript.exe). This is a common technique used by attackers to execute malicious scripts, often delivered via phishing or as secondary payloads.
Detects the execution of MSBuild.exe when spawned by a PowerShell process. This is a common pattern for proxying execution of malicious code, such as the LxBaseRAT, by leveraging MSBuild's inline task capability to execute C# or VB.NET code within a signed Microsoft binary.
Detects the abuse of WerFaultSecure.exe or similar Windows Error Reporting processes, invoked with debugging or dumping flags against security/EDR process names, or spawned by unexpected parent processes. This technique is often used to freeze security tools (EDR-Freeze) by exploiting process suspension via mini-dump handles.
Detects activity associated with the SharePoint ToolShell exploitation chain, specifically monitoring the w3wp.exe process for spawning suspicious child processes like cmd.exe or powershell.exe, and the creation of unexpected .aspx files within the SharePoint LAYOUTS directory.
Detects instances where the Node.js runtime environment (node.exe) deletes a file named 'sharedLoad.min.js' located within a 'node_modules' directory. This behavior is indicative of anti-forensic cleanup activities where malicious npm packages attempt to remove their own footprints or temporary artifacts post-execution.
Detects Xray-core C2 tunnel traffic where the TLS SNI is spoofed to appear as 'dl.google.com'. The detection specifically looks for this behavior originating from non-browser processes such as 'wkspbroker.exe' or 'radcui.dll', which is indicative of malicious tunneling activity.
Detects the modification of registry keys under HKCU\Software\Classes\CLSID\...\InProcServer32, which is a common method for achieving persistence. The rule flags when these registry keys point to file paths within the local user profile (AppData), which is frequently used by malicious actors to load custom DLLs when the corresponding COM object is initialized.
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
Detects the execution of known remote access tools (AnyDesk, TeamViewer, Quick Assist) on Windows systems. The rule is intended to be used in a correlated detection pipeline that identifies a multi-stage attack chain involving an initial email-bombing flood followed by an external Microsoft Teams vishing call impersonating IT support.
Detects the execution and behavioral patterns associated with the malicious 'indexed-btree' npm package. The rule specifically looks for code patterns where a malicious loader is injected into 'BTree.prototype.set' and triggered at runtime. It also monitors for suspicious process spawning behavior, such as running node processes with detached and hidden windows flags, often used by the package to maintain persistence or execute malicious payloads silently.
Detects instances where the AnyDesk process spawns cmd.exe or executes a batch script, which is a common indicator of an attacker performing post-exploitation activities via a remote access session.
Detects the creation of a shortcut file named 'AppUpdateHelper.lnk' within the Windows Startup folder by the 'UpdateAssistant.exe' process. This pattern may indicate an attempt to establish persistence by an application posing as an update process.
Detects the execution of the Windows Workspaces Broker process (wkspbroker.exe) when it loads a library (DLL) from a path within the RemoteApp Gateway directory under LOCALAPPDATA. This behavior is associated with DLL side-loading techniques used to execute malicious payloads such as the Xray-core implant.
This rule detects the execution of common Node.js package managers (npm, yarn, pnpm) attempting to install specific dependencies that match known patterns of malicious or typosquatted packages often used in supply chain attacks. The detection focuses on suspicious package names that mimic common data structure library naming conventions.
Detects instances where a Node.js process spawns another Node.js process to execute a JavaScript file located within the node_modules directory. This pattern is commonly observed when malware or malicious scripts attempt to execute payloads from within project dependencies, potentially hiding malicious activity within seemingly legitimate library paths.
Page 150 of 1871

