Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where a Node.js process spawns another Node.js process to execute a JavaScript file located within the node_modules directory. This pattern is commonly observed when malware or malicious scripts attempt to execute payloads from within project dependencies, potentially hiding malicious activity within seemingly legitimate library paths.
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
Detects a suspicious sequence of events suggesting potential technical support scam or social engineering activity: a rapid influx of emails (email bombing) followed by an external Microsoft Teams call, and subsequently the execution of a common remote access tool on the same host within a short timeframe.
This rule detects network traffic patterns indicative of Xray-core C2 tunnels using a spoofed 'dl.google.com' TLS SNI value. This activity is associated with the Aur0ra/Black Basta playbook, where Xray-core is sideloaded into legitimate processes to exfiltrate or tunnel traffic while mimicking Chrome browser TLS behavior.
Detects the execution of the Windows ftp.exe binary using the -s parameter (or -s"": syntax) to execute a script file. This behavior is commonly associated with attackers using LOLBAS (Living Off the Land Binaries and Scripts) techniques to execute hidden or obfuscated scripts from mounted virtual hard disks (VHD) to facilitate malicious backdoor execution.
This rule detects the creation, modification, or renaming of .lnk shortcut files within the Windows Startup folders (both current user and roaming appdata). It then correlates this activity with the execution of AutoIt3.exe or processes identified as 'AutoIt' that are running scripts with .a3x or .au3 extensions, which are commonly used for persistence and execution of malicious automation scripts.
This rule detects instances where AutoIt (AutoIt3.exe) is observed performing process injection or launching suspicious binaries (RegSvcs.exe or mobsync.exe). Attackers frequently use AutoIt for process automation and to execute malicious payloads, and leveraging legitimate binaries like RegSvcs.exe is a known technique for bypassing defenses.
This rule detects potentially malicious activity where an executable with an MD5-formatted name is created in the user's temporary folder, followed by the creation of a registry key with a matching MD5-formatted name in HKEY_CURRENT_USER\SOFTWARE\ within 15 minutes. This behavior is indicative of a persistence mechanism where malware drops a payload in a temp directory and sets a run or autorun registry key to ensure its execution upon logon or startup.
Detects execution of WMI or PowerShell queries by HTA, WScript, or CScript processes to gather system information such as OSLanguage, BIOS, or hardware identifiers. This behavior is indicative of environment-awareness checks used by the Casbaneiro/Ousaban banking trojan to identify sandbox or virtualization analysis environments before proceeding with the infection.
Detects the creation or modification of a file named '.Outlook' within the AppData or AppData\Roaming folders, followed by network communication to known malicious domains or IP addresses by a process other than outlook.exe within a 30-minute window. This behavior is indicative of potential malware staging or command-and-control communication.
Detects suspicious clipboard activity where the clipboard is either accessed or modified by known utility processes (e.g., AutoIt, RegSvcs) or contains patterns indicative of cryptocurrency address hijacking (e.g., Bitcoin or Ethereum addresses).
Detects the creation or modification of a Windows service named 'ProcAuditManager' using 'sc.exe' or 'services.exe' command-line utilities, or by direct modification of the associated registry key. This activity may indicate persistence establishment or service manipulation by an adversary.
Detects potential Casbaneiro banking trojan activity characterized by a user accessing a known Latin American banking domain via a web browser, followed within 10 minutes by a suspicious process (RegSvcs.exe or mobsync.exe) establishing an outbound network connection, which is consistent with command-and-control (C2) behavior often seen in this malware family.
Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream (ADS) from files. This stream is responsible for the 'Mark-of-the-Web' (MOTW) which triggers security warnings in Windows, including SmartScreen and Protected View. Adversaries use this technique to evade security controls on downloaded malicious files.
Detects instances where the suspicious binary 'x47_bot.exe' performs process injection or hollows a process, followed by an attempt to gain or elevate privileges (such as via UAC bypass, token manipulation, or privilege checking) on the same host within a 15-minute window.
Detects non-browser processes accessing sensitive browser-stored credential and cookie databases concurrently with access to Discord local storage, which is a common behavior of information-stealing malware (e.g., x47.c) to aggregate credentials for exfiltration.
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
This rule detects the execution or presence of specific Go or Terraform modules known to be malicious or associated with suspicious dependency retrieval. It monitors command-line activity from terraform.exe/go.exe attempting to download/run from these paths, as well as file system events involving these specific folder paths and filenames.
Page 151 of 1871


