Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the presence of specific ysoserial gadget chain strings (ActivitySurrogateSelector/ActivitySurrogateDisableTypeCheck) indicative of deserialization attacks targeting Microsoft SharePoint via System.Web.UI.LosFormatter. This typically occurs in memory within w3wp.exe processes following an initial RCE exploit, such as those targeting EditingPageParser or ToolPane.
Detects the presence of ZIP archive files masquerading as 'Evernote.zip' that contain 'notepad++.exe', which is a pattern frequently observed in VBScript-based downloaders utilizing binary sideloading to execute malicious payloads.
Detects signs of Zerologon (CVE-2020-1472) exploitation by correlating Netlogon (MS-NRPC) authentication anomalies involving known exploitation tools/process names with subsequent machine-account password reset events (Event ID 4742) occurring on the same device within a short time window.
Detects the use of WScript or CScript to query the Win32_OperatingSystem WMI class for the InstallDate property. This behavior is commonly used by malware to identify the system installation time, which can serve as a simple heuristic for sandbox evasion or environmental keying.
Detects the creation of files on a host system that match naming conventions consistent with Rhysida ransomware notes. These files (e.g., README, HOW_TO_RECOVER) indicate a post-encryption state where the adversary has demanded payment. The detection joins events to highlight multiple occurrences of these note-like files on a single device.
Detects anomalous, mass-access behavior targeting plaintext credential files, certificate stores, private keys, or password-manager databases located on general-purpose network shares. Such activity is often indicative of an adversary conducting discovery or collection of credentials for lateral movement and privilege escalation.
Detects instances where PowerShell is initiated via LNK files, specifically targeting PDF LNK attachments or known malicious script naming patterns (update1.vbs, update2.ps1) and common downloader cmdlets (e.g., IEX, Invoke-WebRequest). It also includes specific indicators for remote file downloads.
Detects the deletion of .zip files within the Public directory by VBScript or JScript interpreters (wscript.exe or cscript.exe). This pattern is often indicative of a malicious dropper or downloader that extracts a payload from a staged archive and subsequently removes the evidence to hinder analysis and forensics.
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
Detects the execution of Windows Script Host (wscript.exe/cscript.exe) loading WMI-related modules (wbemprox.dll, wbemcomn.dll, etc.). This pattern is often indicative of scripts attempting to query WMI for system information, environment configuration, or locale data, which is a common reconnaissance technique used by malware to identify the victim environment.
Detects the execution of a .vbs script file that contains '.pdf' in its filename, followed within 5 minutes by the execution of a WMI query via wscript.exe. This behavior is indicative of a malicious VBScript dropper attempting to perform system discovery using WMI.
Detects instances where wscript.exe deletes a .zip archive from within the C:\Users\Public\ directory structure. This activity is frequently associated with VBScript droppers performing anti-forensic cleanup by removing staged payloads after extraction but prior to execution.
This rule detects the execution of script files (such as .vbs, .vbe, .js, .jse) via wscript.exe when the file name uses a double-extension technique (e.g., .pdf.vbs) to masquerade as a benign PDF document. These files are typically found in temporary or user-download directories, indicating potential malicious activity initiated by downloaded attachments.
Detects the execution of wscript.exe or cscript.exe with a command line containing a .vbs file, occurring within a 5-minute window of the creation of a file named 'notepad++.exe' or 'readme.txt' within a sub-directory of 'C:\Users\Public\'. This behavior is indicative of a potential multi-stage execution where a script is used to drop or interact with files in public-accessible folders.
Detects potential malicious VBScript behavior where the script queries system language settings via WMI and subsequently launches a decoy message box commonly associated with initial-stage malware loaders or droppers to deceive users before initiating a payload download.
Detects instances where a command-line utility or scripting interpreter references a 'SKILL.md' configuration file, typically associated with agent-skill payloads, followed shortly by network-based file download activity. This behavior is indicative of a secondary payload retrieval triggered by an adversary-controlled or poisoned configuration file.
Detects the execution of the Chisel C2 tool by matching its unique command-line grammar, specifically the 'client' subcommand combined with reverse remote ('R:') configurations. This detection strategy is resilient against binary renaming and infrastructure rotation by focusing on the tool's required argument structure rather than static IOCs like filenames or C2 addresses. It is specifically useful for identifying unauthorized remote tunnels used for persistence and data exfiltration.
Detects instances where the Claude Desktop application spawns a terminal or shell process that immediately executes commands associated with downloading remote payloads or accessing sensitive cryptocurrency wallet artifacts. This behavior is indicative of potential AI prompt injection where an AI assistant is coerced into executing malicious commands without user authorization.
Detects the abuse of the DFS Namespace Management (DFSNM) interface by monitoring calls to NetrDfsAddStdRoot (opnum 12) and NetrDfsRemoveStdRoot (opnum 13). An adversary can trigger these functions to coerce a Windows host to authenticate to an attacker-controlled remote host using NTLM, facilitating NTLM relay attacks.
This rule detects when the MpDlpService.exe process loads the 'mpclient.dll' library from a location other than the legitimate Windows Defender program directories. This behavior is indicative of potential DLL side-loading or hijack execution flow attempts targeting the Microsoft Data Loss Prevention service.
This rule detects potential staging activity for ClickFix or Vidar malware campaigns. It identifies the creation of files or folders in directories mimicking Windows Diagnostics infrastructure (WDI) or known payload paths, correlated with the execution of suspicious PowerShell commands or archive-related utilities within a 30-minute window on the same device.
Page 154 of 1871



