Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a suspicious multi-stage PowerShell execution pattern where an initial process, such as explorer.exe or common loaders, invokes PowerShell with obfuscated or download-related flags (e.g., -enc, IEX, DownloadString), followed immediately by a child PowerShell process performing further download or network operations within a short time window.
This rule monitors for processes that are digitally signed by 'Discord Inc.' or 'Lenovo' but executing from file paths that are not associated with legitimate installations of their software. This behavior is indicative of threat actors using stolen or compromised code-signing certificates to bypass security controls like SmartScreen or endpoint antivirus solutions.
Detects the launch of client32.exe (a core component of NetSupport Manager) as a child process of PowerShell, indicating potential malicious deployment of the software as a RAT rather than legitimate administrative activity.
This rule detects the suspicious copying of a Chromium-based browser 'Web Data' file (which stores sensitive information like saved passwords, credit cards, or address data) to a temporary file, followed by an outbound network connection to a specific exfiltration endpoint pattern within a 30-minute window.
Detects a suspicious sequence where a Python process is spawned by a 'marimo' notebook process, followed immediately by an outbound SSH connection attempt from the same device. This pattern is indicative of automated or scripted lateral movement where a notebook environment is abused as a jump-point for command execution on remote systems.
Detects instances where PowerShell, cmd, or mshta are launched as child processes of browser applications or Windows Explorer, often associated with 'ClickFix' or other social engineering attacks where a user is tricked into pasting malicious commands into the Windows 'Run' dialog. The rule identifies suspicious command-line arguments typical of downloader cradles or obfuscated scripts.
Detects the use of native Windows utilities (vssadmin, wmic, wbadmin, bcdedit) to delete volume shadow copies, clear backup catalogs, or disable system recovery features, which is a common behavior of ransomware before encrypting files.
This rule detects scenarios where common web browsers (e.g., chrome.exe, msedge.exe) spawn known living-off-the-land (LotL) binaries (e.g., powershell.exe, wscript.exe, mshta.exe) with command-line arguments indicative of malicious activity, such as base64-encoded strings, hidden window flags, or remote script invocation (IEX/Invoke-Expression). This pattern is frequently used in drive-by download or phishing delivery chains where an initial payload is triggered directly from a browser context.
Detects instances where mshta.exe is launched from a web browser or explorer.exe with suspicious command-line arguments, such as remote URLs, script protocols, or potentially obfuscated/base64-encoded strings, often indicative of 'ClickFix' social engineering attacks.
Detects the execution of WinRAR utilities (WinRAR.exe, Rar.exe) with suspicious command-line arguments typically associated with data staging, archiving, or encryption. The rule filters out legitimate WinRAR installations and only triggers when the process is spawned by a script interpreter (e.g., PowerShell, CMD) or operates within sensitive file paths (e.g., Users, Shares, Finance, HR, Backup).
This rule detects a single host performing a high volume of connection attempts to internal IP addresses across standard management and file-sharing ports (SMB 445, RDP 3389, WinRM 5985) within a 5-minute window. Such behavior is characteristic of network scanning or reconnaissance activities performed by adversaries attempting to identify targets for lateral movement.
This rule detects processes other than known web browsers (Chrome, Edge, Firefox, Brave, Opera) accessing sensitive browser-related files (Login Data, Cookies, Web Data) and initiating an external network connection within 15 minutes. This behavior is highly characteristic of credential and session cookie theft, often utilized by info-stealing malware for subsequent session hijacking.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
Detects the creation of a Volume Shadow Copy followed by an attempt to access or copy sensitive files, specifically the NTDS.dit database or the SYSTEM registry hive, from that shadow copy. This behavior is indicative of an attempt to perform offline credential theft.
Detects the use of the sc.exe command-line utility to stop or disable the Microsoft Defender Antivirus service (WinDefend). This activity is often associated with ransomware, such as Nova ransomware, to bypass security controls prior to malicious encryption or data destruction.
Detects attempts by malicious software to inhibit system recovery by deleting Volume Shadow Copies. The rule monitors for the execution of vssadmin.exe with deletion flags or wmic.exe with shadowcopy deletion commands combined with non-interactive flags, which are common indicators of ransomware preparation.
Detects attempts by malicious software to inhibit system recovery by deleting Volume Shadow Copies. The rule monitors for the execution of vssadmin.exe with deletion flags or wmic.exe with shadowcopy deletion commands combined with non-interactive flags, which are common indicators of ransomware preparation.
Detects unauthorized processes accessing the 'ConsoleHost_history.txt' file across user profiles. This behavior is indicative of ransomware operators or malicious actors attempting to harvest stored credentials, tokens, or sensitive command-line history before performing lateral movement or privilege escalation.
Detects the use of PsExec to remotely execute binaries on target hosts, a technique observed in The Gentlemen ransomware lateral movement phase when domain controller access is unavailable. The rule identifies psexec.exe process creation with common flags (-s, -d, -c) while filtering out common administrative parent processes.
Detects the use of PowerShell Set-MpPreference commands to disable multiple Microsoft Defender security features, including real-time monitoring, behavioral scanning, and threat detection actions. This activity is consistent with ransomware behavior, such as Nova or The Gentlemen families, attempting to neutralize endpoint protection before proceeding with malicious actions like file encryption.
Detects the use of PowerShell to modify Microsoft Defender exclusion paths by adding root drive letters or temporary directory paths. This behavior is indicative of defense evasion techniques often employed by ransomware families, such as Nova or Gentlemen, to prevent the scanning of files immediately prior to encryption.
Page 156 of 1871


