Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where processes other than standard web browsers attempt to access sensitive browser data files, such as cookies, login data, and browser state files. This behavior is a common indicator of credential theft or browser session hijacking, often performed by stealer malware like OnyxC2.
Detects a suspicious process pattern where an executable running from a staging directory (Temp or Downloads) spawns a child process of itself, followed by a registry modification performed by that child process. This behavior is indicative of malicious loaders, such as OnyxC2, that sideload components and establish runtime configurations before C2 communication.
Detects persistence establishment for the NetSupport Manager remote access tool (client32.exe) via common Windows techniques including registry run keys, Winlogon configuration, service creation, and scheduled tasks. This activity is often associated with the abuse of legitimate RMM software as a covert remote access implant, frequently following initial access via PowerShell or script-based loaders.
Detects the creation or modification of Windows Registry Run/RunOnce keys that reference msbuild.exe without typical build arguments. This is often used by adversaries to maintain persistence by executing malicious XML-based projects or inline C#/VB code via a trusted system utility.
Detects instances where the MSBuild.exe process is subjected to image replacement or tampering, a behavior often associated with process hollowing or malicious code injection techniques aimed at evading security defenses by masquerading as a legitimate developer utility.
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
Detects a suspected EvilTokens attack sequence where a user clicks a phishing URL and subsequently initiates a browser session to the Microsoft device-code authorization page (devicelogin) within 15 minutes, with the phishing lure domain appearing in the browser context.
Detects anomalous network polling patterns consistent with 'EvilTokens' or similar adversary-in-the-middle (AiTM) OAuth phishing kits. The rule identifies web browsers performing high-frequency, low-interval polling (3-6s) against non-reputable/unseen domains (the attacker-controlled status endpoint) immediately preceding or following successful Microsoft OAuth device-code authentication sequences.
Detects anomalous network polling patterns consistent with 'EvilTokens' or similar adversary-in-the-middle (AiTM) OAuth phishing kits. The rule identifies web browsers performing high-frequency, low-interval polling (3-6s) against non-reputable/unseen domains (the attacker-controlled status endpoint) immediately preceding or following successful Microsoft OAuth device-code authentication sequences.
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
Detects the execution of PowerShell or Unix shell commands (such as those containing encoded arguments, IEX, or clipboard reading) that are initiated by GUI-based applications or interactive shell environments like Windows Explorer, terminal emulators, or runtime brokers, often indicating potential malicious command injection or living-off-the-land activity.
Detects the execution of Windows Script Host (WScript.exe or CScript.exe) that creates a file or folder starting with 'Libs_' within the 'C:\Users\Public\' directory. This activity is often associated with attackers staging payloads, configuration files, or tools in publicly writable folders to evade detection.
Detects suspicious file activity where a script or process creates a staging folder within 'C:\Users\Public\' and subsequently writes potential decoy PDF files or compressed archive payloads to that same directory. This behavior is indicative of a dropper or secondary stage malware delivery mechanism utilizing world-writable directories for staging.
Detects instances where the Notepad++ executable is launched from a location within the C:\Users\Public\ directory, specifically when the parent process is a Windows scripting engine (wscript.exe or cscript.exe). This pattern is often indicative of an adversary executing a malicious payload staged in a common public directory using script-based wrappers to bypass execution policy or maintain stealth.
Detects the deletion of a specific file named 'Evernote.zip' located within the 'C:\Users\Public\' directory when executed by Windows Script Host (wscript.exe or cscript.exe). This activity is often associated with the cleanup of second-stage archives used during malicious operations.
This rule detects instances where Windows script hosts (wscript.exe or cscript.exe) create directories with suspicious naming conventions (starting with 'Libs_' or containing 'Temp Documents') within the 'C:\Users\Public\' directory. This activity is often associated with the staging of malicious payloads or collected data prior to exfiltration or execution.
Detects instances where the Windows Script Host (wscript.exe) spawns a process to open a PDF file located within the Public user's 'Temp Documents' directory. This behavior is indicative of a potential malware staging or execution attempt where an adversary attempts to open a malicious document from a publicly accessible folder to bypass user suspicion or execute malicious content.
This rule detects non-standard processes attempting to access sensitive web browser files (e.g., 'Login Data', 'Cookies', 'key4.db') that are typically only accessed by legitimate web browsers. It excludes known browser processes and trusted security or sync applications to identify potential credential theft attempts.
Page 159 of 1871


