Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of the Chisel C2 tool by matching its unique command-line grammar, specifically the 'client' subcommand combined with reverse remote ('R:') configurations. This detection strategy is resilient against binary renaming and infrastructure rotation by focusing on the tool's required argument structure rather than static IOCs like filenames or C2 addresses. It is specifically useful for identifying unauthorized remote tunnels used for persistence and data exfiltration.
The following analytic detects the installation of the XMRIG coinminer driver on a system. It identifies the loading of the `WinRing0x64.sys` driver, commonly associated with XMRIG, by analyzing Sysmon EventCode 6 logs for specific signatures and image loads. This activity is significant because XMRIG is an open-source CPU miner frequently exploited by adversaries to mine cryptocurrency illicitly. If confirmed malicious, this activity could lead to unauthorized resource consumption, degraded system performance, and potential financial loss due to unauthorized cryptocurrency mining.
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
Detects instances where the legitimate Windows Character Map utility (charmap.exe) is spawned by suspicious processes or PowerShell, and subsequently loads clr.dll. This behavior is indicative of potential DLL sideloading or process injection techniques used by malware to execute arbitrary code within a trusted system process context.
This rule detects DNS queries or network connections originating from endpoints to a list of known malicious domains associated with various malware families (ClearFake, IClickFix, AMOS, Vidar, etc.). This helps identify potential C2 communication, malicious payload delivery, or infrastructure interaction.
This rule monitors for indicators of compromise (IOCs) associated with the ShinyHunters threat actor, including specific malicious domains, IP addresses, and artifacts found in command lines or event data. It aggregates telemetry from network events, Entra ID sign-in logs, cloud application activity, email logs, process execution, and general device events to detect interaction with known malicious infrastructure or execution of threat-actor specific artifacts.
Detects attempts to dump credentials from the LSASS process memory, either by executing known credential dumping tools like Mimikatz, using command-line arguments indicative of credential harvesting, or performing suspicious memory access/dumping operations on the lsass.exe process.
This rule detects modifications to Group Policy Objects (GPOs) that are either explicitly marked as malicious based on known indicators (GUIDs or 'PAYLOAD' strings) or involve unauthorized modifications to domain-root or organizational unit GPO links. It monitors Active Directory security event logs for object changes.
This rule monitors for the execution of an executable file (.exe) from a user's 'Downloads' directory followed shortly (within 5 minutes) by a network connection to port 4321, which is characteristic of the Bear C2 HTTPS-AES beacon pattern. This behavior is indicative of a potential secondary stage malware execution or C2 check-in after an initial user-driven download.
This rule detects the execution of a file with an .exe extension from the user's Downloads directory that has been previously tagged with the Mark-of-the-Web (MOTW) Zone.Identifier. It correlates file creation events, the application of the MOTW alternate data stream, and subsequent process execution to identify potentially malicious downloaded executables.
Detects network communication associated with the Bear C2 framework by identifying specific beacon URI patterns (/beacon?id=<uuid>) and connections to known non-standard listener ports (4321, 8080). The rule also monitors for process command lines containing specific hardcoded identifiers associated with this C2 implant.
This rule monitors for the execution of an executable file (.exe) from a user's 'Downloads' directory followed shortly (within 5 minutes) by a network connection to port 4321, which is characteristic of the Bear C2 HTTPS-AES beacon pattern. This behavior is indicative of a potential secondary stage malware execution or C2 check-in after an initial user-driven download.
This rule detects the execution of a file with an .exe extension from the user's Downloads directory that has been previously tagged with the Mark-of-the-Web (MOTW) Zone.Identifier. It correlates file creation events, the application of the MOTW alternate data stream, and subsequent process execution to identify potentially malicious downloaded executables.
Detects network communication associated with the Bear C2 framework by identifying specific beacon URI patterns (/beacon?id=<uuid>) and connections to known non-standard listener ports (4321, 8080). The rule also monitors for process command lines containing specific hardcoded identifiers associated with this C2 implant.
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
This rule identifies potential activity related to the Kothamine malware by monitoring for specific file hashes associated with the malware in process and file execution events, as well as network connections to a specific malicious GitHub repository path used for payload delivery.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the creation of a scheduled task intended to masquerade as 'MicrosoftEdgeUpdateTask' using either schtasks.exe or PowerShell. The rule specifically monitors for tasks being registered in AppData/Roaming directories, which is a common indicator of persistence by malicious actors attempting to mimic legitimate Microsoft Edge update processes.
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Page 160 of 1871





