Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of PowerShell to add an exclusion to Microsoft Defender. The detection looks for common obfuscation flags (Hidden, NonI, NoP, Bypass) in the command line and targets the MicrosoftEdgeUpdateCore executable or DLL for exclusion, which is a common persistence or evasion technique. It excludes parent processes known for administrative activity to reduce noise.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects behavior consistent with the Kothamine agent, where a recently dropped DLL in a temporary directory is loaded by a short-lived explorer.exe process. This rule monitors for file creation, subsequent module loading by the explorer process, and ensures the process was spawned in close proximity to the file activity, indicating likely process injection.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the execution of the Kothamine injector by correlating three distinct stages: the use of PowerShell to create an AV exclusion for 'MicrosoftEdgeUpdateCore', the dropping of the 'MicrosoftEdgeUpdateCore' binary into the user's AppData directory, and subsequent process injection (OpenProcess/VirtualAllocEx/WriteProcessMemory/CreateRemoteThread) into explorer.exe.
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
This rule monitors for a variety of indicators associated with malicious activity, including connections to known malicious IP addresses, the presence of specific malicious file hashes or filenames, modifications to Windows system policies (specifically Legal Notice configuration), and changes to Active Directory Group Policy Objects using specified GUIDs.
Detects the creation of 'auth_codes.json' files within directories containing 'seria' in their path. This file is known to be used to store MD5-derived 8-character hex recovery codes for Dahua devices, allowing for password bypass or recovery via the easy4ipcloud.com portal without valid credentials.
Detects the execution of PowerShell commands that utilize .NET cryptography classes (AesManaged) in conjunction with data compression (GZipStream) and base64 decoding (FromBase64String). This combination of classes is highly characteristic of malicious scripts designed to decrypt and execute obfuscated or packed payloads in memory.
Detects an accelerated sequence of attack phases—specifically recon, privilege escalation, lateral movement, and persistence—occurring on a single device within a short timeframe (15 minutes). This behavioral pattern indicates potential automated or script-orchestrated intrusion activity.
Detects the execution of PowerShell with hidden flags and encoded commands spawned by a 'conhost.exe' process running in '--headless' mode. This specific process pattern is indicative of the obfuscated execution chain used by LausivLoader.
The following analytic detects the usage of wevtutil.exe with parameters for clearing event logs such as Application, Security, Setup, Trace, or System.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments.
This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
If confirmed malicious, this behavior could allow an attacker to erase evidence of their activities, making it difficult to trace their actions and understand the full scope of the compromise.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line arguments.
This activity is significant because clearing event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
If confirmed malicious, this behavior could allow an attacker to erase evidence of their activities, making it difficult to trace their actions and understand the full scope of the compromise.
Detects malicious processes or scripts that perform multi-stage environment fingerprinting to identify virtualization or sandbox environments. The rule identifies chains of suspicious activities, including querying registry keys related to virtualization (e.g., VMware, VirtualBox, QEMU), WMI queries for BIOS/Computer system details, API calls common to sandbox evasion (GetCursorPos, GetTickCount), and artificial execution delays (sleep/timeout), typically used by malware like LummaC2 to perform conditional exits if an analysis environment is detected.
Page 161 of 1871


