Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of a .bat file in the Windows Startup directory, followed by the execution of a command process from a temporary location using a specific command line pattern. This behavior is indicative of persistent malware or a dropper attempting to execute an initial payload upon user logon.
This rule monitors for two potentially suspicious activities on Windows systems: the creation of scheduled tasks named 'MicrosoftEdgeUpdateTask' or 'MicrosoftEdgeUpdateTaskCore' using 'schtasks.exe', and the execution of scripts via 'wscript.exe' with silent flags ('//B' and '//Nologo'). These behaviors are often associated with persistence mechanisms or the execution of obfuscated/malicious scripts.
Detects a coordinated attack sequence where a browser process is terminated, followed immediately by the execution of an unsigned Python interpreter from a suspicious location (temp/downloads folder), which is then followed by the installation of an unsigned browser extension. This pattern mimics ClickFix and browser-based RAT lure campaigns.
Detects unauthorized processes attempting to read or modify Discord's local storage leveldb files, which store user authentication tokens, and correlates this with suspicious network activity to Discord's API or the presence of token-stealing keywords in command-line arguments.
This rule detects potential usage of Hidden VNC (hVNC) tools by monitoring for specific command-line arguments (such as 'hvnc-input', 'hvnc-desktop', or 'HVNC_Telegram') and Windows events related to the creation or switching of desktops (e.g., 'CreateDesktop', 'SwitchDesktop'). hVNC is a common technique used by malware to establish a hidden remote desktop session for unauthorized access and control without alerting the user.
Detects the installation or loading of a non-standard kernel driver followed by the termination of known security/EDR agent processes. This behavior is indicative of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where attackers leverage kernel-level privileges from a vulnerable driver to bypass EDR protections and disable security tools prior to encryption or other malicious activities.
Detects a suspicious pattern of mass security process termination, where a process masquerading as legitimate consumer or gaming software (e.g., Kaspersky, Valorant, Javelin) repeatedly uses commands like taskkill, sc stop, or NtTerminateProcess to disable EDR agents and antivirus software within a short time window. This behavior is indicative of pre-ransomware staging activities used by threat actors.
Detects a suspected ransomware double-extortion sequence: the bulk creation of password-protected archives using compression utilities (e.g., 7z, RAR), followed by significant outbound network connections to common cloud storage or anonymization endpoints, and concluding with mass file modifications indicative of encryption activity.
Detects unauthorized, unsigned processes accessing sensitive browser files (Cookies, Login Data, Local State) across common browsers (Chrome, Edge, Brave, Firefox) followed by an outbound network connection. This behavior is indicative of credential-harvesting infostealer malware.
Detects instances where the Windows Package Manager (winget.exe) initiates potentially suspicious child processes such as command shells or administrative tools, and correlates this activity with network connections originating from those child processes.
Detects a multi-stage process execution chain beginning with common end-user applications (browsers, Office apps, explorer.exe) spawning known LOLBins (Living-off-the-Land Binaries), which in turn execute secondary LOLBins with suspicious command-line indicators. This pattern often signifies post-exploitation activity such as secondary payload delivery, fileless malware execution, or proxy execution of malicious scripts/commands, consistent with ClickFix or BYOVD-related ingress techniques.
This rule detects the suspicious creation or modification of local user accounts (e.g., 'svc_ipurple') occurring within a short 15-minute window following the execution of Windows Package Manager (Winget) configuration tasks. This behavior may indicate an attacker using automated configuration files (DSC) to establish persistence or escalate privileges on a compromised system.
Detects MSBuild.exe establishing a network connection to a specific remote IP address (212.34.141.103) on port 4521. This behavior is indicative of MSBuild being used to proxy execution of malicious code, often associated with downloading and executing second-stage payloads or beaconing to a command-and-control (C2) server.
This rule detects the loading of the 'Microsoft.Management.Configuration.dll' module by specific Windows system processes involved in package management and configuration, namely 'ConfigurationRemotingServer.exe' and 'WindowsPackageManagerServer.exe'. While these are legitimate components of the Windows Package Manager and DSC services, monitoring this activity can establish a baseline for identifying potential process injection or unauthorized library loading within these security-sensitive management binaries.
This rule monitors for suspicious activities involving digital certificates. It detects PowerShell processes attempting to import a certificate into the Root store, which could indicate persistence or credential interception, and it detects the use of curl to download files named 'cert.pem' with insecure SSL settings (no certificate verification).
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
Detects suspicious command-line strings stored in the Windows Explorer RunMRU registry key. Adversaries may use this location to store persistence commands or to obfuscate command-line arguments that are intended to be executed by the user or via automated processes.
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
Detects suspicious execution of the certutil.exe utility for file operations, specifically targeting the copying of certutil or the decoding of files with naming patterns (kid*.exe, kid*.tmp, kid*.bat) within the \Users\Public\Downloads\ directory. This pattern is commonly associated with file staging and deobfuscation of malicious payloads.
Detects instances where PowerShell scripts perform Base64-encoded operations related to cryptographic functions and shortly thereafter establish network connections to known or suspect domains associated with C2 activity.
Detects ClickFix-style social engineering attacks where users are lured to 'cloudrobots.cloud' and subsequently execute malicious commands via Windows shell tools (cmd, powershell, mshta, etc.). The rule correlates browser network events to a specific domain, subsequent process launches by explorer.exe, and suspicious registry modifications associated with the Windows RunMRU, which is often abused to store and execute commands pasted by victims.
Page 163 of 1871
