Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of PowerShell to remove the 'Zone.Identifier' NTFS Alternate Data Stream from a file, effectively bypassing Mark-of-the-Web (MOTW) security protections. This behavior is often associated with the 'Unblock-File' cmdlet and is used by adversaries to execute downloaded malicious files without security warnings.
Detects the execution of 'mshta.exe' loading an .hta file containing specific suspicious terms ('VLC', 'Presentation', 'Denver'), followed by the spawning of child processes such as 'wscript.exe', 'cscript.exe', 'powershell.exe', 'cmd.exe', or 'wmic.exe'. This pattern is frequently used to proxy execution of malicious scripts via legitimate Windows binaries.
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
This rule detects the presence of a 7-Zip library file ('7z.dll') located within a specific 'Traiolx Custom Utils' directory. The rule flags this file based on known malicious file hashes (MD5 or SHA256) or its specific file path. This is indicative of an adversary placing custom or potentially malicious tools on a system for archive manipulation or data staging.
Detects the execution of a specific Visual Basic script named 'Telegram_Private_Call_Session.vbs' by Windows scripting utilities (wscript.exe, cscript.exe) or the Microsoft HTML Application host (mshta.exe). This pattern is often associated with the execution of malicious scripts disguised as legitimate communication application components.
Detects the execution of a PowerShell script named 'lightlife.ps1'. The rule flags instances where this specific script is invoked with bypass execution policies or when it is initiated by script hosts like wscript.exe or mshta.exe, which are common patterns for obfuscated or secondary script execution.
Detects attempts to bypass the Antimalware Scan Interface (AMSI) in PowerShell by using reflection to modify the 'amsiInitFailed' field within the 'AmsiUtils' class. This technique is commonly used by malicious scripts to disable AMSI scanning during their execution.
Detects suspicious PowerShell command lines that utilize both 'Invoke-Expression' (iex) and 'Invoke-RestMethod' (irm), often used to download and execute code directly from remote sources. The rule specifically monitors for known indicators like specific IP addresses, file paths, or the concurrent use of these cmdlets in a single command line.
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
Detects attempts to disable PowerShell Script Block Logging via registry modification or by using the Set-ItemProperty command. Disabling this security feature prevents visibility into the actual contents of executed PowerShell scripts, which is a common tactic used by adversaries to evade detection.
Detects the creation of scheduled tasks using schtasks.exe that are configured to run every minute, specifically targeting command lines associated with known suspicious processes like 'codeflush.exe' or potentially masqueraded music library tasks.
This rule detects the execution of common command-line or scripting tools (cmd.exe, powershell.exe, wscript.exe, cscript.exe, ftp.exe) or .lnk file handling triggered by explorer.exe immediately following the mounting of a VHD or VHDX file. This behavior is indicative of an attacker mounting a malicious virtual disk image and executing payloads contained within it.
Detects Python processes (python.exe, python3.exe, pythonw.exe) loading native library files (.pyd or .so) followed by file access to sensitive browser credential and cookie storage locations (e.g., Login Data, Cookies, Local State). This pattern is characteristic of infostealer activity, where a Python script uses a native module to decrypt or extract browser-stored credentials.
Detects file creation, renaming, or deletion events within the Recycle Bin directory involving suspicious filenames or PDF files, which may indicate an adversary attempting to hide, stage, or delete evidence.
This rule monitors for suspicious network traffic to SMTP services and specific external email addresses, as well as process command lines containing these indicators. Additionally, it tracks email events involving specific sender, recipient, and subject indicators which may be indicative of unauthorized communication or data exfiltration attempts.
Detects instances where the Greenshot.exe application loads DLLs (log4net.dll, GreenshotPlugin.dll, LinqBridge.dll) from locations outside of the expected installation directory ('\Program Files\Greenshot' or '\Program Files (x86)\Greenshot'). The rule also tracks the creation of configuration or updater files ('greenshot-defaults.ini', 'updater.bat') which may be indicative of unauthorized modification, persistence, or potential DLL side-loading attempts.
This rule detects the execution of specific suspicious batch scripts (e.g., 'bd_test_k7old.bat') via cmd.exe, or the creation of a Windows service involving kernel drivers using sc.exe, which may indicate testing of defensive mechanisms or the deployment of potentially malicious kernel-level components.
Detects rapid execution of multiple discovery-related commands (whoami, tasklist, ipconfig, netstat, systeminfo) by common Windows host processes within a 15-minute window. This behavior often indicates an adversary performing reconnaissance after gaining an initial foothold.
Detects the execution of processes or creation of events attempting to mimic Windows Security credential prompts. This pattern is characteristic of the TukTuk C2 framework's 'Cred Prompt' feature, designed to harvest user credentials by presenting a fake authentication dialog.
Detects instances where the Cursor IDE (or associated helper processes) spawns a child process or executes a command involving a specific 'DevOps-Automation/cloudshield' path. This monitors for potential abuse of IDE environments to trigger sensitive automation scripts, possibly indicating malicious use of IDE tooling or unauthorized development activities.
Detects signs of malicious activity involving specific files (StreamServiceSharedBridge.ps1, ComponentTask33Agent) and behaviors, including PowerShell execution, scheduled task creation, script execution via wscript, and registry run key modification. These behaviors are indicative of persistence mechanisms and potentially suspicious command execution.
Page 164 of 1871

