Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects instances where PowerShell is executed by a Windows Script Host process (wscript.exe or cscript.exe) using common suspicious command-line arguments. This pattern is frequently used by adversaries to execute obfuscated or bypassed PowerShell scripts while attempting to hide or proxy the execution through legitimate scripting host processes.
Detects the use of PowerShell to download a file named Document.pdf using Invoke-WebRequest, saving it to disk, and immediately executing it using Start-Process. This behavior is indicative of a dropper or secondary stage payload execution pattern.
Detects the use of PowerShell to delete files with common script or shortcut extensions from directories frequently used for persistence or staging malicious payloads, such as APPDATA, ProgramData, and the Startup folder.
Detects the execution of PowerShell scripts containing specific obfuscation or encoding patterns. The rule identifies potential malicious intent by searching for hardcoded suspicious strings or common binary-to-string conversion methods used to hide script content from security monitoring.
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
Detects potential Remus infostealer activity by monitoring unauthorized processes accessing AI agent credential directories (Claude, Cursor, OpenCode, Codex) or cryptocurrency wallet files, specifically when combined with .lnk shortcut file access behavior.
Detects suspicious process injection attempts into browser processes (e.g., chrome.exe, msedge.exe) characterized by direct NT API syscall invocation (e.g., NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx) originating from a non-browser parent process. This behavior, often associated with the Remus infostealer, bypasses standard user-mode API hooking by using direct syscall stubs to chain injection actions.
Detects the creation or access of .pst files by processes other than standard email clients (Outlook) or web browsers. This activity is often associated with the staging and collection of sensitive email data, which could indicate credential theft or data exfiltration attempts.
Detects command execution patterns consistent with the ClickFix attack technique, where users are socially engineered into pasting and executing commands (often via the Windows Run dialog or web browsers) to bypass fake CAPTCHA prompts. The rule looks for common living-off-the-land binaries (powershell.exe, cmd.exe, etc.) spawned from browsers or explorer.exe executing suspicious downloader/execution cmdlets.
This rule monitors for suspicious activity related to Component Object Model (COM) objects, including registry modifications (creation, setting, or checking of specific CLSIDs related to shell links or WMI locators) in conjunction with process-level alerts (such as Remote Thread API calls, primary token modification, or WMI activity). It specifically filters out known benign system processes to focus on anomalous behavior that may indicate COM hijacking, persistence, or lateral movement.
Detects instances where a process directly reads ntdll.dll from the disk (e.g., C:\Windows\System32). This behavior is a common technique used by malware to bypass EDR hooks by reading a clean copy of the DLL to restore original syscall stubs, commonly known as hook removal or unhooking. The rule excludes common system processes and trusted security software paths.
The following analytic identifies the `finger.exe` utility being spawned with a command line containing an `@` character, indicating a remote host/server was specified.
The Finger protocol utility is largely obsolete in modern environments and has been abused by adversaries as a living-off-the-land binary (LOLBIN) to retrieve encoded payloads or establish covert command-and-control communication with an attacker-controlled finger server.
This behavior is uncommon in legitimate enterprise usage and warrants investigation.
The Finger protocol utility is largely obsolete in modern environments and has been abused by adversaries as a living-off-the-land binary (LOLBIN) to retrieve encoded payloads or establish covert command-and-control communication with an attacker-controlled finger server.
This behavior is uncommon in legitimate enterprise usage and warrants investigation.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
C2 Ioc Detection
YARA-L
Detects Network, File, or Process events associated with known C2 IOCs
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule detects when the Node.js runtime process (node.exe) initiates the Windows command interpreter (cmd.exe) with the '/c' flag, which is commonly used to execute commands or scripts. This behavior is frequently associated with malicious Node.js activity, such as Remote Access Trojans (RATs) or web shells, which may use the shell to execute system-level operations or bypass typical application constraints.
ChainScript file manager 'files' task: node.exe performing high-volume recursive deletion within masqueraded ChainScript installation paths (drive enumeration, dir listing, file read/write, recursive delete)
Page 165 of 1871



