Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects non-browser and non-messaging processes accessing both browser credential stores (like 'Login Data' or 'Cookies') and messaging application session storage (Slack/Discord LevelDB) in a single session. This pattern is characteristic of credential-stealing malware, such as RevStealer, which targets both saved web browser credentials and application session tokens for exfiltration.
Detects the execution of elevated cmd.exe processes (running with High or System integrity) spawned by parent processes originating from the AppData directory. This pattern is commonly associated with malicious installers, droppers, or payload execution where a staged binary in the user profile attempts to perform administrative actions.
Detects PowerShell execution that combines screen capturing capabilities (System.Drawing.Bitmap, Windows.Forms) with network communication (System.Net.WebClient) directed towards known C2 domains (medianewsonline.com) using specific exfiltration parameters (OKey, Who).
Detects unauthorized processes attempting to open handles to Google Chrome or Microsoft Edge with elevated permissions, specifically accessing thread context (often associated with hardware breakpoints used for process injection or credential extraction techniques).
Detects unauthorized access to critical Chromium-based browser credential databases (such as Login Data, Cookies, and History) by processes other than recognized browser executables. This behavior is indicative of credential-harvesting activity, specifically matching techniques employed by infostealers like RevStealer.
Detects suspicious process access attempts targeting common web browsers (chrome, msedge, firefox) using high-privilege access masks (such as 0x1F0FFF or 0x1FFFFF). The detection is specifically scoped to calls originating from unbacked memory (indicated by an UNKNOWN stack trace entry containing ntdll.dll), which is a common indicator of direct or indirect syscalls used by malware for stealthy memory access, such as credential theft or session cookie exfiltration.
Detects the execution of a RevStealer native PE payload by an Electron-based loader (XabivSystem.exe). The rule identifies when the loader spawns an unsigned, detached process from a hidden, randomly-named subdirectory within the user's AppData folder. This process creation is a precursor to the malware's environment checks, anti-VM/sandbox gating, and CAPTCHA verification routines.
Detects a non-privileged user creating a new DLL file within the C:\ProgramData\CrossDevice\ directory on a system that has specific COM registration keys (CLSID {135fd325-45b7-4c30-89f8-4386961669f0} or {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}) pointing to potentially missing or hijacked InprocServer32 paths. This is a common technique used for COM Hijacking or Persistence via phantom DLL loading.
Detects the loading of an unsigned or attacker-controlled DLL into a SYSTEM-context dllhost.exe process, consistent with the exploitation of dangling COM CrossDevice CLSIDs (e.g., forcing ICreateObject::Proc3 to LoadLibrary from a C:\ProgramData location).
Detects instances where dllhost.exe (COM Surrogate) running under high-integrity accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) loads an unsigned DLL file located in the C:\ProgramData\ directory. This pattern is commonly associated with DLL side-loading or malicious library injection to maintain persistence or escalate privileges.
Detects the loading of an unsigned or attacker-controlled DLL into a SYSTEM-context dllhost.exe process, consistent with the exploitation of dangling COM CrossDevice CLSIDs (e.g., forcing ICreateObject::Proc3 to LoadLibrary from a C:\ProgramData location).
Detects the execution of PowerShell commands that leverage specific tooling for scheduled task enumeration, commonly used for discovery or persistence management. The rule flags usage of 'Get-AccessibleScheduledTask' in conjunction with flags associated with tools like NtObjectManager or OleViewDotNet.
Detects non-browser processes accessing sensitive browser credential stores (e.g., Login Data, Cookies) and cryptocurrency wallet files within a short time window. This pattern is characteristic of infostealer malware like Vidar, which grabs browser and wallet data for exfiltration.
Detects web browser processes (Chrome, Edge, Firefox, Brave, Opera, IE) being spawned by a parent process that is not part of the standard, trusted application launch lineage. This pattern is commonly observed in credential-stealing malware like Vidar Stealer, which invokes browsers to access and exfiltrate stored browser data.
Detects the custom ARX-based stream cipher used by Vidar Stealer (v2.2+) to encrypt strings and configuration data. The rule identifies the presence of specific FNV-1a and golden-ratio constants used for state initialization, in combination with unique, per-build keystream constants observed in recent variants.
Detects the presence of known Vidar Stealer malware binaries (internal build versions 2.0 through 3.4) by matching their SHA256 file hashes. Vidar is an infostealer malware typically used to exfiltrate sensitive data from victim systems.
Detects a low-privileged account manually triggering the 'CreateObjectTask' scheduled task, which is a known technique to force the 'Shell Create Object Handler' (dllhost.exe) to start under the SYSTEM context. This behavior is often associated with pre-exploitation steps for privilege escalation vulnerabilities, specifically those involving OBJREF marshaling targeting specific COM objects.
Detects the compiled x86/x64 fetch-decode-execute dispatch loop used by the Vidar Stealer custom VM bytecode interpreter (v2.0+). The rule identifies the structural jump-table bounds-check and computed-jump idiom that is consistent across different builds of the malware, despite randomization of opcode values and XOR keys.
Detects the presence of PIVOTPIPE loader artifacts, specifically the COFF sleep-mask object file (sleepmask.o) and its associated debug log (nb_sleep_dbg.txt), which are written to a randomly named subfolder within the Windows temporary directory as part of a sleep-obfuscation evasion sequence.
Detects the creation of specific named pipes often associated with Cobalt Strike and similar C2 frameworks used for peer-to-peer (P2P) lateral movement. The detection looks for anomalous pipe names created by processes other than standard Windows system processes (svchost, services, lsass), which is a common indicator of beacon communication relaying.
This rule detects potential credential theft by correlating access to local git credential files (e.g., .git-credentials, .netrc) followed by a git push event from the same user account within 24 hours. The rule flags these pushes if they originate from an unrecognized host or an IP address outside of the trusted internal network range.
Page 169 of 1871
