Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
Matches distinctive DragonForce TURN/MQTT campaign artifact filenames only when combined with byte-level markers unique to the malware (PE structure, TURN/MQTT C2 infrastructure strings, or the loader's pipe-caret-pipe thread-trigger byte pattern), to avoid false positives on unrelated benign files sharing these names.
Detects anomalous execution of PowerShell commands spawned by processes identified as 'javaw.exe' or 'GlobalTellurSync.exe' (associated with DragonForce backdoor activity). The detection focuses on instances where these processes launch from non-standard user-writable directories (e.g., AppData, Temp) and execute PowerShell commands that contain obfuscated arguments or payloads, while excluding standard scheduled task invocations.
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
This rule performs a retrospective sweep across Microsoft Defender XDR data sources (DeviceFileEvents, DeviceProcessEvents, DeviceNetworkEvents, and EmailEvents) to identify activity associated with the Star Blizzard (COLDRIVER) campaign. It monitors for specific file hashes, file names, known C2 IP addresses and domains, malicious URL patterns, and known phishing email sender addresses identified in threat intelligence reporting.
Detects the execution of control.exe with suspicious command-line arguments involving WebDAV paths (DavWWWRoot) and file extensions like .cpl or .dll, initiated by Windows task-related processes (svchost, taskeng, schtasks). This pattern is indicative of potential malicious payload loading or proxy execution where a scheduled task is used to trigger a secondary malicious component.
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
Detects wscript.exe or cscript.exe executing a VBScript that uses MSXML2.XMLHTTP and ADODB.Stream to download a file in chunks (using the Range header) to a temporary or AppData location. This technique is often used by malware to evade detection by downloading payloads in smaller pieces.
Detects activity associated with Everest ransomware by matching known file hashes (in DeviceFileEvents/DeviceProcessEvents) and known C2/leak-site domains (in DeviceNetworkEvents).
This rule detects a sequence of events characteristic of the x47.c persistence pattern. It monitors for the creation of persistence mechanisms via Windows Registry Run keys or scheduled tasks, followed by the addition of Windows Defender exclusions using PowerShell within a 30-minute window on the same device.
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
This rule detects potential persistence via scheduled tasks that masquerade as legitimate network components (e.g., 'System Health Monitor'), as well as abnormal use of WebDav via rundll32.exe or net.exe in the context of the Star Blizzard (COLDRIVER) campaign. It monitors for task creation/updates, schtasks command lines, registry artifacts related to task scheduling, and suspicious WebDav network utility usage, while excluding common security tool processes.
This rule detects activities associated with the Star Blizzard (also known as APT28 or Callisto) group's CosmicPulse malware, specifically the downloader and Python-based backdoor. It monitors for suspicious CPL file execution via UNC paths by rundll32.exe or control.exe, unauthorized modifications to the HKCU\Software\Classes\.mollis registry key used for COM hijacking, and anomalous spawning of Python executables from control host processes in user-writable directories.
This rule detects potential post-compromise activity related to a campaign using MSP360-masqueraded installers and ScreenConnect remote access tools. It performs an IOC sweep across device file events for known malicious file hashes (associated with installers and post-compromise utilities) and device network events for connections to known malicious domains used for command and control.
Detects execution of potentially malicious or dual-use tools (such as credential dumpers or security-bypass utilities) from within ScreenConnect temporary directories via the 'RunFile' command. This is indicative of an attacker leveraging legitimate remote support software to deploy secondary payloads.
This rule detects instances where the MSP360 RMM Agent installer triggers an UAC elevation failure. The detection specifically monitors the execution of eventcreate.exe, which is often used to log events, when the command line includes strings indicating that the MSP360 installer failed to elevate privileges.
This rule detects potential unauthorized or suspicious installation of an RMM (Remote Monitoring and Management) agent on a Windows host. It flags cases where a process performs multiple suspicious actions within a 24-hour window, specifically combining the installation or starting of a service related to an RMM agent, the creation of a Windows Firewall rule for the RMM agent executable, and/or the creation of log events related to the installer.
Detects the download of a masqueraded MSP360 RMM v2.5.0.67 installer to the Downloads folder. The rule identifies files matching specific naming conventions, including generated GUIDs, or known malicious hashes, originating from common cloud storage providers often abused by threat actors.
This rule detects various malicious indicators including known file hashes, IP addresses, domains, and specific URLs associated with threat activity. It consolidates hits from process, file, and network telemetry to alert on potential compromise or communication with identified command-and-control (C2) infrastructure.
Detects automated reconnaissance using WMI or PowerShell to perform broad queries for system environment, security products, network adapters, software, and hardware attributes. The detection focuses on clusters of distinct WMI reconnaissance categories occurring within a 15-minute window, which is often indicative of pre-C2 profiling by adversaries.
This rule detects suspicious persistence activity involving known tools or names that are often masqueraded. It looks for the creation of registry run keys or scheduled tasks using names associated with common tools ('Canon Configuration Reader', 'Stardock DeElevation Tool') when the initiating process is not located in the expected vendor-authorized directories. The rule specifically alerts on devices exhibiting these behaviors within a short time window.
Page 17 of 1866


