Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects hosts exhibiting multiple distinct file-manipulation commands (upload, download, stop, delete, append, copy, move) within a single session as identified by the PivotPipe C2 protocol, indicating potential staging, collection, or exfiltration activity.
Detects the execution of PowerShell with suspicious command-line arguments (hidden window, no profile, or encoded commands) spawned directly from a web browser process (e.g., Chrome, Edge, Firefox, Explorer). This behavior is characteristic of ClickFix-style social engineering attacks where a user is tricked into copying and executing malicious PowerShell commands via the Win+R Run dialog or terminal.
Detects a specific pattern of Windows API calls consistent with PIVOTPIPE C2 activity, involving process token impersonation (OpenProcessToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken) followed by a RevertToSelf call. The rule correlates these events within a single process, identifies artifacts related to PIVOTPIPE loader/payloads, and ensures the sequence completes within a short time window.
Detects instances where npm.exe or node.exe initiate child node.exe processes, a behavior commonly associated with multi-stage loaders or malicious packages (e.g., GHAPPIER) that execute arbitrary JavaScript payloads during package installation or execution.
This rule detects unauthorized access, creation, or modification of Git credential files (.git-credentials, .netrc) by processes other than standard Git credential management utilities. It also monitors command-line activity that references these credential stores to identify potential attempts to exfiltrate or manipulate stored credentials.
This rule detects the creation of multiple suspicious files within the \Windows\Temp\nb_ directory. The monitored filenames, such as 'agent.json', 'pk.der', 'sleepmask.o', and 'core.pak', are highly characteristic of post-exploitation toolkits, specifically those associated with beaconing, shellcode injection, or modular C2 agents. Detecting these files in temporary locations, especially when appearing in combination, strongly indicates potential adversary activity involving the staging and execution of malicious payloads.
Detects the creation of specific file artifacts and process execution associated with the PIVOTPIPE .NET loader. The rule monitors for the creation of temporary working directories prefixed with 'nb_' in '\Windows\Temp\', the staging of associated configuration and payload files (such as 'agent.json', 'pk.der', 'sleepmask.o', 'core.pak'), and the execution of associated process names like 'netbeacon_pivot.exe', 'pivot_hop2_kasp.exe', or 'x64beacon.exe'.
Detects the creation or modification of known PIVOTPIPE loader artifacts, specifically the 'sleepmask.o' file and related configuration or helper files ('agent.json', 'pk.der', 'core.pak'), within temporary directories prefixed with 'nb_' under the Windows Temp folder. These files are used by the PIVOTPIPE loader to implement sleep-masking techniques that encrypt beacon memory during dormant periods to evade detection.
Detects PowerShell execution containing multiple command-line arguments indicative of environment discovery, such as checking system uptime, hardware specifications, or specific memory-related delays. These patterns are commonly used by malware to detect virtual machines, sandboxes, or analysis environments to alter execution or exit.
Detects suspicious PowerShell activity involving compression commands (e.g., Expand-Archive) within APPDATA, correlated with the execution of hypersnap.exe with hidden window arguments, and the creation of persistence via scheduled tasks. This pattern is indicative of automated staging or malicious tool execution and persistence setup.
Detects a scenario where a single initiating process terminates multiple distinct processes within a short timeframe (5 minutes). This behavioral pattern is often associated with security tool tampering or EDR-evasion techniques where malicious code attempts to identify and terminate defensive security processes.
Detects the creation of specific debug log files by PIVOTPIPE Cobalt Strike-compatible payloads in the Windows temporary directory. These artifacts indicate active post-exploitation activity, specifically operations involving process token manipulation or impersonation.
This rule monitors for suspicious process behaviors and module loads, specifically focusing on unusual explorer.exe parentage, the loading of common system DLLs (dbghelp.dll, Secur32.dll) in potentially anomalous contexts, and specific command-line strings that may indicate malicious activity or tools.
Detects high-frequency calls to the VirtualProtect API where memory protections are changed to read/write (PAGE_READWRITE) or executable read/write (PAGE_EXECUTE_READWRITE). This behavior is often indicative of process injection techniques or self-modifying code associated with unpacking, loading shellcode, or tampering with process memory.
Detects anomalous, high-frequency interaction with the Windows clipboard by explorer.exe. This activity is often associated with unauthorized data collection or exfiltration attempts by malware residing within or masquerading as the Windows shell.
Detects the loading or installation of a driver file identified as DCRCVDrv.sys followed within 5 minutes by EDR sensor heartbeat loss or process activity, which is characteristic of attempts to tamper with security software or hide malicious activity via a kernel-mode driver.
Detects process execution patterns and DNS requests associated with the GHAPPIER malware staging infrastructure. The rule monitors for specific command-line arguments involving known malicious scripts, temporary files, and deployment infrastructure (e.g., Vercel) often used for delivering or executing malicious payloads via node.js environments.
Detects a process that deletes its own executable file immediately after launching. This anti-forensic behavior is commonly utilized by remote access trojans (RATs) and other malware to minimize their footprint and evade file-based forensic analysis.
Detects malicious JavaScript/npm payloads that attempt to evade static analysis and string-based detection signatures by dynamically reconstructing sensitive strings at runtime using V8 string-object construction or obfuscated string tables.
Detects execution of code using indirect syscalls or ntdll unhooking techniques, often associated with the PIVOTPIPE loader/RAT. The rule monitors for EDR indicators of evasion such as syscall stub execution, direct/indirect Nt* system call invocation, or call stacks originating outside of ntdll.dll, intended to bypass userland security hooks.
Detects the execution of PowerShell with suspicious command-line arguments (e.g., WebClient, hidden flags, or WebDAV paths) spawned directly from browser processes like chrome.exe or msedge.exe. This pattern is commonly associated with fileless delivery techniques where an attacker attempts to download and execute scripts directly from an internet-facing source.
Page 170 of 1871
