Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Detects Vidar Stealer v2.x-3.x custom VM bytecode interpreter used to deobfuscate strings via a fetch-decode-execute loop with sparse opcode dispatch and single accumulator
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
Detects the execution of the AnyDesk remote support tool while Microsoft Teams is currently running. This pattern is often indicative of social engineering or tech support scams where an attacker convinces a victim to run remote access software during a call.
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
Detects the loading of radcui.dll from the non-standard %LOCALAPPDATA%\Microsoft\RemoteApp\Gateway\ directory. This behavior is associated with DLL sideloading chains where signed Microsoft binaries (such as wkspbroker.exe) are abused to load malicious payloads, often seen in the PREY-0058/Aur0ra Teams vishing campaigns.
Detects the presence of file artifacts associated with the Xray-core proxy tool when used as an implant via DLL sideloading. The rule identifies specific files (radcui.dll, config.json, comsrv.dat, KB85809588.bat) or malicious configuration patterns indicating proxy traffic (VLESS/VMess/outbound/inbound) targeting known C2 endpoints.
Detects Node.js processes executing system-level reconnaissance (e.g., CPU, memory, hostname, uptime enumeration) followed by network connections to known exfiltration endpoints (Slack, Telegram API). This behavior aligns with identified npm malware campaigns using host fingerprinting for target selection and data exfiltration.
This rule detects the execution of the AnyDesk remote access tool shortly after its likely download via Microsoft Edge. This pattern is commonly associated with social engineering vishing attacks where an adversary directs a user to download and run remote access software.
Detects persistence attempts using Component Object Model (COM) hijacking by modifying HKCU CLSID InProcServer32 registry keys. The rule specifically identifies instances where the registry value points to a DLL file located within the user's AppData or LocalAppData directories, excluding typical system or program directories, as seen in sideloading persistence chains.
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
Page 174 of 1871

