Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects Node.js processes spawning common system discovery utilities such as systeminfo, wmic, or uname. This behavior is indicative of a post-compromise scenario where a web application or Node.js-based service is being used to gather information about the underlying operating system environment.
Detects the launch or execution of common remote access tools such as AnyDesk, TeamViewer, Quick Assist, or Microsoft Remote Assistance (msra.exe) on an endpoint, excluding instances where these tools act as the parent process. This rule serves as one component of a broader detection chain for potentially unauthorized remote access.
This rule detects potential unauthorized use of MeshAgent RMM software by correlating process execution events (mvtcs.exe, MeshAgent) with network traffic to specific IP addresses identified as associated with Settra command-and-control infrastructure. It specifically filters for MeshAgent activity and validates the threat by requiring an established network connection to known malicious endpoints.
This rule detects potentially malicious activity involving Node.js modules. It monitors for the deletion of specific 'sharedLoad.min.js' or 'extended' files within 'node_modules' directories, the execution of Node.js processes attempting file deletion operations (like 'unlink' or 'rm') within 'node_modules', and the creation or modification of JavaScript files within 'node_modules' that contain 'btree' references. This activity may indicate an attempt to tamper with application dependencies, inject malicious code, or remove artifacts.
This rule detects the execution of AnyDesk within a 30-minute window of Microsoft Teams activity on the same device. This pattern is indicative of a vishing attack, where a malicious actor lures a victim into installing remote access software during a fake technical support session initiated via Teams.
This rule detects instances where a Node.js process spawns a child process, also running as node.exe, that attempts to execute a specific JavaScript file path (sharedLoad.min.js or its extended version). This behavior is characteristic of certain Node.js-based applications or potentially malicious scripts using shared loaders for modular execution.
Detects instances where the Node.js process (node.exe) is executed with a command-line argument referencing 'sharedLoad.min.js'. This is often used in web-based applications or potentially malicious obfuscated scripts, but may flag legitimate JavaScript automation tasks.
Detects the execution of the AnyDesk remote support application when initiated from a web browser (msedge.exe) or the Windows file explorer (explorer.exe). This pattern is often indicative of user-driven execution, potentially as part of a tech support scam or unauthorized remote access attempt.
Detects the installation of specific known malicious NPM packages (indexed-btree, btree-core, mutex-forge) or execution of npm install commands targeting these packages, which are indicative of software supply chain compromise attempts.
Detects a Node.js process deleting specific core application files, such as 'index.js' or 'sharedLoad.min.js', located within 'node_modules' directories. This activity may indicate malicious tampering, package integrity compromise, or an adversary attempting to disrupt application functionality.
This rule detects instances where the legitimate remote desktop application AnyDesk (AnyDesk.exe) acts as the parent process to spawn a Windows command shell (cmd.exe) or execute a batch script (.bat). This behavior is often indicative of unauthorized remote access or the execution of malicious payloads by adversaries leveraging remote support tools.
Detects the modification of InProcServer32 registry keys within the user's Classes/CLSID hive to point to a file located in the AppData directory. This pattern is commonly used for COM hijacking to achieve persistence or execute arbitrary code under the user's context.
This rule detects network connections or DNS requests to domains specifically structured to impersonate MFA registration, passkey setup, or SSO login pages. These domain patterns are commonly associated with phishing campaigns intended to harvest credentials, session tokens, or bypass multi-factor authentication (AiTM phishing).
Detects the loading of wkspbroker.exe or radcui.dll modules from the Microsoft RemoteApp Gateway directory located within the user's AppData path. This behavior may indicate an attempt to utilize or manipulate Remote Desktop components from a non-standard or user-writable location.
Detects a sequence of events where a user is targeted by an email bombing attack, subsequently receives an external or anonymous Microsoft Teams call, and finally launches a known remote access tool (e.g., AnyDesk, TeamViewer) on the same host within a one-hour window. This pattern is consistent with social engineering campaigns designed to trick users into providing remote access to their systems.
Detects the execution of AnyDesk or its installation from common user-writable directories (Downloads or AppData), as well as scenarios where a browser (msedge.exe) initiates an AnyDesk-related download. This is a common indicator of unauthorized remote access tool deployment.
Detects Node.js process executions that involve loading a suspicious JavaScript file named 'sharedLoad.min.js' or 'extended/sharedLoad.min.js'. The rule further flags instances where the process command line includes 'detached' and 'windowsHide' arguments, which are frequently used to execute Node.js scripts in the background without a visible window.
Detects instances where a Node.js process (node.exe) attempts to execute native system discovery commands such as systeminfo, hostname, or wmic queries. This pattern is commonly observed in malicious Node.js applications or compromised environments attempting to gather system reconnaissance information.
Detects the execution of MSBuild.exe with command line arguments pointing to project files (.xml or .csproj) that contain C# inline task structures (e.g., CodeTaskFactory, UsingTask). This technique is commonly used to proxy malicious code execution via a trusted Microsoft binary, bypassing certain application control policies.
Detects instances of rundll32.exe being executed with command line arguments that point to DLLs in common user-writable or non-standard directories (e.g., Temp, AppData, Downloads, ProgramData) or employing known malicious command patterns like Control_RunDLL, javascript: protocol handlers, or shell32.dll proxy execution techniques often used to evade security controls.
Detects msiexec.exe execution with flags intended for silent or standard installation when the source path points to a remote web resource (HTTP/HTTPS) or a UNC path. This behavior is indicative of using the native Windows Installer to proxy the download and execution of arbitrary, potentially malicious, MSI packages.
Page 175 of 1871

