Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects network connections to known SideCopy/ReverseRAT command-and-control infrastructure, including a static C2 IP address and two C2/hosting domains (matched exactly and as proper subdomains to avoid substring false positives).
This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
This rule monitors for indicators of compromise (IOCs) associated with the threat actor SideCopy and their associated malware, such as ReverseRAT. It hunts for specific malicious SHA256 file/process hashes, connections to known malicious C2 infrastructure (IPs and domains), requests to known malicious URLs, and user interaction with these URLs via email clicks.
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
This rule detects potential privilege escalation exploiting a dangling COM object registration (CLSID {E9F83CF2-E0C0-4CA7-AF01-E90C70BEF496}). It monitors for a non-SYSTEM user creating a DLL within the 'CrossDevice' ProgramData folder, followed by a scheduled task trigger, and subsequently detects 'dllhost.exe' running as SYSTEM loading that specific malicious DLL, indicating successful execution of unauthorized code with elevated privileges.
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
Detects instances where the process 'GRrte.exe' forcefully terminates 'iediagcmd.exe' using taskkill.exe. This activity is indicative of an attempt to disable or impair specific security diagnostic tools or EDR-related components on the host.
Detects non-browser processes performing file operations (create, modify, rename) on known web browser credential storage, configuration files, and cryptocurrency wallet artifacts in a short duration. This behavior is indicative of credential harvesting or information stealing activity often associated with malware like Vidar, which stages these sensitive files for exfiltration.
Detects rapid, closely-spaced network requests from the Microsoft Edge process (msedge.exe) to Microsoft-hosted domains within a very short timeframe. This behavior is indicative of a race-condition exploitation technique (CVE-2026-55945) intended to manipulate the Edge AI agent's state transitions, specifically forcing it from 'think' mode into 'act' mode to facilitate unauthorized command injection.
This rule detects the execution of a malicious PowerShell command chain initiated by explorer.exe, consistent with the PlugX malware infection sequence. The detection monitors for specific command-line arguments, including the use of curl for file downloads, tar for extraction, and the launching of associated malicious executables like 'GRrte.exe' following the execution of a shortcut file named 'OIC_Invitation_General_Official.lnk'.
Remote Registry Access via Winreg RPC
Cortex XDR
Detects suspicious remote registry operations performed through the Winreg RPC interface. The rule monitors for interactions with sensitive registry hives (e.g., SAM, SECURITY, SYSTEM) or anomalous levels of remote registry activity originating from remote connections (SMB, TCP, Named Pipes). Such activity is often associated with credential dumping tools like Impacket's secretsdump or unauthorized remote configuration discovery.
Page 178 of 1871




