Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects the execution of known malicious MSI files associated with the LegionLoader malware family by monitoring process creation events involving msiexec.exe. The rule matches on specific file hashes and filenames identified in technical analysis of LegionLoader variants.
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
Detects the loading of a known malicious 7z.dll file within the 'Traiolx Custom Utils' directory. This behavior is indicative of DLL sideloading used by LegionLoader to achieve code execution under the guise of a legitimate application.
Detects the presence of a suspicious or known malicious 'Normaliz.dll' file located within the 'Traiolx Custom Utils' directory, indicative of a DLL sideloading attempt.
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This behavior is often associated with malware or malicious loaders (such as LegionLoader) that use secondary instances to facilitate malicious code execution or persistence while masquerading as legitimate update utilities.
Detects the installation or registration of the legitimate gitlab-runner.exe binary as a persistent Windows service. Adversaries can leverage this technique to establish a command-and-control (C2) channel or persistent backdoor by masquerading as legitimate CI/CD infrastructure.
Detects unsigned or non-standard Python processes loading core Windows system modules like kernel32.dll or ntdll.dll. This behavior is consistent with NarwhalRAT's fileless execution technique, which utilizes ctypes to interact with low-level Windows APIs (VirtualAlloc, RtlMoveMemory, CFUNCTYPE) for in-memory payload allocation and execution, bypassing traditional disk-based detection.
Detects the BTR.sys driver, a tool identified as being extracted from Microsoft's MpEngine.dll and repurposed for kernel-level file and registry manipulation. The rule matches on specific SHA-256 file hashes or combinations of PE metadata strings, indicating the presence of this driver on the system.
This rule detects the creation of a new service in HKLM\SYSTEM\CurrentControlSet\Services that includes specific suspicious command-line arguments (containing ':changelist') and is configured to start automatically (Start value '1') or belongs to the 'Boot Bus Extender' group. This behavior is often associated with persistence mechanisms where adversaries register a service to execute malicious payloads upon system startup.
Detects the execution of BTR_CLI.exe with command line arguments indicative of installing or interacting with the Mimikatz driver (mimidrv.sys). This behavior is associated with loading the malicious driver to facilitate credential dumping from kernel memory.
Detects the creation of .bat files within the Windows Startup folder. Adversaries often use this technique to achieve persistence by ensuring a script executes automatically upon user login.
Detects the execution of PowerShell with suspicious command-line flags often associated with malicious scripts (e.g., hidden windows, no profile, bypassed execution policies) when the script is located in the Windows Temporary directory.
Detects instances of the Windows Character Map utility (charmap.exe) loading graphics-related libraries such as System.Drawing.dll or gdiplus.dll. These modules are typically not required by charmap.exe and their loading is a common indicator of process injection for the purpose of capturing the screen or desktop interface.
Detects instances where PowerShell is launched as a child process of WScript.exe or CScript.exe with suspicious command line flags intended to hide window visibility, bypass execution policies, or run in a non-interactive mode. This behavior is frequently used by adversaries to execute obfuscated or malicious scripts while minimizing user awareness.
Detects instances where PowerShell.exe spawns the .NET C# compiler (csc.exe) with command-line arguments referencing a '.cmdline' file. This pattern is commonly used by adversaries to compile malicious code in-memory, bypassing traditional disk-based file scanning.
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
Detects the loading of 'opencv_world4120.dll' by specific process names commonly associated with update activity (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) when the loaded DLL is either unsigned, untrusted, or has an invalid signature. This is indicative of potential DLL side-loading where malicious code is executed under the context of an ostensibly legitimate update process.
Detects unauthorized processes attempting to access sensitive Mozilla Firefox profile files such as cookies.sqlite, places.sqlite, and permissions.sqlite. These files contain sensitive information including cookies, history, and permission settings. Access by processes other than the legitimate Firefox executable may indicate credential theft, data exfiltration, or reconnaissance activities.
Detects suspicious processes (named UpdateAssistant.exe, AppUpdateHelper.exe, or SysMaintenance.exe) executing from specific file system paths and initiating network connections to known suspicious IP addresses (5.230.249.49, 40.124.169.27) on non-standard ports (27015, 27017). The rule correlates process execution from specific suspicious directories with network activity to identify potential command-and-control communication.
Detects the execution of suspected Hidden VNC (HVNC) backdoor components that demonstrate behaviors consistent with banking credential theft, specifically targeting keystroke logging APIs. The rule monitors for specific process names executing from suspicious directories often used for persistence.
Page 181 of 1871

