Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of known HVNC (Hidden Virtual Network Computing) backdoor binaries identified by specific file names and staging directory paths. These binaries are designed to create hidden desktop sessions and perform input injection to facilitate unauthorized remote control of a compromised host.
Detects instances where the WindowsPackageManagerServer.exe (WinGet COM Server) is invoked to perform DSC (Desired State Configuration) operations (via ConfigurationStaticFunctions) by a process other than the standard winget.exe. This behavior is indicative of an attempt to bypass process-based monitoring of winget.exe by interacting directly with the COM API using custom or alternative tools like DSCourier.exe.
Detects the creation of a local user account and its subsequent addition to the local Administrators group via PowerShell cmdlets (New-LocalUser, Add-LocalGroupMember) triggered by the ConfigurationRemotingServer.exe process. This activity is indicative of abuse of the WinGet Desired State Configuration (DSC) 'Script' resource to establish persistent administrative access.
Detects access or interrogation of the WinGet configuration history database (config.db) by non-standard or user-supplied Python scripts, which may indicate an attempt to enumerate installed package configurations or extract sensitive information from the local configuration state.
Detects the WinGet DSC configuration engine spawning service management processes such as sc.exe or PowerShell to create or modify Windows services. This activity is consistent with the abuse of DSC 'Service' resources to achieve persistence or privilege escalation by registering services to run as LocalSystem.
Detects processes associated with the WinGet/DSC configuration engine (ConfigurationRemotingServer.exe, WindowsPackageManagerServer.exe, or winget.exe) initiating processes with the COR_PROFILER or COR_ENABLE_PROFILING environment variables. This behavior is indicative of leveraging .NET profiler hijacking via the DSC 'Environment' resource for persistence or privilege escalation.
Detects the copying of the legitimate Windows curl.exe binary to a renamed filename within user-writable directories (e.g., %TEMP%) via PowerShell. This technique is often used to masquerade the utility for stealthy file downloads. The rule also identifies the execution of these renamed binaries by checking for a mismatch between the current filename and the binary's original file description embedded in its PE header.
Detects the execution of WinGet DSC backend services, ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe, when launched as child processes of WinGet or DSCourier. This behavior is indicative of potential proxy execution abuse where WinGet components are leveraged to execute arbitrary code or configurations via signed Microsoft binaries.
This rule detects malicious .lnk files typically delivered as email attachments (spearphishing). It identifies shortcuts that execute cmd.exe with the /k switch, combined with environment variable substring expansion techniques designed to obfuscate multi-stage command execution chains.
Detects the creation of files in the Windows Temp directory that match specific naming patterns associated with UnixStealer, including tool executables, database files, stolen data archives, and debug logs. These artifacts are characteristic of the tool's staging and activity tracking behaviors.
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
Detects instances where cmd.exe spawns a powershell.exe process with the execution policy set to bypass. This is a common technique used by attackers to execute malicious scripts while bypassing local security restrictions on script execution.
Detects the creation or execution of a scheduled task named 'MicrosoftMusicLibrariesPackageTaskMachine' and the invocation of specific associated file names 'codeflush.exe' or 'settingenv.cat', which are indicators of persistence used by the threat actor APT37.
Detects the copying of the legitimate Windows curl.exe binary from System32 to a user-writable directory (such as AppData\Local\Temp) and renaming it. This is a common LOLBin (Living Off the Land Binary) technique used by adversaries to disguise the utility as a benign application to evade detection while facilitating the download of second-stage payloads.
Detects the use of the Windows command shell 'copy' utility to concatenate separate files, such as 'header.doc' and 'body.doc', into an executable file named 'Windowsupdate.exe'. This technique is commonly used by adversaries to reassemble malicious payloads that were split to evade signature-based detection or bypass security controls.
Detects network beaconing activity associated with the Casbaneiro (Metamorfo) banking trojan. The rule monitors for specific C2 communication patterns, including the 'client;' string and the 'VVx-4.3' version marker, which are characteristic of this malware's host reconnaissance and command-and-control exfiltration phase.
This rule detects potentially malicious activity where an executable with an MD5-formatted name is created in the user's temporary folder, followed by the creation of a registry key with a matching MD5-formatted name in HKEY_CURRENT_USER\SOFTWARE\ within 15 minutes. This behavior is indicative of a persistence mechanism where malware drops a payload in a temp directory and sets a run or autorun registry key to ensure its execution upon logon or startup.
This rule detects the execution of common command-line utilities (cmd.exe, mshta.exe, AutoIt3.exe) using command-line arguments that mimic legitimate service names or security analysis tools (e.g., 'Microsoft Update Superfetch Core Endpoint Service'). This behavior is indicative of an adversary attempting to mask malicious activity by using strings that resemble benign system services or localized security scanner output, likely for obfuscation or evasion.
Detects the creation or modification of Windows Registry Run keys associated with the name 'SnapCart'. This behavior is characteristic of adversaries attempting to achieve persistence on a host by ensuring malicious code executes automatically upon user logon.
Detects instances where wscript.exe spawns powershell.exe with command-line arguments indicative of stealth or obfuscation, such as hidden windows or encoded commands. This behavior is frequently associated with malicious script execution lures, such as JavaScript-based droppers or ClickFix-style campaigns that use PowerShell to stage and execute in-memory payloads.
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
Page 182 of 1871

