Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
This rule monitors network connections, file events, and process execution command lines for references to a list of known malicious URLs, including indicators associated with ClearFake, IClickFix, AMOS, Remus, and Mozi botnet payloads.
Detects the execution of PowerShell from a shortcut (.lnk) file, particularly when suspicious command-line arguments such as hidden windows, encoded commands, or bypass flags are utilized. This pattern is commonly associated with initial access via malicious attachments or shortcut files.
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
This rule monitors for suspicious process execution (e.g., cmd, powershell) spawned from PaperCut service processes (pc-app.exe, tomcat.exe) followed by a Domain Admin group membership change on the same device within a 30-minute window. This behavior is indicative of privilege escalation attempts following the exploitation of PaperCut vulnerabilities (CVE-2026-81578/CVE-2026-82078).
This rule detects potentially malicious command execution by monitoring additions to the Windows Explorer RunMRU registry key. It specifically triggers when the registry data contains references to 'powershell', 'curl', or appears to be encoded/base64 strings, which are often used by adversaries to execute malicious scripts or download payloads via the Run dialog.
Detects the loading of the Restart Manager DLL (rstrtmgr.dll) by suspicious processes, such as those running from writable user paths (e.g., Temp, AppData) or masquerading as numeric-only named executables. Adversaries may abuse this library for process termination or interaction to facilitate malicious operations, such as clearing file locks during deployment.
This rule detects the creation of Windows scheduled tasks using the 'schtasks.exe' utility or events generated when a task is registered. This technique is commonly used for persistence and execution by adversaries.
Detects the execution of ADExplorer64.exe, a legitimate but potentially misused Sysinternals tool often utilized by attackers for Active Directory reconnaissance and enumeration of domain objects.
This rule detects the use of PowerShell to download common Remote Monitoring and Management (RMM) or remote access tools from the internet. This behavior is frequently associated with malicious actors attempting to establish persistent remote access to a compromised system.
Detects the use of the net.exe or net1.exe utility to add a local user account with the specific password string 'Numlock!123'. This pattern is frequently used by attackers or malicious scripts to establish persistence or secondary access on a system.
Detects the clearing of the Windows Security Event Log. This activity is a common indicator of an adversary attempting to remove evidence of their presence or actions on a compromised host.
This rule monitors network traffic, DNS queries, and user web clicks to detect interactions with known malicious domains associated with credential harvesting and phishing campaigns, specifically those impersonating security or SSO portals.
Detects the execution of rnpkeys.exe dropped by an MSI installer (msiexec.exe) from the C:\ProgramData\keyroll directory. The rule specifically monitors for side-loading of the rnp.dll or tdwp.dll libraries by rnpkeys.exe, a technique associated with the Sauron loader.
Detects anomalous network traffic patterns from the legitimate 'rnpkeys.exe' process when side-loaded from the 'ProgramData\keyroll' directory. The rule specifically looks for a sequence of connections matching initial C2 registration (TLV 0x01) followed by consistent, periodic beaconing (TLV 0x02) at an interval indicating automated task polling, rather than single-connection legitimate activity.
This rule detects the creation of Windows Scheduled Tasks by monitoring for Event ID 4698 (Windows Security Log) or Sysmon Event ID 1 (Process Creation) that involves task name parameters. Adversaries frequently use the Windows Task Scheduler to establish persistence, execute malicious code, or run tasks at system startup.
This rule monitors the rnpkeys.exe process for suspicious environmental reconnaissance activity, specifically targeting locale/keyboard-layout registry queries or domain enumeration via command-line tools. These activities are identified as occurring in a strict temporal sequence (pre-registration check) shortly before an initial outbound network connection, consistent with the behavior of the Sauron loader malware.
Detects a specific staging and execution pattern where a payload file with a 6-16 character random filename is written to a temporary directory and subsequently executed by a common Windows handler process (such as rundll32, regsvr32, or powershell) within a 60-second window. This behavior is indicative of the Sauron Loader task-execution workflow.
Detects a specific staging and execution pattern where a payload file with a 6-16 character random filename is written to a temporary directory and subsequently executed by a common Windows handler process (such as rundll32, regsvr32, or powershell) within a 60-second window. This behavior is indicative of the Sauron Loader task-execution workflow.
Detects the creation of a scheduled task named 'keyroll', which is associated with the persistence mechanism of Sauron Loader. The task is used to launch a DLL side-loading chain involving rnpkeys.exe and tdwp.dll.
Page 183 of 1871



