Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects activity related to potential browser credential theft, specifically targeting Chrome and Microsoft Edge. The rule monitors for the loading of a specific suspicious file, the presence of browser-specific decryption artifacts such as 'browser_decryption.log' or 'ProtectR3.dll', and process command-line arguments containing keywords like 'DecryptData' or 'Elevation Service' associated with browser credential extraction.
This rule detects the creation or modification of Windows Registry Run keys that execute rundll32.exe. This is a common persistence technique where attackers configure malicious DLLs or scripts to run automatically upon user logon or system boot by leveraging the Rundll32 utility.
Detects instances where PowerShell is executed with an explorer.exe parent process, but the actual creating process differs from explorer.exe. This behavior is indicative of parent PID (PPID) spoofing, a technique often used to evade detection or masquerade the execution source by abusing the PROC_THREAD_ATTRIBUTE_PARENT_PROCESS flag in the Windows API.
Detects the loading or file presence of the malicious kernel driver 'Alinubx.sys' (formerly 'CcProtect.sys'), which is utilized by attackers for Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode.
Detects the suspicious execution of ServiceModelReg.exe or command lines containing the 'Elevation:Administrator!new:' string, which is associated with bypasses of Windows User Account Control (UAC). The rule excludes trusted system processes like msiexec, TrustedInstaller, and svchost to reduce noise.
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
Detects the initiation of PowerShell by the Windows Explorer process (explorer.exe), which is often indicative of malicious activity such as lateral movement or execution of scripts originating from user-triggered actions. The rule flags command lines containing obfuscated patterns, bypass arguments, or encoded commands.
Detects when AI-powered development tools or coding assistants (such as Claude, Copilot, Gemini, or Codex) spawn suspicious child processes like command shells (cmd, powershell, bash, sh) or networking utilities (curl, wget, python). This behavior is highly atypical for integrated development environments and may indicate exploitation of the assistant's integration or malicious code execution.
This rule detects potentially unauthorized or suspicious repository interactions by monitoring 'git' commands executed by common AI-assisted coding tools or command-line developer utilities. It flags occurrences where a checkout operation occurs without accompanying standard git history or status checks, which may indicate automated exfiltration or lateral movement attempt within a developer environment.
Detects the execution, network connections, and service installation of MeshAgent or associated binaries (e.g., mvtcs.exe). The rule identifies potential unauthorized or malicious use of this remote management software by looking for process activity, specific network connections to known infrastructure, and service persistence mechanisms.
Detects the execution of ReAgentC.exe with the /disable flag, which disables the Windows Recovery Environment (WinRE). This activity is often used by adversaries to prevent system recovery or to facilitate data impact, such as ransomware deployment.
Detects the execution of PowerShell via WScript or CScript where the command line contains instructions to remove an environment variable. This pattern is commonly used by adversaries to clear sensitive environment data or bypass certain application restrictions.
Detects command-line activity indicating an attempt to bypass or tamper with Anti-Malware Scan Interface (AMSI) functionality. The rule flags processes invoking GetProcAddress or LoadLibrary to resolve and manipulate AMSI-specific functions like AmsiScanBuffer or AmsiScanString within amsi.dll, a common technique for disabling runtime script scanning.
Detects the execution of wscript.exe with silent (/B) and no-logo (/Nologo) flags, spawned by a process named MicrosoftEdgeUpdateTaskCore. This pattern is indicative of potential living-off-the-land techniques where an adversary leverages a legitimate system task to execute scripts stealthily.
Detects execution of PowerShell spawned by wscript.exe or cscript.exe attempting to retrieve a process-level environment variable named 'Kv[0-9]+'. This pattern is associated with 'LausivLoader', which uses environment variables to pass file paths or malicious payloads between a legacy script host and PowerShell. The rule optionally tracks attempts to delete associated files after the handoff.
Detects the spawning of a hidden PowerShell process by wscript.exe via conhost.exe with the --headless argument. This pattern is characteristic of the LausivLoader malware, which utilizes obfuscated command-line arguments to execute hidden PowerShell scripts.
Detects attempts to patch or disable Event Tracing for Windows (ETW) functionality by identifying memory modification operations targeting the 'EtwEventWrite' function or direct memory protection changes within 'ntdll.dll'. This is a common technique used by malware and post-exploitation tools to blind security telemetry.
Detects the use of .NET reflection methods such as Assembly.Load or EntryPoint.Invoke within PowerShell command lines. This behavior is frequently used by attackers to reflectively load malicious .NET assemblies or shellcode directly into process memory, bypassing disk-based detection.
Detects execution of PowerShell scripts spawned by wscript.exe or cscript.exe that retrieve configuration data or file paths from process-specific environment variables, a technique observed in LausivLoader to evade command-line monitoring.
Detects execution of PowerShell scripts spawned by wscript.exe or cscript.exe that retrieve configuration data or file paths from process-specific environment variables, a technique observed in LausivLoader to evade command-line monitoring.
Page 186 of 1871

