Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potential multi-stage desktop takeover attacks by monitoring sequences of process execution within a 5-minute window. It looks for initial shell (explorer.exe or cmd.exe) spawning script-based tools (mshta.exe, wscript.exe, cscript.exe, powershell.exe, cmd.exe) with suspicious command-line arguments (extensions like .lnk, .url, .hta, or PowerShell-specific artifacts like 'IEX', 'DownloadString', or '-enc'). This is immediately followed by a secondary stage where PowerShell, cmd, or rundll32 are used to load external DLLs, register modules via regsvr32, or interact with AppData/Local/Temp directories, indicative of payload staging and execution.
This rule detects potential adversary activity aimed at disabling security tools, critical infrastructure services, or cloud synchronization agents. It monitors for a high volume (6 or more) of process termination commands (e.g., taskkill, net stop) or registry-based service disabling (Start value 4) targeting a predefined list of security and critical system services within a 3-minute window, which is indicative of an attempt to blind security monitoring or disrupt system availability.
This rule detects mass disabling of Windows Event Log channels by monitoring registry value modifications where multiple 'Enabled' values are set to '0' within a short timeframe. This behavior is indicative of anti-forensics activity where an adversary attempts to suppress specific log sources to evade detection.
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
Detects a security-software presence check (360 Total Security/eScan process names) followed within 10 minutes by a persistence-establishing event from the same parent process.
Detects registration/activity of the msagent.sys filesystem minifilter driver used to deny access to and hide CoolClient-protected files and directories.
Detects DLL sideloading where a renamed Sangfor executable (defender.exe/Sang.exe) loads libngs.dll/libsrapc.dll outside the legitimate install path or with a signer mismatch.
Detects modification of the CoolClient rootkit's stealth-configuration registry value (Wid_H1deF5Dirs) under the \SYSTEM\RNG hive.
Detects CoolClient's elevated self-relaunch using the 'passuac' command-line parameter combined with RPC-based process creation and PPID spoofing to bypass UAC.
Detects creation of the 'goopdate' Run-key value pointing to Sang.exe/defender.exe with the 'work' argument and a %programdata% path, used by CoolClient for persistence.
Correlates at least 3 of 4 distinct Abyssos background polling threads (clipboard, process list, network connections, screen capture) launched by the same unsigned/unknown-signature parent process within the same 5-minute window.
Detects the DOUBLECUP/ClickFix loader activity which involves a sequence of suspicious command-line execution patterns. The rule correlates three specific behaviors occurring within a 5-minute window: finding PowerShell paths using 'where', searching for the 'ZZ1984' marker using 'findstr', and executing a minimized background command process. This combination is highly indicative of the ClickFix delivery chain used to trick users into running malicious commands.
Detects the Abyssos UAC_BYPASS_FODHELPER technique: a ms-settings\Shell\Open\command registry value set immediately before fodhelper.exe launches an unsigned child payload, silently elevating to a high-integrity process without a UAC prompt.
Detects a WinRAR-extracted OnyxC2 loader spawning an identical self-copy child process from a temp/download path, marking the transition from loader stage to active stealer logic.
Detects creation of the ONYXC2 mutex used by the malware to enforce single-instance execution.
Detects extraction and execution of OnyxC2 lure archives (Setup_File*.zip, Fling-Standalone*.zip) via WinRAR/7-Zip from a Downloads/Temp directory, correlating the archive-open with the lure-named installer executing shortly after.
Matches endpoint file/process hashes and network IPs against a curated, freshness-checked OnyxC2 indicator feed.
Detects creation of a non-default hidden desktop by a browser process, correlated with either an inherited long-lived authenticated browser network session or a non-standard parent process, consistent with OnyxC2's HVNC capability.
Detects a multi-hop HTTP redirect chain traversing two or more known OnyxC2 phishing lure domains from the same host within a two-minute window, consistent with the redirect obfuscation used before final payload delivery.
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
This rule detects potential privilege escalation through the abuse of a debug backdoor in the Wacom WTabletServiceISD service. It identifies when the 'PowerT' registry value is set for the service, followed shortly by the service spawning a command shell (cmd.exe or powershell.exe) under SYSTEM privileges. It specifically excludes scenarios where AutoAdminLogon is enabled, which might otherwise trigger false positives.
Page 476 of 1866

