Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
This rule monitors for outbound network connections to a list of known malicious IP addresses identified as part of the GhostCode command-and-control (C2) infrastructure. It uses DeviceNetworkEvents data to flag activity originating from endpoints and highlights a specific IP address used during the Intune/MDM enrollment process for further investigation.
This rule detects internal network activity (DNS queries, network connections, and security logs) communicating with domains associated with the GhostCode phishing kit. These domains are typically used to host credential harvesting pages or phishing infrastructure.
Detects Python processes (python.exe, python3.exe, pythonw.exe) performing DNS resolution for Microsoft identity, device login, or Graph API endpoints. This activity is consistent with automated tooling, such as python-requests, performing device-code flow polling or API token authentication within an environment.
This rule detects the creation or modification of Windows Registry Run keys, which are a common technique used for achieving persistence. The rule specifically monitors for known suspicious or potentially malicious file names (e.g., RuntimeSSH.exe, MicDriver.exe, winappx.exe, MsCache.exe, smqdservice.exe) being added to Run locations, which triggers automatic execution upon user logon.
Detects modifications to HKEY_CURRENT_USER Run keys associated with the HEAVYGRAM backdoor, which uses specific filenames and patterns to establish persistence via autorun registry entries.
This rule detects potentially malicious in-memory activity within the 'GRrte.exe' process, specifically targeting behaviors associated with PlugX malware. It monitors for suspicious memory protection changes (e.g., requests for Read-Write-Execute permissions) and the loading of the 'ws2_32.dll' library, which is commonly used to facilitate network communication in side-loaded payloads.
Detects high-volume file/directory enumeration behavior by the PlugX side-loaded process GRrte.exe, consistent with PlugX's use of FindFirstFileW/FindNextFileW/FindFirstFileExW for file and directory discovery (T1083).
This rule detects persistence mechanisms involving the 'JartePortable' application by monitoring Registry Run keys. It flags when a Registry key is created or modified to include a startup entry for 'Jarte.exe' located in 'C:\Users\Public\JartePortable\'. The detection specifically looks for a suspicious registry value data pattern.
Detects browser extension manifest.json files requesting declarativeNetRequest and content_scripts/host_permissions covering AI assistant vendor domains (BragJack attack class)
This rule detects the opening of a specific PDF file named 'OIC_Invitation_General_Official.pdf' by Adobe Acrobat. The detection logic triggers either when Acrobat processes this file or when the file itself is identified on the system. This pattern has been associated with the delivery of the PlugX remote access tool, often used in targeted spearphishing campaigns.
Detects the execution of taskkill.exe to forcibly terminate the iediagcmd.exe diagnostic process, initiated by the process GRrte.exe. This behavior is indicative of an attempt to impair security or diagnostic tools on the endpoint.
This rule detects the execution of a malicious PowerShell command chain initiated by explorer.exe, consistent with the PlugX malware infection sequence. The detection monitors for specific command-line arguments, including the use of curl for file downloads, tar for extraction, and the launching of associated malicious executables like 'GRrte.exe' following the execution of a shortcut file named 'OIC_Invitation_General_Official.lnk'.
Detects Microsoft Exchange Control Panel (ECP) worker process (w3wp.exe) spawning suspicious child processes (e.g., cmd.exe, powershell.exe, mshta.exe) that are commonly associated with the exploitation of CVE-2020-0688. This vulnerability involves unsafe deserialization within the Exchange ECP ViewState handling, which allows an attacker to execute arbitrary code with SYSTEM privileges.
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
Detects suspicious post-exploitation activities, including service creation, local account modification, or security tool tampering, executed as SYSTEM shortly after activity associated with the ADSelfService Plus GINA logon-screen vulnerability (CVE-2026-74849).
This rule monitors for outbound network connections to domains and IP addresses associated with known phishing, loader, and C2 infrastructure, including specific ClickFix patterns.
Detects the execution of suspicious binaries from the user's AppData Local Temp directory, often associated with AutoIt scripting or similar automation tools that utilize configuration (.ini) files to drive malicious activity.
Detects the execution of suspicious binaries from the user's AppData Local Temp directory, often associated with AutoIt scripting or similar automation tools that utilize configuration (.ini) files to drive malicious activity.
Page 188 of 1871



