Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
Detects the creation or renaming of files to a .aspx extension within specific web application directories (member file-upload). The rule specifically filters for file operations initiated by the IIS worker process (w3wp.exe) and requires a non-zero file size, identifying potential web shell deployment attempts.
This rule performs a point-in-time sweep for known Indicators of Compromise (IOCs) associated with the NeedyMantis threat actor group. The detection logic searches for specific file, process, and image-load SHA256 hashes, communication with a known C2 domain (tripswithengine.com), and the use of a hard-coded user-agent string (Firefox/21.0) across various telemetry sources within the last 30 days.
Detects the two Windows-networking-named DLLs the report confirms as sideloaded via the normal OS loader (WinSparkle.dll, libcurl.dll) plus vim64.dll (a filename Vim's real installer never produces at all). Path check now covers any location outside a small allowlist of known-legitimate vendor install folders, not just ProgramData, so it also catches the reported ProgramData\\USOShared, ProgramData\\VIM, and ProgramData\\TightVNC\\VIM placements. Known limitation: the one reported case where the malicious WinSparkle.dll sits at the exact canonical Program Files\\Poedit path cannot be distinguished by path alone -- that specific sideload is instead caught by the companion 'Extensionless Archive Paired with Same-Named DLL Drop' rule via the archive-pairing signal.
Detects the execution of discovery or credential access utilities (e.g., whoami, net, reg, ldapsearch) spawned by Java-based server processes like java.exe or tomcat.exe. This activity is often indicative of an attacker leveraging a vulnerable web application to perform reconnaissance or credential harvesting on the host system.
This rule monitors for indicators of compromise (IOCs) associated with known malware and C2 infrastructure, including specific IP:port combinations, malicious domains, URLs for file downloads, and SHA256 hashes of known malware. The rule correlates data across device network events, file events, and process execution events to identify potential infections or communication with malicious infrastructure.
Detects permanent WMI event subscriptions that are containing `CommandLineEventConsumer` or `ActiveScriptEventConsumer`. Due to their command execution capabilties, given WMI consumers are often leveraged by adversaries for both execution and persistence purposes.
This rule detects a sequence of suspicious activities involving files placed in 'ProgramData\Firefox'. It identifies the creation or modification of a non-standard executable within this folder, followed by its execution by a trusted process (or itself), and the subsequent creation of a Registry run key for persistence. This pattern is often used by adversaries for persistence mechanism implementation using masqueraded file names.
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
Sweeps DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over a rolling 30-day window for known RevStealer indicators: exact SHA-256 matches against all 13 published file hashes, and exact-host matches (via parsed URL host, not substring) against the confirmed C2 domain meta7.archscreen68.one. An empty, extensible IP list is included for when a malicious IP is published.
Detects unauthorized processes attempting to read or create sensitive browser credential files ('Login Data', 'Web Data', 'Cookies', 'logins.json', 'key4.db'). This activity is commonly associated with information-stealing malware (such as Lumma, StealC, Vidar, RedLine, and Amadey) that targets browser databases to extract stored secrets, often bypassing standard browser process access.
This rule detects potential browser-based credential and session theft by monitoring for a process that accesses multiple sensitive web browser artifacts (cookies, local state, session storage) across several user profiles in a short timeframe. It correlates this activity with the subsequent creation of a compressed archive in a temporary directory followed by an outbound network connection, indicating a multi-stage exfiltration workflow.
Detects a suspicious pattern where a user authenticates to a remote access portal (like Citrix or VPN) without multi-factor authentication (MFA) or with an existing risk flag, followed by a surge in file activity (creation, modification, or renaming of >500 files or >200 distinct files) on the same account within a 24-hour window, potentially indicating compromised credential usage for staging data for exfiltration or ransomware.
Detects a potential post-compromise lateral movement sequence where a host, previously identified as accessing sensitive browser credential files by an unauthorized process, subsequently initiates RDP or WinRM connections to other internal hosts using an account not previously observed performing interactive logons on that source host.
Detects unauthorized access or modification attempts to common web browser credential storage files (such as 'Login Data' or 'key4.db') by processes other than standard, trusted web browsers (e.g., Chrome, Edge, Firefox). This behavior is indicative of credential harvesting, where an adversary attempts to steal saved login information from browser data stores.
Detects instances where a user account associated with a detected infostealer malware infection (e.g., Redline, Raccoon, Vidar) successfully authenticates to a cloud service from a suspicious network location, such as a VPN, residential proxy, or Tor exit node, within 24 hours of the infection alert.
Detects access to sensitive browser credential and cookie files by processes that are not recognized web browsers or their designated update components. This behavior is highly indicative of credential theft activity where an adversary is attempting to extract stored credentials or session cookies from local browser storage.
Detects instances where the Windows Terminal application (or related processes like OpenConsole) spawns suspicious command-line utilities such as PowerShell, CMD, curl, or certutil with indicators of potential download activity or command-line obfuscation. This pattern is often indicative of interactive adversary activity attempting to stage tools or execute payloads.
Detects execution of common script interpreters (mshta, powershell, cmd, wscript) from typical UI-based process launch sources (explorer, RunDlg) when the command line includes indicators of malicious activity such as hidden window flags, obfuscated content, or remote URL downloads. This pattern is characteristic of ClickFix-style social engineering attacks where users are tricked into copying and executing malicious commands.
Detects unauthorized access by a non-browser process to Chromium-based 'Cookies' SQLite database files, which are used by browsers like Chrome, Edge, and Brave. This behavior is a strong indicator of credential theft or session hijacking, as attackers target these files to extract session cookies and bypass MFA for cloud services.
This rule detects the suspicious archival of browser credential files (e.g., Login Data, Cookies, wallet.dat) or the transmission of data to common command-and-control (C2) services such as Telegram, Discord, or raw IP addresses using common system tools like PowerShell, curl, or certutil.
Page 19 of 1866


