Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of PowerShell to perform a web request to google.com to download a file named Document.pdf, followed by the immediate execution of that downloaded file using Start-Process.
Detects host reconnaissance activity performed by PureLog Stealer, characterized by the execution of system administration tools (e.g., wmic, reg, systeminfo) spawned as child processes from .NET LOLBins (e.g., msbuild, installutil, regsvcs). This behavior indicates an adversary performing discovery of system configuration and environment details.
This rule detects the manual instantiation of PowerShell ScriptBlock objects via the '::Create' method. This technique is commonly used by malicious PowerShell scripts and offensive security tools to bypass traditional command-line logging by executing code dynamically in memory, often avoiding disk-based signatures.
Detects post-infection data harvesting behavior associated with PureLogs Stealer. The rule monitors specific LOLBins (.NET binaries) and suspected masqueraded payloads (e.g., syscall.exe) as they attempt to access browser credential, cookie, or web data files from Google Chrome, Microsoft Edge, and Mozilla Firefox. It also tracks the creation of these suspicious processes when invoked by scripting interpreters like PowerShell, wscript, or cscript.
Detects Vidar Infostealer variants by identifying its unique per-build polymorphic virtual machine bytecode interpreter and custom ARX stream cipher. The rule uses a combination of high file entropy, lack of standard OS cryptographic API imports, and the presence of structurally invariant indirect jump-table dispatch patterns used in custom VM execution loops.
Detects a single host or account interacting with a high volume of archive (PST/OST) and document files, or initiating mailbox exports within a short window, which is often indicative of mass data staging and collection prior to exfiltration.
IOC hunt for the HEAVYGRAM/CRUDEEXCLUDE campaign: matches known SHA256 file hashes (first-stage malware, implant, RAR/ZIP artefacts) via DeviceFileEvents and DeviceProcessEvents, plus known-malicious domains/staging infrastructure by parsed hostname across network connections, process command lines, and file origin URLs.
Detects Microsoft Exchange Control Panel (ECP) worker process (w3wp.exe) spawning suspicious child processes (e.g., cmd.exe, powershell.exe, mshta.exe) that are commonly associated with the exploitation of CVE-2020-0688. This vulnerability involves unsafe deserialization within the Exchange ECP ViewState handling, which allows an attacker to execute arbitrary code with SYSTEM privileges.
This rule detects known JavaScript payloads associated with the JWR phishing framework by matching their SHA-256 file hashes. This is a signature-based detection for malicious script files commonly used in phishing attacks.
Detects potential credential reuse attacks such as Pass-the-Hash, Pass-the-Ticket, or Overpass-the-Hash. The rule identifies a 'NewCredentials' logon (e.g., runas /netonly) followed by a network or remote interactive logon to a target system (such as a domain controller) by the same user, without an interactive logon session occurring between the events, which is indicative of using stolen credentials to move laterally.
Detects a suspicious sequence of user activity where a device visits a social media platform (Twitter/X) followed shortly by navigation to a Google Doc. This pattern is often consistent with phishing lures where victims are enticed via direct messages or social engineering to open a malicious document hosted on Google Docs.
Detects a suspicious pattern where a user browser visits a Google Document and subsequently initiates a connection to the Telegram Bot API within a short timeframe (10 minutes). This sequence is indicative of malicious Google Apps Scripts embedded in documents attempting to exfiltrate victim information (IP, geolocation, device details) as part of a reconnaissance phase before a ClickFix-style payload delivery.
Detects suspicious processes accessing cryptocurrency wallet data files or browser extension settings, characteristic of infostealer malware such as AMOS or GhostCode. The rule excludes common browser processes and legitimate wallet applications to identify unauthorized attempts to harvest wallet credentials, private keys, or seed phrases.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
C2 Ioc Detection
YARA-L
Detects Network, File, or Process events associated with known C2 IOCs
C2 Ioc Detection
YARA-L
Detects Network, File, or Process events associated with known C2 IOCs
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Page 190 of 1871

