Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the presence of PIVOTPIPE .NET loader components within files by searching for specific magic bytes, debug strings, hardcoded developer file paths, and agent-related operational strings.
Detects the GHAPPIER four-stage loader execution chain initiated during npm postinstall processes. This rule monitors for malicious child process spawning (cmd, powershell, curl, wget) by node or npm, as well as the presence of specific markers like the '.git-checker' string or URLs associated with the PolinRider/FAMOUS CHOLLIMA npm supply chain campaign.
Detects the GHAPPIER four-stage malware loader, specifically targeting npm-based JavaScript files. The rule identifies malicious activity through specific artifacts including hardcoded C2 URLs (vercel.app domains), campaign markers, file paths, and eval-based execution patterns.
Detects the deletion of 'loader.js' from the '%APPDATA%\VSCODE\' directory. This activity is consistent with the initial execution phase of GHAPPIER RAT, where the implant removes its dropper file to avoid detection and hinder forensic analysis.
Detects instances where rundll32.exe is used to execute a DLL file directly from a remote WebDAV-mounted network path (indicated by the 'DavWWWRoot' string). This technique allows for the execution of arbitrary code without writing the malicious payload to the local disk, a common tactic seen in fileless malware delivery and campaigns like ClearFake.
This rule detects the presence of ZigCryptoStealer malware deployed via a NativeAOT-compiled Windows executable. The detection relies on identifying specific hardcoded infrastructure strings, such as a BNB Smart Chain RPC endpoint and a specific contract address used to resolve C2 domains. It also looks for common sideloading hosts associated with the malware's delivery.
Detects internal SMB traffic indicative of P2P beaconing using the IPC$ named pipe, which is often a sign of lateral movement or command-and-control communication between compromised hosts.
Detects unauthorized attempts to modify or patch the AmsiScanBuffer function within amsi.dll in a remote process. This behavior is indicative of an AMSI bypass attempt, a technique often used by malicious loaders and fileless malware to evade security product scanning.
Detects the PIVOTPIPE .NET loader's AMSI-bypass routine by monitoring for the suspicious concurrent loading of amsi.dll and .NET runtime modules (clr.dll, mscoree.dll, or coreclr.dll) within the same process. This behavior is indicative of an attempt to hook into the AMSI interface to disable security scanning before executing malicious payloads.
Detects the execution of rundll32.exe from a WebDAV network path ('@\DavWWWRoot\') where specific suspicious substrings (e.g., 'verification.google', 'pf.ch', 'moor', 'CfgInspectModuleData') are present in the command line. This pattern is commonly associated with the execution of remote payloads or malicious DLLs to bypass security controls.
Detects processes attempting to interact with the Anti-Malware Scan Interface (AMSI) via loading amsi.dll, calling functions such as AmsiScanBuffer or AmsiOpenSession, or modifying related registry keys. This behavior is highly indicative of attempts to disable or bypass AMSI protection, a common step in executing malicious scripts or payloads on Windows systems.
This rule detects potentially malicious modifications to package.json files in npm projects or suspicious npm registry telemetry. It flags manifest files containing common obfuscation markers or excessive/unusual dependencies often associated with supply chain attacks, such as crypto, child_process, and common third-party packages frequently used in malicious npm activity.
This rule detects command line patterns associated with common Impacket tools (wmiexec, psexec, smbexec) executed via Windows processes (cmd.exe, powershell.exe) or via network connections to ports 445 and 135 initiated by Python processes. These tools are frequently used by adversaries for lateral movement, remote service execution, and command execution on compromised systems.
Detects evidence of the PIVOTPIPE .NET loader attempting to disable AMSI scanning. The detection focuses on activity related to patching the 'AmsiScanBuffer' function within 'amsi.dll', specifically identifying the use of the hex signature '80070057' or direct references to the function name, which is an indicator of an AMSI bypass attempt performed to facilitate malicious code execution.
Detects the PIVOTPIPE loader extracting a 'sleepmask.o' Common Object File Format (COFF) file into a temporary directory prefixed with 'nb_'. This behavior is associated with the deployment of post-exploitation sleepmask functionality designed to obfuscate or encrypt beacon memory footprints to evade memory scanners.
Detects the execution of PowerShell commands intended to gather system information, such as OS details, boot time, or video controller configurations. These techniques are often used during the discovery phase to profile a target machine before further malicious actions.
Detects instances where a process attempts to delete its own executable file on disk. This behavior is often associated with malware or adversary tools attempting to remove their footprint post-execution or as part of a cleanup routine.
Detects instances where a Node.js process spawns another Node.js process as a child. This behavior is often associated with malicious npm packages attempting to evade detection during runtime execution or executing secondary malicious payloads.
Detects the deletion of specific files associated with the indexed-btree malware loader, such as 'sharedLoad.min.js' or files within an 'extended/' directory. This behavior indicates potential anti-forensic cleanup following malicious code execution.
Detects persistence attempts using Component Object Model (COM) hijacking by modifying HKCU CLSID InProcServer32 registry keys. The rule specifically identifies instances where the registry value points to a DLL file located within the user's AppData or LocalAppData directories, excluding typical system or program directories, as seen in sideloading persistence chains.
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
Page 193 of 1871

