Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects access to sensitive browser credential storage files (Login Data, key4.db, logins.json) by unauthorized processes. This behavior is indicative of credential theft, where an adversary attempts to extract stored passwords from browser profiles.
Detects instances where the Firefox browser process executes from a path containing 'ProgramData' and creates a new file within the 'ProgramData' directory. This behavior is highly suspicious as legitimate Firefox installations reside in 'Program Files' or 'Program Files (x86)', and 'ProgramData' is often abused by malware for persistent storage or staging.
Detects instances where PowerShell is executed with a command line string containing 'Google Chrome Update' and initiates a network connection. This behavior is indicative of a malicious process masquerading as a legitimate browser update mechanism to hide network activity.
Detects the loading of .NET Common Language Runtime (clr.dll) and System.Management.Automation.dll into a process that is not a recognized PowerShell binary (e.g., powershell.exe, pwsh.exe). This behavior is associated with the 'PSInline' technique used by SloppyRAT, where PowerShell capabilities are invoked directly via COM objects to execute commands in memory. The rule further correlates this activity with the creation of files with a .png extension in temporary directories, which is consistent with the exfiltration staging behavior of the malware.
Detects the creation of scheduled tasks that masquerade as a 'Google Chrome Update' task but are initiated by suspicious processes like cmd.exe, powershell.exe, or schtasks.exe, and do not originate from the legitimate Google Chrome installation directories.
This rule detects potential PowerShell script execution without spawning the standard powershell.exe process. It monitors for the loading of clr.dll and System.Management.Automation.dll into any process other than powershell.exe, which is a technique used by some malware families like SloppyRAT to execute PowerShell code directly within a compromised process memory space.
Detects the creation of a file on the system that matches a known malicious SHA256 hash.
This rule detects the creation, modification, or renaming of files that contain sensitive keywords (e.g., 'password', 'seed', 'wallet', 'recovery') by processes other than standard system or productivity applications. This activity is indicative of credential or sensitive data harvesting.
Detects instances where a process that is not a known PowerShell host (powershell.exe, pwsh.exe, powershell_ise.exe) loads the System.Management.Automation.dll assembly, which is a strong indicator of an attempt to execute PowerShell code within a different process to evade detection.
Detects processes running from user-writable locations (Temp/AppData/Public/Downloads) creating a self-referential Windows Firewall allow rule via netsh, consistent with NJRAT establishing outbound C2 connectivity while evading network-based blocking.
This rule monitors process creation events for common command-line obfuscation patterns used to evade detection. It flags suspicious usage of encoding (e.g., base64), character manipulation (e.g., caret char insertion, case randomization), and scripting-related concatenation or dynamic reassembly techniques within cmd, powershell, or script host commands.
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
Detects the loading of the 'WbElevation.dll' module associated with SectopRAT, followed by suspicious access to browser, email, or cryptocurrency wallet credential stores within a 10-minute window on the same device.
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
Page 198 of 1871


