Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
Detects the execution of known credential harvesting tools such as Mimikatz, LaZagne, and pypykatz, or the use of their specific command-line arguments. The rule includes exclusions for common security software processes and authorized testing paths.
Page 199 of 1871
