Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of the wevtutil.exe utility to clear multiple Windows event logs simultaneously. This is a common defense evasion technique used by attackers to hide malicious activity by deleting security, system, application, or setup event logs.
Detects the use of legitimate data transfer utilities (s5cmd, rclone) configured to exfiltrate sensitive document types (.doc, .pdf, .sql, etc.) to S3-compatible cloud storage. The rule correlates this activity with recent access to files containing sensitive credentials or configuration data, a pattern observed in double-extortion campaigns.
Detects the use of legitimate data transfer utilities (s5cmd, rclone) configured to exfiltrate sensitive document types (.doc, .pdf, .sql, etc.) to S3-compatible cloud storage. The rule correlates this activity with recent access to files containing sensitive credentials or configuration data, a pattern observed in double-extortion campaigns.
This rule detects the execution of known lateral movement tools, including Impacket suite components and NetExec (formerly CrackMapExec), by monitoring process command lines. It specifically flags tools such as psexec.py, wmiexec.py, and secretsdump.py, which are frequently used for remote execution and credential dumping. The rule also joins these process events with network events targeting SMB port 445 to correlate tool usage with potential lateral movement activity.
This rule detects the execution of known lateral movement tools, including Impacket suite components and NetExec (formerly CrackMapExec), by monitoring process command lines. It specifically flags tools such as psexec.py, wmiexec.py, and secretsdump.py, which are frequently used for remote execution and credential dumping. The rule also joins these process events with network events targeting SMB port 445 to correlate tool usage with potential lateral movement activity.
Detects batch scripts that execute renamed Mimikatz-style binaries (e.g., g.com, hs.com) for credential dumping purposes. The rule looks for the combination of command-line arguments to redirect output to text files, the subsequent deletion of the renamed binaries and associated artifacts (mimidrv.sys, temp files), and the execution of 'gpupdate /force', which is a common technique used to trigger or finalize credential dumping operations.
Detects PE files masquerading as PuTTY executables that match the specific file size characteristics associated with the Exvicy Malware-as-a-Service (MaaS) distribution model. The rule identifies suspicious executables by looking for PuTTY-related strings in files that are either unsigned or exhibit high entropy, suggesting potential packing or malicious modification.
Detects the use of legitimate data transfer utilities (s5cmd, rclone) configured to exfiltrate sensitive document types (.doc, .pdf, .sql, etc.) to S3-compatible cloud storage. The rule correlates this activity with recent access to files containing sensitive credentials or configuration data, a pattern observed in double-extortion campaigns.
Detects attempts to disable or tamper with Microsoft Windows Defender via registry modifications or malicious PowerShell/reg.exe commands, specifically targeting security settings like DisableAntiSpyware, DisableRealtimeMonitoring, and exclusion paths.
This rule detects the execution of known lateral movement tools, including Impacket suite components and NetExec (formerly CrackMapExec), by monitoring process command lines. It specifically flags tools such as psexec.py, wmiexec.py, and secretsdump.py, which are frequently used for remote execution and credential dumping. The rule also joins these process events with network events targeting SMB port 445 to correlate tool usage with potential lateral movement activity.
Detects the establishment of a memory-resident webshell following the exploitation of SharePoint (e.g., ToolPane/EditingPageParser SafeControls bypass or XamlServices/LosFormatter deserialization). The rule identifies instances where w3wp.exe loads specific XAML/WPF assemblies used in known gadget chains and subsequently spawns child processes without any corresponding file creation activity on disk.
This rule detects suspicious outbound network connections originating from processes frequently abused in the Exvicy/ErrTraffic ClickFix malware delivery chain, specifically powershell.exe, msiexec.exe, and putty.exe. It also monitors for direct communication to known C2 IP addresses associated with the Exvicy threat actor, providing coverage for both the initial payload delivery and post-compromise C2 phases.
This rule detects malicious PowerShell execution originating from common Office or script-based parent processes (explorer.exe, mshta.exe, wscript.exe). The detection specifically looks for hidden command-line flags combined with indicators related to the Konni/VelvetCake campaign, such as specific artifact filenames (update1.vbs, update2.ps1) or remote downloads from raw.githubusercontent.com.
Detects the creation of a scheduled task named 'OneDriveUpdateScheduler' and the subsequent execution of 'update1.ps1' or 'update2.ps1' by 'explorer.exe'. This behavior is associated with the Konni/VelvetCake malware families, which use this technique to maintain persistence and C2 connectivity.
Detects execution of PowerShell commands initiated by LNK files, characteristic of Konni/VelvetCake spear-phishing campaigns. The rule monitors for PowerShell processes launched by shell applications (explorer, rundll32, etc.) using hidden windows and fetching specific malware-related filenames or downloading from AppData directories.
Detects second-stage reconnaissance patterns indicative of the VelvetCake framework. The rule identifies PowerShell execution that combines multiple discovery commands (system information, network configuration, process listing, file system inspection, and antivirus/security software enumeration) within a single execution sequence or related process events.
Detects the execution of obfuscated PowerShell commands (using -EncodedCommand, -WindowStyle Hidden, and -NonInteractive or -NoProfile flags) spawned by a process located within an Electron application's AppData directory. This pattern is commonly associated with malicious scripts or post-exploitation activities launched by Electron-based applications, excluding the Windows shell (explorer.exe).
Detects instances where Chrome or Microsoft Edge processes are spawned from suspicious AppData subdirectories that do not match standard installation paths. This behavior is indicative of credential theft malware, such as RevStealer, which launches browser processes as debugged child processes from unique working directories to recover App-Bound encryption keys.
Detects unauthorized processes reading sensitive Chromium-based browser files (e.g., Cookies, Login Data) immediately following the termination of a browser process. This behavior is indicative of credential harvesting malware, such as RevStealer, which terminates the browser to release file locks before exfiltrating the databases.
Detects a single process accessing files across three or more distinct cryptocurrency wallet application directories within a one-hour window. This behavior is highly anomalous for legitimate applications and is characteristic of information-stealing malware, such as RevStealer, which targets stored credentials and wallet files.
Detects behavior consistent with the RevStealer malware, specifically focusing on cross-process operations against web browsers originating from hidden AppData subdirectories and the creation of its unique single-instance mutex.
Page 203 of 1871

