Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects the anomalous behavior of a Node.js process acting as a typosquatting agent. The detection identifies a node.exe process initiating a network connection to a known malicious C2 IP and port, followed by the termination of that same process within 45 seconds. This pattern is consistent with the agent crashing due to an unhandled exception (e.g., os.userInfo() failure) after beaconing.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
Detects network activity associated with a malicious NPM package (typosquatting) beaconing to a known C2 server (69.48.229.140) and performing command and control operations, including command polling and data exfiltration, specifically from a Node.js environment.
This rule detects instances where mshta.exe acts as a parent process to initiate powershell.exe. It specifically looks for command line arguments that employ obfuscation techniques, such as character casing variations (e.g., 'POWERsHeLl'), while simultaneously excluding standard casing, combined with flags typical of non-interactive execution (e.g., -NonInteractive or /w h /c). This pattern is commonly used by adversaries to bypass security controls and execute scripts hidden from user view.
This rule detects suspicious activity involving macOS LaunchAgents and files within the 'Application Support/System' directory, often associated with persistence or malicious background execution. The detection looks for the creation or modification of specific plist files (e.g., com.apple.finder.agent.plist) or git-related files in Application Support, correlated with process execution of commands like 'sysnotif-repair', 'launchctl' manipulating agents, or git operations involving custom hooks paths.
This rule detects HTTP POST requests characteristic of the curlRAT malware used by DPRK-affiliated threat actors. The detection looks for a specific POST body format containing 'name=', '&value=', and '&type=' parameters, which indicates C2 communication patterns commonly associated with this specific backdoor.
Detects anomalous HTTP traffic directed to githubusercontent.com containing a custom, non-standard request header 'aohvcoehfg'. This pattern is associated with Kimsuky threat actor activity, specifically related to the 'GitPower' operation involving C2 communication via GitHub repositories.
The following analytic detects when all virtual machines on an ESXi host are abruptly terminated, which may indicate malicious activity such as a deliberate denial-of-service, ransomware staging, or an attempt to destroy critical workloads.
This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
Detects the modification or creation of the registry key '.mollis' within Software\Classes, which is used by the Star Blizzard (RedFlick) CPL downloader to store an encrypted AES key. This activity is performed by common Windows processes such as control.exe, rundll32.exe, or regsvr32.exe.
This rule detects potentially malicious activities involving the creation of suspicious scheduled tasks or the use of system binaries (rundll32.exe and control.exe) to execute commands, often associated with lateral movement or persistence. It looks for schtasks.exe commands creating tasks with specific deceptive names, and rundll32.exe or control.exe executing from remote network paths or suspicious command line arguments.
Detects phishing emails themed around Atlantic Council invitations that contain links attempting to lure users into installing iOS configuration profiles, often associated with malicious backdoors like DarkSword, attributed to the Star Blizzard (G1033) threat group.
Detects a specific multi-stage infection chain associated with Star Blizzard. The sequence begins with a command shell launched under conhost.exe executing SSH with PermitLocalCommand enabled, followed by the execution of a control panel (.cpl) file via control.exe within a two-hour window.
Detects credential-phishing attempts originating from Proton Mail addresses that result in a user clicking on a link. The rule correlates email delivery from known Proton Mail domains with subsequent URL click events to identify potential Adversary-in-the-Middle (AiTM) activity, often associated with the Star Blizzard (COLDRIVER) threat group.
Detects a multi-stage phishing pattern attributed to Star Blizzard (also known as Callisto Group or COLDRIVER). The attack involves an initial email containing no attachments to establish trust or initiate a thread, followed by a subsequent reply-thread email containing both an archive file (ZIP/RAR) and an image file. This technique is designed to bypass email security scanners by hiding the archive password within the image attachment or obscuring the malicious payload context.
Detects potential DNS tunneling or command-and-control (C2) traffic by identifying abnormally long DNS query names, which often indicate encoded data channels, and suspicious usage of TXT or NULL DNS records, which are frequently used by tools like Cobalt Strike, dnscat2, and iodine for C2 communication.
Detects successful RDP (Remote Desktop Protocol) logon events (Event ID 4624, Logon Type 10) where the source IP address is outside the predefined internal network ranges. This behavior is indicative of potential lateral movement, where an attacker attempts to access internal systems from an external, non-corporate source.

