Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects instances where PowerShell is launched with hidden window arguments by explorer.exe or mshta.exe, and the command line indicates interactions with specific file extensions (.vbs, .ps1) located within the AppData directory. This pattern is often indicative of malicious script execution, such as those used in Konni malware campaigns to drop and execute payloads.
Detects the execution of LNK files that use a double extension (e.g., .pdf.lnk) to masquerade as PDF documents. This behavior is indicative of spear-phishing campaigns where malicious shortcuts are delivered via ZIP archives to execute hidden PowerShell commands for secondary stage downloader or persistence mechanisms.
Detects the exploitation of WinRAR CVE-2023-38831, where a maliciously crafted archive triggers WinRAR to execute a secondary payload (such as a script, LNK, or binary) from its temporary extraction directories (Rar$EXa, Rar$DIa, Rar$SR). This behavior is characteristic of adversaries using WinRAR as an initial access vector to bypass security controls.
Detects the execution of VelvetCake modular scripts by PowerShell, which involves downloading and executing scripts from %TEMP% via Invoke-Expression, and monitoring the C:\Users\Public directory for file staging and subsequent exfiltration. This rule captures the tactical loop of script execution, output file creation, and exfiltration preparation often observed in Operation Conflict Compass activity.
Detects malicious PowerShell scripts that perform a sequence of reconnaissance activities, including security product enumeration via WMI (SecurityCenter2), system configuration discovery (ipconfig, systeminfo), process enumeration, recent file access, and drive mapping. This behavior is indicative of second-stage reconnaissance by threat actors to map the target environment.
Detects execution of PowerShell commands indicative of the VelvetCake variant of the Konni malware. The rule identifies the use of 'Net.WebClient.DownloadString' combined with 'Invoke-Expression' (iex) to execute scripts in memory, alongside specific command-line indicators such as the 'Areyou=cake' campaign marker or associated C2 domains.
Detects instances where dllhost.exe (COM Surrogate) running under high-integrity accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) loads an unsigned DLL file located in the C:\ProgramData\ directory. This pattern is commonly associated with DLL side-loading or malicious library injection to maintain persistence or escalate privileges.
This rule detects suspicious PowerShell activity involving the enumeration and manipulation of COM objects and .NET assemblies, patterns often associated with reconnaissance or post-exploitation activities. It flags instances where PowerShell scripts utilize specific command-line arguments (e.g., Get-ComDatabase, Get-ComClass, Import-Win32Module, NtObjectManager) in conjunction, suggesting automated discovery of COM infrastructure or assembly loading.
Detects the use of OleViewDotNet or NtObjectManager PowerShell tools to enumerate running COM host processes (e.g., dllhost.exe) and check for the absence of specific security mitigations like EOAC_NO_CUSTOM_MARSHAL or COMGLB_UNMARSHALING_POLICY_STRONG. This behavior is indicative of reconnaissance activity aimed at identifying targets for fake-marshaled CoGetInstanceFromIStorage exploit chains.
Detects a SYSTEM-level dllhost.exe process, associated with specific COM object instantiation (CLSID {135fd325-45b7-4c30-89f8-4386961669f0}), loading a DLL from the C:\ProgramData\ directory. This behavior is indicative of an attacker-planted DLL being unmarshaled through a crafted OBJREF, effectively bypassing security controls like EOAC_NO_CUSTOM_MARSHAL.
Detects the presence of a specific Russian-language error string ("Не удалось сгенерировать HWID") within binary files, which is characteristic of the HWID generation mechanism used by Vidar Stealer malware.
Detects Vidar Infostealer variants by identifying its unique per-build polymorphic virtual machine bytecode interpreter and custom ARX stream cipher. The rule uses a combination of high file entropy, lack of standard OS cryptographic API imports, and the presence of structurally invariant indirect jump-table dispatch patterns used in custom VM execution loops.
Detects unauthenticated access attempts or requests originating from system/service accounts targeting the PaperCut NG/MF administrative interface, which may indicate exploitation of authentication bypass vulnerabilities (e.g., CVE-2026-81578).
Detects instances where the PaperCut application server process (pc-app.exe) or its underlying Java processes (javaw.exe or java.exe) spawn command-line interpreters such as cmd.exe or powershell.exe. This behavior is indicative of potential post-exploitation activity, specifically Remote Code Execution (RCE) via vulnerabilities targeting PaperCut servers.
Detects the Microsoft Edge browser executable running from an anomalous path (C:\ProgramData\Microsoft\Windows\Telemetry\) or exhibiting suspicious network behavior (to a known malicious domain 'deadhub.org' or IP address '193.23.118.155'). This behavior is indicative of a masquerading attempt to hide malicious activity by mimicking a trusted browser binary.
Detects instances where PowerShell is executed by a process masquerading as a common application (e.g., Telegram, WhatsApp, KeePass) to write a registry run key for persistence. This behavior is indicative of malicious installers or secondary stage delivery.
This rule detects potentially malicious activity where a Python-based process or a PyInstaller-compiled executable invokes a command shell (cmd.exe, powershell.exe) or command execution via 'os.popen', followed by a network connection to 'api.telegram.org' within a 60-second window. This behavior is often characteristic of malware or tools using Telegram's API as a command-and-control (C2) channel or for data exfiltration.
This rule detects the invocation of the undocumented ntdll.dll function 'EtwpCreateEtwThread'. This API call can be abused by adversaries as an alternative to standard thread creation APIs (like CreateThread) to execute shellcode or malicious code in a suspicious process context, often as part of process injection techniques.
Detects sophisticated shellcode execution patterns characteristic of MovieReaper, specifically monitoring for the combination of RWX memory protection allocation, manipulation of Vectored Exception Handlers (VEH), and usage of manual syscall stubs (NtProtectVirtualMemory) to bypass EDR user-mode API hooking.
Detects execution of potential MovieReaper loader components by monitoring for the creation of a specific, statically defined global mutex or patterns indicative of dynamic mutex naming conventions often used to ensure single-instance execution by malware.
Detects the use of PowerShell with the EncodedCommand parameter to modify or create entries in the HKEY_CURRENT_USER Run registry keys, a technique used by the HEAVYGRAM malware for persistence.
Page 204 of 1871
