Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential malicious activity by monitoring for known indicators of compromise, including specific SHA256 file hashes, a known malicious IP address, and URLs associated with identified threats. The detection spans file creation/execution, network connections, and URL visits to block or alert on interactions with suspicious infrastructure.
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
This rule monitors for indicators of compromise (IOCs) associated with Operation SideCopy, including specific file hashes, known command-and-control (C2) IP addresses, malicious domains, and URLs. It triggers on file creation, process execution, and network connections matching these known indicators.
Detects the creation of a Windows service named 'ProcAuditManager', which is associated with the SparroWocky threat. The rule flags the service creation event (Event ID 7045) and identifies if the service description matches the known malicious signature, which attempts to masquerade as a legitimate auditing tool.
Detects incoming HTTP requests to Microsoft Exchange servers that match patterns indicative of exploitation attempts for the ProxyLogon SSRF vulnerability (CVE-2021-26855). This includes detecting specific manipulation of the Autodiscover service and the injection of X-BEResource or X-AnonResource-Backend headers, which were commonly used during the initial access phase of this campaign.
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
Detects mshta.exe spawning suspicious child processes (cmd.exe, powershell.exe, or reg.exe) that are characteristic of the ReverseRAT backdoor. The rule identifies common discovery commands or persistence attempts via Registry Run keys triggered from mshta.exe.
Detects the execution of wmic.exe, powershell.exe, or pwsh.exe with command-line arguments related to querying antivirus products or security centers (e.g., AntiVirusProduct, SecurityCenter2). The rule focuses on executions originating from non-standard system paths (e.g., Temp, Users, AppData) or processes that lack a valid code signing signature, which is often indicative of reconnaissance by malicious actors.
Detects the execution of mshta.exe by explorer.exe with command line arguments containing script protocols (javascript:, vbscript:) or remote URLs. This is a common technique used by attackers to execute malicious HTA files or inline scripts, bypassing security controls.
Detects potential ClickFix-style social engineering attacks where a victim is prompted to execute an encoded PowerShell command (often via copy-paste into a terminal). The rule specifically monitors PowerShell processes initiated by shell environments (explorer.exe, cmd.exe, or WindowsTerminal.exe) that execute encoded, hidden scripts to perform multiple suspicious network requests for files (e.g., .zip, .enc, .bin) from non-standard domains.
Detects network and DNS activity associated with the SideCopy threat group, specifically monitoring for connections to known C2 domains, C2 IP addresses, or the usage of port 5863 typically associated with the ReverseRAT backdoor.
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
Detects execution chains associated with the SideCopy threat group's ReverseRAT payload. The detection looks for mshta.exe being spawned by common shell processes (explorer, wscript, cmd, powershell) to execute remote HTA content or access 'docsportal.in'. It also monitors for subsequent reflective DLL loading via rundll32.exe or regsvr32.exe, which is indicative of the final ReverseRAT payload activation.
This rule monitors for user interactions with specific domains and URLs known to be associated with suspicious or malicious activity. It aggregates data from multiple sources, including email clicks (UrlClickEvents), device network activity (DeviceNetworkEvents), device browser events (DeviceEvents), and DNS queries (DnsEvents), to identify potential exposure to these indicators of compromise.
Detects the suspicious registration of a Cloud Filter provider callback using staging paths and naming conventions associated with the ShieldCrash (CVE-2026-69414) exploit. The rule monitors DeviceEvents for cloud provider activity that originates from unsigned or untrusted binaries, excluding known-legitimate cloud synchronization clients.
Detects the execution of an ONVIF-related tool or process with flags indicating credential retrieval. This is often associated with the reconnaissance or credential access phase targeting IoT devices such as cameras that support the Open Network Video Interface Forum (ONVIF) protocol.
Detects bulk file creation of XML files associated with Dahua credential exports, likely generated by a Python script, which is indicative of credential harvesting or staging for exfiltration.
Detects suspicious process creation patterns indicative of process hollowing. The rule identifies processes spawned by common script interpreters (powershell.exe, wscript.exe, cscript.exe, conhost.exe) in a suspended state, followed by memory operations involving ntdll.dll and APIs such as NtUnmapViewOfSection or ResumeThread, which are characteristic of hollowing injection techniques.
Detects execution of PowerShell commands containing indicators of in-memory AMSI (Antimalware Scan Interface) patching, specifically referencing AmsiScanBuffer, AmsiScanString, or AmsiOpenSession in conjunction with amsi.dll. This behavior is associated with the initialization stage of LausivLoader prior to its payload retrieval phase.
Detects execution of LausivLoader by identifying suspicious process creation patterns typically associated with process hollowing. This includes a parent process (powershell.exe or conhost.exe) launching a child process in a suspended state (CREATE_SUSPENDED), followed by behavioral indicators of memory manipulation and code replacement.
Page 208 of 1871


