Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
This rule monitors for the creation of known Neo-reGeorg web shell files ('tunnel.jsp', 'tunnel.jspx') within common web server directory paths, such as 'webapps', 'applications', 'wlserver', 'PSHTTP', 'PORTAL', or 'webserv'. Neo-reGeorg is a popular tunneling web shell used by adversaries to facilitate persistent access and proxy traffic into a compromised environment.
Detects the execution of the SIDEEYE backdoor (Ple64.exe) when it is spawned by web-based processes such as Java (WebLogic) or shell interpreters (cmd.exe/powershell.exe) invoked by web-based parents. This behavior is indicative of a web shell exploitation attempt.
Detects a sequence of Tox P2P protocol packets consisting of a Cookie Request, Cookie Response, and Crypto Handshake within a single network flow. This pattern is indicative of the Tox P2P protocol, which is sometimes abused by malware (e.g., AvisLoader) for command-and-control (C2) communications to evade traditional network inspection.
Detects network traffic attempting to exploit CVE-2021-33044, an authentication bypass vulnerability in Dahua NetKeyboard devices, by identifying specific login request strings used in the exploit chain.
This rule monitors for known malicious indicators, including a specific file hash, a C2 IP address, a remote URL associated with potential malicious activity (anydesk.exe), and a domain associated with C3Pool crypto-mining activity, across device processes, network events, and file operations.
This rule detects a sequential multi-stage execution chain starting with msiexec.exe launching a hidden PowerShell script, followed by wscript.exe executing a VBScript agent, and finally node.exe executing a JavaScript file within a short time window. This pattern is indicative of a complex, multi-stage dropper or malware execution flow.
Detects the loading of a known malicious 136KB browser injection helper DLL (SHA256: 75018b06c7105a1dca391805d17b402aed35ebd515b92d461236eafbd606cb40) into Google Chrome or Microsoft Edge processes. The rule further correlates this activity with command line arguments indicative of abusing the browser's elevation service, which is a technique often used for process injection or local privilege escalation.
Detects the deletion of Chrome registry keys related to extension integrity verification. This behavior is often associated with browser-based attacks, such as malware or malicious extensions attempting to tamper with browser security configurations to enable persistent browser hijacking or unauthorized extension modification.
Detects the ChainScript RAT agent (executing as node.exe from specific masquerading directory paths) scanning for and enumerating cryptocurrency wallet files, browser-stored wallet extensions, and related sensitive configuration data.
Detects the execution of MSI installers from user-writable directories (e.g., Downloads, Temp, Public) that masquerade as legitimate software applications like Spotify, Zoom, or Microsoft Teams. This behavior is indicative of 'ClickFix' style social engineering lures, where users are prompted to download and execute malicious installers.
Detects the installation of a Windows service that mimics the legitimate NVIDIA File System Filter Driver (NvFsFilter). Adversaries, such as those associated with the Rapuncel infostealer, use this technique to establish persistence and evade security controls by masquerading as a common driver component.
Detects HTTP proxy requests for ZIP archives where the Referer header indicates a navigation originated from a GitHub Pages (github.io) site, but the destination is not a GitHub domain. This behavior is indicative of a multi-hop redirect chain used in campaigns to deliver malicious payloads, such as infostealers, by abusing GitHub Pages to redirect users to external hosting for ZIP archive downloads.
Detects the loading of the malicious NvFsFilter driver (a BYOVD technique often used by the Rapuncel infostealer) followed immediately by a mass burst of process terminations, indicating an attempt to disable security software.
Detects a suspected social engineering attack chain where a user communicates with a recruiter via messaging apps or browsers, subsequently clones or installs a malicious repository using 'npm' or 'VS Code', and triggers suspicious child process activity from 'node.exe'. This pattern is associated with the WaterPlum campaign.
Detects Node.js or Python processes exhibiting behavior characteristic of information-stealing malware (such as the WaterPlum suite: BeaverTail, InvisibleFerret, OtterCookie, StoatWaffle). The rule monitors for these processes accessing sensitive files related to browser credentials, cryptocurrency wallets, scanned identification documents, or performing collection activities like keylogging and screen capturing.
Detects user authentication events to recruitment, career, or applicant-tracking applications where the connection originates from an anonymizing proxy, VPN, or datacenter IP address. This behavior has been observed as a precursor to North Korean IT worker recruitment fraud, where attackers mask their true geographic location to gain unauthorized employment.
No description available.
Detects a specific behavioral chain associated with the CHOSEN BRICK implant. This rule identifies when a suspected malicious process writes image/screenshot files (.png, .jpg, .bmp) to disk, followed by a network connection to the Telegram Bot API within a 15-minute window, suggesting potential data exfiltration.
This rule detects artifacts and behaviors associated with the WaterPlum/Contagious Interview (also known as DeceptiveDevelopment) malware suite, including BeaverTail, InvisibleFerret, and related payloads. The rule specifically targets the presence of embedded family-name strings, as well as the execution of suspicious npm package installations triggered by VS Code task automation (tasks.json) or trust prompts, common in fake technical interview attack scenarios.
Detects a chained sequence of suspicious activity initiated by agentic AI development tools (e.g., Claude Code, Aider, AutoGen). The rule identifies the execution of these tools followed by local reconnaissance commands, lateral movement attempts, and outbound network connections originating from the same host, indicating potential automated exploitation or credential abuse.


