Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects execution of PowerShell scripts attempting to modify Windows Defender settings by adding directory exclusions (including the C:\ drive) via cmdlets like Add-MpPreference, Set-MpPreference, or WMI/CIM methods, often followed by a forced Group Policy refresh. This pattern is associated with malicious staging activity, including malware loaders like LausivLoader.
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
Detects PNG image files containing an 'iTXt' metadata chunk and a specific byte marker (FF 89 AD 4A). This signature is characteristic of LausivLoader, which hides an encrypted payload within the image using steganographic techniques, intended for subsequent extraction via XOR decryption and DEFLATE decompression.
Detects the execution of DahuaConsole processes that are spawned by or associated with the scannerdahua utility. This pattern is often associated with discovery or exploitation activities targeting Dahua devices.
This rule detects suspicious activity related to specific hardcoded indicators 'p2pwn', 'p2password', and references to 'cve-2024-39943'. It scans authentication logs (Identity) and EDR logs (process command lines) for these terms, flagging potential unauthorized access, credential use, or exploitation attempts associated with this specific threat activity.
Detects the creation or execution of scheduled tasks named 'MicrosoftEdgeUpdateTaskCore' that exhibit suspicious behaviors, specifically those marked as hidden, tasks utilizing a LogonTrigger, or tasks executing wscript.exe with specific command-line arguments (e.g., //B, //Nologo) often associated with malicious script execution patterns.
This rule detects attempts by a process (specifically targeting PowerShell or .NET loaders) to tamper with Windows Antimalware Scan Interface (AMSI) components in memory. It correlates EDR or Sysmon events (process access, module loads) targeting 'amsi.dll' or involving specific AMSI API strings like 'AmsiScanBuffer' or 'AmsiInitFailed' with potential malicious loader activity.
This rule detects the creation of XML files matching the 'export_batch_*.xml' naming convention, which is consistent with the output pattern of the Dahua DeviceManager utility. Attackers often use this tool to export camera configuration files containing sensitive credentials (IP, Port, Username, Password). The rule flags activity where multiple such files are created in a short duration, suggesting potential mass exfiltration of camera credentials.
Detects a suspicious execution chain where WScript.exe initiates a process with '--headless' arguments, which in turn spawns a PowerShell process with hidden, encoded, and non-interactive command line flags. This pattern is commonly used by adversaries to execute malicious scripts while attempting to evade detection and user interaction.
This rule detects PowerShell script blocks that exhibit multiple indicators of obfuscation and in-memory execution. It identifies the combination of AES encryption, embedded key bytes commonly associated with deobfuscation routines, GZip compression, and reflective assembly loading (Assembly.Load). The use of multiple techniques simultaneously significantly increases the likelihood of malicious activity, such as fileless malware loading or execution of obfuscated payloads.
Detects attempts to modify Windows Defender security settings by adding exclusions to the scan path using various PowerShell cmdlets or WMI methods. This behavior is often associated with adversaries attempting to evade detection by excluding malicious tools or directories from antivirus scanning.
Detects the execution of JavaScript files using wscript.exe from user-writable directories (e.g., Temp, Downloads, AppData) that exhibit high levels of obfuscation. The rule specifically flags scripts containing a high ratio of comment lines to code, a technique often used in the LausivLoader malware family to mask malicious payloads constructed using String.fromCharCode.
Detects the addition of a file path exclusion to Windows Defender via the command-line registry utility (reg.exe), followed immediately by the execution of gpupdate to force a policy refresh. This pattern is commonly used by adversaries to exclude malicious directories from security scanning and ensure the configuration change takes immediate effect.
Detects attempts to patch ETW (Event Tracing for Windows) functions such as EtwEventWrite within the memory space of PowerShell or PWSH processes. This is a common technique used by attackers to suppress telemetry and evade security monitoring tools, often associated with bypassing AMSI/ETW logging mechanisms.
Detects attempts to patch ETW (Event Tracing for Windows) functions such as EtwEventWrite within the memory space of PowerShell or PWSH processes. This is a common technique used by attackers to suppress telemetry and evade security monitoring tools, often associated with bypassing AMSI/ETW logging mechanisms.
Detects attempts to disable Windows Defender Tamper Protection via direct Registry modification or by executing PowerShell commands. Disabling Tamper Protection is a common tactic used by adversaries to facilitate further malicious activity, such as impairing security controls or deleting malware artifacts without interference from Windows Defender.
Detects the creation of a JavaScript file masquerading as a legitimate Microsoft PhotoEngine component ('PhotoStudio.js') within the '%LOCALAPPDATA%' directory. This behavior is associated with the LausivLoader malware, which uses this masquerading technique to evade detection.
This rule detects the LausivLoader initial-stage obfuscated JavaScript dropper. It identifies the malware either by specific file hashes (MD5/SHA256) or by detecting characteristic behaviors: small file size (<1MB), the presence of 'String.fromCharCode' obfuscation techniques, excessive junk comments, and supply-chain related lure strings.
This rule detects the creation or registration of scheduled tasks using common scripting engines (PowerShell, WScript, CScript) or specific task name patterns (MicrosoftEdgeUpdateTaskCore, PhotoStudio.js) often associated with malicious persistence or execution. It monitors command lines for flags such as /create, /sc onlogon, or /ru system that suggest non-standard or unauthorized task creation patterns.
Detects the presence of known Vidar infostealer samples by matching file hashes against a list of identified malicious artifacts. The rule monitors for file creation events, process execution (both as the primary process and as an initiating process), and network activity originating from these known malicious files.
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
Page 209 of 1871


