Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
Detects the execution or file activity associated with the 'OrionQuests-Setup.exe' installer. This rule monitors both process creation and file system activity to track the presence and usage of this specific installer executable, which may indicate the installation of potentially unauthorized or untrusted software.
Detects the Stella_Gary .NET backdoor loader used by Kimsuky/APT-C-55, identified by managed-layer reflective assembly loading strings (loader.Program.Main, AssemblyResolve callback, Stella_Gary.Program.Main)
This rule detects known side-loaded PlugX RAT host processes ('GRrte.exe' or 'Jarte.exe') located in 'JartePortable' directories attempting to modify process tokens or privileges. This behavior is indicative of privilege escalation preparation, a common activity for the PlugX modular RAT.
Detects removable-media/storage interaction events initiated by the PlugX side-loaded process chain (GRrte.exe / Jarte.exe), consistent with the PlugX core's drive-type query and removable-media ejection behavior (GetDriveTypeW / DeviceIoControl)
Detects execution of the PlugX side-loaded host process (Jarte.exe / GRrte.exe) from the JartePortable directory. This process performs in-memory host/system profiling (GetComputerNameW, GetVersionEx, system directory queries) via the decoded PlugX core (T1082), which is not directly visible as command-line telemetry.
Detects the execution of known Jarte-derived host processes (GRrte.exe or Jarte.exe) which are commonly leveraged as side-loading proxies for the PlugX remote access trojan. The rule flags the process initiation as a proxy indicator for the subsequent execution of PlugX's modular payload, which performs system enumeration and process discovery.
Detects the creation of a scheduled task configured to run under the SYSTEM account that executes a command to add a Windows Defender exclusion using Add-MpPreference. This technique is often used to ensure persistence of security exclusions by re-applying them automatically with high privileges, even if an interactive user attempts to remove them.
This rule detects instances where Adobe Acrobat (Acrobat.exe) is launched by an unusual or potentially obfuscated process (GRrte.exe), specifically when loading a PDF file from a temporary user directory. This pattern is indicative of potential malicious document execution where a PDF is used as a delivery mechanism for malware.
Detects 32-bit Windows PE files packed with UPX that exhibit a zeroed compile timestamp, a characteristic often associated with staged SalatStealer or XenoRAT binaries observed in Operation CameraSwarm.
This rule detects the execution of processes containing 'OnvifUser' and command line arguments specifying '-u', which is consistent with the usage of ONVIF device discovery tools. ONVIF discovery protocols are used to identify network video transmitters. Unauthorized use of these tools can indicate reconnaissance activity within a network to identify cameras or video surveillance devices.
This rule detects various system events (including process execution and user account creation) that contain the specific string 'p2pwn' in combination with the string 'p2password'. This pattern suggests the activity involves potentially malicious credential testing, hardcoded credential usage, or suspicious account interaction activity.
This rule detects two potentially malicious activities: the addition of exclusions to Windows Defender using reg.exe, which can be used to hide malicious files from security scanning, and the forceful update of Group Policy using gpupdate.exe with /force and /wait:0, which can be used to propagate malicious policy changes or force re-application of settings.
Detects instances where the Windows command shell (cmd.exe) creates, modifies, or renames specific suspicious files ('My_Resume.pdf', 'Documents_Details.pdf') within the 'ProgramData' directory, often associated with execution of batch files or file copy operations that may indicate staging of malicious payloads.
Detects the unknown or suspicious process 'doxc' (or 'doxc.exe') executing common Windows system administration utilities ('wmic.exe', 'fsutil.exe', 'cmd.exe') or command-line arguments typically used for reconnaissance and system information discovery, such as listing logical disks or volume information.
Detects the creation or modification of a file named 'uploaded_files.json' within a directory containing 'SmartUploader' under the user's AppData path. This pattern is often indicative of data staging or local file tracking activity by potentially malicious software.
Detects the use of PowerShell cmdlets and parameters to perform system, hardware, and external drive discovery. This includes querying volume information, disk/partition details, and checking for removable or specific bus-type media (USB, SD, MMC), which is commonly associated with reconnaissance activities by an adversary.
Page 210 of 1871



