Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of PowerShell cmdlets and parameters to perform system, hardware, and external drive discovery. This includes querying volume information, disk/partition details, and checking for removable or specific bus-type media (USB, SD, MMC), which is commonly associated with reconnaissance activities by an adversary.
Detects instances where PowerShell is executed with encoded commands, seemingly spawned by a process masquerading as or related to the Microsoft Edge Update Task. The rule specifically monitors for process chains involving 'conhost.exe' with '--headless' arguments and subsequent PowerShell execution containing encoded commands, often associated with obfuscated activity.
This rule detects the execution of cmd.exe or powershell.exe where the command line arguments involve the deletion or renaming of specific file names potentially associated with unauthorized activities or malware components. It looks for common command-line utilities (del, ren) being used by command shells on specific files that may indicate artifact cleanup or staging.
This rule detects PowerShell processes attempting to download specific ZIP files (e.g., DriverInstaller.zip, Automata-20.zip, ww.zip) from Backblaze B2 cloud storage buckets. This pattern is commonly associated with the delivery of malicious payloads or staged tools.
Detects the creation or modification of a file named 'uploaded_files.json' within a directory containing 'SmartUploader' under the user's AppData path. This pattern is often indicative of data staging or local file tracking activity by potentially malicious software.
This rule detects the execution of cmd.exe or powershell.exe where the command line arguments involve the deletion or renaming of specific file names potentially associated with unauthorized activities or malware components. It looks for common command-line utilities (del, ren) being used by command shells on specific files that may indicate artifact cleanup or staging.
Detects common Windows command-line utilities used for internal network reconnaissance, including ARP cache queries, NetBIOS enumeration, SMB share/session discovery, and subnet ping sweeps. These techniques are frequently employed by adversaries for lateral movement preparation and internal network mapping.
This rule monitors network HTTP traffic containing specific strings related to gym-membership APIs and client IDs, alongside process or file activity referencing 'getFitnessProfile'. This combination is a behavioral fingerprint associated with a specific Golang-based remote access trojan (RAT) attempting to exfiltrate or interact with fitness profile data.
Detects the use of PowerShell to enumerate storage devices (USB, disk, partition information) and perform file operations such as copying or logging, potentially indicating malicious data collection from removable media or external drives.
Detects execution of command lines containing suspicious, potentially obfuscated substrings that do not correspond to standard Windows utilities. The use of custom delimiters like 'ASISFH' within common command strings suggests an attempt to bypass signature-based detection.
Detects the creation of files within the 'AppData\Local\SystemFolder32' directory. This path is non-standard and is frequently used by malware or unauthorized scripts to conceal malicious payloads or persistence mechanisms while masquerading as legitimate system components.
Detects a scenario where a process (cmd.exe) executing a file named 'config.bat' subsequently launches another instance of cmd.exe to delete files with a '.lnk' extension. This behavior is indicative of cleanup activities after potential malicious script execution.
This rule detects unauthorized persistence attempts by monitoring processes (reg.exe or powershell.exe) modifying the Windows 'CurrentVersion\Run' registry key to execute an application named 'DailyFitnessTracker' upon user logon.
This rule detects the execution of processes identified as 'DriverInstaller.exe' or files with known malicious SHA256 hashes associated with suspicious driver installation activity. The rule excludes legitimate system processes like msiexec.exe and trustedinstaller.exe, which are typically responsible for authorized software and driver installations.
Detects the execution of PowerShell with encoded commands in headless mode, associated with the Microsoft Edge Update Task (MicrosoftEdgeUpdateTaskUserS-1-5-24). This pattern is indicative of potential malicious activity where legitimate update tasks are abused to run obfuscated scripts.
Detects the use of PowerShell commands (Get-Volume, Get-Partition, Get-Disk) to identify and inspect information about connected removable storage media such as USB, IEEE 1394, SD, or MMC devices. This behavior is indicative of an adversary enumerating potential targets for data staging or exfiltration.
Detects the use of the Windows 'net.exe' utility to establish an IPC$ null session or an authenticated connection to the IPC$ share. These techniques are often used by attackers to perform remote service discovery, interact with remote shares, or facilitate lateral movement within a network.
Detects instances where the process 'UBPUpdater.Exe' spawns a process or command line utilizing 'UBPPatch.Psh'. The rule highlights that 'UBPPatch.Psh' is masquerading as a non-executable PowerShell script while likely operating as a malicious binary or PowerShell executable.
Detects the suspected RUSTYMOVE activity by identifying the creation of specific malicious files (ZIP and LNK) on the root directory of removable drives, followed by reconnaissance commands targeting removable media volumes.
This rule detects PowerShell script execution that interacts with the GitHub API, specifically targeting the upload of files or JSON data to repository endpoints. The logic looks for commands related to file system access, inclusion of 'api.github.com', and references to 'SmartUploader' or 'uploaded_files.json'. It further filters for activity occurring within standard user directories and enforces a check to ensure the GitHub repository name matches the local hostname, which is a common indicator of automated exfiltration scripts.
This rule detects potential lateral movement activity involving the use of the 'net use' command to connect to remote IPC$ shares or administrative tools like 'Test-NetConnection' to probe for SMB and RPC ports (445/135). Such techniques are often used by threat actors like APT36 to verify network connectivity and establish authenticated sessions for lateral movement.
Page 211 of 1871
