Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of a suspicious file named 'FitnessMonitor.exe' within the Windows Startup folder. This technique is commonly used by remote access trojans (RATs) to ensure persistent execution upon user logon.
Detects the creation of files with the name 'README_KRSID.Txt', which is a hallmark behavior of the KRSID ransomware strain used to leave ransom notes on compromised systems.
Detects the execution of command-line operations that involve the deletion of shortcut (.lnk) files or the self-deletion of batch scripts, often used by malware or malicious scripts to minimize their footprint and remove evidence after execution.
Detects the creation of specific file paths and files associated with the PSNATCH file stealer tool, specifically monitoring for the presence of SmartUploader application directories and its associated upload index files. This behavior is indicative of an adversary staging collected data on a local system for subsequent exfiltration.
Detects the presence of KRSID ransomware by identifying specific embedded strings associated with its configuration, including ransom notes (README_KRSID.Txt), log files (ransomware-silent.Log), encrypted file extensions (.krsid), and common command-line arguments used for operational control.
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
Detects known malicious SilverFox trojan payloads by matching their SHA256 file hashes. This rule operates on file hashing metadata to identify specific binary artifacts associated with the SilverFox threat actor, regardless of the delivery mechanism or download source.
Detects the execution of files related to 'UBPPatch' or 'HTSPnew', specifically looking for PowerShell scripts (.psh) or executables (.exe) that match these potentially non-standard or obfuscated update/patch filenames. The rule also looks for command lines referencing 'Update.Lst', often associated with custom or unauthorized patch mechanisms.
Detects modifications to Active Directory user accounts (Event IDs 4720, 4738) that coincide with suspicious MFA registration indicators—such as increased device counts, software token activations, or default device/token placeholders—within one hour of a successful user authentication event. This behavior is indicative of potential account takeover or persistence activities involving MFA manipulation.
Detects the execution of the KRSID ransomware binary, which is written in Rust. The rule identifies the malware based on its unique file extensions, ransom note filenames, specific command-line arguments, log file indicators, and compiled code characteristics.
Detects evidence of the RUSTYMOVE USB-propagation tool, associated with APT36 (Transparent Tribe). The rule identifies the creation of specific staged files (DriverInstaller.zip, DocScanner-11-Aug-2026-5-37pm.pdf.LNK) at the root of removable drives, as well as the creation of a 'log.txt' file on removable media that contains markers indicating successful file copying operations.
Detects host-based network reconnaissance behaviors commonly associated with the threat group APT36 (Transparent Tribe). The rule identifies the execution of various built-in Windows network discovery commands including arp, nbtstat, net view/share/session, and automated ping sweeps or PowerShell-based subnet enumeration scripts, which are used to map reachable hosts and network shares.
Detects individual file access events performed by non-browser python processes. This rule is designed as a proxy to identify automated file collection activities, such as those performed by 'python-httpx', that may be indicative of low-volume data exfiltration when aggregated over time.
This rule detects the execution of 'DriverInstaller.exe' (either by filename or a known malicious SHA256 hash) that subsequently initiates network connections to GitHub domains. This behavior is indicative of potential malicious activity, such as downloading secondary payloads, command-and-control communication, or beaconing from a suspected rogue or masquerading driver installation utility.
Detects the creation of scheduled tasks using either 'schtasks.exe' or 'powershell.exe' (Register-ScheduledTask) where the task name or configuration references common update or startup task patterns, or contains indicators of potential process hiding or encoded command execution.
Detects evidence of PSNATCH or BASHNATCH tools exfiltrating data to GitHub. The rule identifies suspicious file operations related to an 'SmartUploader' tracking file in standard user directories (AppData, .local/share), monitors for SmartUploader process execution, and flags network connections to api.github.com from processes identified as SmartUploader, bash, or PowerShell.
Detects the PUROSANGUE malware loader, which achieves execution by being sideloaded as 'vsdbg.dll' alongside a legitimate debugger executable. The detection leverages YARA rules focusing on specific artifacts such as a hardcoded build path, a custom Base16 alphabet, and a structural anomaly in the PE file's .reloc section compared to the declared base relocation directory size, alongside known malicious hash values.
Detects the creation of specific staging files and directories associated with the Rapuncel infostealer (e.g., UserInformation.txt, installed_applications.txt, sends.log, browser_decryption.log, or the Filegraber directory) within Windows temporary storage paths. This activity typically occurs following the unauthorized collection of sensitive data such as credentials, digital wallet information, and messenger session data.
Detects the loading of the Alinubx.sys kernel driver or the creation of an NvFsFilter service, which are associated with a BYOVD (Bring Your Own Vulnerable Driver) attack leveraging a renamed CcProtect driver to bypass security protections such as PPL.
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
Page 212 of 1871

