Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
Detects potential zero-click administrator session hijacking by correlating a logged-in administrator accessing a page containing user-generated content (e.g., comments) followed immediately by a sensitive administrative action (e.g., plugin installation, user creation) within a 5-second window, suggesting automated script execution via an autofocus/onfocus handler triggered by the admin's browser.
Detects the creation of image files (.bmp, .png, .jpg, .jpeg) by processes executing from non-standard directories such as AppData or ProgramData. This behavior is indicative of unauthorized screen capture activities often used by malware for pattern-of-life monitoring, where screenshots are staged in temporary locations before exfiltration. The rule filters out common legitimate applications known to perform screen captures.
Detects instances of common interpreter processes, specifically node.exe or python variants, accessing known cryptocurrency wallet files or mnemonic storage files on a Windows system. This behavior is highly indicative of malicious activity where an attacker uses lightweight script-based tools to perform credential harvesting or theft of cryptocurrency assets.
Detects potentially malicious LDAP queries logged by Windows Server 2025 (Event IDs 3039/3040). The rule monitors for common attacker reconnaissance techniques, including Kerberoasting, AS-REP roasting, delegation abuse, AD CS enumeration, and BloodHound-style data collection patterns.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
This rule detects when the MpDlpService.exe process loads the 'mpclient.dll' library from a location other than the legitimate Windows Defender program directories. This behavior is indicative of potential DLL side-loading or hijack execution flow attempts targeting the Microsoft Data Loss Prevention service.
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
This rule detects when the MpDlpService.exe process loads the 'mpclient.dll' library from a location other than the legitimate Windows Defender program directories. This behavior is indicative of potential DLL side-loading or hijack execution flow attempts targeting the Microsoft Data Loss Prevention service.
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
This rule detects potential staging activity for ClickFix or Vidar malware campaigns. It identifies the creation of files or folders in directories mimicking Windows Diagnostics infrastructure (WDI) or known payload paths, correlated with the execution of suspicious PowerShell commands or archive-related utilities within a 30-minute window on the same device.
This rule monitors network, DNS, and HTTP activity to identify connections to known infrastructure associated with the ClickFix social engineering campaign and Vidar infostealer malware. The rule correlates device network events, HTTP request events, and DNS queries against a list of known malicious domains, IP addresses, and URL patterns used for C2, staging, and lures.
This rule detects malicious activity related to the exploitation of MpDlpService.exe. It looks for the execution or presence of known malicious file hashes associated with this threat, including a P-stage script, payload files, and a malicious mpclient.dll. Additionally, it identifies instances where the legitimate MpDlpService.exe binary is executed from a non-standard, suspicious directory, which is a common indicator of side-loading or persistence techniques.
This rule detects potential command and control (C2) communication and malicious process execution associated with the Vidar stealer malware. It monitors both network connections and process command lines for indicators of known Telegram C2 channels and secondary Steam community profile C2 infrastructure. The rule specifically highlights activity originating from processes other than common web browsers to identify suspicious automated beaconing or control.
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
Detects process and file creation activity matching known MovieReaper loader and downstream module file hashes (MD5/SHA256). C2 IP/domain network indicators for this campaign require a separate network_connection-category rule, since Sigma logsource categories cannot be mixed within a single rule.
Page 213 of 1871



