Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects process and file creation activity matching known MovieReaper loader and downstream module file hashes (MD5/SHA256). C2 IP/domain network indicators for this campaign require a separate network_connection-category rule, since Sigma logsource categories cannot be mixed within a single rule.
Detects the execution of msiexec.exe to install an MSI package from a remote URL (http/https). The command line includes flags for passive installation (/passive) and an installation parameter (/i), initiated directly by Windows Explorer (explorer.exe), which is often associated with a user manually downloading and opening a malicious MSI file.
Detects the creation of a scheduled task or registry manipulation involving the string 'psychedelicloveUtils' occurring within 30 minutes of the execution of the process 'psychedeliclove.exe'. This pattern is indicative of a persistence mechanism being established by potentially malicious software.
This rule detects the creation of specific suspicious files (e.g., host.ps1, host.bat) within browser native messaging host directories, followed by the termination of the associated web browser process. This pattern suggests an adversary attempting to establish persistence or manipulate browser functionality via native messaging components.
Detects a process accessing browser credential files (Login Data) followed by an outbound network connection to a suspicious exfiltration endpoint commonly associated with credential-stealing malware.
Detects the clearing of Windows event logs using native 'wevtutil.exe' or PowerShell cmdlets. The rule monitors for common log-clearing commands and triggers an alert when multiple such events occur on a single host within a 15-minute window, which is indicative of bulk log-wiping often performed by ransomware or during post-exploitation defense evasion.
Detects User Account Control (UAC) bypass attempts where an adversary writes to specific registry keys under HKCU\Software\Classes to hijack COM handlers, followed shortly by the execution of auto-elevating Windows binaries like fodhelper.exe, computerdefaults.exe, or sdclt.exe. This activity facilitates silent privilege escalation.
Detects processes attempting to enumerate Active Directory objects (users, groups, trusts) while simultaneously establishing a network connection to Active Directory Web Services (ADWS) on port 9389. This behavior is characteristic of tools like SharpADWS, which performs AD enumeration via the ADWS protocol rather than traditional LDAP, potentially bypassing legacy detection mechanisms.
Detects the creation of a remote service using 'sc.exe' where the executable was recently written to an administrative share (ADMIN$ or C$). This behavior often indicates lateral movement by threat actors deploying malicious binaries as services on remote systems.
Detects unauthorized modifications to Group Policy Objects (GPO) involving critical attributes (such as SYSVOL paths or extension configurations) combined with the creation of new script or executable files in the SYSVOL Scripts folder. This behavior is indicative of potential GPO tampering to gain persistence or facilitate large-scale execution, such as ransomware deployment via GPOs.
Detects the execution of Microsoft-signed .NET utilities (RegSvcs, InstallUtil, MSBuild, CSC, VBC, ILAsm, AspNet_Compiler) when spawned by scripting engines like PowerShell, wscript, or cscript. This behavior is indicative of the Veil#Drop framework using trusted developer utilities as a fallback mechanism to execute secondary payloads or bypass security controls.
Detects instances where msiexec.exe, the Windows Installer utility, spawns cmd.exe to execute a batch file named 'xupdate.bat' located within the 'AppData\Roaming\Traiolx Custom Utils\' directory. This behavior is indicative of malicious persistence or execution mechanisms, often associated with loaders like LegionLoader that leverage installer binaries for evasion.
Detects the creation of temporary files with names starting with 'MSI' and ending in '.tmp' within the system's temporary directory. Legitimate installations typically perform these actions via the 'msiexec.exe' process; therefore, files created by other processes may indicate suspicious payload staging or activity by malware attempting to masquerade as MSI installer components.
Detects the execution of a specific VBScript file 'Telegram_Private_Call_Session.vbs' via WScript, or its execution when spawned as a child process of MSHTA. This behavior is indicative of an HTA-dropped malicious script attempting to execute.
Detects the suspicious initiation of Control Panel applet functionality via the COM object 'COpenControlPanel'. Adversaries may leverage this COM interface or the associated 'CPL_INIT' message to proxy malicious code execution through standard Windows processes like dllhost.exe or rundll32.exe, effectively bypassing security controls that might otherwise flag the direct execution of malicious .cpl files.
Detects the execution of wmic.exe when launched by uncommon parent processes, specifically mshta.exe or wscript.exe. These parent processes are often associated with the execution of malicious scripts (e.g., .hta or .vbs files), which may use wmic.exe for system discovery or execution of commands, a common pattern in file-based living-off-the-land attacks.
Detects modifications to the Windows Registry designed to disable PowerShell ScriptBlockLogging. This is a common defense evasion technique used by attackers to hide malicious PowerShell commands and scripts from security monitoring.
Detects evidence of PowerShell execution occurring within a GitLab CI runner environment that exhibits characteristics of command-and-control (C2) activity. This rule monitors PowerShell Script Block Logging (Event ID 4104) for indicators such as specific CI environment variables (e.g., CI_PIPELINE_SOURCE=api, GIT_STRATEGY=none), static job names associated with known exploitation patterns (e.g., CI_JOB_NAME=run_command), and the dynamic execution of commands using Invoke-Expression (IEX) on environmental variables.
Detects the modification of the registry value 'EnableScriptBlockLogging' to '0' (Disabled) under the PowerShell policy path. This action suppresses the generation of Windows Event ID 4104 (PowerShell Script Block Logging), which is a critical source for monitoring attacker-issued PowerShell commands and detecting post-exploitation activity.
Detects the creation of files with the .ent extension within the Microsoft Internet Explorer directory. This behavior is associated with the NarwhalRAT malware, which uses this specific file extension and location to store AES-encrypted configuration files, likely for persistence or subsequent execution by the malware.
Detects the creation or execution of a scheduled task masquerading as a Microsoft Update process. The task is configured to execute potentially malicious components, specifically identified by filenames such as userscreen.exe, UserInerfacePicture, or config.cat. This behavior is indicative of persistence and execution of malicious payloads, as seen in campaigns involving the NarwhalRAT loader.
Page 214 of 1871


