Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of scheduled tasks initiated by the WinGet DSC configuration processes, specifically ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe. This activity is indicative of the abuse of the 'ScheduledTask' resource within a WinGet configuration file to establish persistence via a logon-triggered task.
Detects unauthorized or suspicious persistence attempts where Windows Package Manager (WinGet) configuration processes (ConfigurationRemotingServer.exe or WindowsPackageManagerServer.exe) write to the Windows 'Run' registry keys in HKLM. This behavior can be abused to execute malicious code automatically at system startup.
Detects instances where cmd.exe spawns a PowerShell process with the '-executionpolicy bypass' argument. This pattern is commonly used by attackers to execute malicious scripts while circumventing Windows PowerShell execution policy restrictions.
Detects the execution of the Python interpreter (pythonw.exe) renamed to 'codeflush.exe' residing in non-standard paths like '\Public\Music\MusicLibrariesPackage\'. This behavior is characteristic of adversaries attempting to camouflage malicious Python scripts or binaries as legitimate files to evade detection.
Detects execution of cmd.exe with suspicious command-line patterns utilizing environment variable substring expansion (%VAR:~offset,length%). This technique is used to dynamically reconstruct and execute obfuscated commands, a method historically observed in APT37 delivery chains to hide malicious payloads and bypass simple string-based signatures.
Detects the download and subsequent extraction of the Python embeddable zip package to directories under 'C:\Users\Public'. This activity is consistent with techniques used by threat actors, such as APT37, to establish a covert Python runtime environment on a compromised host for further malicious operations.
Detects the execution of cmd.exe spawned by explorer.exe that contains suspicious command line parameters. The rule specifically targets the use of obfuscated Windows batch substring expansion (e.g., %VAR:~0,1%) or commands being executed directly from common user-writable directories like Temp or Downloads, which are common indicators of malicious LNK file abuse.
Detects outbound TCP traffic containing system reconnaissance data, such as OS information, computer name, and location, being sent to a known C2 server address. The rule monitors for specific content patterns indicative of an infected host checking in or exfiltrating host configuration details.
Detects the creation of a mutex with the 'Global\evolution' prefix, which is a known indicator of the XMRig cryptocurrency miner execution.
Detects instances of MSBuild.exe executing from within the Microsoft.NET framework directory while initiating outbound network connections to a specific known command-and-control (C2) IP address associated with rmrlx infrastructure, or standalone network activity matching these parameters.
Detects the use of Windows command shell variable substring expansion to obfuscate commands. Adversaries use this technique to build malicious command lines dynamically, making them less visible to standard keyword-based detection mechanisms by storing parts of strings in environment variables and reassembling them using substring notation (e.g., %var:~start,length%).
Detects instances of MSBuild.exe executing from within the Microsoft.NET framework directory while initiating outbound network connections to a specific known command-and-control (C2) IP address associated with rmrlx infrastructure, or standalone network activity matching these parameters.
Detects the use of Windows command shell variable substring expansion to obfuscate commands. Adversaries use this technique to build malicious command lines dynamically, making them less visible to standard keyword-based detection mechanisms by storing parts of strings in environment variables and reassembling them using substring notation (e.g., %var:~start,length%).
Detects the use of Windows command shell variable substring expansion to obfuscate commands. Adversaries use this technique to build malicious command lines dynamically, making them less visible to standard keyword-based detection mechanisms by storing parts of strings in environment variables and reassembling them using substring notation (e.g., %var:~start,length%).
Detects instances where curl.exe is spawned by cmd.exe or wscript.exe and uses the -o flag to save downloaded files into user-writable directories (e.g., Temp or AppData), a technique often used to stage secondary payloads during the exploitation process.
Detects the execution of Python interpreters from non-standard, user-writable directories (such as Public\Music) or using suspicious filenames. This behavior is indicative of threat actors abusing the Python Embeddable package to run disguised Python backdoors, such as the Chinotto malware family observed in APT37 operations, often staged via batch scripts or curl.
Detects the execution of batch files from temporary directories that employ command obfuscation techniques such as environment variable substring expansion, or which execute with a hidden window in conjunction with chained system utilities commonly associated with malicious activities (e.g., curl, tar, schtasks). This behavior is often indicative of staged payload delivery and execution.
Detects the execution of batch files from temporary directories that employ command obfuscation techniques such as environment variable substring expansion, or which execute with a hidden window in conjunction with chained system utilities commonly associated with malicious activities (e.g., curl, tar, schtasks). This behavior is often indicative of staged payload delivery and execution.
Detects malicious file system activity where the legitimate Python interpreter (python.exe) is deleted and replaced or renamed to a deceptive filename (codeflush.exe) within the 'C:\Users\Public\Music\MusicLibrariesPackage' directory. This technique is used by threat actors, including APT37, to mask the execution of Python-based backdoors and evade detection.
Detects HTTP POST requests to a known suspicious endpoint ('/board.php') often used by the Chinotto Python backdoor. The rule monitors for outgoing web traffic containing 'data=' parameters or connections to known malicious domains, indicating potential exfiltration of base64-encoded command output.
Detects the execution of the Pester framework's Build.bat script, which is being abused as a LOLBAS (Living Off the Land Binary and Script) technique. This activity is typically characterized by being launched from an LNK file, often indicating a malicious dropper or secondary stage payload delivery.
Page 216 of 1871
