Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects unauthorized access to VPN configuration files associated with common VPN providers (CyberGhost, NordVPN, ExpressVPN). This behavior is characteristic of the Hannibal Stealer, which attempts to exfiltrate these files to compromise user VPN sessions and credentials. The rule filters out legitimate process access to minimize false positives.
Detects suspicious process command lines that access sensitive cryptocurrency wallet data files or registry keys associated with wallet applications, which is a common behavior of information-stealing malware.
Detects the execution of a renamed DISM binary (index.exe) that subsequently loads a specific DLL (DismCore.dll), which is a common technique used for DLL side-loading to evade security controls by masquerading as a legitimate system utility.
Detects the creation of a shortcut (LNK) file within the Windows Startup directory that points to a msedge.exe binary located in a non-standard, masqueraded location within the user's Local AppData path. This behavior is associated with the LucidPawn/LucidRook persistence mechanism.
Detects process execution events where a process is launched with command line arguments containing 's' as an isolated character (often indicative of token stealing tools like Incognito or similar utilities) combined with a discrepancy in the initiating process account or logon session, suggesting potential token duplication or impersonation.
Detects execution of common administrative and potentially malicious processes originating from the Microsoft Exchange Server worker process (w3wp.exe). This pattern is indicative of a web shell or post-exploitation activity where an attacker has achieved code execution on an Exchange server.
Detects processes repeatedly loading GDI/display libraries (gdi32.dll, gdi32full.dll, user32.dll) at a sustained cadence indicative of automated screen capturing. The rule excludes common collaboration and remote access tools known to perform these functions legitimately, flagging high-frequency, long-duration activity consistent with malicious screen scraping techniques.
Detects process injection and hook evasion attempts where a thread is created or modified with a start address that does not resolve to a known, legitimate memory module. This pattern is indicative of shellcode execution or reflective DLL injection where the malicious code resides in anonymous or unbacked memory regions.
Detects a variant of the ClickFix technique where an attacker directs a user to open an administrative PowerShell or Command Prompt instance via the Windows+X power user menu through Windows Terminal. This execution chain, involving WindowsTerminal.exe, OpenConsole.exe, and a shell binary, bypasses traditional RunMRU registry artifacts often associated with the standard Windows Run dialog.
Detects instances where wscript.exe spawns powershell.exe with command-line arguments indicative of stealth or obfuscation, such as hidden windows or encoded commands. This behavior is frequently associated with malicious script execution lures, such as JavaScript-based droppers or ClickFix-style campaigns that use PowerShell to stage and execute in-memory payloads.
Detects PowerShell command lines that simultaneously utilize .NET cryptography classes (TripleDES or AES) for decryption and runspace pipeline creation. This pattern indicates an in-memory execution technique where malicious payloads are decoded and executed directly within the PowerShell process, effectively bypassing disk-based security controls.
Detects the presence of PureLogs Stealer, a .NET-based information stealer, by identifying specific family name strings embedded within PE files that conform to the .NET assembly structure. This rule targets the static analysis of malicious binaries often used in credential harvesting campaigns.
Detects malicious PowerShell command chains often used in ClickFix campaigns. These commands typically move zip files from the user's Downloads directory to a temporary folder, extract them using the tar utility, and execute an embedded PowerShell script using conhost in headless mode. This technique is designed to bypass AMSI command-line inspection by offloading the actual payload execution to an extracted, unmonitored script.
Detects PowerShell scripts attempting to evade detection through programmatic runtime creation using Runspaces (RunspaceFactory, CreatePipeline, AddScript) combined with cryptographic operations or dynamic string substitution techniques. This behavior is often associated with obfuscated malware payloads attempting to execute code in memory.
Detects the use of PowerShell string concatenation to construct the malicious C2 domain 'merabs.pro'. This technique is used to bypass simple string-based detections that look for the full domain name in command-line arguments.
Detects the ClickFix social-engineering technique where an adversary tricks a user into pasting and executing a malicious command via Windows Explorer (Run dialog) or Windows Terminal. This pattern is often used in fake CAPTCHA or job-interview lures to achieve initial code execution.
This rule detects the execution of known Remote Monitoring and Management (RMM) tools across the environment. RMM tools are frequently used by IT administrators for legitimate support, but are also commonly abused by threat actors to establish persistence and gain remote access to systems. The rule tracks the first instance of these processes appearing on any device within a 30-day window.
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
Detects the Kimsuky APT-C-55 'Stella_Gary' attack chain, where PowerShell is used to download a JavaScript verification script from an external C2 (InfinityFree), followed by the execution of that script via cscript.exe in temporary directories. This behavior is used to bypass anti-bot mechanisms and retrieve secondary payloads from hardcoded C2 infrastructure.
Detects known malicious files associated with Kimsuky (APT-C-55) Stella_Gary attack chain by MD5 hash: OrionQuests-Setup.exe installer, guide.url.lnk, test.bef_fri, and backdoor payload component
Detects known malicious files associated with Kimsuky (APT-C-55) Stella_Gary attack chain by MD5 hash: OrionQuests-Setup.exe installer, guide.url.lnk, test.bef_fri, and backdoor payload component
Page 217 of 1871


