Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
The following analytic identifies a LOLBAS process being executed outside of it's expected location.
Processes being executed outside of expected locations may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Processes being executed outside of expected locations may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
The following analytic identifies the execution of commonly used NirSoft utilities on Windows systems.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution details such as process name, parent process, and command-line arguments.
This activity is significant for a SOC because NirSoft utilities, while legitimate, can be used by adversaries for malicious purposes like credential theft or system reconnaissance.
If confirmed malicious, this activity could lead to unauthorized access, data exfiltration, or further system compromise.
Note that this search does not use a where clause to filter out known benign paths, as NirSoft utilities can be executed from various locations. This might hinder performance in environments with high data volumes.
Apply additional filtering as necessary to enhance this.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process execution details such as process name, parent process, and command-line arguments.
This activity is significant for a SOC because NirSoft utilities, while legitimate, can be used by adversaries for malicious purposes like credential theft or system reconnaissance.
If confirmed malicious, this activity could lead to unauthorized access, data exfiltration, or further system compromise.
Note that this search does not use a where clause to filter out known benign paths, as NirSoft utilities can be executed from various locations. This might hinder performance in environments with high data volumes.
Apply additional filtering as necessary to enhance this.
The following analytic detects the execution of multiple offensive toolkits and commands through the process execution datamodel. This method captures commands given directly to powershell.exe, allowing for the identification of suspicious activities including several well-known tools used for credential theft, lateral movement, and persistence. If confirmed malicious, this could lead to unauthorized access, privilege escalation, and potential compromise of sensitive information within the environment.
The following analytic detects the execution of multiple offensive toolkits and commands by leveraging PowerShell Script Block Logging (EventCode=4104). This method captures and logs the full command sent to PowerShell, allowing for the identification of suspicious activities including several well-known tools used for credential theft, lateral movement, and persistence. If confirmed malicious, this could lead to unauthorized access, privilege escalation, and potential compromise of sensitive information within the environment.
The following analytic detects the creation or connection to named pipes used by potentially unwanted applications (PUAs) like VPNs or utilities like PsExec.
It leverages Sysmon EventCodes 17 and 18.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
It leverages Sysmon EventCodes 17 and 18.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
The following analytic detects the creation or connection to known suspicious named pipes, which is a technique often used by offensive tools.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by RMM tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by RMM tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
The following analytic detects the creation of scheduled tasks designed to execute commands using native Windows shells like PowerShell, Cmd, Wscript, or Cscript or from public folders such as Users, Temp, or ProgramData. It leverages Windows Security EventCode 4698, 4700, and 4702 to identify when such tasks are registered, enabled, or modified. This activity is significant as it may indicate an attempt to establish persistence or execute malicious commands on a system. If confirmed malicious, this could allow an attacker to maintain access, execute arbitrary code, or escalate privileges, posing a severe threat to the environment.
The following analytic detects the creation, modification, or enabling of scheduled tasks with known suspicious or malicious task names. It leverages Windows Security EventCode 4698, 4700, and 4702 to identify when such tasks are registered, modified, or enabled. This activity is significant as it may indicate an attempt to establish persistence or execute malicious commands on a system. If confirmed malicious, this could allow an attacker to maintain access, execute arbitrary code, or escalate privileges, posing a severe threat to the environment.
The following analytic detects the creation of a Windows Service with a known suspicious or malicious name using Windows Event ID 7045. It leverages logs from the `wineventlog_system` to identify these services installations. This activity is significant as adversaries, including those deploying Clop ransomware, often create malicious services for lateral movement, remote code execution, persistence, and execution. If confirmed malicious, this could allow attackers to maintain persistence, execute arbitrary code, and potentially escalate privileges, posing a severe threat to the environment.
The following analytic detects the creation or connection to known suspicious C2 named pipes.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by C2 tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by C2 tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain persistence, command and control, or further system compromise.
The following analytic detects the creation or connection to known suspicious named pipes.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by malicious or suspicious tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain privilege escalation,
persistence, c2 communications, or further system compromise.
It leverages Sysmon EventCodes 17 and 18 to identify known default pipe names used by malicious or suspicious tools.
If confirmed malicious, this could allow an attacker to abuse these to potentially gain privilege escalation,
persistence, c2 communications, or further system compromise.
The following analytic detects the loading of known vulnerable Windows drivers, which may indicate potential persistence or privilege escalation attempts. It leverages Sysmon EventCode 6 to identify driver loading events and cross-references them with a list of vulnerable drivers. This activity is significant as attackers often exploit vulnerable drivers to gain elevated privileges or maintain persistence on a system. If confirmed malicious, this could allow attackers to execute arbitrary code with high privileges, leading to further system compromise and potential data exfiltration.
The following analytic identifies DNS queries to domains associated with the 3CX supply chain attack. It leverages the Network_Resolution datamodel to detect these suspicious domain indicators. This activity is significant because it can indicate a potential compromise stemming from the 3CX supply chain attack, which is known for distributing malicious software through trusted updates. If confirmed malicious, this activity could allow attackers to establish a foothold in the network, exfiltrate sensitive data, or further propagate malware, leading to extensive damage and data breaches.
The following analytic identifies DNS queries from internal hosts to dynamic domain providers. It leverages DNS query logs from the `Network_Resolution` data model and cross-references them with a lookup file containing known dynamic DNS providers. This activity is significant because attackers often use dynamic DNS services to host malicious payloads or command-and-control servers, making it crucial for security teams to monitor. If confirmed malicious, this activity could allow attackers to bypass firewall blocks, evade detection, and maintain persistent access to the network.
The following analytic detects DNS queries to domains associated with known remote access software such as AnyDesk, GoToMyPC, LogMeIn, and TeamViewer. This detection is crucial as adversaries often use these tools to maintain access and control over compromised environments. Identifying such behavior is vital for a Security Operations Center (SOC) because unauthorized remote access can lead to data breaches, ransomware attacks, and other severe impacts if these threats are not mitigated promptly.
Detects suspicious activity associated with Cobalt Strike Beacon communication, specifically monitoring for known default named pipes and specific user-agent strings commonly used by Cobalt Strike in HTTP/S traffic.
Detects a suspected exploitation attempt of CVE-2024-21412. The rule identifies a chain of execution involving an internet shortcut (.url) masquerading as a common file type (e.g., .jpg.url), which subsequently opens another shortcut to a WebDAV/IP host. This sequence is used to bypass Mark-of-the-Web (MotW) protections and execute a malicious batch script and Rundll32 process.
Detects the invocation of powershell.exe or pwsh.exe using encoded command flags (-EncodedCommand/-enc) in combination with stealth-oriented arguments such as -WindowStyle Hidden or -NoProfile. This pattern is frequently utilized by threat actors to execute obfuscated, malicious scripts while bypassing command-line visibility and standard profile configurations.
Detects anomalous lateral movement via Remote Desktop Protocol (RDP) by identifying three high-risk patterns: rapid RDP fan-out to multiple destination hosts from a single account, RDP access to sensitive servers from unauthorized source hosts, and RDP sessions followed by the execution of known post-exploitation or credential-theft tooling on the destination host.
This rule detects HTTP GET requests initiated by the Windows PowerShell User-Agent where the destination host is a decimal-encoded IP address. This pattern is commonly associated with ClickFix-style social engineering attacks, where users are tricked into executing obfuscated PowerShell commands to download malicious payloads.
Detects a process reading credential store files (Login Data) from multiple Chromium-based browsers, immediately followed by an HTTP POST request to a specific exfiltration endpoint associated with the Psychedelic Stealer malware.
Page 22 of 1866
