Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects execution of 'clspack.exe' from within the user's AppData directory. This location is frequently used by adversaries to stage and execute malicious binaries to evade detection, as it is outside of typical system directories like System32 or SysWOW64 where trusted system binaries are expected.
Detects the execution of rundll32.exe with the '/sta' command line argument followed by a CLSID. This behavior leverages the IShellRunDll COM interface to execute registered objects, bypassing the standard requirement of providing a DLL path and exported function name. This method is often used by adversaries to execute malicious code while blending in with legitimate system processes.
This rule detects potentially malicious file execution by monitoring for the usage of .pif files, often disguised as image files or documents, which subsequently launch suspicious child processes such as msiexec, wscript, cscript, or rundll32. The detection logic matches on specific parent processes (e.g., browsers, email clients, file explorers) triggering the file, followed by suspicious command line arguments within a 10-minute window.
This rule detects potentially malicious activity involving the execution of WSF scripts from the AppData directory, followed by registry modifications using reg.exe or rundll32.exe. Additionally, it monitors for the creation or presence of specific suspicious files (clspack.exe, filetext.txt, prnfig.wsf) in user profile directories, often indicative of staging or persistence.
Detects instances where a Terraform process or its associated provider plugins spawn a Go toolchain process (go.exe) to execute a local package. This pattern is associated with malicious Terraform providers that use this technique to bootstrap second-stage payloads such as the Graphalgo RAT.
Detects the execution of rundll32.exe with the '/sta' command-line flag and a GUID-formatted CLSID. This technique is often used by malware (e.g., DarkME RAT) to proxy execution through COM components, which hides the actual path of the loaded DLL or payload, aiding in evasion.
This rule detects the execution of 'clspack.exe' from within the AppData\Microsoft directory. 'clspack.exe' is a legitimate Windows utility normally residing in System32 or SysWOW64. Execution from user-writable directories like AppData is a common indicator of masquerading or binary hijacking.
Detects the execution of search-ms or search protocol URIs that contain a 'crumb' parameter combined with either a 'displayname' parameter or remote path indicators (such as WebDAV/UNC paths). This technique is commonly used by adversaries to redirect Windows Search to a remote, malicious location while masking the source by spoofing the displayed name or path to trick users.
Detects potential staging and execution chains involving remote MSI file fetching via msiexec.exe, or the execution of .wsf scripts or registry imports originating from or residing in AppData directories. This behavior is indicative of multistage malware delivery or persistence mechanisms where components are downloaded and executed using LOLBins.
Detects high-frequency TCP SYN scanning activity originating from external networks targeting port 37777, commonly associated with the Dahua DVR P2P discovery service. This behavior is indicative of automated reconnaissance and scanning campaigns searching for vulnerable IoT devices.
Detects a successful login attempt by the user account 'p2pwn' targeting port 37777. Port 37777 is commonly associated with DVR/NVR surveillance equipment and is frequently targeted by brute-force attacks and botnets attempting to gain unauthorized access to embedded devices.
Detects the execution of a file named 'setup.exe' from suspicious user-writable directories (Temp, Downloads, AppData) when the command line arguments contain keywords associated with archive utilities like 7-Zip or Foobar2000. This pattern is indicative of a 'nested installer' technique where legitimate software utilities are leveraged to extract or execute malicious payloads.
This rule detects DLL files being loaded by common archive extraction and setup utilities (7-zip, setup.exe). Adversaries often use self-extracting (SFX) archives or installer wrappers to execute malicious code by placing a malicious DLL in the same directory as the executable to facilitate DLL side-loading or masquerading.
This rule detects network connections on standard web ports (80, 443) initiated by Windows executable files (.exe) to specific, known malicious or suspicious domains (codeonicinc.com, setupsoftwarecenter.com). This pattern is consistent with malware installers attempting to download secondary payloads or communicate with C2 infrastructure.
This rule detects the execution of processes associated with known malicious SHA256 file hashes linked to OpenSUpdater. It monitors DeviceProcessEvents from the past 30 days to identify instances where these specific file hashes are executed on endpoints.
This rule detects network connections originating from hosts to specific remote domains ('codeonicinc.com', 'setupsoftwarecenter.com') which are associated with OpenSUpdater command and control (C2) activity. It leverages Microsoft Defender DeviceNetworkEvents to identify endpoints communicating with these known malicious infrastructure components.
This rule detects the execution of a file named 'setup.exe' that is spawned by common interpreters (explorer.exe, msiexec.exe, powershell.exe, cmd.exe) where the command line arguments reference archiving or compression utilities like 'foobar2000', '7z', or '7zip'. This is a common pattern for self-extracting (SFX) installers or malicious droppers attempting to execute payload components.
KQL Query
This rule detects executable files (ending in .exe) executing from a specific subdirectory within the user's AppData path (\AppData\Microsoft\Update\). This path is often used by adversaries to masquerade malicious activity or persistence mechanisms as legitimate update processes. The rule excludes common system service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise, focusing on processes initiated by user-level accounts.
This rule detects the presence of command line artifacts, filenames, and strings associated with the SilverFox malware. These strings indicate the execution of a malicious desktop monitoring component ('active_desktop_launcher.exe') or the use of specific IPC/configuration markers ('@@RAPID_CFG_START@@') characteristic of this threat's tradecraft.
This rule detects the loading of a suspicious DLL file named 'active_desktop_render_x64.dll' or the initiation of activity by a process named 'PDF_C2089_20260911100446.exe', which may indicate the execution of malicious code or potential process injection activity.


