Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Matches known Vidar Stealer sample SHA256 hashes spanning versions 2.0 through 3.4 as identified by Zscaler ThreatLabz
Detects Vidar's custom stream cipher used for string/config decryption: FNV-1a mixing of the VM-derived key combined with golden-ratio nonce mixing and per-build ARX round constants
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
Detects the presence of zero-width, non-printing, or bidirectional-override Unicode characters in command lines, commonly used for obfuscation or prompt injection.
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
Detects invisible/non-printing Unicode codepoints (zero-width chars, bidi overrides, variation selectors, Unicode tag characters, and Private Use Area icon-font codepoints) embedded in process command lines - covering both classic command/script obfuscation and the emerging use of hidden codepoints to smuggle AI prompt-injection payloads into content later processed by AI copilots/agents. Tightened to require 2+ high-confidence codepoint hits (or 1 from a known scripting host/LOLBin), and gates Private-Use-Area-only matches (a common legitimate icon-font false-positive source) to scripting hosts with 5+ hits, maps to T1027.018.
Detects high-volume file download, access, or preview activity originating from known anonymous proxy services. This behavior is indicative of potential data exfiltration or unauthorized mass data collection from cloud storage applications.
This rule monitors for DNS queries and network connections to known infrastructure domains associated with the threat group UTA0565. It acts as an indicator of compromise (IOC) sweep to identify internal systems attempting to communicate with malicious command-and-control (C2) servers identified by typosquatting and registration-pattern analysis.
Detects accounts showing a spike in requests to public generative-AI services compared to their historical baseline, combined with anomalous indicators like multiple source IPs, regions, or off-hours activity.
Detects the installation of Windows services (Event ID 4697 or 7045) where the service binary path points to command interpreters (PowerShell, cmd.exe) or suspicious directories such as Temp, user profile paths, or file extensions associated with scripts (.ps1, .vbs, .bat). This behavior is often indicative of persistence mechanisms or lateral movement attempts where an attacker attempts to execute arbitrary code via a service.
This rule detects the execution of processes that use file names mimicking legitimate security or system services, such as 'Credential Guard.exe' or 'Window Security Health Services.exe'. These names are often used by adversaries for masquerading to evade detection by blending in with legitimate system activity.
Detects a suspicious sequence of events where a process modifies a Windows Registry Run key to ensure execution at logon, followed shortly by the same executable file being copied into the current user's startup folder. This pattern is often used by malware to establish persistence.
This rule detects potential malicious activity by correlating device events against a known set of malicious file hashes, domains, and URLs. It identifies files with known malicious hashes, network connections to known malicious domains, and command-line processes attempting to download files from known malicious URLs using common living-off-the-land tools like PowerShell, curl, or wget.
Detects suspicious HTTP POST requests to a URI path '/collect' containing specific telemetry parameters ('visitorId', 'timeOnPage', 'stage') characteristic of the 'ClickFix' social engineering campaign. This behavior is used by threat actors to simulate fake bot-protection challenges to trick users into executing malicious code.
Detects the execution of known remote access and support tools (Quick Assist, Microsoft Remote Assistance, or AnyDesk) on a host that has recently received a high volume of emails (over 50). This behavior often aligns with social engineering campaigns where a user is instructed to download or launch a remote support tool under false pretenses.
Detects the exfiltration behavior of the Sauron Loader, where a process tree associated with rnpkeys.exe or its modules (rnp.dll, tdwp.dll) within the C:\ProgramData\keyroll directory performs a burst of numerous small HTTPS POST requests to a single destination. This pattern is characteristic of a screenshot image being fragmented into small chunks and exfiltrated.
Detects the execution of suspected Sauron Loader components staged in C:\ProgramData\keyroll\ (rnpkeys.exe or tdwp.dll) followed by an outbound network connection from the same host within a 2-minute window. This behavior correlates the staging of malicious binaries with the loader's automated outbound registration attempt.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that reference specific task names associated with potentially suspicious activity or persistence (e.g., PlutonAgentScheduler, EnterpriseMgmtServicesScheduler). The rule specifically looks for tasks being placed or modified within 'microsoft' or 'pluton' directories or paths, which may indicate an attempt to masquerade as legitimate system services.




