Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the MovieReaper Stage-3 module which masquerades as Microsoft Edge (msedge.exe) within the C:\ProgramData\Windows\Telemetry directory. The detection focuses on suspicious process execution from this directory and identifies instances where the process respawns itself, suggesting malicious activity post-UAC bypass.
Detects the use of the Add-MpPreference cmdlet with -ExclusionPath, or processes spawned by CRUDEEXCLUDE.exe, which are associated with configuring Microsoft Defender exclusion paths. This is often used by adversaries to evade detection by excluding malicious files or directories from antivirus scanning.
This rule detects instances where Windows scripting engines (WScript or MSHTA) execute script files (WSF, VBS, HTA) which subsequently spawn a PowerShell process using encoded command arguments. This pattern is commonly used by adversaries to mask malicious payloads and bypass execution policy or simple command-line monitoring.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
This rule detects potentially malicious activity where specific non-standard processes (e.g., RuntimeSSH.exe, MicDriver.exe, MsCache.exe) either execute PowerShell commands related to security feature tampering (disabling Windows Defender exclusions) or create persistent Registry run keys associated with these process names. This pattern is indicative of malware attempting to establish persistence or evade security controls.
Detects the invocation of the C# compiler (csc.exe) by PowerShell, where the command line includes specific references to .cmdline files. This pattern is commonly used in fileless execution techniques to compile and execute malicious code in memory after delivery.
Detects SVG image files that contain embedded HTML or script payloads, often used as an initial delivery vector to smuggle malicious code (such as downloaders or web redirects) into a target environment. This technique has been associated with the delivery of various remote access trojans (RATs).
Detects the execution of 'winget.exe' with the 'configure' command. This command is used to apply configuration files (typically YAML-based) to the system, which can automate software deployment, environment setup, or system changes. Adversaries may abuse this utility to facilitate malicious software deployment or system configuration changes via legitimate administrative tools.
Detects the execution of ConfigurationRemotingServer.exe initiated by winget.exe. This could indicate usage of the Windows Package Manager to facilitate remote configuration or management tasks, which warrants investigation for potential unauthorized use or process manipulation.
This rule detects instances of MSBuild.exe executing or communicating over the network while referencing .NET Framework paths. MSBuild is often abused as a LOLBAS (Living Off the Land Binary and Script) to execute arbitrary code or bypass application control, and unusual network activity from this process is a common indicator of beaconing or command-and-control communication.
This rule detects the use of 'winget' or 'ConfigurationRemotingServer.exe' to execute Windows Configuration DSC (Desired State Configuration) files, specifically targeting the invocation of 'PSDscResources/Script' resources, 'SetScript', 'TestScript', or 'GetScript' operations. This technique may be leveraged by attackers to execute arbitrary code or maintain persistence through the configuration management framework.
This rule monitors for outbound TCP traffic from internal hosts to a specific IP address (212.34.141.103) on port 4521, which is associated with C2 beaconing behavior, potentially involving the abuse of MSBuild.exe as a LOLBin.
This rule detects two suspicious activities: first, the execution of 'conhost.exe' with a headless command line argument containing 'cmd /c echo' and either a '.tmp' file reference or a suspicious base64-like encoded string, initiated by explorer.exe or cmd.exe. Second, it identifies the presence of '.lnk' shortcut files within common user-writable directories such as Downloads, Desktop, or Public folders, which is a common indicator of staging or persistence.
This rule monitors process creation events for suspicious activity, specifically detecting two patterns: 1) The creation of a scheduled task named 'OneDrive KeepAlive' using schtasks.exe, which is indicative of persistence mechanisms masquerading as legitimate software, and 2) Execution of the 'taskhostw.exe' binary with command-line arguments 'exec' and 'hide', which is a common indicator of the NirCmd utility being renamed and used for stealthy execution.
This rule detects persistence attempts via Component Object Model (COM) hijacking. It identifies a specific process 'December_blob.exe' creating or modifying registry keys associated with COM CLSIDs (specifically InprocServer32) and simultaneously dropping or utilizing a file named 'hvcsrv.dll' within an 'IdentityNexusIntegration' directory. This combination of registry modification and file system activity suggests the registration of a malicious COM object to achieve execution persistence.
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
This rule detects attempts to query or access the MachineGuid registry key located in HKLM\SOFTWARE\Microsoft\Cryptography. This registry key is commonly used to uniquely identify a Windows installation and is frequently targeted by malicious software to perform system identification or fingerprinting.
Detects the use of nodejs.exe to initiate external network tunnels to known tunneling services like pinggy.io or generic tunnels using common tunnel configuration flags.
Detects the use of nodejs.exe to initiate external network tunnels to known tunneling services like pinggy.io or generic tunnels using common tunnel configuration flags.
Detects the use of the Windows 'tasklist' utility or command execution via 'cmd.exe' when the command line includes strings associated with common debugging tools (e.g., windbg, x64dbg). This behavior may indicate an adversary checking for the presence of analysis tools or attempting to manipulate running processes, which is often associated with debugger evasion or malicious environment reconnaissance.
Page 232 of 1871


