Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of PowerShell script interpreters that utilize .NET runtime methods, such as 'RunspaceFactory' and 'CreateRunspace', to dynamically create and execute scripts, pipelines, or invoke methods. This technique is often used by fileless malware and offensive security tools to bypass traditional command-line logging by interacting directly with the System.Management.Automation assembly.
This rule detects the execution of a specific MSI package identified by its filename and hash (MD5/SHA256). The rule monitors 'msiexec.exe' process executions and alerts when the process command line or file hash matches a known malicious indicator.
This rule detects the execution of a specific MSI package identified by its filename and hash (MD5/SHA256). The rule monitors 'msiexec.exe' process executions and alerts when the process command line or file hash matches a known malicious indicator.
Detects the use of 7-zip (7z.exe) to interact with a specific file (drata.dat) using command-line arguments typical of an archival or extraction operation. This may indicate an adversary attempting to stage, compress, or exfiltrate sensitive data.
Detects the execution of cmd.exe as a child process of msiexec.exe, specifically when the command line includes 'xupdate.bat' and references a suspicious file path within 'AppData\Roaming\Traiolx Custom Utils'. This pattern is indicative of potential malicious installer abuse or software updates being used for code execution.
This rule monitors for the presence of a file named '_socket.pyd', which is a standard Python library component. The alert triggers when this file appears within a specific directory path 'Traiolx Custom Utils' or matches a known file hash associated with potentially malicious activity or unauthorized use of Python modules.
Detects access, retrieval, or modification of the 'RegisteredOrganization' registry value under 'SOFTWARE\Microsoft\Windows NT\CurrentVersion'. This key often contains information about the registered owner or organization of the Windows installation and is frequently queried or modified during reconnaissance or environment configuration.
Detects instances where a process named 'updater.exe' launches another process also named 'updater.exe'. This pattern can indicate suspicious activity where a legitimate updater process is being misused or abused to spawn additional malicious code or side-load components.
This rule monitors for PowerShell commands that combine common data collection flags ('-Recurse', 'Documents') with 'Invoke-WebRequest' to perform a POST method upload. This pattern is commonly associated with the staging and exfiltration of sensitive files from local directories to a remote destination via HTTP/S.
Detects the execution of the Windows binary InstallUtil.exe using specific flags (/logfile=, /LogToConsole=false, and /U) commonly used to execute arbitrary .NET code while bypassing application control mechanisms such as AppLocker or Windows Defender Application Control (WDAC).
Detects the execution of regsvr32.exe with flags indicative of the Squiblydoo technique, which utilizes the /i parameter to load a remote COM scriptlet (.sct file) via scrobj.dll. This method is a known application allowlisting bypass technique.
This rule detects the presence of compiled Python 3.10 bytecode (.pyc) files that have been renamed to or disguised with a .cat extension. It specifically looks for the 'settingenv.cat' file associated with the Chinotto backdoor, as well as associated C2 URL patterns or command-line artifacts indicative of its download and execution chain.
Detects the execution of odbcconf.exe with the REGSVR action. This technique leverages the legitimate Windows utility odbcconf.exe to load and execute arbitrary DLLs, bypassing security controls that might not monitor or restrict this binary.
This rule detects the execution of suspicious shortcut (.lnk) files or the use of command-line interpreters (cmd.exe, powershell.exe, wscript.exe, cscript.exe) to initiate processes related to specific, potentially malicious filenames often associated with phishing or social engineering campaigns. The rule monitors for these activities occurring in user-writable directories such as Downloads, Desktop, or Temp.
Detects execution of PowerShell with bypassed execution policy used to download or copy files from remote locations using curl.exe and Copy-Item. This pattern is commonly associated with file staging or retrieving malicious payloads from external URLs, including specific paths.
Detects the use of forfiles.exe to execute command-line interpreters such as cmd.exe or powershell.exe. This pattern is commonly used by adversaries as a LOLBAS (Living Off the Land Binary and Script) technique to achieve indirect command execution and bypass security controls.
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to initiate process creation on remote hosts. This is achieved by combining the '/node:' flag (to specify a remote target) with the 'process call create' command. This technique is frequently utilized by adversaries and ransomware operators for lateral movement across a Windows network.
Detects the execution of cmstp.exe with silent (/s) and auto-install (/au) flags pointing to an attacker-supplied INF file. This pattern is a documented technique for bypassing User Account Control (UAC) and performing signed-binary proxy execution to load malicious payloads.
Detects the execution of Regasm.exe or Regsvcs.exe where the target assembly is located in a path other than standard Windows or .NET framework directories. This behavior is often indicative of an adversary attempting to use these signed utilities to load and execute malicious .NET payloads as a proxy, thereby bypassing application allowlisting.
Detects the use of command-line utilities (cmd.exe, curl.exe, tar.exe) to download or interact with specific suspicious zip archives (python-3.10.0-embed-amd64.zip, temp012.zip, MusicLibrariesPackage) from known staging directories or external sources often associated with malicious staging or persistence.
Detects the execution of Control Panel (.cpl) files via control.exe from non-standard system directories, or the use of rundll32.exe to invoke CPL applets. These methods are commonly used to proxy malicious code execution while appearing legitimate.
Page 233 of 1871
