Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the abuse of the legitimate Windows script 'SyncAppvPublishingServer.vbs' to proxy the execution of malicious commands, specifically by appending an arbitrary command separated by a semicolon.
Detects the execution of csc.exe (C# compiler) from non-standard directories or when compiling source files located in user-writable paths like Temp or AppData. This behavior is indicative of on-host code compilation used by attackers to bypass static antivirus detection by delivering and compiling malicious payloads on the fly.
Detects the execution of the Program Compatibility Assistant (pcalua.exe) with the '-a' flag to launch executables located in common user-writable directories such as Temp, Downloads, or AppData. This behavior is a known Living off the Land Binaries and Scripts (LOLBAS) technique used to proxy execution and potentially bypass security controls or break parent-child process lineage.
Detects the use of command-line utilities (cmd.exe, curl.exe, tar.exe) to download or interact with specific suspicious zip archives (python-3.10.0-embed-amd64.zip, temp012.zip, MusicLibrariesPackage) from known staging directories or external sources often associated with malicious staging or persistence.
Detects the execution of wscript.exe or cscript.exe with VBScript or JScript files from user-writable and temporary directories, such as %TEMP%, %APPDATA%, and Downloads folders. This pattern is commonly associated with the execution of malicious droppers and loaders in malspam campaigns.
Detects the execution of cmd.exe with suspicious command-line obfuscation patterns. The rule looks for the use of the '/k' flag combined with variable assignment and character substitution/expansion patterns (e.g., %var:~start,len%), often used in batch file obfuscation to execute malicious logic. It specifically triggers when originating from common suspicious parents like explorer.exe or Bandizip.exe, or when targeting syswow64 locations.
This rule detects potentially malicious command execution initiated by or linked to the Bandizip archive utility. It identifies scenarios where Bandizip launches shells (cmd, powershell, wscript, cscript) to execute scripts or commands (e.g., .lnk files, .bat, .vbs, .js, .ps1), or where suspicious 'cmd.exe /k' commands are executed directly or through an updater process.
This rule detects the execution of the Windows FTP client (ftp.exe) using a command script file (via the -s: parameter). It monitors for process creation of ftp.exe with this flag, excluding known legitimate paths. It then correlates this with any child processes initiated by the FTP client to identify potential data exfiltration or automated file transfers.
Detects the use of odbcconf.exe with the REGSVR flag to load DLLs from suspicious directory locations (such as Temp, Downloads, or AppData), a technique used by adversaries to proxy execution and bypass application control.
Detects the execution of installutil.exe with specific command-line arguments (logging disabled, uninstall flag) from file paths outside of the standard .NET directory structure. This pattern is commonly used by attackers to proxy execution of arbitrary managed code, effectively bypassing application whitelisting and security controls.
Detects the abuse of the legitimate Windows utility 'certutil.exe' to download files from external sources or to decode/deobfuscate files on the host, commonly used as a LOLBIN for malicious activities.
Detects file creation, renaming, or deletion events within the Recycle Bin directory involving suspicious filenames or PDF files, which may indicate an adversary attempting to hide, stage, or delete evidence.
Detects the execution of regasm.exe or regsvcs.exe where the command line arguments reference paths typically used for temporary files, user downloads, or public directories. These signed .NET utilities can be abused to proxy the execution of malicious code by loading custom COM assemblies via ComRegisterFunction or ComUnregisterFunction attributes, effectively bypassing application control.
Detects Hancom HWP documents that contain an OLE BIN0001.OLE stream and specific JScript storage structures, which are indicative of a weaponized document used to execute scripts and fetch remote payloads from a specific command-and-control URL.
Detects execution of MSBuild.exe (Microsoft Build Engine) where the project file is located in a potentially user-writable, temporary, or staging directory, or when the command line includes indicators of inline task compilation (e.g., UsingTask or TaskFactory). This behavior is often associated with the use of MSBuild to proxy execution of arbitrary code to bypass application control mechanisms.
Detects the execution of an executable named 'Windowsupdate.exe' located in non-standard user-writable directories (e.g., AppData\Local) when initiated by an FTP client process. This is a common pattern for malicious masquerading or persistence mechanisms.
Detects the use of WMIC to invoke XSL files or perform suspicious process creation commands, a technique often used for proxy execution or script-based attacks.
This rule detects potential User Account Control (UAC) bypass attempts involving the abuse of the COM object associated with 'sppextcomobj.exe'. The rule looks for scenarios where 'rundll32.exe' initiates 'sppextcomobj.exe', which in turn triggers 'slui.exe'. This behavioral chain is a known technique for achieving elevated privileges by exploiting how Windows handles COM auto-elevation.
Detects the abuse of the forfiles.exe utility to indirectly execute command-line interpreters such as cmd.exe, powershell.exe, or other common LOLBins. Adversaries use this technique to bypass security controls that monitor or restrict direct execution of these interpreters.
Detects the use of pcalua.exe to launch executables or scripts located in potentially transient or user-writable directories such as Temp, Downloads, or AppData. This behavior is indicative of an adversary attempting to execute payloads while bypassing security controls or masquerading as legitimate system processes.
Detects the Microsoft Support Diagnostic Tool (msdt.exe) being launched by Office applications or web browsers using the ms-msdt protocol handler or PCWDiagnostic parameters, which is indicative of the Follina (CVE-2022-30190) vulnerability exploitation.
Page 234 of 1871
