Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of diskshadow.exe with the /s (scripted) flag, followed by file access to sensitive Windows credential files (ntds.dit or SAM). This behavior indicates the abuse of the Windows Diskshadow utility to create a volume shadow copy for the purpose of offline credential exfiltration.
Detects file creation, modification, or renaming activity within AppData directories associated with VPN clients (CyberGhost, NordVPN, ExpressVPN). This rule is intended to identify potential unauthorized access, staging, or tampering with VPN configuration files or credentials often stored in these application directories.
Detects the use of dnscmd.exe to register a server-level plugin DLL for the Windows DNS service. This action is a known persistence mechanism that can be used to achieve arbitrary code execution within the context of the DNS service (dns.exe) upon service restart. The rule specifically alerts when a DLL file path outside of standard System32 or SysWOW64 directories is configured.
This rule detects behaviors associated with the Hannibal Stealer, specifically the identification of the Bitcoin Core wallet directory via registry lookups (strDataDir) followed by the unauthorized copying of 'wallet.dat' files into a staging directory structure, commonly used for cryptocurrency wallet exfiltration.
Detects the use of dnscmd.exe to register a server-level plugin DLL for the Windows DNS service. This action is a known persistence mechanism that can be used to achieve arbitrary code execution within the context of the DNS service (dns.exe) upon service restart. The rule specifically alerts when a DLL file path outside of standard System32 or SysWOW64 directories is configured.
Detects non-standard processes loading the iphlpapi.dll library and subsequently executing commands related to ARP network discovery, such as GetBSSID, SendARP, GetDefaultGateway, or GetAllNetworkInterfaces. This behavior is characteristic of network reconnaissance and fingerprinting activities often employed by information stealers like Hannibal Stealer.
Detects remote lateral movement attempts using DCOM to launch the Microsoft Management Console (mmc.exe) via svchost.exe (RPCSS/DCOM), followed by mmc.exe spawning an unexpected child process. This pattern indicates potential remote execution and abuse of signed binary proxies for post-exploitation activities.
This rule detects instances where the DISM core library (DismCore.dll) is loaded by a process named 'index.exe', or where a process named 'index.exe' is executing from or interacting with a folder path containing 'DISM'. This behavior is characteristic of malicious tools or scripts attempting to proxy execution through the Deployment Image Servicing and Management (DISM) binary, a common technique for bypassing security controls.
Detects modifications, creation, or renaming of common cryptocurrency wallet files (e.g., wallet.dat, .wallet files) within known storage directories. This behavior is often associated with infostealers or malware attempting to exfiltrate or manipulate user financial assets.
Detects presence of configuration markers associated with the Hannibal Stealer 'clipper' functionality. These markers (e.g., 'cclipper', 'clipboard_check_delay') are used by the malware to monitor the system clipboard and replace cryptocurrency wallet addresses with attacker-controlled addresses.
Detects components of the LucidPawn malware family using DLL side-loading (e.g., index.exe loading DismCore.dll) or renaming DISM binaries within WindowsApps folders. The detection identifies these processes subsequently querying system locale or language registry keys, indicating a geo-targeting execution gate used to determine if the environment matches the intended target profile (specifically zh-TW).
Detects instances of the Hannibal Stealer module that attempt to masquerade as the legitimate 'CefSharp.BrowsersSubprocess.dll' by spoofing publisher metadata ('LLC Windows'). The detection triggers when this process is identified initiating network connections shortly after execution, which aligns with the malware's known behavior of performing geolocation-based checks before continuing activity.
Detects the use of WMI (via wmic.exe, PowerShell, or other scripting engines) to query the Win32_Process class for process identification or path resolution. This behavior is commonly used by malicious actors, including info-stealers, to map active processes and their file locations for discovery purposes.
Detects instances where an executable masquerading as 'msedge.exe' (Microsoft Edge) is launched from a user's Startup folder. The rule looks for files identified as 'msedge.exe' that contain metadata or product information associated with DISM (Deployment Image Servicing and Management) or base Windows operating system components, indicating a potential attempt to disguise a different utility or payload as a trusted web browser.
Detects the execution of PowerShell with specific Pester build script arguments, initiated by Windows Explorer, followed within 5 minutes by the execution of 'index.exe' on the same host. This sequence may indicate malicious activity involving script execution leading to the spawning of an unknown or suspicious 'index.exe' binary.
This rule detects potential information stealer activity by identifying the staging of files (.html, .txt, .log) in common user directories like AppData or Temp, combined with process command lines querying sensitive system information (e.g., BIOS, wallets, screen resolution) and network connections to the Telegram API for likely exfiltration.
Detects malicious AI assistant links delivered via spearphishing emails that contain pre-populated prompt injection query parameters. The rule correlates the clicking of a high-signal URL (containing parameters like prompt, system, or lengthy search queries with malicious keywords) originating from an email with a subsequent active session to the same AI service within 5 minutes, confirming potential weaponized AI assistant session manipulation. Covers T1566.002, T1204.001
Detects the on-disk presence of a malicious Firefox browser extension, 'pdf-para-texto@extensao.local', used for credential or data harvesting. The rule monitors for the creation of its manifest file or XPI package in specific directories, indicating the staging or installation of the malicious extension.
Detects network communication to specific Gusercontent endpoints consistent with malicious browser extensions exfiltrating captured session tokens or cookies. The rule monitors for POST requests containing parameters like leadId, email, and data, often used to transmit stolen authentication material.
This rule detects the execution of specific suspicious binary names (TempuARKK20.exe, uARKK20.exe) from within temporary directories or their association with command-line arguments involving 'curl.exe' or specific suspicious web hosting strings. This behavior is indicative of malware staging and downloading secondary payloads in an attempt to masquerade as legitimate utilities.
This rule detects various suspicious activities associated with file staging and execution in the C:\Users\Public directory, including the handling of suspicious ZIP archives, renaming of executables (pythonw.exe to userscreen.exe), and the execution of specific batch scripts or obfuscated commands. These behaviors are indicative of an adversary staging tools or persistence mechanisms on a compromised system.
Page 235 of 1871


