Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects execution of rundll32.exe from non-standard locations or utilizing specific exported DLL functions often associated with bypassing application whitelisting, executing scripts, or proxying malicious code execution.
Detects the use of PowerShell to modify Windows Defender configuration settings, specifically targeting the disabling of real-time monitoring, behavioral monitoring, or other security protections via the Set-MpPreference cmdlet.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell where the task binary path resides in suspicious directories frequently used by adversaries for staging, such as AppData, Temp, Downloads, or Public folders.
Detects a dual persistence mechanism where an adversary establishes both an identically-named Registry Run key and a Scheduled Task, both masquerading as legitimate Canon or Stardock configuration software. These artifacts are configured to launch side-loaded host binaries (COTFileReadApp.exe or DeElevate64.exe) to maintain persistence on a Windows host.
Detects network activity associated with the Psychedelic Stealer malware, including C2 check-ins, API-based tasking, and communication with known C2 infrastructure using specific URI patterns and headers like 'X-API-Key'.
Detects a loader module and a corresponding RIFF/WAVE file that utilizes steganography to conceal a secondary malicious payload. The loader extracts the payload from the WAV file using specific offsets and XOR decoding, then executes it in memory. This pattern is characteristic of a DLL sideloading chain involving WMPCL.dll and WPFLocalizeExtension.dll.
Detects the execution of PowerShell scripts that utilize large arrays of negative integers to reconstruct and dynamically execute code via the [scriptblock]::Create method. This technique is commonly used to obfuscate malicious payloads such as downloaders or API calls from static analysis.
Detects a sequence of distinct system and network reconnaissance commands typically performed by malware or RATs for environment fingerprinting. The rule triggers when three or more unique reconnaissance activities—such as querying antivirus status, enumerating network adapters, checking domain information, or listing installed software—occur from the same host within a 5-minute window.
Detects HTTP traffic patterns associated with the Psychedelic Stealer malware command and control (C2) agent. The rule matches specific URI paths used for pinging, configuration retrieval, and tasking, while verifying the presence of the required 'X-API-Key' header, indicating established C2 communication.
Detects HTTP traffic patterns associated with the Psychedelic Stealer malware command and control (C2) agent. The rule matches specific URI paths used for pinging, configuration retrieval, and tasking, while verifying the presence of the required 'X-API-Key' header, indicating established C2 communication.
Detects network traffic attempting to connect to common public DNS-over-HTTPS (DoH) providers (Cloudflare, Google, Quad9) via TLS SNI or HTTP headers. This activity is often associated with malware or malicious agents attempting to bypass traditional DNS monitoring for command and control (C2) communication.
Detects malicious DLLs identified by specific exports and imports (e.g., rdCore.dll, I++u.dll) that are intended to be sideloaded by signed binaries such as Canon's COTFileReadApp.exe or Stardock software. The detection relies on identifying the combination of sideloaded component names and the presence of suspicious import structures characteristic of these specific staging loaders.
Detects outbound HTTP POST requests associated with the Psychedelic Stealer malware, which attempts to exfiltrate data from web browser-based cryptocurrency wallet extensions by targeting specific API endpoints and wallet extension IDs.
Detects instances where the GOMCam2024 executable launches or spawns a Chrome process with specific command-line arguments involving the user-data-directory being set to the system Temp folder. This behavior is often indicative of process injection, proxy-based credential theft, or attempts to execute browser sessions in a non-standard, potentially malicious context.
Detects the creation of a Windows scheduled task using 'schtasks.exe' or the system's scheduled task creation event where the command line or task details contain the string 'psychedelicloveUtils'. This pattern is often indicative of specific malicious persistence mechanisms or automated task-based payloads.
This rule detects the creation or modification of browser native messaging host configuration files (e.g., com.lunex.explorer.json) combined with the simultaneous or subsequent termination of common web browsers. This pattern is indicative of potential browser hijacking, where an adversary sets up a malicious native messaging host to facilitate persistence or intercept browser communications and subsequently restarts or terminates the browser process to reload the configuration.
Detects the execution of msiexec.exe to install an MSI package from a remote URL. This pattern involves the Windows Installer utility being invoked by explorer.exe with the /i (install) and /passive (unattended installation) flags, indicating a potentially malicious download and execution chain often used to deliver payloads via social engineering.
Detects the exploitation of the CMSTPLUA COM-object (CLSID 3E5FC7F9-9A51-4367-9063-A120244FBEC7) to bypass User Account Control (UAC). The rule monitors for PowerShell processes instantiating this object, followed by the execution of a hidden-window PowerShell process, bypassing the consent.exe UAC prompt.
Detects low-prevalence processes executing from non-standard directories that communicate with the same domain across multiple destination IP addresses over HTTPS (443) or DNS (53) within a short period. This behavior may indicate the use of Domain Generation Algorithms (DGA), fast-flux infrastructure, malware beaconing, or resilient command-and-control (C2) communications.
Detects CARBONATO botnet activity where malicious processes are masquerading as legitimate Linux system components. This includes XMRig mining software running as /usr/sbin/systemd-logind, process arguments attempting to mimic kernel kworker threads, or processes running from directories associated with netd-svc/resolved container images.
This rule detects a multi-tool attack chain involving the Cairn autonomous exploitation engine and the Hermes Agent. It flags the co-occurrence of outbound network traffic to both the DeepSeek API (Cairn engine) and the Anthropic Claude API (Hermes Agent) from the same host within a one-hour window. This behavior is indicative of an automated, AI-driven post-exploitation orchestration campaign.


