Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
C2 Ioc Detection
YARA-L
Detects Network, File, or Process events associated with known C2 IOCs
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
Detects usage of the Android Debug Bridge (ADB) 'pair' command initiated by processes other than known legitimate Android development tools (e.g., adb.exe, Android Studio). This may indicate an attacker attempting to wirelessly pair a malicious device or gain unauthorized access to an Android device over the network.
Detects attempts to disable or modify Windows Defender security features, such as Real-time Monitoring, Tamper Protection, or adding unauthorized exclusion paths via PowerShell cmdlets or direct registry modifications.
This rule monitors for known malicious file hashes, IP addresses, C2 domains, and specific URL markers associated with identified threat activity. It consolidates multiple detection vectors including file activity, process execution, network connections, and DNS queries to identify compromised devices communicating with attacker-controlled infrastructure.
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
Detects EDRKiller.exe or WarsawKiller.exe binaries and the associated wsftprm.sys BYOVD driver used by The Gentlemen threat actor to terminate security product processes
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
This rule detects the execution, file presence, or driver loading associated with 'EDRKiller' and 'WarsawKiller', which are malicious tools used to terminate or disable endpoint security products.
Page 238 of 1871

