Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of a local user account using the hardcoded 'Numlock!123' password, a characteristic artifact associated with Ransom Busters threat group operations. The rule monitors command-line activity from net.exe or net1.exe to identify attempts to add users with this specific, known malicious credential.
This rule detects a high frequency of process terminations occurring within a 5-minute window on a device where specific driver-related processes or command lines ('nvfsflt64.sys', 'Alinubx.sys') have been identified. Such behavior is characteristic of malicious activity attempting to disrupt system security components or clear traces, potentially indicating an endpoint denial of service or evasion attempt.
Detects instances where PowerShell or mshta.exe are launched by a web browser or Windows Explorer, often indicative of the 'ClickFix' social-engineering campaign. In this scenario, users are tricked into copying and pasting malicious commands from a fake CAPTCHA or update prompt directly into a Windows terminal or the Run dialog, leading to code execution.
Detects the loading of known vulnerable kernel drivers 'truesight.sys' or 'rentdrv2.sys'. These drivers are frequently abused in Bring-Your-Own-Vulnerable-Driver (BYOVD) attack chains, where attackers leverage specific IOCTL calls (such as 0x22E044 or 0x22E010) to interact with the driver to perform privileged actions, such as terminating security processes.
This rule detects the use of standard Windows administrative utilities (wmic.exe, vssadmin.exe, and wbadmin.exe) to perform destructive operations on volume shadow copies or backup catalogs. These actions are frequently associated with ransomware attacks to prevent system recovery.
Detects the execution of Active Directory Explorer (ADExplorer.exe or ADExplorer64.exe), a legitimate tool often repurposed by adversaries to enumerate Active Directory structures, accounts, and group memberships.
Detects the invocation of SQL Server Management Studio (ssms.exe) by the PsExec or PsExec service process. This behavior is indicative of administrative tools being used for potentially unauthorized remote execution or lateral movement.
Detects the use of the net.exe or net1.exe utilities to create a new user account with a hardcoded password string ('Numlock!123') in the command line. This is a common indicator of automated exploitation, credential hardcoding, or post-exploitation activity.
Detects the presence or installation of 'truesight.sys' or 'rentdrv2.sys' drivers, which are associated with malicious activity. The rule also triggers when system utilities like sc.exe or services.exe are used to set services related to these names to a 'demand' start type, indicating potential persistence or malicious driver loading.
Detects execution of PowerShell processes using the '-w hidden' argument and '-enc' (EncodedCommand) parameter, which is a common technique used by attackers to execute obfuscated code silently.
Detects modifications to the Windows Explorer RunMRU registry key where values contain suspicious commands such as 'powershell', 'curl', or long base64-encoded strings, indicating potential command execution or persistence attempts.
Detects the creation or modification of InprocServer32 registry keys within CLSID paths in HKEY_LOCAL_MACHINE. These registry locations are frequently abused by adversaries to achieve persistence or execute arbitrary code (COM hijacking) by pointing the server path to a malicious DLL or executable.
Detects access, reading, or modification of sensitive credential files (such as KeePass databases, VPN profiles, private SSH keys, and certificates) by a process. This behavior is often associated with pre-encryption staging for data exfiltration during ransomware attacks.
Detects instances where powershell.exe appears to be launched by explorer.exe via parent process ID (PPID) spoofing. The rule identifies processes where the reported parent explorer.exe was created at or after the child powershell.exe, or within a suspiciously short timeframe, indicating that the parent PID association is likely fraudulent rather than a genuine explorer-initiated shell.
Detects the creation of a scheduled task using the schtasks utility where the execution principal is set to SYSTEM. This pattern is commonly observed in malware such as DragonForce ransomware to establish persistence or execute payloads with elevated privileges.
Detects the execution of the s5cmd utility using 'cp' or 'sync' commands directed towards S3 storage paths. This behavior is indicative of unauthorized data exfiltration to attacker-controlled cloud storage, a tactic identified in intrusions associated with the 'Ransom Busters' group.
Detects the loading of rstrtmgr.dll by processes other than explorer.exe. Adversaries, particularly ransomware, utilize the Windows Restart Manager API (RmStartSession, RmRegisterResources, RmShutdown) to identify and forcibly terminate processes that hold file handles to files they intend to encrypt, thereby bypassing file-in-use locks.
Detects the execution of the 'net user' command with the '/add' parameter using the hardcoded password 'Numlock!123'. This pattern is frequently observed as a persistence mechanism employed by threat actors during ransomware operations to establish unauthorized administrative access.
Detects the execution of a renamed Microsoft CoreCLR Debugger (vsdbg.exe) from a directory outside of standard Visual Studio installation paths. This behavior is indicative of DLL side-loading, where a malicious vsdbg.dll is planted alongside the renamed vsdbg.exe, a technique observed in malware loader chains like Rapuncel/BoryptGrab.
Detects the execution of ServiceModelReg.exe following parent process activity involving vsdbg.dll/vsdbg.exe, coupled with cross-process access indicators consistent with COM Elevation Moniker UAC bypass and potential process hollowing. This pattern is associated with the PUROSANGUE loader chain used to execute malicious code within a high-integrity process context.
Detects the execution of ServiceModelReg.exe following parent process activity involving vsdbg.dll/vsdbg.exe, coupled with cross-process access indicators consistent with COM Elevation Moniker UAC bypass and potential process hollowing. This pattern is associated with the PUROSANGUE loader chain used to execute malicious code within a high-integrity process context.
Page 240 of 1871
