Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects rare or infrequent network connections to common VPN and tunneling ports (e.g., 500, 4500, 1194, 1723) initiated by known VPN clients or web browsers. This rule identifies potential unauthorized external remote access or tunneling behavior by baselining against connections seen in the previous 30 days and filtering for low-frequency events.
Detects techniques used by SloppyRAT, including indirect NTDLL syscalls bypassing API hooks (Hell's Gate style), and the use of DJB2 API hashing for NtAllocateVirtualMemory and NtCreateThreadEx. It monitors for CallTrace patterns indicating unbacked memory calls into ntdll.dll, detection of hardcoded DJB2 hash constants, or the presence of the B8 (mov eax, imm32) instruction followed by the 0F 05 syscall opcode.
Detects evidence of the Alinubx.sys kernel driver being loaded or interacted with via its device interface using a specific IOCTL (0x222024). This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, effectively bypassing Windows Protected Process Light (PPL) protections.
Detects evidence of the Alinubx.sys kernel driver being loaded or interacted with via its device interface using a specific IOCTL (0x222024). This driver is known to be abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security software processes from kernel mode, effectively bypassing Windows Protected Process Light (PPL) protections.
This rule detects the execution of the legitimate Microsoft Visual Studio CoreCLR Debugger (vsdbg.exe) from an unauthorized file location. This behavior is indicative of masquerading, where the executable is renamed to appear as an installer to sideload a malicious companion vsdbg.dll, a technique observed in the Rapuncel/BoryptGrab campaign.
Detects the creation of a PowerShell process that identifies itself as being spawned by explorer.exe, while the process ID (PID) and parent process ID (PPID) relationship indicates inconsistency, often characteristic of the PSSpoof technique used by malware like SloppyRAT to evade detection by spoofing the process tree.
Detects attempts by malicious software, specifically SloppyRAT, to query or modify Microsoft Defender settings by interacting with WMI classes like MSFT_MpPreference or MSFT_MpComputerStatus. This activity is indicative of efforts to disable security controls such as real-time monitoring to facilitate further malicious actions.
Detects evidence of SloppyRAT employing the Hell's Gate technique, specifically the resolution and indirect invocation of low-level NT system calls (e.g., NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx) designed to bypass EDR user-mode API hooking during process injection activities.
Detects instances where a user signs in via a Device Code authentication flow and subsequently adds a member to a highly privileged group (e.g., Domain Admins, Global Administrators) within one hour. This behavior is indicative of potential account compromise where an attacker uses an OAuth device code flow to establish access and then escalates privileges.
Detects the mass termination of multiple security-related processes on a host within a short timeframe, correlated with the presence of specific driver modules potentially associated with security software interference or evasive behavior.
This rule monitors network and event logs to detect instances where a single user account, logged into a specific host, initiates connections to two or more distinct, potentially suspicious remote IP addresses. This pattern of multi-destination connection activity may indicate command and control communication, scanning behavior, or data staging.
Detects suspicious device registration or join events occurring within 60 minutes of a Device Code authentication flow. This pattern is consistent with the ARToken post-compromise technique, where an adversary uses an intercepted authentication code to register a new device to maintain persistent access to an Entra ID (Azure AD) environment.
Detects instances where processes other than legitimate PowerShell binaries load the .NET Common Language Runtime (clr.dll) or the System.Management.Automation assembly. This behavior is often indicative of 'PowerShell-less' execution techniques, where adversaries interact with the PowerShell engine directly from arbitrary host processes to execute malicious code or scripts.
Detects the deletion of Google Chrome browser extension settings from the Windows Registry. Adversaries often target the 'extensions.settings' registry value under 'PreferenceMACs' to disable security extensions, force the installation of malicious extensions, or tamper with browser-based security controls.
This rule detects the installation of a new Windows service (Event ID 7045 or 4697) with an 'auto start' configuration that is immediately followed by the termination of multiple processes (either 'services.exe' or the service's own image file) within a 60-minute window on the same host. This pattern can indicate an unstable or malicious service deployment that causes system instability or performs rapid cleanup.
This rule detects indicators of the Rapuncel browser injection by monitoring for the creation of a known malicious DLL hash on disk, identifying non-standard parent processes invoking elevation_service.exe, and detecting the loading of unrecognized DLLs into Google Chrome or Microsoft Edge browser processes.
Detects potential UAC bypass attempts using COM Elevation Monikers or the misuse of ServiceModelReg.exe, often associated with process hollowing techniques.
Detects potential reflective code loading or memory injection attempts within Python interpreter processes (pythonw.exe, ipy.exe). The rule monitors for processes that lack a valid module path or file path on disk while referencing known indicators of malicious memory-based loading, such as 'hostfxr.dll' or specific suspicious strings like 'DLLMemLoader'. This technique is often used to execute payloads directly in memory to evade file-based security controls.
This rule detects suspicious process activity in interpreters (ipy.exe, pythonw.exe) or rundll32.exe involving multiple, rapid consecutive calls to sensitive memory management and thread creation functions (e.g., NtAllocateVirtualMemory, NtWriteVirtualMemory, NtCreateThreadEx). The logic specifically monitors for a high frequency of distinct, powerful Windows API calls, which is often indicative of reflective code injection or process hollowing, including techniques like 'Hell's Gate' or those associated with SloppyRAT, and accounts for potential .NET/hostfxr-related execution vectors.
Detects the execution of processes containing indicators associated with Alinubx or the string 222024, which are potentially linked to malicious software or unauthorized tools.
This rule detects the execution of the Visual Studio Debugger (vsdbg.exe) from suspicious locations such as Downloads, Temp, or Desktop directories. Executing development tools from these user-writable directories is often indicative of an adversary attempting to use legitimate debugging tools to facilitate process injection or malicious activity. The rule excludes legitimate executions located within the official Microsoft Visual Studio installation directory.
Page 241 of 1871

