Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects malicious staging and C2 activity characteristic of RatHat Android malware. The rule identifies processes running under the Android shell user (UID 2000) that execute specific tools (minicap, minitouch, or disguised libraries) from the /data/local/tmp directory, followed by an outbound network connection, which is indicative of a persistence mechanism and reverse-tunneling command-and-control communication.
Detects the NeedyMantis second-stage loader, typically encountered as a malicious script (e.g., encryptbase64.ps1). The detection identifies raw shellcode residing in files that exhibit specific traits: PEB-walking for API resolution using a ROR(11) hashing algorithm, the inclusion of the 'RtlDecompressBuffer' API for payload expansion, and the absence of standard PowerShell script headers at the start of the file.
Detects evidence of the Rapuncel infostealer attempting to compromise Chrome or Edge browsers. The rule identifies suspicious image loads into browser processes linked to known malicious hashes or the creation of specific browser decryption log files used by the malware to defeat App-Bound encryption.
Detects Android applications that request Device Admin privileges followed by the execution of coercive commands, such as disabling biometric authentication, setting admin passwords, or enabling uninstall protection. This behavior is indicative of malicious applications (e.g., RatHat) aiming to establish persistence and prevent uninstallation by the user or security software.
Detects NeedyMantis malware loader components that utilize the RtlDecompressBuffer API for custom XOR-compressed archive extraction. The rule specifically looks for the presence of known staged file names (dnsapi.dll, ws2_32.dll, msvcrt140.dll, or encryptbase64.ps1) alongside decoy file references typically used by the threat actor.
Detects the NeedyMantis malware component loading configuration and communications modules (specifically dnsapi.dll or ws2_32.dll) from a non-standard system directory. This behavior is indicative of DLL hijacking or side-loading, where a malicious library is substituted for a legitimate Windows system library to facilitate command and control or malicious execution.
Detects persistence mechanisms associated with 'ComponentTask33Agent' which involves either creating a scheduled task or modifying Windows Registry Run keys, alongside potential VBScript-based agent execution via wscript.exe.
Detects the creation of Windows services by known binary hosts frequently utilized by NeedyMantis for DLL sideloading. This activity is indicative of the persistence phase where the actor's 'is' module registers itself as a service to ensure survival across system reboots following the execution of the sideloading chain.
Detects a specific privilege escalation and code execution chain attributed to the PUROSANGUE methodology. This activity involves using a COM Elevation Moniker (specifically with the 'Elevation:Administrator!new:' syntax) to bypass UAC, followed by process hollowing into ServiceModelReg.exe. The attack is initiated from unconventional parent processes such as vsdbg.exe or its associated DLL.
Detects NeedyMantis first-stage loader activity where a legitimate application (e.g., Poedit, curl, Vim, TightVNC) is executed to load an update or support DLL from a non-standard staging path (e.g., %ProgramData% subdirectories), followed by the presence of a co-located encrypted second-stage archive.
Detects the ChainScript RAT, executing via a masqueraded Node.js process, enumerating Local Extension Settings for browser wallet plugins. This reconnaissance activity is a precursor to exfiltrating crypto wallet data.
Detects specific Android device admin command sequences that indicate attempts to establish persistent access by hardening the device against removal (e.g., enabling uninstall protection, setting device admin passwords, disabling biometrics) or destructive actions like performing a factory reset or self-uninstallation.
Detects the spawning of script interpreters or loaders by Visual Studio Code (Code.exe) shortly after a workspace is initialized, specifically looking for command-line arguments referencing .vscode or tasks.json. This behavior is consistent with exploitation techniques where a user accepts a 'Trust Workspace' prompt, allowing malicious tasks defined in a repository's .vscode folder to execute.
Detects DNS queries for RatHat C2 panels using characteristic naming patterns and specific malicious domains, as well as outbound network connections to known RatHat C2 IP infrastructure.
Detects network traffic from mobile devices to the Google Gemini API (generativelanguage.googleapis.com) specifically targeting the 'generateContent' endpoint. This behavior is indicative of mobile malware (e.g., RatHat/PromptSpy) that may be utilizing AI-assisted UI-automation, potentially to exfiltrate screen content or automate malicious interactions by processing visual layout data through a generative model.
Detects behavior associated with the TeamFiltration backdoor, where a user account downloads a file from OneDrive, modifies or replaces that file, and re-uploads it within a short timeframe (30 minutes). This pattern is consistent with the 'taint shared content' technique used to distribute malicious files through legitimate cloud storage.
Detects specific malicious archive payloads associated with NeedyMantis that contain a second-stage loader and spoofed system DLLs (e.g., dnsapi.dll, ws2_32.dll, msvcrt140.dll). These archives utilize XOR encoding or RtlDecompressBuffer packing and are designed for DLL sideloading.
Detects network traffic from mobile devices to the Google Gemini API (generativelanguage.googleapis.com) specifically targeting the 'generateContent' endpoint. This behavior is indicative of mobile malware (e.g., RatHat/PromptSpy) that may be utilizing AI-assisted UI-automation, potentially to exfiltrate screen content or automate malicious interactions by processing visual layout data through a generative model.
Detects the NeedyMantis first-stage loader (e.g., WinSparkle.dll variants) which employs anti-debug techniques such as NtQueryInformationProcess and ThreadHideFromDebugger, alongside stack-based string deobfuscation, to prepare for the extraction and execution of a secondary payload (e.g., encryptbase64.ps1).
Detects HTTP traffic patterns associated with a custom 'RatHat' malware variant utilizing Google's Gemini API for command and control or remote automation. The rule identifies the initial POST request to the API with specific generation parameters (temperature 0.1, 256 tokens) and the corresponding JSON-formatted coordinate response from the server.
Detects a potential TeamFiltration-style compromise where multiple accounts with no history of successful authentication and no MFA enforced authenticate successfully within a 7-minute burst window. This behavior is indicative of an adversary mass-testing or accessing newly compromised dormant or un-secured service accounts.

