Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of PowerShell commands that attempt to retrieve hardware and OS-level system information using WMI queries or API-like indicators commonly used by reconnaissance tools.
This rule detects system calls originating from unbacked, private, or unknown memory regions, which is a common indicator of reflective code loading or process injection techniques. It also flags suspicious call stacks where standard processes like PowerShell, rundll32, or .NET execute system calls on ntdll.dll from non-standard module memory.
This rule detects the creation of named pipes commonly used by Cobalt Strike beaconing payloads (e.g., those starting with 'nb_', 'pivot_', or 'beacon_'). The detection excludes known system processes that might otherwise generate similar traffic, focusing on suspicious inter-process communication.
Detects the use of Windows API functions associated with token impersonation, such as ImpersonateLoggedOnUser and DuplicateTokenEx, or the RevertToSelf function, which can be indicators of token theft or privilege escalation attempts by an adversary.
Detects execution of known malicious files that subsequently interact with temporary directory debug logs and establish network listening sockets within a short timeframe. This behavior pattern is characteristic of post-exploitation activity, specifically the staging and operation of listener modules.
This rule detects the GHAPPIER multi-stage loader, typically observed in 'indexe.cjs' files. The loader fetches and executes a remote payload from a Vercel-hosted domain (primevector-app924560.vercel.app) using 'eval' on retrieved content, or matches specific payload identification tags.
Detects the execution of rundll32.exe with a command line containing 'DavWWWRoot', indicating the loading of a DLL payload directly from a remote WebDAV share. This behavior is commonly associated with ClickFix/ClearFake infection chains where users are tricked into executing malicious payloads hosted on attacker-controlled WebDAV servers.
Detects the presence of the known vulnerable DCRCVDrv.sys kernel driver, which has been identified as being abused in Bring Your Own Vulnerable Driver (BYOVD) attacks to terminate security processes via unauthorized IOCTL calls to ZwTerminateProcess.
Detects SMB traffic targeting the IPC$ share within the internal network, which is a common behavior of PIVOTPIPE lateral movement techniques using SMB named pipes for peer-to-peer (P2P) beacon communication.
Detects the PIVOTPIPE .NET loader, which identifies and extracts a 'core.pak' file containing the RAT payload. The loader performs XOR-decoding and GZIP-decompression to reflectively load the malicious payload into memory using .NET reflection methods, bypassing traditional file-based execution.
Detects the presence of the Amatera secondary-payload archive component, which consists of a legitimate signed Chrome executable (platform_experience_helper.exe) paired with a malicious NativeAOT-compiled Secur32.dll designed for DLL side-loading. The malicious DLL is identified by its interaction with the GetUserNameExW Windows API.
Detects a specific execution pattern associated with the PIVOTPIPE RAT involving two consecutive operator-issued commands. First, a process impersonation action (token theft/impersonation) is detected via PROCESS_OPEN activity, followed by a 'RevertToSelf' call within the same process context. This sequence indicates an attempt to temporarily shift privilege context to impersonate another user before returning to the original security context.
Detects the creation of a hidden file named '.git-checker' within system temporary directories (e.g., /tmp or \Temp\). This filename is often associated with adversary activity attempting to stage files, maintain persistence, or perform reconnaissance.
Detects execution of rundll32.exe with command line arguments containing WebDAV paths (DavWWWRoot), which is a common technique used to execute malicious DLLs from remote locations.
The detection rule monitors for access to files commonly used to store sensitive information, including .git-credentials, .netrc, and .gitconfig files configured to store credentials. Accessing these files is a common indicator of credential theft attempts by adversaries looking for plaintext authentication data to pivot to other systems or services.
Detects attempts to modify AMSI (Antimalware Scan Interface) provider registry keys or tampering with the amsi.dll file. These actions are indicative of efforts to disable or blind security instrumentation, often as a precursor to or during malicious code execution.
Detects the presence of specific debug log files ('nb_hook_dbg.txt', 'nb_sleep_dbg.txt', etc.) created within 'C:\WINDOWS\Temp\' by the PIVOTPIPE malware family. These artifacts are produced during the initialization of indirect syscall and sleep-mask evasion routines, serving as a proxy indicator for these stealthy execution techniques.
Detects the execution of known PIVOTPIPE beacon binaries by matching against specific file names and SHA256 hashes. These binaries are associated with post-exploitation activities and internal network pivoting.
Detects the execution of known PIVOTPIPE RAT binary files based on their SHA256 hashes or file names. PIVOTPIPE RAT is capable of token manipulation and impersonation techniques (e.g., ImpersonateLoggedOnUser, DuplicateTokenEx) to perform privileged operations or escalate security context.
Detects the creation of 'explorer.exe' originating from a source process other than known legitimate parent processes like 'userinit.exe', 'winlogon.exe', or 'services.exe'. This behavioral pattern is indicative of potential process hollowing or unauthorized process injection, which is a common vector for stealers like ZigCryptoStealer to gain a foothold before performing malicious activities such as clipboard manipulation.
Detects Node.js processes executing suspicious command lines that involve fetching and executing remote JavaScript code. This behavior is indicative of a loader or downloader script commonly used to pull and evaluate malicious payloads at runtime, specifically referencing indicators associated with 'GHAPPIER'.
Page 244 of 1871
