Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where AI-based coding or agent-driven tools (e.g., Cursor, Claude Code, AutoGPT) perform suspicious file archiving/packaging activities followed by network egress to unauthorized or known exfiltration-prone services. This helps identify potential data exfiltration by AI agents or compromised development environments.
Detects instances where AI coding and agent tools (e.g., Claude Code, Cursor, Copilot CLI, Ollama, LangGraph) create archive or database files containing potentially sensitive data and subsequently initiate network connections to non-AI-provider or non-developer services (exfiltration services or non-standard port connections).
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects file, process, and network activity associated with the TraderTraitor/KelpDAO malware campaign based on known hashes, filenames, paths, and C2 infrastructure.
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects AI coding assistants and LLM agent frameworks spawning shell processes or interpreters to execute potentially malicious commands. The rule monitors for suspicious activity often associated with download cradles, credential access, reconnaissance, or persistence, while excluding standard interactive terminal usage.
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
Detects suspicious process execution patterns associated with RMMCRAT, where the Windows SmartScreen process (smartscreen.exe) spawns cmd.exe, which subsequently launches PowerShell with specific parameters for piped input/output. This behavior is characteristic of malicious code injection and command-and-control activity.
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
Detects parent process ID (PPID) spoofing associated with RMMCRAT and other HVNC malware, where an injected process (e.g., smartscreen.exe) spawns child processes while spoofing explorer.exe as the parent. The rule monitors for a mismatch between the reported parent (explorer.exe) and the actual creator (smartscreen.exe) and focuses on burst activity of common shell and browser processes.
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
Detects indicators of RMMCRAT malware installation, which masquerades as JivaChat software. The rule identifies suspicious process execution (e.g., rmm.exe), specific file artifacts created in ProgramData, and persistence mechanisms including Windows service registration, 'Load' registry value abuse, and a unique COM CLSID hijack. The logic enforces corroboration across different signal types (process, file, registry) or triggers on the unique CLSID.
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
Detects PavokwiLoader behavior where a potentially malicious process spawns a browser or system process (e.g., smartscreen.exe) in a suspended state, followed by cross-process memory allocation and writing, and subsequent thread hijacking or execution resumption, indicating a process hollowing injection technique.
Detects the loading or installation of specific NVIDIA file system filter drivers ('Alinubx.sys', 'CcProtect.sys', 'nvfsflt64.sys') or services related to the 'NvFsFilter'. These drivers are associated with NVIDIA driver components; however, they can be targeted for unauthorized usage or mimicry.
Detects instances where the Visual Studio Debugger (vsdbg.exe) spawns a child process that is not expected, such as common VS diagnostic tools or standard Microsoft/Windows binaries. This is used to identify potential process injection or abuse of the debugger for executing unauthorized payloads.
Page 246 of 1871

