Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects attempts to bypass Windows User Account Control (UAC) by identifying processes that use specific command-line arguments (such as /Elevation:Administrator, /shell:RunAs, or /runas /savecred) combined with known binaries (such as vsdbg, rundll32, or cmstp) often abused to achieve elevated privileges or proxy execution of malicious code.
Detects the installation of Windows services with image paths containing strings associated with known commodity malware or potentially unwanted software (Alinubx, CcProtect, nvfsflt64, NvFsFilter). This activity is often indicative of persistence mechanisms or driver-based malicious components being registered on the host.
Detects suspicious process injection, module loads, or thread creation events where a web browser process (chrome.exe or msedge.exe) is the target, excluding known legitimate browser-related processes or sub-components like the elevation service.
This rule detects potential security software tampering by identifying the loading of a specific driver (Alinubx.sys) followed by the termination or interference of common security agent processes within a short timeframe. This behavior is indicative of an adversary attempting to disable endpoint protection using a Bring Your Own Vulnerable Driver (BYOVD) or malicious driver approach.
Detects the loading of the hostfxr.dll module, the presence of the DLLMemLoader string in command lines, or the execution of python or pythonw processes. These patterns are often associated with the loading of malicious assemblies or execution via scripting environments.
Detects the execution of the legacy 'finger.exe' network utility with suspicious command-line arguments. The finger protocol is an outdated service that provides information about users on a system; adversaries may abuse this utility to perform network reconnaissance, identify user accounts, or gather system-level information.
Detects the loading of the System.Management.Automation.dll (PowerShell assembly) by processes other than standard PowerShell executable files. This behavior often indicates an attempt to execute PowerShell code from a non-standard process, potentially to bypass security controls or obfuscate malicious activity.
Detects the execution of network utilities like finger.exe or curl.exe (with download parameters) initiated by a command shell (cmd.exe, powershell.exe, or pwsh.exe). This pattern is often used by adversaries for reconnaissance or downloading malicious payloads.
Detects the execution of Python processes where command line arguments indicate the use of the DLLMemLoader agent or related indicators like 'hostfxr' or specific hex strings. This activity is often associated with the loading of malicious DLLs or secondary stages in an attack chain.
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden window, download strings, or invocation commands) initiated by Windows Explorer. This is a common pattern for malicious scripts or droppers attempting to execute code covertly.
Detects when a high volume of distinct security-related processes or services are terminated on a single host within a 2-minute window. This behavior is strongly indicative of an adversary attempting to disable endpoint protection software as part of a post-compromise defensive evasion effort.
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
Detects a process that deletes its own executable or script file within a short time window after launch, which is a technique used by some implants.
Detects instances where a parent Node.js process spawns a child Node.js process using a command line structure often associated with malicious npm packages. These packages frequently attempt to execute loader scripts in a detached or background manner to evade detection while maintaining persistence or performing malicious operations.
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
Detects suspicious PowerShell commands involving node.js, hidden window styles, and file downloads or transfers.
Detects creation of a token.cmd file in AppData followed by its execution via cmd.exe within a 5-minute window.
Page 247 of 1871

