Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects creation of .git-checker files in temporary directories, a pattern associated with potential malicious activity.
Detects creation of .git-checker files in temporary directories, a pattern associated with potential malicious activity.
Detects creation of .git-checker files in temporary directories, a pattern associated with potential malicious activity.
Detects a Node.js process spawning a detached, hidden child node.exe process from within a node_modules directory, a technique observed in the indexed-btree npm supply-chain malware to establish a stealthy runtime loader.
Detects the GHAPPIER loader pattern: a top-level require('https').get() call to the primevector-app924560.vercel.app C2 that evals the response, disguised inside a large benign-looking JavaScript benchmark file
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
Detects the PolinRider/GHAPPIER campaign signature of a malicious loader payload silently appended to the end of a legitimate project configuration file
Detects the GHAPPIER loader payload concealed as a single line deep inside a large (~99KB) legitimate-looking JavaScript file, fetching and eval'ing remote code
Detects the GHAPPIER loader payload concealed as a single line deep inside a large (~99KB) legitimate-looking JavaScript file, fetching and eval'ing remote code
Detects the GHAPPIER loader payload concealed as a single line deep inside a large (~99KB) legitimate-looking JavaScript file, fetching and eval'ing remote code
Detects the GHAPPIER loader payload concealed as a single line deep inside a large (~99KB) legitimate-looking JavaScript file, fetching and eval'ing remote code
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
Detects the GHAPPIER loader identified across 65 public npm/GitHub repositories and 22 developer accounts, based on its embedded remote-fetch/eval pattern and campaign markers
Detects malicious code within the BTree.prototype.set function designed to trigger a secondary payload (sharedLoad.min.js) at runtime. This behavior is intended to bypass npm install-script scanning by embedding the logic within legitimate-looking library code and using Node.js child_process spawns with hidden parameters to maintain persistence and execution.
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
Page 248 of 1871

