Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
Detects instances where a process deletes its own executable or script file within 15 seconds of being launched. This behavior is often associated with self-modifying implants, transient scripts, or malicious artifacts attempting to minimize their footprint on the host system immediately after execution.
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
Detects the creation of files named '.git-checker' within common temporary directories. This behavior is often associated with staging or persistence mechanisms used by malware or malicious scripts to track execution or environment status.
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
Detects the creation of a file named 'token.cmd' within the user's AppData\Roaming directory, followed immediately by the execution of that same file via 'cmd.exe'. The rule filters for specific file size characteristics to reduce noise.
Detects the execution of signed, Microsoft-publisher binaries that are located in typically user-writable or suspicious directories (e.g., AppData, ProgramData, Temp, Users) when initiated by cmd.exe or powershell.exe with an argument indicating a batch file reference. This pattern is indicative of potential masquerading or living-off-the-land techniques where a signed binary is moved or executed from an unconventional location to bypass security controls or execution policies.
This rule detects the execution of the Xray proxy utility (xray-core) when launched by the RemoteApp workspace broker process (wkspbroker.exe) or located within the RemoteApp Gateway application data folder. This behavior is indicative of an adversary using proxy tools to facilitate command-and-control communication or network traffic tunneling via trusted remote access infrastructure.
Detects the modification of InProcServer32 registry keys within the user's Classes/CLSID hive to point to a file located in the AppData directory. This pattern is commonly used for COM hijacking to achieve persistence or execute arbitrary code under the user's context.
Detects the 'sharedLoad.min.js' loader script associated with the malicious 'indexed-btree' npm package family. This script utilizes X25519 ECDH for key exchange and AES-256 decryption to retrieve and execute a second-stage payload hosted on a Sepolia smart contract.
Detects the execution of Node.js processes where the command line contains references to specific strings potentially associated with malicious packages or libraries often used in supply chain attacks or obfuscated payloads.
Detects file removal, write, or rename operations performed by the Node.js process within the 'node_modules' directory, specifically targeting sensitive files like 'sharedLoad.min.js' or paths containing 'extended' or 'btree'. This behavior is indicative of potential malicious activity related to software supply chain compromise or unauthorized modification of dependencies within a Node.js application environment.
Page 249 of 1871

