Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects Node.js processes executing command lines containing known malicious indicators or accessing specific suspicious JavaScript files (e.g., sharedLoad.min.js) associated with malicious loaders or hardcoded cryptographic keys.
Detects the loading of radcui.dll by the WkspBroker.exe process when the DLL is located within a path associated with Microsoft RemoteApp Gateway, which is often indicative of DLL sideloading or execution hijacking of a legitimate process.
Detects the execution of known remote access and support tools on a host shortly after an email bombing or spam flood alert has been generated for the same user. This pattern is commonly associated with social engineering campaigns where attackers overwhelm a user's inbox to distract them while coercing them into running remote support software to 'resolve' the issue.
This rule detects network connections or DNS queries to known typosquatted and malicious domains associated with the SilverFox campaign. These domains impersonate legitimate software (e.g., SteelSeries GG, Bcut, DeepSeek) to lure users into downloading malware via SEO poisoning and deceptive downloads.
Detects the presence of a hardcoded X25519 public key associated with the 'indexed-btree' npm malware loader. This loader uses the key for ECDH key derivation to decrypt secondary payloads retrieved from an Ethereum smart contract, a technique used by malicious packages to hide their functionality.
Detects the execution of 'wkspbroker.exe' or the loading of 'radcui.dll' from a non-standard, user-writable directory path ('AppData\Local\Microsoft\RemoteApp\Gateway'). This behavior is indicative of DLL sideloading or execution of potentially malicious or unauthorized binaries masquerading as legitimate Windows remote connectivity components.
Detects the execution of AnyDesk shortly after a Microsoft Teams meeting or call initiation on the same host. This pattern is commonly observed in social engineering attacks where an adversary convinces a user to use remote access software during a live support or phishing call.
This rule detects a multi-stage attack chain targeting a single user within a 2-hour window. It identifies the combination of email bombing (a distraction technique), an incoming external or anonymous Teams call (social engineering channel), and the installation of common remote access tools (e.g., AnyDesk, TeamViewer) on the same host.
This rule detects a multi-stage attack chain targeting a single user within a 2-hour window. It identifies the combination of email bombing (a distraction technique), an incoming external or anonymous Teams call (social engineering channel), and the installation of common remote access tools (e.g., AnyDesk, TeamViewer) on the same host.
This rule monitors for suspicious Node.js process activity, specifically focusing on the loading of scripts associated with obfuscated or malicious packages (e.g., sharedLoad.min.js, indexed-btree) and the use of child_process spawn patterns that indicate detached, hidden, or unreferenced child processes, which are common tactics for bypassing detection or maintaining stealthy execution.
Detects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts
Detects the modification of network interface IP addresses using netsh or PowerShell cmdlets. This activity can be associated with unauthorized network configuration changes, static IP assignment for persistence, or evasion techniques.
This rule detects activity associated with the 'Ghostcode' threat campaign by monitoring multiple telemetry sources. It identifies connections to known malicious IP addresses and domains, patterns consistent with phishing kit hosting, and specific URL structures used in credential harvesting or payload delivery. The rule correlates sign-in logs, device network events, DNS queries, and email telemetry to identify potential compromise.
Detects usage of the 'finger' utility via command line within scripts or batch files, or network connections originating from the 'finger' process on port 79 to non-internal destinations. This activity is commonly associated with internal network reconnaissance to gather user information or system details.
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
This rule detects non-standard processes attempting to access sensitive web browser files (e.g., 'Login Data', 'Cookies', 'key4.db') that are typically only accessed by legitimate web browsers. It excludes known browser processes and trusted security or sync applications to identify potential credential theft attempts.
This rule detects non-standard processes attempting to access sensitive web browser files (e.g., 'Login Data', 'Cookies', 'key4.db') that are typically only accessed by legitimate web browsers. It excludes known browser processes and trusted security or sync applications to identify potential credential theft attempts.
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
Detects file artifacts referencing InvisibleFerret, a Python-based backdoor used by WaterPlum/North Korean IT worker actors for persistent access to victim networks
Detects file artifacts referencing InvisibleFerret, a Python-based backdoor used by WaterPlum/North Korean IT worker actors for persistent access to victim networks
Page 250 of 1871




