Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects file artifacts referencing InvisibleFerret, a Python-based backdoor used by WaterPlum/North Korean IT worker actors for persistent access to victim networks
Detects file artifacts referencing InvisibleFerret, a Python-based backdoor used by WaterPlum/North Korean IT worker actors for persistent access to victim networks
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
Detects the initialization of known-malicious Terraform providers (dockerd) followed within one hour by the execution of a 'go run' process from the .terraform directory. This pattern is indicative of a supply chain compromise where an adversary leverages a typosquatted or malicious Terraform provider to facilitate the execution of a secondary payload.
Detects the mounting of a USB storage device on an endpoint, which can be a precursor to data exfiltration or the introduction of malicious files.
This rule detects interaction with specific infrastructure identified as deceptive dating applications. It monitors network communication, sign-in attempts, email interactions, and endpoint execution associated with known malicious domains (e.g., archat.us, heyhru.com, sitin.ai), specific IP addresses (38.129.138.244), and unique package identifiers (com.cavalier.nalo, com.qiga.vio). The detection logic spans across DeviceNetworkEvents, EntraIdSignInEvents, EmailUrlInfo, EmailEvents, DeviceEvents, and DeviceProcessEvents to identify exposure to these Indicators of Compromise (IOCs) across both network and endpoint layers.
This rule monitors for network and email activity associated with known fraudulent AI reseller infrastructure. It aggregates data from device network connections, email URL inspections, and email header analysis to identify potential interactions with malicious domains known to facilitate AI-related fraud.
Detects the malicious OIC_Invitation_General_Official.lnk sample used as the entrypoint for PlugX infection chain
Detects execution of the PlugX side-loaded host process (Jarte.exe / GRrte.exe) from the JartePortable directory. This process performs in-memory host/system profiling (GetComputerNameW, GetVersionEx, system directory queries) via the decoded PlugX core (T1082), which is not directly visible as command-line telemetry.
Detects the execution of known Jarte-derived host processes (GRrte.exe or Jarte.exe) which are commonly leveraged as side-loading proxies for the PlugX remote access trojan. The rule flags the process initiation as a proxy indicator for the subsequent execution of PlugX's modular payload, which performs system enumeration and process discovery.
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
Detects the execution of npm commands to install specific, potentially malicious or typo-squatted npm packages. The rule filters for common npm install command line arguments and matches against a predefined list of package names that are often associated with supply chain compromise attempts.
This rule detects potentially malicious child processes spawned by Node.js. It specifically monitors for scenarios where a Node.js process executes a detached child process using standard library options ('detached', 'stdio', 'windowsHide', 'ignore'), which is a common technique used by malware to run background tasks while remaining hidden from the parent process terminal. The rule excludes common benign development, build, and process management tools to reduce false positives.
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
Page 251 of 1871



