Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects instances where a Node.js process spawns a child Node.js process from a 'node_modules' directory using configuration flags typically associated with hidden, detached background tasks (e.g., 'detached', 'stdio', 'windowsHide', 'ignore'). It explicitly excludes common Node.js process managers and build tools to reduce false positives associated with legitimate development activities.
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
Detects Microsoft Defender (MsMpEng) performing scan or remediation actions against non-standard filesystem paths, specifically NT object-manager namespace paths or CLFS-driver-prefixed paths. This behavior is indicative of an exploitation attempt (e.g., CVE-2026-69414) where an attacker uses symbolic links and CLFS driver namespaces to redirect the Defender scanning engine to arbitrary files on the system, potentially allowing file reads as SYSTEM.
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.
This rule detects the execution of a specific batch file named 'Right-click to open Invoice Details.bat', or execution of a batch file matching a known malicious SHA256 hash associated with AsyncRAT distribution campaigns.
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. The investigation exposed the attacker’s admin panel, affiliate network, phishing infrastructure, and thousands of stolen credentials and session cookies, revealing how modern AiTM attacks can hijack authenticated sessions even after MFA.
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
This rule monitors endpoint network events, file events, and process executions for indicators associated with the Kamasers malware. It specifically looks for connections to known malicious C2 IP addresses and domains, as well as the presence or execution of files matching known malicious SHA256 hashes.
This rule detects non-browser processes initiating network connections to common file-sharing or cloud services (e.g., GitHub Gist, Telegram, Dropbox) followed by subsequent network activity from the same process within a 5-minute window. This behavior is indicative of potential command and control (C2) communication, payload retrieval, or data staging/exfiltration using legitimate web services.
Detects the execution of PowerShell commands initiated from a .lnk file that query system information related to virtualization technologies (e.g., VMware, VirtualBox, Hyper-V) or hardware details (e.g., BIOS, VideoController). This pattern is often used for environmental awareness or anti-sandbox/anti-analysis techniques by malware.
Detects access to sensitive browser credential storage files (Login Data, key4.db, logins.json) by unauthorized processes. This behavior is indicative of credential theft, where an adversary attempts to extract stored passwords from browser profiles.
Detects instances where a process named firefox.exe attempts to modify or create a registry run key, which is a common persistence technique, but the process file path does not correspond to the legitimate Mozilla Firefox installation directory. This behavior often indicates that an attacker is masquerading as a legitimate browser process to establish persistence.
Detects files that contain a valid RTF file header but also contain signatures indicative of embedded non-RTF content such as PE executables, ZIP archives, or OLE objects. This technique is often used to masquerade malicious payloads as benign document files.
Detects potential local privilege escalation via Windows ALPC (Advanced Local Procedure Call) heap-based buffer overflow by identifying a non-SYSTEM Chrome process tree spawning child processes with SYSTEM privileges. The rule specifically monitors for suspicious child binaries or paths characteristic of exploit payloads while excluding legitimate Chrome update and crash handler processes.
This rule identifies the Stella_Gary modular C# backdoor framework, which has been attributed to the Kimsuky (APT-C-55) threat group. The rule functions by detecting specific naming conventions within the binary and the presence of .NET assembly loading capabilities combined with plugin management functionality, characteristic of this modular malware family.
Detects the execution of PowerShell with suspicious command-line arguments (e.g., -enc, -nop, -windowstyle hidden) originating from an LNK file launched by explorer.exe. This pattern is commonly used by adversaries to execute obfuscated malicious payloads embedded within shortcut files.
This rule detects non-browser processes attempting to access sensitive web browser credential files, such as 'Login Data', 'logins.json', and 'key4.db'. Such activity is highly characteristic of credential-stealing malware (including BabylonRAT) attempting to exfiltrate stored passwords or session data from Google Chrome or Mozilla Firefox profiles.
Detects unauthorized processes attempting to access browser credential database files such as Login Data for Chromium-based browsers or logins.json and key4.db for Firefox. The rule filters out known browser processes to isolate potential credential harvesting or exfiltration activity.
This rule detects PowerShell commands that utilize specific character array joining techniques (e.g., [char]nnnn -join '') often used to obfuscate malicious strings or bypass keyword-based security filters. This is a common tactic for evading detection when downloading or executing payloads.
Detects the execution of PowerShell with common obfuscation or stealth-related flags (e.g., -enc, -nop, -w hidden) when initiated by CMD or from a LNK file, particularly when originating from Windows Explorer. This is a common pattern for malicious file execution and dropper activity.
Page 252 of 1871




