Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects suspicious process command-line activity on devices identified as ATMs. It looks for known malware-related executables (CSCSERVICE.EXE) and common ATM software components (DISPENSR, XFS, MSXFS, AGILIS, APTRA, PROCASH, *.xfs) being executed or initiated by unusual processes like svchost.exe, rundll32.exe, or regsvr32.exe. This activity could indicate an attempt at ATM jackpotting or other unauthorized access.
This rule monitors network traffic and internal logs for connections to known malicious IP addresses or domain names associated with 'ClickFix' social engineering campaigns (often impersonating services like HBO Max). The logic explicitly filters out known threat intelligence scanners and security researcher probes. It performs correlation by requiring domain/message matches for generic IP-based alerts to reduce noise, and aggregates events per host over 15-minute windows to produce consolidated alerts.
Detects network communication with domains and IP addresses known to be associated with 'ClickFix' social engineering campaigns (specifically those masquerading as legitimate HBO Max or macOS related updates). The rule applies a strict correlation between observed malicious IP traffic and specific DNS requests to reduce noise from IP address reuse or threat intelligence feed probes, while also excluding known security-related processes.
This detection rule identifies what are the sensitivity-labeled files present on a specified device using the DeviceFileEvents table in Microsoft Defender for Endpoint.
You can run this query to quickly determine whether a compromised device contains any files with sensitivity labels during investigation.
You can run this query to quickly determine whether a compromised device contains any files with sensitivity labels during investigation.
Detects a suspected malicious activity pattern known as the Veltrix Capital fake job-lure. The rule monitors for a sequence where a user clones a job-task repository (containing 'veltrix-capital' in the command) followed by the installation of a suspicious dependency (using names like 'graph*' or 'big*' with npm or pip) within a 30-minute window on the same device.
Detects a specific loader sequence associated with the DarkMe malware/Water Hydra threat actor. The rule monitors for the execution of rundll32.exe with the /sta flag and a specific CLSID, followed by the presence or execution of targeted applications (cryptocurrency wallets, password managers, and system utilities) within a 15-minute timeframe. This sequence is indicative of the malware enumerating potential targets on the infected host before proceeding with malicious activity.
Detects execution of the Go runtime invoking a local module ('go run .') initiated by infrastructure-as-code tools like Terraform or standard command-line interpreters. This pattern matches the behavior of the Graphalgo RAT, which uses a hash-gated mechanism within malicious modules to trigger a second-stage payload.
Detects instances where a process other than a known legitimate web browser attempts to read or enumerate files within the MetaMask browser extension directory or related local settings. This behavior is indicative of a Remote Access Trojan (RAT) or information-stealing malware performing reconnaissance to target cryptocurrency wallet data stored within the browser's profile.
Detects a suspicious sequence where a Go toolchain is used to fetch dependencies, followed by a 'go run' execution that spawns a child process which initiates an outbound network connection shortly thereafter. This behavior is indicative of a 'hidden entry point' pattern where legitimate development tools are abused to download, compile, and execute a second-stage remote access trojan (RAT) or malicious payload.
Detects the installation of known malicious npm or PyPI packages followed within 30 minutes by the execution of a package manager (node or python) performing network activity. This pattern matches the behavior of downloader stages in the 'Graphalgo' campaign, which uses coding-task lures to trick users into installing malicious packages.
This rule detects internal network activity (DNS queries, network connections, and security logs) communicating with domains associated with the GhostCode phishing kit. These domains are typically used to host credential harvesting pages or phishing infrastructure.
Detects Bird Agent malware samples that exhibit characteristic behavior of binding configuration decryption to the Windows MachineGuid registry value. The rule identifies binaries that contain references to 'config.toml' and the Windows Cryptography registry key used to retrieve the MachineGuid, often used as a unique machine-based key for decryption.
Detects the execution of common command-line and scripting tools initiated by ScreenConnect (ConnectWise) remote administration processes. This pattern often indicates unauthorized remote access, lateral movement, or post-compromise activity where legitimate administrative software is abused to run arbitrary commands.
This rule detects the execution of Mimikatz or the use of its common command-line arguments, which are indicative of credential dumping and post-exploitation activities. It monitors process creation events for the 'mimikatz.exe' binary or command-line patterns associated with credential theft techniques such as dumping LSASS memory, extracting passwords, or Kerberos ticket manipulation.
This rule detects a sequence of suspicious events related to the 'ENCFORGE' threat actor or toolset. It monitors for evidence of initial access (via validation/code API calls), command and control communication (to specific IP/port), and destructive impact, correlating these activities within a 4-hour window on the same host.
Detects instances where the ScreenConnect remote access client processes perform file creation or modification actions that are not preceded by or correlated with legitimate session activity logs (such as 'SessionConfirmed' or 'TransferFiles') within a 5-minute window. This behavior may indicate an unauthorized remote session or abuse of the remote access tool.
Detects instances where a service account (indicated by a trailing $ in the username, excluding computer accounts) authenticates to three or more distinct hosts within a short time frame. This behavior is indicative of potential lateral movement or automated discovery activities using a compromised service credential.
Detects the execution of powershell.exe or cmd.exe with a combination of -NonInteractive, -NoProfile, and -Command arguments. This combination is frequently used by adversaries to execute scripts or commands stealthily, without user interaction or loading profile configuration files, which is a common behavior during the execution phase of an attack.
Detects instances where the ScreenConnect remote support client initiates outbound network connections to an unusually high number of distinct remote IP addresses (greater than 5). This behavior is characteristic of unauthorized lateral movement, reconnaissance, or establishing multiple C2 tunnels via a legitimate RMM tool.
Detects instances where permissions related to file transfers are granted or accessed within a ScreenConnect remote access session. This rule monitors for session-related events or permission updates that could indicate an attacker leveraging the remote access tool to exfiltrate data or interact with the filesystem.
Detects instances where web server or application-related processes (pc-app, java, pc-tomcat, PCClient) spawn command shell interpreters (cmd, powershell, pwsh). This behavior is often indicative of exploitation of a web application vulnerability, such as remote code execution.
Page 253 of 1871




