Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential attempts to abuse a Trusted Domain Object (TDO) to traverse a one-way Active Directory trust. It identifies suspicious activities such as Kerberos ticket requests (AS-REQ/TGS-REQ) targeting trust accounts (inter-realm indicators) or DCSync-style replication requests targeting the TDO object to extract domain secrets.
This rule detects potentially malicious activity targeting Microsoft Entra Connect (formerly Azure AD Connect) servers. It identifies the execution of known credential harvesting tools like AADInternals or attempts to access/extract the ADSync database files and encryption components. Such actions indicate an attempt to gain unauthorized access to synchronized identities, local domain credentials, or cloud synchronization service accounts.
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
Detects the creation of Windows services using sc.exe, powershell.exe, or cmd.exe that reference specific DLL files (winfsp-x64.dll or DukeQt.dll). This behavior is often associated with persistence mechanisms or DLL hijacking/side-loading techniques where a malicious service is configured to load a specific library.
Detects a specific pattern associated with the VioletRAT stage-2 loader, where cmd.exe executes a randomly-named batch file from a temporary directory, which subsequently launches a hidden PowerShell process designed to download or reflectively load a .NET assembly.
Detects a specific pattern associated with the VioletRAT stage-2 loader, where cmd.exe executes a randomly-named batch file from a temporary directory, which subsequently launches a hidden PowerShell process designed to download or reflectively load a .NET assembly.
Detects the creation or modification of registry run keys under HKCU or HKEY_USERS that use the value 'WindowsDefender' to point to an executable located within the AppData directory. This is a common technique used by malware to establish persistence while masquerading as a legitimate security component.
Detects a specific pattern associated with the VioletRAT stage-2 loader, where cmd.exe executes a randomly-named batch file from a temporary directory, which subsequently launches a hidden PowerShell process designed to download or reflectively load a .NET assembly.
IOC sweep against network telemetry for confirmed BengalSEO/MayaBot campaign infrastructure: the Hostmaza backend IP (5.101.140.80), Matomo tracking domains (stats.us3.org, us3.my), named MayaBot C2 domains (cus.cam, dll.lat, us99.org), and the ~170-domain Traffic Distribution System redirector fleet used to funnel victims to payload delivery. The source intel report contains no file hashes (MD5/SHA1/SHA256) -- only IPs, domains, and URLs -- so this sweep is IP/domain-only. Note the much larger corpus of single-use lure-page domains (~1,000 additional indicators) is excluded as too high-churn for static embedding.
Detects MayaBot's scheduled-task persistence chain by correlating two signals on the same device within a 60-minute window: (1) schtasks.exe creating a daily task referencing a hidden batch script (update.bat/backup.bat/firewall-update.bat) under AppData\Local, spawned from wscript.exe/cscript.exe/cmd.exe, and (2) cmd.exe launching a hidden-window PowerShell process referencing the same batch scripts under AppData\Local. Requiring both signals together, anchored to the AppData\Local path, sharply reduces false positives compared to alerting on either behavior alone.
This rule detects potentially malicious system configuration changes, specifically the suspension or disabling of BitLocker drive encryption via 'manage-bde.exe' and the weakening of SChannel security protocols or ciphers by modifying registry keys. These activities are indicative of an attacker attempting to bypass disk encryption or lower the security posture of network communication.
Detects outbound network connections from internal devices to public IP addresses over standard MQTT (1883) or MQTT over TLS (8883) ports. MQTT is frequently used for IoT communication but can be abused for command and control (C2) or unauthorized data exfiltration.
Detects the use of rundll32.exe to execute comsvcs.dll's MiniDump functionality against the LSASS process, a common technique for dumping credentials. The rule includes behavioral correlation by identifying the same user account executing this pattern on multiple devices within a one-hour window.
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects potential persistence attempts via registry modifications involving rundll32.exe. The rule monitors for two patterns: registry keys associated with shell commands for specific file types triggering rundll32.exe, and registry 'Run' keys using a 'Locked' value name with a custom URI handler, often indicative of malware or suspicious persistence mechanisms.
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
Detects instances where PowerShell scripts are executed via the Windows Task Scheduler from within potential staging directories (ProgramData with randomized folder names). The rule identifies execution that uses common PowerShell obfuscation flags (e.g., -EncodedCommand) and requires secondary hardening bypass flags (e.g., -WindowStyle hidden), followed by correlated network activity to a specific suspicious C2 domain.
Page 256 of 1871


