Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects >=2 of the four NeedyMantis archive-extraction artifacts (encryptbase64.ps1, dnsapi.dll, ws2_32.dll, msvcrt140.dll) written by the same process within 60 seconds. Anchored to the known sideload staging directories (ProgramData/ProgramFiles subfolders used by the Poedit/curl/Vim/TightVNC/Office/Broadcom/Intel/NVIDIA-masquerading bundles) and excludes System32/SysWOW64, since ws2_32.dll and dnsapi.dll are legitimate system DLL names that would otherwise cause noise if matched by name alone anywhere on disk.
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
Detects Impacket-style hands-on-keyboard staging: a NeedyMantis bundle file dropped by cmd.exe/wmiprvse.exe/services.exe carrying the distinctive remote-execution fingerprint (ADMIN$ share reference, %COMSPEC% invocation, or 2>&1 output redirection used by wmiexec/smbexec/atexec), followed within 15 minutes by execution referencing the same bundle folder with the same fingerprint. Requiring the ADMIN$/%COMSPEC%/redirection fingerprint on both the copy and the execution -- rather than just matching on common process names like cmd.exe or svchost.exe -- removes the bulk of ordinary software installation and update activity that also uses cmd.exe to stage files.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
Detects a .ps1-named file being loaded as an executable image or created as a process's own file name (both anomalous under normal Windows semantics, since PowerShell always runs scripts via powershell.exe/pwsh.exe as the process image, never as the .ps1 itself). Anchored to the known NeedyMantis sideload staging folders to exclude unrelated developer/test tooling elsewhere on disk that might trip a similar anomaly.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Hunts telemetry for published NeedyMantis indicators: three known SHA-256 hashes (WinSparkle.dll first-stage loader and its encrypted archive, plus the older libcurl archive), the C2 domain corp.tripswithengine[.]com, and the C2 URL path /library/zip/ on that domain. Domain/URL matching parses the actual host out of RemoteUrl and requires an EXACT match (not substring 'has/contains'), so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') or as a prefix of an unrelated domain (e.g. 'corp.tripswithengine.com.evil.net') cannot match. No malicious IP address has been published for this campaign, so IP-based matching is intentionally not included.
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
Exact-hash match for the known NeedyMantis first-stage loader sample masquerading as Poedit's WinSparkle.dll
Detects the NeedyMantis main-component handshake: an HTTP GET to port 443 with a User-Agent that is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end) and an explicit 'Upgrade: websocket' header, marking the HTTPS-to-WebSocket protocol switch used before the RC4 key exchange. Restricting to port 443 and requiring an exact (not substring) UA match removes generic WebSocket apps and any traffic where 'firefox/21.0' merely appears inside a real, longer browser UA string.
Detects the NeedyMantis main-component handshake: an HTTP GET to port 443 with a User-Agent that is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end) and an explicit 'Upgrade: websocket' header, marking the HTTPS-to-WebSocket protocol switch used before the RC4 key exchange. Restricting to port 443 and requiring an exact (not substring) UA match removes generic WebSocket apps and any traffic where 'firefox/21.0' merely appears inside a real, longer browser UA string.
Detects the NeedyMantis main-component handshake: an HTTP GET to port 443 with a User-Agent that is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end) and an explicit 'Upgrade: websocket' header, marking the HTTPS-to-WebSocket protocol switch used before the RC4 key exchange. Restricting to port 443 and requiring an exact (not substring) UA match removes generic WebSocket apps and any traffic where 'firefox/21.0' merely appears inside a real, longer browser UA string.
Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
Detects egress to the NeedyMantis C2 domain corp.tripswithengine[.]com across three vantage points: TLS SNI (port 443), DNS resolution, and HTTP Host header. Each content match is anchored to the start of its buffer ('startswith') so a different domain that merely contains 'corp.tripswithengine.com' as a suffix of a longer label (e.g. 'notcorp.tripswithengine.com') cannot match — only this exact domain or a genuine subdomain of it triggers.
Detects NeedyMantis' WebSockets comms-module handshake: an outbound HTTP GET to port 443 whose User-Agent is EXACTLY the hard-coded literal 'firefox/21.0' (anchored start+end, not a substring of a real browser UA) AND whose headers contain an explicit 'Upgrade: websocket' value. Anchoring the UA to an exact match and requiring the literal upgrade header (rather than just the presence of an 'Upgrade' header name) removes legitimate WebSocket apps and any app whose real UA merely contains 'firefox/21.0' as a substring.
