Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where cmd.exe or powershell.exe are launched from explorer.exe with command-line arguments containing DocuSign-themed keywords. This behavior is indicative of a 'ClickFix' phishing attack, where a user is socially engineered to copy and execute a malicious command via the terminal after interacting with a fraudulent DocuSign lookalike page.
Detects registry value modifications to the Windows Explorer RunMRU key where the data contains indicators of obfuscated PowerShell commands. This pattern is commonly associated with the 'ClickFix' social-engineering campaign, where users are prompted to copy and paste a malicious PowerShell command into the Windows Run dialog.
Detects the silent installation or execution of Remote Monitoring and Management (RMM) tools when launched by script hosts (wscript.exe, mshta.exe, powershell.exe) which themselves were spawned by browser processes or explorer.exe. This pattern is characteristic of social engineering delivery chains, such as 'ClickFix', where a user is tricked into executing a script that subsequently fetches and runs RMM payloads for persistent remote access.
Detects behavior indicative of the MLTBackdoor malware, specifically the creation or modification of a DLL file (such as *dlp.dll) shortly after or before the creation of an RC4-encrypted 'data.bin' file on the same host. The rule also looks for an optional preceding archive extraction event of common file types from Temp or Downloads directories by standard extraction utilities, which may indicate the staging of the initial payload.
Detects the execution of 'filemanager.exe' and its subsequent access to sensitive browser credential stores (e.g., 'Login Data', 'cookies.sqlite'), occurring within a short window following a PowerShell-based ClickFix-style attack chain. The rule correlates initial suspicious script execution (often involving hidden windows, obfuscated commands, or web requests) with follow-on credential harvesting behavior on the same host.
Detects mshta.exe initiating outbound network connections, followed closely by the execution of a powershell.exe process with an unusually large command line, or PowerShell script block events containing large, potentially obfuscated scripts. This behavior is indicative of 'DeepLoad' or 'ClickFix' style staging, where legitimate binaries are leveraged to download and execute heavily obfuscated payloads.
Detects potential credential theft or malicious browser extension installation (DeepLoad-style) by monitoring for browser extension manifest file drops or registry-based extension force-installs occurring shortly after suspicious PowerShell command execution (ClickFix-style) on the same device.
Detects a sequence of activity where an endpoint performs multiple anti-analysis or sandbox evasion checks (using commands like wmic, powershell, or reg to query system information or look for debugger/VM artifacts) followed within 10 minutes by an outbound network connection to a domain that has not been observed from that specific device in the last 7 days.
Detects ClickFix-style fileless execution patterns where PowerShell pipelines (Invoke-RestMethod/Invoke-WebRequest) directly into execution cmdlets (Invoke-Expression/IEX) to download and execute remote scripts entirely in memory. The rule monitors for common bypass flags, hidden windows, and connections to suspicious IP address patterns or non-standard ports typically associated with malicious C2 staging.
This rule detects a multi-stage attack pattern involving potential social engineering via lookalike conferencing domains. It identifies users visiting suspicious domains resembling well-known conferencing platforms (e.g., Teams, Meet, Zoom), followed by modifications to the Windows RunMRU registry key and subsequent execution of suspicious commands (PowerShell, CMD, mshta) by explorer.exe within a short timeframe.
Detects potential supply chain attacks where a common external script (e.g., a widget) is loaded across multiple unrelated domains, followed by correlation with suspicious user-executed commands indicative of 'ClickFix' tactics (copying and pasting malicious code from a browser-based overlay into the Windows Run dialog).
Detects a suspected ClickFix-style delivery mechanism where a user visits suspicious domains mimicking legitimate CLI tools (e.g., Gemini, Claude) via web browsers. The detection correlates this initial network access with subsequent suspicious Windows RunMRU activity and the spawning of shell processes (powershell.exe, cmd.exe) from explorer.exe using encoded or download-oriented command line arguments within a 5-minute window.
Detects a potential ClickFix delivery attack where a user navigates to an automotive-themed website, interacts with the system via the Windows Run dialog (RunMRU), and subsequently executes command-line interpreters (powershell, cmd, wscript, mshta) spawned by explorer.exe within a short time window.
Detects 'unshare' creating a user/mount/net namespace by a non-root user, outside
sanctioned container and sandbox runtimes. This is the shared precursor across CIFSwitch,
OVSwrap, pedit COW and container escapes. Enriched with a namespace-flag decode, an
exploit-family ProfileHint (user+net = OVSwrap shape, user+mount = CIFSwitch/overlay
shape), sandbox-lineage FP suppression, RiskScore / TriagePriority and DeviceInfo context.
Treat as a precursor/triage signal - MDE cannot tie unshare to the subsequent root
transition (no uid_change event). Detection logic adapted from Elastic Security Labs.
sanctioned container and sandbox runtimes. This is the shared precursor across CIFSwitch,
OVSwrap, pedit COW and container escapes. Enriched with a namespace-flag decode, an
exploit-family ProfileHint (user+net = OVSwrap shape, user+mount = CIFSwitch/overlay
shape), sandbox-lineage FP suppression, RiskScore / TriagePriority and DeviceInfo context.
Treat as a precursor/triage signal - MDE cannot tie unshare to the subsequent root
transition (no uid_change event). Detection logic adapted from Elastic Security Labs.
Detects a shell launched with the privilege-preserving -p flag from a location outside the
standard binary directories - the execution step that converts a SUID-root shell copy into
an interactive root shell. Pairs directly with OS-DET-LNX-005 (see correlation
OS-DET-LNX-007). Detection logic adapted from Elastic Security Labs.
standard binary directories - the execution step that converts a SUID-root shell copy into
an interactive root shell. Pairs directly with OS-DET-LNX-005 (see correlation
OS-DET-LNX-007). Detection logic adapted from Elastic Security Labs.
Detects instances where AI developer tools or IDE assistants (e.g., Claude, Copilot, Cursor) execute data collection commands (such as directory traversal or archiving) followed by or concurrent with the bulk access of sensitive files (credentials, configuration files) or personal user data.
Detects process command lines containing LLM tool-calling syntax (e.g., 'tool_call', 'function_call') in conjunction with keywords associated with offensive security capabilities (e.g., 'exploit', 'mimikatz', 'exfiltrate'). This pattern is consistent with the behavior of malicious LLM-based agents attempting to autonomously invoke and execute offensive tasks.
Detects AI coding assistants and LLM agent frameworks attempting to access, read, or export sensitive credential files, registry hives, or application secrets. The rule monitors both file system operations on known secret locations and process execution patterns indicative of credential dumping or API token retrieval by these tools.
This rule performs a point-in-time IOC hunt within CommonSecurityLog data to detect indicators associated with NeedyMantis. It monitors for specific C2 infrastructure domains ('tripswithengine.com') and a hardcoded user-agent string ('Firefox/21.0') in proxy, firewall, or network logs, which are characteristic of this threat actor's activity.
Detects a behavioral fingerprint associated with the NeedyMantis group, characterized by the creation of a DLL and a identically-named, extensionless, encrypted archive file in the same directory within a short time window. This approach identifies the underlying packaging strategy rather than relying on static file names or known paths.
Detects .ps1-named files dropped to disk that are never actually executed by a PowerShell interpreter (powershell.exe / pwsh.exe) within a short window afterward. NeedyMantis's second-stage loader (e.g. encryptbase64.ps1) is raw x64 shellcode, not a real script -- it's read and executed directly by the dropping process, so no genuine PowerShell host process ever references the file by name. Replaces an earlier version of this rule that watched DeviceImageLoadEvents for a .ps1 extension: Windows can only emit an image-load event for a file with a valid PE header loaded via the OS loader, and raw shellcode has no PE header and is never mapped that way, so that approach would not have fired on this malware. Caveat: legitimate deployment tooling that stages a script for delayed or remote execution can also produce this create/execute mismatch; tune the window and add known-good deployment-tool exclusions for your environment.



