Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects execution of PowerShell commands using encoded arguments combined with network download cmdlets. This pattern is indicative of a multi-stage loader chain often used in 'ClickFix' style social engineering lures to download and execute secondary malicious payloads.
Detects instances of thread execution where the start module is identified as a critical system component (ntdll.dll or kernel32.dll) but the associated call trace contains 'UNKNOWN' entries. This behavior is indicative of call stack spoofing, a technique used by malicious software to hide the true origin of code execution and evade endpoint security analysis by mimicking legitimate thread start addresses.
Detects a suspicious process chain where an AutoIT loader (originating from temporary directories or associated with charmap.exe command line anomalies) executes charmap.exe, followed by the loading of amsi.dll within that charmap.exe process. This behavior is indicative of AsyncRAT injection patterns, specifically where charmap.exe is used as a host process to tamper with AMSI via in-memory patching of AmsiScanBuffer.
This rule detects the presence or execution of known files 'winfsp-x64.dll' or 'DukeQt.dll' when located in suspicious, user-writable directories such as AppData, Temp, or ProgramData, while excluding standard system or program installation paths.
This rule detects potential defense evasion activity identified by SentinelOne as call stack spoofing. The rule triggers when behavioral indicator tags related to spoofed call stacks, thread execution masking, or suspicious indicators involving RtlUserThreadStart, BaseThreadInitThunk, or kernel32.dll are detected, suggesting an attempt to hide malicious thread execution from security monitoring tools.
This rule identifies potential persistence activity on a Windows host by correlating multiple indicators such as service creation, scheduled tasks, registry run key modifications, Winlogon helper modifications, and driver loading. It specifically monitors for indicators associated with 'NetSupport' or 'client32' filenames or services. The rule triggers when two or more distinct persistence mechanisms are detected for the same host and user.
Detects instances where browser processes (chrome.exe or comet.exe) access multiple files in sensitive or unexpected directories (e.g., System32, /etc/, Documents) without an associated user click event. This activity often indicates potential malicious scripts or automated data collection running within the context of a browser process.
Detects ClickFix-style social engineering attacks where users are prompted to copy and execute malicious commands in a shell environment. The rule triggers on process execution of terminal or shell binaries (zsh, sh, cmd.exe, powershell.exe) containing indicators of obfuscated execution or remote code downloading, such as piped shell commands (curl | sh/zsh) or PowerShell encoded command execution.
Detects the Perplexity Comet or Google Chrome browser processes accessing files in locations outside expected directories (such as Downloads, User Data, or Temp), which is a common indicator of a malicious browser extension or process attempting to read arbitrary files from the filesystem.
Detects incoming HTTP requests to Microsoft Exchange servers that match patterns indicative of exploitation attempts for the ProxyLogon SSRF vulnerability (CVE-2021-26855). This includes detecting specific manipulation of the Autodiscover service and the injection of X-BEResource or X-AnonResource-Backend headers, which were commonly used during the initial access phase of this campaign.
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
Detects execution of PowerShell or CMD initiated by the Kimsuky GitPower loader. The rule identifies suspicious command-line artifacts including excessive character padding (leading spaces), extremely long command lines, and the presence of a hardcoded, unique base64 decoding variable ('$VIUSBvejbawf') associated with this specific malware family.
Detects potential ClickFix-style social engineering attacks where a victim is prompted to execute an encoded PowerShell command (often via copy-paste into a terminal). The rule specifically monitors PowerShell processes initiated by shell environments (explorer.exe, cmd.exe, or WindowsTerminal.exe) that execute encoded, hidden scripts to perform multiple suspicious network requests for files (e.g., .zip, .enc, .bin) from non-standard domains.
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
This rule detects the LausivLoader initial-stage obfuscated JavaScript dropper. It identifies the malware either by specific file hashes (MD5/SHA256) or by detecting characteristic behaviors: small file size (<1MB), the presence of 'String.fromCharCode' obfuscation techniques, excessive junk comments, and supply-chain related lure strings.
Detects the execution of command interpreters or scripting engines spawned by the ManageEngine ADSelfService Plus GINA client process (typically present at the Windows logon screen). This activity is highly suspicious as it indicates potential command injection or abuse of a pre-authentication component running at SYSTEM privileges.
Detects the execution of command interpreters or scripting engines spawned by the ManageEngine ADSelfService Plus GINA client process (typically present at the Windows logon screen). This activity is highly suspicious as it indicates potential command injection or abuse of a pre-authentication component running at SYSTEM privileges.
This rule detects the execution of PowerShell from a WScript or CScript parent process where the PowerShell script also performs suspicious actions such as reading environment variables (specifically those following a 'Kv\d+' pattern) and accessing files using 'IO.File::ReadAllText'. This behavior is indicative of malicious scripts, such as those used by specific malware or post-exploitation tools, attempting to retrieve configuration data or credentials stored in environment variables.
Detects the execution of command interpreters or scripting engines spawned by the ManageEngine ADSelfService Plus GINA client process (typically present at the Windows logon screen). This activity is highly suspicious as it indicates potential command injection or abuse of a pre-authentication component running at SYSTEM privileges.
This rule monitors for two distinct stages of potential account recovery abuse. First, it detects the execution of suspected Python scripts on an endpoint that contain command-line arguments related to password recovery or authentication codes. Second, it monitors network proxy/web logs for a high volume of API requests to the 'easy4ipcloud.com' domain associated with password reset or device probe endpoints, which may indicate automated credential stuffing or unauthorized device account recovery attempts.
Detects 32-bit PE files that are packed using UPX and utilize specific file names (1.exe or xeno.exe) associated with the SalatStealer credential harvester. The rule also checks for a zeroed compile timestamp in the PE header, which is a common characteristic of this malicious file.
Page 259 of 1871



