Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Detects the creation, modification, or renaming of common JSP web shell filenames (x.jsp, u.jsp, u2.jsp) within known web application directories (e.g., webapps, Peoplesoft, WebLogic). This pattern is indicative of an adversary attempting to establish a web shell for persistent access or command execution on a vulnerable web server.
Detects execution of MeshAgent binaries when initiated by common scripting or application processes (e.g., java, sh, bash, python) or when displaying suspicious command-line patterns indicative of unauthorized remote access or download activity, particularly in environments like WebLogic or PeopleSoft.
This rule performs an indicator of compromise (IOC) hunt for artifacts related to the Lazarus Group's Graphalgo/GHAPPIER campaign. It monitors DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents over the past 90 days to identify matches against known malicious file hashes (SHA256/SHA1), command-and-control (C2) IP addresses, and malicious domains associated with this campaign.
This rule performs a sweep across device file and network events for indicators of compromise (IOCs) associated with the UAT-11587/Antino campaign. It detects malicious file hashes, specific C2 domain connections, and known lure URLs (HTA/WSF) identified by Cisco Talos.
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
Detects activity associated with the MALFEX npm supply-chain campaign (also known as Overlord/movinlike). This rule performs a sweep for known malicious file hashes, suspicious process command lines, outbound network connections to malicious domains or IPs, and email communications from identified adversary-controlled accounts.
Detects the installation or execution of known MALFEX malicious packages via npm or Node.js, which are used as entry points for polyglot or disguised payload delivery.
This rule detects potential Remote Desktop Protocol (RDP) session hijacking or suspicious automation activity. It monitors for the execution of tscon.exe, a system utility used to control remote desktop sessions, or the usage of mstsc.exe (Remote Desktop Connection) over the standard RDP port 3389, which can be indicative of lateral movement or unauthorized access.
Detects attempts to dump the Local Security Authority Subsystem Service (LSASS) process memory for credential harvesting. The rule monitors for unauthorized process access requests (e.g., PROCESS_VM_READ), suspicious file creation of memory dumps in common writeable directories, and command-line execution of tools or techniques commonly associated with LSASS dumping (e.g., Mimikatz, procdump, or abusing comsvcs.dll).
Detects the execution of script files with .js or .se extensions using wscript.exe or cscript.exe outside of standard system directories. This behavior is consistent with the More_eggs JScript backdoor, which has been utilized by the FIN6 threat group (also known as Skeleton Spider) to establish persistent backdoors for follow-on payload delivery.
Detects the use of PowerShell to download content from a remote URI and execute it using encoded commands or expression evaluation, a pattern commonly used by the FIN8 threat group (Syssphinx) to deploy the BADHATCH backdoor.
Detects Microsoft Office applications (winword.exe or excel.exe) spawning shell processes (cmd.exe or powershell.exe). This behavior is commonly associated with malicious VBA macro execution in weaponized Office documents used for malware delivery, such as Dridex.
Detects the creation of scheduled tasks that invoke rundll32.exe to execute code from suspicious, user-writable, or temporary file paths. This pattern is consistent with common persistence mechanisms employed by threat groups such as Wizard Spider (also known as Grim Spider, Gold Blackburn, and Periwinkle Tempest) to execute payloads like TrickBot or BazarLoader.
Detects command-line indicators associated with destructive disk-wiping activity, specifically targeting disk structure corruption to render systems unbootable. This rule monitors for unauthorized use of the Windows 'diskpart' utility, direct raw physical drive access, and specific file system utility commands (fsutil) frequently observed in wipers attributed to APT44 (Sandworm).
Detects the creation or modification of Windows Registry Run or RunOnce keys where the associated executable path is located in suspicious or non-standard directories (e.g., Temp, AppData, ProgramData). This behavior is characteristic of adversaries, such as APT28, attempting to maintain persistence by ensuring malicious code executes automatically upon user login.
Detects the loading of an unsigned or invalidly signed DLL from commonly abused user-writable directories (Temp, AppData, Public). This behavior is characteristic of DLL side-loading techniques, often used by threat actors like the Lazarus Group to execute malicious code via a legitimate, trusted application.
Detects Microsoft Office applications (Winword/Excel) spawning PowerShell or MSHTA with base64-encoded command-line arguments, followed by subsequent persistence mechanisms such as creating scheduled tasks or modifying Registry Run keys. This behavior is indicative of APT38 (BlueNoroff) and similar campaigns delivering banking Trojans via malicious Office macros.
This rule detects instances where Microsoft Word (winword.exe) or Microsoft Excel (excel.exe) initiate a PowerShell (powershell.exe) process containing command-line arguments typical of downloader stagers, such as 'IEX', 'DownloadString', or hidden execution flags. This behavior is a common indicator of macro-based delivery of malware, frequently observed in campaigns associated with FIN7/Carbanak and other threat actors utilizing Cobalt Strike or similar offensive frameworks.
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
Page 26 of 1866


