Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where AI coding assistants (such as Claude, Copilot, or Gemini) are used as parent processes to execute specific git commands, including 'git rev-parse HEAD' or 'git checkout'. This can indicate automated or adversary-driven repository interaction initiated by an AI tool, potentially for source code theft, reconnaissance, or malicious automation.
Detects the execution of PowerShell with encoded commands that are unusually long (over 300 characters). Adversaries often use Base64 encoding to obfuscate malicious PowerShell scripts, and long encoded strings are a strong indicator of non-interactive or automated command execution, such as during the initial stage of an attack.
This rule detects suspicious process injection activity directed at Chrome or Edge browser processes, followed immediately by file access to sensitive browser data files like 'Login Data' or 'Cookies'. This pattern is indicative of an adversary attempting to steal credentials or session cookies from a user's web browser memory and disk storage.
Detects the execution of diskpart.exe with command-line arguments using the /s flag, triggered by processes originating from unconventional locations such as Perflogs or Documents, or by executables ending with _win64.exe. Diskpart is a command-line disk partitioning utility that can be abused for credential dumping, data staging, or destructive activities.
Detects suspicious Git activity or file modifications within the plugin directories of various AI coding assistants (such as Claude, Codex, Copilot, or Gemini). This may indicate an attempt to inject malicious code or persistence mechanisms into the local environment via untrusted plugins.
Detects the use of the 'wevtutil.exe' utility to clear Windows Event Logs. This is a common technique used by adversaries to disrupt logging and evade detection of their actions on a host. The rule specifically monitors for the 'cl' (clear-log) command applied to sensitive operational channels, triggering when multiple clearing operations are detected within a 5-minute window.
Detects instances where Windows Explorer (explorer.exe) spawns PowerShell with heavily obfuscated command lines, characterized by caret-obfuscation and execution policy bypass flags. This pattern is characteristic of ClickFix social engineering, where a user is tricked into pasting malicious commands into the Windows Run dialog.
This rule detects PowerShell command lines that include .NET API calls typically used for anti-debugging and anti-analysis evasion, such as 'Debugger.IsAttached', 'Debugger.IsLogging', 'CheckRemoteDebuggerPresent', and 'Environment.FailFast'. These checks are common in malicious loaders and implants to determine if the process is being analyzed or monitored, allowing the malware to modify its behavior accordingly.
Detects the use of the [Reflection.Assembly]::Load method within PowerShell command lines. This method is often abused by attackers to reflectively load malicious .NET assemblies directly into memory, bypassing disk-based security controls.
Detects the creation of a .lnk shortcut file within the Windows Startup folder, which is a common persistence mechanism. The detection logic also flags the usage of WScript.Shell and CreateShortcut methods, which are frequently abused by scripts (e.g., VBScript or PowerShell) to programmatically establish this persistence.
Detects the use of PowerShell commands that perform decryption (AES-256-CBC) and decompression (Gzip) of data, followed by the reflective loading of a .NET assembly into memory using [Reflection.Assembly]::Load. This behavior is indicative of fileless malware execution where a payload is hidden in an obfuscated or compressed format and unpacked at runtime.
Detects unauthorized processes attempting to access sensitive browser files, including Login Data (passwords) and Network/Cookies databases for Chrome, Edge, and Firefox. These files are primary targets for credential dumping and session hijacking.
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
Detects the execution of the 'reagentc.exe' utility with the '/disable' argument. This command is used to disable the Windows Recovery Environment (WinRE), which is a common post-compromise activity performed by ransomware and other malware to prevent system recovery and hinder incident response efforts.
Detects instances of PowerShell being launched directly from Windows Explorer (explorer.exe) using suspicious command-line arguments. This pattern is commonly associated with malicious scripts, remote access trojans, or fileless execution techniques where an adversary executes code through shell-based file interaction.
Detects the execution of the Windows cipher.exe utility with the /w flag, which is used to overwrite deleted data on a disk to prevent forensic recovery. This is a common technique used by adversaries to perform data destruction or cover their tracks.
Detects the execution of 'reagentc.exe' with the '/disable' flag, which is used to disable the Windows Recovery Environment (WinRE). Adversaries often perform this action as part of an attempt to inhibit system recovery during ransomware operations or other destructive attacks.
Detects obfuscated PowerShell commands bypassing execution policy to download or execute 'configuration.ps1' or communicate with known malicious infrastructure associated with the ClickFix campaign. The rule specifically looks for caret-based obfuscation, bypass switches, and known IOCs in the command line.
Detects instances where PowerShell attempts to inject code into legitimate processes (such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe) using direct syscalls NtAllocateVirtualMemoryRemote or NtSetContextThreadRemote, indicating potential process injection activity.
Detects the execution of the Windows cipher.exe utility with the /w flag, which is used to overwrite free space on a volume to permanently delete data, a common technique for anti-forensics and data destruction.
Page 260 of 1871
