Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
Detects the use of PowerShell to modify Windows Defender exclusions by adding the 'C:\' drive root as an exclusion path. This technique, which can be executed via 'Add-MpPreference', 'Set-MpPreference', or 'Invoke-CimMethod', effectively disables real-time scanning across the entire system drive and is often employed by adversaries to hide malicious activity from antivirus detection.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
Detects the execution of PowerShell or PowerShell ISE with command line arguments indicative of suspicious activity, such as the use of GZipStream for payload decompression, AesManaged for payload decryption, or in-memory assembly loading via Reflection.Assembly or EntryPoint.Invoke, often associated with fileless malware execution or obfuscated script runners.
Detects the execution of WScript via a scheduled task named 'MicrosoftEdgeUpdateTaskCore'. This pattern is often used to masquerade malicious activity by using the name of a legitimate Microsoft Edge update process to execute scripts silently (using //B //Nologo).
Detects instances where WScript or CScript (Windows Script Host) initiate child processes like PowerShell or Conhost, specifically when those child processes contain command line arguments referencing environment variable access pattern 'GetEnvironmentVariable' for 'Kv' keys. This pattern is commonly associated with retrieving stored configuration or sensitive data using script-based wrappers to execute logic.
This rule detects potentially malicious behavior where common scripting processes such as PowerShell, WScript, or CScript interact with sensitive memory-related APIs (e.g., VirtualProtect, GetProcAddress, LoadLibrary) or monitor modules (amsi.dll, clr.dll). This pattern is often indicative of reflective loading, memory injection, or attempts to bypass security controls like AMSI.
Detects the presence of PNG image files containing a specific steganographic marker embedded within the iTXt metadata chunk, often used by the LausivLoader malware for C2 communication or payload delivery. The rule looks for the specific marker 0xFF89AD4A or known C2 indicators (yapw.life, stego_zrgaixkku8.png) within PNG files.
Detects the presence of PNG image files containing a specific steganographic marker embedded within the iTXt metadata chunk, often used by the LausivLoader malware for C2 communication or payload delivery. The rule looks for the specific marker 0xFF89AD4A or known C2 indicators (yapw.life, stego_zrgaixkku8.png) within PNG files.
This rule detects unauthorized memory modification of ntdll.dll, specifically targeting the EtwEventWrite function, by identifying processes writing to memory regions with execution-permission flags (e.g., PAGE_EXECUTE_READWRITE). This behavior is characteristic of adversaries attempting to blind Event Tracing for Windows (ETW) telemetry, often following suspicious .NET assembly loading (such as Assembly.Load) typical of malware loaders like LausivLoader.
Detects attempts to modify Microsoft Defender settings, such as adding file path exclusions via PowerShell, Registry manipulation, or Scheduled Tasks, as well as disabling Tamper Protection. These actions are commonly used by attackers to evade security monitoring by hiding malicious files or disabling protective features.
Detects the creation, renaming, or modification of a file named 'FitnessMonitor.exe' within the Windows Startup folder. This behavior is indicative of an attempt to establish persistence by ensuring the executable runs automatically upon user login.
Detects the addition of a 'DailyFitnessTracker' registry entry into the 'HKCU\Software\Microsoft\Windows\CurrentVersion\Run' key. This is a common persistence technique where programs are configured to execute automatically upon user login, utilizing either 'reg.exe' or PowerShell 'New-ItemProperty' to modify the registry.
Detects the creation or renaming of files within the '\ProgramData\doxc' directory, and correlates this with the execution of 'mklink /H' commands that point to that directory. This behavior is indicative of an adversary establishing persistence or hiding files by creating hard links.
This rule detects the execution of a command shell (cmd.exe) that is launched via or involving a batch file ('config.bat' or other .bat files), followed by the deletion of '.lnk' files. This pattern is commonly associated with cleanup activities performed by malicious scripts or malware attempting to remove traces or shortcuts after execution.
Detects the creation or renaming of files within the '\ProgramData\doxc' directory, and correlates this with the execution of 'mklink /H' commands that point to that directory. This behavior is indicative of an adversary establishing persistence or hiding files by creating hard links.
Page 262 of 1871

