Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects unauthorized attempts to disable Windows Defender Tamper Protection by setting the TamperProtection registry value to 0. This action allows an adversary to weaken system security, potentially enabling them to modify Defender exclusions or stop security services without interference.
Detects the deletion of registry keys or values associated with Chrome extension settings by processes other than chrome.exe. This activity is often associated with the removal or tampering of browser extension configurations to maintain persistence, bypass security, or disable malicious extensions during an incident response or by an attacker.
Detects PowerShell processes spawned from Windows Script Host (wscript.exe/cscript.exe) that interact with environment variables starting with 'Kv'. This behavior is indicative of the LausivLoader malware, which passes data between script stages via inherited environment variables to avoid using command-line arguments.
Detects instances of vsdbg.exe (Visual Studio Debugger) loading vsdbg.dll from suspicious, temporary, or user-controlled locations (e.g., Temp, Downloads, AppData) when initiated from a path outside of the standard Microsoft Visual Studio installation directories. This behavior is indicative of potential masquerading or side-loading of the debugger utility by an attacker.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
Detects the use of PowerShell to modify Windows Defender exclusions by adding the 'C:\' drive root as an exclusion path. This technique, which can be executed via 'Add-MpPreference', 'Set-MpPreference', or 'Invoke-CimMethod', effectively disables real-time scanning across the entire system drive and is often employed by adversaries to hide malicious activity from antivirus detection.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
Detects the execution of PowerShell or PowerShell ISE with command line arguments indicative of suspicious activity, such as the use of GZipStream for payload decompression, AesManaged for payload decryption, or in-memory assembly loading via Reflection.Assembly or EntryPoint.Invoke, often associated with fileless malware execution or obfuscated script runners.
Detects the execution of WScript via a scheduled task named 'MicrosoftEdgeUpdateTaskCore'. This pattern is often used to masquerade malicious activity by using the name of a legitimate Microsoft Edge update process to execute scripts silently (using //B //Nologo).
Detects instances where WScript or CScript (Windows Script Host) initiate child processes like PowerShell or Conhost, specifically when those child processes contain command line arguments referencing environment variable access pattern 'GetEnvironmentVariable' for 'Kv' keys. This pattern is commonly associated with retrieving stored configuration or sensitive data using script-based wrappers to execute logic.
This rule detects potentially malicious behavior where common scripting processes such as PowerShell, WScript, or CScript interact with sensitive memory-related APIs (e.g., VirtualProtect, GetProcAddress, LoadLibrary) or monitor modules (amsi.dll, clr.dll). This pattern is often indicative of reflective loading, memory injection, or attempts to bypass security controls like AMSI.
Detects the presence of PNG image files containing a specific steganographic marker embedded within the iTXt metadata chunk, often used by the LausivLoader malware for C2 communication or payload delivery. The rule looks for the specific marker 0xFF89AD4A or known C2 indicators (yapw.life, stego_zrgaixkku8.png) within PNG files.
Detects the presence of PNG image files containing a specific steganographic marker embedded within the iTXt metadata chunk, often used by the LausivLoader malware for C2 communication or payload delivery. The rule looks for the specific marker 0xFF89AD4A or known C2 indicators (yapw.life, stego_zrgaixkku8.png) within PNG files.
This rule detects unauthorized memory modification of ntdll.dll, specifically targeting the EtwEventWrite function, by identifying processes writing to memory regions with execution-permission flags (e.g., PAGE_EXECUTE_READWRITE). This behavior is characteristic of adversaries attempting to blind Event Tracing for Windows (ETW) telemetry, often following suspicious .NET assembly loading (such as Assembly.Load) typical of malware loaders like LausivLoader.
Detects attempts to modify Microsoft Defender settings, such as adding file path exclusions via PowerShell, Registry manipulation, or Scheduled Tasks, as well as disabling Tamper Protection. These actions are commonly used by attackers to evade security monitoring by hiding malicious files or disabling protective features.
Detects the creation, renaming, or modification of a file named 'FitnessMonitor.exe' within the Windows Startup folder. This behavior is indicative of an attempt to establish persistence by ensuring the executable runs automatically upon user login.
Page 263 of 1871


