Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of common command-line utilities used for network reconnaissance and discovery, such as arp, nbtstat, net, and ping. These commands are frequently used by adversaries to map network infrastructure, identify active hosts, and discover shared resources on a target network.
Detects execution of command-line tools (cmd.exe or .bat files) triggered by Windows Explorer, where the process command line or parent command line references a shortcut (.lnk) file or specific naming conventions like 'doxc.bat' or 'config.bat'. This pattern is frequently used in phishing attacks to execute malicious payloads disguised as legitimate files.
This rule detects unauthorized persistence attempts by monitoring for the creation of a registry value named 'DailyFitnessTracker' under the HKEY_CURRENT_USER Run key. It triggers when 'reg.exe' is used to add the key, PowerShell is used to set the registry property, or when a general registry event indicates the creation of this specific key. This behavior is indicative of a persistence mechanism designed to launch a potentially malicious or unwanted program upon user logon.
Detects the creation of hard links on a Windows system using utilities such as mklink or fsutil. Specifically, this rule identifies scenarios where a malicious executable located in %APPDATA% is linked to a backdoor binary stored in C:\ProgramData\, a technique used by adversaries to mask the true file path and evade security controls or detection mechanisms.
Detects the creation of files within the 'SystemFolder32' or 'System Folder32' directory under the user's Local AppData path, a known behavioral pattern for payload staging used by the Transparent Tribe threat actor.
Detects instances where Windows Explorer spawns cmd.exe to execute specific batch files (doxc.bat or config.bat), a behavior often associated with Transparent Tribe (APT36) activity involving malicious LNK shortcuts.
Detects the creation of scheduled tasks using schtasks.exe or PowerShell that masquerade as legitimate Microsoft Edge or OneDrive update tasks. This behavior is associated with APT36 (Transparent Tribe) and their use of modular malware to establish persistence.
Detects malicious scheduled task creation using names associated with Microsoft Edge updates, or the execution of PowerShell commands that utilize encoded arguments and known APT36 download cradles, indicating an attempt to establish persistence or retrieve secondary payloads.
Detects malicious scheduled task creation using names associated with Microsoft Edge updates, or the execution of PowerShell commands that utilize encoded arguments and known APT36 download cradles, indicating an attempt to establish persistence or retrieve secondary payloads.
Detects network discovery activities including ICMP sweeps, ARP cache checks, and SMB share/session enumeration, which are common tactics used for internal reconnaissance by the threat group APT36 (Transparent Tribe).
Detects the creation of hard links using 'mklink /H' targeting specific paths in ProgramData or linking to specific executable paths in AppData. This behavior is often indicative of adversaries attempting to perform file system manipulation for persistence, defense evasion, or masquerading.
This rule detects the execution of RUSTYMOVE, a tool associated with the Transparent Tribe (APT36) threat group, which is used for propagation via removable media. It monitors for the specific executable 'Automata-20.exe', the presence of specific task-related command line arguments, the dropping of suspicious file paths, and PowerShell-based enumeration of connected USB/removable drives.
Detects the execution of the RUSTYSHADE Rust-based backdoor, observed during Operation RapidRust, associated with the threat group APT36 (Transparent Tribe). The rule monitors for the specific 'DriverInstaller.exe' filename, known malicious file hashes, and suspicious command-line patterns involving PowerShell-based downloads of 'DriverInstaller.zip' from Backblaze cloud storage.
Detects the addition of a 'DailyFitnessTracker' entry to the HKCU Windows Registry Run key, which is a technique used by Golang-based RATs to establish persistence. The rule monitors both 'reg.exe' command-line operations and PowerShell 'New-ItemProperty' cmdlets targeting this specific registry path.
Detects the execution of HTSPnew.Exe with specific command-line arguments indicative of KRSID ransomware operations, such as configuration flags for paths, batch processing, and dry-run modes. The use of these flags with this specific executable name is a strong indicator of malicious activity.
Detects the creation of files with the name 'README_KRSID.Txt', which is a hallmark behavior of the KRSID ransomware strain used to leave ransom notes on compromised systems.
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Page 264 of 1871

