Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects the execution of PowerShell or Command Prompt processes that attempt to bypass execution policies while performing file downloads from suspicious domains (mnl.ac) or IP addresses (149.255.35.135). It also flags the use of common web-request cmdlets (Invoke-WebRequest, IWR, DownloadString, DownloadFile) to fetch scripts named 'configuration.ps1'. The rule includes detection for obfuscated commands using caret (^) symbols often used to evade keyword-based security filters.
This rule detects the execution of PowerShell or Command Prompt processes that attempt to bypass execution policies while performing file downloads from suspicious domains (mnl.ac) or IP addresses (149.255.35.135). It also flags the use of common web-request cmdlets (Invoke-WebRequest, IWR, DownloadString, DownloadFile) to fetch scripts named 'configuration.ps1'. The rule includes detection for obfuscated commands using caret (^) symbols often used to evade keyword-based security filters.
Detects the creation or execution of script files (.lnk) within the Windows Startup folder initiated by script hosts (wscript.exe or cscript.exe) that contain suspicious command-line arguments indicative of malicious activity, such as PowerShell obfuscation or encoded commands.
Detects the use of fsutil.exe to create a hardlink pointing to files within a user's AppData directory, specifically involving a folder named 'doxc'. This behavior is often associated with file manipulation to bypass security controls or masquerade malicious files.
Detects the use of cmd.exe to execute copy commands involving specific batch files (doxc.bat or config.bat) or suspicious file paths, which may indicate malicious file staging or automated data collection behavior.
Detects behavior indicative of KRSID ransomware, characterized by mass file renaming to the .krsid extension and the creation of a 'ransomware-silent.Log' file. The detection specifically correlates this activity with the absence of vssadmin shadow copy deletion commands, which is an atypical behavior for most ransomware families, thereby serving as a distinguishing heuristic.
Detects the use of PowerShell to perform recursive file/directory enumeration within sensitive user profile directories (Desktop, Documents, Downloads, Pictures, OneDrive) immediately followed by a network connection over port 443. This behavior is indicative of potential data staging and exfiltration activity performed by a malicious script or threat actor.
Detects the presence of QuasarRAT-related processes combined with the creation of known log filenames associated with its keylogging functionality.
Detects persistence attempts via registry run key modifications or additions, specifically targeting the 'DailyFitnessTracker' value. The rule monitors both direct registry operations (value setting, key creation) and process-based modifications performed by reg.exe or PowerShell.
Detects attempts to clear Windows event logs using administrative tools like wevtutil.exe, PowerShell, or through the detection of mass log-clear audit events (such as Event IDs 1102 and 104) occurring in a rapid burst. This activity is often used by adversaries to hide evidence of post-compromise actions.
Detects attempts to clear Windows event logs using administrative tools like wevtutil.exe, PowerShell, or through the detection of mass log-clear audit events (such as Event IDs 1102 and 104) occurring in a rapid burst. This activity is often used by adversaries to hide evidence of post-compromise actions.
Detects the loading of the 'gdrv.sys' driver, which is a known vulnerable driver often used in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks to facilitate privilege escalation to kernel mode.
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
This rule detects the presence, installation, or execution attempts of the known vulnerable GIGABYTE driver (gdrv.sys). Monitoring for this specific driver is a common practice to identify attempts to perform 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, which can be used for kernel-mode code execution and privilege escalation.
This rule detects the presence, installation, or execution attempts of the known vulnerable GIGABYTE driver (gdrv.sys). Monitoring for this specific driver is a common practice to identify attempts to perform 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, which can be used for kernel-mode code execution and privilege escalation.
Detects host-enumeration activities performed by PowerShell processes, including anti-virus queries, system information gathering, network configuration checks, and file/drive enumeration, specifically when correlated with suspicious outbound network connections to common task-runner C2 infrastructure.
Detects a sequence of PowerShell commands consistent with the VelvetCake reconnaissance module, including enumeration of antivirus software via SecurityCenter2, system information, IP configurations, running processes, recent files, and drive mapping within a short timeframe.
Detects instances where the Zoom installer process (zoominstaller.exe) initiates potentially suspicious child processes such as cmd.exe, powershell.exe, or scripting hosts (wscript.exe, cscript.exe) that are executing script files within a short timeframe. This behavior is indicative of a potential installer hijack or malicious payload execution attempting to leverage the context of a legitimate software installer.
Detects a sequence of PowerShell commands consistent with the VelvetCake reconnaissance module, including enumeration of antivirus software via SecurityCenter2, system information, IP configurations, running processes, recent files, and drive mapping within a short timeframe.
Detects a multi-stage malware execution pattern consistent with VelvetCake activity. This includes staging text-based files in C:\Users\Public, downloading PowerShell scripts to temporary directories, executing the script via PowerShell, and subsequently deleting both the staged text files (except for specific allowed filenames) and the payload script.
Page 265 of 1871


