Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects the execution, file creation, or registry modification associated with specific ScreenConnect (ConnectWise Control) installation artifacts that align with known suspicious deployment patterns. It monitors for binaries and configuration artifacts that may indicate the unauthorized installation or persistence of remote administration tools.
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
This rule performs a hunting activity across multiple telemetry sources (Network, Email, Endpoint) to detect known indicators of compromise (IOCs) associated with Anthropic threat intelligence reporting (September 2026). It looks for specific malware file names, command-line patterns, service installations, phishing email addresses, and C2 communication URLs.
Detects unauthorized access or file creation events targeting the 'tdata' directory, which stores local Telegram session and authentication data. The rule triggers when processes other than legitimate Telegram or system file explorers interact with these files, a common technique for session theft and account takeover.
This rule detects potentially malicious behavior involving the Python interpreter spawning command-line shells (cmd.exe or powershell.exe), or interactions (creation/modification) with a specific file at 'C:\ProgramData\ur.txt'. This behavior is often associated with post-exploitation activities, staging, or script-based execution of malicious payloads.
This rule detects the execution of specific suspicious binary names or processes loading a specific DLL from locations outside of the legitimate Windows System32 or SysWOW64 directories. This behavior is indicative of potentially malicious executables or side-loaded DLLs masquerading as system components or running from non-standard locations to evade detection.
Detects Microsoft Edge executable (msedge.exe) being created, deleted, or renamed within the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This path is often used by adversaries to masquerade malicious files or persistence mechanisms as legitimate telemetry components.
Detects instances of an executable named msedge.exe running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a suspicious location for a browser executable, often used by malware to masquerade as legitimate software to evade detection.
This rule detects processes manually resolving API function addresses by traversing the Process Environment Block (PEB) Ldr structure or parsing module export tables. This technique is often used by malicious code to resolve Windows API functions dynamically without relying on standard LoadLibrary or GetProcAddress calls, effectively evading common API-hooking based monitoring.
Detects the use of PowerShell to download files from Vultr Object Storage, specifically targeting patterns associated with the HEAVYGRAM malware distribution. The rule monitors for PowerShell cradles (WebClient, DownloadFile), archive extraction commands, or the execution of a specific payload name (RuntimeSSH.exe) often linked to the Handala Hack threat activity.
Detects instances where processes other than the legitimate Telegram Desktop application or its updater attempt to access files within the Telegram Desktop 'tdata' directory. This directory contains session information, which can be harvested by malicious actors to hijack user sessions or access sensitive information.
Detects the execution of a binary named 'msedge.exe' from within the 'Windows\Telemetry' directory. This behavior is indicative of the MovieReaper malware attempting to masquerade as the legitimate Microsoft Edge browser to evade detection and maintain persistence.
Detects instances where processes other than the legitimate Telegram Desktop application or its updater attempt to access files within the Telegram Desktop 'tdata' directory. This directory contains session information, which can be harvested by malicious actors to hijack user sessions or access sensitive information.
Detects the execution of a binary named 'msedge.exe' from within the 'Windows\Telemetry' directory. This behavior is indicative of the MovieReaper malware attempting to masquerade as the legitimate Microsoft Edge browser to evade detection and maintain persistence.
Detects network activity associated with the HEAVYGRAM PowerShell implant, specifically identifying outbound traffic to the Telegram Bot API (api.telegram.org). The rule looks for established connections and HTTP requests containing Telegram bot-specific URI patterns ('/bot', '/getUpdates') coupled with a 'WindowsPowerShell' user agent, indicating an automated beaconing mechanism used for command and control.
Detects network communication to known MovieReaper C2 infrastructure (deadhub.org or 193.23.118.155) originating from a masqueraded 'msedge.exe' process located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicating potential C2 check-ins or data exfiltration by the file manager module.
Detects the use of the undocumented NTAPI function EtwpCreateEtwThread within a thread creation call trace. This function is often abused by shellcode loaders to execute malicious code within a target process while attempting to evade standard EDR detection mechanisms.
Detects the execution of the MovieReaper malware loader, which masquerades as 'msedge.exe' within the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This technique is used to bypass anti-sandbox checks by respawning as a legitimate-looking process in a persistent location after initial environment analysis is completed.
Detects the execution of processes with suspicious file names that are commonly associated with masquerading, potentially impersonating legitimate software or system tools.
Detects the execution of suspicious executables spawned from common torrent client applications. This rule monitors for known malicious file hashes or processes launched by torrent clients with suspicious naming patterns typically associated with pirated software or malware masquerading as media files (e.g., tags like 1080p, x264, bluray in executable names).
This rule detects Windows executable files that attempt to masquerade as legitimate software installers for Telegram, KeePass, or Pictory. These filenames and branding artifacts are associated with social engineering campaigns known to distribute malware families such as HEAVYGRAM and CRUDEEXCLUDE.
Page 270 of 1871


