Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects non-browser processes performing file operations (create, modify, rename) on known web browser credential storage, configuration files, and cryptocurrency wallet artifacts in a short duration. This behavior is indicative of credential harvesting or information stealing activity often associated with malware like Vidar, which stages these sensitive files for exfiltration.
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
This rule monitors for network connections to Telegram-related domains (t.me, telegra.ph, teleg.run) initiated by processes other than standard web browsers. This behavior is frequently associated with malware or adversary tools utilizing the Telegram API for command and control (C2) or data exfiltration, as it bypasses legitimate browser usage.
Detects the execution of PowerShell with suspicious command-line arguments (headless mode, hidden window, encoded commands) spawned by WScript.exe. This pattern is commonly associated with obfuscated script execution or fileless malware staging.
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
This rule detects potential malicious activity by matching file hashes against a known list of malicious indicators and monitoring for suspicious network connections. The network monitoring includes connections to hardcoded malicious IP addresses, specific C2 URLs, and DNS queries for known fallback domains used in malicious infrastructure when the initiating process is not a recognized web browser or wallet application.
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
Detects anomalous post-exploitation behavior associated with SectopRAT, where a suspicious process (e.g., ReportDump.exe) establishes a persistent network connection to a known C2 IP address followed closely by the invocation of common command-line utilities (cmd, powershell, tasklist, etc.) used for file and process management.
This rule detects potential SectopRAT loader activity by identifying non-.NET-native processes accessing 'pool.db' in the ProgramData directory followed by the immediate loading of .NET CLR libraries (clr.dll or mscoreei.dll). This pattern is indicative of reflective loading of a decrypted .NET payload into memory within a target process.
Detects network communication associated with the SectopRAT/ArechClient2 remote access trojan, specifically identifying its characteristic length-prefixed, AES-encrypted command-and-control handshake on non-standard ports. The rule matches traffic containing a specific length-prefixed packet structure starting with null bytes, typically seen during C2 check-in.
Detects potential activity related to the SectopRAT loader by monitoring the execution sequence of 'ReportDump.exe'. The rule identifies the side-loading of a specific DLL ('sdkcra.dll') followed by the process reading a known configuration or database file ('pool.db') within a short time window, which is indicative of the loader's secondary decryption phase.
Detects a specific execution sequence associated with the SectopRAT loader. The rule identifies a process named 'ReportDump.exe' reading a payload file 'Activation.Desktop.db' and subsequently loading 'stp_aim_x64_vc15.dll', which is known to trigger malicious shellcode via an exported function.
Detects the use of the Windows command shell (cmd.exe) to execute a file deletion command following a forced delay using the 'choice' command. This technique is often used by adversaries to facilitate file deletion by introducing a pause, possibly to bypass file locks or to time execution during an intrusion.
Detects network activity related to the SectopRAT malware downloading a secondary module named 'WbElevation.dll' from a known command and control (C2) server. This module is typically associated with browser credential theft functionality.
Detects the suspicious loading of both 'FrameworkBase.dll' and 'sdkcra.dll' by the 'ReportDump.exe' process within a two-minute window. This behavior is often associated with the execution of specialized tools or potential post-exploitation activity where legitimate processes are abused to load specific modules.
Detects the execution of 'ReportDump.exe' from within the 'C:\ProgramData' directory when initiated by system processes associated with scheduled tasks (svchost.exe, taskeng.exe, schtasks.exe) containing 'Schedule' in the command line. This behavior is indicative of potential persistence mechanisms or malicious file execution using legitimate Windows scheduling utilities.
Detects the use of ntdsutil.exe to create an Install From Media (IFM) set, which copies the NTDS.dit file and registry hives to a specified folder. Adversaries often use this technique to stage Active Directory credentials for exfiltration, frequently using the C:\Windows\Temp directory as a staging area. The rule includes exclusions for common legitimate system management and backup agents.
Detects network communication with 10729e014d0e.skyleen.fr, associated with the SCKIT malware downloading binaries during CI/CD emitter activities. This rule flags potential ingress tool transfers as part of a supply chain compromise campaign identified as 'memos-semi-nuclear'.
Detects specific C2 communication patterns associated with SCKIT, including HTTPS beaconing to the skyleen.fr domain and structured URI patterns used for configuration and status requests.
Detects the execution of the 'sckit' Go-based implant when spawned by Node.js or Python processes using the command-line arguments 'stage0 --config64'. This pattern is associated with malicious npm and PyPI supply chain packages (memtensor) designed to harvest credentials and establish persistence.
Detects malicious BASH_ENV injection within GitHub Actions CI pipelines originating from the compromised sckit_poetry_build.py build backend. The injection, which targets GITHUB_ENV to introduce a malicious _pypi_bridge.sh script, is used to intercept PyPI publishing tokens during build processes, characteristic of the MemTensor/sckit supply chain attack.


