Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of a scheduled task using 'schtasks.exe' configured to run as the SYSTEM account for a one-time execution. This behavior is often associated with persistence mechanisms or privilege escalation attempts where an adversary seeks to execute malicious code in a high-privileged context.
This rule detects the use of 'taskkill.exe' to terminate critical services, including security software (MsMpEng.exe), database processes (sql.exe, oracle.exe, sqlservr.exe), and common user applications (outlook.exe, onedrive.exe). This behavior is characteristic of the DragonForce ransomware, which disables protective services and applications before encryption to minimize interference and ensure successful file locking.
Detects unauthorized modification of the registry path 'HKCU\Software\Classes\ms-settings\Shell\Open\command'. This registry key is commonly hijacked by the 'fodhelper.exe' UAC bypass technique, where an attacker writes a malicious command to be executed with elevated privileges when the OS triggers the ms-settings protocol handler.
Detects the CRPx0 ransomware technique of unhooking ntdll.dll in memory. This is achieved by reading the ntdll.dll file from disk and overwriting the in-memory .text section with a clean, unhooked version to bypass EDR monitoring and execute direct syscalls.
Detects modifications to the Windows RunMRU registry key that include suspicious strings such as 'powershell', 'curl', or long base64-encoded sequences. This behavior is indicative of the 'ClickFix' technique, where users are socially engineered to paste and execute malicious commands directly into the Windows Run dialog.
Detects the execution of PowerShell encoded commands that result in the installation of known remote monitoring and management (RMM) software. This pattern is indicative of attackers, specifically those associated with Ransom Busters or similar affiliates, establishing persistent remote access to compromised systems.
Detects the creation of a Windows scheduled task configured to execute as the SYSTEM account using a one-time execution trigger. This combination is frequently used by adversaries for post-exploitation activities, such as lateral movement or persistence, as it allows for a single, immediate execution of a malicious payload with high-level privileges.
Detects the execution of the SoftPerfect Network Scanner tool (netscan.exe), which is often used by adversaries for reconnaissance to identify active hosts, open ports, and services within a network.
Detects the termination of critical processes, including security software (MsMpEng.exe), database services (sql.exe, oracle.exe, sqlservr.exe), and office productivity applications (excel.exe, outlook.exe, winword.exe). The sudden termination of these processes can indicate unauthorized attempts to disable security controls, disrupt database operations, or interfere with end-user activity.
Detects files containing specific structural footers (537 bytes) and RSA key generation strings commonly associated with ransomware encryption. The footer indicates the use of RSA-4096 to encrypt files, with modes for full, striped, or header-only encryption patterns.
This rule monitors Microsoft Teams communications for keywords related to passkey or Single Sign-On (SSO) configuration, which are common themes in social engineering and credential harvesting attacks. It correlates these messages with Windows logon events (Event ID 4624) for the sender to identify potentially compromised accounts or active phishing attempts originating from within the environment.
Detects DNS resolution requests for graph.microsoft.com initiated by a python interpreter (python.exe, python3.exe, or pythonw.exe). This activity may indicate a script or custom tool communicating with Microsoft Graph API, which is frequently used for data collection, exfiltration, or cloud service interaction in adversarial campaigns.
Detects DNS resolution requests to 'graph.microsoft.com' on endpoint devices. This is intended to act as a precursor indicator for potential Microsoft 365 or Azure environment enumeration and discovery activities, which would typically involve subsequent API calls.
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
Page 272 of 1871

