Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
Detects the MovieReaper payload behavior where a specific file manager process masquerading as a legitimate system utility (msedge.exe) performs mass file enumeration or access followed by suspicious outbound network connections, indicative of data staging and exfiltration.
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
Detects execution of the MovieReaper initial loader, which employs specific anti-sandboxing and anti-analysis techniques. The detection relies on identified file hashes, as well as heuristic analysis of process filenames containing common media-related keywords in sensitive directories and command line arguments indicating the presence of Global mutexes.
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
Detects instances where a process named msedge.exe is running from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. This is a common location used by attackers to hide malicious executables by masquerading them as legitimate browser processes, particularly when the process command line includes arguments like 'preview' or 'thumbnail' which are often used to blend in with background system activity.
Page 273 of 1871
