Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Movie Reaper Activity
YARA-L
Detects activity associated with MovieReaper campaign including process, file, and network indicators
Movie Reaper Activity
YARA-L
Detects activity associated with MovieReaper campaign including process, file, and network indicators
Movie Reaper Activity
YARA-L
Detects activity associated with MovieReaper campaign including process, file, and network indicators
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
This rule monitors DeviceNetworkEvents for outbound network connections to a list of known malicious IP addresses associated with various C2 frameworks and malware families, as identified by threat intelligence feeds (e.g., ThreatFox). Identifying these connections helps detect potential C2 communication and ingress tool transfer.
This rule monitors for ADFS-related security events that may indicate credential theft or authentication bypass attempts. It flags anomalous federated sign-in events (e.g., MFA bypass, unfamiliar location), unauthorized access to the ADFS DKM container in Active Directory, and suspicious attempts to export ADFS token-signing certificates.
Detects successful network connections to a specific domain (buildersouthwestlondon.com) where the request URL path includes the string '/cloud/'. This pattern is often indicative of downloading secondary payloads, command-and-control communication, or accessing malicious infrastructure related to a specific campaign.
This rule detects the presence of files matching known SHA256 hashes associated with the GhostCode phishing kit. It monitors for these files both in email attachments and on local device filesystems to identify potential delivery and execution of malicious phishing payloads.
This rule monitors for outbound network connections to a list of known malicious IP addresses identified as part of the GhostCode command-and-control (C2) infrastructure. It uses DeviceNetworkEvents data to flag activity originating from endpoints and highlights a specific IP address used during the Intune/MDM enrollment process for further investigation.
This rule detects internal network activity (DNS queries, network connections, and security logs) communicating with domains associated with the GhostCode phishing kit. These domains are typically used to host credential harvesting pages or phishing infrastructure.
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
Detects network activity and HTTP request headers associated with the GhostCode phishing kit. The rule identifies specific URI patterns, custom site keys, malicious User-Agent strings, and session cookie artifacts indicative of interaction with a phishing server.
This rule detects the presence of files matching known SHA256 hashes associated with the GhostCode phishing kit. It monitors for these files both in email attachments and on local device filesystems to identify potential delivery and execution of malicious phishing payloads.
Detects mass file renaming activity associated with OpnKey ransomware, which appends specific ransom identifiers to files. This behavior is indicative of the encryption phase of a ransomware attack, where files are renamed to reflect the encryption status or to include a unique victim identifier.
Detects anomalous network connection attempts using DCOM (port 135) or WinRM (ports 5985/5986) that originate from external networks or exceed established internal baseline frequencies. This pattern is often indicative of lateral movement or remote administration abuse via WMI or WinRM.
Detects instances of PowerShell being launched directly by Windows Explorer (explorer.exe), which is indicative of a user interacting with the 'Run' dialog (Win+R). The rule specifically flags common ClickFix social-engineering patterns, such as hidden windows and the use of download/execution cmdlets (e.g., Invoke-WebRequest, Invoke-RestMethod) used to fetch and run remote payloads.
Detects PowerShell command execution patterns indicative of the VelvetCake malware module. The rule identifies scripts that enumerate files within the C:\Users\Public directory, calculate file metrics using [math]::Round, and stage discovered files for transmission over a raw TCP connection using System.Net.Sockets.TcpClient.
Page 274 of 1871



