Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the ClickFix social-engineering pattern where a user is tricked into pasting and executing a command, typically via the Windows Run dialog (explorer.exe), that triggers the command shell (cmd.exe or powershell.exe) to utilize finger.exe or curl.exe for downloading and staging malicious payloads like CastleRAT.
Detects unauthorized access to critical browser files such as cookies, login data, and local state files. These files contain sensitive information such as authentication cookies and stored credentials, which are primary targets for infostealer malware.
Detects the execution of curl.exe by various script interpreters (cmd.exe, powershell.exe, wscript.exe, mshta.exe) or Windows Explorer. This pattern is commonly used by adversaries to download malicious payloads or intermediate loaders as part of an attack chain, such as deploying CastleLoader/CastleRAT.
Detects the presence of the CastleLoader intermediate loader binary on disk, associated with the SloppyRAT infection chain. The rule identifies specific file content patterns, including hardcoded strings such as 'CastleLoader', 'CastleRAT', specific user-agents, and embedded Python code used for base64/zlib decoding of further payloads.
Detects the CastleRAT intermediate loader, which acts as a secondary stage before deploying SloppyRAT. The rule identifies the malicious payload by scanning for unique embedded strings, specific user-agent strings, and command-and-control (C2) communication patterns (domains and URI paths) within executable files.
Detects the loading or presence of the Alinubx.sys kernel driver, a malicious component used for Bring Your Own Vulnerable Driver (BYOVD) attacks. This driver facilitates the mass termination of security product processes (AV/EDR) by exposing a specific IOCTL (0x222024) to interface with kernel-mode process termination primitives (e.g., ZwTerminateProcess), often serving as a precursor to the deployment of stealers like Rapuncel.
Detects suspicious PE files that masquerade as Mozilla Firefox by using Firefox-related product names and metadata, but lack valid Mozilla Corporation code-signing signatures and are located within the ProgramData directory.
This rule detects modifications to the Windows hosts file by unauthorized processes. The hosts file is often targeted by adversaries to redirect network traffic, intercept communications, or prevent access to security-related websites.
Detects the use of PowerShell commands that reflectively load assemblies into memory, often associated with obfuscated or encoded payloads typically used in fileless malware execution and post-exploitation activity.
Detects the execution of PowerShell commands intended to gather system information, specifically targeting the discovery of security software (anti-virus/EDR) and virtualization/sandbox artifacts. This behavior is indicative of an attacker performing environment reconnaissance to identify defensive controls or to determine if the payload is executing within an analysis environment.
Detects the execution of an LNK file that initiates a command chain resulting in an encoded PowerShell script. This behavior is indicative of malicious shortcut files often used in initial access to trigger multi-stage payloads, consistent with techniques observed in Kimsuky-linked infection chains.
Detects the execution of a .lnk file that directly triggers a PowerShell process. This behavior is frequently associated with malicious shortcut files used in initial access and execution, such as those observed in Kimsuky (APT-C-55) infection chains where disguised installers drop LNK files that execute PowerShell scripts for anti-analysis and subsequent payload deployment.
Detects non-browser processes performing file operations (create, modify, rename) on known web browser credential storage, configuration files, and cryptocurrency wallet artifacts in a short duration. This behavior is indicative of credential harvesting or information stealing activity often associated with malware like Vidar, which stages these sensitive files for exfiltration.
Detects execution of PowerShell spawned by suspicious processes (e.g., installers or Windows Explorer) involving LNK file patterns or suspicious command-line obfuscation techniques commonly associated with Kimsuky (APT-C-55) activity.
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
This rule identifies potential malicious activity by detecting the presence of known malicious file hashes (SHA256 and MD5) on endpoints and monitoring for DNS queries or network connections to a known malicious staging domain (yapw.life). The detection correlates file execution, file activity, and network communication to identify stages of an attack such as malware installation or C2 communication.
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
Page 278 of 1871


