Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors endpoint telemetry (File, Process, and Network events) to identify activity associated with a pre-defined set of known malicious file hashes, IP addresses, and domains. It correlates these indicators to detect potential malware execution, persistence, or command-and-control communication on monitored devices.
Detects the use of tasklist.exe combined with process filtering (findstr) to identify common debugger names such as 'dbg.exe', 'x64dbg.exe', 'windbg.exe', or 'ollydbg.exe'. This technique is a known evasion tactic employed by the Kimsuky threat group (and others) to check for the presence of analysis tools before continuing execution of malicious batch scripts.
Detects the creation of a scheduled task named 'OneDrive KeepAlive' or a task set to execute every 5 minutes, in conjunction with the execution of 'taskhostw.exe' containing 'exec hide' in its command line. This pattern is indicative of the Kimsuky threat group using a renamed version of the NirCmd utility to maintain persistence and execute commands silently.
Detects the suspicious copying of the Windows certutil.exe binary to an alternate location (e.g., /Users/Public/Downloads/) followed by execution with decoding or caching flags. This behavior is indicative of an adversary attempting to use certutil as a LOLBin to decode or reassemble malicious payloads, a tactic frequently observed in Kimsuky-related LNK malware campaigns.
Detects unauthorized access to common browser credential and cookie files by processes other than standard web browsers. This activity is a common indicator of credential harvesting malware or unauthorized data collection.
Detects PowerShell command execution containing specific strings associated with the Veil framework XOR decoding routine, including a hardcoded key and the use of the -bxor operator for payload deobfuscation.
Detects instances where WScript.exe or CScript.exe spawn PowerShell.exe as a child process. The rule specifically looks for command-line arguments indicative of policy bypass (-ExecutionPolicy Bypass) and remote payload retrieval (Invoke-WebRequest, DownloadString), which is a common pattern in obfuscated JavaScript-based infection chains.
Detects the use of .NET reflection APIs (specifically System.Reflection.Assembly::Load) within PowerShell script blocks. This technique allows for the dynamic loading of .NET assemblies into memory, often to execute obfuscated or encrypted payloads without writing them to disk, which is a common tactic for bypassing file-based security controls.
Detects the use of PowerShell Stop-Process being used to terminate common scripting and .NET-related processes, a behavior associated with the Veil#Drop loader to clear potential conflicts or interference from legitimate host processes.
Detects the use of [ScriptBlock]::Create() within PowerShell command lines. This method allows for the dynamic construction and execution of arbitrary PowerShell code entirely in memory, a technique often used by fileless malware and frameworks like Veil#Drop to evade disk-based detection mechanisms.
Detects the potential creation or execution of malicious JavaScript files that masquerade as PDF or other common documents using double extensions (e.g., .pdf.js). This behavior is often associated with file-based loaders where the operating system masks the true file extension. The rule also triggers when these files are explicitly launched via Windows Script Host (wscript.exe or cscript.exe).
This rule aggregates vulnerability data from Microsoft Defender for Endpoint (Threat and Vulnerability Management) over the last 7 days. It groups vulnerable devices by CVE ID and severity level, providing an overview of known software weaknesses currently present across the fleet.
Detects the presence of a specific malicious _socket.pyd Python module associated with LegionLoader dropped into non-standard directories like 'Traiolx Custom Utils'. The detection leverages file path patterns and known file hashes of the malicious component.
Detects the execution of mshta.exe with command-line arguments that reference VLC-themed filenames or presentations. This behavior is indicative of a malicious HTA file being used as a lure to drop the Lightlife RAT loader, leveraging the mshta.exe utility to bypass standard application execution controls.
Detects modifications to Windows Registry Run keys that execute PowerShell scripts named 'Update.ps1' with hidden window and bypass execution policy flags. This pattern is consistent with Lightlife RAT persistence mechanisms.
Detects the execution of PowerShell with a combination of flags commonly used to hide malicious activity: -NoProfile, -WindowStyle Hidden, and -EncodedCommand. This combination is frequently used by adversaries to execute obfuscated code silently, bypassing user visibility and script analysis.
Detects the execution of wscript.exe as a child process of mshta.exe, specifically when the wscript.exe command line contains references to .vbs or .js files. This behavioral pattern is often associated with malicious HTA files using mshta.exe as a proxy to execute secondary script payloads, a technique commonly leveraged for initial access and execution.
Detects PowerShell execution commands attempting to disable Antimalware Scan Interface (AMSI) by reflectively accessing System.Management.Automation.AmsiUtils. This is a common technique used by attackers to execute malicious scripts while avoiding detection by security software.
Detects the execution of the Lightlife RAT via a PowerShell script named 'lightlife.ps1'. The rule monitors for processes running from the LOCALAPPDATA directory, the use of PowerShell with execution policy bypass and hidden window style, or execution triggered via common scripting hosts like wscript.exe or mshta.exe combined with PowerShell download cmdlets.
Detects Python compiled bytecode (.pyc) files that have been renamed to .cat, a common Windows Security Catalog extension. This is a masquerading technique often used by backdoors to evade detection and facilitate malicious loader execution.
Detects the registration of the gitlab-runner Windows service as a custom Event Log provider under the Application registry key. This registry modification occurs during the installation of the GitLab Runner service. When observed on endpoints not intended for CI/CD operations, this activity may indicate an adversary is installing a GitLab Runner for use as a C2 implant.
Page 283 of 1871


