Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects the creation or modification of a file named 'ClipBoard.txt' within the directory 'AppData\Roaming\ConfigsEx\', as well as the creation of the 'ConfigsEx' directory using command-line tools. This behavior is indicative of an adversary staging sensitive information, such as harvested clipboard data, for potential exfiltration.
Detects instances where browser processes or related credential files are accessed or targeted by process termination (e.g., taskkill.exe) followed by attempts to access sensitive files like Login Data, logins.json, or key4.db. This pattern is indicative of credential theft from web browsers.
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
Detects a potential destructive activity pattern involving the staging of a payload in a non-standard directory (utilizing a directory name with a trailing space) followed by a burst of file deletions on the same device. This behavior is indicative of a secondary destructive payload execution, often associated with disk-wiping malware.
Detects a potential destructive activity pattern involving the staging of a payload in a non-standard directory (utilizing a directory name with a trailing space) followed by a burst of file deletions on the same device. This behavior is indicative of a secondary destructive payload execution, often associated with disk-wiping malware.
Detects a suspicious sequence of activity involving persistence via Registry Run keys (specifically targeting SMQDService or winappx entries) followed by modifications to Microsoft Defender configuration (adding exclusions via PowerShell) within a two-hour window on the same device.
Detects a suspicious sequence of activity involving persistence via Registry Run keys (specifically targeting SMQDService or winappx entries) followed by modifications to Microsoft Defender configuration (adding exclusions via PowerShell) within a two-hour window on the same device.
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
Detects network connection attempts from endpoints to known proxy service domains (IPRoyal, LightningProxies) that have been observed acting as infrastructure for CHOSEN BRICK Telegram-based C2 and exfiltration traffic.
This rule detects outbound network connections from processes to known public cloud object storage providers (vultrobjects.com, storjshare.io, backblazeb2.com). These domains have been associated with the 'CHOSEN BRICK' threat actor's secondary data exfiltration paths for stolen assets such as screenshots, audio, and browser/email data.
This rule detects modifications to Windows 'Run' registry keys, specifically monitoring for the creation or value setting of keys associated with known suspicious or persistence-related names such as 'SMQDService' or 'winappx'. These registry keys are frequently used by attackers to maintain persistence by ensuring malicious code executes automatically upon user login.
Detects a suspicious sequence of activity involving persistence via Registry Run keys (specifically targeting SMQDService or winappx entries) followed by modifications to Microsoft Defender configuration (adding exclusions via PowerShell) within a two-hour window on the same device.
Detects a potential destructive activity pattern involving the staging of a payload in a non-standard directory (utilizing a directory name with a trailing space) followed by a burst of file deletions on the same device. This behavior is indicative of a secondary destructive payload execution, often associated with disk-wiping malware.
Detects the creation of specific mutexes associated with the CHOSEN BRICK malware shortly after establishing persistence via Windows Run registry keys. This behavior indicates a potentially malicious process initializing its single-instance guardrail on a compromised host.
Detects files written to a non-standard path containing a deliberate trailing space after 'Windows' (e.g., 'C:\Windows \SysWOW64') combined with the creation of a registry run key for persistence. This pattern is associated with the CHOSEN BRICK threat activity to hide and maintain persistence for secondary payloads.
This rule detects the creation of executable files (.exe or .dll) within the 'C:\Windows\SysWOW64\' directory by processes other than trusted Windows OS installation or servicing components. This activity is indicative of potential malware staging, side-loading, or persistence mechanisms where an adversary drops malicious payloads into a trusted system directory to evade detection.
Detects specific malicious processes (smdqservice.exe, winappx.exe) or suspicious paths associated with the CHOSEN BRICK malware suite writing image files (png, jpg, jpeg, bmp) to sensitive system directories. This activity typically precedes the exfiltration of sensitive desktop capture data to C2 infrastructure.
This rule detects the addition of Microsoft Defender exclusions via PowerShell cmdlets (Add-MpPreference, Set-MpPreference) or direct Registry key modifications, occurring within two hours of a new autorun persistence entry being created on the same device. This behavior is indicative of a persistence-then-evasion sequence often used to ensure malicious tools remain undetected.
Page 284 of 1871

