Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of AutoIt3 scripts using mshta.exe as the parent process from suspicious or non-standard directories such as Temp, Downloads, or AppData. This behavior is indicative of an attempt to bypass application execution policies or obfuscate malicious script execution.
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
Detects potential process injection attempts by unidentified executable files originating from suspicious directories (AppData or Temp) targeting critical system or service processes (e.g., explorer.exe, svchost.exe). The rule monitors CreateRemoteThread events and excludes signed dotnet host processes, characteristic of Hannibal Stealer behavior.
Detects instances where a process other than the legitimate Firefox browser executable loads the NSS (Network Security Services) libraries nss3.dll or mozglue.dll from the Firefox installation directory. This behavior is indicative of unauthorized attempts to decrypt saved browser credentials by interacting with Firefox-specific security modules, a technique commonly used by credential-stealing malware.
Detects the presence of configuration markers associated with cryptocurrency clipboard-swapping malware. The rule monitors process command lines for specific flags (e.g., 'cclipper', 'clipboard_check_delay') and cryptocurrency wallet address dictionary keys, which are common indicators of malicious software designed to replace legitimate destination wallet addresses copied to the clipboard with attacker-controlled addresses.
This rule detects the presence of the 'antiSNG' flag in command-line arguments of newly created processes. This flag is specific to the configuration of Hannibal Stealer, which uses it to perform anti-analysis checks, likely related to geofencing or environmental detection to evade sandbox or security analyst investigation.
Detects the execution of a potentially malicious, renamed AutoIT interpreter from a temporary directory, where the process command line or associated file activity involves a specific, obfuscated loader script (kojuyn.ini). The rule identifies behavioral patterns consistent with malware staging and execution, including the use of random filenames for both the interpreter and the script, characteristic of loaders using custom string deobfuscation and decryption routines.
Detects the initialization of the SEE_MASK_NOZONECHECKS environment variable within a PowerShell process command line. Setting this variable to '1' is a known technique used to suppress Windows zone-based security prompts (Mark-of-the-Web) for downloaded files, facilitating the execution of potentially malicious payloads.
Detects a suspicious sequence of Microsoft-signed .NET binaries (regsvcs.exe, installutil.exe, msbuild.exe, aspnet_compiler.exe) spawned by a single parent process in a short timeframe. This behavior is indicative of an attacker cycling through multiple trusted binaries in a fallback strategy to bypass application allowlisting or endpoint protection controls.
Detects unauthorized modifications to the InprocServer32 registry key for the specific CLSID {2155fee3-2419-4373-b102-6843707eb41f}, a technique used by malware to achieve persistence by hijacking COM object instantiation to load a malicious DLL.
Detects the termination of 'wscript.exe' using 'taskkill.exe' or PowerShell 'Stop-Process'. This behavior is commonly used by malicious loaders to stop script-based execution after a payload has been staged or executed to minimize forensic artifacts and potential detection by defenders monitoring long-running processes.
Detects the Windows Script Host (wscript.exe or cscript.exe) executing files with suspicious double extensions, specifically those mimicking PDF documents (e.g., .pdf.js) or utilizing the .jse extension. This pattern is commonly associated with fileless initial execution lures, often seen in ClickFix-style or VEIL#DROP campaigns designed to trick users into executing malicious scripts.
Detects the use of .NET reflection APIs, such as Assembly.Load or Reflection.Emit, within PowerShell command lines. This technique is commonly used to load and execute malicious code entirely in memory, facilitating fileless malware execution and bypassing traditional disk-based security controls.
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
HBO Max ClickFix attacks IOC Hunt
Cortex XDR
Detects network activity (DNS queries or direct IP communication) associated with 'ClickFix' social engineering attacks targeting users under the guise of an HBO Max update or repair utility. The rule includes indicators for known malicious domains and IP addresses while incorporating filters to minimize false positives from security scanners, threat intel feeds, and automated crawlers by analyzing User-Agent strings and network source addresses.
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
This rule detects the use of 'npm' or 'node' to install packages from a registry other than trusted, standard registries (e.g., npmjs.org, GitHub). It specifically monitors command lines involving 'claude-code' that utilize custom, non-standard registry URLs. This behavior is indicative of potential supply chain attacks or the installation of unauthorized/malicious dependencies.
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
Page 285 of 1871


