Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of Windows services using sc.exe, powershell.exe, or cmd.exe that reference specific DLL files (winfsp-x64.dll or DukeQt.dll). This behavior is often associated with persistence mechanisms or DLL hijacking/side-loading techniques where a malicious service is configured to load a specific library.
Detects the loading of known SparroWocky loader DLLs (winfsp-x64.dll or DukeQt.dll) into a process, followed by the absence of new executable file creation within the same process and time window. This behavior is indicative of in-memory execution techniques, such as Beacon Object File (BOF) loading, aimed at extending implant functionality without writing files to disk.
Detects process executions, file deletions, renames, and movements initiated by known SparroWocky malware files or suspicious DLLs (winfsp-x64.dll, DukeQt.dll). This monitors malicious lifecycle activity on endpoints.
This rule detects the suspicious loading of known SparroWocky loader DLLs (winfsp-x64.dll or DukeQt.dll) into a process, followed by that same process loading graphics-related libraries (gdi32.dll, gdi32full.dll, or user32.dll) within a 10-minute window. This behavioral pattern is indicative of the backdoor's screen-capture capability, as these GDI/User32 modules are required for capturing screen content.
Detects a process loading known malicious DLLs (winfsp-x64.dll or DukeQt.dll) used by the FamousSparrow threat actor, followed by the creation or modification of a .dat file in the same process context. This pattern is indicative of the reflective loading of a backdoor payload without leaving the secondary binary on disk.
Detects the presence of known artifacts associated with the SparroWocky loader and backdoor, specifically identifying the file names 'winfsp-x64.dll' and 'DukeQt.dll', or files matching known SHA1 hashes of SparroWocky samples. The presence of these files on a host is a strong indicator of compromise.
Detects anomalous thread execution call stacks indicative of the SparroWocky anti-forensic evasion technique. This method involves spoofing thread start addresses and call stacks by injecting or manually manipulating stack frames to include legitimate-looking system functions (e.g., BaseFlushAppcompatCacheWorker, BaseCheckVDMp) alongside malicious execution patterns involving NtDelayExecution and SleepEx to hide the true origin of code execution.
Identifies instances of Google Chrome running on endpoints with version numbers below the threshold patched for CVE-2026-85046. This detection focuses on specific build numbers (e.g., 152.0.7977.82 for Windows/Linux) to identify potentially vulnerable browser installations in the environment.
Detects the execution of 'charmap.exe' from the Syswow64 directory where the process hierarchy indicates suspicious activity. The detection identifies a chain where PowerShell spawns 'conhost.exe', which in turn spawns a process from a temporary directory (interpreted as a renamed AutoIT executable) that then launches 'charmap.exe'. This pattern is indicative of a multi-stage obfuscated execution flow often used in malware dropper scenarios to bypass standard monitoring.
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects the creation of specific Object Manager namespace directories and objects used by the ShieldCrash proof-of-concept (CVE-2026-69414) to hijack the Microsoft Defender scan process.
Detects rapid deletion and creation cycles of the WD_SCAN object manager link, a behavioral pattern associated with a Time-of-Check-to-Time-of-Use (TOCTOU) exploit chain targeting Windows Defender (referenced as CVE-2026-69414). The rule monitors for at least three cycle events occurring within a 5-second window, specifically involving the 'WD_SCAN' object identifier.
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
Detects suspicious use of Windows API functions (SetWindowsHookEx) often associated with keylogging, correlated with the presence of temporary staging files in common directories (e.g., Temp, AppData). The rule excludes known legitimate applications that frequently utilize system hooks.
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
Page 286 of 1871

