Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
This rule detects potentially malicious child processes spawned by Visual Studio Code (Code.exe) when using VS Code tasks (tasks.json). It identifies suspicious CLI arguments often associated with downloading, executing, or obfuscating scripts (e.g., PowerShell, curl, python, mshta) that are not part of standard development workflows like npm, yarn, or git, which are explicitly filtered out as noise.
Detects suspicious use of Windows API functions (SetWindowsHookEx) often associated with keylogging, correlated with the presence of temporary staging files in common directories (e.g., Temp, AppData). The rule excludes known legitimate applications that frequently utilize system hooks.
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
This rule detects suspicious clipboard access attempts initiated by common scripting interpreters (node.exe, python.exe, powershell.exe) in non-standard paths or correlated with recent external network connections. It is designed to identify potential credential theft or data staging using clipboard interaction methods often employed by malware.
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
Detects file artifacts referencing OtterCandy malware, which combines OtterCookie and RATatouille RAT capabilities, associated with WaterPlum/Contagious Interview campaign
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
Detects OtterCookie JavaScript-based RAT/infostealer malware artifacts associated with WaterPlum/Contagious Interview campaign
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
Detects BeaverTail JavaScript-based loader malware hidden inside NPM packages, distributed via GitHub or Bitbucket during fake technical interviews
This rule monitors for the presence or execution of files matching a known set of SHA256 hashes associated with the 'DXSCAN' malware, utilizing both device file and process events.
This rule monitors for the presence or execution of files matching a known set of SHA256 hashes associated with the 'DXSCAN' malware, utilizing both device file and process events.
Detects file and process activity associated with the Hermes ransomware, specifically targeting the presence of 'SOUL.md' files, '.hermes' file paths, and the 'HERMES_DISABLE_SAFETY=1' command-line argument.
This rule monitors various logs (device network events, Entra ID sign-ins, cloud application events, and email events) for any interaction with a predefined list of indicator IP addresses identified as being associated with malicious actor egress traffic.
Detects persistence attempts related to the NetSupport Manager remote access tool by monitoring modifications to Windows Registry keys associated with run keys, Winlogon notification packages, and services.
This rule detects potentially malicious file access patterns by the executable 'comet.exe'. It alerts when this process accesses sensitive files or directories associated with credentials, configuration files, or sensitive browser data, while explicitly excluding benign locations such as Chrome data folders and temporary directories.
Detects the execution of a hidden PowerShell process that subsequently spawns a child process using the 'Start-Process' cmdlet with the '-Verb RunAs' argument within a short time window. This pattern is commonly associated with attempts to bypass User Account Control (UAC) or execute processes with elevated privileges silently.
Page 287 of 1871



