Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors various logs (device network events, Entra ID sign-ins, cloud application events, and email events) for any interaction with a predefined list of indicator IP addresses identified as being associated with malicious actor egress traffic.
Detects persistence attempts related to the NetSupport Manager remote access tool by monitoring modifications to Windows Registry keys associated with run keys, Winlogon notification packages, and services.
This rule detects potentially malicious file access patterns by the executable 'comet.exe'. It alerts when this process accesses sensitive files or directories associated with credentials, configuration files, or sensitive browser data, while explicitly excluding benign locations such as Chrome data folders and temporary directories.
Detects the execution of a hidden PowerShell process that subsequently spawns a child process using the 'Start-Process' cmdlet with the '-Verb RunAs' argument within a short time window. This pattern is commonly associated with attempts to bypass User Account Control (UAC) or execute processes with elevated privileges silently.
Detects the execution of 'client32.exe', which is the executable associated with NetSupport Manager, a legitimate remote management software often abused by adversaries to establish persistence and provide remote interactive access to compromised systems.
Detects the execution or loading of specific components (winfsp-x64.dll, DukeQt.dll) associated with the SparroWocky malware framework, or suspicious image load events lacking a defined module path that typically precede reflective mapping.
Detects the execution of PowerShell commands that utilize both obfuscation techniques (such as Base64 encoding or 'FromBase64String') and remote payload retrieval or memory execution methods (such as 'IEX', 'DownloadString', or 'Invoke-WebRequest'). This combination is a classic indicator of malicious PowerShell activity designed to download and execute second-stage payloads.
This rule detects Windows PE executables that are digitally signed with code-signing certificates attributed to 'Discord Inc.' or 'Lenovo'. It performs a negative check to verify that the file metadata (such as internal names or company strings) does not match legitimate software from these vendors. This is intended to identify potential abuse of stolen certificates by adversaries to bypass security controls and masquerade as trusted software.
This rule detects the creation, modification, or renaming of a browser extension's 'manifest.json' file, which is a critical configuration file for browser extensions. It correlates this file activity with simultaneous or subsequent network requests to common web-based productivity or email services (e.g., Google, Microsoft, Perplexity). This combination of file modification in an extension directory and network activity to sensitive domains may indicate the installation of a malicious browser extension designed for session hijacking or unauthorized data collection.
Detects instances where a process named 'comet.exe' (or 'comet') accesses sensitive file system locations such as Documents, Desktop, Pictures, or system directories like /etc/ or C:\Windows\. This rule excludes known-legitimate installation and application directories associated with Comet software to reduce noise.
Detects persistent, periodic network communication patterns to remote IPs on common ports (443, 8080) that deviate from known administrative remote access tools. The rule identifies processes communicating with a consistent, low-frequency interval, which is highly indicative of automated Command and Control (C2) beaconing behavior.
Detects remote thread creation attempts (via CreateRemoteThread or NtCreateThreadEx) where the associated module path is empty or null, which is a common indicator of process injection techniques attempting to execute code without a backing file on disk.
Detects the creation of a 'manifest.json' file within a directory path containing 'Extensions' by common web browsers, followed by an immediate file access event from a non-standard browser location within one hour of the installation. This pattern is indicative of the installation of a potentially malicious or sideloaded browser extension followed by anomalous file activity.
Detects the execution of an executable file where the command line matches a specific pattern of a single character argument (e.g., '.exe s'). This behavior is frequently associated with malicious tools attempting to perform actions with minimal command-line footprints or potential process injection/tampering patterns when executed by a different user than the initiating process.
Detects evidence of anti-forensic activities associated with the SparroWocky toolset. The rule monitors for the removal of the 'ProcAuditManager' service, deletion of the 'SnapCart' registry key, and the execution of a self-deleting batch script used to remove forensic artifacts.
Detects threads created using CreateThread or CreateRemoteThread where the start address resolves to the AnimateWindow function in user32.dll. This technique is often used by malware, such as those leveraging the MinHook library, to disguise the true entry point of injected code by redirecting thread execution through a legitimate Windows API function (hooking).
Detects signs of NetSupport Manager (client32.exe) establishing multiple persistence mechanisms simultaneously or in quick succession, including Windows service creation, Winlogon helper registration, Registry Run key modification, scheduled task creation, and keyboard filter driver installation. This behavior is indicative of unauthorized use of remote access tools to maintain persistence on a host.
Detects forged thread call stacks by identifying processes that spoof legitimate thread entry points such as RtlUserThreadStart and BaseThreadInitThunk in kernel32.dll, a technique commonly associated with advanced thread execution hijacking methods like SilentMoonwalk or StackMoonwalk.
Detects the installation or update of browser extensions that possess both 'declarativeNetRequest' and 'content_scripts' permissions, while also requesting host permissions for major AI assistant or trusted vendor domains (e.g., google.com, gemini.google.com, copilot.microsoft.com, claude.ai). This specific combination of permissions is characteristic of the BragJack attack chain used to redirect network traffic and hijack AI browser agent sessions.
Detects the allocation of executable memory regions (RWX or EXECUTE_READ) that are not backed by a file on disk (i.e., anonymous memory). This behavior is a common indicator of process injection, shellcode execution, or fileless malware techniques where code is injected into a process and executed directly from memory without a corresponding file on disk.
Detects instances where PowerShell attempts to execute an external process with elevated privileges using 'Start-Process -Verb RunAs' combined with hidden window flags. The rule specifically looks for evidence that the targeted executable was recently initiated or exists in the context of the PowerShell operation, potentially indicating a UAC bypass attempt or malicious elevation of privileges.
Page 288 of 1871

