Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
This rule monitors DeviceNetworkEvents for any outbound network connections to a specific list of known malicious domains. The rule identifies potential command and control (C2) communication by matching remote URLs against a hardcoded set of domains associated with known threats.
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
Detects instances where the process 'GRrte.exe' forcefully terminates 'iediagcmd.exe' using taskkill.exe. This activity is indicative of an attempt to disable or impair specific security diagnostic tools or EDR-related components on the host.
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
Detects network activity or command line parameters initiated by the Jarte text processor (Jarte.exe or GRrte.exe) originating from a JartePortable directory, indicating potential C2 activity involving the domain 'castanaksa.com' or the IP address '192.64.119.189'.
This rule detects the opening of a specific PDF file named 'OIC_Invitation_General_Official.pdf' by Adobe Acrobat. The detection logic triggers either when Acrobat processes this file or when the file itself is identified on the system. This pattern has been associated with the delivery of the PlugX remote access tool, often used in targeted spearphishing campaigns.
This rule detects the creation or modification of registry run keys associated with the JartePortable application. The detection logic looks for persistence mechanisms that point to executable paths in public directories or specific registry value data associated with known PlugX malware activity.
Detects Adobe Acrobat (Acrobat.exe) launched by a suspicious parent process (GRrte.exe) while opening a specific PDF document from the user's temporary directory. This pattern is indicative of a potential malicious document lure often associated with malware delivery.
This rule detects modifications to the Windows Registry 'Run' keys that point to specific, potentially suspicious executable paths located in 'C:\ProgramData\'. These paths are commonly associated with persistence mechanisms used by malware or unauthorized software to ensure execution at system startup.
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
Detects the creation of a scheduled task using schtasks.exe where the command line involves 'MicrosoftNodeRuntimeUpdater' and references 'node.exe' or '.js' files, specifically when initiated by script engines like node.exe, wscript.exe, or cscript.exe, while excluding known legitimate nodejs installation paths.
Page 290 of 1871


