Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects HTML, XHTML, or SVG files used in Mirage2FA phishing campaigns. These files act as stagers by constructing hidden iframes to load remote JavaScript payloads from '/api/xls/' paths, utilizing specific placeholder tokens and obfuscation techniques such as XOR deobfuscation (0xAD) and custom function wrappers.
Detects potential account compromise by identifying a specific sequence of behavior: reconnaissance of sensitive users (HR/Payroll) via Microsoft Graph API calls, followed by the creation of inbox rules (e.g., forwarding) by the same user account within a 12-hour window.
Detects a multi-stage local execution chain associated with the Mirage2FA malware. The activity begins with WinRAR extracting an HTML stager from an Outlook quarantine directory, followed by rundll32.exe invoking shell32.dll to open the stager, and concluding with a spawned Microsoft Edge process executing the local HTML file.
Detects the initialization stage of a Mirage2FA phishing attack, characterized by the execution of a locally saved HTML file in a web browser, closely followed by an outbound network connection to the ipify.org API for victim IP geolocation and fingerprinting before the malicious sign-in page is rendered.
Detects the specific fingerprinting sequence associated with Mirage2FA AiTM phishing campaigns. The detection triggers when a process downloads a specific JavaScript loader from an '/xls/' path, followed closely within two minutes by an IP/geolocation lookup request to common services (api.ipify.org, api.country.is, api.ipgeolocation.io), which is a characteristic precursor to credential interception.
Detects instances where rundll32.exe is used to invoke shell32.dll with the SHCreateLocal function, or where a web browser process (msedge.exe, chrome.exe, or firefox.exe) is spawned by rundll32.exe to open an HTML file. This pattern is often indicative of malicious activity such as HTML smuggling or local file execution attacks where rundll32 is used as a proxy to open files via the browser.
Detects Microsoft Graph API requests targeting user information endpoints (/v1.0/users or /v1.0/me) using specific search filters associated with payroll or human resources and identified by the Axios HTTP client User-Agent string. This pattern is consistent with reconnaissance activities.
Detects the presence or execution of files associated with the 'MacSync' malware family, based on a list of known MD5 file hashes.
Detects specific, targeted search operations within M365 environments for keywords related to payroll, HR, and banking information. This behavior is indicative of post-compromise reconnaissance activity, often following AiTM (Adversary-in-the-Middle) session hijacking where an attacker attempts to locate financial documents and payroll correspondence.
Detects the use of a malicious 'borlndmm.dll' file intended for DLL side-loading to deploy the OnyxC2 stealer payload. The rule identifies files masquerading as NVIDIA graphics libraries or Borland memory managers that contain embedded encrypted payloads, matching known indicators for OnyxC2 activity.
Detects OnyxC2 RunPE injection behavior where a process drops or loads a suspicious sideloaded DLL (specifically borlndmm.dll) and immediately initiates a secondary process instance, indicative of process hollowing or memory unpacking of a malicious payload.
Detects instances where a non-browser process accesses multiple distinct browser credential or session artifacts (such as Login Data, Cookies, or Local State) across different browser profiles in a short period. This behavior is indicative of credential harvesting activities, often associated with C2 frameworks or post-exploitation tools attempting to steal session cookies, 2FA backup codes, or saved passwords.
Detects the specific behavior associated with the OnyxC2 C2 framework where a process re-spawns a child instance of itself, followed by a rapid registry modification by that child process. This pattern serves as a marker for the ONYXC2 loader configuration stage.
Detects anomalous Microsoft Graph API activity characterized by user enumeration or querying for sensitive organizational groups (e.g., payroll, finance, HR) often associated with post-AiTM account-takeover reconnaissance. This detection specifically identifies multiple requests for sensitive URIs or high-count enumeration requests originating from suspicious User-Agent strings like 'axios/1.18.1', commonly observed in threat actor activity such as Storm-2755.
Detects Microsoft 365 sign-in activity consistent with adversary-in-the-middle (AiTM) token theft. The rule identifies successful sign-ins with multi-factor authentication, immediately followed by a new session attempt for the same user within 30 minutes from a different device, IP address, or location.
Detects the initiation of a SOCKS5 proxy handshake from an internal host to an external destination. The rule monitors for the characteristic SOCKS5 greeting (0x05) while specifically excluding HTTP traffic to identify potential unauthorized proxy tunneling used for command and control or data exfiltration.
Detects a suspicious staging behavior associated with OnyxC2 premium-tier malware. The detection identifies a process respawning itself—a common precursor to hidden VNC or credential access activity—followed by the execution of Microsoft Edge with specific utility flags typically used to masquerade as an indexing component. This pattern is characteristic of techniques used to hijack authenticated browser sessions for C2 purposes.
Detects unauthorized processes attempting to access the memory of the Local Security Authority Subsystem Service (LSASS) with high-privilege access masks, a technique commonly used for credential dumping to harvest passwords and authentication tokens.
Detects the use of WinRAR to open or extract password-protected ZIP archives containing 'Setup_File' in the filename, immediately followed by the execution of a file extracted into a WinRAR temporary directory. This behavior is associated with the OnyxC2 delivery chain, where attackers use password-protected archives to bypass security scanning.
Detects the execution of ServiceModelReg.exe from the standard .NET Framework directories. While this utility is a legitimate tool used for registering and configuring WCF components, its abuse has been observed in the wild by threat actors, including the OnyxC2 malware, to leverage built-in Windows utilities for suspicious activities.
Detects the presence of an OnyxC2 sideloaded DLL, identified by the filename 'borlndmm.dll', masquerading as an NVIDIA graphics library. The rule identifies suspicious files that are unusually large (50MB-200MB) with high entropy, suggesting an encrypted payload appended to the file. It also looks for associations with known loaders like 'ABRSubProcess.exe' or 'Setup_File_92.118.3096.exe' and the 'ACCA software S.p.A.' digital signature.

