Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects a suspicious staging behavior associated with OnyxC2 premium-tier malware. The detection identifies a process respawning itself—a common precursor to hidden VNC or credential access activity—followed by the execution of Microsoft Edge with specific utility flags typically used to masquerade as an indexing component. This pattern is characteristic of techniques used to hijack authenticated browser sessions for C2 purposes.
Detects unauthorized processes attempting to access the memory of the Local Security Authority Subsystem Service (LSASS) with high-privilege access masks, a technique commonly used for credential dumping to harvest passwords and authentication tokens.
Detects the use of WinRAR to open or extract password-protected ZIP archives containing 'Setup_File' in the filename, immediately followed by the execution of a file extracted into a WinRAR temporary directory. This behavior is associated with the OnyxC2 delivery chain, where attackers use password-protected archives to bypass security scanning.
Detects the execution of ServiceModelReg.exe from the standard .NET Framework directories. While this utility is a legitimate tool used for registering and configuring WCF components, its abuse has been observed in the wild by threat actors, including the OnyxC2 malware, to leverage built-in Windows utilities for suspicious activities.
Detects the presence of an OnyxC2 sideloaded DLL, identified by the filename 'borlndmm.dll', masquerading as an NVIDIA graphics library. The rule identifies suspicious files that are unusually large (50MB-200MB) with high entropy, suggesting an encrypted payload appended to the file. It also looks for associations with known loaders like 'ABRSubProcess.exe' or 'Setup_File_92.118.3096.exe' and the 'ACCA software S.p.A.' digital signature.
Detects reconnaissance activity targeting sensitive personnel groups (payroll, HR, finance) via Microsoft Graph API. The rule identifies suspicious URI patterns combined with the use of the 'axios' User-Agent library, potentially indicating automated enumeration by an adversary to map high-value targets for future business email compromise or credential theft.
Detects an adversary-in-the-middle (AiTM) phishing pattern where the legitimate Microsoft authentication URL is embedded as a sub-path within an attacker-controlled proxy domain. This technique is characteristic of AiTM kits, such as Evilginx2, which proxy the legitimate Microsoft authentication flow to capture credentials and session cookies.
Detects instances where processes other than standard web browsers attempt to access sensitive browser data files, such as cookies, login data, and browser state files. This behavior is a common indicator of credential theft or browser session hijacking, often performed by stealer malware like OnyxC2.
Detects the creation of a suspicious 'com.apple.finder.agent' plist file within a user LaunchAgents directory followed shortly by the termination of known macOS notification and background management agents. This pattern is often associated with malware attempting to evade detection or manipulate user notifications by disabling system components.
Detects instances where processes other than standard web browsers attempt to access sensitive browser data files, such as cookies, login data, and browser state files. This behavior is a common indicator of credential theft or browser session hijacking, often performed by stealer malware like OnyxC2.
This rule detects a sequence of events indicative of MacSync credential phishing on macOS. It identifies the tampering of Pluggable Authentication Modules (PAM) configuration files or SecurityAgent plugins (often used to hook authentication processes), immediately followed by the use of osascript to display a spoofed password dialog to the user. This combined activity suggests an adversary is attempting to harvest local user account credentials.
Detects a suspicious process pattern where an executable running from a staging directory (Temp or Downloads) spawns a child process of itself, followed by a registry modification performed by that child process. This behavior is indicative of malicious loaders, such as OnyxC2, that sideload components and establish runtime configurations before C2 communication.
Detects network activity associated with the GhostCode kit's bot-filter challenge, which performs session token/hash chaining prior to a device-code phishing redirect. The rule monitors for specific URL patterns containing 'check=1' and a session identifier, coupled with a mandatory 'js_enabled=1' cookie, commonly used to filter automated security scanners and verify bot activity before serving malicious content.
Detects network activity associated with the GhostCode phishing campaign, which leverages themed pages (e.g., MailDashboard) and Cloudflare Turnstile to perform security bypass checks. The rules identify the initial access URI pattern, the presence of specific phishing content in the HTTP response, and the subsequent verification cookies used after the CAPTCHA solution.
Detects the use of PowerShell processes that employ command-line encoding (e.g., -enc, -EncodedCommand) in conjunction with download-related cmdlets (e.g., DownloadString, IEX, Invoke-WebRequest), or instances of PowerShell spawned as a child process of another PowerShell process. This pattern is indicative of a loader or stage-one script fetching additional malicious payloads.
Detects persistence establishment for the NetSupport Manager remote access tool (client32.exe) via common Windows techniques including registry run keys, Winlogon configuration, service creation, and scheduled tasks. This activity is often associated with the abuse of legitimate RMM software as a covert remote access implant, frequently following initial access via PowerShell or script-based loaders.
Detects the creation or modification of Windows Registry Run/RunOnce keys that reference msbuild.exe without typical build arguments. This is often used by adversaries to maintain persistence by executing malicious XML-based projects or inline C#/VB code via a trusted system utility.
Detects instances where the MSBuild.exe process is subjected to image replacement or tampering, a behavior often associated with process hollowing or malicious code injection techniques aimed at evading security defenses by masquerading as a legitimate developer utility.
Detects the MSBuild.exe process adding new root or intermediate certificate authorities to the Windows certificate stores. This activity is indicative of potential malicious PKI infrastructure staging, which can be used to facilitate adversary-in-the-middle (AiTM) attacks or bypass certificate validation.
Detects high-frequency connection attempts from a single source IP to multiple destination IPs over the non-standard DVRIP port 37777, often used by Dahua surveillance equipment. This behavior is indicative of automated scanning, brute-forcing, or exploitation attempts targeting vulnerable IoT/CCTV devices.
Detects rapid mass-cloning or downloading of private GitHub repositories shortly after an OAuth token authorization, originating from IP addresses or countries not previously associated with the user account. This behavior is indicative of unauthorized bulk data extraction using compromised credentials, consistent with threat actor activity (e.g., TeamPCP/UNC6780).


