Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects sensitive access to the Local Security Authority Subsystem Service (LSASS) process, commonly associated with credential dumping attempts. This rule monitors Windows Security Event 4663, specifically flagging processes attempting to gain specific access levels (e.g., Read, Query, or Full Control) to the lsass.exe process.
Detects the BlueMoon exploit kit's post-exploitation activity, specifically identifying when a Chromium-based browser process (chrome.exe or msedge.exe) initiates command-line tools such as cmd.exe, powershell.exe, or curl.exe to download and execute a secondary payload named 'msgbox.exe' within the user's temporary directory.
Detects suspicious file create or write operations within the domain SYSVOL Policies directory. This pattern is commonly associated with attackers attempting to deploy malicious payloads, such as ransom notes or configuration changes, via Group Policy Objects (GPO). The rule monitors Windows Event ID 4663 to identify unauthorized modification attempts by non-system accounts.
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
Detects successful network connections to a known hVNC RAT (GapiUpdate) C2 infrastructure IP address on port 5556, based on DeviceNetworkEvents logs.
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
The following analytic detects process injection into Notepad.exe using Sysmon EventCode 10. It identifies suspicious GrantedAccess requests (0x40 and 0x1fffff) to Notepad.exe, excluding common system paths like System32, Syswow64, and Program Files. This behavior is often associated with the SliverC2 framework by BishopFox. Monitoring this activity is crucial as it may indicate an initial payload attempting to execute malicious code within Notepad.exe. If confirmed malicious, this could allow attackers to execute arbitrary code, potentially leading to privilege escalation or persistent access within the environment.
The following analytic detects a process requesting duplicate-handle and query-limited-information access to winlogon.exe.
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
It leverages Sysmon EventCode 10 and checks for access masks that combine PROCESS_DUP_HANDLE (0x40) and PROCESS_QUERY_LIMITED_INFORMATION (0x1000).
The following analytic detects duplicate-handle access to known UAC-bypass binaries from a non-standard source path.
It leverages Sysmon EventCode 10, converts GrantedAccess from hexadecimal, and checks for PROCESS_DUP_HANDLE.
It leverages Sysmon EventCode 10, converts GrantedAccess from hexadecimal, and checks for PROCESS_DUP_HANDLE.
The following analytic detects potential process injection attempts into executables that are commonly abused leveraging Sysmon EventCode 10.
It identifies Access Mask requests (0x40 and 0x1fffff) to processes such as notepad.exe, wordpad.exe and calc.exe, excluding common system paths like System32, Syswow64, and Program Files.
This activity was associated with the SliverC2 framework by BishopFox.
Monitoring this activity may indicate an initial payload attempting to execute malicious code.
It identifies Access Mask requests (0x40 and 0x1fffff) to processes such as notepad.exe, wordpad.exe and calc.exe, excluding common system paths like System32, Syswow64, and Program Files.
This activity was associated with the SliverC2 framework by BishopFox.
Monitoring this activity may indicate an initial payload attempting to execute malicious code.
This rule detects instances where the Terraform CLI tool connects to suspected lookalike domains associated with supply chain compromise attempts (e.g., hashicorp-aws[.]com or hashicorp-terraform[.]io) during common initialization or application workflows. It correlates process execution with network connection logs and optionally validates the presence of a related .terraform.lock.hcl file associated with the malicious origin.
The following analytic detects the usage of wevtutil.exe with the "clear-log" parameter in order to clear the contents of logs.
Clearing the event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
Clearing the event logs can be an attempt to cover tracks after malicious actions, hindering forensic investigations.
The following analytic detects the wermgr.exe process creating an alternate stream in the temp directory. It leverages Sysmon EventID 15 to identify these actions.
This activity is significant because wermgr.exe is typically associated with error reporting, not file creation. Such activity is significant as it may indicate RoguePlanet malware, which creates an alternate stream in the temp directory to execute malicious code.
If confirmed malicious, this could lead to further malware infections, data exfiltration, or system compromise.
This activity is significant because wermgr.exe is typically associated with error reporting, not file creation. Such activity is significant as it may indicate RoguePlanet malware, which creates an alternate stream in the temp directory to execute malicious code.
If confirmed malicious, this could lead to further malware infections, data exfiltration, or system compromise.
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
This rule monitors for indicators of compromise (IOCs) associated with the Rapuncel/Cruciferra 'Bring Your Own Vulnerable Driver' (BYOVD) malware-as-a-service (MaaS) campaign. It detects malicious file hashes (associated with dropped binaries or drivers), connections to known malicious command-and-control (C2) IP addresses, and network requests to domains used by the infrastructure.
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
Detects post-exploitation shell activity spawned from the IIS worker process (w3wp.exe), narrowed to command lines carrying encoded/obfuscated PowerShell flags, remote-download cradles, or basic recon/persistence commands (whoami, certutil, bitsadmin, schtasks, reg add). This reduces noise from benign w3wp.exe-initiated automation while retaining the behavioral pattern seen in the Telerik UI for ASP.NET AJAX unauthenticated RCE chain (webshell/in-memory DLL execution dropping to a shell).
Page 293 of 1871


