Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
Detects the use of the native Windows utility cipher.exe with the /w flag executed from the command prompt. The /w switch instructs cipher to remove data from available unused disk space, which is a technique often used by threat actors to hinder forensic recovery of deleted files.
Detects the use of wevtutil.exe to clear the Microsoft-Windows-Defender/Operational event log, which is often done by adversaries to remove evidence of security software activity or detection.
Detects the execution of diskpart.exe using a script file (/s) launched from an atypical parent process. Diskpart is a powerful disk management utility that can be abused for staging or data destruction; invoking it via scripts from processes other than standard management shells (cmd, powershell, explorer) or services may indicate malicious activity.
Detects execution of AI coding assistants or CLI tools (such as Claude, Gemini, Copilot, etc.) that are attempting to access sensitive local configuration, credential, or authentication files, including SSH keys, AWS credentials, and browser cookies.
Detects repository activity involving the 'FETCH_HEAD' reference, which often indicates automated fetching, local caching, or potential attempts to manipulate or inspect the state of a Git repository during reconnaissance or post-exploitation activities.
Detects instances where AI-assisted coding tools or command-line wrappers (e.g., Claude, Copilot, Gemini) execute Git commands (clone, checkout, fetch) involving a commit hash. This behavior may indicate automated or AI-assisted code retrieval and manipulation, which could be part of an adversary's workflow for reconnaissance or downloading malicious code repositories.
This rule detects PowerShell command lines that include .NET API calls typically used for anti-debugging and anti-analysis evasion, such as 'Debugger.IsAttached', 'Debugger.IsLogging', 'CheckRemoteDebuggerPresent', and 'Environment.FailFast'. These checks are common in malicious loaders and implants to determine if the process is being analyzed or monitored, allowing the malware to modify its behavior accordingly.
Detects the execution of the MeshAgent remote management tool when renamed to 'mvtcs.exe'. This technique is often used by adversaries to maintain persistent remote access while evading basic file-name based detections.
Detects the use of the [Reflection.Assembly]::Load method within PowerShell command lines. This method is often abused by attackers to reflectively load malicious .NET assemblies directly into memory, bypassing disk-based security controls.
Detects the creation of a .lnk shortcut file within the Windows Startup folder, which is a common persistence mechanism. The detection logic also flags the usage of WScript.Shell and CreateShortcut methods, which are frequently abused by scripts (e.g., VBScript or PowerShell) to programmatically establish this persistence.
Detects the use of PowerShell commands that perform decryption (AES-256-CBC) and decompression (Gzip) of data, followed by the reflective loading of a .NET assembly into memory using [Reflection.Assembly]::Load. This behavior is indicative of fileless malware execution where a payload is hidden in an obfuscated or compressed format and unpacked at runtime.
Detects unauthorized processes attempting to access sensitive browser files, including Login Data (passwords) and Network/Cookies databases for Chrome, Edge, and Firefox. These files are primary targets for credential dumping and session hijacking.
Detects PowerShell instances performing suspicious memory operations like thread injection (e.g., VirtualAllocEx, WriteProcessMemory, CreateRemoteThread) targeting common processes such as csc.exe, browser processes (chrome.exe, msedge.exe), and system processes like SearchIndexer.exe. This activity is indicative of malicious code injection often used in stealth execution and credential harvesting campaigns.
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
Detects the execution of the Windows Diskpart utility using a script file, as indicated by the /s command-line argument. This behavior is often associated with malicious actors attempting to perform destructive operations such as removing recovery partitions to inhibit system recovery during ransomware attacks.
Detects the use of the native Windows utility cipher.exe with the /w flag. This command is designed to overwrite free disk space with random data to sanitize it and make previously deleted files irrecoverable. While this is a legitimate administrative feature, adversaries may utilize it as a form of anti-forensics or to perform data destruction.
Detects the execution of the 'reagentc.exe' utility with the '/disable' argument. This command is used to disable the Windows Recovery Environment (WinRE), which is a common post-compromise activity performed by ransomware and other malware to prevent system recovery and hinder incident response efforts.
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
Page 294 of 1871

