Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
Detects unexpected child processes spawned from directories associated with AI coding agent plugins (e.g., Claude Code, Copilot, Codex, Gemini CLI). This activity could indicate post-exploitation behavior, such as Plugin4Shell, where a malicious plugin auto-update facilitates remote code execution.
Detects the execution of known command-line utilities (cmd, powershell, mshta, wscript) spawned by explorer.exe that utilize external network request tools (curl, finger) to initiate network connections. This pattern is commonly observed in stage-1 downloader behavior where a user-initiated action from explorer triggers an attempt to pull down external payloads.
Detects instances where explorer.exe spawns cmd.exe or powershell.exe with command-line arguments indicative of obfuscated execution, such as encoded commands, hidden window styles, or bypass flags. This pattern is consistent with ClickFix social engineering attacks where users are deceived into manually executing malicious commands via the Windows Run dialog.
Detects instances where explorer.exe spawns cmd.exe or powershell.exe with command-line arguments indicative of obfuscated execution, such as encoded commands, hidden window styles, or bypass flags. This pattern is consistent with ClickFix social engineering attacks where users are deceived into manually executing malicious commands via the Windows Run dialog.
Detects the creation of an LNK file in the Windows Startup directory, a common technique used to achieve persistence by executing a specific program or script upon user logon.
Detects PowerShell attempts to perform remote process injection into potentially suspicious or sensitive processes (csc.exe, chrome.exe, msedge.exe, SearchIndexer.exe) by searching for command line arguments indicating the usage of Windows memory allocation or thread context manipulation APIs such as NtAllocateVirtualMemoryRemote and NtSetContextThreadRemote.
Detects successful user authentication events originating from an external source IP address. This rule is intended to identify remote logins that can be correlated with RMM (Remote Monitoring and Management) activity or other remote access patterns.
Detects the use of AI assistant command-line interfaces (such as Claude, GitHub Copilot, or Gemini) to execute git checkout commands with specific commit hashes or references like FETCH_HEAD. This behavior may indicate an attempt to use automated AI tooling to stage or interact with repository code, which could be part of an automated exfiltration or unauthorized code modification attempt.
This rule detects the creation or pushing of a local Git branch where the branch name matches the pattern of a 40-character SHA-1 or 64-character SHA-256 hash. This behavior is indicative of the Plugin4Shell exploitation technique, where attackers create branches named after specific commit SHAs to bypass security checks on self-hosted Git services like Bitbucket by pinning them to unintended commits.
Detects the execution of a local git force-push operation, which is a technique used by an adversary to overwrite existing repository tags or branches during a software supply chain compromise or repository takeover scenario.
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
Detects file hash hits matching known malicious IOCs or network connections to suspicious domains/URLs.
Detects the presence of the known vulnerable GIGABYTE driver (gdrv.sys) used in Bring Your Own Vulnerable Driver (BYOVD) attacks to bypass security controls and facilitate kernel-mode execution, as associated with Settra ransomware campaigns.
Detects execution of long, obfuscated command strings initiated by Windows Explorer, often indicative of the 'ClickFix' social engineering technique where users are tricked into copying and pasting malicious commands into the Windows Run dialog.
Detects the creation of shortcut files (.lnk) within the current user's Startup folder using Windows command line utilities or scripts that leverage the WScript.Shell COM object. This behavior is indicative of an adversary establishing persistence to ensure malicious payloads execute upon user logon.
Detects unauthorized processes attempting to access sensitive browser data files, specifically 'Login Data' (passwords) and 'Cookies' for Google Chrome and Microsoft Edge. The rule excludes the browser applications themselves and their update processes to minimize noise.
Page 295 of 1871

