Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where processes associated with Claude or Codex modify or create files within a plugin directory without a preceding legitimate installation or session command (such as 'install' or 'plugin add'). This behavior may indicate unauthorized plugin installation, persistence establishment, or malicious code injection into the development environment.
This rule monitors for any process execution event captured by the EDR solution. It serves as a catch-all for recording process creation telemetry.
This rule detects the creation or modification of registry keys within the RunOnce path in both HKEY_CURRENT_USER and HKEY_LOCAL_MACHINE. These keys are commonly abused by adversaries to achieve persistence, as programs referenced in them execute automatically upon the next user logon or system start.
This rule detects the creation of a synchronization mutex with a specific naming pattern ('Global\EVOLUTION') often used by malware families to ensure only a single instance of the malicious process runs on the infected host. The rule monitors DeviceEvents for 'MutexCreated' or 'MutexEvent' and parses the synchronization object name to identify this specific indicator.
This rule monitors for file creation or existence patterns in the user's Local Temp directory that are commonly associated with infostealer malware, specifically looking for naming conventions like 'evo_cl_*.exe', 'evo_db_*.db', or the presence of a 'stolen.zip' file within subdirectories.
Detects instances where Outlook (OUTLOOK.EXE) spawns an executable named 'ai.exe' with a command line containing a 16+ character hexadecimal string, followed closely (within 10 minutes) by a Microsoft Edge (msedge.exe) process execution acting as a network utility. This pattern is indicative of a potential phishing-initiated attack where a malicious payload is executed and subsequently leverages browser components for network communication or C2 activity.
Detects the execution of ConfigurationRemotingServer.exe initiated by winget.exe. This could indicate usage of the Windows Package Manager to facilitate remote configuration or management tasks, which warrants investigation for potential unauthorized use or process manipulation.
This rule detects network upload operations (HTTP POST or similar requests ending in '/upload') to a specific external IP address (2.26.126.50). It specifically monitors for processes other than common web browsers, and filters for connections where significant data volume (greater than 10KB) is transferred or the data size is unknown.
This rule detects network upload operations (HTTP POST or similar requests ending in '/upload') to a specific external IP address (2.26.126.50). It specifically monitors for processes other than common web browsers, and filters for connections where significant data volume (greater than 10KB) is transferred or the data size is unknown.
This rule detects the use of 'winget' or 'ConfigurationRemotingServer.exe' to execute Windows Configuration DSC (Desired State Configuration) files, specifically targeting the invocation of 'PSDscResources/Script' resources, 'SetScript', 'TestScript', or 'GetScript' operations. This technique may be leveraged by attackers to execute arbitrary code or maintain persistence through the configuration management framework.
Detects successful network connections initiated by the ConfigurationRemotingServer.exe process. This binary is associated with Windows configuration remoting services and may be used for remote administrative tasks or unauthorized remote management activities.
This rule monitors outbound network traffic for the inclusion of a Windows-style hostname pattern (e.g., 'DESKTOP-XXXXXX'), which is often used by stealer malware or RATs to identify victim machines during C2 communication. It explicitly excludes Microsoft licensing traffic to reduce false positives.
This rule detects potential malware delivery by correlating network visits to known malicious domains used for lure distribution with subsequent large file downloads (.zip files >= 100MB) in typical user download or temporary folders within a short time window. This pattern is characteristic of campaigns leveraging social engineering and file-based evasive techniques (such as padding to bypass static analysis) to distribute malicious payloads.
This rule detects two suspicious activities: first, the execution of 'conhost.exe' with a headless command line argument containing 'cmd /c echo' and either a '.tmp' file reference or a suspicious base64-like encoded string, initiated by explorer.exe or cmd.exe. Second, it identifies the presence of '.lnk' shortcut files within common user-writable directories such as Downloads, Desktop, or Public folders, which is a common indicator of staging or persistence.
This rule detects network upload operations (HTTP POST or similar requests ending in '/upload') to a specific external IP address (2.26.126.50). It specifically monitors for processes other than common web browsers, and filters for connections where significant data volume (greater than 10KB) is transferred or the data size is unknown.
This rule detects the presence of files and folders associated with the Rapuncel infostealer malware. It monitors DeviceFileEvents for specific SHA256 hashes known to be malicious, as well as specific file names related to data exfiltration and log collection (e.g., 'browser_decryption.log', 'sends.log'), and the creation of files within folders containing 'Filegraber'.
This rule monitors process creation events for suspicious activity, specifically detecting two patterns: 1) The creation of a scheduled task named 'OneDrive KeepAlive' using schtasks.exe, which is indicative of persistence mechanisms masquerading as legitimate software, and 2) Execution of the 'taskhostw.exe' binary with command-line arguments 'exec' and 'hide', which is a common indicator of the NirCmd utility being renamed and used for stealthy execution.
This rule detects persistence attempts via Component Object Model (COM) hijacking. It identifies a specific process 'December_blob.exe' creating or modifying registry keys associated with COM CLSIDs (specifically InprocServer32) and simultaneously dropping or utilizing a file named 'hvcsrv.dll' within an 'IdentityNexusIntegration' directory. This combination of registry modification and file system activity suggests the registration of a malicious COM object to achieve execution persistence.
Detects instances where Windows Terminal (WindowsTerminal.exe) is launched by Explorer and immediately spawns a shell process (PowerShell, PWSH, or CMD), specifically excluding devices that have recorded recent RunMRU registry history. This pattern may indicate suspicious or non-interactive execution by an adversary attempting to bypass traditional shell history tracking.
This rule detects attempts to query or access the MachineGuid registry key located in HKLM\SOFTWARE\Microsoft\Cryptography. This registry key is commonly used to uniquely identify a Windows installation and is frequently targeted by malicious software to perform system identification or fingerprinting.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Page 296 of 1871


