Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects attempts to query or access the MachineGuid registry key located in HKLM\SOFTWARE\Microsoft\Cryptography. This registry key is commonly used to uniquely identify a Windows installation and is frequently targeted by malicious software to perform system identification or fingerprinting.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
Detects explorer.exe spawning the genuine cmd.exe binary with an explicit /c flag to run either the doxc\doxc.bat script from the 'My Resume.iso' lure chain, or config.bat co-occurring with the Documents_Details/windowSysUpdates decoy artifacts from the Document_Detail.zip lure chain — both used by Transparent Tribe (APT-C-56) to launch CrimsonRAT or the Golang RAT.
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
Detects execution of PowerShell commands containing suspicious arguments (e.g., encoded commands, download cradles) initiated by scheduled task binaries (svchost.exe, taskeng.exe, schtasks.exe) or involving specific suspicious strings associated with identified threat activity.
This rule detects potential malicious activity by matching endpoint file events against a known list of malicious file hashes (SHA256, SHA1, MD5) and monitoring for connections to known malicious domains or URLs.
Detects modifications, creation, or renaming of common cryptocurrency wallet files (e.g., wallet.dat, .wallet files) within known storage directories. This behavior is often associated with infostealers or malware attempting to exfiltrate or manipulate user financial assets.
Detects presence of configuration markers associated with the Hannibal Stealer 'clipper' functionality. These markers (e.g., 'cclipper', 'clipboard_check_delay') are used by the malware to monitor the system clipboard and replace cryptocurrency wallet addresses with attacker-controlled addresses.
Detects components of the LucidPawn malware family using DLL side-loading (e.g., index.exe loading DismCore.dll) or renaming DISM binaries within WindowsApps folders. The detection identifies these processes subsequently querying system locale or language registry keys, indicating a geo-targeting execution gate used to determine if the environment matches the intended target profile (specifically zh-TW).
Detects instances of the Hannibal Stealer module that attempt to masquerade as the legitimate 'CefSharp.BrowsersSubprocess.dll' by spoofing publisher metadata ('LLC Windows'). The detection triggers when this process is identified initiating network connections shortly after execution, which aligns with the malware's known behavior of performing geolocation-based checks before continuing activity.
Detects unauthorized access, modification, or creation of the FileZilla 'sitemanager.xml' configuration file by a process other than the legitimate 'filezilla.exe'. This is a common indicator of an adversary attempting to steal stored FTP credentials or modify connection configurations.
This rule monitors for outbound network connections to domains and IP addresses associated with known phishing, loader, and C2 infrastructure, including specific ClickFix patterns.
Detects the deletion of the Windows Application Event Log registry key. This action is a known technique used by adversaries to disable or tamper with event logging mechanisms to conceal malicious activity.
Detects the use of PowerShell to download the 'gitlab-runner-windows-amd64.exe' binary, potentially indicating unauthorized installation or deployment of automation agents using legitimate download sources.
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
Page 297 of 1871


