Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
Page 298 of 1871
