Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,142 detections
Filters
Last updated
All Time
Detection languages
23,200
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,099
11,460
5,732
4,980
4,798
Platforms
39,723
6,855
6,349
4,079
3,510
Products / Services
10,351
9,601
6,991
4,335
3,859
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
Detects the Kothamine UAC-bypass technique, which uses fodhelper.exe to spawn an elevated PowerShell process. The rule monitors for fodhelper.exe being launched without arguments (a common indicator of this bypass) followed immediately by an elevated PowerShell process containing indicators like 'elevated.ps1' or 'TailscalePortable' paths.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects anomalous credential access behavior by identifying instances where a compromised explorer.exe process (injected with the Kothamine payload DLL MicrosoftEdgeUpdateCore.dll) accesses browser cookie stores and gaming credential files in quick succession.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
Detects post-exploitation command execution originating from a compromised explorer.exe process. The rule identifies processes like cmd.exe, powershell.exe, or conhost.exe spawned by an explorer.exe instance that has previously loaded the malicious 'MicrosoftEdgeUpdateCore.dll' module, correlating this activity with the established 'tailcat.exe' command-and-control tunnel.
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
This rule detects unauthorized downloads of Tailscale VPN client binaries or related dependencies (such as wintun.dll) originating from a specific GitHub repository ('cphc811-ui'). Such activity is often associated with the Kothamine threat actor attempting to establish unauthorized remote access or command-and-control channels by provisioning VPN software on compromised hosts.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
This rule detects the Kothamine dropper chain by correlating network connections or command-line activity fetching payloads from a specific GitHub repository ('cphc811-ui/new-tails') with the subsequent creation of associated malicious files (e.g., tailscale-related binaries, injector DLLs) on the same host within a one-hour window.
