Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
Detects StealC-related .NET payload protected with ConfuserEx, requiring the sample-specific mutex string, AES key material, and multiple anti-debugging indicators together to avoid matching benign ConfuserEx-obfuscated applications
Detects instances where the Windows Search Indexer service process (SearchIndexer.exe) performs suspicious process-related API calls such as memory writes, remote thread creation, or opening processes against common web browser executables (chrome.exe, msedge.exe). This behavior is characteristic of malicious process injection where a legitimate, high-privileged system process is abused to inject code into a browser process.
Detects a suspicious PowerShell process lineage spawned by explorer.exe that exhibits characteristics of a 'ClickFix' social engineering lure (using obfuscated command lines) and proceeds to inject code into legitimate Windows or browser processes such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe. This activity is often associated with malware attempting to evade debugging.
Detects instances where explorer.exe initiates cmd.exe with suspicious command-line patterns often associated with malicious script execution or evasion. These include caret-based obfuscation, mixed-case PowerShell invocations, or base64-like blobs, alongside indicators of common malicious file paths or execution policy bypass flags.
This rule monitors for suspicious PowerShell command-line activity originating from Windows Explorer (explorer.exe) or embedded within RunMRU registry modifications. It detects obfuscated or hidden command execution patterns, such as base64 encoding, the use of -EncodedCommand, Invoke-Expression, or execution policy bypass flags, which are commonly associated with malicious scripts and fileless malware execution.
Detects known PowerShell dropper and embedded StealC payload binaries used in the ClickFix infection chain via exact SHA256 hash equality only
Detects unauthorized processes attempting to modify, create, or rename sensitive browser files (Login Data or Cookies) belonging to Google Chrome or Microsoft Edge. The rule filters out known browser processes and looks for suspicious initiating processes characterized by unsigned code or execution from common staging areas like Temp folders.
Detects a suspicious multi-step process injection sequence originating from an obfuscated PowerShell process. The rule identifies PowerShell executing with common obfuscation flags (e.g., -enc, -nop, IEX) and performing multiple API calls (such as NtAllocateVirtualMemoryRemote, NtSetContextThreadRemote, CreateRemoteThread, or OpenProcess) targeting specific executables like csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe.
Detects execution of PowerShell commands that exhibit characteristics frequently associated with malicious activity, such as reflective assembly loading, compression/decompression operations, use of specific known obfuscation markers, encoded commands, or execution originating from suspicious parent processes like explorer.exe or cmd.exe.
Detects the execution of PowerShell with hidden window styles and encoded command arguments initiated directly from explorer.exe. This pattern is often indicative of malicious activity, such as fileless malware execution or obfuscated script delivery, where an attacker attempts to blend in with standard user interactions.
Detects the loading of the 'gdrv.sys' driver, which is a known vulnerable driver often used in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks to facilitate privilege escalation to kernel mode.
Detects the execution of reagentc.exe with the /disable command-line argument, which is used to disable the Windows Recovery Environment (WinRE). Adversaries use this technique to inhibit system recovery and prevent users or automated systems from restoring the operating system to a known good state after an attack, such as data destruction or encryption.
Detects the loading of the 'gdrv.sys' driver, which is a known vulnerable driver often used in 'Bring Your Own Vulnerable Driver' (BYOVD) attacks to facilitate privilege escalation to kernel mode.
Detects the use of the built-in Windows 'cipher.exe' utility with the '/w' flag, which is used to securely overwrite free space on a disk, a technique often used by adversaries for anti-forensics or data destruction to prevent file recovery. The rule specifically alerts on execution from command-line environments (cmd.exe) where the command output is redirected to null, often used to hide the progress or output of the wiping process.
Detects the execution of diskpart.exe using a script file (via the /s parameter) where the parent process is not a standard system utility. This behavior is often indicative of attackers using diskpart to automate disk operations, such as clearing volume shadowing or modifying disk configurations, during post-exploitation activities.
Detects attempts to clear Windows event logs using administrative tools like wevtutil.exe, PowerShell, or through the detection of mass log-clear audit events (such as Event IDs 1102 and 104) occurring in a rapid burst. This activity is often used by adversaries to hide evidence of post-compromise actions.
This rule detects potential ransomware activity by correlating three distinct events: the execution of a suspicious, potentially obfuscated binary (matching a specific naming pattern of _win64.exe) from an untrusted location (e.g., Temp, AppData, Downloads), followed by a high volume of file modifications or renames with specific ransomware-related extensions (.locked), and the dropping of a known ransom note file (RESTORE_FILES.txt) within a short 15-minute time window.
Page 299 of 1871

