Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects the presence, installation, or execution attempts of the known vulnerable GIGABYTE driver (gdrv.sys). Monitoring for this specific driver is a common practice to identify attempts to perform 'Bring Your Own Vulnerable Driver' (BYOVD) attacks, which can be used for kernel-mode code execution and privilege escalation.
The following analytic identifies a process command line referencing the IronLanguages GitHub repository, which hosts .NET implementation of popular scripting engines.
Adversaries have downloaded these .NET implementations to avoid getting detected by security controls while executing their payloads.
This activity is uncommon in typical enterprise environments outside of software development contexts.
Adversaries have downloaded these .NET implementations to avoid getting detected by security controls while executing their payloads.
This activity is uncommon in typical enterprise environments outside of software development contexts.
Detects outbound network connections from internal devices to a set of known malicious IP addresses (45.151.45.31 and 46.166.79.31) which may indicate command and control communication or other malicious activity.
Detects outbound network connections from internal devices to a set of known malicious IP addresses (45.151.45.31 and 46.166.79.31) which may indicate command and control communication or other malicious activity.
This rule detects the use of specific tools associated with credential dumping and memory forensics, including Dokan driver installations for file system mounting, the use of DumpIt for creating memory dumps, and the subsequent analysis of these dumps using MemProcFS to access sensitive process memory information such as LSASS minidumps.
Detects potential C2 activity associated with MQTTDoor or MatrixDoor malware by monitoring suspicious network traffic patterns. This includes unauthorized processes connecting to MQTT brokers (hivemq.com), non-chat applications interacting with a Matrix homeserver, and geo-location lookups (ip-api.com) occurring shortly after process execution.
Detects potential C2 activity associated with MQTTDoor or MatrixDoor malware by monitoring suspicious network traffic patterns. This includes unauthorized processes connecting to MQTT brokers (hivemq.com), non-chat applications interacting with a Matrix homeserver, and geo-location lookups (ip-api.com) occurring shortly after process execution.
Detects potential C2 activity associated with MQTTDoor or MatrixDoor malware by monitoring suspicious network traffic patterns. This includes unauthorized processes connecting to MQTT brokers (hivemq.com), non-chat applications interacting with a Matrix homeserver, and geo-location lookups (ip-api.com) occurring shortly after process execution.
This rule detects the execution of suspicious command lines involving 'evilsocket/nyx' and the use of 'iex' (Invoke-Expression) within PowerShell or common download utilities (curl, wget). It also correlates this with network connections to 'raw.githubusercontent.com' fetching 'nyx.ps1', which is a common pattern for downloading and executing malicious scripts in memory.
Detects the creation of Windows services using 'sc.exe' with command line arguments containing 'cplsupport' or 'wtas'. These specific strings are associated with persistence mechanisms used by the MQTTDoor and MatrixDoor backdoors.
This rule detects the use of specific tools associated with credential dumping and memory forensics, including Dokan driver installations for file system mounting, the use of DumpIt for creating memory dumps, and the subsequent analysis of these dumps using MemProcFS to access sensitive process memory information such as LSASS minidumps.
Detects potential C2 activity associated with MQTTDoor or MatrixDoor malware by monitoring suspicious network traffic patterns. This includes unauthorized processes connecting to MQTT brokers (hivemq.com), non-chat applications interacting with a Matrix homeserver, and geo-location lookups (ip-api.com) occurring shortly after process execution.
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
Detects instances where AI coding assistants or tools (e.g., Claude, Copilot, Gemini) invoke git.exe to clone or fetch repositories from non-standard (non-GitHub) hosts, followed by a checkout operation within a short timeframe. This behavior may indicate an attacker using automated tools to stage or exfiltrate sensitive code repositories to unauthorized infrastructure.
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
Detects git checkout of a bare 40-hex commit SHA or the literal FETCH_HEAD ref, executed by a recognized AI coding-agent process. Narrowed to the Plugin4Shell exploitation fingerprint (checkout of a pinned-SHA-shaped or FETCH_HEAD ref) rather than ordinary branch/tag checkouts, which these agents perform constantly during normal plugin installs.
Detects evidence of potential credential dumping from the Local Security Authority Subsystem Service (LSASS) process. The rule monitors for two distinct behaviors: the use of MemProcFS with device memory access flags targeting a RAW file, and the creation of files containing 'lsass.exe', 'minidump', and 'readme.txt' in their paths or filenames, which is characteristic of certain post-exploitation toolkits that harvest LSASS memory.
Detects evidence of potential credential dumping from the Local Security Authority Subsystem Service (LSASS) process. The rule monitors for two distinct behaviors: the use of MemProcFS with device memory access flags targeting a RAW file, and the creation of files containing 'lsass.exe', 'minidump', and 'readme.txt' in their paths or filenames, which is characteristic of certain post-exploitation toolkits that harvest LSASS memory.
Detects the execution of PowerShell commands that reference the 'nyx' script from 'raw.githubusercontent.com', combined with common download and execution patterns such as 'Invoke-Expression' or 'Invoke-WebRequest'. This activity is consistent with retrieving and executing remote post-exploitation scripts.
Page 300 of 1871

