Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects activities associated with suspicious credential dumping and lateral movement tool usage, specifically targeting 'DumpIt.exe' for memory dumping, 'dokan.exe' for potential driver installation, and the creation of known suspicious files like 'memfix.zip' or 'Server.raw'. These actions are commonly indicative of post-exploitation credential harvesting and preparation for exfiltration.
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
This rule detects persistence mechanisms involving the creation or modification of a specific Windows Registry Run key ('ComponentTask33Agent') within the HKEY_CURRENT_USER hive, or the execution of PowerShell commands targeting this specific registry value. This is indicative of malware, such as the ChainScript Node.js RAT, attempting to maintain access across user reboots by abusing standard Windows autostart configuration points.
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
This rule detects potential persistence mechanisms and suspicious execution patterns associated with the ChainScript malware. It specifically monitors for the creation of scheduled tasks using PowerShell with indicators like 'StreamServiceSharedBridge.ps1' or 'ComponentTask33Agent', and the execution of VBScript-based agents via wscript.exe. It also flags tasks configured with specific execution time limits often associated with this malware's behavior.
Detects EDRKiller.exe or WarsawKiller.exe binaries and the associated wsftprm.sys BYOVD driver used by The Gentlemen threat actor to terminate security product processes
Detects EDRKiller.exe or WarsawKiller.exe binaries and the associated wsftprm.sys BYOVD driver used by The Gentlemen threat actor to terminate security product processes
This rule detects potentially malicious process execution chains where VBScript or unknown/suspicious binaries (such as ProfileQuickHost.exe) are used to launch Node.js processes, specifically targeting JavaScript files or VBScript agents. This pattern is often associated with the execution of remote access trojans (RATs) or custom malware loaders.
This rule detects the execution of mshta.exe with a command line referencing an HTA file, followed within 10 minutes by a network connection initiated by mshta.exe to a remote URL containing .js or .xml extensions. This behavior is indicative of mshta.exe being used as a proxy to execute remote malicious payloads, a common technique for fileless malware execution and defense evasion.
Detects the creation of a hidden file named '.Outlook' within the user's AppData Roaming directory. This behavior is atypical for standard Outlook operations and may indicate malicious activity, such as configuration tampering, persistence mechanisms, or data staging by malware.
This rule detects the execution of npm or node.js commands involving specific, potentially malicious package names or internal project naming patterns often associated with dependency confusion or supply chain attacks. It monitors npm/node CLI arguments for targeted library names or installation commands that deviate from standard organizational behavior.
Detects concurrent creation of a hexadecimal-named folder in the %TEMP% directory and a corresponding registry key in HKCU\SOFTWARE, both named with the same MD5 hash. This specific behavior is a known indicator of Casbaneiro (also known as Metamorfo) banking trojan infection, where the malware uses these locations to stage components and achieve persistence.
Detects network communication with known malicious domains and IP addresses, as well as the presence of known malicious file hashes on the system. The rule correlates network connection events, file creation events, and process creation events against predefined lists of C2 infrastructure and malware indicators.
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
This rule detects the execution or presence of batch files named 'Invoice Details.bat'. The use of such naming conventions in scripts is often a tactic employed in phishing campaigns to lure users into executing malicious code disguised as business-related documents.
Detects network connections originating from browser processes to known JeetBot command and control (C2) infrastructure. The rule identifies suspicious C2 communication and, specifically, attempts at token exfiltration by monitoring for auth tokens in the URL of requests directed to known JeetBot hosts and Twitch-related infrastructure.
Detects code injection attempts targeting the Windows Media Network Sharing Service (wmpnetwk.exe), specifically monitoring for the loading of suspicious or common networking-related DLLs into this process. This behavior is indicative of an adversary attempting to mask malicious activity within a legitimate system process.
Detects instances where a single process on a device performs a large number (more than 100) of file deletions or renames within a one-minute window. This behavior is indicative of potential data destruction, ransomware activity, or cleanup operations attempting to remove evidence of intrusion.
This rule detects potential indicators of compromise related to the 'ATodaPotencia' campaign by monitoring email URL logs, process command-line arguments, and general device events for the string 'ATodaPotencia'. The rule searches across multiple data sources to identify where this specific handle or artifact appears within an environment.
Page 301 of 1871





