Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the activity of the PIVOTPIPE .NET loader, which involves writing specific artifacts (core.pak, agent.json, pk.der, or sleepmask.o) to a temporary directory with the 'nb_' prefix or the creation of debug files containing strings associated with in-memory reflective loading of a remote access tool (RAT).
This rule detects activity matching known indicators of compromise (IOCs) associated with recent Russian espionage campaigns, including malicious domains, IP addresses, email senders, file names, and file hashes. It monitors network, sign-in, email, process, and file events across enterprise systems.
Detects the execution of PowerShell scripts located in the user's temporary folder. The detection logic looks for common obfuscation flags such as WindowStyle Hidden, NoProfile, and NoLogo, combined with the -File argument, which are frequently used by droppers and malicious payloads to execute scripts in the background while evading immediate user observation.
Detects the loading of 'libcurl.dll' or related DLL patterns from suspicious directories such as '\Microsoft\Crypto\RuntimeBroker\', often associated with process masquerading or side-loading activities. The rule also monitors for the execution of suspicious binaries ('Tax_Notice_45594.exe') or binaries that mimic 'Notepad++' metadata from within these paths.
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
This rule detects the presence or execution of a specific file on a device, identified by its SHA256 hash. The rule monitors both file creation/access and process execution events to identify if a known malicious binary is interacting with the system.
This rule monitors DeviceFileEvents and DeviceProcessEvents for the execution or presence of files matching a predefined list of known malicious SHA256 hashes.
This rule monitors for the presence of files matching a known list of malicious SHA256 hashes on devices. It correlates these file events with process creation events occurring on the same device within a 10-minute window, identifying potential execution of malicious binaries or artifacts.
Detects thread creation events where the initiating module is ntdll.dll, bypassing the conventional CreateThread path originating from kernel32.dll. This is a common behavioral indicator of process injection techniques used to hide malicious thread execution.
Detects network activity associated with the HEAVYGRAM PowerShell implant, specifically identifying outbound traffic to the Telegram Bot API (api.telegram.org). The rule looks for established connections and HTTP requests containing Telegram bot-specific URI patterns ('/bot', '/getUpdates') coupled with a 'WindowsPowerShell' user agent, indicating an automated beaconing mechanism used for command and control.
Detects unauthorized or suspicious modifications to the SyncRootManager registry keys. This rule is designed to identify potential exploitation attempts, such as the ShieldCrash zero-day, which abuse the Windows CFAPI sync-root mechanisms to achieve privilege escalation or bypass security features. Legitimate synchronization software is explicitly excluded from this detection.
This rule detects command line patterns associated with common Impacket tools (wmiexec, psexec, smbexec) executed via Windows processes (cmd.exe, powershell.exe) or via network connections to ports 445 and 135 initiated by Python processes. These tools are frequently used by adversaries for lateral movement, remote service execution, and command execution on compromised systems.
This rule detects suspicious usage of certutil.exe for file downloading or the execution of the Chisel proxy tool, specifically targeting connections or authentication towards the suspicious IP address 69.48.228.86. This behavior is indicative of C2 communication or ingress tool transfer.
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
This rule detects suspicious activity involving the creation of scheduled tasks for persistence using command-line arguments indicative of tool execution (e.g., chisel, powershell) or the direct execution of hidden PowerShell scripts intended to bypass execution policy.
Detects the execution of PowerShell with commands intended to modify or interact with Windows Registry Run keys, a common technique for establishing persistence.
Detects the execution of PowerShell with commands intended to modify or interact with Windows Registry Run keys, a common technique for establishing persistence.
This rule detects the use of the 'Add-MpPreference' PowerShell cmdlet with the '-ExclusionPath' argument to add specific file or directory paths to Microsoft Defender's exclusion list. This behavior is a common technique used by adversaries to bypass security controls by ensuring malicious tools or scripts are not scanned by Windows Defender. The rule specifically alerts on exclusions related to common staging areas or specific tools such as Telegram Desktop, SSH cache folders, and package management directories.
Detects when common torrent client applications spawn a child process that is an executable. This behavior is often associated with the execution of malicious payloads delivered or masqueraded as files within torrent environments.
This rule detects modifications to the Windows 'Run' registry key intended to achieve persistence by launching potentially malicious executables named 'RuntimeSSH.exe' or 'winappx.exe'. Attackers often use these paths to ensure that their malicious code executes automatically upon user login.
Page 302 of 1871




