Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects when common torrent client applications spawn a child process that is an executable. This behavior is often associated with the execution of malicious payloads delivered or masqueraded as files within torrent environments.
This rule detects modifications to the Windows 'Run' registry key intended to achieve persistence by launching potentially malicious executables named 'RuntimeSSH.exe' or 'winappx.exe'. Attackers often use these paths to ensure that their malicious code executes automatically upon user login.
This rule detects the loading of a module named 'MicDriver.dll' or the execution of a process named 'MicDriver.exe'. These filenames are potentially indicative of malicious activity using masquerading or attempts to hijack execution flow using filenames that resemble legitimate audio drivers.
Detects potentially malicious script execution patterns, specifically targeting Windows Script Host (wscript.exe) invoking .vbs or .wsf files, and PowerShell execution involving suspicious command line arguments such as encoding (-enc), external URL downloading, or attempts to execute or archive files (Expand-Archive, WebClient DownloadFile).
Detects the execution of a file named 'msedge.exe' residing within the C:\ProgramData\Microsoft\Windows\Telemetry\ directory. Microsoft Edge typically resides in 'C:\Program Files (x86)\Microsoft\Edge\Application\', making execution from the telemetry directory highly suspicious and indicative of potential process masquerading.
This rule detects potentially malicious activity by monitoring for a specific executable file name ('msedge.exe') located in a non-standard path ('ProgramData'), as well as network connections to a known malicious IP address ('193.23.118.155') and DNS requests for a domain associated with suspicious activity ('deadhub.org').
This rule detects the execution of a file with a suspicious media-themed filename (e.g., related to 1080p, BluRay, etc.) from a known BitTorrent client process, followed by an immediate network connection to a known malicious C2 IP address or domain within a 10-minute window. This behavior is indicative of a user downloading and executing a malicious file disguised as pirated media.
This rule detects the execution of a specific known malicious file (identified by MD5 hash A0B13781EDD7CFDAB13D79AFFF3C83C1) followed by an outbound network connection to a suspicious IP address (193.23.118.155) or domain (deadhub.org) within a 10-minute window. This behavior is indicative of a malicious loader establishing a command and control (C2) channel.
Detects the execution of known development, scripting, and administrative tools (e.g., Python, Node.js, GCC, Docker) from non-standard or unauthorized file paths. The rule leverages allowlists for process names, publishers, and trusted installation directories to identify potentially unauthorized usage of powerful tooling often abused by attackers for post-exploitation activities.
This rule detects potential persistence and execution activity associated with the HEAVYGRAM implant. It monitors for registry value modifications in the Windows Run keys by known malicious file names, as well as process execution events where those same files are executed with command-line arguments typically used for registry manipulation.
Detects the use of PowerShell to modify Microsoft Defender (MpPreference) settings by adding specific directories or files to the exclusion list. This behavior is frequently associated with adversaries attempting to evade security detection by ensuring malicious tools, staged payloads, or persistent files remain unscanned by the antivirus engine.
Detects the execution of suspicious binaries that are spawned by known torrent clients or appear to masquerade as media files (e.g., using movie quality naming conventions like 1080p, Bluray). This rule identifies potential delivery of malicious payloads via P2P file sharing environments by looking for specific process patterns and filename indicators associated with file masquerading.
Detects memory allocation operations in processes where the protection mask is set to PAGE_EXECUTE_READWRITE (0x40). This behavior is often associated with code injection techniques, where an adversary allocates memory with write and execute permissions to load or execute malicious payloads in memory.
Detects suspicious thread injection activities (CreateRemoteThreadApiCall, NtCreateThreadEx, or RtlCreateThread) or the loading of 'ntdll.dll' by specific potentially unauthorized binaries (e.g., RuntimeSSH.exe, smqdservice.exe, etc.) or within the 'ProgramData\Microsoft\Windows\Telemetry' directory. This often indicates reflective code injection or process tampering, excluding known legitimate Windows system processes.
Detects anomalous mass file enumeration, creation, deletion, and renaming activity within common system or temporary directories, indicative of the MovieReaper stage-4 file manager module. The rule monitors for the execution of command-line utilities (cmd.exe, powershell.exe) with specific file management arguments followed by a high volume of file system operations within a 5-minute window.
Detects execution of a process masquerading as msedge.exe located within the Windows Telemetry directory. This behavior is associated with the MovieReaper malware, specifically as a stage-3 payload activity following UAC bypass and persistence establishment.
Detects a Delphi-compiled Windows Screen Saver (.scr) file acting as a dropper. The binary contains embedded RCDATA ZIP resources and utilizes Persian-language filenames related to academic or student-focused lures to trick victims into execution. This rule specifically identifies the presence of the dropper's strings and the Borland Delphi marker.
Detects sophisticated process injection behavior where malicious shellcode is mapped into RWX memory. The payload utilizes a Vectored Exception Handler (VEH) and deliberate 0xCC (breakpoint) instructions to intercept execution and redirect it into raw syscall stubs (e.g., NtProtectVirtualMemory). This technique is designed to bypass security product API hooking by avoiding standard calls to memory protection functions.
Detects creation of .git-checker files in temporary directories, a pattern associated with potential malicious activity.
Detects a Node.js process executing a JavaScript file that spawns a secondary Node.js child process, followed immediately by the creation or modification of Windows Run registry keys for persistence. This sequence is indicative of malicious npm package activity where a secondary, hidden payload is downloaded and configured to execute upon system startup.
Detects the GHAPPIER loader pattern: a top-level require('https').get() call to the primevector-app924560.vercel.app C2 that evals the response, disguised inside a large benign-looking JavaScript benchmark file
Page 303 of 1871

