Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects execution of the s5cmd command-line tool performing synchronization, copy, or move operations to a cloud storage URI (s3://) followed by an outbound network connection on port 443 within a 10-minute window. This behavior is indicative of potential data exfiltration to cloud storage.
Detects the deletion of Volume Shadow Copies using the Windows Management Instrumentation Command-line (WMIC) utility. This behavior is commonly observed in ransomware attacks, including those attributed to DragonForce and CRPx0, as a method to inhibit system recovery prior to file encryption.
Detects attempts by PowerShell processes to modify the memory space of amsi.dll, a common technique used to bypass the Antimalware Scan Interface (AMSI) by patching its functions in-memory.
Detects the execution of the CRPx0 ransomware Stage 2 stager DLL via rundll32.exe. The attack leverages ordinal-based invocation (exporting crypto globals rather than named functions) and masquerades the malicious DLL as a system file named 'WindowsUpdate.log'.
Detects the use of legitimate Windows administrative utilities (vssadmin.exe, wmic.exe, wbadmin.exe) to delete volume shadow copies or backup catalogs. This behavior is a common tactic employed by ransomware actors to inhibit system recovery and prevent restoration of encrypted data.
Detects lateral movement activities involving the use of WMIC to remotely create processes or Schtasks to remotely create scheduled tasks. These techniques are often used by threat actors, including those associated with DragonForce and CRPx0 ransomware, to propagate across a network by executing commands on remote systems.
Detects the loading of rstrtmgr.dll by processes other than known Windows installers, update services, or explorers. The Restart Manager API is often abused by ransomware to terminate processes holding file locks, facilitating the encryption of files that would otherwise be in use.
Detects the creation or modification of Windows Scheduled Tasks involving system-level components. The rule monitors modifications to the TaskCache registry keys specifically containing 'System' or the creation of task files in the System32 directory. It excludes trusted processes like msiexec.exe and trustedinstaller.exe, which are typically responsible for legitimate system updates or installations.
Detects the execution of PowerShell or Rundll32 processes with command-line arguments that reference Anti-Malware Scan Interface (AMSI) components. This is a common indicator of an attempt to bypass or disable AMSI to facilitate the execution of malicious scripts or payloads.
Detects instances where specific suspicious or known-malicious processes load 'ntdll.dll' from the 'System32' directory. This behavior is indicative of potential DLL side-loading, process injection, or evasive execution patterns where an attacker leverages legitimate system binaries to load malicious code.
Detects instances where Windows Explorer (explorer.exe) launches common script interpreters like PowerShell or mshta, often indicative of a 'ClickFix' social engineering attack where a user is coerced into pasting malicious commands into the Windows Run dialog.
Detects suspicious command-line entries within the Windows RunMRU registry key, which logs recently executed commands from the Run dialog (Win+R). This detection targets common ClickFix or copy-paste attack patterns, specifically identifying the presence of 'powershell', 'curl', or long base64-encoded strings.
Detects the use of the Windows Management Instrumentation Command-line (WMIC) utility to delete individual Volume Shadow Copy (VSS) snapshots. This technique is commonly used by ransomware families to inhibit system recovery by preventing users from restoring files from shadow copies.
Detects the UAC bypass technique using fodhelper.exe, where an adversary modifies the 'Software\Classes\ms-settings\shell\open\command' registry key to execute malicious code, followed by the execution of the fodhelper.exe binary, which inherently runs with elevated privileges.
Detects a host initiating rapid sequential SMB tree connections to more than 10 distinct remote hosts within a 5-minute window. This behavior is indicative of network reconnaissance, specifically the enumeration of accessible SMB shares, which is a common precursor to lateral movement and large-scale ransomware encryption activity as observed in DragonForce-related incidents.
Detects the execution of base64 encoded PowerShell commands used by CRPx0 to stage a DLL payload, specifically saving it as 'WindowsUpdate.log' followed by the execution of that payload using rundll32.exe.
Detects files containing specific structural footers (537 bytes) and RSA key generation strings commonly associated with ransomware encryption. The footer indicates the use of RSA-4096 to encrypt files, with modes for full, striped, or header-only encryption patterns.
Detects the use of bcdedit.exe to modify boot configuration data to enable Safe Mode with Networking. This technique is used by Akira ransomware affiliates to potentially disable or impair EDR and other security tooling prior to deploying the ransomware payload.
Detects the use of bcdedit.exe to modify boot configuration data to enable Safe Mode with Networking. This technique is used by Akira ransomware affiliates to potentially disable or impair EDR and other security tooling prior to deploying the ransomware payload.
Detects the rapid termination of multiple critical processes (security, database, backup, and office applications) consistent with the kill list behavior exhibited by DragonForce ransomware. The rule monitors for a pattern of three or more unique processes from a defined list being terminated on the same host within a 5-minute window, a common precursor to file encryption.
Detects the use of vulnerable kernel drivers, specifically TrueSight.sys and rentdrv2.sys, as part of a Bring Your Own Vulnerable Driver (BYOVD) technique. This activity, associated with DragonForce ransomware, involves registering or accessing these drivers and sending specific IOCTL codes (0x22E044 or 0x22E010) to terminate security software processes.
Page 306 of 1871
