Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
Detects suspicious activity related to the Windows Subsystem for Linux (WSL), such as installing new distributions (especially penetration testing ones like Kali), importing custom images, or executing commands non-interactively. Attackers may use WSL to run malicious Linux binaries, hide artifacts, and evade defenses.
Detects the execution of known GoCaracal malware samples, identified by specific file hashes or staging file paths, occurring in conjunction with low-level keyboard hook installations using SetWindowsHookEx. This behavior is indicative of active keylogging activity.
Detects a pattern of multiple failed authentication attempts (brute force) from an external IP address followed by a successful authentication event on remote access services such as RDP, VPN, or NTLM. The rule filters for non-private IP addresses and flags successes occurring outside of standard business hours.
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
This rule detects modifications to Windows Registry persistence keys (Run and RunOnce) associated with specific suspicious filenames ('cplsupport.exe', 'wtass.exe'), as well as modifications to specific Synapse agent configuration registry keys. These patterns are often associated with persistence mechanisms or unauthorized software configuration changes.
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
This rule detects the process 'ShieldCrash.exe' accessing or interacting with the Windows ELAM (Early Launch Anti-Malware) configuration directory. ELAM drivers are critical components for secure boot and early malware detection; unauthorized access or manipulation by unknown processes may indicate an attempt to tamper with security tools or evade endpoint protection.
This rule detects instances where a process named 'wsc_updata.exe' executing from a Temp directory loads a library named 'wsc.dll'. This behavior is characteristic of DLL side-loading or DLL hijacking, where a malicious or potentially unwanted executable attempts to load a library from a user-writable directory to execute arbitrary code.
Detects browser navigation events where the target URL is a locally generated 'blob:' URI that includes keywords associated with common credential harvesting targets (e.g., login, Microsoft 365, DocuSign). Adversaries use blob URIs to render phishing content directly from memory, which can help bypass certain static URL reputation filters and email security gateways.
Detects instances where the Steam service (steamservice.exe) is executing suspicious child processes such as command interpreters or binaries located in unusual paths like Temp, Downloads, or AppData, often indicating an attempt to hide malicious activity under a trusted process.
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
Detects the obfuscated first-stage JavaScript payload sharedLoad.min.js dropped by the malicious npm indexed-btree package, identified by string-array encoding and self-checksumming array rotation obfuscation patterns
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
Detects the sharedLoad.min.js obfuscated first-stage loader dropped by the malicious npm indexed-btree package, triggered via BTree.prototype.set to evade static/taint-analysis scanners
Detects the indexed-btree npm malware loader embedded in BTree.prototype.set that spawns a detached hidden Node.js child process and references sharedLoad.min.js
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
Detects the execution of Ruby or Yard processes where specific command-line arguments (e.g., --load) are used to invoke potentially malicious Ruby script files like evil.rb, loader.rb, or script.rb. This pattern is indicative of an adversary leveraging existing legitimate tools to execute arbitrary script code.
Detects known malicious SilverFox payloads by comparing the file hash against a list of known SHA256 signatures associated with the malware.
Page 307 of 1871


