Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where a new executable file (.exe) is written to the file system following a download event. The rule specifically looks for scenarios where the download URL ends in .exe or is a direct download link, while flagging cases where the referrer is empty or missing, often indicative of direct downloads from C2 infrastructure or scripts rather than user-initiated browser navigation.
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
Detects download or installation attempts of specific trojanized versions (2.35 and 2.36) of the Admin Menu Editor Pro plugin, which were distributed via a compromised update channel on adminmenueditor.com.
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
Detects bulk filesystem operations (create, copy, rename, move, delete) performed by the masqueraded process 'msedge.exe' located in 'C:\ProgramData\Microsoft\Windows\Telemetry\', indicative of the MovieReaper 'file manager' module performing mass file manipulation.
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
This rule detects the creation of specific system mutexes commonly used by malware for persistence or to avoid multiple infections (Mutual Exclusion). It monitors for both a specific hardcoded mutex and a pattern-based approach (15-20 alphanumeric characters) initiated by executables from common temporary or user-writable directories, which is a frequent indicator of malicious secondary payloads or droppers.
This rule monitors for processes named 'msedge.exe' executing from the 'C:\ProgramData\Microsoft\Windows\Telemetry\' directory. The rule filters out legitimate Edge update processes and common browser command-line arguments to isolate potentially malicious masquerading attempts by identifying binaries that share the name of a legitimate application but reside in unexpected, often non-standard locations.
Detects execution of the MovieReaper initial loader binary. This malware employs advanced anti-analysis techniques, specifically manual PEB-walking to resolve APIs and evade detection by standard library loading hooks. The rule alerts on known file hashes and specific masquerading filenames.
This rule detects a multi-stage malicious behavior chain: the execution of a suspected loader (identified by hash or specific mutex), followed by network communication to a known C2 domain or IP, and concluded by the placement of a file in the Windows Telemetry folder (typically mimicking msedge.exe). The events are correlated within a short time window (2 hours between each stage) on the same device.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Page 308 of 1871

