Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the modification of service permissions for the 'AgtaBackupAgentSvc' service using the 'sdset' command via 'sc.exe', 'cmd.exe', or 'powershell.exe'. Adversaries use this technique to hide services or modify access to them by applying a specific Service Descriptor Definition Language (SDDL) string to bypass security enumeration or maintain persistence.
Detects the execution of PowerShell from processes associated with legitimate Remote Monitoring and Management (RMM) tools (such as ScreenConnect or LogMeIn) running under the SYSTEM account. This behavior is indicative of an attacker who has gained access to an RMM tenant and is using an interactive session to execute commands, perform reconnaissance, or deploy further malicious payloads.
Detects the disabling of the built-in 'Administrator' account initiated by a system-level process (e.g., service or background task), which is characteristic of GPO enforcement or malicious tampering.
Detects the execution of known PAYLOAD ransomware process-termination utilities (killer.exe or kill.exe). These tools are used by adversaries to forcefully terminate security software, backup services, and database processes prior to file encryption.
Detects execution of common Windows utilities used by adversaries post-encryption to hinder system recovery and clear forensic evidence. This includes disabling the Windows Recovery Environment (ReAgentC), wiping disk free space (Cipher), clearing DNS caches, and clearing Windows Event Logs via Wevtutil or PowerShell.
Detects the creation of new Group Policy Objects (GPOs), linking of GPOs at the domain root level, or modifications to existing GPOs that include 'Firewall' in their configuration settings. These activities are common precursors or indicators of persistence mechanisms and defensive bypass attempts by adversaries seeking to weaken security controls or maintain unauthorized access.
This rule correlates multiple telemetry sources (File Events, Certificate Info, Network Events, and DNS Events) to detect known malicious indicators, including specific file hashes, IP addresses, domains, and URLs associated with malicious activity.
This rule detects potential malicious activity where a non-browser process downloads a specific payload file from a suspicious domain ('easyllms.xyz') and is subsequently linked to process activity involving the discovery of system or user information (e.g., GetComputerNameA, GetUserNameA). This pattern is characteristic of a dropper or stage-one malware attempting to profile the compromised host.
This rule detects potential command and control (C2) beaconing activity where specific suspicious API endpoints (/api/v1/ping.php and /api/v1/connect.php) are accessed by common system processes (msedge_proxy.exe or WindowsUpdate.exe). The logic clusters these network requests by device and process, triggering an alert when both endpoints are observed from the same process on a single device, a common indicator of a C2 communication pattern.
Detects the execution of a file named 'msedge_proxy.exe' located in temporary directories (AppData\Local\Temp or Windows\Temp). The rule excludes processes initiated from legitimate Microsoft Edge installation paths, and flags processes that are either spawned simultaneously with the parent or are not spawned by explorer.exe, indicating potential masquerading or unauthorized execution of a malicious file disguised as a browser component.
This rule detects potential brute force or account compromise attempts by identifying user accounts that have successfully authenticated or initiated authentication events from two or more distinct IP addresses within the observed time window. It monitors Windows Event IDs 4624 (Successful Logon), 4648 (Logon attempted using explicit credentials), and 4776 (The domain controller attempted to validate the credentials for an account).
Detects instances where common scripting or development language runtimes (Go, Node.js, WScript, CScript) access sensitive configuration or credential files, such as AWS credentials, Kubernetes configs, SSH keys, or environment files. This activity is often indicative of credential harvesting or unauthorized access to sensitive secrets by potentially malicious scripts or processes.
Detects the 'ClickFix' social engineering pattern where an adversary tricks a user into using the Windows Run dialog (explorer.exe) to execute msiexec.exe, downloading and installing a remote MSI package. This is frequently associated with malware delivery, such as Psychedelic Stealer, where users are prompted to copy and paste malicious commands under the guise of fake error messages or CAPTCHAs.
Detects potential exfiltration staging by copying files from Windows mounts (/mnt/) into the WSL Linux filesystem using wsl.exe -e cp/mv
Detects Microsoft Installer (MSI) files associated with the psychedelic stealer malware family. The rule identifies MSI components that contain embedded paths to the psychedeliclove.exe payload, specific command and control IP/port combinations, and decoy file names (e.g., MsMpEng.exe or explorer.exe) used to disguise the malware installation or execution process.
Detects the creation of a Windows service that impersonates the legitimate Windows Time (w32time) service name or display name but utilizes a binary located outside of the standard system32 directory. This behavior is indicative of a persistence mechanism, often used by backdoors like RemotePanel to evade detection after initial compromise.
This rule detects persistence mechanisms involving the creation or modification of Windows Registry Run keys, the creation of scheduled tasks, or the execution of specific binaries (COTFileReadApp.exe, DeElevate64.exe) associated with potentially unauthorized activity, specifically tracking strings related to 'Canon Configuration Reader' or 'Stardock DeElevation Tool'.
Detects a credential-theft pattern associated with Psychedelic Stealer where a process accesses the 'Login Data' file of common Chromium-based browsers, followed shortly by a network connection to a known stealer exfiltration API endpoint.
This rule detects the creation of a new Windows service using common administrative tools like sc.exe or PowerShell's New-Service cmdlet that masquerades as the legitimate Windows Time service (w32time). The rule specifically flags service creation commands that use relevant service names but point to non-standard, suspicious executable paths or configurations, potentially indicating persistence or malicious activity by RemotePanel.
Detects the loading of spoofed system DLLs (dnsapi.dll or ws2_32.dll) from non-system directories, followed by network beaconing to suspicious domains associated with the NeedyMantis malware.
Detects the execution of taskkill.exe to terminate known security software processes, when the command is initiated from sqlservr.exe or via a command shell child process of sqlservr.exe. This activity is a common post-exploitation step after abusing xp_cmdshell to neutralize defenses before deploying further payloads.
Page 31 of 1866



