Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
Detects instances where suspicious or potentially non-standard processes (e.g., winappx.exe, MsCache.exe) or Python scripts running from specific ProgramData subdirectories spawn cmd.exe with a /c command line argument. This pattern is often indicative of persistence mechanisms, lateral movement, or malicious script execution.
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
This rule detects unauthorized processes modifying the 'Secure Preferences' configuration file in Google Chrome or Microsoft Edge browser data directories. This activity often indicates an attempt by malicious software to hijack browser settings, such as forcing extensions or modifying security policies, which is a common precursor to credential theft or persistent malicious access.
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
This rule detects network connections to known command-and-control (C2) infrastructure associated with the KREMLIN browser extension. The extension exfiltrates browser data (cookies, sessionStorage, localStorage) by masquerading data transfer within requests to .css files hosted on the attacker-controlled domain 'luizestrelhashapr.online'.
This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.
This rule monitors endpoint network events, file operations, and process executions for known malicious indicators (domains and file hashes) associated with Kremlin activity. It detects connections to suspicious remote domains and the existence or execution of specific malicious file hashes.
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
This rule monitors network traffic for requests directed at a specific domain ('luizestrelhashapr.online') and path ('/google_api/b83fa72d.css'), which is identified in threat intelligence as an indicator of browser history exfiltration.
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
Detects outbound network communication from common web browsers (chrome.exe, msedge.exe) to a specific malicious domain and path associated with suspected Kremlin-linked screenshot exfiltration activities.
Detects instances where the VLC Media Player process (vlc.exe) acts as the parent to common LOLBAS (Living Off the Land Binary and Script) executables such as cmd.exe, powershell.exe, and others. This pattern is often indicative of exploitation attempts or malicious activity where a compromised or trojanized application triggers secondary payloads.
Matches known Phantom Stealer MaaS infostealer sample hashes
Matches known Phantom Stealer MaaS infostealer sample hashes
Matches known Phantom Stealer MaaS infostealer sample hashes
Detects the presence of known file hashes associated with Vectra Remote Access Trojan (RAT). The rule monitors both file creation/existence events and process execution events where the SHA256 hash matches the identified indicators of compromise.
Page 310 of 1871

