Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Matches known VectraRAT sample SHA-256 hashes and the ClickFix distribution domain (verify-cloud.digital) recovered from pivoting across exposed VectraRAT distribution infrastructure
Detects a two-stage pattern indicative of command-and-control (C2) communication. The rule identifies an initial request to a 'relays.json' endpoint (relay discovery) followed by a request to an 'api.php' endpoint (dispatcher decision) within a 5-second window, both using a 13-digit timestamp query string for cache-busting. It also captures single-stage 'api.php' requests as lower confidence alerts.
Matches known SilverFox malware payload samples by SHA256 hash
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
This rule detects the sequence of an external file download over HTTP, followed by the immediate creation and execution of an executable file (.exe, .dll, .scr) on the endpoint. It specifically filters out common system installers (e.g., msiexec.exe, trustedinstaller.exe) to reduce noise, focusing on potentially malicious payloads delivered via network channels.
Detects process creation events containing command-line arguments indicative of an OAuth 2.0 device code flow, commonly used in consent phishing or device code phishing attacks to hijack account access via a malicious OAuth application registration.
Detects executable files containing XOR-obfuscated strings associated with BabylonRAT capabilities, including browser credential theft, keylogging, HOSTS file manipulation, DDoS, and remote dynamic API resolution. This rule identifies patterns commonly used to evade static analysis.
Detects network activity and HTTP traffic associated with the Iron Man System kit, specifically targeting hardcoded C2 infrastructure (IP-based) and lure domain patterns involving specific brand tokens combined with disposable TLDs.
This rule detects unauthorized persistence attempts by monitoring for the creation of a registry value named 'DailyFitnessTracker' under the HKEY_CURRENT_USER Run key. It triggers when 'reg.exe' is used to add the key, PowerShell is used to set the registry property, or when a general registry event indicates the creation of this specific key. This behavior is indicative of a persistence mechanism designed to launch a potentially malicious or unwanted program upon user logon.
Detects execution of cmd.exe originating from potentially malicious or unexpected parent processes associated with RUSTYSHADE malware activity. This rule monitors for cmd.exe invoked by processes like 'DriverInstaller.exe' or 'Automata-20.exe', or processes other than standard Windows system processes (explorer.exe or services.exe), which is indicative of command-line shell abuse for malicious operations.
Detects execution of a config.bat file combined with indicators of cleanup or reference to potentially malicious LNK files and payloads (e.g., windowsysupdates.txt). The rule monitors command-line activity via Sysmon to identify potential post-exploitation staging and cleanup behavior.
This rule detects potential data exfiltration by monitoring for screen capture activity, identified by API calls like BitBlt or CopyFromScreen or the loading of gdi32.dll, followed by the creation of a screenshot file and subsequent network connections to GitHub domains.
Detects the creation of suspicious scheduled tasks using either schtasks.exe or PowerShell's Register-ScheduledTask cmdlet. The rule specifically looks for masquerading attempts involving names like 'StandAloneOneDriveUpdater-2626', the usage of AtLogOn triggers, and the execution of the binary 'Automata-20.exe'.
Detects rapid execution of multiple native Windows discovery commands (whoami, ipconfig, hostname, tasklist) within a short window, which is often indicative of an adversary performing environment reconnaissance post-compromise.
Detects the execution of a scheduled task named 'MicrosoftEdgeUpdateTaskUserS-1-5-24' which triggers conhost.exe with the --headless argument or PowerShell with an EncodedCommand. This behavior is indicative of a malicious persistence mechanism masquerading as a legitimate Edge update task, specifically associated with the retrieval of payloads from the malicious domain 'indiatodays.org'.
This rule detects the execution of the HTSPnew.Exe ransomware payload, associated with a trojanized HTS DLL, and subsequent ransomware-related file operations, such as the creation of .krsid encrypted files and the dropping of a Korean-language ransom note (README_KRSID.Txt).
Detects the execution of 'HTSPnew.Exe', a utility associated with suspicious activity or ransomware simulation, combined with command-line arguments that suggest testing, batch execution, or help requests.
This rule detects various common command-line techniques used for network reconnaissance and internal environment enumeration on Windows systems. It tracks the execution of native tools such as ARP for ARP cache dumping, Ping for subnet sweeps, and NetBIOS or SMB-related commands (nbtstat, net view, net share, net session) to identify remote systems, network shares, and active sessions.
Detects the execution of common command-line or scripting interpreters (cmd, powershell, cscript, etc.) spawned by the ScreenConnect remote administration client. This is a common pattern used by attackers leveraging legitimate remote access tools for post-exploitation activities and lateral movement.
Detects potential SQL injection attempts by monitoring for 'INSERT INTO' SQL commands executed via command-line arguments. The rule specifically looks for operations targeting user or role tables and including administrative keywords, originating from database or application-related processes like mysql or java.
Page 311 of 1871


