Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation or renaming of specific files ('windowSysUpdates.txt' or 'GymTraniningShedule.exe') within the user's Local AppData directory or its 'SystemFolder32'/'System Folder32' subdirectories. This behavior is indicative of potential malicious activity, such as staged malware persistence or disguised payloads.
Detects the use of PowerShell to enumerate system disks, volumes, and partitions, specifically targeting removable media identifiers. This behavior is commonly associated with reconnaissance activities where an adversary attempts to identify attached storage devices for potential data staging or exfiltration.
Detects the execution of processes named 'DriverInstaller.exe' or 'Automata-20.exe', the invocation of cmd.exe as a child process of these executables, or network requests originating from these processes to GitHub API and raw content endpoints. This pattern is indicative of potential initial access, tool staging, or malicious payload retrieval.
Detects modifications to the Windows Registry 'Run' key or execution of commands via reg.exe or PowerShell that attempt to create or modify a persistence entry named 'DailyFitnessTracker'. This technique is commonly used by malware to ensure execution upon user logon.
Detects the creation or modification of scheduled tasks using the 'schtasks.exe' utility, specifically looking for indicators associated with persistence mechanisms such as task names or commands like 'StandAloneOneDriveUpdater-2626' and 'Automata-20.exe'.
This rule detects potentially malicious command patterns involving PowerShell and the Windows Task Scheduler. It identifies suspicious uses of Microsoft Edge update task names, PowerShell commands executing encoded scripts, and specific external download patterns associated with potential dropper or downloader activity.
Detects potential command and control (C2) beaconing activity to GitHub repository API endpoints. The rule monitors for a high frequency of requests to specific file names commonly associated with C2 payloads (e.g., command.txt, results.txt, heartbeat.txt) and employs statistical analysis to identify consistent, non-random connection patterns that deviate from expected business usage.
Detects the execution of LNK files that launch cmd.exe to execute batch script files (e.g., .bat). This pattern is frequently used in malicious infection chains, such as those leveraged by Transparent Tribe (APT36), where ISO or ZIP archives contain LNK files masquerading as document files to trick users into executing malicious scripts.
Detects malicious LNK files associated with the Transparent Tribe (APT36) campaign, which are designed to execute concealed batch scripts (e.g., doxc.bat, config.bat) via cmd.exe. These files are typically disguised as documents (resumes, details) to facilitate the deployment of secondary payloads like CrimsonRAT.
Detects persistence mechanisms used by a Golang RAT, specifically targeting the creation of a 'DailyFitnessTracker' registry value in the HKCU Run key using reg.exe or PowerShell, and the placement of 'FitnessMonitor.exe' into the Windows Startup folder.
Detects execution of shell commands by cmd.exe in conjunction with the creation or modification of 'command.txt' or 'results.txt' files, which are indicative of the RUSTYSHADE backdoor's C2 synchronization behavior.
Detects execution of APT36's RUSTYSHADE backdoor, typically delivered via a DriverInstaller executable or zip file, and specifically tracks downloads from Backblaze B2 storage buckets using PowerShell.
Detects the establishment of persistence by the RUSTYMOVE malware through the creation of a scheduled task via PowerShell. The rule specifically looks for a command line containing both 'Register-ScheduledTask' and the specific masqueraded name 'StandAloneOneDriveUpdater-2626', which mimics a legitimate OneDrive update process.
Detects potential CrimsonRAT backdoor binaries on Windows systems by identifying characteristic obfuscated ASISFH command tokens, embedded C2 infrastructure strings, and specific dropper file artifacts associated with Transparent Tribe (APT36).
Detects the execution of PowerShell commands by the RUSTYMOVE tool intended to enumerate external removable storage devices (USB, SD, MMC, IEEE1394). The rule monitors for the concurrent use of Get-Volume, Get-Partition, and Get-Disk cmdlets with specific BusType filtering patterns.
Detects malicious scheduled task creation using names intended to mimic Microsoft Edge update tasks. The rule identifies suspicious process activity including the spawning of conhost.exe with headless flags, PowerShell commands with encoded arguments, and attempts to fetch external scripts from the known malicious typosquatted domain indiatodays.org, all of which are characteristic of APT36 (Transparent Tribe) activity.
Detects a Golang-based remote access trojan (RAT) attributed to the Transparent Tribe (APT36) threat group. The rule identifies the malware based on distinctive fitness-themed C2 API endpoints, specific function names, hardcoded authentication secrets, and embedded Go runtime markers, while also monitoring for associated persistence registry keys and file paths.
Detects the execution of a process named 'UBP.Exe' located within a 'UBP-Asset' directory at the root of a drive. This behavior is associated with the KRSID ransomware distribution campaign, which impersonates Union Bancaire Privée to lure victims into executing the fraudulent binary.
Detects the historical HPlus HTS fraud infrastructure chain. The rule monitors for the reading of a configuration file named 'config.Ini', followed by an outbound FTP connection (port 21), and the subsequent launch of an executable, which is indicative of a Quasar RAT deployment sequence.
Detects the KRSID Rust-based ransomware binary by matching against known file hashes or by identifying specific command-line arguments and embedded file/log indicators commonly used by the malware.
Detects ISO or ZIP archive files containing a specific combination of a LNK file named 'My Resume.pdf.lnk' and a 'doxc' directory. This specific file structure is associated with Transparent Tribe (APT36) activity used to deliver malicious payloads via social engineering lures.
Page 312 of 1871
