Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,902
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of the Windows 'net' or 'net1' utility to connect to the hidden 'IPC$' inter-process communication share. This behavior is often associated with lateral movement, reconnaissance, or establishing authenticated sessions to remote systems for further malicious activity, such as remote command execution.
This rule logs the execution of 'UBPUpdater.exe'. While the purpose of this binary is not inherently malicious, tracking its execution can be useful for auditing software updates or identifying unauthorized applications running on the system.
This rule monitors network traffic to GitHub API endpoints and categorizes the activity based on APT36's known operational window (weekdays, 04:00-11:00 UTC). Traffic patterns deviating from this schedule are flagged as anomalous, helping to identify potential C2 communication outside of established threat actor activity windows.
Detects instances where a process named UBP.Exe spawns a child process named HTSPnew.Exe, specifically when both binaries reside within the same directory path containing 'UBP'. This behavior may indicate an application-specific pattern or potentially malicious execution where one component of a suite invokes another.
Detects instances where cmd.exe or wscript.exe are executed from explorer.exe or via a .lnk file, which is a common pattern for initial access and execution of malicious payloads, often seen in spearphishing scenarios involving obfuscated or disguised files.
This rule detects potential ransomware activity by monitoring for specific file naming patterns associated with known ransom notes (.krsid, README_KRSID.Txt) and the execution of suspicious processes (HTSPnew.Exe, UBPUpdater.exe).
Detects execution of processes associated with QuasarRAT or references to its configuration files, originating from or involving files and processes named 'UBPUpdater.exe' or 'UBPPatch.Psh'. Also identifies network connections via FTP or involving configuration files ('config.Ini') initiated by these specific processes, which may indicate malicious activity, command and control, or data exfiltration.
This rule detects potentially malicious file manipulation activities, such as renaming, moving, copying, or deleting files, specifically when involving targeted filenames (e.g., 'GymTraniningShedule.exe') or locations (e.g., 'SystemFolder32'). The detection monitors for suspicious command-line arguments executed by 'cmd.exe' or 'conhost.exe' and cross-references them with file deletion events involving '.lnk' files or specific application artifacts.
Detects the use of mklink.exe or cmd.exe with mklink arguments to create symbolic links associated with specific file paths (ProgramData\doxc) or specific suspicious filenames (hzwzucr_widsisa.exe). This behavior is often associated with malware persistence or evasion, where adversaries link malicious binaries to disguise their location or execution source.
Detects the execution of PowerShell commands containing indicators of AMSI or ETW unhooking (e.g., references to amsi.dll, AmsiScanBuffer, EtwEventWrite, or VirtualProtect). This activity is commonly associated with attackers attempting to bypass endpoint security telemetry and antimalware scanning mechanisms prior to executing malicious payloads.
This rule detects the installation or modification of ScreenConnect services on Windows endpoints. It monitors for the creation of services using 'sc.exe', process commands related to ScreenConnect setup executables, or registry modifications and service installations associated with specific ScreenConnect identifiers, often indicative of unauthorized remote management software installation.
Detects the Stella_Gary .NET backdoor loader used by Kimsuky/APT-C-55, identified by managed-layer reflective assembly loading strings (loader.Program.Main, AssemblyResolve callback, Stella_Gary.Program.Main)
Detects the Stella_Gary .NET backdoor loader used by Kimsuky/APT-C-55, identified by managed-layer reflective assembly loading strings (loader.Program.Main, AssemblyResolve callback, Stella_Gary.Program.Main)
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
This rule detects the execution of PowerShell commands that simultaneously perform reconnaissance for security analysis tools and virtual machine environment indicators. The presence of encoded, hidden, or non-interactive PowerShell flags in conjunction with these discovery actions is indicative of an adversary attempting to verify their execution environment to evade detection and analysis by security researchers or automated sandbox systems.
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
This rule monitors for network connections, firewall traffic, and Entra ID authentication events involving known malicious IP addresses (the 'Wall of Shame'). The rule specifically flags interactions occurring over common VPN ports, suggesting potential unauthorized access or persistence attempts via VPN services.
Detects network connection events to known domains and subdomains associated with the SilkParasite threat actor. The rule specifically monitors for connections to specific parent domains (natcommunzu.com, kginfocom.com, mfa-uz.com) and subdomains utilizing service-oriented naming patterns (e.g., mail, service, help, storage, support, microsoft, post) commonly used by this actor for command and control infrastructure.
Page 313 of 1871



