Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
This rule detects specific JavaScript helper functions and state machine constants commonly used in 'ClickFix' phishing campaigns (e.g., Exvicy and ErrTraffic). These scripts typically prompt users to copy and paste malicious code snippets, often disguised as error fixes or CAPTCHA resolution, to facilitate initial access.
These rules detect various exploitation attempts targeting SharePoint to bypass SafeControls, an security mechanism used to restrict the types of controls allowed in web parts. The patterns match suspicious Register directives and markup injection techniques often associated with remote code execution or privilege escalation, as identified in CVE-2026-65660.
Detects the IIS worker process (w3wp.exe) used by SharePoint loading a specific combination of assemblies (PresentationFramework.dll, System.Xaml.dll, and System.Data.Services.dll). This behavior is indicative of an ExpandedWrapper/XamlServices.Parse() insecure deserialization gadget chain, typically associated with the exploitation of vulnerabilities like CVE-2026-65660, which enables fileless in-memory code execution.
Detects outbound network traffic from internal hosts to known IP addresses associated with Exvicy Malware-as-a-Service (MaaS) Command and Control (C2) or hosting infrastructure. This rule acts as an indicator of compromise (IOC) match to identify potential infected hosts communicating with malicious external servers.
Detects HTTP POST requests to SharePoint ToolPane or WebPartPage endpoints containing serialized gadget chains (e.g., ysoserial ExpandedWrapper/ObjectDataProvider or XamlServices) indicative of deserialization exploitation attempts, specifically targeting CVE-2026-65660.
Detects unauthenticated HTTP POST requests targeting SharePoint WebPartPage-derived endpoints using the 'webPartMarkup' parameter. This activity attempts to exploit a vulnerability (CVE-2026-65660) where anonymous access to specific pages bypasses authentication, allowing an attacker to invoke internal methods for malicious register-directive injection.
Detects instances where the SharePoint IIS worker process (w3wp.exe) initiates command interpreters or known living-off-the-land binaries (LOLBins). This behavior is characteristic of post-exploitation activity, such as command execution following successful exploitation of SharePoint vulnerabilities involving insecure deserialization or malicious directive injection.
Detects non-browser and non-messaging processes accessing both browser credential stores (like 'Login Data' or 'Cookies') and messaging application session storage (Slack/Discord LevelDB) in a single session. This pattern is characteristic of credential-stealing malware, such as RevStealer, which targets both saved web browser credentials and application session tokens for exfiltration.
Detects outbound HTTP POST requests to the 'vpugy.vcqi' domain, which is associated with RevStealer malware exfiltration. The rule specifically looks for traffic using a spoofed Chrome/147 user-agent and specific cookie artifacts used for session tracking in the exfiltration communication.
Detects the execution of elevated cmd.exe processes (running with High or System integrity) spawned by parent processes originating from the AppData directory. This pattern is commonly associated with malicious installers, droppers, or payload execution where a staged binary in the user profile attempts to perform administrative actions.
Detects PowerShell execution that combines screen capturing capabilities (System.Drawing.Bitmap, Windows.Forms) with network communication (System.Net.WebClient) directed towards known C2 domains (medianewsonline.com) using specific exfiltration parameters (OKey, Who).
Detects unauthorized processes attempting to open handles to Google Chrome or Microsoft Edge with elevated permissions, specifically accessing thread context (often associated with hardware breakpoints used for process injection or credential extraction techniques).
Detects unauthorized access to critical Chromium-based browser credential databases (such as Login Data, Cookies, and History) by processes other than recognized browser executables. This behavior is indicative of credential-harvesting activity, specifically matching techniques employed by infostealers like RevStealer.
Detects suspicious process access attempts targeting common web browsers (chrome, msedge, firefox) using high-privilege access masks (such as 0x1F0FFF or 0x1FFFFF). The detection is specifically scoped to calls originating from unbacked memory (indicated by an UNKNOWN stack trace entry containing ntdll.dll), which is a common indicator of direct or indirect syscalls used by malware for stealthy memory access, such as credential theft or session cookie exfiltration.
Detects the execution of a RevStealer native PE payload by an Electron-based loader (XabivSystem.exe). The rule identifies when the loader spawns an unsigned, detached process from a hidden, randomly-named subdirectory within the user's AppData folder. This process creation is a precursor to the malware's environment checks, anti-VM/sandbox gating, and CAPTCHA verification routines.
Detects non-browser processes accessing sensitive browser credential stores (e.g., Login Data, Cookies) and cryptocurrency wallet files within a short time window. This pattern is characteristic of infostealer malware like Vidar, which grabs browser and wallet data for exfiltration.
Detects web browser processes (Chrome, Edge, Firefox, Brave, Opera, IE) being spawned by a parent process that is not part of the standard, trusted application launch lineage. This pattern is commonly observed in credential-stealing malware like Vidar Stealer, which invokes browsers to access and exfiltrate stored browser data.
Detects the custom ARX-based stream cipher used by Vidar Stealer (v2.2+) to encrypt strings and configuration data. The rule identifies the presence of specific FNV-1a and golden-ratio constants used for state initialization, in combination with unique, per-build keystream constants observed in recent variants.
Detects the presence of known Vidar Stealer malware binaries (internal build versions 2.0 through 3.4) by matching their SHA256 file hashes. Vidar is an infostealer malware typically used to exfiltrate sensitive data from victim systems.
This rule detects potential execution of Vidar Stealer by identifying specific diagnostic loader strings (e.g., 'Loader: write failed') within file modification and process execution events. The presence of these strings in file metadata or command-line arguments indicates stage-specific activity related to the malware's loading process.
Detects a low-privileged account manually triggering the 'CreateObjectTask' scheduled task, which is a known technique to force the 'Shell Create Object Handler' (dllhost.exe) to start under the SYSTEM context. This behavior is often associated with pre-exploitation steps for privilege escalation vulnerabilities, specifically those involving OBJREF marshaling targeting specific COM objects.
