Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
This rule monitors for network connections to known command-and-control (C2) domains or DGA-patterned domains (ending in .icu or .cfd), as well as the execution or file creation of files matching known malicious SHA256 hashes.
This rule monitors the Windows Application event log for critical Microsoft SQL Server (MSSQL) events. It detects server crashes, access violations, stack overflows, and high-severity (20+) errors. These events often indicate severe database corruption, underlying system instability, or potential exploitation attempts targeting the database engine.
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
This rule detects the execution of processes associated with CLI proxy routers (such as CLIProxyAPI or router-for-me) that establish network connections to multiple AI provider APIs (e.g., Anthropic, OpenAI, Google Gemini) within a short window. This pattern is indicative of efforts to bypass rate-limiting or allowlisting mechanisms commonly used by corporate environments to control and audit AI service interactions.
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
Detects the execution of BloodHound/SharpHound reconnaissance tools and the presence of their generated output files (ZIP or JSON format) on a host. This rule monitors both the process creation events associated with the tool's execution and file creation events indicative of data staging or collection output.
Detects the use of obfuscated PowerShell commands that utilize .NET [Convert]::FromBase64String combined with character replacement string manipulation, a common technique to hide malicious payloads from simple static analysis.
Detects obfuscated PowerShell commands that utilize XOR operations combined with byte array manipulation and common file writing methods. This pattern is frequently used by malicious scripts to deobfuscate and drop payloads to disk.
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
Detects the execution of PowerShell with common obfuscation flags (-W Hidden, -nop, -nol) that attempt to load and execute a script directly from the user's local Temp directory. The detection specifically monitors for processes launched by command interpreters like cmd.exe or batch files, which is a common indicator of a malware dropper or stager.
Detects the creation or execution of suspicious .bat files within the Windows Startup folder, often coupled with command-line arguments involving .ini files. This behavior is indicative of persistence mechanisms where adversaries leverage the startup folder to ensure malicious scripts run upon user logon.
Detects suspicious execution of files located in the AppData Local Temp directory initiated by PowerShell or using PowerShell-specific hidden window arguments. This behavior is commonly associated with dropper scripts or malware staging execution from a user's temporary folder.
Detects the creation or modification of a file with a specific randomized name ('nloemfbihmhm') in the temporary directory, followed by the execution of a process identified as AutoIt from the same directory.
This rule detects the process 'charmap.exe' establishing an outbound network connection to a known AsyncRAT command-and-control (C2) IP address and port. This behavior is indicative of process injection where the legitimate Windows Character Map utility is utilized as a host process for malicious AsyncRAT payload execution.
Page 315 of 1871

