Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where npm.exe or node.exe initiate child node.exe processes, a behavior commonly associated with multi-stage loaders or malicious packages (e.g., GHAPPIER) that execute arbitrary JavaScript payloads during package installation or execution.
This rule detects unauthorized access, creation, or modification of Git credential files (.git-credentials, .netrc) by processes other than standard Git credential management utilities. It also monitors command-line activity that references these credential stores to identify potential attempts to exfiltrate or manipulate stored credentials.
This rule detects the creation of multiple suspicious files within the \Windows\Temp\nb_ directory. The monitored filenames, such as 'agent.json', 'pk.der', 'sleepmask.o', and 'core.pak', are highly characteristic of post-exploitation toolkits, specifically those associated with beaconing, shellcode injection, or modular C2 agents. Detecting these files in temporary locations, especially when appearing in combination, strongly indicates potential adversary activity involving the staging and execution of malicious payloads.
Detects the creation of specific file artifacts and process execution associated with the PIVOTPIPE .NET loader. The rule monitors for the creation of temporary working directories prefixed with 'nb_' in '\Windows\Temp\', the staging of associated configuration and payload files (such as 'agent.json', 'pk.der', 'sleepmask.o', 'core.pak'), and the execution of associated process names like 'netbeacon_pivot.exe', 'pivot_hop2_kasp.exe', or 'x64beacon.exe'.
Detects the creation or modification of known PIVOTPIPE loader artifacts, specifically the 'sleepmask.o' file and related configuration or helper files ('agent.json', 'pk.der', 'core.pak'), within temporary directories prefixed with 'nb_' under the Windows Temp folder. These files are used by the PIVOTPIPE loader to implement sleep-masking techniques that encrypt beacon memory during dormant periods to evade detection.
Detects PowerShell execution containing multiple command-line arguments indicative of environment discovery, such as checking system uptime, hardware specifications, or specific memory-related delays. These patterns are commonly used by malware to detect virtual machines, sandboxes, or analysis environments to alter execution or exit.
Detects suspicious PowerShell activity involving compression commands (e.g., Expand-Archive) within APPDATA, correlated with the execution of hypersnap.exe with hidden window arguments, and the creation of persistence via scheduled tasks. This pattern is indicative of automated staging or malicious tool execution and persistence setup.
Detects a scenario where a single initiating process terminates multiple distinct processes within a short timeframe (5 minutes). This behavioral pattern is often associated with security tool tampering or EDR-evasion techniques where malicious code attempts to identify and terminate defensive security processes.
Detects the creation of specific debug log files by PIVOTPIPE Cobalt Strike-compatible payloads in the Windows temporary directory. These artifacts indicate active post-exploitation activity, specifically operations involving process token manipulation or impersonation.
Monitors for the publication of specific NPM packages ('@dforge-core/dforge-mcp' or 'dforge-mcp') with a specific version ('0.2.21'). This rule is designed to track software supply chain activity related to this specific package and version.
Detects high-frequency actions including code pushes, branch policy overrides, or workflow completions on the 'main' branch of the 'dforge-core/dforge-mcp' repository within a short time window (under 120 minutes). This may indicate automated interaction, potential rapid CI/CD activity, or unauthorized mass modification of the core repository.
This rule monitors for suspicious process behaviors and module loads, specifically focusing on unusual explorer.exe parentage, the loading of common system DLLs (dbghelp.dll, Secur32.dll) in potentially anomalous contexts, and specific command-line strings that may indicate malicious activity or tools.
Detects high-frequency calls to the VirtualProtect API where memory protections are changed to read/write (PAGE_READWRITE) or executable read/write (PAGE_EXECUTE_READWRITE). This behavior is often indicative of process injection techniques or self-modifying code associated with unpacking, loading shellcode, or tampering with process memory.
Detects anomalous, high-frequency interaction with the Windows clipboard by explorer.exe. This activity is often associated with unauthorized data collection or exfiltration attempts by malware residing within or masquerading as the Windows shell.
Detects the loading or installation of a driver file identified as DCRCVDrv.sys followed within 5 minutes by EDR sensor heartbeat loss or process activity, which is characteristic of attempts to tamper with security software or hide malicious activity via a kernel-mode driver.
Detects process execution patterns and DNS requests associated with the GHAPPIER malware staging infrastructure. The rule monitors for specific command-line arguments involving known malicious scripts, temporary files, and deployment infrastructure (e.g., Vercel) often used for delivering or executing malicious payloads via node.js environments.
Detects a process that deletes its own executable file immediately after launching. This anti-forensic behavior is commonly utilized by remote access trojans (RATs) and other malware to minimize their footprint and evade file-based forensic analysis.
Detects network activity associated with NetSupport Manager remote access software, specifically targeting DNS lookups, TLS SNI connections, and direct TCP beaconing to a known-malicious infrastructure IP. This rule is designed to identify unauthorized use of legitimate remote support tools for command and control purposes.
Detects malicious JavaScript/npm payloads that attempt to evade static analysis and string-based detection signatures by dynamically reconstructing sensitive strings at runtime using V8 string-object construction or obfuscated string tables.
Detects execution of code using indirect syscalls or ntdll unhooking techniques, often associated with the PIVOTPIPE loader/RAT. The rule monitors for EDR indicators of evasion such as syscall stub execution, direct/indirect Nt* system call invocation, or call stacks originating outside of ntdll.dll, intended to bypass userland security hooks.
Correlates an MFA method change with the next sign-in occurring from an ASN/country never seen for that user in 30 days, operationalizing TrustSphere's 2026 finding that reset-then-new-location access is the clearest signal separating a hijack from a genuine recovery.
