Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of cmd.exe with command-line arguments typical of self-deleting batch scripts. The pattern includes a delay (timeout /t 2) followed by a file deletion command (del), often used to remove temporary scripts or malicious artifacts after execution.
Detects the creation of threads where the entry point or call stack is associated with 'kernel32.dll' but originates from memory regions that are unbacked by a file on disk (i.e., 'unbacked', 'unknown') or have a null return address. This pattern is highly indicative of reflective code injection or manual shellcode execution, where an adversary attempts to execute code within a legitimate Windows process without a corresponding file-backed image.
Detects the execution of a process named 's.exe' (or similar match) with a command-line argument consisting of a single character 's' followed by a digit. This pattern is commonly associated with malicious usage or obfuscation, where 's.exe' might be a renamed utility or a malicious artifact attempting to masquerade or execute specific tasks.
Detects the installation or update of browser extensions that utilize 'declarativeNetRequest' or 'webRequest' APIs in conjunction with 'content_scripts' and either broad URL access ('all_urls') or access to sensitive web domains (e.g., Google Gemini, Microsoft Copilot, Perplexity, Claude). This combination is highly indicative of extensions designed for data interception, credential theft, or unauthorized web traffic manipulation.
Detects instances where the Chrome browser process accesses camera or microphone hardware, or invokes media device APIs, potentially indicating unauthorized audio or video recording.
This rule detects rapid, repetitive state change operations (such as think, act, or mode changes) occurring within the Microsoft Edge browser context when interacting with Microsoft domains. This behavior is indicative of automated browser interactions, such as those performed by botnets, automated testing frameworks, or potentially malicious browser automation scripts.
This rule detects potentially malicious attempts to import certificates into the Windows certificate store using command-line tools like certutil or direct modification of the registry. This behavior is frequently associated with attackers attempting to establish persistence, bypass certificate validation, or install rogue trust anchors for man-in-the-middle operations.
Detects instances where common web browsers (Chrome, Edge, Firefox, Safari) or related desktop applications spawn shell interpreters (PowerShell on Windows, bash/zsh/sh on macOS) with command-line arguments indicative of malicious activity, such as base64-encoded payloads, hidden windows, or remote script downloading.
This rule detects potentially unauthorized installation of root certificates on Windows and macOS systems. Attackers use this technique to bypass security warnings, establish adversary-in-the-middle capabilities, or inspect encrypted traffic by adding their own certificates to the system's trust store.
This rule detects the loading of specific DLLs (winfsp-x64.dll or dukeqt.dll) by processes from locations outside of the standard Windows System32 or SysWOW64 directories. This behavior is indicative of DLL side-loading, where an adversary attempts to execute malicious code by placing a rogue DLL in a path where a legitimate application might attempt to load it, or by intentionally side-loading it alongside an executable.
Detects browser-based processes (Chrome, Opera, Edge) making network requests to AI and cloud service domains (Google Gemini, Claude, Opera). This rule monitors for potentially unauthorized or excessive browser communication with these services.
Detects the creation of compressed archive files (zip, rar, 7z, dat) followed by a significant network upload (exceeding 5MB) on the same host within a 30-minute window, which is indicative of staging and exfiltrating collected data.
Detects instances where the Google Chrome browser process interacts with files or registry keys associated with audio and video capture devices, such as cameras and microphones. This may indicate unauthorized use of media peripherals by the browser process.
Detects the loading of specific DLLs ('winfsp-x64.dll' or 'DukeQt.dll') where the module path is empty or null. This behavior is indicative of potential memory-only execution or process injection (e.g., reflective loading), as the module is not associated with a valid file on disk.
Detects the presence of known synchronization objects (mutexes, events, or shared memory) associated with SparroWocky malware, identified via Microsoft Defender DeviceEvents and DeviceProcessEvents telemetry. The rule monitors for these specific markers in process creation, remote thread creation, and named pipe events.
This rule identifies potential SparroWocky malware payload files by detecting a specific custom header (0x11328712 in both little-endian and big-endian format) used for identifying encrypted .dat files that contain embedded RC4 keys.
This rule detects a process loading English (.en-US) MUI resource files from the C:\Windows\System32\en-US\ directory when the initiating process is located outside of standard system directories (System32, SysWOW64, Program Files). This behavior is indicative of a masquerading or camouflage technique where a malicious executable attempts to mimic a legitimate system process by loading its localized resources.
This rule detects remote thread creation where the start function address is identified as 'AnimateWindow'. This behavior is associated with the SparroWocky technique, which uses thread execution hijacking by pointing the thread start address to legitimate UI-related Windows APIs to mask the actual malicious entry point, thereby evading traditional detection mechanisms that monitor for suspicious thread start addresses.
This rule monitors for indicators of code execution anomalies commonly associated with process injection, ROP (Return-Oriented Programming) chains, or memory manipulation. It specifically looks for spoofed call stacks, return address validation failures, suspicious API usage in common thread initialization routines, and ROP gadgets within critical modules like kernel32.dll.
This rule detects potential masquerading activity where an executable is signed by 'Discord Inc' or 'Lenovo' but the image path does not correspond to expected legitimate installation directories or filenames. It flags processes that claim a trusted publisher identity while residing in suspicious or unexpected locations.
Detects ClickFix-style activity where a web browser or common application launcher spawns a terminal or PowerShell process to execute obfuscated, copied, or piped commands. This behavior often indicates a social engineering attack where a user is tricked into manually executing a malicious command script.
Page 317 of 1871
