Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of a registry value named 'SnapCart' within the Windows Run keys. Adversaries use Run keys to ensure that malicious programs execute automatically upon user login or system startup, establishing persistence on the compromised host.
This rule detects high-frequency, sub-second screen capture activity typically associated with malwares utilizing screen scraping to exfiltrate changed screen regions. It specifically monitors API calls related to graphical interface manipulation (BitBlt, GDI) and screen capture events, triggering when the frequency of these calls reaches a consistent, rapid interval.
Detects in-memory execution and stack-spoofing activities associated with the SparroWocky BOF loader (RunCOFF). It monitors for suspicious remote thread creation (EventCode 8), process access with highly permissive access masks (EventCode 10), and the loading of specific suspect DLLs (EventCode 7) that are indicative of this technique.
Detects network communication to known malicious infrastructure associated with the GRAYRABBIT malware campaign. The rule correlates TCP connections on port 443 to the domain 'mail.uaiubifas.top' with process events attempting to discover system and user information (GetAdaptersAddresses, gethostname, GetUserNameA), which is characteristic of the malware's initial beaconing behavior.
Detects network communication to known malicious infrastructure associated with the GRAYRABBIT malware campaign. The rule correlates TCP connections on port 443 to the domain 'mail.uaiubifas.top' with process events attempting to discover system and user information (GetAdaptersAddresses, gethostname, GetUserNameA), which is characteristic of the malware's initial beaconing behavior.
Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.
Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.
Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.
Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.
Detects anomalous behavior indicative of the GRAYRABBIT shellcode which uses manual module walking and hash-based API resolution to load 'urlmon.dll' dynamically, followed shortly by an outbound network connection to a known malicious staging IP. This pattern reflects an evasion technique designed to avoid static import table analysis.
Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.
Detects potential data exfiltration activity associated with the GRAYRABBIT threat actor, where a local file is accessed or modified by a process shortly before or after that same process initiates a network connection to a known GRAYRABBIT C2 endpoint over port 443.
Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.
Detects behavior indicative of the GRAYRABBIT malware, specifically identifying network connections to known command-and-control (C2) infrastructure (mail.uaiubifas.top) followed within a short time window (10 minutes) by reflective in-memory module loading activities within the same process. This pattern suggests the delivery and execution of a plugin or additional malicious payload without writing the binary to disk.
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
Detects the creation or modification of a Windows service named 'ProcAuditManager' via registry keys or command-line utilities. This pattern is indicative of potential persistence mechanisms or service manipulation for malicious purposes.
Detects potential exploitation of CVE-2025-3248 in Langflow by identifying suspicious inbound network traffic targeting the /api/v1/validate/code endpoint, correlated with subsequent python child processes containing base64 decoding and execution primitives such as eval, exec, or subprocess.
Detects the creation of mutexes or named pipes containing the string 'SALITY', which is a characteristic indicator of the Sality malware family.
This rule detects potential credential dumping attempts targeting the Local Security Authority Subsystem Service (LSASS) process. It identifies suspicious file execution based on a blocklist of known credential dumping utility hashes, unauthorized OpenProcess calls to lsass.exe with specific access rights, and the creation of process memory dump files (e.g., .dmp, .dump) correlated with an lsass.exe access event.
This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
This rule detects potential DLL side-loading activity by identifying when known malicious file hashes are loaded by a specific set of executable files that are commonly abused for side-loading, or when these executables are executed from locations outside of their standard, verified installation directories.
Page 318 of 1871


