Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects potential process injection attempts involving 'charmap.exe', a Windows system utility. The rule monitors for a sequence of memory management and thread creation API calls (OpenProcess, VirtualAlloc, WriteProcessMemory, and CreateRemoteThread) originating from or targeting this binary, which is often abused as a host for malicious code to bypass security controls.
This rule detects a correlation between the creation or modification of a specific file name ('nloemfbihmhm') and the subsequent execution of processes from the 'Temp' directory involving related filenames ('kojuyn.ini', 'ogftogcyiblzjccmcbnw.exe', or 'nloemfbihmhm') within a 5-minute window. This behavior is indicative of a multi-stage execution chain, often used by malware to drop and execute secondary payloads.
This rule detects PowerShell commands that utilize specific character array joining techniques (e.g., [char]nnnn -join '') often used to obfuscate malicious strings or bypass keyword-based security filters. This is a common tactic for evading detection when downloading or executing payloads.
Detects PowerShell command execution that uses bitwise XOR operations combined with the .NET [IO.File]::WriteAllBytes method. This pattern is commonly used by malware, such as AsyncRAT, to deobfuscate and drop secondary payloads or modules onto the file system during execution.
Detects browser extension manifest.json files requesting declarativeNetRequest and content_scripts/host_permissions covering AI assistant vendor domains (BragJack attack class)
Detects network connections from common web browsers to domains associated with the BragJack threat actor infrastructure. This activity potentially indicates an end-user accessing malicious sites used for credential harvesting, malware delivery, or C2 communication.
Detects the installation or modification of a browser extension (manifest.json file creation) followed by network activity from the browser to trusted AI assistant domains within a five-minute window. This behavior is indicative of potentially malicious browser extensions or content scripts being introduced to intercept or manipulate user interaction with AI services.
Detects instances where browser processes (chrome.exe or comet.exe) create multiple screenshot-related files in quick succession without apparent user interaction, a behavior pattern observed in the BragJack attack chain associated with hijacked browser AI agents.
Detects browser activity where a user agent navigates to common webmail services (Gmail, Outlook) followed quickly by network traffic to potentially malicious external infrastructure or non-standard endpoints, suggesting unauthorized email content exfiltration.
Detects rapid AI agent state transitions (from 'think' to 'act') within Microsoft Edge processes, specifically identifying potential exploitation of the CVE-2026-55945 race condition vulnerability, which could be used to force the unauthorized execution of an injected prompt.
Detects high-frequency, automated interactions with popular AI assistant web interfaces (e.g., Gemini, Perplexity, Claude, Copilot) from common browser processes. This pattern often indicates unauthorized automated data submission or scraping, which may follow or facilitate automated exfiltration of browser-resident data.
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
This rule detects scenarios where 'MpClient.dll' is loaded by a process that is not a recognized Microsoft Defender security process, and this load event occurs in close temporal proximity to the creation or modification of 'ShieldCrash_' artifacts. This pattern is indicative of potential DLL side-loading or defense evasion activities, where an adversary attempts to masquerade malicious activity using components associated with security product internals or crash reporting mechanisms.
Detects potential exploitation of a CrowdStrike Falcon remediation process vulnerability ('FalconFlank'). The rule identifies either direct execution of the PoC binary or the suspicious combination of a CrowdStrike remediation process loading an unsigned or untrusted DLL from a user-writable path followed by the same process spawning a command shell in the SYSTEM context within 15 minutes.
Detects the use of 'curl.exe' to download a file named 'msgbox.exe' to the local temporary directory, specifically when triggered by 'cmd.exe' originating from 'chrome.exe'. This pattern is indicative of a browser-based delivery mechanism initiating a secondary malicious download.
This rule detects PowerShell commands that exhibit signs of obfuscation by searching for specific string manipulation methods commonly used to hide malicious code. Specifically, it identifies the use of base64 decoding (FromBase64String) or string concatenation combined with character replacement techniques (Replace) on the command line, which are often used by threat actors to execute encoded payloads while bypassing simple string-based signatures.
This rule monitors network traffic and internal logs for connections to known malicious IP addresses or domain names associated with 'ClickFix' social engineering campaigns (often impersonating services like HBO Max). The logic explicitly filters out known threat intelligence scanners and security researcher probes. It performs correlation by requiring domain/message matches for generic IP-based alerts to reduce noise, and aggregates events per host over 15-minute windows to produce consolidated alerts.
This rule monitors network traffic and internal logs for connections to known malicious IP addresses or domain names associated with 'ClickFix' social engineering campaigns (often impersonating services like HBO Max). The logic explicitly filters out known threat intelligence scanners and security researcher probes. It performs correlation by requiring domain/message matches for generic IP-based alerts to reduce noise, and aggregates events per host over 15-minute windows to produce consolidated alerts.
Detects network communication with domains and IP addresses known to be associated with 'ClickFix' social engineering campaigns (specifically those masquerading as legitimate HBO Max or macOS related updates). The rule applies a strict correlation between observed malicious IP traffic and specific DNS requests to reduce noise from IP address reuse or threat intelligence feed probes, while also excluding known security-related processes.
Detects network communication with domains and IP addresses known to be associated with 'ClickFix' social engineering campaigns (specifically those masquerading as legitimate HBO Max or macOS related updates). The rule applies a strict correlation between observed malicious IP traffic and specific DNS requests to reduce noise from IP address reuse or threat intelligence feed probes, while also excluding known security-related processes.
HBO Max ClickFix attacks IOC Hunt
Cortex XDR
Detects network activity (DNS queries or direct IP communication) associated with 'ClickFix' social engineering attacks targeting users under the guise of an HBO Max update or repair utility. The rule includes indicators for known malicious domains and IP addresses while incorporating filters to minimize false positives from security scanners, threat intel feeds, and automated crawlers by analyzing User-Agent strings and network source addresses.
Page 320 of 1871



