Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects unauthorized processes accessing sensitive web browser files (login data, cookies, local state) from suspicious or non-standard paths. This is a common behavioral pattern for infostealers attempting to exfiltrate user credentials and browser session tokens.
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
Detects anomalous, high-volume authentication failures originating from a single source IP address targeting multiple distinct internal devices within a short timeframe. This behavior is indicative of a password spraying or brute-force attack.
This rule detects network connections and HTTP requests to known malicious URLs, including file downloads associated with C2 infrastructure and malware distribution campaigns. It monitors both direct device network events and HTTP requests logged through security product events to identify potential secondary-stage payload delivery.
Detects the ShieldCrash CVE-2026-69414 exploit PoC binary/PDB via multiple corroborating distinguishing strings and file size
Detects the execution of the Cloudflare Tunnel client (cloudflared.exe) on Windows endpoints by monitoring process command line arguments, such as 'tunnel', 'run', or 'proxy-dns'. This tool can be used to establish unauthorized remote access tunnels, potentially bypassing firewall configurations.
This rule detects when common Windows applications (explorer.exe, svchost.exe, winword.exe, excel.exe, rundll32.exe) load DLLs that are either unsigned or located in user-writable directories (e.g., \Users\, \AppData\, \Temp\, \ProgramData\). This is a common indicator of potential DLL hijacking or side-loading attacks.
Comprehensive IOC sweep across endpoint file/process/network telemetry for the full set of known SilkParasite/SpiceRAT/NodeEdgeRAT/NomadRAT/BloodAlchemy infrastructure indicators reported by Hunt.io and Security Affairs: all listed C2/decoy/certificate-hosting IPs, all listed spoofed/infrastructure domains, and known file/certificate hashes (SHA256, SHA1).
Detects outbound network connections from devices to specific suspicious domains identified in the detection logic. This rule monitors for connections to 'ns2.asiainfo.it.com' and 'www.wordcheck.info', which may be indicative of malware communication, command and control, or malicious web activity.
This rule detects network connections from internal devices to known SpiceRAT Command and Control (C2) infrastructure IPs. The detection filters for successful connections on common ports (80, 443) that meet a volume threshold, indicating potential ongoing beaconing or communication with malicious infrastructure.
Detects the deletion of the registry key responsible for Chrome extension integrity verification (PreferenceMACs). Deleting this key allows an adversary to tamper with installed Chrome extensions without triggering security warnings. This activity has been observed in the Rapuncel campaign.
Detects the loading and service creation of the CcProtect/Alinubx kernel driver, a known technique for Bring Your Own Vulnerable Driver (BYOVD) attacks. The rule identifies suspicious characteristics such as file name mismatches, unauthorized product/company signatures, and the creation of services associated with this malicious driver family (e.g., NvFsFilter) to facilitate EDR/AV termination or privilege escalation.
Detects the deletion of the registry key responsible for Chrome extension integrity verification (PreferenceMACs). Deleting this key allows an adversary to tamper with installed Chrome extensions without triggering security warnings. This activity has been observed in the Rapuncel campaign.
Detects the loading and service creation of the CcProtect/Alinubx kernel driver, a known technique for Bring Your Own Vulnerable Driver (BYOVD) attacks. The rule identifies suspicious characteristics such as file name mismatches, unauthorized product/company signatures, and the creation of services associated with this malicious driver family (e.g., NvFsFilter) to facilitate EDR/AV termination or privilege escalation.
Detects the execution of ServiceModelReg.exe following parent process activity involving vsdbg.dll/vsdbg.exe, coupled with cross-process access indicators consistent with COM Elevation Moniker UAC bypass and potential process hollowing. This pattern is associated with the PUROSANGUE loader chain used to execute malicious code within a high-integrity process context.
This rule detects the potential bypassing of Protected Process Light (PPL) in Windows, characterized by kernel-mode driver activity (such as ObOpenObjectByPointer) correlated with the mass termination of security-related processes (e.g., Defender, CrowdStrike, SentinelOne). The correlation between driver-level object handle manipulation and the termination of protected security binaries is a strong indicator of an adversary attempting to disable EDR/AV protections via kernel exploitation or driver abuse.
Detects the installation and loading of a suspicious driver named 'NvFsFilter' (nvfsflt64.sys), accompanied by registry persistence and suspicious process termination events. This pattern is characteristic of a 'kill-loop' persistence mechanism where malicious drivers or services repeatedly terminate security agents (AV/EDR) to maintain a persistent foothold on the endpoint.
Detects DLL injection into browser processes (chrome.exe or msedge.exe) followed by the invocation of the browser's Elevation Service 'DecryptData' function, a behavior characteristic of the Rapuncel credential stealer attempting to bypass app-bound encryption.
Detects the loading or file presence of known suspicious or potentially malicious kernel drivers, specifically 'alinubx.sys' and 'ccprotect.sys', which are associated with unauthorized system-level activity or potential rootkit behavior.
Detects process injection behavior by monitoring for the usage of specific Windows API functions (NtAllocateVirtualMemory, NtCreateThreadEx, NtProtectVirtualMemory, NtWriteVirtualMemory, NtOpenProcess) frequently used by adversaries to execute malicious code within the context of a legitimate process.
Detects unauthorized processes accessing cryptocurrency wallet data files, including 'wallet.dat' or specific browser-based extension storage databases (e.g., MetaMask, Coinbase Wallet), which is indicative of the Rapuncel stealer attempting to exfiltrate sensitive wallet data.
Page 321 of 1871




