Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the delivery of Rapuncel infostealer via abnormally large ZIP archives that incorporate binary padding with junk DLL files (such as TitanStorage.dll or ProManager.dll). This technique is used to evade security scanners that have file size limitations. The rule tracks specific campaign filenames and junk file markers.
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
Detects the silent installation of remote monitoring and management (RMM) software using 'msiexec.exe' initiated by scripting engines (powershell.exe, wscript.exe, or cscript.exe). The rule targets installations occurring in user-writable directories, such as Temp or Downloads, which are common staging locations for malicious droppers, while excluding known legitimate software deployment paths.
This rule detects network connections or process command lines associated with known malicious domains, IP addresses, or payload URLs. Additionally, it correlates connections to common public file-sharing platforms or APIs (e.g., Gofile, Telegram) if these events occur on the same device within a 60-minute window of a confirmed malicious infrastructure event, reducing false positives from legitimate uses of shared infrastructure.
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
Detects the execution of base64 encoded PowerShell commands initiated by conhost.exe with the --headless flag. The decoded command contains specific suspicious patterns, including accessing environment variables, reading file content, and deleting files, which is characteristic of malicious scripts attempting to stealthily interact with the environment.
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
Detects the execution of PowerShell with encoded commands, specifically when initiated by a 'conhost.exe' process running with the '--headless' flag. The rule further inspects the decoded command to identify patterns indicative of .NET reflection-based code execution, often used in malicious activity such as reflective assembly loading.
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
This rule detects attempts to tamper with the Anti-Malware Scan Interface (AMSI) or suspicious modifications to the memory of common scripting and proxy processes (powershell.exe, pwsh.exe, rundll32.exe, mshta.exe, wscript.exe, cscript.exe). Such activities are often indicative of an adversary attempting to bypass security detection mechanisms to execute malicious code or hide their presence.
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
Detects in-memory tampering of the EtwEventWrite function within ntdll.dll, a technique commonly used by malware and loaders to disable Event Tracing for Windows (ETW) telemetry to avoid detection by security products.
This rule detects the execution of arbitrary commands via the Windows Subsystem for Linux (WSL) by monitoring process creation events where 'wsl.exe' is the executable. It specifically looks for command lines that include flags like '--exec' or '-e', or common shell commands and downloaders such as 'curl', 'wget', 'bash -c', 'sh -c', 'nc ', or 'ncat '. This activity can indicate an adversary leveraging WSL to execute malicious code or bypass security controls.
Detects suspicious activities originating from CrowdStrike Falcon remediation processes (e.g., CSFalconService.exe, CSFalconContainer.exe). The rule identifies two distinct patterns: either a file operation (delete, modify, rename, quarantine, or restore) followed within 2 minutes by the loading of an unsigned or non-standard DLL, or the spawning of an elevated SYSTEM process from a non-SYSTEM parent process. This behavior is indicative of potential LPE (Local Privilege Escalation) abuse via the Falcon remediation engine, often referred to as FalconFlank-style exploitation.
KQL Query from file: repeated-unauthenticated-post-to-elementor-pro-forms-endpoint-cve-2026-32475-pr.kql
Page 322 of 1871

