Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
60,137 detections
Filters
Last updated
All Time
Detection languages
23,195
16,896
4,280
4,077
3,289
Contributors
11,679
8,664
7,082
6,786
4,478
Categories
20,098
11,459
5,732
4,979
4,798
Platforms
39,719
6,854
6,349
4,078
3,510
Products / Services
10,348
9,600
6,991
4,335
3,859
MITRE Techniques
18,030
15,416
12,645
8,188
6,021
CVEs
68
68
58
56
50
IDS Classtypes
1,896
482
449
381
237
IDS Protocols
2,379
848
406
318
97
Detects instances where a Node.js process spawns another Node.js process to execute a JavaScript file located within the node_modules directory. This pattern is commonly observed when malware or malicious scripts attempt to execute payloads from within project dependencies, potentially hiding malicious activity within seemingly legitimate library paths.
Detects the execution of PowerShell with hidden window style attempting to download Node.js related files (e.g., .msi or node.exe) from nodejs.org using common download cmdlets or utilities.
Detects the launch or execution of common remote access tools such as AnyDesk, TeamViewer, Quick Assist, or Microsoft Remote Assistance (msra.exe) on an endpoint, excluding instances where these tools act as the parent process. This rule serves as one component of a broader detection chain for potentially unauthorized remote access.
This rule detects potentially malicious activity involving Node.js modules. It monitors for the deletion of specific 'sharedLoad.min.js' or 'extended' files within 'node_modules' directories, the execution of Node.js processes attempting file deletion operations (like 'unlink' or 'rm') within 'node_modules', and the creation or modification of JavaScript files within 'node_modules' that contain 'btree' references. This activity may indicate an attempt to tamper with application dependencies, inject malicious code, or remove artifacts.
This rule detects the execution of AnyDesk within a 30-minute window of Microsoft Teams activity on the same device. This pattern is indicative of a vishing attack, where a malicious actor lures a victim into installing remote access software during a fake technical support session initiated via Teams.
Detects high-volume or systematic SharePoint search queries performed by a single user, specifically looking for indicators of data discovery activities such as searching for SharePoint sites, web structures, or iterating through document IDs which may suggest an adversary attempting to map or identify sensitive data within the environment.
This rule detects instances where a Node.js process spawns a child process, also running as node.exe, that attempts to execute a specific JavaScript file path (sharedLoad.min.js or its extended version). This behavior is characteristic of certain Node.js-based applications or potentially malicious scripts using shared loaders for modular execution.
Detects instances where the Node.js process (node.exe) is executed with a command-line argument referencing 'sharedLoad.min.js'. This is often used in web-based applications or potentially malicious obfuscated scripts, but may flag legitimate JavaScript automation tasks.
Detects the execution of the AnyDesk remote support application when initiated from a web browser (msedge.exe) or the Windows file explorer (explorer.exe). This pattern is often indicative of user-driven execution, potentially as part of a tech support scam or unauthorized remote access attempt.
Detects the installation of specific known malicious NPM packages (indexed-btree, btree-core, mutex-forge) or execution of npm install commands targeting these packages, which are indicative of software supply chain compromise attempts.
Detects a Node.js process deleting specific core application files, such as 'index.js' or 'sharedLoad.min.js', located within 'node_modules' directories. This activity may indicate malicious tampering, package integrity compromise, or an adversary attempting to disrupt application functionality.
This rule detects instances where the legitimate remote desktop application AnyDesk (AnyDesk.exe) acts as the parent process to spawn a Windows command shell (cmd.exe) or execute a batch script (.bat). This behavior is often indicative of unauthorized remote access or the execution of malicious payloads by adversaries leveraging remote support tools.
Detects the modification of InProcServer32 registry keys within the user's Classes/CLSID hive to point to a file located in the AppData directory. This pattern is commonly used for COM hijacking to achieve persistence or execute arbitrary code under the user's context.
This rule detects network traffic patterns indicative of Xray-core C2 tunnels using a spoofed 'dl.google.com' TLS SNI value. This activity is associated with the Aur0ra/Black Basta playbook, where Xray-core is sideloaded into legitimate processes to exfiltrate or tunnel traffic while mimicking Chrome browser TLS behavior.
This rule detects network connections or DNS requests to domains specifically structured to impersonate MFA registration, passkey setup, or SSO login pages. These domain patterns are commonly associated with phishing campaigns intended to harvest credentials, session tokens, or bypass multi-factor authentication (AiTM phishing).
Detects the loading of wkspbroker.exe or radcui.dll modules from the Microsoft RemoteApp Gateway directory located within the user's AppData path. This behavior may indicate an attempt to utilize or manipulate Remote Desktop components from a non-standard or user-writable location.
Detects a sequence of events where a user is targeted by an email bombing attack, subsequently receives an external or anonymous Microsoft Teams call, and finally launches a known remote access tool (e.g., AnyDesk, TeamViewer) on the same host within a one-hour window. This pattern is consistent with social engineering campaigns designed to trick users into providing remote access to their systems.
Detects the execution of AnyDesk or its installation from common user-writable directories (Downloads or AppData), as well as scenarios where a browser (msedge.exe) initiates an AnyDesk-related download. This is a common indicator of unauthorized remote access tool deployment.
Detects Node.js process executions that involve loading a suspicious JavaScript file named 'sharedLoad.min.js' or 'extended/sharedLoad.min.js'. The rule further flags instances where the process command line includes 'detached' and 'windowsHide' arguments, which are frequently used to execute Node.js scripts in the background without a visible window.
Detects instances where a Node.js process (node.exe) attempts to execute native system discovery commands such as systeminfo, hostname, or wmic queries. This pattern is commonly observed in malicious Node.js applications or compromised environments attempting to gather system reconnaissance information.
This rule detects network connections or DNS queries made to suspicious domains that utilize MFA or credential-themed keywords (e.g., 'mfa', 'sso', 'passkey', 'register'). These domains are often used in phishing campaigns to impersonate authentication portals and harvest user credentials or MFA tokens.

