Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
Detects web requests to 'wp-admin/theme-install.php' containing suspicious query parameters that indicate an attempt to force an unauthenticated theme installation via a Cross-Site Request Forgery (CSRF) exploit (Click2Shell). The rule identifies requests with malicious payloads in the 'theme' parameter, specifically looking for indicators that attempt to bypass CSRF protections when originating from an external site or a non-admin session context.
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
This rule detects potential web shell activity by identifying instances where a web server process creates or modifies a PHP file within a 'wp-content/themes' directory, followed closely (within 15 minutes) by that same web server process spawning a shell process (e.g., sh, bash, cmd.exe).
Detects modifications to the 'HKCU\Software\Classes\ms-settings\shell\open\command' registry key, a technique used to hijack the fodhelper.exe binary to achieve silent UAC elevation. This allows attackers to execute commands with administrative privileges without triggering a UAC prompt.
Detects the execution of hidden, base64-encoded PowerShell commands spawned directly from explorer.exe, a pattern observed in the CRPx0 ClickFix campaign where attackers trick users into pasting malicious commands into the Windows Run dialog.
Detects execution of rundll32.exe using ordinal-based export calling syntax to load suspicious DLLs (e.g., sys_<hex>.dll) or reference non-executable files (e.g., WindowsUpdate.log). This behavior is consistent with the CRPx0 Stage 2 stager, which typically exports crypto globals and lacks standard named exports.
Detects host and user discovery commands (whoami, hostname, systeminfo, wmic) executed within a 15-minute window following a suspected CRPx0 ransomware execution event, identified by either encoded PowerShell or curl-to-bash activity.
Detects potential lateral movement activity associated with the CRPx0 propagation technique. The rule monitors for WmiPrvSE.exe spawning unusual child processes (indicative of remote Win32_Process.Create execution) which are concurrently correlated with outbound network activity from the same host.
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
Detects Ruby processes executing with arguments explicitly disabling SSL/TLS verification (OpenSSL::SSL::VERIFY_NONE) while correlating with the presence of suspicious helper scripts ('loader.rb' or 'script.rb') within Ruby gem-related directories. This behavior is indicative of an adversary attempting to perform man-in-the-middle attacks or bypass security controls for outbound C2 communications.
Detects usage of the 'gem' command (install, build, push, publish) that includes naming patterns or specific command strings associated with the GemStuffer supply chain compromise campaign. This targets attempts to introduce malicious dependencies into the environment using RubyGems.
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
This rule detects file creation or modification events within the WordPress plugin directory for 'admin-menu-editor-pro'. Given that WordPress plugins are frequent targets for web shell placement, this rule monitors for unauthorized changes to the plugin's file structure, which may indicate an attempt to gain persistence or remote code execution on the web server.
Detects file-related operations (creation, modification, renaming, or deletion) performed on files containing 'acronis' or 'backup' in their path, executed by a process associated with Acronis, running under highly privileged system contexts (root or SYSTEM). This activity is indicative of potential unauthorized manipulation or disabling of backup software, commonly seen in ransomware attacks to inhibit recovery.
This rule identifies successful network connections from local devices to a predefined list of known malicious IP addresses within the last 7 days. Such connections often indicate active communication between a compromised endpoint and adversary-controlled infrastructure.
Detects potential installation of compromised Admin Menu Editor Pro plugin updates by identifying sequential download events for specific plugin versions from the 'adminmenueditor.com' domain within a 24-hour window. This behavior is indicative of a supply chain attack where a legitimate update mechanism is leveraged to deliver malicious payloads without integrity verification.
Detects successful POST requests to the WordPress admin-ajax.php endpoint utilizing the 'wwlc_file_upload_handler' action with an empty referrer header. This pattern is characteristic of attackers attempting to upload malicious files via vulnerable WordPress plugins to establish web shell persistence.
Page 330 of 1871


