Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,273 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,525
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,767
9,473
3,749
3,682
3,674
Platforms
39,273
6,901
6,444
3,782
3,524
Products / Services
10,164
9,427
6,496
1,858
1,707
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
This rule monitors for execution of files with specific SHA256 hashes known to be malicious, and network connections to a known malicious domain associated with Vultr storage. It aggregates file creation, process execution, and network connection events to detect potential threat activity.
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
This rule detects file creation or modification events occurring within the 'ProgramData\ZlibDate' directory. This specific path and the associated file extensions (.Dat and .zip) are frequently associated with data staging activities or unauthorized file management by malicious software attempting to persist or exfiltrate data under the guise of legitimate application data.
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
This rule detects the creation of files in directory paths that look similar to the legitimate 'C:\Windows\SysWOW64' folder but contain a hidden trailing space (e.g., 'C:\Windows \SysWOW64'). Attackers use this directory spoofing technique to hide malicious files or executables from users and some security tools that might not normalize the path correctly.
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
This rule detects the execution of a process named 'WhatssApp.exe' from a non-standard location ('C:\ProgramData\Drivers\Whatsapp\'), which is indicative of masquerading. It further correlates this activity with the prior termination of the legitimate 'whatsapp.exe' process within a 30-minute window, a pattern often associated with 'WhatsappCheker' or similar malicious tools designed to hijack legitimate application sessions.
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
This rule detects potentially malicious activity by monitoring the execution of Python interpreters or specific suspicious executable names from within the C:\ProgramData directory. The detection logic focuses on processes launching from directories associated with configuration or data storage folders, often used by malware for staging or execution to avoid detection. It specifically flags Python execution involving certain suspicious file or argument strings, and the launch of named executables (e.g., RuntimeSSH.exe, smqdservice.exe) located in specific ProgramData subdirectories.
This rule detects potentially malicious activity by monitoring the execution of Python interpreters or specific suspicious executable names from within the C:\ProgramData directory. The detection logic focuses on processes launching from directories associated with configuration or data storage folders, often used by malware for staging or execution to avoid detection. It specifically flags Python execution involving certain suspicious file or argument strings, and the launch of named executables (e.g., RuntimeSSH.exe, smqdservice.exe) located in specific ProgramData subdirectories.
This rule detects potentially malicious activity by monitoring the execution of Python interpreters or specific suspicious executable names from within the C:\ProgramData directory. The detection logic focuses on processes launching from directories associated with configuration or data storage folders, often used by malware for staging or execution to avoid detection. It specifically flags Python execution involving certain suspicious file or argument strings, and the launch of named executables (e.g., RuntimeSSH.exe, smqdservice.exe) located in specific ProgramData subdirectories.
Page 333 of 1871
