Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects remote command execution using WMI by monitoring RPC calls to the IWbemServices interface (UUID {9556DC99-828C-11CF-A37E-00AA003240C7}). The rule specifically targets the ExecMethod operation (opnum 24) commonly used by tools like Impacket's wmiexec to execute Win32_Process.Create on remote targets. Filter for COMSPEC to increase fidelity for detecting wmiexec.
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
Detects the loading of the Alinubx.sys (aka CcProtect.sys) kernel driver, often dropped as nvfsflt64.sys or registered as NvFsFilter, followed by a rapid, simultaneous termination of security product processes. This activity is indicative of a BYOVD (Bring Your Own Vulnerable Driver) attack chain where kernel-mode primitives are used to terminate EDR/AV processes.
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
Detects the creation of executable or script files within non-system directories that were initiated by the OneDrive sync process. This activity may indicate a user downloading malicious files via a compromised OneDrive account or a malicious payload being synced to the local system.
Detects suspicious modifications to browser 'Secure Preferences' files associated with known bypass techniques for extension integrity checks, coupled with browser process termination and subsequent relaunch using the --restore-last-session flag. This pattern is consistent with adversary activity attempting to inject malicious browser extensions by manipulating browser configuration files.
Detects anomalous child processes spawned by a Chrome renderer process. This behavior is often indicative of exploitation attempts, such as the BlueMoon exploit kit leveraging CVE-2026-85046, where a compromised renderer attempts to escape the sandbox or execute arbitrary code in the host process.
Detects anomalous child processes spawned by a Chrome renderer process. This behavior is often indicative of exploitation attempts, such as the BlueMoon exploit kit leveraging CVE-2026-85046, where a compromised renderer attempts to escape the sandbox or execute arbitrary code in the host process.
Detects the execution of REAgentC.exe with the /disable command-line argument. This utility is used to manage the Windows Recovery Environment (WinRE). Adversaries often disable WinRE to prevent system recovery and impede incident response, often as a prelude to data destruction or ransomware attacks.
Detects the frequent clearing of specific Windows Event Logs using the built-in wevtutil.exe utility. Attackers often clear logs to hide evidence of post-exploitation activity such as credential access, lateral movement, or persistence installation.
Detects instances where PowerShell or PowerShell ISE performs suspicious process injection activities, specifically targeting executables such as csc.exe, chrome.exe, msedge.exe, or SearchIndexer.exe, or utilizes specific remote thread/memory allocation functions.
Detects PowerShell command lines that attempt to hide the console window by calling ShowWindowAsync from user32.dll while assigning a randomly generated GUID as the window title. This technique is used to evade detection by keeping malicious PowerShell activity invisible to the user, as seen in recent StealC infostealer loader chains.
Detects host-based activity or network communication associated with the SloppyRAT remote access trojan. The rule monitors for specific malicious file hashes and connection attempts to known C2 IP addresses and domains.
Detects the execution of the Windows Event Utility (wevtutil.exe) with the 'cl' (clear-log) command, specifically targeting multiple critical event logs simultaneously. This behavior is indicative of anti-forensic activity aimed at obfuscating post-compromise actions, as seen in the Settra ransomware campaign.
Detects Git checkout operations executed by AI coding agent processes that specify a full 40-character commit hash or use 'FETCH_HEAD'. This behavior is indicative of potential supply chain attacks, specifically the 'Plugin4Shell' vulnerability, where malicious actors attempt to force the agent to checkout arbitrary, potentially malicious, repository references.
Detects the use of the 'wevtutil.exe' command to clear Windows Event Logs where the command specifies a misspelled event log name, 'Microsoft-Windows-Defender/Operational' instead of the correct 'Microsoft-Windows-Windows-Defender/Operational'. This specific spelling error is associated with the Settra ransomware and indicates an unsuccessful attempt to clear Windows Defender logs.
Detects Git commands initiated by AI coding agent processes that perform a checkout of a specific 40-character SHA hash or a FETCH_HEAD reference. This behavior is potentially indicative of a supply chain attack where an AI plugin agent is being instructed to swap code components or load specific, potentially malicious, commit versions from a remote repository.
Detects .NET malicious payloads associated with the StealC info-stealer by identifying anti-debugging and anti-analysis routines. The rule specifically looks for the usage of System.Diagnostics.Debugger methods (IsAttached, IsLogging), native debugger presence checks (IsDebuggerPresent, CheckRemoteDebuggerPresent), and Environment.FailFast usage, often in combination with obfuscation markers like ConfuserEx.
Detects .NET malicious payloads associated with the StealC info-stealer by identifying anti-debugging and anti-analysis routines. The rule specifically looks for the usage of System.Diagnostics.Debugger methods (IsAttached, IsLogging), native debugger presence checks (IsDebuggerPresent, CheckRemoteDebuggerPresent), and Environment.FailFast usage, often in combination with obfuscation markers like ConfuserEx.
Detects the creation of a specifically named shortcut (.lnk) file in the Windows Startup directory, a common persistence mechanism used by StealC/ClickFix malware variants.
Page 335 of 1871




