Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,878
6,387
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects periodic, beacon-like network activity targeting public platforms such as Steam community profiles or Telegram (api.telegram.org / t.me) originating from suspicious processes (script interpreters, unsigned binaries). This behavior is characteristic of LummaC2 and similar malware families using public web services as dead-drop resolvers for C2 fallback communication.
Detects instances of potential lateral movement using PsExec or WMI following an alert related to credential compromise, infostealers, or session hijacking, where the same user account is involved in both events.
Detects a single process reading browser cookie SQLite database files across multiple distinct browser profile directories or different web browsers within a short time window. This behavior is indicative of infostealer activity attempting to harvest session cookies for session hijacking and MFA bypass.
Detects a suspected infostealer activity chain involving the unauthorized access of credential and session cookie files, followed by the archival of these files into a temporary or staging directory, and concluding with an outbound network connection to an uncommon destination from the archiving process.
This rule detects potential session hijacking by correlating endpoint-based detections of known infostealer malware (e.g., Vidar, Lumma, Redline) with a subsequent cloud Identity Provider (IdP) login for the same user. The correlation specifically focuses on instances where the IdP authentication originates from an IP address different from the infected host, suggesting the use of stolen session cookies by an external actor to access corporate resources.
Detects the loading of specific commonly side-loaded DLLs (libcef.dll, version.dll, msimg32.dll) from user-writable directories such as Downloads, Temp, or AppData. Attackers often use these locations to drop malicious DLLs alongside legitimate applications to achieve DLL side-loading for persistence or defense evasion.
Detects unauthorized non-browser processes attempting to access Chrome browser master keys or bypass App-Bound Encryption by interacting with the Chrome IElevator service, DPAPI routines, or the 'Local State' configuration file. This behavior is indicative of infostealer activity aiming to decrypt browser-stored session cookies and credentials.
Detects unauthorized processes attempting to read sensitive session files or databases associated with messaging applications like Telegram, Signal, and Discord. Accessing these files (such as 'tdata', 'db.sqlite', or 'leveldb') allows for full account takeover by extracting session tokens, enabling attackers to bypass authentication and 2FA.
Detects non-CLI and non-DevOps utility processes accessing sensitive cloud credential and configuration files, including AWS SSO caches, AWS credentials, kubeconfig, and gcloud configuration files. This behavior is indicative of credential theft or discovery by infostealers attempting to gain unauthorized access to cloud environments.
Detects unauthorized access to DPAPI master key files located in the Windows user profile (%APPDATA%\Microsoft\Protect\). This activity is commonly associated with infostealers attempting to decrypt browser-stored credentials (cookies, passwords) by manually accessing the master key files after exfiltrating encrypted data stores.
Detects DNS resolution attempts for newly registered or suspicious top-level domains (e.g., .xyz, .top, .live) that mimic corporate Identity Provider (IdP) or Single Sign-On (SSO) login portals. This behavior is characteristic of Adversary-in-the-Middle (AiTM) phishing kits like EvilProxy or Tycoon2FA, intended to capture user session tokens. Note: This rule monitors for initial domain contact and should be correlated with subsequent authentication logs to identify potential session hijacking.
Detects unauthorized access to common browser credential storage files (Login Data, Cookies, Web Data, Local State) by processes other than standard web browsers. This rule identifies potentially malicious activity by filtering for rare or unsigned binaries executing from common staging directories (Temp, Downloads) or accessing browser files shortly after the process launch, which is a common behavior pattern for info-stealer malware.
This rule correlates endpoint security alerts for popular information-stealer malware (Lumma, StealC, Vidar, RedLine, Acreed, Atomic Stealer) with subsequent successful cloud identity authentication events from the same user account. The correlation window is set to 72 hours following an endpoint infostealer detection, which suggests potential account takeover or unauthorized access facilitated by credentials stolen from a compromised endpoint.
Detects the startup or configuration of the WebClient service, commonly associated with WebDAV redirection, followed within 15 minutes by a process (e.g., control.exe, rundll32.exe, svchost.exe) interacting with a WebDAV-style UNC path. This behavioral pattern is indicative of attackers, such as the Star Blizzard group, abusing built-in Windows functionality to facilitate credential theft or remote file execution via malicious WebDAV shares.
Detects a multi-stage exfiltration sequence consisting of: (1) bulk file archival/compression using common utilities, (2) suspicious OAuth grant or service principal authorization, and (3) abnormal network egress volume to common ports. This pattern suggests an adversary is preparing data, establishing or leveraging an identity/application for cloud access, and subsequently exfiltrating data.
Detects the LEMURLOOT ASP.NET web shell deployed by Cl0p following exploitation of CVE-2023-34362 in MOVEit Transfer
Detects the first-ever observed network connection from a device to WhatsApp Web or Telegram Web within a 30-day lookback period. This behavior is used to identify potentially unauthorized companion-device linking to a user's messenger account, which could indicate credential theft or unauthorized access.
Detects the creation of a new Windows service where the service executable is located in potentially suspicious directories such as \Temp\, \Users\Public\, \AppData\, or \ProgramData\. Attackers often use these locations to drop and execute malicious payloads or persistence mechanisms while bypassing standard software installation security controls.
Detects endpoint, process, and network activity associated with the 'TaskStomp' threat actor, specifically targeting known malicious file hashes, command-and-control domains, and specific URLs used in their campaigns.
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
Detects malicious activity associated with the ClickFix/Vidar campaign, where adversaries create persistence using the Windows Run registry key while masquerading as the legitimate 'VoidTools Everything.exe' utility. The rule correlates registry modifications with the creation or execution of a file path mimicking the legitimate software in suspicious locations.
Page 34 of 1866



