Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the execution of COM files located in the AppData\Local directory with a numeric filename and specific command-line arguments indicative of file transfer or proxying tools like curl/wget wrappers.
Detects indicators of the 'ShieldCrash' proof-of-concept (CVE-2026-69414 exploit bypass) on Windows systems. The rule monitors for specific malicious file activity, module loading, and the presence of decoy archive files associated with the PoC, which are used to achieve arbitrary file read as SYSTEM.
This rule detects processes manually resolving API function addresses by traversing the Process Environment Block (PEB) Ldr structure or parsing module export tables. This technique is often used by malicious code to resolve Windows API functions dynamically without relying on standard LoadLibrary or GetProcAddress calls, effectively evading common API-hooking based monitoring.
Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.
Detects rapid, non-interactive ransomware-like behavior characterized by system reconnaissance followed by automated bulk file deletion of model/data files (e.g., .ckpt, .pt). The rule identifies campaigns where discovery, lateral movement or automated execution, and destructive impact occur within a 3-hour window without any interactive user login evidence.
Detects processes registering a Vectored Exception Handler (VEH) while simultaneously performing memory write operations and thread context modifications. This behavior is highly indicative of advanced process injection techniques, such as using VEH as a redirection mechanism to execute raw syscalls or malicious shellcode within a target process.
Detects indicators of the MovieReaper loader, specifically the downloading of shellcode fragments disguised as image assets from known malicious C2 infrastructure, and the masquerading of a malicious binary as 'msedge.exe' within the Windows Telemetry folder for persistence. The rule specifically targets the loader's behavior of using PEB Ldr traversal to resolve APIs and evade hooking-based security controls.
Detects artifacts associated with the CRUDEEXCLUDE Delphi-based loader, which is used to deploy the HEAVYGRAM backdoor. The rule identifies a combination of Delphi indicators, anti-analysis sandbox connectivity checks, decoy message boxes, and attempts to modify Windows Defender exclusions for specific paths associated with the malware's activity.
Detects the HEAVYGRAM malware utilizing the Telegram Bot API to download file attachments, followed by the extraction of an archive using PowerShell to a masqueraded directory (C:\ProgramData\Kee_Pass), and the subsequent execution of a binary masquerading as KeePass.exe.
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
Detects modifications or creation of the VS Code 'settings.json' file within a '.vscode' folder where the configuration includes 'workbench.startupEditor' and 'readme'. This pattern is frequently used in malicious extensions or malicious repository configurations to trick users into opening a malicious README file upon starting the editor, potentially leading to further compromise.
Detects the installation of Visual Studio Code extensions via the command line interface using the Code.exe process. Adversaries may abuse VS Code extensions to achieve code execution or persistence by installing malicious .vsix files.
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
Page 342 of 1870


