Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,272 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,524
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,766
9,472
3,749
3,682
3,674
Platforms
39,272
6,901
6,444
3,782
3,524
Products / Services
10,164
9,426
6,495
1,858
1,706
MITRE Techniques
13,653
12,961
7,909
5,844
4,367
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the HEAVYGRAM malware utilizing the Telegram Bot API to download file attachments, followed by the extraction of an archive using PowerShell to a masqueraded directory (C:\ProgramData\Kee_Pass), and the subsequent execution of a binary masquerading as KeePass.exe.
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
Detects instances where a Visual Studio Code (VS Code) extension host process launches potentially suspicious child processes, specifically command-line tools like cmd.exe, powershell.exe, or calc.exe, within 30 seconds of the extension host starting.
This rule detects the use of the VS Code command line interface to install extensions, specifically by monitoring for the 'workbench.extensions.installExtension' command. This activity can be indicative of automated installation of extensions, which could be used for malicious purposes or persistence if an attacker installs a malicious extension.
This rule detects potentially malicious activity originating from code editors (VS Code, Electron-based applications) spawning suspicious child processes (cmd.exe, powershell.exe, calc.exe) or the creation of a specific suspicious file 'EXTINSTALL_PWNED.txt' in the 'Users\Public' directory.
Detects modifications or creation of the VS Code 'settings.json' file within a '.vscode' folder where the configuration includes 'workbench.startupEditor' and 'readme'. This pattern is frequently used in malicious extensions or malicious repository configurations to trick users into opening a malicious README file upon starting the editor, potentially leading to further compromise.
Detects the installation of Visual Studio Code extensions via the command line interface using the Code.exe process. Adversaries may abuse VS Code extensions to achieve code execution or persistence by installing malicious .vsix files.
Detects unauthorized attempts to dump the process memory of the Local Security Authority Subsystem Service (LSASS), a common technique used by attackers to harvest credentials from memory. This includes the use of legitimate diagnostic tools like procdump and comsvcs.dll, as well as the identification of resulting dump files in directory paths associated with LSASS.
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
This rule detects suspicious command executions (e.g., whoami, downloadstring, iex, registry modifications) initiated by processes associated with the CrowdStrike Falcon agent. It also correlates these executions with the loading of unsigned or unverifiable DLLs by the same Falcon processes within a 5-minute window, which may indicate attempts to tamper with or masquerade as the security agent.
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
IOC hunt for the HEAVYGRAM/CRUDEEXCLUDE campaign: matches known SHA256 file hashes (first-stage malware, implant, RAR/ZIP artefacts) via DeviceFileEvents and DeviceProcessEvents, plus known-malicious domains/staging infrastructure by parsed hostname across network connections, process command lines, and file origin URLs.
IOC hunt for the HEAVYGRAM/CRUDEEXCLUDE campaign: matches known SHA256 file hashes (first-stage malware, implant, RAR/ZIP artefacts) via DeviceFileEvents and DeviceProcessEvents, plus known-malicious domains/staging infrastructure by parsed hostname across network connections, process command lines, and file origin URLs.
Detects HEAVYGRAM/CRUDEEXCLUDE persistence via Run-key registry writes or reg.exe command-line adds, scoped to payloads staged in AppData/ProgramData/Temp/Public/Downloads and excluding legitimate Program Files/System32 targets to reduce false positives from normal software autorun entries.
Page 343 of 1871


