Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects execution or file presence associated with HOOKEDGE/HEADLACE malware. This rule uses a dual-approach: matching known malicious file hashes (SHA256) and monitoring for specific script files (bat, vbs, cmd) following a GUID-formatted naming convention typically used by the HOOKEDGE installer chain.
This rule detects the creation of a scheduled task via schtasks.exe that uses a name similar to 'Google Chrome Update' but is initiated by a process other than the legitimate Google Update executable or from an unexpected folder location. This behavior is commonly used by adversaries to establish persistence while masquerading as legitimate software update mechanisms.
Detects the Kimsuky trojanized .NET installer OrionQuests-Setup.exe that decrypts embedded AES resource OrionSetup.payload.enc to drop a decoy OrionLauncher installer and malicious LNK file
Detects known malicious files associated with Kimsuky (APT-C-55) Stella_Gary attack chain by MD5 hash: OrionQuests-Setup.exe installer, guide.url.lnk, test.bef_fri, and backdoor payload component
This rule detects a correlation between host-level reconnaissance activity using WMI (via PowerShell or WMIC) to query system information, followed by network exfiltration to a known C2 IP address over a specific URI within a 10-minute window.
Detects repeated, non-interactive requests to the Google Sheets Visualization API (gviz/tq) originating from common web browsers. This pattern is indicative of a malicious browser extension attempting to reconstruct or reinject payloads when a user visits specific targeted websites.
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
Detects network connections initiated by common web browsers to a specific LinodeObjects domain or any subdomains within the linodeobjects.com infrastructure, which may indicate command and control communication or data exfiltration via legitimate cloud storage providers.
Detects user account logins following a recent MFA registration (within 1 to 30 days) combined with subsequent network activity that utilizes node.js applications to query the Microsoft Graph API, which may indicate account takeover or malicious persistence setup.
This rule detects successful user authentication events within the environment. It acts as a base filter to capture login success, which can be further refined with context such as IP addresses or usernames to monitor for anomalous login patterns, though it does not inherently provide detection of complex attacks like session token hijacking on its own.
Detects a successful authentication event where standard endpoint identification metadata (endpoint name and IP address) is absent. This often indicates logs originating from sources without proper endpoint telemetry integration or potential attempts to obfuscate the source of an authentication request.
Detects high-volume outbound network traffic (exceeding 100MB) generated by processes identifying as 'python-httpx' to non-internal IP addresses. This activity is often associated with automated data exfiltration using Python-based tools.
This rule monitors DNS requests and network connections for activity targeting domains identified as malicious: 'gg-steelseries.com.cn' and 'org-bcut.com.cn'. These domains are often associated with command and control infrastructure or malware distribution, and their presence in network logs is a high-fidelity indicator of a potential compromise.
Detects executable file downloads initiated by common web browsers where the associated Zone.Identifier (Mark-of-the-Web) file lacks a ReferrerUrl. This pattern is often used by malware to conceal the source of a payload, potentially indicating a direct download or a hidden link redirection that bypassed standard referral tracking.
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
This rule detects the creation of a scheduled task intended to run an executable named 'wsc_updata.exe' from a temporary directory, or identifies svchost.exe initiating a process from that location. Such behavior is indicative of potential persistence mechanisms where malicious actors attempt to run code from unauthorized or writable directories under the context of system processes or scheduled tasks.
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
This rule detects instances where a process named 'wsc_updata.exe' executing from a Temp directory loads a library named 'wsc.dll'. This behavior is characteristic of DLL side-loading or DLL hijacking, where a malicious or potentially unwanted executable attempts to load a library from a user-writable directory to execute arbitrary code.
Detects execution of a specific suspicious executable file masquerading in the Windows Temp directory, coupled with the access of an associated .ini configuration file. This behavior is indicative of AsyncRAT deployment, often involving initial execution or staging of configuration files within volatile user directories.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Page 344 of 1870



