Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects activity associated with the 'MovieReaper' threat campaign by identifying known malicious file hashes, command and control (C2) IP addresses, and communication with identified malicious domains. This rule monitors process execution, file operations, and network connections within the campaign's active timeframe.
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
Detects instances where the 'msedge.exe' binary is executed from the non-standard path 'C:\ProgramData\Microsoft\Windows\Telemetry\', excluding instances initiated by the legitimate Microsoft Edge Update process. This pattern often indicates masquerading, where an adversary places a malicious file with a legitimate name in an attempt to evade detection.
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
Detects the invocation of the undocumented ntdll function 'EtwpCreateEtwThread', which is used as an alternative to standard thread-creation APIs like CreateThread or CreateRemoteThread. This technique is often associated with advanced shellcode execution, such as MovieReaper, designed to evade common thread-creation monitoring sensors.
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
Detects evidence of the MovieReaper loader technique. This behavior involves registering or rewriting Vectored Exception Handlers, allocating memory with EXECUTE_READWRITE protection, and triggering debug-break exceptions to redirect execution into raw NtProtectVirtualMemory syscalls, effectively bypassing user-mode API hooks often used for monitoring.
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
Detects execution artifacts of the MovieReaper stage 2 implant, specifically its capability to parse and load COFF modules into memory without writing them to disk. The rule monitors process command lines for 'module_init' and identifies suspicious API activity related to memory-based module loading, such as reflective DLL loading or remote thread creation.
Detects PowerShell command execution that uses bitwise XOR operations combined with the .NET [IO.File]::WriteAllBytes method. This pattern is commonly used by malware, such as AsyncRAT, to deobfuscate and drop secondary payloads or modules onto the file system during execution.
This rule detects potential persistence mechanisms where a suspicious batch file (.bat) is placed within the Windows Startup folder and subsequently executed using command-line arguments that include specific file extensions like .exe and .ini. This behavior is indicative of malware, such as remote access trojans (RATs), attempting to maintain persistence upon system reboot.
Detects suspicious service installation patterns involving WmiPrvSE, common in lateral movement techniques.
Detects a network connection to potentially malicious infrastructure or non-standard ports following a request to ipify.org, which is commonly used for external IP reconnaissance by malware and C2 frameworks.
Page 345 of 1870


