Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects unauthorized attempts to disable or stop critical Windows Update services (wuauserv, UsoSvc, uhssvc, WaaSMedicSvc) via command line tools or service configuration changes. This behavior is indicative of defense evasion by malware such as Silver Fox/Gh0st RAT, aimed at preventing security updates or disabling security-related service monitoring.
This rule detects PowerShell processes spawned directly or indirectly by LNK files that include command-line arguments indicative of anti-analysis, anti-VM, or reconnaissance techniques. These include querying for specific WMI classes (e.g., Win32_Process, Win32_ComputerSystem), checking for virtualization artifacts (e.g., 'virtualbox', 'vmware', 'qemu', 'sandboxie'), or querying security and hardware information (e.g., 'antivirusproduct', 'securitycenter2', 'getmac').
Detects the use of .NET reflection methods (such as Assembly.Load or LoadFrom) within command-line arguments of processes frequently abused for secondary execution (e.g., rundll32.exe, regsvr32.exe) when initiated by common scripting or execution engines like PowerShell, cmd.exe, or mshta.exe. This pattern is indicative of fileless malware execution or reflective assembly loading commonly used to bypass traditional signature-based detection.
Detects the loading of the 'user32.dll' library into a process named 'firefox.exe' where the process is either unsigned or executing from a suspicious location like 'ProgramData'. This pattern is consistent with the behavior of BabylonRAT, which masquerades as the Firefox browser to perform keylogging by hooking system APIs.
This rule detects instances of a process named 'firefox.exe' that is executing from a directory other than the standard 'Mozilla Firefox' program folders. When this masquerading process loads critical system DLLs like 'kernel32.dll' or 'ntdll.dll', it flags potential dynamic API resolution activity commonly associated with BabylonRAT and similar malware that attempts to hide its capabilities by resolving system functions at runtime.
This rule monitors network connections and DNS queries directed towards Microsoft's OAuth device code authorization endpoints ('/common/oauth2/deviceauth' or '/device'). This flow is frequently abused by adversaries to perform device code phishing, allowing them to gain access to a victim's account without requiring the user's password or bypassing traditional MFA.
Detects the execution of OrionQuests-Setup.exe, a .NET-based executable identified as a malicious installer used by the Kimsuky (APT-C-55/BabyShark) threat group. The rule flags PE files that match the specific filename and contain both .NET framework indicators and references to LNK files, suggesting the dropper mechanism for initial stage infection.
Detects the execution of PowerShell with suspicious command line flags (such as hidden windows, bypass execution policies, or encoded commands) where the parent process is a shortcut (.lnk) file. This is a common technique used by attackers to execute malicious scripts via phishing or social engineering, where a user is tricked into clicking a malicious link file.
Detects the execution of a process named 'firefox.exe' that is running from a path other than the standard Mozilla Firefox installation directory. This is a common technique used by malware to masquerade as a legitimate web browser.
Detects the use of .NET reflection assembly loading techniques (e.g., Assembly.Load, [Reflection.Assembly]::Load) within the command line arguments of known LOLBAS (Living Off the Land Binary and Script) processes. This behavior is frequently associated with fileless malware execution or the loading of malicious assemblies directly into the memory space of trusted Windows binaries.
This rule detects processes named 'firefox.exe' running from locations other than the standard Mozilla Firefox installation directories. This behavior is often indicative of an adversary attempting to masquerade malicious activity by using a legitimate browser process name.
Detects unauthorized write, modification, or rename operations performed on the Windows hosts file (C:\Windows\System32\drivers\etc\hosts) by processes that are not typically authorized for such activity, such as standard system processes (svchost, services, etc.).
Detects the use of .NET reflection assembly loading techniques (e.g., Assembly.Load, [Reflection.Assembly]::Load) within the command line arguments of known LOLBAS (Living Off the Land Binary and Script) processes. This behavior is frequently associated with fileless malware execution or the loading of malicious assemblies directly into the memory space of trusted Windows binaries.
Detects unauthorized processes attempting to access browser credential database files such as Login Data for Chromium-based browsers or logins.json and key4.db for Firefox. The rule filters out known browser processes to isolate potential credential harvesting or exfiltration activity.
This rule detects processes named 'firefox.exe' running from locations other than the standard Mozilla Firefox installation directories. This behavior is often indicative of an adversary attempting to masquerade malicious activity by using a legitimate browser process name.
Detects unauthorized write, modification, or rename operations performed on the Windows hosts file (C:\Windows\System32\drivers\etc\hosts) by processes that are not typically authorized for such activity, such as standard system processes (svchost, services, etc.).
Detects execution, file writing, or network activity associated with the process named 'Stella_Gary', which may indicate the retrieval or use of malicious plugin modules.
Detects the creation or registration of scheduled tasks that masquerade as Google Chrome updates but point to non-standard executable paths. This is a common technique used by malware to establish persistence by mimicking legitimate software update tasks.
This rule detects the execution of 'OrionQuests-Setup.exe' triggered via a shortcut (.lnk) file. It correlates file creation events involving .lnk files with subsequent process creation events for the specified executable to track potential user execution or masquerading attempts.
Detects the execution of PowerShell with common obfuscation or stealth-related flags (e.g., -enc, -nop, -w hidden) when initiated by CMD or from a LNK file, particularly when originating from Windows Explorer. This is a common pattern for malicious file execution and dropper activity.
This rule detects the execution of 'OrionQuests-Setup.exe' triggered via a shortcut (.lnk) file. It correlates file creation events involving .lnk files with subsequent process creation events for the specified executable to track potential user execution or masquerading attempts.
Page 348 of 1870

