Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects PowerShell commands that enumerate system, security, or virtualization-related artifacts. It specifically looks for the usage of WMI and PowerShell cmdlets (e.g., Get-Process, Get-WmiObject) to query for known analysis tools, debuggers, or virtualization software strings, which is a common behavior of malware attempting to identify and evade sandbox or analyst environments.
Detects the creation of scheduled tasks that contain the string 'Google Chrome Update' in the command line, but are not associated with the legitimate GoogleUpdate.exe binary. This is a common technique used by malware to establish persistence by masquerading as a legitimate update process.
This rule searches for any process, image load, or file events containing the string 'Stella_Gary' within file names, folder paths, or process command lines. This is a generic hunting rule typically used to identify artifacts, indicators, or files associated with a specific entity or project codename.
This rule searches for any process, image load, or file events containing the string 'Stella_Gary' within file names, folder paths, or process command lines. This is a generic hunting rule typically used to identify artifacts, indicators, or files associated with a specific entity or project codename.
Detects instances of 'firefox.exe' executing from locations other than the standard Mozilla installation directories, such as AppData, Temp, Downloads, or ProgramData. Additionally, the rule validates if the binary is digitally signed by Mozilla. This behavior is indicative of a masquerading attempt, where an attacker runs a malicious executable disguised as Firefox.
Detects instances of 'firefox.exe' executing from locations other than the standard Mozilla installation directories, such as AppData, Temp, Downloads, or ProgramData. Additionally, the rule validates if the binary is digitally signed by Mozilla. This behavior is indicative of a masquerading attempt, where an attacker runs a malicious executable disguised as Firefox.
Detects the use of PowerShell to reflectively load .NET assemblies into memory, often associated with fileless malware execution. The rule monitors for common reflection-based methods (e.g., Assembly.Load, [System.Reflection.Assembly]) in conjunction with encoded command patterns or script execution.
Detects instances where a process named firefox.exe, executing from the ProgramData directory, is used to establish persistence via Windows Registry Run keys or to create scheduled tasks/services. This behavior is indicative of a malicious process masquerading as the legitimate Firefox browser to maintain persistence on a host.
Detects unauthorized processes attempting to access sensitive web browser files (login data, cookies, configuration) located in Chrome or Firefox profile directories. The detection excludes known browser-related processes and system processes, focusing on third-party or potentially malicious utilities that could be used to harvest credentials stored in these local files.
This rule detects modifications to the Windows hosts file (C:\Windows\System32\drivers\etc\hosts). Adversaries often modify this file to redirect legitimate traffic to malicious IP addresses, a technique commonly used for command and control or phishing campaigns.
Detects instances where a process masquerading as 'firefox.exe' executes common system reconnaissance commands such as systeminfo, ipconfig, whoami, and tasklist from non-standard file paths. This behavior is indicative of the BabylonRAT malware attempting to gather system and network information after establishing persistence.
Detects instances where a process named firefox.exe is running from a non-standard location or includes keywords indicative of keylogging activity such as 'SetWindowsHookEx', 'GetAsyncKeyState', 'GetKeyState', or 'keylog'. This is a common behavioral indicator for the BabylonRAT malware.
Detects execution of the suspicious installer 'OrionQuests-Setup.exe' or the creation of shortcut (.lnk) files associated with this specific executable name. This activity is indicative of potential malicious installer behavior, likely used to distribute malware or drop persistent components.
Detects execution of the suspicious installer 'OrionQuests-Setup.exe' or the creation of shortcut (.lnk) files associated with this specific executable name. This activity is indicative of potential malicious installer behavior, likely used to distribute malware or drop persistent components.
Detects instances of 'firefox.exe' executing from locations other than the standard Mozilla Firefox program directories, a technique used by BabylonRAT and other malware to masquerade as a legitimate browser application.
Detects the creation of a scheduled task named 'Google Chrome Update' using the Windows schtasks.exe utility. The rule flags instances where the task is created from locations other than the legitimate Google Chrome installation directories, identifying potential persistence mechanisms masquerading as a common software update process.
Detects the use of PowerShell's System.Reflection.Assembly Load methods to dynamically load .NET assemblies into process memory from a byte array. This technique is often used by adversaries to execute malicious code directly in memory, bypassing disk-based detection mechanisms.
Detects the execution or loading of modules, processes, or command lines associated with the Stella_Gary C# backdoor framework. This framework is utilized by the Kimsuky (APT-C-55) threat group as part of a modular, plugin-based capability loading architecture.
Detects PowerShell command lines that perform environment validation by enumerating running processes for security software (AV/EDR/Analysis tools) and querying WMI for virtualization artifacts. This behavior is consistent with anti-analysis and anti-sandbox evasion techniques used by threat actors, such as Kimsuky, to identify and verify the execution environment before proceeding with malicious activity.
Detects files that are masquerading as Rich Text Format (RTF) documents but do not contain valid RTF magic bytes and instead contain embedded Portable Executable (PE) headers or DOS stubs. This behavior is indicative of malware delivery via file-type masquerading, often used in spearphishing campaigns by actors such as Kimsuky.
Detects unauthorized modifications to the Windows HOSTS file (C:\Windows\System32\drivers\etc\hosts). Adversaries frequently modify this file to perform DNS hijacking or domain redirection, steering users to malicious infrastructure or bypassing security controls. The rule filters out known legitimate system processes that typically interact with this file.
Page 349 of 1870
