Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of Windows Run registry keys by a process named 'firefox.exe' that originates from a non-standard file path. This behavior is indicative of BabylonRAT attempting to establish persistence by masquerading as the Mozilla Firefox browser.
Detects the presence of the modular C# backdoor framework known as Stella_Gary, used by the Kimsuky (APT-C-55) threat group. The rule identifies specific namespace and class strings associated with the framework within .NET executable files.
Detects Windows PE files exhibiting characteristics of BabylonRAT, specifically the use of dynamic API resolution via GetProcAddress and LoadLibrary to hide imports, combined with XOR-obfuscated strings for sensitive functions like CreateProcess, WriteFile, and InternetOpen to evade static analysis.
Detects the execution of 'OrionQuests-Setup.exe' followed by the creation of a shortcut (.lnk) file by the same process. This activity is a known indicator of the Kimsuky (APT-C-55) Stella_Gary infection chain, where a disguised installer drops malicious shortcuts to facilitate further execution.
Detects the creation of a Windows scheduled task named 'Google Chrome Update' where the command-line action does not point to the legitimate GoogleUpdate.exe binary. This behavior is indicative of persistence mechanisms used by threat actors, notably the Kimsuky group, to masquerade malicious tasks as legitimate software updaters.
Detects the execution of a process named 'firefox.exe' from a directory other than the standard Mozilla Firefox installation path ('C:\Program Files\Mozilla Firefox' or 'C:\Program Files (x86)\Mozilla Firefox'). This behavior is commonly associated with the BabylonRAT malware, which masquerades as the legitimate Firefox browser to hide its presence and facilitate initial infection.
Detects the execution of a process named 'firefox.exe' from a directory other than the standard Mozilla Firefox installation path ('C:\Program Files\Mozilla Firefox' or 'C:\Program Files (x86)\Mozilla Firefox'). This behavior is commonly associated with the BabylonRAT malware, which masquerades as the legitimate Firefox browser to hide its presence and facilitate initial infection.
Detects modification of the Windows HOSTS file (C:\Windows\System32\drivers\etc\hosts), which is a common technique used by malware to redirect network traffic, block access to security updates, or facilitate command and control communication.
Detects persistence mechanisms associated with BabylonRAT that utilize Windows Registry Run or RunOnce keys. The rule specifically identifies instances where a file named 'firefox.exe' is executed from the 'ProgramData' directory, which is a common indicator of a masqueraded malicious binary attempting to achieve persistence.
Detects instances where a non-browser process attempts to read sensitive credential store files (e.g., 'Login Data', 'logins.json', 'key4.db') belonging to Google Chrome or Mozilla Firefox. This activity is indicative of credential harvesting often performed by malware.
Detects PowerShell scripts attempting to identify security software, virtualization environments, or sandbox analysis tools. The rule monitors for the enumeration of security processes, WMI queries for system hardware information (e.g., BIOS, Disk, Video Controller), and checks for registry keys or driver files associated with virtualization software (e.g., VMware, VirtualBox). This behavior is commonly observed in malware attempting to evade automated analysis.
Detects the reflective loading of .NET assemblies into memory using APIs like Assembly.Load or Reflection.Emit, where no corresponding DLL file is written to the disk. This technique is often used by malware (such as the Stella_Gary backdoor) to execute code in a fileless manner and evade disk-based security detections.
This rule detects files that feature a valid RTF file header (literal '{' followed by 'rtf1') at the start of the file, but lack standard RTF control words such as \ansi or \fonttbl. The presence of executable content, PowerShell commands, or script markers within these files indicates a file-type masquerading technique used to bypass security controls by disguising malicious payloads as RTF documents.
This rule detects the presence of the unsigned 'OrionQuests-Setup.exe' file, which is a deceptive .NET installer associated with the Kimsuky (APT-C-55) threat actor, used to distribute the Stella_Gary backdoor. The rule looks for specific strings associated with .NET binaries and shortcut (LNK) file interaction, while excluding signed executables to reduce noise.
This rule detects the creation of scheduled tasks that attempt to masquerade as legitimate Google Chrome Update tasks. It flags tasks that use the 'Google Chrome Update' name but do not follow the standard naming convention (which typically includes 'GoogleUpdateTaskMachine') or tasks that initiate suspicious actions using scripting engines (like PowerShell, cmd.exe, mshta, etc.) rather than the signed Google update binary.
Detects the execution or creation of files masquerading as Mozilla Firefox components (e.g., firefox.exe) located within non-standard, suspicious directories under 'ProgramData'. The rule further refines these alerts by identifying instances where the file lacks a valid Mozilla digital signature or contains an incorrect company name in its metadata.
This rule detects PowerShell commands or script blocks that enumerate running processes and query WMI/CIM classes (such as Win32_ComputerSystem or Win32_BIOS) to identify indicators of virtualization, sandboxing, or the presence of security analysis tools. This behavior is indicative of anti-analysis and sandbox-evasion techniques, commonly used by threat actors like Kimsuky to verify their execution environment before proceeding with malicious activity.
Detects instances where a process named firefox.exe attempts to establish persistence via Windows Registry Run keys or Windows Task Scheduler while operating outside of standard Mozilla Firefox installation directories. This behavior is indicative of masquerading techniques used by threats such as BabylonRAT to maintain persistence under the guise of a common web browser.
Detects unauthorized access to sensitive browser credential files (e.g., Chrome 'Login Data', Firefox 'logins.json' and 'key4.db') by processes other than legitimate browser executables. This behavior is indicative of credential harvesting attacks, such as those performed by BabylonRAT.
Detects instances where a process masquerading as Firefox (executing outside of legitimate program directories) attempts to modify the Windows 'hosts' file. This behavior is indicative of BabylonRAT or similar malware attempting to redirect network traffic to malicious domains by tampering with local DNS resolution.
Detects instances where a process masquerading as Firefox (executing outside of legitimate program directories) attempts to modify the Windows 'hosts' file. This behavior is indicative of BabylonRAT or similar malware attempting to redirect network traffic to malicious domains by tampering with local DNS resolution.
Page 350 of 1870
