Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects anomalous child processes spawned by a Chrome renderer process. This behavior is often indicative of exploitation attempts, such as the BlueMoon exploit kit leveraging CVE-2026-85046, where a compromised renderer attempts to escape the sandbox or execute arbitrary code in the host process.
Detects the execution of 'bun' during a Node.js package installation process (npm or node). This behavior can be indicative of a supply chain attack where malicious actors attempt to leverage alternative runtimes during the 'preinstall' phase or package installation to execute arbitrary code or bypass security controls typically associated with standard Node.js installations.
Detects the execution of 'bun' during a Node.js package installation process (npm or node). This behavior can be indicative of a supply chain attack where malicious actors attempt to leverage alternative runtimes during the 'preinstall' phase or package installation to execute arbitrary code or bypass security controls typically associated with standard Node.js installations.
Detects the execution of 'bun' during a Node.js package installation process (npm or node). This behavior can be indicative of a supply chain attack where malicious actors attempt to leverage alternative runtimes during the 'preinstall' phase or package installation to execute arbitrary code or bypass security controls typically associated with standard Node.js installations.
This rule detects potential attempts to tamper with or bypass Windows Defender by monitoring for files or processes named 'ShieldCrash' occurring in close temporal proximity to the creation or modification of files within Windows Defender's shadow or scan directories (BaseNamedObjects\Restricted\WD_SHADOW_ or WD_SCAN). This behavior is often associated with malware attempting to evade security detection.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects a sequence of events where a user visits a Cloudflare Pages URL (*.pages.dev) and shortly after, a suspicious command (mshta, powershell, or curl) is executed. This pattern is consistent with the UNC5142 threat actor's TTP of using social engineering lures hosted on Cloudflare Pages to trick users into running malicious commands.
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.
This rule detects potentially malicious memory manipulation and thread execution activity originating from the ERAAgent.exe process. It specifically identifies when ERAAgent.exe calls VirtualProtect or VirtualAlloc to set memory as PAGE_EXECUTE_READWRITE, followed shortly by a CreateThread or CreateRemoteThread operation. This behavior is indicative of process injection or reflective code loading, where an executable image is manually mapped into memory and executed, bypassing traditional file-based detection.
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) modifies registry keys related to Windows network security settings, such as LSA policies, NullSession pipes/shares, or server/workstation auto-sharing. These settings can be manipulated to weaken Windows security posture, potentially facilitating lateral movement or credential access.
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
This rule monitors for the connection of specific KVM-over-IP hardware devices (e.g., PiKVM, Guermok) which can be used by an adversary to gain remote access to a system's physical keyboard, video, and mouse interface, effectively bypassing software-based security controls.
Detects instances where the SQL Server process (sqlservr.exe) initiates a child process that is a known command-line tool, script interpreter, or utility often used in living-off-the-land attacks, or when a child process is spawned from suspicious directory paths such as AppData, Temp, or Windows\Temp.
This rule monitors web server logs (IIS, W3C, and Azure Application Gateway) for incoming traffic that matches known malicious or automated vulnerability scanners, as well as requests for common system fingerprinting paths (such as /server-status or /.git/config). The rule aggregates these hits by source IP address to identify potential active reconnaissance or vulnerability scanning attempts.
This rule monitors for email events where the email is flagged for suspicious properties (SPF/DKIM/DMARC failure, threat categorization) and includes potentially malicious attachments or URLs. It then correlates these suspicious emails with subsequent process execution events on the recipient's endpoint within a 30-minute window, identifying a potential successful execution of a phishing payload.
This rule monitors for web server exploit attempts (indicated by patterns like JNDI lookups or SQL injection sequences in URI/cookie data) that correlate with a surge in server-side errors (400+ status codes) and subsequent anomalous process creation or outbound network connections from the web server process.
Page 355 of 1870
