Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects potential exploitation of a CrowdStrike Falcon remediation process vulnerability ('FalconFlank'). The rule identifies either direct execution of the PoC binary or the suspicious combination of a CrowdStrike remediation process loading an unsigned or untrusted DLL from a user-writable path followed by the same process spawning a command shell in the SYSTEM context within 15 minutes.
This rule detects suspicious command executions (e.g., whoami, downloadstring, iex, registry modifications) initiated by processes associated with the CrowdStrike Falcon agent. It also correlates these executions with the loading of unsigned or unverifiable DLLs by the same Falcon processes within a 5-minute window, which may indicate attempts to tamper with or masquerade as the security agent.
Detects the loading of registry hives using the 'reg load' command. This technique is often associated with adversary attempts to manipulate the Windows registry, access sensitive data, or establish persistence, particularly when followed by actions executed in the SYSTEM context from the same process lineage.
Detects rapid, repeated invocation of Microsoft Defender remediation processes (mpcmdrun.exe, MsMpEng.exe) occurring in conjunction with suspicious file write or rename operations in System32. This pattern is characteristic of a Time-of-Check to Time-of-Use (TOCTOU) race condition, where an attacker attempts to exploit the timing gap between Defender's detection and remediation actions to replace a file with a malicious version.
This rule detects unauthorized attempts to modify CrowdStrike Falcon sensor exclusion registry keys or commands involving DLL loading techniques that may indicate evasion preparation, specifically referencing potential FalconFlank-related activities. It filters out legitimate management activity from known service accounts, SCCM, and the CrowdStrike Falcon agent itself.
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
This rule detects the execution of processes or network connections that impersonate 'WhatsApp' or 'Instagram' companion applications. It identifies specific file names and process command lines that mimic these applications, often associated with browser-launched or malicious payloads, and monitors for associated network traffic directed toward suspicious endpoints like herokuapp domains.
This rule monitors the software inventory for outdated versions of the PostgreSQL database server. It identifies installations where the major and minor versions are below the threshold for current security releases (e.g., v18 < 6, v17 < 11, v16 < 15, v15 < 19, v14 < 24). Running outdated software increases the risk of exploitation of known vulnerabilities.
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
Detects when the Postgres service process or account attempts to modify system-level persistence mechanisms, such as scheduled tasks (cron/schtasks) or system services (systemd/startup folders), which are typical behaviors for an adversary using database service context to maintain persistence.
Detects instances where common web server applications (e.g., Apache, Tomcat, IIS, Nginx) or Java runtime environments spawn suspicious child processes like command shells (cmd.exe, powershell.exe, sh, bash) or network utilities (wget, curl). This behavior often indicates exploitation of a web vulnerability, such as Remote Code Execution (RCE), allowing an adversary to execute commands or download further malicious payloads.
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
This rule detects potential bulk data exfiltration by monitoring for high volumes of file access events (FileAccessed, FileRead, FileModified) originating from the 'doc_helper.aspx' file-management web shell. It summarizes activity by device and user account, flagging instances where over 100 unique files are touched within a short timeframe, which is indicative of automated collection and exfiltration activities.
Detects modifications or creation of InprocServer32 COM registry keys by suspicious processes like mshta.exe or powershell.exe, which is indicative of COM Hijacking for persistence or privilege escalation.
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
KQL Query from file: clickfix-mshtapowershell-run-dialog-exec-with-download-cradle-after-captcha-lu.kql
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
Page 356 of 1870
