Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
This rule detects potential cryptocurrency mining activity where known miner executables (specifically XMRig) or malicious scripts/processes are masquerading as or being spawned by 'LockAppHost.exe' or 'LockAppHost14a02b.exe'. It also monitors for subsequent attempts by these processes to terminate security-related tasks or establish persistence via registry run keys.
Detects when a Node.js process initiates a low-level keyboard hook (WH_KEYBOARD_LL or WH_KEYBOARD) while running from common user-writable directories, which may indicate malicious keylogging activity by a suspicious process.
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
Detects the execution of node.exe or electron.exe with command-line arguments indicative of browser automation (e.g., launching headless browsers, cookie access) when executed from high-risk, writable directories like AppData\Temp, AppData\Roaming, ProgramData, or Users\Public. This behavior is frequently associated with information-stealing malware or unauthorized browser automation.
Detects Node.js or related helper processes executing shell commands (cmd.exe, powershell.exe) or other processes where the execution involves the 'withCreateProcessUser' argument. This often indicates attempts to bypass execution restrictions or run malicious payloads by utilizing Node.js as an execution proxy within unconventional or temporary directories.
Detects Terraform processes (init or apply) executed in conjunction with suspicious post-deployment indicators, such as references to '.terraform' folders, execution of automation scripts like 'dlp.sh' or 'dlp-docker.sh', or access to sensitive telemetry data external to typical infrastructure management.
This rule detects unauthorized or suspicious access to sensitive configuration and credential files (e.g., .aws, .azure, .ssh) by specific DLP (Data Loss Prevention) or automation scripts, and identifies subsequent attempts to expose environment variables or sensitive tokens within process command lines.
This rule detects process command line arguments that include the string 'data.external.telemetry', which may indicate the use of specialized tools, telemetry collection agents, or unauthorized data exfiltration channels.
Detects network activity from infrastructure provisioner tools (Terraform, Coder) or shell processes attempting to connect to suspicious domains (e.g., coder-infra.com) that resemble legitimate infrastructure domains. This activity is indicative of credential theft, specifically targeting OIDC tokens, SSH keys, or authentication tokens during automated provisioning processes.
Detects PEEP Secure Preferences integrity-hash forgery (protection.macs/super_mac) and known PEEP persistence scripts (patch_secure_prefs.ps1, install_silent.ps1, force_enable.ps1), anchored to actual Chrome/Edge profile paths rather than generic terms like 'protection' or 'developer_mode' that appear in unrelated admin tooling.
Detects the use of the native Windows registry utility 'reg.exe' to import configuration files (install.reg) related to the Radmin remote access software, specifically targeting the security settings registry path.
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
Detects the execution of 'famitrf2.exe' when it is launched as a child process of 'rserver3.exe' from the specific path 'C:\intel\rserver\rserver3.exe'. This pattern is highly indicative of Remote Administrator (RAdmin) software activity, which can be leveraged for legitimate remote management or malicious remote access.
Detects instances where PowerShell is used to download an executable named 'svchost.exe' from an external IP address (103.86.86.244). The rule monitors for network connections to this IP, file creation events matching specific download patterns in fonts directories, and direct command-line arguments involving the suspicious IP and file path, indicating potential malware dropper activity.
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
Detects multiple methods of tampering with Windows security controls, including disabling Windows SmartScreen via registry, bulk removal of Mark-of-the-Web (Zone.Identifier) via scripting, and disabling driver signature enforcement (TestSigning/NoIntegrityChecks) using BCDedit. These actions are indicative of an adversary attempting to bypass security protections to facilitate the execution of untrusted or malicious code.
This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
Page 357 of 1870
