Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
Detects remote file access (via SMB, named pipes, or TCP) to the Active Directory Certificate Services (AD CS) 'CertLog' directory. This directory contains the CA database (.edb), which holds issued certificates and archived private keys. Access to these files from a non-CA host is a strong indicator of an attempt to exfiltrate the CA database for offline certificate and private key recovery.
Detects text/report artifacts (markdown, JSON, plain text) produced by an autonomous AI-driven vulnerability research pipeline that decompiles binaries, traces cross-references, hypothesizes memory-safety flaws, and generates/debugs proof-of-concept exploits
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
This rule detects potential attempts to tamper with Microsoft Defender security settings by creating or managing scheduled tasks that modify Defender exclusion paths. It correlates process execution (specifically schtasks.exe or PowerShell commands used for setting exclusions) with Windows Registry events that modify the Microsoft Defender exclusion path registry keys, flagging suspicious activity within a 15-minute window.
Detects suspected exploitation of CVE-2026-81963, an Elevation of Privilege vulnerability in the Windows Update stack. The rule monitors for the creation of reparse points, junctions, or symbolic links within update staging paths by Windows Update processes, followed by either the spawning of suspicious child processes or unauthorized file writes/renames outside of expected directories, which are indicative of a privileged link-following exploit.
Detects PEEP credential/session theft via the native-messaging bridge, native host registration, staged CRX, or extension ID references. The nm_host.exe branch is now anchored to the known PEEP extension IDs (primary and alternate build) or the com.peep.lab path, rather than firing on any nm_host.exe spawned by a browser.
This rule detects outbound network connections from internal devices to a list of known malicious IP addresses associated with adversary command and control infrastructure. The rule specifically monitors connections over common ports, potentially indicating established communication with malicious servers.
Detects execution or file presence of known malicious files based on a pre-defined list of SHA256 hashes associated with known threat activity.
Detects anomalous child process execution originating from PaperCut application processes (pc-app.exe) or associated Java processes. This is indicative of post-exploitation activity following an RCE vulnerability where the application server is leveraged to spawn command interpreters, discovery utilities, or ingress tools.
GhostContainer
YARA
Detects GhostContainer .NET-based backdoor assembly components deployed on compromised Exchange servers, requiring multiple corroborating unique indicators (module/class names, C2 header, masquerading filenames) to reduce false positives on generic .NET assemblies
GhostContainer
YARA
Detects GhostContainer .NET-based backdoor assembly components deployed on compromised Exchange servers, requiring multiple corroborating unique indicators (module/class names, C2 header, masquerading filenames) to reduce false positives on generic .NET assemblies
This rule detects potential web shell creation on a Microsoft Exchange server by monitoring for suspicious child processes spawned by the IIS web server process (w3wp.exe) that correlate with the creation or modification of web-accessible script files (.aspx, .ashx, .asp, .dll) within the Exchange virtual directories (ecp, owa, aspnet_client). This pattern is consistent with common post-exploitation activities used by attackers to gain persistent access via web shells.
This rule detects potential web shell creation on a Microsoft Exchange server by monitoring for suspicious child processes spawned by the IIS web server process (w3wp.exe) that correlate with the creation or modification of web-accessible script files (.aspx, .ashx, .asp, .dll) within the Exchange virtual directories (ecp, owa, aspnet_client). This pattern is consistent with common post-exploitation activities used by attackers to gain persistent access via web shells.
This rule detects potential web shell creation on a Microsoft Exchange server by monitoring for suspicious child processes spawned by the IIS web server process (w3wp.exe) that correlate with the creation or modification of web-accessible script files (.aspx, .ashx, .asp, .dll) within the Exchange virtual directories (ecp, owa, aspnet_client). This pattern is consistent with common post-exploitation activities used by attackers to gain persistent access via web shells.
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
Page 362 of 1870



