Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
Detects in-memory modification of the ntdll.dll module to patch EtwEventWrite or EtwEventWriteFull functions, a technique used by adversaries to evade Windows event tracing and suppress telemetry. The rule specifically targets activities originating from w3wp.exe, consistent with behavior observed in IIS-hosted deployments like GhostContainer.
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
This rule detects HTTP requests directed at Microsoft Exchange Outlook Web Access (OWA) that contain suspicious 'fakePath' and 'fakePageName' parameters in the URI. These parameters are indicators of the 'GhostContainer' malware attempting to establish a socket forwarding proxy through the web server to facilitate command and control communications.
Detects the GhostContainer .NET-based backdoor assembly deployed on compromised Microsoft Exchange servers, requiring multiple corroborating unique indicators (C2 header, proxy class name, virtual path parameters) alongside .NET/PE structure to reduce false positives
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
Detects Active Directory DCSync attempts by monitoring for Windows Security Event ID 4662 where the object properties contain GUIDs associated with directory replication services (DS-Replication-Get-Changes, DS-Replication-Get-Changes-All, and DS-Replication-Get-Changes-In-Filtered-Set). The rule excludes domain controller machine accounts and known legitimate service accounts used for synchronization or backup operations.
Detects the execution of the rdp2tcp tunneling tool in conjunction with RDP virtual channel activity using the 'rdp2tcp' channel name. This combination is a strong indicator of RDP-based protocol tunneling.
Detects potential tampering with Windows Event Logs or audit services by correlating manual service stops or log clearing events (EventIDs 1100, 1102, 104, 7036, 7040) with a sudden, significant decrease in total event volume on the same host. The rule accounts for planned maintenance and legitimate event log service restarts to reduce noise.
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
Detects the use of command-line tools like curl, wget, PowerShell, or Python to perform DNS over HTTPS (DoH) queries, identified by specific command-line arguments and connections to known public DoH resolvers. This behavior can be indicative of attempts to bypass local DNS monitoring or security controls.
Detects the presence of the Docro Hijacker browser hijacker component (Adblock.dll) designed to tamper with Chrome's 'Secure Preferences' file. It specifically looks for indicators of HMAC-SHA256 integrity check bypass mechanisms used to force-install malicious browser extensions.
This rule detects suspicious PowerShell execution that attempts to download files from the internet using the Invoke-WebRequest cmdlet. It specifically looks for PowerShell processes launched with hidden and execution policy bypass flags, coupled with specific hardcoded malicious URL patterns associated with a known campaign (NotaFiscal/nfe_valid_access_key_2026_secure).
This rule identifies devices within the environment that are susceptible to CVE-2026-81963. It correlates vulnerability data with knowledge base information to flag the software, vendor, version, severity level, and the availability of public exploits for this specific vulnerability.
Detects a specific pattern of PowerShell execution involving the download of files from a remote endpoint using parameters associated with Brazilian tax documents (NotaFiscal) to the Desktop directory, followed by immediate execution. The rule looks for a combination of hidden window style, Invoke-WebRequest, specific URL parameters (dl.php, NFe identifiers), and subsequent Start-Process calls, which is indicative of malware dropper activity.
This rule detects the creation, modification, or renaming of 'ntdll.dll' within a specific directory path matching the pattern 'ShieldCrash_{GUID}'. This pattern is indicative of potential malicious activity, such as the use of NTFS Alternate Data Streams (ADS) for persistence or execution evasion. The rule explicitly excludes known legitimate system processes that may handle DLL files to minimize noise.
Detects suspicious file activity within directories named 'ShieldCrash' followed by a cloud provider registration or placeholder creation event within a 5-minute window. This behavior is indicative of unauthorized software or an adversary attempting to stage data for exfiltration or create persistent storage aliases outside of legitimate cloud client applications.
Detects the eicar_com.zip test archive used by the ShieldCrash PoC (CVE-2026-69414) to trigger Windows Defender's vulnerable scan/read path, only when observed alongside ShieldCrash binary or staging path/context indicators to reduce false positives from routine EICAR AV testing
Detects the eicar_com.zip test archive used by the ShieldCrash PoC (CVE-2026-69414) to trigger Windows Defender's vulnerable scan/read path, only when observed alongside ShieldCrash binary or staging path/context indicators to reduce false positives from routine EICAR AV testing
This rule detects suspicious file operations (creation, modification, or renaming) initiated by MsMpEng.exe (Microsoft Defender Antivirus) involving specific indicators related to ELAM (Early Launch Anti-Malware) or 'ShieldCrash' components. These indicators often suggest tampering attempts or the presence of tools designed to interfere with Defender's security operations by targeting its configuration, staging, or protected storage locations.
Page 363 of 1870



