Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation, modification, or renaming of PHP files within the 'wp-content/uploads' directory of a WordPress installation. This pattern is commonly indicative of an attacker uploading a web shell to maintain persistence or execute arbitrary code on a compromised web server.
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
Detects instances where a process named MsCache.exe deletes files within the Google Chrome User Data directory. This pattern may indicate unauthorized activity by a process masquerading as a cache-related utility to modify or delete browser-related artifacts.
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe, whoami) by PaperCut application processes (java.exe, pc-app.exe, PCClient.exe), which is indicative of post-exploitation activity following an authentication bypass and remote code execution chain against PaperCut NG/MF.
Detects nm_host.exe (PEEP native messaging host binary) spawned by Chrome/Edge, tightened to require either the known PEEP extension ID in the native-messaging invocation command line or the distinctive com.peep.lab host path.
Detects a DLL file being created directly under C:\Windows\System32 by a process running at less than System integrity (not SYSTEM/TrustedInstaller). Legitimate System32 DLL writes are performed by installers or the OS itself running with SYSTEM privileges; a standard-user or low/medium-integrity process writing a new DLL into this protected path is consistent with the HardBreacher/SolidSnake local privilege-escalation exploit chain. Scoped on protected-directory + non-privileged-writer, not on filename, to generalize to renamed variants.
Detects unauthenticated HTTP POST requests to the PaperCut web management interface that attempt to modify server configuration settings. This behavior is consistent with exploitation attempts targeting vulnerabilities like CVE-2026-81578, which may allow for unauthorized pre-authentication remote code execution.
The following analytic detects the creation or modification of adsource.dll or other staging files with the name adsource_*.dll within the SCCM SMS Provider bin directory, consistent with exploitation of CVE-2026-47301.
This abuses a DLL side-loading vulnerability in the Microsoft Configuration Manager SMS Provider component.
An attacker can plant a malicious adsource.dll in the SCCMProvider bin\X64 path, causing the SMS Provider service to load the attacker-controlled library in a privileged context.
The presence of renamed dlls alongside adsource.dll is a strong indicator of the classic DLL hijacking pattern where the legitimate library has been renamed so the malicious replacement can proxy calls to it.
If confirmed malicious, this activity represents a privilege escalation vector that can result in SYSTEM-level code execution on any host running the SCCM SMS Provider role.
This abuses a DLL side-loading vulnerability in the Microsoft Configuration Manager SMS Provider component.
An attacker can plant a malicious adsource.dll in the SCCMProvider bin\X64 path, causing the SMS Provider service to load the attacker-controlled library in a privileged context.
The presence of renamed dlls alongside adsource.dll is a strong indicator of the classic DLL hijacking pattern where the legitimate library has been renamed so the malicious replacement can proxy calls to it.
If confirmed malicious, this activity represents a privilege escalation vector that can result in SYSTEM-level code execution on any host running the SCCM SMS Provider role.
Detects node.js or bun runtime processes accessing known sensitive cloud, CI, and package manager credential files on disk. This behavior is indicative of malicious npm supply chain attacks (e.g., Mini Shai-Hulud) attempting to exfiltrate secrets stored in standard configuration paths.
This rule detects DNS queries or network connections originating from endpoints to a list of known malicious domains associated with various malware families (ClearFake, IClickFix, AMOS, Vidar, etc.). This helps identify potential C2 communication, malicious payload delivery, or infrastructure interaction.
This rule detects DNS queries or network connections originating from endpoints to a list of known malicious domains associated with various malware families (ClearFake, IClickFix, AMOS, Vidar, etc.). This helps identify potential C2 communication, malicious payload delivery, or infrastructure interaction.
This rule monitors DeviceNetworkEvents for outbound network connections to a list of known malicious IP addresses associated with various C2 frameworks and malware families, as identified by threat intelligence feeds (e.g., ThreatFox). Identifying these connections helps detect potential C2 communication and ingress tool transfer.
This rule detects network connections and HTTP requests to known malicious URLs, including file downloads associated with C2 infrastructure and malware distribution campaigns. It monitors both direct device network events and HTTP requests logged through security product events to identify potential secondary-stage payload delivery.
This rule detects the presence of files or process execution events matching a known set of SHA256 hashes associated with the BlueMoon malware family. The detection covers both file system events and process creation events.
This rule detects DNS queries and network connections to a curated list of domains identified as malicious. It correlates events from DNS logs and device network logs to identify potential command-and-control (C2) or malicious infrastructure interaction.
This rule detects potential ransomware activity by correlating risky user identity events (such as impossible travel or malicious IP access) with subsequent endpoint behavior typical of ransomware, specifically the deletion of shadow copies or system backups, or mass file modification activity occurring within a short window.
This rule detects potential ransomware activity by correlating risky user identity events (such as impossible travel or malicious IP access) with subsequent endpoint behavior typical of ransomware, specifically the deletion of shadow copies or system backups, or mass file modification activity occurring within a short window.
Detects attempts to modify, disable, or exclude paths and processes from Microsoft Defender Antivirus using legitimate administrative utilities such as PowerShell, cmd, sc, and netsh. This behavior is indicative of an adversary attempting to evade security monitoring.
This rule detects potential web skimmer activity where a user's browser performs a network connection to known payload delivery hosts (e.g., paste.sh or Google Sheets API) followed by a clipboard modification event on the same device within a one-hour window. This behavior is consistent with malicious scripts attempting to replace copied cryptocurrency wallet addresses with an attacker-controlled address.
Detects the creation of WMI event filters and consumers associated with CommandLineEventConsumer or ActiveScriptEventConsumer, excluding known legitimate system processes. This behavior is a common technique for establishing persistence and executing arbitrary code via WMI event subscriptions.
Detects the creation of WMI event filters and consumers associated with CommandLineEventConsumer or ActiveScriptEventConsumer, excluding known legitimate system processes. This behavior is a common technique for establishing persistence and executing arbitrary code via WMI event subscriptions.
Page 365 of 1870



