Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
Detects instances where the Windows Management Instrumentation service (wmiprvse.exe) launches suspicious command-line interfaces or interpreters (PowerShell, CMD, cscript, etc.), or executes scripts from sensitive/temporary directories. The rule includes exclusions for common management tools to reduce noise.
Detects the loading of WMI-related DLLs (wbemcomn.dll, wbemprox.dll) by processes that are commonly abused to proxy execution (LOLBins) such as certutil, mshta, or office applications. This behavior is often associated with WMI-based persistence or execution techniques.
Detects remote administration activity via Windows Management Instrumentation (WMI) originating from a host that has no recorded history of performing such actions within the previous 30 days. This includes the use of wmic.exe for remote nodes, Invoke-WmiMethod, or WmiPrvSe.exe spawning common command-line interpreters or utilities.
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
Detects execution of rundll32.exe with command-line arguments involving 'DavWWWRoot' and external domains ('pf.ch' or 'verification.google'), which is characteristic of attempts to force remote WebDAV authentication or execute malicious code via network-hosted resources.
Detects high-frequency, automated web scraping behavior targeting product catalog pages, indicative of content harvesting for site replication. The rule monitors IIS logs for non-browser user agents (e.g., Python, curl, Scrapy) performing rapid, multi-page requests within a short duration.
Detects network connections to known command and control (C2) infrastructure, including hardcoded malicious domains, specific C2 IP addresses, and suspicious GitHub access patterns by processes other than standard web browsers, which may indicate malicious ingress tool transfer or C2 communication.
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
Detects outbound network connections initiated by the VLC media player (vlc.exe) to public IP addresses using the RTSP protocol (port 554) or referencing common media file extensions (e.g., .m3u, .xspf) in the command line. This behavior is often associated with remote stream retrieval or, in adversarial contexts, the potential use of media players to exfiltrate data or retrieve malicious remote payloads.
Detects the deletion of volume shadow copies using common Windows administrative utilities including vssadmin.exe, wmic.exe, diskshadow.exe, or through PowerShell WMI/CIM cmdlets. This behavior is frequently associated with ransomware and data destruction attacks aiming to prevent system recovery.
Detects the deletion of volume shadow copies using common Windows administrative utilities including vssadmin.exe, wmic.exe, diskshadow.exe, or through PowerShell WMI/CIM cmdlets. This behavior is frequently associated with ransomware and data destruction attacks aiming to prevent system recovery.
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
Detects package manager processes (npm, pip, python) executing install-related commands followed by the creation or modification of sensitive files (SSH keys, cloud credentials, shell configurations) within a short timeframe. This behavior is indicative of potential supply chain attacks where a malicious package attempts to steal credentials or secrets upon installation.
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
Detects access to sensitive credential stores (KeePass databases, Firefox logins, SSH keys, VPN configuration files) by suspicious processes, specifically those associated with potential credential harvesting tools or unauthorized update binaries.
Page 366 of 1870

