Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the creation of scheduled tasks using the 'schtasks.exe' utility that reference suspicious paths (AppData/Local or Roaming) or specific executables often associated with suspicious activity (Launcher.exe, GapiUpdate.exe) in conjunction with 'DeviceSetupManager'. Additionally, it includes a hash-based detection for a specific known malicious file artifact.
Detects access to sensitive credential stores (KeePass databases, Firefox logins, SSH keys, VPN configuration files) by suspicious processes, specifically those associated with potential credential harvesting tools or unauthorized update binaries.
Detects access to sensitive credential stores (KeePass databases, Firefox logins, SSH keys, VPN configuration files) by suspicious processes, specifically those associated with potential credential harvesting tools or unauthorized update binaries.
This rule monitors network, DNS, and email activity to identify communication or references to a set of known malicious domains associated with threat activity. It consolidates logs from device network events, DNS queries, and email telemetry (URLs and sender domains) to detect potential compromise or phishing attempts.
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
This rule detects potential malicious activity by monitoring for specific file hashes, specific suspicious filenames, and suspicious command-line patterns (e.g., 'antivm') initiated by known update or launcher processes. This is likely an indicator of malware behavior involving anti-sandbox or evasion techniques.
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
Detects unauthorized processes attempting to access sensitive application data files such as browser cookies, local state, or data stored by applications like Discord, Telegram, and Steam, which are frequent targets for credential-stealing malware.
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
This rule detects potentially malicious activities aimed at credential harvesting and system recovery inhibition. It monitors for the execution of vssadmin.exe with arguments to list shadow copies (often a precursor to deletion) or references to DPAPI master keys in command lines. Additionally, it identifies unauthorized processes attempting to access sensitive browser-based credential files (e.g., Login Data, Cookies, key4.db) from standard browser installation paths, specifically excluding legitimate browser and update processes.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
This rule detects potential automated cryptocurrency wallet draining activity by correlating the execution of known stealer processes (such as GapiUpdate or NeedleStealer) with subsequent outbound network connections to suspicious command-and-control domains or API endpoints within a 30-minute window.
Detects NeedleStealer Go-based stealer payload via embedded module path, internal API namespace, build tag, and C2 backend domain
Detects NeedleStealer Go-based stealer payload via embedded module path, internal API namespace, build tag, and C2 backend domain
This rule detects potential command-and-control beaconing activity associated with the Go RAT used in the GapiUpdate campaign. It monitors for outbound network connections over TCP port 5556 to a known malicious C2 IP address, or alternatively, detects persistent outbound activity to other external (non-RFC1918) IP addresses characterized by multiple successive connections within a 10-minute window, which mimics the behavior of persistent beaconing.
Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.
Detects network activity associated with Rust-based stealer malware, specifically focusing on connections to a known C2 IP address (31.76.7.137) or HTTP requests directed at static-asset paths (e.g., analytics.gif, pixel.png, content.js) when the destination is an IPv4-literal address. This behavior is indicative of C2 beacons or data exfiltration disguised as legitimate web traffic.
Page 367 of 1870

