Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,261 detections
Filters
Last updated
All Time
Detection languages
15,001
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,035
Categories
17,755
9,465
3,749
3,682
3,674
Platforms
39,261
6,901
6,444
3,782
3,524
Products / Services
10,164
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
40
24
19
IDS Protocols
181
171
20
17
8
Detects the use of PowerShell to download string content from the internet and execute it immediately using Invoke-Expression (IEX). This is a common pattern for fileless malware delivery and secondary stage payload execution.
Detects the creation of a scheduled task using schtasks.exe or reg.exe that is configured to run at system logon (/sc onlogon) using potentially malicious or persistence-related filenames such as client32.exe or NSM789508.
Detects the creation of a scheduled task using schtasks.exe or reg.exe that is configured to run at system logon (/sc onlogon) using potentially malicious or persistence-related filenames such as client32.exe or NSM789508.
Detects the use of PowerShell to download string content from the internet and execute it immediately using Invoke-Expression (IEX). This is a common pattern for fileless malware delivery and secondary stage payload execution.
Detects the execution of rundll32.exe with a command line pointing to a WebDAV share path (DavWWWRoot). This technique is commonly used to execute remote payloads by forcing the system to access a remote resource, often as part of a malicious DLL loading chain.
This rule detects the creation of a scheduled task named 'GlobalProtectVPNUpdate' using schtasks.exe, which has been identified as a technique used to facilitate the execution of malicious payloads masquerading as legitimate GlobalProtect VPN components. It also monitors for the subsequent execution of 'GlobalProtect.exe' when initiated by Windows background services like taskeng.exe or svchost.exe, which is indicative of persistence and unauthorized code execution.
Detects the execution of the Windows shutdown utility (shutdown.exe) with parameters configured to force an immediate reboot (/r /t 0 /f). This behavior is often associated with disruptive activities or attempts to clear system state by unauthorized actors.
Detects the XHOPELESS wiper routine 'KillNetworkPermanent' which severs network connectivity by resetting the TCP/IP stack using netsh, blocking all traffic via Windows Advanced Firewall commands, and disabling network adapters via devcon.exe as a final destructive action.
Detects malicious command-line activity associated with the XHOPELESS v1.0 wiper, specifically targeting firmware/BIOS/UEFI integrity. The detection covers WMI-based corruption of BIOS attributes, abuse of OEM-specific BIOS management namespaces, execution of legitimate firmware update tools with suspicious flags, modification of registry keys intended to disable firmware updates, and interaction with specific UEFI NVRAM GUIDs.
Detects potential web reconnaissance or scanning activity against Microsoft IIS servers. The rule identifies suspicious behavior by monitoring for high frequencies of distinct URI requests, excessive 404 Not Found status codes indicative of path brute-forcing, and the presence of known security scanning user-agents.
This rule detects suspicious command executions (e.g., whoami, downloadstring, iex, registry modifications) initiated by processes associated with the CrowdStrike Falcon agent. It also correlates these executions with the loading of unsigned or unverifiable DLLs by the same Falcon processes within a 5-minute window, which may indicate attempts to tamper with or masquerade as the security agent.
Detects suspicious activities originating from CrowdStrike Falcon remediation processes (e.g., CSFalconService.exe, CSFalconContainer.exe). The rule identifies two distinct patterns: either a file operation (delete, modify, rename, quarantine, or restore) followed within 2 minutes by the loading of an unsigned or non-standard DLL, or the spawning of an elevated SYSTEM process from a non-SYSTEM parent process. This behavior is indicative of potential LPE (Local Privilege Escalation) abuse via the Falcon remediation engine, often referred to as FalconFlank-style exploitation.
This rule detects unauthorized attempts to modify CrowdStrike Falcon sensor exclusion registry keys or commands involving DLL loading techniques that may indicate evasion preparation, specifically referencing potential FalconFlank-related activities. It filters out legitimate management activity from known service accounts, SCCM, and the CrowdStrike Falcon agent itself.
This rule detects potential ransomware activity by correlating three distinct indicators: deletion of Volume Shadow Copies (using native Windows utilities), mass file modifications (>100 files in 15 minutes), and the creation or modification of files typically associated with ransom notes. The rule uses an inner join to ensure these events happen within a 30-minute window of each other on the same device.
Detects unauthorized remote access sessions within N-able N-central by monitoring the Windows Application log for events indicating usage of the default 'MSP Support' account or source IP addresses associated with active exploitation of CVE-2026-18577.
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
Detects the ESET Remote Administrator (ERAAgent.exe) process loading the 'dpapisvc.dll' module. This behavior is indicative of potential DLL side-loading where an attacker places a malicious DLL with the same name as a legitimate system library in the agent's directory to achieve code execution.
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
Page 370 of 1870



