Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects web server processes (e.g., w3wp.exe, nginx.exe, tomcat.exe) spawning command-line interpreters or utilities that could indicate remote code execution, web shell activity, or post-exploitation discovery/download attempts.
Detects the creation or modification of Windows Registry run keys (Run or RunOnce) that attempt to point to executables within 'ProgramData\Synaptics' or named 'synaptics.exe'. This behavior is characteristic of adversaries attempting to establish persistence by masquerading as legitimate Synaptics driver software, while excluding legitimate installation directories.
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
Detects the use of database or archiving command-line utilities to export data related to RADIUS services. The rule filters out known backup service accounts and authorized backup processes, flagging activity that occurs outside of standard business hours or is performed by accounts not explicitly designated for administrative or database maintenance tasks.
This rule detects potentially malicious activity involving the modification of Excel macro security settings (specifically VBAWarnings or AccessVBOM) or the creation of autorun.inf files on removable drives. It identifies these behaviors when they coincide with the execution of Synaptics.exe within a 30-minute window, suggesting a potential correlation between local administrative tasks and malicious document-based payloads or portable drive staging.
Detects execution and file activity associated with the XRed backdoor, which masquerades as 'Synaptics.exe' by running from the non-standard 'C:\ProgramData\Synaptics\' directory instead of authorized system paths.
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Detects instances where internal devices access the 3BB sales portal (agent.3bb.co.th) while demonstrating signs of compromise. The rule correlates the portal access with recent network activity involving identified MeshCentral attacker infrastructure (ayuthayatech.com or 92.63.180.133) and further filters for behavioral anomalies such as off-hours access, the use of non-standard browser processes, or the use of unexpected service accounts.
Detects network requests to unpkg.com or npmmirror for 'index.html' files directly under a package path. This behavior deviates from standard package management usage (which typically fetches tarballs or specific JavaScript modules) and is often associated with adversaries using npm packages as hosting infrastructure for phishing landing pages.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
This rule detects potential execution of malicious files from removable media (e.g., USB drives). It monitors for a sequence of events where a removable drive is mounted, a file is subsequently created on that drive, and then that same file is executed within a short time window.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Detects uncommon or suspicious child processes spawning from a WSL process. This could indicate an attempt to evade parent/child relationship detections or persistence attempts via cron using WSL.
Page 375 of 1870

