Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects suspicious DLL loads or file drops performed by security product processes (avp.exe, MsMpEng.exe) from directories outside of standard, trusted vendor paths. It specifically flags unsigned or invalidly signed DLLs, which is indicative of DLL sideloading techniques used to abuse security software workflows for potential privilege escalation.
Detects the execution of command-line shells (cmd, powershell, pwsh) running under the SYSTEM context that were initiated by or associated with a process containing 'ShieldBreak' in its filename. This behavior is indicative of a suspicious or potentially malicious process (e.g., a security bypass tool) attempting to spawn elevated shells.
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
Detects the execution of msiexec.exe referencing a 'Temp.txt' file located within the user's AppData Local Temp directory, which matches a known suspicious file hash. This pattern often indicates an attempt to proxy the execution of malicious payloads via the Windows Installer utility.
Detects msiexec.exe executing from the Temp directory with suspicious command-line arguments (such as hidden windows) and spawning child processes like cmd.exe, tasklist.exe, or taskkill.exe. This behavior is often indicative of malicious installation scripts attempting to perform discovery or terminate security processes while remaining stealthy.
Detects msiexec.exe executing from the Temp directory with suspicious command-line arguments (such as hidden windows) and spawning child processes like cmd.exe, tasklist.exe, or taskkill.exe. This behavior is often indicative of malicious installation scripts attempting to perform discovery or terminate security processes while remaining stealthy.
This rule detects instances where a process named 'wsc_updata.exe' executing from a Temp directory loads a library named 'wsc.dll'. This behavior is characteristic of DLL side-loading or DLL hijacking, where a malicious or potentially unwanted executable attempts to load a library from a user-writable directory to execute arbitrary code.
This rule detects instances where a process named 'wsc_updata.exe' executing from a Temp directory loads a library named 'wsc.dll'. This behavior is characteristic of DLL side-loading or DLL hijacking, where a malicious or potentially unwanted executable attempts to load a library from a user-writable directory to execute arbitrary code.
This detection/hunting query identifies Chromium-based browser extensions matching known malicious extension IDs from the ExtSentry IOC feed. Adversaries and commodity malware families sideload extensions to steal session cookies, intercept credentials, and maintain persistence inside the browser, where the activity survives endpoint remediation that does not touch the browser profile. The rule covers three installation paths: files written to the extension directories, registry registration and policy-based force-install, and command-line sideloading via --load-extension. Wallet and password manager extensions are excluded upstream as sensitive rather than malicious.
This rule detects potentially malicious activity where a critical system library like 'kernelbase.dll' is loaded into a Chrome process, followed by events indicative of reflective DLL injection or memory-based code loading. Such behavior is often associated with browser-based exploitation, where an attacker attempts to inject malicious code into the legitimate Chrome process space to maintain persistence or conduct further malicious activities.
Detects suspicious process injection attempts originating from or targeting the Google Chrome browser (chrome.exe). The rule identifies cross-process activities such as remote thread creation or opening processes with high-privilege access masks (0x1FFFFF), which are common techniques used by malware to execute code within the memory space of a legitimate web browser.
This rule detects a correlation between the creation of a specific suspicious file named 'A08744D2.tmp' and the subsequent activity of the Windows Media Player Network Sharing Service ('wmpnetwk.exe') within a short time window. This pattern often indicates potentially malicious activity where a temporary file may be used to stage or interact with the service process.
This rule monitors for potential persistence and malicious activity by aggregating three distinct detection signals: COM hijacking attempts via the InprocServer32 registry key, the creation of scheduled tasks using specific suspicious naming conventions, and the identification of named mutexes indicative of specific malware presence.
Detects the legitimate wmpnetwk.exe process, commonly used as a target for ShadowPad process injection, initiating outbound network connections while simultaneously accessing Firefox browser profile data. This behavior is indicative of credential theft and command-and-control communication typical of post-compromise activity.
Detects anomalous clipboard activity where content is repeatedly replaced by cryptocurrency wallet address patterns (Bitcoin or Ethereum) within a short timeframe. This behavior is indicative of clipboard hijacking (clipjacking), a technique used by malware like EggJagger to substitute legitimate payment addresses with attacker-controlled addresses.
This rule detects potential Server-Side Request Forgery (SSRF) activity where web application or runtime processes attempt to access the Cloud Instance Metadata Service (IMDS) or container task metadata endpoints. By monitoring network connections and application logs, the rule filters out known legitimate metadata clients and identifies suspicious processes frequently associated with web-based vulnerabilities that are repeatedly querying sensitive metadata paths.
Detects automated reconnaissance and enumeration of sensitive web application paths (admin, config, environment files, etc.) from a single source IP. The rule identifies high-frequency request patterns that target specific non-public surface areas while excluding known search engine crawlers and monitoring bots.
Detects text/report artifacts (markdown, JSON, plain text) produced by an autonomous AI-driven vulnerability research pipeline that decompiles binaries, traces cross-references, hypothesizes memory-safety flaws, and generates/debugs proof-of-concept exploits
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
Detects anomalous activity patterns consistent with automated firmware reverse engineering pipelines, specifically correlating the high-frequency execution of firmware analysis tools (e.g., binwalk, Ghidra) with the creation of vulnerability research knowledge base artifacts. This behavioral heuristic aims to identify potential AI-driven or automated zero-day discovery workflows by tracking tool usage density and output characteristics.
This rule detects potential automated web scraping activity by identifying high-volume, repetitive network requests directed towards domains identified as government (.gov) or military (.mil). It correlates these network patterns with the execution of common browser automation frameworks (e.g., Puppeteer, Playwright) or headless browsers, indicating a likely coordinated scraping operation or bot activity.
Page 377 of 1870



