Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Matches known Phantom Stealer MaaS infostealer sample hashes
Matches known VectraRAT sample SHA-256 hashes and the ClickFix distribution domain (verify-cloud.digital) recovered from pivoting across exposed VectraRAT distribution infrastructure
Matches known SilverFox malware payload samples by SHA256 hash
Matches known SilverFox malware payload samples by SHA256 hash
Matches known SilverFox malware payload samples by SHA256 hash
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
Detects network, HTTP, and DNS activity associated with the known three-tier delivery infrastructure (phishing sites, relay/dispatcher servers, and payload hosts) used by the threat actor UNC6671/SilverFox/Aurora. The rule distinguishes between high-confidence confirmed connections and low-confidence DNS-only events.
Detects the deletion of the XHOPELESS wiper executable from the filesystem, a technique commonly used by malware to remove its own traces and hinder forensic analysis after execution.
Detects unauthorized remote access sessions within N-able N-central by monitoring the Windows Application log for events indicating usage of the default 'MSP Support' account or source IP addresses associated with active exploitation of CVE-2026-18577.
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
This rule monitors for the connection of specific KVM-over-IP hardware devices (e.g., PiKVM, Guermok) which can be used by an adversary to gain remote access to a system's physical keyboard, video, and mouse interface, effectively bypassing software-based security controls.
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
Detects pre-encryption activity typical of the CRPx0 ransomware, involving the destruction of Windows Volume Shadow Copies, Windows Backup Catalogs, or macOS Time Machine snapshots using system utilities such as vssadmin, wbadmin, wmic, or tmutil. This behavior is indicative of an imminent encryption phase.
Detects the creation of scheduled tasks using the 'schtasks.exe' utility, a technique often used by the CRPx0 ransomware to establish persistence on a system. The rule specifically monitors for the '/create' command-line argument while excluding common, benign updater processes such as those from Microsoft Edge, Google, and OneDrive.
Detects the creation of a large file (exceeding 4MB) named 'WindowsUpdate.log' on the system. This behavior is indicative of a masquerading attempt where a malicious PE DLL is disguised with the extension of a known legitimate log file, a technique observed in the CRPx0 ClickFix lure to evade security inspection.
Detects the creation of new executable files (DLL or EXE) that contain a certificate subject string referencing 'Microsoft' but are located outside of the standard 'C:\Windows\' directory. This behavior is indicative of an attacker attempting to bypass trust validation mechanisms by creating binaries with self-signed, fake Microsoft certificates, a technique observed in the CRPx0 builder toolset to evade EDR and AV inspection.
Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.
Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.
Detects the execution of PowerShell commands containing indicators of AMSI or ETW unhooking (e.g., references to amsi.dll, AmsiScanBuffer, EtwEventWrite, or VirtualProtect). This activity is commonly associated with attackers attempting to bypass endpoint security telemetry and antimalware scanning mechanisms prior to executing malicious payloads.
Detects evidence of sandbox or virtualization evasion by identifying discovery commands that query WMI hypervisor classes or common virtual machine hardware strings. This activity is considered a precursor (pre-detonation check) when followed by the execution of encoded PowerShell commands or Python scripts on the same host, which is characteristic of the CRPx0 ClickFix attack chain.
Detects network communication with a known CRPx0 clearnet relay (207.180.29.236:8080) coupled with evidence of local Tor SOCKS5 proxy activity (ports 9050/9150) on the same host, indicating the bridging of traffic to an onion-hosted C2 server.
Page 379 of 1870


