Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects anomalous authentication behavior where a user account utilizes the same authentication session (LogonId) or material to authenticate across multiple distinct destination hosts in a short timeframe. This rule monitors for both NTLM (Type 3) and Kerberos (TGS/TGT) events, which are indicative of lateral movement techniques such as Pass-the-Hash or Pass-the-Ticket.
This rule detects the presence of files or process execution events matching a known set of SHA256 hashes associated with the BlueMoon malware family. The detection covers both file system events and process creation events.
This rule detects the presence of files or process execution events matching a known set of SHA256 hashes associated with the BlueMoon malware family. The detection covers both file system events and process creation events.
This rule detects the creation of a specific mutex named 'GlobolID-4465173'. Mutexes are often used by malware to ensure that only a single instance of the malicious process runs on an infected host, serving as a reliable indicator of compromise (IOC) for specific malware families or campaigns.
This rule detects potential credential theft activity by monitoring for unauthorized access to sensitive browser-related credential files (e.g., Login Data, cookies.sqlite) or direct access to the LSASS process memory by non-standard browser processes. It further correlates these events with user sign-ins on previously unknown or unassociated devices within a short timeframe to identify potential account compromise.
Detects anomalous command-line arguments and process injection behaviors associated with the Sogou IME protocol handler (biz_helper.exe). The rule monitors for malicious argument injection (e.g., embedded scripts, URLs pointing to non-Sogou domains) and correlates these events with suspicious child processes or network activity, consistent with techniques observed in the GRAYRABBIT / UNC3569 threat activity.
Detects UNC3569/GRAYRABBIT shellcode combining call/pop self-location, PEB InLoadOrderModuleList walk, and the specific XOR-then-ROR8 export-name hashing loop observed in the GRAYRABBIT loader chain, requiring multiple distinctive elements together to reduce false positives on generic shellcode idioms
This rule detects the termination of critical security software processes (e.g., antivirus agents) by a process that has recently acquired SeDebugPrivilege. This behavior is indicative of a malicious actor attempting to disable endpoint security controls to evade detection.
Detects Rust-compiled executables exhibiting C2-capable characteristics consistent with backdoors dropped on compromised JFrog Artifactory servers
Detects network communication with Google Sheets API endpoints that contain specific indicators of C2 behavior, such as suspicious User-Agents, specific spreadsheet cell references, or input options characteristic of automated data exfiltration or command retrieval.
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
Detects a command shell (cmd.exe, powershell.exe, powershell_ise.exe, pwsh.exe) created with a SYSTEM SID whose immediate parent process is a POSITIVELY IDENTIFIED non-SYSTEM account running at Low/Medium integrity. Excludes known-benign SYSTEM-spawning binaries and blank-parent scheduled-task/service noise confirmed via live telemetry and attached evidence logs, and drops the prior TokenElevationTypeFull branch which mostly matched routine UAC-elevated admin activity rather than an actual SYSTEM token.
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
Detects network connections from Windows hosts to known IP addresses and domain names associated with the exploitation infrastructure used in CVE-2026-18577, targeting N-able N-central servers.
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe, whoami) by PaperCut application processes (java.exe, pc-app.exe, PCClient.exe), which is indicative of post-exploitation activity following an authentication bypass and remote code execution chain against PaperCut NG/MF.
Matches known RedTail malware payloads and staging scripts by exact SHA-256 hash equality
Matches known RedTail malware payloads and staging scripts by exact SHA-256 hash equality
Matches known RedTail malware payloads and staging scripts by exact SHA-256 hash equality
Detects PowerShell processes initiating network connections to known public DNS-over-HTTPS (DoH) providers over port 443. This behavior is often associated with efforts to bypass standard organizational DNS logging and security controls by tunnelng DNS queries through encrypted HTTPS traffic.
Detects the execution of 'charmap.exe' from the Syswow64 directory where the process hierarchy indicates suspicious activity. The detection identifies a chain where PowerShell spawns 'conhost.exe', which in turn spawns a process from a temporary directory (interpreted as a renamed AutoIT executable) that then launches 'charmap.exe'. This pattern is indicative of a multi-stage obfuscated execution flow often used in malware dropper scenarios to bypass standard monitoring.
Page 381 of 1870




