Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the execution of 'charmap.exe' from the Syswow64 directory where the process hierarchy indicates suspicious activity. The detection identifies a chain where PowerShell spawns 'conhost.exe', which in turn spawns a process from a temporary directory (interpreted as a renamed AutoIT executable) that then launches 'charmap.exe'. This pattern is indicative of a multi-stage obfuscated execution flow often used in malware dropper scenarios to bypass standard monitoring.
Detects the use of PowerShell's 'WriteAllBytes' method to write a file to the user's Local AppData Temp directory, immediately followed by the creation of a known or suspicious executable file in that same location. This pattern is commonly indicative of a stage in a fileless-style malware attack or automated payload delivery.
Detects the execution of PowerShell commands that utilize a combination of 'Test-Path', 'Start-Sleep' (or 'sleep'), and arithmetic obfuscation (e.g., -lt (63+17)). This pattern is often used in malicious scripts to implement a delay while obfuscating the duration, a technique frequently seen in staging or persistence phases to evade sandbox analysis or signature-based detection.
Detects the execution of PowerShell commands that use character-based obfuscation to call 'CreateDirectory' and interact with the user's temporary environment folder. This pattern is commonly observed when scripts attempt to hide file staging or payload delivery paths from static analysis.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to known JeetBot infrastructure domains and IP addresses. The rule specifically identifies potential exfiltration of Twitch OAuth tokens via URL parameters or interaction with known token-collection proxy endpoints, which are associated with the JeetBot/Twitch Enhanced Viewer credential harvesting campaign.
Detects network connections to command-and-control infrastructure associated with the JeetBot/Twitch Enhanced Viewer malicious browser extension. The rule triggers on connections to known malicious domains or IPs, as well as specific API endpoints on ambiguous domains that are used for exfiltrating Twitch OAuth tokens.
Detects network connections to JeetBot/Twitch Enhanced Viewer malicious browser extension infrastructure exfiltrating Twitch OAuth tokens. Apex domains (jeetbot.cc, api.jeetbot.cc) are gated on a token-forwarding indicator to avoid false positives.
This rule monitors for a multi-stage attack pattern involving two potential indicators: first, it identifies phishing emails containing a 'Google Docs' link combined with an attachment named 'API Logic Flaw'. Second, it detects browser activity involving the paste of JavaScript code or suspicious browser clipboard activity, which may indicate an attacker attempting to execute malicious scripts directly in the user's browser context.
This rule detects potential web skimmer activity where a user's browser performs a network connection to known payload delivery hosts (e.g., paste.sh or Google Sheets API) followed by a clipboard modification event on the same device within a one-hour window. This behavior is consistent with malicious scripts attempting to replace copied cryptocurrency wallet addresses with an attacker-controlled address.
Detects browser-based network requests to the Google Sheets Visualization API (gviz/tq) that appear to be used for fetching malicious JavaScript payloads from public Google Sheets. The rule specifically identifies instances where a process initiates these requests without any corresponding active browser session associated with standard Google Docs or Sheets editing activity.
This rule detects potential browser-based manipulation or phishing campaigns where a user visits a known loader script host (paste.sh) and subsequently visits cryptocurrency trading sites (SimpleSwap, SwapZone) within a short time window. This behavior is indicative of an injected script modifying the browser's view of trading sites to display deceptive 'Loyalty Bonus' or discount banners to lure users into transactions.
This rule detects potential browser-based wallet address substitution attacks by monitoring for a specific sequence of network connections within a single browser process. It looks for connections to cryptocurrency swap platforms (SimpleSwap/SwapZone) closely followed by the retrieval of an external loader script (paste.sh) and a Google Sheets Visualization API payload, which is a known technique for injecting malicious scripts that intercept and modify XHR/fetch responses in the user's browser.
Detects browser-based network requests to the Google Sheets Visualization API (gviz/tq) that appear to be used for fetching malicious JavaScript payloads from public Google Sheets. The rule specifically identifies instances where a process initiates these requests without any corresponding active browser session associated with standard Google Docs or Sheets editing activity.
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
Detects the loading or usage of the malicious driver 'DCRCVDrv.sys' associated with the ClearFake crypto stealer campaign, which uses a Bring-Your-Own-Vulnerable-Driver (BYOVD) technique to interact with the device path '\Device\DCRCVDRV_U' to terminate or impair EDR and security tools.
This rule monitors for file, process, and image load events associated with a set of known malicious indicators (IOCs). It specifically flags potential DLL side-loading anomalies, such as 'Secur32.dll' being loaded by 'platform_experience_helper.exe' from non-system directories, or 'platform_experience_helper.exe' executing from locations outside the standard Google application directory.
This rule monitors for file, process, and image load events associated with a set of known malicious indicators (IOCs). It specifically flags potential DLL side-loading anomalies, such as 'Secur32.dll' being loaded by 'platform_experience_helper.exe' from non-system directories, or 'platform_experience_helper.exe' executing from locations outside the standard Google application directory.
This rule monitors for indicators of compromise (IOCs) associated with a specific AutoIT-based malware delivery chain. It tracks the execution and presence of specific malicious file names and SHA256 hashes, as well as network connections to a identified command-and-control (C2) infrastructure IP address (158.51.122.136). The detection spans file creation, process execution, image loading, and network communication events to identify the multi-stage attack lifecycle.
Page 382 of 1870

