Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
Detects the execution of PowerShell or PWSH with command-line arguments often used to obfuscate scripts or hide activity, such as encoded commands (-enc), base64 decoding, or running the process with a hidden window.
Detects the execution of PowerShell or PWSH with command-line arguments often used to obfuscate scripts or hide activity, such as encoded commands (-enc), base64 decoding, or running the process with a hidden window.
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
Detects the execution of package managers (pip or npm) to install software dependencies initiated by development or agent-related processes (like IDEs or background services) in a non-interactive session. This behavior can be indicative of automated dependency confusion attacks, malicious supply chain activity, or unauthorized package installation occurring without direct user oversight.
Detects the installation of software packages in build or CI pipelines where the package was published to its registry between 30 and 90 days prior to being first used in the environment. This pattern is indicative of potential dependency confusion or typosquatting attacks, where adversaries use newly created packages to deliver malicious code.
This rule detects the use of package managers like 'pip' or 'npm' to install specific suspicious software packages or tools often associated with supply chain compromise or malicious library installation (e.g., 'huggingface-cli', 'unused-imports', 'react-codeshift').
This rule detects activity associated with known indicators of compromise (IOCs) related to European political targeting campaigns. It monitors network, email, and authentication logs for connections to specific malicious domains (including .onion addresses) and IP addresses. The rule spans multiple data sources, including device network events, Entra ID sign-in logs, cloud application events, and email communications.
Detects network communication to known malicious infrastructure associated with the GRAYRABBIT malware campaign. The rule correlates TCP connections on port 443 to the domain 'mail.uaiubifas.top' with process events attempting to discover system and user information (GetAdaptersAddresses, gethostname, GetUserNameA), which is characteristic of the malware's initial beaconing behavior.
Detects the spawning of cmd.exe from 7z.exe, which is characteristic of the GRAYRABBIT malware sideloading chain where 7z.exe is used to load malicious DLLs (e.g., boy.dll, core.dll) that subsequently initiate an interactive reverse shell.
Detects child processes spawned by 7z.exe when it is executed from the 'C:\Users\Public\Documents\' directory. This is consistent with the behavior of the GRAYRABBIT backdoor, where a trojanized 7z.dll or boy.dll is sideloaded into the 7z.exe process to facilitate silent arbitrary process execution.
This rule detects the use of the 7-Zip utility (7z.exe) located in 'C:\Users\Public\Documents\' to archive files, specifically monitoring for the creation of an archive file named 'p.7z' within the same directory. This pattern of staging files and using an archive utility in public, writeable directories is a common behavior observed in adversary data exfiltration preparation.
This rule detects the use of the 7-Zip utility (7z.exe) located in 'C:\Users\Public\Documents\' to archive files, specifically monitoring for the creation of an archive file named 'p.7z' within the same directory. This pattern of staging files and using an archive utility in public, writeable directories is a common behavior observed in adversary data exfiltration preparation.
This rule detects the use of the 7-Zip utility (7z.exe) located in 'C:\Users\Public\Documents\' to archive files, specifically monitoring for the creation of an archive file named 'p.7z' within the same directory. This pattern of staging files and using an archive utility in public, writeable directories is a common behavior observed in adversary data exfiltration preparation.
Detects the execution of 'SGMyInput.exe' with command-line arguments that include a 'skincenter' parameter and a custom URL parameter. This pattern may be indicative of specific application behavior or potential misuse involving external URL triggers.
Detects the execution of SGWebRender.exe with command-line arguments that weaken browser security, such as disabling web security, allowing file access, or disabling the sandbox. These flags are often used to facilitate malicious activity, such as bypassing cross-origin policies, accessing sensitive local files, or executing malicious code without sandbox constraints.
This rule detects potential file obfuscation attempts where a file is renamed to include a colon followed by a 6 to 10 character suffix, characteristic of an NTFS Alternate Data Stream (ADS). It monitors for a specific pattern where a file is renamed to this format and followed by a file deletion or another rename of the same file within a 300-second window, which may indicate an adversary trying to hide content or bypass security controls.
This rule detects potential process injection or evasion attempts by correlating the allocation of memory with Read-Write-Execute (RWX) permissions followed by the execution of Windows Thread Pool APIs (CreateThreadpoolWork, SubmitThreadpoolWork, or WaitForThreadpoolWorkCallbacks). Attackers may use these APIs as a mechanism to execute malicious code within a thread, bypassing standard monitoring of traditional thread creation APIs.
Detects execution of the GRAYRABBIT loader (specifically 7z.exe from the Users\Public\Documents staging path) in environments exhibiting low process count activity (<= 50 processes). This behavior is consistent with anti-sandbox checks used by this loader to gate XOR key derivation for payload decryption.
Detects network communication to known malicious infrastructure associated with the GRAYRABBIT malware campaign. The rule correlates TCP connections on port 443 to the domain 'mail.uaiubifas.top' with process events attempting to discover system and user information (GetAdaptersAddresses, gethostname, GetUserNameA), which is characteristic of the malware's initial beaconing behavior.
This rule monitors for specific PowerShell command-line patterns often associated with malicious activity, including 'ClickFix' clipboard-paste lures (using iex/irm with sleep timers), evasion techniques involving pscustomobject/ScriptBlock, and WinHttp COM object usage for stage-2 payload fetching. These patterns are characteristic of adversary attempts to bypass security controls and download secondary implants.
Page 383 of 1870


