Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects usage of the 'finger' utility via command line within scripts or batch files, or network connections originating from the 'finger' process on port 79 to non-internal destinations. This activity is commonly associated with internal network reconnaissance to gather user information or system details.
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
Detects the creation of Windows services immediately following a network logon event (Logon Type 3) using NTLM or Kerberos. The rule monitors for service names or file paths characteristic of PsExec-style remote execution tools, specifically focusing on suspicious paths (e.g., Temp, UNC paths) or file extensions (e.g., .bat, .ps1, .tmp) used by attackers to execute payloads laterally.
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
Detects the use of PowerShell to modify Windows Defender security settings by adding exclusion paths or processes. This behavior is indicative of an adversary attempting to whitelist malicious files or processes to evade detection by the antivirus solution.
Detects instances where PowerShell is used to download an executable named 'svchost.exe' from an external IP address (103.86.86.244). The rule monitors for network connections to this IP, file creation events matching specific download patterns in fonts directories, and direct command-line arguments involving the suspicious IP and file path, indicating potential malware dropper activity.
Detects the execution of 'famitrf2.exe' when it is launched as a child process of 'rserver3.exe' from the specific path 'C:\intel\rserver\rserver3.exe'. This pattern is highly indicative of Remote Administrator (RAdmin) software activity, which can be leveraged for legitimate remote management or malicious remote access.
This rule detects potentially malicious PowerShell execution patterns involving hidden windows, administrative elevation via 'Start-Process -Verb RunAs', and the targeting or execution of rsetup64.exe within specific system paths. It also flags execution chains where 'net session' commands, often used for discovery or local privilege verification, are piped to null and followed by or initiate the same target executables, suggesting lateral movement or persistence attempts.
This rule detects potentially malicious PowerShell execution patterns involving hidden windows, administrative elevation via 'Start-Process -Verb RunAs', and the targeting or execution of rsetup64.exe within specific system paths. It also flags execution chains where 'net session' commands, often used for discovery or local privilege verification, are piped to null and followed by or initiate the same target executables, suggesting lateral movement or persistence attempts.
Detects files referencing malicious implant install paths under C:\Windows\Fonts\web used to blend with legitimate system files
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
Detects the execution of PowerShell with suspicious command-line arguments (e.g., encoded commands, hidden windows) initiated by mshta.exe, excluding instances where a .ps1 script file is involved. This pattern often indicates attempts to bypass execution policy or run obfuscated payloads in memory, which is a common behavior of malicious HTA files.
Detects the loading of 'Adblock.dll' by the executable 'eld2.exe', specifically when 'eld2.exe' is executed as a child process of 'windirstat.exe'. This behavior is indicative of DLL side-loading where a legitimate or potentially malicious application is used to load a secondary library.
Detects instances where multiple executables named 'eld0.exe', 'eld1.exe', or 'eld2.exe' are executed on the same device within a short time window, all containing a 'CID=' argument in the command line. This behavior is often indicative of automated deployment, staging, or modular malware execution patterns.
Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
Page 384 of 1870


