Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
Detects instances where rundll32.exe is executed by a process named 'eld0.exe' residing in user-writable or temporary directories (e.g., Users, ProgramData, Temp, AppData). This behavior is characteristic of execution flow hijacking or malicious payload loading from suspicious file paths.
Detects rapid, repeated invocation of Microsoft Defender remediation processes (mpcmdrun.exe, MsMpEng.exe) occurring in conjunction with suspicious file write or rename operations in System32. This pattern is characteristic of a Time-of-Check to Time-of-Use (TOCTOU) race condition, where an attacker attempts to exploit the timing gap between Defender's detection and remediation actions to replace a file with a malicious version.
Detects the use of bcdedit.exe to disable automatic system recovery features, a common technique used by ransomware and other malware to prevent automated restoration of the operating system after compromise.
Detects the creation of a scheduled task named 'Windows Update ALPHV' using the schtasks.exe utility. This task is associated with the OpnKey ransomware, which uses this name to masquerade as a legitimate Windows Update task while running with SYSTEM privileges to maintain persistence.
Detects the execution of vssadmin.exe or WMIC.exe with commands intended to delete Volume Shadow Copies. This behavior is commonly associated with ransomware attempting to prevent system restoration by deleting local backups.
Detects command-line execution containing 'Processes.KillRunningProcesses', a string characteristic of the OpnKey ransomware builder configuration, suggesting an intent to terminate critical processes to facilitate encryption.
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
Detects command-line execution patterns indicative of OpnKey ransomware host fingerprinting. The ransomware gathers system metadata, including system IDs, PC hostnames, domain information, Windows versions, and processor names, likely to profile the environment prior to encryption or exfiltration.
Detects usage of the Windows API function GetUserObjectInformationW to inspect the current window station for specific strings, such as 'Service-0x'. This technique is often used by malware for environmental awareness, specifically to detect if it is running within a virtual machine or analysis sandbox by checking window station object attributes.
Detects the presence of OpnKey ransomware-specific configuration strings related to size-tiered file encryption settings in process command lines. These indicators suggest the execution of a binary with hardcoded logic to categorize files for encryption based on their size.
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
Detects an HTTP GET request to 'dl.php' containing an 'f' parameter (target file) and an 'k' parameter (access token), followed by a response body starting with the 'MZ' header, indicating the successful download of a Windows PE executable as part of a potential phishing campaign stage-2 payload delivery.
Detects PE binaries masquerading as Microsoft's Windows Update Assistant via forged VersionInfo metadata combined with an unsigned or invalid/unverified digital signature, associated with HVNC backdoor delivery
Detects instances where a shell process (powershell, cmd, mshta, or wscript) is spawned by a browser-related process (explorer, wt, or SearchHost) shortly after a user focuses on a web browser, followed by a network connection from that shell within a short time window. This pattern is indicative of potential web-based exploitation or file download and execution chains.
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
Detects the download of ZIP files with filenames matching known phishing patterns associated with NFe (Nota Fiscal Eletrônica) campaigns, correlated with access to specific malicious or suspicious download URLs within a 15-minute window.
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
Page 385 of 1870



