Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the presence of known malicious Outlook VBA project files (VbaProject.OTM), modifications to Outlook macro-security registry keys to enable macro execution, and subsequent network activity initiated by Outlook on devices that have exhibited these suspicious behaviors.
Detects the execution of common system administration tools (cmd, powershell, net, nltest, etc.) used to perform environment discovery or credential enumeration, specifically when targeting Domain Controllers, Active Directory objects, database credentials, or sensitive configuration files.
Detects the execution of known offensive security tools often used for lateral movement, credential dumping, and remote code execution, such as Impacket modules and the 'Invoke-TheHash' PowerShell suite, via common command-line interpreters.
This rule detects potentially malicious activity originating from Microsoft Word (WINWORD.EXE). It monitors for two specific patterns: the creation of script files (.bat, .vbs, .cmd) with GUID-based filenames in non-temp directories, and the creation or execution of files matching known malicious hashes associated with the Hookedge malware family.
This rule detects potentially malicious activity originating from Microsoft Word (WINWORD.EXE). It monitors for two specific patterns: the creation of script files (.bat, .vbs, .cmd) with GUID-based filenames in non-temp directories, and the creation or execution of files matching known malicious hashes associated with the Hookedge malware family.
This rule detects potentially malicious activity originating from Microsoft Word (WINWORD.EXE). It monitors for two specific patterns: the creation of script files (.bat, .vbs, .cmd) with GUID-based filenames in non-temp directories, and the creation or execution of files matching known malicious hashes associated with the Hookedge malware family.
Detects the execution of known malicious files associated with the BlueDelta threat group, specifically the HOOKEDGE and HEADLACE malware families, using a curated list of SHA-256 file hashes. Additionally, the rule monitors for the execution of scripts with GUID-based filenames, a common tactic for temporal or staged file deployment.
Matches known HOOKEDGE malware samples attributed to BlueDelta (APT28) via SHA256 hash comparison
Detects execution or file presence associated with HOOKEDGE/HEADLACE malware. This rule uses a dual-approach: matching known malicious file hashes (SHA256) and monitoring for specific script files (bat, vbs, cmd) following a GUID-formatted naming convention typically used by the HOOKEDGE installer chain.
Detects execution or file presence associated with HOOKEDGE/HEADLACE malware. This rule uses a dual-approach: matching known malicious file hashes (SHA256) and monitoring for specific script files (bat, vbs, cmd) following a GUID-formatted naming convention typically used by the HOOKEDGE installer chain.
Detects execution or file presence associated with HOOKEDGE/HEADLACE malware. This rule uses a dual-approach: matching known malicious file hashes (SHA256) and monitoring for specific script files (bat, vbs, cmd) following a GUID-formatted naming convention typically used by the HOOKEDGE installer chain.
Detects the deletion of registry keys associated with Windows SafeBoot configuration. Adversaries may delete these keys to disrupt system recovery mechanisms, preventing administrators from booting the system into Safe Mode to diagnose or remove malicious software.
Detects attempts to tamper with or destroy Windows Boot Configuration Data (BCD) using bcdedit.exe to weaken system security policies or registry-based deletion of the BCD store to inhibit system boot and recovery.
Detects the creation or modification of Registry values under 'Image File Execution Options' (IFEO) that register a debugger for common administrative or diagnostic tools (e.g., Task Manager, Registry Editor, PowerShell). This technique can be used by malicious actors like XHOPELESS to intercept, block, or hijack the execution of legitimate tools, often to maintain persistence or impair security analysis.
Detects modifications to the Winlogon Shell or Userinit registry keys. These keys are commonly used by adversaries for persistence to execute malicious binaries or scripts upon user logon.
This rule detects the creation of scheduled tasks using names that masquerade as legitimate update services for Microsoft Edge, OneDrive, or Windows. Adversaries often use these names to hide persistence mechanisms within the Task Scheduler to maintain system access.
Detects the use of living-off-the-land binaries such as mshta.exe, wmic.exe, and rundll32.exe to execute commands or code indirectly. This technique is often used to bypass security restrictions that might prevent the direct execution of common command-line interpreters.
Detects the clearing of Windows event logs using the native 'wevtutil.exe' command or the PowerShell 'Clear-EventLog' cmdlet. This activity is commonly associated with anti-forensic techniques used by threat actors and wiper malware to obstruct incident response efforts and remove traces of malicious activity.
Detects the presence of PostgreSQL logical decoding output plugins (shared libraries) that export the '_PG_init' initialization function and contain strings indicative of unauthorized catalog modification, privilege escalation, or persistence attempts, often associated with PostGREShell-style attack vectors (CVE-2026-6471).
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
Page 389 of 1870


