Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects Java-based Metasploit/Meterpreter payload files (.class/.jar) dropped post-exploitation, as observed following PaperCut RCE exploitation chain
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
This rule detects activity associated with the exploitation of PaperCut vulnerabilities. It looks for connections to known malicious IP addresses, the presence of specific credential harvesting tools, reconnaissance commands (whoami, tasklist) executed by the PaperCut application (pc-app.exe), suspicious PowerShell downloads of AnyDesk, and unauthorized access to PaperCut configuration files or log files containing known exploit strings.
Detects the execution of common discovery commands like 'whoami' combined with system information gathering commands (tasklist, ver, uname) when initiated by an application named 'pc-app.exe'. This pattern is frequently observed during the reconnaissance phase of an attack.
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
Detects the execution of Certipy, an open-source tool used for enumerating and exploiting Active Directory Certificate Services (AD CS). The rule monitors for common command-line arguments used during various stages of AD CS attack lifecycle, including finding misconfigurations, requesting certificates, relaying, and template exploitation.
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
Detects unauthorized processes (e.g., cmd.exe, powershell.exe, node.exe) accessing sensitive web browser files like 'Login Data' or 'Cookies' in common browser directories. This behavior is indicative of credential theft or data exfiltration attempts.
Detects Windows Application Error events where the faulting module is 'nvoglv64.dll'. This is indicative of a crash in the NVIDIA OpenGL/Vulkan user-mode driver, which may be associated with the exploitation of the GreenSection shared-memory corruption vulnerability.
Detects the execution of PowerShell commands that utilize base64-encoded strings, window style arguments for obfuscation, and subsequent decoding to reveal suspicious indicators such as network downloading commands or archive manipulation, indicative of potential fileless malware staging.
Monitors Active Directory Certificate Services (AD CS) for an unusual volume of certificate requests from a single requester within a short timeframe. This behavior is indicative of enumeration or exploitation activity by tools such as Certify or Certipy, which often perform rapid certificate requests to identify vulnerable templates or request certificates for unauthorized identities.
Detects offreg.dll (Windows Offline Registry Library) being loaded by a process running outside the standard System32/SysWOW64 directories and that is not a known Windows registry-management host process, excluding Malwarebytes' own bundled private copy of the DLL. PrettyPrague uses this library to read the SAM/LSA hive and derive boot-key material outside normal registry API paths. Scoped to the loading process's directory and identity rather than any specific PoC binary name.
Detects direct file access attempts to critical Windows registry hive files (SAM, SECURITY, SYSTEM, SOFTWARE) on disk. These files contain sensitive system and credential information, and direct access is frequently used by adversaries to perform offline credential dumping.
This rule detects network connections and DNS queries associated with the QTFY proxy infrastructure, including specific domains, known proxy management system IPs, and suspicious IP ranges. This behavior is indicative of command and control (C2) activity utilizing proxy services to obfuscate traffic.
This rule detects network connections and DNS queries associated with the QTFY proxy infrastructure, including specific domains, known proxy management system IPs, and suspicious IP ranges. This behavior is indicative of command and control (C2) activity utilizing proxy services to obfuscate traffic.
This rule detects network connections and DNS queries associated with the QTFY proxy infrastructure, including specific domains, known proxy management system IPs, and suspicious IP ranges. This behavior is indicative of command and control (C2) activity utilizing proxy services to obfuscate traffic.
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
The detection rule identifies network connections to 'dauntingmoon.online' specifically hitting '/api/verification/init' or '/api/verification/check' paths. It validates that both 'session' and 'link_id' query parameters are present in the request. This pattern is indicative of a specific adversary beaconing or command and control (C2) callback mechanism involving session-based authentication or handshake steps with a remote server.
This rule detects attempts by users to disable or clear command line history logs for shell environments, including PowerShell (e.g., modifying PSReadLine history) and Unix-like shells (e.g., unset HISTFILE, setting HISTSIZE to 0, or disabling history collection). Such actions are frequently performed by adversaries to hinder incident response and forensic analysis by obscuring their post-exploitation activity.
Page 392 of 1870





