Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects instances where the GlobalProtect VPN client executable spawns a Windows command shell (cmd.exe). This behavior is highly suspicious as a legitimate VPN client typically does not launch interactive shells, and this pattern has been associated with the execution of malicious payloads such as fake MSI installers.
Detects OAuth2 JWT bearer-grant token requests to Google's OAuth endpoint using the attacker-controlled service-account identity and Sheets API scope observed in the fake GlobalProtect campaign
Detects potential DLL side-loading attempts involving GlobalProtect VPN components. The rule identifies the execution of GlobalProtect.exe with specific command-line arguments combined with the presence of suspicious versions of bcrypt.dll or WININET.dll within the same directory, which are characteristic of recent malicious activity involving modified DLL files targeting GlobalProtect environments.
Detects the creation or modification of Windows Registry RunOnce keys using the value name 'GlobalProtectVPN', intended to execute 'GlobalProtect.exe'. This pattern is associated with malware masquerading as legitimate GlobalProtect VPN software to achieve persistence upon user logon.
This rule detects the creation of a scheduled task named 'GlobalProtectVPNUpdate' using schtasks.exe, which has been identified as a technique used to facilitate the execution of malicious payloads masquerading as legitimate GlobalProtect VPN components. It also monitors for the subsequent execution of 'GlobalProtect.exe' when initiated by Windows background services like taskeng.exe or svchost.exe, which is indicative of persistence and unauthorized code execution.
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
Detects the invocation of the AppInstaller executable to install .msix packages, often used in software installation or malicious delivery scenarios involving application deployment.
Detects the execution or presence of files, processes, or paths associated with the 'SnowKiller' malware or tool, as identified by keyword matching in process event logs.
This rule detects the installation of browser extensions that occur during an idle user session (greater than 7 minutes). This behavior is consistent with automated, remote-driven synthetic input injection, often utilized by malware (e.g., NinjaMare) to install malicious extensions without user consent while the system is unattended.
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
This rule detects a suspicious sequence of events where a process with a name resembling an updater (AutoUpdate.exe or au.exe) accesses a specific remote configuration file from a herokuapp.com URL, followed by the creation or modification of specific application binaries (e.g., InstaTime.exe, ffmpegsumo.dll). This pattern is indicative of a supply chain compromise or an automated software update hijacking where malicious binaries are staged to replace legitimate application components.
This rule detects the presence of specific file hashes known to be associated with backdoored software builds, specifically related to recent supply chain compromises affecting South Korean software vendors (e.g., HAProxy builds). It monitors device file events, process initiation, and identity logon events to identify systems that have deployed, executed, or been accessed by these malicious binaries.
Detects access to the SAM registry hive or SAM-related LSA control keys initiated by a process associated with the Avast Sandbox component rather than LSASS or an administrative security tool. The PrettyPrague PoC abuses a vulnerability in Avast Sandbox to dump the SAM database and spawn a SYSTEM shell, so SAM hive reads originating from the sandbox component itself are anomalous.
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
This rule detects the execution of powershell.exe with command-line arguments that utilize 'curl' to download a file from a specific remote IP address (103.86.86.244). This behavior is characteristic of adversaries using built-in Windows tools or redirected utilities to perform ingress tool transfer as part of a malicious payload delivery.
Detects the use of PowerShell to modify Windows Defender security settings by adding exclusion paths or processes. This behavior is indicative of an adversary attempting to whitelist malicious files or processes to evade detection by the antivirus solution.
Detects the use of PowerShell to modify Windows Defender security settings by adding exclusion paths or processes. This behavior is indicative of an adversary attempting to whitelist malicious files or processes to evade detection by the antivirus solution.
Detects instances where PowerShell is used to download an executable named 'svchost.exe' from an external IP address (103.86.86.244). The rule monitors for network connections to this IP, file creation events matching specific download patterns in fonts directories, and direct command-line arguments involving the suspicious IP and file path, indicating potential malware dropper activity.
Page 394 of 1870



