Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects UNC3569/GRAYRABBIT shellcode combining call/pop self-location, PEB InLoadOrderModuleList walk, and the specific XOR-then-ROR8 export-name hashing loop observed in the GRAYRABBIT loader chain, requiring multiple distinctive elements together to reduce false positives on generic shellcode idioms
Detects UNC3569/GRAYRABBIT shellcode combining call/pop self-location, PEB InLoadOrderModuleList walk, and the specific XOR-then-ROR8 export-name hashing loop observed in the GRAYRABBIT loader chain, requiring multiple distinctive elements together to reduce false positives on generic shellcode idioms
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
Detects reconnaissance commands (e.g., file listing, directory enumeration) executed as child processes of the JFrog Artifactory service. This behavior is often associated with the exploitation of Artifactory plugins or misconfigured endpoints that allow arbitrary code execution, enabling an attacker to perform discovery actions.
Detects Rust-compiled executables exhibiting C2-capable characteristics consistent with backdoors dropped on compromised JFrog Artifactory servers
Detects Rust-compiled executables exhibiting C2-capable characteristics consistent with backdoors dropped on compromised JFrog Artifactory servers
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
Detects a specific self-deletion technique used by the GRAYRABBIT loader, which utilizes NTFS Alternate Data Streams (ADS). The malware uses SetFileInformationByHandle with FileRenameInfo to rename the file to an ADS (colon-delimited), followed by FileDispositionInfo to mark the file for deletion upon handle closure, effectively bypassing standard file deletion alerts. This rule is scoped to processes originating from common user-writable or temporary directories while excluding known legitimate software installers.
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
Detects the suspicious execution of cmd.exe with piped stdio handles (indicative of a reverse shell) initiated by non-standard parent processes associated with the GRAYRABBIT malware, correlated with an immediate outbound network connection from the same process.
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
Detects the execution of an unsigned 7z.exe that loads an unsigned 7z.dll from a public, user-writable directory (C:\Users\Public\Documents). The rule specifically looks for the creation of the DLL shortly before it is loaded, indicating potential DLL side-loading to bypass security controls using a renamed or modified archive utility.
This rule detects the use of PowerShell or common command-line network tools (curl, wget) to download or interact with files containing references to WPPConnect or WhatsApp automation JavaScript libraries. It flags activity where the parent process is a common LOLBIN (Living Off the Land Binary) or originates from suspicious locations such as user temporary directories, which is indicative of malicious automated tooling or script execution.
Detects when an attacker tries to disable User Account Control (UAC) notification by tampering with the "UACDisableNotify" value.
UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users.
When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
UAC is a critical security feature in Windows that prevents unauthorized changes to the operating system. It prompts the user for permission or an administrator password before allowing actions that could affect the system's operation or change settings that affect other users.
When "UACDisableNotify" is set to 1, UAC prompts are suppressed.
Detects the installation of common remote access tools (such as TeamViewer, AnyDesk, or ScreenConnect) followed by an external network connection within a 10-minute window, which may indicate unauthorized remote access setup.
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
Page 405 of 1870



