Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the installation or execution of known remote access tools (RMM) from suspicious parent processes (browsers, archives) or from user-writable directories (Temp, Downloads). This behavior is characteristic of initial access and staging activities performed by ransomware operators or Initial Access Brokers (IABs). The rule excludes known IT-managed deployment paths and signed binaries used by the organization.
Detects the installation or execution of known remote access tools (RMM) from suspicious parent processes (browsers, archives) or from user-writable directories (Temp, Downloads). This behavior is characteristic of initial access and staging activities performed by ransomware operators or Initial Access Brokers (IABs). The rule excludes known IT-managed deployment paths and signed binaries used by the organization.
Detects the creation or modification of Windows Registry RunOnce keys using the value name 'GlobalProtectVPN', intended to execute 'GlobalProtect.exe'. This pattern is associated with malware masquerading as legitimate GlobalProtect VPN software to achieve persistence upon user logon.
Detects anomalous child process execution by Chromium-based browsers (e.g., chrome.exe, msedge.exe, brave.exe). This behavior is indicative of potential exploitation of browser vulnerabilities such as CVE-2026-85046, where a memory corruption vulnerability is leveraged to escape the browser sandbox and execute arbitrary commands via interpreters like cmd.exe or powershell.exe.
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
This rule monitors security event logs for the presence of a specific file hash identified as potentially malicious (d41d8cd98f00b204e9800998ecf8427e). This hash specifically corresponds to an empty file (MD5 checksum of an empty string), often indicating potential obfuscation techniques, failed file writes, or placeholder files used by malicious scripts.
Detects the creation of a Windows Scheduled Task configured with the 'InteractiveToken' LogonType. This configuration is often associated with adversary techniques designed to execute tasks in an interactive user context, potentially to bypass certain security controls or to facilitate the extraction of sensitive tokens or credentials (e.g., PRT cookies).
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
Detects the ESET Remote Administrator (ERAAgent.exe) process loading the 'dpapisvc.dll' module. This behavior is indicative of potential DLL side-loading where an attacker places a malicious DLL with the same name as a legitimate system library in the agent's directory to achieve code execution.
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
Detects instances where WerFault.exe or WerMgr.exe, running with SYSTEM privileges, loads a DLL file from the Windows\System32 directory that was created within 10 minutes of the image load event. This behavior is indicative of potential DLL side-loading or hijack techniques used to achieve privilege escalation.
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
Detects potential credential harvesting or process memory manipulation against browser processes (Chrome or Edge). The rule monitors for unauthorized debugging activity initiated against browser processes (e.g., using flags like DEBUG_PROCESS or specific API calls) and the access of the App-Bound encryption provider symbol, which is often a target for attackers seeking to decrypt browser-stored secrets.
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
Detects the execution of processes named 'ProManager.exe' or 'ProManagerServicedc894.exe', which may be indicative of unauthorized software or potentially malicious activity.
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
Detects the execution of an executable file located within the Windows Temp directory structure via the command prompt (cmd.exe). This pattern is commonly associated with the execution of downloaded payloads, droppers, or staged malware that are moved to temporary directories to evade initial detection.
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
Detects processes other than the official Telegram desktop client accessing sensitive local data files ('key_datas', 'settingss', 'usertag') within the Telegram application directory. This activity is often associated with credential theft or session hijacking.
Page 408 of 1870



