Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
Detects attempts to modify or disable the Windows Update service (wuauserv) using command-line utilities (sc.exe, cmd.exe, powershell.exe) in a context involving 'LockAppHost.exe'. This pattern is often associated with unauthorized attempts to tamper with security update mechanisms to prevent system patching.
This rule detects file access, creation, modification, or renaming operations involving sensitive files associated with cryptocurrency wallets (Bitcoin, Electrum, ElectrumSV), game account configurations (Battle.net, Steam, Minecraft), and browser-based cookies (Roblox). The rule filters out legitimate process interactions, identifying suspicious activity from unknown or unauthorized applications potentially attempting to exfiltrate credentials or session tokens.
This rule detects file access, creation, modification, or renaming operations involving sensitive files associated with cryptocurrency wallets (Bitcoin, Electrum, ElectrumSV), game account configurations (Battle.net, Steam, Minecraft), and browser-based cookies (Roblox). The rule filters out legitimate process interactions, identifying suspicious activity from unknown or unauthorized applications potentially attempting to exfiltrate credentials or session tokens.
Detects the use of 'schtasks.exe' to disable critical Windows Update or ExploitGuard Malware Removal tasks when initiated by 'LockAppHost.exe'. This behavior is highly irregular, as the LockAppHost process is typically associated with the Windows Lock Screen and should not be modifying security-related scheduled tasks.
Detects the use of 'schtasks.exe' to disable critical Windows Update or ExploitGuard Malware Removal tasks when initiated by 'LockAppHost.exe'. This behavior is highly irregular, as the LockAppHost process is typically associated with the Windows Lock Screen and should not be modifying security-related scheduled tasks.
Detects malicious network connections, file downloads, or process execution associated with the REVSTEALER malware campaign, which utilizes hijacked YouTube channels to distribute fake game-cheat videos that lure users into downloading 'resightloader.exe' from specific malicious domains.
Detects malicious network connections, file downloads, or process execution associated with the REVSTEALER malware campaign, which utilizes hijacked YouTube channels to distribute fake game-cheat videos that lure users into downloading 'resightloader.exe' from specific malicious domains.
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
Detects modifications to the Windows UserInitMprLogonScript registry value. This registry entry allows the execution of a logon script whenever a user logs into the system. Adversaries can abuse this mechanism to achieve persistence by pointing this value to a malicious executable or script, such as 'SoftManager.exe' in this specific detection context.
Detects unauthorized remote write operations (via SMB, Named Pipes, or TCP) to the Windows Certificate Services CertLog directory (C:\Windows\System32\CertLog\). This directory contains sensitive CA database, transaction logs, and checkpoint files. Any modification by a process other than the legitimate certsvc.exe is indicative of potential CA database tampering, malicious log manipulation, or anti-forensics activity.
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
This rule detects potential VNC remote access activity by identifying systems that exhibit both the presence of specific VNC configuration/history files (AccInfo.ini, History.txt) and concurrent network activity on port 10635, which is commonly associated with VNC-like remote access tools.
Page 409 of 1870

