Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
Detects the GoCaracal lightweight implant performing process injection by identifying combinations of remote process memory allocation (VirtualAllocRemoteApiCall), memory writing (WriteProcessMemoryRemoteApiCall), and remote thread creation (CreateRemoteThreadApiCall) associated with specific suspicious filenames. It also monitors command-line activity for injection-related flags.
This rule monitors for active reconnaissance or scanning behavior by detecting a single source IP interacting with a high number of distinct ports/hosts within a short time frame (NetworkScan) or accessing a high number of distinct URI paths/404 errors (WebContentScan).
This rule monitors web server logs (IIS, W3C, and Azure Application Gateway) for incoming traffic that matches known malicious or automated vulnerability scanners, as well as requests for common system fingerprinting paths (such as /server-status or /.git/config). The rule aggregates these hits by source IP address to identify potential active reconnaissance or vulnerability scanning attempts.
This rule monitors for web server exploit attempts (indicated by patterns like JNDI lookups or SQL injection sequences in URI/cookie data) that correlate with a surge in server-side errors (400+ status codes) and subsequent anomalous process creation or outbound network connections from the web server process.
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
Detects a specific evasion behavior associated with the NinjaMare malware, where a process idles for at least 7 minutes before moving its window to off-screen coordinates during automated mouse or keystroke input, followed by restoring the window to its original position.
Detects modifications to the PostgreSQL configuration file 'pg_hba.conf' closely followed by a reload command (via pg_ctl or postgres processes). This behavior is indicative of an attacker attempting to modify authentication or connection access controls for a database.
This rule detects potentially malicious modifications to PostgreSQL configuration files or the creation of new library files (.so or .dll) by the PostgreSQL service process. It also flags when the PostgreSQL service process is initiated with command-line arguments referencing 'shared_preload_libraries', which can be abused to load arbitrary code or malicious extensions into the database engine.
This rule detects potential persistence mechanisms in a PostgreSQL database by identifying the creation of a new shared library file (e.g., .so or .dll) within PostgreSQL plugin directories, followed by a modification to the PostgreSQL configuration files (postgresql.conf or postgresql.auto.conf) within a short 30-minute window. This behavior is indicative of an attacker registering a malicious shared library to be loaded upon database startup, a technique associated with PostGREShell-style post-exploitation.
Detects network activity associated with the CurlRAT malware during its beaconing phase. The rule monitors for process command line arguments containing 'writeservice_info' or 'atd_get_system_info', which indicate the collection of system information, and correlates this with network connections that potentially transmit a ~10KB data payload characteristic of its check-in mechanism.
Detects suspicious execution of PowerShell or Mshta spawned from Explorer.exe. It looks for specific malicious indicators including references to known malicious domains, PowerShell encoding flags, hidden window arguments, or Mshta HTTP requests, which are common patterns for fileless malware or dropper execution.
This rule detects the use of 'mshta.exe' to execute a file from a remote location by inspecting the command line for 'http' protocols and a specific suspicious domain. Adversaries often abuse mshta.exe to proxy the execution of malicious HTML Application (HTA) files or scripts to bypass security controls.
Detects processes that access sensitive browser credential or cookie files (e.g., Login Data, Cookies) followed by network activity within a 10-minute window, which is a common behavior pattern of information-stealing malware such as Amatera or ACR Stealer.
Detects modifications to the Windows Registry that disable Microsoft Defender Tamper Protection. Tamper Protection is a security feature that prevents malicious changes to security settings, including the disabling of antivirus and real-time monitoring.
This rule detects potentially malicious command-line activity involving powershell.exe or mshta.exe that is initiated by a web browser process (chrome.exe, msedge.exe, firefox.exe, or iexplore.exe). It monitors for indicators such as encoded commands, usage of Invoke-Expression, download cradles, hidden window flags, and specific known IOCs, correlating these events with recent browser activity to identify potential drive-by download or browser-based exploitation attempts.
Detects network requests to unpkg.com or npmmirror for 'index.html' files directly under a package path. This behavior deviates from standard package management usage (which typically fetches tarballs or specific JavaScript modules) and is often associated with adversaries using npm packages as hosting infrastructure for phishing landing pages.
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
Page 410 of 1866
