Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects instances where Adobe Acrobat or Adobe Reader processes initiate suspicious child processes, such as common interpreters (PowerShell, CMD, WScript, CScript) or binaries (rundll32, browser executables) often used in malicious document-based attacks to achieve initial code execution.
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
This rule monitors network connections for specific domains and URL patterns associated with the 'FlowerStorm' campaign. It flags potential phishing attempts by identifying low-prevalence connections to known malicious infrastructure from browser or PDF reader processes.
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
This rule detects instances where a PDF file located in the Outlook temporary internet cache is opened or accessed, followed shortly (within 3 minutes) by a network request from the device to a Google Sites URL. This behavior is indicative of a phishing attack where an email attachment redirects the user to a malicious site for credential harvesting or malware delivery.
Detects instances where the Kaspersky antivirus process (avp.exe) spawns potentially malicious or administrative binaries like cmd.exe, powershell.exe, or specific artifacts related to 'HardBreacher'. This behavior is highly irregular as antivirus software typically does not initiate these types of processes under high-privilege tokens.
Detects a sequence of events where a PDF file opened from a Microsoft Outlook content directory triggers an immediate subsequent execution of a Microsoft Edge process pointing to a Google Sites URL, or containing suspicious command line arguments often associated with malicious redirection or web-based credential harvesting.
Detects Python processes executing common system and network enumeration tools (e.g., net.exe, tasklist.exe, dsquery, Get-ADUser). This activity is indicative of the SynkLoader system profiler module, used to size the victim environment for ransom-value estimation and lateral movement preparation.
Detects instances where the NW.js (Node-Webkit) framework binaries (nw.exe, node.exe) spawn common command-line interpreters or script-hosting utilities (e.g., cmd.exe, powershell.exe, wscript.exe) while executing associated application files like main.js or nw.pak. This behavior is indicative of potential exploitation of a browser-based application to gain shell access or execute arbitrary code on the host system.
This rule detects unauthorized modifications to browser search provider settings in the Windows Registry, targeting keys associated with Chrome and Microsoft Edge search configuration. This activity is often indicative of browser hijacking or search engine redirection campaigns, such as the NinjaMare malware.
Detects Evil-WinRM / WinRM-fs usage or wsmprovhost.exe-spawned PowerShell tied specifically to bird-agent backdoor artifacts (cplsupport, wtass, config.toml) or encoded/download-cradle command patterns, rather than any WinRM session, reducing noise from routine remote administration.
Detects the execution of known potentially malicious tools cplsupport.exe and wtass.exe with install parameters, or the creation of a Windows service associated with these filenames using sc.exe. This activity is indicative of service-based persistence or malicious software installation.
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
Detects instances where the Windows Remote Management host process (wsmprovhost.exe) is associated with the execution of specific suspicious files (config.toml, cplsupport.exe, or wtass.exe) within a short time window. This activity often indicates post-exploitation behavior or remote execution of secondary tools using WinRM.
Detects modifications to the 'metrics_interval' registry value within the 'Software\SynapseAgent' key. This activity suggests configuration changes to the SynapseAgent, which could indicate tampering with agent telemetry or polling frequency.
This rule detects modifications to Windows Registry persistence keys (Run and RunOnce) associated with specific suspicious filenames ('cplsupport.exe', 'wtass.exe'), as well as modifications to specific Synapse agent configuration registry keys. These patterns are often associated with persistence mechanisms or unauthorized software configuration changes.
This rule monitors DNS queries and network connection events for interactions with a list of domains associated with the Kali365 infrastructure. It flags activity by identifying both direct matches and subdomains associated with 'ssengineers.com' and 'clientengagenow.de', often used in phishing or C2 communications.
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
Detects the use of the Windows 'diskpart' utility combined with a script or command execution containing 'clean all', which performs a destructive multi-pass overwrite of disk data structures to render it irrecoverable. This behavior is typically associated with malicious data destruction or wiping activities.
Detects the execution of vssadmin.exe to delete volume shadow copies or attempts to clear recovery-related directories such as SoftwareDistribution or Windows.old. This behavior is indicative of ransomware or destructive activity aimed at inhibiting system recovery.
Page 413 of 1870



