Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
Detects an HTTP GET request to 'dl.php' containing an 'f' parameter (target file) and an 'k' parameter (access token), followed by a response body starting with the 'MZ' header, indicating the successful download of a Windows PE executable as part of a potential phishing campaign stage-2 payload delivery.
Detects PE binaries masquerading as Microsoft's Windows Update Assistant via forged VersionInfo metadata combined with an unsigned or invalid/unverified digital signature, associated with HVNC backdoor delivery
Detects PE binaries masquerading as Microsoft's Windows Update Assistant via forged VersionInfo metadata combined with an unsigned or invalid/unverified digital signature, associated with HVNC backdoor delivery
Detects the malicious NFe-themed ZIP dropper MOTOROLA_MOB_COM_NFe_2026-07-16_21781624.zip by known hash and archive structure
Detects the malicious NFe-themed ZIP dropper MOTOROLA_MOB_COM_NFe_2026-07-16_21781624.zip by known hash and archive structure
Detects HVNC final payload masquerading as Windows Update Assistant, combining Firefox credential theft strings, hardcoded AV process names, and XOR-encoded C2 host configuration
Detects HVNC final payload masquerading as Windows Update Assistant, combining Firefox credential theft strings, hardcoded AV process names, and XOR-encoded C2 host configuration
Detects the execution of known Windows update-related binaries (UpdateAssistant.exe or AppUpdateHelper.exe) from non-standard, suspicious locations within AppData directories. This behavior is indicative of masquerading, where an adversary attempts to blend in by using a legitimate process name from an unexpected path.
This rule detects suspicious PowerShell execution that attempts to download files from the internet using the Invoke-WebRequest cmdlet. It specifically looks for PowerShell processes launched with hidden and execution policy bypass flags, coupled with specific hardcoded malicious URL patterns associated with a known campaign (NotaFiscal/nfe_valid_access_key_2026_secure).
This rule detects suspicious PowerShell execution that attempts to download files from the internet using the Invoke-WebRequest cmdlet. It specifically looks for PowerShell processes launched with hidden and execution policy bypass flags, coupled with specific hardcoded malicious URL patterns associated with a known campaign (NotaFiscal/nfe_valid_access_key_2026_secure).
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
Detects the creation of specific mutex objects ('AppUpdateHelper' or 'WinSvc') commonly associated with Hidden VNC (hVNC) backdoors. These mutexes are used by the malware to ensure only one instance is running on the host, and the regex pattern targets the specific naming convention (including a hex suffix) utilized by these threats.
Page 421 of 1870
