Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
Detects the Silver Fox HVNC malware dropper initiating browser instances via the command line to access known malicious C2 domains or infrastructure. The rule specifically monitors for known malicious binaries (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) launching browsers with suspicious command-line parameters associated with this campaign.
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
Detects access to Firefox profile database files (cookies.sqlite, places.sqlite, permissions.sqlite) by suspicious processes that are masquerading as legitimate system maintenance or update utilities. This rule specifically targets known masquerading process names (UpdateAssistant.exe, AppUpdateHelper.exe, SysMaintenance.exe) while excluding the legitimate firefox.exe process and its installation directory.
This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.
This rule detects behavior associated with Hidden Virtual Network Computing (HVNC) implants, which allow remote attackers to interact with a hidden desktop session on a compromised host. The rule specifically looks for processes that perform a sequence of sensitive Windows API calls—CreateDesktopA, SetThreadDesktop, BitBlt/GetDIBits (for screen capture), and SendInput (for input simulation)—when originating from suspicious, unsigned, or non-standard file paths, indicating potential malicious use rather than legitimate software.
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
Detects the creation of a shortcut file (.lnk) in the Windows Startup directory by the 'UpdateAssistant.exe' process. The rule specifically looks for evidence of a masquerading attempt where the shortcut appears to be an application update helper but potentially references or exhibits characteristics of being linked to a notepad execution, suggesting persistence via shortcut file manipulation.
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
This rule detects potentially malicious keylogging activity by identifying binaries named UpdateAssistant.exe or AppUpdateHelper.exe that import keylogging-related APIs (GetAsyncKeyState/GetKeyboardState). To minimize false positives, the rule correlates these findings with suspicious metadata such as unsigned binaries, untrusted signers, or execution from non-standard directories like AppData subfolders or Temp.
Detects attempts to crash or terminate the Kaspersky Antivirus process (avp.exe), as well as associated events indicating the service has been stopped or is encountering abnormal fault conditions. This behavior is indicative of an adversary attempting to disable security software.
Detects anomalous access to specific registry keys under SYSTEM\CurrentControlSet\Control\Lsa that are associated with LSA secrets. The rule monitors for multiple registry operations (set, create, delete) performed by processes other than standard Windows system processes (lsass.exe, svchost.exe, winlogon.exe, services.exe), which is often indicative of credential dumping attempts.
Detects the issuance of certificates using templates associated with the Certificate Request Agent. This is a critical component of the ESC3 attack vector, where an adversary first acquires an Enrollment Agent certificate and subsequently uses it to enroll for certificates on behalf of other privileged users or principals.
Detects Invoke-Mimikatz PowerShell script and alike. Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords.
Detects suspicious PowerShell execution spawned by common development tools or shell environments like node, npm, or WSL. The rule evaluates the process lineage and scores the command line arguments for characteristics commonly used by malicious payloads, such as hidden execution, bypass flags, network download activity, or temporary file access, which are indicative of software supply chain attacks or automated malicious script execution.
Detects the creation or renaming of files with an 'ELAM' (Early Launch Anti-Malware) naming convention pattern outside of standard system driver directories, performed by processes that are not verified Microsoft-signed binaries. This may indicate an attempt to install or masquerade as a boot-start driver for persistence or subverting security controls.
This rule detects the use of raw sockets by 'ERAAgent.exe' by monitoring for socket I/O control (Ioctl) operations involving 'SIO_RCVALL'. This configuration, often associated with promiscuous mode, allows an application to capture all network traffic received by the network interface, a behavior commonly used by network sniffing tools or malicious implants to intercept sensitive data.
This rule detects potentially malicious memory manipulation and thread execution activity originating from the ERAAgent.exe process. It specifically identifies when ERAAgent.exe calls VirtualProtect or VirtualAlloc to set memory as PAGE_EXECUTE_READWRITE, followed shortly by a CreateThread or CreateRemoteThread operation. This behavior is indicative of process injection or reflective code loading, where an executable image is manually mapped into memory and executed, bypassing traditional file-based detection.
Page 422 of 1870




