Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Adversaries may communicate using a protocol and port paring that are typically not associated.
For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443.
For example, HTTPS over port 8088(Citation: Symantec Elfin Mar 2019) or port 587(Citation: Fortinet Agent Tesla April 2018) as opposed to the traditional port 443.
Detects suspicious PowerShell invocation command parameters
Remove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
This rule detects the use of the LockAppHost process to execute suspicious commands associated with tampering with security configurations, including Windows Defender settings, service management (sc.exe), and task scheduling. Adversaries may abuse this process to bypass security controls, disable real-time monitoring, or maintain persistence.
Detects the presence of known malicious file hashes associated with the Mini Shai-Hulud supply chain compromise (e.g., malicious npm package artifacts). The rule monitors device file, process, and image load events for SHA256 matches.
The following analytic detects instances where an adversary modifies security permissions of a file or directory using commands like "icacls.exe", "cacls.exe", or "xcacls.exe" with deny options.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions.
This activity is significant as it is commonly used by Advanced Persistent Threats (APTs) and coinminer scripts to evade detection and impede access to critical files.
If confirmed malicious, this could allow attackers to maintain persistence and hinder incident response efforts.
It leverages data from Endpoint Detection and Response (EDR) agents, focusing on process names and command-line executions.
This activity is significant as it is commonly used by Advanced Persistent Threats (APTs) and coinminer scripts to evade detection and impede access to critical files.
If confirmed malicious, this could allow attackers to maintain persistence and hinder incident response efforts.
Detects JNDI lookup patterns associated with Log4Shell (CVE-2021-44228) exploitation attempts.
Detects the creation, modification, or renaming of PHP files within the 'wp-content/uploads' directory of a WordPress installation. This pattern is commonly indicative of an attacker uploading a web shell to maintain persistence or execute arbitrary code on a compromised web server.
Detects instances where base64-encoded PHP code, obfuscated behind a 'data:image/gif;base64' MIME type prefix, is written to the disk as a .php file or initiated by web server processes. This pattern is commonly used in file upload bypass attacks to execute arbitrary code.
This rule detects potential persistence attempts by monitoring for the execution and service installation commands of specific binaries: cplsupport.exe and wtass.exe. The rule triggers if these files are executed directly, invoked with specific command-line arguments (e.g., '--install'), or used in conjunction with the 'sc.exe' utility to create new services, which is a common technique for establishing persistence or privilege escalation.
Detects instances where the process wtass.exe (often associated with specific legacy or third-party enterprise tools) spawns cmd.exe. This pattern is potentially indicative of command-line abuse, where a legitimate application's child process is leveraged to execute shell commands.
Detects execution of PowerShell.exe initiated by cplsupport.exe with hidden window styles and non-interactive, no-profile flags, which is often indicative of obfuscated command execution or malicious script activity.
This rule detects unauthorized modification of the desktop wallpaper registry key to an empty string, typically used for desktop defacement or disruptive activity, followed by a system parameter refresh to apply the changes immediately. It monitors for the use of reg.exe to clear the wallpaper registry value and rundll32.exe to invoke the User32.dll UpdatePerUserSystemParameters function, which forces the Windows shell to refresh desktop settings.
Detects the use of VPN clients, tunneling tools (like Tor, ngrok, plink, and SSH port forwarding), and network proxy configurations on endpoints. The rule monitors for known VPN process execution, network connections to VPN provider domains, unauthorized tunnel protocol activity, and Windows registry-based proxy modifications.
Detects the loading of the somkernl.dll module by 360speedld.exe or SoftupNotify.exe, or the execution of these binaries. These files are associated with 360 Safe/360 Security software components, and this rule monitors for their specific activity patterns, which may be used to identify software presence or potential process hollowing/masquerading attempts involving these legitimate components.
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
Detects the execution of common command-line utilities and tools used to enumerate virtual machines, hypervisors, and cloud instance information. Adversaries may perform this reconnaissance to identify virtualization environments, sandbox targets, or cloud infrastructure configurations.
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
This rule detects potentially malicious command-line activity involving powershell.exe or mshta.exe that is initiated by a web browser process (chrome.exe, msedge.exe, firefox.exe, or iexplore.exe). It monitors for indicators such as encoded commands, usage of Invoke-Expression, download cradles, hidden window flags, and specific known IOCs, correlating these events with recent browser activity to identify potential drive-by download or browser-based exploitation attempts.
Page 424 of 1870






