Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects attempts to access or create copies of the Active Directory 'ntds.dit' database or the Windows Security Account Manager (SAM) registry hive using unauthorized processes. Attackers often target these files to extract credential hashes from Domain Controllers or local systems.
Detects file system operations targeting common user directories and specific file extensions (.bak, .backup, .locked) often associated with data exfiltration, staging, or ransomware activity.
Detects the creation of a Windows Scheduled Task (Event ID 4698) that uses the 'InteractiveToken' LogonType, where the user specified to execute the task is different from the user who registered the task. This behavior is indicative of potential session hijacking or lateral movement techniques, such as those used by tools like 'atexec' or to facilitate PRT (Primary Refresh Token) theft.
Detects attempts to install or modify the 'WMI Provider Host' (WmiPrvSE) service, which is a common technique used by adversaries for persistence or to masquerade malicious activity. The rule monitors process execution, registry modifications, and service installation events specifically targeting this service name.
Detects WinRAR SFX droppers deploying CCProxy proxy server with associated configuration and account files (CCProxy.ini, AccInfo.ini, renamed svchost.exe)
Detects WinRAR SFX droppers deploying CCProxy proxy server with associated configuration and account files (CCProxy.ini, AccInfo.ini, renamed svchost.exe)
Detects WinRAR SFX droppers deploying CCProxy proxy server with associated configuration and account files (CCProxy.ini, AccInfo.ini, renamed svchost.exe)
This rule detects potentially malicious activity involving the manipulation of Windows services using 'sc.exe' to stop or delete services, combined with the forceful termination of 'svchost.exe' processes via 'wmic.exe'. This pattern is often associated with adversaries attempting to disable security tools, logging agents, or other defensive mechanisms on an endpoint.
This rule detects the installation of Windows services that utilize names or display names commonly associated with known malware, potentially mimicking legitimate system services to maintain persistence or evade detection.
Detects SoftEther VPN bridge dropper/installer disguised as svchost.exe with masquerading MixedRealityOpen service, based on install script and dropped files (a.Bat, hamcore.se2, vpn_server.config)
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
Detects the use of the Windows reg.exe utility to copy Registry keys related to Radmin, a legitimate remote access tool that is frequently abused by threat actors for persistence and remote control. The command-line arguments /s and /f indicate a silent, forced copy operation, which is characteristic of script-based configuration tampering.
Detects files referencing malicious implant install paths under C:\Windows\Fonts\web used to blend with legitimate system files
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
Detects the creation of a Windows service named 'WpnUserHost' or the modification of its registry configuration where the binary path does not reside within the System32 directory. This behavior is indicative of a potential attempt to masquerade a malicious service or achieve persistence using a legitimate-sounding service name.
Detects PyInstaller-built UltraVNC installer renamed to svchost.exe and staged for deployment to the non-standard C:\Windows\Fonts\web directory
The following analytic detects a Python process making an outbound network connection during package installation.
Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.
This activity is significant because it allows adversaries to establish a foothold or exfiltrate data without any direct interaction from the victim beyond running `pip install`.
If confirmed malicious, this could indicate a successful software supply chain compromise.
Adversaries can abuse `setup.py` build scripts by leveraging `distutils`/`setuptools` command classes to execute arbitrary code, including network beacons to third-party domains, the moment a malicious Python package is installed.
This activity is significant because it allows adversaries to establish a foothold or exfiltrate data without any direct interaction from the victim beyond running `pip install`.
If confirmed malicious, this could indicate a successful software supply chain compromise.
TeamViewer_Desktop.exe is create during install
Enumerates Active Directory to determine computers that are joined to the domain
Page 427 of 1870



