Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects potentially malicious memory manipulation and thread execution activity originating from the ERAAgent.exe process. It specifically identifies when ERAAgent.exe calls VirtualProtect or VirtualAlloc to set memory as PAGE_EXECUTE_READWRITE, followed shortly by a CreateThread or CreateRemoteThread operation. This behavior is indicative of process injection or reflective code loading, where an executable image is manually mapped into memory and executed, bypassing traditional file-based detection.
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
Detects periodic execution cycles of ERAAgent.exe that involve memory protection changes, characteristic of the SLEEPWALKER malware's XOR-decrypt-execute-reencrypt loop scheduled by a cron-like mechanism.
Detects instances where processes other than the primary web browsers (Chrome, Brave, Firefox) create, rename, or modify sensitive browser data files like 'Cookies' or 'Login Data'. This behavior is indicative of credential theft or data exfiltration attempts where an adversary is accessing browser-stored information.
Detects the creation of an NTUSER.MAN file followed by an update or creation of a registry run key (Run or RunOnce) on the same device within a 60-minute window. NTUSER.MAN is a mandatory user profile file that, when present, can be used to override user settings and persist malicious configurations or startup entries.
Detects the execution of known GoCaracal malware samples, identified by specific file hashes or staging file paths, occurring in conjunction with low-level keyboard hook installations using SetWindowsHookEx. This behavior is indicative of active keylogging activity.
This rule monitors the Windows Application event log for critical Microsoft SQL Server (MSSQL) events. It detects server crashes, access violations, stack overflows, and high-severity (20+) errors. These events often indicate severe database corruption, underlying system instability, or potential exploitation attempts targeting the database engine.
Detects instances where the SQL Server process (sqlservr.exe) initiates a child process that is a known command-line tool, script interpreter, or utility often used in living-off-the-land attacks, or when a child process is spawned from suspicious directory paths such as AppData, Temp, or Windows\Temp.
This rule monitors for email events where the email is flagged for suspicious properties (SPF/DKIM/DMARC failure, threat categorization) and includes potentially malicious attachments or URLs. It then correlates these suspicious emails with subsequent process execution events on the recipient's endpoint within a 30-minute window, identifying a potential successful execution of a phishing payload.
Detects instances where 'TieringEngineService.exe' or 'MsMpEng.exe' (Windows Defender) create, modify, or rename executable, library, or system files within the 'C:\Windows\System32\' directory. This behavior is highly irregular as these processes should not be authoring binaries in protected system folders, and may indicate process masquerading, unauthorized persistence, or defense evasion.
Detects the loading of registry hives using the 'reg load' command. This technique is often associated with adversary attempts to manipulate the Windows registry, access sensitive data, or establish persistence, particularly when followed by actions executed in the SYSTEM context from the same process lineage.
Detects instances where WerFault.exe or WerMgr.exe, running with SYSTEM privileges, loads a DLL file from the Windows\System32 directory that was created within 10 minutes of the image load event. This behavior is indicative of potential DLL side-loading or hijack techniques used to achieve privilege escalation.
Detects instances where the NW.js (Node-Webkit) framework binaries (nw.exe, node.exe) spawn common command-line interpreters or script-hosting utilities (e.g., cmd.exe, powershell.exe, wscript.exe) while executing associated application files like main.js or nw.pak. This behavior is indicative of potential exploitation of a browser-based application to gain shell access or execute arbitrary code on the host system.
Detects the invocation of the AppInstaller executable to install .msix packages, often used in software installation or malicious delivery scenarios involving application deployment.
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
This rule detects the installation of browser extensions that occur during an idle user session (greater than 7 minutes). This behavior is consistent with automated, remote-driven synthetic input injection, often utilized by malware (e.g., NinjaMare) to install malicious extensions without user consent while the system is unattended.
This rule detects unauthorized modifications to browser search provider settings in the Windows Registry, targeting keys associated with Chrome and Microsoft Edge search configuration. This activity is often indicative of browser hijacking or search engine redirection campaigns, such as the NinjaMare malware.
Detects execution patterns associated with 'NinjaMare' style malware, where a process masquerading as a browser (e.g., tenbrowser.exe, fireflybrowser.exe) performs an external IP geolocation lookup followed by suspicious registry or file modifications indicative of browser hijacking or extension installation within a five-minute window.
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
This rule detects a suspicious sequence of events where a process with a name resembling an updater (AutoUpdate.exe or au.exe) accesses a specific remote configuration file from a herokuapp.com URL, followed by the creation or modification of specific application binaries (e.g., InstaTime.exe, ffmpegsumo.dll). This pattern is indicative of a supply chain compromise or an automated software update hijacking where malicious binaries are staged to replace legitimate application components.
This rule detects the execution of processes or network connections that impersonate 'WhatsApp' or 'Instagram' companion applications. It identifies specific file names and process command lines that mimic these applications, often associated with browser-launched or malicious payloads, and monitors for associated network traffic directed toward suspicious endpoints like herokuapp domains.
Page 431 of 1870
