Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the modification of the Print Spooler (Spooler) Windows service configuration via command-line registry utilities (reg.exe or regedit.exe). This activity may indicate an attempt to restore or re-enable the Print Spooler service, which is frequently targeted for disabling as a mitigation strategy against vulnerabilities like PrintNightmare.
Detects potential anti-forensic activities performed by malware, specifically the use of 'attrib.exe' to hide files and 'cmd.exe' with 'del /f /q' to forcibly remove dropped payloads. These actions are common indicators of a cleanup phase in a malware lifecycle to hinder analysis.
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
Detects execution of netsh.exe when launched from unexpected parent processes (tapctl.exe or openvpnserv.exe) from locations other than the standard System32 or SysWOW64 directories. This pattern is indicative of potential malicious activity or persistence via Netsh helper DLLs masquerading or executing via non-standard paths.
Detects instances where OpenVPN service binaries (openvpn.exe or openvpnserv.exe) spawn command-line interpreters (cmd.exe or powershell.exe) with suspicious command-line characters or potentially unbalanced quotes. This behavior may indicate an attempt to leverage OpenVPN for code execution or persistence, often seen in environments where VPN configurations are manipulated to run arbitrary scripts.
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
This rule detects potential malicious activity where a process attempts to communicate over DNS over HTTPS (DoH) using common public resolvers (e.g., Google DNS) while simultaneously establishing persistence via Windows Registry 'Run' keys. It excludes common, legitimate applications known to use DoH, focusing on unexpected processes. The detection relies on correlating network events (DoH to known public resolvers) with registry modification events occurring within a 30-minute window of the network activity.
Detects installation of a Windows service (Security EventID 4697)
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
Detects suspicious file transfer and subsequent execution activity associated with the ScreenConnect (ConnectWise Control) remote access application, which may indicate exploitation of file-transfer vulnerabilities. The rule monitors for ScreenConnect processes dropping executable or script files to disk followed by the spawning of command interpreters to execute those files.
Detects suspicious activity associated with the exploitation of a vulnerability in N-central (CVE-2026-86218). The rule monitors for unauthorized child process spawning by N-central components, creation of files in the application directory consistent with web shells, outbound network connections indicative of command and control, and the creation of new local or service accounts for persistence.
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
This rule identifies potential command and control (C2) activity by correlating DNS over HTTPS (DoH) requests initiated by non-browser or unsigned processes with subsequent network connections to a known malicious C2 domain (gw.proxyvector.cc) within a 15-minute window.
Detects network connection attempts or established connections to a specific remote IP (103.141.13.26) on UDP port 3479. This pattern is often associated with command and control infrastructure or unauthorized data communication.
Detects the creation or modification of specific dropper/loader files and service worker registration within WordPress directory structures (wp-content/plugins, wp-content/themes, wp-content/uploads). These files are often associated with the injection of malicious scripts (e.g., on-chain resolvers) to facilitate drive-by compromises by site visitors.
This rule identifies potential command and control (C2) activity by correlating DNS over HTTPS (DoH) requests initiated by non-browser or unsigned processes with subsequent network connections to a known malicious C2 domain (gw.proxyvector.cc) within a 15-minute window.
Detects suspicious activity associated with the exploitation of a vulnerability in N-central (CVE-2026-86218). The rule monitors for unauthorized child process spawning by N-central components, creation of files in the application directory consistent with web shells, outbound network connections indicative of command and control, and the creation of new local or service accounts for persistence.
Page 433 of 1870



