Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
Detects Node.js or Electron processes executing from suspicious paths (e.g., Temp, Roaming) while interacting with web browser credential files or executing commands consistent with automated credential dumping tools.
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
Detects Node.js or Electron processes executing a command to list installed applications while originating from or residing within suspicious, writable directories such as Temp, AppData, or Public folders, which is a common pattern for reconnaissance by malicious software or droppers.
Detects scripts or files referencing the JSCeal loading chain that invokes node.exe with -r preflight.js to decompress and execute a compiled V8 bytecode app.jsc payload
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
This rule detects the presence of 'winpty-agent.exe' or 'winpty.dll' in proximity to 'node.zip' or 'build.zip' files within common user-writable or temporary directories ('AppData\Local\Temp', 'AppData\Roaming', 'ProgramData', 'Users\Public'). This pattern is often associated with the staging and execution of malicious tools or command-line wrappers in non-standard locations, bypassing legitimate application installation directories.
Detects a hardcoded PEM RSA public key embedded alongside JSCeal-specific compiled V8 bytecode obfuscation artifacts, used to encrypt exfiltrated data or C2 communications
Detects the execution of BrowserCore.exe, a native messaging component for web browsers, when combined with command-line redirection (< or >) or specific output file creation (e.g., prt_cookie.txt, formatted_nonce.txt). This behavior is characteristic of an attack designed to extract Primary Refresh Tokens (PRTs) or browser cookies, which can be used to bypass authentication mechanisms.
Detects periodic screen capture activity performed by Node.js or Electron-based processes, correlated with subsequent outbound network connections to public IP addresses within a short timeframe. This behavior is indicative of the JSCeal malware's surveillance and exfiltration module, where local reconnaissance via screenshotting is followed by data transmission.
Detects execution of Electron or Node.js processes attempting to export Telegram sessions, specifically targeting execution paths often used for staging or temporary storage (Temp, Roaming, ProgramData, Public folders).
Detects when a Node.js process initiates a low-level keyboard hook (WH_KEYBOARD_LL or WH_KEYBOARD) while running from common user-writable directories, which may indicate malicious keylogging activity by a suspicious process.
Detects when a Node.js process initiates a low-level keyboard hook (WH_KEYBOARD_LL or WH_KEYBOARD) while running from common user-writable directories, which may indicate malicious keylogging activity by a suspicious process.
Detects anomalous child process execution (e.g., cmd.exe, powershell.exe, whoami) by PaperCut application processes (java.exe, pc-app.exe, PCClient.exe), which is indicative of post-exploitation activity following an authentication bypass and remote code execution chain against PaperCut NG/MF.
Detects anomalous child process creation (e.g., cmd.exe, powershell.exe, rundll32.exe) spawned by the VMware host process 'vmware-vmx.exe'. This behavioral pattern is a high-confidence indicator of potential guest-to-host virtual machine escape, specifically monitoring for activity associated with vulnerabilities like CVE-2026-59346.
This rule detects the execution of processes or network connections that impersonate 'WhatsApp' or 'Instagram' companion applications. It identifies specific file names and process command lines that mimic these applications, often associated with browser-launched or malicious payloads, and monitors for associated network traffic directed toward suspicious endpoints like herokuapp domains.
Detects execution of PowerShell.exe initiated by cplsupport.exe with hidden window styles and non-interactive, no-profile flags, which is often indicative of obfuscated command execution or malicious script activity.
Detects the modification or creation of the 'SealedConfig' value within the 'Software\synapse\Config' registry key, correlated with the deletion of a 'config.toml' file on the same device. This pattern may indicate an adversary tampering with Synapse software configuration or attempting to remove audit/configuration trails.
This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
Page 435 of 1870



