Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects the termination of specific security-related processes (e.g., antivirus services) shortly after a specific driver, 'ardrv.sys', is loaded on a Windows system. This sequence is characteristic of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where an adversary loads a signed but vulnerable kernel driver to gain elevated privileges, which they then use to disable or terminate security monitoring processes.
Detects instances where a Java process spawns a shell (cmd.exe, powershell.exe, sh, or bash) that executes suspicious commands often associated with remote code execution (RCE) patterns like those seen in Log4j exploitation. The rule excludes common Java-based build tools to reduce noise.
This rule detects the presence of files known to be part of the SynkLoader malware delivery chain by matching their SHA256 hashes. It specifically identifies a malicious MSI installer, a Python-based loader (ss.py), and a fake msvcp150.dll runtime file used for DLL side-loading.
Detects the execution of the SSH client (ssh.exe) with remote port forwarding arguments (-R). This technique is commonly used by adversaries to establish a reverse SSH tunnel, allowing them to proxy Remote Desktop Protocol (RDP) traffic from an internal victim machine to an external attacker-controlled server, effectively bypassing perimeter firewall restrictions. This behavior has been observed in various ransomware and C2 campaigns, including Bumblebee and Akira.
Detects the execution of psql.exe to query the Veeam Backup & Replication PostgreSQL database for stored credentials. This pattern is associated with credential theft techniques utilized during ransomware operations (e.g., Bumblebee, Akira) where sensitive configuration or credential data is retrieved and potentially later decrypted via DPAPI.
This rule monitors for email events where the email is flagged for suspicious properties (SPF/DKIM/DMARC failure, threat categorization) and includes potentially malicious attachments or URLs. It then correlates these suspicious emails with subsequent process execution events on the recipient's endpoint within a 30-minute window, identifying a potential successful execution of a phishing payload.
Detects the use of reg.exe to modify a Windows Run registry key to execute a destructive 'format C:' command upon system startup, indicative of wiper-style malware activity.
Detects unauthorized access to Chrome and Microsoft Edge login data files. This behavior is indicative of credential theft, frequently observed in info-stealer malware such as Stealer/1.0, which attempts to extract stored browser credentials for exfiltration.
Detects the use of reg.exe to create persistence via Windows Registry Run or RunOnce keys using specific naming conventions commonly associated with Stealer/1.0 malware (e.g., SystemUpdate, SystemCheck) targeting files located in the Downloads directory.
This rule detects when a .zip archive file is created on a host. The creation of archive files can be a precursor to data exfiltration or a method for adversaries to bundle malicious tools for movement.
This rule detects instances where LockAppHost.exe or a variation of it (likely used as a proxy) initiates processes or command-line arguments that interact with Windows services, scheduled tasks, or Windows Defender configurations. This behavior is indicative of an adversary attempting to disable security features, suppress Windows updates, or manipulate system services to evade detection.
Detects the execution of cmstp.exe with the /au parameter, which is commonly used to install malicious INF files, when initiated by LockAppHost.exe. This pattern is often indicative of an attempt to bypass application control or achieve privilege escalation by leveraging the legitimate Microsoft Connection Manager Profile Installer.
Detects anomalous registry enumeration or modification activities targeting software uninstallation registry keys (Run/Uninstall). By monitoring for multiple subkey accesses by processes not associated with standard software management tools (like MsiExec or explorer), this rule identifies potential reconnaissance or software discovery patterns indicative of malicious activity.
This rule detects the creation of a scheduled task using 'schtasks.exe' where the task name matches commonly abused names such as 'WinUpdate.exe', 'SoftManager.exe', or 'LockAppHost.exe'. These names are frequently used by adversaries to masquerade as legitimate Windows processes to achieve persistence.
This rule detects the addition of specific suspicious executables to Windows Registry run keys. Adversaries use these keys to achieve persistence, ensuring that malicious programs execute automatically upon user logon.
Detects bulk file enumeration/access across multiple users' virtual desktop profile shares via a compromised root DFS drive, which CISA's red team used to read local files of all users regardless of active session.
Detects suspicious executions of 'nslookup.exe' and 'svchost.exe' when triggered by the Windows LockAppHost process. This pattern is indicative of potential process injection or masquerading attempts by malicious actors using legitimate system processes as proxies for unauthorized activity.
This rule detects potential cryptocurrency mining activity where known miner executables (specifically XMRig) or malicious scripts/processes are masquerading as or being spawned by 'LockAppHost.exe' or 'LockAppHost14a02b.exe'. It also monitors for subsequent attempts by these processes to terminate security-related tasks or establish persistence via registry run keys.
This rule detects potential cryptocurrency mining activity where known miner executables (specifically XMRig) or malicious scripts/processes are masquerading as or being spawned by 'LockAppHost.exe' or 'LockAppHost14a02b.exe'. It also monitors for subsequent attempts by these processes to terminate security-related tasks or establish persistence via registry run keys.
This rule detects the use of the Windows Service Control Manager (sc.exe) to create or configure a service named 'TaskHandler'. The rule specifically looks for command lines that reference potentially malicious files like 'F7u00ex.exe' or specific driver/restart patterns often associated with the persistence mechanism of the Spark RAT.
Detects the execution of an executable file located within a randomly-generated, hex-like directory structure directly beneath the %AppData%\Roaming folder. This pattern is characteristic of the GoCaracal malware dropper used by the Dark Caracal threat group to evade detection by hiding executables in paths that mimic temporary or system-generated folder structures.
Page 437 of 1870






