Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the loading of the ProRAM implant DLL (somkernl.dll) when initiated by known sideloading carriers such as 360speedld.exe or SoftupNotify.exe, which are signed utilities frequently abused for this purpose.
Detects potential remote code execution (RCE) attempts targeting vulnerable Sub-Store instances (versions < 2.38.2). The detection identifies web browsers making network connections to local ports (38324) associated with Sub-Store, followed by the spawning of shell processes (cmd, powershell, bash, sh) by the Node.js process hosting the application.
Detection of sc.exe utility adding a new service with special permission which hides that service.
Detects command line containing reference to the "::$index_allocation" stream, which can be used as a technique to prevent access to folders or files from tooling such as "explorer.exe" or "powershell.exe"
This rule detects when PowerShell is used to create or modify a LNK file within the Windows Startup folder. Adversaries often place malicious LNK files in this directory to achieve persistence, ensuring their code executes upon user login.
Detects a pattern of multiple failed authentication attempts (brute force) from an external IP address followed by a successful authentication event on remote access services such as RDP, VPN, or NTLM. The rule filters for non-private IP addresses and flags successes occurring outside of standard business hours.
Detects network requests to unpkg.com or npmmirror for 'index.html' files directly under a package path. This behavior deviates from standard package management usage (which typically fetches tarballs or specific JavaScript modules) and is often associated with adversaries using npm packages as hosting infrastructure for phishing landing pages.
Detects HTML content that mimics Cloudflare CAPTCHA challenges to perform social engineering (ClickFix). The rule specifically identifies the combination of fake CAPTCHA UI text, connection to suspicious domains (DDR patterns), and JavaScript snippets used to fetch and execute secondary payloads or redirects.
This rule detects HTML content containing common indicators of fake Cloudflare 'Verify you are human' CAPTCHA lure pages associated with the Beamglea/ClickFix campaign. These lures often use typosquatted domains or specific API key patterns and include JavaScript code to facilitate the 'copy-and-paste' execution workflow typical of the ClickFix attack technique.
Detects outbound web requests directed at public NPM mirrors and CDNs (unpkg, npmmirror, yarnpkg, jsdelivr) that contain strings matching known malicious package names associated with the 'Beamglea/ClickFix' campaign. This activity is typically indicative of a victim visiting a deceptive Cloudflare CAPTCHA phishing page designed to execute malicious scripts in the browser.
This rule detects network connections or DNS queries to known phishing domains (typosquatted Microsoft login domains), DeadDrop Resolver domains, and suspicious HTML payloads served from common CDN/package hosting sites (e.g., unpkg.com, npmmirror.com, cdn.jsdelivr.net, yarnpkg.com). These patterns are indicative of initial access attempts via phishing or the secondary stage of malware C2 communication.
Detects the registration of a new scheduled task occurring within a network logon session (LogonType 3). This behavior is characteristic of lateral movement techniques where attackers use remote service execution tools (such as Impacket's atexec or PRTremote) to register and execute tasks on a remote host via SMB/RPC. The rule correlates Windows Security Event 4698 (Task creation) with network logon events and validates the action using Task Scheduler operational logs.
Detects the abuse of the Windows ftp.exe utility to execute a local script file provided via the -s flag. Adversaries may leverage this behavior, often triggered by malicious LNK files, to proxy the execution of commands or scripts.
Detects the use of the native Windows utility 'wbadmin.exe' to initiate a backup procedure targeting the Active Directory database (NTDS.dit) and associated registry hives (SYSTEM, SECURITY). This technique is utilized by adversaries for offline credential harvesting by extracting the directory database file. This behavior has been observed in intrusion campaigns involving ransomware actors like Akira.
Detects new Microsoft Teams chats created by external unmanaged Microsoft accounts, identified by a .cid. prefixed UserId, targeting internal users. It is intended to identify possible impersonation, social engineering, or BEC-style activity.
This rule detects potentially malicious activity involving the execution of scripts or the creation of scheduled tasks named 'SysEdgeUpdate'. It monitors for the execution of 'schtasks.exe', 'wscript.exe', or 'cscript.exe' with suspicious command lines related to 'SysEdgeUpdate', and tracks the creation or presence of a 'SysEdgeUpdate.vbs' file within the Microsoft Edge extensions directory, which is a common indicator of persistence mechanisms or malicious extensions.
Detects instances where 'ebook-edit.exe' (a component of the Calibre software) loads a suspicious DLL ('calibre-launcher.dll') or interacts with 'edit2.hlp' files. This pattern may indicate process hollowing, DLL sideloading, or the execution of malicious payloads masquerading as legitimate Calibre application components.
This rule detects cross-process injection techniques, such as OpenProcess, CreateRemoteThread, and memory modifications, specifically targeting 'svchost.exe' instances that do not appear to be hosting critical Windows services. By filtering out known critical services (e.g., RpcSs, DcomLaunch), the rule flags suspicious attempts to inject code into legitimate service host processes to mask malicious activity.
This rule detects the creation of a Windows scheduled task named 'TaskHandler' using the schtasks.exe utility. The task is configured to execute a specific file, 'F7u00ex.exe', on system startup under the 'NT AUTHORITY\SYSTEM' account. This behavior is indicative of a persistence mechanism, often associated with the Spark RAT malware, which attempts to maintain a foothold on the system with high-level privileges.
Detects MSBuild process execution originating from command shells loading obfuscated scripts or inline projects associated with PavinLoader.
This rule detects potential reflective code injection or in-memory loading (fileless) where a DLL or PE image is loaded by mshta.exe or powershell.exe, but the module load event lacks a valid file path on disk (or indicates a device path). This behavior is often associated with the execution of malicious payloads such as the Amatera loader, where payloads are executed directly in memory to evade file-based security detections.
Page 439 of 1870







