Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the creation of files within a directory structure matching 'ShieldBreak_' that involve 'BERLIN:' in the file path, specifically when 'ntdll.dll' is present in either the previous filename or the initiating process command line. This pattern is indicative of specific malware behavior involving file manipulation and potential DLL sideloading or obfuscation attempts.
This rule detects file creation and modification events within a specific 'ShieldBreak' directory structure, as well as process execution events where the command line references this directory or contains a specific 'Placeholder created.' string. This pattern is indicative of potential data staging or file-based operations by malicious activity using this naming convention.
Detects instances where processes other than the primary web browsers (Chrome, Brave, Firefox) create, rename, or modify sensitive browser data files like 'Cookies' or 'Login Data'. This behavior is indicative of credential theft or data exfiltration attempts where an adversary is accessing browser-stored information.
Detects the creation of an NTUSER.MAN file followed by an update or creation of a registry run key (Run or RunOnce) on the same device within a 60-minute window. NTUSER.MAN is a mandatory user profile file that, when present, can be used to override user settings and persist malicious configurations or startup entries.
Detects the GoCaracal lightweight implant performing process injection by identifying combinations of remote process memory allocation (VirtualAllocRemoteApiCall), memory writing (WriteProcessMemoryRemoteApiCall), and remote thread creation (CreateRemoteThreadApiCall) associated with specific suspicious filenames. It also monitors command-line activity for injection-related flags.
Detects file creation, modification, or rename activity involving filenames that contain credential related indicators. The detection focuses on common document, spreadsheet, text, PDF, and archive formats that are frequently used to store sensitive authentication material. Such files may represent exposed credentials that could be leveraged by adversaries for credential access, privilege escalation, or lateral movement following endpoint compromise.
Detects the execution of Node.js processes where the command line contains the argument 'parser.js'. This is often used by adversaries to execute JavaScript-based payloads or custom scripts for malicious purposes.
This rule monitors for the execution of Node.js processes involving a file named 'parser.js' and a component or argument referred to as 'ldata'. This behavior is characteristic of specific application workflows, but when observed as a standalone or unusual process, it may indicate unauthorized script execution or the activity of a malicious node-based tool.
Detects the execution of Node.js processes where the command line contains the argument 'parser.js'. This is often used by adversaries to execute JavaScript-based payloads or custom scripts for malicious purposes.
This rule detects the execution of a file named 'report.bin' and correlates it with subsequent network connections originating from the same process. This behavior is indicative of a potential C2 heartbeat or exfiltration activity involving a non-standard or obfuscated executable.
Detects the execution of 'driverquery.exe' to enumerate information about the 'npf.sys' driver (Network Packet Filter), which is associated with Npcap/WinPcap used for packet capture. The rule specifically monitors when this command is launched by non-standard parent processes like 'report.bin' or 'nw.exe', which may indicate malicious reconnaissance or network monitoring tools.
Detects the addition of suspicious file names or known potentially unwanted program artifacts to Windows Run registry keys, often used for persistence. The rule correlates registry modifications with potential installer process activity.
Detects instances where the Mp3tag executable (Mp3tag.exe) loads the DLL 'tak_deco_lib.dll'. This behavior is indicative of potential DLL sideloading or search order hijacking, where a malicious DLL is placed in the application's directory to be loaded by the legitimate process.
Detects behavior observed during BTR Reforged execution by correlating a .sys file staged from a user-writable location with subsequent driver service configuration and kernel driver loading within a short time window. The detection focuses on the behavior rather than specific BTR filenames, hashes, or process names.
Detects installation of a Windows service (System EventID 7045)
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
named after known VirtualBox Guest Additions components (VBoxGuest, VBoxMouse, VBoxSF,
VBoxService, VBoxVideo, VBoxWDDM). Fires when either:
(a) the service binary is registered outside the legitimate VirtualBox install/driver
paths, or
(b) a driver-class component name (VBoxGuest/VBoxMouse/VBoxSF/VBoxVideo/VBoxWDDM) is
registered as a user-mode/own-process service instead of a kernel or file-system
driver — a structural mismatch that cannot occur with the genuine component and is
a strong indicator of name-based masquerading (T1036.005).
Adversaries reuse trusted VirtualBox names to blend malicious persistence into expected
guest-VM/EDR-noise telemetry.
Detects interactive sign-in by an Entra Connect/AAD Connect sync service account (Sync_ prefix), which should only authenticate non-interactively. CISA's red team compromised a hybrid sync account to pivot from on-prem AD into cloud resources.
The following analytic identifies the use of ping commands as a delay or sleep mechanism within batch-style command execution.
It leverages process creation telemetry from Endpoint Detection and Response (EDR) agents and examines process and parent process command-line fields for ping commands that specify a count and are chained with additional commands using command separators or redirection operators.
While execution of the command may generate individual process creation events, such as a separate ping.exe process, this analytic specifically focuses on the original command string passed to a command interpreter, such as cmd.exe /c, that combines the ping-based delay with subsequent command execution.
Adversaries may use ping as an alternative to explicit sleep or timeout commands to introduce execution delays, potentially evading automated analysis, sandboxing, or behavior-based detection.
Because ping is commonly used for legitimate network troubleshooting, findings should be reviewed in the context of the complete command line, parent process, user, and commands executed before or after the delay.
It leverages process creation telemetry from Endpoint Detection and Response (EDR) agents and examines process and parent process command-line fields for ping commands that specify a count and are chained with additional commands using command separators or redirection operators.
While execution of the command may generate individual process creation events, such as a separate ping.exe process, this analytic specifically focuses on the original command string passed to a command interpreter, such as cmd.exe /c, that combines the ping-based delay with subsequent command execution.
Adversaries may use ping as an alternative to explicit sleep or timeout commands to introduce execution delays, potentially evading automated analysis, sandboxing, or behavior-based detection.
Because ping is commonly used for legitimate network troubleshooting, findings should be reviewed in the context of the complete command line, parent process, user, and commands executed before or after the delay.
Detects the execution of JavaScript files using Windows Script Host (wscript.exe or cscript.exe) containing specific obfuscated patterns or indicators typically associated with malicious multi-stage dropper payloads. These patterns are indicative of obfuscated code attempting to evade static analysis and security controls during the initial execution phase.
Detects periodic execution cycles of ERAAgent.exe that involve memory protection changes, characteristic of the SLEEPWALKER malware's XOR-decrypt-execute-reencrypt loop scheduled by a cron-like mechanism.
Detects instances where 'ERAAgent.exe', part of the ESET Remote Administrator agent, loads the 'dpapi.dll' library from a location outside of standard Windows System directories (System32 or SysWOW64). Furthermore, the rule flags this behavior if the loaded 'dpapi.dll' file is either unsigned or contains an untrusted digital signature, which may indicate a malicious DLL side-loading or masquerading attempt to access protected system credentials.
Detects upload requests targeting executable or server-side script file extensions.
Page 444 of 1870







