Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,879
6,387
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule performs a two-layer hunt for the ShieldBreak/RoguePlanet (CVE-2026-50656) exploit. Layer 1 detects potential privilege escalation by identifying Windows Error Reporting processes (WerFault, WerFaultSecure, or WerMgr) running as SYSTEM that initiate suspicious child processes like cmd.exe, powershell.exe, or rundll32.exe. Layer 2 identifies the presence of known exploit artifacts including 'ShieldBreak.exe', 'Warden.dll', and the 'eicar_com.zip' test file via process execution or file creation events.
This rule detects cross-process injection techniques, such as OpenProcess, CreateRemoteThread, and memory modifications, specifically targeting 'svchost.exe' instances that do not appear to be hosting critical Windows services. By filtering out known critical services (e.g., RpcSs, DcomLaunch), the rule flags suspicious attempts to inject code into legitimate service host processes to mask malicious activity.
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
This rule detects in-memory patching of critical Windows security functions, specifically AmsiScanBuffer (used by AMSI) and EtwEventWrite (used by ETW). It monitors for suspicious API calls such as VirtualProtect, WriteProcessMemory, NtProtectVirtualMemory, or NtWriteVirtualMemory targeting these specific DLLs (amsi.dll and ntdll.dll), which is a common technique used by malware and offensive security tools to blind endpoint security and logging mechanisms.
Correlates a Sysmon DriverLoad event matching known BTR.sys hashes with a subsequent System-process (PID 4) deletion of specific Defender binaries or WdFilter/WinDefend registry keys within a 10-second window — the definitive Defender self-destruction signature of the kernel primitive.
Detects outbound HTTP traffic indicative of pyCodeVx RAT check-in behavior. The rule identifies communication with ddnsfree.com C2 domains or requests containing the 'pyCodeVx' marker in the URL or User-Agent, coupled with a base64-encoded, fixed-format victim/session ID.
Detects modification of autostart extensibility point (ASEP) in registry. Adversaries may modify these keys to execute malicious code when Office files are opened.
There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive.
Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
There are various legitimate add-ins that also use these keys and this filter list might not be exhaustive.
Thus, it is recommended to review and tune filters for your environment to reduce false positives before deploying to production.
Detects msedge.exe launched headless (--headless / --headless=new) with CDP remote debugging enabled (--remote-debugging-port=), a temp profile directory matching the launcher-edge- naming pattern, and window flags positioning it off-screen (--window-position=-32000,-32000, --window-size=1,1). This combination matches the TWINLOOT implant's technique of spawning a headless Edge instance with a Chrome DevTools Protocol connection, using the browser's authenticated same-origin session to proxy Microsoft Graph API C2 traffic so it blends in with legitimate browser network activity while remaining invisible on-screen. Excludes known browser-automation/CI framework parent processes and the --enable-automation flag to reduce false positives.
references:
- https://detections.ai/inspirations/01a01ade-da64-7718-8281-426118171583
- https://detections.ai/inspirations/01a01ade-d9a6-742d-8e2f-f60b5efce416
- https://detections.ai/inspirations/01a01ade-da04-700d-ba14-769eef28e475
- https://github.com/ontinue-research/threat-intel-iocs/blob/main/Public/2026-07-27-TWINLOOT-IOCs.md
- https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
references:
- https://detections.ai/inspirations/01a01ade-da64-7718-8281-426118171583
- https://detections.ai/inspirations/01a01ade-d9a6-742d-8e2f-f60b5efce416
- https://detections.ai/inspirations/01a01ade-da04-700d-ba14-769eef28e475
- https://github.com/ontinue-research/threat-intel-iocs/blob/main/Public/2026-07-27-TWINLOOT-IOCs.md
- https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet and an policy scope of either Effective, LDAP, or Local.
The DSInternals PowerShell Module exposes several internal features of Active Directory and Azure Active Directory.
These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
These include FIDO2 and NGC key auditing, offline ntds.dit file manipulation, password auditing, DC recovery from IFM backups and password hash calculation.
Correlates the hardcoded BootClean.log creation-then-deletion lifecycle (performed by the System process) with a preceding anomalous or hash-matched BTR.sys driver load within a tight time window, reducing the otherwise high false-positive rate of alerting on the log artifact alone.
Detects creation of an HKCU Run key value whose data references a temp or AppData temp path, consistent with the Windows persistence step of the botking implant after the build-time payload drop.
The following analytic detects Windows Filtering Platform filters that are added and configured to block outbound traffic for known EDR and security agent processes.
Tools such as EDRSilencer abuse WFP to disrupt outbound telemetry from EDR processes, which can bypass detections that only look for the tool process name.
This detection looks for WFP add events with a block action and EDR process names embedded in the hexdump-like Conditions field.
Tools such as EDRSilencer abuse WFP to disrupt outbound telemetry from EDR processes, which can bypass detections that only look for the tool process name.
This detection looks for WFP add events with a block action and EDR process names embedded in the hexdump-like Conditions field.
Detects malicious DLL files attempting to masquerade as legitimate Microsoft Visual C++ runtime libraries (msvcp150.dll or msvcp160.dll) by identifying export markers and internal strings associated with the SynkLoader reflective PE loader.
This rule monitors for the loading of a specific DLL file ('dsp_ippv2_x64.dll') by 'FineReader.exe'. This pattern may be indicative of DLL side-loading or hijacking attempts, where a legitimate application is used to load a malicious library.
This rule monitors for potential privilege escalation or process manipulation by identifying non-system processes that interact with or follow execution patterns associated with MsMpEng.exe (Microsoft Defender) within a short timeframe. It specifically looks for a lower-privileged process triggering an activity related to the Defender service, followed immediately by a system-privileged process on the same device, which may indicate a bypass or injection technique used to gain or abuse system permissions.
Detects additions or modifications to the Registry 'Run' keys in HKEY_CURRENT_USER, which are a common technique used by malware and adversaries to achieve persistence by automatically executing programs upon user logon.
This rule detects a multi-stage attack chain characteristic of the WordlistLoader/Amatera malware. It identifies the sequential occurrence of module unhooking (via CreateToolhelp32Snapshot), ETW bypass (via AddVectoredExceptionHandler), and remote process injection (via WriteProcessMemory, CreateRemoteThread, etc.) originating from the same process within a 15-minute window.
Detects unauthorized, non-browser processes accessing sensitive Chromium-based browser credential files (e.g., 'Local State', 'Login Data', 'Cookies') followed by suspicious outbound network connections. This pattern is characteristic of credential-stealing malware (infostealers) like Amatera, Lumma, and Remus.
Detects PDF documents that impersonate Notion invitation notifications and incorporate multiple redundant/overlapping URI links. This technique is used by the threat actor DOUBLOON DREDGER to facilitate EvilTokens device code harvesting campaigns.
Detects the presence of known malicious Rust crate archive files (arrayref-0.3.10.crate, proc-macro1-*, and related typosquatted package names) in a host's local Cargo registry cache, indicating the compromised dependency was fetched.
Page 446 of 1866







