Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects the termination of specific security-related processes (e.g., antivirus services) shortly after a specific driver, 'ardrv.sys', is loaded on a Windows system. This sequence is characteristic of a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where an adversary loads a signed but vulnerable kernel driver to gain elevated privileges, which they then use to disable or terminate security monitoring processes.
Detects processes attempting to open a handle to the Local Security Authority Subsystem Service (LSASS) process with read-capable access rights (0x1010 or 0x1410). These access rights are commonly associated with credential dumping tools like Mimikatz, which read LSASS process memory to extract credentials. Legitimate system processes such as wininit.exe and services.exe are excluded to reduce noise.
Identifies devices with software versions affected by CVE-2026-45321 or devices running TanStack related packages identified via vulnerability management and software inventory data.
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
Detects ERAAgent.exe performing suspicious dynamic API resolution for functions commonly used by the SLEEPWALKER malware (VirtualProtect, SetSecurityDescriptorDacl, and CryptGenRandom). By resolving these functions at runtime via GetProcAddress rather than including them in the static import table, the malware attempts to evade detection and analysis.
Detects ERAAgent.exe (ESET Remote Administrator Agent) interacting with suspicious named pipes (e.g., mojo, spoolss) and attempts to extract credentials from command line parameters, indicating potential credential dumping or lateral movement techniques using the agent process.
Detects various indicators of Microsoft Connection Manager Profile Installer execution
SynkLoader PhishLocker Behavior
Cortex XDR
Detects indicators of the PhishLocker credential harvester, specifically the loading of fake Microsoft Visual C++ runtime DLLs from non-standard (user-writable) paths and unauthorized access to Windows lock screen images by Python-based processes.
Detects behavioral indicators associated with the ChocoShell malware, a fileless PowerShell-based infostealer. The rule monitors for malicious command-line activity including AMSI bypass, credential theft from Token Broker and WLAN profiles, disabling of Microsoft Defender signatures, and communication with local API endpoints typical of the CornFlake controller.
Correlates email delivery, URL click telemetry, endpoint network connections, and process execution evidence for one or more suspicious URLs or domains.
This query helps analysts identify who received an email containing a target URL, who clicked it, whether the URL was observed on managed endpoints, which devices were involved, and what processes initiated related network or command-line activity.
It is useful for phishing investigations, malicious URL exposure reviews, post-delivery impact checks, campaign scoping, and confirming whether a user interaction led to endpoint activity.
The query uses Microsoft Defender XDR advanced hunting tables including EmailUrlInfo, EmailEvents, UrlClickEvents, DeviceNetworkEvents, and DeviceProcessEvents. Microsoft documents UrlClickEvents as containing Safe Links click information from email messages, Teams, and Office apps, populated by Defender for Office 365.
This query helps analysts identify who received an email containing a target URL, who clicked it, whether the URL was observed on managed endpoints, which devices were involved, and what processes initiated related network or command-line activity.
It is useful for phishing investigations, malicious URL exposure reviews, post-delivery impact checks, campaign scoping, and confirming whether a user interaction led to endpoint activity.
The query uses Microsoft Defender XDR advanced hunting tables including EmailUrlInfo, EmailEvents, UrlClickEvents, DeviceNetworkEvents, and DeviceProcessEvents. Microsoft documents UrlClickEvents as containing Safe Links click information from email messages, Teams, and Office apps, populated by Defender for Office 365.
Detects access to SQL developer tool configuration files (connections.json, product-preferences.xml) followed by a decryption utility, used by CISA's red team to recover cleartext database credentials from a targeted workstation.
Detects the execution of a process named ShieldBreak.exe by monitoring device process events.
This rule detects processes or file activities involving path strings related to Windows Defender shadow scan operations, specifically targeting the 'WD_SHADOW_' and 'WD_SCAN\BERLIN' named object patterns. These artifacts are typically associated with security software internal processes or potential attempts by adversaries to interact with or monitor Windows Defender's scanning activities.
ServiceDll Hijack
Sigma
Detects changes to the "ServiceDLL" value related to a service in the registry.
This is often used as a method of persistence.
This is often used as a method of persistence.
Detects ClickFix-style initial access where a Run-dialog-spawned interpreter (cmd.exe, powershell.exe, mshta.exe, cscript.exe) executes an encoded or obfuscated command line, consistent with clipboard-paste delivery of C2Looper.
Detects mass deletion of files related to backups, archives, or disaster recovery across multiple distinct devices within a short timeframe. This behavior is indicative of an adversary attempting to destroy backup infrastructure to prevent system recovery following a disruptive event such as ransomware deployment.
This rule detects suspicious file downloads initiated by common browsers from a specific remote domain ('reficon.pro') associated with '/vizio.com/'. It enriches this activity by checking for prior beaconing activity to 'stats.us3.org' (often used for Matomo analytics), which may indicate a multi-stage attack where an initial profiling beacon precedes a malicious payload download.
Detects instances where the Google Chrome browser is executed with flags that disable the sandbox security feature, such as --no-sandbox and --allow-no-sandbox-job. This configuration is often used by adversaries to facilitate credential dumping from the browser by bypassing sandbox restrictions that typically prevent unauthorized process memory access.
msiexec.exe running as SYSTEM, spawned by a script/task host, with no installer package.
Procedure is currently being used by Lazarus group in conjunction with CVE-2026-68820
Ref https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
Procedure is currently being used by Lazarus group in conjunction with CVE-2026-68820
Ref https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html
Page 447 of 1870











