Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,879
6,387
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects hash-matched BTR.sys driver loads that are validly signed by Microsoft but not initiated by a legitimate Windows Defender platform process (MsMpEng.exe/MpCmdRun.exe or the Defender Platform folder) — indicating the driver is being loaded by an unauthorized process to abuse its kernel-level file/registry operation primitive.
Detects the Rust rustls custom AcceptAll ServerCertVerifier pattern (all three verify methods returning success unconditionally) used by the proc-macro1 payload to bypass TLS certificate validation when fetching its remote payload.
Detects the execution of the QUICAgent backdoor (Windowsupdate.exe) from an AppData folder path. The rule monitors for this specific process name, which has been associated with C2 activity including hostname and username enumeration.
This rule Hunts Microsoft Defender for Endpoint DeviceFileEvents for .aspx/.ashx/.asmx files created by w3wp.exe (the IIS worker process) inside SharePoint-specific directories (wss\VirtualDirectories, Web Server Extensions, TEMPLATE\LAYOUTS, App_Code, App_Web, \bin\) — a classic webshell-drop pattern used once an attacker has already gained code execution on the server. It excludes benign SYSTEM/TrustedInstaller writes of default.aspx/upgrade.aspx to cut noise from normal patching/upgrade activity. This is a post-exploitation signature — it doesn't detect the exploit itself, only the artifact an attacker typically drops afterward.
CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.
Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.
Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
Detects TWINLOOT persistence mechanisms observed in the TWINLOOT Python implant framework, including COM hijacking via a scriptlet (.sct) reference written to the TypeLib registry key for CLSID {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} version 1.1 (win32/win64), and the creation of a Run key value named 'UserExperienceSync' under CurrentVersion\Run for autorun persistence.
Detects PowerShell or pwsh processes spawned from Teams.exe with command-line arguments indicative of remote download and execution (e.g. Invoke-WebRequest, curl, encoded commands, IEX, Invoke-Expression, Expand-Archive of a zip archive). This pattern matches the TWINLOOT campaign's initial access chain, in which victims are lured via fake Microsoft Teams messages (T1566.004) into launching malicious content that triggers PowerShell execution (T1059.001) from within the Teams process, consistent with user execution of a malicious link or file (T1204.002).
Detects anomalous pythonw.exe execution from non-standard installation paths that exhibits a fan-out pattern of network connections to multiple sensitive internal administrative ports (445, 3389, 5985, 22, 1433, 135, 389). This behavior is characteristic of lateral movement using a SOCKS5 proxy tunnel, such as the activity observed in the TWINLOOT campaign where implants pivot through reverse tunnels to access internal resources.
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
Detects instances where the SQL Server process (sqlservr.exe) initiates a child process that is a known command-line tool, script interpreter, or utility often used in living-off-the-land attacks, or when a child process is spawned from suspicious directory paths such as AppData, Temp, or Windows\Temp.
Detects malicious PDF attachments that masquerade as DocuSign remittance advice notifications. These PDFs contain embedded hyperlinks (via /URI or /Link action annotations) designed to redirect users to malicious external sites rather than legitimate DocuSign services, commonly used in phishing campaigns.
The following analytic detects WerMgr.exe (Windows Error Reporting) spawning a child process running at SYSTEM integrity level.
WerMgr.exe normally runs at the integrity level of the reporting user or as a background SYSTEM-owned service that does not launch interactive children.
In the ShieldBreak exploit, WerMgr.exe is manually triggered via the QueueReporting scheduled task and loads an attacker-planted phantom DLL (phoneinfo.dll), which then spawns an elevated shell.
If confirmed malicious, this activity indicates successful local privilege escalation to SYSTEM.
WerMgr.exe normally runs at the integrity level of the reporting user or as a background SYSTEM-owned service that does not launch interactive children.
In the ShieldBreak exploit, WerMgr.exe is manually triggered via the QueueReporting scheduled task and loads an attacker-planted phantom DLL (phoneinfo.dll), which then spawns an elevated shell.
If confirmed malicious, this activity indicates successful local privilege escalation to SYSTEM.
Detects creation of the ':changelist' configuration stream or a feedback (*.dat) stream written onto a .sys driver file itself, distinguishing the abuse pattern (feedback stream on the driver) from legitimate Defender remediation, which writes feedback to a standalone ProgramData path.
Detects SYSTEM processes initiated by non-service user accounts from user-writable locations such as AppData, Temp, Public, ProgramData, and Downloads. This behavior may indicate local privilege escalation and is relevant to post-exploitation activity associated with CVE-2026-68820.
Correlation detection for the PureLogs Stealer / fake Adobe Sign campaign. Fires when 3+ of 6 distinct attacker behaviors (Downloads-sourced 'output_*.js' execution via wscript/cscript, UserinitMprLogonScript persistence pointing at a .js payload, PowerShell fileless env-var payload reconstruction via [System.Environment]::GetEnvironmentVariable+IEX, in-memory .NET Assembly.Load without a disk-based .dll/.exe argument, PowerShell-initiated PixelDrain PNG retrieval, and PowerShell-initiated C2 traffic to vm180012.hosted-by.qwins.co) occur on the same host within a 15-minute window. All network/PowerShell legs are scoped to powershell.exe specifically to avoid flagging benign browser traffic to the legitimate PixelDrain file-sharing service.
Detects a suspicious process chain where 'conhost.exe' with the '--headless' command-line argument spawns 'cmd.exe', which subsequently executes 'powershell.exe'. This pattern is often indicative of automated execution, lateral movement, or malicious script deployment using obfuscated or hidden command-line execution methods.
Detects modifications to the UserInitMprLogonScript registry value that point to suspicious locations or file types (e.g., AppData, .js, .vbs). This registry key is commonly used for persistence by executing a script at user logon. The rule excludes common legitimate paths like NETLOGON or SYSVOL.
Detects file access events targeting the Mozilla Thunderbird profile directory on Windows systems, which may indicate unauthorized collection or theft of local email data, archives, and account configuration files.
Detects file system access to the ProtonVPN local configuration directory. This directory may contain sensitive data, such as cached credentials or session information, which could be targeted by unauthorized actors to facilitate credential theft or session hijacking.
Detects the creation of a registry RunOnce key pointing to an executable named 'vlc.exe' located within a user's temporary directory. This pattern is commonly associated with persistence mechanisms where malware masquerades as a legitimate application to gain execution upon user login.
Detects the deletion of specific staging files (8bfa.zip or 8bfa.bin) within the Windows user's local Temp directory, often associated with adversary cleanup activities after staging data or tools.
Detects known malicious stage-2 payload binaries dropped by the compromised proc-macro1/arrayref Rust supply-chain attack via hash, size, and file-type match.
Page 450 of 1866






