Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects potential DGA fallback beaconing: repeated lookups (~10 per 5 days) of algorithmically-generated .com domains with a failed-resolution cadence, matching the botking implant's C2 fallback behavior.
Detects a specific Windows PE wrapper associated with the BRIDGEHEAD malware, characterized by a Rust-compiled binary (~22-23MB) with a zeroed-out PE timestamp and a large embedded encrypted payload block.
Detects unauthorized processes accessing browser credential databases (e.g., 'Login Data') used by Google Chrome, Brave, and Microsoft Edge. This activity is a common indicator of credential theft by malicious software.
Detects files with names containing '-EMS' or the specific string 'PO26-EMS134.zip' being created or written to the 'Downloads' directory by common web browsers. This pattern is often associated with phishing campaigns distributing malicious attachments.
Detects installation of unauthorized remote-access/RMM software (AnyDesk, RealVNC, Jump Desktop, Chrome Remote Desktop) outside the normal IT-provisioning window combined with a connection to an unfamiliar external IP, consistent with facilitator-maintained device access in PurpleDelta operations.
This rule detects the creation of a scheduled task where the initiating process is not the standard 'schtasks.exe'. It monitors for activity associated with COM objects (CLSID_TaskScheduler, ITaskService) typically used by applications to interact with the Task Scheduler API programmatically, which is a common technique for persistence or execution in non-standard ways.
Detects the execution of cmd.exe as a child process of the IIS worker process (w3wp.exe) when the worker process is associated with an Exchange application pool. This pattern is indicative of a webshell exploiting an ASPX component to execute arbitrary commands on an Exchange Server.
Detects a sequence of events where a user interacts with a suspected fraudulent CAPTCHA or slider gate on an non-allowlisted domain, followed by interaction with a spoofed Microsoft 365 login page on the same device within 15 minutes. This behavior is characteristic of the Mirage2FA phishing kit, which intercepts credentials and MFA tokens in real-time.
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) modifies registry keys related to Windows network security settings, such as LSA policies, NullSession pipes/shares, or server/workstation auto-sharing. These settings can be manipulated to weaken Windows security posture, potentially facilitating lateral movement or credential access.
Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
This rule monitors process command lines for identifiers related to virtual machine communication interfaces such as 'VMCI', 'AF_VSOCK', 'svm_cid', or 'vm:2'. It specifically targets both the ESET Remote Administrator (ERA) Agent and any other processes utilizing these communication mechanisms, which can be indicators of inter-process communication across virtual machine boundaries or potential hypervisor-related activity.
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
Detects the loading of compression libraries (such as lzma.dll or 7z.dll) by ERAAgent.exe followed by suspicious process or thread activity (e.g., remote thread creation, memory allocation). This pattern is often associated with the staging and execution of malicious payloads in memory.
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
This rule detects suspicious file system activity (creation, modification, or renaming) performed by the ESET Remote Administrator (ERA) Agent process, excluding files within standard ESET installation and ProgramData directories. This behavior may indicate an adversary attempting to leverage the legitimate ERA agent to perform unauthorized file operations or masquerading as the agent.
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
Detects modifications to Windows LSA and LanmanServer registry keys (RestrictAnonymous, NullSessionPipes) in conjunction with ERAAgent.exe process execution, as well as ERAAgent creating named pipes accessible by anonymous logon, which may indicate configuration tampering to facilitate unauthorized access or credential collection.
Detects behavior where the ERAAgent process writes a file to disk and executes that same file shortly after (within 5 minutes). This pattern is consistent with staged payload delivery, decompression, or assembly often observed in malicious activity, specifically referencing SLEEPWALKER malware patterns.
Detects Python processes (python.exe, pythonw.exe, py.exe) executing with high or system integrity levels and interacting with named pipes, a technique often used for inter-process communication, persistence, or process injection.
Page 451 of 1866




