Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,879
6,387
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
The following analytic identifies the creation of executables or scripts in temporary file paths on Windows systems. It leverages the Endpoint.Filesystem data set to detect files with specific extensions (e.g., .exe, .dll, .ps1) created in temporary directories (e.g., \windows\Temp\, \AppData\Local\Temp\).
This activity can be significant as adversaries often use these paths to evade detection and maintain persistence.
If confirmed malicious, this behavior could allow attackers to execute unauthorized code, escalate privileges, or persist within the environment, posing a significant security threat.
This activity can be significant as adversaries often use these paths to evade detection and maintain persistence.
If confirmed malicious, this behavior could allow attackers to execute unauthorized code, escalate privileges, or persist within the environment, posing a significant security threat.
Detects TWINLOOT's fake lock screen credential harvesting technique, where the implant creates a window using highly unique class names (launcher_black_screen_31337, launcher_fake_lockscreen_view) to simulate a Windows lock screen and then calls GetUserNameExW to capture the logged-on user's credentials without validation, feeding harvested credentials into subsequent lateral movement.
Detects the loading of unsigned .node files.
Adversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack.
.node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code.
This technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.
Adversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack.
.node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code.
This technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.
The following analytic detects mpclient.dll, the Windows Defender client API library, being loaded by a process that is not part of the Windows Defender platform.
mpclient.dll exposes the API surface used to drive on-demand Defender scans (IOAV, MpScan). In the ShieldBreak exploit, the attacker binary loads mpclient.dll directly and calls its scan APIs against an object-manager path in order to trigger a Defender scan against attacker-controlled content as part of a race condition targeting Defender's placeholder-hydration behavior.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
mpclient.dll exposes the API surface used to drive on-demand Defender scans (IOAV, MpScan). In the ShieldBreak exploit, the attacker binary loads mpclient.dll directly and calls its scan APIs against an object-manager path in order to trigger a Defender scan against attacker-controlled content as part of a race condition targeting Defender's placeholder-hydration behavior.
If confirmed malicious, this activity indicates an attempt to weaponize Windows Defender's own scanning pipeline for local privilege escalation.
Detects a Ray raylet, gcs_server, or dashboard process spawning a calculator process (a near-certain PoC/exploit indicator) or a shell child process carrying suspicious network, encoding, or reverse-shell command-line indicators, consistent with post-exploitation of CVE-2025-62593. Known-legitimate pipeline package-install commands are filtered out to reduce noise from normal Ray job workers.
Detects the creation of a scheduled task via the Windows COM interface, a technique used by malware like SynkLoader to bypass command-line monitoring (e.g., schtasks.exe). The rule monitors Windows Security Event IDs 4698 and 4702 for tasks configured to trigger on logon that execute script-based content (Python or PowerShell) from user-writable directories.
This rule monitors for successful certificate enrollments (Event ID 4886 and 4887) using sensitive certificate templates typically reserved for domain controllers or Kerberos authentication. It specifically alerts when these requests are made by user accounts that do not end in '$' (machine accounts) and are not known service accounts like 'CAService', which may indicate unauthorized attempts to obtain high-privilege credentials via AD Certificate Services (AD CS).
Detects Active Directory replication events (Event ID 4662) targeting sensitive objects related to replication (e.g., Replication-Get-Changes-All). The rule filters out known Domain Controllers and designated replication service accounts to identify potential DCSync attacks or unauthorized directory replication attempts.
Detects network requests targeting 'chickplaybox.com', which is associated with a phishing campaign masquerading as the Adobe Sign platform. This rule monitors both cleartext HTTP host headers and TLS SNI fields to identify attempts to access the malicious domain.
Detects PureLogs Stealer payload binaries by identifying specific artifacts including a hardcoded nibble-decoding alphabet, minimal PE imports, and high-entropy sections containing obfuscated Windows API strings like GetProcAddress, kernel32.dll, and ntdll.dll.
The following analytic detects non-Chrome processes accessing the Chrome "Local State" file, which contains critical settings and information. It leverages Windows Security Event logs, specifically event code 4663, to identify this behavior.
This activity is significant because threat actors can exploit this file to extract the encrypted master key used for decrypting saved passwords in Chrome.
If confirmed malicious, this could lead to unauthorized access to sensitive information, posing a severe security risk.
Monitoring this anomaly helps identify potential threats and safeguard browser-stored data.
This activity is significant because threat actors can exploit this file to extract the encrypted master key used for decrypting saved passwords in Chrome.
If confirmed malicious, this could lead to unauthorized access to sensitive information, posing a severe security risk.
Monitoring this anomaly helps identify potential threats and safeguard browser-stored data.
System File Execution Location Anomaly
Cortex XDR
Detects Windows system binaries and commonly abused native LOLBins executing from outside their expected system directories, indicating a renamed, relocated, or imposter copy consistent with masquerading, DLL side-loading staging, or process-name spoofing.
Detects WordlistLoader binaries containing the decode-and-execute routine that reconstructs shellcode via a wordlist mapping or UUID string array, then marks it RWX before invoking the entry point
Detects unexpected child processes spawned by Rust build tools (cargo/rustc) that initiate network connections during build processes. This rule specifically monitors for instances where the build process performs network-related activities associated with build scripts (build.rs) or cargo build commands, which may indicate malicious dependency injection or build-time exfiltration.
This rule detects PowerShell processes performing file downloads using common commands (such as Invoke-WebRequest, BITS, or Certutil) and saving or targeting files within user-profile specific directories (AppData). This behavior is often indicative of an adversary staging malicious tools or payloads in a writeable user directory.
This rule detects the execution of 'cmd.exe' with specific arguments 'start /max' used to open a file named 'TrainingAnnouncement.pdf'. This pattern is associated with Operation QUICSILVER, where attackers use this specific command line invocation to masquerade a malicious process or backdoor installation as a benign document opening event.
This rule detects a suspicious sequence of activities that potentially indicates an attempt to exploit Common Log File System (CLFS) vulnerabilities or manipulate cloud filter drivers for privilege escalation. The rule monitors for a correlation between Registry modifications involving Cloud Filter settings (HKLM\SYSTEM\CurrentControlSet\Services\CldFlt) and the creation or modification of specific CLFS-related files (.blf, .blf2, .regtrans-ms) occurring within a 10-minute window, with an optional check for symbolic link manipulation (NtCreateSymbolicLinkObject).
This rule detects PowerShell commands that programmatically create a Windows shortcut (.lnk file) targeting a startup folder or mimicking Windows update processes. This behavior is indicative of an adversary attempting to establish persistence by creating a shortcut that executes a malicious script or binary upon user login or system startup, often associated with the QUICSILVER campaign.
Detects an Exchange server initiating outbound SMB (port 445) connections to non-private (external) IP addresses. This behavior is highly characteristic of PetitPotam (MS-EFSR) coercion, where an attacker forces the server to authenticate to an external, attacker-controlled UNC path to capture NTLM authentication credentials or relay them to other network resources.
Detects execution of pythonw.exe (windowless Python) with the LAUNCHER_BG_CHILD=1 environment marker present on the command line alongside TWINLOOT-specific staging marker filenames (.agent.lock, .vendor.ok, .vendor.stamp, .reobf.manifest, client_id.txt). TWINLOOT is a modular Python implant that relaunches itself windowlessly via pythonw.exe, extracts a vendor ZIP, and uses these marker files to track staging state during its bootstrap and PyArmor-protected launcher stages, while abusing Microsoft 365/Azure services for C2.
Detects creation of a mandatory profile hive (NTUSER.MAN) matching the size produced by the RegLoadAppKeyW -> ORCreateKey/ORSetValue/ORSaveHive offreg.dll API sequence used to forge an offline registry hive for persistence, as observed with the TWINLOOT Python implant. TWINLOOT builds the offline hive via offreg.dll (RegLoadAppKeyW, ORCreateKey, ORSetValue, ORSaveHive) with Run key or COM hijack values baked in, then writes it to %USERPROFILE%\NTUSER.MAN so Windows loads it in preference to NTUSER.DAT at the next user logon, achieving persistence with no registry events, no admin privileges, and no visibility to standard tooling. Tightened to exclude the process image when it is a known legitimate profile-management or provisioning tool (USMT, SCCM, Intune Management Extension) that also uses offreg.dll to build NTUSER.MAN during normal mandatory/roaming profile deployment.
Page 452 of 1866









