Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the exact base64-encoded URL fragments used by the malicious proc-macro1 build.rs to obscure the C2 download URL (23.254.165.112:9089) prior to fetching a remote payload.
This rule detects the creation of files with specific names '8bfa.zip' or '8bfa.bin' within the Windows AppData Local Temp directory. This behavior is indicative of a threat actor staging payloads or tools on a compromised system, typically as a precursor to execution or lateral movement.
Detects read access to the Windows Registry keys associated with Outlook profile SMTP passwords. Attackers may attempt to extract these credentials to gain unauthorized access to email accounts.
Detects instances where a non-SYSTEM process attempts to open a handle to winlogon.exe. Since winlogon.exe typically runs as SYSTEM and manages user sessions, unauthorized access to its process handle is often a precursor to credential dumping or token manipulation attacks aimed at escalating privileges to SYSTEM.
This rule detects the creation of a Windows scheduled task named 'TaskHandler' using the schtasks.exe utility. The task is configured to execute a specific file, 'F7u00ex.exe', on system startup under the 'NT AUTHORITY\SYSTEM' account. This behavior is indicative of a persistence mechanism, often associated with the Spark RAT malware, which attempts to maintain a foothold on the system with high-level privileges.
Detects the execution of Chrome or Microsoft Edge with remote debugging enabled (--remote-debugging-port) in a headless configuration (--headless=new). This combination is commonly used by automated scripts, scrapers, or potential malicious activity to interact with the browser remotely, which can be leveraged for data exfiltration, session hijacking, or automated attacks.
This rule monitors for the execution of msiexec.exe with command-line arguments involving 'update_ms.msi' specifically referencing 'Updates Verify' or 'LexSoft Ltd.', which may indicate the installation of potentially unauthorized or malicious software masquerading as legitimate updates.
Detects instances where the Windows Defender antimalware service (MsMpEng.exe) spawns common shell processes (cmd.exe, powershell.exe, pwsh.exe, or conhost.exe) while running under the SYSTEM account. This behavior is highly anomalous and indicative of potential exploitation involving privilege escalation via the Microsoft Defender process.
Detects C2Looper disabling Windows Error Reporting via registry modification to suppress crash dialogs, excluding common enterprise provisioning tools that legitimately configure the same keys.
Detects Active Directory replication events (Event ID 4662) targeting sensitive objects related to replication (e.g., Replication-Get-Changes-All). The rule filters out known Domain Controllers and designated replication service accounts to identify potential DCSync attacks or unauthorized directory replication attempts.
Detects pythonw.exe executing from non-standard paths (ProgramData, AppData, or Temp) while loading netapi32.dll or ntdsapi.dll, consistent with the TWINLOOT implant's recon module performing NetAPI-based enumeration of domain controllers, admins, and domain trusts via DsEnumerateDomainTrusts and related calls, as observed being tasked by operators through the SharePoint dead-drop C2 channel.
Detects hash-matched BTR.sys driver loads that are validly signed by Microsoft but not initiated by a legitimate Windows Defender platform process (MsMpEng.exe/MpCmdRun.exe or the Defender Platform folder) — indicating the driver is being loaded by an unauthorized process to abuse its kernel-level file/registry operation primitive.
Detects the Rust rustls custom AcceptAll ServerCertVerifier pattern (all three verify methods returning success unconditionally) used by the proc-macro1 payload to bypass TLS certificate validation when fetching its remote payload.
Detects the execution of the QUICAgent backdoor (Windowsupdate.exe) from an AppData folder path. The rule monitors for this specific process name, which has been associated with C2 activity including hostname and username enumeration.
This rule Hunts Microsoft Defender for Endpoint DeviceFileEvents for .aspx/.ashx/.asmx files created by w3wp.exe (the IIS worker process) inside SharePoint-specific directories (wss\VirtualDirectories, Web Server Extensions, TEMPLATE\LAYOUTS, App_Code, App_Web, \bin\) — a classic webshell-drop pattern used once an attacker has already gained code execution on the server. It excludes benign SYSTEM/TrustedInstaller writes of default.aspx/upgrade.aspx to cut noise from normal patching/upgrade activity. This is a post-exploitation signature — it doesn't detect the exploit itself, only the artifact an attacker typically drops afterward.
CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.
Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
CVE-2026-63520 An unauthenticated remote-code-execution flaw in SharePoint Server's Business Connectivity Services, caused by unsafe .NET type instantiation, disclosed jointly by Rapid7 and Microsoft. It lets an attacker execute arbitrary code with the privileges of the SharePoint site's service account. It's the second half of a two-part chain — combined with the earlier CVE-2026-55040 (disclosed the prior month), it enables full unauthenticated RCE. As of disclosure there was no public PoC and no observed exploitation, though Microsoft rated it "exploitation more likely," and CVSS attack complexity is high, meaning reliably chaining both CVEs takes real effort.
Since no exploitation artifacts for this CVE chain are public yet, this rule is a generic SharePoint webshell hunt tagged to the CVEs for tracking -- it's not a signature of the BCS exploitation primitive itself.
Detects TWINLOOT persistence mechanisms observed in the TWINLOOT Python implant framework, including COM hijacking via a scriptlet (.sct) reference written to the TypeLib registry key for CLSID {EAB22AC0-30C1-11CF-A7EB-0000C05BAE0B} version 1.1 (win32/win64), and the creation of a Run key value named 'UserExperienceSync' under CurrentVersion\Run for autorun persistence.
Detects PowerShell or pwsh processes spawned from Teams.exe with command-line arguments indicative of remote download and execution (e.g. Invoke-WebRequest, curl, encoded commands, IEX, Invoke-Expression, Expand-Archive of a zip archive). This pattern matches the TWINLOOT campaign's initial access chain, in which victims are lured via fake Microsoft Teams messages (T1566.004) into launching malicious content that triggers PowerShell execution (T1059.001) from within the Teams process, consistent with user execution of a malicious link or file (T1204.002).
Detects anomalous pythonw.exe execution from non-standard installation paths that exhibits a fan-out pattern of network connections to multiple sensitive internal administrative ports (445, 3389, 5985, 22, 1433, 135, 389). This behavior is characteristic of lateral movement using a SOCKS5 proxy tunnel, such as the activity observed in the TWINLOOT campaign where implants pivot through reverse tunnels to access internal resources.
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
trying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create
user accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
Detects instances where the SQL Server process (sqlservr.exe) initiates a child process that is a known command-line tool, script interpreter, or utility often used in living-off-the-land attacks, or when a child process is spawned from suspicious directory paths such as AppData, Temp, or Windows\Temp.
Detects malicious PDF attachments that masquerade as DocuSign remittance advice notifications. These PDFs contain embedded hyperlinks (via /URI or /Link action annotations) designed to redirect users to malicious external sites rather than legitimate DocuSign services, commonly used in phishing campaigns.
Page 453 of 1870







