Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects the use of the Windows 'copy /b' command to reconstruct an executable file (named Windowsupdate.exe) by concatenating two separate files ('header.doc' and 'body.doc'). This behavior is consistent with file-based reconstruction techniques used to bypass security controls by splitting payloads into seemingly benign components.
Detects activity (opens, reads, or writes) involving the Windows Registry key associated with Chrome's App Paths. Modifying this key is a common method for achieving persistence or hijacking the execution path of the Chrome browser.
This rule detects browser-based runtime evaluations that utilize WebRTC's RTCPeerConnection and createDataChannel APIs, often indicative of an adversary attempting to establish a covert command-and-control (C2) channel directly from a compromised browser session.
Detects instances of Chrome or Edge browsers initiating a network connection to the localhost (loopback) while executing commands associated with the Chrome DevTools Protocol, specifically targeting Page.setBypassCSP. This behavior is indicative of an adversary attempting to disable Content Security Policy (CSP) protections, often as part of a browser-based attack or malicious extension activity using remote debugging features.
Detects the presence of Afd4Eop12_x64.dll or the execution of command lines referencing specific exploit indicators such as 'initialize_afd_npfs_exploit' or 'enable_god_mode', often associated with local privilege escalation exploits leveraging kernel vulnerabilities.
The following analytic detects a process enabling the "SeDebugPrivilege" privilege token. It leverages Windows Security Event Logs with EventCode 4703, filtering out common legitimate processes. This activity is significant because SeDebugPrivilege allows a process to inspect and modify the memory of other processes, potentially leading to credential dumping or code injection. If confirmed malicious, an attacker could gain extensive control over system processes, enabling them to escalate privileges, persist in the environment, or access sensitive information.
Detects a victim's WhatsApp Web session being abused to automatically propagate ClickFix lure links to contacts, correlated with recent infection indicators.
Detects AutoIt3.exe launched with a .a3x script argument from a %TEMP%\IXP* self-extraction directory, spawned by WEXTRACT.EXE — the ACRStealer first-stage execution chain (setup_patched.exe IExpress self-extractor deploying an encrypted AutoIt payload).
Detects self-deletion of ACRStealer's first-stage payload artifacts (Proper.a3x / BrowserMetrics) by the same process that recently created a persistence Run key or dropped follow-on files, indicating anti-forensic cleanup after installation.
Detects OptiDrive.exe sweeping multiple browser credential/cookie store files (Local State, Login Data, Cookies, History) across at least 3 distinct files within a 2-minute window, consistent with ACRStealer's browser credential harvesting.
Windows AD User Added to Monitored Group
Cortex XDR
Detects Windows Security events (Event IDs 4728 and 4756) where a member is added to a sensitive or privileged Active Directory domain global or universal security group. The rule compares the target group against a locally maintained inventory of monitored groups to identify potential unauthorized privilege escalation or persistence.
This rule detects a multi-stage attack pattern associated with Akira ransomware, including AD enumeration using PowerShell, data staging with WinRAR, S3 exfiltration via s5cmd, AnyDesk service installation, registry manipulation for persistence via Safe Mode, and boot configuration changes to facilitate EDR bypass. It also incorporates detection for specific IOCs like attacker jump host RDP connections and malicious file hashes.
Detects modifications to Windows user accounts where the 'Password Never Expires' flag is enabled. This modification, often represented by the DONT_EXPIRE_PASSWORD userAccountControl flag (Event ID 4738), may indicate an attempt to establish persistence or weaken credential lifecycle security by bypassing password rotation requirements.
This rule detects attempts to manipulate process access tokens using the Windows 'SetTokenInformation' API. Specifically, it monitors for adjustments to token privileges or integrity levels, or the presence of 'Untrusted' markers. These behaviors are often indicative of an adversary attempting to bypass Windows access controls, perform token manipulation, or conduct privilege escalation.
Detects the loading of known vulnerable drivers (BYOVD - Bring Your Own Vulnerable Driver) by cross-referencing Sysmon Event ID 6 (Driver Loaded) image hashes with the LOLDrivers.io project database. This technique is often used by adversaries to elevate privileges to kernel mode by exploiting vulnerabilities within signed, legitimate drivers.
Detects the backdoor's put-command file-drop evasion: RtkNGUI64.exe creates tempcache.tmp then renames it to the target path before patching the corrupted MZ header bytes.
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
This rule detects potentially malicious process injection activities (CreateRemoteThreadApiCall, ProcessInjection, OpenProcessApiCall) targeting the Volume Shadow Copy Service process (vssvc.exe). It monitors for interactions originating from processes other than legitimate system processes (svchost.exe, services.exe) or vssadmin.exe, which is commonly associated with Volume Shadow Copy manipulation. Such activity often indicates attempts by malware or attackers to inject code into a critical system process to gain persistence, escalate privileges, or evade detection.
This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
Page 455 of 1866





