Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
This rule detects attempts to perform process injection techniques (such as creating remote threads or opening processes) targeting the 'ctfmon.exe' process, where the initiating process is not 'ctfmon.exe' itself. This behavior is indicative of potential malicious activity such as reflective code loading or the execution of malware like SparkRAT, which may use this legitimate Windows process to mask its activity.
This rule detects the creation of a Windows scheduled task named 'TaskHandler' using the schtasks.exe utility. The task is configured to execute a specific file, 'F7u00ex.exe', on system startup under the 'NT AUTHORITY\SYSTEM' account. This behavior is indicative of a persistence mechanism, often associated with the Spark RAT malware, which attempts to maintain a foothold on the system with high-level privileges.
This rule detects the use of the Windows Service Control Manager (sc.exe) to create or configure a service named 'TaskHandler'. The rule specifically looks for command lines that reference potentially malicious files like 'F7u00ex.exe' or specific driver/restart patterns often associated with the persistence mechanism of the Spark RAT.
Detects the process 'Acrobatlog.exe' loading the library 'scansts.dll'. This behavior is potentially indicative of DLL injection or side-loading techniques aimed at executing malicious code within the context of a legitimate or masquerading process.
This rule detects the use of the Windows Service Control Manager (sc.exe) to create or configure a service named 'TaskHandler'. The rule specifically looks for command lines that reference potentially malicious files like 'F7u00ex.exe' or specific driver/restart patterns often associated with the persistence mechanism of the Spark RAT.
Detects the execution of the Cortex XDR agent administration tool (Cytool) with the 'protect disable' command line argument. This indicates an attempt to manually disable the security agent's protective features on an endpoint, which is a common technique used by adversaries to impair security controls.
This rule detects multiple occurrences of suspicious Common Log File System (CLFS) error strings within command-line arguments of processes executed on the same device within a 5-minute window. These specific error messages are often indicative of attempts to interact with or exploit vulnerabilities within the Windows CLFS driver.
This rule detects the presence of the file 'eicar_com.zip', which is used in ShieldBreak Proof-of-Concept repositories to validate the bypass or evasion of Windows Defender.
Detects the execution of a process named 'Windowsupdate.exe' from within the user's Local AppData directory. This pattern is indicative of masquerading, where malware attempts to evade detection by mimicking the legitimate Windows Update executable, a technique observed in the Operation QUICSILVER campaign.
Detects repeated network requests to specific JSON files hosted on GitHub (e.g., beacon.json) initiated by processes other than standard web browsers or git. This behavior is indicative of a C2 heartbeat mechanism where an agent periodically retrieves configuration or tasking files from a public repository.
Detects the C2Looper secondary payload dropped as pld.exe under %LocalAppData%, typically staged as a ransomware precursor after backdoor check-in.
Detects C2Looper's remote interactive shell and ShellExecuteW run-and-self-delete command execution, correlated with the c2_out.txt output-capture artifact.
This rule detects the installation of malicious VS Code extensions by monitoring file system writes within common VS Code and VS Code Server extension directories. It specifically alerts on a predefined list of extension namespaces associated with a known malicious coordinated campaign that impersonated legitimate publishers.
Detects the spawning of cmd.exe by processes associated with Microsoft Exchange Server, specifically MSExchangeMailboxReplication.exe or w3wp.exe. This activity is indicative of post-exploitation command execution following an exploit of an Exchange web service or MRSProxy endpoint.
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces)
using either the WinNT or LDAP provider. This is an uncommon method to create user accounts
and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
using either the WinNT or LDAP provider. This is an uncommon method to create user accounts
and may indicate an attempt to evade detection by avoiding more commonly monitored commands
such as "net user", "New-LocalUser" or "New-ADUser".
Aggregates identity, endpoint, cloud application, and messaging telemetry to build a consolidated profile of the devices, clients, applications, and user agents associated with a specific user account.
The query combines Microsoft Entra sign-in data, endpoint logon activity, cloud application events, and email telemetry to provide a high-level overview of a user's activity footprint across the environment.
This query is useful for incident response, account compromise investigations, insider threat investigations, and validating whether a user is accessing services from expected devices and client applications.
The query combines Microsoft Entra sign-in data, endpoint logon activity, cloud application events, and email telemetry to provide a high-level overview of a user's activity footprint across the environment.
This query is useful for incident response, account compromise investigations, insider threat investigations, and validating whether a user is accessing services from expected devices and client applications.
Detects BeaverTail malware deployed via PurpleDelta/PurpleBravo coordination; requires multiple occurrences of the distinctive BeaverTail string to reduce false positives
Detects the execution of various command-line tools (sc, net, powershell, wmic, taskkill, systemctl, launchctl) used to stop or disable system services. This behavior is often associated with adversaries attempting to stop security services, backup agents, or other critical infrastructure for impact, defense evasion, or prior to data destruction.
Detects network activity (DNS queries and TLS connections) to the known command-and-control (C2) domain 'vm180012.hosted-by.qwins.co' associated with the PureLogs Stealer malware.
Detects the BYOVD kill chain for the DCRCVDrv.sys driver: drop to C:\Windows\Temp\, DCRCVDRV_U/LEGACY_DCRCVDRV_U service installation, device open, and IOCTL 0x2205c0 invocation used to terminate security/EDR processes from kernel context.
Detects Amatera Stealer shellcode anti-emulation patching stub using cff_state control-flow flattening and inplace_xor_decrypt reflective loader routine
Page 456 of 1866








