Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects a Zoom process (zoom.us/zoom.exe/CptHost.exe) writing to the Windows camera/microphone/screen-capture consent-store registry keys while no meeting network activity occurred within 15 minutes before or after, excluding pre-meeting device checks from Zoom Settings — a potential post-exploitation surveillance indicator following ZOOMSDAY RCE.
Detects the ACRStealer BYOVD driver's ungated IOCTL 0x2205c0 being sent to \\.\DCRCVDRV_U by a non-management process, correlated within 2 minutes with termination of a security/EDR process, indicating kernel-level defense evasion via the vulnerable driver.
Detects execution chains where archive utilities (7-Zip, WinRAR) or explorer.exe, when initiated from temporary or download directories, spawn common scripting engines (PowerShell, mshta.exe, cmd.exe, wscript.exe) that contain suspicious network-related or obfuscated command-line indicators.
This rule detects potential command-and-control (C2) activity from the TWINLOOT malware, which utilizes Microsoft Teams TURN relay infrastructure to establish a reverse SOCKS5 tunnel. The detection identifies connections to 'worldaz-msit.relay.teams.microsoft.com' followed immediately by a SOCKS5 handshake pattern (05 01 00), indicating encapsulated tunneling within the relay communication.
Detects GhostTask-style hidden scheduled task persistence associated with the TWINLOOT Python implant framework. Legitimate scheduled tasks always write a security descriptor (SD) value under HKLM\...\Schedule\TaskCache\Tasks\<GUID>\SD alongside the corresponding HKLM\...\Schedule\TaskCache\Tree\<TaskName> entry. GhostTask abuses RegLoadAppKey/offreg.dll to build the TaskCache structure offline, producing a Tree entry and a Tasks\<GUID> key WITHOUT the accompanying SD value. The absence of the SD value combined with presence of the Tree entry is the key differentiator from normal task creation, which always writes SD. This technique is used by TWINLOOT to establish persistence while evading standard registry-event-based detections that rely on the presence of an SD value.
Detects the TWINLOOT Python implant's self-update mechanism, in which a schtasks.exe process is spawned with '/Run' by a pythonw.exe parent process while referencing a reobf.json manifest on the command line, indicating the implant is relaunching itself via a scheduled task after fetching an updated/reobfuscated payload configuration.
This rule detects instances where the Windows Defender Antivirus service (MsMpEng.exe) spawns common command-line shells (cmd.exe, powershell.exe, conhost.exe) while running under the SYSTEM context. This behavior is highly irregular for a security product and is indicative of process injection, exploit payload execution, or anti-tampering bypass attempts.
Detects instances where a host that is not identified as a Domain Controller performs a DRSUAPI 'DRSGetNCChanges' request against another Domain Controller. This pattern is commonly associated with DCSync attacks, where an adversary mimics the Active Directory replication process to extract password hashes.
Detects instances where a host that is not identified as a Domain Controller performs a DRSUAPI 'DRSGetNCChanges' request against another Domain Controller. This pattern is commonly associated with DCSync attacks, where an adversary mimics the Active Directory replication process to extract password hashes.
This rule detects the creation or modification of Registry values within the Windows 'Run' keys that contain the specific value name 'goopdate' and associated data containing the string 'work'. This pattern is indicative of a persistence mechanism used by specific threats to ensure their components, often disguised or related to malicious executable payloads, are launched automatically upon user logon.
Detects the use of curl.exe or curl to communicate with the malicious domain 'i.apee.my.id', initiated by a VS Code integrated terminal process. This behavior is indicative of malicious VS Code extensions exfiltrating data via a hidden terminal session.
Detects the execution of native binaries, the creation/modification of Node-API (.node) files, or the loading of .node modules from Visual Studio Code extensions directories. This behavior is indicative of malicious VS Code extensions attempting to execute arbitrary native code for reconnaissance, persistence, or exfiltration.
This rule detects instances of VS Code, code-server, or associated Node.js processes executing 'git config --get user.email'. This behavior is characteristic of malicious VS Code extensions (specifically 'evil-twin' extensions) attempting to perform developer reconnaissance by harvesting local Git identity information, which can then be exfiltrated.
The following analytic detects creation of DLL files with names associated with phantom DLL hijacking opportunities.
These DLLs are usually absent from standard Windows installations, but legitimate Windows components or services may attempt to load them when they are present in expected search paths such as System32.
Phantom DLL hijacking involves placing a malicious DLL where a legitimate process will search for a non-existent dependency, allowing the attacker-controlled library to execute in that process context.
ShieldBreak is one example where the exploit redirects a privileged Defender-driven write into C:\Windows\System32\phoneinfo.dll and then triggers Windows Error Reporting so wermgr.exe loads the planted DLL at SYSTEM integrity.
If confirmed malicious, this activity can indicate preparation for code execution, persistence, or local privilege escalation through DLL search order hijacking.
These DLLs are usually absent from standard Windows installations, but legitimate Windows components or services may attempt to load them when they are present in expected search paths such as System32.
Phantom DLL hijacking involves placing a malicious DLL where a legitimate process will search for a non-existent dependency, allowing the attacker-controlled library to execute in that process context.
ShieldBreak is one example where the exploit redirects a privileged Defender-driven write into C:\Windows\System32\phoneinfo.dll and then triggers Windows Error Reporting so wermgr.exe loads the planted DLL at SYSTEM integrity.
If confirmed malicious, this activity can indicate preparation for code execution, persistence, or local privilege escalation through DLL search order hijacking.
Detects outbound connections to the known Rust supply-chain C2 infrastructure, plus a lower-confidence rule for the broader Hostwinds range on port 9089.
Detects binaries embedding both the hardcoded AES-128-GCM key 'i am botking' and the embedded RSA-2048 private key used for C2 command authentication
Detects the botking RAT's C2 beacon: HTTPS POST with the 'i am botking' registration marker and form-urlencoded action=check polling, plus associated TLS/DNS indicators.
Detects the presence of known vulnerable drivers (rwdrv.sys and hlpdrv.sys) associated with 'Bring Your Own Vulnerable Driver' (BYOVD) attacks. Adversaries utilize these drivers to gain kernel-level access, allowing them to disable security software, escalate privileges, or maintain persistence.
Detects ClickFix-style clipboard/paste-and-run execution: PowerShell, PowerShell ISE, mshta, or cmd spawned from the Windows Run dialog (explorer.exe/RunMRU) with IEX/Invoke-Expression/DownloadString/FromBase64String or mshta HTTP(S) invocation, consistent with the UNC5142 ClickFix lure delivering the DeviceManager RAT.
Detects processes attempting to interact with multiple browser binaries (chrome.exe or msedge.exe) across different standard application directories within a short time window. This behavior often indicates an adversary or malicious script probing for specific installed browsers to facilitate credential harvesting, configuration dumping, or session hijacking.
Detects outbound C2 connections to known ACRStealer infrastructure IPs specifically from a process already flagged as hollowed/injected (wab.exe, MSBuild.exe, dllhost.exe) via a companion flowbit, rather than flagging all egress from these processes.
Page 457 of 1866






