Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,878
6,387
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the full process-hollowing sequence (suspended process creation, SetThreadContext, ResumeThread) executed against the same target PID for wab.exe or MSBuild.exe within a short window — the ACRStealer campaign's injection technique.
Detects a non-browser process reading browser session-cookie databases or 2FA/authenticator extension local storage across 200+ targeted apps, consistent with OnyxC2's MFA-bypass and account-takeover capability.
Detects DNS resolution, network connections, or email-embedded URLs matching known JWR phishing framework hosting domains and IP addresses, including banking/government/logistics brand-impersonation lookalikes and smishing-delivered typosquats.
The following analytic detects the creation of a Python site hook file (`sitecustomize.py` or `usercustomize.py`) within a `site-packages`/`dist-packages` directory in conjunction with a package installation process.
Python's `site` module loads these hooks from directories on `sys.path` before Python is executed.
If an adversary manipulates or plants one of these files, they can hijack the Python environment and execute their payload with every Python invocation, achieving persistence on the victim endpoint.
The VIPERTUNNEL backdoor was reported to abuse site hooks in order to import and trigger DLL execution.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host.
Python's `site` module loads these hooks from directories on `sys.path` before Python is executed.
If an adversary manipulates or plants one of these files, they can hijack the Python environment and execute their payload with every Python invocation, achieving persistence on the victim endpoint.
The VIPERTUNNEL backdoor was reported to abuse site hooks in order to import and trigger DLL execution.
If confirmed malicious, this could result in arbitrary code execution every time Python is invoked on the compromised host.
This rule detects the creation or modification of suspicious files (extensions associated with web shells or modules, such as .aspx, .ashx, .asmx, .dll, or .config) within common Microsoft IIS and Exchange web directories. It correlates these file events with process activity initiated by common web server or management processes (e.g., w3wp.exe, powershell.exe) and filters out trusted files (Microsoft-signed), known administrative update activity, and files with a broader footprint in the environment to identify potentially malicious, low-prevalence artifacts.
Detects persistence established via a Run registry key named 'Rapid' or 'TIEmounter' pointing to C:\ProgramData\Rapid\creator-ws.exe, correlated with the corresponding process launch, matching ACRStealer's second-stage payload persistence mechanism.
The following analytic detects the use of net.exe or net1.exe to configure the Windows maximum password age policy as unlimited.
It leverages process creation telemetry from Endpoint Detection and Response (EDR) agents and identifies executions of the `net accounts` command using the `/maxpwage:unlimited` option.
When specified, Windows configures the maximum password age with an unlimited value, effectively preventing passwords governed by the affected password policy from expiring.
This behavior is significant because an adversary may modify password expiration settings to weaken credential security controls and maintain access to compromised accounts for an extended period.
If confirmed malicious, this activity may indicate an attempt to establish or maintain persistence by preventing expected password rotation from invalidating credentials under the affected password policy.
It leverages process creation telemetry from Endpoint Detection and Response (EDR) agents and identifies executions of the `net accounts` command using the `/maxpwage:unlimited` option.
When specified, Windows configures the maximum password age with an unlimited value, effectively preventing passwords governed by the affected password policy from expiring.
This behavior is significant because an adversary may modify password expiration settings to weaken credential security controls and maintain access to compromised accounts for an extended period.
If confirmed malicious, this activity may indicate an attempt to establish or maintain persistence by preventing expected password rotation from invalidating credentials under the affected password policy.
Detects the temporary enablement of the UseLogonCredential registry value by setting it to 1, followed by a subsequent reversion to 0 on the same host. This pattern is indicative of a deliberate 'hit-and-run' attempt to force the WDigest security package to store plaintext credentials in memory for harvesting.
This rule monitors for suspicious activity involving the OneDrive directory, specifically the file 'wtsapi32.dll'. It triggers when this DLL file is created, modified, or renamed within the OneDrive folder, followed by the termination of the OneDrive process, and subsequent loading of the same DLL file by that process. This pattern is indicative of a DLL side-loading attack where a legitimate application (OneDrive) is used to load a malicious DLL.
Detects the execution of commands 'ls' or 'drives' via command line, which are often used by threat actors for reconnaissance and file/directory enumeration on a compromised host.
Detects the presence of the BRIDGEHEAD malware based on its unique Rust-compiled implementation of ChaCha20, specifically identifying a non-standard initialization string and a known hash associated with a decrypted in-memory payload.
Detects the download or presence of the BRIDGEHEAD malware payload (main.exe), specifically the version hosted on GitHub release infrastructure associated with the BRIDGEHEAD npm typosquatting campaign.
This rule detects the creation or modification of the 'goopdate' registry value under the HKCU\Software\Microsoft\Windows\CurrentVersion\Run path. This technique is used to achieve persistence by executing specified files (e.g., Sang.exe or defender.exe with the 'work' parameter) upon user logon.
Suspicious Discovery Command Execution
Cortex XDR
Detects the execution of common command-line utilities frequently used by adversaries for system, network, and account discovery after gaining initial access to a host.
This rule detects malicious activity associated with the RtkNGUI64.exe backdoor, which masquerades as a legitimate Realtek Audio process. It identifies when this process spawns cmd.exe for command execution or interacts with 'tempcache.tmp' files, indicating potential C2 tasking and persistence via WMI event consumers.
Detects the StopAndProtect two-stage PowerShell chain: stage 1 downloads/executes stage 2, which reflectively loads a base64-encoded .NET assembly and invokes an Execute method.
Detects the invocation of the Windows Error Reporting service (WerFault.exe) where the command line arguments reference Zoom-related processes (Zoom.exe, CptHost.exe, or zoom.us). This behavior is often indicative of an abnormal application crash, which may be associated with memory corruption exploitation attempts against the Zoom client.
Detects instances where a user account requests or enrolls a certificate from Active Directory Certificate Services (AD CS) that is associated with a computer account (SID). This behavior, specifically when the requester is not the computer account itself, is a known indicator of potential AD CS abuse, such as certificate theft or impersonation techniques.
Detects a suspicious pattern associated with the SLEEPWALKER technique, involving multiple memory write operations followed by a memory protection change within an ERAAgent.exe process. This behavior suggests code injection or dynamic code loading within a process.
Detects instances where the ESET Remote Administrator Agent (ERAAgent.exe) terminates shortly after loading the Data Protection API service (dpapisvc.dll). This pattern may indicate an attempt to interact with or disrupt DPAPI services, potentially to facilitate credential dumping or sensitive data access.
Detects the ESET Management Agent (ERAAgent.exe) initiating outbound network connections using non-standard socket families, specifically AF_VSOCK (virtual socket) or VMCI (Virtual Machine Communication Interface). These interfaces are typically used for inter-process communication between a host and a guest virtual machine, or between guest virtual machines, and may indicate malicious activity such as lateral movement from a virtualized environment, virtual machine escape attempts, or unauthorized communication within an ESXi host environment.
Page 458 of 1866








