Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects access to the FileZilla RecentServers.xml file, which contains historical server connection information. Attackers frequently target this file to extract stored FTP credentials, hostnames, and usernames for lateral movement or data exfiltration.
Detects the execution of Windows Script Host (wscript.exe) where the Interactive mode is explicitly disabled in the script content or command line arguments. Disabling interactive mode is a common technique used by attackers to ensure malicious scripts run silently without triggering UI prompts or requiring user interaction.
Detects Run key persistence for follow-on ACRStealer payloads (creator-ws.exe under ProgramData\Rapid, pgocvt.exe under ProgramData\TIEmounter) launched via a cmd /c start wrapper.
Detects the creation of domain user accounts using the native 'net.exe' or 'net1.exe' utilities with command-line arguments that include '/add', '/dom', and naming conventions indicating 'backup_DA' or 'backup_EA'. This pattern is often associated with adversary attempts to establish persistence or backdoors using privileged service-like account names.
Detects the installation or creation of a Windows service related to RustDesk, a remote access software application. This may indicate unauthorized installation or persistence setup of remote control tools by an adversary.
Detects rapid execution of multiple system discovery commands (systeminfo, nltest, whoami, quser, ping) within a 15-minute window on a single host. Attackers often use these tools sequentially to gather intelligence about the environment, user identity, and network topography post-compromise.
This rule detects the creation of a Windows service named 'Cloud Sync Service' using command-line tools like 'sc.exe' or 'New-Service', or via direct service event monitoring. This behavior is often associated with malware persistence mechanisms that use misleading names to blend in with legitimate software services.
Detects network activity associated with the PureLogs Stealer, specifically connections to identified infrastructure hosting payloads on Pixeldrain and attempts to retrieve steganographic payloads via specific API endpoints.
Detects process hollowing/injection into wab.exe, MSBuild.exe, dllhost.exe, or rundll32.exe — suspended process creation combined with SetThreadContext or NtQueueApcThread on the same process within a 5-minute window, followed by an outbound connection to known ACRStealer C2 (49.13.169.214) or renewed browser credential-store access.
Windows Multiple User Accounts Disabled
Cortex XDR
Detects five or more distinct Windows user-account disable events (Event ID 4725) performed by the same actor on the same host within a one-hour time bucket, which may indicate unauthorized account access removal.
Detects potential exploitation of the ScreenConnect SetupWizard.aspx to bypass authentication and create unauthorized administrative users. The rule monitors for the creation or modification of User.xml or Users.xml files in the ScreenConnect application directories, correlating these file events with suspicious process activity (such as cmd.exe or powershell.exe) or web requests to the SetupWizard.aspx endpoint.
Detects completed administrative actions within the Cortex management console that result in a pause of endpoint protection. This action reduces security coverage on the targeted host and requires validation to ensure it aligns with authorized maintenance, troubleshooting, or incident response activities.
The following analytic detects non-Chrome processes attempting to access the Chrome extensions file.
It leverages Windows Security Event logs, specifically event code 4663, to identify this behavior.
This activity is significant because adversaries may exploit this file to extract sensitive information from the Chrome browser, posing a security risk.
If confirmed malicious, this could lead to unauthorized access to stored credentials and other sensitive data, potentially compromising the security of the affected system and broader network.
It leverages Windows Security Event logs, specifically event code 4663, to identify this behavior.
This activity is significant because adversaries may exploit this file to extract sensitive information from the Chrome browser, posing a security risk.
If confirmed malicious, this could lead to unauthorized access to stored credentials and other sensitive data, potentially compromising the security of the affected system and broader network.
The following analytic detects the execution of the 'rmdir' command with '/s' and '/q' options to delete files and directory trees. This detection leverages data from Endpoint Detection and Response (EDR) agents, focusing on command-line executions and process metadata. This activity is significant as it may indicate malware attempting to remove traces or components during cleanup operations. If confirmed malicious, this behavior could allow attackers to eliminate forensic evidence, hinder incident response efforts, and maintain persistence by removing indicators of compromise.
The following analytic detects the suspicious creation of msmpeng.exe or mpsvc.dll in non-default Windows Defender folders. It leverages the Endpoint.Filesystem datamodel to identify instances where these files are created outside their expected directories. This activity is significant because it is associated with the REvil ransomware, which uses DLL side-loading to execute malicious payloads. If confirmed malicious, this could lead to ransomware deployment, resulting in data encryption, system compromise, and potential data loss or extortion.
Detects C2Looper Rust-based backdoor by requiring at least 3 of 4 weak indicator categories: dynamic API resolution artifacts, v2 debug string, PE section layout, and Rust runtime strings; known hash is an optional fast-path only
Detects at least 3 distinct C2Looper-associated discovery commands (ipconfig /all, whoami /all, nltest /dclist, net group /domain "domain admins"/"domain computers", wmic product get name,version) executed by the same parent process within a 60 second window, reducing false positives from isolated legitimate admin usage of any single command.
Detects the creation of a 'SystemIn.lnk' shortcut file within the Windows Startup folder, as well as the execution of temporary PowerShell scripts ('create_lnk_*.ps1') that use WScript.Shell to establish persistence. This behavior is associated with the QUICAgent backdoor attributed to Operation QUICSILVER.
Detects the use of .NET AesCryptoServiceProvider in PowerShell scripts, which is frequently used by adversaries to decrypt embedded, obfuscated, or encrypted payloads within a script for malicious execution.
Detects Zoom-related processes (zoom.us.exe, Zoom.exe, CptHost.exe) modifying registry keys within the Windows CapabilityAccessManager ConsentStore for webcam or microphone access. This activity indicates the system is recording the time a process initiated hardware access, potentially signaling unauthorized surveillance or post-compromise activity.
Detects TWINLOOT PyArmor 9.2.5-protected implant components via known file hashes combined with expected filesize range and filename/extension pattern (bootstrap-fat.pyc, pyarmor_runtime.pyd, .pyarmor.ikey, embedded vendor ZIP) to reduce false positives from renamed unrelated files with coincidental hash context
Page 460 of 1866






