Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects malicious JavaScript injection attempts by msaRAT that leverage the Chrome DevTools Protocol (CDP) Runtime.evaluate method. The malware attempts to execute specific code snippets to facilitate flow-controlled data transfers over WebRTC DataChannels using Base64ToArrayBuffer conversions and a 24KB buffer threshold.
Detects the NetworkShareScanner SMB/USB worm by known hash or by unsigned-executable propagation to remote shares/removable drives.
Detects wscript.exe executing OptiDrive.vbs from the %LOCALAPPDATA%\DriveOptimize Technologies\ masquerade directory to invoke the renamed AutoIt interpreter OptiDrive.exe — the ACRStealer staging/masquerade technique.
Detects the creation of a scheduled task using the schtasks.exe utility designed to run with SYSTEM privileges upon system startup. This behavior is often associated with persistence mechanisms where an adversary attempts to maintain long-term access by ensuring malicious code executes automatically with high privileges whenever the system boots.
KQL Query
Detects non-interactive PowerShell invoked via the Sysnative path with -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command -, reading attacker commands from standard input, spawned by a process that is not a known RMM/patch-management agent and is unsigned, low-integrity, or itself suspicious — matching ACRStealer's follow-on command execution.
Detects the unsigned/untrusted DLL tbbmalloc.dll being side-loaded by pgocvt.exe from C:\ProgramData\TIEmounter\, matching ACRStealer's second payload-set DLL side-loading technique.
Detects installation/loading of the DCRCVDrv.sys BYOVD driver at the atypical staging path C:\Windows\Temp\DCRCVDrv.sys — including SCM service registration, \Device\DCRCVDRV_U device/symlink creation, and named kernel share-event objects — distinguishing attacker deployment from a legitimate DLP install.
Windows PowerShell Password Input Window
Cortex XDR
Detects a user-session window titled 'Password Input' associated with PowerShell, PowerShell Core, or PowerShell ISE processes. This technique may be used for GUI-based credential capture or social engineering.
Detects the creation of a new Group Policy Object (GPO) in Active Directory by monitoring Windows Security Event ID 5137 where the object class is 'groupPolicyContainer'. While typically an administrative task, the creation of new GPOs can be a precursor to malicious configuration changes or domain persistence via Group Policy modification.
Windows Multiple User Account Deletions
Cortex XDR
Detects five or more distinct Windows user-account deletion events (Event ID 4726) performed by the same actor on the same host within a one-hour time window, which may indicate unauthorized account access removal or malicious impact activity.
Windows Multiple User Account Creations
Cortex XDR
Detects five or more distinct Windows user-account creation events (Event ID 4720) associated with the same actor and host within a one-hour time bucket, which may indicate unauthorized account creation for persistence or mass provisioning.
Detects the use of net.exe or net1.exe to interact with administrator accounts, specifically looking for attempts to hardcode passwords in the command line or enabling/modifying domain accounts. This is a common pattern for local account persistence, privilege escalation, or lateral movement.
Detects the execution or installation of the cloudflared utility via PowerShell, which is often used by adversaries to establish persistence or remote access tunnels (Cloudflare Tunnel). The rule triggers on process command lines involving 'cloudflared' and '1.ps1' keywords commonly associated with scripted deployment.
Detects the creation of a local user account followed by the modification of the Winlogon SpecialAccounts\UserList registry key to hide the account from the Windows logon UI. This behavior is indicative of persistent access maintenance by adversaries, such as the Andariel threat group.
Detects anomalous child process creation by Zoom client executables (Zoom.exe, CptHost.exe, ZoomOpener.exe, zoom.us), specifically monitoring for command interpreters, script hosts, and browser processes, which may indicate exploitation of the Zoom client for code execution.
Detects creation of a zero-byte C:\ProgramData\desktop.ini by RtkNGUI64.exe, the crash artifact left behind when the implant's config has not been staged on a host.
Detects RtkNGUI64.exe creating or writing to tempcache.tmp during command-output staging, scoped to direct process attribution. The rename-away leg of this file's lifecycle is covered by the separate put-command drop-and-rename detection.
Detects command-history clearing and log-deletion events (history -c, PowerShell history wipe, Clear-EventLog, wevtutil cl) co-occurring with another suspicious indicator (credential access or lateral movement) on the same host within a 1-hour window, excluding scheduled group-policy retention jobs.
Detects RtkNGUI64.exe being launched via a WMI consumer using the 8.3 short-path form (Progra~1\Realtek\Audio), the same masquerading binary used for backdoor persistence.
Detects execution of command shell interpreters (cmd.exe, powershell.exe) associated with specific command-and-control opcodes indicative of the LxBaseRAT remote interactive shell subsystem.
Page 461 of 1866






