Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects C2Looper sideloading a malicious wtsapi32.dll from a non-System32 path by terminating and relaunching the legitimate OneDrive.exe process to load it.
Detects C2Looper injecting shellcode into the legitimate winspool.drv module via a remote thread, excluding legitimate print subsystem processes.
Detects C2Looper disabling Windows Error Reporting via registry modification to suppress crash dialogs, excluding common enterprise provisioning tools that legitimately configure the same keys.
Detects presence of persona-fabrication and identity-fraud enablement software (Wavebox, MEmu, eSIM Plus, Blacktel, insertFace, TrustID Card) via process, network, or file-system artifacts on an endpoint, consistent with PurpleDelta identity-fraud tradecraft.
Detects execution of face-swapping or deepfake software, excluding known legitimate virtual-background/video-filter tools, consistent with PurpleDelta operators disguising their identity during video interviews.
Detects the compiled ShieldBreak C++ proof-of-concept exploit binary via embedded source/resource path strings and PE header, indicating local possession or execution of the CVE-2026-50656 Defender bypass PoC.
Detects loading of Warden.dll — the Defender-bypass component of the ShieldBreak exploit — when unsigned or not signed by Microsoft, excluding legitimate signed Defender platform update binaries.
The following analytic identifies non-Chrome processes accessing the Chrome user data file "login data."
This file is an SQLite database containing sensitive information, including saved passwords.
The detection leverages Windows Security Event logs, specifically event code 4663, to monitor access attempts.
This activity is significant as it may indicate attempts by threat actors to extract and decrypt stored passwords, posing a risk to user credentials.
If confirmed malicious, attackers could gain unauthorized access to sensitive accounts and escalate their privileges within the environment.
This file is an SQLite database containing sensitive information, including saved passwords.
The detection leverages Windows Security Event logs, specifically event code 4663, to monitor access attempts.
This activity is significant as it may indicate attempts by threat actors to extract and decrypt stored passwords, posing a risk to user credentials.
If confirmed malicious, attackers could gain unauthorized access to sensitive accounts and escalate their privileges within the environment.
The following analytic detects the use of the taskkill command in a process command line to terminate several known browser processes, a technique commonly employed by the Braodo stealer malware to steal credentials. By forcefully closing browsers like Chrome, Edge, and Firefox, the malware can unlock files that store sensitive information, such as passwords and login data. This detection focuses on identifying taskkill commands targeting these browsers, signaling malicious intent. Early detection allows security teams to investigate and prevent further credential theft and system compromise.
This rule detects the loading of a driver by system utilities (drvinst.exe, pnputil.exe, setupapi.dll, or System process) shortly after a PnP (Plug and Play) device connection event. It specifically flags instances where the driver file is located in suspicious directories (Windows/Temp, Users/Public, AppData/Local/Temp) or the file does not have a .sys extension, which are common indicators of malicious driver installation or BYOVD (Bring Your Own Vulnerable Driver) tactics.
Detects the use of the BITSAdmin utility to create, add, resume, or complete download jobs, which may indicate an adversary attempting to download malicious files or tools onto a system.
Detects vssvc.exe opening a handle to MsMpEng.exe.
In the RedSun exploit, VSS participates in the cloud-file restore race that directs WD to write through the NTFS junction.
This handle acquisition is observed at the exact moment of exploitation.
vssvc querying MsMpEng is not expected in normal operation.
In the RedSun exploit, VSS participates in the cloud-file restore race that directs WD to write through the NTFS junction.
This handle acquisition is observed at the exact moment of exploitation.
vssvc querying MsMpEng is not expected in normal operation.
Detects ACRStealer C2 data-transfer bursts (outbound credential-data exfiltration >100KB, inbound follow-on payload >1MB) correlated with prior credential-sweep and process-injection-stage flowbits, rather than raw transfer size alone.
Detects a malformed/high-entropy repeated-label DNS query pattern used by ACRStealer as a connectivity canary check prior to establishing C2.
Detects sandbox/VM fingerprinting via combined Win32_DiskDrive and Win32_VideoController WMI queries from the same process/host within a short window — anti-analysis behavior observed in the ACRStealer AutoIt payload prior to execution.
Detects CoolClient's data-collection module: co-occurring keylogging hook installation, clipboard access, and Chromium credential-store file access from an unsigned/non-OS-vendor process.
Detects the creation of .php files within the wp-content/uploads directory tree by common web server or PHP-FPM processes. This behavior is indicative of an adversary attempting to drop a web shell via file upload bypass vulnerabilities, such as those exploiting MIME-type manipulation.
Detects StopAndProtect malware binaries via the hardcoded developer source path string, validated against PE format or a known sample hash.
This rule detects suspicious activity where an executable named 'new.exe' located in a temporary directory initiates a process image load of a non-DLL file or an unspecified module. This pattern is indicative of reflective code loading or process injection, where a malicious binary attempts to execute payloads directly in memory rather than relying on standard DLL loading mechanisms.
Potential exploitation of JetBrains TeamCity (Unauthenticated RCE, CVE-2026-63077) looking for suspicious child processes spawned by TeamCity services.
Detects coordinated activity where a PowerShell process executes multiple distinct administrative utilities (such as wevtutil, vssadmin, wbadmin, or bcdedit) to perform destructive actions like clearing event logs, deleting shadow copies, or disabling system recovery settings. This rule uses correlation to identify sequences of at least three distinct commands and utilities, reducing false positives associated with single administrative tasks.
Page 463 of 1866





