Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the fake, undersized RtkNGUI64.exe exiting without reading C:\ProgramData\desktop.ini. Scoped by file size to the known 12,288-byte backdoor binary -- the legitimate, much larger signed Realtek Audio Console also never reads that file, so without this filter every normal launch of the real app would match.
Detects RtkNGUI64.exe creating a mutex named as an 8-character hex string, consistent with the backdoor's CRC-32(USERNAME+USERDOMAIN+COMPUTERNAME) per-victim beacon ID used for single-instance checking.
Requires the 'Realtek'-named WMI object AND (the 19:50 time-trigger query pattern OR the RtkNGUI64.exe destination) together, rather than matching on the name alone -- avoids flagging unrelated benign WMI objects that happen to share the name.
Detects HTTP POST tasking check-ins to /version/check.php using the backdoor's hardcoded, obsolete Chrome 78.0.3904.108 user-agent string.
Consolidated detection for RtkNGUI64.exe spawning cmd.exe to execute CMD= tasking (SYSTEM/PUT/TIME verbs). Merges two previously separate rules that detected the same underlying signal via different tasking-mechanism angles.
This rule detects instances where the Windows Defender Antivirus service (MsMpEng.exe) spawns common command-line shells (cmd.exe, powershell.exe, conhost.exe) while running under the SYSTEM context. This behavior is highly irregular for a security product and is indicative of process injection, exploit payload execution, or anti-tampering bypass attempts.
Detects instances where the Windows spooler driver (winspool.drv) is loaded by a process that subsequently performs suspicious memory operations typical of process injection (e.g., CreateRemoteThreadApiCall, WriteToProcessMemory, ProcessInjection) within a 5-minute window.
Detects anomalous, frequent, or repetitive device crash events (including BSODs) on a single device, which may indicate system instability, hardware failure, or an attempt to induce a Denial of Service (DoS) condition on the endpoint.
Detects devices exhibiting sustained high CPU or memory utilization (>= 90%) for a duration of at least 30 minutes, which may indicate resource exhaustion, performance degradation, or potentially malicious activity such as cryptocurrency mining, denial-of-service, or other unauthorized resource-intensive processes.
Detects high-frequency state changes in authentication events for a single account within a short time window. This type of 'flapping' behavior, where an account repeatedly toggles between different authentication statuses (e.g., success and failure) on one or more hosts, can be an indicator of brute force attempts, credential stuffing, or misconfigured automated authentication services.
This rule detects potential Bumblebee loader activity by identifying files named 'msimg32.dll' that possess specific known builder file versions and exhibit anomalous, dictionary-derived 'gibberish' entries within their PE version information metadata fields (Comments, CompanyName, or FileDescription).
Detects modifications to the 'userPrincipalName' attribute in Active Directory via Security Event ID 5136 where the assigned value lacks an '@' character. This behavior is indicative of the ResetNightmare exploitation technique (CVE-2026-27912), which involves setting the UPN to a bare sAMAccountName to facilitate unauthorized password resets or account takeover.
Detects instances where the legitimate Windows consent.exe process loads the library 'msimg32.dll' from a non-standard system directory, specifically targeting suspicious paths such as user-writable AppData or application installation folders. This behavior is indicative of DLL side-loading, where an attacker places a malicious DLL with the same name as a legitimate library to achieve arbitrary code execution under the context of the trusted consent.exe process.
Detects the use of the built-in Windows tool 'wbadmin.exe' to perform a system backup that specifically includes the Active Directory database (ntds.dit) along with SYSTEM and SECURITY registry hives. This technique is often used by adversaries to perform offline credential theft by creating an accessible copy of sensitive domain files.
Detects the TWINLOOT Python implant's arbitrary shell command handler, in which pythonw.exe running from a non-standard directory (ProgramData, AppData, or Temp) spawns cmd.exe with a /c argument and CREATE_NO_WINDOW creation flags, consistent with the implant's default command handler executing operator-tasked commands with a hidden console window.
Detects the loading of the 'calibre-launcher.dll' library by the 'ebook-edit.exe' process when accompanied by the creation of an 'edit2.hlp' file within a 10-minute window. This behavior pattern is indicative of potential side-loading or exploitation attempts where a legitimate process is coerced into interacting with a malicious or specifically placed helper file.
This rule detects unauthorized or suspicious registration of native Internet Information Services (IIS) modules. It monitors command-line activity involving common administrative tools used to modify IIS configurations (appcmd.exe) and manage .NET assemblies (gacutil.exe), as well as the execution of specific PowerShell cmdlets like New-WebGlobalModule. Such activities are often indicative of an attacker attempting to establish persistence on a web server by loading malicious modules.
Detects the creation of symbolic links involving the Common Log File System (CLFS) path or paths containing 'ShieldBreak', often associated with local privilege escalation exploits that leverage race conditions or symbolic link attacks to interact with kernel-mode components.
Detects static file artifacts bundled with the publicly released ShieldBreak Microsoft Defender exploit kit
Detects the creation of new domain user accounts using the 'net user /add /domain' command. This activity can be indicative of an adversary establishing persistence or escalating privileges within a Windows domain environment.
This rule detects potentially malicious behavior where a process accesses environment variables containing 'TOKIO_WORKER_THREADS' (often associated with Rust applications or specific runtime environments) and simultaneously performs sensitive process operations like 'GetSystemInfo' or 'CreateThread'. This pattern may indicate an attempt by an adversary to perform discovery or process injection within a target application environment.
Page 464 of 1866







