Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,178 detections
Filters
Last updated
All Time
Detection languages
14,936
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,966
Categories
17,726
9,432
3,736
3,667
3,662
Platforms
39,178
6,877
6,386
3,772
3,516
Products / Services
10,109
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects execution of msiexec.exe involving specific command-line arguments (CA_Run_EA2AEBC3, Bin_lib_EA2AEBC3) often associated with malicious installers or library side-loading, correlated with the loading of 'lib.dll' by the msiexec process.
Detects endpoint security scanner hits indicating the presence of msaRAT malware, specifically identifying its characteristic double-layer encryption scheme (DTLS transport paired with application-layer ChaCha-Poly1305 encryption) triggered by a 0xFE handshake frame.
This rule detects potential infection by fake-VPN browser extensions associated with the 'Myxa VPN' campaign by monitoring for specific file paths and filenames linked to known malicious extension IDs. Additionally, it monitors for network connections to known command-and-control IP addresses associated with this campaign.
Detects logons using built-in default accounts (Administrator, Guest) or domain-admin accounts occurring outside an established baseline (new host, unusual time, first-ever interactive logon), repeated at least twice and excluding newly-provisioned accounts within their grace period or approved break-glass accounts.
Detects data exfiltration by the Kynx Stealer ChunkSender module which uses HTTP POST requests to a specific ingestion path.
Detects C2Looper injecting shellcode into the legitimate winspool.drv module via a remote thread, excluding legitimate print subsystem processes.
Suricata signature detecting a Zoom annotation CAnnoFormatBlock/CAnnoTextFrame/CAnnoTextRange PDU where a count field (count1-4) precisely exceeds 64, overflowing the 128-byte destination buffer — the wire-level trigger for the ZOOMSDAY buffer overflow, stack overflow, and heap-disclosure primitives (CVE-2026-53413).
This rule detects potential multi-stage desktop takeover attacks by monitoring sequences of process execution within a 5-minute window. It looks for initial shell (explorer.exe or cmd.exe) spawning script-based tools (mshta.exe, wscript.exe, cscript.exe, powershell.exe, cmd.exe) with suspicious command-line arguments (extensions like .lnk, .url, .hta, or PowerShell-specific artifacts like 'IEX', 'DownloadString', or '-enc'). This is immediately followed by a secondary stage where PowerShell, cmd, or rundll32 are used to load external DLLs, register modules via regsvr32, or interact with AppData/Local/Temp directories, indicative of payload staging and execution.
Detects execution of the NetProvider network-monitoring utility from a non-standard install path or in close time proximity to an active videoconferencing session, consistent with PurpleDelta operator self-monitoring of network traffic during interviews.
Detects screen-recording or AI voice-transcription applications (iTop Screen Recorder, Krisp, Caption.Ed) running within 60 minutes of an active videoconferencing session, consistent with PurpleDelta operators recording or transcribing interviews or meetings to generate scripted answers.
Detects rapid self-deletion of the initial ACRStealer payload artifacts (Proper.a3x, BrowserMetrics) within 5 minutes of their creation by the setup_patched.exe/AutoIt execution chain — an indicator-removal behavior.
Detects non-interactive PowerShell launched via the Sysnative path with -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command - reading commands from stdin — the ACRStealer payload's command-execution technique.
Detects the ACRStealer Telegram Dead Drop Resolver handoff: a non-Telegram-client TLS/SNI contact into Telegram's IP range immediately followed by a DNS/TLS/HTTP connection to the resolved C2 domain res.explicittweak.cc.
Detects successful SYSTEM-level privilege escalation via the ShieldBreak exploit, which bypasses the fix for CVE-2026-50656 (RoguePlanet) on fully patched Windows 10, 11, and Server 2025 systems while Microsoft Defender is enabled. Fires when ShieldBreak.exe spawns cmd.exe running as NT AUTHORITY\SYSTEM with a whoami/system confirmation, correlated with Defender activity on the host within a 5-minute window.
Detects HTTP requests using JWR's e-commerce integration masquerade, where a base64-encoded 's' parameter carries harvested card data or a 'cart_data' parameter resolves to a non-Shopify checkout domain used to spoof the WebSocket C2 origin.
This rule detects instances where the Windows Defender Antivirus service (MsMpEng.exe) spawns common command-line shells (cmd.exe, powershell.exe, conhost.exe) while running under the SYSTEM context. This behavior is highly irregular for a security product and is indicative of process injection, exploit payload execution, or anti-tampering bypass attempts.
Detects an AutoIt3.exe/OptiDrive.exe process performing WMI sandbox-fingerprinting queries (Win32_DiskDrive, Win32_VideoController) followed within 15 minutes by access to browser credential files, consistent with ACRStealer's anti-analysis check preceding data collection.
Detects the execution of Windows processes where the file's web-origin metadata (Mark-of-the-Web) contains a referrer URL pointing to the public GitHub Desktop repository. This rule serves as a provenance and threat hunting signal to track the origin of binaries executed in the environment, identifying software potentially derived from this specific source repository.
Detects high or critical severity audit events generated by Cortex XDR Collectors, which may indicate health, connectivity, processing, or configuration issues leading to gaps in security visibility.
Detects DNS queries to definitionupdates.microsoft.com or the go.microsoft.com fwlink redirect used for WD update downloads, when the querying process is not a Windows system component. BlueHammer utilizes these definition updates as part of its exploit chain.
Detects Windows Defender engine (mpengine.dll) or signature database files (*.vdm) being created by any process that is not a Windows Defender component.
BlueHammer extracts these files from the downloaded mpam-fe update package into a UUID-named subdirectory of %TEMP% as part of staging the TOCTOU privilege escalation.
BlueHammer extracts these files from the downloaded mpam-fe update package into a UUID-named subdirectory of %TEMP% as part of staging the TOCTOU privilege escalation.
Page 465 of 1866




