Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects the loading of unsigned DLLs from non-system directories where the DLL filename matches common Windows system libraries. This behavior is indicative of DLL side-loading, where adversaries use a trusted, digitally-signed application to load a malicious DLL in an attempt to bypass security controls and maintain persistence.
Detects the creation of .aspx, .ashx, or .asp files within Exchange OWA/ECP or IIS wwwroot directories by web server processes (w3wp.exe or UMWorkerProcess.exe). This pattern is consistent with web shell deployment following the exploitation of public-facing web applications, a technique often used by threat actors like APT40.
Detects the modification of registry keys under HKLM or HKCU classes related to COM objects, specifically the InprocServer32 subkey, where the default value is changed to point to a DLL in common user-writable locations such as AppData, Temp, or ProgramData. This behavior is indicative of COM Hijacking used for persistence, as observed in Turla (Secret Blizzard) campaigns.
Detects Gamaredon (Armageddon) group activity characterized by Microsoft Office applications (winword.exe or excel.exe) writing to global template files (Normal.dotm or Personal.xlsb) to implant malicious macros, or dropping .vbs or .lnk files into startup or template directories to achieve persistence and facilitate further propagation.
Detects the silent installation of common Remote Monitoring and Management (RMM) tools (ScreenConnect, Atera, AnyDesk) when triggered by potentially suspicious parent processes such as email clients, web browsers, or archive utilities. This pattern is characteristic of MuddyWater's (Mango Sandstorm) post-compromise tradecraft for establishing persistent C2 channels.
Detects the execution of shortcut (.lnk) files located on removable media (USB) that spawn common Windows binaries (powershell.exe, cmd.exe, mshta.exe) with hidden window flags. This behavior is indicative of initial access or lateral movement techniques used by Mustang Panda (Earth Preta) for USB-based malware propagation and DLL side-loading.
Detects Node.js, npm, or npx processes modifying files within common development directories such as .claude/settings.json, .vscode/tasks.json, or node_modules. This behavior is potentially indicative of malicious scripts or supply chain compromises attempting to persist or modify development environments.
This rule performs a sweep across device file and process events to identify the execution or presence of files matching a curated list of 161 SHA256 hashes associated with twelve known malicious threat actors and families (Lynx, ANUBIS, Rhysida, LockBit, ALPHV/BlackCat, Qilin, Medusa, The Gentlemen, NetRunner, Genesis, Pay2Key, and Handala). The rule filters out events occurring in known EDR/AV quarantine or sandbox directory structures and dedupes hits on a per-device and per-hash basis within 24-hour windows to reduce alert noise.
Detects the Antino backdoor components (GatherOsState.exe or a standalone installer) spawning cmd.exe or powershell.exe to execute commands, indicative of command-and-control tasking.
Detects potential persistence mechanism of the Antino implant, involving the creation of a file under the directory '%LOCALAPPDATA%\Windows GatherOSStateKit\' followed by a corresponding entry in the HKCU Run registry key to maintain persistence upon user logon.
Detects a suspicious sequence of events where a remote access tool (RAT) is installed on a device, followed by significantly elevated and anomalous database query activity performed by the same account over an extended period. The rule utilizes a baseline window to identify deviations from normal query volumes while excluding known service accounts and administrative ETL/BI tasks.
Detects mshta.exe, wscript.exe, or cscript.exe initiating network connections to common CDN infrastructure (Cloudflare R2, CloudFront, pages.dev) to retrieve scripts (js, txt, log). This behavior is indicative of a staging phase in a malicious orchestration, often associated with subsequent deserialization attacks and DLL sideloading.
Detects a multi-stage attack pattern involving a non-MFA login to a Citrix portal, followed by lateral movement, and concluding with ransomware deployment behaviors such as shadow copy deletion, recovery disablement, or the dropping of ransom notes associated with ALPHV/BlackCat ransomware.
Detects SQL injection exploitation attempts against MOVEit Transfer targeting the CVE-2023-34362 vulnerability, followed by the deployment and subsequent interaction with the 'human2.aspx' webshell associated with Cl0p ransomware mass-exploitation campaigns.
Detects evidence of the Antino backdoor performing sleep-masking shellcode evasion. The rule monitors for 'slc.dll' being sideloaded by 'GatherOsState.exe' and the subsequent invocation of memory management APIs (VirtualAlloc, NtAllocateVirtualMemory) paired with memory protection changes (VirtualProtect) or thread context modification, which are characteristic behaviors used by Antino to mask malicious shellcode in memory between execution intervals.
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
Detects network activity associated with the 'ClickFix' social engineering campaign, which commonly targets users with fake error messages to trick them into executing malicious commands. The rule identifies communication with known malicious infrastructure (domains and IP addresses) found in CommonSecurityLog events, while implementing filters to exclude common security scanners and deduplicating per-host alerts.
Detects the installation of a browser extension that requests excessive permissions, including proxy configuration ('proxy' and 'webRequestAuthProvider') and unrestricted host access ('<all_urls>'). This pattern is commonly exploited by malicious extensions, such as the 'VPN for X' family, to perform adversary-in-the-middle attacks or proxy browser traffic.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
This rule detects various malicious indicators of compromise (IOCs) across multiple telemetry sources, including DNS queries, web network traffic, file executions, process creation, and email activity. It monitors for interactions with known malicious domains, URLs, file hashes, and specific sender email addresses to identify potential malware distribution or C2 activity.
Detects the modification of AI agent configuration files (e.g., mcp.json, config.json) followed shortly by the agent spawning a child process that matches typical Model Context Protocol (MCP) server execution patterns. This behavior may indicate an attacker has modified the configuration to inject malicious server commands or tools that the AI agent will execute upon next initialization, effectively achieving persistent code execution via the agent's legitimate functionality.
Page 47 of 1870


