Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects the loading of a driver by system utilities (drvinst.exe, pnputil.exe, setupapi.dll, or System process) shortly after a PnP (Plug and Play) device connection event. It specifically flags instances where the driver file is located in suspicious directories (Windows/Temp, Users/Public, AppData/Local/Temp) or the file does not have a .sys extension, which are common indicators of malicious driver installation or BYOVD (Bring Your Own Vulnerable Driver) tactics.
Detects installation of the 'media_updaten' Windows service configured to run Sang.exe with the 'work' argument, used by CoolClient for persistence.
Detects scheduled-task persistence launching masqueraded defender.exe/Sang.exe with SYSTEM privileges at startup, outside legitimate Windows Defender/Sangfor install paths.
This rule detects potentially malicious PowerShell activity characterized by the co-occurrence of file download indicators (such as Invoke-WebRequest, WebClient, or UserAgent strings) and file execution or staging commands (such as IEX, Expand-Archive, or Copy-Item) within the same command line. It is designed to identify ingress tool transfer and command-line execution patterns often associated with post-exploitation or malware staging, while reducing noise by requiring both download and operational intent.
This rule detects processes initiating network connections to standard POP3 (110, 995) and IMAP (143, 993) ports that are not identified as trusted, well-known mail clients. By filtering out connections from common email application paths and local IP ranges, it aims to identify potentially malicious processes, scripts, or non-standard tools attempting to perform email collection or exfiltration directly from mail servers.
This rule detects the use of the Windows certutil.exe utility with flags commonly abused by adversaries for file downloads (-urlcache, -urlfetch) or file deobfuscation/decoding (-decode, -decodehex, -encode). It specifically targets LOLBIN (Living Off the Land Binary) behavior by monitoring process command line arguments, while providing allowances for common administrative tasks like PKI maintenance or CRL/OCSP updates to minimize false positives.
Detects Defender XDR alerts and evidence potentially related to Certighost / CVE-2026-54121 AD CS abuse, including suspicious certificate requests, Kerberos activity, LDAP security principal anomalies, and possible DCSync or directory replication abuse.
This rule detects suspicious activity originating from an Internet Information Services (IIS) worker process (w3wp.exe) associated with Microsoft SharePoint. It monitors for the spawning of common command-line shells, interpreters, or Living-off-the-Land Binaries (LOLBins) from the SharePoint IIS worker process, which is a potential indicator of Remote Code Execution (RCE) exploitation, specifically targeting vulnerabilities like the hypothetical CVE-2026-45659.
This rule detects the creation of potentially malicious web-accessible files (e.g., .aspx, .ashx, .asmx) within sensitive SharePoint directory paths by the w3wp.exe process. This behavior is indicative of a webshell upload, which is a common persistence mechanism used by adversaries after gaining access to a web server.
Detects unusually large 7-Zip/WinRAR archive creation from non-standard staging directories followed by outbound network activity, consistent with Gunra's data-staging step before double-extortion exfiltration.
Detects registry key/value creation, modification, or deletion by the unsigned OnyxC2 dropper process (Setup_File_92.118.3096.exe) running from a Temp\Rar or Downloads path, consistent with OnyxC2 configuration/persistence storage.
Detects LSASS memory access via PROCESS_VM_READ combined with MiniDumpWriteDump-style API usage from an unsigned or untrusted process, correlated with a nearby dump-file creation, consistent with OnyxC2's premium-tier credential dumping.
Detects HTTP requests to the OnyxC2 backend API sync endpoint (akmuniverstall.top) carrying the characteristic hwid, ownertoken, and botversion=3.0 parameters used for device-fingerprint C2 check-ins.
Detects a low-level keyboard hook or screen-capture API call from an unsigned, non-standard-path process, correlated with periodic image/keystroke buffer file staging, consistent with OnyxC2's premium keylogger/screenshot module.
Correlates the ShieldBreak PoC's 'Exploit succeeded' console output with a SYSTEM-privileged cmd.exe spawn in the same process session within a short window, confirming successful end-to-end exploitation of CVE-2026-50656.
Detects JWR phishing framework client engine script via known SHA256 hashes (standalone high-confidence), or the co-occurrence of anti-debug check, staging path structure, and Simplified Chinese operator status strings
Correlates DNS/network requests to newly observed domains matching JWR's brand-plus-suffix generation pattern across .top/.cfd/.info/.cc TLDs, requiring multiple distinct hostnames sharing the same brand token within a short window to flag likely batch-registered phishing infrastructure.
Detects the hard-coded RC4 key fragment used by BTR.sys to decrypt its transaction structure when co-located within 0x4000 bytes of the FEE1DEAD magic value and Version 2 header field, targeting the encrypted transaction/ADS payload content independent of driver binary version.
Detects suspicious Active Directory Replication Service (ADRS) requests originating from
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.
Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
a machine account (SubjectUserName ending in '$') rather than a legitimate Domain Controller.
Under normal operation, only Domain Controllers initiate replication requests carrying the
DS-Replication-Get-Changes-All right. If a threat actor obtains valid machine account
credentials — for example by abusing certificate-based authentication (PKINIT) to
impersonate a DC after exploiting a CA vulnerability such as CVE-2026-54121 (Certighost),
where a temporary machine account is created to request a DC certificate and then used to
perform DCSync — they can dump all domain credential material including the krbtgt hash.
Detects additions to privileged groups (e.g. Domain Admins) or modification of password-change-policy flags on a previously dormant account being reactivated, excluding changes linked to an approved change-management ticket and weighting more heavily for off-hours or non-standard admin workstation origin.
Detects creation of a scheduled task named 'IntelSoftwareUpdater' via schtasks.exe that launches pythonw.exe with run.pyw, used by the UNC5142 DeviceManager RAT for persistence, relaunching every 10 minutes.
Page 471 of 1866




