Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects executables launched by common LOLBins (msiexec, powershell, cmd, wscript, cscript, regsvr32, rundll32)
that are either signed by a non-Microsoft/non-trusted-third-party publisher, or entirely unsigned.
that are either signed by a non-Microsoft/non-trusted-third-party publisher, or entirely unsigned.
The following analytic detects non-Firefox processes accessing the Firefox profile directory, which contains sensitive user data such as login credentials, browsing history, and cookies. It leverages Windows Security Event logs, specifically event code 4663, to monitor access attempts. This activity is significant because it may indicate attempts by malware, such as RATs or trojans, to harvest user information. If confirmed malicious, this behavior could lead to data exfiltration, unauthorized access to user accounts, and further compromise of the affected system.
This rule detects scenarios where a new user account is created (Event ID 4720) and is subsequently logged into (Event ID 4624) within a 30-minute window. This behavior can indicate an adversary creating a backdoor or service account for persistence or lateral movement, followed by immediate usage of that account.
This rule detects network connections from common administrative processes (such as PowerShell, CMD, WScript, or Rundll32) to known dynamic DNS providers. This pattern is frequently indicative of malware beacons, command and control (C2) communication, or other unauthorized remote access tools utilizing dynamic DNS services to maintain connectivity to adversary infrastructure.
Detects run.pyw wrapper scripts embedding RC4-encrypted RAT blob with key-schedule byte pattern and ChaCha20 decryption routine with constant signature, for EtherHiding C2 config, used by DeviceManager RAT
Detects the DeviceManager RAT (run.pyw, spawned via python.exe/pythonw.exe) launching PowerShell or cmd with encoded/obfuscated arguments (-enc, -EncodedCommand, -e, -nop, -w hidden), consistent with C2-tasked arbitrary command execution.
This rule detects when Microsoft Defender SmartScreen identifies and blocks or warns users about access to known 'ClickFix' phishing landing pages. These pages often attempt to social engineer users into executing malicious commands via copy-paste actions (e.g., in a terminal or Run dialog) as a deceptive remediation step for fake browser errors.
This rule identifies non-Microsoft processes (based on file name, file company name, and process signer) that initiate network connections to known Microsoft authentication endpoints. This behavior is often indicative of an adversary-controlled process attempting to leverage cloud services or perform authentication-related activities outside of expected system or productivity software.
Detects certutil.exe -urlcache usage or PowerShell Invoke-WebRequest retrieving main.exe/cryptor.exe or similarly named payloads, followed by execution of the downloaded file, excluding downloads from an allowlist of approved internal software-distribution domains.
This rule detects the use of native Windows utilities 'vssadmin.exe' and 'wmic.exe' to delete Volume Shadow Copies. This activity is a common tactic used by ransomware and other malicious actors to prevent system recovery by destroying backups, and is classified as Inhibit System Recovery.
This rule detects the use of the 'bcdedit.exe' utility to modify Windows Boot Configuration Data (BCD) settings to disable system recovery features, such as boot recovery or automatic failure handling. Such actions are commonly performed by ransomware or other destructive malware to prevent system restoration after encryption or data damage.
Correlates DNS TXT-tunneling activity and HTTP POST traffic from the same host resolving to the same base destination domain within a 2-minute window, with minimum volume thresholds on each channel, consistent with malware that branches between DNS tunneling and HTTP POST C2 modes based on the first byte of a decrypted configuration string.
This rule detects potential multi-stage desktop takeover attacks by monitoring sequences of process execution within a 5-minute window. It looks for initial shell (explorer.exe or cmd.exe) spawning script-based tools (mshta.exe, wscript.exe, cscript.exe, powershell.exe, cmd.exe) with suspicious command-line arguments (extensions like .lnk, .url, .hta, or PowerShell-specific artifacts like 'IEX', 'DownloadString', or '-enc'). This is immediately followed by a secondary stage where PowerShell, cmd, or rundll32 are used to load external DLLs, register modules via regsvr32, or interact with AppData/Local/Temp directories, indicative of payload staging and execution.
This rule detects potential adversary activity aimed at disabling security tools, critical infrastructure services, or cloud synchronization agents. It monitors for a high volume (6 or more) of process termination commands (e.g., taskkill, net stop) or registry-based service disabling (Start value 4) targeting a predefined list of security and critical system services within a 3-minute window, which is indicative of an attempt to blind security monitoring or disrupt system availability.
This rule detects mass disabling of Windows Event Log channels by monitoring registry value modifications where multiple 'Enabled' values are set to '0' within a short timeframe. This behavior is indicative of anti-forensics activity where an adversary attempts to suppress specific log sources to evade detection.
Detects instances where a VS Code or similar IDE process launches suspicious child processes (Python or temporary executables) shortly after an extension installation or modification event, followed by an outbound network connection to a .workers.dev domain. This behavior is indicative of a malicious IDE extension establishing an interactive command and control (C2) channel or exfiltrating data.
Detects a security-software presence check (360 Total Security/eScan process names) followed within 10 minutes by a persistence-establishing event from the same parent process.
Detects registration/activity of the msagent.sys filesystem minifilter driver used to deny access to and hide CoolClient-protected files and directories.
Detects DLL sideloading where a renamed Sangfor executable (defender.exe/Sang.exe) loads libngs.dll/libsrapc.dll outside the legitimate install path or with a signer mismatch.
Detects modification of the CoolClient rootkit's stealth-configuration registry value (Wid_H1deF5Dirs) under the \SYSTEM\RNG hive.
Detects CoolClient's elevated self-relaunch using the 'passuac' command-line parameter combined with RPC-based process creation and PPID spoofing to bypass UAC.
Page 475 of 1866



