Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects creation of the 'goopdate' Run-key value pointing to Sang.exe/defender.exe with the 'work' argument and a %programdata% path, used by CoolClient for persistence.
Correlates at least 3 of 4 distinct Abyssos background polling threads (clipboard, process list, network connections, screen capture) launched by the same unsigned/unknown-signature parent process within the same 5-minute window.
Detects the DOUBLECUP/ClickFix loader activity which involves a sequence of suspicious command-line execution patterns. The rule correlates three specific behaviors occurring within a 5-minute window: finding PowerShell paths using 'where', searching for the 'ZZ1984' marker using 'findstr', and executing a minimized background command process. This combination is highly indicative of the ClickFix delivery chain used to trick users into running malicious commands.
Detects the Abyssos UAC_BYPASS_FODHELPER technique: a ms-settings\Shell\Open\command registry value set immediately before fodhelper.exe launches an unsigned child payload, silently elevating to a high-integrity process without a UAC prompt.
Detects a WinRAR-extracted OnyxC2 loader spawning an identical self-copy child process from a temp/download path, marking the transition from loader stage to active stealer logic.
Detects creation of the ONYXC2 mutex used by the malware to enforce single-instance execution.
Detects extraction and execution of OnyxC2 lure archives (Setup_File*.zip, Fling-Standalone*.zip) via WinRAR/7-Zip from a Downloads/Temp directory, correlating the archive-open with the lure-named installer executing shortly after.
Matches endpoint file/process hashes and network IPs against a curated, freshness-checked OnyxC2 indicator feed.
Detects creation of a non-default hidden desktop by a browser process, correlated with either an inherited long-lived authenticated browser network session or a non-standard parent process, consistent with OnyxC2's HVNC capability.
Detects a multi-hop HTTP redirect chain traversing two or more known OnyxC2 phishing lure domains from the same host within a two-minute window, consistent with the redirect obfuscation used before final payload delivery.
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
This rule detects potential privilege escalation through the abuse of a debug backdoor in the Wacom WTabletServiceISD service. It identifies when the 'PowerT' registry value is set for the service, followed shortly by the service spawning a command shell (cmd.exe or powershell.exe) under SYSTEM privileges. It specifically excludes scenarios where AutoAdminLogon is enabled, which might otherwise trigger false positives.
This one's the interesting bit they're using Ethereum RPC calls as a C2channel and dumping stolen secrets to attacker-owned public repos tagged "Shai-Hulud: Here We Go Again". Also flags Claude/VS Code config file writes dropped by the worm for lateral persistence across dev machines.
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
Detects the use of native Windows utilities such as vssadmin, wbadmin, wmic, diskshadow, and bcdedit to delete volume shadow copies, backup catalogs, or modify boot configuration to prevent system recovery. The rule explicitly excludes designated backup servers to reduce noise from legitimate management activities.
This rule detects the creation or modification of files within the Google Chrome browser extensions directory by processes other than legitimate Chrome-related binaries (chrome.exe, GoogleUpdate.exe). This activity is highly indicative of malicious browser extension sideloading or persistence, where an adversary attempts to install a rogue extension to achieve goals such as credential theft, session hijacking, or command-and-control communication.
This rule detects potentially unauthorized access or memory dumping attempts against the Local Security Authority Subsystem Service (LSASS) process. It monitors for events where processes interact with LSASS or execute commands containing 'lsass.exe', 'MiniDump', or 'comsvcs.dll', while excluding known administrative and benign processes like Task Manager, Procdump, and Windows Error Reporting.
Detects python.exe executing from unusual locations (AppData, Temp, or ProgramData directories) that subsequently establish outbound network connections, consistent with DeviceManager RAT behavior delivered via the DOUBLECUP loader.
Detect DNS tunnelling via long subdomain labels. The query is useful for identifying DNS queries with unusually long request strings (typically 40+ characters per label) and high volumes of repetitive requests used by attackers to exfiltrate data or run command-and-control (C2) channels.
This rule detects instances where a process that is not a recognized web browser attempts to access sensitive files associated with browser credential stores, such as Login Data, Cookies, and web browser state files. Such activity is commonly associated with infostealer malware, which attempts to exfiltrate saved passwords, session cookies, and autofill information.
Detects execution of a 'setup.mjs' preinstall lifecycle hook, the stage-1 loader used in the
4 August 2026 compromise of the keyv and cacheable npm namespaces. The trojanised package.json
adds "preinstall": "node setup.mjs" while leaving dist/ byte-identical to the last clean
release, so the only execution-time signal is the hook itself. The loader downloads a
standalone Bun runtime and executes an obfuscated second stage (Math_Symbol.js).
4 August 2026 compromise of the keyv and cacheable npm namespaces. The trojanised package.json
adds "preinstall": "node setup.mjs" while leaving dist/ byte-identical to the last clean
release, so the only execution-time signal is the hook itself. The loader downloads a
standalone Bun runtime and executes an obfuscated second stage (Math_Symbol.js).
Page 476 of 1866




