Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule detects the presence of command line artifacts, filenames, and strings associated with the SilverFox malware. These strings indicate the execution of a malicious desktop monitoring component ('active_desktop_launcher.exe') or the use of specific IPC/configuration markers ('@@RAPID_CFG_START@@') characteristic of this threat's tradecraft.
This rule detects executable files (ending in .exe) executing from a specific subdirectory within the user's AppData path (\AppData\Microsoft\Update\). This path is often used by adversaries to masquerade malicious activity or persistence mechanisms as legitimate update processes. The rule excludes common system service accounts (SYSTEM, LOCAL SERVICE, NETWORK SERVICE) to reduce noise, focusing on processes initiated by user-level accounts.
Detects the specific pattern associated with Storm-2570 for enabling Remote Desktop Protocol (RDP) on a target host to facilitate lateral movement. The detection looks for registry modifications to disable RDP denial (fDenyTSConnections=0), firewall rules allowing TCP port 3389 via netsh or PowerShell, and the deployment of these configurations using PsExec against a target host list file.
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
This rule detects installation of known malicious npm packages associated with the PhantomSub campaign, which abuse WhatsApp spam channels. It also identifies network connections to known remote C2 channel-list URLs or domains used by these packages to automate channel joining.
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
Detects the VelvetCake malware installation and operational pattern, which utilizes a scheduled task named 'OneDriveUpdateScheduler' to execute PowerShell scripts ('update1.ps1' or 'update2.ps1'). These scripts periodically retrieve modules or payloads from external infrastructure, specifically hardcoded C2 IPs or a dedicated GitHub repository.
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors network, file, and process telemetry for matches against a predefined list of malicious IP addresses, domain names, and file hashes. It flags suspicious network connections to known C2 infrastructure and the presence or execution of known malicious files based on SHA256 and SHA1 indicators.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Detects C:\Windows\System32\wsl.exe spawning a child wsl.exe process from outside the legitimate WSL install locations.
When WSL or bash is invoked, the System32 stub (wsl.exe) looks up the InstallLocation registry key and executes the wsl.exe found there.
An attacker who modifies InstallLocation to a controlled path causes the stub to transparently proxy execution to a malicious payload,
which then appears as a wsl.exe child of the legitimate System32 stub.
When WSL or bash is invoked, the System32 stub (wsl.exe) looks up the InstallLocation registry key and executes the wsl.exe found there.
An attacker who modifies InstallLocation to a controlled path causes the stub to transparently proxy execution to a malicious payload,
which then appears as a wsl.exe child of the legitimate System32 stub.
Detects the use of reg.exe or PowerShell to modify the WSL InstallLocation registry key via command-line arguments.
Legitimate modifications to this key are performed exclusively by the Windows Installer (msiexec.exe) during WSL package installation or update.
Manual use of reg.exe or PowerShell to set this value strongly indicates an attempt to redirect WSL execution to a malicious binary.
Legitimate modifications to this key are performed exclusively by the Windows Installer (msiexec.exe) during WSL package installation or update.
Manual use of reg.exe or PowerShell to set this value strongly indicates an attempt to redirect WSL execution to a malicious binary.
Detects anomalous behavior where a node.exe process establishes an outbound network connection, characteristic of a C2 registration or ping loop, followed shortly by the spawning of an interactive command shell (cmd.exe or powershell.exe) by the same node.exe process. This pattern is indicative of a RAT (Remote Access Trojan) shell handler execution.
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
Detects a sequence of activity indicative of destructive ransomware or wiper behavior on a Windows device. The rule correlates a high volume of file modification, creation, or rename events within a short timeframe with concurrent attempts to delete or modify Windows backup and recovery mechanisms (such as Volume Shadow Copies or Boot Configuration Data) using native administrative utilities.
Detects suspicious post-compromise activity associated with ALPHV/BlackCat affiliates. This rule monitors for anomalous Kerberos ticket requests (e.g., weak encryption types or TGS requests) closely followed by access to sensitive credential stores or tools on the same host, which is indicative of credential harvesting after a session hijacking or initial access event.
Detects coordinated activity characteristic of NotPetya-like lateral movement. It identifies a local account authenticating across multiple hosts (credential reuse), followed by the creation of a transient Windows service (typically for remote command execution) and the invocation of rundll32.exe to execute a DLL export by ordinal on the same device.
Page 49 of 1866



