Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
This rule detects file and process activity originating from or involving specific directories and filenames associated with 'Agta' software, including temporary files such as PowerShell scripts and XML tasks. This behavior is indicative of potential unauthorized use of backup or testing utilities for malicious purposes, such as script execution or task manipulation.
This rule identifies two distinct security threats on Windows systems: the execution or presence of files matching a known malicious SHA256 hash list, and modifications to the 'PromptOnSecureDesktop' registry key, which could indicate an attempt to weaken User Account Control (UAC) protections.
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
This rule monitors for processes masquerading as Dell-related software (e.g., 'Dell Window Guard.exe', 'Dell.Virus.Guard.exe') or processes containing the command-line argument 'AgtaBackstage'. It flags devices where multiple variations of these suspicious file names appear or where the specific 'AgtaBackstage' string is present, which is indicative of potential malicious activity or persistence mechanisms using software-related naming conventions.
Detects known AgtaBackup RAT staged installers and dropped payload via SHA-256 hash or characteristic filenames
Detects the creation of files with specific naming patterns (starting with 'agta_av_' for PowerShell scripts or 'agta_task_' for XML files) within the Windows SystemTemp directory. This behavior is indicative of potential staging of malicious scripts or scheduled task definitions by adversaries.
Detects the AgtaBackup RAT keylogger process, which masks itself as a legitimate Windows service ('Window Security Health Services.exe'), running with SYSTEM privileges and lacking a valid digital signature.
This rule monitors for suspicious persistence mechanisms associated with 'Agta Backup' software, specifically looking for the creation of new Windows services, the addition of scheduled tasks, and the manipulation of processes related to 'Credential Guard.exe' within Agta Backup directories. It also tracks the presence of specific file artifacts within the application's install directories, which could indicate unauthorized installation or persistence attempts.
Detects the modification of service permissions for the 'AgtaBackupAgentSvc' service using the 'sdset' command via 'sc.exe', 'cmd.exe', or 'powershell.exe'. Adversaries use this technique to hide services or modify access to them by applying a specific Service Descriptor Definition Language (SDDL) string to bypass security enumeration or maintain persistence.
Detects the 'Credential Guard.exe' process (associated with AgtaBackup RAT) accessing sensitive browser files (Login Data, Cookies, History, Bookmarks) and subsequently exfiltrating data to a specific C2 endpoint.
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
Detects the execution of conhost.exe with the --headless flag, which is commonly observed in Kimsuky LNK-based malware campaigns to execute encoded cmd.exe payloads. This pattern involves the use of certutil or echo commands to deobfuscate and execute embedded scripts, often leveraging hidden windows or process hollowing techniques for persistence and evasion.
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
Detects attempts to exploit a vulnerability (CVE-2026-68536) in the Apache MyFaces JSF resource handler. The rule monitors for malicious URI parameters ('ln' or 'library') that attempt Server-Side Request Forgery (SSRF) targeting cloud metadata services, path traversal, or URI-based injection attacks.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Page 50 of 1866


