Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,169 detections
Filters
Last updated
All Time
Detection languages
14,931
13,545
2,503
1,803
1,719
Contributors
7,678
6,007
5,306
4,504
3,957
Categories
17,726
9,432
3,736
3,663
3,653
Platforms
39,169
6,860
6,378
3,772
3,516
Products / Services
10,104
9,405
6,482
1,853
1,706
MITRE Techniques
13,640
12,926
7,897
5,843
4,354
CVEs
50
45
30
30
29
IDS Classtypes
210
56
36
24
19
IDS Protocols
177
171
20
17
4
Detects execution of mshta.exe when initiated by common office or web browser applications, or when command arguments include external network references (URLs/UNC paths) or script protocols (vbscript/javascript), which are common patterns for LOLBAS-based initial access or exploitation.
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
Detects a suspicious sequence of events where a known web server process (e.g., IIS, Nginx, Apache) spawns a command shell process, followed shortly by the creation of a file with a web shell-like extension (.aspx, .jsp, .php) in the same environment. This pattern is indicative of an adversary exploiting a public-facing application to upload and potentially access a web shell.
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
Detects the 'ClickFix' social engineering pattern where a user is instructed to copy and paste a malicious command into the Windows Run dialog. The rule triggers on PowerShell being launched from explorer.exe with 'ExecutionPolicy Bypass', utilizing 'irm' (Invoke-RestMethod) to download content, and saving it to the user's TEMP directory via 'Out-File' for subsequent execution.
Detects the execution of known, signed legitimate binaries (COTFileReadApp.exe or DeElevate64.exe) from user-writable directories, such as %LOCALAPPDATA%\Programs\. This behavior is a common indicator of DLL sideloading, where adversaries utilize a trusted, signed application to execute malicious code by placing a malicious DLL in the same directory as the executable.
Detects a multi-stage evasion sequence where a process first queries the system for virtualization or sandbox artifacts (e.g., VM tools, system information), followed by an intentional sleep or delay to bypass sandbox analysis, and concluding with subsequent process activity. This pattern is characteristic of malware attempting to detect and evade automated analysis environments.
Detects unauthorized data staging activities using archival utilities followed by data exfiltration to known public cloud storage providers. The rule specifically excludes hosts experiencing mass file renaming activity, focusing on extortion-only scenarios where data is stolen without encryption.
Detects the execution of rundll32.exe or regsvr32.exe where the command line arguments reference a DLL that was recently written to the disk on the same host. This behavior is indicative of a RAT or malware dropping a secondary payload (DLL) and immediately executing it using built-in Windows binary proxies to bypass security controls.
This rule detects potential post-exploitation activity where a web server process spawns a command shell, executes system discovery commands, and immediately initiates an outbound network connection. This behavior is indicative of a web-based exploit leading to interactive command execution and subsequent C2 communication.
Detects potential browser-based infostealer activity where a non-standard process, launched from temporary or user-download directories, accesses sensitive browser data files (cookies, login data) followed by a suspicious outbound network connection to a previously unseen domain, matching common patterns for LummaStealer or Vidar malware.
Detects sophisticated in-memory loader activity characterized by a sequence of events: process module loads involving AMSI patching (amsi.dll), fresh ntdll.dll remapping to bypass EDR hooks, and the enumeration of hypervisor-related drivers or services, often associated with advanced payload execution chains like ClickFix.
This rule detects potential process injection or process hollowing attempts by correlating Sysmon Event ID 10 (ProcessAccess) events indicating process memory modification permissions (such as PROCESS_VM_WRITE and PROCESS_CREATE_THREAD) with subsequent Sysmon Event ID 8 (CreateRemoteThread) events targeting the same process. This behavior is indicative of an adversary injecting malicious code into a legitimate host process (e.g., svchost.exe, explorer.exe).
Detects modifications to Windows Registry auto-start keys (Run, RunOnce, Winlogon, or Services) by suspicious processes (e.g., script interpreters, shell, or office applications) or processes running from temporary directories, where the registry value points to paths commonly used by adversaries (AppData, Temp, or ProgramData).
Detects the execution of PowerShell commands that reflectively load .NET assemblies into memory, followed immediately by a process injection event targeting Chromium-based browsers (e.g., chrome.exe) or Firefox. This behavior is highly characteristic of credential harvesting tools like BoundSiphon, which injects code into browser processes to decrypt and extract App-Bound encryption keys.
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
Detects potential 'ClickFix' activity where a browser or file explorer process initiates a shell (e.g., cmd, powershell, osascript) with command arguments indicative of remote script execution, obfuscated commands, or web-based payload downloading. This pattern matches known social engineering tactics that entice users to copy-paste malicious code into a system shell.
This rule detects cross-process operations where common user applications or scripting hosts initiate activity towards sensitive system processes (e.g., lsass.exe, services.exe). This pattern is a frequent indicator of process injection techniques used to achieve code execution in the context of high-privilege or critical system services, often for the purpose of credential theft or persistence.
Detects the execution of 'tscon.exe', a Windows utility used to control Remote Desktop sessions. The rule specifically alerts when 'tscon.exe' is executed with parameters indicative of session hijacking (such as '/dest:') or when it is invoked by suspicious processes or under SYSTEM privileges, which are characteristic of RDP session hijacking techniques used for privilege escalation and lateral movement.
Detects obfuscated PowerShell command lines indicative of malicious file downloading and execution. The detection logic searches for specific indicators such as 'scriptblock', '::create', and numeric obfuscation patterns paired with common .NET web client methods ('net.webclient', 'downloadfile', 'downloadstring') used for staged payloads.
Page 52 of 1866
