Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects instances where common web browsers (chrome, msedge, firefox, brave) are spawned as child processes by suspicious parent applications or scripting environments such as PowerShell, CMD, WScript, MSHTA, or Office documents (Winword, Excel). This behavior is often indicative of malicious document execution, file-less malware techniques, or drive-by download attempts.
Detects a low-privileged account manually triggering the 'CreateObjectTask' scheduled task, which is a known technique to force the 'Shell Create Object Handler' (dllhost.exe) to start under the SYSTEM context. This behavior is often associated with pre-exploitation steps for privilege escalation vulnerabilities, specifically those involving OBJREF marshaling targeting specific COM objects.
Detects the VelvetCake malware installation and operational pattern, which utilizes a scheduled task named 'OneDriveUpdateScheduler' to execute PowerShell scripts ('update1.ps1' or 'update2.ps1'). These scripts periodically retrieve modules or payloads from external infrastructure, specifically hardcoded C2 IPs or a dedicated GitHub repository.
This rule monitors endpoint telemetry for known indicators of compromise associated with the Casbaneiro/Ousaban banking trojan. It identifies activity across network connections (IPs and domain patterns), DNS queries for specific C2 domains, and the presence or execution of known malicious file hashes (e.g., PDF lures, HTA, AutoIt scripts, and payload binaries).
This rule monitors for network connections to known malicious domains and IP addresses, as well as the presence or execution of files with specific SHA256 hashes known to be associated with threat activity. The indicators focus on Vercel-hosted domains and specific file hashes linked to recent campaign activity.
Hunts network, HTTP, and email-URL telemetry for known ARToken infrastructure (operator backend IPs and phishing/panel domains). Bounded to a 30-day lookback and tiers matches by confidence: domain hits are high-confidence (attacker-registered infrastructure), while IP hits are medium-confidence since the IPs sit on shared DigitalOcean hosting that can be reassigned to unrelated tenants once ARToken's infrastructure is taken down. Empty/unparsed indicator fields are excluded to avoid spurious matches in the HTTP event parsing branch. No known file hashes are associated with this intel.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors endpoint telemetry for occurrences of known malicious file hashes, C2 IP addresses, and C2 domains. It aggregates file creation/modification events, process execution, and network connections to detect activity associated with known malicious entities.
This rule monitors for file and process creation events associated with known MD5 and SHA256 hashes linked to the Vidar infostealer malware.
Detects the use of reg.exe or PowerShell to modify the WSL InstallLocation registry key via command-line arguments.
Legitimate modifications to this key are performed exclusively by the Windows Installer (msiexec.exe) during WSL package installation or update.
Manual use of reg.exe or PowerShell to set this value strongly indicates an attempt to redirect WSL execution to a malicious binary.
Legitimate modifications to this key are performed exclusively by the Windows Installer (msiexec.exe) during WSL package installation or update.
Manual use of reg.exe or PowerShell to set this value strongly indicates an attempt to redirect WSL execution to a malicious binary.
Detects anomalous behavior where a node.exe process establishes an outbound network connection, characteristic of a C2 registration or ping loop, followed shortly by the spawning of an interactive command shell (cmd.exe or powershell.exe) by the same node.exe process. This pattern is indicative of a RAT (Remote Access Trojan) shell handler execution.
Detects instances where a single Kerberos logon session (TargetLogonId) is utilized to authenticate from multiple distinct source hosts or IP addresses within a one-hour window. This behavior is inconsistent with normal Kerberos authentication patterns and is a strong indicator of Pass-the-Ticket (PtT) activity, commonly associated with tools like Mimikatz or Rubeus where a stolen ticket is injected into multiple sessions or systems.
Detects a sequence of activity indicative of destructive ransomware or wiper behavior on a Windows device. The rule correlates a high volume of file modification, creation, or rename events within a short timeframe with concurrent attempts to delete or modify Windows backup and recovery mechanisms (such as Volume Shadow Copies or Boot Configuration Data) using native administrative utilities.
Detects suspicious post-compromise activity associated with ALPHV/BlackCat affiliates. This rule monitors for anomalous Kerberos ticket requests (e.g., weak encryption types or TGS requests) closely followed by access to sensitive credential stores or tools on the same host, which is indicative of credential harvesting after a session hijacking or initial access event.
Detects coordinated activity characteristic of NotPetya-like lateral movement. It identifies a local account authenticating across multiple hosts (credential reuse), followed by the creation of a transient Windows service (typically for remote command execution) and the invocation of rundll32.exe to execute a DLL export by ordinal on the same device.
This rule performs a retrospective hunt for indicators of compromise (IOCs) associated with the ClosedQuorum malware. It identifies suspicious activity by matching against known file hashes, specific filenames, and network traffic directed towards services (such as DeepSeek, OpenRouter, Mistral, and Discord) which the malware uses for C2 or data exfiltration. The detection logic aggregates results from file system, process, and network telemetry.
This rule monitors for execution of suspicious files or processes and network communication associated with known malicious indicators (hashes, domains, and IP addresses) typically used by specific threat actors for command and control (C2) and payload delivery.
This rule detects file and process activity originating from or involving specific directories and filenames associated with 'Agta' software, including temporary files such as PowerShell scripts and XML tasks. This behavior is indicative of potential unauthorized use of backup or testing utilities for malicious purposes, such as script execution or task manipulation.
This rule identifies two distinct security threats on Windows systems: the execution or presence of files matching a known malicious SHA256 hash list, and modifications to the 'PromptOnSecureDesktop' registry key, which could indicate an attempt to weaken User Account Control (UAC) protections.
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
This rule monitors for processes masquerading as Dell-related software (e.g., 'Dell Window Guard.exe', 'Dell.Virus.Guard.exe') or processes containing the command-line argument 'AgtaBackstage'. It flags devices where multiple variations of these suspicious file names appear or where the specific 'AgtaBackstage' string is present, which is indicative of potential malicious activity or persistence mechanisms using software-related naming conventions.
Page 55 of 1870



