Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
39,252 detections
Filters
Last updated
All Time
Detection languages
14,996
13,546
2,513
1,803
1,722
Contributors
7,678
6,007
5,306
4,504
4,026
Categories
17,755
9,465
3,749
3,677
3,674
Platforms
39,252
6,892
6,432
3,782
3,524
Products / Services
10,159
9,415
6,493
1,858
1,706
MITRE Techniques
13,649
12,957
7,908
5,843
4,364
CVEs
50
45
30
30
29
IDS Classtypes
214
56
36
24
19
IDS Protocols
177
171
20
17
8
Detects known AgtaBackup RAT staged installers and dropped payload via SHA-256 hash or characteristic filenames
Detects the creation of files with specific naming patterns (starting with 'agta_av_' for PowerShell scripts or 'agta_task_' for XML files) within the Windows SystemTemp directory. This behavior is indicative of potential staging of malicious scripts or scheduled task definitions by adversaries.
Detects the AgtaBackup RAT keylogger process, which masks itself as a legitimate Windows service ('Window Security Health Services.exe'), running with SYSTEM privileges and lacking a valid digital signature.
This rule monitors for suspicious persistence mechanisms associated with 'Agta Backup' software, specifically looking for the creation of new Windows services, the addition of scheduled tasks, and the manipulation of processes related to 'Credential Guard.exe' within Agta Backup directories. It also tracks the presence of specific file artifacts within the application's install directories, which could indicate unauthorized installation or persistence attempts.
Detects the modification of service permissions for the 'AgtaBackupAgentSvc' service using the 'sdset' command via 'sc.exe', 'cmd.exe', or 'powershell.exe'. Adversaries use this technique to hide services or modify access to them by applying a specific Service Descriptor Definition Language (SDDL) string to bypass security enumeration or maintain persistence.
Detects the 'Credential Guard.exe' process (associated with AgtaBackup RAT) accessing sensitive browser files (Login Data, Cookies, History, Bookmarks) and subsequently exfiltrating data to a specific C2 endpoint.
Detects modifications to the Windows registry key 'PromptOnSecureDesktop' to set it to '0' (disabled). This configuration change effectively disables the secure desktop for User Account Control (UAC) prompts, which is a technique used by adversaries to facilitate UAC bypasses or simplify credential harvesting by making UAC prompts more easily spoofable or interceptable.
Detects the execution of conhost.exe with the --headless flag, which is commonly observed in Kimsuky LNK-based malware campaigns to execute encoded cmd.exe payloads. This pattern involves the use of certutil or echo commands to deobfuscate and execute embedded scripts, often leveraging hidden windows or process hollowing techniques for persistence and evasion.
Detects a sequence of activity where a user receives a high volume of inbound emails (potential vishing or social engineering lures) within a short window, followed by the user executing Windows Remote Assistance or Quick Assist tools within the next 6 hours, which is highly indicative of remote access social engineering pre-cursors.
Detects attempts to exploit a vulnerability (CVE-2026-68536) in the Apache MyFaces JSF resource handler. The rule monitors for malicious URI parameters ('ln' or 'library') that attempt Server-Side Request Forgery (SSRF) targeting cloud metadata services, path traversal, or URI-based injection attacks.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects anomalous file manipulation behavior consistent with the Kothamine agent, characterized by rapid create, write, and delete cycles on a single file. The detection specifically targets processes identified as either explorer.exe with a reflected Kothamine DLL module or the standalone MicrosoftEdgeUpdateCore.exe loader running from an AppData staging path.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects unauthorized access to Windows camera or microphone consent store registry keys by either a suspected Kothamine agent masquerading as 'MicrosoftEdgeUpdateCore.exe' or an injected 'explorer.exe'. The rule correlates these registry access events with the presence of specific Kothamine-related file artifacts (MicrosoftEdgeUpdateCore.dll and tailcat.exe) on the same host within a 24-hour window to minimize noise.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
Detects the initialization and persistence of a 'tailcat.exe' process operating from a non-standard, user-profile directory, typically mimicking legitimate tools. The rule monitors for the specific 'forward' command-line argument containing port mapping strings, an immediate loopback connection to that port, and subsequent periodic external network keep-alive traffic originating from the same process or parent lineage, indicating a C2 tunnel setup.
Detects the execution of VBScript files that use a double extension (.pdf.vbs) via Windows Script Host (wscript.exe or cscript.exe). This technique is commonly used to masquerade malicious scripts as benign PDF documents to deceive users into executing them.
Page 56 of 1870



